Ransomware Stats
{
“groups”: 357,
“victims”: 29647
}
[
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-11T13:34:52.828675+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=b004c1c5-0926-4073-8d0d-11a7f9167b2d”,
“country”: “US”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-11T13:35:16.397025+00:00”,
“domain”: “www.centuryequities.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/74cdf5eac0f39d5093ffb01a0c21d638.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2VudHVyeSBFcXVpdGllc0BxaWxpbg==”,
“victim”: “Century Equities”
},
{
“activity”: “Telecommunication”,
“attackdate”: “2026-07-11T13:34:09.665860+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=eb22c190-4265-4182-9698-7c5ca02d59b5”,
“country”: “IT”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-11T13:34:33.497262+00:00”,
“domain”: “www.retelit.it”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/acce0409cf60bd239494e01cb2783687.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UmV0ZWxpdCBTcEEgUElWQUBxaWxpbg==”,
“victim”: “Retelit SpA PIVA”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-11T13:33:18.248155+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=1f779231-53ef-41fe-9d57-1e865d24c8b5”,
“country”: “US”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-11T13:33:50.618844+00:00”,
“domain”: “www.carolinaap.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4b916db1df883b8a4871268b6dceadd4.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2Fyb2xpbmEgQWdyaS1Qb3dlckBxaWxpbg==”,
“victim”: “Carolina Agri-Power”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-11T13:32:29.644012+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=7717ad8a-e1ca-42e3-be5b-cceb307536f9”,
“country”: “NH”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-11T13:32:59.154142+00:00”,
“domain”: “www.alliedpnh.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/73143ea6a3267efd05c3519344938c9b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWxsaWVkIFBsdW1iaW5nICYgSGVhdGluZ0BxaWxpbg==”,
“victim”: “Allied Plumbing & Heating”
},
{
“activity”: “Energy”,
“attackdate”: “2026-07-11T10:50:28.080537+00:00”,
“claim_url”: “”,
“country”: “GH”,
“data_size”: null,
“description”: “Wassa is located in south-western Ghana. Golden Star commenced production from the surface operation at Wassa in 2005 and commercial production was achieved at Wassa Underground on January 1, 2017. In early 2018 Wassa transitioned into an underground-focused operation. Thanks to the scale of the historical open pit mining operation the processing plant has significant excess capacity and is currently only running at 70-80% (based on 2020 actuals) utilization. Development of the large inferred mineral resource which comprises the southern Extension zone, was the subject of a Preliminary Economic Assessment which was included in the March 2021 Technical Report. Given the scale of the resource at Wassa, the Company is exploring the potential to increase the mining rate in order to fill the mill.”,
“discovered”: “2026-07-11T10:50:29.730582+00:00”,
“domain”: “www.gsr.com”,
“group”: “cmdorganization”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/R29sZGVuIFN0YXIgUmVzb3VyY2VzQGNtZG9yZ2FuaXphdGlvbg==”,
“victim”: “Golden Star Resources”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T21:26:03.370903+00:00”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=d08d0ea2-3184-4606-8198-38fd270460a4”,
“country”: “US”,
“data_size”: null,
“description”: “The Schuett Companies, Inc. is a family-owned business with over 50 years of experience specializing in affordable housing for seniors, individuals with disabilities, and families. They manage approximately 1,600 housing units across Minnesota, North Dakota, and South Dakota. Since 1968, they have also offered Home Health Care services through their CompassionCare program, ensuring residents can age in place comfortably. The company’s commitment to providing a supportive community emphasizes the importance of a stable home for a healthy life.”,
“discovered”: “2026-07-10T21:57:26.296097+00:00”,
“domain”: “www.schuettcares.com”,
“group”: “dragonforce”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f42b7537d43f38869f241d48f66de50b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VGhlIFNjaHVldHQgQ29tcGFuaWVzQGRyYWdvbmZvcmNl”,
“victim”: “The Schuett Companies”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-10T15:57:05.622957+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=63fc378c-2a9e-4383-82fd-e8075df9a758”,
“country”: “MA”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T15:57:41.264897+00:00”,
“domain”: “www.eurodefis.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/69761099489a1f1bf5b39d432bd00af2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RXVyb2RlZmlAcWlsaW4=”,
“victim”: “Eurodefi”
},
{
“activity”: “Education”,
“attackdate”: “2026-07-10T15:26:03.706341+00:00”,
“claim_url”: “http:\/\/t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion\/index.php?p=”,
“country”: “US”,
“data_size”: null,
“description”: “Borger Independent School District serves approximately 2,500 students on six campuses in Hutchinson County, Texas. The district fails to foster a collaborative environment for students, parents, and the community. They are not responsible or committed to ensuring the security of your data. This is not the first time they have neglected their students, with confidential information about staff, students, and their parents, as well as all incidents, the district’s financial situation, and other information they concealed, leaking online. We offer you 330 GB of this information.”,
“discovered”: “2026-07-10T15:26:21.459274+00:00”,
“domain”: “borgerisd.net”,
“group”: “interlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 5,
“update”: “2026-07-10T15:26:03”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f8ed78eb1f995dec16e179242de98292.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Qm9yZ2VyIElTREBpbnRlcmxvY2s=”,
“victim”: “Borger ISD”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T15:06:02.067570+00:00”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=71752b28-6410-4be5-b260-ffa493fdc9d3”,
“country”: “AU”,
“data_size”: null,
“description”: “Access Group International is a leading privately owned provider of access, material handling, power generation, and construction equipment. The company is dedicated to safety, performance, and reliability, serving Australia’s demanding industries with dependable equipment and expertise. Their integrated services include maintenance, OEM manufacturing, transport, logistics, and workforce solutions, allowing for seamless project support. With a focus on adaptability and tailored solutions, Access Group International is a trusted partner for projects of all sizes.”,
“discovered”: “2026-07-11T15:25:06.066641+00:00”,
“domain”: “www.accessgroup.net.au”,
“group”: “dragonforce”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9b64e6ace1529f1fe1b677cf1641dc48.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWNjZXNzIEVxdWlwbWVudCBIaXJlQGRyYWdvbmZvcmNl”,
“victim”: “Access Equipment Hire”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:26:53.636858+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=4e31bd9a-f323-46b7-8f7e-7da304924083”,
“country”: “CO”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T13:27:14.036134+00:00”,
“domain”: “www.hilo.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0c32457130579a1e96efe850b1b3971f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SGlsb0BxaWxpbg==”,
“victim”: “Hilo”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-10T13:26:13.319836+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=e5e2fa00-1d2c-4921-bc64-005bac006c8f”,
“country”: “MX”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T13:26:34.704242+00:00”,
“domain”: “www.promotorazacapu.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f8e8e7b1bf37d61d0efa59774b770cf2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvbW90b3JhIFphY2FwdUBxaWxpbg==”,
“victim”: “Promotora Zacapu”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:25:33.559646+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=9acf3fe5-90ad-4918-93fc-4988ca91df8a”,
“country”: “AE”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T13:25:54.342797+00:00”,
“domain”: “www.navana-realestate.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7e16c792e581418586842b9fa005c99e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TmF2YW5hIFJlYWwgRXN0YXRlQHFpbGlu”,
“victim”: “Navana Real Estate”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:15:09.460369+00:00”,
“claim_url”: “”,
“country”: “”,
“data_size”: null,
“description”: “Business direction: Mew mew”,
“discovered”: “2026-07-10T13:15:10.940807+00:00”,
“domain”: “”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2F0Y29ycEBEZWFkbG9jaw==”,
“victim”: “Catcorp”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T13:14:48.947189+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOndlaW5iZXJnLmh1fGV1LWNlbnRyYWwtMXxBWkg0WUIzNTkxNExCREpFS0tKQnxFekw0emNQbUZLdXU3YXI3dzVmWmUzenBFMHZlOE5ET1JucHpCYVBB”,
“country”: “HU”,
“data_size”: null,
“description”: “Weinberg ”93 \u00c9p\u00edt\u0151 Kft., a prominent Hungarian construction and steel fabrication company. Overview: Founded in 1993 and headquartered in S\u0431rospatak, it is a 100% privately owned Hungarian company. Core Services: The firm specializes in general contracting and the manufacture of complex steel structures. Major Projects: They have handled significant industrial developments, including: – Volvo Trucks Hungary: Completed a 5,500 m\u0406 advanced truck center in Ecser. – Continental Automotive: Construction of electronics manufacturing plants. – East Gate PRO Business Park: Developed BREEAM-certified sustainable warehouses. – Becton Dickinson: Expansion of a major syringe factory in Hungary. Recognitions: The company has received numerous awards, such as the Lechner \u0426d\u0446n Award (2024) and the Steel Structure Award (2022). Over 650 gigabytes of sensitive internal data were stolen from this company: all commercial information about contractors, information about specialized construction technologies and metal structure production, internal financial transactions, and operations demonstrating corruption in construction projects. We invite all journalists, lawyers, and law enforcement agencies to review this information.”,
“discovered”: “2026-07-10T13:14:50.464738+00:00”,
“domain”: “weinberg.hu”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 3,
“update”: “2026-07-10T13:14:48”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/3c8438e6e6199bda09bc8eac197ea405.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V2VpbmJlcmcgJyc5MyDDiXDDrXTFkSBLZnQuQERlYWRsb2Nr”,
“victim”: “Weinberg ”93 \u00c9p\u00edt\u0151 Kft.”
