BRIEFRansomwarelowP33
Anubis ransomware publishes German firm Gaedke & Partner
Gaedke & Partner Steuerberatung
Detected22 September 2026 · 22:43 UTC
The ransomware group Anubis published German accounting firm Gaedke & Partner Steuerberatung on its leak site, claiming a breach of client information. Tax and accounting firms hold sensitive financial and personal records, making them high-value targets and a supply-chain risk for their clients. The victim is small and outside Latin America, but it is a freshly published extortion claim.
CategoryRansomware
Severitylow
Priority score33
Detected22 September 2026 · 22:43 UTC
Ransomware● 55
Silent Ransom publica a la firma legal estadounidense Clark HillSilent Ransom Group has listed Clark Hill, a large US law firm, as a ransomware victim. Law firms hold privileged, confidential client data, so a breach can disrupt litigation and expose sensitive information. Outside the region, but a notable active victim publication to track.Ransomware● 76
ShinyHunters amenaza con filtrar datos de Fresenius Medical CareShinyHunters has listed Fresenius Medical Care, a major German healthcare and dialysis provider, threatening to publish sensitive data unless contacted by 25 Sep 2026. Ransomware against healthcare can disrupt clinical operations and exposes protected health information. Outside Latin America, but a fresh, high-impact victim worth tracking.Ransomware● 88
Ransomware Titan publica al prestador de salud argentino HospifarThe ransomware group Titan has listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on its leak site. Healthcare is critical infrastructure and exposure of patient records carries regulatory and safety consequences. Argentine health entities should treat this as an active, time-sensitive incident.Ransomware● 55
Ransomware Kairos publica a Krapf Group, operador de transporte escolar de EE. UU.The Kairos ransomware group has published Krapf Group, a US transportation firm running 2,500+ school buses with 3,500 employees. The stolen data reportedly includes personal information of thousands of bus drivers, raising safety and privacy concerns for a large workforce. Freshly listed victims signal an active campaign worth tracking for TTPs and regional spillover.Ransomware● 42
Ransomware Qilin publica al local estadounidense The Fifty/50Qilin ransomware lists The Fifty/50, a US-based victim, on its leak site. No data volume or record count was disclosed yet, so impact is unclear. A fresh extortion listing signals an active incident that defenders may want to track for naming and TTPs.Ransomware● 50
Ransomware Akira reclama a la textilera TDMIAkira claims textile firm TDMI, threatening to release 33GB including employee SSNs, driver's licenses, passports, credit cards and client data. The mix of PII and financial data raises fraud and account-takeover risk. Track the leak for reuse of credentials and identity documents.