Back to Victim Disclosures

ERPIS LLC

auroraransomware group
Published
Aug 26, 2026

Added Aug 26, 2026

ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers. The exposed material includes: Complete product source code — all versions (2.0–5.4) of ShipERP's ABAP source, the company's sole revenue-generating asset ($20.6M backlog) 128+ SAP cryptographic private keys (PSE files) — enabling JWT forgery, TLS impersonation, and SSO bypass across the entire SAP landscape Live QuickBooks financial database (705 MB) — complete payroll (SSN, bank accounts, salaries), vendor banking details, AR/AP, and general ledger Full customer contract register — exact pricing for all 88 enterprise customers with $20.6M in deferred revenue Production API credentials — 7 Intuit keys, UPS JWT tokens, TSheets OAuth, Melio payment API, SFTP credentials SAP installation media (245 GB) — full HANA, S/4HANA, and kernel distributions Customer SAP integration configurations (13 GB) — Boeing, IDT, EGLO, KTM, and dozens more

Leak Page Screenshot

Organization Details

Organization

ERPIS LLC

Industry Sector

Professional Services

Leak Data

Data Size

705 MB

Published

Aug 26, 2026

Publication Status

Published

Discovered

Aug 26, 2026

Leak URL
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/erpis-llc-bb485230
Site OnlineLast scanned 9m ago

Threat Group

aurora

ransomware group

View full group profile →

Quick Facts

SectorProfessional Services
Data Size705 MB
AddedAug 26, 2026