BRIEFRansomwarehighP76
DragonForce ransomware lists health insurer ARS Renacer
ARS Renacer
Detected20 September 2026 · 21:37 UTC
The DragonForce group has listed ARS Renacer, a Latin American health-risk administrator (ARS) licensed under SISALRIL that serves hundreds of thousands of affiliates, on its ransomware leak site. The posting implies exfiltration of member and medical data from a regulated health payer. This is a fresh regional healthcare ransomware victim; defenders should monitor for extortion escalation and abuse of exposed affiliate data.
CategoryRansomware
Severityhigh
Priority score76
Detected20 September 2026 · 21:37 UTC
Ransomware● 70
Ransomware Emperador publica a la clínica Alabama Woman's Health CareThe Emperador ransomware group listed Alabama Woman's Health Care, a US healthcare provider, as a fresh victim, claiming theft of several thousand employee and patient documents plus a photo archive. Healthcare breaches expose highly sensitive medical and personal data and enable double-extortion. It matters as a newly published victim in a critical, regulated sector.Ransomware● 40
Ransomware auditteam publica a una empresa italianaThe auditteam ransomware group published a new Italian victim whose name is partially masked. The sector is not stated, but a fresh ransomware listing indicates a confirmed network compromise and data theft. Organizations in the affected sector across Italy/Europe should watch for extortion follow-up and reuse of stolen data.Ransomware● 45
Ransomware auditteam publica a la firma rusa de energía térmica TEK SPBThe auditteam ransomware group listed TEK SPB (tek-spb.ru), a St. Petersburg heat-engineering company, as a victim. The firm designs and maintains district heating points and metering units, i.e. critical urban infrastructure, so a breach could disrupt heating services or expose industrial data. Energy/utility defenders should treat this as a reminder of OT risk arising from IT compromise.Ransomware● 36
Ransomware Qilin publica a la empresa alemana KMLSQilin ransomware has listed KMLS, a German company, on its leak site, indicating a confirmed breach with likely data exfiltration. The group typically targets mid-market firms using double-extortion tactics. German industrial and supply-chain partners should assess their third-party exposure.Ransomware● 42
Ransomware Qilin publica al minorista tailandés ShopDunkQilin ransomware has published ShopDunk, a Thai retail and e-commerce brand, as a victim on its extortion site. Publication implies a confirmed intrusion with a data-theft component, exposing customer and payment-adjacent records. Retail and e-commerce defenders should watch for credential-stuffing and fraud spikes.Ransomware● 52
Ransomware Qilin publica al Touring Club SuisseThe Qilin ransomware group has listed Touring Club Suisse, a major Swiss motoring and travel-services organization, on its leak site. A published victim of this scale signals a confirmed compromise and likely exfiltration of member and operational data. Swiss and neighboring financial/insurance partners should treat it as a real third-party risk.