},
{
“activity”: “Public Sector”,
“attackdate”: “2026-07-10T13:14:27.732787+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/756b97e0-6273-42e6-9cb0-9c78a9557b67”,
“country”: “US”,
“data_size”: null,
“description”: “The Morton Grove Park District (MGPD) is a separate municipal agency established in 1951, governed by five elected commissioners and subject to Illinois state laws. Their motto is: Everyone who lives in, works in, or visits Morton Grove has constitutional rights, no matter their citizenship or immigration status. The Village is committed to making sure every person feels safe, supported, and respected. More than 50 GB of data containing personal and sensitive information belonging to both internal employees and the organization’s clients and suppliers. Documents on financial plans and internal policies are protected by a non-disclosure policy. (Including racist and sexist insights) We invite all journalists, lawyers, and law enforcement agencies to review this information.”,
“discovered”: “2026-07-10T13:14:29.947231+00:00”,
“domain”: “mortongroveparks.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:14:27”,
“users”: 7,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d9acf218032c2467f914793429a7646a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VGhlIE1vcnRvbiBHcm92ZSBQYXJrIERpc3RyaWN0QERlYWRsb2Nr”,
“victim”: “The Morton Grove Park District”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-10T13:14:07.338237+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/043e392a-5172-4fa4-b171-aeb6476ca2cf”,
“country”: “AR”,
“data_size”: null,
“description”: “LA SEVILLANITA is the leading transport company in Argentina.”,
“discovered”: “2026-07-10T13:14:08.884362+00:00”,
“domain”: “www.lasevillanita-online.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/34d60aedab2bf16a7d5ebc66191ff407.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TEEgU0VWSUxMQU5JVEEgU1JMQERlYWRsb2Nr”,
“victim”: “LA SEVILLANITA SRL”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:13:44.196442+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/2b6a6392-78d5-4ccc-9020-e1729ab0de34”,
“country”: “US”,
“data_size”: null,
“description”: “Schlenker & Cantwell, P.A. is a certified public accounting firm based in the USA, offering services such as tax preparation and planning, auditing and assurance, bookkeeping, payroll, financial reporting, consulting, and estate-trust management.”,
“discovered”: “2026-07-10T13:13:45.714975+00:00”,
“domain”: “cpasch.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:13:44”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b9627159c21d631fdfeafba9fce08bdd.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U2NobGVua2VyIGFuZCBDYW50d2VsbCwgUC5BLkBEZWFkbG9jaw==”,
“victim”: “Schlenker and Cantwell, P.A.”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-10T13:13:22.787120+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/76ec6bcf-c188-45da-8f4e-1bff04283c4b”,
“country”: “IT”,
“data_size”: null,
“description”: “WIBEATS is one among the last few independent Italian Asset Management and Loans Service group, specialised performing and non performing real estate. Over 150 gigabytes of internal email datastore were stolen from this company. more than 50 GB of internal sensitive data containing contracts and official papers containing construction and renewal permits”,
“discovered”: “2026-07-10T13:13:24.369298+00:00”,
“domain”: “www.wibeats.it”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/915bc06574c99112f06669863b272fee.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V2lCZWF0cyBTLnIubC5ARGVhZGxvY2s=”,
“victim”: “WiBeats S.r.l.”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:13:01.608578+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/5cef915e-9de4-4e46-ab3e-61aa2fb557f5”,
“country”: “MX”,
“data_size”: null,
“description”: “Grupo Vanguardia is an automotive group”,
“discovered”: “2026-07-10T13:13:03.243903+00:00”,
“domain”: “grupovanguardia.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 2,
“update”: “2026-07-10T13:13:01”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/db9dd21037b335ac7d7b31308191f455.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R3J1cG8gVmFuZ3VhcmRpYUBEZWFkbG9jaw==”,
“victim”: “Grupo Vanguardia”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:12:33.177931+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/82bede2b-0f53-4644-9801-6a68a1c4a605”,
“country”: “DE”,
“data_size”: null,
“description”: “WH M\u00fcller is a family business in the field of electrical engineering and IT technology.”,
“discovered”: “2026-07-10T13:12:42.701332+00:00”,
“domain”: “www.whm.de”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/615ac017450a4b0e7583b9b5ea24f26e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V0ggTcO8bGxlckBEZWFkbG9jaw==”,
“victim”: “WH M\u00fcller”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T13:12:09.536069+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/16533b83-d9f6-4717-abe3-8adb93f7b763”,
“country”: “US”,
“data_size”: null,
“description”: “Doctus offers top-tier medical records services in the USA, specializing in the management and organization of medical documentation.”,
“discovered”: “2026-07-10T13:12:11.758659+00:00”,
“domain”: “www.doctususa.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b98aa022d5c27f1a6d7e463293848634.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RE9DVFVTIFVTQSBJbmNARGVhZGxvY2s=”,
“victim”: “DOCTUS USA Inc”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-07-10T13:11:45.160554+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/c9ee9250-6619-434c-bacc-42cde16c23f7”,
“country”: “UY”,
“data_size”: null,
“description”: “[AI generated] The Automobile Club of Uruguay (ACU) is a nonprofit organization based in Uruguay that provides services to motorists and travelers. It offers roadside assistance, vehicle inspections, travel planning, and tourism-related services. Operating within the automotive services and transportation industry, ACU also promotes road safety and mobility across Uruguay. It maintains affiliations with international automobile club networks, extending member benefits abroad.”,
“discovered”: “2026-07-10T13:11:50.376076+00:00”,
“domain”: “acu.com.uy”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 5,
“update”: “2026-07-10T13:11:45”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/6dde1951d917dcde9faab8184f8ce10d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QUNVIC0gVGhlIEF1dG9tb2JpbGUgQ2x1YiBvZiBVcnVndWF5QERlYWRsb2Nr”,
“victim”: “ACU – The Automobile Club of Uruguay”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:11:24.705171+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/a20d7345-4d52-4ba5-8ad2-167f83e369cb”,
“country”: “AR”,
“data_size”: null,
“description”: “CIATI is a technology center dedicated to providing analytical services, technical assistance, and research and development for the food, geochemistry, and environmental industries.”,
“discovered”: “2026-07-10T13:11:26.101012+00:00”,
“domain”: “ciati.com.ar”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:11:24”,
“users”: 5,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/22af88304e8087c84a52317d197a1bf6.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q0lBVElARGVhZGxvY2s=”,
“victim”: “CIATI”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:10:59.416800+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/35e907c3-0f63-41ff-b05a-bc5ca66cbcac”,
“country”: “MX”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:11:02.031925+00:00”,
“domain”: “quetzalquimica.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:10:59”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f70c55967979bf67642b003ca328c183.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UXVldHphbCBRdcOtbWljYUBEZWFkbG9jaw==”,
“victim”: “Quetzal Qu\u00edmica”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:10:35.749507+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/c50492b5-6a85-4010-aad3-19065af74ffe”,
“country”: “IN”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:10:39.241569+00:00”,
“domain”: “abhayprabhavana.org”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-10T13:10:35”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/90296102ab68fae860f22d026b131389.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWJoYXkgUHJhYmhhdmFuYUBEZWFkbG9jaw==”,
“victim”: “Abhay Prabhavana”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:10:23.969682+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/4d566f56-112b-4ae5-bc14-af224bba2b37”,
“country”: “TR”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:10:26.975500+00:00”,
“domain”: “gmm.com.tr”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:10:23”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/da96289c7079d9cd7c24d26eb83b370d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R8O8dmVuIE3DvGhlbmRpc2xpayBNYWtpbmFARGVhZGxvY2s=”,
“victim”: “G\u00fcven M\u00fchendislik Makina”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:10:02.265454+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/fab08dc1-66b7-4814-91b6-0ddb60e7ebc2”,
“country”: “CA”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:10:05.144975+00:00”,
“domain”: “www.3gisolutions.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d245583067659733aaaeb89e42c113b0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/M0dpIFNvbHV0aW9ucywgaXMgYW4gSVQgU2VydmljZXMgUHJvdmlkZXIgbG9jYXRlZCBpbiBNb250cmVhbCwgUXVlYmVjLkBEZWFkbG9jaw==”,
“victim”: “3Gi Solutions, is an IT Services Provider located in Montreal, Quebec.”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:09:39.853097+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/44d7f179-1705-48b8-a021-7b684a75e456”,
“country”: “BR”,
“data_size”: null,
“description”: “Werken Qu\u00edmica Brasil S.A. is a company specializing in the development and supply of chemical products, headquartered in Indaial, Santa Catarina. It operates primarily within the textile industry, offering solutions for pretreatment, dyeing, printing, yarn lubrication, and effluent treatment, with a focus on functional technologies.”,
“discovered”: “2026-07-10T13:09:41.919621+00:00”,
“domain”: “www.werken.com.br”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0aa03e5418a3e05f92949ebcdf218881.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V2Vya2VuIFF1w61taWNhIEJyYXNpbCBTLkEuQERlYWRsb2Nr”,
“victim”: “Werken Qu\u00edmica Brasil S.A.”
