BRIEFRansomwarehighP45
Akira ransomware lists Wallatec, threatens 15GB data dump
Wallatec
Detected24 September 2026 · 14:51 UTC
Akira ransomware listed Wallatec, a carbonation-systems manufacturer, and announced an upcoming 15GB dump including passports, projects and client/financial data. The detailed threat suggests employee PII and business records are at risk. Defenders should watch for leaked identity documents that fuel fraud and account takeover.
CategoryRansomware
Severityhigh
Priority score45
Detected24 September 2026 · 14:51 UTC
Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.Ransomware● 45
Ransomware Everest publica a la japonesa UNIRITAThe Everest ransomware group listed UNIRITA, a Tokyo-listed IT and infrastructure-software vendor, as a victim on its leak site. Named corporate victims such as mid-size IT vendors matter because they can be supply-chain footholds into their customers. It is a real but lower-priority alert for a LATAM-focused feed.Ransomware● 69
Ransomware BLACKNET-00 contra el municipio de Tel Aviv-YafoThe BLACKNET-00 group claims to have breached the Tel Aviv-Yafo municipality, a government target, and is publishing it as a ransomware victim. A municipal compromise exposes citizen services, internal systems and sensitive records, and the same group is listing multiple victims, signalling an active campaign. Even though it is outside LATAM, government-targeting ransomware from an active crew is worth tracking for pattern awareness.Ransomware● 70
Blacknet-00 publica el robo de datos de SriLankan AirlinesThe Blacknet-00 group claims an official breach of SriLankan Airlines, the national flag carrier, typically meaning exfiltrated passenger and operational data. State-linked airlines hold passport, booking and employee data, making this a high-value leak with identity-theft and DDoS follow-on risk. Airlines and their partners should monitor for leaked customer credentials and extortion pressure.Ransomware● 48
Ransomware LockBit publica a la aseguradora de salud Taspen LifeThe LockBit5 group listed Taspen Life, a health and group insurance provider (listed under Kazakhstan), as a ransomware victim. Healthcare breaches disrupt patient and policyholder services and expose sensitive health and personal data. It lies outside Latin America but is a fresh victim relevant for sector and insurer monitoring.Ransomware● 68
Ransomware Qilin publica a la fabricante española Iberia CompositechQilin ransomware listed Iberia Compositech Manufacturing, a Spanish manufacturer, as a fresh victim on its leak site with no sample data published yet. An active extortion usually gives defenders a short window to contain, assess backups and check whether Ibero-American subsidiaries or shared credentials are exposed. Manufacturing is a frequent supply-chain entry point, so this warrants monitoring.