Ransomware impacted jasperplastics.info, a US-based manufacturing company with 10 employees and about $5M revenue, where incransom allegedly targeted Jasper Plastics Solutions’ operations. Jasper Plastics Solutions provides turn-key plastic and polyurethane components for OEM manufacturers across the RV, Marine, Automotive, and Construction industries, potentially disrupting production and services in the United States. #UnitedStates
Category: Ransom Monitor
Promepla in Argentina, a Contract Design Manufacturer specializing in single-use plastic medical components and devices, reported a ransomware incident attributed to the RansomHouse threat actor. The attack impacted operations across its healthcare-focused product design, prototyping, cleanroom manufacturing, and sterilization services in #Argentina.
Cloak ransomware targeted ra-*******e, deploying malware that encrypted the victim’s data and disrupting access to approximately 1.1TB of private files. The incident was assessed with country attribution as applicable. #
Threat actor shadowbyt3$ claimed a ransomware breach against TINYpulse (nintendo.com) in Japan, demanding affected organizations respond to leaked private employee chats and providing “file trees” as proof, with additional victims promised. The actor stated the leaked data included employee names and emails plus internal private message content, and warned of potential lawsuits and further disclosures. #Japan
safepay ransomware targeted kawaius.com in the US, seeking to disrupt operations and coerce payment through the threat of data exposure or service interruption. The incident impacted the United States#UnitedStates
spacebears ransomware actors claimed to have stolen approximately 2 TB of data from ECOVACS, a highly successful Chinese robotics company founded in Suzhou in 1998 and a global leader in smart home cleaning solutions. The victim, located in China, was impacted in #China
The Kedah State Government (MY) was targeted, with nova allegedly compromising its official corporate portal used to provide public services and updates for citizens, businesses, and tourists. The threat actor’s claim includes providing a tree of stolen data samples upon contacting the support department to substantiate exfiltration. #Malaysia
The Q Link Wireless ransomware claim by threat actor qilin alleges data encryption affecting operations in the United States. #UnitedStates
Miseric,órdia de Santo Tirso in Portugal reported a ransomware attack attributed to the qilin threat actor, following unauthorized access and encryption of critical files. The incident resulted in service disruption and data impact, with the impacted country being #Portugal
The ransomware claim targets tokyocivil.co.jp in Japan, attributed to the safepay threat actor. The incident impacts organizations supporting public infrastructure and civil engineering projects serving the Tokyo metropolitan area, resulting in disruption across #Japan
Hughstirling.co.uk in Germany was targeted by the safepay ransomware group, attributed to threat activity linked to a company headquartered in Goslar, Lower Saxony that has operated since 1975 and expanded via additional offices. The ransomware incident impacted Germany #Germany
Incransom ransomware targeted smithassociatescpa.com, a US-based Certified Public Accounting firm in Maine providing accounting, auditing, tax planning, and advisory services. The incident impacted #UnitedStates
Glendale Community College (glendale.edu) in the United States was targeted by ransomware activity attributed to shinyhunters, with 62+ gigabytes of data (304,000+ files) compromised from PeopleSoft Campus Solutions systems spanning GCC, integrations, financial aid, and admissions, including 150,000+ student records and multiple sensitive processing and compliance exports from September 2020 through June 2026. The threat includes a final demand with a 18 June 2026 deadline before data leakage, and warns of operational disruption related to enrollment, immunization compliance, and transcript availability. #UnitedStates
Ransomware actors (shinyhunters) targeted moody.edu in the US, compromising over 23GB of data across enrollment, donor relations, payroll, and communications systems, including 46 million communication records, 2.2 million enrollment lead records, and extensive biodemographic, donor gift, payroll, admissions outreach, and housing data. This is a final deadline warning to contact the attackers by 18 June 2026 to avoid leakage and associated disruptions. #UnitedStates
Illinois Central College (icc.edu) in the US was targeted by the ransomware threat actor shinyhunters, with over 28 gigabytes of data (122,000+ files) compromised across PeopleSoft Campus Solutions and Human Resources systems, including 9,200+ employee payslip PDFs, Social Security–number-containing SURS payroll files, direct deposit records (bank account and routing numbers), and sensitive student and enrollment exports spanning 2021 through June 2026. The claim includes a demand for payment before 18 June 2026 to avoid leakage and “digital” disruption. #UnitedStates