Ransomware victim disclosure
← All victimsERPIS LLC
listed as ERPIS LLC (ShipERP) · Claimed by AUR0RA · listed 5 days ago
Status timeline
- ListedSep 8, 2026
- Data leakeddate unknown
At a glance
- Group
- AUR0RA
- Status
- Data leaked
- Country
- United States
- Sector
- Software/SAP Integration
- Listed on leak site
- Sep 8, 2026
- Data size
- 705 MB QuickBooks DB + 13 GB customer SAP configs + 245 GB SAP installation media
- Records
- 88 enterprise customers, 128+ SAP PSE files, $20.6M contract backlog
About the victim
AI dossier — public-source company profileERPIS LLC, operating as ShipERP, is a Texas-based SAP integrator specializing in enterprise shipping management software. The company serves major Fortune 500 clients including Boeing, Pfizer, NVIDIA, John Deere, and Medtronic, with 83+ enterprise customers and a reported $20.6M backlog.
- Industry
- Enterprise Software & SAP Integration
- Address
- Texas, US
Attack summary
Severity: critical — Exfiltration of proprietary source code representing the company's entire revenue asset, combined with 128+ SAP cryptographic keys enabling impersonation attacks and compromise of 83+ Fortune 500 enterprise customers' SAP environments. Exposure of customer configurations and installation media amplifies downstream risk to regulated sectors (aerospace, pharma, semiconductor, medical devices).AUR0RA claims to have exfiltrated complete product source code (ShipERP versions 2.0–5.4), 128+ SAP cryptographic private keys (PSE files) enabling JWT forgery and TLS impersonation, 705 MB of QuickBooks databases, 13 GB of customer SAP configurations, and 245 GB of SAP installation media. The breach exposes the company's sole revenue-generating asset and compromises cryptographic security controls across customer deployments.
Data the group says was taken
AI dossier — extracted from the leak post- Complete product source code (ShipERP 2.0–5.4)
- SAP cryptographic private keys (PSE files)
- QuickBooks database export
- Customer SAP configurations
- SAP installation media
- Enterprise customer deployment data
What the group claims
Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers.
The leak post
captured from the group's site[ Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states. Complete employee compensation database — ~260 employees with Korean and English names, departments, salaries, bonuses, and 1099 contractor data spanning 2015–2018. A 340 MB Shopify database backup — full customer table (names, emails, phones, addresses), product catalog, pricing, and warehouse assignments. Active Directory domain enumeration — all 239+ user accounts…
Data the group says was taken
- product source code
- SAP cryptographic private keys
- financial database
- payroll data
- SSN
- bank accounts
- customer contracts
- API credentials
- SAP installation media
- customer SAP integration configurations
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

