# Aurora ransomware group lists Buford-Thompson Company

Published: 2026-09-30 · Severity: elevated · Sectors: education, non-profit, financial-services, manufacturing
Canonical: https://vorant.io/reports/d71883da-577c-586e-9caf-f35bc7bad8bb/aurora-ransomware-group-lists-buford-thompson-company

> Aurora ransomware actors claim a 1.7TB data leak from Texas contractor Buford-Thompson, exposing employee SSNs, bank credentials, and school district project data.

Ransomware.live has indexed a victim listing from the Aurora ransomware group targeting Buford-Thompson Company, LTD, a Texas-based construction general contractor specializing in K-12 school building projects. The claimed exfiltrated dataset totals 1.707 TB and reportedly includes highly sensitive material: five years of W-2 EFW2 files (2021-2025) with plaintext SSNs and wages for 350+ current and former employees, 9.3 GB of attorney-client privileged litigation files from a lawsuit with Stanton ISD, complete Frost Bank account and ACH routing details, and documentation for 36+ active school construction projects including blueprints, bid estimates, and subcontractor pricing.

Beyond the primary victim, the leak reportedly implicates third parties: over 2,000 donor records from a Phoenix homeless-services nonprofit (Human Services Campus) and QuickBooks accounting/donor/payroll files from a prison ministry organization (Along Side Ministries), suggesting shared infrastructure, cloud storage, or a common service provider was compromised alongside the primary target. Personal financial and property records belonging to the company's owning family are also claimed to be included.

No technical indicators, initial access vector, or malware artifacts are provided in this listing — it is a leak-site/victim posting rather than a technical intrusion analysis. Defenders in construction, education-sector contracting, and organizations sharing cloud/accounting infrastructure with small nonprofits should treat this as a reminder to audit third-party data exposure, monitor for credential/financial fraud stemming from the leaked Frost Bank details, and review data retention practices for W-2/EFW2 files and privileged legal correspondence.

## Mentioned in this report

- Threat actors: aurora

Source reporting: https://www.ransomware.live/id/QnVmb3JkLVRob21wc29uIENvbXBhbnksIExUREBhdXJvcmE=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d71883da-577c-586e-9caf-f35bc7bad8bb/aurora-ransomware-group-lists-buford-thompson-company.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
