Qilin ransomware group claims attack on auto supplier Yanfeng

Organization
Yanfeng Automotive Interiors
Exploit
Ransomware
Industry
Automotive Manufacturing

Yanfeng Automotive Interiors, a Chinese supplier of instrument panels, door panels, consoles and seating with more than 57,000 employees across roughly 240 locations, was named on the Qilin ransomware group's dark web leak site in late November 2023. Qilin, which launched in 2022 under the name Agenda, posted samples it said proved access to the company's systems.

The published samples included financial documents, non-disclosure agreements, quotation files, technical data sheets and internal reports, according to BleepingComputer. The group threatened to release everything it held within days but set no specific deadline and named no ransom figure publicly.

The claim followed a disruption earlier in the month that rippled through the North American auto supply chain. Stellantis told reporters that production at some of its North America assembly plants was interrupted during the week of November 13 because of an issue at an external supplier, and that full production had resumed by November 16. Stellantis did not name the supplier or identify the affected plants, and said it was working with the supplier to limit further impact.

Yanfeng did not answer requests for comment and issued no statement. Its main website was unreachable for a period before returning online in late November without explanation. As of the reporting date the company had neither confirmed nor denied the ransomware claim.

Sources