Ransomware group aurora hits ERPIS LLC
ERPIS LLC — a professional services target has been listed by the aurora ransomware group on 2026-08-26. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | ERPIS LLC |
|---|---|
| Threat Group | aurora |
| Summary | [software] ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers. The exposed material includes: Complete product source code — all versions (2.0–5.4) of ShipERP's ABAP source, the company's sole revenue-generating asset ($20.6M backlog) <redacted> Live QuickBooks financial database (705 MB) — complete payroll (SSN, bank accounts, salaries), vendor banking details, AR/AP, and general ledger Full customer contract register — exact pricing for all 88 enterprise customers with $20.6M in deferred revenue <redacted> SAP installation media (245 GB) — full HANA, S/4HANA, and kernel distributions <redacted> |
| Date of Breach | 2026-08-26 |
| Discovery Date | 2026-08-26 |
| Region | — |
| Target Domain | ERPIS LLC |
| Business Sector | Professional Services |
| Severity | MEDIUM |
Claim by aurora
[software] ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers. The exposed material includes: Complete product source code — all versions (2.0–5.4) of ShipERP's ABAP source, the company's sole revenue-generating asset ($20.6M backlog) <redacted> Live QuickBooks financial database (705 MB) — complete payroll (SSN, bank accounts, salaries), vendor banking details, AR/AP, and general ledger Full customer contract register — exact pricing for all 88 enterprise customers with $20.6M in deferred revenue <redacted> SAP installation media (245 GB) — full HANA, S/4HANA, and kernel distributions <redacted>
Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
ERPIS LLC
Leak post (onion / Tor)
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/erpis-llc-bb485230
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

