Ransomware victim disclosure
← All victimsAura Group, Inc. (aura.com)
Claimed by Hunters International · listed 2 months ago
Status timeline
- Listed
Mar 15, 2026
- Data leaked
At a glance
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 15, 2026
- Data size
- 12 GB
- Records
- 2M records
About the victim
AI dossier — public-source company profileAura Group, Inc. (aura.com) is a U.S.-based consumer cybersecurity and digital safety company offering an all-in-one platform covering identity theft protection, credit monitoring, VPN, antivirus, parental controls, and fraud insurance. The company markets plans starting at $10/month and provides up to $1,000,000 identity theft insurance coverage per adult member. Aura serves both individual consumers and business/MSP partners across the United States.
- Industry
- Consumer Digital Safety & Identity Theft Protection
- Employees
- 501-1000
- Founded
- 2019
Attack summary
Severity: critical — Over 2 million PII records exfiltrated and published from a company that itself stores sensitive consumer identity, credit monitoring, and financial data; the scale, sensitivity, and confirmed data publication all meet the critical threshold, and the reputational and regulatory exposure is compounded by Aura's core business being personal data protection.Hunters International claims to have exfiltrated over 2 million records containing personally identifiable information and internal corporate data, totaling 12 GB compressed, and has published the data after negotiations with the company failed.
Data the group says was taken
AI dossier — extracted from the leak post- PII records (2M+)
- Internal corporate data
- Customer account information
The group's post references roughly 1 proof file.
What the group claims
Over 2M records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care. | Size: 12GB (compressed) | Updated: 15 Mar 2026 | SHA256: 0d5bf85c7865b023266adc95a7449dd1bff6b208b4634976441ce5ee650894d0
Sources
- Victim siteaura.com
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
