A ransomware group known as aurora claims to have stolen extensive data from Thomas Y. Pickett & Co., including employee Social Security numbers, financial records, medical files, and a digital signing certificate. The company has not confirmed the incident. Affected individuals should monitor credit reports and consider a credit freeze immediately.
| Company | Thomas Y. Pickett & Co., Inc. |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Social Security Numbers, W-4 Tax Forms, Direct Deposit Information, Medical Records, Bank Statements, Property Owner Records, Client Contracts, Digital Signing Certificate |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Thomas Y. Pickett Data Breach?
A ransomware group calling itself aurora has claimed it stole a large volume of data from Thomas Y. Pickett & Co., Inc., a property tax appraisal consulting firm based in the Dallas area. The claim appeared on the group’s leak site, listing extensive files the attackers say they copied from company systems. As of now, Thomas Y. Pickett has not publicly confirmed the incident.
According to the group’s own posting, the stolen data includes 13 SQL Server database backups totaling 127 gigabytes. This reportedly includes the firm’s TYPortal web portal database, which the attackers say holds property owner records and user login credentials. The posting also references an 11 gigabyte Azure DevOps repository containing the company’s proprietary software source code.
Because this report stems from the threat actor’s claims rather than a confirmed company statement, important details remain unknown. The exact intrusion method, the date unauthorized access to the network occurred, and the breach discovery date have not been publicly disclosed. As a result, affected individuals should watch for official communication directly from Thomas Y. Pickett & Co. in the coming weeks.
No independent forensic confirmation of this incident has been made public yet. However, the specificity of the claimed inventory, which allegedly includes financial records, HR files, and technical infrastructure details, suggests a significant compromise if verified. Readers should treat these details as an unconfirmed but serious claim until the company issues its own notification.
Who was affected?
The leaked inventory described by the attackers suggests two main groups could be impacted. The first group includes current and former employees of Thomas Y. Pickett & Co., a firm of roughly 40 people. The second group includes property owners and clients whose records sit inside the company’s TYPortal system.
Because Thomas Y. Pickett appraises mineral, industrial, and utility properties for county appraisal districts, its client base spans multiple states. These include Texas, Wyoming, North Dakota, Mississippi, and Oklahoma, among others. This means the potential exposure is not limited to Texas residents alone.
The total number of individuals affected has not been publicly disclosed. Given the company’s small employee count and the scope of county-level property data referenced in the claim, the number of impacted property owners could be considerably higher than the staff count alone. Minors are not specifically mentioned in the claimed data, though family financial records sometimes touch dependents indirectly.
What Information Was Potentially Exposed?
The threat actor’s posting describes a wide range of sensitive data categories. If accurate, this would represent a serious exposure spanning both personal employee records and company financial and operational information. The claimed inventory covers multiple systems rather than a single database.
- Social Security cards and numbers for employees
- W-4 tax forms and direct deposit information
- Salary schedules and termination documents
- Medical records tied to employee HR files
- Bank statements from PNC and Frost accounts
- Ten-year budget and accounts receivable records
- Property owner records and user credentials from the TYPortal system
- Client contracts and pricing details for county appraisal districts
- A digital signing certificate, including a private key, tied to an HR manager
If these claims hold up, the risk to affected employees is substantial. Social Security numbers combined with W-4 forms and direct deposit data give criminals nearly everything needed to commit tax fraud or redirect paychecks. In addition, medical records mentioned in the claim could be used for medical identity theft, which is often harder for victims to detect than standard financial fraud.
The alleged digital signing certificate adds another layer of concern. Because this credential could allow someone to forge documents under an HR manager’s identity, it creates risk beyond typical identity theft. Meanwhile, the exposure of client contracts and pricing data could harm the company competitively, though that risk falls on the business rather than individual consumers.
What is the company doing?
Because this incident stems from a threat actor’s claim rather than a company announcement, there is no confirmed public record of Thomas Y. Pickett’s investigation or response steps. The company has not issued a statement confirming the breach, and no notification timeline has been publicly disclosed. This is common in the early stages following a leak-site posting.
Affected individuals should not assume that credit monitoring, notification letters, or remediation steps have already started. Instead, they should watch for direct communication from the company itself. If Thomas Y. Pickett confirms the incident and notifies affected individuals, that notice would typically include details on any protective services offered, such as credit monitoring or identity protection enrollment.
In the meantime, individuals who may have worked for or done business with the firm should remain cautious. Because the situation remains unconfirmed, taking personal protective steps now is the most reliable way to reduce risk while official details develop.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request a free copy of their credit report from each of the three major bureaus. Reviewing these reports regularly helps catch new accounts or inquiries you did not authorize. This is especially important given the claimed exposure of Social Security numbers.
You can access free weekly reports through AnnualCreditReport.com. Because fraud can take months to surface, continue checking reports periodically rather than just once. If you notice unfamiliar accounts, report them to the bureau immediately.
Consider a Credit Freeze or Fraud Alert
Given the claimed exposure of Social Security numbers and financial account details, placing a credit freeze is one of the strongest protective steps available. A freeze blocks lenders from accessing your credit file, which stops most new-account fraud before it starts. This step is free and can be requested directly with each credit bureau.
Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Either way, acting early reduces the window criminals have to misuse stolen information.
Watch for Tax and Employment Fraud
Because W-4 forms and direct deposit information were reportedly included in the stolen data, employees should watch closely for signs of tax-related fraud. This includes unexpected IRS notices or rejected tax filings. Filing your taxes early each year can help reduce the chance someone else files first using your information.
In addition, consider requesting an Identity Protection PIN from the IRS. This PIN adds a layer of verification that makes it harder for someone to file a fraudulent return using your Social Security number. If you notice unusual payroll changes, notify your HR department right away.
Stay Alert for Phishing Attempts
Stolen personal and employment data often fuels convincing phishing emails and phone calls. Scammers may pose as banks, the IRS, or even the company itself to extract more information. Because the claimed data includes detailed employment and salary records, any phishing attempt tied to this breach could appear highly credible.
Never click links or share information in response to unsolicited messages. Instead, verify requests by contacting the organization directly through a known phone number or website. If something feels urgent or threatening, that is often a sign of a scam.
Protect Medical and Health Information
Because medical records were reportedly part of the stolen HR files, affected employees should also monitor their health insurance statements closely. Look for unfamiliar claims or services you did not receive. Medical identity theft can lead to incorrect information appearing in your health records.
If you spot anything suspicious, contact your health insurance provider immediately. Request an itemized statement of benefits to review past claims in detail. Catching medical fraud early helps prevent complications with future treatment or billing.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
