Ransomware victim disclosure
← All victimsChip 1 Exchange
Claimed by AUR0RA · listed 3 hours ago
Status timeline
- ListedSep 17, 2026
- Data leakeddate unknown
At a glance
- Group
- AUR0RA
- Status
- Data leaked
- Country
- Germany
- Sector
- Electronics Distribution
- Listed on leak site
- Sep 17, 2026
- Data size
- 5.7 GB (Outlook PST archives alone)
- Records
- 124000 files
About the victim
AI dossier — public-source company profileChip 1 Exchange is a global independent electronics distributor headquartered in Neu-Isenburg, Germany with primary US operations in Laguna Hills, California. The company distributes electronic components and serves major OEMs and defense contractors across North America and Europe, with estimated annual revenue exceeding $100 million.
- Industry
- Electronics Distribution
- Address
- Neu-Isenburg, Germany (HQ); Laguna Hills, California, USA (primary US operations)
- Employees
- 100-500
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated data at scale: employee PII (SSNs, passport photos, tax documents) across US, Mexican, and European workforce; complete corporate banking and ERP credentials enabling immediate financial and operational access; ITAR-controlled defense customer records and potential export control violations; 13 years of financial intelligence including bank account numbers and proprietary supplier agreements.AUR0RA claims to have exfiltrated 13 years (2013–2026) of corporate data including employee identity documents, financial records, banking credentials, supplier agreements, and ITAR-controlled defense customer sales orders. The group published 5.7 GB of Outlook PST email archives containing C-suite and employee correspondence.
Data the group says was taken
AI dossier — extracted from the leak post- Passport photographs (40+)
- I-9 forms with SSNs
- W-4 tax forms
- Payroll registers
- Firefox password vault (53 credentials) with decryption key
- Corporate banking credentials (Wells Fargo)
- ERP access (NetSuite)
- Domain management credentials (GoDaddy)
- Supplier portal credentials (15+: Arrow, Farnell, Microchip, Texas Instruments)
- 2026 financial statements (P&L, AR/AP aging, chart of accounts with bank account numbers)
- Franchise manufacturer agreements with pricing and territory allocations
- Gross profit margin data by customer
- ITAR registration documents
- Defense customer sales orders (Jabil Defense, Curtis-Wright, GEN3 Defense, Cobham Remec)
- Outlook PST email archives (5.7 GB)
What the group claims
Global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California.
The leak post
captured from the group's site[ Chip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California. The dataset spans 13 years (2013-2026) of corporate operations and encompasses: 40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, payroll registers — the complete identity theft toolkit for the entire US, Mexican, and European workforce. A Firefox saved-password vault (53 credentials) with its decryption key — granting immediate access to Wells Fargo corporate banking, NetSuite ERP, GoDaddy domain management, and 15+ supplier portals including Arrow, Farnell, Microchip, and Texas Instruments. Complete 2026 financial intelligence — P&L through July, executive financial health assessment, AR/AP aging, chart of accounts revealing all bank account numbers. 15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins — the core competitive IP of a $100M+ distributor. ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec — potential export control violation. 5.7 GB of Outlook PST email arch…
Data the group says was taken
- passport photographs
- I-9 forms
- SSNs
- W-4 tax forms
- payroll registers
- password vault
- financial records
- franchise agreements
- ITAR registration
- defense customer sales orders
- email archives (PST)
- bank account numbers
- AR/AP aging reports
- P&L statements
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

