{ “groups”: 391, “victims”: 31099 }
[ { “activity”: “Technology”, “attackdate”: “2026-08-23T02:27:34.498343+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “This time the post is about you , not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided \”as is\” for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us. | Updated: 23 Aug 2026″, “discovered”: “2026-08-23T02:27:36.597005+00:00”, “domain”: “reliaquest.com”, “group”: “shinyhunters”, “infostealer”: { “employees”: 1, “employees_url”: 1, “infostealer_stats”: { “Raccoon”: 1 }, “last_employee_compromised”: “1980-12-08T09:34:52+00:00”, “last_user_compromised”: “1970-01-01T00:00:00+00:00”, “thirdparties”: 8, “update”: “2026-08-23T06:24:22.386241”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UmVsaWFRdWVzdCwgTExDQHNoaW55aHVudGVycw==”, “victim”: “ReliaQuest, LLC” }, { “activity”: “Other”, “attackdate”: “2026-08-22T22:22:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6a8979d59cd108bf26069fa7”, “country”: “CH”, “data_size”: null, “description”: “Unauthorized access has been gained to the company’s confidential files, including client data, proprietary R&D, and financial documentation.”, “discovered”: “2026-08-22T22:54:30.808147+00:00”, “domain”: “el-group.ch”, “group”: “incransom”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-23T06:24:37.557797”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3dcaa6cac94750125ca258310b8d6a1f.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZWwtZ3JvdXBAaW5jcmFuc29t”, “victim”: “el-group” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-22T19:21:15.313576+00:00”, “claim_url”: “http:\/\/helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion\/p\/05d7e14bd3e7d7efce2406aad744dc6daa15edfbca7d38cb8ced622125d3c989”, “country”: “US”, “data_size”: null, “description”: “AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier.”, “discovered”: “2026-08-22T19:21:33.550146+00:00”, “domain”: “amspecgroup.com”, “group”: “Helix”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 82, “update”: “2026-08-23T06:26:14.595724”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5db9096708326ebbd3d1f0788ad11ab5.png”, “url”: “https:\/\/www.ransomware.live\/id\/QW1TcGVjQEhlbGl4”, “victim”: “AmSpec” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-22T15:32:00+00:00”, “claim_url”: “\/post\/vietnam-electricityevnhanoi\/”, “country”: “VN”, “data_size”: null, “description”: “Vietnam Electricity (EVN), legally known as T\u1eadp \u0111o\u00e0n \u0110i\u1ec7n l\u1ef1c Vi\u1ec7t Nam, is the largest power company and the sole national electric utility in Vietnam. Fully owned and controlled by the Vietnamese government since its inception in 1994, EVN operates as a vertically integrated monopoly responsible for the nationwide generation, transmission, and distribution of electricity, as well as international power exchanges. The group oversees all major power plants and regional distribution subsidiaries, including EVNHANOI. Serving as a crucial pillar for Vietnam’s macroeconomic stability and industrial expansion, EVN is currently undertaking extensive grid digitalization and spearheading the national transition from coal dependency toward clean and renewable energy integration.\n\nThe data content exceeds 300GB, comprising 13.36 million rows of customer details, 6.99 million subscriptions, 2.26 million account records, and other miscellaneous data.The price is open to negotiation.\n\nSession:054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608\nTox:852E34CBEBA2D40FD21BAC9F9E588B5194DBA9F31CACF9ECE316403120BE18765D22A8A453C4 [Size: 300.0 GB | Sector: Government, Energy]”, “discovered”: “2026-08-22T16:20:45.961955+00:00”, “domain”: “evn.com.vn”, “group”: “emperador”, “infostealer”: { “employees”: 1201, “employees_url”: 100, “infostealer_stats”: { “Acreed”: 36, “Atomic”: 1, “Azorult”: 13, “CRYPTBOT”: 5, “Ficker”: 4, “Generic Stealer”: 561, “KPOT”: 1, “Lumma”: 555, “Mystic”: 4, “Predator”: 5, “Raccoon”: 146, “RedLine”: 1361, “Remus”: 3, “StealC”: 115, “UNKNOWN”: 22, “Vidar”: 100 }, “last_employee_compromised”: “2026-07-30T12:22:49.025000+00:00”, “last_user_compromised”: “2026-08-08T09:58:21+00:00”, “thirdparties”: 50, “update”: “2026-08-23T06:25:25.462936”, “users”: 1809, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VmlldG5hbSBFbGVjdHJpY2l0eShFVk5IQU5PSSlAZW1wZXJhZG9y”, “victim”: “Vietnam Electricity(EVNHANOI)” }, { “activity”: “Healthcare”, “attackdate”: “2026-08-22T14:01:02.987228+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/ihs911”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-22T14:01:24.687171+00:00”, “domain”: “ihs911.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 2, “employees_url”: 2, “infostealer_stats”: { “Azorult”: 2 }, “last_employee_compromised”: “2020-08-29T13:36:02+00:00”, “last_user_compromised”: “2019-01-11T00:00:00+00:00”, “thirdparties”: 5, “update”: “2026-08-22T14:02:59.607830”, “users”: 0, “users_url”: 1 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9c28127e9efdb548b61b4f2c530a61ec.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW50ZWdyYXRlZCBIZWFsdGggU3lzdGVtc0Bjb2luYmFzZWNhcnRlbA==”, “victim”: “Integrated Health Systems” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T13:59:38.309317+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/tower-co-nz”, “country”: “NZ”, “data_size”: null, “description”: “[AI generated] Tower Insurance is a New Zealand-based insurance company offering a range of personal and business insurance products, including home, contents, car, travel, and commercial coverage. Founded in 1869, it operates primarily in New Zealand and the Pacific Islands. Tower is listed on the New Zealand Stock Exchange and is known for its digital-first approach, providing customers with online policy management and claims services.”, “discovered”: “2026-08-22T14:00:01.113291+00:00”, “domain”: “tower.co.nz”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 4, “update”: “2026-08-22T14:02:06.329781”, “users”: 486, “users_url”: 10 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ec1f4ab9630efd8c91d6ea974888bc31.png”, “url”: “https:\/\/www.ransomware.live\/id\/VG93ZXIgSW5zdXJhbmNlQGNvaW5iYXNlY2FydGVs”, “victim”: “Tower Insurance” }, { “activity”: “Transportation”, “attackdate”: “2026-08-22T13:58:57.419152+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/flechabus”, “country”: “AR”, “data_size”: null, “description”: “[AI generated] Flecha Bus is an Argentine intercity bus company operating in the passenger transportation industry. Founded in the mid-20th century, it provides long-distance coach services connecting Buenos Aires with various provinces across Argentina. Known for offering multiple service categories including standard and premium seating options, Flecha Bus is one of the prominent operators in Argentina’s extensive national road transport network.”, “discovered”: “2026-08-22T13:59:20.157772+00:00”, “domain”: “flechabus.com.ar”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:01:55.275171”, “users”: 123, “users_url”: 11 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f193fb33a41de1ccefc3417a9f3c4749.png”, “url”: “https:\/\/www.ransomware.live\/id\/RmxlY2hhIEJ1c0Bjb2luYmFzZWNhcnRlbA==”, “victim”: “Flecha Bus” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-22T13:58:17.034411+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/oteis”, “country”: “FR”, “data_size”: null, “description”: “[AI generated] OTEIS Conseil & Ing\u00e9nierie is a French engineering and consulting firm specializing in building and infrastructure design. Operating in France, the company provides technical expertise across disciplines including structural engineering, fluids, electricity, and project management. It serves sectors such as real estate, public works, and urban development, supporting both public and private clients throughout project lifecycle phases.”, “discovered”: “2026-08-22T13:58:39.310188+00:00”, “domain”: “oteis.fr”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 8, “employees_url”: 5, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 10, “update”: “2026-08-22T14:04:40.692361”, “users”: 0, “users_url”: 2 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/83d1770b3fc421c9a81ab976781b7da4.png”, “url”: “https:\/\/www.ransomware.live\/id\/T1RFSVMgQ29uc2VpbCAmIEluZ8OpbmllcmllQGNvaW5iYXNlY2FydGVs”, “victim”: “OTEIS Conseil & Ing\u00e9nierie” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T13:57:29.731521+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/longhorninvestments”, “country”: “”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-22T13:57:58.968347+00:00”, “domain”: “longhorninvestments.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-22T14:01:43.518485”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ccbb1537f80e2f32c162e6a4636b0195.png”, “url”: “https:\/\/www.ransomware.live\/id\/TG9uZ2hvcm4gSW52ZXN0bWVudHNAY29pbmJhc2VjYXJ0ZWw=”, “victim”: “Longhorn Investments” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-22T13:56:50.512212+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/kesslercreative”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-22T13:57:11.643234+00:00”, “domain”: “kesslercreative.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 1, “employees_url”: 1, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-22T14:05:00.172751”, “users”: 0, “users_url”: 3 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0b8c376fa73b189211c4293d8018a81b.png”, “url”: “https:\/\/www.ransomware.live\/id\/S2Vzc2xlciBDcmVhdGl2ZUBjb2luYmFzZWNhcnRlbA==”, “victim”: “Kessler Creative” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-22T13:56:05.465051+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/klaskolaw”, “country”: “US”, “data_size”: null, “description”: “[AI generated] Klasko Immigration Law Partners is a US-based immigration law firm headquartered in Philadelphia, Pennsylvania. The firm specializes in business immigration law, assisting corporations and individuals with employment-based visas, green cards, and compliance matters. It serves multinational companies, healthcare organizations, and academic institutions, providing legal counsel on navigating US immigration regulations and workforce mobility challenges.”, “discovered”: “2026-08-22T13:56:32.313882+00:00”, “domain”: “klaskolaw.