Ransomware Group thegentlemen Hits: Zanini
Summary
In the latest cybersecurity news, Zanini — an organization based in BR — has fallen victim to a ransomware attack conducted by the group thegentlemen. This data breach, discovered on 2026-09-07T21:53:24.730906+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | Zanini |
| Threat Group | thegentlemen |
| Summary | zanini.com zoominfo.com/c/zanini/359207305 Zanini is the global market leader in automotive wheel trim — a Spanish family firm founded in 1965 in Barcelona, owned by the Torras family since 1976, with 1,800 employees across 12 plants on 3 continents. It makes 1 in 4 wheel covers sold worldwide (~100M units/year) for virtually every major OEM, plus grilles, emblems, EV charge-port covers and pedestrian airbag parts. Its strategic pivot: radar-transparent, heated & illuminated front emblems (radomes) — first launched on VW Atlas, now featured on the new Mercedes CLA (2025) — the key sensor window for the autonomous-driving era. Proprietary tech: ZANICHROME® metallization (chrome-look without chrome, “night & day” effects, electromagnetic transparency) + 17 patent families and TactoTek IMSE license (2024). Funded privately (€81.5M debt raise, Oct 2025), chairman Joan Miquel Torras, CEO Jordi Torras (twice a Dakar Rally racer). |
| Date of Breach | 2026-09-07T15:12:32+00:00 |
| Discovery Date | 2026-09-07T21:53:24.730906+00:00 |
| Region | BR |
| Target Domain | zanini.com |
| Business Sector | Manufacturing |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- train staff to spot attacks — close the gap attackers exploit.
- monitor the dark web for leaked logins — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
