Ransomware group aurora hits Corporación Primax S.A.
Corporación Primax S.A. — a not found target operating in PE has been listed by the aurora ransomware group on 2026-06-23. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Corporación Primax S.A. |
|---|---|
| Threat Group | aurora |
| Summary | [distribution, fuel] ***.A. is Peru's largest fuel distribution company, operating 2,185+ stations across Peru, Ecuador, Colombia, and Uruguay with annualised revenue of approximately USD 3.4 billion (Peru alone). The dataset spans every function of the business: Complete financial reporting — Monthly P&L, balance sheet, cash flow, and EBITDA through May 2025. GRIO (Grupo Romero Investment Office) management reporting packages. Budget 2025 vs. actuals. Employee identity data for 15,000–60,000 individuals — DNI national ID numbers, bank accounts, salary amounts, pension fund details, scanned identity documents. Live system credentials — Plaintext SQL database passwords, banking SFTP credentials (Banco Bolivariano Ecuador), AD encryption master key, OSINERGMIN fuel-control system credentials. Complete OT network map — IP addresses and identifiers for 137 fuel stations on the internal 10.55.40.x network, plus JD Edwards ERP production servers. 54 GB of POS transaction data — XML records of consumer fuel purchases across the entire station network. Legal and M&A documentation — Arbitration case files (PUCP/AMCHAM), UNO Corp acquisition materials (Dec 2025), bank covenant waivers. |
| Date of Breach | 2026-06-23 |
| Discovery Date | 2026-06-23 |
| Region | PE |
| Target Domain | Corporación Primax S.A. |
| Business Sector | Not Found |
| Severity | MEDIUM |
Claim by aurora
[distribution, fuel] ***.A. is Peru's largest fuel distribution company, operating 2,185+ stations across Peru, Ecuador, Colombia, and Uruguay with annualised revenue of approximately USD 3.4 billion (Peru alone). The dataset spans every function of the business: Complete financial reporting — Monthly P&L, balance sheet, cash flow, and EBITDA through May 2025. GRIO (Grupo Romero Investment Office) management reporting packages. Budget 2025 vs. actuals. Employee identity data for 15,000–60,000 individuals — DNI national ID numbers, bank accounts, salary amounts, pension fund details, scanned identity documents. Live system credentials — Plaintext SQL database passwords, banking SFTP credentials (Banco Bolivariano Ecuador), AD encryption master key, OSINERGMIN fuel-control system credentials. Complete OT network map — IP addresses and identifiers for 137 fuel stations on the internal 10.55.40.x network, plus JD Edwards ERP production servers. 54 GB of POS transaction data — XML records of consumer fuel purchases across the entire station network. Legal and M&A documentation — Arbitration case files (PUCP/AMCHAM), UNO Corp acquisition materials (Dec 2025), bank covenant waivers.
Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
Corporación Primax S.A.
Leak post (onion / Tor)
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/corporacin-primax-sa-9fd84393
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

