2026 Chip 1 Exchange — Aurora leak-site claim (unverified); alleged HR/finance/ITAR data
Data compromised
Actor listing claims passport photos, I-9 forms with SSNs, W-4s, payroll, financial statements, franchise agreements, ITAR/defense customer orders, and Outlook PST archives — unverified; no company-attested inventory
Technical writeup
Unverified ransomware / extortion leak-site claim — Aurora published a listing naming Chip 1 Exchange (chip1.com), a global independent electronics distributor with Germany HQ and U.S. operations in Laguna Hills, California, observed around September 2, 2026 and tracked by HackerFeeds and related ransomware monitors. The actor narrative alleges multi-year corporate and personnel data including passport photographs, I-9/SSN forms, W-4s, payroll, 2026 financials, manufacturer franchise agreements, ITAR registration and defense customer sales orders, and large Outlook PST archives. At indexing time no statement from Chip 1 Exchange, no regulator filing, and no reputable trade-press confirmation citing company acknowledgment had been published, and no independently validated victim count was available, so recordsAffected is 0 and the row is labelled unverified. Leak-site listings are marketing for extortion: appearance of a name proves the group claims access, not that data was stolen or that claimed volumes/data types are accurate. This row will be updated if the company confirms an incident or a regulator publishes a notice.
Root cause
Unverified Aurora ransomware/extortion leak-site listing naming Chip 1 Exchange — the organisation had not confirmed any incident at indexing time