Ransomware attributed to krybit targeted xuerong.com in China, with Shanghai Xuerong Biotechnology Co., Ltd. (上海雪榕生物科技股份有限公司)—formerly known as Shanghai Gaoron—impacted by the attack. The impacted country is: #China
Category: Ransom Monitor
S.J. Louis in Brazil was reportedly impacted by the qilin ransomware, which encrypted files and disrupted operations. The incident is believed to have originated in Brazil and caused harm within the organization in #Brazil
The spacebears ransomware threat actor targeted Biessse (IT), claiming access to personal information of employees and clients, financial documents, and a SQL database hosted on https://www.***.com/. The BiesSse group, a 40+ year global manufacturer of technical adhesive tapes with operations in multiple subsidiaries, reports the incident impacted Italy. #Italy
Threat Actor chaos claims to have breached corepharma.com in the US and gained a comprehensive archive of internal operations, alleging full GMP and regulatory compromise. CorePharma’s data exposure is described as impacting US. #UnitedStates
We are officially announcing that we successfully breached the internal network of Opportune LLP and obtained full operational transparency by accessing the victim’s entire internal data environment. The threat actor Chaos is claiming data exposure of Opportune LLP in #UnitedStates
The thegentlemen ransomware threat actor reportedly targeted Kosmos in Germany, impacting operations for Franckh-Kosmos Verlags-GmbH & Co. KG, a major Stuttgart-based media publishing house known for books and educational kits. The incident affected business continuity in #Germany
Keifert GmbH, a master-certified building cleaning company based in Schallstadt, Germany, reported a ransomware incident linked to the threat actor thegentlemen, with additional references to the organization identified via ***.de zoominfo.com/c/keifert-gmbh/429980133. The company’s services span office, industrial, and specialized cleaning across Southern Baden, and the attack affected operations in #Germany
Thegentlemen ransomware targeted Ce Ratp Comite D entreprise Ratp, the digital platform for the RATP Works Council in France. The intrusion disrupted access to employee benefits and social/cultural services used by staff and their beneficiaries. #France
The ransomware claim targets Arabia Falcon Insurance Company SAOG (OM), a leading Oman-based insurer providing general, motor, medical, and life coverage. The threat actor “thegentlemen” is implicated in the incident against the organization in Oman. #Oman
The ransomware claim alleges that thegentlemen targeted hiddeenn, conducting an attack attributed to hidddenn. The incident’s claimed impact is listed as on #UNKNOWN
Spedidam (France) suffered a ransomware claim attributed to thegentlemen targeting ***.fr, potentially disrupting its French collective management operations. Founded in 1959 and based in Paris, Spedidam manages and distributes neighboring rights royalties for performers and supports artistic and cultural initiatives. #France
Quanterm Logistics Sdn Bhd in Malaysia was targeted in a ransomware incident attributed to thegentlemen, impacting the organization’s operations and data availability. The company is a freight forwarding and total logistics provider founded in 1992, and the attack affected Malaysia. #Malaysia
The Virginia Historical Society in the US, operated through its Virginia Museum of History & Culture platform, reportedly experienced a ransomware incident attributed to the threat actor thegentlemen. The attack impacted operations linked to the organization’s digital services and collections, with effects for the organization and its stakeholders. #UnitedStates
Aesthetic Surgical Images, a plastic surgery practice in Omaha, Nebraska, US, was targeted by incransom in a ransomware incident involving its medical records managed by Morgan Records Management. The attack threatened the confidentiality and availability of patient records maintained for compliance with state and federal retention and confidentiality requirements. #UnitedStates
The threat actor thegentlemen targeted LogiQuip in GB with ransomware, as reported by ZoomInfo (***/com/zoominfo.com/c/logiquip/146752157). LogiQuip, a healthcare-focused inventory management and storage manufacturer founded in 1992, was impacted in the United Kingdom. #UnitedKingdom