On February 2, 2026, the incransom ransomware group listed Behbehani Motors Company on its leak site, claiming to hold 1.3TB of the Kuwaiti dealership’s internal files. The company, founded in 1957 as the first Porsche dealership in the Middle East, sells and services Volkswagen and Porsche vehicles and operates a bodyshop and car rental division. The attackers say the data includes internal mail, accounting records, and company customer information, with plans to publish it the following week.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from Reporting
Public reporting indicates the listing appeared on the incransom leak site on February 2, 2026. The group states it exfiltrated 1.3TB of data during a ransomware attack on Behbehani Motors Company. Exposed material is described as internal email, accounting documents, and customer records. No confirmed victim count has been released, and it remains unclear exactly how many individuals’ personal details are contained in the files. The company has not issued a public statement on the breach as of the latest available information.
Why This Matters for You and Your Family
When a business like a car dealership suffers a breach, the customer records it loses often contain names, addresses, phone numbers, email addresses, national identification numbers, and payment details. If your family has ever bought, serviced, rented, or repaired a vehicle with Behbehani Motors, some of that information may now sit on a ransomware leak site. Once published, the data can be downloaded by anyone and combined with other leaks to build a detailed profile of your household. This increases the chance of identity theft, loan fraud in your name, or unwanted contact from scammers who already know you own a Porsche or Volkswagen.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at posting one file dump. They frequently release additional batches to pressure the victim, and the data they expose can link your work email to personal accounts, reveal family member names, or expose vehicle registration details that tie back to your home address. These connections create what security analysts call an identity chain. A single leaked customer record can lead to gaming account takeovers, especially for children whose usernames or parent-linked emails appear in family purchase histories. Credential leaks of this kind have repeatedly cascaded into full doxxing campaigns where attackers publish addresses, phone numbers, and social media handles together.