RANSOMWARE VICTIMTRANSPORTATION/LOGISTICS

Diamond Truck Centres

Aurora📍 Canada (CA)📅 June 16, 2026
8
same group

Attack Intelligence

Diamond Truck Centres was compromised in a ransomware attack attributed to Aurora in June 2026. The organization, operating in the Transportation/Logistics sector in Canada, was added to the group's data leak site as part of an extortion campaign.

Aurora operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

[dealership, trucks] *** — Western Canada's largest International Trucks dealership group (9 dealer + 13 sub-dealer locations, ~$63M revenue, 250 employees). The dataset spans 17 years of unbroken operational history (2009–2026) and represents the full shared-drive contents of the entire company: HR, payroll, accounting, military contracts, and individual employee profiles. The exposed material includes: 53 customer Pre-Authorized Debit (PAD) forms — full bank account numbers, transit numbers, institution numbers, and authorized signatures for commercial customers including the City of Saskatoon. 17 years of employee payroll data — wages, SINs (implied), pension contributions, benefits, termination calculations for every employee since 2009. Biometric data — ADP fingerprint timeclock enrollment records for all locations. Immigration documents for 6+ foreign workers — LMIA applications, offers of employment, provincial nominee support docs. System credentials in plaintext — ADP timeclock passwords, manager training logins, safe combination. Military contract documentation — Diamond's Controlled Goods Security Plan (ITAR/CGP), MSVS delivery matrices, military vehicle VINs, CFB Edmonton and RCMP vehicle program data. 289 GB of daily bank deposit scans (2017–2026) — customer cheque images with names, amounts, and account details. A complete Outlook PST archive (166 MB) — years of internal email likely containing credentials and customer data.

Additional Details

Other Victims — Aurora (8)

Quick Facts

CountryCanada (CA)
SectorTransportation/Logistics
Attack DateJun 16, 2026
Intel Sourceransomware.live

Threat Group

Aurora
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.