The ransomware claim targets jshotels.com, belonging to JS Hotels, which owns and manages ten hotel properties scattered across Majorca. The attackers, lockbit5, encrypted or exfiltrated data after compromising the organization, impacting the victim in #Jordan
Category: Ransom Monitor
In a ransomware claim involving Golden Star Resources in Ghana (GH), the threat actor cmdorganization alleged it breached the organization and disrupted operations related to the Wassa mine in south-western Ghana. The company’s ongoing production and mill utilization at Wassa were cited in the context of the impact, affecting operations within Ghana #Ghana
Die Ransomware attacke auf giesdl.de durch den Threat Actor lockbit5 betraf die Die Gies Dienstleistungen GmbH, ein deutsches Gebäudedienstleistungsunternehmen in Deutschland. #Germany
LockBit 5 ransomware claims it breached magna.com.do in the Dominican Republic, targeting Magna Dominicana, a company with over 50 years of experience offering globally recognized vehicle brands. The threat actor claims to have impacted systems and data within the country’s infrastructure. #DominicanRepublic
Bancroft Engineering (bancrofteng.com) in the United Kingdom, a designer and manufacturer of automated welding equipment and related systems, reported a ransomware attack attributed to lockbit5. The incident impacted operations in #UnitedKingdom
Grupo Vanguardia, an automotive group in MX, reported a ransomware incident attributed to the Deadlock threat actor, resulting in disruption and data encryption. The impact is reported in #Mexico
Deadlock ransomware group targeted WiBeats S.r.l. in Italy, stealing over 150 GB from the company’s internal email datastore. More than 50 GB of sensitive internal materials—including contracts and official construction and renewal permits—were exfiltrated, impacting #Italy
Deadlock ransomware reportedly targeted Schlenker and Cantwell, P.A., a US-certified public accounting firm providing services including tax preparation, auditing, bookkeeping, payroll, and consulting. The incident is claimed to have impacted United States. #UnitedStates
Deadlock ransomware allegedly targeted LA SEVILLANITA SRL, the leading transport company in Argentina, in an attack claimed to have disrupted company operations in the country. The impacted country(s): #Argentina
The Schuett Companies, Inc., a US family-owned housing provider, reported a ransomware incident attributed to dragonforce targeting its operations managing approximately 1,600 senior and disability housing units across Minnesota, North Dakota, and South Dakota, along with Home Health Care services through its CompassionCare program. The incident threatens service continuity for residents and emphasizes the disruption of critical housing and healthcare operations in #UnitedStates
Deadlock ransomware actors claim to have compromised and exfiltrated more than 50 GB of personal and sensitive data from the Morton Grove Park District (MGPD), impacting internal employees as well as clients and suppliers, and releasing information they allege includes internal policy and financial documents. The claim involves affected documents protected by an organization non-disclosure policy and ends by inviting journalists, lawyers, and law enforcement to review the material, according to the threat actor’s disclosure. #UnitedStates
Weinberg ”93, Építő Kft., a prominent Hungarian general contractor and steel structure manufacturer, was targeted by the Deadlock ransomware group, which claims to have stolen 650GB of sensitive internal data, including contractor commercial information, specialized construction and metal production technologies, and internal financial transaction records tied to alleged corruption. The stolen data include operational details related to construction projects and was subsequently used as leverage against the company, with journalists, lawyers, and law enforcement invited to review the information. #Hungary
Catcorp reported a ransomware attack attributed to Deadlock, resulting in disruption and unauthorized encryption of business systems. The incident is described as “Mew mew,” and affected the #countryname
Navana Real Estate in the UAE was targeted by the qilin ransomware threat actor, resulting in file encryption and disruption of operations. The incident impacted UAE #UnitedArabEmirates
Interlock ransomware attackers claim to have compromised Borger Independent School District (Borger ISD) in the US, leaking confidential information about staff, students, and parents, along with purported internal details about incidents and financial matters. The threat actor states they offer access to 330 GB of stolen data from the breach, targeting the impacted organization in #UnitedStates