BRIEFRansomwarehighP58
1 TB technical data leak from i-one (South Korea)
i-one
Detected30 August 2026 · 10:16 UTC
The South Korean auto parts maker i-one was listed by the Black X ransomware group, which claims to have exfiltrated 1 TB of technical data, including drawings and supply chain information. The exposure of industrial intellectual property is critical for the company and its customers. Organizations should verify if this campaign affects their supply chain.
CategoryRansomware
Severityhigh
Priority score58
Detected30 August 2026 · 10:16 UTC
Ransomware● 62
Ransomware Wallstreet publica datos del municipio de Andover, MassachusettsThe Wallstreet ransomware group listed the Town of Andover, Massachusetts, a U.S. municipal government, as a victim. Municipal data, including citizen records and infrastructure details, may be exposed. Although outside Latin America, this fresh ransomware victim is relevant for tracking current ransomware activity.Ransomware● 55
Ransomware Falcon publica a DistributionNOW (distribuidor de energía de EE. UU.)Falcon ransomware claims 344 GB exfiltrated from energy distributor DistributionNOW, including financial records, SCADA gateway backups, and PLC logic. Loss of OT-related data indicates potential impact on industrial operations. This case is relevant to Latin American energy and critical infrastructure sectors as a warning of similar attack patterns.Ransomware● 60
Ransomware Falcon publica a Globus Medical (fabricante de dispositivos médicos de EE. UU.)Falcon ransomware claims to have exfiltrated 2.96 TB from medical device maker Globus Medical, including customer records, FDA submissions, and product complaint logs. The incident exposes sensitive healthcare and regulatory data, raising supply-chain concerns. Even though the victim is in the US, this type of attack highlights TTPs relevant for Latin American healthcare and critical infrastructure defenders.Ransomware● 70
Ransomware Qilin publica a la constructora qatarí Black Cat EngineeringQilin ransomware has added Black Cat Engineering Construction Wll, a Qatari manufacturing/construction company, to its leak site. The publication may expose project documents and corporate data. This fresh ransomware incident highlights the group's ongoing activity in the Gulf region.Ransomware● 70
Ransomware Qilin publica a la consultora británica Absolute Consultancy ServicesQilin ransomware has published Absolute Consultancy Services, a UK-based professional services firm. The leak may include client data and corporate documents. This is a fresh victim post, indicating active ransomware operations targeting the professional services sector.Ransomware● 70
Ransomware Qilin publica a la farmacéutica CrystalpharmatechThe Qilin ransomware group has added Crystalpharmatech to its leak site. The company is in the healthcare sector, and the publication likely includes sensitive corporate and possibly patient-related data. This is a fresh ransomware incident that requires immediate attention.