{ “groups”: 407, “victims”: 32579 }
[ { “activity”: “Manufacturing”, “attackdate”: “2026-10-10T20:04:49.616282+00:00”, “claim_url”: “http:\/\/xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion\/blog\/?post_uuid=b895683d-2b2c-48ae-89b1-31aea880f383”, “country”: “TW”, “data_size”: null, “description”: “TEXMA International Co., Ltd. is a leading Taiwanese apparel manufacturer specializing in high-quality women’s woven apparel, activewear, and sportswear. Founded in 1975, the company operates under a \”Taiwan orders, global production\” business model, supplying some of the world’s most recognizable fashion brands.”, “discovered”: “2026-10-10T20:31:45.583913+00:00”, “domain”: “texma.com.tw”, “group”: “dragonforce”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/af703a7360550825c7e5d59814fdb673.png”, “url”: “https:\/\/www.ransomware.live\/id\/VEVYTUEgSW50ZXJuYXRpb25hbCBDby4sIEx0ZEBkcmFnb25mb3JjZQ==”, “victim”: “TEXMA International Co., Ltd” }, { “activity”: “Government & Defense”, “attackdate”: “2026-10-10T18:02:05+00:00”, “claim_url”: “”, “country”: “TH”, “data_size”: null, “description”: “rtaf.mi.th is the official portal of the Royal Thai Air Force, one of Asia’s oldest air forces (founded November 2, 1913; independent since 1937), with ~46,000 personnel and 11 combat wings, now running a modern Odoo-based portal publishing financial reports, procurement plans, and White Papers on its \”Unbeatable Air Force\” roadmap to 2037. Its fleet spans 46 F-16s, 11 Gripen C\/D, 13 F-5TH Super Tigris, Saab 340 Erieye AEW&C, C-130s, and a VIP fleet including an ex-Thai Airways A340-500. In July 2025 the RTAF fought its first combat since 1988 in the Thai-Cambodian border conflict, with its Gripens achieving the type’s first-ever combat weapons launch. The centerpiece modernization is the Gripen E\/F program: Thailand signed the $550M \”Peace Burapha 1\” contract in August 2025 \u2014 first in APAC \u2014 with deliveries from 2029 and 8 more jets sought toward a 12-aircraft squadron by 2037. Air Chief Marshal Seksan Kantha, the 31st commander since October 2025″, “discovered”: “2026-10-10T20:30:08.186003+00:00”, “domain”: “rtaf.mi.th”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Um95YWwgVGhhaSBBaXIgRm9yY2VAdGhlZ2VudGxlbWVu”, “victim”: “Royal Thai Air Force” }, { “activity”: “Education”, “attackdate”: “2026-10-10T16:54:02.119535+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “EG”, “data_size”: null, “description”: “Helwan International Technological University \u2014 a pioneering Egyptian institution offering cutting-edge programs in Cybersecurity, Data Science, Artificial Intelligence, and Mechatronics, equipped with advanced labs and strong industry partnerships to prepare students for the digital future.”, “discovered”: “2026-10-10T16:54:23.654958+00:00”, “domain”: “helwan.edu.eg”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/SGVsd2FuIFVuaXZlcnNpdHkgKEhJVFUpQFVtQnJh”, “victim”: “Helwan University (HITU)” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-10T16:53:11.980798+00:00”, “claim_url”: “http:\/\/neclc36yt4yaa5lv54kh4qbhvjcvuv6nnaurqowkellytpvj3afh4aid.onion”, “country”: “US”, “data_size”: null, “description”: “Sector: Medical Equipment | Revenue: $4.97B USD”, “discovered”: “2026-10-10T16:53:38.697114+00:00”, “domain”: “dexcom.com”, “group”: “Redact”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/dde43211c986889efac13449e9a1813d.png”, “url”: “https:\/\/www.ransomware.live\/id\/RGV4Q29tQFJlZGFjdA==”, “victim”: “DexCom” }, { “activity”: “Other”, “attackdate”: “2026-10-10T16:06:14.655018+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=6e8bbd6e-69b7-4987-bf25-f6957818db17”, “country”: “CO”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-10T16:06:32.517468+00:00”, “domain”: “www.aciproyectos.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/268643db4927c9f66b176d5c49e755cf.png”, “url”: “https:\/\/www.ransomware.live\/id\/QUNJIFByb3llY3RvcyBTQVNAcWlsaW4=”, “victim”: “ACI Proyectos SAS” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-10T14:31:32.355306+00:00”, “claim_url”: “http:\/\/m3ksukzn2glzfdvlusohril7n3iyk4z4fudf6mm22lwhpbpt5aiee5qd.onion#KOIKE%20Sanso%20Kogoyo%20Co.%20Ltd.”, “country”: “JP”, “data_size”: null, “description”: “Website: koike-japan.com\nYou have time until Tuesday(10.13.2026). If you wouldn’t contact us we will start selling data.\nWe have 5.8 TB of data: \nagreements\nconfidential data \ncorrespondence files\nall customers and clients data\nengineering drawings \nAND MUCH MORE…\n\nContact us until your time runs out.”, “discovered”: “2026-10-10T14:31:50.448423+00:00”, “domain”: “koike-asia.com”, “group”: “exitium”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c81dede367c10a30f7403435fa01065f.png”, “url”: “https:\/\/www.ransomware.live\/id\/S09JS0UgU2Fuc28gS29nb3lvIENvLiBMdGQuQGV4aXRpdW0=”, “victim”: “KOIKE Sanso Kogoyo Co. Ltd.” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-10T12:46:25.165608+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=282”, “country”: “US”, “data_size”: null, “description”: “Gress Clark Young & Schoepper 167,804 files \/ ~166.4 GBBanking details – of the firm and its clients.SSNs + signatures of clients\/witnesses; W-9, I-9 forms with DL\/SSN card copies; W-4 forms.BIIA case-management procedures (Board of Industrial Insurance Appeals): default orders (Order of Default), internal ‘Conference Questions’, consulting-fee payments to experts.Firm finances: the firm’s QuickBooks company file, VOID checks bearing signatures, expert-payment records, SaaS invoices.Medical photos and imaging; hundreds of pages of PHI\/APF (Activity Prescription Forms) – X-rays, complete medical records.’Coaching’ letters to doctors – including a letter to the physician in the Jachacy matter with wording indicative of steering a medical opinion (‘coaching letter’) – a potential ethics violation regarding witness handling.Credentials\/access to the SPC e-file system (court e-filing).Disciplinary action against partner Daniel W. Gress. More”, “discovered”: “2026-10-10T12:46:50.865750+00:00”, “domain”: “gressandclarklaw.com”, “group”: “rhysida”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f626d52dc6305c1c670eb771cafe32d1.png”, “url”: “https:\/\/www.ransomware.live\/id\/R3Jlc3MgQ2xhcmsgWW91bmcgJiBTY2hvZXBwZXJAcmh5c2lkYQ==”, “victim”: “Gress Clark Young & Schoepper” }, { “activity”: “Hospitality”, “attackdate”: “2026-10-10T12:45:30.756183+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=64c96687-0ac2-4814-927a-9a898e162e7b”, “country”: “US”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-10T12:45:59.206369+00:00”, “domain”: “www.glenhardiecc.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/eada10de7b52ebe778f9fcc115c75697.png”, “url”: “https:\/\/www.ransomware.live\/id\/R2xlbmhhcmRpZSBDb3VudHJ5IENsdWJAcWlsaW4=”, “victim”: “Glenhardie Country Club” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-10T12:44:37.847387+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=6a330232-150f-4da4-a303-01abb01bd7eb”, “country”: “CL”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-10T12:45:10.486069+00:00”, “domain”: “www.ldconstructora.cl”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TEQgQ29uc3RydWN0b3JhQHFpbGlu”, “victim”: “LD Constructora” }, { “activity”: “Not Found”, “attackdate”: “2026-10-09T22:51:47.778927+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “Saber1 Technologies LLC is a American supplier and distributor of machine vision components, industrial cameras and image processing systems.”, “discovered”: “2026-10-09T22:51:48.912828+00:00”, “domain”: “saber1.com”, “group”: “Deadlock”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/U2FiZXIxQERlYWRsb2Nr”, “victim”: “Saber1” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-09T22:51:26.429631+00:00”, “claim_url”: “”, “country”: “ES”, “data_size”: null, “description”: “idi pharma is an Italian pharmaceutical company specializing in the research and development of innovative nutraceuticals and medical devices. The company focuses on formulations covered by patents and unique dosage technologies to improve patient health and quality of life (but their data leak).”, “discovered”: “2026-10-09T22:51:27.775430+00:00”, “domain”: “www.idipharma.com”, “group”: “Deadlock”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/aWRpIHBoYXJtYUBEZWFkbG9jaw==”, “victim”: “idi pharma” }, { “activity”: “Hospitality”, “attackdate”: “2026-10-09T22:10:13.152190+00:00”, “claim_url”: “http:\/\/safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion\/blog\/post\/hoteldelfinoluganoch\/”, “country”: “CH”, “data_size”: null, “description”: “The hotel was founded in 1972 and has been managed directly by the Haas family for four generations. Since 2001, \u2026”, “discovered”: “2026-10-09T22:10:29.512693+00:00”, “domain”: “hoteldelfinolugano.ch”, “group”: “safepay”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2cc2f37504dc434c428b6a06f7c7e035.png”, “url”: “https:\/\/www.ransomware.live\/id\/aG90ZWxkZWxmaW5vbHVnYW5vLmNoQHNhZmVwYXk=”, “victim”: “hoteldelfinolugano.ch” }, { “activity”: “Other”, “attackdate”: “2026-10-09T22:09:25.453136+00:00”, “claim_url”: “http:\/\/safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion\/blog\/post\/dwi-baude\/”, “country”: “DE”, “data_size”: null, “description”: “The company specializes in building systems for metal roofs and facades, serving customers in the construction and building sectors. Its \u2026”, “discovered”: “2026-10-09T22:09:44.515861+00:00”, “domain”: “dwi-bau.de”, “group”: “safepay”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/df12bcbbc935a00e943b59c41f2fa09b.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZHdpLWJhdS5kZUBzYWZlcGF5”, “victim”: “dwi-bau.de” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-10-09T21:20:10+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/supreme-energy”, “country”: “SG”, “data_size”: null, “description”: “Supreme Energy is an Indonesian renewable-energy company that develops geothermal power projects to generate clean electricity.”, “discovered”: “2026-10-09T21:25:22.284883+00:00”, “domain”: “”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/ac6cbc2ecbfc883fc19a184be327cc97.png”, “url”: “https:\/\/www.ransomware.live\/id\/U3VwcmVtZSBFbmVyZ3lAUGFuemVy”, “victim”: “Supreme Energy” }, { “activity”: “Technology”, “attackdate”: “2026-10-09T21:15:58+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/solutend”, “country”: “”, “data_size”: null, “description”: “Bolivian technology company that provides audiovisual systems, digital signage, interactive displays, and business computing solutions.”, “discovered”: “2026-10-09T21:24:50.670968+00:00”, “domain”: “”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b8d16dc0e9be5352eea49c145eb2900d.png”, “url”: “https:\/\/www.ransomware.live\/id\/c29sdXRlbmRAUGFuemVy”, “victim”: “solutend” }, { “activity”: “Not Found”, “attackdate”: “2026-10-09T20:07:41.988255+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=45bf5b10-ebf4-4c21-b7f3-d67531a86863”, “country”: “SE”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-09T20:08:10.108235+00:00”, “domain”: “www.vadetogroup.