# Aurora group claims Metrea defense contractor breach

Published: 2026-09-05 · Severity: high · Sectors: defense
Canonical: https://vorant.io/reports/7ab4ae56-c374-50cb-802c-0e4c92b766bb/aurora-group-claims-metrea-defense-contractor-breach

> An extortion group claims to have stolen ITAR-controlled military radio firmware and SOCOM program data from US defense contractor Metrea LLC and subsidiary Commuter Air Technology.

Ransomware.live has indexed a data leak listing for Metrea LLC (formerly Meta Special Aerospace) and its subsidiary Commuter Air Technology, Inc. (CAT), US defense contractors that operate Contractor Owned, Contractor Operated (COCO) ISR aircraft for US Special Operations Command, including modified King Air 350 surveillance platforms deployed in Niger, East Africa, and the Philippines. The listing claims exfiltration of roughly 339 MB of Harris PRC-117G tactical radio firmware, including compiled waveform binaries for SINCGARS, HAVEQUICK II, ROVER, and other ITAR-controlled (USML Category XI) waveforms.

The claimed data set extends well beyond technical firmware: named deployment rosters for operators at Sable Spear sites in Niger and East Africa with rotation schedules and SIPRNet access documentation, divert airfield planning, and complete SOCOM contract pricing portfolios (labor and burn rates, TINA-certified cost data, subcontractor pricing) tied to SOCPAC C3PO, Sable Spear, and Sable Dagger programs. Also claimed are 232 employee personnel files (resumes, W-9 forms with SSNs, SERE training certificates, security clearance data, expense reports, deployment records) and training exercise documentation involving NSWDG (SEAL Team Six), MARSOC, and 75th Rangers under the Alpha 28 program.

No technical intrusion vector, malware, or exploited vulnerability is described in this listing. The source is an aggregator (Ransomware.live) that indexes publicly posted extortion claims rather than the underlying stolen data itself, so the veracity of the claimed data set has not been independently confirmed in this reporting. Given the sensitivity of the alleged material — ITAR-controlled munitions-list technical data, special operations deployment details, and PII of cleared personnel — this warrants urgent validation by the affected organizations and downstream government stakeholders regardless of confirmation status.

## Mentioned in this report

- Threat actors: aurora

Source reporting: https://www.ransomware.live/id/TWV0cmVhIExMQy9Db21tdXRlciBBaXIgVGVjaG5vbG9neSwgSW5jLkBhdXJvcmE=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7ab4ae56-c374-50cb-802c-0e4c92b766bb/aurora-group-claims-metrea-defense-contractor-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
