Ransomware group aurora hits EDIF S.p.A.
EDIF S.p.A. — a manufacturing target operating in IT has been listed by the aurora ransomware group on 2026-08-27. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | EDIF S.p.A. |
|---|---|
| Threat Group | aurora |
| Summary | [wholesale] EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices. Copies appear in source code, setup packages and old folders. Customer and employee information is also exposed: invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts and records about CCTV or recorder password resets. The dataset contains internal software, databases, commercial records, legal/tax folders and a detailed 2024 financial report. |
| Date of Breach | 2026-08-27 |
| Discovery Date | 2026-09-04 |
| Region | IT |
| Target Domain | EDIF S.p.A. |
| Business Sector | Manufacturing |
| Severity | MEDIUM |
Claim by aurora
[wholesale] EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices. Copies appear in source code, setup packages and old folders. Customer and employee information is also exposed: invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts and records about CCTV or recorder password resets. The dataset contains internal software, databases, commercial records, legal/tax folders and a detailed 2024 financial report.
Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
EDIF S.p.A.
Leak post (onion / Tor)
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/edif-spa-privateonlyaccess
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

