Ransom! FREYWILLE (AUG-2026)
The ransomware claim targets FREYWILLE in Austria, allegedly by the aurora threat actor, compromising 142+ employee files including salary statements, social security numbers (ELDA), employment contracts across 24 countries, and identity and benefits documentation. It also claims theft of FREYWILLE trade secrets such as 2025 product costing data and enamel color recipe formulations, plus legal and incident records tied to lawsuits and prior attacks affecting #Austria.

Incident Details

  • Victim: FREYWILLE
  • Sector: Retail & E-Commerce
  • Country: AT
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/freywille-7c86d6ae
  • Discovered: 2026-08-11T05:51:58.070271+00:00
  • Published: 2026-08-11T00:00:00+00:00

Information

  • Employee files including salary statements (2024–2026), social security numbers, employment contracts across 24 countries, COVID vaccination records, passport copies, visa card statements spanning a decade, and personnel records.
  • Trade secrets, including complete 2025 product costing for all lines and enamel colour recipes from the Siebdruck department.
  • Fire-enamel technique formulations for SPHINX, JOYB2, and Entwurf colour systems.
  • Legal defence files from 40+ lawsuits across Austria, the US, China, France, Canada, Slovakia, Poland, and Belgium, including a criminal proceedings file.
  • Documentation related to the 2018 webshop malware attack, including DSB filings, customer notification drafts, and incident reports.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live