ShellCodeX
Tools β€’ Events β€’ News β€’ Insights
Victim Claim

ALS Global

aurora πŸ‡¦πŸ‡Ί Australia Business Services ALS Global
Claimed by aurora
Listed on leak site 19 Jun 2026
Reported attack date 05 Jun 2026
Group claims tracked 21
Unverified claim. This entry reproduces a listing published by the aurora group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that ALS Global suffered a breach, or what data was actually taken.

About the organisation

[certification, inspection] ALS Limited (ASX:ALQ) β€” a global testing, inspection, and certification company with AUD 3.19B revenue, 20,500+ employees, and operations in 65+ countries β€” identified unauthorised access to its IT systems. ~400–500 employee home directories β€” personal documents, cached credentials, email settings, family photos, personal finance files for employees from Australia to Peru to Sweden to Romania. The company's 1Password team vault emergency recovery kit β€” a single 45 KB PDF that enables total recovery of every shared credential in ALS's enterprise password vault. 291 plaintext password files including administrator credentials, FTP passwords, portal passwords, and the document control system master password. 1,018 passport and identity document scans β€” Swedish passports, Mexican passports, Australian passports β€” each one a 10-year identity-theft enabler. 601 bank account detail files including IBAN, SWIFT routing codes, BSB numbers, and sort codes for employees across 15+ countries, plus Russian-language SWIFT salary payment files. 1,986 salary, payroll, and compensation files β€” named individuals, exact amounts, pay scales, negotiation records across AU, US, EU, UK, CA, BR, SE, RO. 453 medical, drug test, and workplace injury records β€” GDPR Art. 9 special category data. 57 complete Outlook email archives (PST files) β€” years of correspondence, attachments, privileged communications. 7,327 client laboratory results β€” mining assay data, certificates of analysis, and geochemistry results held under NDA. 20 GB of proprietary analytical method development β€” ALS's core competitive IP: PFAS, dioxin, acrylamide, glyphosate LC-MS/GC-MS method packages representing years and millions of AUD in R&D. For a TIC company, analytical methods are the product. 7.2 GB of Internal Research reports β€” 68+ formal research reports (IR153–IR287+) spanning 15 years, including IsaMill grinding R&D, GlyLeach joint-venture process IP (with mutual NDA), flotation, mineralogy, and QEMSCAN data. The FY2025–2026 innovation roadmap β€” "ALS Environmental Innovation β€” Priority projects for 2024-25" (10 MB PPTX) and Nordic Innovation Business Plans revealing which methods ALS plans to develop and which markets it plans to enter. 3.7 GB of Cryptosporidium water-testing methods (WA_Crypto) β€” UKAS-accredited, DWI-regulated detection methods where few UK labs hold accreditation. QuickBooks live bookkeeping, AR aging reports, and stock sale records β€” taken 12 days before FY26 results announcement. 111 PKI certificates with private keys β€” corporate WiFi, TLS server certs, personal signing certificates. A compiled Chrome password extraction tool with source code β€” credential harvesting infrastructure resident on ALS systems.

What the listing means

ALS Global appeared on the aurora leak site on 19 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated β€” the attack itself is dated 05 June 2026, 14 days before the listing. This group has published 1 claim in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing ALS Global as suspicious β€” leaked data gets weaponised for phishing within days.
  • If you hold an account on ALS Global, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Business Services organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach β€” check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/QUxTIEdsb2JhbEBhdXJvcmE=

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the aurora leak-site listing for ALS Global