Ransomware victim disclosure
← All victimsJinny Beauty Supply
Claimed by Aurora · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Country
- United States
- Sector
- Retail & E-Commerce
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profileJinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. The company serves 7,400+ beauty supply stores and 2,800+ international distributors.
- Industry
- Wholesale Beauty Distribution
- Employees
- 260
Attack summary
Severity: critical — Confirmed exfiltration of highly regulated sensitive data including: payment card data (PCI scope), employee SSNs and tax documents (federal records), customer PII at scale, complete infrastructure credentials enabling full system compromise, and financial account credentials. Multiple compliance violations (PCI-DSS, SOX, state privacy laws).Aurora claims to have exfiltrated a complete password vault, VMware hypervisor credentials, scanned credit card authorization forms, employee compensation and tax documents, Active Directory enumeration data, and multiple database backups. The group has published evidence of access to financial payment systems, employee PII at scale (SSNs, bank account details), customer payment card data, and complete infrastructure topology.
Data the group says was taken
AI dossier — extracted from the leak post- 50+ plaintext credentials (PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP, tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, email)
- VMware vCenter and ESXi root passwords
- 911 scanned credit card authorization forms with full card numbers, CVV, expiry, cardholder signatures
- Employee compensation database (260 employees, 2015-2018)
- 340 MB Shopify database backup (customer names, emails, phones, addresses, catalog, pricing)
- Active Directory domain enumeration (239+ user accounts, 17 admin accounts, 50+ servers)
- Employee W-4 forms (SSNs)
- Employee I-9 forms (SSN, DOB, citizenship)
- Direct deposit forms (bank account and routing numbers)
- 3.6 GB SQL Server database backups (e-commerce customer/order/product data, Nov 2019 - Mar 2020)
What the group claims
[distributors] Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states. Complete employee compensation database — ~260 employees with Korean and English names, departments, salaries, bonuses, and 1099 contractor data spanning 2015–2018. A 340 MB Shopify database backup — full customer table (names, emails, phones, addresses), product catalog, pricing, and warehouse assignments. Active Directory domain enumeration — all 239+ user accounts including 17 admin accounts, the complete server topology across 7 geographic sites (50+ servers), and DPAPI-encrypted RDP passwords. Employee tax documents — W-4 forms (SSN), I-9 forms (SSN + DOB + citizenship), direct deposit forms (bank account and routing numbers). 3.6 GB of SQL Server database backups — e-commerce customer/order/product data spanning November 2019 to March 2020.
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

