Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Campaigns aurora: Hagerman & Company

aurora: Hagerman & Company

TLP:CLEAR
Inactive

AI Analysis

No AI analysis yet.

Description

Ransomware attack attributed to aurora. | Sector: Business Services | Website: Hagerman & Company | *** — a 40-year-old Autodesk Platinum Partner headquartered in Mt. Zion, Illinois, serving 250+ enterprise customers across manufacturing, energy, defense, healthcare, and education. The exposed dataset includes: Complete proprietary source code for 15+ commercial products including the HNC Licensing System (License Generator, License Server, License Manager) — enabling unlimited piracy of all Hagerman products. 8+ plaintext database credentials in .udl files, including an Oracle SYS (DBA superuser) account with password "Hagerman@1!" reused across multiple systems. Engineering vault databases for 14+ critical infrastructure entities — NYPA (7 power plants including Niagara Falls), Kinder Morgan (Elba Island LNG terminal), HydroOne (Ontario electricity), Phillips 66, Chevron, and 8+ petroleum refineries. Defense/government data — NASA IT Security Requirements, Lockheed Martin configurat...

Details

Confidence
80%
First Seen
Jun 19, 2026
Last Seen
Jun 19, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.