BRIEFRansomwarehighP55
BLACKNET-00 publishes a new ransomware victim
Detected6 October 2026 · 14:07 UTC
Threat actor Blacknet00 posted a brand-new ransomware victim on DarkForums just minutes ago, signalling an active double-extortion operation. The victim name is not disclosed in this post, but the recency means data and extortion details will likely surface shortly. Tracking it matters to identify any regional exposure once the target is named.
CategoryRansomware
Severityhigh
Priority score55
Detected6 October 2026 · 14:07 UTC
Ransomware● 38
Ransomware Umbra publica al fabricante estadounidense Four Hands LLCThe Umbra group listed Four Hands LLC, a US wholesaler of home furnishings, as a ransomware victim. As a newly named victim in a live extortion campaign, the company and its retail partners face potential disruption and downstream supply-chain phishing. It is a US target with no regional or critical-infrastructure link, so it ranks low for AR-LATAM operators.Ransomware● 41
Ransomware Akira publica a la empresa estadounidense HygradeAkira added Hygrade, a US safety and industrial products manufacturer, to its leak site, claiming theft of employee names, addresses and phone numbers plus project specifications and NDAs. The data supports targeted social engineering and business-email-compromise against the firm and its supply chain. It is a fresh US victim only marginally relevant to AR-LATAM infrastructure defenders.Ransomware● 47
Ransomware Akira publica a la firma contable Michael K. Shelby (EE. UU.)Akira listed the Annapolis CPA firm Michael K. Shelby, threatening to leak 18 GB of corporate data that includes client and employee SSNs and payment information. Stolen tax and financial records are highly sensitive PII that feed identity fraud and follow-on phishing against clients. The victim is US-only, lowering priority for AR-LATAM defenders but illustrating active accounting-sector targeting.Ransomware● 44
Ransomware Qilin publica a la naviera finlandesa Delta MarineQilin has newly published Delta Marine, a Finnish transportation/marine company, as a ransomware victim. Transport and logistics firms are high-value targets due to operational dependence on IT and the potential for port or fleet disruption. Nordic transport defenders should monitor for Qilin affiliates.Ransomware● 45
Ransomware Qilin publica a la manufacturera irlandesa Corby Rock MillQilin has freshly listed Corby Rock Mill, an Irish manufacturing company, among its ransomware victims. Manufacturing victims risk operational shutdown, IP theft and supply-chain disruption. EU/IE critical-production defenders should track Qilin activity and affiliate TTPs.Ransomware● 52
Ransomware Qilin publica a la financiera J&D FinancialThe Qilin ransomware group has freshly listed J&D Financial, a financial-services victim, on its leak site. Financial firms face regulatory pressure and elevated fraud risk when customer and transaction data is exfiltrated. Defenders in finance should review Qilin TTPs and third-party exposure.