BRIEFRansomwarehighP66
Clop lists Australia's Transport for NSW state transport agency
Transport for NSW (Australia)
Detected23 September 2026 · 15:17 UTC
Reposts collapsed3
Clop listed Transport for NSW (transport.nsw.gov.au), the Australian state agency running trains, buses, ferries, roads and traffic systems. A ransomware hit on a government transport operator raises risks for public-safety and mobility infrastructure and potential exposure of citizen and operational data. Though outside Latin America, it is a genuine critical-infrastructure victim worth tracking for TTPs and victimology.
CategoryRansomware
Severityhigh
Priority score66
Detected23 September 2026 · 15:17 UTC
Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.Ransomware● 40
Ransomware Spirals publica al grupo logístico Asyad (Omán)The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.Ransomware● 76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.Ransomware● 52
Ransomware Clop publica a la marca finlandesa SuuntoClop lists Suunto.cn, the Chinese storefront of Finnish sports-instrument maker Suunto, as a victim. Clop runs large-scale extortion campaigns, so the involvement of a recognized global brand is notable even if the listed domain is the China site. Exposure could include customer orders and account data.Ransomware● 58
Ransomware 'endzone' publica al operador móvil Trump MobileRansomware group 'endzone' lists Trump Mobile, a US MVNO, as a victim, claiming exposure of eSIM QR codes and customer PII. The brand's political profile makes it a notable target, though the operator reports only about 4,000 users, limiting impact. Watch for downstream SIM-swap and account-takeover attempts.