BRIEFRansomwarehighP55
Akira ransomware publishes Slovenian group HIT d.d.
HIT d.d.
Detected23 September 2026 · 13:29 UTC
Akira claims 367 GB of corporate data from HIT d.d., a major Slovenian hotel, casino and entertainment group operating in Slovenia and Bosnia. A breach of a hospitality operator exposes guest PII, booking and payment data. Casinos are high-value targets and the leak can feed identity theft and card fraud.
CategoryRansomware
Severityhigh
Priority score55
Detected23 September 2026 · 13:29 UTC
Ransomware● 45
IncRansom publica a la firma legal Lemon LawIncRansom published 16.8 GB (about 42k files) allegedly stolen from Lemon Law, a US litigation firm in West Virginia. The dump reportedly includes client personal data, litigation materials and financial records. Law firms hold privileged and sensitive client data, creating strong extortion and secondary-fraud risk.Ransomware● 48
Akira publica a la firma legal Apex Litigation SupportAkira lists Apex Litigation Support, a US provider of litigation services to law firms, with 77 GB of data to be released. The claim includes employee and client personal information such as passports, licenses, addresses and emails. This enables identity theft and targeted attacks against attorneys and their clients.Ransomware● 50
Ransomware Qilin publica a la tecnológica InkriptThe Qilin ransomware group just listed Inkript, a technology-sector victim, on its leak site; the country field is empty so the region is unconfirmed. Fresh ransomware postings give defenders a short window to check for exposure, hunt the listed indicators and validate backups. Track it because Qilin frequently escalates to full data leaks when victims do not pay.Ransomware● 72
Ransomware arcusmedia publica a la agroindustrial peruana Agrofruto SACThe arcusmedia group lists Peruvian agroindustrial firm Agrofruto SAC as a ransomware victim with a leak deadline of 2026-09-30, indicating stolen corporate data and active extortion. It is one of the few Latin American victims in this batch, making it a live regional incident worth monitoring for broader targeting of the Peruvian agribusiness sector.Ransomware● 40
Ransomware booba project publica a la clínica Smart Eye CareThe 'booba project' group published Smart Eye Care, a healthcare provider, as a victim, claiming 7 GB of stolen data. Healthcare breaches expose sensitive patient records and can disrupt care, making this fresh listing relevant despite the smaller scale and unknown country.Ransomware● 42
Ransomware booba project publica al consorcio italiano COSEFThe 'booba project' ransomware group listed COSEF, an Italian economic development consortium, claiming 200 GB of stolen data. That large volume of corporate and partner data is significant for defenders profiling the group's targeting and exfiltration patterns across sectors.