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/da6ee6c7a7567e58377acc1dc3e1713b.png”, “url”: “https:\/\/www.ransomware.live\/id\/VmFkZXRvIEdyb3VwQHFpbGlu”, “victim”: “Vadeto Group” }, { “activity”: “Transportation”, “attackdate”: “2026-10-09T19:33:21.471991+00:00”, “claim_url”: “http:\/\/threeamkelxicjsaf2czjyz2lc4q3ngqkxhhlexyfcp2o6raw4rphyad.onion\/detail\/2j6omt34vg6p5jjsdnb9iljb3g2y18”, “country”: “US”, “data_size”: null, “description”: “Fleetworks Inc. offers comprehensive heavy-duty truck repair and fleet services across California, with locations in Oakland, Santa Fe Springs, and Riverside. Their skilled team specializes in a wide range of services including diesel repair, flee”, “discovered”: “2026-10-09T19:33:42.469953+00:00”, “domain”: “fleetworksinc.com”, “group”: “threeam”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c29a6d971d8238c2351e5d7b046d80a4.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZmxlZXR3b3Jrc2luYy5jb21AdGhyZWVhbQ==”, “victim”: “fleetworksinc.com” }, { “activity”: “Technology”, “attackdate”: “2026-10-09T18:05:20.869709+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=2c77552f-9b72-4958-b644-d9aa697380d3”, “country”: “FI”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-09T18:05:46.973522+00:00”, “domain”: ” www.tepcomp.fi”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a0d26e27697af4e25c381fef1095bea6.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGVwY29tcEBxaWxpbg==”, “victim”: “Tepcomp” }, { “activity”: “Education”, “attackdate”: “2026-10-09T18:01:42.661165+00:00”, “claim_url”: “http:\/\/mqiq3x2ghaoy4w36gqk6bqgta5y6x4bchf5ejh5ytsekug7c46rryxyd.onion\/index.php?p=”, “country”: “US”, “data_size”: null, “description”: “As a school, Shalom Christian Academy is legally and ethically obligated to maintain a wide range of confidential information. However, they are grossly negligent in protecting their own security and that of their students and staff. Consequently, we provide you with student grades, disciplinary and special education records, health and immunization records, financial aid and tuition information, donation history, employee background checks, salary data, and internal security documents. This leak into the public domain constitutes an unacceptable betrayal that can lead to identity theft, financial fraud, extortion, harassment, and devastating harm to children and families. The school is culpable for this act and must be held accountable to the fullest extent of the law.”, “discovered”: “2026-10-09T18:02:14.927410+00:00”, “domain”: “shalomca.com”, “group”: “interlock”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/U2hhbG9tIENocmlzdGlhbiBBY2FkZW15QGludGVybG9jaw==”, “victim”: “Shalom Christian Academy” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-09T17:27:16.082628+00:00”, “claim_url”: “http:\/\/om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion\/r\/YCPIrn+gKQU5fApLYhqeuR7sko8OodBRK+atohofjQQGM1g3QrZSPuAlcj4xbB7PtIJF5ptwSf4gHZQ+hxecclp6ZnBIaU1r”, “country”: “”, “data_size”: null, “description”: “Property owners\u2019 personal data.”, “discovered”: “2026-10-09T17:28:37.344824+00:00”, “domain”: “”, “group”: “anubis”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/e546a0b391c14b55e7dd60b68cdb0b60.png”, “url”: “https:\/\/www.ransomware.live\/id\/TXluZEBhbnViaXM=”, “victim”: “Mynd” }, { “activity”: “Financial Services”, “attackdate”: “2026-10-09T15:59:04.035000+00:00”, “claim_url”: “http:\/\/blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion\/target\/6ac90f73698707a00251b714”, “country”: “GB”, “data_size”: null, “description”: “Lopay is a UK-based fintech company that provides a payment platform enabling small and medium-sized enterprises (SMEs) and sole traders to accept credit card and mobile payments, as well as manage their sales and settlements. This includes financial information belonging to client companies, such as customer payment details, card information, banking data, transaction history, and payment terminal information.”, “discovered”: “2026-10-09T19:12:37.596311+00:00”, “domain”: “lopay.com”, “group”: “Black X”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a68d6f28c18e5df0fb8af5aa6b3ef8ec.png”, “url”: “https:\/\/www.ransomware.live\/id\/bG9wYXlAQmxhY2sgWA==”, “victim”: “lopay” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-10-09T15:52:00+00:00”, “claim_url”: “http:\/\/emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion\/post\/imperial-diamond-jewellery\/”, “country”: “”, “data_size”: null, “description”: “Engaged in the sale of jewelry made of precious metals, \ndiamond jewelry and the manufacture of custom jewelry.\nCountry: Hong Kong, China. Year of foundation: 2011\nFinancial documents, personal and customer data. [Sector: Manufacturing, Finance]”, “discovered”: “2026-10-09T17:21:57.756871+00:00”, “domain”: “”, “group”: “emperador”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/feae521d9461d03253fa1707d7e48f0c.png”, “url”: “https:\/\/www.ransomware.live\/id\/SW1wZXJpYWwgRGlhbW9uZCBKZXdlbGxlcnlAZW1wZXJhZG9y”, “victim”: “Imperial Diamond Jewellery” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-09T14:14:47.332385+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=a0fbcecd-f9ad-49ca-8a41-16ebba61af99”, “country”: “IT”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-09T14:15:33.839294+00:00”, “domain”: “www.melchioni.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/311fc1adf0b90baff77b316b85b7021c.png”, “url”: “https:\/\/www.ransomware.live\/id\/TWVsY2hpb25pIFNwYUBxaWxpbg==”, “victim”: “Melchioni Spa” }, { “activity”: “Technology”, “attackdate”: “2026-10-09T13:58:20.640000+00:00”, “claim_url”: “http:\/\/blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion\/target\/6ac8f325698707a00251b3ee”, “country”: “JP”, “data_size”: null, “description”: “enTouch is a Japanese IT company specializing in the medical and pharmaceutical sectors, providing services for online consultations, sales activities, and customer data management between pharmaceutical companies and medical institutions. We possess the entire database from data.entouch.jp, the data analysis system used by enTouch. The database contains sensitive customer information, including names, contact details, consultation schedules and records, and sales activity data categorized by pharmaceutical company.”, “discovered”: “2026-10-09T19:13:19.588979+00:00”, “domain”: “entouch.jp”, “group”: “Black X”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/560bd2a4d225e04869ede2068dca6e70.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZW5Ub3VjaEBCbGFjayBY”, “victim”: “enTouch” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-09T12:51:50+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=833”, “country”: “MX”, “data_size”: null, “description”: “ladrillera.mx\/\u2014Ladrillera Mecanizada is the largest producer and exporter of 100% natural Deadline: 2026-10-16 12:44:00.000000”, “discovered”: “2026-10-09T13:30:13.573522+00:00”, “domain”: “ladrillera.mx”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c842244fa23d82911a030ccb7771138c.png”, “url”: “https:\/\/www.ransomware.live\/id\/TGFkcmlsbGVyYSBNZWNhbml6YWRhQGFyY3VzbWVkaWE=”, “victim”: “Ladrillera Mecanizada” }, { “activity”: “Not Found”, “attackdate”: “2026-10-09T12:51:41+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=829”, “country”: “CA”, “data_size”: null, “description”: “mblllp.ca\u2014Our objective at MBL LLP is simple: To always exceed the expectations of our cli Deadline: 2026-10-16 12:44:00.000000”, “discovered”: “2026-10-09T13:30:47.891304+00:00”, “domain”: “mblllp.ca”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/54454214a0c75529bb8d8c1663e21437.png”, “url”: “https:\/\/www.ransomware.live\/id\/bWJsbGxwQGFyY3VzbWVkaWE=”, “victim”: “mblllp” }, { “activity”: “Not Found”, “attackdate”: “2026-10-09T12:50:13+00:00”, “claim_url”: “http:\/\/arcuufpr5xxbbkin4mlidt7itmr6znlppk63jbtkeguuhszmc5g7qdyd.onion\/?p=831”, “country”: “BR”, “data_size”: null, “description”: “Aethos Sistemas offers a comprehensive suite of software solutions designed to streamline Deadline: 2026-10-16 12:44:00.000000”, “discovered”: “2026-10-09T13:31:23.706804+00:00”, “domain”: “aethosconsultoria.com.br”, “group”: “arcusmedia”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1f6ad413f37efeeda6a792c5e45af394.png”, “url”: “https:\/\/www.ransomware.live\/id\/QUVUSE9TQGFyY3VzbWVkaWE=”, “victim”: “AETHOS” }, { “activity”: “Other”, “attackdate”: “2026-10-09T12:37:00.057257+00:00”, “claim_url”: “http:\/\/bravoxxwcfz5qk43ychgveprpd5mw5hvxfs4a2uz2okx7mumiht4fzyd.onion\/blog\/4043786e-3518-4171-b082-b3a995fa0d75”, “country”: “US”, “data_size”: null, “description”: “Dudley Land Company, Inc. is a U.S. land-services company founded in 1980 and headquartered in Oklahoma City, Oklahoma. For more than four decades, it has supported energy and infrastructure projects across the United States.”, “discovered”: “2026-10-09T12:37:17.746583+00:00”, “domain”: “www.dudley-land.com”, “group”: “bravox”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/fe60a2da7f5282b5c75c75f0ea1e11b3.png”, “url”: “https:\/\/www.ransomware.live\/id\/RHVkbGV5IExhbmQgQ29tcGFueUBicmF2b3g=”, “victim”: “Dudley Land Company” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-09T12:22:49.310000+00:00”, “claim_url”: “http:\/\/blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion\/target\/6ac8dc81698707a00251b256”, “country”: “DE”, “data_size”: null, “description”: “Bayer is a global life science company with more than 160 years of innovation behind us. Operating at the intersection of health and nutrition, we are committed to addressing some of society’s most pressing challenges and creating lasting value for people, communities, and the world around us.”, “discovered”: “2026-10-09T19:14:00.205357+00:00”, “domain”: “www.bayer.com\/en”, “group”: “Black X”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/192ae3c66fa5e79d6b69711850e33d2a.png”, “url”: “https:\/\/www.ransomware.live\/id\/YmF5ZXJAQmxhY2sgWA==”, “victim”: “bayer” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-09T12:22:05.037000+00:00”, “claim_url”: “http:\/\/termiteuslbumdge2zmfmfcsrvmvsfe4gvyudc5j6cdnisnhtftvokid.onion\/post\/6ab0fe8700ab5ab6ab5a1389”, “country”: “BR”, “data_size”: null, “description”: “iDentalSoft offers a cloud-based dental practice management software that is secure, modern, and designed for efficiency. The software provides comprehensive features such as smart scheduling, advanced clinical charting, and patient communication tools, making it suitable for both single and multi-practice management.”, “discovered”: “2026-10-09T12:59:37.236746+00:00”, “domain”: “www.identalsoft.com”, “group”: “termite”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/186c713da2ae2516e91d2e95b5464515.png”, “url”: “https:\/\/www.ransomware.live\/id\/aURlbnRhbFNvZnRAdGVybWl0ZQ==”, “victim”: “iDentalSoft” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-09T12:09:34.421365+00:00”, “claim_url”: “http:\/\/rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion\/archive.php?company=281”, “country”: “US”, “data_size”: null, “description”: “RealManage RealManage is a privately held, tech-enabled community association management company headquartered in Plano, Texas. Founded in 2002 and backed by American Securities, the company has grown into one of the largest and fastest-growing community association management firms in the United States, having been recognized on the Inc.1.84 TBThe tax, banking and debt secrets of hundreds of American HOAs and thousands of homeowners – complete with SSNs, account numbers and signatures.Genuine W-9 forms with Social Security numbers, addresses and signatures; IRS 1099-MISC\/NEC e-file transmissions for 2014\ufffd2025 – thousands of vendor TINs\/SSNsHomeowners’ banking keys: ACH debit files with routing and account numbers, USAA brokerage statements, signed bank signature cardsPeople’s debts by name: assessments through September 2026, bankruptcies, late-fee waivers, hardship letters from debtors begging for payment plansPersonal documents: HUD-1 home purchase settlements (names, prices, mortgages), signed waivers with addresses, HOA election ballots with voter namesFull SQL Server databases: RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity (portal accounts), CiraBooks_GL (general ledger)Mail and document flow: CiraMail$, CiraDocs$, SalesDocs$ More”, “discovered”: “2026-10-09T12:10:15.176224+00:00”, “domain”: “”, “group”: “rhysida”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/8906edabfd1f4aac9263b446a2b7aae7.png”, “url”: “https:\/\/www.ransomware.live\/id\/UmVhbE1hbmFnZUByaHlzaWRh”, “victim”: “RealManage” }, { “activity”: “Not Found”, “attackdate”: “2026-10-09T11:10:56.274008+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=02c84896-69ec-44c2-a179-277329fd86fc”, “country”: “IL”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-09T11:11:18.416828+00:00”, “domain”: “www.hagiva.co.il”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d0424be7e136d49ccf4acb62818cec85.png”, “url”: “https:\/\/www.ransomware.live\/id\/SGFnaXZhIFloQHFpbGlu”, “victim”: “Hagiva Yh” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-10-09T04:20:20.773861+00:00”, “claim_url”: “http:\/\/qr6uopkqxmq254osyct3oibil32xp3qsimkkbqdscsrsb4zqbagnifad.onion\/MPS-CROATIA.txt?download=1”, “country”: “HR”, “data_size”: null, “description”: “We have complete database dumps from the Ministry of Agriculture and all documents from its main file server. They contain information about residents of Croatia, including agricultural registration records and personal data such as phone numbers, surnames, first names, and photos, as well as details about each resident\u2019s agricultural activities. We also have Ministry of Agriculture contracts and other confidential documents.\nRecently, the authorities claimed that no data breach had occurred. It\u2019s unfortunate that this was a lie.\nhttps:\/\/mps.hr | Status: selling | $50,000”, “discovered”: “2026-10-09T04:20:25.706924+00:00”, “domain”: “poljoprivreda.gov.hr”, “group”: “Barracuda”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWluaXN0YXJzdHZvIHBvbGpvcHJpdnJlZGUsIMWhdW1hcnN0dmEgaSByaWJhcnN0dmFAQmFycmFjdWRh”, “victim”: “Ministarstvo poljoprivrede, \u0161umarstva i ribarstva” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-09T00:00:00+00:00”, “claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion\/#Deloitte”, “country”: “US”, “data_size”: null, “description”: “www.deloitte.com https:\/\/www.zoominfo.com\/c\/deloitte\/14812699 Revenue\r\n$74.5 Billion Deloitte is a global professional services organization providing audit and assurance, consulting, financial advisory, risk advisory, tax, legal and related services. Its capabilities also span cybersecurity, AI and data, enterprise technology, human capital and business process solutions. Deloitte serves organizations across a wide range of industries, helping clients manage complex challenges, transform operations, navigate risks, and drive sustainable growth. \r\nData info – soon”, “discovered”: “2026-10-09T19:21:30.182669+00:00”, “domain”: “www.deloitte.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/605c7d7538b9f6f3743a851bd9187ad8.png”, “url”: “https:\/\/www.ransomware.live\/id\/RGVsb2l0dGVAdGhlZ2VudGxlbWVu”, “victim”: “Deloitte” }, { “activity”: “Other”, “attackdate”: “2026-10-09T00:00:00+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “YAREMA specializes in metal fabrication and assembly services. The company offers a range of cu\nstom solutions to meet various industrial needs. Their intended clients include manufacturers a\nnd businesses requiring precision metalwork.\n\nWe will upload 13gb of corporate data soon. Employee information (passports, DLs, SSNs (scans a\nnd 45 numbers)), projects, client info, NDAs and so on.\n”, “discovered”: “2026-10-09T13:29:16.968913+00:00”, “domain”: “”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/WWFyZW1hQGFraXJh”, “victim”: “Yarema” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-09T00:00:00+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “Design Electric is a company specializing in industrial, government & transportation electrical\nin St. Cloud, MN.\n\nWe will upload 15gb of corporate data soon. Detailed employee information (passports, DLs of mo\nre than 100 employees, about 350 SSN numbers, addresses, phones and so on), projects, lots of c\nontacts, client info, NDA and so on.\n”, “discovered”: “2026-10-09T12:35:35.763382+00:00”, “domain”: “”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/RGVzaWduIEVsZWN0cmljQGFraXJh”, “victim”: “Design Electric” }, { “activity”: “Other”, “attackdate”: “2026-10-09T00:00:00+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “DCC is a full-service print and packaging provider located in NJ, NY, and MA, specializing in t\nransforming creative ideas into high-quality communication tools. They offer a wide range of se\nrvices including offset printing, digital printing, large format printing, and packaging soluti\nons tailored for various industries such as pharmaceuticals, beauty, retail, and consumer goods\n.\n\nWe will upload 9 gb of corporate data soon. Employee and clients personal information, projects\nand so on.\n”, “discovered”: “2026-10-09T12:35:16.047263+00:00”, “domain”: “”, “group”: “akira”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VGlnZXJQcmVzcyAoRENDKUBha2lyYQ==”, “victim”: “TigerPress (DCC)” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-09T00:00:00+00:00”, “claim_url”: “”, “country”: “AE”, “data_size”: null, “description”: “Data is not available now.”, “discovered”: “2026-10-09T06:03:43.772196+00:00”, “domain”: “”, “group”: “nightspire”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UE1HIFByb2plY3QgTWFuYWdlbWVudCBHcm91cEBuaWdodHNwaXJl”, “victim”: “PMG Project Management Group” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-08T23:22:08.028078+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “U.S. national law firm focused primarily on business litigation and labor & employment law. It was fou\u2026”, “discovered”: “2026-10-08T23:22:09.715901+00:00”, “domain”: “ohaganmeyer.com”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TydIYWdhbiBNZXllckBTaWxlbnRSYW5zb21Hcm91cA==”, “victim”: “O’Hagan Meyer” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-08T22:40:05.070307+00:00”, “claim_url”: “http:\/\/netrunrsb3bivj5gnwajzxlig5qkteb6edgthxj7fmsvhkzxtwfxwaad.onion\/view\/MAGOPSA”, “country”: “US”, “data_size”: null, “description”: “Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates (MAGOPSA) is one of the largest single groups of gynecologic oncologists in the mid-Atlantic region.”, “discovered”: “2026-10-08T22:40:26.720698+00:00”, “domain”: “www.magopsa.com”, “group”: “netrunner”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/616b2db50a4bae8a4eb22f3c189e2612.png”, “url”: “https:\/\/www.ransomware.live\/id\/TWlkIEF0bGFudGljIEd5bmVjb2xvZ2ljIE9uY29sb2d5IGFuZCBQZWx2aWMgU3VyZ2VyeSBBc3NvY2lhdGVzQG5ldHJ1bm5lcg==”, “victim”: “Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates” }, { “activity”: “Technology”, “attackdate”: “2026-10-08T21:36:23.658445+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “BR”, “data_size”: null, “description”: “SOCOCO \u2014 A Brazilian mid-sized food company with 40 employees, blending tradition and modern marketing through WordPress-driven platforms.”, “discovered”: “2026-10-08T21:36:50.533825+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/U09DT0NPQFVtQnJh”, “victim”: “SOCOCO” }, { “activity”: “Technology”, “attackdate”: “2026-10-08T21:06:22.501849+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=145417bb-37b7-4537-af14-4c1bff717df3”, “country”: “MX”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-08T21:07:24.672943+00:00”, “domain”: “www.mcmtelecom.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TUNNIFRlbGVjb21AcWlsaW4=”, “victim”: “MCM Telecom” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-08T20:52:31.158437+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “[AI generated] Baker McKenzie is a global law firm headquartered in Chicago, Illinois, United States. Founded in 1949, it operates in the legal services industry, providing counsel in areas such as corporate law, tax, dispute resolution, mergers and acquisitions, employment law, and intellectual property. The firm serves multinational corporations and organizations, with offices across North America, Europe, Asia-Pacific, Latin America, and the Middle East.”, “discovered”: “2026-10-08T20:52:34.476155+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QmFrZXIgTWNLZW56aWVAU2lsZW50UmFuc29tR3JvdXA=”, “victim”: “Baker McKenzie” }, { “activity”: “Education”, “attackdate”: “2026-10-08T20:28:37.185281+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “IN”, “data_size”: null, “description”: “MAHE \u2014 India\u2019s global private university excelling in Medicine, Engineering, Business, and Research with 28,000+ students from 57 nations.”, “discovered”: “2026-10-08T20:29:01.377809+00:00”, “domain”: “manipaldubai.com”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/TWFuaXBhbCBBY2FkZW15IG9mIEhpZ2hlciBFZHVAVW1CcmE=”, “victim”: “Manipal Academy of Higher Edu” }, { “activity”: “Education”, “attackdate”: “2026-10-08T20:27:54.059177+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “IN”, “data_size”: null, “description”: “IIT Roorkee \u2014 India\u2019s oldest institute excelling in Engineering, Architecture, Computer Science, Water Resources, Energy, and Applied Sciences since 1847.”, “discovered”: “2026-10-08T20:28:18.438174+00:00”, “domain”: “iitr.ac.in”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/SUlUIFJvb3JrZWVAVW1CcmE=”, “victim”: “IIT Roorkee” }, { “activity”: “Education”, “attackdate”: “2026-10-08T20:27:07.617589+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “EG”, “data_size”: null, “description”: “FSE, Cairo University \u2014 Leading Egypt\u2019s future in arts, music, media, and creative education excellence.”, “discovered”: “2026-10-08T20:27:35.313179+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/RlNFLCBDYWlybyBVbml2ZXJzaXR5QFVtQnJh”, “victim”: “FSE, Cairo University” }, { “activity”: “Retail & E-Commerce”, “attackdate”: “2026-10-08T19:32:51.279392+00:00”, “claim_url”: “http:\/\/payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion\/posts\/c76973f9-dba2-4851-87b0-0c26fd6192f1”, “country”: “CH”, “data_size”: null, “description”: “Boullard Musique (boullard.ch) is one of Switzerland’s premier specialty retailers of musical instruments and audio gear, founded in Morges in 1979. The company operates a dedicated physical showroom alongside an extensive e-commerce platform offering acoustic instruments, electronic gear, and accessories. Beyond retail, they provide comprehensive instrument rentals, maintenance, and expert repair services through their on-site workshops.”, “discovered”: “2026-10-08T19:33:32.557265+00:00”, “domain”: “boullard.ch”, “group”: “payload”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f8ce3d9357949395312954e2c9e3fb22.png”, “url”: “https:\/\/www.ransomware.live\/id\/Qm91bGxhcmQgTXVzaXF1ZUBwYXlsb2Fk”, “victim”: “Boullard Musique” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-08T16:26:50.754614+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “(NYSE: ANDG) reported $217.7 million in revenue for the second quarter of 2026 and $838.7 million in f\u2026”, “discovered”: “2026-10-08T16:26:51.947000+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QW5kZXJzZW4gR3JvdXAgSW5jLkBTaWxlbnRSYW5zb21Hcm91cA==”, “victim”: “Andersen Group Inc.” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-08T11:53:42.058625+00:00”, “claim_url”: “http:\/\/vnoa7t4c3wr6himmurl4it3ctvgmm6munjknuztqlu4nbz34367vokyd.onion\/morton\/morton.html”, “country”: “US”, “data_size”: null, “description”: “Morton LTC is an independent fourth-generation family-owned Wisconsin pharmacy.”, “discovered”: “2026-10-08T11:54:06.766447+00:00”, “domain”: “”, “group”: “RunSomeWares”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2055a720d379af2b31495b48f8d82f6e.png”, “url”: “https:\/\/www.ransomware.live\/id\/TW9ydG9uIExUQyBQaGFybWFjeUBSdW5Tb21lV2FyZXM=”, “victim”: “Morton LTC Pharmacy” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-08T00:00:00+00:00”, “claim_url”: “http:\/\/yecdjimqiaekprxza6wkqecma4bwt757qiyfjngsaxg7rkjv4xukpwad.onion\/data\/dipecarr.com.br\/”, “country”: “BR”, “data_size”: null, “description”: “[AI generated] N\/A\n\nI don’t have reliable, verifiable information about a company operating at \”dipecarr.com.br.\” I’m unable to confirm its business activities, industry classification, or operational details with confidence. Providing fabricated details about an unfamiliar domain could result in inaccurate threat intelligence. If you have additional context or source material about this entity, I’d be glad to help analyze it.”, “discovered”: “2026-10-08T21:21:19.222767+00:00”, “domain”: “dipecarr.com.br”, “group”: “Eclipse”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/48b1df997bbefe970b777d78d5fe48f6.png”, “url”: “https:\/\/www.ransomware.live\/id\/ZGlwZWNhcnIuY29tLmJyQEVjbGlwc2U=”, “victim”: “dipecarr.com.br” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-08T00:00:00+00:00”, “claim_url”: “http:\/\/yecdjimqiaekprxza6wkqecma4bwt757qiyfjngsaxg7rkjv4xukpwad.onion\/data\/simplexengg.in\/”, “country”: “IN”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-10-08T17:53:39.641217+00:00”, “domain”: “simplexengg.in”, “group”: “Eclipse”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/c2ltcGxleGVuZ2cuaW5ARWNsaXBzZQ==”, “victim”: “simplexengg.in” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-08T00:00:00+00:00”, “claim_url”: “http:\/\/yecdjimqiaekprxza6wkqecma4bwt757qiyfjngsaxg7rkjv4xukpwad.onion\/data\/sanjoseattorneys.com\/”, “country”: “US”, “data_size”: null, “description”: “[AI generated] N\/A\n\nBased on the domain name alone, I cannot reliably verify specific details about this website, such as its actual operating status, business legitimacy, ownership, or operational history. The name suggests a legal services website potentially related to attorneys in San Jose, California, USA, but I don’t have verified, factual information about this specific entity to provide an accurate threat intelligence assessment.”, “discovered”: “2026-10-08T17:52:47.896965+00:00”, “domain”: “sanjoseattorneys.com”, “group”: “Eclipse”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/c2Fuam9zZWF0dG9ybmV5cy5jb21ARWNsaXBzZQ==”, “victim”: “sanjoseattorneys.com” }, { “activity”: “Other”, “attackdate”: “2026-10-08T00:00:00+00:00”, “claim_url”: “http:\/\/eclipse4g5kxfwsvpu4qx5sdcnrji6gxl5gt67bucjlgt35g7akvjoid.onion\/place\/yhygyivu46x3u7zf\/”, “country”: “BR”, “data_size”: null, “description”: “Dipecarr is Brazil’s top truck parts distributor, founded in 1994 by Adilson Jos\u00e9 de Almeida. With over 10,000 items ready to ship and partnerships with world-known brands, they serve 80,000 customers across seven branches in key Brazilian states. The company offers everything a truck owner needs, focusing on quality service and continuous growth.”, “discovered”: “2026-10-08T14:22:39.888264+00:00”, “domain”: “www.dipecarr.com.br”, “group”: “Eclipse”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/16c547c69e597e35c729940009b2ce9d.png”, “url”: “https:\/\/www.ransomware.live\/id\/RElQRUNBUlJARWNsaXBzZQ==”, “victim”: “DIPECARR” }, { “activity”: “Transportation”, “attackdate”: “2026-10-08T00:00:00+00:00”, “claim_url”: “http:\/\/eclipse4g5kxfwsvpu4qx5sdcnrji6gxl5gt67bucjlgt35g7akvjoid.onion\/place\/iv0bg55g3yh25d3y\/”, “country”: “SG”, “data_size”: null, “description”: “Global Airfreight International is a logistics solution provider specializing in air freight, ocean freight, cross-border trucking, and contract logistics. They cater to various industries including aerospace, healthcare, technology, and general cargo, offering services such as temperature-controlled solutions and project cargo management. The company focuses on delivering high standards of service and innovative solutions to meet customer requirements. Their clients include businesses in need of reliable and efficient supply chain solutions for critical shipments.”, “discovered”: “2026-10-08T13:22:17.469894+00:00”, “domain”: “www.globalair.com.sg”, “group”: “Eclipse”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/8b69dc0e512277f6d1f82b7477c525b0.png”, “url”: “https:\/\/www.ransomware.live\/id\/R2xvYmFsIEFpckZyZWlnaHQgSW50ZXJuYXRpb25hbEBFY2xpcHNl”, “victim”: “Global AirFreight International” }, { “activity”: “Not Found”, “attackdate”: “2026-10-07T23:53:24.073911+00:00”, “claim_url”: “https:\/\/business-data-leaks.com\/about#86920d7dae1d6aa0c9b065824”, “country”: “”, “data_size”: null, “description”: “Redacted entry – full company name pending disclosure (FULL DATA TIMER active).”, “discovered”: “2026-10-07T23:54:15.501274+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/c938014f683b3f79b345b4219214ebab.png”, “url”: “https:\/\/www.ransomware.live\/id\/Sy4uLkBTaWxlbnRSYW5zb21Hcm91cA==”, “victim”: “K…” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-10-07T23:10:16.514068+00:00”, “claim_url”: “http:\/\/xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion\/blog\/?post_uuid=da72940b-1f4b-409b-93b0-559587b4334c”, “country”: “BR”, “data_size”: null, “description”: “Petrosul is a Brazilian company established in 1994, specializing in fuel storage terminal operations since 2015. The company offers state-of-the-art infrastructure, real-time control, and efficient management to ensure quality service. Its primary clients include businesses in need of reliable fuel storage solutions. Petrosul operates terminals in Sorocaba, Paul\u00ednia, and Senador Canedo.”, “discovered”: “2026-10-07T23:29:33.604203+00:00”, “domain”: “petrosul.com.br”, “group”: “dragonforce”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/942e997a9052236c203951337c1c7478.png”, “url”: “https:\/\/www.ransomware.live\/id\/UGV0cm9zdWwgRGlzdHJpYnVpZG9yYSwgVHJhbnNwb3J0YWRvcmEgZSBDb23DqXJjaW8gZGUgQ29tYnVzdMOtdmVpcyBMdGRhLkBkcmFnb25mb3JjZQ==”, “victim”: “Petrosul Distribuidora, Transportadora e Com\u00e9rcio de Combust\u00edveis Ltda.” }, { “activity”: “Technology”, “attackdate”: “2026-10-07T22:47:44.733726+00:00”, “claim_url”: “http:\/\/xjhmtitnrdrgzw4vmsghirdoo2fk35a3tzj4enlmah4pvehdspydsiyd.onion\/blog\/?post_uuid=e7424f37-2786-42d1-a413-a7c88a8b1796”, “country”: “FR”, “data_size”: null, “description”: “R\u00e9so specializes in secondary works, offering a wide range of products including ceilings, partitions, floors, technical floors, and facades. They provide modular and dry partitions, acoustic products, and various accessories, ensuring a comprehensive solution for construction needs. With numerous agencies across France and a team of specialists trained in the latest innovations, R\u00e9so serves a diverse clientele with thousands of available products. Their commitment to quality and service is reflected in their partnerships and significant projects. \n\n676 GB of confidential information about their customers, partners, employees were stolen. The entire network was locked including nearly 8TB of Veeam backups. \nThe company has failed to reach for an agreement.”, “discovered”: “2026-10-07T22:59:59.635731+00:00”, “domain”: “www.reso.fr”, “group”: “dragonforce”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b0256cc0088e71cee58540be2474ffa5.png”, “url”: “https:\/\/www.ransomware.live\/id\/UsOJU09AZHJhZ29uZm9yY2U=”, “victim”: “R\u00c9SO” }, { “activity”: “Other”, “attackdate”: “2026-10-07T19:03:26.827620+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=c2d1bd63-c776-4fe4-bf99-7626626f457e”, “country”: “QA”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-07T19:03:44.410454+00:00”, “domain”: “www.qnie.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1c953d428c5c5acd457b2c6964b778fb.png”, “url”: “https:\/\/www.ransomware.live\/id\/UWF0YXIgTmF0aW9uYWwgSW1wb3J0ICYgRXhwb3J0QHFpbGlu”, “victim”: “Qatar National Import & Export” }, { “activity”: “Agriculture and Food Production”, “attackdate”: “2026-10-07T19:02:49.027105+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=d9ccbd6a-765e-4a6d-9076-5f62521f8b63”, “country”: “ES”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-07T19:03:06.978880+00:00”, “domain”: “www.avinyo.net”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/4f111ef5640a963cfe29dcd17e6e1dba.png”, “url”: “https:\/\/www.ransomware.live\/id\/TWF0YWRlcm8gRnJpZ29yw61maWNvIEF2aW55w7NAcWlsaW4=”, “victim”: “Matadero Frigor\u00edfico Aviny\u00f3” }, { “activity”: “Education”, “attackdate”: “2026-10-07T18:28:40+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/university-of-rostock”, “country”: “DE”, “data_size”: null, “description”: “The University of Rostock, founded in 1419, is the oldest university in the Baltic Sea region, offering over 140 diverse study programs across various fields. It focuses on innovative research and interdisciplinary collaboration to address contemporary societal challenges. The university welcomes students and staff from around the world, promoting a family-friendly and inclusive environment. It also emphasizes democratic values and the importance of free academic exchange.”, “discovered”: “2026-10-07T18:53:05.443804+00:00”, “domain”: “”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/1426b647200a15d235d698822a738b4a.png”, “url”: “https:\/\/www.ransomware.live\/id\/VW5pdmVyc2l0eSBvZiBSb3N0b2NrQFBhbnplcg==”, “victim”: “University of Rostock” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-07T18:00:29.373900+00:00”, “claim_url”: “http:\/\/puvoz5h52oepibye5hqzvfyhqhsfxzmzkr7v4tjtioxe3qaao2b6faqd.onion\/index.php?p=”, “country”: “US”, “data_size”: null, “description”: “Riviera Healthcare Center is a for-profit skilled nursing facility in operation for over 50 years. It provides 24-hour nursing and rehabilitation services. Due to negligence and poor security practices, confidential data was exposed, including patient protected health information (PHI)names, diagnoses, medical histories, fall\/fracture and treatment information, payment records, and employee\/HR data. This breach violates HIPAA and the California CMIA (and potentially the CCPA\/CPRA) and will result in mandatory breach notification, federal and state fines, civil lawsuits, corrective action plans, and significant reputational and financial damage.”, “discovered”: “2026-10-07T18:00:56.245957+00:00”, “domain”: “https:rivierahealthcare.com”, “group”: “interlock”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/90cd9997f8bcdb32764c72a1d4c6ccdc.png”, “url”: “https:\/\/www.ransomware.live\/id\/Uml2aWVyYSBIZWFsdGhjYXJlIENlbnRlckBpbnRlcmxvY2s=”, “victim”: “Riviera Healthcare Center” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-07T16:53:59.421347+00:00”, “claim_url”: “http:\/\/anubisyfkh5rixydjpoo3jqucauajz2juybrbtuglcppjj2y3eg3y6ad.onion\/r\/jNZ0t3nxvnSAkyqAS7tURCu1YxDX8hnxPAi6FnT0Z7WEwi1DWwrt8cjerwPahR2gtHsxSidDLuNZhSveRQ3TC29nQlpkU3RH”, “country”: “DE”, “data_size”: null, “description”: “Will they allow this leak to happen?”, “discovered”: “2026-10-07T16:54:20.040745+00:00”, “domain”: “”, “group”: “anubis”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/bf8119d6cc0b3a65b0b3af89935c25a3.png”, “url”: “https:\/\/www.ransomware.live\/id\/TGVhZGVjQGFudWJpcw==”, “victim”: “Leadec” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-07T15:14:34+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “bewellctr.org zoominfo.com\/c\/north-philadelphia-health-system\/27968159 The Behavioral Wellness Center at Girard (\”Be Well\”) is a nonprofit addiction and psychiatric treatment provider at 801 W. Girard Ave, Philadelphia, with revenue growing from $38.8M (FY2019) to a record $63.4M (FY2025, 95% from program services), though it posted a $4.4M loss in FY2024 and carries $68.7M in liabilities. Tracing its roots to the 1896 Philadelphia Children’s Homeopathic Hospital, it survived a 1990 merger of two bankrupt hospitals, closed St. Joseph’s in 2016, filed Chapter 11 that December, and emerged in 2018 after selling its real estate ($8.45M Girard campus sale to Iron Stone) while saving ~500 jobs. Today it employs ~480 staff and runs one of Philadelphia’s oldest and largest methadone programs (Goldman Clinic, ~600 clients\/day, ~217,000 visits\/year), plus detox, residential, and 85 extended-acute psychiatric beds.”, “discovered”: “2026-10-09T19:21:50.911412+00:00”, “domain”: “bewellctr.org”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Tm9ydGggUGhpbGFkZWxwaGlhIEhlYWx0aCBTeXN0ZW1AdGhlZ2VudGxlbWVu”, “victim”: “North Philadelphia Health System” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-07T14:13:47+00:00”, “claim_url”: “http:\/\/yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion\/company\/6ac6539b017ad22f3de0f1e8”, “country”: “CA”, “data_size”: null, “description”: “CETAM is the largest employer in prehospital care in Mont\u00e9r\u00e9gie, comprising over 400 ambulance technicians and paramedics. Founded in 1988, it operates on a cooperative model where all workers are members, allowing them to participate in decision-making and benefit from annual financial returns. The organization serves a wide territory, responding to nearly 20,000 calls annually across multiple municipalities. CETAM is dedicated to providing high-quality emergency medical services to the local population. \nThe company headquarters is located in 310 Rue Lawrence, Greenfield Park, QC J4V 2Z6, Canada. 201-500 Employees”, “discovered”: “2026-10-08T05:25:57.714492+00:00”, “domain”: “”, “group”: “Storm”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/b669653c7752ab3c726660602a0275aa.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q29vcGVyYXRpdmUgRGVzIFRlY2huaWNpZW5zIEFtYnVsYW5jaWVycyBEZSBMYSBNb250ZUBTdG9ybQ==”, “victim”: “Cooperative Des Techniciens Ambulanciers De La Monte” }, { “activity”: “Technology”, “attackdate”: “2026-10-07T11:26:58.400810+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “”, “data_size”: null, “description”: “SANAtech Global Solutions is an Egypt-based IT services and software development company located in Cairo, delivering customized technology solutions with a dedicated team of around 25 employees.”, “discovered”: “2026-10-07T11:27:15.004314+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/U0FOQXRlY2ggR2xvYmFsIFNvbHV0aW9uc0BVbUJyYQ==”, “victim”: “SANAtech Global Solutions” }, { “activity”: “Technology”, “attackdate”: “2026-10-07T11:26:20.115534+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “”, “data_size”: null, “description”: “Raqib is a Saudi cybersecurity and digital surveillance company based in Riyadh, providing monitoring and security solutions with a small dedicated team.”, “discovered”: “2026-10-07T11:26:39.728303+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/UmFxaWJAVW1CcmE=”, “victim”: “Raqib” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-07T08:23:13.450489+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “ZA”, “data_size”: null, “description”: “Tharisa is a Cyprus-based mining group focused on the production and processing of platinum group metals (PGMs) and chrome, with major operations in South Africa and development projects in Zimbabwe.”, “discovered”: “2026-10-07T08:23:30.103540+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhhcmlzYUBVbUJyYQ==”, “victim”: “Tharisa” }, { “activity”: “Technology”, “attackdate”: “2026-10-07T05:51:28.933082+00:00”, “claim_url”: “http:\/\/nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-chibitek”, “country”: “US”, “data_size”: null, “description”: “managed IT services (MSP) \u00b7 USA | Complete client financial records held by this managed IT provider (accounting, inventory, payroll data); Client network credentials and configuration secrets; Internal company documents | [NOT PAID \u2014 EXPOSED: leak 2026-10-11 04:43 UTC]”, “discovered”: “2026-10-07T05:51:42.782349+00:00”, “domain”: “”, “group”: “N0n”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/793491f17c29cb5d5c524abfcfa884b8.png”, “url”: “https:\/\/www.ransomware.live\/id\/Q2hpYml0ZWtATjBu”, “victim”: “Chibitek” }, { “activity”: “Education”, “attackdate”: “2026-10-07T03:30:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6ac64a809cd108bf26a28ae3”, “country”: “US”, “data_size”: null, “description”: “The New Community School is an independent co-educational day school located in Richmond, VA, catering to students in grades 5-12 with dyslexia. The school offers a customized curriculum designed to unlock each student’s potential, emphasizing small class sizes and a student-centered approach. With a focus on nurturing relationships and community connections, TNCS empowers students to achieve success academically and personally. The school also provides a range of extracurricular activities, including arts, athletics, and community service opportunities.”, “discovered”: “2026-10-07T22:09:57.343601+00:00”, “domain”: “”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0e1bb9ffe6a7625f8e55183e7ca553f0.png”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIE5ldyBDb21tdW5pdHkgU2Nob29sQGluY3JhbnNvbQ==”, “victim”: “The New Community School” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-07T00:10:39.005522+00:00”, “claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=5093f473-f69e-4e01-836a-96966df26538”, “country”: “ES”, “data_size”: null, “description”: “N\/A”, “discovered”: “2026-10-07T00:10:58.269068+00:00”, “domain”: “www.eptisa.com”, “group”: “qilin”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/f7c2e20a96aac76df799ad46a500b72c.png”, “url”: “https:\/\/www.ransomware.live\/id\/RVBUSVNBQHFpbGlu”, “victim”: “EPTISA” }, { “activity”: “Education”, “attackdate”: “2026-10-07T00:00:00+00:00”, “claim_url”: “”, “country”: “TW”, “data_size”: null, “description”: “Data is not available now.”, “discovered”: “2026-10-08T02:01:04.841064+00:00”, “domain”: “”, “group”: “nightspire”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TmFudG91IFNoaXVoa3VhbmcgU2VuaW9yIEhpZ2ggU2Nob29sLkBuaWdodHNwaXJl”, “victim”: “Nantou Shiuhkuang Senior High School.” }, { “activity”: “Technology”, “attackdate”: “2026-10-07T00:00:00+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “You’re in big big trouble, oh no, what will you ever do in this situation? Well, we think you should get in touch with BYOD. We won’t display what we have for the public to see, just yet, we’ll give you the chance. Anyways, you know where to find us (contact tab). We will take you down when communication has been established between our team and yours.”, “discovered”: “2026-10-07T23:20:43.410917+00:00”, “domain”: “”, “group”: “BYOD”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VE1vYmlsZUBCWU9E”, “victim”: “TMobile” }, { “activity”: “Financial Services”, “attackdate”: “2026-10-07T00:00:00+00:00”, “claim_url”: “”, “country”: “SG”, “data_size”: null, “description”: “12 Million Users, Phone numbers, Nicknames, Balance\/VIP Tier List, 2FA Indicator (differentiates, Passkey\/Auth) Region, UIDs, Gender, Position, AUM, Profit Rates, Verification Status, City, Strategy, Account Age, Profile Key, and SO much more. This is terrible, for you guys of course, we wonder what will happen if this ever gets out onto the corners of the internet it shouldn’t. Anyways, you know where to find us (contact tab). We will take you down when communication has been established between our team and yours.”, “discovered”: “2026-10-07T23:20:23.690423+00:00”, “domain”: “”, “group”: “BYOD”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/R2F0ZSB8IENyeXB0byBFeGNoYW5nZUBCWU9E”, “victim”: “Gate | Crypto Exchange” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-06T23:52:24.080097+00:00”, “claim_url”: “”, “country”: “”, “data_size”: null, “description”: “[AI generated] N\/A”, “discovered”: “2026-10-06T23:52:26.171128+00:00”, “domain”: “”, “group”: “SilentRansomGroup”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QW5kZXJzZW4gR3JvdXBAU2lsZW50UmFuc29tR3JvdXA=”, “victim”: “Andersen Group” }, { “activity”: “Education”, “attackdate”: “2026-10-06T22:23:59.841502+00:00”, “claim_url”: “http:\/\/umbra7isogjsgdcndz3uu6qvl5zftjptt6s3iiuecjlwbt4yqyvrhcid.onion”, “country”: “EG”, “data_size”: null, “description”: “Beni Suef Technological University (BTU) is Egypt\u2019s first technological university, offering industry-focused programs in ICT, Mechatronics, Renewable Energy, Autotronics, Railway Technology, and other applied technology fields, with international cooperation and ABEEK-accredited programs.”, “discovered”: “2026-10-06T22:24:17.238937+00:00”, “domain”: “”, “group”: “UmBra”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/d05c021893576e0ade86ab4a66fdbf28.png”, “url”: “https:\/\/www.ransomware.live\/id\/QmVuaSBTdWVmIFRlY2hub2xvZ2ljYWwgVW5pdmVyc2l0eSDigJMgQlRVQFVtQnJh”, “victim”: “Beni Suef Technological University \u2013 BTU” }, { “activity”: “Hospitality”, “attackdate”: “2026-10-06T22:15:15+00:00”, “claim_url”: “”, “country”: “IN”, “data_size”: null, “description”: “ajesticindiaholidays.com datanyze.com\/companies\/majestic-holidays-india\/347590614 Majestic Holidays India Private Limited is a micro-sized travel and transport operator based at 2N\/72, B.P., NIT Faridabad, Haryana (Delhi NCR), incorporated on 26 March 2015 (CIN U74900HR2015PTC055011, ROC Haryana, GSTIN 06AAJCM6666Q1ZK, DPIIT-recognized startup). Registered activity is \”travel agency and tour operators,\” but the business has pivoted to corporate\/government vehicle rental \u2014 sedans, SUVs, vans, and buses with professional drivers \u2014 serving institutional clients including BPCL, the Regional Centre for Biotechnology (RCB), THSTI, and AJNIFM; in July 2026 it won THSTI’s monthly cab-hiring tender (\u20b920 lakh value) as L1 bidder at \u20b916.2 lakh, beating 14 competitors. The company is run by promoter-directors Priyanka Devi (since inception) and Harinder Yadav (since December 2019), a family that controls a small cluster”, “discovered”: “2026-10-09T19:22:36.213075+00:00”, “domain”: “ajesticindiaholidays.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWFqZXN0aWMgSG9saWRheXMgSW5kaWEgUHJpdmF0ZSBMaW1pdGVkQHRoZWdlbnRsZW1lbg==”, “victim”: “Majestic Holidays India Private Limited” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-06T22:10:58+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “allsmilesnova.com zoominfo.com\/c\/all-smiles-dental-of-falls-church\/357420653 All Smiles Dental is a family-owned dental practice at 6400 Seven Corners Pl, Suite K, Falls Church, VA (Washington DC suburbs), serving Northern Virginia for over three decades \u2014 founded in the early 1990s by Vietnamese-immigrant dentists Dr. Thang Pham and Dr. Nu Dang, who met at Saigon Dental School and retrained cum laude at MCV\/VCU. Their son Dr. Long Pham (Virginia Tech summa cum laude, VCU DDS 2008) joined in 2008 and now leads the practice alongside Dr. Jennifer Lee and Dr. Tuan Anh Ta; the family also runs two related practices \u2014 Nova Dental Practice in Herndon and All Smiles Dental PLLC in Great Falls (owned by Dr. Long’s wife, Dr. Erica Sok). The practice offers full-service dentistry with a flagship focus on biomimetic dentistry \u2014 Dr. Long Pham is one of the few US dentists with mastership from the Alleman Center for Biomimetic Dentistry \u2014 plus CEREC same-day crowns, Invisalign\/SureSmile aligners”, “discovered”: “2026-10-09T19:22:53.300743+00:00”, “domain”: “allsmilesnova.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWxsIFNtaWxlcyBEZW50YWwgb2YgRmFsbHMgQ2h1cmNoQHRoZWdlbnRsZW1lbg==”, “victim”: “All Smiles Dental of Falls Church” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-06T22:07:49+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “jrwalshlaw.com The Law Office of James R. Walsh is a small plaintiff-side law firm in Lynnwood, WA (north of Seattle), specializing in workers’ compensation (L&I claims), personal injury, maritime, and Social Security cases. Founder James R. Walsh (admitted 1981) has practiced for 44+ years and was named to \”Top Attorneys of North America 2015-16.\” The firm fights for injured workers against Washington’s Dept. of Labor & Industries and self-insured employers, with published precedents including Elliott v. L&I (2009) and ITT Rayonier v. Dalman (1992). It acts as a talent incubator \u2014 attorney Joshua L. Hughes (UW Law, JD with honors) rose from paralegal (2017) to attorney (2022), following the path of earlier associates.”, “discovered”: “2026-10-09T19:22:56.955394+00:00”, “domain”: “jrwalshlaw.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VGhlIExhdyBPZmZpY2Ugb2YgSmFtZXMgUiBXYWxzaEB0aGVnZW50bGVtZW4=”, “victim”: “The Law Office of James R Walsh” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-06T22:07:13+00:00”, “claim_url”: “http:\/\/pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion\/company\/edfelectronics”, “country”: “”, “data_size”: null, “description”: “EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.”, “discovered”: “2026-10-06T22:55:53.652676+00:00”, “domain”: “”, “group”: “Panzer”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/7a67c76fa4869b897f00ac5c3063199e.png”, “url”: “https:\/\/www.ransomware.live\/id\/RURGZWxlY3Ryb25pY3NAUGFuemVy”, “victim”: “EDFelectronics” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-06T22:03:18+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “potomacanimalhospital.com zoominfo.com\/c\/potomac-animal-hospital\/183255483 Potomac Animal Hospital is a family-owned, full-service small animal medical and surgical facility at 10020 River Road in Potomac, Maryland, an affluent Washington, DC suburb, founded in 1973 and led since 1983 by Air Force veteran Dr. Michael Scott (CSU DVM 1969; former officer in charge of the Europe Military Working Dog Referral Center in Ramstein). His son Dr. Jason Scott joined in 1999 \u2014 hooded at graduation by his father exactly 30 years to the day after his own \u2014 and now leads a team including Dr. Sarah Orloff (2021) and Dr. Kimber Wagner (2025); Dr. Michael retired in 2018 but remains owner. Beyond medicine (wellness exams, international health certificates, laser surgery, dentistry with digital oral radiography, in-house lab), the hospital runs a separate boarding kennel ($42.50\u2013$72.50\/night, dogs exercised every 2\u20133 hours, VIP suites) and a grooming salon \u2014 all powered through outages by an industria”, “discovered”: “2026-10-09T19:23:13.992984+00:00”, “domain”: “potomacanimalhospital.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UG90b21hYyBBbmltYWwgSG9zcGl0YWxAdGhlZ2VudGxlbWVu”, “victim”: “Potomac Animal Hospital” }, { “activity”: “Not Found”, “attackdate”: “2026-10-06T21:58:53+00:00”, “claim_url”: “”, “country”: “FR”, “data_size”: null, “description”: “mabris.fr) zoominfo.com\/c\/mabris\/513443412MABRIS is a French family-owned industrial contractor based in Saint-Pierre-la-Cour (Mayenne), founded in the 1980s and registered as an SAS in 1999, with a second workshop in Airvault under the OPTEOR banner since 2006. It provides end-to-end services \u2014 boilerwork (chaudronnerie), industrial piping, metalwork, and industrial mechanics\/maintenance \u2014 split ~60% maintenance \/ 40% design, with an in-house design office using AutoCAD, SolidWorks, and 3D point-cloud scanning. Working B2B-only across 18 departments in western France (zero export), it serves chemical, food, and energy industry clients, and partners with neighboring firm AROM for tungsten-carbide hardfacing (whose facility it acquired in 2022 for \u20ac45,000). Led by president Jacques Belaud since 2011, it employs ~26 people and holds MASE safety certification (renewed November 2025). Financially it staged a strong turnaround: revenue grew from \u20ac6.37M (2021) to a record \u20ac7.97M (2024)”, “discovered”: “2026-10-09T19:23:18.072218+00:00”, “domain”: “mabris.fr”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWFicmlzQHRoZWdlbnRsZW1lbg==”, “victim”: “Mabris” }, { “activity”: “Healthcare”, “attackdate”: “2026-10-06T21:55:31+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “aa.org zoominfo.com\/c\/alcoholics-anonymous\/71374 lcoholics Anonymous is a worldwide fellowship of over 2 million members recovering from alcoholism, founded on June 10, 1935, in Akron, Ohio by Bill W. and Dr. Bob, and based on the \”12 Steps and 12 Traditions\” outlined in its 1939 basic text, the \”Big Book\” \u2014 now translated into 70+ languages. aa.org is the official site of the General Service Office (New York) serving the U.S.\/Canada, with content in English, Spanish, and French, offering free literature (PDF, audio, and ASL versions), a searchable Big Book, meeting finders, and the Meeting Guide app. The fellowship operates in ~180 countries with 123,000+ groups; its 2022 membership survey (6,000 respondents) showed an average age of 52 and 44% with over 10 years of sobriety. A.A. is an \”upside-down\” organization: ultimate authority rests with autonomous groups, leaders are rotating \”trusted servants,\” and it is fully self-supporting accepting money only from members $7,5k person\/year”, “discovered”: “2026-10-09T19:23:33.474645+00:00”, “domain”: “aa.org”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWxjb2hvbGljcyBBbm9ueW1vdXNAdGhlZ2VudGxlbWVu”, “victim”: “Alcoholics Anonymous” }, { “activity”: “Not Found”, “attackdate”: “2026-10-06T21:52:27+00:00”, “claim_url”: “”, “country”: “TW”, “data_size”: null, “description”: “abilitytw.com zoominfo.com\/c\/ability-enterprise-co-ltd\/1340859360 Ability Enterprise is a Taiwan-based ODM\/OEM manufacturer founded in 1965, headquartered in New Taipei City, and one of the world’s leading producers of digital imaging and optical camera products. The company designs and manufactures camera modules, action cameras, Edge AI webcams, automotive cameras, and security\/surveillance systems for global brands, with factories in Taiwan, China (Dongguan), and Vietnam. Roughly half of its workforce is in R&D, and the company holds 42 patents from the last three years, focusing on AI vision, 3D ToF, and robotics. Financially, it’s on a strong growth run: FY2025 revenue hit NT$9.91 billion (+60% YoY), and 2026 revenue is tracking above NT$10 billion with an ambitious NT$30 billion target by 2028. Its strategic pivot \u2014 \”Transformation 3.0\” \u2014 positions it as the \”eyes for AI robots,\” supplying vision modules for humanoid robots (Agility Robotics, Mantis Robotics) and drones”, “discovered”: “2026-10-09T19:23:38.769340+00:00”, “domain”: “abilitytw.