{ “groups”: 401, “victims”: 31946 }
[ { “activity”: “Financial Services”, “attackdate”: “2026-11-18 00:00:00.000000”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Paylogix is an insuretech pioneer offering premium technology sol\nutions that streamline the administration of voluntary benefits. \nTheir robust suite of services includes enrollment, premium billi\nng, alternative funding, and a software-as-a-service platform tai\nlored for groups of all sizes.\n\nWe will upload 185gb of corporate data soon. Employee personal in\nformation (complete information about 130 employees including SSN\ns, passports, DLs and so on), client information, detailed financ\nials, internal confidential files, NDAs and so on.\n”, “discovered”: “2026-01-15T13:48:29.435004+00:00”, “domain”: “paylogix.com”, “group”: “akira”, “press”: { “link”: “https:\/\/www.ransomware.live\/id\/cGF5bG9naXguY29tQDIwMjYtMTEtMTg=”, “source”: “https:\/\/therecord.media\/paylogix-cyberattack-akira-ransomware”, “summary”: “La soci\u00e9t\u00e9 de gestion des avantages sociaux Paylogix a \u00e9t\u00e9 victime d’une cyberattaque. Des pirates informatiques ont vol\u00e9 des informations sensibles, y compris des num\u00e9ros de s\u00e9curit\u00e9 sociale, des donn\u00e9es financi\u00e8res, des informations de sant\u00e9 et des num\u00e9ros de passeport, appartenant \u00e0 des dizaines de milliers de personnes. L’incident, qui a eu lieu entre le 13 et le 18 novembre, a \u00e9t\u00e9 revendiqu\u00e9 par l’enseigne de ransomware Akira en janvier 2026.” }, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UGF5bG9naXhAYWtpcmE=”, “victim”: “Paylogix” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-20T14:54:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/alabama-womans-health-care\/”, “country”: “US”, “data_size”: null, “description”: “Alabama Woman’s Health Care\nComprehensive Consultative Medicine, Wellbeing and Aesthetic Care Organization\nSeveral thousand documents of employees and clients and an archive of photos\n420 Lowell Dr\nSuite 400\nHuntsville, AL 35801 [Sector: Medical, Other]”, “discovered”: “2026-09-20T15:51:17.640727+00:00”, “domain”: “alabamawomenshealth.com”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/170e7ad6ce99aff54cd891f375825850.png”, “url”: “https:\/\/www.ransomware.live\/id\/QWxhYmFtYSBXb21hbidzIEhlYWx0aCBDYXJlQGVtcGVyYWRvcg==”, “victim”: “Alabama Woman’s Health Care” }, { “activity”: “Technology”, “attackdate”: “2026-09-20T14:11:35.009723+00:00”, “claim_url”: “http:\/\/krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion\/blog\/4f64bd4cbeb824f0996d4a452888a817f61920ab51cd08b9bc364e7eb1e91982\/”, “country”: “TR”, “data_size”: null, “description”: “Ahluwalia Contracts (India) Limited (ACIL) is one of India’s largest civil construction and contracting companies, incor…”, “discovered”: “2026-09-20T14:11:58.952794+00:00”, “domain”: “acilnet.com”, “group”: “krybit”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/670ac9c8397c73f15ba7862a2b0c5a26.png”, “url”: “https:\/\/www.ransomware.live\/id\/YWNpbG5ldC5jb21Aa3J5Yml0”, “victim”: “acilnet.com” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-20T12:14:45.367654+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=51f10216-38bf-4521-a65e-4d8e1cad8cd6”, “country”: “TR”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-20T12:15:03.477485+00:00”, “domain”: “www.zorlu.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/66fa3f8451171985f225ef19823d1950.png”, “url”: “https:\/\/www.ransomware.live\/id\/Wm9ybHUgSG9sZGluZ0BxaWxpbg==”, “victim”: “Zorlu Holding” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-09-20T12:14:07.283736+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=283a4d27-c413-4819-9937-3ea8ec6725c7”, “country”: “TH”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-20T12:14:25.639076+00:00”, “domain”: “www.shopdunk.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ae49679759af4524c3942c83a7847694.png”, “url”: “https:\/\/www.ransomware.live\/id\/U2hvcER1bmtAcWlsaW4=”, “victim”: “ShopDunk” }, { “activity”: “Not Found”, “attackdate”: “2026-09-20T12:13:25.492875+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=7daa7895-84f8-4fbd-8985-f6edc7e64dc5”, “country”: “DE”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-20T12:13:43.083355+00:00”, “domain”: “www.kmls.de”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5bf3005d273367c48505fa654eee1e58.png”, “url”: “https:\/\/www.ransomware.live\/id\/S01MU0BxaWxpbg==”, “victim”: “KMLS” }, { “activity”: “Transportation”, “attackdate”: “2026-09-20T12:12:41.316706+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=e220ce0a-da54-4c3e-84ef-163069506fd3”, “country”: “CH”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-20T12:13:05.737287+00:00”, “domain”: “www.tcs.ch”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e7d6c3ee924cf48f643848368ab3d41a.png”, “url”: “https:\/\/www.ransomware.live\/id\/VG91cmluZyBDbHViIFN1aXNzZUBxaWxpbg==”, “victim”: “Touring Club Suisse” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-20T08:30:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/studio-notarile-associato-salvatore-costantino-e-anna-favarato\/”, “country”: “IT”, “data_size”: null, “description”: “Studio Notarile Associato Salvatore Costantino E Anna Favarato, Follina \n+39 0438 971778\nPiazza Iv Novembre, 20, 31051, Follina , Italia\nNotary’s office\nseveral thousand documents\nThere are many customer documents and employee data. [Sector: Finance, Other]”, “discovered”: “2026-09-20T09:35:30.781513+00:00”, “domain”: “costantinofavarato.it”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1a7e115d59cc65f4b2feb6765fb96a0d.png”, “url”: “https:\/\/www.ransomware.live\/id\/U3R1ZGlvIE5vdGFyaWxlIEFzc29jaWF0byBTYWx2YXRvcmUgQ29zdGFudGlubyBFIEFubmEgRmF2YXJhdG9AZW1wZXJhZG9y”, “victim”: “Studio Notarile Associato Salvatore Costantino E Anna Favarato” }, { “activity”: “Technology”, “attackdate”: “2026-09-20T06:23:58.684061+00:00”, “claim_url”: “http:\/\/bravoxxwcfz5qk43ychgveprpd5mw5hvxfs4a2uz2okx7mumiht4fzyd.onion\/blog\/0b9cd65a-d90a-4a98-9cb8-4f3289fecdb8”, “country”: “US”, “data_size”: null, “description”: “A geomatics veteran since 1955, providing surveying, LiDAR, photogrammetry, and GIS services primarily for U.S. federal agencies, including the Army Corps of Engineers and the Department of Defense.”, “discovered”: “2026-09-20T06:24:14.282329+00:00”, “domain”: “www.towill.com”, “group”: “bravox”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3d61640a78dcf448704ccd12bfcb47dc.png”, “url”: “https:\/\/www.ransomware.live\/id\/VE9XSUxMQGJyYXZveA==”, “victim”: “TOWILL” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-09-20T02:50:48.609533+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-fanatics”, “country”: “US”, “data_size”: null, “description”: “Sports commerce \/ e-commerce \u00b7 United States | Complete order history: 46,902 order files (108 GB) with customer personal data; Accounts-payable invoices of league and brand partners; Customer balances, bank transaction archive, customer tax exemption certificates; The fraud-prevention data set | Their cloud data estate is under our destructive control; deletion has begun. | [ACTIVE: deadline 2026-09-23 01:01 UTC]”, “discovered”: “2026-09-20T02:51:07.611792+00:00”, “domain”: “fanatics.com”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/eb4211112e60459b4d8270967ec93208.png”, “url”: “https:\/\/www.ransomware.live\/id\/RmFuYXRpY3MgKGdsb2JhbCBzcG9ydHMgY29tbWVyY2UgcGxhdGZvcm0pQE4wbg==”, “victim”: “Fanatics (global sports commerce platform)” }, { “activity”: “Not Found”, “attackdate”: “2026-09-20T00:00:00+00:00”, “claim_url”: “http:\/\/6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion\/entity\/FFD8A9B88CF2335C”, “country”: “IT”, “data_size”: null, “description”: “”, “discovered”: “2026-09-20T14:50:19.435450+00:00”, “domain”: “”, “group”: “AuditTeam”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b5d1db4ab35b2587d7d6ee5ffa9b70d3.png”, “url”: “https:\/\/www.ransomware.live\/id\/c3QqKipjb0BBdWRpdFRlYW0=”, “victim”: “st***co” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-09-20T00:00:00+00:00”, “claim_url”: “http:\/\/mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.onion\/index.html?new_hvsakjnduqmxtrecpo”, “country”: “IN”, “data_size”: null, “description”: “Our journey started in 2001 with baby steps like \u2013 treatability studies, general analysis of chemicals, water and wastewaters and providing technical consultancy for CC&A and NOC applications of chemical industries; and eventually, Siddhi Green expanded to offer a wide spectrum of environmental services under one roof with systematic planning and a quality-oriented approach.”, “discovered”: “2026-09-20T14:21:12.939737+00:00”, “domain”: “siddhigreen.com”, “group”: “Orova”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f88c598a3c4a0f19a326018ef69ce70e.png”, “url”: “https:\/\/www.ransomware.live\/id\/U2lkZGhpIEdyZWVuIEV4Y2VsbGVuY2UgUHZ0LiBMdGRAT3JvdmE=”, “victim”: “Siddhi Green Excellence Pvt. Ltd” }, { “activity”: “Not Found”, “attackdate”: “2026-09-20T00:00:00+00:00”, “claim_url”: “http:\/\/mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.onion\/index.html?nioujydqxuyyhfjpug”, “country”: “US”, “data_size”: null, “description”: “Avila Real Estate, LLC is a vertically-integrated multifamily company, adding value through acquisition, development of land, construction and operating residential assets. Headquartered in Atlanta, Georgia, Avila has developed over $800 million in 25 multifamily transactions since 1986 for its own account and on behalf of global and institutional investors.”, “discovered”: “2026-09-20T13:51:47.255355+00:00”, “domain”: “avilare.com”, “group”: “Orova”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/cbcce569a88a9a476d4b7ed83d271d1f.png”, “url”: “https:\/\/www.ransomware.live\/id\/RXVyYW1leCBNYW5hZ2VtZW50IEdyb3VwQE9yb3Zh”, “victim”: “Euramex Management