BRIEFRansomwarehighP55
BrainCipher ransomware lists US lender Gold Star Financial
Gold Star Financial (goldstarfinancial.com)
Detected23 September 2026 · 18:51 UTC
BrainCipher has listed a US financial-services firm, goldstarfinancial.com, as a new ransomware victim. Mortgage and lending data is highly sensitive and often fuels downstream identity fraud. The victim identity and sector details are unverified, so confirm before acting.
CategoryRansomware
Severityhigh
Priority score55
Detected23 September 2026 · 18:51 UTC
Ransomware● 35
Ransomware barracuda publica a Abtach/Intersys como víctimaThe 'barracuda' ransomware group published Abtach Ltd. (renamed Intersys Ltd., Pakistan) as a victim, claiming it encrypted all virtual machines and snapshots. The group also alleges fraud and illicit opioid trafficking against the firm. A ransomware publication signals a confirmed disruptive incident, useful for tracking this group's targeting and TTPs.Ransomware● 60
Ransomware SpaceBears publica al fabricante portugués TomixThe SpaceBears ransomware group has published Tomix / Grupo JOPER, a Portuguese manufacturer of agricultural equipment, as a victim. Manufacturing victims can disrupt supply chains and expose proprietary designs and client data. It is a fresh extortion listing outside Latin America but relevant to regional supply chains.Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.Ransomware● 40
Ransomware Spirals publica al grupo logístico Asyad (Omán)The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.Ransomware● 76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.