PULSE
FEED
ransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransombyod reclama a Royal Selangor · MY · Manufacturingransomlamashtu reclama a Fluge Audiovisuales · ES · Otherransomlamashtu reclama a Bender Tribunenbau · DE · Manufacturingransomlamashtu reclama a TRANS LOGROÑO SOCIEDAD ANONIMA · ES · Transportationransomlamashtu reclama a Grupo Industrial Tauro · MX · Manufacturingransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturing
Kalir Brief · Item5 October 2026 · 10:55 UTC
BRIEFRansomwarehighP72

Ransomware group Emperador hits Peruvian firm Metrocolor

Metrocolor S.A.

Detected5 October 2026 · 10:55 UTC
Why it matters

The ransomware group 'emperador' has published Peruvian printing company Metrocolor S.A., claiming to hold thousands of documents with staff and customer data. As a real Latin American victim, it is a direct regional alert and a signal for similar firms. Reviewing the leak helps assess exposure of personal and commercial data.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score72
Detected5 October 2026 · 10:55 UTC
Related items6
Ransomware● 62
Ransomware emperador publica a la logística panameña Pan CaribbeanThe 'emperador' ransomware group posted Pan Caribbean Logistics Group, a Panamanian international cargo and freight company, claiming financial documents plus personal and customer data. This is a fresh regional ransomware victim in the transportation/logistics sector, which is heavily targeted for its operational dependencies. LATAM logistics and supply-chain defenders should treat it as an active sector and third-party risk.
26m
Ransomware● 84
Base de datos de empresa nicaragüense filtrada con ransomwareA threat actor claims to have dumped the full database of an unnamed Nicaraguan company and bundles ransomware access or samples with it. A fresh regional breach involving operational data plus ransomware significantly raises the risk of extortion and lateral movement against Central American entities.
5h
Ransomware● 73
Wallstreet publica al contratista del estadio del Mundial 2034 en JeddahThe Wallstreet ransomware group published the Sama Construction / China Railway Construction consortium, main contractor for the Jeddah Central Stadium for the FIFA World Cup 2034. It claims 17 TB and 1.5M files exfiltrated, including main contracts, interim payment certificates and a suspension claim against PIF-owned Jeddah Central Development Company. This is a large fresh leak of sensitive financial and contractual data on a high-profile critical project.
2d
Ransomware● 72
Ransomware Akira publica al Colegio de Arquitectos de León (México)The Akira ransomware group listed the College of Architects of León on its leak site, claiming roughly 77GB of corporate data including passports, financial records, and student and client information. This is a fresh LATAM victim whose exposure of identity documents and financial data creates serious identity-theft and fraud risk. Defenders in Mexico's professional-services sector should treat Akira as an active threat targeting their organizations.
2d
Ransomware● 43
Qilin publica a la empresa británica Sports Events365Qilin ransomware listed Sports Events365, a UK hospitality-sector company, as a fresh victim. Hospitality is a frequent ransomware target and a public victim page enables downstream extortion and phishing. It is worth noting for Qilin's ongoing campaign activity, though it has no direct LATAM link.
3d
Ransomware● 60
Rhysida publica al fabricante sueco Electro Heat SwedenRhysida published Electro Heat Sweden AB, an industrial furnace maker, claiming 2.55 TB (1.72M files) including SolidWorks CAD designs, PDM vault backups, payroll and accounting databases for four legal entities. This hits an energy/utilities-sector company with highly sensitive IP. Though outside LATAM, the scale and sector make it a notable ransomware event.
3d