},
{
“activity”: “Public Sector”,
“attackdate”: “2026-07-10T13:09:18.992027+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOnppZGxvY2hvdmljZS5jenxldS1jZW50cmFsLTF8QjJPVElQV01GWlRWUkNHQjJNMDF8VnEybFhGdldXU053aVMyVmlhYlR1WHpzVldYakxIQkJaNlZCTHBxcQ%3D%3D”,
“country”: “CZ”,
“data_size”: null,
“description”: “Internal city administration documents have been leaked. Personal data from the database will be sold on darknet forums. Mayor ‘Jan Vitula’ claims the attack was prevented and no data was stolen. An investigation has been launched with the police, and countermeasures are being taken. =) xD In press: https:\/\/www.denik.cz\/regiony\/zidlochovice-hackeri-kyberneticky-utok-vykupne-data-software-ransomware-kldr.html https:\/\/www.irozhlas.cz\/zpravy-domov\/poslete-bitcoiny-nebo-vas-nepustime-k-datum-urad-v-zidlochovicich-zjistuje-skody_2603172012_bva https:\/\/www.***.cz\/cs\/aktuality\/dulezite-upozorneni-mimoradne-uzavreni-meu.html Over 150 gigabytes of internal data”,
“discovered”: “2026-07-10T13:09:20.876310+00:00”,
“domain”: “www.zidlochovice.cz”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/ce47069c51e8fc705cfe4574ff4b9ed7.png”,
“url”: “https:\/\/www.ransomware.live\/id\/xb1pZGxvY2hvdmljZSBjaXR5QERlYWRsb2Nr”,
“victim”: “\u017didlochovice city”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:08:56.781205+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/523846d5-06be-46c5-b15a-6771d7295d4f”,
“country”: “ES”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:08:59.748758+00:00”,
“domain”: “cpubcn.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 2,
“update”: “2026-07-10T13:08:56”,
“users”: 6,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/fe1cde0bc0f5c89affd786903e3ffe18.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QkFSQ0VMT05BIFVSQkFOIFBST1BFUlRZIENIQU1CRVJARGVhZGxvY2s=”,
“victim”: “BARCELONA URBAN PROPERTY CHAMBER”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T13:08:33.792988+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/94976cb7-b0f4-4872-9712-509f5d440e14”,
“country”: “AR”,
“data_size”: null,
“description”: “Optimal Care Sociedad Anonima manufactures cleaning applications. The Company offers wet wipes for personal care, baby wipes, make-up remover, multipurpose wipes, and cleaning applications. Optimal Care serves customers in Spain.”,
“discovered”: “2026-07-10T13:08:35.128891+00:00”,
“domain”: “www.optimalcaresa.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/bf7f5f4834b64e8d24f01b096cc4c9c4.png”,
“url”: “https:\/\/www.ransomware.live\/id\/T3B0aW1hbCBDYXJlIFNBQERlYWRsb2Nr”,
“victim”: “Optimal Care SA”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-10T13:08:12.390405+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/3db54998-e982-44d4-b75c-cb5dc67dc0ef”,
“country”: “PT”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T13:08:14.869333+00:00”,
“domain”: “”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/93893c05862dcede4f9de349852327f3.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QW5pZGFwb3J0IC0gSW52ZXN0aW1lbnRvcyBJbW9iaWxpw6FyaW9zIExkYS4sIExpc2JvbiwgUG9ydHVnYWxARGVhZGxvY2s=”,
“victim”: “Anidaport – Investimentos Imobili\u00e1rios Lda., Lisbon, Portugal”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:07:50.583475+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/bcc0cf80-bb73-44f4-8eee-ae4f69a68564”,
“country”: “PL”,
“data_size”: null,
“description”: “LIVISTO is an international pharmaceutical company with extensive experience in the veterinary market.”,
“discovered”: “2026-07-10T13:07:54.032673+00:00”,
“domain”: “www.livisto.pl”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/66950d28dfb905862e4cb102c1ac714d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TElWSVNUT0BEZWFkbG9jaw==”,
“victim”: “LIVISTO”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-10T13:07:29.900368+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/42a11be4-f662-49a4-8a65-3eaca7820111”,
“country”: “IT”,
“data_size”: null,
“description”: “Industrie Tecnologiche is a software development center for the food industry.”,
“discovered”: “2026-07-10T13:07:31.677166+00:00”,
“domain”: “www.industrietecnologiche.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a0e853ef8c9b4b331ec253d82e3203c3.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SW5kdXN0cmllIFRlY25vbG9naWNoZSBpdEBEZWFkbG9jaw==”,
“victim”: “Industrie Tecnologiche it”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:07:09.158696+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOnZidy5ubHxldS1jZW50cmFsLTF8VDlWU0ZVQUg2VFJMVlhJQjNDRlp8OUFNanZJV0JveUI2eTRGTnJ0VzRIQ1RpUm9Zejl3T0tDblhnQm1OWg%3D%3D”,
“country”: “NL”,
“data_size”: null,
“description”: “VBW Makelaars & Taxateurs specializes in real estate and property valuations in the Netherlands. Real estate agency and certified appraisers”,
“discovered”: “2026-07-10T13:07:10.906106+00:00”,
“domain”: “www.vbw.nl”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7c7cad1212b1e65437c46b6ee7a36508.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VkJXIE1ha2VsYWFycyBhbmQgVGF4YXRldXJzQERlYWRsb2Nr”,
“victim”: “VBW Makelaars and Taxateurs”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-10T13:06:48.574320+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmVrb2Zsb3IuaHJ8ZXUtY2VudHJhbC0xfFQ5VlNGVUFINlRSTFZYSUIzQ0ZafDlBTWp2SVdCb3lCNnk0Rk5ydFc0SENUaVJvWXo5d09LQ25YZ0JtTlo%3D”,
“country”: “HR”,
“data_size”: null,
“description”: “Eko-Flor Plus d.o.o. is the largest private waste management company in Croatia. Headquartered in Oroslavje, the company specializes in collecting, sorting, and processing municipal and non-hazardous waste.”,
“discovered”: “2026-07-10T13:06:50.300626+00:00”,
“domain”: “eko-flor.hr”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:06:48”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a2e7f7aeab067cd8dabb51adbf256a38.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RWtvLUZsb3IgUGx1cyBkLm8uby5ARGVhZGxvY2s=”,
“victim”: “Eko-Flor Plus d.o.o.”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:06:27.238894+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/229202ff-b928-4ed3-b01b-e052e87174d9”,
“country”: “IT”,
“data_size”: null,
“description”: “Zaffrani Srl, an Italian manufacturer specializing in advanced agricultural machinery. Founded in 1959, the company is headquartered in the Marche region of Italy and has become a global leader in crop harvesting and drying technology.”,
“discovered”: “2026-07-10T13:06:28.863670+00:00”,
“domain”: “www.zaffrani.it”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d8f4281b677b53a8812dca212ddfe944.png”,
“url”: “https:\/\/www.ransomware.live\/id\/WmFmZnJhbmkgU3JsQERlYWRsb2Nr”,
“victim”: “Zaffrani Srl”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:05:56.358076+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/ad48b2b9-d9c0-4e4e-94d9-8b0cacab345b”,
“country”: “MX”,
“data_size”: null,
“description”: “Grupo Mercurio is a leading Mexican business conglomerate primarily recognized for its dominance in the bicycle and sports industry. Based in San Luis Potos\u00ed, the group operates one of the largest bicycle manufacturing plants in Mexico.”,
“discovered”: “2026-07-10T13:06:00.887109+00:00”,
“domain”: “www.grupomercurio.mx”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b950ebfd342e7b52530edd80981e0014.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R3J1cG8gTWVyY3VyaW9ARGVhZGxvY2s=”,
“victim”: “Grupo Mercurio”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:05:41.656567+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/662fed85-d93d-465d-9703-85222eed1f03”,
“country”: “TR”,
“data_size”: null,
“description”: “Senoco Tekstil Sanayi ve Ticaret A.\u015e., a Turkish company specializing in the production of nonwoven fabrics. Maxplast is a Turkish manufacturing company based in Gaziantep that specializes in plastic packaging and houseware solutions. Founded in 2016, the company produces a wide range of PET and PE containers for various industries, including food, cosmetics, agriculture, and chemistry. https:\/\/www.maxplast.com.tr\/”,
“discovered”: “2026-07-10T13:05:47.459642+00:00”,
“domain”: “senoco.com.tr”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:05:41”,
“users”: 1,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/dfd311a080d3db1734fb6acd0f32f88f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TWF4cGxhc3QgQU5EIFNlbm9jb0BEZWFkbG9jaw==”,
“victim”: “Maxplast AND Senoco”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:05:17.074935+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/60fedb3b-53b3-4fb0-adda-bd0c0304229a”,
“country”: “ES”,
“data_size”: null,
“description”: “Gerusia S.L., a Spanish service company headquartered in Oviedo, Asturias. Founded in 1995 and managed by women, the company provides a wide range of cleaning, auxiliary, and social-sanitary services for both public and private sectors throughout the Asturias region.”,
“discovered”: “2026-07-10T13:05:22.695724+00:00”,
“domain”: “gerusia.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:05:17”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c7384885368cb620d049428b4d878639.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R2VydXNpYSBTLkwuQERlYWRsb2Nr”,
“victim”: “Gerusia S.L.”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:04:54.787123+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/3b678bb0-0b34-402b-97ea-2a9caf1dcac1”,
“country”: “LT”,
“data_size”: null,
“description”: “Founded in 1996 in Vilnius, Lithuania, UAB Elmoris is a major manufacturer specializing in light metal packaging and \”twist-off\” lug caps for the food industry. The company is noted for producing PVC-free, environmentally friendly caps and providing metal printing services, holding AEO certification for international trade.”,
“discovered”: “2026-07-10T13:04:57.090275+00:00”,
“domain”: “www.elmoris.lt”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/99107b80c98c2926a68070c0487e4cff.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RWxtb3Jpc0BEZWFkbG9jaw==”,
“victim”: “Elmoris”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:04:34.403511+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/2657865f-0bd7-4bcc-ab5a-537cdd53e63d”,
“country”: “SE”,
“data_size”: null,
“description”: “ONE Contact is a Swedish-managed contact center located in Barcelona, Spain, offering customer service, telemarketing, and retention strategies targeted at the Scandinavian market. Services include 1st\/2nd line support and digital customer service solutions, with a physical office located on Calle Padilla in Barcelona.”,
“discovered”: “2026-07-10T13:04:35.883528+00:00”,
