BRIEFRansomwarelowP38
Qilin ransomware publishes victim Invincible GG
Invincible GG
Detected17 September 2026 · 20:12 UTC
The Qilin ransomware group listed a new victim, 'Invincible GG', sector Technology, on its leak site. Fresh victim publications give defenders a short window to detect related intrusion activity. Although the country is unlisted, the listing should be monitored for any LATAM link or supply-chain exposure.
CategoryRansomware
Severitylow
Priority score38
Detected17 September 2026 · 20:12 UTC
Ransomware● 42
Ransomware Chaos publica a Express Employment ProfessionalsThe Chaos group announced the public release phase for expresspros.com after failed negotiations, exposing a large US staffing and professional-services firm. Employment agencies hold extensive personal, payroll and client data, making the leak a strong phishing and fraud vector. It matters mainly as a fresh leak site entry outside the LATAM region.Ransomware● 48
Ransomware Qilin publica al Gran Hotel Inglés de EspañaQilin added the Gran Hotel Inglés, a hospitality business in Spain, to its leak site, signaling a fresh intrusion in a Spanish-speaking country. Hospitality breaches typically expose guest records, payment data and booking systems, and the sector is a frequent ransomware target. It is relevant for regional awareness even at a single-property scale.Ransomware● 52
Ransomware BrainCipher publica a la firma de infraestructura AECOMBrainCipher listed AECOM, a global engineering and infrastructure giant that designs and manages transport, water, energy and government facilities in over 150 countries. A breach at a firm of this scale can expose sensitive project, client and government-contract data with cross-border impact. Defenders should watch for downstream exposure affecting public-sector infrastructure programs.Ransomware● 76
Ransomware Qilin publica a la empresa argentina TechwiseThe Qilin ransomware group listed Techwise, an Argentine technology company, as a fresh victim, indicating an active intrusion affecting the LATAM region. Such listings usually coincide with stolen data and extortion pressure, so defenders in Argentina should treat it as a live regional incident. Verify whether Techwise supplies clients with infrastructure or services that could widen the exposure.Ransomware● 76
Ransomware settra publica a la tecnológica mexicana Sánchez y MartínThe settra group published Sánchez y Martín, S.A. de C.V. (sym.com.mx), a Mexican technology company, exposing sensitive corporate documentation. As a Mexican technology provider, the leak could affect client data and internal systems. This is a recent ransomware disclosure in the region worth monitoring.Ransomware● 74
Ransomware settra publica a la hotelera brasileña First Call HospitalityThe settra ransomware group published First Call Hospitality, a Brazilian hotel management firm (fchhotels.com), leaking internal documents. The company operates hotels in Brazil and the exposed files may include guest, financial and operational data. A fresh regional ransomware victim warrants tracking for possible impact on partners and clients.