Ransomware victim disclosure
← All victimsUS Installation Group, Inc.
Claimed by AUR0RA · listed 1 day ago
Status timeline
- ListedOct 1, 2026
- Data leakeddate unknown
At a glance
- Group
- AUR0RA
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Oct 1, 2026
- Data size
- 1.707 TB
- Records
- 200-550 corporate/field staff, 500-1500 subcontractors, 18 active bank accounts
About the victim
AI dossier — public-source company profileUS Installation Group, Inc. (USIG) has been installing flooring for The Home Depot since 1993, operating from Boca Raton, Florida. The company performs over 100,000 installations annually across 33 markets in 14 states through 15+ legal entities under MRS Holdings, with 2025 gross revenue of $46.67 million entirely from Home Depot remittances.
- Industry
- Flooring Installation & Service
- Address
- Boca Raton, Florida
- Employees
- 200-550
- Founded
- 1993
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII (SSNs, addresses for 200–550+ employees and family members), complete banking infrastructure credentials, and operational/financial data for a substantial revenue-generating enterprise operating across 14 states.AUR0RA claims to have exfiltrated 1.707 TB of data including complete payroll records (W-2/EFW2 files with plaintext SSNs for 200–550 employees), banking infrastructure details across 18 JPMorgan Chase accounts, operational project data for 100,000+ annual installations, and personal records of the founding family.
Data the group says was taken
AI dossier — extracted from the leak post- W-2 and EFW2 payroll files (2021–2025) with plaintext SSNs
- Employee personal records and addresses
- Banking credentials and account information (JPMorgan Chase)
- ACH routing and line-of-credit agreements
- Installation project blueprints, bids, and cost structures
- Subcontractor pricing and change orders
- Founder personal financial records
What the group claims
Flooring installation company founded by Bruce DeLuca in Boca Raton, Florida, operating through 15+ legal entities under MRS Holdings, performing over 100,000 installations annually across 33 markets in 14 states, primarily for The Home Depot since 1993.
The leak post
captured from the group's site[ Buford-Thompson Company, LTD, a Texas construction general contractor with 30+ years of history building schools for K-12 districts across the state. The exposed dataset totals 1.707 TB and includes: 5 years of W-2 EFW2 files (2021–2025) containing plaintext Social Security numbers, wages, and addresses for 350+ current and former employees — every SSN readable without any decryption. 9.3 GB of attorney-client privileged files from the Stanton ISD v. BTC litigation — legal strategy, discovery responses, and counsel communications. Complete Frost Bank infrastructure — four account numbers, ACH routing credentials, line-of-credit agreements (renewed April 2026), signature cards, and monthly bank statements spanning 2022–2026. 36+ active school construction projects — blueprints, bid estimates, cost structures, subcontractor pricing, and change orders for ISD projects across Texas. A competitor's dream dataset. 2,000+ donor records from Human Services Campus (Phoenix homeless-services nonprofit) with full PII: name, address, phone, email, employer, and donation amounts. QuickBooks company files (.QBW) from Along Side Ministries (Phoenix prison ministry) containing complete accountin…
Data the group says was taken
- financial records
- bank account information
- corporate records
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

