Corporación Primax S.A.
[distribution, fuel] ***.A. is Peru's largest fuel distribution company, operating 2,185+ stations across Peru, Ecuador, Colombia, and Uruguay with annualised revenue of approximately USD 3.4 billion (Peru alone). The dataset spans every function of the business: Complete financial reporting — Monthly P&L, balance sheet, cash flow, and EBITDA through May 2025. GRIO (Grupo Romero Investment Office) management reporting packages. Budget 2025 vs. actuals. Employee identity data for 15,000–60,000 individuals — DNI national ID numbers, bank accounts, salary amounts, pension fund details, scanned identity documents. Live system credentials — Plaintext SQL database passwords, banking SFTP credentials (Banco Bolivariano Ecuador), AD encryption master key, OSINERGMIN fuel-control system credentials. Complete OT network map — IP addresses and identifiers for 137 fuel stations on the internal 10.55.40.x network, plus JD Edwards ERP production servers. 54 GB of POS transaction data — XML records of consumer fuel purchases across the entire station network. Legal and M&A documentation — Arbitration case files (PUCP/AMCHAM), UNO Corp acquisition materials (Dec 2025), bank covenant waivers.
Incident Details
- Threat Group
- aurora
- Victim / Organization
- Corporación Primax S.A.
- Website / Domain
- Corporación Primax S.A.
- Industry Sector
- Not Found
- Country / Region
- 🇵🇪 PE
- Date Discovered
- Tuesday, June 23, 2026
What This Listing Means
Posting on aurora's ransomware leak site typically signals that the threat actor claims to have:
- ▸Gained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
- ▸Exfiltrated sensitive data — potentially including financial records, PII, customer data, or trade secrets
- ▸Deployed ransomware to encrypt systems and disrupt operations
- ▸Issued a ransom demand with a deadline to publish all stolen data publicly if unpaid
Open Source Investigation
Is This Your Organization?
Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.
Get Emergency ResponseIR Services OverviewProtect Your Organization
- AlertMonitor
Dark web & ransomware monitoring for your domains
- Managed SOC & MDR
24/7 threat detection and response
- Penetration Testing
Find ransomware entry points before attackers do
Other aurora Victims
- ▸Aerospace & Advanced Composites GmbHDE
- ▸NTP B.V. Civil Engineering ConstructionNL
- ▸Kochs GmbHDE
- ▸NationsBuilders Insurance Services