BRIEFRansomwarecriticalP90
Peru government portal gob.pe listed by ransomware group safepay
gob.pe (Gobierno del Perú)
Detected15 September 2026 · 20:12 UTC
The 'safepay' ransomware group listed gob.pe, Peru's central government services portal, as a victim. It is the country's primary online contact point between public institutions and citizens, i.e. critical national infrastructure. A compromise could disrupt public services and expose citizen data.
CategoryRansomware
Severitycritical
Priority score90
Detected15 September 2026 · 20:12 UTC
Ransomware● 72
Proveedor de salud mexicano La Concepción, víctima de ransomware safepayThe 'safepay' ransomware group added laconcepcion.com.mx to its victim list. The organization identifies itself as one of the principal private healthcare providers in the Coahuila region of Mexico. A ransomware hit on a healthcare provider risks patient safety and sensitive medical data.Ransomware● 42
Ransomware Dark Project publica a Cumar Marble & GraniteThe Dark Project ransomware group has published Cumar Marble & Granite, a stone fabricator, as a victim. Though a mid-size manufacturer outside the region, fresh victim postings indicate an active intrusion and data-theft campaign. Low regional priority but worth tracking for sector trends.Ransomware● 68
Ransomware Interlock publica a la ciudad de Fort Smith, ArkansasThe Interlock ransomware group has listed the City of Fort Smith, Arkansas as a victim, claiming a major leak of confidential data from a US municipal government. Municipal breaches disrupt public services and expose resident data. It is a fresh, high-impact government victim release.Ransomware● 42
Ransomware Qilin publica a Bravo Group (Singapur)Qilin ransomware has listed 'Bravo Group' (Singapore) as a victim, indicating a fresh intrusion with data theft and extortion. Newly published victims are time-sensitive because the operation may still be ongoing. Defenders should verify the entity and monitor for related data exposure.Ransomware● 46
Ransomware Qilin publica a la víctima IncrysThe Qilin ransomware group has published 'Incrys' as a new victim on its leak site. Publication signals an active intrusion with stolen data, threatening operational disruption and extortion. Region and sector are unclear, so the entity should be verified to assess exposure.Ransomware● 55
Ransomware thegentlemen publica a la heladería peruana GelartiThe thegentlemen ransomware group listed Gelarti, Peru's largest gourmet ice-cream chain with 39 outlets, as a victim. Retail and franchise operators hold customer loyalty, payment and supplier data. Encryption of POS or back-office systems could interrupt sales across Peru and expose customer and franchisee information.