Group” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-20T00:00:00+00:00”, “claim_url”: “”, “country”: “HK”, “data_size”: null, “description”: “Data is not available now.”, “discovered”: “2026-09-20T06:40:26.051276+00:00”, “domain”: “greatbay-bio.com”, “group”: “nightspire”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/R3JlYXQgQmF5IEJpb0BuaWdodHNwaXJl”, “victim”: “Great Bay Bio” }, { “activity”: “Technology”, “attackdate”: “2026-09-19T16:20:02.009146+00:00”, “claim_url”: “http:\/\/unsafeipw6wbkzzmj7yqp7bz6j7ivzynggmwxsm6u2wwfmfqrxqrrhyd.onion\/reel\/6aaead79102e2455604e87ec?page=1”, “country”: “”, “data_size”: null, “description”: “Revenue: $1.5 milion”, “discovered”: “2026-09-19T16:20:33.854537+00:00”, “domain”: “voltgames.io”, “group”: “unsafe”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2038848f7265346314726324e3e68a68.png”, “url”: “https:\/\/www.ransomware.live\/id\/dm9sdGdhbWVzLmlvQHVuc2FmZQ==”, “victim”: “voltgames.io” }, { “activity”: “Not Found”, “attackdate”: “2026-09-19T15:30:18+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=812”, “country”: “BR”, “data_size”: null, “description”: “akazzo.com.br\u2014Akazzo Footwear specializes in exclusive fashion products, particularly focu Deadline: 2026-09-26 15:25:00.000000”, “discovered”: “2026-09-19T16:53:14.452502+00:00”, “domain”: “akazzo.com.br”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/daa2872fa95b24c7f85b106d658b28b8.png”, “url”: “https:\/\/www.ransomware.live\/id\/QUtBWlpPQGFyY3VzbWVkaWE=”, “victim”: “AKAZZO” }, { “activity”: “Technology”, “attackdate”: “2026-09-19T15:30:10+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=813”, “country”: “CA”, “data_size”: null, “description”: “www.scomputing.ca\u2014Schneider\u2019s Computing & Websites Ltd. is a Canadian-owned and Deadline: 2026-09-26 15:25:00.000000”, “discovered”: “2026-09-19T16:53:54.774549+00:00”, “domain”: “scomputing.ca”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/cc19f111625acbab33a94b269ff342df.png”, “url”: “https:\/\/www.ransomware.live\/id\/U2NobmVpZGVy4oCZcyBDb21wdXRpbmdAYXJjdXNtZWRpYQ==”, “victim”: “Schneider\u2019s Computing” }, { “activity”: “Government & Defense”, “attackdate”: “2026-09-19T07:14:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/cassias-mg-government\/”, “country”: “BR”, “data_size”: null, “description”: “network commitment, from government credentials to justice panels, such as access to the financial sector, police, personal data, medical (SUS), RG(CIN), BIRTH CERTIFICATE, CPF (identity number in Brazil) among other data from CASSIAS.MG.GOV departments, we will give you a deadline to negotiate with us! [Size: 720.0 MB | Sector: Medical, Government, Finance]”, “discovered”: “2026-09-19T07:50:51.612488+00:00”, “domain”: “cassia.mg.gov.br”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c2021581f800c5b83882d43d78f29c6f.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q2Fzc2lhcyBNRyBHb3Zlcm5tZW50QGVtcGVyYWRvcg==”, “victim”: “Cassias MG Government” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-19T00:00:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/electrolux\/”, “country”: “SE”, “data_size”: null, “description”: “Electrolux Group is a Swedish multinational home-appliance manufacturer, producing refrigerators, washing machines, ovens, dishwashers, vacuum cleaners, and other household appliances under several brands worldwide.\r\n\r\nWe were able to access your azure database, and export every piece of data which adds up to ~41GB.\r\n\r\nYou will receive an email shortly containing the instructions you need to proceed.\r\n\r\nElectro_backup.7z is currently password locked, but if they do not pay the ransom, the password and the data WILL be leaked\r\n\r\nTime is ticking, Pay the ransom.\r\n\r\nIf you are having issues receiving instructions, contact me at: xdlmfao@morke.ru [Size: 12.7 GB | Sector: Manufacturing]”, “discovered”: “2026-09-19T15:50:53.665077+00:00”, “domain”: “electroluxgroup.com”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/64f02caadca9086a4b41e9e6183ebb2e.png”, “url”: “https:\/\/www.ransomware.live\/id\/RWxlY3Ryb2x1eEBlbXBlcmFkb3I=”, “victim”: “Electrolux” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-19T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “## Coming soon…”, “discovered”: “2026-09-19T13:25:01.672733+00:00”, “domain”: “”, “group”: “cry0”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/WW91bmcgSW5qdXJ5IExhd0Bjcnkw”, “victim”: “Young Injury Law” }, { “activity”: “Not Found”, “attackdate”: “2026-09-19T00:00:00+00:00”, “claim_url”: “http:\/\/6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion\/entity\/32373FFB7AF7E725”, “country”: “IT”, “data_size”: null, “description”: “”, “discovered”: “2026-09-19T10:50:28.792216+00:00”, “domain”: “”, “group”: “AuditTeam”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e2ab796dd9bdbe1d5c1ca1256a8c96e7.png”, “url”: “https:\/\/www.ransomware.live\/id\/dGQqKip1cEBBdWRpdFRlYW0=”, “victim”: “td***up” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T23:54:24.784425+00:00”, “claim_url”: “http:\/\/om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion\/r\/ZxMuptij8OrXtBb4TyaPrfDFsvfmfD4otvTwmnvCXIBU5W+YfSjke0DNnrdrCPDPvRWvmCkwFFbjgtFGU3mvjEl1dFI5V3NB”, “country”: “US”, “data_size”: null, “description”: “Employee data, internal files, and a few unexpected discoveries.”, “discovered”: “2026-09-18T23:55:10.634158+00:00”, “domain”: “questgroupsearch.com”, “group”: “anubis”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/50d09192e033a23bbac427d70f5d761c.png”, “url”: “https:\/\/www.ransomware.live\/id\/UXVlc3QgR3JvdXBAYW51Ymlz”, “victim”: “Quest Group” }, { “activity”: “Other”, “attackdate”: “2026-09-18T21:31:14+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/k3g-solutions-brazil”, “country”: “BR”, “data_size”: null, “description”: “K3G Solutions is a Brazilian telecom\/IT consulting company based in Manaus, providing network engineering, ISP support, monitoring, call-center, CDN, and colocation services.”, “discovered”: “2026-09-18T22:23:09.430695+00:00”, “domain”: “k3gsolutions.com.br”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/abe341c9c909a7ab4e04e8e19df99db4.png”, “url”: “https:\/\/www.ransomware.live\/id\/SzNHIFNvbHV0aW9ucyBCcmF6aWxAUGFuemVy”, “victim”: “K3G Solutions Brazil” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-18T20:44:05.484544+00:00”, “claim_url”: “http:\/\/ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion\/topic.php?id=GEK3Hk0FkaPAwQ”, “country”: “CA”, “data_size”: null, “description”: “Canada”, “discovered”: “2026-09-18T20:44:20.711951+00:00”, “domain”: “www.vistahelps.com”, “group”: “play”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/868fe81372d2ae2bda43db356bb505ed.png”, “url”: “https:\/\/www.ransomware.live\/id\/VmlzdGEgUGxhc3RpYyBTb2x1dGlvbnNAcGxheQ==”, “victim”: “Vista Plastic Solutions” }, { “activity”: “Hospitality”, “attackdate”: “2026-09-18T20:43:30.559756+00:00”, “claim_url”: “http:\/\/ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion\/topic.php?id=30nnxBd36EMmja”, “country”: “CA”, “data_size”: null, “description”: “Canada”, “discovered”: “2026-09-18T20:43:47.009719+00:00”, “domain”: “www.inglewoodgolfclub.ca”, “group”: “play”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/8051a6065b2582c4b8d642991f8b83ca.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW5nbGV3b29kIEdvbGZAcGxheQ==”, “victim”: “Inglewood Golf” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-18T20:42:37.606181+00:00”, “claim_url”: “http:\/\/ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion\/topic.php?id=zd7L3yfXL6YNRC”, “country”: “IE”, “data_size”: null, “description”: “Ireland”, “discovered”: “2026-09-18T20:43:11.872555+00:00”, “domain”: “www.barrettmahony.com”, “group”: “play”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QmFycmV0dCBNYWhvbnkgQ29uc3VsdGluZyBFbmdpbmVlcnNAcGxheQ==”, “victim”: “Barrett Mahony Consulting Engineers” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-18T20:24:27.665303+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “[AVAILABLE DATA] Radiology and health imaging, client personal and health data.”, “discovered”: “2026-09-18T20:24:29.068946+00:00”, “domain”: “pittsrad.net”, “group”: “Spirals”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UElUVFNSQURAU3BpcmFscw==”, “victim”: “PITTSRAD” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T19:50:50.860113+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-inter”, “country”: “VE”, “data_size”: null, “description”: “Telecommunications \/ ISP \u00b7 Venezuela | Subscriber connection records: 15,300,000+ entries, tens of thousands of subscriber addresses with the services they contacted; Complete internal network map across all regional operations; Core infrastructure configuration evidence | Network traffic remains severed until settlement. | [ACTIVE: deadline 2026-09-20 18:39 UTC]”, “discovered”: “2026-09-18T19:51:07.604510+00:00”, “domain”: “inter.com.ve”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/bc68bed920c5ed1b44ec27bc063c3582.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW50ZXIgKFZlbmV6dWVsYSdzIGxhcmdlc3QgaW50ZXJuZXQgcHJvdmlkZXIpQE4wbg==”, “victim”: “Inter (Venezuela’s largest internet provider)” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-18T17:51:01.431211+00:00”, “claim_url”: “http:\/\/gammax6w3dkfdjfrjthtmqzsioue52vzy6lz54qy6jcvmogfpubutjyd.onion\/post\/HGvxCUBphjeJKnWK1EVU0CE0x7gVH6YJ”, “country”: “US”, “data_size”: null, “description”: “Premier Lighting & Controls is a full-service commercial lighting agency. It serves architects, contractors, distributors, building owners, and en…”, “discovered”: “2026-09-18T17:52:03.699855+00:00”, “domain”: “premierlight.com”, “group”: “Gammax”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UHJlbWllciBMaWdodGluZyAmIENvbnRyb2xzQEdhbW1heA==”, “victim”: “Premier Lighting & Controls” }, { “activity”: “Not Found”, “attackdate”: “2026-09-18T15:50:07.534378+00:00”, “claim_url”: “http:\/\/6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion\/entity\/192EB2B6AD7B98D9”, “country”: “RU”, “data_size”: null, “description”: “[AI generated] N\/A\n\nI don’t have any reliable information about a company named \”Paid Victim 192EB2B6AD7B98D9.