ALS Global
bd_38cdcfc1ea5d352a · schema v1 · pii pii-v1
Full breach record for ALS Global →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Aurora on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
[certification, inspection] ALS Limited (ASX:ALQ) — a global testing, inspection, and certification company with AUD 3.19B revenue, 20,500+ employees, and operations in 65+ countries — identified unauthorised access to its IT systems. ~400–500 employee home directories — personal documents, cached credentials, email settings, family photos, personal finance files for employees from Australia to Peru to Sweden to Romania. The company's 1Password team vault emergency recovery kit — a single 45 KB PDF that enables total recovery of every shared credential in ALS's enterprise password vault. 291 plaintext password files including administrator credentials, FTP passwords, portal passwords, and the document control system master password. 1,018 passport and identity document scans — Swedish passports, Mexican passports, Australian passports — each one a 10-year identity-theft enabler. 601 bank account detail files including IBAN, SWIFT routing codes, BSB numbers, and sort codes for employees across 15+ countries, plus Russian-language SWIFT salary payment files. 1,986 salary, payroll, and compensation files — named individuals, exact amounts, pay scales, negotiation records across AU, US, EU, UK, CA, BR, SE, RO. 453 medical, drug test, and workplace injury records — GDPR Art. 9 special category data. 57 complete Outlook email archives (PST files) — years of correspondence, attachments, privileged communications. 7,327 client laboratory results — mining assay data, certificates of analysis, and geochemistry results held under NDA. 20 GB of proprietary analytical method development — ALS's core competitive IP: PFAS, dioxin, acrylamide, glyphosate LC-MS/GC-MS method packages representing years and millions of AUD in R&D. For a TIC company, analytical methods are the product. 7.2 GB of Internal Research reports — 68+ formal research reports (IR153–IR287+) spanning 15 years, in
Source provenance
- Source URL
- https://www.ransomware.live/id/QUxTIEdsb2JhbEBhdXJvcmE=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 5, 2026
- Raw hash
- 86b0f4badbf04f43d040b1bc42d16474f1e4cdbf726eca19c0639a7722e059b2
Reporting entity
- Name
- aurora
Victim entity
- Name
- ALS Globalnorm: als global
- Industry
- Professional Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· aurora
- Threat actor
- AuroraExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.