RANSOMWARE VICTIMMANUFACTURINGDUPLICATE CLAIM

Crown Automotive Sales

www.crownautomotivesales.com
sinobi📍 United States (US)📅 October 28, 2025
8
same group

Attack Intelligence

Crown Automotive Sales was compromised in a ransomware attack attributed to sinobi in October 2025. The organization, operating in the Manufacturing sector in United States, was added to the group's data leak site as part of an extortion campaign.

sinobi operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Crown Automotive Sales Co specializes in providing high-quality replacement parts for Jeep, Chrysler, and Dodge vehicles. With over 8,000 part numbers and a diverse range of applications, the company supplies authorized dealers with essential components for both maintenance and upgrades. Additionally, their RT Off-Road line features performance accessories specifically tailored for Jeep models. The company has been a key player in the automotive parts industry since 1963, serving retailers and dealers exclusively.

Additional Details

Other Victims — sinobi (8)

Quick Facts

CountryUnited States (US)
SectorManufacturing
Attack DateOct 28, 2025
Domainwww.crownautomotivesales.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

sinobi
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.