Ransomware victim disclosure
← All victimsJinny Beauty Supply
Claimed by AUR0RA · listed 5 days ago
Status timeline
- ListedSep 8, 2026
- Data leakeddate unknown
At a glance
- Group
- AUR0RA
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 8, 2026
- Data size
- 3.6 GB SQL backups + 340 MB Shopify backup
- Records
- 911 credit card forms, ~260 employees, 239+ AD user accounts, 50+ server topology
About the victim
AI dossier — public-source company profileJinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers across multiple states. They serve 7,400+ beauty supply stores and 2,800+ international distributors, functioning as a critical supply-chain intermediary in the beauty retail sector.
- Industry
- Wholesale Beauty Distribution
- Address
- Multiple locations: Doraville, Georgia to Commerce, California (9 distribution centers)
- Employees
- 260
Attack summary
Severity: critical — Confirmed exfiltration of payment card data (PII at scale: 911 authorization forms with full card details and signatures), employee tax records with SSN/DOB, complete customer PII databases, and administrative infrastructure credentials providing attackers persistent access to critical business systems affecting thousands of downstream retail partners.AUR0RA claims to have exfiltrated 3.6 GB of SQL database backups (customer orders November 2019–March 2020), a 340 MB Shopify backup, complete password vaults for payment processors and ERP systems, Active Directory enumeration, employee compensation records, tax documents, and 911 scanned credit card authorization forms with full card details and cardholder signatures.
Data the group says was taken
AI dossier — extracted from the leak post- SQL database backups (e-commerce customer/order/product data)
- Shopify customer database (names, emails, phones, addresses)
- 911 credit card authorization forms with full PAN, CVV, expiry, signatures
- Employee compensation database (~260 employees, 2015–2018)
- Employee tax documents (W-4, I-9, SSN, direct deposit records)
- Payment processor credentials (PayPal, Braintree, Amazon, eBay)
- ERP system credentials (Acumatica production)
- Tax portal credentials (12 state systems)
- VMware hypervisor root passwords (vCenter, ESXi)
- Active Directory enumeration (239+ user accounts, 17 admin accounts)
- Server topology and RDP passwords (50+ servers across 7 sites)
What the group claims
One of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers. Serves 7,400+ beauty supply stores and 2,800+ international distributors.
The leak post
captured from the group's site[ Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states. Complete employee compensation database — ~260 employees with Korean and English names, departments, salaries, bonuses, and 1099 contractor data spanning 2015–2018. A 340 MB Shopify database backup — full customer table (names, emails, phones, addresses), product catalog, pricing, and warehouse assignments. Active Directory domain enumeration — all 239+ user accounts…
Data the group says was taken
- credentials/passwords
- VMware hypervisor root credentials
- credit card data
- employee compensation data
- Shopify database backup
- Active Directory enumeration
- employee tax documents
- SQL Server database backups
- W-4 forms
- I-9 forms
- direct deposit forms
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

