auroraRansomware Victim๐Ÿ‡บ๐Ÿ‡ธ US OrganizationRetail & E-Commerce

Natco Home Group

[manufacturer] Natco Home Group โ€” a fourth-generation, family-owned home furnishings manufacturer headquartered in West Warwick, Rhode Island, with ~800 employees, ~$100M annual revenue, and facilities across seven US states. The exfiltrated dataset spans the company's entire corporate history and includes: Social Security numbers in plaintext for 100โ€“120 legacy employees dating back to 1979 in an unencrypted PayUSA payroll database, plus 10 years of ADP payroll data (2017โ€“2026) covering 700โ€“1,000 current and former employees โ€” pay stubs, W-2s, W-4s, 401k records, drug test results, background checks, and medical leave records. <censored> <censored> <censored> <censored> Years of divisional financial statements, income tax records, customer credit data for major retailers, 18 years of bad-debt reserve calculations, and acquisition-related materials.

Incident Details

Threat Group
aurora
Victim / Organization
Natco Home Group
Website / Domain
natcohome.com
Industry Sector
Retail & E-Commerce
Country / Region
๐Ÿ‡บ๐Ÿ‡ธ US
Date Discovered
Monday, August 17, 2026

What This Listing Means

Posting on aurora's ransomware leak site typically signals that the threat actor claims to have:

  • โ–ธGained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
  • โ–ธExfiltrated sensitive data โ€” potentially including financial records, PII, customer data, or trade secrets
  • โ–ธDeployed ransomware to encrypt systems and disrupt operations
  • โ–ธIssued a ransom demand with a deadline to publish all stolen data publicly if unpaid

๐Ÿ‡บ๐Ÿ‡ธ US-based organizations hit by ransomware may have mandatory breach notification obligations under state laws, HIPAA (healthcare), SEC regulations (public companies), or CISA guidelines. The notification window is typically 72 hours from discovery.

Is This Your Organization?

Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.

Get Emergency ResponseIR Services Overview

Protect Your Organization

โ† Back to Ransomware Tracker