“domain”: “onecontact.se”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:04:34”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d57f65eb8a1fe5f92b82f2e661421cad.png”,
“url”: “https:\/\/www.ransomware.live\/id\/T05FIENvbnRhY3RARGVhZGxvY2s=”,
“victim”: “ONE Contact”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T13:04:10.405517+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/8560fbfc-ef7d-4bb7-a2be-6ac8282ee321”,
“country”: “ES”,
“data_size”: null,
“description”: “Consulting Valladolid S.A. is a professional firm with over 40 years of experience providing comprehensive legal, tax, labor, and accounting services in Valladolid, Spain. The firm utilizes advanced technology to deliver tailored advisory solutions for both companies and individuals”,
“discovered”: “2026-07-10T13:04:15.409916+00:00”,
“domain”: “consultingvalladolid.es”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T13:04:10”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d3117e1aa05be9936de137a765821b47.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q29uc3VsdGluZyBWYWxsYWRvbGlkQERlYWRsb2Nr”,
“victim”: “Consulting Valladolid”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-10T13:03:49.393687+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/cb5835e5-2da2-4063-a4f7-71fe0c70fe7b”,
“country”: “ES”,
“data_size”: null,
“description”: “ADM Value is a leading international company specializing in outsourced customer relationship management (CRM) and Business Process Outsourcing (BPO)”,
“discovered”: “2026-07-10T13:03:51.550963+00:00”,
“domain”: “admvalue.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 67,
“employees_url”: 15,
“infostealer_stats”: {
“Generic Stealer”: 7,
“Lumma”: 11,
“Raccoon”: 2,
“RedLine”: 27,
“StealC”: 1,
“Vidar”: 3
},
“last_employee_compromised”: “2026-06-19T00:00:00+00:00”,
“last_user_compromised”: “1970-01-01T00:00:00+00:00”,
“thirdparties”: 41,
“update”: “2026-07-10T13:03:49”,
“users”: 0,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/49e386e05867a00df7c8f4a73e010d11.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QURNIFZhbHVlIEJhcmNlbG9uYUBEZWFkbG9jaw==”,
“victim”: “ADM Value Barcelona”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:03:28.737952+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/73216a16-b9de-4688-9b00-ff223ac8d143”,
“country”: “”,
“data_size”: null,
“description”: “rtpbz.ro is the official domain for Ring Textile Production RTP SRL, a Romanian textile manufacturing company based in Buz\u0103u. Industry: Manufacture of outerwear and tricot clothing, specializing in women’s nightwear, underwear, and cotton\/linen apparel.”,
“discovered”: “2026-07-10T13:03:30.319034+00:00”,
“domain”: “”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/42a519501643eb97298eb7adaa0d79dd.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UmluZyBUZXh0aWxlIFByb2R1Y3Rpb24gUlRQIFNSTEBEZWFkbG9jaw==”,
“victim”: “Ring Textile Production RTP SRL”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:03:03.574316+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/a8b2c240-5ec2-47b6-9090-13bd9f7614ec”,
“country”: “BR”,
“data_size”: null,
“description”: “Bombas Ideal is a Spanish manufacturer established in 1902 specializing in water pumps and pressure systems for agricultural, industrial, and fire protection applications. Based in Valencia, the company offers a range of vertical, submerged, and solar pumping solutions with international operations.”,
“discovered”: “2026-07-10T13:03:08.413309+00:00”,
“domain”: “www.bombasideal.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7b28cc5449ddf4f8ba98bbd47b8712a6.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Qm9tYmFzIElkZWFsQERlYWRsb2Nr”,
“victim”: “Bombas Ideal”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-07-10T13:02:41.085721+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/555aeaa9-5d97-413a-8032-07e569049e3f”,
“country”: “ES”,
“data_size”: null,
“description”: “This chain operates various urban and beach properties primarily in the Valencia and Alicante regions. Key Properties: SH Valencia Palace: A 5-star hotel located near the city center of Valencia. SH Villa Gadea: A luxury resort in Altea known for its extensive Thalasso-Spa facilities. SH Ingl\u00e9s: A boutique hotel situated in a renovated 18th-century palace in Valencia’s historical center. Other locations: Includes properties in J\u00e1vea, Denia, and Gand\u00eda”,
“discovered”: “2026-07-10T13:02:42.827668+00:00”,
“domain”: “www.sh-hoteles.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/ee9ece9dad69d7d822e9d48c1573f1a9.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U0ggSG90ZWxlcyAoU3BhaW4pQERlYWRsb2Nr”,
“victim”: “SH Hoteles (Spain)”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:02:18.117754+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/2700afb0-1b0b-4dbc-b884-56c3a38ef4fb”,
“country”: “IT”,
“data_size”: null,
“description”: “Bridgeport a leading Italian manufacturing company specializing in the production of valves for air, gas, and fluids.”,
“discovered”: “2026-07-10T13:02:20.122658+00:00”,
“domain”: “www.bridgeport.it”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/da1f026b7e6b4ca726855d48164d1a05.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QnJpZGdlcG9ydCBTLnAuQS5ARGVhZGxvY2s=”,
“victim”: “Bridgeport S.p.A.”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:01:56.541147+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/1463342b-a9d2-4c1e-94c2-2789972fb9c4”,
“country”: “DK”,
“data_size”: null,
“description”: “AK Service & Vedligehold is a Hiller\u00f8d-based contractor providing construction, maintenance, and energy solutions across Zealand, Denmark. The company specializes in electrical work, heat pumps, charging stations, carpentry, and masonry services.”,
“discovered”: “2026-07-10T13:01:59.132058+00:00”,
“domain”: “aksv.dk”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 4,
“update”: “2026-07-10T13:01:56”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2601f87f49eb55f5c4309be0020bc2ad.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QUtTVkBEZWFkbG9jaw==”,
“victim”: “AKSV”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:01:35.709335+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/b54a465d-df3d-4109-aaaf-a26bec535310”,
“country”: “DE”,
“data_size”: null,
“description”: “EFCA a specialized accounting firm based in Paris, France. Core Expertise With over 30 years of experience, the firm specializes in real estate accounting and property management. Key services and areas of focus include: Property Management Support: Expertise in managing accounts for property administrators and real estate agencies. Trustee & Agent Accounting: Mastery of \”comptabilit\u00e9 mandants\” (client\/trustee accounting) and navigating relationships with guarantee funds. Tax & Advisory: Handling complex tax and accounting issues specific to the real estate market.”,
“discovered”: “2026-07-10T13:01:37.415389+00:00”,
“domain”: “www.efca-europe.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/332991596d96f7236b0e26405826495f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RUZDQUBEZWFkbG9jaw==”,
“victim”: “EFCA”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:01:15.160171+00:00”,
“claim_url”: “https:\/\/www.swisstransfer.com\/d\/7930659e-b3bd-48d2-a57f-72e3f84a9f45”,
“country”: “SG”,
“data_size”: null,
“description”: “Starconn (registered as Chief Land Electronic Co., Ltd.) is a top-five connector manufacturer based in Taiwan. Founded in 1978, the company specializes in high-precision connectors for telecommunications, data centers, and consumer electronics. Core Products & Services Connectors: They produce a wide range of connectors, including high-speed backplane (up to 25Gbps), FPC, and EDSFF E1.S connectors. Target Markets: Their components are used in desktops, laptops, LCD panels, servers, storage, and networking equipment. Manufacturing Capabilities: The company integrates plastic mold tooling, micro-injection molding, and automated assembly. Technical Services: They offer R&D partnerships for custom system designs, utilizing CAE software for mechanical and signal integrity simulations. Company Details Headquarters: Wugu District, New Taipei City, Taiwan. Presence: They have significant operations and certifications (ISO 9001, IATF 16949) in both Taipei and Kunshan, China. Intellectual Property: As of 2022, they held over 500 patents.”,
“discovered”: “2026-07-10T13:01:16.850192+00:00”,
“domain”: “www.starconn.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/29345bafb30e2743097e53964865c7c4.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U3RhcmNvbm5ARGVhZGxvY2s=”,
“victim”: “Starconn”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T13:00:47.398404+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOnBpY2Fzc2VudC5lc3xldS1jZW50cmFsLTF8VDlWU0ZVQUg2VFJMVlhJQjNDRlp8OUFNanZJV0JveUI2eTRGTnJ0VzRIQ1RpUm9Zejl3T0tDblhnQm1OWg%3D%3D”,
“country”: “ES”,
“data_size”: null,
“description”: “Ayuntamiento de Picassent (Picassent City Council), a municipality located in the Horta Sud region of Valencia, Spain.”,
“discovered”: “2026-07-10T13:00:56.152756+00:00”,
“domain”: “www.picassent.es”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/acedf2a833b022b7def919f8e90a5949.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UGljYXNzZW50QERlYWRsb2Nr”,
“victim”: “Picassent”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:00:26.564914+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOnRlc3RidGVzdGJ8ZXUtd2VzdC0yfFM3VURJVDRZRkROSkdRM0FaVk9UfGc3UkZCbTFmTzhHZ1RnMER3ZzNlM1QzdzhQREFNRUZ1bHIwN3F0Uno%3D”,
“country”: “PG”,
“data_size”: null,
“description”: “United Finance Limited (UFL) is a 100% nationally owned financial institution based in Papua New Guinea. Registered in 2017 and fully established in April 2019, the company provides personal and commercial lending services designed to assist individuals and small businesses with quick access to capital.”,
“discovered”: “2026-07-10T13:00:28.348304+00:00”,
“domain”: “www.ufl.com.pg”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/5f2481b29277aca9b86a31936aa0e347.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VUZMQERlYWRsb2Nr”,
“victim”: “UFL”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T13:00:04.463838+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmZpcmVzdGEuY3p8ZXUtY2VudHJhbC0xfFQ5VlNGVUFINlRSTFZYSUIzQ0ZafDlBTWp2SVdCb3lCNnk0Rk5ydFc0SENUaVJvWXo5d09LQ25YZ0JtTlo%3D”,
“country”: “CZ”,
“data_size”: null,
“description”: “Firesta-Fi\u0161er, a.s. is a Czech construction company based in Brno, established in 1990, specializing in transport infrastructure, including bridge, road, and railway construction. With over 600 employees, the company also operates in Slovakia, Poland, and Romania.”,
