RANSOMWARE VICTIMTRANSPORTATION

Van Eijck International Car Rescue

Aurora📍 Netherlands (NL)📅 July 30, 2026
8
same group

Attack Intelligence

Van Eijck International Car Rescue was compromised in a ransomware attack attributed to Aurora in July 2026. The organization, operating in the Transportation sector in Netherlands, was added to the group's data leak site as part of an extortion campaign.

Aurora operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Van Eijck International Car Rescue B.V. — a family-owned Dutch towing and recovery company with 225+ vehicles, 180+ employees, and 20 branch offices across the Netherlands and Spain. The exposed material includes: <censored> 227 employee home directories (156 GB) containing personal documents, tax forms (loonheffingen), salary records, photos, and financial data. 12 GB of RentRunner customer rental contracts with copies of identity documents, driving licenses, and vehicle registrations. 10 years of customer claims data (2010–2019) — 500+ individual claims with damage assessments, insurance details, and customer PII. Complete Google Workspace backup (CubeBackup) — Gmail, Drive, and Calendar for 18 user accounts and 206 groups. <censored>

Additional Details

Other Victims — Aurora (8)

Quick Facts

CountryNetherlands (NL)
SectorTransportation
Attack DateJul 30, 2026
Intel Sourceransomlook

Threat Group

Aurora
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.