On January 26, 2026, Prem Motors, a major Maruti Suzuki dealership group based in Gwalior, India, appeared on the leak site of the tengu ransomware group. The company, which operates 58 showrooms and 43 workshops across multiple states, had internal files exfiltrated during a ransomware attack. While the exact number of customers affected remains unknown, anyone who has bought a car, serviced a vehicle, financed a purchase, or bought insurance through Prem Motors since the company was founded in 1990 could have personal data now at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch premmotors.com
Get alerted the next time premmotors.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about premmotors.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that tengu claims to have stolen internal documents from Prem Motors’ networks. The data includes files that typically contain customer names, contact details, addresses, vehicle purchase records, financing agreements, and insurance information. The leak site listing appeared on January 26, 2026, and follows the group’s standard pattern of publishing proof of compromise before threatening wider release. No official statement from Prem Motors had been widely reported at the time of initial publication.
Why This Matters for You and Your Family
If you or anyone in your household has ever interacted with Prem Motors, your information may now sit in a ransomware leak repository. Customer records from car dealerships often include phone numbers, email addresses, physical addresses, dates of birth, and payment details — exactly the building blocks criminals need to impersonate you. For families this can mean sudden spam calls, targeted phishing texts pretending to be from your bank or insurer, or attempts to open loans in your name. Children’s names sometimes appear on family insurance or service records, pulling them into the exposure as well.
The Doxxing and Identity-Chain Risks
A single dealership breach rarely stops at one dataset. Criminals combine the leaked Prem Motors files with information from other sources to build detailed profiles. An email address found here can be matched to a gaming username, a social-media handle, or a reused password from another breach. Once linked, attackers can hijack accounts, publish personal information, or harass family members. Credential leaks like this one frequently cascade into gaming account takeovers, especially for children who use the same email or password across platforms.