\” This appears to be an anonymized or coded identifier, possibly from a ransomware leak site or threat intelligence feed, rather than an actual company name. Without access to the specific database or source that generated this identifier, I cannot provide factual details about its operations, industry, or country.”, “discovered”: “2026-09-18T15:50:21.961822+00:00”, “domain”: “”, “group”: “AuditTeam”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/36bee1856fdf96af07b7be1482ffff84.png”, “url”: “https:\/\/www.ransomware.live\/id\/UGFpZCBWaWN0aW0gMTkyRUIyQjZBRDdCOThEOUBBdWRpdFRlYW0=”, “victim”: “Paid Victim 192EB2B6AD7B98D9” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T15:27:02.291248+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-paypal-transcom”, “country”: “SE”, “data_size”: null, “description”: “Outsourced customer support \/ financial services \u00b7 Netherlands \/ Tunisia | 86.7M connection records: daily support-agent sessions into PayPal corporate Citrix\/AAA systems; Complete infrastructure map: internal AD, PKI, Netskope\/Zscaler tenants, all 8 sites | All 8 sites are enforcing a network blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC]”, “discovered”: “2026-09-18T15:27:18.196030+00:00”, “domain”: “transcom.com”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/58e32ed0c1c2b0fc6946da8719b87e95.png”, “url”: “https:\/\/www.ransomware.live\/id\/UGF5UGFsIHN1cHBvcnQgb3BlcmF0aW9ucyAoVHJhbnNjb20gV29ybGRXaWRlKUBOMG4=”, “victim”: “PayPal support operations (Transcom WorldWide)” }, { “activity”: “Government & Defense”, “attackdate”: “2026-09-18T15:26:28.255117+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-minedu-ar”, “country”: “AR”, “data_size”: null, “description”: “Government \/ education \u00b7 Argentina | Complete network-security configuration of the ministry network; 1.08M connection records: national library (BNM), school-book selection platform, scholarship systems (becasprogresar), titulosvalidez, certificadosinfd, sitrared; Evidence of the Monero cryptocurrency miner operating inside the ministry network | The ministry network is under a total blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC]”, “discovered”: “2026-09-18T15:26:43.848015+00:00”, “domain”: “argentina.gob.ar”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/eb18f7d348cd7bef92cb798bf883c42d.png”, “url”: “https:\/\/www.ransomware.live\/id\/TWluaXN0cnkgb2YgRWR1Y2F0aW9uIOKAlCBBcmdlbnRpbmFATjBu”, “victim”: “Ministry of Education \u2014 Argentina” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T15:25:52.063207+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-argentem-creek”, “country”: “US”, “data_size”: null, “description”: “Investment management \/ private credit \u00b7 United States | Full corporate network evidence: 2.5M+ connection records, complete internal systems map (Active Directory, SharePoint, MSP tooling, office-security integrations); Tax-season document flows of the firm and its investor document delivery platform | Corporate connectivity remains severed until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC]”, “discovered”: “2026-09-18T15:26:08.569411+00:00”, “domain”: “argentemcreek.com”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5300504d3bd946e1873c09c1221f7b15.png”, “url”: “https:\/\/www.ransomware.live\/id\/QXJnZW50ZW0gQ3JlZWsgUGFydG5lcnMgKGludmVzdG1lbnQgZmlybSlATjBu”, “victim”: “Argentem Creek Partners (investment firm)” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-18T15:25:26.892080+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-astrazeneca-tr”, “country”: “TR”, “data_size”: null, “description”: “Pharmaceutical manufacturing (GxP) \u00b7 T\u00fcrkiye | Complete internal network-security configuration of all 3 sites (940 MB): every rule, device definition, remote-access mappings; 1.35M connection records: M365\/Intune, SAP Concur, UniFi camera estate, internal applications | All sites are enforcing a total network blackout until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC]”, “discovered”: “2026-09-18T15:25:43.614300+00:00”, “domain”: “astrazeneca.com.tr”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ceb2ef216858eb491ab2685961e63906.png”, “url”: “https:\/\/www.ransomware.live\/id\/QXN0cmFaZW5lY2EgVMO8cmtpeWVATjBu”, “victim”: “AstraZeneca T\u00fcrkiye” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T15:24:52.166408+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-stokr”, “country”: “LU”, “data_size”: null, “description”: “Digital securities \/ investment platform \u00b7 Luxembourg – EU | KYC investor register: full names, emails, countries, nationalities, wallet addresses and tax IDs where present; Identity-to-crypto-wallet mapping of KYC-accepted investors (FR, DE, CH, BE, NL, UK and others); Internal platform admin directory with staff accounts and roles | The investor data will also be delivered to the tax authorities of the investors’ countries. | [ACTIVE: deadline 2026-09-20 22:40 UTC]”, “discovered”: “2026-09-18T15:25:08.389430+00:00”, “domain”: “stokr.io”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9239fe5ba509dd02a55b2f77ce6073b6.png”, “url”: “https:\/\/www.ransomware.live\/id\/U1RPS1IgKGRpZ2l0YWwgc2VjdXJpdGllcyBwbGF0Zm9ybSlATjBu”, “victim”: “STOKR (digital securities platform)” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-18T15:24:17.950696+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-konnatus”, “country”: “BR”, “data_size”: null, “description”: “Legal services \/ real estate \u00b7 Brazil | The application database: chart of accounts, income\/outflow structures, account types; User accounts with password hashes | Publication proceeds after the deadline. | [ACTIVE: deadline 2026-09-20 03:32 UTC]”, “discovered”: “2026-09-18T15:24:33.536579+00:00”, “domain”: “”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1e3cde325c01761f42b90725a6802754.png”, “url”: “https:\/\/www.ransomware.live\/id\/S29ubmF0dXMgKHVzdWNhcGnDo28gbGVnYWwgc2VydmljZXMpQE4wbg==”, “victim”: “Konnatus (usucapi\u00e3o legal services)” }, { “activity”: “Education”, “attackdate”: “2026-09-18T15:23:43.319402+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-beliteacher”, “country”: “VN”, “data_size”: null, “description”: “Education \/ edtech \u00b7 Vietnam | The complete CRM lead database: 152,044 contact records \u2014 names, emails, +84 phone numbers, cities, study interests, engagement history; The CRM file archive (tasks, forums, comments, customer files) migrated from GetFly CRM | Publication proceeds in batches after the deadline. | [ACTIVE: deadline 2026-09-20 02:47 UTC]”, “discovered”: “2026-09-18T15:23:59.412779+00:00”, “domain”: “beliteachers.com”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/8f8b1800b0ad33bd82a52d5e213ceef8.png”, “url”: “https:\/\/www.ransomware.live\/id\/QmVMaSBUZWFjaGVyIC8gRlNDIGVkdWNhdGlvbiBjZW50ZXJzIChBV1MpQE4wbg==”, “victim”: “BeLi Teacher \/ FSC education centers (AWS)” }, { “activity”: “Other”, “attackdate”: “2026-09-18T15:23:07.178275+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-vn-betting”, “country”: “VN”, “data_size”: null, “description”: “Online gambling \/ agent platform \u00b7 Vietnam \/ Switzerland | The complete bettor database: 2,021,011 registered bettors with names, +84 phone numbers, email addresses, deposit and withdrawal amounts; The full agent network: 39,998 agent accounts, hierarchy, balances, credit lines and commission ladders; 85 million login records with IP addresses and device identifiers; Daily trading and P&L data per provider; The fraud stack: 33,000+ blacklisted emails and phones, arbitrage and odds-mover reports, multi-account detection rules | Publication proceeds in batches after the deadline. | [ACTIVE: deadline 2026-09-20 01:37 UTC]”, “discovered”: “2026-09-18T15:23:23.007025+00:00”, “domain”: “”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b030ea31941779ae78da1006e0b75298.png”, “url”: “https:\/\/www.ransomware.live\/id\/VmlldG5hbWVzZSBiZXR0aW5nIG9wZXJhdG9yIChHQzc4OSBuZXR3b3JrIC8gQm91bmRsZXNzIFRFKUBOMG4=”, “victim”: “Vietnamese betting operator (GC789 network \/ Boundless TE)” }, { “activity”: “Education”, “attackdate”: “2026-09-18T15:22:32.781736+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-uft”, “country”: “US”, “data_size”: null, “description”: “Education \/ Labor Union \u00b7 US \u2014 New York | The union\u2019s complete legal case archive \u2014 approx. 181,420 documents: grievance and arbitration files, disciplinary appeal decisions and personnel case files, each named for a member; Contract documents: CBAs, MOUs, MOAs and side letters; Nurse-federation and health-benefit-fund case materials; Teacher evaluation and class-size complaint files; Staff search and case-view audit logs | Publication proceeds in batches after the deadline. The victim can verify everything and settle in their private negotiation room. | [ACTIVE: deadline 2026-09-19 14:58 UTC]”, “discovered”: “2026-09-18T15:22:48.612462+00:00”, “domain”: “uft.org”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c9208d0402744c08eef5b9da802bcecf.png”, “url”: “https:\/\/www.ransomware.live\/id\/VW5pdGVkIEZlZGVyYXRpb24gb2YgVGVhY2hlcnNATjBu”, “victim”: “United Federation of Teachers” }, { “activity”: “Education”, “attackdate”: “2026-09-18T14:00:27+00:00”, “claim_url”: “”, “country”: “VN”, “data_size”: null, “description”: “Quy Nhon University (QNU) is a public, multidisciplinary university located in Quy Nhon City, Binh Dinh Province, Vietnam. Established in 1977, the university has a long-standing tradition in teacher education and has developed into a comprehensive institution offering a wide range of academic programs.”, “discovered”: “2026-09-19T07:54:22.255428+00:00”, “domain”: “qnu.edu.vn”, “group”: “Vexy Ransomware”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UXV5IE5ob24gVW5pdmVyc2l0eUBWZXh5IFJhbnNvbXdhcmU=”, “victim”: “Quy Nhon University” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-18T13:48:02.770533+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=273”, “country”: “DE”, “data_size”: null, “description”: “MPA Pharma MPA Pharma GmbH is an internationally active, rapidly growing company specializing in the import and trade of high-quality pharmaceuticals, including both patented and generic products. 