Thomas Y. Pickett & Co., Inc. Listed by Aurora Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Thomas Y. Pickett & Co., Inc. was listed on October 05, 2026 by the Aurora ransomware group, which claims to hold data belonging to an undisclosed number of individuals. Anyone who may have shared information with the firm should verify their exposure and consider protective steps.
A ransomware group known as Aurora has listed Thomas Y. Pickett & Co., Inc. on its leak site, asserting that it holds company material. As of writing, the firm has not publicly confirmed the claim. For property owners, employees, or others who may appear in appraisal or internal records, the practical question is conditional: if the claim were accurate, what kinds of information might be involved and what sensible steps follow.
Public detail is limited. The listing does not establish that a breach occurred, that files left the company, or that any particular person is affected. It is an unverified accusation posted by an extortion crew. Readers should treat it as a claim, watch for any statement from the company or regulators, and act on precaution rather than on panic.
Inside the listing
According to the leak-site entry attributed to Aurora, Thomas Y. Pickett & Co., Inc. was listed with a reported date of October 05, 2026. The number of people affected is unknown. Data types are not disclosed in a clean inventory sense in the public summary available here; the listing’s own marketing language refers to claimed material rather than a confirmed forensic tally.
The group’s listing text claims an “inventory” that includes 13 SQL Server database backups totaling 127 GB, among them a 102 GB TYPortal web portal database said to contain property owner records and user credentials, plus complete HR records (the listing text appears truncated in the available summary). These figures and descriptions come from the attackers’ post. They are not independently verified. Method of access, timing of any alleged intrusion, ransom demand, and whether any data was actually copied or published beyond the listing itself are undisclosed in the facts at hand.
Thomas Y. Pickett & Co., Inc. has not publicly confirmed the claim as of writing. A leak-site listing is a pressure tactic. It does not, by itself, prove theft, exposure, or the accuracy of the file descriptions.
Inside Aurora
Aurora is known in public reporting as a ransomware and data-extortion operation. Groups in this category typically claim to encrypt systems, exfiltrate files, and threaten publication on a dedicated leak site unless payment is made. They often post victim names, selective file samples or volume claims, and countdowns to increase pressure on the named organization and its partners.
Public knowledge of Aurora’s broader pattern—double-extortion style claims, leak-site branding, and listing of corporate victims—does not verify any single entry. For this matter, the only incident-specific assertion in the provided facts is that Aurora has listed Thomas Y. Pickett & Co., Inc. and has described certain database backups and HR-related material in its own words. No confirmation from the company, a regulator, or a breach index is included in those facts.
Thomas Y. Pickett & Co., Inc. and its sector
Thomas Y. Pickett & Co., Inc., according to the same summary used for the listing context, was founded in 1926 and is headquartered in the Addison/Dallas, Texas area. It is described as one of the older property tax appraisal consulting firms in the United States, appraising mineral, industrial, and utility properties for county appraisal districts in Texas, Wyoming, North Dakota, Mississippi, Oklahoma, and other jurisdictions. The summary places the firm at roughly 40 employees and about $5.3 million in annual revenue, with a long-standing professional reputation.
Firms in property tax appraisal consulting sit between public appraisal districts, property owners, and complex asset classes such as minerals, industrial plants, and utilities. Work of this kind routinely involves ownership details, valuation workpapers, correspondence, and systems used to serve clients and districts. A credible compromise in this sector would matter because the same records can touch financial, identity, and credential data for owners and staff. That consequence is why an unverified listing still draws attention—even when nothing has been confirmed.
The information in question
Named data types in the sense of a confirmed exposure list are not disclosed as verified fact. The Aurora listing claims large SQL Server backups, a substantial TYPortal database allegedly holding property owner records and user credentials, and complete HR records. Those are the group’s assertions, not an audited inventory.
If files of the kind such firms typically maintain were ever taken, organizations in this line of work often hold some mix of property owner identifiers and contact details, appraisal and parcel-related records, portal or system credentials, and employee HR files (which can include names, contact information, and other employment data). Whether any of that left Thomas Y. Pickett & Co., Inc., in what form, or for which individuals remains unconfirmed. Exact contents, completeness, and publication status are not established by a leak-site post alone.
Why it matters
For people who might be in property-owner or employee datasets, the conditional risks are familiar: phishing that references real appraisal or tax context, attempts to reset portal accounts if credentials were involved, and misuse of HR-style personal details for fraud or social engineering. For the organization, an extortion listing can disrupt client trust, district relationships, and day-to-day operations whether or not the underlying claim is fully accurate.
None of that requires treating Aurora’s post as proven. It requires recognizing that leak-site claims are designed to create urgency, that sector data is often sensitive when real, and that individuals should respond with measured hygiene rather than assumptions that “their” file is already public.
Steps worth taking either way
Because the incident is unconfirmed, the useful posture is precaution. If you have a relationship with the firm as a property owner, client contact, or employee, consider the following:
- Treat unexpected emails, texts, or calls about appraisals, tax values, “portal locks,” or wire instructions as high-risk until verified through a known phone number or official channel.
- If you use any related web portal, change the password from a device you trust, use a unique passphrase, and turn on multi-factor authentication where available.
- Watch financial and credit activity for unfamiliar inquiries; freeze or lock credit if you have a concrete reason to believe sensitive identity data may be involved.
- Employees should follow any internal guidance the company issues and avoid reusing work passwords on personal accounts.
- Do not pay or engage anyone claiming to “recover” your data from this listing; that is a common secondary scam pattern.
You can also run a free exposure scan of your email address to see whether it has already appeared in other known breach datasets unrelated to this claim. Keep expectations realistic: a clean scan does not disprove an unverified listing, and a hit on older breaches does not prove this one. Stay alert for any public confirmation from Thomas Y. Pickett & Co., Inc. or official notices; until then, Aurora’s listing remains an accusation, not an established breach record.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Metrea LLC/Commuter Air Technology, Inc. Listed by Aurora Ransomware GroupBuford-Thompson Company, LTD Listed by Aurora Ransomware GroupBenshaw, Inc. Listed by Aurora Ransomware GroupJinny Beauty Supply Listed by Aurora Ransomware GroupLatest breaches
Publicly posted by aurora — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.