“discovered”: “2026-07-10T13:00:07.221417+00:00”,
“domain”: “www.firesta.cz”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c9167cdb99b073ff27eab003910235bb.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RklSRVNUQUBEZWFkbG9jaw==”,
“victim”: “FIRESTA”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:59:43.586122+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZ2VvcGFydG5lci5wbHxldS1jZW50cmFsLTF8QVJSNUdEVDMwUlZURFdMTjFaMU58UHJhVGhYWkc2VmZPNkVjZXR6RDczdUFJRmx6VWRxWjNzVGlhNGZ6MA%3D%3D”,
“country”: “PL”,
“data_size”: null,
“description”: “Geopartner Geomatics Sp. z o.o. is a Gda\u0144sk-based engineering firm specializing in advanced surveying, mapping, and BIM services for the infrastructure sector. The company utilizes LiDAR scanners and drones to support road and rail projects, operating in the Polish and Swedish markets. GEOPARTNER Sp. z o.o. is a Polish engineering firm specializing in geophysical and geotechnical services, primarily focused on investigating ground conditions for energy, infrastructure, and mining projects.”,
“discovered”: “2026-07-10T12:59:45.169939+00:00”,
“domain”: “www.geopartner-geomatics.pl”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a7aa27a979f5318762046e4f49585ea7.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R0VPUEFSVE5FUiBTcC4geiBvLm8uIGFuZCBHRU9QQVJUTkVSIEdFT01BVElDUyBTcC4geiBvLm8uQERlYWRsb2Nr”,
“victim”: “GEOPARTNER Sp. z o.o. and GEOPARTNER GEOMATICS Sp. z o.o.”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T12:59:23.226555+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtam9zby5ub3xldS1jZW50cmFsLTJ8TU1MVjVVVVFPRERLNDhCRzIxTDd8ZThiMHpQbVlKbkc0ZW45SWRhNlk3czJuWHkyWkljRzd2YTVpSlo1OA%3D%3D”,
“country”: “NO”,
“data_size”: null,
“description”: “JOSO, a Norwegian industrial engineering and manufacturing company. Based in Lonev\u00e5g, Norway, the company specializes in producing high-quality mechanical components and hardware.”,
“discovered”: “2026-07-10T12:59:24.695321+00:00”,
“domain”: “joso.no”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T12:59:23”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e5f56f0e0f2313422c266b1165866788.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Sk9TT0BEZWFkbG9jaw==”,
“victim”: “JOSO”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:59:00.738051+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtb3Blcm9zYS5pdHxldS1jZW50cmFsLTF8REhYTDBRTTRVNklWRjlPSEo5VUV8QzlaUlFzUWFzem1JUVFGNld6T1dwekRhUHk4U1hTS2tlRHJ0ajM0Mg%3D%3D”,
“country”: “IT”,
“data_size”: null,
“description”: “The leaked files will be available for download on May 10, 2026. C.A.A. \”Giorgio Nicoli\” S.r.l. Integra S.r.l L’Operosa S.p.A.”,
“discovered”: “2026-07-10T12:59:02.438162+00:00”,
“domain”: “www.caa.it”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0771c59fbc04faaee8473b4b3e285ad0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SW50ZWdyYSBhbmQgT3Blcm9zYUBEZWFkbG9jaw==”,
“victim”: “Integra and Operosa”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T12:58:36.376746+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOjhwMi5kZXxldS1jZW50cmFsLTF8QzAxVFRVR1E4VTdMQ0pMM0NLVk18bFNUald1bE5rTGU0TzhjWFdxa0FyN044NGF5ODNsYmFvbVl1SmFmMg%3D%3D”,
“country”: “DE”,
“data_size”: null,
“description”: “8.2 Group an international network of over 40 independent engineering firms specializing in technical inspection, consulting, and engineering for renewable energy projects. Headquartered in Germany, the group provides services throughout the lifecycle of wind, solar, and battery storage projects worldwide.”,
“discovered”: “2026-07-10T12:58:37.713831+00:00”,
“domain”: “www.8p2.de”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/61c4aaa0b4808cdf8710d58b2de278b0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/OC4yIEdyb3VwIGUuVi5ARGVhZGxvY2s=”,
“victim”: “8.2 Group e.V.”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:58:15.866204+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtcGxpc3prYS5wbHxldS1jZW50cmFsLTF8QkQyNVdPUk5TNjNRMzRWQ0pMMzR8enVJZ0REUGE0NFJHMTU0Yzdoa3JjNlFmTHVUNkJjUU93amc0WUo3Tw%3D%3D”,
“country”: “PL”,
“data_size”: null,
“description”: “PB Sprinkler Engineering (formerly Pliszka Sprinkler) provides comprehensive fire protection solutions, including technical design in 2D and 3D, and customized, certified systems. The company specializes in electronic detection and fixed gas extinguishing systems. Pliszka is a Polish engineering firm based in Gda\u0144sk with over 30 years of experience specializing in comprehensive active fire protection systems. The company provides design, installation, and maintenance services for automatic extinguishing, fire alarm, and smoke removal systems, along with 24\/7 service.”,
“discovered”: “2026-07-10T12:58:17.493143+00:00”,
“domain”: “pliszka.pl\/en”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e4d1c92b79cffd50c1f7246f5603b91f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UEIgU3ByaW5rbGVyIEVuZ2luZWVyaW5nIFNwLiB6IG8uby4gYW5kIFBMSVNaS0EgRmlyZSBQcm90ZWN0aW9uIEVuZ2luZWVyaW5nQERlYWRsb2Nr”,
“victim”: “PB Sprinkler Engineering Sp. z o.o. and PLISZKA Fire Protection Engineering”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:57:55.144078+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtdW5pY2FyZC5wbHxldS1jZW50cmFsLTF8QkQyNVdPUk5TNjNRMzRWQ0pMMzR8enVJZ0REUGE0NFJHMTU0Yzdoa3JjNlFmTHVUNkJjUU93amc0WUo3Tw%3D%3D”,
“country”: “PL”,
“data_size”: null,
“description”: “SKK Networks is a specialized IT infrastructure provider based in Krak\u00f3w, Poland, that designs, builds, and maintains professional LAN and WLAN networks. They focus on creating high-performance connectivity solutions for challenging environments like high-bay warehouses, cold storage facilities, and industrial plants. Unicard Systems is a Polish manufacturer and integrator of security and building automation systems with over 30 years of experience. Based in Krak\u00f3w, the company specializes in designing and implementing proprietary hardware and software solutions for business and public infrastructure. SKK Labels , a prominent Polish label manufacturer and printing company based in Krak\u00f3w. With over 30 years of experience, the company provides comprehensive product marking solutions across various industries, including pharmaceutical, automotive, and logistics.”,
“discovered”: “2026-07-10T12:57:57.024953+00:00”,
“domain”: “www.skk-networks.com\/en”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a10eab84bda5a0a48a4e8f6fef8418db.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U0tLIE5ldHdvcmtzIFNwLiB6IG8uby4gYW5kIFVOSUNBUkQgU3lzdGVtcyBTcC4geiBvLiBvLiBhbmQgU0tLIFNBQERlYWRsb2Nr”,
“victim”: “SKK Networks Sp. z o.o. and UNICARD Systems Sp. z o. o. and SKK SA”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T12:57:33.499184+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZHlocmJlcmcuY2h8ZXUtY2VudHJhbC0xfEJEMjVXT1JOUzYzUTM0VkNKTDM0fHp1SWdERFBhNDRSRzE1NGM3aGtyYzZRZkx1VDZCY1FPd2pnNFlKN08%3D”,
“country”: “CH”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T12:57:36.260977+00:00”,
“domain”: “www.dyhrberg.ch”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/694bb44c2f74a421ba92c8ed7d34bc4a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RHlocmJlcmcgQUcgU3dpdHplcmxhbmRARGVhZGxvY2s=”,
“victim”: “Dyhrberg AG Switzerland”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:57:11.955286+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZ3J1cG9hY3R1YWwucHR8ZXUtY2VudHJhbC0xfEFSUjVHRFQzMFJWVERXTE4xWjFOfFByYVRoWFpHNlZmTzZFY2V0ekQ3M3VBSUZselVkcVozc1RpYTRmejA%3D”,
“country”: “AO”,
“data_size”: null,
“description”: “The leaked files will be available for download on May 10, 2026. Grupolider is a prominent Angolan conglomerate that has been operating in the national market since 1999. Headquartered in Catete, Luanda, the group initially started as a freight forwarding company and has since diversified into a wide range of sectors including agriculture, construction, and furniture. Grupo Actual is a human resources and recruitment agency in Portugal that provides temporary work solutions, permanent recruitment, and selection services.Following a rebranding in late 2025, the company formerly known as Leader now operates under the Actual brand.”,
“discovered”: “2026-07-10T12:57:13.578726+00:00”,
“domain”: “grupolider-ao.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 11,
“update”: “2026-07-10T12:57:11”,
“users”: 4,
“users_url”: 3
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e1a9821854d9ab5ac841c243cf692b8c.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R3J1cG9saWRlciB8IEdydXBvIEFjdHVhbEBEZWFkbG9jaw==”,
“victim”: “Grupolider | Grupo Actual”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-07-10T12:56:50.674928+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtYmFlci1jYXJnb2xpZnQucGx8ZXUtY2VudHJhbC0xfERTRE5IQUxCMlBSTUcwTjZEUVhDfHlDY0NnelF6VjVLOGxxZWlpY0swMGdTcDJaS0NBSEdnWU90dDJVY0M%3D”,
“country”: “PL”,
“data_size”: null,
“description”: “B\u00e4r Cargolift specializing in the manufacturing of hydraulic tail lifts for vehicles, featuring products with capacities from 500 kg to 3,000 kg. The site offers an online WebShop for spare parts, technical support via B\u00e4r CargoCheck, and operator training, with a local headquarters in Gda\u0144sk.”,
“discovered”: “2026-07-10T12:56:53.057546+00:00”,
“domain”: “www.barcargolift.pl”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/810d1c07e353bc911d91bd02f8a3b371.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QsOkciBDYXJnb2xpZnQgUG9sc2thIFNwLiB6IG8uby5ARGVhZGxvY2s=”,
“victim”: “B\u00e4r Cargolift Polska Sp. z o.o.”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:56:29.708325+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZXhwcmVzb2tuYS5wbHxldS1jZW50cmFsLTF8QkQyNVdPUk5TNjNRMzRWQ0pMMzR8enVJZ0REUGE0NFJHMTU0Yzdoa3JjNlFmTHVUNkJjUU93amc0WUo3Tw%3D%3D”,
“country”: “PL”,
“data_size”: null,
“description”: “EXPRESOKNA SP. Z O.O. a Polish manufacturer and distributor specializing in window and door systems. Based in Siemianowice \u015al\u0105skie, the company is known for its exceptionally fast turnaround times for PVC and aluminum products.”,
“discovered”: “2026-07-10T12:56:31.791737+00:00”,
“domain”: “expresokna.pl”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T12:56:29”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4cfe6336561660bac323cceadbcfb8a3.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RVhQUkVTT0tOQSBTUC4gWiBPLk8uQERlYWRsb2Nr”,
“victim”: “EXPRESOKNA SP. Z O.O.”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2026-07-10T12:56:08.808979+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOnRwdG95cy5jb218ZXUtY2VudHJhbC0xfEIyT1RJUFdNRlpUVlJDR0IyTTAxfFZxMmxYRnZXV1NOd2lTMlZpYWJUdVh6c1ZXWGpMSEJCWjZWQkxwcXE%3D”,