2,899,290 files, ~5.8 TBPharmaceutical companyCategories: accounting records and database backups, government audits (customs \/ corporate tax \/ social security \/ wage tax),corporate ownership (nominee structure, beneficial-ownership filings, related-party payments), narcotics\/BtM records (opioids, cannabis, precursors),litigation files, executive and employee personal data, IT artifacts, pharmacovigilance correspondence.Credit cards with CVV of executives, Oltersdorf ID card valid until 2030, the Pfeiffer letter on the hidden Paranova Pack B.V., UBO passportsSQL backups (17.7 million general-ledger rows), commercial register extract (HRB), organizational chartCredentials (TIER 1) – a list of all password files (values not repeated here, stored in the MPA PASSWORDS report)Government audits – customs 17,011.77 EUR with a breakdown, corporate tax +202,203.18 EUR, social security (DRV) 23,134.96 EUR with a separate case against the managing director, wage-tax auditNarcotics (BtM) – permits (318 04 74), reconciliations of 588 rows \/ 93 differences, fentanyl, hydromorphone, oxycodone, tapentadol, unexplained remainders of 1-13 units, documentation gap 2017-2020, cannabis up to 22 percent THC, precursorsLitigation – MSD\/Merck memo, settlement agreement, Amgros judgment 5,180,043.09 DKK, complaint to the Ministry of Health, arbitration filingPeople, security, pharmacovigilance, bulk financial recordsArtifacts – leadership phone book, employee medical documents, Eli Lilly 2025, AstraZeneca, rebate contracts, a list of all produced reports More”, “discovered”: “2026-09-18T13:48:49.890285+00:00”, “domain”: “mpapharma.de”, “group”: “rhysida”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b36a81a2bdc8c574a7401ccf2a995ca7.png”, “url”: “https:\/\/www.ransomware.live\/id\/TVBBIFBoYXJtYUByaHlzaWRh”, “victim”: “MPA Pharma” }, { “activity”: “Hospitality”, “attackdate”: “2026-09-18T11:40:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6aad206a9cd108bf2661a43a”, “country”: “NL”, “data_size”: null, “description”: “Roan Luxury Camping Holidays is a Dutch tour operator specializing in deluxe mobile home and tent rentals at 4- and 5-star campsites across Europe”, “discovered”: “2026-09-18T12:42:56.146503+00:00”, “domain”: “www.roancampingholidays.com”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/842b5c96fe3f714395c266a231075d65.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LnJvYW5jYW1waW5naG9saWRheXMuY29tQGluY3JhbnNvbQ==”, “victim”: “www.roancampingholidays.com” }, { “activity”: “Education”, “attackdate”: “2026-09-18T11:40:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6aad21c99cd108bf2661c398”, “country”: “US”, “data_size”: null, “description”: “Founded in 1944, Kendall Hunt Publishing is a publisher of hands-on, inquiry-based science, mathematics, and gifted curricula for grades PreK-12. Their research and standards-based programs are available in both print and digital components that encompass students, teachers, and parents. Kendall Hunt is headquartered in Dubuque, IA.”, “discovered”: “2026-09-18T12:42:19.468052+00:00”, “domain”: “www.kendallhunt.com”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/7ff1e9b5a8acf214bebf4b856433244c.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LmtlbmRhbGxodW50LmNvbUBpbmNyYW5zb20=”, “victim”: “www.kendallhunt.com” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-18T11:17:00+00:00”, “claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/894eaf4e34caee8450298129bdabc15e”, “country”: “CL”, “data_size”: null, “description”: “Founded in 1980 and headquartered in Santiago, Chile, Forus is a provider of apparel. The company pr…”, “discovered”: “2026-09-18T21:48:40.205034+00:00”, “domain”: “forus.cl”, “group”: “lockbit5”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/83a2b43b1eb6e19da2c9075c02e8aaa7.png”, “url”: “https:\/\/www.ransomware.live\/id\/Zm9ydXMuY2xAbG9ja2JpdDU=”, “victim”: “forus.cl” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T10:11:54.326095+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=27ad9490-4a4f-461f-bd1f-3e86dd364b6e”, “country”: “SG”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-18T10:12:12.276011+00:00”, “domain”: “www.ascendcom.com.sg”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/118f1130f0aa16409dd507a2974b9978.png”, “url”: “https:\/\/www.ransomware.live\/id\/QXNjZW5kIENvbUBxaWxpbg==”, “victim”: “Ascend Com” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-09-18T10:11:09.367050+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=6693ceb2-7649-44c6-917b-c4d3e3d4d027”, “country”: “AR”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-18T10:11:27.447248+00:00”, “domain”: “www.cerestolvas.com.ar”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/cba6fd366d6b96645dcd4bbe324cbeb9.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q2VyZXMgVG9sdmFzQHFpbGlu”, “victim”: “Ceres Tolvas” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-09-18T10:10:23.470630+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=34e3efee-621c-4d46-9791-50f56711a881”, “country”: “CL”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-18T10:10:42.446298+00:00”, “domain”: “www.futuroforestal.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/4be20cbde8f09dc74ac3240c52cb014e.png”, “url”: “https:\/\/www.ransomware.live\/id\/RnV0dXJvIEZvcmVzdGFsQHFpbGlu”, “victim”: “Futuro Forestal” }, { “activity”: “Other”, “attackdate”: “2026-09-18T10:09:37.197663+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=d44f5165-81b9-4f2b-a94c-8fcbf7602ca9”, “country”: “MX”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-18T10:09:56.603763+00:00”, “domain”: “www.grupojuste.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/17090925ca7c9ad13f6c7dac19592a42.png”, “url”: “https:\/\/www.ransomware.live\/id\/R3J1cG8gSnVzdGVAcWlsaW4=”, “victim”: “Grupo Juste” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-09-18T10:08:46.714427+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=16806e54-1da3-4aa8-863c-e92e922afbcb”, “country”: “TT”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-18T10:09:09.954520+00:00”, “domain”: “www.iocltt.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/cabc6e90d1a4fd4f289b679d1de052fb.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW5sYW5kIGFuZCBPZmZzaG9yZSBDb250cmFjdG9yc0BxaWxpbg==”, “victim”: “Inland and Offshore Contractors” }, { “activity”: “Government & Defense”, “attackdate”: “2026-09-18T07:06:40.340016+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Revenue: $144.4 million\n\nAccela is a comprehensive cloud based software platform used by state and local governments to manage internal agency operations. We have successfully extracted over 50 GB of data from Accela. Data includes over 2 million lines of user data with PII, and 6 million user requests (from their citizen engagement portal where citizens report everyday non-emergencies in\/around their neighbourhoods) also with PII. There is a lot of government data, from FBI agents to cops to regular government workers. Speak soon or Leak soon!”, “discovered”: “2026-09-18T07:06:41.424685+00:00”, “domain”: “Accela.com”, “group”: “EndZone”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWNjZWxhLmNvbUBFbmRab25l”, “victim”: “Accela.com” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T07:06:20.213947+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Revenue: $125.6 billion\n\nInitial access was via a CX contractor doing business with AT&T. Access originally used as vehicle for Equipment Changes\/Call Forwarding (thanks a lot TORCH patch) – VPN + HVD (both external and internal MyDesktop) instances were accessed for a prolonged period without any detection or incident response taking place. Certificates exported from certlm in the VDI + OPUS self installer (automatically joins EP to S1) opened up the door to the VPN. Salesforce data was accessed via a project manager ATTUID + a DirecTV contractor who for some reason had the apps available in Salesforce. AT&T CSO, if you are reading this, you are to contact us ASAP!”, “discovered”: “2026-09-18T07:06:21.557117+00:00”, “domain”: “att.com”, “group”: “EndZone”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QVQmVEBFbmRab25l”, “victim”: “AT&T” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T07:03:19.935227+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “Certified IT Asset Disposition (ITAD) and e-waste management for federal agencies, defense contractors, and enterprise organizations demanding the highest chain-of-custody standards.”, “discovered”: “2026-09-18T07:03:21.102539+00:00”, “domain”: “www.anythingit.com”, “group”: “Spirals”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QU5ZVEhJTkdJVEBTcGlyYWxz”, “victim”: “ANYTHINGIT” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T05:49:42+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6aacd0f69f1388101e0e607b”, “country”: “US”, “data_size”: null, “description”: “First Secure Community Bank is a locally-owned financial institution based in Sugar Grove, Illinois, offering a range of personal and business banking services. Their product offerings include residential lending, personal and business credit cards, and interest-bearing accounts such as CDs and IRAs. The bank focuses on meeting the financial needs of local residents and businesses, ensuring convenience and security in managing finances. Established in 2000, First Secure Community Bank has become a trusted fixture in the community, dedicated to helping clients achieve their financial goals. \nThe company headquarters is located in 670 Sugar Grove Parkway (Route 47), Sugar Grove, IL 60554, United States. 