SYS::ONLINE
Wasteland.
Briefs2286
Issues25
SinceFeb 2026
LIVE
█ Ransomware SHIPERP-ERPIS-AURO 2026-08-27

ShipERP (ERPIS LLC): Aurora Ransomware Supply Chain Extortion

"The Aurora ransomware group listed ERPIS LLC, the Texas software firm trading as ShipERP, on its extortion portal on 26 August 2026, claiming theft of the company's complete ABAP source code, a live QuickBooks financial…"

The Aurora ransomware group listed ERPIS LLC, the Texas software firm trading as ShipERP, on its extortion portal on 26 August 2026, claiming theft of the company's complete ABAP source code, a live QuickBooks financial database and the contract register covering its entire enterprise customer base. ShipERP builds natively integrated shipping and multi carrier logistics software that sits inside customer SAP environments, which turns a single mid sized vendor compromise into a supply chain problem for the Fortune 500 names the actor claims as customers. One critical caveat frames everything below: every detail currently in circulation traces back to Aurora's own leak post as indexed by ransomware tracking feeds. There is no victim statement, no regulator filing and no national CERT advisory. Breach House records the disclosure status as "Not disclosed yet" as of listing, and no source in this set reports a company response.

What Happened

Aurora published the ERPIS LLC entry on 26 August 2026. HookPhish timestamps the discovery precisely at 2026-08-26T11:22:44 UTC and records the same date as the breach date, though a leak site listing date is a publication event and should not be read as the intrusion date. DeXpose dates its own writeup 27 August and identifies the target domain as shiperp.com. Breach House assigns victim ID 2xWv9nut8DlT, places the company in the United States at 51 to 100 employees, and measures its "Window Zero" exposure gap at zero days open, meaning the listing surfaced and was indexed with no prior public warning.

Accounts differ slightly on how the company is classified. Breach House files it under IT, DeXpose and Brinztech treat it as enterprise software, and HookPhish categorises it as Professional Services. The underlying business description is consistent across all four: a single product SAP integrator selling shipping management software.

The four ShipERP sources also differ in completeness rather than substance. Brinztech describes the exfiltration as covering source code and financial and administrative data, but does not reproduce the customer count, the contract register or the SAP media component. Breach House, DeXpose and HookPhish each carry what appears to be Aurora's verbatim leak post, and those three agree line for line on the inventory. Where Brinztech is thinner, it is not contradicting the others, it is simply summarising less.

What Was Taken

Aurora's claimed haul, as reproduced identically by Breach House, DeXpose and HookPhish:

Complete product source code covering all versions 2.0 through 5.4 of ShipERP's ABAP codebase. Brinztech independently describes the same version range and characterises it as the company's primary revenue generating asset. Breach House and the leak text attach a $20.6M backlog figure to it.

A live QuickBooks financial database of roughly 705 MB. All four sources agree on the size. Contents are described as complete payroll including Social Security numbers, employee bank account and routing details and salaries, plus vendor banking configurations, accounts receivable and payable, and the general ledger.

A full customer contract register with exact pricing for all 88 enterprise customers, tied to $20.6M in deferred revenue. The leak text names Boeing, Pfizer, NVIDIA, John Deere and Medtronic plus "83 other enterprise customers," which is where the 88 figure resolves. Brinztech does not cite a customer count and instead describes the footprint generically as Fortune 500 firms in aerospace, healthcare, technology and manufacturing. Note that the customer names are the attacker's claim, not a vendor confirmed reference list.

SAP installation media totalling 245 GB, described as full HANA, S/4HANA and kernel distributions. This item appears in the three sources carrying the verbatim post and is absent from Brinztech.

Breach House also reports that Aurora posted proof of breach screenshots, listing file_tree.png, finance_2024.xlsx, passport_scan.jpg and contract_signed.pdf. Worth flagging: the identical four filenames appear on Breach House's FREYWILLE record, which suggests these are placeholder or template previews in that index rather than verified ShipERP specific artefacts. Treat them as weak evidence.