“country”: “GB”,
“data_size”: null,
“description”: “TP Toys is a UK-based company that has specialized in designing and manufacturing high-quality children\u2019s outdoor play equipment for over 60 years”,
“discovered”: “2026-07-10T12:56:10.879666+00:00”,
“domain”: “www.tptoys.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7d8f49fcdad23de7f6abdf21c1885b3d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VFBUb3lzQERlYWRsb2Nr”,
“victim”: “TPToys”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-10T12:55:48.097664+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmlmY2V1cm9wYS5jb218ZXUtY2VudHJhbC0xfEIyT1RJUFdNRlpUVlJDR0IyTTAxfFZxMmxYRnZXV1NOd2lTMlZpYWJUdVh6c1ZXWGpMSEJCWjZWQkxwcXE%3D”,
“country”: “DE”,
“data_size”: null,
“description”: “IFC Europa is a Spanish-based distributor specializing in car audio, automotive lighting, and electronics.”,
“discovered”: “2026-07-10T12:55:49.858397+00:00”,
“domain”: “www.ifceuropa.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e5d0d536d0c904fbac0d92055cc19ea7.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SUZDIEV1ckBEZWFkbG9jaw==”,
“victim”: “IFC Eur”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T12:55:27.182958+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmVzbm92YS5jb218ZXUtY2VudHJhbC0xfEIyT1RJUFdNRlpUVlJDR0IyTTAxfFZxMmxYRnZXV1NOd2lTMlZpYWJUdVh6c1ZXWGpMSEJCWjZWQkxwcXE%3D”,
“country”: “ES”,
“data_size”: null,
“description”: “Esnova (Esnova Racks S.A.) is a leading Spanish manufacturer specializing in industrial shelving and warehouse storage systems. Based in Gij\u00f3n, Asturias, the company designs, manufactures, and installs solutions for logistics and warehouse management across more than 35 countries. Noega Systems is a specialized industrial company that designs, manufactures, and installs metal racking and storage solutions. Founded in 2010 and headquartered in Gij\u00f3n, Spain, the firm provides end-to-end intralogistics services, including technical inspections (ITE) and automated warehouse planning. Over 130 gigabytes of internal data”,
“discovered”: “2026-07-10T12:55:29.274977+00:00”,
“domain”: “esnova.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T12:55:27”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/651da31a3ba60633521d945d83afef42.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Tm9lZ2EgYW5kIEVzbm92YUBEZWFkbG9jaw==”,
“victim”: “Noega and Esnova”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T12:55:05.706363+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmlhc2suaHV8ZXUtY2VudHJhbC0xfEFaSDRZQjM1OTE0TEJESkVLS0pCfEV6TDR6Y1BtRkt1dTdhcjd3NWZaZTN6cEUwdmU4TkRPUm5wekJhUEE%3D”,
“country”: “HU”,
“data_size”: null,
“description”: “The Institute of Advanced Studies K\u0151szeg is a Hungarian research center focusing on interdisciplinary studies, regional transformation in Central\/Southeastern Europe, and sustainability. It operates as a hub for research, hosting an annual International Summer University and maintaining specialized collections at the Festetics Palace.”,
“discovered”: “2026-07-10T12:55:07.197359+00:00”,
“domain”: “iask.hu\/en”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4c79153041ca44baba0d42181eefd4c0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/aUFTS0BEZWFkbG9jaw==”,
“victim”: “iASK”
},
{
“activity”: “Energy”,
“attackdate”: “2026-07-10T12:54:45.178976+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZmluYW1nYWJvbi5jb218ZXUtY2VudHJhbC0xfFlVQk1OV1JZUFFYMVc2Qk0zQzJEfDIyOTJ5WURNQnoyUFZJOXZFbTFGOGNXVk1GWHNhY0JrZFNIa3I1UlM%3D”,
“country”: “GA”,
“data_size”: null,
“description”: “The leaked files will be available for download on May 15, 2026. Finam Gabon (Financi\u00e8re Africaine de Micro-projets) is a microfinance institution operating in Gabon since 2005, with over 150,000 clients. It provides a range of savings, loans and mobile banking services.”,
“discovered”: “2026-07-10T12:54:46.804615+00:00”,
“domain”: “finamgabon.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: {
“Raccoon”: 1,
“StealC”: 1
},
“last_employee_compromised”: “1970-01-01T00:00:00+00:00”,
“last_user_compromised”: “2024-09-12T22:02:51+00:00”,
“thirdparties”: 1,
“update”: “2026-07-10T12:54:45”,
“users”: 1,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2340556afaf9efdee7a54cefed9599da.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RmluYW0gR2Fib25ARGVhZGxvY2s=”,
“victim”: “Finam Gabon”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:54:23.218951+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtYWZ3LnNnfGV1LWNlbnRyYWwtMXw2R1gxM1dGSFlCOUZTMDNKSVI1U3xldEJPTWVHN0dCRWdkRWVadHppYTNsTFVEMUxkWWV6Uks1UHo4RGdI”,
“country”: “SG”,
“data_size”: null,
“description”: “AFW an international architectural and design firm based in Singapore. Formerly known as Andy Fisher Workshop, the firm has been operating since 2004. They are a multi-disciplinary practice that works on a variety of large-scale and boutique projects across Asia and beyond.”,
“discovered”: “2026-07-10T12:54:26.159024+00:00”,
“domain”: “www.afw.sg”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2015242f663d71d39e02c63ae2db1a44.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QUZXb3Jrc2hvcEBEZWFkbG9jaw==”,
“victim”: “AFWorkshop”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:54:00.044569+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtbmlwcG9uZXhwcmVzc2l0YWxpYS5jb218ZXUtY2VudHJhbC0xfFRBUzA2WFJURVRQVlVYMkxIN0U3fEVUeWFSNjJkZDI0ODJKWFdXcTNJVXkwSzRuWnpYUDhlRVNldjZvbno%3D”,
“country”: “IT”,
“data_size”: null,
“description”: “The leaked files will be available for download on May 15, 2026. Nippon Express Italia SpA (NXIT) is the Italian division of the global NX Group (formerly Nippon Express). It was established on January 1, 2020, following a major merger involving several high-profile Italian logistics companies, including Franco Vago and Traconf . Recorded a consolidated turnover of almost EUR 1 billion in 2022. Core Services: The company specializes in integrated logistics and global freight forwarding, with a particularly strong reputation in the Fashion & Luxury sector. Traconf Srl a major Italian logistics firm specializing in fashion and luxury goods. Portuguese branch of Franco Vago , which, much like Traconf, is now a key part of the Nippon Express Italia SpA (NX Group) network. In Portugal, the company operates as a specialized freight forwarder with a strong focus on the textile, footwear, and luxury sectors\u2014leveraging the historical expertise of the Franco Vago brand. Over 220 gigabytes of sensitive internal data were stolen from this company”,
“discovered”: “2026-07-10T12:54:01.820965+00:00”,
“domain”: “www.nipponexpressitalia.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/30fe901ce099fb889c44b4a016c7001f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TlhJVCBhbmQgRnJhbmNvIFZhZ28gUy5wLmEuIGFuZCBUcmFjb25mIFNybEBEZWFkbG9jaw==”,
“victim”: “NXIT and Franco Vago S.p.a. and Traconf Srl”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T12:53:39.461073+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtYmVycy5iZ3xldS1jZW50cmFsLTF8NkdYMTNXRkhZQjlGUzAzSklSNVN8ZXRCT01lRzdHQkVnZEVlWnR6aWEzbExVRDFMZFllelJLNVB6OERnSA%3D%3D”,
“country”: “BG”,
“data_size”: null,
“description”: “Bers logistics has been providing logistics services and high quality 3pl outsourcing of integrated logistics services.”,
“discovered”: “2026-07-10T12:53:41.076602+00:00”,
“domain”: “bers.bg”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-10T12:53:39”,
“users”: 1,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/591298e5067d7a1e882dcedb1bbf8c2b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/YkVSU0BEZWFkbG9jaw==”,
“victim”: “bERS”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-07-10T12:53:18.722034+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtbXV6ZXVtdmFsYXNza28uY3p8ZXUtY2VudHJhbC0xfERNTThCWllTUVZVU1A0NFZOTDJGfG5MdVl6SDVWR2tLYVVWbnlYUFZHaExtOWtHb0pkWTN1NGlON0s5ZTc%3D”,
“country”: “CZ”,
“data_size”: null,
“description”: “Muzeum regionu Vala\u0161sko (The Museum of the Wallachian Region) is a multi-site cultural institution in the Zl\u00edn Region of the Czech Republic.”,
“discovered”: “2026-07-10T12:53:20.252509+00:00”,
“domain”: “www.muzeumvalassko.cz”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/df6efe4e116f646b0935cf47cd8e5015.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TXV6ZXVtIFZhbGFzc2tvQERlYWRsb2Nr”,
“victim”: “Muzeum Valassko”
},
{
“activity”: “Energy”,
“attackdate”: “2026-07-10T12:52:57.864107+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtYnJlZGFlbmVyZ2lhLml0fGV1LWNlbnRyYWwtMXw5SzhCSjhKNlZRUVMxNFVSR0NQRXxPZWRQN3AxaGdxZTJXSnRKRnVEdnBWTDJLYXRZTGNpY0EwdTlvSG16”,
“country”: “IT”,
“data_size”: null,
“description”: “Breda Energia S.p.A. is a global leader in the Oil & Gas industry, specializing in innovative products and services for onshore, offshore, and subsea applications. The company offers a wide range of solutions including wellheads, valves, high integrity pressure protection systems, and packaged systems, all designed with a focus on sustainability and cutting-edge technology. With over 60 years of experience, Breda Energia aims to be a partner to its clients, providing not just equipment but also qualified services to optimize performance and maintenance. Their commitment to quality is reflected in their adherence to various international standards and certifications.”,
“discovered”: “2026-07-10T12:52:59.295349+00:00”,
“domain”: “www.bredaenergia.it”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/92b6e74a44768ebc4bde77c4b3655440.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QnJlZGEgRW5lcmdpYUBEZWFkbG9jaw==”,
“victim”: “Breda Energia”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:52:35.801593+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtZWRpc2EtaW52ZXJ0aWdlfGV1LWNlbnRyYWwtMXxKRTlaTzZBVzJVS1lBR1EwWFFJWnxOZXczdjZlT1JldHVVRUx5QVMwVHpoUkpybXNWdGN3Nk5taERVd0NS”,
“country”: “”,
“data_size”: null,
“description”: “Estudios de Investigaci\u00f3n Servicio SL (also known commercially in some rankings as EDISA ) is a Limited liability company of a patrimonial and real estate nature with headquarters in Valencia, Spain.Although its corporate name includes the words \”research studies\”, its real corporate purpose and main activities are focused on asset management, investment in other companies and real estate development. INVERTIGE SL is a Spanish company headquartered in ValenciaThe company is registered for central management functions and consultancy , with a focus on the administration and governance of other companies, and has an annual turnover of around EUR 1.9 million.”,
“discovered”: “2026-07-10T12:52:39.024948+00:00”,
“domain”: “”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2739ae7c489dae4cf61a262fe469ebd2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RURJU0EgYW5kIElOVkVSVElHRUBEZWFkbG9jaw==”,
“victim”: “EDISA and INVERTIGE”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2026-07-10T12:52:16.219630+00:00”,
“claim_url”: “http:\/\/deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion\/s3.php?d=d2FzYWJpOmRhdGEtYXV0b3BhcmsuY29tLmJyfGV1LWNlbnRyYWwtMXxMM0FXVlc2MEhOUjNHVUZIVDVZQnw2bG1mVnlEV2tDZ0t6TENBZUM5VFFGYUpRNE9DQmk1QjFKOTJPRklS”,
“country”: “BR”,
“data_size”: null,
“description”: “Autopark Estacionamentos is one of the largest and most reputable parking management companies in Brazil.Founded in Curitiba, Paran\u00e1 , the company has over 36 years of experience in the market.”,
“discovered”: “2026-07-10T12:52:17.624479+00:00”,
“domain”: “autopark.com.br”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 6,
“employees_url”: 4,
“infostealer_stats”: {
“Generic Stealer”: 12,
“Lumma”: 27,
“Raccoon”: 10,
“RedLine”: 20,
“StealC”: 4,
“UNKNOWN”: 1,
“Vidar”: 4
},
“last_employee_compromised”: “2026-03-23T12:44:00+00:00”,
“last_user_compromised”: “2026-04-23T00:00:00+00:00”,
“thirdparties”: 22,
“update”: “2026-07-10T12:52:16”,
“users”: 78,
“users_url”: 28
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9e886593af1ceb421fc9e95e55a0ac11.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RGlyZcOnw6NvIEVzdGFjaW9uYW1lbnRvcyBTLkEuQERlYWRsb2Nr”,
“victim”: “Dire\u00e7\u00e3o Estacionamentos S.A.”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-10T12:33:12.176529+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=1b5dabef-3604-486e-a4bb-a6b218d64794”,
“country”: “SG”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T12:33:39.526402+00:00”,
“domain”: “www.spacelogic.com.sg”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e06627ee03079d14dbd4b39a3c411295.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U1BBQ0Vsb2dpY0BxaWxpbg==”,
“victim”: “SPACElogic”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T12:32:29.858235+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=b0f5ac07-c0fe-4311-a395-078bc298ca8f”,
“country”: “US”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T12:32:52.497496+00:00”,
“domain”: “www.globalstrategic.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/80bfc2e1b97858a15884d4a6b0fb9adc.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R2xvYmFsIFN0cmF0ZWdpYyBCdXNpbmVzcyBQcm9jZXNzIFNvbHV0aW9uc0BxaWxpbg==”,
“victim”: “Global Strategic Business Process Solutions”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T12:31:46.460039+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=53072cde-abae-4f7b-b8de-de51d5d95d98”,
“country”: “AR”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T12:32:07.869082+00:00”,
“domain”: “www.crzconstrucciones.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c852773476f0a6615548ccf765572f48.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q1JaIENvbnN0cnVjY2lvbmVzQHFpbGlu”,
“victim”: “CRZ Construcciones”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-07-10T12:31:05.863471+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=242a6cc9-5e6c-4cda-8a28-6bb684772df9”,
“country”: “PH”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-10T12:31:27.328550+00:00”,
“domain”: “www.redplanethotels.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/663b5bde2a4d1eb4979d8f7dc06a82cb.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UmVkIFBsYW5ldCBIb3RlbHNAcWlsaW4=”,
“victim”: “Red Planet Hotels”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T12:01:13.388305+00:00”,
“claim_url”: “http:\/\/payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion\/posts\/0a46eb9e-76c0-49b2-8037-303ac1082022”,
“country”: “”,
“data_size”: null,
“description”: “Roofinox is an Austrian manufacturer of premium stainless steel specifically engineered for long-lasting roofing and facade systems. The company offers innovative materials with unique matte and textured surfaces that blend beautifully with architecture without creating harsh glare. Thanks to its exceptional corrosion resistance and durability in harsh climates, Roofinox products are recognized as an eco-friendly, virtually timeless architectural solution.”,
“discovered”: “2026-07-10T12:01:53.199181+00:00”,
“domain”: “”,
“group”: “payload”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/fe7d6b9cc86f32443db60058db116354.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Um9vZmlub3hAcGF5bG9hZA==”,
“victim”: “Roofinox”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T09:53:15+00:00”,
“claim_url”: “http:\/\/ejzl7cjxmkx7lzhiqwidmrwtfjv45pkczbc4fnyaut3t7gll3yaiq5id.onion\/blog?uuid=5e7268b2-200b-3bbc-87d1-c4add2955fb3”,
“country”: “CN”,
“data_size”: null,
“description”: “Confidential data will be released soon.”,
“discovered”: “2026-07-10T10:53:44.840128+00:00”,
“domain”: “txdkj.com”,
“group”: “blackwater”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T10:53:28”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/18e9f5b78c642267712b2f753a1e550e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/dHhka2ouY29tQGJsYWNrd2F0ZXI=”,
“victim”: “txdkj.com”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T08:20:14.321991+00:00”,
“claim_url”: “http:\/\/iacjvmxjb2ivqkxxzmde4w6g53gn6ym7c3g6mfifvejyhqtp4wrkypyd.onion\/victim\/hospital-di-camp”,
“country”: “”,
“data_size”: null,
“description”: “Status: upcoming | Data size: N\/A | Files: 0 files | Deadline: 2026-07-21T00:00:00Z”,
“discovered”: “2026-07-10T08:20:29.041483+00:00”,
“domain”: “”,
“group”: “Doommageddon”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a792bf72caeffdf933678f7617ac40e5.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SG9zcGl0YWwgRGkgQ2FtcEBEb29tbWFnZWRkb24=”,
“victim”: “Hospital Di Camp”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T03:55:50+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “***.com Dash Door & Glass is a prominent commercial contractor and facility support specialist headquartered in Doral, Florida, with a rich history dating back to 1955. The company specializes in the supply, installation, and maintenance of commercial doors, glass, and architectural hardware for large-scale construction projects across South Florida. Operating with a dedicated team of professionals, the firm has established itself as a major industry player, generating an impressive annual revenue of approximately $113.3 million”,
“discovered”: “2026-07-11T07:17:30.773133+00:00”,
“domain”: “dashdoor.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-11T07:17:26”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RGFzaCBEb29yIEdsYXNzQHRoZWdlbnRsZW1lbg==”,
“victim”: “Dash Door Glass”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T03:52:16+00:00”,
“claim_url”: “”,
“country”: “GR”,
“data_size”: null,
“description”: “***.gr zoominfo.com\/c\/bdo-certified-public-accountants-sa\/372555588 BDO Greece is a leading Athens-based accounting, tax, and advisory firm that operates as a member of the global BDO network. The company provides comprehensive audit, assurance, and business consulting services to a diverse range of industries, including real estate, hospitality, and the public sector. Employing between 50 and 200 professionals, the firm generates an estimated annual revenue of over $23 million while helping clients navigate complex financial and regulatory landscapes”,
“discovered”: “2026-07-11T07:17:50.436259+00:00”,
“domain”: “bdo.gr”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 2,
“update”: “2026-07-11T07:30:02”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QkRPIEdyZWVjZUB0aGVnZW50bGVtZW4=”,
“victim”: “BDO Greece”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T03:50:59+00:00”,
“claim_url”: “”,
“country”: “FR”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/carita\/358348689 Carita is a prestigious French luxury skincare brand founded in 1945, renowned for its professional-grade beauty treatments and high-end cosmetics. Now part of L’Or\u00e9al’s Luxury Division following its acquisition from Shiseido in 2022, the brand operates globally with a focus on exceptional skincare rituals and personalized beauty experiences. Available in over 130 countries, Carita combines innovative formulations with artisanal expertise, generating annual revenue in the range of $9-10 million for its core operations”,
“discovered”: “2026-07-11T07:18:11.867905+00:00”,
“domain”: “carita.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:18:10”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2FyaXRhQHRoZWdlbnRsZW1lbg==”,
“victim”: “Carita”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T03:50:11+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/lopes-law-llc\/449811320 Lopes Law LLC is a Philadelphia-based law firm founded by Anthony Lopes that specializes in franchise law, representing both franchisees and franchisors nationwide. The firm provides comprehensive legal services including Franchise Disclosure Document (FDD) reviews, franchise agreement negotiations, and dispute resolution using transparent flat-fee pricing. In addition to franchise expertise, the practice acts as fractional general counsel for businesses and offers specialized tax law services to help companies navigate complex legal landscapes”,
“discovered”: “2026-07-11T07:18:32.539868+00:00”,
“domain”: “lopeslawllc.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:18:30”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TG9wZXMgTGF3QHRoZWdlbnRsZW1lbg==”,
“victim”: “Lopes Law”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T03:47:57+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/gene-codes-forensics-inc\/1208843964 Gene Codes Forensics is a Michigan-based technology company and a global leader in disaster victim identification and human DNA matching. They provide specialized forensic software, such as Sequencher and M-FISys, which are utilized by numerous states and countries as central DNA resources for identifying remains in mass disasters. In addition to providing software and consulting services, the company operates a one-million-dollar Humanitarian Grant Program to support non-profit organizations conducting forensic DNA testing”,
“discovered”: “2026-07-11T07:18:53.887333+00:00”,
“domain”: “genecodesforensics.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:18:51”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/R2VuZSBDb2RlcyBGb3JlbnNpY3NAdGhlZ2VudGxlbWVu”,
“victim”: “Gene Codes Forensics”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T03:44:17+00:00”,
“claim_url”: “”,
