ransomware Credible Tunisia (TN)

SETCAR listed by the thegentlemen ransomware group

SETCAR

📅 12 May 2026
CompanySETCAR
CountryTunisia (TN)
Sector
Breach date2026-05-12
People affectedNot disclosed
Ransomware groupthegentlemen
Data typesNot disclosed

Overview

On 12 May 2026, the ransomware group The Gentlemen listed SETCAR on its leak site. SETCAR, based in Tunisia, is a private manufacturer of buses, coaches and minibuses operating since 1976, producing up to 500 vehicles a year for public transport, tourism and institutional clients across Africa and the Middle East.

What was published

The Gentlemen's listing named SETCAR as a victim but did not provide a record count or data inventory. The group has followed a disclosure pattern of naming companies and later publishing stolen files. No archive associated with SETCAR was observed during the analysis period.

Risks for affected individuals

Employees, dealers and institutional clients of SETCAR could be affected if personnel records, order documentation or engineering files were exfiltrated. Commercial data of this kind supports phishing, invoice fraud and attempts to impersonate company officials.

What remains unknown

The scope of the exfiltration and whether the group published any files are not confirmed. SETCAR has not issued a public statement about the incident, and the claim rests on the leak site listing.

What affected people should do

Staff and business partners should reset credentials for systems linked to SETCAR and enable multi-factor authentication. Clients should verify order and payment communications through established contacts and report any suspicious email referencing the company.

Sources

  • https://setcar.com.tn