BRIEFRansomwarelowP35
LockBit5 ransomware lists Finnish accounting firm HTT Oy
HTT Oy
Detected14 September 2026 · 15:12 UTC
LockBit5 has listed Finnish accounting firm HTT Oy as a ransomware victim on its leak site. Accounting firms hold sensitive financial records of many client companies, making them attractive extortion targets. A breach here can cascade into data-exposure and fraud risks across the firm's entire client base.
CategoryRansomware
Severitylow
Priority score35
Detected14 September 2026 · 15:12 UTC
Ransomware● 40
LockBit5 publica a la empresa taiwanesa tpi.twLockBit5 has listed the Taiwanese technology company tpi.tw as a ransomware victim on its leak site. The intrusion targets a tech firm, and stolen data may be published if no ransom is paid. Even a smaller victim can expose supply-chain partners and customers to follow-on phishing and fraud.Ransomware● 55
LockBit5 publica al municipio italiano Robecco sul NaviglioLockBit5 ransomware has published Comune di Robecco sul Naviglio, a municipality in the Metropolitan City of Milan, under the Government & Defense sector. Local-government systems typically hold citizen records, tax and registry data, and municipal service platforms. A confirmed public-sector victim raises the risk of sensitive data exposure and service disruption for residents.Ransomware● 80
Ransomware Qilin publica a la argentina Vitar GroupThe Qilin ransomware group has listed Vitar Group, an Argentine organization, on its leak site. The sector is listed as 'Other', but a fresh regional victim signals an active intrusion with data-theft and extortion risk. Defenders in Argentina should watch for related TTPs and possible publication of stolen data.Ransomware● 42
Ransomware 'booba project' publica a la naviera Atlas Ocean VoyagesThe 'booba project' ransomware group published Atlas Ocean Voyages, a US travel and hospitality company, claiming 37 GB of stolen data. A fresh victim listing points to an active intrusion with data theft and likely extortion pressure. It matters mainly as ransomware-ecosystem context, as it falls outside the Argentina/LATAM scope.Ransomware● 50
Ransomware Qilin publica a la francesa CARIDRO Val de LoireThe Qilin ransomware group has listed CARIDRO Val de Loire, a French agriculture and food-production firm, as a new victim. Ransomware in food/agri supply chains can disrupt distribution and is often accompanied by data theft. It is a fresh victim but in France, so outside the AR/LATAM scope.Ransomware● 44
El ransomware safepay publica a la tecnológica estadounidense CompunnelThe safepay ransomware group has listed US technology-services firm Compunnel as a victim, indicating a breach with data-theft and extortion claims. Compunnel provides IT consulting and workforce services, so its clients may face downstream exposure of shared data. Watch for leaked client records and credential reuse.