Sumitomo Electric Bordnetze SE
bd_e3eabb25a2af020e · schema v1 · pii pii-v1
Full breach record for Sumitomo Electric Bordnetze SE →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Aurora on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
[electric] *** SE (SEBN) — a Wolfsburg-headquartered subsidiary of Sumitomo Electric Industries (TSE:5802, ~$31B group revenue), employing approximately 40,000 people across 14 countries. Exfiltrated 1.1 terabytes of data from five manufacturing sites. SEBN Moldova (103 GB) — HR, payroll, personal tax records, competition-council litigation files, home directories SEBN Ukraine (115 GB) — HR/salary, Audi B9 project data, process documentation, including displaced-worker records for Ukrainian IDPs SEBN Tunisia — Fejja (191 GB + 493 GB shared) — passport copies, email archives (671 MB PST), quality/FMEA data, finance SEBN Slovakia (268 GB) — the crown jewel: Citibank corporate banking infrastructure including the TESTKEY authentication system, IBAN registries, daily bank statements, SAP salary-payment files, and years of department email archives The dataset contains 173,000 Excel files, 149,000 PDFs, 2,500 CAD engineering drawings, 2,500 Outlook messages, 1,500 FMEA/PPAP quality files, and 9 Outlook PST archives.
Source provenance
- Source URL
- https://www.ransomware.live/id/U3VtaXRvbW8gRWxlY3RyaWMgQm9yZG5ldHplQGF1cm9yYQ==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 16, 2026
- Raw hash
- 254cd115dcfb668d356921354eea7464c93c686ffe4e04d09eb89c6709dacf6b
Reporting entity
- Name
- aurora
Victim entity
- Name
- Sumitomo Electric Bordnetze SEnorm: sumitomo electric bordnetze
- Industry
- Manufacturingllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· aurora
- Threat actor
- AuroraExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.