VORANT. Threat Intelligence Research Sign in Create a free account

Aurora ransomware group lists Buford-Thompson Company

elevated threat educationnon-profitfinancial-servicesmanufacturing

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Aurora ransomware actors claim a 1.7TB data leak from Texas contractor Buford-Thompson, exposing employee SSNs, bank credentials, and school district project data.

Ransomware.live has indexed a victim listing from the Aurora ransomware group targeting Buford-Thompson Company, LTD, a Texas-based construction general contractor specializing in K-12 school building projects. The claimed exfiltrated dataset totals 1.707 TB and reportedly includes highly sensitive material: five years of W-2 EFW2 files (2021-2025) with plaintext SSNs and wages for 350+ current and former employees, 9.3 GB of attorney-client privileged litigation files from a lawsuit with Stanton ISD, complete Frost Bank account and ACH routing details, and documentation for 36+ active school construction projects including blueprints, bid estimates, and subcontractor pricing.

Beyond the primary victim, the leak reportedly implicates third parties: over 2,000 donor records from a Phoenix homeless-services nonprofit (Human Services Campus) and QuickBooks accounting/donor/payroll files from a prison ministry organization (Along Side Ministries), suggesting shared infrastructure, cloud storage, or a common service provider was compromised alongside the primary target. Personal financial and property records belonging to the company's owning family are also claimed to be included.

No technical indicators, initial access vector, or malware artifacts are provided in this listing — it is a leak-site/victim posting rather than a technical intrusion analysis. Defenders in construction, education-sector contracting, and organizations sharing cloud/accounting infrastructure with small nonprofits should treat this as a reminder to audit third-party data exposure, monitor for credential/financial fraud stemming from the leaked Frost Bank details, and review data retention practices for W-2/EFW2 files and privileged legal correspondence.

Mentioned in this report

Threat actors aurora

Source reporting: https://www.ransomware.live/id/QnVmb3JkLVRob21wc29uIENvbXBhbnksIExUREBhdXJvcmE=

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,730 reports from 154 sources, 556 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs