Ransom! Bretford Manufacturing (JUL-2026)

Ransom! Bretford Manufacturing (JUL-2026)

Bretford Manufacturing, Inc. (US) reported a ransomware claim involving the aurora threat actor, following exposure of sensitive workforce data, including Social Security Numbers from ACA Census files, 1099 forms, and payroll records spanning 2010–2026. The compromised materials also included Bretford’s and vendors’ bank account details from NACHA ACH files, full network architecture (including VPN and Active Directory details), 20 years of HR records, and the complete product engineering library. #UnitedStates

Incident Details

  • Victim: Bretford Manufacturing
  • Sector: Manufacturing
  • Country: US
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/bretford-manufacturing-b4537780
  • Discovered: 2026-07-29T06:51:40.642786+00:00
  • Published: 2026-07-29T00:00:00+00:00

Information

  • Privately held manufacturer of charging solutions for mobile devices, founded in 1948 and headquartered in Franklin Park, Illinois, serving education, healthcare, retail, and government sectors.
  • Social Security Numbers for the entire workforce, including current employees, 200–400 historical employees, and dependents, exposed through ACA Census files, 1099 forms, and payroll records spanning 2010–2026.
  • Corporate and vendor bank account details, including the company’s own checking account information and more than 26 vendor bank accounts from NACHA ACH batch files.
  • Complete network architecture data, including VPN gateway IP, internal topology diagram, IP allocation tables, infrastructure inventory, disaster recovery plan, and Active Directory domain name.
  • Twenty years of HR records covering medical leave, disability accommodations, drug tests, garnishments, pension, 401(k), insurance enrollment, and termination records.
  • Complete product engineering library, including SolidWorks CAD files for all products, CNC and laser programs, and manufacturing process documentation.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live