Ransom! Van Eijck International Car Rescue (JUL-2026)

Ransom! Van Eijck International Car Rescue (JUL-2026)

Aurora ransomware targeted Van Eijck International Car Rescue in the Netherlands, exposing 156 GB of employee home directories, 12 GB of RentRunner rental contracts with identity documents, and 10 years of customer claims data (2010–2019) containing extensive PII. The attacker also compromised a complete Google Workspace backup (CubeBackup) covering Gmail, Drive, and Calendar for 18 user accounts and 206 groups. #Netherlands

Incident Details

  • Victim: Van Eijck International Car Rescue
  • Sector: Transportation
  • Country: NL
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/van-eijck-international-car-rescue-91e93f21
  • Discovered: 2026-07-30T07:23:44.017849+00:00
  • Published: 2026-07-30T00:00:00+00:00

Information

  • Family-owned Dutch towing and recovery company with 225+ vehicles, 180+ employees, and 20 branch offices across the Netherlands and Spain.
  • 227 employee home directories (156 GB) containing personal documents, tax forms (loonheffingen), salary records, photos, and financial data.
  • 12 GB of RentRunner customer rental contracts with copies of identity documents, driving licenses, and vehicle registrations.
  • 10 years of customer claims data (2010–2019), including 500+ individual claims with damage assessments, insurance details, and customer PII.
  • Complete Google Workspace backup (CubeBackup) covering Gmail, Drive, and Calendar for 18 user accounts and 206 groups.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live