11-50 Employees”, “discovered”: “2026-09-18T07:50:52.053135+00:00”, “domain”: “1stsecurebank.com”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9091582f2a6662b5e8ca9f96048754f4.png”, “url”: “https:\/\/www.ransomware.live\/id\/Rmlyc3QgU2VjdXJlIENvbW11bml0eSBCYW5rQFN0b3Jt”, “victim”: “First Secure Community Bank” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T05:47:07+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6aacd05b9f1388101e0e6079”, “country”: “US”, “data_size”: null, “description”: “The State Bank Group is comprised of Wonder Lake State Bank (east), Wonder Lake State Bank (west), Johnsburg State Bank, Spring Grove State Bank, Lakemoor State Bank and Hebron State Bank. The company is proud to have directorship of local business owners and professionals. It has always been the company’s focus as a community bank to provide the best banking services available. The company has selected the company’s banking locations by identifying areas that were at the time unserviced. Therefore, each of the company’s bank locations represents the first bank in their respective community. The company’s group of banks has grown since the company’s inception in 1979. The company currently have a staff of more than 80 employees. In addition to myself, the company has a teller who has been servicing the company’s customers banking needs since 1979. The company thrive on building relationships with the company’s customers and believe the company’s slogan, \”Bank Where You’re Known\”, promotes the company’s continuing mission and commitment to providing true \”Community Banking\”. The company’s extended lobby and drive-up hours provide the company’s customers with the most flexible banking hours in McHenry County. All of the company’s locations are full service banks, staffed with loan officers and new accounts representatives. In addition, all the company’s locations have safe deposit boxes. Each of the company’s loan officers have \”real\” lending authority, meaning that you will always be dealing with the decision makers. This makes your experience both personal and efficient. To the company’s customers who are visiting the company’s web site, \”Thank You Very Much\”. If you are not currently a customer, the company invite you to \”Bank Where You’re Known\”. \nThe company headquarters is located in 7526 Hancock Drive, Wonder Lake, IL 60097, United States.11-50 Employees”, “discovered”: “2026-09-18T07:50:21.637759+00:00”, “domain”: “thestatebankgroup.com”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/15361f30ca64e86753b45a9881ebfe93.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIFN0YXRlIEJhbmtAU3Rvcm0=”, “victim”: “The State Bank” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T05:44:18+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6aaccfb29f1388101e0e6077”, “country”: “US”, “data_size”: null, “description”: “First Secure Bank and Trust was founded in Palos Hills, Illinois in 1977 to serve the financial needs of the company’s friends and neighbors. Today, the company is still in the neighborhood and continuing with that mission. The company is the only \”true\” locally owned bank in the area. The company care about the community because the company live here, too. This local knowledge and commitment gives the company a tremendous advantage when it comes to helping you with your financial needs. Other nearby bank branches have headquarters miles away and employees that move from location to location as the need arises. The company is always here to listen to you and then use the company’s years of experience to help you achieve your financial goals, whether it is a simple free checking account or sophisticated investment advice. The company will always give you the right service-right here, right now. \nThe company headquarters is located in 10360 S Roberts Road, Palos Hills, IL 60465, United States. 11-50 Employees”, “discovered”: “2026-09-18T07:49:50.710298+00:00”, “domain”: “firstsecurebank.com”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/250dd4dc6556d9cb7308bc359fb6cc84.png”, “url”: “https:\/\/www.ransomware.live\/id\/Rmlyc3QgU2VjdXJlIEJhbmsgYW5kIFRydXN0QFN0b3Jt”, “victim”: “First Secure Bank and Trust” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-18T05:41:33+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6aaccf0d9f1388101e0e6075”, “country”: “US”, “data_size”: null, “description”: “American Casting Company is an ISO 9001 and AS9100 certified investment casting foundry located in Hollister, California, specializing in premier quality investment castings for the aerospace and medical industries. The company offers a variety of castings made from super alloys and other high-performance materials, ensuring the industry’s shortest lead times through advanced manufacturing processes, including 3D printing and vacuum melting. Their services include design for manufacturability, NADCAP heat treating, and non-destructive testing, catering to clients in sectors such as medical, aerospace, defense, and industrial applications. With a focus on innovation and quality, American Casting Company commits to delivering precise, durable, and strong investment castings perfect for complex geometries. \nThe company headquarters is located in 205 Apollo Way, Suite A, Hollister, CA 95023, United States. 51-200 Employees”, “discovered”: “2026-09-18T07:51:54.315828+00:00”, “domain”: “americancastingco.com”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f134ba8a81f5e6768ecbbddd5b004e9f.png”, “url”: “https:\/\/www.ransomware.live\/id\/QW1lcmljYW4gQ2FzdGluZyBDb21wYW55QFN0b3Jt”, “victim”: “American Casting Company” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-18T05:38:09+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6aacce419f1388101e0e6073”, “country”: “US”, “data_size”: null, “description”: “Johnson Investment Counsel is an independent, employee-owned wealth management firm founded in 1965 and headquartered in Cincinnati, Ohio. The company provides comprehensive financial services to individuals, families, businesses, corporations, retirement plans, foundations, and nonprofit organizations. Its services include investment management, financial planning, retirement and cash-flow planning, estate planning, trust services, charitable planning, and business solutions. Johnson Investment Counsel operates as a fee-only Registered Investment Advisor and emphasizes fiduciary responsibility, long-term relationships, and customized financial strategies. As of June 30, 2026, the firm manages approximately $23 billion in assets and has 159 employees, serving clients across all 50 U.S. states. \nThe company headquarters is located in 7755 Montgomery Road, Suite 180, Cincinnati, OH 45236, United States.51-200 Employees”, “discovered”: “2026-09-18T07:51:22.892150+00:00”, “domain”: “johnsoninv.com”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0e88747c5643d0975e408f366c321b29.png”, “url”: “https:\/\/www.ransomware.live\/id\/Sm9obnNvbiBJbnZlc3RtZW50IENvdW5zZWxAU3Rvcm0=”, “victim”: “Johnson Investment Counsel” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-18T02:02:18.434722+00:00”, “claim_url”: “”, “country”: “SG”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-09-18T02:02:22.189825+00:00”, “domain”: “giti-corp.com”, “group”: “killsec”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/R2l0aSBDb3JwQGtpbGxzZWM=”, “victim”: “Giti Corp” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T00:04:38+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/stim”, “country”: “FR”, “data_size”: null, “description”: “Stim France specializes in video surveillance solutions within the security industry. The company offers a range of video recorders, video receivers, storage expansion, and integration services for surveillance cameras, as well as software for video surveillance management.”, “discovered”: “2026-09-18T00:22:35.462541+00:00”, “domain”: “stim.fr”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e3f35a31d0049595a9a85a00f653f2b6.png”, “url”: “https:\/\/www.ransomware.live\/id\/U3RpbUBQYW56ZXI=”, “victim”: “Stim” }, { “activity”: “Technology”, “attackdate”: “2026-09-18T00:02:08+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/inovapy”, “country”: “PY”, “data_size”: null, “description”: “INOVAPY is a technology company specializing in software development and digital transformation solutions for small and medium-sized businesses, offering reliable and scalable technological services across Latin America and beyond.”, “discovered”: “2026-09-18T00:23:07.460324+00:00”, “domain”: “inovapy.com”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/db41740b2faf3a9f4601807a12dd0878.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW5vdmFweUBQYW56ZXI=”, “victim”: “Inovapy” }, { “activity”: “Other”, “attackdate”: “2026-09-18T00:00:00+00:00”, “claim_url”: “http:\/\/securo45z554mw7rgrt7wcgv5eenj2xmxyrsdj3fcjsvindu63s4bsid.onion”, “country”: “US”, “data_size”: null, “description”: “Status: AWAITING\nSize: 1135 GB”, “discovered”: “2026-09-18T15:45:39.091519+00:00”, “domain”: “www.prefix.com”, “group”: “securotrop”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/803e55e296e455f81d0ab9e71f8387ab.png”, “url”: “https:\/\/www.ransomware.live\/id\/UHJlZml4IENvcnBAc2VjdXJvdHJvcA==”, “victim”: “Prefix Corp” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-18T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Anderson Industries is a cutting-edge engineering and manufacturing company that assists forwar\nd-thinking businesses in bringing innovative products to market. They offer a range of products\nincluding agricultural equipment, trailers, and foundry services.\n\nWe will upload 9gb of corporate data soon. Employee personal information, client information, l\nots of projects, specifications, orders, financials, NDAs and so on.