BRIEFRansomwarehighP60
Emperador ransomware publishes US shipper OnTrac
OnTrac
Detected23 September 2026 · 21:51 UTC
Emperador ransomware group published OnTrac, a major US last-mile delivery firm (LaserShip/OnTrac merger), leaking its full employee database of roughly 197,000 records with names, employee numbers and PII. The data enables targeted phishing, payroll fraud and identity theft against staff. Defenders should watch for credential stuffing and social engineering tied to OnTrac.
CategoryRansomware
Severityhigh
Priority score60
Detected23 September 2026 · 21:51 UTC
Ransomware● 35
Ransomware barracuda publica a Abtach/Intersys como víctimaThe 'barracuda' ransomware group published Abtach Ltd. (renamed Intersys Ltd., Pakistan) as a victim, claiming it encrypted all virtual machines and snapshots. The group also alleges fraud and illicit opioid trafficking against the firm. A ransomware publication signals a confirmed disruptive incident, useful for tracking this group's targeting and TTPs.Ransomware● 55
Ransomware BrainCipher publica a la financiera Gold Star FinancialBrainCipher has listed a US financial-services firm, goldstarfinancial.com, as a new ransomware victim. Mortgage and lending data is highly sensitive and often fuels downstream identity fraud. The victim identity and sector details are unverified, so confirm before acting.Ransomware● 60
Ransomware SpaceBears publica al fabricante portugués TomixThe SpaceBears ransomware group has published Tomix / Grupo JOPER, a Portuguese manufacturer of agricultural equipment, as a victim. Manufacturing victims can disrupt supply chains and expose proprietary designs and client data. It is a fresh extortion listing outside Latin America but relevant to regional supply chains.Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.Ransomware● 40
Ransomware Spirals publica al grupo logístico Asyad (Omán)The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.Ransomware● 76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.