Why It Matters

The exposure here is not primarily ERPIS LLC's downtime. It is what a middle layer ERP integration vendor's source code buys an attacker downstream. ABAP modules that run inside customer SAP systems carry the integration logic, authorisation assumptions and any hardcoded interface handling that a reverse engineer would need to hunt for exploitable paths into environments running the product. If the claim is accurate, adversaries now hold six major versions of that code, meaning customers still on older releases are exposed to defect discovery in exactly the branches least likely to be patched. Brinztech's assessment centres on this same tightly integrated middle layer risk.

The contract register compounds it. A pricing and deferred revenue file for 88 named enterprises is a target list with commercial context attached, useful for both social engineering against ShipERP's customers and competitive or extortion leverage against ShipERP itself.

The pattern also matters. Aurora's recent listings in this source set show a consistent operating preference for source code and trade secrets over bulk consumer PII. Darkfield's Pyramid Analytics record from 30 July 2026 describes a claimed haul of the complete Pyramid Decision Intelligence Platform source with 10 plus copies including full Git history, 22 GB of SQL Server production backups, credentials and customer data from Shufersal and ABB. Darkfield's FREYWILLE record from 11 August 2026 describes 142 plus employee files with SSNs and passport copies alongside proprietary enamel colour formulations. vpn.social separately reports an Aurora claim against a Dutch transport firm involving employee data, contracts and multi year internal archives. Across these, the through line is double extortion aimed at crown jewel intellectual property and the victim's own customers. ShipERP fits that profile precisely.

The Attack Technique

No source in this set reports an initial access vector, a dwell time, an encryption event, a ransom demand or a negotiation status for ERPIS LLC. Anyone claiming otherwise is inferring. The only technique level detail that is well supported is Aurora's extortion model itself: vpn.social describes the group as operating double extortion, exfiltrating first and encrypting second, with leak site publication used as pressure before any independent verification of the claim occurs. That framing is generic to the actor, not specific to this intrusion.

vpn.social also makes the general point that unverified leak site claims routinely precede, and sometimes outrun, the facts. HookPhish's own disclaimer notes its reporting is drawn from public threat intelligence feeds rather than direct analysis. For ShipERP customers, the practical posture is to treat the claim as credible enough to act on and unconfirmed enough not to over commit to specifics.

What Organizations Should Do

If you run ShipERP in your SAP landscape, inventory it now. Identify every system where ShipERP ABAP modules are installed, record the exact version, and note whether it falls inside the claimed 2.0 to 5.4 range. Escalate anything on an older release first.

Contact ERPIS LLC directly for a written incident statement and, critically, a signed integrity attestation for any build you have deployed or are about to deploy. Do not accept transitive assurance. Until the vendor speaks, freeze installation of any new ShipERP release or patch, and verify hashes on binaries and transports you already hold.

Audit the authorisations and service accounts ShipERP components use inside SAP. Source code exposure makes any embedded credential, default account or over privileged RFC destination materially riskier. Rotate integration credentials and API keys touching the product, and constrain those accounts to least privilege.

Increase monitoring on the SAP interfaces the product touches, specifically anomalous RFC calls, unexpected transport imports and unusual ABAP program execution. If the source code claim holds, the realistic follow on is targeted exploitation attempts against known integration paths, not broad scanning.

Brief finance and AP teams. The claimed vendor banking and AR/AP exposure is directly usable for payment redirection fraud against ShipERP's customer base. Require out of band verification for any change to ShipERP or related vendor payment details, and treat inbound invoices referencing real contract terms with additional scepticism, since exact pricing data is reportedly in the dataset.

Extend this to your wider vendor programme. As DeXpose recommends, run compromise assessments and validate that backups are current, encrypted, offline and immutable. More durably, the ShipERP case argues for contractual source code and breach notification obligations with any vendor whose code executes inside your ERP.

Sources: Aurora Ransomware Group Targets U.S. Enterprise Shipping Software P... | ERPIS LLC — AURORA Ransomware Attack Breach House | Aurora Targets ERPIS LLC in Ransomware Attack | Ransomware Group aurora Hits: ERPIS LLC | FREYWILLE data breach — Aurora ransomware leak (2026) · Darkfield | Aurora Ransomware Claims Breach at Dutch Transport Firm — vpn.social | FREYWILLE — AURORA Ransomware Attack Breach House | Pyramid Analytics B.V. data breach — Aurora ransomware leak (2026)...