\n”, “discovered”: “2026-09-18T13:24:19.257383+00:00”, “domain”: “anderson-industries.com”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QW5kZXJzb24gSW5kdXN0cmllc0Bha2lyYQ==”, “victim”: “Anderson Industries” }, { “activity”: “Education”, “attackdate”: “2026-09-17T23:58:10+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/universitt-hamburg”, “country”: “DE”, “data_size”: null, “description”: “Universit\u00e4t Hamburg is the largest research and educational institution in Northern Germany, with over 42,000 students. It offers a wide range of academic programs and is recognized for its excellence in research and teaching. The university serves diverse target groups including prospective students, current students, researchers, and alumni. It collaborates with various societal and economic partners to address contemporary challenges and contribute to future solutions.”, “discovered”: “2026-09-18T00:23:38.112427+00:00”, “domain”: “uni-hamburg.de”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2e92305cf48a74a8c3daf76abd722aa6.png”, “url”: “https:\/\/www.ransomware.live\/id\/VW5pdmVyc2l0dCBIYW1idXJnQFBhbnplcg==”, “victim”: “Universitt Hamburg” }, { “activity”: “Not Found”, “attackdate”: “2026-09-17T22:54:42.863987+00:00”, “claim_url”: “https:\/\/business-data-leaks.com\/about#7de782357297de659a1cfae28”, “country”: “”, “data_size”: null, “description”: “Redacted entry – full company name pending disclosure (FULL DATA TIMER active).”, “discovered”: “2026-09-17T22:54:46.483222+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Qy4uLkBTaWxlbnRSYW5zb21Hcm91cA==”, “victim”: “C…” }, { “activity”: “Not Found”, “attackdate”: “2026-09-17T22:31:36.567511+00:00”, “claim_url”: “http:\/\/krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion\/blog\/c2efa8a9d5b87b9220c068fd828ef1de123ade488796a1cc3c71a0c47aa83cc3\/”, “country”: “TR”, “data_size”: null, “description”: “Harput Yap\u0131 is an Istanbul-based residential real estate developer and construction company operating under the legal n…”, “discovered”: “2026-09-17T22:31:56.163903+00:00”, “domain”: “www.harputyapi.com”, “group”: “krybit”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3f9de9392d8c320267bedd8d9136ab4f.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LmhhcnB1dHlhcGkuY29tQGtyeWJpdA==”, “victim”: “www.harputyapi.com” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-17T22:30:58.472020+00:00”, “claim_url”: “http:\/\/krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion\/blog\/de7e0d4866fbf62b75c43232d4fe7b1b027939b6c70eec209729816d09f88f64\/”, “country”: “DE”, “data_size”: null, “description”: “Diakoniewerk Apolda gGmbH is a German non-profit social welfare organization (gemeinn\u00fctzige GmbH) founded in 2006, head…”, “discovered”: “2026-09-17T22:31:17.184459+00:00”, “domain”: “www.diakonie-apolda.de”, “group”: “krybit”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/85e33dfd72862cafa33bb59bca3d2ea5.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LmRpYWtvbmllLWFwb2xkYS5kZUBrcnliaXQ=”, “victim”: “www.diakonie-apolda.de” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T20:58:17.051722+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=17c492a1-01f4-417a-a5b2-054009087ccb”, “country”: “DE”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-17T20:58:39.918548+00:00”, “domain”: “www.vigatec.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/31d2e9a55a31a0164a5c37bcd4531619.png”, “url”: “https:\/\/www.ransomware.live\/id\/VmlnYXRlY0BxaWxpbg==”, “victim”: “Vigatec” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T19:03:02.920495+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=b134bc7a-1f8f-4ef3-8397-df4f5fc37d50”, “country”: “”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-17T19:03:55.192442+00:00”, “domain”: ” www.invinciblegg.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b670327272a2967edbaeec82085150bd.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW52aW5jaWJsZSBHR0BxaWxpbg==”, “victim”: “Invincible GG” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-17T16:25:30.619483+00:00”, “claim_url”: “http:\/\/hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion\/post\/mFUAsV9Nk0iS2j0zwsyTIswYOdzplru9”, “country”: “US”, “data_size”: null, “description”: “Express Employment Professionals \u2014 Data Breach Notification & Public Disclosure\n\nWe have officially initiated the public release phase regarding expresspros.com.\n\nDespite our direct attempts to establish communication, company leadership and their representatives have chosen a strategy of silence\u2026”, “discovered”: “2026-09-17T16:25:49.137734+00:00”, “domain”: “expresspros.com”, “group”: “chaos”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e82248c85b0413bef834248e84495f19.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZXhwcmVzc3Byb3MuY29tQGNoYW9z”, “victim”: “expresspros.com” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-17T16:21:00.676622+00:00”, “claim_url”: “http:\/\/vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion\/n\/hoyletanner-com”, “country”: “GB”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-09-17T16:21:16.157857+00:00”, “domain”: “hoyletanner.com”, “group”: “BrainCipher”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c4700684775d8cdb3370640650d330ac.png”, “url”: “https:\/\/www.ransomware.live\/id\/aG95bGV0YW5uZXIuY29tQEJyYWluQ2lwaGVy”, “victim”: “hoyletanner.com” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-17T16:20:21.575723+00:00”, “claim_url”: “http:\/\/vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion\/n\/aecom-com”, “country”: “US”, “data_size”: null, “description”: “[AI generated] AECOM is a global infrastructure and engineering firm headquartered in the United States. The company provides design, consulting, construction, and management services across sectors including transportation, water, environment, energy, and government facilities. Operating in over 150 countries, AECOM serves public and private clients worldwide and is recognized as one of the largest engineering services firms globally.”, “discovered”: “2026-09-17T16:20:40.449862+00:00”, “domain”: “aecom.com”, “group”: “BrainCipher”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f63ab3013cc127108dd6d5a4b028db52.png”, “url”: “https:\/\/www.ransomware.live\/id\/YWVjb20uY29tQEJyYWluQ2lwaGVy”, “victim”: “aecom.com” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T16:02:45.609722+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=cb9f4dc6-aaa4-4f2e-bd06-1ed0bcadf0c5”, “country”: “AR”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-17T16:03:05.744131+00:00”, “domain”: “www.techwise.com.ar”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5db1c28741d959d9760776c5532aa633.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGVjaHdpc2VAcWlsaW4=”, “victim”: “Techwise” }, { “activity”: “Hospitality”, “attackdate”: “2026-09-17T16:02:00.647951+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=3343be57-81f3-4d30-9288-164ff3e08a4c”, “country”: “ES”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-17T16:02:26.222726+00:00”, “domain”: “www.granhotelingles.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/69372cd42c5efd51c2898e0afaf753a0.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIEdyYW4gSG90ZWwgSW5nbGVzQHFpbGlu”, “victim”: “The Gran Hotel Ingles” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T15:20:51.637758+00:00”, “claim_url”: “http:\/\/vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion\/n\/xpera-ca”, “country”: “CA”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-09-17T15:21:08.683727+00:00”, “domain”: “xpera.ca”, “group”: “BrainCipher”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c12019ca85614f5b5414970c207c6a21.png”, “url”: “https:\/\/www.ransomware.live\/id\/eHBlcmEuY2FAQnJhaW5DaXBoZXI=”, “victim”: “xpera.ca” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-17T13:05:47.981785+00:00”, “claim_url”: “https:\/\/metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion\/0AFC:69dede1fde2d2b15c8c0684c2cec2c0b9ffa5cc58029dcdb4bdcc3ba58e4c4ba\/0AFC:3b502590e85a6459a5c8ca953c9b95b6e07aa7bab527f481177c7c4ee1b89814”, “country”: “US”, “data_size”: null, “description”: “Beckman Coulter Diagnostics is a leading U.S.-based medical diagnostics company and a Danaher company. It develops and manufactures clinical laboratory instruments, diagnostic systems, and testing solutions used by hospitals, laboratories, and healthcare providers worldwide. The company\u2019s technologies support areas such as hematology, immunoassay, clinical chemistry, microbiology, and laboratory automation.”, “discovered”: “2026-09-17T13:06:14.342679+00:00”, “domain”: “www.beckmancoulter.com”, “group”: “metaencryptor”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/bee3005a113720ec4ee9247dfb9330c8.png”, “url”: “https:\/\/www.ransomware.live\/id\/QmVja21hbiBDb3VsdGVyLCBJbmNAbWV0YWVuY3J5cHRvcg==”, “victim”: “Beckman Coulter, Inc” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-17T13:05:05.376194+00:00”, “claim_url”: “https:\/\/metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion\/0AFC:f59088f2478cb682d8411fe9c50d0b587bb1b418afffb1f1447b95f0ebf69cef\/0AFC:bfd01c503339b09aa9c70b64d042ae29ee8a1503f6dc41e58d4dc3ab0664a9a6”, “country”: “US”, “data_size”: null, “description”: “AECOM is a leading U.S.-based global infrastructure consulting and engineering company. It provides design, engineering, construction management, and advisory services for major infrastructure projects across transportation, water, energy, buildings, environmental services, and government markets. AECOM operates worldwide and serves public- and private-sector clients.”, “discovered”: “2026-09-17T13:05:28.259842+00:00”, “domain”: “aecom.com”, “group”: “metaencryptor”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1e7ecb18453d1bf6e3f5c5ed43242028.png”, “url”: “https:\/\/www.ransomware.live\/id\/QUVDT01AbWV0YWVuY3J5cHRvcg==”, “victim”: “AECOM” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T13:04:12.239237+00:00”, “claim_url”: “https:\/\/metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion\/0AFC:d1d156018a59719bc6c26d946e39dea988d372074374fdc9182e0f8ee4a937c0\/0AFC:94a9c567c8a08d157fa138690c663634fde5134819f8cc7c9347c78a2e12eba1291b6caa210deb0751fdb30d2d98d20e”, “country”: “US”, “data_size”: null, “description”: “ProMantra is a U.S.