Incident Details
- Victim: Benshaw, Inc.
- Sector: Manufacturing
- Country: US
- Actor: aurora
- Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/benshaw-inc-a8850418
- Discovered: 2026-09-07T13:52:58.625199+00:00
- Published: 2026-08-27T00:00:00+00:00
Information
- ~100+ corporate Visa/PCard records with full PAN, SSN, DOB, and home address
- 637 former employees with full SSN, DOB, and address on one spreadsheet
- 88 active employee folders plus multi-year Canada payroll data
- Global bank account numbers across multiple institutions
- ACH NACHA files containing vendor routing and account numbers
- UEdit source code with a hardcoded XOR key and date-based backdoor function
- Oil and gas customer job packs for major clients including Chevron, Petrobras, EOG, Santos AU, and KOC

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.