Breaking (July 26, 2026): The ransomware group Global Secret Group has listed Hinduja Tech on its dark web leak site, claiming to have exfiltrated 515 GB of data — 212,785 files across 83,982 folders — from the Indian engineering services company. Hinduja Tech serves major global automotive manufacturers including BMW Group and Škoda Auto. The company has not issued a public breach notification. Negotiations are reportedly being demanded.

On July 26, 2026, the ransomware operation known as Global Secret Group made a significant announcement on its dark web leak site: it had successfully breached Hinduja Tech, one of India’s leading engineering services providers, and exfiltrated 515 gigabytes of internal data covering more than 212,000 files. The announcement was accompanied by a threat to publicly release the data unless Hinduja Tech enters into ransom negotiations.

The timing — posted on a Saturday — follows a common ransomware group tactic of maximising disruption and media attention by publishing leak notices at the start of the weekend, when corporate communications teams and incident response staff are least available to respond.

Hinduja Tech: Who Are They and Why Does This Matter?

Hinduja Tech is part of the Hinduja Group, one of India’s largest diversified conglomerates with operations across banking, insurance, healthcare, media, and IT. Hinduja Tech specifically focuses on engineering services and digital transformation for the global manufacturing sector — particularly automotive.

Among Hinduja Tech’s major clients are:

  • BMW Group — one of the world’s largest premium automotive manufacturers
  • Škoda Auto — the Czech member of the Volkswagen Group
  • Other Tier-1 and Tier-2 automotive suppliers across Europe, North America, and Asia

The nature of Hinduja Tech’s work means the stolen data is likely to include:

  • Engineering designs and CAD drawings for automotive components
  • Manufacturing process documentation
  • Client project files, contracts, and communications
  • Employee personally identifiable information (PII)
  • Proprietary automotive design data belonging to BMW and Škoda
  • Supply chain and vendor information
  • Internal financial and business data

This breach affects not just Hinduja Tech — it potentially exposes the intellectual property of BMW Group and Škoda Auto, making it a multi-jurisdiction, multi-company incident with significant legal and financial implications.

The 515 GB Dataset: What the Numbers Mean

The scale of the exfiltration — 515 GB across 212,785 files in 83,982 folders — provides clues about the nature of the breach:

Metric Value Implication
Total data volume 515 GB Large-scale, prolonged exfiltration (not a smash-and-grab)
File count 212,785 files Mix of documents, designs, and communications
Folder count 83,982 folders Systematic directory traversal — structured data theft
Average file size ~2.5 MB per file Consistent with engineering documents, PDFs, CAD files

The structured folder hierarchy (83,982 folders) suggests that attackers spent significant time mapping and selectively exfiltrating data rather than simply compressing and stealing everything. This indicates a threat actor with patience and clear intelligence objectives — hallmarks of a professional ransomware operation with potential nation-state clients for the stolen data.

Who Is Global Secret Group?

Global Secret Group is a ransomware-as-a-service (RaaS) operation that emerged in 2025. The group has claimed victims across multiple sectors and geographies, with a notable focus on manufacturing, automotive, and engineering services companies. Their operational profile:

  • Primary targets: Mid-to-large enterprises in manufacturing, automotive, energy, and engineering
  • Geography: Global — victims in India, Europe, and Asia Pacific
  • Monetisation: Data extortion + ransomware encryption; double-extortion model
  • Affiliate model: Operates as RaaS with affiliates receiving percentage of ransom proceeds
  • Known concurrent victims: Alongside Hinduja Tech, the group has also listed BMW Group and Škoda Auto simultaneously — suggesting a coordinated campaign targeting the automotive supply chain

The simultaneous listing of Hinduja Tech, BMW Group, and Škoda Auto is particularly significant. It suggests that the attackers may have used Hinduja Tech as a supply chain pivot point — gaining access to Hinduja Tech’s systems first, and then leveraging the established data-sharing connections and credentials between Hinduja Tech and its clients to access BMW and Škoda systems.

The Automotive Supply Chain as an Attack Surface

The automotive industry has become one of the most targeted sectors for ransomware operations, driven by several factors:

  1. High digitalisation: Modern automotive manufacturers share vast amounts of technical data with hundreds of Tier-1 and Tier-2 suppliers electronically — creating a massive and distributed attack surface
  2. Just-in-time manufacturing: A ransomware attack that disrupts one supplier can halt production lines at the OEM within hours — creating enormous pressure to pay
  3. High-value IP: Automotive design data, especially for electric vehicles, autonomous driving systems, and advanced safety technology, has enormous commercial value on secondary markets
  4. Inconsistent security standards: Large OEMs like BMW have sophisticated security programmes, but smaller suppliers (Tier-2, Tier-3) often have minimal cybersecurity maturity

India-based engineering services providers like Hinduja Tech sit at a particularly vulnerable position in this supply chain: they are large enough to hold significant client data, but often lack the dedicated security operations centre (SOC) and incident response capabilities that their OEM clients maintain.