-based healthcare technology and business process services company specializing in Revenue Cycle Management (RCM), medical billing, healthcare data processing, and automation. Founded in 2003, the company provides technology-enabled services designed to help healthcare providers manage the financial and administrative processes associated with patient care”, “discovered”: “2026-09-17T13:04:44.711719+00:00”, “domain”: “promantra.us”, “group”: “metaencryptor”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UHJvbWFudHJhLCBJbmNAbWV0YWVuY3J5cHRvcg==”, “victim”: “Promantra, Inc” }, { “activity”: “Education”, “attackdate”: “2026-09-17T08:51:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/westbridge-institute-of-technology-inc\/”, “country”: “”, “data_size”: null, “description”: “Full Employee Information\nFull Students Information\nFull Guardians Information [Size: 102.0 MB | Sector: Education]”, “discovered”: “2026-09-17T09:20:37.646173+00:00”, “domain”: “”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/7a5dc57b093bf01e6abf006f41a658bf.png”, “url”: “https:\/\/www.ransomware.live\/id\/V2VzdGJyaWRnZSBJbnN0aXR1dGUgb2YgVGVjaG5vbG9neSwgSW5jLkBlbXBlcmFkb3I=”, “victim”: “Westbridge Institute of Technology, Inc.” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-09-17T07:15:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6aab92029cd108bf2638c39c”, “country”: “AR”, “data_size”: null, “description”: “Diarco is a company that operates in the HR & Staffing industry. It employs 1000to4999 people and has 1Gto5G of revenue. The company is headquartered in San Telmo, Capital Federal, Argentina.”, “discovered”: “2026-09-17T07:24:58.489284+00:00”, “domain”: “www.diarco.com.ar”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ff96c8f32f2cde22f00af73326ffc8a7.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LmRpYXJjby5jb20uYXJAaW5jcmFuc29t”, “victim”: “www.diarco.com.ar” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-17T07:00:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6aab8c5b9cd108bf2637fece”, “country”: “US”, “data_size”: null, “description”: “Appliance Factory & Mattress Kingdom offers a wide range of discount appliances and mattresses, providing unbeatable savings to customers across multiple locations including Colorado, Kentucky, Wyoming, and Indiana. Their extensive product lineup includes kitchen appliances, laundry machines, refrigeration units, and various mattress types from well-known brands. The company emphasizes next-day delivery, professional installation, and financing options to enhance customer convenience. Targeting homeowners and trade partners, they pride themselves on excellent service and a hassle-free shopping experience.”, “discovered”: “2026-09-17T07:25:33.093862+00:00”, “domain”: “www.appliancefactory.com”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e9beb4c39472d4ff6512335799299247.png”, “url”: “https:\/\/www.ransomware.live\/id\/d3d3LmFwcGxpYW5jZWZhY3RvcnkuY29tQGluY3JhbnNvbQ==”, “victim”: “www.appliancefactory.com” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-09-17T01:36:11+00:00”, “claim_url”: “”, “country”: “IT”, “data_size”: null, “description”: “stpfashionlab.it is the website of STP Fashion Lab, a Tuscan company that has specialized in making Made in Italy womenswear for over twenty years. It produces the FRIVOLIT\u00c9 brand, founded in 2019, which targets independent, sensitive, and playful women.”, “discovered”: “2026-09-17T09:51:37.319780+00:00”, “domain”: “stpfashionlab.it”, “group”: “Vexy Ransomware”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/U1RQIEZhc2hpb24gTGFiQFZleHkgUmFuc29td2FyZQ==”, “victim”: “STP Fashion Lab” }, { “activity”: “Not Found”, “attackdate”: “2026-09-17T01:28:51.543724+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “Processing publication of this company unless they start negotiating appropriately. Deadline: 18 Sep 2026 | Updated: 17 Sep 2026 | Warning: FINAL WARNING”, “discovered”: “2026-09-17T01:28:52.351958+00:00”, “domain”: “”, “group”: “shinyhunters”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UWkqKioqQHNoaW55aHVudGVycw==”, “victim”: “Qi****” }, { “activity”: “Professional Services”, “attackdate”: “2026-09-17T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Practice Management specializes in providing comprehensive medical billing and revenue cycle ma\nnagement services tailored for healthcare organizations, particularly Federally Qualified Healt\nh Centers (FQHCs).\n\nWe will upload 43gb of corporate data soon. Detailed employee personal information (NAME, addre\nss, phone, email), client information (name, IDs and medical information), projects and so on.\n”, “discovered”: “2026-09-17T13:52:14.523659+00:00”, “domain”: “maximizedrevenue.com”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UHJhY3RpY2UgTWFuYWdlbWVudCAobWF4aW1pemVkcmV2ZW51ZS5jb20pQGFraXJh”, “victim”: “Practice Management (maximizedrevenue.com)” }, { “activity”: “Technology”, “attackdate”: “2026-09-17T00:00:00+00:00”, “claim_url”: “”, “country”: “BR”, “data_size”: null, “description”: “Vetta Digital Servi\u00e7os specializes in providing integrated digital solutions focused on energy \nmanagement and sustainability for industrial operations. Their offerings include advanced softw\nare technologies, industrial automation projects, and data infrastructure optimization aimed at\nreducing carbon footprints and energy costs.\n\nWe will upload corporate data soon. Internal files, a bit of corporate docs, clients, projects.\n”, “discovered”: “2026-09-17T13:24:13.577335+00:00”, “domain”: “vetta.digital”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VmV0dGFAYWtpcmE=”, “victim”: “Vetta” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-09-17T00:00:00+00:00”, “claim_url”: “”, “country”: “BR”, “data_size”: null, “description”: “Javep Chevrolet makes buying a car simple and easy. They help customers find their perfect vehi\ncle through a complete online experience. From first contact to final delivery, everything happ\nens right from home.\n\nWe will upload 16gb of corporate data soon. Detailed employee personal information (passport nu\nmber, NAME, address, phone, email address and so on), projects, clients information, Chevrolet \nagreements and so on.\n”, “discovered”: “2026-09-17T13:23:54.271641+00:00”, “domain”: “javepchevrolet.com.br”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/SmF2ZXAgQ2hldnJvbGV0QGFraXJh”, “victim”: “Javep Chevrolet” }, { “activity”: “Other”, “attackdate”: “2026-09-16T21:52:54.960881+00:00”, “claim_url”: “https:\/\/mega.nz\/figureitout”, “country”: “US”, “data_size”: null, “description”: “We have locked out The manager and staff. Time to negotiate now we are extending the day to September 22 2026 at 3:00pm to get it figured out. What we have is real.\n\nvillaslitchfieldmgr@greystar.com\nvillaslitchfieldmnt@greystar.com\n\nEveryone is locked out and we possess the data below\n\n- Physical-to-Digital Key Maps (Reports)\n- Property Intelligence & Vulnerability Logs (HandyTrac Key Control.pdf)\n- Employee Identity & Credential Data (Employees)\n- Financial & Vendor Records (Open_and_closed_Invoices)\n- Administrative Portal Control (Dashboard \/ Administration)\n\nThis is not a joke or a bluff it’s a sign of a corporate disaster.\n\nproof of lockout: http:\/\/sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion\/locked_out.jpg\n\nwe turned off all those and deleted it.\n\nurl: http:\/\/sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion\/everyones_lockedout.png\n\nno on that new one it doesn’t show Website Logins now everyone is locked out. Read the emails ceo, privacy email, and manager and staff that we sent you a week ago.”, “discovered”: “2026-09-16T21:53:11.343671+00:00”, “domain”: “new.handytrac.com”, “group”: “ShadowByt3$”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5acd5db6df9f20f498252241f798169a.png”, “url”: “https:\/\/www.ransomware.live\/id\/SGFuZHlUcmFjIEdyZXlzdGFyIEFaIFdBUk5JTkdAU2hhZG93Qnl0MyQ=”, “victim”: “HandyTrac Greystar AZ WARNING” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-16T20:26:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/rda-motors-spa\/”, “country”: “IT”, “data_size”: null, “description”: “is an Italian company engaged in premium cars. There are many customer documents and employee data [Size: 7.3 GB | Sector: Technology, Other]”, “discovered”: “2026-09-16T20:50:58.426399+00:00”, “domain”: “rda-stellantis.it”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/50858e8ea313ad0692366423611f1031.png”, “url”: “https:\/\/www.ransomware.live\/id\/UkRBIE1PVE9SUyBTLlAuQS5AZW1wZXJhZG9y”, “victim”: “RDA MOTORS S.P.A.” }, { “activity”: “Financial Services”, “attackdate”: “2026-09-16T19:41:31+00:00”, “claim_url”: “http:\/\/ctyfftrjgtwdjzlgqh4avbd35sqrs6tde4oyam2ufbjch6oqpqtkdtid.onion\/d7ba2a3f-0d92-4bc9-b30d-6f0edbeaf54b”, “country”: “”, “data_size”: null, “description”: “Industry: Finance Lending & BrokerageLocation: USA Data Volume: 9.3TBData Description: Financials, HR, Clients\u2019 Private Data & Financial Details, PII & PHI Records, Mailboxes & Email Correspondence, Database Exports, OneDrive StoredDownload:Link 1http:\/\/wu22mxmkgd4hgs7j3x7aqurgzhwzy3gf5qpwngpobpnet4i6myebutyd.onion\/optimumfirst.comLink 2http:\/\/zvacnemrrluposfmwgp4bqvb34ipoorgh7yyqoozu6gcmh5z32wjgsad.onion\/optimumfirst.comOptimum First Mortgage provides mortgage solutions, including:Home purchase loansRefinancing optionsThey operate as a wholesale lender in the United States, helping clients secure home loans and restructure their debts. The company specializes in real estate financial services.”, “discovered”: “2026-09-16T19:54:07.070553+00:00”, “domain”: “”, “group”: “blacknevas”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d9d8b3f0a648cdd61667fa6b2af4634b.png”, “url”: “https:\/\/www.ransomware.live\/id\/T3B0aW11bSBGaXJzdCBNb3J0Z2FnZSAoUGVhcidzIGFjdGluZyBncm91cCdzIHByb21vdGlvbmFsIGJsb2cpQGJsYWNrbmV2YXM=”, “victim”: “Optimum First Mortgage (Pear’s acting group’s promotional blog)” }, { “activity”: “Not Found”, “attackdate”: “2026-09-16T17:48:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/sevenoaks-sro\/”, “country”: “CZ”, “data_size”: null, “description”: “Sevenoaks, S.R.O. is an enterprise based in Czech Republic.