BRIEFRansomwarehighP64
Ransomware 'emperador' publishes Electrolux, leaks Azure data
Electrolux
Detected19 September 2026 · 16:23 UTC
Reposts collapsed2
The 'emperador' ransomware group lists Electrolux as a victim, claiming it exported roughly 41GB from the company's Azure database. Electrolux is a major multinational appliance manufacturer, so leaked corporate and operational data could enable further intrusion, extortion and supply-chain abuse. Although Swedish, its global footprint makes this relevant to any region it operates in.
CategoryRansomware
Severityhigh
Priority score64
Detected19 September 2026 · 16:23 UTC
Ransomware● 47
Ransomware 'unsafe' publica a la tecnológica voltgames.ioThe 'unsafe' ransomware group published technology company voltgames.io (approx. $1.5M revenue) as a victim. Fresh extortion posts give defenders little warning but confirm active targeting of tech firms. Review exposure, backups and credentials if connected.Ransomware● 40
Ransomware cry0 publica al bufete estadounidense Young Injury LawRansomware group cry0 has listed Young Injury Law, a US professional-services (legal) firm, as a new victim, with the leak page still pending. Fresh ransomware listings indicate a recent intrusion where stolen data may soon be published or sold. Although outside the LATAM region, tracking cry0's activity helps map sector overlap and evolving TTPs.Ransomware● 45
Ransomware Anubis publica a la tecnológica Quest GroupThe Anubis ransomware group listed Quest Group, a technology-sector victim, claiming to have stolen employee data and internal files. Technology firms often hold source code, credentials and customer records that can fuel follow-on intrusions. No country is specified, so the victim may sit outside Argentina/LATAM, which limits the direct regional impact.Ransomware● 80
Ransomware Panzer publica a la consultora brasileña K3G SolutionsRansomware group Panzer listed K3G Solutions, a Brazilian telecom/IT consultancy in Manaus that provides network engineering, ISP support, monitoring, call-center, CDN and colocation services. That places a regional telecom/critical-infrastructure provider on a leak site, exposing potential supply-chain risk to its ISP and enterprise clients. LATAM defenders should treat this as a fresh ransomware incident and review third-party connectivity.Ransomware● 60
Ransomware LockBit publica a la empresa alemana HyGear (salud)The LockBit group has added HyGear, a German on-site and on-demand hydrogen supplier in the healthcare sector, to its extortion portal. The victim combines industrial/OT hydrogen production with healthcare supply chains, so a breach could disrupt operations and expose partner or client data. Defenders in energy and healthcare supply chains should watch for leaked credentials and follow-on access attempts.Ransomware● 78
Ransomware LockBit publica a la minorista chilena ForusThe LockBit leak site has listed Forus, a Chilean apparel retailer headquartered in Santiago and founded in 1980, as a victim in the professional services sector. As a large regional company it holds customer, supplier and transaction data, so a confirmed breach could expose personal and financial information across Chile. A defender should verify the claim and monitor for leaked or traded Forus data.