Aurora’s name surfaced beside ALS Global, but the public record so far shows an extortion claim and a hash-like marker, not a confirmed intrusion.
A claimed Aurora victim entry around ALS Global points to a familiar ransomware pattern, but the dangerous part is not just stolen files - it is the possibility that recovery secrets, credentials, and trust records were sitting in the same blast radius.