Ransom! Benshaw, Inc. (SEP-2026)

Incident Details

  • Victim: Benshaw, Inc.
  • Sector: Manufacturing
  • Country: US
  • Actor: aurora
  • Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/benshaw-inc-a8850418
  • Discovered: 2026-09-07T13:52:58.625199+00:00
  • Published: 2026-08-27T00:00:00+00:00

Information

  • ~100+ corporate Visa/PCard records with full PAN, SSN, DOB, and home address
  • 637 former employees with full SSN, DOB, and address on one spreadsheet
  • 88 active employee folders plus multi-year Canada payroll data
  • Global bank account numbers across multiple institutions
  • ACH NACHA files containing vendor routing and account numbers
  • UEdit source code with a hardcoded XOR key and date-based backdoor function
  • Oil and gas customer job packs for major clients including Chevron, Petrobras, EOG, Santos AU, and KOC

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live