The aurora ransomware threat actor compromised Chip 1 Exchange, accessing extensive corporate and personnel data in Singapore, including passport photographs, I-9 forms with SSNs, W-4 tax documents, payroll records, and large Outlook PST email archives. The breach also reportedly exposed detailed financial intelligence and bank account details, along with ITAR-related defense customer sales orders, impacting Singapore #Singapore
Incident Details
- Victim: Chip 1 Exchange
- Sector: Technology
- Country: SG
- Actor: aurora
- Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/chip-1-exchange-13b819b4
- Discovered: 2026-09-02T06:52:31.237644+00:00
- Published: 2026-09-02T00:00:00+00:00
Information
- 40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, and payroll registers
- Complete 2026 financial intelligence, including P&L through July, executive financial health assessment, AR/AP aging, and a chart of accounts revealing all bank account numbers
- 15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins
- ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec
- 5.7 GB of Outlook PST email archives spanning years of C-suite and employee correspondence

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.