BRIEFRansomwarehighP72
Akira ransomware publishes the College of Architects of León (Mexico)
Colegio de Arquitectos de León (COAL)
Detected3 October 2026 · 07:02 UTC
The Akira ransomware group listed the College of Architects of León on its leak site, claiming roughly 77GB of corporate data including passports, financial records, and student and client information. This is a fresh LATAM victim whose exposure of identity documents and financial data creates serious identity-theft and fraud risk. Defenders in Mexico's professional-services sector should treat Akira as an active threat targeting their organizations.
CategoryRansomware
Severityhigh
Priority score72
Detected3 October 2026 · 07:02 UTC
Ransomware● 43
Qilin publica a la empresa británica Sports Events365Qilin ransomware listed Sports Events365, a UK hospitality-sector company, as a fresh victim. Hospitality is a frequent ransomware target and a public victim page enables downstream extortion and phishing. It is worth noting for Qilin's ongoing campaign activity, though it has no direct LATAM link.Ransomware● 60
Rhysida publica al fabricante sueco Electro Heat SwedenRhysida published Electro Heat Sweden AB, an industrial furnace maker, claiming 2.55 TB (1.72M files) including SolidWorks CAD designs, PDM vault backups, payroll and accounting databases for four legal entities. This hits an energy/utilities-sector company with highly sensitive IP. Though outside LATAM, the scale and sector make it a notable ransomware event.Ransomware● 71
Ransomware Panzer publica a la brasileña Paes SoluçõesThe Panzer ransomware group listed Paes Soluções, a Brazilian IT firm in Campo Mourão (Paraná) offering business software, hosting, cloud backup and VPS. A breach of such a provider risks many downstream business customers and managed services. As a fresh Brazilian victim it is directly relevant to LATAM incident response and monitoring.Ransomware● 52
Ransomware Settra publica a la tecnológica TranslarityThe ransomware group Settra listed Translarity, a US firm that tests semiconductors for Boeing and the US military, on its leak site. The publication implies theft of sensitive corporate data with defense supply-chain implications. It is outside LATAM but worth tracking for defense-sector awareness.Ransomware● 48
Ransomware Chaos publica a la clínica dental Park DentalThe chaos ransomware group published Park Dental, a UK dental clinic, threatening to release stolen data if management does not respond within 24 hours. Healthcare providers hold sensitive patient records that make them high-value extortion targets. This is a live, time-sensitive extortion case worth monitoring for data release.Ransomware● 48
Ransomware Incransom publica al centro de adicciones RimrockThe incransom ransomware group has listed Rimrock Foundation, a large US addiction-treatment provider, on its leak site. Healthcare victims face operational disruption and exposure of highly sensitive patient records. It signals active targeting of the healthcare sector, so defenders should watch for related extortion activity.