Aurora ransomware claims Thomas Y. Pickett breach
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Aurora ransomware group lists Texas tax appraisal firm Thomas Y. Pickett, claiming theft of databases, HR records, source code and signing certificates.
Ransomware.live has indexed a victim listing from the Aurora ransomware group naming Thomas Y. Pickett & Co., Inc., a Texas-based property tax appraisal consulting firm operating across several US states. The posting claims exfiltration of a substantial data set: 13 SQL Server database backups (127GB) including a 102GB web portal database with property owner records and user credentials, complete employee HR files (SSNs, W-4s, medical records, termination documents), an 11GB Azure DevOps repository containing full source history including a proprietary COBOL tax-notice generation program, over 200 client contracts with pricing data for county appraisal districts, and financial records including bank statements and evidence of a prior fraud incident.
Notably the claim includes two high-impact exposure items: a developer password allegedly visible in a directory name within the leaked file listing, and a PKCS#12 private signing certificate belonging to an HR manager, which if genuine would enable forgery of signed documents attributed to that individual. These specifics suggest the actors had broad access to internal source control and credential material, not just file shares.
Defenders at organizations with similar exposure (source control systems, backup repositories, HR document stores) should treat this as a reminder to audit for credentials embedded in file/directory names, rotate any signing certificates with exposed private keys, and ensure database backups and DevOps repositories are access-controlled and monitored for bulk export activity. As this is a claims-based leak-site posting, the full extent and veracity of the exfiltrated data has not been independently verified by this brief.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/VGhvbWFzIFkuIFBpY2tldHQgJiBDby4sIEluYy5AYXVyb3Jh
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,719 reports from 152 sources, 479 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs