Ransomware Victim: Diamond Truck Centres (aurora)

Fecha
16 Jun 2026
Actor
aurora
Tipo
Ransomware
Pais
Canada
Sector
Transportation
Confianza
high
60
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

0IOCs
0TTPs
auroraActor
CanadaPais
Executive Summary
Victima de ransomware reportada en el dashboard de aurora.

Key Points

  • Ransomware Dashboard
  • Fuente original

Diamond Truck Centres

Victima de ransomware reportada en el dashboard de aurora.

CampoValor
Grupoaurora
PaisCA
SectorTransportation/Logistics
Fecha2026-06-16T13:21:27.187972+00:00

Detalles

[dealership, trucks] *** β€” Western Canada's largest International Trucks dealership group (9 dealer + 13 sub-dealer locations, ~$63M revenue, 250 employees). The dataset spans 17 years of unbroken operational history (2009–2026) and represents the full shared-drive contents of the entire company: HR, payroll, accounting, military contracts, and individual employee profiles. The exposed material includes: 53 customer Pre-Authorized Debit (PAD) forms β€” full bank account numbers, transit numbers, institution numbers, and authorized signatures for commercial customers including the City of Saskatoon. 17 years of employee payroll data β€” wages, SINs (implied), pension contributions, benefits, termination calculations for every employee since 2009. Biometric data β€” ADP fingerprint timeclock enrollment records for all locations. Immigration documents for 6+ foreign workers β€” LMIA applications, offers of employment, provincial nominee support docs. System credentials in plaintext β€” ADP timeclock passwords, manager training logins, safe combination. Military contract documentation β€” Diamond's Controlled Goods Security Plan (ITAR/CGP), MSVS delivery matrices, military vehicle VINs, CFB Edmonton and RCMP vehicle program data. 289 GB of daily bank deposit scans (2017–2026) β€” customer cheque images with names, amounts, and account details. A complete Outlook PST archive (166 MB) β€” years of internal email likely containing credentials and customer data.

Referencias

Diamond Model

Adversary
aurora
Ver perfil →
Victim
Ransomware Victim: Diamond Truck Centres (aurora)
Canada
Capability
Ransomware
Filtracion: 289 GB
Infrastructure
Sin infraestructura confirmada

Referencias y enlaces

→ Perfil del actor aurora en el blog → Ver aurora en IntelTracker → URL IntelTracker: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Fuente OSINT: u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion → Buscar aurora en APTTrail → Repositorio APTTrail → Mas incidentes en Canada → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes