Ransomware group aurora hits Natco Home Group
Natco Home Group — a retail & e-commerce target operating in US has been listed by the aurora ransomware group on 2026-08-17. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Natco Home Group |
|---|---|
| Threat Group | aurora |
| Summary | [manufacturer] Natco Home Group — a fourth-generation, family-owned home furnishings manufacturer headquartered in West Warwick, Rhode Island, with ~800 employees, ~$100M annual revenue, and facilities across seven US states. The exfiltrated dataset spans the company's entire corporate history and includes: Social Security numbers in plaintext for 100–120 legacy employees dating back to 1979 in an unencrypted PayUSA payroll database, plus 10 years of ADP payroll data (2017–2026) covering 700–1,000 current and former employees — pay stubs, W-2s, W-4s, 401k records, drug test results, background checks, and medical leave records. <censored> <censored> <censored> <censored> Years of divisional financial statements, income tax records, customer credit data for major retailers, 18 years of bad-debt reserve calculations, and acquisition-related materials. |
| Date of Breach | 2026-08-17 |
| Discovery Date | 2026-08-17 |
| Region | US |
| Target Domain | Natco Home Group |
| Business Sector | Retail & E-Commerce |
| Severity | MEDIUM |
Claim by aurora
[manufacturer] Natco Home Group — a fourth-generation, family-owned home furnishings manufacturer headquartered in West Warwick, Rhode Island, with ~800 employees, ~$100M annual revenue, and facilities across seven US states. The exfiltrated dataset spans the company's entire corporate history and includes: Social Security numbers in plaintext for 100–120 legacy employees dating back to 1979 in an unencrypted PayUSA payroll database, plus 10 years of ADP payroll data (2017–2026) covering 700–1,000 current and former employees — pay stubs, W-2s, W-4s, 401k records, drug test results, background checks, and medical leave records. <censored> <censored> <censored> <censored> Years of divisional financial statements, income tax records, customer credit data for major retailers, 18 years of bad-debt reserve calculations, and acquisition-related materials.
Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
Natco Home Group
Leak post (onion / Tor)
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/natco-home-group-77b27d0d
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

