Sumitomo Electric Bordnetze
About the organisation
[electric] *** SE (SEBN) β a Wolfsburg-headquartered subsidiary of Sumitomo Electric Industries (TSE:5802, ~$31B group revenue), employing approximately 40,000 people across 14 countries. Exfiltrated 1.1 terabytes of data from five manufacturing sites. SEBN Moldova (103 GB) β HR, payroll, personal tax records, competition-council litigation files, home directories SEBN Ukraine (115 GB) β HR/salary, Audi B9 project data, process documentation, including displaced-worker records for Ukrainian IDPs SEBN Tunisia β Fejja (191 GB + 493 GB shared) β passport copies, email archives (671 MB PST), quality/FMEA data, finance SEBN Slovakia (268 GB) β the crown jewel: Citibank corporate banking infrastructure including the TESTKEY authentication system, IBAN registries, daily bank statements, SAP salary-payment files, and years of department email archives The dataset contains 173,000 Excel files, 149,000 PDFs, 2,500 CAD engineering drawings, 2,500 Outlook messages, 1,500 FMEA/PPAP quality files, and 9 Outlook PST archives.
What the listing means
Sumitomo Electric Bordnetze appeared on the aurora leak site on 16 June 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 1 claim in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Sumitomo Electric Bordnetze as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account on Sumitomo Electric Bordnetze, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Manufacturing organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/U3VtaXRvbW8gRWxlY3RyaWMgQm9yZG5ldHplQGF1cm9yYQ==
Show leak-site screenshot
Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.