Jinny Beauty Supply
bd_6d3f19cff734f8bc · schema v1 · pii pii-v2
Full breach record for Jinny Beauty Supply →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Aurora on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
[distributors] Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states. Complete employee compensation database — ~260 employees with Korean and English names, departments, salaries, bonuses, and 1099 contractor data spanning 2015–2018. A 340 MB Shopify database backup — full customer table (names, emails, phones, addresses), product catalog, pricing, and warehouse assignments. Active Directory domain enumeration — all 239+ user accounts including 17 admin accounts, the complete server topology across 7 geographic sites (50+ servers), and DPAPI-encrypted RDP passwords. Employee tax documents — W-4 forms (SSN), I-9 forms (SSN + DOB + citizenship), direct deposit forms (bank account and routing numbers). 3.6 GB of SQL Server database backups — e-commerce customer/order/product data spanning November 2019 to March 2020.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 7, 2026
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
aurora
According to ransomware.live, Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.