INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Aurora Publishes New Victim Thomas Y Pickett & Co Inc
| 2026-10-05 08:57 HIGH LOW
Executive Summary
AI-generated
Thomas Y. Pickett & Co., Inc., a 100-year-old property tax appraisal consulting firm in the United States, was targeted by an exfiltration tactic involving server exploitation and ransomware, with the attackers gaining access to sensitive data including HR records for approximately 40 employees, financial records, client contracts, and database backups totaling around 13 Server database backups of 127 GB. The incident is believed to have occurred in May 2025, with a developer's password exposed, enabling document forgery. The attackers also accessed the TYPortal web portal database containing property owner records and user credentials, as well as an Azure DevOps repository with source code history, including proprietary COBOL programs.
Technical Mitigations AI-generated
• Patch SQL Server database backups to prevent unauthorized access and data exfiltration.
• Detect the 6,105-line proprietary COBOL program (NOTICE14) using reverse engineering techniques or pattern recognition tools.
• Block Azure DevOps repository directory names that contain sensitive information, such as developer passwords.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
HydraqHydraq
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
Incident Timeline
May 2025
A publicly visible directory name on a file listing exposed the password of an HR manager, leading to unauthorized access and theft of sensitive documents.
Click on any entity below to view its context and source!
industry
Legal
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
tactic
Exfiltration
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
tactic
T1584.004 - Server
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
target_region
United Kingdom
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
organisation
Social Security
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
organisation
TWC
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
organisation
PNC
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
infrastructure
13 Server database backups
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
data_breach
127 GB
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
data_breach
102 TYPortal portal database
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
victims
40 employees
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
data_breach
11 GB
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
general_metric
6,105 line
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
2026/10/05
Aurora has published a new victim, Thomas Y. Pickett & Co., Inc., indicating the company was targeted by Aurora on October 5, 2026.
Click on any entity below to view its context and source!
victims
40 employees
Roughly 40 employees, ~$5.3M annual revenue, nearly a century of reputation.
Tactical Metrics
Metrics
infrastructure
13
Server Database Backups
Click for context!
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
Metrics
data_breach
127
Gb
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
Metrics
data_breach
102
Typortal Portal Database
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
Metrics
victims
40
Employees
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
Roughly 40 employees, ~$5.3M annual revenue, nearly a century of reputation.
Metrics
data_breach
11
Gb
…loper's password exposed in a directory name visible to anyone who looks at the file listing
A PKCS#12 digital signing certificate (private key) for an HR manager — enabling document forgery
Legal Disclaimer:
Ransomware.live
does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained…
Intelligence Sources
Ransomware Live
2026-10-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:58
Comprehensive Tactical Telemetry
Highly Correlated Entities
3x
organisation
Identified Entity
Social Security
entity
2x
target region
Target Country
United States
country
2x
tactic
Cyber Operation Type
Exfiltration
tactic
2x
timeline
Temporal Reference
10-year
date
2x
data breach
Gb
127
gb
Contextual Telemetry
Context Block
7 METRICS
industry
Targeted Sector
Legal
sector
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
infrastructure
Server Database Backups
13
server database backups
data breach
Typortal Portal Database
102
typortal portal database
victims
Employees
40
employees
general metric
Line
6,105
line
malware
Malware Payload
Hydraq
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.