Watermark

Informazioni Incidente

ID: 31754 29-04-2026 21:35:32
Organizzazione

Atlas Metal Industries Inc

Gruppo Criminale

aurora

Hash RF
f38ee012b560f6a27ddcdf3075aaec18f8e8c61645ae53d683af54bbf5cb455f
Data Rilevamento 29-04-2026 21:35:32
Località Obiettivo USA
Dominio Obiettivo
atlasfoodserv.com CTI
Settore Economico Manufacturing
Dati Pubblicati N/D
Descrizione
[food, metal] Atlas Metal Industries Inc. — a privately held commercial-foodservice-equipment manufacturer headquartered in Miami, Florida.

The dataset is a complete Microsoft Dynamics GP environment: production databases, payroll records, system credentials, Autodesk Vault product-design backups, CNC fabrication programs, and all supporting infrastructure configuration. The exfiltration occurred on or about April 8, 2026; the attack was identified April 22, 2026.

The exposed material includes:

15.8 GB of payroll-records database (PYREC) — full Employee Master with SSNs, DOBs, addresses, direct-deposit bank routing numbers, salary, W-4 tax data, garnishments, and check history dating to at least 2018.
30+ SQL Server login accounts with password hashes in a sp_help_revlogin dump — named employees, system admins (DYNSA, sa), service accounts, and Active Directory domain accounts.
74 GB of Autodesk Vault Professional backup — complete product-design history from 2019 through 2026, covering every product line Atlas Metal manufactures.
Hundreds of CNC fabrication programs — laser-cutter and Amada punch-press G-code for the full catalogue of sheet-metal components.
A base64-encoded SQL credential for the TimeClock Plus timekeeping system, stored in plaintext XML.
8 SQL Server databases with full backup chains — ATLAS (primary), PYREC (payroll), DYNAMICS (system), TEST (18 GB dev clone), TWO, AMIT, plus system databases (master, msdb, DynamicsGPSecurity).

Stai cercando un corso su Dark Web e Cyber Threat intelligence (CTI)?

Se vuoi comprendere a fondo le dinamiche del Dark Web e le minacce di sicurezza informatica, non perdere il corso "DarkWeb & Cyber Threat Intelligence" della Red Hot Cyber Academy. Puoi accedere al corso in modalità e-learning oppure attraverso live-class interattive con professore online. Inoltre, il corso non finisce con la certificazione, ma all'interno del laboratorio di intelligence DarkLab. Scrivi alla Red Hot Cyber Academy per maggiori dettagli.

Red Hot Cyber Academy

Formazione specializzata in Cyber Threat Intelligence