Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-08-28
Ransomware·2026-08-28·60 Sources·34 Items

Ransomware Watch · Aug 28, 2026

In the 36-hour window, the two leak-site trackers (RansomLook, primary, cross-validated against ransomware.live) logged 34 new victim claims across 10 groups.

Headline: Aurora leaks core assets of SAP integrator ERPIS/ShipERP

The Aurora group claims to have breached ERPIS LLC (trading as ShipERP), a Texas-based SAP integrator whose enterprise shipping-management software serves 83 corporate customers including Boeing, Pfizer, NVIDIA, John Deere, and Medtronic. The claimed haul includes: the company's sole revenue-generating asset — the complete ShipERP ABAP source code across all versions (2.0–5.4), tied to a $20.6M order backlog; a 705MB live QuickBooks financial database (employee SSNs, bank accounts, payroll); a full customer contract and pricing register for all 88 enterprise customers, tied to $20.6M in deferred revenue; and 245GB of SAP installation media, including full HANA, S/4HANA, and kernel distributions. If accurate, the exposure reaches beyond ERPIS itself — its customer roster and product source code are exposed too, raising a supply-chain risk.

Sources: RansomLook · ransomware.live

Group activity

krybit — 12 new claims, the most active group this period

Victims span Thailand, India, Vietnam, Egypt, Brazil, and Guatemala, mostly small-to-mid manufacturing, trading, and healthcare firms, including Syscon (Thailand), Jindal Life Science (an Indian contract research organization), and Karkinos Healthcare (an Indian oncology-care platform), among 12 total.

Sources: RansomLook · ransomware.live

qilin — 7 new claims

Mostly US manufacturing and business-services targets: WireCo, California Truck Equipment, Northern Leasing Systems, Air International Thermal Systems (automotive parts), and others, plus one target tagged "Government," ATF.

Sources: RansomLook · ransomware.live

the gentlemen — 5 new claims

Manufacturing and professional-services targets across the US, Latin America, and Europe: Party Rental, a large US event-rental company founded in 1972; TEC Container, a Spanish container-handling equipment maker; and three Chilean firms — Verbux (IT services), Espinos (power generation), and Incolur (industrial supply distribution).

Sources: RansomLook · ransomware.live

akira — 3 new claims

Gill Rock Drill (a US drilling-equipment maker, claimed 5GB stolen), a Massachusetts oral and maxillofacial surgery practice (claimed 14GB stolen), and PA-ID GmbH (a German mechanical manufacturer, claimed 119GB stolen).

Sources: RansomLook

ailock — 2 new claims

Morgan Services (a century-old Chicago textile/linen rental company) and Hamilton Company (a Nevada lab-automation and robotics equipment maker).

Sources: RansomLook

abyss-data / eclipse / auditteam / deadlock — 1 new claim each

MEMSIC (a US sensor manufacturer), Simplex Engineering (an Indian industrial equipment manufacturer), Demidov Steel Group (a Russian steel trading company), and FBC (a South African furniture-industry bargaining council).

Sources: RansomLook

← Prev
Ransomware Watch · Aug 27, 2026