HackerFeeds
All ransomware incidents
typco.com

Ransomware group aurora hits Thomas Y. Pickett & Co., Inc.

MEDIUM
·Professional Services·US·2026-10-05

Thomas Y. Pickett & Co., Inc. — a professional services target operating in US has been listed by the aurora ransomware group on 2026-10-05. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationThomas Y. Pickett & Co., Inc.
Threat Group
aurora
Summary[consulting] Thomas Y. Pickett & Co., Inc. — founded in 1926, headquartered in Addison/Dallas, Texas — is one of the oldest property tax appraisal consulting firms in the United States. They appraise mineral, industrial, and utility properties for county appraisal districts across Texas, Wyoming, North Dakota, Mississippi, Oklahoma, and beyond. Roughly 40 employees, ~$5.3M annual revenue, nearly a century of reputation. Inventory: 13 SQL Server database backups (127 GB) including the 102 GB TYPortal web portal database containing all property owner records and user credentials Complete HR records for all 40+ employees — Social Security cards, W-4s, direct deposit forms, salary schedules, medical records, termination documents, TWC hearing notices 11 GB Azure DevOps repository — the entire source code history, including a 6,105-line proprietary COBOL program (NOTICE14) that generates tax appraisal notices 200+ client contracts with pricing for every county appraisal district they serve — the competitive intelligence gold mine Complete financial records — bank statements (PNC and Frost), 10-year budget, accounts receivable, payroll, and evidence of a prior fraud incident in May 2025 A developer's password exposed in a directory name visible to anyone who looks at the file listing A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Date of Breach2026-10-05
Discovery Date2026-10-05
RegionUS
Target Domaintypco.com
Business SectorProfessional Services
Severity
MEDIUM

Claim by aurora

[consulting] Thomas Y. Pickett & Co., Inc. — founded in 1926, headquartered in Addison/Dallas, Texas — is one of the oldest property tax appraisal consulting firms in the United States. They appraise mineral, industrial, and utility properties for county appraisal districts across Texas, Wyoming, North Dakota, Mississippi, Oklahoma, and beyond. Roughly 40 employees, ~$5.3M annual revenue, nearly a century of reputation. Inventory: 13 SQL Server database backups (127 GB) including the 102 GB TYPortal web portal database containing all property owner records and user credentials Complete HR records for all 40+ employees — Social Security cards, W-4s, direct deposit forms, salary schedules, medical records, termination documents, TWC hearing notices 11 GB Azure DevOps repository — the entire source code history, including a 6,105-line proprietary COBOL program (NOTICE14) that generates tax appraisal notices 200+ client contracts with pricing for every county appraisal district they serve — the competitive intelligence gold mine Complete financial records — bank statements (PNC and Frost), 10-year budget, accounts receivable, payroll, and evidence of a prior fraud incident in May 2025 A developer's password exposed in a directory name visible to anyone who looks at the file listing A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery

Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

typco.com

Leak post (onion / Tor)

tor

http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/thomas-y-pickett-co-inc-603ef49c

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.