Ransomware victim disclosure
← All victimsChip 1 Exchange
Claimed by Aurora · listed 3 days ago
Status timeline
- ListedSep 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Aurora
- Status
- Data leaked
- Country
- Singapore
- Sector
- Technology
- Listed on leak site
- Sep 2, 2026
About the victim
AI dossier — public-source company profileChip 1 Exchange is a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with significant operations in the United States (Laguna Hills, California and Arlington, Texas). The company serves both commercial and defense sectors.
- Industry
- Electronics Distribution
- Address
- Neu-Isenburg, Germany (HQ); Laguna Hills, California, USA (primary US ops); 2202 E. Randol Mill Rd. Arlington, TX 76011, USA
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive data including PII at scale (SSNs, I-9 forms, passport photos), complete financial intelligence, regulated defense-sector information (ITAR, defense contractor sales orders), and proprietary business agreements. Data spans 13 years of operations.The aurora group claims to have exfiltrated 13 years (2013–2026) of corporate data including employee personal documents, financial records, business agreements, and defense-related correspondence. The group asserts access to complete 2026 financial intelligence, franchise agreements, ITAR registration materials, and defense customer sales orders.
Data the group says was taken
AI dossier — extracted from the leak post- Passport photographs (40+)
- I-9 forms with SSNs
- W-4 tax forms
- Payroll registers
- Financial statements (P&L through July 2026)
- Accounts receivable/payable aging
- Bank account numbers
- Franchise manufacturer agreements with pricing and territory data
- ITAR registration
- Defense customer sales orders
- Outlook PST email archives (5.7 GB)
What the group claims
[distributor] Chip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California. The dataset spans 13 years (2013-2026) of corporate operations and encompasses: 40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, payroll registers. <redacted> Complete 2026 financial intelligence — P&L through July, executive financial health assessment, AR/AP aging, chart of accounts revealing all bank account numbers. 15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins. ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec. 5.7 GB of Outlook PST email archives spanning years of C-suite and employee correspondence.
The leak post
captured from the group's siteChip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California. The dataset spans 13 years (2013-2026) of corporate operations and encompasses: 40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, payroll registers. <redacted> Complete 2026 financial intelligence — P&L through July, executive financial health assessment, AR/AP aging, chart of accounts revealing all bank account numbers. 15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins. ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec. 5.7 GB of Outlook PST email archives spanning years of C-suite and employee correspondence. 2202 E. Randol Mill Rd. Arlington, TX 76011, USA
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

