Skip to main content

Ransomware victim disclosure

← All victims

Buford-Thompson Company, LTD

Claimed by Aurora · listed 5 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedSep 30, 2026
  2. Data leakeddate unknown

At a glance

Group
Aurora
Status
Data leaked
Listed on leak site
Sep 30, 2026

About the victim

AI dossier — public-source company profile

Buford-Thompson Company, LTD is a Texas-based construction general contractor with over 30 years of history specializing in school construction for K-12 districts across Texas. The company manages 36+ active school construction projects and maintains banking relationships with Frost Bank.

Industry
Construction – General Contracting (K-12 School Projects)
Address
1450 N. Jim Wright Freeway, White Settlement, Texas 76108
Employees
350+

Attack summary

Severity: critical — Confirmed exfiltration of regulated sensitive data at scale: 350+ unencrypted Social Security numbers in W-2 files, attorney-client privileged communications, active banking credentials and statements, and large-scale PII from third-party nonprofits. Data includes both regulated employee tax records and operational financial controls.

The aurora group claims to have exfiltrated 1.707 TB of data including five years of employee W-2 records with plaintext Social Security numbers, confidential litigation files, complete banking infrastructure credentials, school construction project details, and personal records of the owner and unrelated nonprofit organizations.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • W-2 and EFW2 files (2021–2025) with SSNs and employee PII
  • Attorney-client privileged litigation documents (Stanton ISD v. BTC)
  • Frost Bank account numbers, routing credentials, and statements (2022–2026)
  • School construction blueprints, bid estimates, and subcontractor pricing
  • Donor records from Human Services Campus (Phoenix nonprofit)
  • QuickBooks accounting files from Along Side Ministries
  • Owner personal financial and property records

What the group claims

[construction] Buford-Thompson Company, LTD, a Texas construction general contractor with 30+ years of history building schools for K-12 districts across the state. The exposed dataset totals 1.707 TB and includes: 5 years of W-2 EFW2 files (2021–2025) containing plaintext Social Security numbers, wages, and addresses for 350+ current and former employees — every SSN readable without any decryption. 9.3 GB of attorney-client privileged files from the Stanton ISD v. BTC litigation — legal strategy, discovery responses, and counsel communications. Complete Frost Bank infrastructure — four account numbers, ACH routing credentials, line-of-credit agreements (renewed April 2026), signature cards, and monthly bank statements spanning 2022–2026. 36+ active school construction projects — blueprints, bid estimates, cost structures, subcontractor pricing, and change orders for ISD projects across Texas. A competitor's dream dataset. 2,000+ donor records from Human Services Campus (Phoenix homeless-services nonprofit) with full PII: name, address, phone, email, employer, and donation amounts. QuickBooks company files (.QBW) from Along Side Ministries (Phoenix prison ministry) containing complete accounting, donor, and likely payroll data. Thompson family personal records — owner personal insurance, loans, ranch property (Jack County), airplane ownership, bond dividends, and personal tax documents.

The leak post

captured from the group's site
Buford-Thompson Company, LTD, a Texas construction general contractor with 30+ years of history building schools for K-12 districts across the state. The exposed dataset totals 1.707 TB and includes: 5 years of W-2 EFW2 files (2021–2025) containing plaintext Social Security numbers, wages, and addresses for 350+ current and former employees — every SSN readable without any decryption. 9.3 GB of attorney-client privileged files from the Stanton ISD v. BTC litigation — legal strategy, discovery responses, and counsel communications. Complete Frost Bank infrastructure — four account numbers, ACH routing credentials, line-of-credit agreements (renewed April 2026), signature cards, and monthly bank statements spanning 2022–2026. 36+ active school construction projects — blueprints, bid estimates, cost structures, subcontractor pricing, and change orders for ISD projects across Texas. A competitor's dream dataset. 2,000+ donor records from Human Services Campus (Phoenix homeless-services nonprofit) with full PII: name, address, phone, email, employer, and donation amounts. QuickBooks company files (.QBW) from Along Side Ministries (Phoenix prison ministry) containing complete accounting,…

Sources

Source

Indexed 5 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About aurora

Aurora is a recently emerged ransomware group first observed in April 2026, operating with apparent financial motivations through targeted attacks across multiple sectors. Given its recent emergence, limited public documentation exists regarding the group's specific country of origin or affiliations with established ransomware operations, though its targeting patterns suggest a professional operation potentially operating as an independent entity rather than a known Ransomware-as-a-Service model. The group has demonstrated a preference for attacking business-critical sectors including business services, consumer services, manufacturing, healthcare, and financial services, with documented attacks spanning the United States, Canada, the Maldives, and Great Britain, though specific initial access vectors and technical methodologies remain undocumented by major threat intelligence firms. With only seven known victims documented since April 2026, Aurora represents a relatively small-scale operation compared to established ransomware families, though its cross-sector targeting approach and international victim scope indicate deliberate selection criteria rather than opportunistic attacks. The group remains active as of current reporting, though the limited victim count and recent emergence suggest either a highly selective targeting approach or a nascent operation still developing its operational capabilities. The group has been linked to 40 public disclosures across our corpus. First observed on a leak site on April 29, 2026; most recent post September 30, 2026. The operation is currently active.

Timeline of this disclosure

  • September 30, 2026Buford-Thompson Company, LTD listed by aurora on the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Manufacturing sector, which has 3,696 disclosures indexed across all operators we track. Geographically, Buford-Thompson Company, LTD is reported in United States, a country with 3,167 ransomware disclosures in our corpus.

If your organisation is affected

A listing by aurora means Buford-Thompson Company, LTD appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CISA (United States), as required for your jurisdiction.
  • Monitor for the data appearing on aurora's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.