Ncerio News blogCVE feed
What we measure across the estates we audit

Neumaticos Corral S.A. listed on Ransomlook following qilin incident

Automotive parts manufacturer Neumaticos Corral S.A. appears on ransomware leak site Ransomlook after a qilin attack.
29 August 2026

The automotive parts company Neumaticos Corral S.A. has been identified as a victim of a ransomware incident involving the qilin variant. This information originates from public data collected by ransomlook.io, which tracks active extortion groups and their claimed victims.

The specific case is documented on the ransomlook.io platform under a blog entry dedicated to this group. The source lists Neumaticos Corral S.A. as one of the entities affected by the qilin ransomware operation. The platform serves as a repository for information regarding ongoing cybercrime activities, providing details on which organizations have been publicly claimed by threat actors.

According to the listing on ransomlook.io, the incident is categorized under the automotive parts sector. This classification helps contextualize the type of business operations targeted by this particular strain of malware. The data provided on the site indicates that the company's systems were compromised and encrypted, leading to the public naming as part of the extortion process.

The entry on ransomlook.io does not provide extensive technical details regarding the specific vector of initial access or the extent of data exfiltration beyond confirming the encryption event. The primary function of the source is to record and display these claims for monitoring purposes within the cybersecurity community.

This report focuses solely on the public listing of Neumaticos Corral S.A. by the qilin ransomware group as recorded in open-source intelligence databases. It reflects the current status of the incident as observed by external tracking services without implying any internal audit findings or preventive measures related to the target organization.

Source: Neumaticos Corral S.A. โ€” hit by qilin ransomware โ€” ransomlook.io
← all posts  ยท  CVE feed