BRIEFRansomwarehighP60
Akira ransomware publishes manufacturer Anderson Industries
Anderson Industries
Detected18 September 2026 · 14:12 UTC
The Akira ransomware group listed Anderson Industries, an engineering and manufacturing firm producing agricultural equipment and foundry services, and threatens to publish 9GB of corporate data including employee and client personal information, project specs, orders, financials and NDAs. The victim's country is not confirmed, but manufacturing supply chains are high-value targets and the mix of personal and financial records raises fraud and competitive-risk concerns for peers.
CategoryRansomware
Severityhigh
Priority score60
Detected18 September 2026 · 14:12 UTC
Ransomware● 55
Ransomware Incransom publica a la editorial estadounidense Kendall HuntIncransom ransomware has published Kendall Hunt Publishing, a US K-12 educational publisher, as a victim on its leak site. Educational publishers hold student, teacher and customer data plus proprietary curricula, making the breach sensitive. The victim is outside Latin America, so priority for AR-LATAM defenders is moderate.Ransomware● 40
Ransomware Incransom publica a la operadora neerlandesa Roan CampingThe Incransom ransomware group has listed Roan Luxury Camping Holidays, a Dutch tour operator, on its leak site. A breach could expose booking and customer payment data during the active European travel season. The victim is a small business outside Latin America, so regional impact is low.Ransomware● 52
Ransomware Spirals publica a la empresa ITAD ANYTHINGITSpirals ransomware listed ANYTHINGIT, an IT asset disposition and e-waste firm serving federal agencies, defense contractors and enterprises under strict chain-of-custody requirements. The victim's role in handling sensitive federal hardware and data creates real supply-chain risk. Defenders should assess downstream exposure to any agency data passing through this provider.Ransomware● 64
Ransomware Endzone publica datos de la gubernamental AccelaEndzone published over 50 GB allegedly from Accela, a cloud platform used by US state and local governments, including 2 million lines of PII and 6 million citizen-service requests. Compromise of a government-services vendor can cascade into many public agencies that depend on it. Public-sector defenders should verify exposure and monitor Accela downstream dependencies.Ransomware● 74
Ransomware Endzone publica datos robados de AT&TThe Endzone ransomware group claims to have breached AT&T through a CX contractor, holding VPN and internal VDI access for a prolonged period without detection and exporting certificates. AT&T is Tier-1 telecom infrastructure, so any confirmed intrusion risks customer and operational data at massive scale. Defenders should treat this as a live third-party/VPN access vector and review remote access controls.Ransomware● 42
Ransomware KillSec publica a la manufacturera Giti Corp (Singapur)The KillSec ransomware group listed Giti Corp, a manufacturing company in Singapore, on its leak site, threatening to publish stolen data. This is a confirmed fresh victim, but Singapore is outside the Argentina/LATAM focus, so direct impact for regional defenders is limited. It is still worth noting as evidence KillSec remains active and is targeting industrial/manufacturing firms that may have Latin American operations or supply-chain links.