On December 07, 2023, British bus manufacturer Alexander Dennis appeared on the leak site of the Black Basta ransomware group. The listing states that attackers exfiltrated 507 GB of internal files covering Group data, HR, Finance, Legal, Engineering, and other departments following a ransomware incident. The company, which holds roughly half the UK bus and coach market and operates plants and partnerships across North America, Asia, Europe, and Africa, has not publicly quantified how many individuals may be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch alexander-dennis.com
Get alerted the next time alexander-dennis.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about alexander-dennis.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Black Basta leak site entry, still accessible via its onion address as of the initial publication, claims the data was taken during a ransomware attack and lists the exposed material under six broad categories: Group data, HR, Finance, Legal, Engineering, and “Departments and etc.” The disclosure does not specify the exact number of records involved, nor does it name individual files or confirm whether customer or supplier information was taken. It simply presents the 507 GB volume as proof of successful exfiltration and sets an implicit deadline typical of the group’s double-extortion model.
Public reporting on Black Basta indicates the actors follow a pattern of encrypting victim networks while simultaneously removing sensitive files to use as leverage for ransom payment. When payment is not made, samples or full archives are published on their leak portal to pressure the victim and any third parties whose data may be inside the archive.
Why This Matters for You and Your Family
Even though Alexander Dennis is a commercial vehicle builder rather than a consumer-facing retailer, its HR, Finance, and Legal folders almost certainly contain personal information belonging to current and former employees, contractors, and possibly their dependents. If your name, address, date of birth, national insurance number, salary details, bank account information, or family contact data sat inside those folders, it may now be in the hands of criminals. That information does not expire. It can be sold, traded, or used years later to impersonate you, file fraudulent tax returns, or open accounts in your name.