BRIEFRansomwarecriticalP84
Nicaraguan company database leaked alongside ransomware
Detected5 October 2026 · 06:55 UTC
A threat actor claims to have dumped the full database of an unnamed Nicaraguan company and bundles ransomware access or samples with it. A fresh regional breach involving operational data plus ransomware significantly raises the risk of extortion and lateral movement against Central American entities.
CategoryRansomware
Severitycritical
Priority score84
Detected5 October 2026 · 06:55 UTC
Ransomware● 73
Wallstreet publica al contratista del estadio del Mundial 2034 en JeddahThe Wallstreet ransomware group published the Sama Construction / China Railway Construction consortium, main contractor for the Jeddah Central Stadium for the FIFA World Cup 2034. It claims 17 TB and 1.5M files exfiltrated, including main contracts, interim payment certificates and a suspension claim against PIF-owned Jeddah Central Development Company. This is a large fresh leak of sensitive financial and contractual data on a high-profile critical project.Ransomware● 72
Ransomware Akira publica al Colegio de Arquitectos de León (México)The Akira ransomware group listed the College of Architects of León on its leak site, claiming roughly 77GB of corporate data including passports, financial records, and student and client information. This is a fresh LATAM victim whose exposure of identity documents and financial data creates serious identity-theft and fraud risk. Defenders in Mexico's professional-services sector should treat Akira as an active threat targeting their organizations.Ransomware● 43
Qilin publica a la empresa británica Sports Events365Qilin ransomware listed Sports Events365, a UK hospitality-sector company, as a fresh victim. Hospitality is a frequent ransomware target and a public victim page enables downstream extortion and phishing. It is worth noting for Qilin's ongoing campaign activity, though it has no direct LATAM link.Ransomware● 60
Rhysida publica al fabricante sueco Electro Heat SwedenRhysida published Electro Heat Sweden AB, an industrial furnace maker, claiming 2.55 TB (1.72M files) including SolidWorks CAD designs, PDM vault backups, payroll and accounting databases for four legal entities. This hits an energy/utilities-sector company with highly sensitive IP. Though outside LATAM, the scale and sector make it a notable ransomware event.Ransomware● 71
Ransomware Panzer publica a la brasileña Paes SoluçõesThe Panzer ransomware group listed Paes Soluções, a Brazilian IT firm in Campo Mourão (Paraná) offering business software, hosting, cloud backup and VPS. A breach of such a provider risks many downstream business customers and managed services. As a fresh Brazilian victim it is directly relevant to LATAM incident response and monitoring.Ransomware● 52
Ransomware Settra publica a la tecnológica TranslarityThe ransomware group Settra listed Translarity, a US firm that tests semiconductors for Boeing and the US military, on its leak site. The publication implies theft of sensitive corporate data with defense supply-chain implications. It is outside LATAM but worth tracking for defense-sector awareness.