HackerFeeds
All ransomware incidents
s.p.a

Ransomware group aurora hits EDIF S.p.A.

MEDIUM
·Manufacturing·IT·2026-08-27

EDIF S.p.A. — a manufacturing target operating in IT has been listed by the aurora ransomware group on 2026-08-27. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationEDIF S.p.A.
Threat Group
aurora
Summary[wholesale] EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices. Copies appear in source code, setup packages and old folders. Customer and employee information is also exposed: invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts and records about CCTV or recorder password resets. The dataset contains internal software, databases, commercial records, legal/tax folders and a detailed 2024 financial report.
Date of Breach2026-08-27
Discovery Date2026-09-04
RegionIT
Target DomainEDIF S.p.A.
Business SectorManufacturing
Severity
MEDIUM

Claim by aurora

[wholesale] EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include passwords for company systems, customer file transfers, certified email and warehouse devices. Copies appear in source code, setup packages and old folders. Customer and employee information is also exposed: invoices, tax numbers, addresses, phone lists, shipment details, computer-profile artifacts and records about CCTV or recorder password resets. The dataset contains internal software, databases, commercial records, legal/tax folders and a detailed 2024 financial report.

Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

EDIF S.p.A.

Leak post (onion / Tor)

tor

http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/edif-spa-privateonlyaccess

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.