BRIEFRansomwarehighP50
Ransomware group 'blacklocks' publishes architecture firm ARCA Unlimited
ARCA Unlimited Architects
Detected26 September 2026 · 18:16 UTC
Ransomware group blacklocks has listed ARCA Unlimited Architects (South Africa, professional services) as a victim on its leak site. Fresh victim postings give defenders a short window to hunt for the listed TTPs and to warn linked third parties. The professional-services sector is a common pivot into larger client networks.
CategoryRansomware
Severityhigh
Priority score50
Detected26 September 2026 · 18:16 UTC
Ransomware● 58
Ransomware Termite publica a la transportista de combustible CrossettThe Termite ransomware group has listed Crossett Home, a US fuel/petroleum transporter, as a victim. Hitting a fuel logistics operator raises supply-chain and critical-infrastructure concerns across energy and transport. Security teams in these sectors should track related TTPs and any leaked operational data.Ransomware● 45
Ransomware metaencryptor publica a Platinum Healthcare Staffingmetaencryptor has listed Platinum Healthcare Staffing, a U.S. nursing and allied-health staffing agency, as a ransomware victim. Staffing firms hold worker PII and protected health information plus client hospital data. Exposure raises the risk of identity theft and targeted phishing against staff and partner facilities.Ransomware● 48
Ransomware metaencryptor publica a la auditora PKF Hadiwinatametaencryptor has listed PKF Hadiwinata, a top-10 Indonesian accounting and audit firm, as a ransomware victim. Such firms hold sensitive client financial and tax data, so a breach can ripple to many downstream companies. Monitor for client-data exposure and follow-on fraud against those customers.Ransomware● 72
Ransomware metaencryptor publica a la energética GE VernovaThe metaencryptor group has listed GE Vernova, a global energy equipment maker tied to roughly a quarter of world electricity generation, as a ransomware victim. A successful intrusion against energy-sector suppliers can cascade to utilities and grid operators. The listing signals potential data theft and operational disruption across critical energy infrastructure.Ransomware● 63
Ransomware Emperador publica a Electrolux y OnTracThe 'Emperador' group has listed Electrolux and logistics firm OnTrac as victims, threatening to release employee data within a week. Electrolux is a major global appliance manufacturer, so a real breach would expose corporate systems, HR records and supply-chain data. Multinationals and their logistics partners should treat this as an active extortion campaign.Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.