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWJpbGl0eSBFbnRlcnByaXNlQHRoZWdlbnRsZW1lbg==”, “victim”: “Ability Enterprise” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-06T21:47:30+00:00”, “claim_url”: “”, “country”: “CZ”, “data_size”: null, “description”: “k2machine.cz zoominfo.com\/c\/machine-sro\/537154777 K2 Machine s.r.o. is a private Czech industrial machinery manufacturer founded in 2011 in Pardubice, Czech Republic, growing from 3 founders in a small office to ~25\u201350 employees and 400+ completed projects over 15 years. Annual turnover is 100+ million CZK (~\u20ac4M), though 2024 saw a sharp \u221218.7% revenue decline (operating revenue \u221227.7%). The company designs and builds special-purpose machines, automated production lines, robotic cells (including 3D Bin Picking), conveyor systems, and performs CNC machining, equipment repowering, and line relocation \u2014 serving primarily the automotive and consumer industries. Its full-cycle capability spans Solid Edge 3D design, EPLAN electrical engineering, CNC production, assembly, commissioning, and after-sales service under one roof at its own Semt\u00edn campus (since 2020).”, “discovered”: “2026-10-09T19:23:54.076553+00:00”, “domain”: “k2machine.cz”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWFjaGluZSBzcm9AdGhlZ2VudGxlbWVu”, “victim”: “Machine sro” }, { “activity”: “Education”, “attackdate”: “2026-10-06T21:45:01+00:00”, “claim_url”: “”, “country”: “CA”, “data_size”: null, “description”: “nwpolytech.ca zoominfo.com\/c\/northwestern-polytechnic\/1310919676 Northwestern Polytechnic (NWP) is a publicly funded polytechnic institution founded in 1966 in Grande Prairie, Alberta, serving 3,800+ students (2,227 full-load equivalents) with ~372\u2013438 employees under President & CEO Dr. Vanessa Sheane (since 2023). Its annual budget is ~$79.5M CAD (2026-27), funded 62.5% by government grants and 21.9% by student tuition, with total net assets of $49.8M (CRA data). NWP operates across 4 schools (Applied Science & Technology, Business & Education, Health, Skilled Trades) offering apprenticeships, diplomas, and a new Bachelor of Education degree, plus unique research assets like the National Bee Diagnostic Centre \u2014 Canada’s only bee diagnostics lab (NSERC Technology Access Centre) \u2014 and a 40,000 sq ft Health Education Centre inside the Grande Prairie hospital. The campus features iconic Douglas J. Cardinal architecture (winner of the Prix du XXe Si\u00e8cle)”, “discovered”: “2026-10-09T19:23:59.451693+00:00”, “domain”: “nwpolytech.ca”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/Tm9ydGh3ZXN0ZXJuIFBvbHl0ZWNobmljQHRoZWdlbnRsZW1lbg==”, “victim”: “Northwestern Polytechnic” }, { “activity”: “Other”, “attackdate”: “2026-10-06T21:41:21+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “polishingproz.com zoominfo.com\/c\/polishing-proz-inc\/409891680 Polishing Proz LLC is a small, family-owned marble and natural stone care company based in Centennial, Colorado (Denver metro), founded around 2008\u20132012 with 13+ years of experience. It generates estimated revenue of $200K\u2013$500K\/year with just ~3\u20136 employees, led by owner-founder James Medina. Core services include marble crystallization, polishing, grinding, sealing, grout cleaning, and full restoration of marble, granite, travertine, limestone, and polished concrete \u2014 for both residential and commercial clients. The company serves the greater Denver area with free estimates and a hands-on, owner-operated approach. It specializes in high-end restoration work such as marble fireplaces, countertops, staircases, and commercial floors. With minimal online presence and zero external funding, Polishing Proz competes against larger stone care franchises (ServPro, Stanley Steemer, local stone specialists) through reputation”, “discovered”: “2026-10-09T19:24:14.744459+00:00”, “domain”: “polishingproz.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UG9saXNoaW5nIFByb3pAdGhlZ2VudGxlbWVu”, “victim”: “Polishing Proz” }, { “activity”: “Other”, “attackdate”: “2026-10-06T21:37:30+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “myworkstream.com maverickdesk.com Maverick Desk is a private, U.S.-based office furniture manufacturer founded in 1992 in Gardena, California, with a second production plant in Fairfield, Ohio, and estimated annual revenue of $19.1M with ~23\u201350 employees. It produces 9+ collections of casegoods \u2014 desks, credenzas, conference tables, height-adjustable workstations, and school furniture \u2014 using thermally fused melamine with 20 colors and free mix-and-match customization. Its standout competitive edge is QuickShip in 48\u201372 hours on 400+ SKUs (fastest in the industry) and full custom builds under the motto \”If you can draw it, we can make it.\” All products are Made in the USA (CARB-compliant) and backed by a 10-year warranty, and the company is GSA Approved for U.S. government procurement. Led by President Tony Pacheco and VP Operations Ramiro Serna, it distributes across North America through a dealer network.”, “discovered”: “2026-10-09T19:24:20.212741+00:00”, “domain”: “myworkstream.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/TWF2ZXJpY2sgRGVza0B0aGVnZW50bGVtZW4=”, “victim”: “Maverick Desk” }, { “activity”: “Professional Services”, “attackdate”: “2026-10-06T21:37:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6ac5cc759cd108bf2693b58b”, “country”: “DE”, “data_size”: null, “description”: “Architektur in der Symbiose aus der erfahrenen und sicheren Anwendung der innovativen Bauteilevorfertigung, mit \u00f6konomischer Umsetzung, ist seit\u00fcber 40 Jahren unsere Leidenschaft.\r Employees: 20\r Revenue: $5 Million\r Phone Number: 06761\/95900”, “discovered”: “2026-10-07T05:06:37.227225+00:00”, “domain”: “architekt-vondanwitz.de”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/2a25b72464ff616d6e01aa575fe1781c.png”, “url”: “https:\/\/www.ransomware.live\/id\/YXJjaGl0ZWt0LXZvbmRhbndpdHouZGVAaW5jcmFuc29t”, “victim”: “architekt-vondanwitz.de” }, { “activity”: “Energy & Utilities”, “attackdate”: “2026-10-06T21:26:32+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “ragelectric.com zoominfo.com\/c\/rag-electric-inc\/401375471 RAG Electric, Inc. is a private, family-owned electrical contractor founded in 1987 (originally as FEIZ Electric) in Los Angeles, California, incorporated in 2001 and run by founder Farshad Feizbakhsh and his son Matthew. It generates estimated revenue of $2\u20135M\/year with ~6\u201311 employees, holding a clean C-10 electrical license (#510327) active for 38 years with zero violations in CSLB records. Over four decades RAG has powered 7,500+ residential units across the LA metro area, specializing in ground-up multifamily construction, assisted living\/senior care, and historic rehabilitation. Recent flagship projects include Vered on Ventura (123-unit assisted living in Encino), Rolling Hills Estates (114-unit memory care), and Sync on Canoga (220-unit multifamily in Canoga Park). Services span full design-build, tenant improvements, underground site work, and emergency troubleshooting \u2014 all fully NEC\/LADBS-compliant, licensed, bonded”, “discovered”: “2026-10-09T19:24:35.787189+00:00”, “domain”: “ragelectric.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UmFnIEVsZWN0cmljQHRoZWdlbnRsZW1lbg==”, “victim”: “Rag Electric” }, { “activity”: “Transportation”, “attackdate”: “2026-10-06T21:24:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6ac5c9869cd108bf26935649”, “country”: “US”, “data_size”: null, “description”: “Harbor Pacific Contractors, Inc. specializes in Industrial, Mechanical, and Heavy Civil Construction Services in the Pacific Northwest. Their offerings include wastewater and water treatment facilities, transportation infrastructure, pump stations, and power generation facilities. The company serves clients in Washington, Oregon, and Alaska, focusing on large-scale construction projects. With a commitment to quality and efficiency, they cater to various industrial construction needs.\r Employees: 20\r Revenue: $5 Million\r Phone Number: (425) 488-7131\r “, “discovered”: “2026-10-07T05:07:34.873428+00:00”, “domain”: “harborpacific.com”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/a820decadff3d347b7208bbf7cf4516c.png”, “url”: “https:\/\/www.ransomware.live\/id\/aGFyYm9ycGFjaWZpYy5jb21AaW5jcmFuc29t”, “victim”: “harborpacific.com” }, { “activity”: “Education”, “attackdate”: “2026-10-06T21:17:28+00:00”, “claim_url”: “”, “country”: “AU”, “data_size”: null, “description”: “allsouls.qld.edu.au zoominfo.com\/c\/all-souls-st-gabriels-school\/350907535 All Souls St Gabriels School (ASSG) is an independent Anglican co-educational boarding and day school founded in 1920 in Charters Towers, North Queensland, serving ~431\u2013459 students (Pre-Prep to Year 12) on a 45-hectare campus, with 186\u2013200 boarders (one of the region’s largest boarding programs). It employs ~66\u201379 staff (44 teachers, 1:8\u20131:10 student ratio) under Headmaster Shannon Lee (since 2022). Annual fees range from $4,675 (primary) to $14,620 (Year 12) plus $28,800 boarding, generating estimated revenue of ~$10\u201314M AUD with healthy $2.5M cash reserves and $3.2M in debt-free capital expenditure (new Aquatic Centre, 2024). Founded as two single-sex schools merged in 1990, it famously closed in 2000 and was rescued by the community \u2014 reopened under a new incorporated board. Academically, 14% of graduates achieve OP 1\u20135, and the school has produced 3 Rhodes Scholars across its history.”, “discovered”: “2026-10-09T19:24:40.772304+00:00”, “domain”: “allsouls.qld.edu.au”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QWxsIFNvdWxzIFN0IEdhYnJpZWxzIFNjaG9vbEB0aGVnZW50bGVtZW4=”, “victim”: “All Souls St Gabriels School” }, { “activity”: “Education”, “attackdate”: “2026-10-06T21:11:54+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “ansonia.org zoominfo.com\/c\/ansonia-public-schools\/6671532 Ansonia Public Schools is a public PK\u201312 school district in Ansonia, Connecticut (Naugatuck Valley), serving ~2,332\u20132,404 students across 4 schools with 166 teachers (14.5:1 ratio, avg salary $99K) under Superintendent Dr. Joseph DiBacco. Annual BOE budget is $39.5M (2026-27), spending $19,869 per pupil ($2,185 below CT state average), funded 54% by state aid, 34% local property taxes, and 13% federal. The district faces severe academic challenges: math proficiency at just 12\u201315% (state: 41%) and reading at 24\u201325% (state: 51%), ranking it in the bottom 50% of Connecticut districts (1\/10 rating). Demographics are high-need \u2014 80% minority enrollment, 63.6% on free\/reduced meals, and 23.1% chronic absenteeism. Graduation rate is 85.7% (state: 88.9%), with strong positives in college-prep course-taking (95.7%) and on-track graduation (92.5%). Financially fragile: the city has been a \”distressed municipality\” since 2010, fund balance”, “discovered”: “2026-10-09T19:24:56.618762+00:00”, “domain”: “ansonia.org”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QW5zb25pYSBQdWJsaWMgU2Nob29sc0B0aGVnZW50bGVtZW4=”, “victim”: “Ansonia Public Schools” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-06T21:07:00+00:00”, “claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6ac5c58c9cd108bf2692d1e7”, “country”: “US”, “data_size”: null, “description”: “Acme Stamping & Wire Forming Co. specializes in metal stamping, CNC machining, precision wire forming, and tool & die services. They offer a range of capabilities including progressive blanking, deep draw, and single station compound processes. The company caters to clients requiring high-quality manufacturing solutions with advanced equipment and precision engineering. Located in Pittsburgh, PA, Acme Stamping & Wire Forming is equipped to handle various production needs.