# Aurora ransomware leaks German firm GILDE Handwerk

Published: 2026-08-04 · Severity: medium · Sectors: retail
Canonical: https://vorant.io/reports/d3230137-3766-5b02-8e18-930b8a7207f1/aurora-ransomware-leaks-german-firm-gilde-handwerk

> The Aurora ransomware group posted stolen ID documents, payroll, tax and financial records from German wholesaler GILDE Handwerk Macrander.

GILDE Handwerk Macrander GmbH & Co. KG, a German Mittelstand wholesale group based in Bocholt with brands including GILDE Handwerk, Fink Living, and HAKU Möbel operating across 50+ legal entities in Germany, Austria, the Netherlands, France, the UK, and Hong Kong, has been listed as a victim on the Aurora ransomware group's leak site. The claimed exfiltrated data spans two decades and includes highly sensitive material: over 148 scanned personal identity documents (national ID cards, passports, driver's licences, marriage certificates) belonging to employees, directors and family members; ELSTER tax filing certificates for 50+ entities that could enable fraudulent VAT or income tax submissions; full payroll records from 2006-2025 covering an estimated 400-900 current and former employees, including tax IDs, social security numbers, bank details, salaries, sick notes and disciplinary records; 20 years of consolidated financial statements and loan/shareholder documentation; and over 1,800 Access databases containing inventory, customer, supplier and pricing data.

This posting represents a significant data-exposure event for the victim organization due to the breadth and sensitivity of personal and financial data involved, particularly the tax certificates and identity documents which carry downstream fraud risk (tax fraud, identity theft) for hundreds of individuals. No technical intrusion details, malware samples, or exploited vulnerabilities are disclosed in the source material, limiting this brief to the extortion/leak aspect of the incident rather than the initial compromise vector.

## Mentioned in this report

- Threat actors: aurora
- Malware: Aurora

Source reporting: https://www.ransomware.live/id/R0lMREUgSGFuZHdlcmsgTWFjcmFuZGVyIEdtYkggJiBDby4gS0dAYXVyb3Jh

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d3230137-3766-5b02-8e18-930b8a7207f1/aurora-ransomware-leaks-german-firm-gilde-handwerk.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