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:01:33.988862”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b34d1e3a6eacc0da162889648816e839.png”, “url”: “https:\/\/www.ransomware.live\/id\/S2xhc2tvIEltbWlncmF0aW9uIExhdyBQYXJ0bmVyc0Bjb2luYmFzZWNhcnRlbA==”, “victim”: “Klasko Immigration Law Partners” }, { “activity”: “Not Found”, “attackdate”: “2026-08-22T13:55:13.734254+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/patelcpaoffice”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A\n\nThe name \”Patel\” is too generic to identify a specific company with reliable information. It is a common surname and business name used by numerous unrelated entities across many industries and countries. Please provide additional context such as the full company name, industry, or country to allow for an accurate description.”, “discovered”: “2026-08-22T13:55:47.269575+00:00”, “domain”: “patelcpaoffice.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:05:47.727395”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c670ec1823d5298521fa578273cb66f2.png”, “url”: “https:\/\/www.ransomware.live\/id\/UGF0ZWxAY29pbmJhc2VjYXJ0ZWw=”, “victim”: “Patel” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T13:54:34.473455+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/abacusadv”, “country”: “”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-22T13:54:55.285516+00:00”, “domain”: “abacusadv.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:01:24.938478”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f25dc50ff7770f74aad549f297c7e8d2.png”, “url”: “https:\/\/www.ransomware.live\/id\/QWJhY3VzIEFkdmlzb3JzQGNvaW5iYXNlY2FydGVs”, “victim”: “Abacus Advisors” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T13:53:52.357054+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/lifebankfoundation”, “country”: “PH”, “data_size”: null, “description”: “[AI generated] LifeBank Microfinance Foundation is a nonprofit microfinance institution operating in the Philippines. It provides financial services, including small loans, savings programs, and livelihood assistance, primarily to low-income individuals and underserved communities. The organization aims to promote financial inclusion and economic empowerment by offering accessible credit and support to micro-entrepreneurs who lack access to traditional banking services.”, “discovered”: “2026-08-22T13:54:14.699056+00:00”, “domain”: “lbf.ph”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:08:06.472733”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e5d12abe9372e3b52113bd8271b3795d.png”, “url”: “https:\/\/www.ransomware.live\/id\/TGlmZUJhbmsgTWljcm9maW5hbmNlIEZvdW5kYXRpb25AY29pbmJhc2VjYXJ0ZWw=”, “victim”: “LifeBank Microfinance Foundation” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-08-22T13:53:11.568774+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/airmancur”, “country”: “ID”, “data_size”: null, “description”: “[AI generated] PT Perusahaan Jamu Air Mancur is an Indonesian company operating in the traditional herbal medicine industry. Based in Solo, Central Java, it manufactures and distributes jamu, a traditional Indonesian herbal remedy, along with related health and wellness products. Founded in 1963, the company is one of Indonesia’s well-known herbal medicine producers, serving both domestic and export markets across Southeast Asia.”, “discovered”: “2026-08-22T13:53:34.215756+00:00”, “domain”: “”, “group”: “coinbasecartel”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/43d6abb500c6865d7d9d52a7f0ba118b.png”, “url”: “https:\/\/www.ransomware.live\/id\/UFQgUGVydXNhaGFhbiBKYW11IEFpciBNYW5jdXJAY29pbmJhc2VjYXJ0ZWw=”, “victim”: “PT Perusahaan Jamu Air Mancur” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T13:52:28.447095+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/bprbintan”, “country”: “ID”, “data_size”: null, “description”: “[AI generated] PT. Bank Perekonomian Rakyat Bintan is an Indonesian rural bank, known as a Bank Perkreditan Rakyat or BPR, operating in the Bintan regency of Riau Islands province, Indonesia. It provides basic financial services including savings, deposits, and credit facilities primarily to local communities, small businesses, and micro-enterprises. As a rural bank, it operates under supervision of the Indonesian Financial Services Authority, OJK, serving the local economy.”, “discovered”: “2026-08-22T13:52:53.314637+00:00”, “domain”: “”, “group”: “coinbasecartel”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/41e51e01cb73de43f21f32603fccd0a5.png”, “url”: “https:\/\/www.ransomware.live\/id\/UFQuIEJhbmsgUGVyZWtvbm9taWFuIFJha3lhdCBCaW50YW5AY29pbmJhc2VjYXJ0ZWw=”, “victim”: “PT. Bank Perekonomian Rakyat Bintan” }, { “activity”: “Healthcare”, “attackdate”: “2026-08-22T11:10:00+00:00”, “claim_url”: “”, “country”: “IL”, “data_size”: null, “description”: “This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK”, “discovered”: “2026-08-22T14:13:59.045511+00:00”, “domain”: “novocure.com”, “group”: “shinyhunters”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 3, “update”: “2026-08-22T14:19:00.183463”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Tm92b0N1cmUgTGltaXRlZEBzaGlueWh1bnRlcnM=”, “victim”: “NovoCure Limited” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-22T11:10:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK”, “discovered”: “2026-08-22T14:13:39.736556+00:00”, “domain”: “bokfinancial.com”, “group”: “shinyhunters”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: { “Azorult”: 5, “Raccoon”: 1, “RedLine”: 8, “Redline”: 2, “Vidar”: 1, “racoon”: 1 }, “last_employee_compromised”: “1970-01-01T00:00:00+00:00”, “last_user_compromised”: “2026-08-06T17:28:35.344000+00:00”, “thirdparties”: 0, “update”: “2026-08-22T14:18:29.110970”, “users”: 150, “users_url”: 41 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Qk9LIEZpbmFuY2lhbEBzaGlueWh1bnRlcnM=”, “victim”: “BOK Financial” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-08-22T07:59:53.426250+00:00”, “claim_url”: “http:\/\/5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion\/companies\/71\/holzmarkt-chemnitz”, “country”: “DE”, “data_size”: null, “description”: “Holzmarkt Chemnitz is a specialized retail store for building materials and wood products, operating two branches in Chemnitz (Fichtestra\u00dfe and Kalkstra\u00dfe).\u00a0They serve as a competent partner for both professional builders and private customers.-Personal information of employees and clients\u00a0-Financial documents-SQL DB https:\/\/holzmarkt-chemnitz.de\/”, “discovered”: “2026-08-22T08:00:14.089124+00:00”, “domain”: “holzmarkt-chemnitz.de”, “group”: “spacebears”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T07:59:53”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5a4b7854f8a08c7e1479782351b919a8.png”, “url”: “https:\/\/www.ransomware.live\/id\/aG9sem1hcmt0IGNoZW1uaXR6QHNwYWNlYmVhcnM=”, “victim”: “holzmarkt chemnitz” }, { “activity”: “Not Found”, “attackdate”: “2026-08-22T07:59:22.439135+00:00”, “claim_url”: “http:\/\/5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion\/companies\/72\/freelom”, “country”: “CZ”, “data_size”: null, “description”: “Freelom.net s.r.o. is a Czech internet service provider and IT company based in Lomnice nad Popelkou, which has been operating since 2009 .\u00a0The company’s primary focus is providing wireless internet access via its own network, with services available 24 hours a day, 7 days a week.The company is led by two managing directors, Ji\u0159\u00ed Plichta and Petr Mal\u00fd.\u00a0A priority for Freelom.net is the speed, reliability, and quality of its services , and it aims to resolve technical issues within a maximum of 24 hours-SQL Data (All client personal data) https:\/\/freelom.cz\/”, “discovered”: “2026-08-22T07:59:41.537374+00:00”, “domain”: “freelom.cz”, “group”: “spacebears”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T07:59:22”, “users”: 1, “users_url”: 1 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e0ebecf15a9179092fe420658c90ef16.png”, “url”: “https:\/\/www.ransomware.live\/id\/RnJlZWxvbUBzcGFjZWJlYXJz”, “victim”: “Freelom” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-22T05:55:56.903592+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=264”, “country”: “US”, “data_size”: null, “description”: “CRI Electric CRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial clients, offering services such as emergency electrical repairs, EV charger installations, and home rewiring. We are pleased to present:Employee’s federal account artifacts** (`HR-Confidential\\Israel’s Forms`): Login.gov personal recovery key (VA identity), TSP (retirement savings), ID.me, DoD DS Logon, PIEE (DoD contract payments)151 vendor W-9 forms** (SSN\/EIN), payroll docs, HR-lawyer (privileged) correspondence, OSHA-adjacent injury\/incident reports with photos.Public-sector bid pricing** (2025\ufffd2026: SAWS HQ EV charging, SAISD, NISD) \ufffd bid-competitiveness and Davis-Bacon certified-payroll context.Corporate docs (SDVOSB certification, Articles, bylaws, stock ledgers), QuickBooks financials, a Power of Attorney More”, “discovered”: “2026-08-22T05:56:26.446012+00:00”, “domain”: “crielectric.com”, “group”: “rhysida”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T05:57:39.939581”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f7c0c9ba955aee3907d5bb9d20840e89.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q1JJIEVsZWN0cmljQHJoeXNpZGE=”, “victim”: “CRI Electric” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-22T00:00:00+00:00”, “claim_url”: “http:\/\/fjg4zi4opkxkvdz7mvwp7h6goe4tcby3hhkrz43pht4j3vakhy75znyd.onion\/companies\/rxhk”, “country”: “CN”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-22T14:00:44.796415+00:00”, “domain”: “rxpe.com”, “group”: “coinbasecartel”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T14:03:32.918458”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ba6d0314b4c0942d89938bd972be7ecd.png”, “url”: “https:\/\/www.ransomware.live\/id\/UlhQRSBHcm91cEBjb2luYmFzZWNhcnRlbA==”, “victim”: “RXPE Group” }, { “activity”: “Transportation”, “attackdate”: “2026-08-22T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Full network image staged. ERP exports, dispatch DB and payroll archives recovered. Pending final inventory before publication.”, “discovered”: “2026-08-22T05:19:52.744287+00:00”, “domain”: “meridianlogisticgroup.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T05:38:41.001498”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWVyaWRpYW4gTG9naXN0aWNzIEdyb3VwQHRoZWdlbnRsZW1lbg==”, “victim”: “Meridian Logistics Group” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-21T14:55:56.695559+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=59a43842-d0d8-41db-ab38-2cd125d91db2”, “country”: “MX”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T14:56:15.304066+00:00”, “domain”: “www.quakerstate.com.mx”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/072038d419f6335db9fb3e595d06e44a.png”, “url”: “https:\/\/www.ransomware.live\/id\/UXVha2VyIFN0YXRlIE1leGljb0BxaWxpbg==”, “victim”: “Quaker State Mexico” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-21T14:55:18.858993+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=769179b7-db54-45e8-b3ba-9d7c94951e5d”, “country”: “US”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T14:55:37.675449+00:00”, “domain”: “www.ipic.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9aa3939e31cb3cfaffb8079db31c0cc2.png”, “url”: “https:\/\/www.ransomware.live\/id\/aVBpY0BxaWxpbg==”, “victim”: “iPic” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-21T12:56:35.156385+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=01be5eca-c028-47e8-add2-46a852dccda7”, “country”: “MX”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T12:56:53.309028+00:00”, “domain”: “www.cinepolis.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e693ca6267e36f71d9241983370c1656.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q2luw6lwb2xpc0BxaWxpbg==”, “victim”: “Cin\u00e9polis” }, { “activity”: “Healthcare”, “attackdate”: “2026-08-21T12:27:46.881499+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=260”, “country”: “US”, “data_size”: null, “description”: “Fairview Dental Group Fairview Dental Group offers a range of dental services including family dentistry, cosmetic treatments, dental implants, and invisible braces.We are pleased to present:Full patient database, patient X-rays, scanned forms\/consents\/invoices, health records (PHI) of the entire practice, unencrypted. More”, “discovered”: “2026-08-21T12:28:19.425238+00:00”, “domain”: “”, “group”: “rhysida”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/RmFpcnZpZXcgRGVudGFsIEdyb3VwQHJoeXNpZGE=”, “victim”: “Fairview Dental Group” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-21T11:56:53.567455+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=a4a0d54e-27c5-45ec-a3aa-39184e012167”, “country”: “IN”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T11:57:12.828596+00:00”, “domain”: “www.gindre.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5027b000787f3a73c5977bf6380778e2.png”, “url”: “https:\/\/www.ransomware.live\/id\/R2luZHJlIEluZGlhQHFpbGlu”, “victim”: “Gindre India” }, { “activity”: “Education”, “attackdate”: “2026-08-21T10:27:30.392150+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=259”, “country”: “US”, “data_size”: null, “description”: “Battle Creek Public Schools Battle Creek Public Schools in Nebraska provides educational services for students from pre-kindergarten through 12th grade. We are pleased to present:Student records of named minors:** IEP\/special-ed files, disability determination notices, discipline\/suspension records.Federal funds compliance trail (ESSA\/Title I application), staff health-spending claims (payflex\/EHA) More”, “discovered”: “2026-08-21T10:28:03.015892+00:00”, “domain”: “battlecreekschools.net”, “group”: “rhysida”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T12:08:12.937412”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ea396a8af2be120d9c49372ac9f464a7.png”, “url”: “https:\/\/www.ransomware.live\/id\/QmF0dGxlIENyZWVrIFB1YmxpYyBTY2hvb2xzQHJoeXNpZGE=”, “victim”: “Battle Creek Public Schools” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-21T09:56:37.430203+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=9859bcba-a0f1-4b0a-9653-a68d5327e833”, “country”: “US”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T09:56:54.942935+00:00”, “domain”: “www.pendaslaw.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ffa9bbde523c941dbfb4b0defc4f3931.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIFBlbmRhcyBMYXcgRmlybUBxaWxpbg==”, “victim”: “The Pendas Law Firm” }, { “activity”: “Other”, “attackdate”: “2026-08-21T09:55:55.398297+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=dab4ef20-3fbb-4db3-a653-66247f20272f”, “country”: “US”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T09:56:18.422995+00:00”, “domain”: “www.blakeservices.us”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b172f622201e9ed11822194d7b68b72e.png”, “url”: “https:\/\/www.ransomware.live\/id\/Qmxha2UgU2VydmljZXNAcWlsaW4=”, “victim”: “Blake Services” }, { “activity”: “Not Found”, “attackdate”: “2026-08-21T09:55:13.328310+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=86a79d53-e85b-47ba-8ae4-bb869cad0dac”, “country”: “US”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-21T09:55:36.454369+00:00”, “domain”: “www.wwccpa.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d45a5d723cb872cf85b044d3bbdc58a1.png”, “url”: “https:\/\/www.ransomware.live\/id\/UHJvZmVzc2lvbmFsQHFpbGlu”, “victim”: “Professional” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-21T08:20:48+00:00”, “claim_url”: “”, “country”: “IT”, “data_size”: null, “description”: “arielenergia.it zoominfo.com\/c\/gdl-spa\/1311974459 Ariel Energia is a prominent Italian company based in Turin with over 40 years of experience in the home energy and comfort sector.\nThey specialize in producing and distributing \”Made in Italy\” heating and cooling solutions, including pellet stoves, boilers, and air conditioners.\nThe company also provides renewable energy systems like photovoltaics and advanced water purifiers to promote sustainability and energy efficiency.”, “discovered”: “2026-08-21T08:25:56.260015+00:00”, “domain”: “arielenergia.it”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:25:54”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QXJpZWwgRW5lcmdpYUB0aGVnZW50bGVtZW4=”, “victim”: “Ariel Energia” }, { “activity”: “Transportation”, “attackdate”: “2026-08-21T08:19:21+00:00”, “claim_url”: “”, “country”: “WS”, “data_size”: null, “description”: “oceanica.ws Oceanica Internacional is a comprehensive logistics and freight forwarding company operating across Central America.\nThey serve as a strategic logistics partner, providing international trade and supply chain solutions in countries like Costa Rica, Panama, and Guatemala.\nThe company specializes in coordinating imports, exports, and cargo transportation to support businesses throughout the region.”, “discovered”: “2026-08-21T08:26:16.423654+00:00”, “domain”: “oceanica.ws”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 5, “update”: “2026-08-21T08:26:15”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/T2NlYW5pY2EgSW50ZXJuYWNpb25hbEB0aGVnZW50bGVtZW4=”, “victim”: “Oceanica Internacional” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-21T08:17:41+00:00”, “claim_url”: “”, “country”: “BZ”, “data_size”: null, “description”: “cazinvestments.com zoominfo.com\/c\/caz-investments-lp\/16765398 CAZ Investments We have taken NDA files, HR data, user data, employee data, models, bank statements, tax and legal documents, confidential files, photos of your work and leisure time, screenshots, information about interactions with offshore accounts, your and your clients’ dirty laundry, passport scans, VIP client data, and much more the total volume of data exceeds 478 GB. is a Houston-based wealth management and multi-family office firm founded in 2001.\nThey manage over $10.3 billion in assets, providing exclusive access to alternative investments like private equity, credit, and sports ownership.\nThe firm curates unique investment opportunities for a global network of individual investors, financial advisors, and institutions.”, “discovered”: “2026-08-21T08:26:36.533245+00:00”, “domain”: “cazinvestments.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:26:35”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Q0FaIEludmVzdG1lbnRzQHRoZWdlbnRsZW1lbg==”, “victim”: “CAZ Investments” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-08-21T08:14:29+00:00”, “claim_url”: “”, “country”: “NO”, “data_size”: null, “description”: “aquasea.com rocketreach.co\/aquasea-inc-profile_b468216cfc5c9f6e Aquasea Inc. is a clothing and apparel manufacturing company headquartered in Compton, California, operating since 1995.\nThe business specializes in full-package production, including cut and sew services, private label manufacturing, and screen printing.\nThey also operate nearshore textile manufacturing facilities to support their comprehensive apparel production capabilities.”, “discovered”: “2026-08-21T08:26:56.904022+00:00”, “domain”: “aquasea.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:26:55”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QXF1YXNlYUB0aGVnZW50bGVtZW4=”, “victim”: “Aquasea” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-21T08:02:04+00:00”, “claim_url”: “”, “country”: “AT”, “data_size”: null, “description”: “arbeiterkammer.at The Austrian Chamber of Labour is a statutory public organization dedicated to representing the interests of employees and consumers across Austria.\nIt provides its members with free legal advice on labor and social law, educational support, and strong consumer protection services.\nThe organization actively advocates for workers’ rights, fair wages, and social justice through extensive research and political lobbying.”, “discovered”: “2026-08-21T08:27:17.126751+00:00”, “domain”: “arbeiterkammer.at”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:27:15”, “users”: 26, “users_url”: 16 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QVJCRUlURVJLQU1NRVJOQHRoZWdlbnRsZW1lbg==”, “victim”: “ARBEITERKAMMERN” }, { “activity”: “Not Found”, “attackdate”: “2026-08-21T08:00:07+00:00”, “claim_url”: “”, “country”: “FR”, “data_size”: null, “description”: “geb.fr zoominfo.com\/c\/geb-sas\/372743980 GEB SAS is a historic French chemical manufacturing company established in 1860.\nThey specialize in formulating and producing essential sealing solutions, adhesives, and PVC glues.\nThe family-owned business primarily provides high-quality maintenance and installation products for plumbing and heating professionals.”, “discovered”: “2026-08-21T08:27:36.668027+00:00”, “domain”: “geb.fr”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:30:02”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/R2ViIFNhc0B0aGVnZW50bGVtZW4=”, “victim”: “Geb Sas” }, { “activity”: “Other”, “attackdate”: “2026-08-21T07:58:50+00:00”, “claim_url”: “”, “country”: “AE”, “data_size”: null, “description”: “al-meergroup.com zoominfo.com\/c\/almeer\/1326290906 Almeer General Contracting Establishment is a Saudi-owned company established in 2010 and headquartered in Jubail, Saudi Arabia.\nThey specialize in comprehensive electrical, civil construction, and mechanical erection services for industrial facilities.\nThe firm primarily serves large-scale sectors, including oil refineries and fertilizer plants, utilizing a team of qualified engineers.”, “discovered”: “2026-08-21T08:27:57.363626+00:00”, “domain”: “al-meergroup.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:27:55”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWxtZWVyQHRoZWdlbnRsZW1lbg==”, “victim”: “Almeer” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-21T07:56:18+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “escon.us zoominfo.com\/c\/escon-group\/352605618 ESCON Group is a veteran-owned electrical contracting company based in Bay City, Michigan, with a history tracing back to 1907.\nThey specialize in providing comprehensive commercial and residential electrical services, low voltage solutions, and fiber optics.\nThe company also offers advanced security systems, smart integrations, and robust commercial generator installations to ensure reliable power.”, “discovered”: “2026-08-21T08:28:18.956384+00:00”, “domain”: “escon.us”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:28:16”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/RVNDT04gR3JvdXBAdGhlZ2VudGxlbWVu”, “victim”: “ESCON Group” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-21T07:55:14+00:00”, “claim_url”: “”, “country”: “JP”, “data_size”: null, “description”: “akatake.co.jp crunchbase.com\/organization\/akatake-engineering-co-ltd Akatake Engineering Co., Ltd. is a Japanese manufacturing company based in Numazu, Shizuoka, established in 1971.\nThey specialize in powder handling technology, providing comprehensive solutions for the storage, feeding, weighing, and transportation of bulk powders.\nThe company designs and manufactures custom industrial equipment and container systems for various industries dealing with fine particulate materials.”, “discovered”: “2026-08-21T08:28:39.396907+00:00”, “domain”: “akatake.co.jp”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:28:37”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWthdGFrZSBFbmdpbmVlcmluZ0B0aGVnZW50bGVtZW4=”, “victim”: “Akatake Engineering” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-21T07:50:43+00:00”, “claim_url”: “”, “country”: “MX”, “data_size”: null, “description”: “magdalenagrand.com zoominfo.com\/c\/magdalena-grand-beach–golf-resort\/348187300 Magdalena Grand Beach & Golf Resort is a luxury hotel and resort located in Lowlands on the beautiful island of Tobago.\nIt features premium oceanfront accommodations with access to a championship golf course, spa, pools, and tennis courts.\nThe property is also a popular destination for weddings, offering guests a variety of dining options and vibrant nightlife.”, “discovered”: “2026-08-21T08:28:59.855519+00:00”, “domain”: “magdalenagrand.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-21T08:28:58”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWFnZGFsZW5hIEdyYW5kIEJlYWNoIEdvbGYgUmVzb3J0QHRoZWdlbnRsZW1lbg==”, “victim”: “Magdalena Grand Beach Golf Resort” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T07:48:07+00:00”, “claim_url”: “”, “country”: “PL”, “data_size”: null, “description”: “logsystem.pl zoominfo.com\/c\/log-systems\/372786485 LOG Systems is a Polish software company based in Wroc\u0142aw that develops comprehensive IT management and Helpdesk solutions.\nTheir flagship product, LOG Plus, is an advanced ITSM platform designed to streamline ticketing, incident management, and IT infrastructure monitoring.\nThe software also includes powerful Software Asset Management features to help organizations optimize licensing and ensure data security.”, “discovered”: “2026-08-21T08:29:20.326445+00:00”, “domain”: “logsystem.pl”, “group”: “thegentlemen”, “infostealer”: { “employees”: 1, “employees_url”: 14, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-21T08:29:18”, “users”: 11, “users_url”: 34 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TE9HIFN5c3RlbXNAdGhlZ2VudGxlbWVu”, “victim”: “LOG Systems” }, { “activity”: “Other”, “attackdate”: “2026-08-21T07:47:04+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “lexacaucho.com zoominfo.com\/c\/lexacaucho–laminados-y-extruidos-de-caucho-sac\/457170004 Lexacaucho is a Peruvian manufacturing company based in Lima with over 25 years of experience in the rubber and polymer industry.\nThey specialize in producing molded rubber sheets, profiles, linings, and custom parts using materials like natural rubber, SBR, and EPDM.\nThe company primarily serves the mining, fishing, and general industrial sectors by providing durable elastomer solutions.”, “discovered”: “2026-08-21T08:29:40.489466+00:00”, “domain”: “lexacaucho.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 1, “employees_url”: 2, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-21T08:29:39”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TGV4YWNhdWNob0B0aGVnZW50bGVtZW4=”, “victim”: “Lexacaucho” }, { “activity”: “Not Found”, “attackdate”: “2026-08-21T07:45:17+00:00”, “claim_url”: “”, “country”: “AE”, “data_size”: null, “description”: “awjholding.com zoominfo.com\/c\/awj-holding-co\/448239448 AWJ Holding Company is a prominent Saudi-based single-family office and investment firm established in 2016.\nHeadquartered in Riyadh, the company specializes in real estate development, property management, and strategic investment management.\nIt focuses on high-impact developments and operates dynamic subsidiaries across retail, hospitality, and infrastructure sectors.”, “discovered”: “2026-08-21T08:29:56.576661+00:00”, “domain”: “awjholding.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 18, “update”: “2026-08-21T08:29:55”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QVdKIEhvbGRpbmdAdGhlZ2VudGxlbWVu”, “victim”: “AWJ Holding” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T07:43:44+00:00”, “claim_url”: “”, “country”: “DE”, “data_size”: null, “description”: “dlp-motive.de dlp motive is a German full-service event technology provider founded in 2007, successfully realizing around 600 projects annually.\nThey offer comprehensive technical solutions including lighting, audio, video, kinetics, and rigging for corporate, e-sports, and public events.\nThe company handles the entire event lifecycle, providing everything from initial concept and design to logistics, on-site production, and equipment rental.”, “discovered”: “2026-08-21T08:30:00.595422+00:00”, “domain”: “dlp-motive.de”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:29:59”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/ZGxwIG1vdGl2ZUB0aGVnZW50bGVtZW4=”, “victim”: “dlp motive” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-21T07:41:04+00:00”, “claim_url”: “”, “country”: “BR”, “data_size”: null, “description”: “uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna, Austria, founded in 2015.