Atlas Metal Industries Inc
About the organisation
[food, metal] Atlas Metal Industries Inc. β a privately held commercial-foodservice-equipment manufacturer headquartered in Miami, Florida. The dataset is a complete Microsoft Dynamics GP environment: production databases, payroll records, system credentials, Autodesk Vault product-design backups, CNC fabrication programs, and all supporting infrastructure configuration. The exfiltration occurred on or about April 8, 2026; the attack was identified April 22, 2026. The exposed material includes: 15.8 GB of payroll-records database (PYREC) β full Employee Master with SSNs, DOBs, addresses, direct-deposit bank routing numbers, salary, W-4 tax data, garnishments, and check history dating to at least 2018. 30+ SQL Server login accounts with password hashes in a sp_help_revlogin dump β named employees, system admins (DYNSA, sa), service accounts, and Active Directory domain accounts. 74 GB of Autodesk Vault Professional backup β complete product-design history from 2019 through 2026, covering every product line Atlas Metal manufactures. Hundreds of CNC fabrication programs β laser-cutter and Amada punch-press G-code for the full catalogue of sheet-metal components. A base64-encoded SQL credential for the TimeClock Plus timekeeping system, stored in plaintext XML. 8 SQL Server databases with full backup chains β ATLAS (primary), PYREC (payroll), DYNAMICS (system), TEST (18 GB dev clone), TWO, AMIT, plus system databases (master, msdb, DynamicsGPSecurity).
What the listing means
Atlas Metal Industries Inc appeared on the aurora leak site on 29 April 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 1 claim in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Atlas Metal Industries Inc as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account on atlasfoodserv.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Manufacturing organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/QXRsYXMgTWV0YWwgSW5kdXN0cmllcyBJbmNAYXVyb3Jh
Show leak-site screenshot
Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.