The metaencryptor ransomware group has listed Factory Five Racing Inc on its leak site, claiming to have obtained roughly 130GB of the Massachusetts kit-car manufacturer's internal files. Factory Five has not publicly confirmed the claim as of writing. The listing does not state how many people, if any, were affected, nor does it enumerate specific categories of customer information.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch FactoryFive
Get alerted the next time FactoryFive files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about FactoryFive’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Ongoing Lawsuits and Contracts Mean for You
The group claims the material includes detailed records from several active lawsuits — parties, witnesses, testimonies, and case files — along with legal contracts, NDAs, tax documents, banking statements, insurance policies, CRM contacts, and engineering CAD files. These are not the kinds of records that expire. If any of your correspondence, agreements, or dispute-related information with Factory Five was included, that material remains permanently sensitive. Opposing parties in litigation, business competitors, or others with access to the leak could use it to gain advantage in negotiations, court proceedings, or commercial dealings long after passwords have been reset.
What a Ransomware Leak-Site Listing Actually Establishes
Leak sites like metaencryptor’s are marketing tools operated by the extortion crew itself. The group posts samples and volume claims to pressure the target into paying. Many such listings later prove to be recycled from older incidents, exaggerated, or entirely false. The presence of a company name on one of these sites is an accusation, not evidence. Real confirmation would require an admission by Factory Five, a regulatory filing detailing the scope, or forensic findings released by a third-party investigator. Until then, the only fact established is that the group chose to list Factory Five on August 23, 2026. The filing itself provides no incident date, no discovery timeline, and no verified inventory of what, if anything, left the company’s network.
The Pattern Small Manufacturers Are Seeing
Small manufacturing firms have appeared with increasing frequency on ransomware leak sites in recent years. Attackers often target operational data — CAD files, ERP systems, contracts, and legal correspondence — rather than large volumes of customer PII. These listings frequently emphasize the business impact: disrupted production data, exposed pricing, or sensitive litigation materials that could affect ongoing disputes. For customers and business partners of these companies, the recurring risk is not always identity theft but the long-term exposure of relationships, financial arrangements, and legal positions that cannot be reissued like a credit card.