Aurora Claims Data Theft From Jinny Beauty Supply
Aurora claims it stole sensitive data from Jinny Beauty Supply. The allegation comes from an attacker leak-site listing and remains unverified.
- Report priority
- High
- Involves
- Jinny Beauty Supply
- Group
- Aurora
What is known
- An Aurora leak-site post claims the group obtained internal data from Jinny Beauty Supply.
- The post names password-vault exports, infrastructure credentials, card authorization forms, employee documents, and databases.
- It doesn't disclose how access began or confirm that ransomware encrypted any systems.
- Ransomware.live says it only indexes operators' public claims and doesn't obtain the underlying files.
What to do
Jinny administrators should check internal incident records for evidence involving the systems and data named in the listing. Other readers can't confirm exposure from the post alone. Employees, customers, contractors, and partner stores should ask Jinny's privacy or security contact whether their records were involved and what action they should take. Review relevant card statements for unfamiliar transactions, but finding none doesn't rule out data exposure.
Jinny's security team should investigate the allegation and communicate any confirmed scope through an official notice. Individuals should follow that notice if one appears. Report unfamiliar card charges to the issuer using the verified number on the card or statement.
Reported details
RANSOM-aurora-jinny-beauty-s is a tracking identifier for an extortion claim, not a CVE. Ransomware.live recorded the Aurora listing on September 7, 2026. The operator claims it obtained more than 50 plaintext credentials, VMware root credentials, 911 card authorization forms, records for about 260 workers, information on more than 239 directory accounts, a 340 MB Shopify backup, and 3.6 GB of SQL Server backups.
Some claimed employee records cover 2015 to 2018, while claimed e-commerce data covers November 2019 to March 2020. The allegation remains unverified, and the listing doesn't explain how access began or establish that systems were encrypted.