\nThey specialize in strategic management, business development, and investment consulting.”, “discovered”: “2026-08-21T08:30:17.481144+00:00”, “domain”: “uol-consult.com”, “group”: “thegentlemen”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T08:30:15”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VU9MY29uc3VsdEB0aGVnZW50bGVtZW4=”, “victim”: “UOLconsult” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-21T06:04:52.978569+00:00”, “claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=ed288008-26ad-4b2d-babf-32879da1a35d”, “country”: “US”, “data_size”: null, “description”: “Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division, with a focus on high-asset cases. The firm is led by experienced attorneys who have authored key reference materials on Colorado family law, providing them with a unique advantage in legal representation. They serve a diverse clientele, including executives, business owners, and professionals, ensuring personalized and strategic legal solutions. With offices in Denver and Aspen, they are dedicated to protecting clients’ interests and achieving favorable outcomes in family law matters.”, “discovered”: “2026-08-21T06:25:00.986120+00:00”, “domain”: “hoganomidi.com”, “group”: “dragonforce”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T06:24:58”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f0a836e5bc9b523d5bd3f13fb8d0222d.png”, “url”: “https:\/\/www.ransomware.live\/id\/SG9nYW4gT21pZGkgUC5DLkBkcmFnb25mb3JjZQ==”, “victim”: “Hogan Omidi P.C.” }, { “activity”: “Healthcare”, “attackdate”: “2026-08-21T02:52:18.456997+00:00”, “claim_url”: “http:\/\/om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion\/r\/qSyLjdjTxND8z6QcanI76118t3safzffkx25VyrsP8pRisU9uC3yns7FVVZTZ2KwlAv3deD5VCYDtdSoeUz2NJc1JRNFJi”, “country”: “US”, “data_size”: null, “description”: “Data breach at a major healthcare franchise headquarters.”, “discovered”: “2026-08-21T02:53:01.068671+00:00”, “domain”: “interimhealthcare.com”, “group”: “anubis”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: { “Azorult”: 2, “Generic Stealer”: 3, “Lumma”: 1, “RedLine”: 1 }, “last_employee_compromised”: “1970-01-01T00:00:00+00:00”, “last_user_compromised”: “2025-05-09T00:22:30+00:00”, “thirdparties”: 4, “update”: “2026-08-21T05:28:44.319095”, “users”: 5, “users_url”: 6 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/185bc067268bd0d0ff7bd1e8461dcd97.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW50ZXJpbSBIZWFsdGhDYXJlIFtIZWFkIG9mZmljZV1AYW51Ymlz”, “victim”: “Interim HealthCare [Head office]” }, { “activity”: “Education”, “attackdate”: “2026-08-21T02:23:05.936000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/110”, “country”: “”, “data_size”: null, “description”: “[AI generated] Studee is an online platform that helps international students find and apply to universities around the world. Operating in the education technology industry, the company is based in the United Kingdom. It connects prospective students with hundreds of universities globally, offering guidance on courses, applications, and admissions processes, making higher education more accessible to students seeking to study abroad.”, “discovered”: “2026-08-21T02:23:41.243426+00:00”, “domain”: “studee.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-21T02:23:21”, “users”: 607, “users_url”: 8 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/26b90e0b662815c01d99e0bd06e741b5.png”, “url”: “https:\/\/www.ransomware.live\/id\/U3R1ZGVlQGRpcmV3b2xm”, “victim”: “Studee” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-21T02:22:13.723000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/109”, “country”: “DK”, “data_size”: null, “description”: “[AI generated] Reviso Cloud Accounting Limited is a software company that provides cloud-based accounting solutions primarily targeting small and medium-sized businesses. The platform offers tools for bookkeeping, invoicing, financial reporting, and VAT management. The company operates within the financial technology and accounting software industry and is based in the United Kingdom, serving businesses seeking accessible and scalable online accounting services.”, “discovered”: “2026-08-21T02:24:16.463163+00:00”, “domain”: “reviso.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:24:00”, “users”: 286, “users_url”: 23 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/673c3b1d1a6e60c8fb835e273b019c66.png”, “url”: “https:\/\/www.ransomware.live\/id\/UmV2aXNvIENsb3VkIEFjY291bnRpbmcgTGltaXRlZEBkaXJld29sZg==”, “victim”: “Reviso Cloud Accounting Limited” }, { “activity”: “Other”, “attackdate”: “2026-08-21T02:20:59.939000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/108”, “country”: “AE”, “data_size”: null, “description”: “Building Materials”, “discovered”: “2026-08-21T02:24:48.392055+00:00”, “domain”: “mctuae.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 2, “update”: “2026-08-21T02:24:35”, “users”: 1, “users_url”: 3 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f48e04510d645d2433fbaf665e258087.png”, “url”: “https:\/\/www.ransomware.live\/id\/TUNUIEdyb3VwIG9mIENvbXBhbmllc0BkaXJld29sZg==”, “victim”: “MCT Group of Companies” }, { “activity”: “Transportation”, “attackdate”: “2026-08-21T02:20:44.311000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/107”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-21T02:25:21.518145+00:00”, “domain”: “hpcarriers.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:25:07”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/7ad40afb06d715176a3cc03bcab91a78.png”, “url”: “https:\/\/www.ransomware.live\/id\/SFAgQ2FycmllcnNAZGlyZXdvbGY=”, “victim”: “HP Carriers” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-21T02:20:28.442000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/106”, “country”: “US”, “data_size”: null, “description”: “Business Services”, “discovered”: “2026-08-21T02:25:53.441478+00:00”, “domain”: “allstarindustries.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:25:40”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2a3c04e3f57e362be76d41507a4aba13.png”, “url”: “https:\/\/www.ransomware.live\/id\/QWxsc3RhciBJbmR1c3RyaWVzQGRpcmV3b2xm”, “victim”: “Allstar Industries” }, { “activity”: “Education”, “attackdate”: “2026-08-21T02:20:12.703000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/105”, “country”: “US”, “data_size”: null, “description”: “Education”, “discovered”: “2026-08-21T02:26:25.037171+00:00”, “domain”: “deemack.org”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 15, “update”: “2026-08-21T02:26:12”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/69b37bdf6ec1570db668b23a121207b0.png”, “url”: “https:\/\/www.ransomware.live\/id\/RGVlciBDcmVlay1NYWNraW5hdyBDVVNEQGRpcmV3b2xm”, “victim”: “Deer Creek-Mackinaw CUSD” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-21T02:19:53.322000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/103”, “country”: “MX”, “data_size”: null, “description”: “Business Services”, “discovered”: “2026-08-21T02:26:56.908828+00:00”, “domain”: “isonxperiences.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 113, “update”: “2026-08-21T02:26:43”, “users”: 44, “users_url”: 11 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f5508bf29b3f0d0b140795b7ff25095b.png”, “url”: “https:\/\/www.ransomware.live\/id\/aVNPTiBYUEVSSUVOQ0VTQGRpcmV3b2xm”, “victim”: “iSON XPERIENCES” }, { “activity”: “Other”, “attackdate”: “2026-08-21T02:19:32.079000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/102”, “country”: “”, “data_size”: null, “description”: “Jewelry & Watch Retail”, “discovered”: “2026-08-21T02:27:28.504869+00:00”, “domain”: “diacoglobal.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:27:15”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f52388c235bcf9d4153ec07fdcfc928c.png”, “url”: “https:\/\/www.ransomware.live\/id\/RGlhY28gR2xvYmFsQGRpcmV3b2xm”, “victim”: “Diaco Global” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T02:18:51.438000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/101”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-21T02:28:02.005161+00:00”, “domain”: “authenticateis.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:27:47”, “users”: 18, “users_url”: 6 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/830da2f6adde592810ea310666407627.png”, “url”: “https:\/\/www.ransomware.live\/id\/QXV0aGVudGljYXRlIEluZm9ybWF0aW9uIFN5c3RlbXNAZGlyZXdvbGY=”, “victim”: “Authenticate Information Systems” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T02:18:32.517000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/100”, “country”: “NL”, “data_size”: null, “description”: “Engineering Software”, “discovered”: “2026-08-21T02:28:35.988894+00:00”, “domain”: “prosim.aero”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-21T02:28:23”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/9b6123017e5f525221759cc1274a2d70.png”, “url”: “https:\/\/www.ransomware.live\/id\/UHJvU2ltIEF2aWF0aW9uIFJlc2VhcmNoQGRpcmV3b2xm”, “victim”: “ProSim Aviation Research” }, { “activity”: “Other”, “attackdate”: “2026-08-21T02:18:06.897000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/99”, “country”: “US”, “data_size”: null, “description”: “Hospitality”, “discovered”: “2026-08-21T02:29:07.494801+00:00”, “domain”: “therevelcollective.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:28:54”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ddd21a002a62bf17084f99590ef6aafa.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIFJldmVsIENvbGxlY3RpdmVAZGlyZXdvbGY=”, “victim”: “The Revel Collective” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T02:17:44.567000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/98”, “country”: “MX”, “data_size”: null, “description”: “Engineering Software”, “discovered”: “2026-08-21T02:29:39.820450+00:00”, “domain”: “aztecsoftware.com”, “group”: “direwolf”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T02:29:26”, “users”: 941, “users_url”: 22 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/917874a9ee0e6d4f18210377c797579a.png”, “url”: “https:\/\/www.ransomware.live\/id\/QXp0ZWMgU29mdHdhcmVAZGlyZXdvbGY=”, “victim”: “Aztec Software” }, { “activity”: “Not Found”, “attackdate”: “2026-08-21T02:05:29.519000+00:00”, “claim_url”: “http:\/\/direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion\/api\/public\/articles\/97”, “country”: “CA”, “data_size”: null, “description”: “Enterprise Resource Planning”, “discovered”: “2026-08-21T02:30:11.201341+00:00”, “domain”: “cbsnorthstar.com”, “group”: “direwolf”, “infostealer”: { “employees”: 7, “employees_url”: 10, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 8, “update”: “2026-08-21T02:29:58”, “users”: 9, “users_url”: 8 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/54858244d228366c4afd1e16efc11a57.png”, “url”: “https:\/\/www.ransomware.live\/id\/Tm9ydGhTdGFyQGRpcmV3b2xm”, “victim”: “NorthStar” }, { “activity”: “Technology”, “attackdate”: “2026-08-21T00:00:00+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/nteitalia”, “country”: “IT”, “data_size”: null, “description”: “NTE Italia, an engineering and telecommunications service provider based in Catanzaro, Italy. Sensitive thousands of documents are compromised.”, “discovered”: “2026-08-21T16:51:22.138601+00:00”, “domain”: “nteitalia.it”, “group”: “Panzer”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T05:47:30.581770”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/98a6059b01e7bf737f774d0cd6beec20.png”, “url”: “https:\/\/www.ransomware.live\/id\/TnRlaXRhbGlhQFBhbnplcg==”, “victim”: “Nteitalia” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-08-21T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “JC Sales is a leading full-service wholesaler based in Los Angeles, California, specializing in\na vast array of wholesale products including health and beauty items, food and beverages, gene\nral merchandise, and seasonal items.