ShellCodeX
Tools β€’ Events β€’ News β€’ Insights
Victim Claim

Sumitomo Electric Bordnetze

aurora πŸ‡©πŸ‡ͺ Germany Manufacturing Sumitomo Electric Bordnetze
Claimed by aurora
Listed on leak site 16 Jun 2026
Reported attack date 16 Jun 2026
Group claims tracked 21
Unverified claim. This entry reproduces a listing published by the aurora group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Sumitomo Electric Bordnetze suffered a breach, or what data was actually taken.

About the organisation

[electric] *** SE (SEBN) β€” a Wolfsburg-headquartered subsidiary of Sumitomo Electric Industries (TSE:5802, ~$31B group revenue), employing approximately 40,000 people across 14 countries. Exfiltrated 1.1 terabytes of data from five manufacturing sites. SEBN Moldova (103 GB) β€” HR, payroll, personal tax records, competition-council litigation files, home directories SEBN Ukraine (115 GB) β€” HR/salary, Audi B9 project data, process documentation, including displaced-worker records for Ukrainian IDPs SEBN Tunisia β€” Fejja (191 GB + 493 GB shared) β€” passport copies, email archives (671 MB PST), quality/FMEA data, finance SEBN Slovakia (268 GB) β€” the crown jewel: Citibank corporate banking infrastructure including the TESTKEY authentication system, IBAN registries, daily bank statements, SAP salary-payment files, and years of department email archives The dataset contains 173,000 Excel files, 149,000 PDFs, 2,500 CAD engineering drawings, 2,500 Outlook messages, 1,500 FMEA/PPAP quality files, and 9 Outlook PST archives.

What the listing means

Sumitomo Electric Bordnetze appeared on the aurora leak site on 16 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 1 claim in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Sumitomo Electric Bordnetze as suspicious β€” leaked data gets weaponised for phishing within days.
  • If you hold an account on Sumitomo Electric Bordnetze, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Manufacturing organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach β€” check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/U3VtaXRvbW8gRWxlY3RyaWMgQm9yZG5ldHplQGF1cm9yYQ==

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the aurora leak-site listing for Sumitomo Electric Bordnetze