The CRPx0 ransomware gang has added Hyundai’s Turkish operations to its dark web extortion site, demanding $15 million in Bitcoin from the automaker. CRPx0 Ransomware Claims Hyundai Turkey Breach The listing reveals Hyundai's automotive sector operations located in Istanbul, Turkey, with a leaked volume of 1.5 GB and over 3,143 unique views as of publication on their portal. Initial infection chains relied on social engineering lures, such as fake OnlyFans account offers packaged in malicious ZIP files containing shortcuts that deploy the malware instead of the promised content.

Aryaka Threat Research Labs has been tracking this campaign since its emergence, describing it as a highly organized, staged operation built on a Python-based execution framework with persistent command-and-control communication.

This incident follows a pattern of repeated cybersecurity setbacks affecting Hyundai's global operations, including a 2024 Black Basta attack on its European division and a 2025 breach at Hyundai AutoEver America that affected millions of customer records. CyberWatch notes that CRPx0’s dual focus on cryptocurrency theft and sensitive HR data suggests operators may seek to monetize both financial assets and reputational leverage against victims who fail to negotiate before the countdown expires. Cut SOC investigation blind spots and contain threats earlier with ANY.RUN.