Ransomware victim disclosure
← All victimsEDIF S.p.A.
Claimed by AUR0RA · listed 6 days ago
Status timeline
- ListedSep 7, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileEDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The company serves commercial and retail customers with a range of building and electrical supplies.
- Industry
- Wholesale Distribution / Electrical Equipment & Building Materials
Attack summary
Severity: high — Confirmed exfiltration of significant business data including customer PII (invoices, tax numbers, addresses, phone lists), employee information, financial records, and internal systems access credentials. Scale and sensitivity of commercial and personal data exposed justifies high severity.AUR0RA claims to have exfiltrated internal systems and databases from EDIF S.p.A., including passwords for company systems, customer file transfers, and warehouse devices. The exposed data includes customer and employee information, internal software, databases, commercial records, legal and tax documentation, and a 2024 financial report.
Data the group says was taken
AI dossier — extracted from the leak post- system passwords
- customer file transfers
- warehouse device credentials
- customer invoices
- tax identification numbers
- employee addresses and phone lists
- shipment details
- internal software and source code
- commercial databases
- legal and tax records
- 2024 financial report
- CCTV and recorder credentials
What the group claims
Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. Exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices, source code, setup packages, customer and employee information, invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts, CCTV/recorder password resets, internal software, databases, commercial records, legal/tax folders, and a detailed 2024 financial report.
The leak post
captured from the group's site### [Metrea LLC/Commuter Air Technology, Inc. Metrea LLC (formerly Meta Special Aerospace, LLC) and its subsidiary Commuter Air Technology, Inc. (CAT) are US defense contractors providing Contractor Owned, Contractor Operated (COCO) ISR aircraft services to US Special Operations Command. They operate modified King Air 350 surveillance aircraft in Niger, East Africa, the Philippines, and other theaters. <redacted> 339 MB of Harris PRC-117G military tactical radio firmware including compiled waveform binaries for SINCGARS, HAVEQUICK II, ROVER, and 10 other ITAR-controlled waveforms (USML Category XI). Named deployment data for 14+ operators at Sable Spear sites in Niger and East Africa, with rotation schedules, SIPRNet access documentation, and divert airfield planning. Complete SOCOM contract pricing portfolios — labor rates, burn rates, TINA-certified cost data, and subcontractor pricing for SOCPAC C3PO, Sable Spear, and Sable Dagger programs. 232 employee personnel files including resumes, W-9 forms (SSN), SERE training certificates, security clearances, expense reports, and deployment records. NSWDG (SEAL Team Six), MARSOC, and 75th Rangers training exercise documentation — 37 se…
Data the group says was taken
- passwords
- customer files
- employee information
- invoices
- tax numbers
- addresses
- phone lists
- shipment details
- source code
- databases
- financial reports
- legal/tax records
Screenshot of the leak post

Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

