Desk live·
ForensicPost
Ransomware/Aftermath/File 22-1104b

LockBit Claimed 40TB From Continental Three Months After the Company Disclosed

Continental reported a cyberattack in early August 2022. On 4 November LockBit claimed it, offered 40TB for $50 million, and published a file list when nobody paid — including material reportedly belonging to its automotive customers.

Constructed geometry · not a chart of case data
JurisdictionGermanyHanoverthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetContinental
ActorLockBit
D. Kennedy11 min readConfidence: medium3 sources reviewed

Continental, the German automotive supplier, experienced a cyberattack in early August 2022 and disclosed it at the time. On 4 November 2022 the LockBit operation claimed responsibility, stating it held around 40TB of data and offering the full set for $50 million. When it was not paid, a file list of more than 400MB was published for free download.

Continental confirmed that significant amounts of data had been stolen. Reporting indicated the material may include information relating to automotive customers including Volkswagen, BMW and Mercedes, and that samples suggested technical documents and source code.

Three Months Between The Event And Its Size

The August disclosure and the November revelation are two different entries in the public record about one incident. In between, anyone relying on the first would have had the wrong picture.

We have recorded the same asymmetry at 23-1110, where a leak disclosed the entry route its victim would not, and argues at 26-0802 that this database is built from what organisations choose to say. Here the correction to the record came from the party with an interest in maximising it, which is not a good source and was the only one available.

A File List Is A Pressure Instrument

Publishing an index rather than the contents is a deliberate intermediate step. It demonstrates possession, lets every named third party see their own name, and keeps the material itself in reserve.

We have recorded staged release as the mechanism at 22-1024 and 22-0903, and the listing choreography at 23-1110. What distinguishes a file list is who it is aimed at: not the victim, who knows what was taken, but the victim’s customers, who now have to ask.

The Customers Were In The Supplier

The reported presence of material relating to major manufacturers is the part with consequences beyond Continental. A components supplier holds its customers’ specifications and engineering data because it cannot make the parts otherwise.

We filed that dependency at 22-0301, where one supplier stopped fourteen Toyota plants, and at 26-0713. Third-party risk assessment asks whether a supplier can be disrupted; it much less often asks what of yours they hold, which is the question this incident poses.

How we reported this

Compiled from contemporaneous reporting of the leak-site listing and of Continental’s statements, listed below. The 40TB volume is the operation’s own claim about its own haul and is carried as a claim. Reporting that the material may relate to named automotive manufacturers rests on samples and file names described by researchers and journalists; this desk has not accessed any published material and does not confirm whose data it contains — which is why this file is graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. LockBit ransomware claims attack on Continental automotive giantBleepingComputer
  2. LockBit Claims Ransomware Attack on ContinentalInfosecurity Magazine
  3. Stolen data from Continental ransomware attack for sale for $50MSC Media
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary