Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Chip 1 Exchange

chip1.com

Group Aurora
Discovered 2026-09-02 06:52 UTC
Est. attack date 2026-09-02
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

[distributor] Chip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California. The dataset spans 13 years (2013-2026) of corporate operations and encompasses: 40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, payroll registers. <redacted> Complete 2026 financial intelligence — P&L through July, executive financial health assessment, AR/AP aging, chart of accounts revealing all bank account numbers. 15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins. ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec. 5.7 GB of Outlook PST email archives spanning years of C-suite and employee correspondence.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 7


External Attack Surface: 1


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusedomainbox.com
MX Records
  • chip1-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • MS=2C9AA74C86B9294AC48C1D6EE1458DF1371C984A
  • v=spf1 a:mailo.chip1.com a:mailex.chip1.com include:servers.mcsv.net include:spf.protection.outlook.com ~all
  • 549cmcn7umrna1nujkedrpbjev
Cloud / SaaS Services Detected
Mailchimp

Leak Screenshot:

Leak Screenshot