Jinny Beauty Supply (US) was targeted by the Aurora ransomware threat actor, with attackers exfiltrating a broad range of exposed credentials and sensitive data including password vault exports, VMware hypervisor root credentials (vCenter/ESXi), and 911-scanned customer credit card authorization forms containing full card details and signatures. The compromise also included significant operational databases and employee/financial records such as Microsoft 365 and analytics data, Shopify and SQL Server backups, Active Directory domain enumeration (including admin accounts and RDP/DPAPI data), and employee tax documents (W-4, I-9, direct deposit), impacting #UnitedStates
Incident Details
- Victim: Jinny Beauty Supply
- Sector: Retail & E-Commerce
- Country: US
- Actor: aurora
- Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/jinny-beauty-supply-4926057b
- Discovered: 2026-09-07T14:25:08.483784+00:00
- Published: 2026-09-07T00:00:00+00:00
Information
- One of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California, serving 7,400+ beauty supply stores and 2,800+ international distributors.
- A complete password vault export with 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP, 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email.
- VMware hypervisor root credentials, including vCenter and ESXi root passwords, providing complete control over the virtual infrastructure.
- 911 scanned credit card authorization forms containing full card numbers, CVV, expiry dates, and cardholder signatures for customers across 26 US states.
- A complete employee compensation database covering around 260 employees, with Korean and English names, departments, salaries, bonuses, and 1099 contractor data from 2015–2018.
- A 340 MB Shopify database backup containing the full customer table, product catalog, pricing, and warehouse assignments.
- Active Directory domain enumeration covering 239+ user accounts, including 17 admin accounts, the complete server topology across 7 geographic sites, and DPAPI-encrypted RDP passwords.
- Employee tax documents, including W-4 forms, I-9 forms, and direct deposit forms with bank account and routing numbers.
- 3.6 GB of SQL Server database backups containing e-commerce customer, order, and product data from November 2019 to March 2020.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.