BRIEFRansomwarelowP38
Nightspire lists a US school as a ransomware victim
Detected21 September 2026 · 19:37 UTC
Nightspire ransomware listed a US school as a victim, though no data samples were published at the time of collection. Education victims hold student and staff PII, making them attractive for downstream identity fraud if the leak is confirmed. It signals an active ransomware campaign and a sector pattern worth monitoring despite the limited detail.
CategoryRansomware
Severitylow
Priority score38
Detected21 September 2026 · 19:37 UTC
Ransomware● 44
Ransomware Nightspire publica a la consultora italiana 360 ConsulenzaNightspire ransomware listed 360 Consulenza S.r.l., an Italian professional-services firm, claiming theft of client documents, project files and software source code. Publishing source code and client data enables follow-on fraud, IP theft and phishing against the firm's customers. It sits outside Latin America but shows an active group and a pattern regional defenders should track.Ransomware● 45
Ransomware Global Secret Group publica al fabricante Allied Supply Co.The ransomware group 'Global Secret Group' published Allied Supply Co., a US industrial machinery and wholesale firm, claiming about 25.3 GB of stolen files. The leak exposes internal business data and pressures the victim to pay. It is outside Latin America, but the TTPs and victim profile remain useful context.Ransomware● 50
Ransomware Global Secret Group publica a la emisora estadounidense KJLAThe ransomware group 'Global Secret Group' published KJLA, a US broadcasting company, claiming roughly 783 GB across more than 500,000 files. Such a large haul can expose corporate, employee and programme data and pressures the victim. It is outside Latin America, but the group's activity is worth tracking for future regional targeting.Ransomware● 60
Ransomware moneymessage publica a la energética U.S. Electrical ServicesThe 'moneymessage' ransomware group has listed U.S. Electrical Services and Wiedenbach Brown, an electrical distribution firm in the energy and utilities sector, as a victim. Publication indicates a live or confirmed intrusion against a critical-sector supplier with exposure of operational and customer data. Energy-sector defenders should watch for related leaks and lateral activity.Ransomware● 48
Ransomware Metaencryptor publica a Visual IntelligenceThe metaencryptor ransomware group has freshly published Visual Intelligence, Inc., a US managed-services and telecom-data technology firm, as a victim. A new listing signals an active intrusion with likely data theft and extortion. Though outside Latin America, its telecom-data services may carry supply-chain relevance for regional operators.Ransomware● 42
Ransomware Qilin publica a la japonesa IKEGAMI TSUSHINKIThe Qilin ransomware group published IKEGAMI TSUSHINKI, a Japanese manufacturing company, on its victim leak site, indicating a confirmed recent intrusion and data-theft extortion. Such manufacturing victims face operational disruption and exposure of proprietary and employee data. Although outside Latin America, it is a fresh ransomware victim worth tracking for sector TTPs and supply-chain relevance.