Skip to main content

Ransomware victim disclosure

All victims

GILDE Handwerk Macrander GmbH & Co. KG

Claimed by Aurora · listed 4 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedAug 4, 2026
  2. Data leakeddate unknown

At a glance

Group
Aurora
Status
Data leaked
Country
Germany
Listed on leak site
Aug 4, 2026

About the victim

AI dossier — public-source company profile

GILDE Handwerk Macrander GmbH & Co. KG is a family-owned German Mittelstand wholesale group headquartered in Bocholt, North Rhine-Westphalia. It operates across multiple brands (GILDE Handwerk, Fink Living, HAKU Möbel) with 50+ legal entities spanning Germany, Austria, the Netherlands, France, the UK, and Hong Kong, serving the gifts, home accessories, and furniture sectors.

Industry
Wholesale Trade – Gifts, Home Accessories & Furniture
Address
Bocholt, Nordrhein-Westfalen, Germany
Employees
400–900

Attack summary

Severity: critical — Confirmed exfiltration of regulated PII at scale (148+ identity documents, 400–1000 individuals' tax IDs, SSNs, bank details), 20 years of sensitive financial records for a multinational group, and digital tax credentials enabling fraudulent VAT/income tax filings. Data spans executives, employees, and family members across multiple jurisdictions.

Aurora claims to have exfiltrated comprehensive corporate and personal data. The group states it obtained 148+ employee/director identity documents, digital tax credentials for 50+ entities, full payroll records spanning 2006–2025 for 400–1000 individuals, 20 years of consolidated financial records, and 1,800+ inventory/commercial databases.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • personal ID documents (Personalausweise, passports, driver licences, marriage certificates)
  • ELSTER tax certificates (50+ entities)
  • employee payroll records (2006–2025)
  • tax IDs and social security numbers
  • bank account details
  • sick notes and disciplinary records
  • consolidated financial records (2004–2025)
  • balance sheets and P&L statements
  • loan documentation and shareholder agreements
  • access databases (inventory, customer lists, supplier terms, pricing)
  • order history

What the group claims

[wholesale] GILDE Handwerk Macrander GmbH & Co. KG is a family-owned German Mittelstand group headquartered in Bocholt, Nordrhein-Westfalen. The GILDE Gruppe operates across wholesale trade in gifts, home accessories, and furniture through brands including GILDE Handwerk, Fink Living, and HAKU Möbel, with 50+ legal entities spanning Germany, Austria, the Netherlands, France, the UK, and Hong Kong. The exposed material includes: <censored> 148+ personal ID document scans — Personalausweise (national ID cards), Reispässe (passports), Führerscheine (driver's licences), and Heiratsurkunden (marriage certificates) for employees, directors, and family members. Names range from warehouse staff to the CEO. ELSTER tax certificates for 50+ entities — the digital keys for filing tax returns with the German Finanzamt, plus personal certificates for directors and family members. Enables fraudulent VAT returns and income tax filings. <censored> Full employee payroll records (2006–2025) — tax IDs (Steuer-IDs), social security numbers, bank accounts, salary details, sick notes (Krankmeldungen), and disciplinary records for an estimated 200–400 current and 200–500 former employees across all entities. 20 years of consolidated financial records — balance sheets, P&L statements, bank reconciliations, loan documentation, shareholder agreements, and capital contribution records for the entire group from 2004 to 2025. 1,800+ Access databases — inventory valuations, customer lists, supplier terms, product pricing, and order history spanning the entire commercial operation.

Sources

Source

Indexed 4 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About aurora

Aurora is a recently emerged ransomware group first observed in April 2026, operating with apparent financial motivations through targeted attacks across multiple sectors. Given its recent emergence, limited public documentation exists regarding the group's specific country of origin or affiliations with established ransomware operations, though its targeting patterns suggest a professional operation potentially operating as an independent entity rather than a known Ransomware-as-a-Service model. The group has demonstrated a preference for attacking business-critical sectors including business services, consumer services, manufacturing, healthcare, and financial services, with documented attacks spanning the United States, Canada, the Maldives, and Great Britain, though specific initial access vectors and technical methodologies remain undocumented by major threat intelligence firms. With only seven known victims documented since April 2026, Aurora represents a relatively small-scale operation compared to established ransomware families, though its cross-sector targeting approach and international victim scope indicate deliberate selection criteria rather than opportunistic attacks. The group remains active as of current reporting, though the limited victim count and recent emergence suggest either a highly selective targeting approach or a nascent operation still developing its operational capabilities. The group has been linked to 27 public disclosures across our corpus. First observed on a leak site on April 29, 2026; most recent post August 4, 2026. The operation is currently active.

Timeline of this disclosure

  • August 4, 2026GILDE Handwerk Macrander GmbH & Co. KG listed by auroraon the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Manufacturing sector, which has 3,684 disclosures indexed across all operators we track. Geographically, GILDE Handwerk Macrander GmbH & Co. KG is reported in Germany, a country with 380 ransomware disclosures in our corpus.

If your organisation is affected

A listing by aurora means GILDE Handwerk Macrander GmbH & Co. KG appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CERT-Bund (Germany), as required for your jurisdiction.
  • Monitor for the data appearing on aurora's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.