All ransomware incidents
Ransomware group thegentlemen hits EP Manufacturing Bhd
EP Manufacturing Bhd — a manufacturing target operating in MY has been listed by the thegentlemen ransomware group on 2026-08-31. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | EP Manufacturing Bhd |
|---|---|
| Threat Group | thegentlemen |
| Summary | epmb.com.my zoominfo.com/c/ep-manufacturing-bhd/372140192 EPMB (7773, Bursa Malaysia) — Malaysian auto manufacturer, operating since 1982. Formerly made parts for Proton, Perodua, Honda, Toyota. Now assembles complete cars in Melaka for Chinese brands: GWM, BAIC, XPENG, MG. Capacity raised to 30,000 vehicles/year; in 2026 output exceeds 1,000 cars/month. Q2 2026: net profit RM5.15m (19× up), revenue RM212.7m (+67%) — 10-year record. Share price ~RM0.44, market cap ~RM125m, dividend ~1.2%; risks — debt and low liquidity. |
| Date of Breach | 2026-08-31 |
| Discovery Date | 2026-08-31 |
| Region | MY |
| Target Domain | epmb.com.my |
| Business Sector | Manufacturing |
| Severity | MEDIUM |
Claim by thegentlemen
epmb.com.my zoominfo.com/c/ep-manufacturing-bhd/372140192 EPMB (7773, Bursa Malaysia) — Malaysian auto manufacturer, operating since 1982. Formerly made parts for Proton, Perodua, Honda, Toyota. Now assembles complete cars in Melaka for Chinese brands: GWM, BAIC, XPENG, MG. Capacity raised to 30,000 vehicles/year; in 2026 output exceeds 1,000 cars/month. Q2 2026: net profit RM5.15m (19× up), revenue RM212.7m (+67%) — 10-year record. Share price ~RM0.44, market cap ~RM125m, dividend ~1.2%; risks — debt and low liquidity.
Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

