Skip to content
Ransomware News

Ransomware Group aurora Hits: Corporación Primax S.A.

Admin
HookPhish team
Target organization Corporación Primax S.A. Corporación Primax S.A. Not Found

Summary

In the latest cybersecurity news, Corporación Primax S.A. — an organization based in PE — has fallen victim to a ransomware attack conducted by the group aurora. This data breach, discovered on 2026-06-23T06:21:35.978085+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization Corporación Primax S.A.
Threat Group aurora
Summary [distribution, fuel] ***.A. is Peru’s largest fuel distribution company, operating 2,185+ stations across Peru, Ecuador, Colombia, and Uruguay with annualised revenue of approximately USD 3.4 billion (Peru alone).

The dataset spans every function of the business:

Complete financial reporting — Monthly P&L, balance sheet, cash flow, and EBITDA through May 2025. GRIO (Grupo Romero Investment Office) management reporting packages. Budget 2025 vs. actuals.
Employee identity data for 15,000–60,000 individuals — DNI national ID numbers, bank accounts, salary amounts, pension fund details, scanned identity documents.
Live system credentials — Plaintext SQL database passwords, banking SFTP credentials (Banco Bolivariano Ecuador), AD encryption master key, OSINERGMIN fuel-control system credentials.
Complete OT network map — IP addresses and identifiers for 137 fuel stations on the internal 10.55.40.x network, plus JD Edwards ERP production servers.
54 GB of POS transaction data — XML records of consumer fuel purchases across the entire station network.
Legal and M&A documentation — Arbitration case files (PUCP/AMCHAM), UNO Corp acquisition materials (Dec 2025), bank covenant waivers.

Date of Breach 2026-06-23T00:00:00+00:00
Discovery Date 2026-06-23T06:21:35.978085+00:00
Region PE
Target Domain Corporación Primax S.A.
Business Sector Not Found

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions