Diamond Truck Centres
bd_a23734c68881ca28 · schema v1 · pii pii-v1
Full breach record for Diamond Truck Centres →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Aurora on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
[dealership, trucks] *** — Western Canada's largest International Trucks dealership group (9 dealer + 13 sub-dealer locations, ~$63M revenue, 250 employees). The dataset spans 17 years of unbroken operational history (2009–2026) and represents the full shared-drive contents of the entire company: HR, payroll, accounting, military contracts, and individual employee profiles. The exposed material includes: 53 customer Pre-Authorized Debit (PAD) forms — full bank account numbers, transit numbers, institution numbers, and authorized signatures for commercial customers including the City of Saskatoon. 17 years of employee payroll data — wages, SINs (implied), pension contributions, benefits, termination calculations for every employee since 2009. Biometric data — ADP fingerprint timeclock enrollment records for all locations. Immigration documents for 6+ foreign workers — LMIA applications, offers of employment, provincial nominee support docs. System credentials in plaintext — ADP timeclock passwords, manager training logins, safe combination. Military contract documentation — Diamond's Controlled Goods Security Plan (ITAR/CGP), MSVS delivery matrices, military vehicle VINs, CFB Edmonton and RCMP vehicle program data. 289 GB of daily bank deposit scans (2017–2026) — customer cheque images with names, amounts, and account details. A complete Outlook PST archive (166 MB) — years of internal email likely containing credentials and customer data.
Source provenance
- Source URL
- https://www.ransomware.live/id/RGlhbW9uZCBUcnVjayBDZW50cmVzQGF1cm9yYQ==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 16, 2026
- Raw hash
- 1c0205ee00b25dfb478fab486a7f3aad7d8d20c9b2eece476978dc0872eaa593
Reporting entity
- Name
- aurora
Victim entity
- Name
- Diamond Truck Centresnorm: diamond truck centres
- Industry
- Transportation & Logisticsllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· aurora
- Threat actor
- AuroraExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.