In Germany, the Neubrandenburger Wohnungsgesellschaft mbH (NEUWOGES), a municipal housing provider (neuwoges.de), was targeted by the ransomware threat actor incransom, with alleged data theft occurring during the attack. The organization’s leadership reportedly reduced spending on IT and continued cost-cutting post-incident, prompting attempts to assess the stolen data through the supervisory board. #Germany
Category: Ransom Monitor
In the US, ransomware group incransom claims it exfiltrated and analyzed 7 terabytes of Horizon Family Medical Group data, including patient records and 6TB of mission-critical SQL and QuickBooks databases, threatening confidentiality and business operations. The actor’s post alleges the data contains sensitive clinical, financial, and behavioral health information and frames it as being preserved for long-term exposure. #UnitedStates
NAIC.org in the US reports more than 3.1TB of data across its INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems, including 105,000+ files (2.1M insurer regulatory filing PDFs and 40,000 quarterly statistical CSVs with federal EINs), were compromised by the threat actor shinyhunters. The claim is a final warning to contact the attackers by 22 June 2026 to avoid data leakage and related digital disruptions. #UnitedStates
Ransomware attackers affiliated with shinyhunters claimed that Amazon-owned OneMedical.com in the US had over 8.8TB of data compromised, issuing a final warning to contact them by 22 June 2026 or face an alleged leak. They threatened disruptive consequences and urged prompt action, warning that the impacted country is #UnitedStates.
The ransomware claim alleges that threat actor lynx targeted www.wolfconstruction.net (Wolf Construction Services, Inc), a US-based commercial and residential construction provider specializing in wood framing, trim carpentry, and pitched roofing, including re-roofing services in Des Moines and Central Iowa. The intended victims are commercial and residential property owners, and the incident is reported as impacting the United States. #UnitedStates
The Associated Builders and Contractors of Indiana/Kentucky, a trade association in the US, was targeted by the genesis ransomware threat actor. The attack encrypted or disrupted organizational data and services, impacting operations in #UnitedStates
United Personnel (a division of Masis Staffing Solutions) in the United States reported a ransomware incident attributed to the Genesis threat actor. The attack impacted staffing services operations in the US. #UnitedStates
Ransomware claimed to have impacted zaunsysteme.de in Germany, targeting the country’s construction materials and perimeter security sector. The threat actor safepay allegedly affected the company’s operations, including double-wire mesh products, with the impact limited to #Germany
Safepay ransomware targeted harcourts.net in Australia, encrypting data and disrupting services following an attack attributed to the group. Founded in 1888 in Wellington, New Zealand, Harcourts expanded from a local real estate agency into a global brand—impacting #australia
The ransomware claim targets seinordovest.it in Italy, attributed to the threat actor safepay, leveraging pressure against a public utility headquartered in Italy’s Piedmont region. The organization serves numerous municipalities in northwestern Italy, and the incident impacts Italy #Italy
Ransomware claimed by threat actor RansomHouse targeted Prince George County, a US local government responsible for essential services such as public safety, waste management, parks and recreation, and social services. The disruption is intended to impact services for local residents, businesses, and visitors in the impacted country(s): #UnitedStates
spacebears ransomware actors reportedly targeted Chebib Control in Brazil, a hospitality management and intelligent automation provider offering PMS and security-focused integrations. The attack purportedly involved encrypting SQL databases and exfiltrating client data including names, booking dates, hotel details, emails, CPFs, phone numbers, and related metadata, impacting #Brazil.
Akira ransomware actors claimed to have exfiltrated and threatened to leak approximately 10GB of corporate data from Smith Filter, including employee personal information (passports, SSNs, driver’s licenses, and scanned IDs), credit card details, project and client information, and sensitive documents such as NDAs. The company, a leading air and grease filter manufacturer, was established in 1939 and supplies OEM and custom orders; impacted country information was not provided.
Insite Architects, a firm founded in 2002 focused on senior and affordable housing design, is claiming ransomware activity attributed to the Akira threat actor. The attackers allegedly exfiltrated and threatened to leak approximately 65GB of corporate data, including employee personal information (passports, SSNs, DLs, and other documents), credit card data, and sensitive projects, clients, and partner details. #
Threat actors associated with krybit targeted ersa.com.py in Paraguay with a ransomware attack, aiming to disrupt operations and impact availability of company systems. The ransomware claim affects Paraguay #Paraguay