Ransomware victim disclosure
← All victimsEDIF S.p.A.
Claimed by Aurora · listed 16 hours ago
Status timeline
- ListedSep 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Country
- Italy
- Sector
- Manufacturing
- Listed on leak site
- Sep 4, 2026
About the victim
AI dossier — public-source company profileEDIF S.p.A. is an Italian wholesale distributor specializing in electrical equipment, plumbing, and lighting systems. The company serves commercial and retail customers across Italy.
- Industry
- Electrical Equipment & Building Materials Wholesale
Attack summary
Severity: high — Confirmed exfiltration of significant business data including customer PII at scale (invoices, tax numbers, addresses), employee records, system credentials, and detailed financial information. The breadth of exposed data—spanning operations, customers, employees, and internal systems—indicates substantial organizational compromise.The aurora group claims to have exfiltrated a comprehensive dataset including system credentials, customer records, employee information, internal databases, financial reports, and commercial documentation. Both customer and employee PII alongside sensitive business records were exposed.
Data the group says was taken
AI dossier — extracted from the leak post- System passwords
- Customer invoices
- Tax numbers and financial records
- Employee contact lists
- Physical addresses
- Shipment details
- CCTV and recorder credentials
- Internal software and source code
- Commercial databases
- 2024 financial report
- Legal and tax documentation
What the group claims
[wholesale] EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices. Copies appear in source code, setup packages and old folders. Customer and employee information is also exposed: invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts and records about CCTV or recorder password resets. The dataset contains internal software, databases, commercial records, legal/tax folders and a detailed 2024 financial report.
Sources
Source
Indexed 16 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

