Ransomware victim disclosure
← All victimsERPIS LLC
Claimed by Aurora · listed 4 hours ago
Status timeline
- ListedAug 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Sector
- Professional Services
- Listed on leak site
- Aug 26, 2026
About the victim
AI dossier — public-source company profileERPIS LLC, doing business as ShipERP, is a Texas-based SAP integrator that develops enterprise shipping management software. The company serves 88 enterprise customers including Boeing, Pfizer, NVIDIA, John Deere, and Medtronic, with a reported $20.6M backlog.
- Industry
- Enterprise Software & SAP Integration
- Address
- Texas, United States
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive data including employee PII (SSN, banking), proprietary source code representing the company's sole revenue asset, complete financial records, customer contracts with pricing, and SAP media. Affects 88 enterprise customers in regulated sectors (aerospace, pharmaceuticals, medical devices). Represents existential threat to the company.Aurora claims to have exfiltrated complete source code for ShipERP (versions 2.0–5.4), live financial databases including payroll and banking details, customer contracts with pricing information, and SAP installation media. The group published the data.
Data the group says was taken
AI dossier — extracted from the leak post- Product source code (ShipERP versions 2.0–5.4)
- QuickBooks financial database
- Employee payroll records (SSN, bank accounts, salaries)
- Vendor banking details
- Accounts receivable/payable records
- General ledger
- Customer contract register with pricing
- SAP installation media (HANA, S/4HANA, kernel)
What the group claims
[software] ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers. The exposed material includes: Complete product source code — all versions (2.0–5.4) of ShipERP's ABAP source, the company's sole revenue-generating asset ($20.6M backlog) <redacted> Live QuickBooks financial database (705 MB) — complete payroll (SSN, bank accounts, salaries), vendor banking details, AR/AP, and general ledger Full customer contract register — exact pricing for all 88 enterprise customers with $20.6M in deferred revenue <redacted> SAP installation media (245 GB) — full HANA, S/4HANA, and kernel distributions <redacted>
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

