La Cour des Comptes du Sénégal (www.courdescomptes.sn) in Senegal was reportedly targeted by the krybit ransomware threat actor, seeking to disrupt operations and/or extract data. The impacted country(s): #Senegal
Category: Ransom Monitor
In Brazil, the spacebears ransomware threat actor compromised Gerencial Contábil (Gerencial PR), a Paraná-based accounting and business advisory firm, allegedly targeting around 1,000 personal digital certificates (.pfx/.p12) and their passwords for Brazilian government portals, along with client records (tel, email, IDs, passwords, etc.) and approximately 600,000+ files containing personal information. The incident impacted individuals and organizations connected to the firm’s multi-office operations across Paraná. #brazil
SilentRansomGroup allegedly deployed ransomware against He..t S..it., causing disruption and threatening data exposure while encrypting files. #countryname
Tecfi SpA in Italy, a company specialising in fastening systems, was targeted by dragonforce ransomware, disrupting operations across its plastic and rubber moulding, sheet metal moulding with blanking, and cold stamping and flatbed rolling production lines. The incident impacted #Italy.
Ralph Lauren in the US was hit by ransomware from shinyhunters, with over 220GB of data exposed, including customer PII and purchase/transaction information, plus unreleased releases scheduled for 2027 and beyond. The company failed to reach an agreement with the attackers, who ultimately claimed more data was compromised despite prior offers and chances. #UnitedStates
Shinyhunters claims the primary server hosting all leaked data is undergoing scheduled maintenance and will be unavailable for about 24 hours, while it deploys data mirrors and plans to offer torrent links for faster distribution. It further asserts that no data has been lost due to backups and that the leaked files will remain publicly accessible until “the end of time.” #
On aurora’s ransomware operation against Sumitomo Electric Bordnetze (DE), the group exfiltrated 1.1 terabytes of data from manufacturing sites, including HR/payroll and engineering/quality documentation across multiple regions. The dataset included sensitive banking material such as Citibank corporate authentication systems and related operational records, impacting Germany, Moldova, Ukraine, Tunisia, and Slovakia #Germany #Moldova #Ukraine #Tunisia #Slovakia
Diamond Truck Centres (Canada) reported a ransomware-related data breach impacting Western Canada’s largest International Trucks dealership group (CA), attributed to the aurora threat actor. The incident exposed extensive shared-drive data including HR and payroll records, biometric fingerprint timeclock enrollment data, immigration documents, plaintext system credentials, military contract/vehicle information, and customer bank deposit and PAD form details. #Canada
SilentRansomGroup ransomware targeted He..t S..t. using a disruptive payload designed to encrypt data and pressure payment. The incident impacted #Unknowncountry
Aurora ransomware activity targeted Allan Brothers Fruit, a third-generation U.S. tree-fruit operation in Naches, Washington, and threatened to disrupt operations by exfiltrating sensitive systems and employee data. Stolen information included ADP records, W-2 filings with Social Security Numbers, direct deposit details for ACH fraud, H-2A/I-9 employment documentation, Oracle RMAN production backups, badge photos, and OSHA incident logs, impacting the United States #UnitedStates
Novo Nordisk, headquartered in Denmark, reported a ransomware claim by the threat actor fulcrumsec targeting its systems. The incident impacts Denmark. #Denmark
Incransom ransomware targeted framesiprofessional.com, a US-based professional hair care and styling products company serving licensed salons and stylists, potentially disrupting operations for its 200 employees and $25.1M revenue business. The company’s professional-focused cosmetics and beauty product distribution may have been impacted by this ransomware incident in the United States. #UnitedStates
Ransomware impacted jasperplastics.info, a US-based manufacturing company with 10 employees and about $5M revenue, where incransom allegedly targeted Jasper Plastics Solutions’ operations. Jasper Plastics Solutions provides turn-key plastic and polyurethane components for OEM manufacturers across the RV, Marine, Automotive, and Construction industries, potentially disrupting production and services in the United States. #UnitedStates
Promepla in Argentina, a Contract Design Manufacturer specializing in single-use plastic medical components and devices, reported a ransomware incident attributed to the RansomHouse threat actor. The attack impacted operations across its healthcare-focused product design, prototyping, cleanroom manufacturing, and sterilization services in #Argentina.
Cloak ransomware targeted ra-*******e, deploying malware that encrypted the victim’s data and disrupting access to approximately 1.1TB of private files. The incident was assessed with country attribution as applicable. #