BRIEFRansomwarehighP44
Ransomware 'emperador' publishes Italian notary Studio Notarile Costantino
Studio Notarile Associato Salvatore Costantino e Anna Favarato
Detected20 September 2026 · 10:37 UTC
The ransomware group 'emperador' has posted the Italian notary firm Studio Notarile Associato Salvatore Costantino e Anna Favarato to its leak site. The listing claims several thousand documents, including customer files and employee data. A freshly published victim signals an active extortion campaign and warrants monitoring.
CategoryRansomware
Severityhigh
Priority score44
Detected20 September 2026 · 10:37 UTC
Ransomware● 46
Ransomware Nightspire publica a la sanitaria Great Bay Bio de Hong KongNightspire ransomware listed Great Bay Bio, a Hong Kong healthcare firm, among its victims; data availability is still unclear. Healthcare breaches endanger sensitive patient data and can disrupt clinical operations. It signals an active ransomware campaign, though outside the AR-LATAM region.Ransomware● 72
El ransomware n0n publica a la minorista deportiva FanaticsRansomware group n0n published US sports-commerce platform Fanatics, claiming 108 GB including 46,902 order files, customer PII, partner invoices and fraud-prevention data, with a 2026-09-23 deadline. A fresh, high-impact victim whose leaked records can drive follow-on fraud and third-party risk. Outside LatAm but timely as a newly published ransomware case.Ransomware● 48
Ransomware arcusmedia publica a la canadiense Schneider's Computingarcusmedia ransomware has published Canadian IT provider Schneider's Computing & Websites with a near-term deadline. Compromise of an IT and web-hosting provider can cascade to its many clients, amplifying impact. Though outside LATAM, it shows the group's active targeting of service providers.Ransomware● 72
Ransomware arcusmedia publica a la empresa brasileña de calzado AkazzoThe arcusmedia ransomware group has listed Brazilian footwear company Akazzo (akazzo.com.br) as a victim with a near-term deadline. A fresh LATAM victim signals active regional operations and risk of data exfiltration. Brazilian firms should review exposure and backup integrity now.Ransomware● 47
Ransomware 'unsafe' lista al sitio de videojuegos voltgames.ioThe 'unsafe' ransomware group has listed voltgames.io, a gaming site with roughly $1.5M revenue. Freshly published victims give defenders a window to check for the same intrusion vectors. Value is moderate since the target lies outside the region and appears lower-impact.Ransomware● 64
Ransomware 'emperador' publica a Electrolux y datos de AzureThe 'emperador' ransomware group lists Electrolux as a victim, claiming it exported roughly 41GB from the company's Azure database. Electrolux is a major multinational appliance manufacturer, so leaked corporate and operational data could enable further intrusion, extortion and supply-chain abuse. Although Swedish, its global footprint makes this relevant to any region it operates in.