BRIEFRansomwarelowP34
Qilin ransomware publishes Thorndale Foundation (Australia)
Thorndale Foundation
Detected16 September 2026 · 16:12 UTC
The Qilin ransomware group has listed Thorndale Foundation in Australia, sector Other, as a victim. Details are scarce, but a new Qilin posting signals active operations and probable data theft or encryption. Regional relevance is minimal; it is noted mainly for victimology and group-tracking purposes.
CategoryRansomware
Severitylow
Priority score34
Detected16 September 2026 · 16:12 UTC
Ransomware● 36
El ransomware Qilin publica al fabricante francés Thema FoundriesThe Qilin ransomware group has published Thema Foundries, a French manufacturing firm, as a victim. Manufacturing is a frequent target for operational disruption and supply-chain impact, and a listing usually implies stolen data or encryption. Latin American relevance is limited, but it confirms ongoing Qilin activity worth mapping.Ransomware● 62
RansomHouse publica a la Fuerza de Defensa de Namibia como víctimaThe RansomHouse group has listed the Namibian Defence Force, the national military of Namibia, as a ransomware victim. A defence/military target raises the risk of exposure of operational, personnel and logistics data. Although outside Latin America, a government-defence victim is a high-signal alert for tracking ransomware activity.Ransomware● 43
Ransomware Akira publica a la contratista británica MandersThe Akira ransomware group listed Manders Companies, a GB manufacturing/contracting firm, and claims it will upload ~70GB of corporate data. The leak reportedly includes employee SSNs, passports, driver's licenses, financials, client contracts and NDAs. It is a fresh victim publication with sensitive PII, useful for tracking Akira's targeting and data-monetization patterns.Ransomware● 42
Ransomware Panzer publica a la firma Nielsen DesignThe ransomware group 'panzer' has listed Nielsen Design as a newly published victim on its leak site. The entry gives no country or sector detail, so direct regional impact is unclear and the firm appears to be a small European design/architecture company. It is worth monitoring if the group shifts toward Latin American targets, but remains a lower priority for a region-focused operator.Ransomware● 72
Proveedor de salud mexicano La Concepción, víctima de ransomware safepayThe 'safepay' ransomware group added laconcepcion.com.mx to its victim list. The organization identifies itself as one of the principal private healthcare providers in the Coahuila region of Mexico. A ransomware hit on a healthcare provider risks patient safety and sensitive medical data.Ransomware● 90
El portal gubernamental de Perú gob.pe, víctima de ransomware safepayThe 'safepay' ransomware group listed gob.pe, Peru's central government services portal, as a victim. It is the country's primary online contact point between public institutions and citizens, i.e. critical national infrastructure. A compromise could disrupt public services and expose citizen data.