California Truck Equipment Data Breach

Alleged

Ransomware claim involving California Truck Equipment.

Published: Aug 26, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
California Truck Equipment
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Aug 26, 2026

Executive Summary

On August 26, 2026, the Qilin ransomware group added California Truck Equipment (CTEC) to its dark web leak portal. CTEC, a United States-based manufacturer and upfitter of custom truck bodies for commercial and government fleet applications, was identified through SOCRadar’s Dark Web Monitoring service. This listing is considered an allegation and not a confirmed breach. The company’s role in providing specialized vehicle upfitting services for government fleet customers makes it a potential target for ransomware operations. In the 60 days preceding this claim, Qilin had listed 217 victims, indicating significant operational tempo. Transportation organizations frequently appear in their victimology, with notable examples including WIS LOGISTICS (US), AGUNSA (Chile), DELTA WAYS (Germany), and G.M.A. GRANDI MARCHE AUTOMOBILI (Italy). Qilin primarily targets organizations in the United States, Germany, and Italy, with a preference for the Manufacturing, Professional Services, and Technology sectors. CTEC’s profile aligns well with Qilin’s established targeting patterns.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for the domain ctec-truckbody[.]com returned no records within the queried dataset. It is important to note that this result covers only a paginated sample. Data exposure may exist in threat feeds outside this specific dataset, under alternate corporate domains, or via personal email aliases used by employees. Ransomware groups like Qilin, and the initial access brokers they collaborate with, heavily depend on credentials harvested from stealer logs to gain authenticated access to corporate portals. Such access is often a precursor to ransomware deployment. While the absence of records in this particular query is noted, it does not definitively rule out a compromise, as credentials might have been used and rotated prior to indexing, or may exist in unindexed data. The absence of direct telemetry findings should not be interpreted as evidence of no compromise. Continued monitoring of ctec-truckbody[.]com and proactive credential hygiene practices across the organization are recommended. This includes regular password rotation and reviewing authentication logs for any unusual activity, particularly concerning Microsoft 365, VPNs, and remote access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.