Meta in Brazil reported ransomware activity attributed to threat actor bravox, impacting its occupational health services focused on workplace safety, ergonomics, and preventive healthcare programs. The attack resulted in disruption of services and operational continuity across the organization in Brazil. #Brazil
Category: Ransom Monitor
Incransom targeted horizoneye.com, a US-based network of independent optometric clinics and medical practices offering comprehensive eye care and related surgical services, by deploying ransomware to disrupt operations. The claim is linked to the impacted country(s): #UnitedStates
Coldstat Refrigeration in the UK reported a ransomware incident involving the threat actor cmdorganization, affecting its operations. The company provides commercial refrigeration equipment sales, installation, maintenance, repair, layout planning, custom system design, and removal of old equipment. #UnitedKingdom
Lapsus$ claimed to have exfiltrated everything for AYA Bank’s main platform, providing a full dump and PII data, and stated that if AYA Bank does not contact them or pay the ransom they will begin selling the data. The threat was directed toward Bangladesh #Myanmar
Lee International in Singapore reported a ransomware attack attributed to the qilin threat actor, resulting in disruption of its systems. The impacted country is #Singapore
Reynella East College in Australia reported a ransomware claim by the interlock threat actor involving the leak of sensitive personal data after inadequate protection of student and staff privacy. The actor provided 600 GB of purported files and documents, including contracts, financial reports, personal data, identification numbers, and seating charts, indicating exposure of information in #Australia.
Nova ransomware actors allegedly claimed to exfiltrate and threaten to disclose data belonging to cloudquantum, a software company providing application and automation solutions at cloudquantum.co, unless the company contacted support. The actor provided a “tree” and samples of stolen data to the company and demanded engagement with its support department. #unknown
The Icarus threat actor claimed to have exfiltrated Salesforce data from the victim, using ransomware tactics that involved stolen SF data and a compressed payload size. #countryname
Icarus ransomware claim alleges that it stole compressed Salesforce data from G*, leveraging unauthorized access to exfiltrate SF information before deployment of ransomware. This activity is said to have impacted #countryname.
The ransomware claim targets H*, with data stolen from Salesforce systems. Threat actor Icarus reportedly exfiltrated compressed Salesforce data from H*. #
Icarus ransomware claim against Cbassociations reported theft of Salesforce (SF) data. The attackers exfiltrated compressed SF data, impacting #Unknown
Icarus ransomware operators compromised Cqcrm’s Salesforce environment, exfiltrating compressed SF data before encryption/impact. The incident impacted #
Randa.net, a New York–headquartered global apparel and lifestyle accessories company, was impacted by ransomware claimed by the chaos threat actor. The claim indicates encrypted systems and disruption to Randa’s operations, but the impacted country is not specified in the provided details. #unknown
Gms-net reported a ransomware incident involving data theft from Salesforce, where SF data was exfiltrated in compressed form. The threat actor Icarus is implicated, impacting #countryname
Icarus ransomware claim against HDS (Hdscorp) reports that compressed Salesforce (SF) data was stolen, with threat actors accessing and exfiltrating customer and business information from the Salesforce environment. Impacted country is not provided, so the impacted country(s): #Unknown