“country”: “RU”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/vigilantes-asociados-al-servicio-de-banca-y-empresas-vasbe-sl\/458305259 VASBE Vigilantes Asociados Al Servicio De Banca Y Empresas Vasbe is a well-established Spanish private security and surveillance company with over 30 years of industry experience. Based primarily in the Salamanca region, they provide comprehensive protection solutions including physical guarding, 24\/7 central alarm monitoring, and advanced video surveillance. The company specializes in designing customized security plans to safeguard businesses, financial institutions, and valuable assets around the clock.”,
“discovered”: “2026-07-11T07:19:14.392790+00:00”,
“domain”: “vasbe.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-11T07:19:12”,
“users”: 22,
“users_url”: 12
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VkFTQkVAdGhlZ2VudGxlbWVu”,
“victim”: “VASBE”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T03:41:39+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/welders-supply–equipment-rentals\/355927450 WSE Rentals (Welders Supply & Equipment Rentals) is a specialized equipment rental company headquartered in Port Allen, Louisiana. They focus on providing a comprehensive range of high-quality, reliable welding tools and machinery from well-known industry brands for various industrial projects. The company serves contractors and businesses by offering tailored rental solutions and dedicated delivery services to support their operational needs”,
“discovered”: “2026-07-11T07:19:39.312347+00:00”,
“domain”: “wserentals.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:19:37”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/V2VsZGVycyBTdXBwbHkgRXF1aXBtZW50IFJlbnRhbHNAdGhlZ2VudGxlbWVu”,
“victim”: “Welders Supply Equipment Rentals”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T03:40:06+00:00”,
“claim_url”: “”,
“country”: “”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/pharma-wholesale\/353577758 Pharma Wholesale Corp. is a licensed pharmaceutical wholesaler and distributor headquartered in Florida, USA, with over 24 years of industry experience. The company specializes in the global distribution of prescription and OTC medications, vitamins, supplements, and health and beauty products. Operating as a mid-sized enterprise, they supply affordable healthcare solutions to pharmacies and medical facilities both domestically and internationally”,
“discovered”: “2026-07-11T07:19:59.502985+00:00”,
“domain”: “pharmawholesale.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:19:58”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UGhhcm1hIFdob2xlc2FsZUB0aGVnZW50bGVtZW4=”,
“victim”: “Pharma Wholesale”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-10T03:37:03+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/crossroads-medical-management-llc\/354034077 Crossroads Medical Management is a healthcare management company headquartered in Perry, Georgia, specializing in full-service financial, clinical, and operations management for the senior community. As a legacy organization with three generations of experience, they focus on providing quality-oriented care and a home-like environment across multiple affiliated skilled nursing facilities. Operating primarily in states like Georgia, the company manages several senior care centers, generating an estimated annual revenue of over $12 million while expanding to meet the evolving needs of elderly residents”,
“discovered”: “2026-07-11T07:20:20.812520+00:00”,
“domain”: “crossroadsmedicalmgmt.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:20:18”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/Q3Jvc3Nyb2FkcyBNZWRpY2FsIE1hbmFnZW1lbnRAdGhlZ2VudGxlbWVu”,
“victim”: “Crossroads Medical Management”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-10T03:32:48+00:00”,
“claim_url”: “”,
“country”: “DE”,
“data_size”: null,
“description”: “***.de zoominfo.com\/c\/inet\/429716454 INTERNET AG is a professional German IT service provider specializing in reliable, sustainable, and flexible hosting and server solutions. The company delivers customized IT infrastructures, managed services, and global network connectivity tailored to complex business needs. Alongside its partner INTERNIC GmbH, it offers comprehensive enterprise software and secure digital operations for corporate clients”,
“discovered”: “2026-07-11T07:20:41.761238+00:00”,
“domain”: “inet.de”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 2,
“update”: “2026-07-11T07:20:39”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SU5URVJORVQgQUdAdGhlZ2VudGxlbWVu”,
“victim”: “INTERNET AG”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-07-10T03:27:23+00:00”,
“claim_url”: “”,
“country”: “IE”,
“data_size”: null,
“description”: “***.com Open Options was a prominent Texas-based software company specializing in open-architecture access control solutions, best known for its flagship enterprise platform, DNA Fusion. The company focused on delivering scalable physical security and identity management software tailored to complex organizational needs. Following a strategic acquisition, the company’s technology and brand were integrated into Acre Security, where it continues to operate and evolve as DNA Fusion by acre security”,
“discovered”: “2026-07-11T07:21:02.433644+00:00”,
“domain”: “ooaccess.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:21:00”,
“users”: 7,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/T3BlbiBPcHRpb25zQHRoZWdlbnRsZW1lbg==”,
“victim”: “Open Options”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-10T03:24:27.052375+00:00”,
“claim_url”: “”,
“country”: “ES”,
“data_size”: null,
“description”: “[AI generated] N\/A”,
“discovered”: “2026-07-10T03:24:28.917422+00:00”,
“domain”: “new-tiles.com”,
“group”: “gunra”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-10T03:24:26”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TmV3IFRpbGVzIFMuTC5AZ3VucmE=”,
“victim”: “New Tiles S.L.”
},
{
“activity”: “Energy”,
“attackdate”: “2026-07-10T03:23:23+00:00”,
“claim_url”: “”,
“country”: “CZ”,
“data_size”: null,
“description”: “***.cz zoominfo.com\/c\/energon\/430910504 ENERGON HOLDING is a prominent Czech group uniting various companies specialized in energy services, photovoltaics, and modern sustainable technologies. With over 25 years of industry experience, the group drives innovations that enhance the energy independence and competitiveness of the Czech Republic. They also actively invest in startups focused on renewable energy optimization, diagnostics, and the security of power infrastructure”,
“discovered”: “2026-07-11T07:21:24.821830+00:00”,
“domain”: “energon.cz”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:21:23”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RW5lcmdvbkB0aGVnZW50bGVtZW4=”,
“victim”: “Energon”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-07-10T03:22:21+00:00”,
“claim_url”: “”,
“country”: “IT”,
“data_size”: null,
“description”: “***.it zoominfo.com\/c\/vicenzi-spa\/1101977046 Vicenzi Group, founded in 1905 by Matilde Vicenzi, is a historic Italian confectionery company renowned for producing high-quality biscuits and traditional pastries. Based in Verona, the family-owned business has grown into a global brand dedicated to becoming the world leader in premium Italian sweet treats. The company employs hundreds of people and successfully combines authentic recipes with modern sustainable practices to deliver its products to international markets”,
“discovered”: “2026-07-11T07:21:45.049540+00:00”,
“domain”: “vicenzi.it”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:21:43”,
“users”: 17,
“users_url”: 6
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VmljZW56aSBHcm91cEB0aGVnZW50bGVtZW4=”,
“victim”: “Vicenzi Group”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-10T03:20:17+00:00”,
“claim_url”: “”,
“country”: “MX”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/triquesta-pte-ltd\/346670373 Triquesta is a Singapore-based fintech company specializing in collateral, compliance, and risk management software for structured commodity finance.Founded by seasoned banking professionals, the firm provides cutting-edge technology that helps global banks and direct lenders reliably track assets and mitigate risks.With a strong international presence across Europe and Australia, their solutions empower financial institutions to navigate complex commodity markets efficiently”,
“discovered”: “2026-07-11T07:22:06.470154+00:00”,
“domain”: “triquesta.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 1,
“employees_url”: 1,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-11T07:22:03”,
“users”: 0,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VHJpcXVlc3RhQHRoZWdlbnRsZW1lbg==”,
“victim”: “Triquesta”
},
{
“activity”: “Construction”,
“attackdate”: “2026-07-10T03:17:35+00:00”,
“claim_url”: “”,
“country”: “PT”,
“data_size”: null,
“description”: “***.com Aveiro Constructors Limited is a Canadian general contractor established in 1976 and headquartered in Southwestern Ontario. The company specializes in the Industrial, Commercial, and Institutional (ICI) sectors, delivering design-build, new construction, and renovation projects both locally and internationally. Originally starting with pre-engineered steel buildings, they have grown over the decades into a comprehensive construction firm offering specialized services like HVAC and project management”,
“discovered”: “2026-07-11T07:22:26.835965+00:00”,
“domain”: “aveiroconstructors.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:22:25”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QXZlaXJvIENvbnN0cnVjdG9ycyBMaW1pdGVkQHRoZWdlbnRsZW1lbg==”,
“victim”: “Aveiro Constructors Limited”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2026-07-10T03:15:45+00:00”,
“claim_url”: “”,
“country”: “ES”,
“data_size”: null,
“description”: “***.com zoominfo.com\/c\/martin-cava-sa\/366183664 Martin Cava S.A. is a prominent Argentine supplier of equipment, specialty papers, and consumables for the graphic and printing industry, boasting nearly 90 years of market experience.Based in Buenos Aires, they distribute a wide array of products including HP plotters, inks, holographic vinyls, and offset printing materials.The company is highly regarded for offering innovative solutions that allow businesses to personalize garments, promotional items, and various surfaces”,
“discovered”: “2026-07-11T07:22:47.393408+00:00”,
“domain”: “martincava.com”,
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-11T07:22:45”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TWFydGluIENhdmFAdGhlZ2VudGxlbWVu”,
“victim”: “Martin Cava”
}
]





