On May 7, 2024, the French automotive group GORRIAS appeared on the LockBit 3.0 ransomware leak site. The company, which has sold and serviced Mercedes-Benz vehicles across the Hauts-de-France region for more than three decades, was listed after a ransomware attack in which internal files were allegedly exfiltrated. The disclosure does not specify how many individuals are affected or exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch gorrias-mercedes-benz.fr
Get alerted the next time gorrias-mercedes-benz.fr files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about gorrias-mercedes-benz.fr’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page states that data was stolen from GORRIAS during a ransomware intrusion and that the files remain available for download on the extortion platform. No customer record count is published, and the listing does not itemize the precise data types beyond describing them as internal files exfiltrated in a ransomware attack. The notification window shown on the site follows LockBit’s standard countdown format, after which the group typically escalates by publishing or selling the archive. Public mirrors of the onion page, such as those aggregated on ransomware.live, state the listing date as May 7, 2024.
Why This Matters for You and Your Family
When a regional car dealership and service group suffers a breach, the people most exposed are ordinary customers who bought vehicles, financed purchases, booked repairs, or left contact details for test drives and warranty work. That information often includes names, home addresses, phone numbers, email addresses, driver’s license data, and financial details tied to vehicle loans. Even without an exact headcount, the regional focus means thousands of families in northern France likely had personal data inside the compromised systems. Once exfiltrated, these records do not expire; they circulate on dark-web markets for years and can be combined with other leaks to build detailed profiles.
The Doxxing and Identity-Chain Risk
Stolen dealership files frequently contain enough personal anchors to link an individual’s real identity to their online handles, social-media accounts, and even children’s gaming profiles. A single address or phone number recovered from a service record can be cross-referenced with credential leaks from other breaches, enabling attackers to hijack email, reset banking passwords, or impersonate victims to family members. Credential leaks like this one cascade into account takeovers and doxxing chains, especially when gaming accounts belonging to children share the same household email or phone. Continuous monitoring across 13.1B+ breach records and 100+ platforms, combined with AI-powered identity-chain mapping, becomes essential for spotting these connections before harm occurs.