\r Employees: 20\r Revenue: $5 Million\r Phone Number: (412) 771-5720”, “discovered”: “2026-10-07T05:08:14.160618+00:00”, “domain”: “acmestamping.com”, “group”: “incransom”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/0914130314cd35d0a5bc387efb0fb77e.png”, “url”: “https:\/\/www.ransomware.live\/id\/YWNtZXN0YW1waW5nLmNvbUBpbmNyYW5zb20=”, “victim”: “acmestamping.com” }, { “activity”: “Education”, “attackdate”: “2026-10-06T21:03:13+00:00”, “claim_url”: “”, “country”: “OM”, “data_size”: null, “description”: “uob.edu.om zoominfo.com\/c\/university-of-buraimi\/464061196 University of Buraimi (UOB) is a private higher education institution founded in 2016 (originally College of Banking & Financial Studies, upgraded to university status in 2024) in Buraimi, Oman, just 5 minutes from the UAE border (Al Ain). Licensed by Oman’s Ministry of Higher Education (MOHERI), it operates 4 faculties (Computing & IT, Engineering, Business, Health Sciences) with 11 departments offering programs in AI, cybersecurity, civil\/electrical\/mechanical engineering, nursing, architecture, business, and MBA. It serves ~500\u20131,500 students from 40+ countries (30\u201340% international) with ~50\u201382 staff (PhD-holders from UK, USA, Canada, Malaysia). Tuition runs ~$6,000\u201312,000\/year with extensive scholarships. The university follows a US academic model, earned a spot in UI GreenMetric World Rankings 2025 (289th for sustainability), and is currently undergoing OAAA accreditation. Led by Chancellor HE Sheikh Saif Al-Mamari”, “discovered”: “2026-10-09T19:25:01.407530+00:00”, “domain”: “uob.edu.om”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/VW5pdmVyc2l0eSBvZiBCdXJhaW1pQHRoZWdlbnRsZW1lbg==”, “victim”: “University of Buraimi” }, { “activity”: “Education”, “attackdate”: “2026-10-06T20:54:16+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “santeesd.net zoominfo.com\/c\/santee-school-district-foundation\/153059622 Santee School District is a public K\u20138 school district founded in 1891 in Santee, California (San Diego County), operating 9 schools serving approximately 5,922\u20135,990 students (ages 2\u201314, including Pre-K\/TK). It employs ~640\u2013846 FTE staff (355 certificated teachers + 488 classified staff) under Superintendent Dr. Kristin Baranski, with a student-teacher ratio of ~23:1. Annual budget: ~$99.3M expenditures vs $90.7M revenue (2025-26), funded 77% by the state (LCFF), with ~$15,800\u201318,900 spent per student. Demographics: 49% White, 31% Hispanic, 20.5% special education, 37% socio-economically disadvantaged, 36\u201340 languages spoken. The district is known for its innovative Preschool\u2013Grade 8 model and 1:1 iPad program, with strong SPED and Prop 28 arts funding. However, it faces serious financial headwinds: enrollment declining ~5% (projected 5,778 by 2026-27), expenditures exceeding revenue, reserve dropping from 16.5%”, “discovered”: “2026-10-09T19:25:17.311454+00:00”, “domain”: “santeesd.net”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/U2FudGVlIFNjaG9vbCBEaXN0cmljdCBGb3VuZGF0aW9uQHRoZWdlbnRsZW1lbg==”, “victim”: “Santee School District Foundation” }, { “activity”: “Other”, “attackdate”: “2026-10-06T20:54:00+00:00”, “claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/7ea291f1cdc12ccee23f9267a1968a50”, “country”: “AR”, “data_size”: null, “description”: “Argentina Valores S.A. is a financial services company focused on capital markets, registered with t…”, “discovered”: “2026-10-08T03:31:57.308030+00:00”, “domain”: “avsa.com.ar”, “group”: “lockbit5”, “press”: null, “ransom”: null, “screenshot”: “https:\/\/images.ransomware.live\/victims\/36c22e7715c31839fffa9cb71d8d122b.png”, “url”: “https:\/\/www.ransomware.live\/id\/YXZzYS5jb20uYXJAbG9ja2JpdDU=”, “victim”: “avsa.com.ar” }, { “activity”: “Manufacturing”, “attackdate”: “2026-10-06T20:51:19+00:00”, “claim_url”: “”, “country”: “TW”, “data_size”: null, “description”: “jentech.com.tw zoominfo.com\/c\/jentech-precision-industrial-co-ltd\/344286614 Jentech Precision Industrial Co., Ltd. (TWSE: 3653) is a publicly listed Taiwanese thermal management and precision metal components manufacturer founded in 1987 in Taoyuan, Taiwan, IPO’d on the Taiwan Stock Exchange in 2009. It generates ~$450\u2013640M USD annual revenue (NT$14.28B in FY2024, growing 20% CAGR) with 2,000+ employees across Taiwan (970), China Wuxi (639), Malaysia, Germany, and the USA. Jentech is the global leader in integrated heat spreaders (IHS) for CPU\/GPU\/AI chips \u2014 its flagship products include Vapor Chamber Lids, Micro-Channel Lids (1000W+ TDP), liquid cooling modules, and EV battery cold plates, all manufactured with sub-micron precision using 99.99% oxygen-free copper and full vertical integration. Key clients include NVIDIA, AMD, Intel, TSMC, Sony, IBM, and Qualcomm. The company is riding the AI boom \u2014 semiconductor segment revenue surged +237% in 4 years \u2014 and holds a unique VC + MC”, “discovered”: “2026-10-09T19:25:26.433237+00:00”, “domain”: “jentech.com.tw”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/SmVudGVjaCBQcmVjaXNpb24gSW5kdXN0cmlhbEB0aGVnZW50bGVtZW4=”, “victim”: “Jentech Precision Industrial” }, { “activity”: “Other”, “attackdate”: “2026-10-06T20:40:12+00:00”, “claim_url”: “”, “country”: “US”, “data_size”: null, “description”: “pirsales.com zoominfo.com\/c\/pir-sales-inc\/84001098 PIR Sales, Inc. is a private, independent manufacturers’ representative firm founded in 1992 in Chandler, Arizona, serving plumbing, irrigation, waterworks, fire\/life safety, and HVAC markets across Arizona, Southern Nevada, New Mexico, and El Paso TX. It generates estimated annual revenue of $20\u201323M with only ~17\u201319 employees (9 outside + 8 inside sales) \u2014 an exceptional ~$1.2\u20131.35M revenue per employee. The firm represents 40+ premium brands including A.O. Smith, Watts Water Technologies, Bradley Corp., Panasonic HVAC, Stiebel Eltron, and Highland Tank, backed by 25+ year manufacturer relationships and a 27,000 sq ft warehouse offering 24\/7 commercial water heater pickup. It serves 20 distribution channels (architects, engineers, contractors, municipalities, utilities) and employs dedicated Specification Consultants for architects in both Arizona and Las Vegas. Led by President Bob Saylor (29 years at PIR) and VP Craig Addington”, “discovered”: “2026-10-09T19:25:37.817628+00:00”, “domain”: “pirsales.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/UElSIFNhbGVzQHRoZWdlbnRsZW1lbg==”, “victim”: “PIR Sales” }, { “activity”: “Hospitality”, “attackdate”: “2026-10-06T20:33:41+00:00”, “claim_url”: “”, “country”: “CA”, “data_size”: null, “description”: “asessippi.com zoominfo.com\/c\/asessippi-ski-resort\/2900411 Asessippi Ski Area & Resort is a private, family-owned ski resort founded in 1998\/99 in Inglis, Manitoba, Canada, owned by Daymon Guillas (Russell Inn Group) and managed by GM Richard Crosthwaite. It generates estimated revenue of $3.6\u20135M\/year with ~30 year-round staff scaling to 150 in winter (300+ across the Russell Inn ecosystem), attracting 60,000\u201385,000 visitors per season including 15,000 school children. It is the largest ski resort in Manitoba and the Canadian Prairies \u2014 26\u201327 trails across 200 acres with the biggest vertical drop on the prairies (121m), 3 chairlifts, night skiing with LED lights, and 100% snowmaking coverage. Built with $10M total investment ($7M private + $3M government), it offers year-round activities: skiing, tubing, snow biking, adaptive CADS-certified programs (11 instructors), summer weddings, conferences, spa, and ski-in\/ski-out cottage real estate (Cottage Cove).”, “discovered”: “2026-10-09T19:25:47.077498+00:00”, “domain”: “asessippi.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/QXNlc3NpcHBpIFNraSBSZXNvcnRAdGhlZ2VudGxlbWVu”, “victim”: “Asessippi Ski Resort” }, { “activity”: “Not Found”, “attackdate”: “2026-10-06T20:21:56+00:00”, “claim_url”: “”, “country”: “SG”, “data_size”: null, “description”: “habbaslaw.com zoominfo.com\/c\/habbas–associates\/348628386 Habbas & Associates (Habbas Law) is a private, family-owned personal injury law firm founded in 1988 by Omar Habbas in San Jose, California, now operating 6 offices statewide (San Jose, Oakland, SF, LA, Modesto, Rocklin). It generates estimated annual revenue of ~$20\u201321M with 20\u201344 employees, working on a contingency fee basis (\”No Recovery, No Fee\”). Over 38 years the firm has resolved 20,000+ cases and secured $750M+ in total client recoveries, with founder Omar Habbas alone accounting for $450M+ \u2014 he holds an AV Preeminent rating, Super Lawyers status, and was admitted to the U.S. Supreme Court in 2019. The firm is now transitioning to its second generation: son Tarik Habbas (Partner, 3\u00d7 Super Lawyers Rising Star) and son Nicholas Habbas (admitted to the CA Bar in 2026). Core practice areas: car\/truck accidents, wrongful death, brain\/spinal injuries, medical malpractice, and employment law. Client ratings are strong”, “discovered”: “2026-10-09T19:22:32.596720+00:00”, “domain”: “habbaslaw.com”, “group”: “thegentlemen”, “press”: null, “ransom”: null, “screenshot”: “”, “url”: “https:\/\/www.ransomware.live\/id\/SGFiYmFzIEFzc29jaWF0ZXNAdGhlZ2VudGxlbWVu”, “victim”: “Habbas Associates” } ]