\n Its main office is in Prague. \nThe company operates in the Computer Systems Design and Related Services industry. [Size: 3.3 GB | Sector: Technology, Other]”, “discovered”: “2026-09-16T18:54:25.922000+00:00”, “domain”: “7oaks.cz”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/89ddd071dc5042151a624e34d601e7c9.png”, “url”: “https:\/\/www.ransomware.live\/id\/U0VWRU5PQUtTIHMuci5vLkBlbXBlcmFkb3I=”, “victim”: “SEVENOAKS s.r.o.” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-16T17:21:00+00:00”, “claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/46963a87c3396e773aa56818c0faa510”, “country”: “DE”, “data_size”: null, “description”: “yGear specializes in providing reliable and affordable on-site and on-demand hydrogen and industrial…”, “discovered”: “2026-09-18T21:49:22.248691+00:00”, “domain”: “hygear.com”, “group”: “lockbit5”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3c0939ac526e7a0955765958c4eb6e1c.png”, “url”: “https:\/\/www.ransomware.live\/id\/aHlnZWFyLmNvbUBsb2NrYml0NQ==”, “victim”: “hygear.com” }, { “activity”: “Not Found”, “attackdate”: “2026-09-16T17:02:35.837644+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=c394bf70-d7e3-4abc-a1ee-75daf9e0992c”, “country”: “AU”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-16T17:02:52.900583+00:00”, “domain”: “www.reddrop.com.au”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/97f87027600d0574ffbddbd697df2d2c.png”, “url”: “https:\/\/www.ransomware.live\/id\/UmVkZHJvcCBHcm91cEBxaWxpbg==”, “victim”: “Reddrop Group” }, { “activity”: “Other”, “attackdate”: “2026-09-16T17:02:03.657438+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=ec979c95-ef83-4795-bd28-0f493f2488ca”, “country”: “CA”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-16T17:02:23.386174+00:00”, “domain”: “www.inthecompanyofhuskies.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/47280a6f3315c7a58d14ae5f0bbbdab9.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW4gVGhlIENvbXBhbnkgb2YgSHVza2llc0BxaWxpbg==”, “victim”: “In The Company of Huskies” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-16T16:00:05+00:00”, “claim_url”: “”, “country”: “IR”, “data_size”: null, “description”: “Roshd Sanat is an Iranian industrial company providing engineering, manufacturing, and technical services, with a focus on industrial and energy-sector projects.”, “discovered”: “2026-09-16T16:22:09.883088+00:00”, “domain”: “”, “group”: “Wallstreet”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Um9zaGQgU2FuYXRAV2FsbHN0cmVldA==”, “victim”: “Roshd Sanat” }, { “activity”: “Education”, “attackdate”: “2026-09-16T15:59:02+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Odyssey Charter School, Inc. is a nonprofit organization operating tuition-free public charter schools in Florida for students from preschool through 12th grade, with a focus on academic achievement and whole-child development.”, “discovered”: “2026-09-16T16:22:21.437082+00:00”, “domain”: “”, “group”: “Wallstreet”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/T2R5c3NleSBDaGFydGVyIFNjaG9vbCwgSW5jLkBXYWxsc3RyZWV0”, “victim”: “Odyssey Charter School, Inc.” }, { “activity”: “Other”, “attackdate”: “2026-09-16T15:05:39.086964+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=37d18455-0338-497c-a8dd-0897783de757”, “country”: “AU”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-16T15:05:57.178270+00:00”, “domain”: “www.thorndale.com.au”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ae5755a2c6be7916fa69ff9b90fc0a90.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhvcm5kYWxlIEZvdW5kYXRpb25AcWlsaW4=”, “victim”: “Thorndale Foundation” }, { “activity”: “Government & Defense”, “attackdate”: “2026-09-16T13:12:17+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=809”, “country”: “”, “data_size”: null, “description”: “Arda.or.th\u2014The Agricultural Research Development Agency (Public Organization) serves as a Deadline: 2026-09-23 13:09:00.000000”, “discovered”: “2026-09-16T13:53:57.333588+00:00”, “domain”: “”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f9969d01f2ea0922baca116ead0de0af.png”, “url”: “https:\/\/www.ransomware.live\/id\/QVJEQUBhcmN1c21lZGlh”, “victim”: “ARDA” }, { “activity”: “Other”, “attackdate”: “2026-09-16T12:55:17+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/nielsen-design”, “country”: “”, “data_size”: null, “description”: “Helmar Nielsen dreamed of a frame that was accessible, precise, and above all, industrially reproducible, without sacrificing elegance. This was the birth of a concept that, a few years later, would forever change the perception of framing.”, “discovered”: “2026-09-16T13:22:39.132189+00:00”, “domain”: “”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1353057f8888d31b4ea7fae81b148772.png”, “url”: “https:\/\/www.ransomware.live\/id\/TmllbHNlbiBEZXNpZ25AUGFuemVy”, “victim”: “Nielsen Design” }, { “activity”: “Manufacturing”, “attackdate”: “2026-09-16T04:00:41.272162+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=6670e26d-3391-43e8-bcb6-f00c2ba10bc7”, “country”: “SE”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-09-16T04:01:03.907051+00:00”, “domain”: “www.aarsleff.se”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/36adf15f0acef57b82df3e597fc67a46.png”, “url”: “https:\/\/www.ransomware.live\/id\/QWFyc2xlZmZAcWlsaW4=”, “victim”: “Aarsleff” }, { “activity”: “Healthcare”, “attackdate”: “2026-09-16T03:53:35.671558+00:00”, “claim_url”: “http:\/\/xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion\/blog\/?post_uuid=2be33b50-70f7-4151-8b86-b60b31e5e1ba”, “country”: “GB”, “data_size”: null, “description”: “Full DATA 400 GB+\n\nThe brain uses the eyes to gather information about our surroundings. The brain cannot process all our view so it must first decide what to look for. The eyes-brain system then has to select that information, usually by shifting eye position and often by shifting focus. How the eyes-brain go through this process is the real test of visual efficiency. \n\nHere at Owen Leigh Optometry, we specialise in helping patients of all ages to develop flexibility in their vision to meet all their needs and interests. We start this by observing and measuring your eye-brain system with a wide range of visual challenges. \n\nEye health and eyesight are important, but this must not be the end point of developing good vision. We want to take you much further than that, to explore ways that you can see more, feel more, move better, plan better and understand quicker. \n\n\u200b\n\nWe use ‘visual efficiency glasses’, vision exercises (vision therapy) and ‘training\/learning lenses’ to help you develop your own vision. We add visual hygiene, consider coloured lenses and refer to other disciplines if that will help you meet your goals.\n\n \n\n\u201cWhat we see is dependant upon what we are looking for and what we managed to see last time.\u201d”, “discovered”: “2026-09-16T03:54:08.705686+00:00”, “domain”: “owenleighoptometry.co.uk”, “group”: “dragonforce”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/309ff6f687de6532ccdb144d0f0f6a44.png”, “url”: “https:\/\/www.ransomware.live\/id\/T3dlbiBMZWlnaCBPcHRvbWV0cnlAZHJhZ29uZm9yY2U=”, “victim”: “Owen Leigh Optometry” }, { “activity”: “Other”, “attackdate”: “2026-09-16T03:49:20.010594+00:00”, “claim_url”: “http:\/\/xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion\/blog\/?post_uuid=dbdc4732-e361-4834-a8bf-52778bae559f”, “country”: “US”, “data_size”: null, “description”: “full data 200 GB+ \n\nWe have been in business since 1978 as a management firm specializing in the management of common interest developments including condominiums and planned unit developments.\n\nCPM rapidly evolved into one of the premier association management firms in the industry and is on the forefront of innovative and specialized services. Our reputation for attentiveness to the needs of each association is one of which Community Property Management is very proud.\n\nOur dedication to excellence and our staffs skills and professionalism have become the trademark at Community Property Management. Management level personnel attend courses offered through Community Associations Institute, a national organization of community association, and California Association of Community Managers. CPM has also earned its Accredited Management Organization designation with IREM, and Certified Property Manager from CAI, the industries highest designation.\n\nWe are responsive and dedicated to our Associations and their unique service requirements. We have found, over the years that association needs are constantly changing. Therefore, we analyze and formulate objective plans for the guidance and support of the Association through its Board Members.\n\nOur company has developed expertise in all areas of association management and keeps Board Members updated on law changes. We stand ready to assist you with all your Associations requirements.”, “discovered”: “2026-09-16T03:55:01.189986+00:00”, “domain”: “cpm1.com”, “group”: “dragonforce”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9454f01de383ca12d3bdf5436901426d.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q29tbXVuaXR5IFByb3BlcnR5IE1hbmFnZW1lbnRAZHJhZ29uZm9yY2U=”, “victim”: “Community Property Management” } ]