The ransomware claim targets Tèrra Aventura, operating in PT (Portugal), with the threat actor nova demanding that the victim provide tree and samples along with proofs only after contacting the support department through the channels listed in the recovery file. Impacted country(s): #Portugal
Category: Ransom Monitor
RehaVital Gesundheitsservice GmbH in Germany was targeted by the qilin ransomware threat actor, resulting in disruption of operations and encrypted data. The incident impacted Germany #Germany
Argonaut Manufacturing Services (argonautms.com) reported unauthorized access and confirmed data exfiltration by the RU-based threat actor chaos. 295 GB of critical corporate, technical, and operational data were taken, with a 48-hour countdown to establish contact before public release. #Russia
Nova ransomware actors claimed to target La Financi,ère d’Orion (finorion) in France, allegedly exfiltrating around 20GB of client documents and financial information including “ERES.pdf”. The threat actor reportedly provided tree/sample stolen data to the company when contacted, seeking support-driven engagement. #France
Nova ransomware actor “nova” targeted Canal 9 Litoral (AR), threatening to expose “MXF secret files” stolen from the news platform AHORA Entre Ríos and offering data-leak terms upon contact with the company’s support team. The incident threatens the platform’s minute-by-minute regional reporting across Entre Ríos, Santa Fe, and the Litoral region. #Argentina
Nova ransomware targeted Marpatech, an instrumentation and control solutions provider serving mining and industrial customers across Latin America, by obtaining access to its data and offering it to the company in exchange for contact with support. The claim indicates stolen data was provided to Marpatech after initial compromise and outreach through its support channel, impacting Peru, Argentina, and Colombia #PeruArgentinaColombia
Kreysler & Associates in the United States was targeted by the play ransomware threat actor, resulting in file encryption and disruption of operations. The impacted country(s): #UnitedStates
Play ransomware claim targets Tax MT in the United States, encrypting files and disrupting operations. The incident is attributed to the play threat actor. #UnitedStates
Qilin ransomware targeted Evergreen Title in the United States, encrypting files and disrupting operations. This ransomware claim attributes the incident to the qilin threat actor, with the affected impacted country(s) #UnitedStates
The ransomware claim involves One Community FCU in the US, where threat actor dragonforce allegedly released databases and internal documentation, including client data such as financial information, statements, and documents related to delinquent payments. The incident also references TraceSecurity, LLC’s security work for the institution and its alleged shortcomings contributing to the breach. #UnitedStates
In an alleged ransomware incident targeting downies.com in Australia, the Threat Actor settra reportedly extorted Downies Collectables Pty Ltd, claiming $1.4M per month with an additional $78K in rent paid to itself. The impacted country is #Australia
The ransomware claim by the akira threat actor alleges they compromised Novasport s.r.o. (Novasport spol. s r.o.) in the Czech Republic and will publish approximately 17GB of corporate data, including detailed employee information (passports and other records), projects, contracts, and financial and client data. The impacted country(s) is/are: #CzechRepublic
Nichirei in Japan was impacted by ransomware attributed to the threat actor ransomhouse, disrupting its temperature-controlled logistics and frozen food operations. The incident highlights the risk such attacks pose to Japan’s critical food distribution infrastructure. #Japan
PinnPACK (US) reported a ransomware attack attributed to threat actor worldleaks, resulting in unauthorized access and disruption of files and systems. The incident impacted the United States #UnitedStates
St. Francis Xavier Catholic School System, a private Catholic school system in the United States, reported a ransomware incident involving the worldleaks threat actor. The attack is associated with disruption of school operations and potential exposure of data belonging to the organization and its community. #UnitedStates