BRIEFRansomwarehighP54
Clop ransomware publishes insurer PALIG (PLM)
PALIG / Pennsylvania Lumbermens Mutual Insurance
Detected23 September 2026 · 15:25 UTC
Clop lists PALIG (Pennsylvania Lumbermens Mutual Insurance / PLM), a US specialty insurer. Insurance records include policyholder PII and claims data valuable for fraud and identity theft. Flag for confirmation of scope and data types.
CategoryRansomware
Severityhigh
Priority score54
Detected23 September 2026 · 15:25 UTC
Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.Ransomware● 52
Ransomware Clop publica a la marca finlandesa SuuntoClop lists Suunto.cn, the Chinese storefront of Finnish sports-instrument maker Suunto, as a victim. Clop runs large-scale extortion campaigns, so the involvement of a recognized global brand is notable even if the listed domain is the China site. Exposure could include customer orders and account data.Ransomware● 58
Ransomware 'endzone' publica al operador móvil Trump MobileRansomware group 'endzone' lists Trump Mobile, a US MVNO, as a victim, claiming exposure of eSIM QR codes and customer PII. The brand's political profile makes it a notable target, though the operator reports only about 4,000 users, limiting impact. Watch for downstream SIM-swap and account-takeover attempts.Ransomware● 62
Clop publica al bufete internacional Kirkland & Ellis como víctimaClop named Kirkland & Ellis LLP, one of the world's highest-grossing law firms, as a ransomware victim. Law firms concentrate highly sensitive client, litigation and M&A material, so a breach can cascade to many corporate and financial clients. It is a notable out-of-region victim useful for tracking Clop victimology and third-party risk.Ransomware● 68
Clop publica a Columbia Banking System (Umpqua Bank) como víctimaClop listed Columbia Banking System, the US financial holding company behind Umpqua Bank, as a ransomware victim. A regional bank breach risks customer financial data, lending and wealth-management systems, and raises fraud and regulatory concerns. It is a solid out-of-region financial-sector victim worth monitoring for leaked customer records.Ransomware● 66
Clop incluye a Transport for NSW, agencia estatal de transporte de AustraliaClop listed Transport for NSW (transport.nsw.gov.au), the Australian state agency running trains, buses, ferries, roads and traffic systems. A ransomware hit on a government transport operator raises risks for public-safety and mobility infrastructure and potential exposure of citizen and operational data. Though outside Latin America, it is a genuine critical-infrastructure victim worth tracking for TTPs and victimology.