The double-extortion ransomware group known as CRPx0 has recently made headlines by listing Hyundai’s Turkish operations on its dark web leak site. The group has claimed to have exfiltrated a substantial 1.5 gigabytes of sensitive personnel and recruitment data from the automaker’s assessment systems. This incident is not only significant for Hyundai but highlights ongoing security challenges within the automotive sector, particularly as cyber threats continue to evolve.
According to reports from CyberWatch, which first flagged the incident through its data-leak portal, the targeted entity is identified as a Korean automotive manufacturer operating in Turkey, specifically linked to the domain hyundai.com.tr. The breach is categorized as part of an automotive sector attack, with the attack’s locus pinpointed to Istanbul, Turkey.
At the time of this reporting, the listing related to this breach is marked with a “pending” status, signifying that the group is still executing its strategy. CRPx0’s countdown timer indicates around four days remain before the group plans to initiate an alleged data leak, an action that has already attracted a notable 3,100 unique views on the leak website. This is indicative of the growing concern and interest surrounding cyberattacks on major corporations.
CRPx0 claims that the stolen 1.5 gigabyte archive encompasses numerous categories of highly sensitive human resources (HR) and recruitment-related information. Among the alleged contents is candidate assessment data, which reportedly includes individual interview answers, evaluation scores, and results. The data theft extends further to encompass information regarding recruitment sources and tracking records for candidates.
What further complicates the security implications is that CRPx0 also claims to possess proctored exam data, which consists of photographs and videos captured during testing sessions. This includes executive assessment reports that detail psychometric evaluations and personality analyses for both candidates and management personnel. Additionally, the haul includes evaluation criteria, scoring documentation, and selection materials for critical positions, along with internal emails pertinent to recruitment and personnel assessments.
The existence of proctoring footage coupled with psychometric evaluation data raises alarms about the potential for misuse. Such sensitive material can be exploited for targeted social engineering attacks or identity-based fraud aimed at both candidates and executives should it be released publicly.
Following a typical double-extortion ransomware model, CRPx0 has communicated that the stolen data currently resides on its servers. The group has informed Hyundai of the breach, suggesting a window for private resolution before a public deadline is reached, which remains a standard tactic employed by ransomware gangs.
The group has also provided designated communication channels, including Tox and Session messenger identifiers on the leak page, which reflect a common practice among ransomware actors to avoid centralized infrastructure for ransom negotiations. This method increases their anonymity while conducting operations.
In recent months, CRPx0 has ramped up its activities, particularly in mid-2026. They have targeted numerous Turkey-based organizations and have included a separate group of ten U.S.-based entities on their leak portal. Cybersecurity experts from Aryaka Threat Research Labs have analyzed the malware operations associated with the group. Their findings describe a sophisticated Python-based, cross-platform loader that operates on both Windows and macOS systems. This technology combines file encryption with cryptocurrency theft through clipboard hijacking, wallet seed-phrase harvesting, and employs live command-and-control communication for the deployment of malicious payloads.
This is not the first instance of Hyundai facing ransomware threats. The Black Basta group previously claimed to have stolen approximately three terabytes of data from Hyundai Motor Europe in early 2024. Furthermore, Hyundai AutoEver America reported a separate breach in 2025 that compromised employee Social Security numbers and driver’s license information. The repeated targeting of Hyundai’s regional subsidiaries reveals a troubling pattern of vulnerability within the company’s decentralized IT environments, particularly in HR and recruitment sectors that often receive less cybersecurity scrutiny compared to production or customer-facing systems.
Currently, Hyundai has yet to issue a public statement confirming CRPx0’s claims, and the authenticity of the leaked sample has not been independently verified. As the landscape of cyber-attacks continues to change rapidly, companies like Hyundai may need to rethink their security strategies to safeguard sensitive data against increasingly sophisticated threats.

