Evosys Laser GmbH (DE), an Erlangen-based industrial laser welding systems manufacturer, disclosed a ransomware claim by threat actor aurora involving the compromise of its complete corporate repository, including HR, server infrastructure (mRemoteNG XML with domain admin credentials), and customer project data. The claimed impact includes exposure of industrial control assets and sensitive communications, with impacted country(s): #Germany
Incident Details
- Victim: Evosys Laser GmbH
- Sector: Manufacturing
- Country: DE
- Actor: aurora
- Source: http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/evosys-laser-gmbh-4511a1ae
- Discovered: 2026-07-30T07:23:03.854269+00:00
- Published: 2026-07-30T00:00:00+00:00
Information
- Complete corporate repository spanning every business function.
- 130 employeesβ full HR files, including contracts, salary histories, IBANs, tax IDs, social insurance numbers, pension records, medical exams, disciplinary warnings, and two confirmed minorsβ health records.
- Complete server infrastructure map via mRemoteNG XML, including seven named servers, domain admin credentials, internal IPs, and the Citrix admin password.
- 326 GB of customer project data, including laser welding process parameters, CAD files, robot control software, and award-winning AQW process know-how.
- Complete financial history, including annual financial statements from 2015 to 2025, P&L forecasts through 2028, cash positions, investor documents, and executive compensation.
- Attorney-client privileged communications and whistleblower reports under HinSchG.
- Industrial control data, including robot SRS source code, PLC programs, nginx private keys for laser system web interfaces, and VPN configurations for customer site remote access.

Disclaimer: This post is based on public claims made by the ransomware group "aurora". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.