On June 12, 2023, Australian automotive climate-control manufacturer Air International appeared on the LockBit 3.0 ransomware leak site. The listing states that internal files were exfiltrated during a ransomware attack on ai-thermal.com and gives the company until a set deadline to negotiate before full publication.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ai-thermal.com
Get alerted the next time ai-thermal.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ai-thermal.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page explicitly names Air International, founded in 1967 in Australia, and states that attackers obtained internal files after gaining access to the company’s systems. The disclosure does not quantify how many records were taken, list specific data types such as customer databases or employee personal information, or reveal the exact ransom demand. It simply states that data was exfiltrated and will be released if the company does not pay. The primary source remains the onion link hosted by the LockBit 3.0 operation, mirrored on ransomware.live.
Why This Matters for You and Your Family
When a manufacturer like Air International suffers a breach, anyone who has ever bought one of their aftermarket air-conditioning units, submitted a warranty claim, or interacted with their global dealer network may have personal details exposed. Even though the exact contents remain undisclosed, ransomware groups routinely harvest names, addresses, phone numbers, email accounts, and payment records. For ordinary customers this can mean sudden spikes in phishing texts, identity-theft attempts, or fraudulent loan applications opened in your name. Your family’s exposure is real because these datasets often contain home addresses tied to vehicle registrations — information that connects digital identities to physical locations.
The Doxxing and Identity-Chain Risk
Exfiltrated internal files frequently include spreadsheets that link customer emails to phone numbers, order histories, and sometimes driver’s-license copies for warranty purposes. Once published on a ransomware site, these records are scraped by dozens of other criminals who chain them with data from previous breaches. A single leaked email can reveal your username on a gaming platform, your child’s Roblox or Fortnite account, and your home address within hours. This creates persistent doxxing chains that lead to swatting, harassment, or targeted social-engineering attacks. Credential leaks of this nature routinely cascade into account takeovers precisely because people reuse the same password across work, shopping, and gaming services.