On 21 September the MetaEncryptor ransomware crew added Astemo, Ltd. to its data leak site. Astemo is one of the world's larger automotive suppliers: a Tokyo-headquartered maker of braking, steering, powertrain and driver-assistance systems with roughly 80,000 employees, majority owned by Honda with Hitachi keeping a stake. According to the ransomware.live tracker entry for the listing, the crew posted a screenshot as supposed proof.
That is all the evidence there is. Astemo has published nothing confirming an intrusion, and the listing says nothing about what, if anything, was taken. Treat it as a criminal group's assertion until the company says otherwise.
A supplier wired into the global car industry
Astemo was formed in January 2021 when Hitachi Automotive Systems merged with three Honda-affiliated suppliers, Keihin, Showa and Nissin Kogyo, and it dropped the Hitachi prefix from its name in April 2025. That lineage matters for anyone weighing the claim. A supplier this size connects to carmakers, tier-two component makers and logistics partners across Japan, the United States, China and Europe, so if the claim holds up, the questions will quickly move from Astemo's own network to what it shares with customers.
Japanese manufacturers have had a hard run of it. IntelFusions has already tracked a month of hacktivist DDoS and real breaches in Japan over the summer, and our Japan country profile rates it among the most heavily targeted economies we follow.
The crew's list keeps getting bigger
The more telling part of this story is who else MetaEncryptor has been naming. Ten days ago we reported that the crew had moved from small firms to industrial giants, culminating in a 15 September claim against Nippon Steel. It has not slowed down. In IntelFusions' incident data, the crew has posted 12 more names since that piece, in three batches:
- 17 September: the US engineering firm AECOM, the diagnostics maker Beckman Coulter, and a US technology services company.
- 21 September: Astemo, the contract manufacturer Flex, the scientific instrument maker Bruker, the South Korean camera-module test equipment maker HyVision System, and two smaller US firms.
- 25 September: the power equipment maker GE Vernova, the Indonesian accounting firm PKF Hadiwinata, and a US healthcare staffing agency.
That brings the crew's total to 25 claims since 23 August. None of the large companies named has confirmed a MetaEncryptor intrusion, and a run of famous names is exactly what a crew would post if it wanted to look more capable than it is. Leak site entries get recycled from older incidents, padded, or pinned on a parent company when the real victim is a subsidiary or supplier.
MetaEncryptor, which IntelFusions also tracks under the LostTrust alias, is a double extortion operation first observed in mid-2023. Nothing in the listings reveals how it gets in.
For Astemo's partners, check the connections now
Until Astemo speaks, the practical step for its customers and suppliers is the one that applies after any claim against a large trading partner: review shared VPN and file-transfer access, supplier portal accounts and any service credentials the two organizations hold in common, and watch for invoice or payment-change requests that lean on the news.
The pattern is what to watch. A crew that went from a Canadian consumer goods supplier to GE Vernova in five weeks is either landing much bigger intrusions or learning that big names buy attention. The first company to confirm or deny will tell us which.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.