Quest Health Solutions (anubis) ransomware claim affected employee data and internal files, along with a few unexpected discoveries reported by the victim. # (impacted country not provided)
Category: Ransom Monitor
Stormous is alleged to have accessed and exfiltrated over 400 GB of data from maglificioliliana.com, including product designs, historical fashion lines, and technical garment specifications. The attackers reportedly also stole customer databases, financial records, commercial contracts, employee data, staff personal files, daily operational documents, and more. #
stormous claims to have compromised jaggroup.com, exfiltrating a full database containing corporate emails, Active Directory domain logins, and clear plain-text passwords, along with Microsoft Dynamics GP databases, license keys, financial reports, and system configuration details. The actor also alleges access to multiple compressed archives, SQL connection data, IM.mdb files, and internal project management and business import sheets, impacting #countryname
mlit.com.my (MY) is claimed to have been hit by stormous ransomware, with a 10GB full data dump leaked via a new link. The compromised data is said to include sensitive internal operations and financial records, including complete Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, general ledger accounts across linked entities, and extracted internal directory trees and file structures from network shares and remote desktop sessions, impacting #Malaysia
The ransomware incident involving transvill, attributed to threat actor nova, targeted Transvill SRL’s logistics and road transport operations, disrupting service delivery and access to company data. The impacted country(s): #
Ransomware claim: the victim is alejandria, allegedly impacted by the Nova threat actor. The incident involves interference with Alexandria’s teleinformation systems and information architecture, impacting #countryname
Threat actor nova is allegedly targeting LP Group (lpgroup), a 2006-founded company with large-scale commercial, logistics, and service developments, after compromising the victim’s data profile as part of a ransomware incident. The claim describes a complex intrusion and affected information, but does not specify a country; #countryname
Miami Machine Inc. in the US was targeted by Akira ransomware, with claims that corporate data will be exfiltrated, including employee personal documents, NDAs, projects, contracts, and client information. The impacted country(s) is: #UnitedStates
The ransomware claim targets transvill.com.pe in Peru, attributed to the nova threat actor. Transvill SRL provides national and international road transport and logistics services for cargo shipments, with a data profile to be provided soon—impacted country(s): #Peru
Jit Ex, a regional and local trucking fleet operating in Memphis and Nashville, is claimed to have been targeted by Akira (JIT-EX, LLC) ransomware, with stolen data including employee personal documents, SSNs, passports/drivers’ license numbers, W-9s, credit card and payment details, NDAs, and customer contracts. The attacker’s disclosure indicates 40GB of corporate data will be published soon, impacting the victim’s operations in #UnitedStates.
The ransomware claim targets lpgroup.pt in Portugal by Threat Actor nova, presented by LP Group, founded in 2006 and credited with completing about 1 million square meters of complex commercial, logistics, and service projects. The actors claim a compromised data profile (as shown in the sample), impacting #Portugal
IH Engineers, P.C. (an engineering consulting firm) was targeted by the Akira ransomware group, with the threat actor claiming access to employee personal documents, confidential internal files, contracts and agreements, NDAs, and project materials after 65GB of corporate data is to be exposed. The impacted countries are #UnitedStates.
Akira ransomware actors allegedly targeted Leo International, established in 1986, a manufacturer serving the PVF, HVAC, and Plumbing industries, with the claim of exfiltrating sensitive corporate and employee personal data including passports, SSNs, driver’s licenses, medical information, and confidential internal files. The actor states they will upload 10GB of data, impacting #Unknown.
The threat actor APT73 targeted gov.br, the official state digital platform and domain zone of the Brazilian Federal Government, with a ransomware campaign aimed at disrupting government services. This incident impacted Brazil #Brazil
In a ransomware claim targeting kliknklik.com, the threat actor APT73 allegedly compromised the Indonesia-based online retailer and distributor of computer equipment, disrupting access to data and systems. The impacted country(s): #Indonesia