Ransomware victim disclosure
← All victimsAura Group, Inc
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 12, 2026
- Records
- 2M records
About the victim
AI dossier — public-source company profileAura Group, Inc is likely a financial services or wealth management firm based in the United States. Without an accessible public site, specific operational details cannot be confirmed, but companies operating under the 'Aura Group' name in the US typically offer investment advisory, asset management, or related financial services. Scale and headquarters remain unverified from available sources.
- Industry
- Financial Services & Wealth Management
Attack summary
Severity: critical — Over 2 million PII-containing records claimed exfiltrated at scale by a known prolific threat actor (ShinyHunters); if the company is in financial services, the data likely includes regulated financial PII, meeting the critical threshold.ShinyHunters claims to have exfiltrated over 2 million records containing PII and internal corporate data, issuing a final warning deadline of 14 March 2026 before publishing the data and threatening additional unspecified 'digital problems' if no contact is made.
Data the group says was taken
AI dossier — extracted from the leak post- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 14 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

