PULSE
FEED
ransomaurora reclama a Thomas Y. Pickett & Co., Inc. · US · Professional Servicesransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomaurora reclama a Thomas Y. Pickett & Co., Inc. · US · Professional Servicesransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturing
Kalir Brief · Item5 October 2026 · 12:55 UTC
BRIEFRansomwarehighP66

BYOD ransomware publishes Franklin Empire, 700 GB of data

Franklin Empire

Detected5 October 2026 · 12:55 UTC
Why it matters

The BYOD ransomware group has published Franklin Empire, claiming over 700 GB exfiltrated, including AWS keys, Moonshot AI API keys, SMTP credentials, and customer PII. It is a high-impact victim with highly sensitive data, partly rotated already. Though outside Latin America, the vector and leaked cloud keys are relevant threat intelligence.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score66
Detected5 October 2026 · 12:55 UTC
Related items6
Ransomware● 42
Ransomware doommageddon amenaza a las escuelas ENKA de TurquíaThe doommageddon group has published Turkish education group ENKA Schools with a deadline of October 15, 2026. It is a recent ransomware victim but outside Latin America and the regional critical sector. Its value to a local operator is low, though it confirms the group is active and worth tracking.
58m
Ransomware● 62
Ransomware emperador publica a la logística panameña Pan CaribbeanThe 'emperador' ransomware group posted Pan Caribbean Logistics Group, a Panamanian international cargo and freight company, claiming financial documents plus personal and customer data. This is a fresh regional ransomware victim in the transportation/logistics sector, which is heavily targeted for its operational dependencies. LATAM logistics and supply-chain defenders should treat it as an active sector and third-party risk.
2h
Ransomware● 72
Ransomware Emperador publica a la peruana Metrocolor S.A.The ransomware group 'emperador' has published Peruvian printing company Metrocolor S.A., claiming to hold thousands of documents with staff and customer data. As a real Latin American victim, it is a direct regional alert and a signal for similar firms. Reviewing the leak helps assess exposure of personal and commercial data.
3h
Ransomware● 84
Base de datos de empresa nicaragüense filtrada con ransomwareA threat actor claims to have dumped the full database of an unnamed Nicaraguan company and bundles ransomware access or samples with it. A fresh regional breach involving operational data plus ransomware significantly raises the risk of extortion and lateral movement against Central American entities.
7h
Ransomware● 73
Wallstreet publica al contratista del estadio del Mundial 2034 en JeddahThe Wallstreet ransomware group published the Sama Construction / China Railway Construction consortium, main contractor for the Jeddah Central Stadium for the FIFA World Cup 2034. It claims 17 TB and 1.5M files exfiltrated, including main contracts, interim payment certificates and a suspension claim against PIF-owned Jeddah Central Development Company. This is a large fresh leak of sensitive financial and contractual data on a high-profile critical project.
2d
Ransomware● 72
Ransomware Akira publica al Colegio de Arquitectos de León (México)The Akira ransomware group listed the College of Architects of León on its leak site, claiming roughly 77GB of corporate data including passports, financial records, and student and client information. This is a fresh LATAM victim whose exposure of identity documents and financial data creates serious identity-theft and fraud risk. Defenders in Mexico's professional-services sector should treat Akira as an active threat targeting their organizations.
2d