Safepay ransomware targeted shuttlemeadowcc.com in the United States, disrupting operations at the long-standing New England private golf club founded in 1917. The incident resulted in business interruption for the victim in the United States. #UnitedStates
Category: Ransom Monitor
TitanTV, Inc. in the US reported a ransomware incident attributed to the qilin threat actor, resulting in unauthorized access and disruption of its systems. The attack had impacts across #UnitedStates
The ransomware claim targets Nicholson y Cano Abogados (Argentina), a leading full-service law firm established in 1976 with 29 partners and over 150 lawyers providing legal services across 20 practice areas for local and international clients. The threat actor dragonforce is reported to have carried out the attack impacting #Argentina
Webosphere in IN reported a ransomware incident attributed to the nightspire threat actor, involving theft or exposure of -SQL Database- and corresponding source code. The activity impacted #India
Northeast Rescue Systems in the US reportedly fell victim to ransomware activity attributed to the dragonforce threat actor, disrupting the specialized rescue, safety, and protective equipment provider’s operations across its New England-focused customer base. The incident impacted operations in the United States. #UnitedStates
The D1R threat actor D1R, targeting ARM in GB, exploited leaked Synopsys database information and cross-referenced other group leaks to gain access and investigate remotely, later using Athena Download Manager—requiring an SSL certificate tied to ARM’s parent-owned product infrastructure—to bypass ARM’s 2FA email/SMS checks. This capability severely incapacitated operations despite 2FA protections, ultimately enabling unauthorized downloads from ARM-associated sources and amplifying impact to GB #UnitedKingdom
D1R ransomware activity against Bosch in DE was claimed based on technical leak analysis and cross-referenced targets from TARGETLIST.txt, resulting in unauthorized access and theft of $10,000 gem: Bosch CAN module implementation data. The threat actor says the data will be shared publicly, attributing its roadmap and target discovery to Synopsys. #Germany
The spacebears ransomware claim states that Turbosoft in Cameroon was targeted, threatening exposure of personal information of employees and clients, financial documents, and other files. The victim asserts the company’s systems were impacted in #Cameroon
The ransomware claim targets Els for Autism Foundation and its Els Center of Excellence campus in Jupiter, Florida, run by the organization founded by Liezl and Ernie Els, with the threat actor cmdorganization allegedly seeking disruption. The impacted country(s): #UnitedStates
Community Advocates reported that the Anubis ransomware gang exposed law firm clients’ personal data in connection with the incident. The claim affects #countryname
Surtifamiliar reported a ransomware claim in which the threat actor anubis allegedly targeted and exposed the passports of employees of a supermarket chain. The impacted country is unknown.
Casper Orthopedics reported that anubis ransomware exposed orthopedic clinic patients’ data and medical records. #countryname
STEP Oiltools in Romania, a leading global solids control and drilling waste management provider, reported a ransomware incident attributed to the dragonforce threat actor. The claim involved disruption impacting the company’s operations serving oil and gas and civil engineering customers in Romania. #Romania
Dragonforce reportedly targeted Al – Saidi Factory in Saudi Arabia, claiming ransomware deployment against the Al Saidi Al Saidi Trading and Industry organization, which provides chemical manufacturing and logistics services for the Middle East. The threat actor alleges to have disrupted operations supporting supply chain management, freight forwarding, and Oil & Gas/petrochemical chemical production. #SaudiArabia
Deadlock ransomware targeted Aldaco Avance 2022 S.L., a Spanish industrial engineering and construction materials company with operations across Asturias, Galicia, and Madrid. The incident impacted Spain #Spain