Back to Victim Disclosures

Evosys Laser GmbH

auroraransomware group
Published
Jul 30, 2026

Added Jul 30, 2026

Evosys Laser GmbH — an Erlangen-based industrial laser welding systems manufacturer with ~130 employees, subsidiaries in the US, China, and a string of Tier 1 automotive customers. The dataset is the complete corporate repository, spanning every business function: 130 employees' complete HR files — employment contracts, salary histories, bank IBANs, tax IDs, social insurance numbers, pension records, medical examinations, disciplinary warnings, and two confirmed minors' health records. A photographed KeePass vault — someone scanned the password manager's contents as a PDF, making every password readable without the master key. 42 customer portal credentials in plaintext — Volkswagen, Bosch, Siemens, Roche, TE Connectivity, Samsung SDI, Dräxlmaier, and 35 others, stored in text files with names like Passwort Brose.txt. A reused base password Evo2016Sys appears across multiple portals. The SSL wildcard private key for *.evosys-laser.com — valid 2025–2026, enabling man-in-the-middle attacks on every subdomain. Complete server infrastructure map via mRemoteNG XML — 7 servers named, domain admin credentials, internal IPs. The Citrix admin password is Password1. 326 GB of customer project data — laser welding process parameters, CAD files, robot control software, and the award-winning AQW process know-how. Complete financial history — Jahresabschlüsse (2015–2025), P&L forecasts through 2028, cash positions, investor documents, executive compensation. Attorney-client privileged communications (230 MB) and whistleblower reports under HinSchG. Industrial control data — robot SRS source code, PLC programs, nginx private keys for laser system web interfaces, VPN configurations for customer site remote access.

Leak Page Screenshot

Organization Details

Organization

Evosys Laser GmbH

Country

🇩🇪 DE

Industry Sector

Manufacturing

Leak Data

Data Size

326 GB

Published

Jul 30, 2026

Publication Status

Published

Discovered

Jul 30, 2026

Leak URL
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/evosys-laser-gmbh-4511a1ae
Site OnlineLast scanned 12m ago

Threat Group

aurora

ransomware group

View full group profile →

Quick Facts

Country🇩🇪 DE
SectorManufacturing
Data Size326 GB
AddedJul 30, 2026