Ransom! Aerospace & Advanced Composites GmbH (JUN-2026)

Ransom! Aerospace & Advanced Composites GmbH (JUN-2026)

Incident Details

  • Victim: Aerospace & Advanced Composites GmbH
  • Sector: Manufacturing
  • Country: DE
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/aerospace-advanced-composites-gmbh-4304f151
  • Discovered: 2026-06-22T14:50:58.039216+00:00
  • Published: 2026-06-22T00:00:00+00:00

Information

  • Complete NAS snapshots covering more than 30 years of operations, including testhouse, R&D, engineering, administrative, and accounting data.
  • Archived ESA thermal vacuum test records, polymer composites formulations, and 22 Outlook PST email backups.
  • Administrative files with the managing director’s full PC backup, browser credentials, passport scans, financial statements, shareholder agreements, and IT credentials.
  • Full business accounting database with employee payroll, SEPA payments, and VAT declarations.
  • BitLocker recovery keys and WMI system dumps for multiple endpoints.
  • Passport scans, a social security number, complete HR files for employees, and hundreds of applicant CVs.
  • Master password spreadsheet containing all system credentials, plus browser-stored logins for ESA SSO, the IT provider, and industrial suppliers.
  • Recovery keys enabling full-disk decryption of company laptops.
  • Thirty-plus years of ESA thermal vacuum test data representing a core competitive advantage that cannot be recreated.
  • Executed NDAs with major partners including Airbus, RUAG, Safran, Thales, ESA, BMW, Tesla, Google, Samsung SDI, CERN, DLR, and many others.
  • Fifteen years of annual financial statements, bank records, insurance policies, and shareholder agreements exposing the company’s full financial structure.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live