Another vehicle manufacturer has surfaced on Clop’s extortion portal, and the entry is thin even by leak-site standards. The Milwaukee motorcycle maker Harley-Davidson appeared as a victim on September 10, with no evidence attached.
Threat-monitoring feeds picked up the entry the same day. As of September 12 the group had published no sample files, screenshots, ransom note or technical indicators, and Harley-Davidson had said nothing publicly about an intrusion. Its dealers, connected services and back-office systems went unmentioned in the post.
The absence of proof matters. Ransomware operators routinely name companies before negotiations close, sometimes to pressure a target, sometimes to inflate a reputation. A leak-site entry is a negotiating move until the victim or independent reporting confirms it, and breach trackers classify this listing as unverified.
The pattern fits Clop’s recent trajectory. The group once best known for mass exploitation of file-transfer appliances has spent 2026 working through industrial and manufacturing victims, where engineering data and product designs sit beside ordinary corporate records.
For vehicle makers the stakes reach past stolen documents. Design files, supplier contracts and dealer credentials feed production planning, and an intrusion that touches product data can complicate compliance work under UNECE R155 and the EU Cyber Resilience Act, both of which now expect manufacturers to report exploited vulnerabilities on tight clocks.
Harley-Davidson has not responded to the listing. Until it does, the claim stands as an allegation.