Florida Engineering Services, a US-based organization, reported a ransomware incident attributed to the Qilin threat actor. The attack resulted in disruption and data impact for the victim, affecting operations in the United States. #UnitedStates
Category: Ransom Monitor
Tri-tec, based in the US, was hit by the Qilin ransomware, which encrypted files to disrupt operations and extort payment. The attack impacted the United States #UnitedStates
Wall ISD, a US educational institution in Wall, Texas serving elementary, middle, and high school students, reported a ransomware claim associated with threat actor cmdorganization. The incident impacted systems supporting resources for students and families across the Wall community, #UnitedStates
Sivatel Bangkok in Thailand reported a ransomware incident attributed to the qilin threat actor, resulting in disruption of their systems and data. The impact was reported in Thailand #Thailand
Taiwan Sintong Machinery Co., Ltd in Taiwan was targeted by the qilin ransomware group, which deployed malware to disrupt operations and encrypt victim files. The attack resulted in data loss and downtime, with potential pressure for recovery or ransom payment. #Taiwan
stormous is claimed to have hit jaggroup.com with an UPDATE-FULL DATA DUMP ransomware incident, exfiltrating a full database including corporate emails (@jaggroup.com), Active Directory domain logins, and plain-text passwords, along with Microsoft Dynamics GP data, license keys, financial reports, and system configuration. The attacker allegedly stole compressed archives (zBackups.zip and wetransfer packages) and additional artifacts like SQL connection data and IM.mdb files, plus project, user, purchasing, and sales import logs. #
Incransom reportedly gained unauthorized access to jktornel’s confidential files, including client data, proprietary R&D, and financial documentation. The ransomware claim impacts Mexico. #Mexico
nightspire claimed it deployed ransomware targeting Artistic Smiles in the US, with data reportedly unavailable at this time. The impacted country(s) is #UnitedStates
Nova ransomware hit Lockers IT, a self-owned Bangladeshi custom software development company founded in 2013 and headquartered in Chandpur, encrypting files and exfiltrating data from its servers. Nova then threatened the company by offering tree and sample(s) of stolen data and claiming to provide a decryption sample file upon contact with the support department, impacting #Bangladesh
Nova ransomware actors (HOSAB) targeted Hosab, an organized industrial zone in Bursa, to disrupt essential utilities and infrastructure supporting industrial tenants, while attempting to extort the organization by providing stolen data “tree” and samples upon contact with the support department. The claim includes data-theft and ransom demands directed at the facility’s operations serving local businesses and industries within the zone. #Turkey
Dosab (Demirtaş Organize Sanayi Bölgesi, DOSAB) in South Africa reported a ransomware incident involving the threat actor “nova,” who allegedly exfiltrated data and provided “tree and samples” of stolen information after the organization contacted their support department. The attack impacted DOSAB’s operations and services across its industrial community in South Africa. #SouthAfrica
Nova ransomware targeted nhathanhpho.com.vn, an Vietnamese real estate listing platform operated by an individual in Nh,à Thành Phố, and encrypted data while demanding the company provide stolen-tree and sample files to the support team, including a single decrypted sample file upon contact. The operation impacted Vietnam #Vietnam
Threat actor ransomexx claimed responsibility for ransomware activity against Go2Joy (go2joy.vn) in Vietnam, and stated that it released the complete database of the company. The impacted country(s) is Vietnam#Vietnam
Preferred Properties, Inc. was targeted by the ransomware threat actor payload, resulting in an impact to the company’s operations and access to its systems. The impacted country(s): # (country name not provided)
Qualiflex Solutions (qualiflex.solutions) is reportedly targeted by the ransomware group payload, a threat actor alleged to encrypt or disrupt the victim’s systems. Qualiflex Solutions AG, specializing in automation and control technology and related IT infrastructure and managed services, serves clients with building and industrial automation projects; the impacted country(s) #