# Aurora ransomware claims Thomas Y. Pickett breach

Published: 2026-10-05 · Severity: elevated · Sectors: government-national
Canonical: https://vorant.io/reports/7a040375-cdd5-530f-8658-f5fe3ec49ef5/aurora-ransomware-claims-thomas-y-pickett-breach

> Aurora ransomware group lists Texas tax appraisal firm Thomas Y. Pickett, claiming theft of databases, HR records, source code and signing certificates.

Ransomware.live has indexed a victim listing from the Aurora ransomware group naming Thomas Y. Pickett & Co., Inc., a Texas-based property tax appraisal consulting firm operating across several US states. The posting claims exfiltration of a substantial data set: 13 SQL Server database backups (127GB) including a 102GB web portal database with property owner records and user credentials, complete employee HR files (SSNs, W-4s, medical records, termination documents), an 11GB Azure DevOps repository containing full source history including a proprietary COBOL tax-notice generation program, over 200 client contracts with pricing data for county appraisal districts, and financial records including bank statements and evidence of a prior fraud incident.

Notably the claim includes two high-impact exposure items: a developer password allegedly visible in a directory name within the leaked file listing, and a PKCS#12 private signing certificate belonging to an HR manager, which if genuine would enable forgery of signed documents attributed to that individual. These specifics suggest the actors had broad access to internal source control and credential material, not just file shares.

Defenders at organizations with similar exposure (source control systems, backup repositories, HR document stores) should treat this as a reminder to audit for credentials embedded in file/directory names, rotate any signing certificates with exposed private keys, and ensure database backups and DevOps repositories are access-controlled and monitored for bulk export activity. As this is a claims-based leak-site posting, the full extent and veracity of the exfiltrated data has not been independently verified by this brief.

## Mentioned in this report

- Threat actors: aurora
- Malware: Aurora

## Detection guidance (public sample)

### Rclone Used to Copy or Sync Data to Remote Cloud Storage

ATT&CK: T1567

rclone.exe run with copy/sync/move verbs, a common tool for bulk exfiltration of database backups and repositories to cloud storage. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Rclone Used to Copy or Sync Data to Remote Cloud Storage
description: Detects rclone executed with copy, sync or move verbs, a common bulk-exfiltration
  pattern to web or cloud storage services. Matches the tool behaviour and verbs,
  not any specific remote name. Reviewers should check the destination remote and
  source path size.
tags:
- attack.exfiltration
- attack.t1567
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith: \rclone.exe
  selection_verb:
    CommandLine|contains:
    - ' copy '
    - ' sync '
    - ' move '
    - ' copyto '
  condition: selection_img and selection_verb
falsepositives:
- Administrators using rclone for sanctioned backup replication to cloud storage
- DevOps jobs that sync build artifacts with rclone
level: high
id: 4a25d463-74e4-5d57-a829-baae5814e812
status: experimental
author: Vorant
references:
- https://www.ransomware.live/id/VGhvbWFzIFkuIFBpY2tldHQgJiBDby4sIEluYy5AYXVyb3Jh
```

### Archiver Packing SQL Backups or PKCS12 Certificates

ATT&CK: T1530

7-Zip or WinRAR creating archives that include SQL Server backup (.bak) or PKCS#12 (.pfx/.p12) files, a staging step before bulk exfiltration. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Archiver Packing SQL Backups or PKCS12 Certificates
description: Detects archive utilities adding SQL Server backup files or PKCS#12 private
  key containers to an archive, which is typical data staging ahead of exfiltration.
  Generalises on file types and the archiver add command, not victim-specific names.
tags:
- attack.collection
- attack.t1530
- attack.t1560.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
    - \7z.exe
    - \7za.exe
    - \rar.exe
    - \winrar.exe
  selection_add:
    CommandLine|contains:
    - ' a '
    - ' u '
  selection_files:
    CommandLine|contains:
    - .bak
    - .pfx
    - .p12
  condition: selection_img and selection_add and selection_files
falsepositives:
- DBAs compressing SQL backups for archival or transfer
- Certificate backup routines run by PKI administrators
level: medium
id: daa00c95-4749-51ec-8dd5-4ccb3bd54205
status: experimental
author: Vorant
references:
- https://www.ransomware.live/id/VGhvbWFzIFkuIFBpY2tldHQgJiBDby4sIEluYy5AYXVyb3Jh
```

### Recursive Search of Files for Passwords via Findstr or PowerShell

ATT&CK: T1552.001

Recursive findstr or Select-String searches for password strings across files, used to harvest credentials stored in configs or scripts. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Recursive Search of Files for Passwords via Findstr or PowerShell
description: Detects recursive command-line searches for password strings in files
  using findstr /s or Get-ChildItem -Recurse piped to Select-String. Indicates hunting
  for unsecured credentials in source trees, configs and file shares.
tags:
- attack.credential-access
- attack.t1552.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_findstr:
    Image|endswith: \findstr.exe
    CommandLine|contains|all:
    - /s
    - pass
  selection_ps_img:
    Image|endswith:
    - \powershell.exe
    - \pwsh.exe
  selection_ps_cmd:
    CommandLine|contains|all:
    - Select-String
    - -Recurse
  selection_ps_pw:
    CommandLine|contains:
    - password
    - passwd
    - pwd
  condition: selection_findstr or (selection_ps_img and selection_ps_cmd and selection_ps_pw)
falsepositives:
- Developers or auditors scanning code for hard-coded secrets
- Security tooling performing credential hygiene checks
level: medium
id: 8247a6bd-1b9c-5657-85c7-77d2bd7a2373
status: experimental
author: Vorant
references:
- https://www.ransomware.live/id/VGhvbWFzIFkuIFBpY2tldHQgJiBDby4sIEluYy5AYXVyb3Jh
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.ransomware.live/id/VGhvbWFzIFkuIFBpY2tldHQgJiBDby4sIEluYy5AYXVyb3Jh

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7a040375-cdd5-530f-8658-f5fe3ec49ef5/aurora-ransomware-claims-thomas-y-pickett-breach.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
