BRIEFRansomwarehighP75
Emperador ransomware publishes US LMS provider NetExam
NetExam
Detected20 August 2026 · 18:53 UTC
Emperador ransomware listed NetExam, a US-based LMS provider, on its leak site. The exposure could compromise corporate training and certification data from client companies. Latin American organizations using NetExam should monitor and rotate credentials.
CategoryRansomware
Severityhigh
Priority score75
Detected20 August 2026 · 18:53 UTC
Ransomware● 55
Universidad de Delhi atacada por ransomware Dysphor1aThe University of Delhi, one of India's largest public universities, has been listed as a victim of the Dysphor1a ransomware operation. The leak may contain sensitive institutional and student data, and the publication appears recent. Though outside Latin America, it signals a ransomware group that could expand operations regionally.Ransomware● 45
Nueva víctima de ransomware publicada por SilentRansomGroupSilentRansomGroup has published a new victim on ransomware.live; the entry is redacted with a full-data timer active. The country and sector are undisclosed, so impact is unknown. Defenders should watch the listing for unredaction to see if any Latin American organizations are affected.Ransomware● 68
Ransomware Kairos publica datos del Ayuntamiento de Velilla de San AntonioThe Kairos ransomware group has listed the City Council of Velilla de San Antonio (Madrid, Spain) on its leak site, indicating municipal data has been compromised. Local government leaks can expose residents' personal records and disrupt public services. This is a fresh ransomware victim in the Spanish-speaking public sector that should be tracked closely.Ransomware● 80
Fuga de datos masiva de Gruppo Spaggiari Parma (6.1 TB de información personal)A threat actor is threatening to leak 6.1 TB of personal data from Gruppo Spaggiari Parma, an Italian school management software provider. The dataset likely contains millions of students' and staff records across multiple countries, making it a major fresh PII exposure. Organizations using this software should treat this as a supply-chain risk and watch for credential reuse.Ransomware● 72
ShinyHunters amenaza con filtrar datos de la empresa tecnológica CyrusThe ShinyHunters group has issued a final warning to the technology company Cyrus, threatening to leak its data if demands are not met by 24 August 2026. The exact scope is unknown, but the group has a history of publishing large databases. This is an active extortion incident that could become a confirmed breach within days.Ransomware● 55
Panzer ransomware publica a Frisian Flag IndonesiaThe Panzer ransomware group has posted Frisian Flag Indonesia, a FrieslandCampina subsidiary, on its leak site. The company is a major dairy producer in Indonesia, and the breach may expose corporate or customer data. Although the victim is outside Latin America, it is a fresh ransomware publication worth monitoring for TTPs and infrastructure indicators.