W****e in the US reported a ransomware attack attributed to the threat actor payoutsking, in which the attackers encrypted data and demanded a ransom for its release. The impacted country was #UnitedStates
Category: Ransom Monitor
On an incident targeting guardianbarrierservices.com in the UK, the threat actor threeam deployed ransomware, disrupting Guardian Barrier Services’ event infrastructure operations. Guardian Barrier Services provides crowd control barriers, cable ramps, truss structures, and temporary flooring, impacting services in #UnitedKingdom
Lam Soon in Thailand reported a ransomware incident attributed to the qilin threat actor. The attack disrupted operations and access to systems and data, affecting businesses in #Thailand
Boston Orthotics & Prosthetics in the US suffered a ransomware attack in which threat actor anubis allegedly accessed and exposed patient data, continuing the pattern of breaches at negligent clinics. The impacted country(s) is/are #UnitedStates
ESMS Global Limited in GB reported a medical information services data breach associated with ransomware operations attributed to the threat actor anubis. The incident resulted in unauthorized access to sensitive medical data and potential exposure of impacted records. #UnitedKingdom
Stormous breached eshacloudqa.com, an ESHA Research/ESHA Cloud Services organization in the US, compromising core product development databases and exfiltrating highly confidential industry secrets and formulation data tied to SupplementFormula, PureFood, and FoodGroup. The stolen intellectual property includes secret product designs, manufacturing blueprints, and recipes, along with deep laboratory, nutritional testing, allergen classification, and sensitive registries containing client profiles, user metrics, and market consumer activity (Consumer, Activity). #UnitedStates
eogb.co.uk in GB suffered Stormous ransomware-related compromise with deep access to Microsoft Dynamics GP, exposing complete corporate accounting, invoices, vendor details, and commercial transactions. The attackers also accessed internal legal documents and customer contracts (including CBIF OSMO agreements) and exfiltrated operational spreadsheets, financial reports, and executive materials via corporate systems, impacting #UnitedKingdom
METCO Services, a multi-disciplinary engineering consulting firm serving the water and wastewater sector, was impacted by ransomware activity attributed to the threat actor cmdorganization. The incident disrupted operations for organizations providing study, design, and construction engineering services for public water and wastewater systems in the United States. #UnitedStates
HIGUCHI USA, INC in the US was impacted by ransomware attributed to stormous, with indicators linked to a Dallas–HongKong–LosAngeles operational chain and the presence of .ptb files. Compromised Sage 50 (Peachtree) backups and corporate financial/inventory systems exposed balance sheet and A/R/A/P records, with the impacted country(s) #UnitedStates
higuchi-inc.co.jp in Japan reported ransomware activity by threat actor stormous, demanding payment after encrypting or threatening access to comprehensive financial statements (Balance Sheets, asset records, liabilities, capital, A/R, and A/P) and Sage 50 database backups associated with the .ptb extension. The incident also impacted corporate operational data including domestic and international inventory tracking and trade/business operations in #Japan
Nidec Chaun-Choung Technology Corporation (CCIC) (ccic.com.tw) in Taiwan reported a ransomware incident attributed to the Blackfield threat actor. The attack impacted operations and data availability within the organization in #Taiwan
NASCO in the US suffered a ransomware attack attributed to the qilin threat actor, resulting in disruption of access to their systems and data. The incident impacted #UnitedStates
Axionlog in the Czech Republic reported a ransomware incident attributed to the qilin threat actor. #CzechRepublic
Villea Hotels in AttanaHo reported a ransomware attack attributed to the “payload” threat actor, which encrypted files and disrupted operations. The affected location was in #attanaHo
J&J Gaming, in the United States, reportedly experienced a ransomware attack attributed to the threat actor “play.” The incident resulted in encrypted files and operational disruption for the victim, impacting #UnitedStates