Attack Timeline and Technical Analysis

Based on the volume of exfiltrated data (515 GB) and the characteristics of the folder structure, a likely attack timeline for the Hinduja Tech breach:

  1. Initial access (weeks to months before July 26): Global Secret Group affiliates gained initial access — likely through phishing of a privileged employee, exploitation of a VPN or remote access vulnerability, or compromise of credentials exposed in a previous breach. Automotive engineering services firms typically rely heavily on VPN access for remote engineering work.
  2. Dwell time and lateral movement: Attackers spent time moving laterally across Hinduja Tech’s internal network, mapping file servers, project repositories, and shared drives containing client data
  3. Data staging: 515 GB was staged within the compromised environment before exfiltration — possibly compressed and encrypted to reduce detection signatures during transfer
  4. Exfiltration: Data transferred out via HTTPS to attacker-controlled cloud storage — difficult to distinguish from legitimate business traffic
  5. Ransomware deployment (potentially): Encryption may have been deployed simultaneously with the dark web listing
  6. Extortion notice (July 26, 2026): Leak site listing published

What BMW and Škoda Auto Should Do Immediately

As entities whose data is almost certainly included in the 515 GB exfiltration through their engineering partner, BMW Group and Škoda Auto should immediately:

  1. Terminate or restrict Hinduja Tech’s system access pending investigation — including revoking all API keys, VPN credentials, and shared repository access
  2. Audit data sharing agreements with Hinduja Tech to understand exactly what IP and data was accessible to Hinduja Tech systems
  3. Engage threat intelligence vendors to purchase or access a sample of the Global Secret Group data to assess what specific files are included
  4. Notify relevant regulators — GDPR (for European employee/customer data), India’s DPDP Act, and automotive sector regulators in relevant jurisdictions
  5. Review all shared supply chain connections — if Global Secret Group pivoted through Hinduja Tech to access BMW/Škoda systems, those connections need to be forensically examined

Ransomware in India: A Growing Crisis

The Hinduja Tech attack is part of a surge in ransomware attacks targeting Indian enterprises in 2026. India has become a priority target for ransomware groups for several reasons:

  • India is now the world’s 5th largest economy with a large number of mid-size enterprises that have significant revenue but less mature cybersecurity
  • Indian companies are increasingly integrated into global supply chains — making them valuable pivot points for attacking Western OEMs and partners
  • Ransomware payments from Indian companies are often not publicly disclosed, reducing reputational risk for attackers
  • India’s cybersecurity talent shortage means many companies lack in-house incident response capability

According to Seqrite’s India Cyber Threat Report 2026, ransomware attacks against Indian organisations increased by 43% year-on-year in 2025–2026, with manufacturing and engineering services among the top five targeted sectors.

What Hinduja Tech Must Do Now

  1. Engage a professional incident response firm immediately — scope the breach, contain the threat actor, and eradicate any remaining access
  2. Notify affected clients including BMW Group, Škoda Auto, and all other customers whose data may have been on compromised systems
  3. Notify CERT-In — India’s Computer Emergency Response Team requires mandatory breach notification within 6 hours of discovery for certain categories of incident
  4. Do not pay the ransom without legal counsel — OFAC sanctions considerations may apply depending on the threat actor’s jurisdiction
  5. Preserve forensic evidence — full forensic imaging of affected systems before any remediation
  6. Issue a public statement — prolonged silence increases reputational damage and regulatory risk

Conclusion

The Global Secret Group attack on Hinduja Tech is a high-impact event not just for the company itself but for the global automotive supply chain it serves. 515 GB of data — including what is almost certainly BMW and Škoda intellectual property — is now in the hands of a ransomware operation with a track record of publishing unredeemed data publicly.

Engineering and manufacturing firms in India that handle global client data must treat their cybersecurity posture as a contractual and legal obligation — not an optional expense. For a professional ransomware readiness assessment and incident response planning, contact Vivek Verma.

Sources: DeXpose — Global Secret Group / Hinduja Tech | HookPhish — Ransomware Report | Ransomware.live — Victim Listing