\n\nWe will upload 206gb of corporate data soon. Detailed personal employee information (passports,\nDLs, addresses, phones, contacts), confidential financials, contracts and agreements, client i\nnformation, NDAs and so on.\n”, “discovered”: “2026-08-21T13:21:20.842951+00:00”, “domain”: “jcsalesweb.com”, “group”: “akira”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T16:02:55.378410”, “users”: 403, “users_url”: 15 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/SkMgU2FsZXNAYWtpcmE=”, “victim”: “JC Sales” }, { “activity”: “Not Found”, “attackdate”: “2026-08-20T20:51:44.285065+00:00”, “claim_url”: “https:\/\/business-data-leaks.com\/about#0417ca7b8c548d47e48d19c85”, “country”: “”, “data_size”: null, “description”: “Redacted entry – full company name pending disclosure (FULL DATA TIMER active).”, “discovered”: “2026-08-20T20:52:31.218246+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/faec41f464c98489ac1842a7ca9d42a2.png”, “url”: “https:\/\/www.ransomware.live\/id\/RC4uLkBTaWxlbnRSYW5zb21Hcm91cA==”, “victim”: “D…” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T19:31:25.293462+00:00”, “claim_url”: “http:\/\/2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onion\/company\/spaggiari\/”, “country”: “IT”, “data_size”: null, “description”: “School management software”, “discovered”: “2026-08-20T19:31:43.321420+00:00”, “domain”: “spaggiari.eu”, “group”: “xpl0itrs”, “infostealer”: { “employees”: 6, “employees_url”: 2, “infostealer_stats”: { “Acreed”: 110, “Atomic”: 89, “Azorult”: 695, “CRYPTBOT”: 95, “DarkCrystal”: 20, “Ficker”: 4, “Generic Stealer”: 8569, “Lumma”: 9945, “Mystic”: 63, “Raccoon”: 6430, “RedLine”: 19252, “StealC”: 1364, “Taurus”: 74, “UNKNOWN”: 956, “Vidar”: 2334 }, “last_employee_compromised”: “2026-07-17T00:00:00+00:00”, “last_user_compromised”: “2026-08-19T02:15:40.528000+00:00”, “thirdparties”: 8, “update”: “2026-08-21T05:30:37.381216”, “users”: 62539, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b0ce0c86646b80471050a7fdb097eff7.png”, “url”: “https:\/\/www.ransomware.live\/id\/R3J1cHBvIFNwYWdnaWFyaSBQYXJtYUB4cGwwaXRycw==”, “victim”: “Gruppo Spaggiari Parma” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-08-20T18:29:39.461192+00:00”, “claim_url”: “http:\/\/iah6477wcvisc45wl54u524fbrh4dnmtcctpg2fpe5epf3jbpkiwu4qd.onion\/a\/regencycenters\/”, “country”: “US”, “data_size”: null, “description”: “Size: 219.5 GiB”, “discovered”: “2026-08-20T18:29:54.881503+00:00”, “domain”: “regencycenters.com”, “group”: “iah6477”, “infostealer”: { “employees”: 1, “employees_url”: 1, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 2, “update”: “2026-08-20T18:30:38.272099”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/7bc1b0446bf452ebb7612a95ee0d6724.png”, “url”: “https:\/\/www.ransomware.live\/id\/cmVnZW5jeWNlbnRlcnNAaWFoNjQ3Nw==”, “victim”: “regencycenters” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-20T18:29:15.592179+00:00”, “claim_url”: “http:\/\/iah6477wcvisc45wl54u524fbrh4dnmtcctpg2fpe5epf3jbpkiwu4qd.onion\/a\/acima\/”, “country”: “US”, “data_size”: null, “description”: “Size: 2.1 TiB”, “discovered”: “2026-08-20T18:29:32.073610+00:00”, “domain”: “acima.com”, “group”: “iah6477”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 17, “update”: “2026-08-20T18:31:27.160658”, “users”: 984, “users_url”: 22 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b8021e4e071479aa1ff2f21a4781009b.png”, “url”: “https:\/\/www.ransomware.live\/id\/YWNpbWFAaWFoNjQ3Nw==”, “victim”: “acima” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T18:28:52.888142+00:00”, “claim_url”: “http:\/\/iah6477wcvisc45wl54u524fbrh4dnmtcctpg2fpe5epf3jbpkiwu4qd.onion\/a\/marvin\/”, “country”: “”, “data_size”: null, “description”: “Size: 2.2 TiB”, “discovered”: “2026-08-20T18:29:08.217573+00:00”, “domain”: “”, “group”: “iah6477”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f2f82659129371fd4abf14161a70bbad.png”, “url”: “https:\/\/www.ransomware.live\/id\/bWFydmluQGlhaDY0Nzc=”, “victim”: “marvin” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T17:27:46.550664+00:00”, “claim_url”: “http:\/\/j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion\/topic.php?id=HnvwXHCG9p7DS”, “country”: “US”, “data_size”: null, “description”: “United States”, “discovered”: “2026-08-20T17:28:01.340305+00:00”, “domain”: “www.bemedia.com”, “group”: “play”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3127eb079fbe9f161885360d07452354.png”, “url”: “https:\/\/www.ransomware.live\/id\/QmUgTWVkaWFAcGxheQ==”, “victim”: “Be Media” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T17:27:11.668713+00:00”, “claim_url”: “http:\/\/j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion\/topic.php?id=4dYU8GZcqgxs1J”, “country”: “LV”, “data_size”: null, “description”: “Canada”, “discovered”: “2026-08-20T17:27:28.429624+00:00”, “domain”: “www.latoplast.com”, “group”: “play”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/aa03aa232997cffaf4af0d4b7d6f4cf1.png”, “url”: “https:\/\/www.ransomware.live\/id\/TGF0b3BsYXN0QHBsYXk=”, “victim”: “Latoplast” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T17:26:05.068448+00:00”, “claim_url”: “http:\/\/payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion\/posts\/33d6a45b-360e-4c37-b5dc-141a87b54a19”, “country”: “CH”, “data_size”: null, “description”: “Qualiflex Datacenter – data from companies such as HWZ-Studieng\u00e4nge (fh-hwz.ch), myenb.ch, schelling.ch, kaelteringag.ch & kaeltebucher.ch, cbmswiss.ch, vitabad.ch, ign8.ch, etc., was stolen”, “discovered”: “2026-08-20T17:26:46.782348+00:00”, “domain”: “fh-hwz.ch”, “group”: “payload”, “infostealer”: { “employees”: 2, “employees_url”: 1, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 1, “update”: “2026-08-20T17:26:05”, “users”: 1, “users_url”: 2 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d3d40469f840f449e20709d25d73b76c.png”, “url”: “https:\/\/www.ransomware.live\/id\/UXVhbGlmbGV4IERhdGFjZW50ZXIgfCBIV1otU3R1ZGllbmduZ2UgKGZoLWh3ei5jaCksIG15ZW5iLmNoLCBldGNAcGF5bG9hZA==”, “victim”: “Qualiflex Datacenter | HWZ-Studiengnge (fh-hwz.ch), myenb.ch, etc” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-08-20T16:12:23+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/frisian-flag-indonesia”, “country”: “ID”, “data_size”: null, “description”: “Frisian Flag Indonesia specializes in high-quality dairy products, including sweetened condensed milk, UHT milk, powdered milk for families, and cheese. The company aims to provide nutritious options that support the health and well-being of families, offering products enriched with vitamins and minerals. Their target clients include families, pregnant women, and children, focusing on delivering nutritional benefits through their diverse product range. Established in 1871, Frisian Flag is committed to building strong families by promoting healthy dietary habits.”, “discovered”: “2026-08-20T16:22:01.160769+00:00”, “domain”: “”, “group”: “Panzer”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/5c98bf9b5055c6d166d7d9a1998cf670.png”, “url”: “https:\/\/www.ransomware.live\/id\/RnJpc2lhbiBGbGFnIEluZG9uZXNpYUBQYW56ZXI=”, “victim”: “Frisian Flag Indonesia” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T15:47:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/termotecnica-industriale-s-r-l-fully-encrypted-nvq3vlm9az”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] Termotecnica Industriale S.r.l. is an Italian company operating in the industrial thermal engineering sector. Based in Italy, it specializes in the design and manufacturing of heating systems, thermal equipment, and industrial burners. The company serves various industrial clients requiring customized thermal solutions for production processes. It operates primarily in the energy and industrial plant engineering market within Italy and potentially broader European markets.”, “discovered”: “2026-08-20T16:58:09.992470+00:00”, “domain”: “termotecnica.it”, “group”: “titan”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T16:57:46”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b6e1455faee8aef608521dd357848970.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGVybW90ZWNuaWNhIEluZHVzdHJpYWxlIFMuci5sLkB0aXRhbg==”, “victim”: “Termotecnica Industriale S.r.l.” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T15:42:00+00:00”, “claim_url”: “\/post\/netexam\/”, “country”: “”, “data_size”: null, “description”: “NetExam (netexam.com) \u2014 the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18.1 MB | Sector: Education, Retail, Other]”, “discovered”: “2026-08-20T17:50:47.687999+00:00”, “domain”: “netexam.com”, “group”: “emperador”, “infostealer”: { “employees”: 6, “employees_url”: 48, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 5, “update”: “2026-08-20T18:30:03”, “users”: 565, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TmV0RXhhbUBlbXBlcmFkb3I=”, “victim”: “NetExam” }, { “activity”: “Other”, “attackdate”: “2026-08-20T14:02:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/poema-s-r-l-nvl0i0et3b”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T15:00:55.423349+00:00”, “domain”: “www.poemasrl.it”, “group”: “titan”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/4b6b20268b9ee5b8abfd224711c7f53e.png”, “url”: “https:\/\/www.ransomware.live\/id\/UE9FTUEgUy5yLmwuQHRpdGFu”, “victim”: “POEMA S.r.l.” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-20T13:58:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/tedesco-partners-stp-srl-nvsnoipfgr”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T15:01:34.551430+00:00”, “domain”: “tedescoepartners.it”, “group”: “titan”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T15:01:14”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a64c62e8bbc1c3ca3de399756030a475.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGVkZXNjbyAmIFBhcnRuZXJzIFNUUCBzcmxAdGl0YW4=”, “victim”: “Tedesco & Partners STP srl” }, { “activity”: “Not Found”, “attackdate”: “2026-08-20T13:52:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/ctp-s-r-l-nv982ohgtl”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] CTP S.r.l. is an Italian company operating in the printing and publishing technology sector. Based in Italy, it specializes in the development and supply of software and systems for editorial production, prepress, and content management. The company serves media, publishing, and printing industries, providing workflow automation solutions that help customers manage and streamline the production of newspapers, magazines, and other printed or digital content.”, “discovered”: “2026-08-20T15:02:58.212512+00:00”, “domain”: “ctpsrl.it”, “group”: “titan”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T15:02:34”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0091ddc9693ff98958992f53deed3228.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q1RQIFMuci5sLkB0aXRhbg==”, “victim”: “CTP S.r.l.” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T13:16:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/elbor-s-p-a-nvpfzeetk4”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] Elbor S.p.A. is an Italian company operating in the distribution and wholesale sector. Based in Italy, it specializes in the commercialization of industrial and technical products, serving businesses across various sectors. The company functions as a trading and supply chain intermediary, providing goods and services to industrial clients. Specific details about its scale, founding date, and full product portfolio are limited in widely available sources.”, “discovered”: “2026-08-20T13:59:30.029925+00:00”, “domain”: “www.elbor.it”, “group”: “titan”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e6e7cb50c7680ae27cd41c0371a60937.png”, “url”: “https:\/\/www.ransomware.live\/id\/RWxib3IgUy5wLkEuQHRpdGFu”, “victim”: “Elbor S.p.A.” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T13:02:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/condor-spa-fully-encrypted-nvn6gfawl6”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] CONDOR SPA is a Chilean airline operating in South America. Founded in 1979, it provides domestic passenger and cargo air transport services within Chile, connecting major cities and remote regions including Patagonia and Easter Island. The company plays a key role in regional connectivity, serving routes that are difficult to access by land. It operates under civil aviation regulations in Chile.”, “discovered”: “2026-08-20T14:00:11.814438+00:00”, “domain”: “www.condor-group.it”, “group”: “titan”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0401413c6df007f7219ad0be33ef99e8.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q09ORE9SIFNQQUB0aXRhbg==”, “victim”: “CONDOR SPA” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-20T12:53:41.540151+00:00”, “claim_url”: “http:\/\/everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion\/news\/cca-bank”, “country”: “”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T13:54:00.451257+00:00”, “domain”: “cca-bank.com”, “group”: “everest”, “infostealer”: { “employees”: 1, “employees_url”: 1, “infostealer_stats”: { “Generic Stealer”: 1 }, “last_employee_compromised”: “2021-03-23T08:29:34+00:00”, “last_user_compromised”: “1970-01-01T00:00:00+00:00”, “thirdparties”: 2, “update”: “2026-08-22T05:49:25.152704”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/fe7546ef7787f1b71264979252a309f1.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q0NBIEJhbmtAZXZlcmVzdA==”, “victim”: “CCA Bank” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T12:42:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/tecnologica-s-r-l-fully-encrypted-nveenvscd0”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T13:32:30.069314+00:00”, “domain”: “tecnologicasrl.com”, “group”: “titan”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T13:32:09”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/16884de36acbc6aa3f5bb2b1a6a6b8ca.png”, “url”: “https:\/\/www.ransomware.live\/id\/VEVDTk9MT0dJQ0EgUy5yLmwuQHRpdGFu”, “victim”: “TECNOLOGICA S.r.l.” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T11:10:00+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 20 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK”, “discovered”: “2026-08-20T18:43:17.962996+00:00”, “domain”: “”, “group”: “shinyhunters”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Q3lydXMqKioqKipAc2hpbnlodW50ZXJz”, “victim”: “Cyrus******” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-20T10:33:28.765501+00:00”, “claim_url”: “http:\/\/lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onion”, “country”: “”, “data_size”: null, “description”: “PUBLICATION SCHEDULED. [LEAK \/ 5045 FILES]”, “discovered”: “2026-08-20T10:33:42.058405+00:00”, “domain”: “”, “group”: “majinahanashi”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0e5738c903e77e652564711fd74111a4.png”, “url”: “https:\/\/www.ransomware.live\/id\/R3JhbmQgSW9uIERlbGVtZW4gSG90ZWxAbWFqaW5haGFuYXNoaQ==”, “victim”: “Grand Ion Delemen Hotel” }, { “activity”: “Hospitality”, “attackdate”: “2026-08-20T10:32:56.195015+00:00”, “claim_url”: “http:\/\/lthicpjqc7gkn5eq3epxndc2uig3yngvcbdya4u3m3byjod5km4yuwqd.onion”, “country”: “GB”, “data_size”: null, “description”: “PUBLICATION SCHEDULED. [LEAK \/ 8080 FILES]”, “discovered”: “2026-08-20T10:33:10.513742+00:00”, “domain”: “themargohotel.com”, “group”: “majinahanashi”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T05:49:44.887944”, “users”: 429, “users_url”: 6 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0e5738c903e77e652564711fd74111a4.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIE1hcmdvIEhvdGVsQG1hamluYWhhbmFzaGk=”, “victim”: “The Margo Hotel” }, { “activity”: “Financial Services”, “attackdate”: “2026-08-20T10:08:00+00:00”, “claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/9d0b9595b62e70efa9c62d22143bcde3”, “country”: “US”, “data_size”: null, “description”: “U.S. Bank is a multinational financial institution that provides banking, lending, payment, and inve…”, “discovered”: “2026-08-20T10:36:56.053136+00:00”, “domain”: “usbank.com”, “group”: “lockbit5”, “infostealer”: { “employees”: 18, “employees_url”: 9, “infostealer_stats”: { “Acreed”: 967, “Atomic”: 48, “Aura Stealer”: 3, “Azorult”: 1586, “CRYPTBOT”: 30, “DarkCrystal”: 19, “Ficker”: 1, “Generic Stealer”: 7246, “Lumma”: 3330, “Mystic”: 10, “Predator”: 3, “Raccoon”: 1055, “RedLine”: 4702, “Remus”: 30, “StealC”: 308, “Taurus”: 5, “UNKNOWN”: 301, “Vidar”: 669 }, “last_employee_compromised”: “2026-03-21T05:54:18+00:00”, “last_user_compromised”: “2026-08-19T02:21:59.071000+00:00”, “thirdparties”: 56, “update”: “2026-08-20T10:36:38”, “users”: 21245, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f73ca14597962d4254a07dc825ca1e8d.png”, “url”: “https:\/\/www.ransomware.live\/id\/dXNiYW5rLmNvbUBsb2NrYml0NQ==”, “victim”: “usbank.com” }, { “activity”: “Manufacturing”, “attackdate”: “2026-08-20T09:18:00+00:00”, “claim_url”: “https:\/\/titanblog.org\/post\/elcon-megarad-s-p-a-fully-encrypted-nv34pi6ihb”, “country”: “IT”, “data_size”: null, “description”: “[AI generated] ELCON MEGARAD S.p.A. is an Italian company specializing in the design and manufacture of radiation-crosslinked materials and heat-shrinkable products. Operating in the electrical and industrial sectors, it produces cable accessories, insulation components, and protective solutions used in energy, rail, and telecommunications applications. Headquartered in Italy, the company serves both domestic and international markets with engineered polymer-based products.”, “discovered”: “2026-08-20T11:03:16.876321+00:00”, “domain”: “elconmegarad.com”, “group”: “titan”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T11:02:55”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/51532b1cbd061960b4d940af3279ee16.png”, “url”: “https:\/\/www.ransomware.live\/id\/RUxDT04gTUVHQVJBRCBTLnAuQUB0aXRhbg==”, “victim”: “ELCON MEGARAD S.p.A” }, { “activity”: “Not Found”, “attackdate”: “2026-08-20T09:11:08+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “full-service event rental company established in 1972, specializing in high-quality items and equipment for special events. They serve the Northeast and Mid-Atlantic regions along the East Coast, offering an extensive selection of furniture, linens, and decor. The company is dedicated to helping clients bring their unique event visions to life with professional customer care and design support. With its main facility in Teterboro, New Jersey, and a showroom in New York City, it remains a leading provider in the event services industry.”, “discovered”: “2026-08-20T14:15:06.307986+00:00”, “domain”: “”, “group”: “thegentlemen”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UCoqKiogUioqKioqQHRoZWdlbnRsZW1lbg==”, “victim”: “P**** R*****” }, { “activity”: “Not Found”, “attackdate”: “2026-08-20T08:57:44.149213+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=33182c8f-74a1-4af9-ba49-b7efdffd6217”, “country”: “PH”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-20T08:58:01.647158+00:00”, “domain”: “www.questronix.com.ph”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/4aaab79f47b16b37eb9b0ad076478514.png”, “url”: “https:\/\/www.ransomware.live\/id\/UXVlc3Ryb25peEBxaWxpbg==”, “victim”: “Questronix” }, { “activity”: “Other”, “attackdate”: “2026-08-20T08:56:27.597073+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=2bfe5896-59d5-44f2-8311-d2be2f67209f”, “country”: “ZA”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-08-20T08:56:45.119537+00:00”, “domain”: “www.trendsandconceptsinteriors.com”, “group”: “qilin”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2022ad4327d6372e46417f83519f5574.png”, “url”: “https:\/\/www.ransomware.live\/id\/VHJlbmRzIEFuZCBDb25jZXB0c0BxaWxpbg==”, “victim”: “Trends And Concepts” }, { “activity”: “Other”, “attackdate”: “2026-08-20T06:20:29.315765+00:00”, “claim_url”: “”, “country”: “GB”, “data_size”: null, “description”: “JP Molyneux Studio Ltd showcases the exclusive work of internationally renowned interior designer Juan Pablo Molyneux.”, “discovered”: “2026-08-20T06:20:30.921839+00:00”, “domain”: “www.molyneuxstudio.com”, “group”: “Deadlock”, “infostealer”: “”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/SlAgTW9seW5ldXggU3R1ZGlvQERlYWRsb2Nr”, “victim”: “JP Molyneux Studio” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T02:54:18.851417+00:00”, “claim_url”: “http:\/\/everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion\/news\/kingston-technology”, “country”: “US”, “data_size”: null, “description”: “[AI generated] Kingston Technology is a privately held American company founded in 1987 and headquartered in Fountain Valley, California. It is one of the world’s largest manufacturers of memory products, including DRAM modules, flash storage, USB drives, and solid-state drives. Kingston serves consumer, enterprise, and embedded markets globally, supplying components to major OEMs and retail customers across the technology industry.”, “discovered”: “2026-08-20T03:54:37.992161+00:00”, “domain”: “kingston.com”, “group”: “everest”, “infostealer”: { “employees”: 26, “employees_url”: 5, “infostealer_stats”: { “Acreed”: 2, “Azorult”: 25, “DarkCrystal”: 2, “Generic Stealer”: 77, “Lumma”: 53, “Mystic”: 1, “Raccoon”: 23, “RedLine”: 110, “StealC”: 7, “Taurus”: 1, “UNKNOWN”: 8, “Vidar”: 12 }, “last_employee_compromised”: “2026-02-05T01:44:19.353000+00:00”, “last_user_compromised”: “2026-07-23T08:40:09.214000+00:00”, “thirdparties”: 11, “update”: “2026-08-20T07:37:53.288407”, “users”: 348, “users_url”: 71 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/58e4bc112d65a3fd9172b50b72dce001.png”, “url”: “https:\/\/www.ransomware.live\/id\/S2luZ3N0b24gVGVjaG5vbG9neUBldmVyZXN0”, “victim”: “Kingston Technology” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-20T02:53:43.217469+00:00”, “claim_url”: “http:\/\/everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion\/news\/experts-entreprendre”, “country”: “FR”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T03:54:00.679781+00:00”, “domain”: “expert-entreprendre.com”, “group”: “everest”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T07:37:28.263792”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a49e7472c6284888c2d263ec51459e93.png”, “url”: “https:\/\/www.ransomware.live\/id\/RXhwZXJ0cyBFbnRyZXByZW5kcmVAZXZlcmVzdA==”, “victim”: “Experts Entreprendre” }, { “activity”: “Other”, “attackdate”: “2026-08-20T02:53:24.230662+00:00”, “claim_url”: “http:\/\/everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion\/news\/grupo-dt”, “country”: “ES”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-08-20T02:53:41.315894+00:00”, “domain”: “grupodt.es”, “group”: “everest”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-20T07:38:28.402861”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/37d2fb6f1963241c816b3d24f30f4f5e.png”, “url”: “https:\/\/www.ransomware.live\/id\/R3J1cG8gRFRAZXZlcmVzdA==”, “victim”: “Grupo DT” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-20T01:52:45.089178+00:00”, “claim_url”: “http:\/\/everestndkvzcibcje2cqxhre2hmmybl3rn2gwzwsblz7gx6uryn5rad.onion\/news\/capgemini-engineering”, “country”: “FR”, “data_size”: null, “description”: “[AI generated] Capgemini Engineering is a global technology and engineering services company headquartered in France. It provides R&D and engineering outsourcing services across industries including aerospace, automotive, telecommunications, energy, and semiconductors. Operating in over 30 countries, it combines software, hardware, and connected systems expertise to help clients design, develop, and deploy innovative products and digital solutions.”, “discovered”: “2026-08-20T02:53:03.557990+00:00”, “domain”: “capgemini.com”, “group”: “everest”, “infostealer”: { “employees”: 2082, “employees_url”: 100, “infostealer_stats”: { “Acreed”: 122, “Atomic”: 7, “Azorult”: 286, “CRYPTBOT”: 111, “DarkCrystal”: 7, “Ficker”: 17, “Generic Stealer”: 2918, “KPOT”: 2, “Lumma”: 2278, “Predator”: 15, “Raccoon”: 1316, “RedLine”: 2331, “Remus”: 5, “StealC”: 363, “Taurus”: 4, “UNKNOWN”: 118, “Vidar”: 505 }, “last_employee_compromised”: “2026-08-17T00:00:00+00:00”, “last_user_compromised”: “2026-08-17T00:00:00+00:00”, “thirdparties”: 2720, “update”: “2026-08-20T07:36:01.137388”, “users”: 8672, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/998877d00f2bce5ce762b4a92effe597.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q2FwZ2VtaW5pIEVuZ2luZWVyaW5nQGV2ZXJlc3Q=”, “victim”: “Capgemini Engineering” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-08-20T00:00:45.349971+00:00”, “claim_url”: “http:\/\/2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onion\/company\/target\/”, “country”: “US”, “data_size”: null, “description”: “General merchandise retail”, “discovered”: “2026-08-20T00:00:59.697641+00:00”, “domain”: “target.com”, “group”: “xpl0itrs”, “infostealer”: { “employees”: 39, “employees_url”: 27, “infostealer_stats”: { “Acreed”: 1400, “Atomic”: 144, “Aura Stealer”: 3, “Azorult”: 4434, “CRYPTBOT”: 72, “DarkCrystal”: 38, “Ficker”: 3, “Generic Stealer”: 13221, “KPOT”: 1, “Lumma”: 7401, “Mystic”: 32, “Predator”: 6, “Raccoon”: 3539, “RedLine”: 16431, “Remus”: 31, “StealC”: 629, “Taurus”: 68, “UNKNOWN”: 830, “Vidar”: 1717 }, “last_employee_compromised”: “2026-05-19T20:49:35+00:00”, “last_user_compromised”: “2026-08-19T02:21:59.071000+00:00”, “thirdparties”: 107, “update”: “2026-08-20T07:36:32.172788”, “users”: 131772, “users_url”: 100 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c51886b01d079e72863294beed262913.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGFyZ2V0QHhwbDBpdHJz”, “victim”: “Target” }, { “activity”: “Technology”, “attackdate”: “2026-08-20T00:00:00+00:00”, “claim_url”: “http:\/\/pearsmob5sn44ismokiusuld34pnfwi6ctgin3qbvonpoob4lh3rmtqd.onion\/Companies\/islandnetjm”, “country”: “JM”, “data_size”: null, “description”: “Provider for Business-class Internet, Cybersecurity & Home Wi-Fi”, “discovered”: “2026-08-22T07:57:34.331049+00:00”, “domain”: “islandnetjm.com”, “group”: “pear”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: { “Generic Stealer”: 1 }, “last_employee_compromised”: “1970-01-01T00:00:00+00:00”, “last_user_compromised”: “2025-11-01T18:02:16.678000+00:00”, “thirdparties”: 1, “update”: “2026-08-22T07:57:21”, “users”: 1, “users_url”: 1 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/3d3e4ca9057f0d3545125c4308a31942.png”, “url”: “https:\/\/www.ransomware.live\/id\/SXNsYW5kIE5ldHdvcmtzQHBlYXI=”, “victim”: “Island Networks” }, { “activity”: “Professional Services”, “attackdate”: “2026-08-20T00:00:00+00:00”, “claim_url”: “http:\/\/pearsmob5sn44ismokiusuld34pnfwi6ctgin3qbvonpoob4lh3rmtqd.onion\/Companies\/mgrlaw”, “country”: “US”, “data_size”: null, “description”: “Services in family law”, “discovered”: “2026-08-22T07:57:08.921168+00:00”, “domain”: “mgrlaw.com”, “group”: “pear”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T07:56:54”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a0bac84758360eb2c281428f3b1f0e30.png”, “url”: “https:\/\/www.ransomware.live\/id\/TW9ncmVuLCBHbGVzc25lciAmIEFocmVucywgUC5TLkBwZWFy”, “victim”: “Mogren, Glessner & Ahrens, P.S.” }, { “activity”: “Government & Defense”, “attackdate”: “2026-08-20T00:00:00+00:00”, “claim_url”: “”, “country”: “ES”, “data_size”: null, “description”: “El Ayuntamiento de Velilla de San Antonio es el organismo oficial de gobierno local y administraci\u00f3n del municipio de Velilla de San Antonio, situado en la Comunidad de Madrid, Espa\u00f1a. Gestiona los servicios p\u00fablicos, el padr\u00f3n, los impuestos locales y la vida ciudadana de la localidad.”, “discovered”: “2026-08-20T18:54:17.542228+00:00”, “domain”: “ayto-velilla.es”, “group”: “kairos”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-21T05:30:56.832595”, “users”: 2, “users_url”: 3 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QXl1bnRhbWllbnRvIGRlIFZlbGlsbGEgZGUgU2FuIEFudG9uaW9Aa2Fpcm9z”, “victim”: “Ayuntamiento de Velilla de San Antonio” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-08-20T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Cascade Coffee is a premier gourmet coffee contract manufacturer based near Seattle, Washington\n, specializing in roasting, grinding, flavoring, and packaging coffee. The company caters to so\nme of the world’s finest coffee brands, providing a wide range of products including whole bean\n, ground, flavored coffees, and specialty blends.\n\nWe will upload corporate data soon. Detailed personal employee information (passports, DLs, add\nresses, phones, car information), details, financials, contracts and agreements, NDAs and so on\n.\n”, “discovered”: “2026-08-20T14:21:22.360343+00:00”, “domain”: “cascadecoffee.com”, “group”: “akira”, “infostealer”: { “employees”: 0, “employees_url”: 0, “infostealer_stats”: [], “last_employee_compromised”: null, “last_user_compromised”: null, “thirdparties”: 0, “update”: “2026-08-22T05:49:00.296199”, “users”: 0, “users_url”: 0 }, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Q2FzY2FkZSBDb2ZmZWVAYWtpcmE=”, “victim”: “Cascade Coffee” } ]