On November 19, 2024, aviation maintenance firm AeroWorx appeared on the leak site of the frag ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the FAA-certified repair station that specializes in pneumatic, hydraulic, electromechanical, and fuel systems. Anyone whose employment, contractual, or personal records passed through AeroWorx now faces the possibility that their information sits in an attacker-controlled archive.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch AeroWorx
Get alerted the next time AeroWorx files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AeroWorx’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The frag leak site, archived on ransomware.live, explicitly lists AeroWorx and describes two categories of stolen material. The first includes corporate internal documents, agreements, and financial statements. The second, labeled by the attackers as “the icing on the cake,” contains non-disclosure agreements along with employee passports and other personal documents. The disclosure does not quantify the number of records, name specific data fields beyond those categories, or state whether customer data was taken. It simply states that exfiltration occurred and that the files are now in the group’s possession.
Why This Matters for You and Your Family
When an employer’s internal repository is stolen, the exposure rarely stops at the company name. Employee passports, NDAs, and financial statements often contain full legal names, dates of birth, passport numbers, home addresses, and signatures. If you or a family member worked at AeroWorx, contracted with them, or had your information included in their vendor or partner files, those details can be used to open accounts, file fraudulent tax returns, or impersonate you in official correspondence. Even if the exact number of affected individuals remains unknown, the presence of scanned identity documents raises the probability that real-world fraud will follow.
The Doxxing and Identity-Chain Risk
Passports and NDAs do not exist in isolation. A single leaked document can link an email address to a physical address, a phone number, and a date of birth. Attackers then cross-reference those details across other breaches to build a complete identity chain. The same credentials used for an AeroWorx portal may also protect personal email, banking, or social-media accounts. Once one account falls, the rest collapse in sequence. Children’s gaming accounts tied to a parent’s email or address are especially vulnerable because gaming platforms rarely enforce the same verification standards as financial services. A single leaked corporate file can therefore cascade into doxxing that reaches every member of the household.