GBHackers

CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data


The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems.

According to CyberWatch, first flagged on its data-leak portal, the target is described as a “Korean automotive manufacturer (Turkish operations)” with the compromised infrastructure tied to hyundai.com.tr.

The listing categorizes the attack as an automotive sector attack, with the target location specified as Istanbul, Turkey.

As of publication, the entry carries a “pending” status, with the group’s countdown timer showing roughly four days remaining before the alleged data cascade is triggered, and the listing has already drawn over 3,100 unique views on the leak site.

CRPx0 Ransomware Claims Hyundai Turkey Breach

CRPx0 claims the stolen 1.5 GB archive spans several categories of highly sensitive HR and recruitment information. The trove reportedly includes candidate assessment data, such as interview answers, evaluation scores, and results, as well as recruitment source information and candidate tracking records.

It also allegedly contains proctored exam data, including photos and videos captured during testing sessions, as well as executive assessment reports covering psychometric tests and personality analyses for both candidates and management personnel.

Rounding out the claimed haul are evaluation criteria, scoring documentation, and selection materials tied to key positions, along with internal email correspondence related to recruitment and personnel evaluation.

The presence of biometric proctoring footage alongside psychometric evaluation data raises the stakes considerably, since such material can be used for targeted social engineering or identity-based fraud against both candidates and executives if leaked publicly.

Following the standard double-extortion playbook, CRPx0 states the stolen data is currently held on its own servers and that Hyundai has been notified with an opportunity to resolve the matter privately before a public deadline.

The group has published Tox and Session messenger identifiers on the leak page as designated negotiation and purchase channels, a tactic consistent with ransomware crews that avoid centralized, easily seized infrastructure for ransom communications.

CRPx0 has been increasingly active in mid-2026, having recently added a batch of Turkey-based victims and a separate cluster of 10 U.S.-based organizations to its leak portal.

Security researchers at Aryaka Threat Research Labs have separately profiled the group’s malware operations, describing a Python-based, cross-platform loader that runs on both Windows and macOS.

This combines file encryption with cryptocurrency theft via clipboard hijacking and wallet seed-phrase harvesting, alongside live command-and-control communication for staged payload deployment.

This is not Hyundai’s first brush with ransomware actors; the Black Basta group claimed to have stolen roughly 3 terabytes of data from Hyundai Motor Europe in early 2024, and Hyundai AutoEver America disclosed a separate breach in 2025 affecting employees’ Social Security numbers and driver’s license data.

The recurring targeting of Hyundai’s regional subsidiaries underscores a persistent pattern of exposure across the group’s decentralized IT environments, particularly in HR and recruitment platforms, which often receive less security scrutiny than production or customer-facing systems.

Hyundai has not issued a public statement confirming the CRPx0 claims at the time of writing, and the authenticity of the leaked sample has not been independently verified.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.





Source link