ShellCodeX
Tools β€’ Events β€’ News β€’ Insights
Victim Claim

Costa Solutions, LLC

aurora πŸ‡ΊπŸ‡Έ United States Business Services costasolutions.com
Claimed by aurora
Listed on leak site 29 Apr 2026
Reported attack date 29 Apr 2026
Group claims tracked 21
Unverified claim. This entry reproduces a listing published by the aurora group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Costa Solutions, LLC suffered a breach, or what data was actually taken.

About the organisation

[warehouse] Costa Solutions, LLC β€” a privately held managed-labor and warehousing company headquartered in San Antonio, Texas, with ~$140M annual revenue and 200–1,000 employees. The file server contained the complete operational, financial, legal, and human resources infrastructure of the company: 3,000–8,000+ individuals' personal data β€” current employees, former employees (12 years of records), independent contractors, employee dependents, and job applicants. SSNs on W-2s, W-4s, 1099s, I-9s, background checks. Bank account and routing numbers on 200+ direct deposit forms. Medical and injury records β€” 150+ employee injury/medical files from 2013–2026, FMLA medical certifications, drug test results (random, reasonable suspicion, post-incident, promotional), and workers' compensation claims for 23+ named individuals. CEO's entire file system β€” Josh Wean's Documents folder (5.3 GB) including P&L statements, a 17-subfolder "Confidential" directory, legal correspondence, strategic plans, a C-12 peer advisory group archive, and a $RECYCLE.BIN with 60+ deleted items. Client contracts and competitive intelligence β€” pricing, SLAs, and contract terms for HEB, CVS, Sysco, Amazon, McLane, Labatt, Valvoline. Competitor pricing intelligence. RFP bid documents with cost models. Active legal case files β€” litigation records (2021–2022), HR internal investigation notes (2018–2021), arbitration files, active investigations marked "DO NOT DELETE" β€” all subject to attorney-client privilege. Infrastructure secrets β€” an HEB production server TLS certificate, a Cisco AnyConnect VPN installer, and the CEO's Remote Desktop connection file. Corporate financials β€” multi-year budgets, valuation & sale documents (indicating possible M&A activity), PPP loan forgiveness records, Form 5500 ERISA filings, and annual reporting.

What the listing means

Costa Solutions, LLC appeared on the aurora leak site on 29 April 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 1 claim in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Costa Solutions, LLC as suspicious β€” leaked data gets weaponised for phishing within days.
  • If you hold an account on costasolutions.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Business Services organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach β€” check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/Q29zdGEgU29sdXRpb25zLCBMTENAYXVyb3Jh

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the aurora leak-site listing for Costa Solutions, LLC