Randa.net, a New York–headquartered global apparel and lifestyle accessories company, was impacted by ransomware claimed by the chaos threat actor. The claim indicates encrypted systems and disruption to Randa’s operations, but the impacted country is not specified in the provided details. #unknown
Category: Ransom Monitor
Gms-net reported a ransomware incident involving data theft from Salesforce, where SF data was exfiltrated in compressed form. The threat actor Icarus is implicated, impacting #countryname
Icarus ransomware claim against HDS (Hdscorp) reports that compressed Salesforce (SF) data was stolen, with threat actors accessing and exfiltrating customer and business information from the Salesforce environment. Impacted country is not provided, so the impacted country(s): #Unknown
belpointeasset.com / belpointe.com in the United States was targeted by incransom ransomware, resulting in approximately 400GB of encrypted/compromised data. The incident caused service disruption and demands consistent with incransom’s extortion tactics. #UnitedStates
Huntress in the US reported that the threat actor Icarus encrypted its Salesforce data, resulting in compressed data theft as part of a ransomware claim. The impacted country is #UnitedStates.
Schumacher Homes in the US reported a ransomware incident attributed to the Qilin (qilin) threat actor. The attack resulted in disruption to their systems and data availability, impacting #UnitedStates
In a ransomware attack attributed to safepay, ehg.bayern in Germany reported that its infrastructure operations were compromised, disrupting services and systems. #Germany
PrinzEugen ransomware actors, operating as Threat Actor “PrinzEugen,” claimed that data associated with NEW PRINZ EUGEN SITE (NOT A CASE FILE) was compromised, with the OLD SITE expected to be taken offline shortly. The ransom note references an onion address used by the group (prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion) and lists the affected location as unspecified. #countryname
Akira ransomware allegedly targeted Ntd Apparel, with 62GB of corporate data to be exfiltrated, including employee personal documents such as passports, SSNs, driver’s licenses, medical information, and contact details, alongside projects and client information. The claim ends with the impacted country(s): #countryname
Ransomware targeting bits-pilani.ac.in in India was attributed to the dragonforce threat actor, impacting the BITS Pilani research university across its campuses. BITS Pilani, founded in 1964 and recognized as an “Institution of Eminence” with elite engineering and science programs, is highly selective with a 1.47% acceptance rate and a 0% attendance policy with mandatory industry immersion. #India
The ransomware incident targeting the Central Bank of Libya was attributed to the qilin threat actor. The attack resulted in disruption and potential data impact, affecting #Libya
Aaurora (AAC) ransomware actors compromised Aerospace & Advanced Composites GmbH in Germany and exfiltrated two NAS snapshots totaling 209 GB, including ESA thermal vacuum test archives, R&D/composites formulations, and administrative data such as financial statements and IT credentials. The breach also exposed HR and applicant records, identity documents, BitLocker recovery keys for 12 endpoints, and the company’s core system-password spreadsheet, along with 137 partner NDAs—impacting Germany #Germany
Union Tractor Ltd., an aftermarket construction and transportation parts distributor based in Nisku, Canada, reported a ransomware incident involving threat actor cmdorganization. The attack impacted the organization in #UnitedStates.
Homes By J Anthony in the US reported a ransomware incident attributed to the qilin threat actor. The attack impacted business operations and data availability in the US #UnitedStates
Dean Cosmetic Dentistry in the United States was reportedly targeted by Nightspire ransomware. Data details are not available at this time, and the impacted country(s) is #UnitedStates