The ransomware attack claimed by the threat actor “thegentlemen” targeted Tangram Interiors in GB, stating that client personal data was involved and that the incident impacted 400+GB of information. Tangram Interiors, a commercial interior solutions provider and Steelcase dealer founded in 1963, reported revenue of $245.1 million at the time of the claim. #UnitedKingdom
Category: Ransom Monitor
Sanaa in Yemen was targeted by ransomware attributed to Black X, resulting in file encryption and disruption to affected systems. The attack impacted Yemen #Yemen
Converting Equipment International (GB) reported that ransomware activity by the interlock threat actor led to the exposure of confidential information, including equipment development details, contracts, customer relationships, and personal data. The incident was attributed to CEI’s long-standing security neglect, impacting the United Kingdom. #UnitedKingdom
Southport Outdoor Living (GB), a Canadian outdoor patio furniture company founded in 2008 specializing in lounge, dining, grilling products, umbrellas, and custom cushions, reported a ransomware incident associated with threat actor dragonforce. The attack impacted operations in the United Kingdom #UnitedKingdom
Kee Wah Bakery in Hong Kong reported a ransomware incident attributed to the dragonforce threat actor, threatening access to company systems supporting its production and customer services. As a bakery offering traditional and innovative baked goods—including mooncakes, festive treats, and gift items—the organization faces disruption across its operations impacting customers and corporate partners in #Hongkong
Sinai Grand Casino in Egypt reported a ransomware incident attributed to the dragonforce threat actor, impacting its 24/7 casino operations and services. As the premier casino destination in Sharm El Sheikh, disruptions to its gaming, entertainment, and guest experience affected the organization’s ability to serve international tourists. #Egypt
Saint George’s School in Colombia, a bilingual Bogotu00e1 school offering a Cambridge curriculum and EFQM-certified quality, reported a ransomware incident. The threat actor, cmdorganization, is associated with the attack. #Colombia
Torsiongroup.co.uk in the UK was impacted by ransomware by the threat actor settra, resulting in operational disruption after the company failed to protect its systems. The incident highlights the risk of inadequate security controls and the potential impact on availability for residents and services. #UnitedKingdom
acilab.com in BR was reportedly targeted by the settra ransomware group, with attackers claiming involvement in the financing and rental arrangements for the owners’ other companies as described in “How ACI Financed Its Owners’ Companies,— and Paid Them Rent PROLOGUE Inside the archive of American…”. #Brazil
Ferrovial in ES is claimed to have been impacted by ransomware attributed to threat actor AiLock. The attack disrupted the global infrastructure and mobility operator’s public and private project services, toll road concession operations, and related systems, impacting #Spain
AiLock ransomware targeted Solid Advance Inc. in Japan, an in-house Japanese software company founded in 2004 and based in Tokyo and Aomori that develops and sells All Gather CRM, including cloud and on-premise deployments, as well as network and cybersecurity services. The incident disrupted Solid Advance Inc.’s operations and services in the affected organizations. #Japan
AiLock ransomware targeted Nihon Kotsu Co., Ltd., a leading taxi and limousine operator in Japan, disrupting its operations and potentially impacting services. Nihon Kotsu reported annual consolidated revenue of ¥103.445 billion for the fiscal year ending May 2025, with group and partner company sales totaling ¥155.457 billion. #Japan
South Plains Rural Health Services, Inc. in the US reported a ransomware incident attributed to the threat actor “pear,” disrupting comprehensive and family care services in West Texas. The attack impacted operations across the United States. #UnitedStates
Carient Heart & Vascular in the United States reported a ransomware incident allegedly linked to the “pear” threat actor, which targeted its systems as part of an extortion campaign. As a leading expert resource for heart and vascular care in Northern Virginia, the attack resulted in service disruption and data impact for the organization. #UnitedStates
Jani-King in the US reported a ransomware incident in which the Booba Project exfiltrated and stole 12 GB of facilities services data. The attack affected operations in the impacted country(s): #UnitedStates