LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Yokohama-oht (atgtire) Listed by akira Ransomware Group

HIGH severityUnverified claimHow we verify

Yokohama-oht (atgtire) Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 21, 2023
Yokohama-oht (atgtire) Listed by akira Ransomware Group

Reported June 21, 2023.

HIGH
Severity
June 21, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Yokohama-oht (atgtire) Listed by akira Ransomware Group (reported June 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure industrial and manufacturing firms by pairing encryption with the threat of public data leaks, a pattern that has become routine across the automotive and heavy-equipment supply chain. In that climate, the appearance of Yokohama-oht (atgtire) on a ransomware leak site in mid-2023 fits a familiar script: an organisation is named, a volume of material is advertised, and the claim itself becomes the first public signal that something may have gone wrong.

On 21 June 2023 the Akira ransomware group listed Yokohama-oht (atgtire), identified in the group’s own wording as Yokohama Off-Highway Tires America Inc. The listing asserted that internal files had been taken in a ransomware attack and that roughly 1.3 TB of data would be published. The number of people affected remains unknown, and independent confirmation of the intrusion has not been supplied in the available record. The episode matters because any organisation that holds operational, commercial or employee information can become a vector for secondary harm once that material leaves its control.

Inside the incident

Public detail is limited to the leak-site entry dated 21 June 2023. According to that entry, Akira claimed to have exfiltrated internal files belonging to Yokohama Off-Highway Tires America Inc and stated that the volume of material was 1.3 TB, which the group said would be made available “soon.” No technical description of the initial access method, no timeline of the intrusion, and no confirmed count of affected individuals have been disclosed in the facts at hand. The listing itself constitutes an unverified claim by the threat actor; whether the data were in fact stolen, whether encryption occurred, and whether any ransom demand was paid or refused are not established by independent reporting within the given record.

What is known is therefore narrow: a named industrial company appeared on Akira’s leak site, the actor characterised the material as internal files from a ransomware attack, and a specific data volume was advertised. Everything beyond those assertions remains undisclosed.

Who is akira?

Akira is a ransomware operation that became publicly visible in early 2023. Like many contemporary groups, it has favoured double-extortion tactics: encrypting systems while simultaneously copying data and threatening to publish it if payment is not made. The group has typically posted victim names and sample descriptions on a dedicated leak site, sometimes accompanied by statements about data volume or industry sector. Its targets have spanned manufacturing, professional services and other mid-sized enterprises, reflecting a broad rather than highly specialised victimology.

Public reporting on Akira has noted the use of common initial-access routes seen across the ransomware ecosystem—stolen credentials, exposed remote-access services, and exploitation of unpatched systems—though the precise technique used against any single victim is rarely confirmed by the group itself. In this case, the only statement attributed to Akira is the leak-site claim that it took 1.3 TB of internal files from Yokohama Off-Highway Tires America Inc and intended to release them. No further specific assertions by the group about this victim appear in the available facts.

Who is Yokohama-oht (atgtire)?

Yokohama-oht (atgtire) is identified in the incident record as Yokohama Off-Highway Tires America Inc, a company operating in the automotive and off-highway tire sector. Organisations of this type design, manufacture or distribute specialised tires for construction, agricultural, industrial and other heavy-duty equipment. They typically maintain engineering documentation, supplier and customer contracts, logistics data, employee records, and commercial pricing or product information.

A breach involving such a firm is consequential because the sector sits inside larger supply chains. Disruption or exposure of internal material can affect not only the company itself but also dealers, fleet operators and original-equipment manufacturers that rely on timely product and technical data. Even when the precise contents of a claimed leak remain unverified, the mere assertion that a well-known tire business’s “secrets” may appear publicly raises practical concerns for partners and staff whose information could be mixed into the same repositories.

What data was at risk

The facts state that the exposed material was described as internal files exfiltrated in a ransomware attack, with the actor claiming a volume of 1.3 TB. No further breakdown—such as whether the files included employee personal data, customer lists, financial records, or engineering drawings—has been disclosed. Exact contents are therefore unconfirmed.

Companies in the off-highway tire and automotive-supply space ordinarily hold a mix of operational and personal information: human-resources files, business correspondence, design or testing documents, and commercial agreements. It is reasonable to expect that some combination of those categories could have been present in a large internal archive, yet it would be inaccurate to treat any specific category as proven in this incident. Until independent verification or an official statement appears, the only firm description remains the actor’s claim of “internal files” totalling 1.3 TB.

Why it matters

For individuals whose details may have been stored by the company, the practical risks are familiar: possible misuse of contact or identity information, targeted phishing that references genuine internal context, and longer-term exposure if documents later circulate on criminal forums. For the organisation, the consequences can include operational distraction, contractual notifications, and erosion of trust among suppliers and customers even when the full scope of the leak stays unconfirmed.

Because the number of people affected is unknown and the precise data types beyond “internal files” are undisclosed, the scale of personal harm cannot be quantified from the public record. The incident still illustrates how ransomware listings function as pressure tools: the threat of publication alone can compel costly response activity and leave employees and partners uncertain about their own exposure.

What to do if you're exposed

If you have a past or present relationship with Yokohama Off-Highway Tires America Inc or related entities, treat the listing as a prompt to review your own posture rather than as confirmed proof that your data were taken. Practical first steps include:

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such checks do not confirm involvement in this specific incident, but they provide a concrete starting point for personal risk assessment while public detail remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyYokohama-oht (atgtire) security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Yokohama-oht (atgtire)’s full breach history →

More recent breaches

International Electronic Machines Corp Listed by akira Ransomware GroupDecember 25, 2023SmartWave Technologies Listed by akira Ransomware GroupDecember 12, 2023Nissan Australia Listed by akira Ransomware GroupDecember 6, 2023Midea Carrier Listed by akira Ransomware GroupDecember 4, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Yokohama-oht (atgtire) Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram