BRIEFRansomwarehighP52
Endzone ransomware lists global staffing firm eTeam
eTeam Inc.
Detected24 September 2026 · 01:51 UTC
Ransomware group Endzone listed eTeam Inc., a global workforce-solutions company with roughly $229M revenue, as a victim and claims to have exfiltrated data. Professional-services firms hold employee and client PII, so leaked records raise phishing and fraud risk. It is not confirmed as Latin America-based, but matters for supply-chain exposure.
CategoryRansomware
Severityhigh
Priority score52
Detected24 September 2026 · 01:51 UTC
Ransomware● 87
Ransomware Barracuda publica a la petrolera argentina Solucioning S.A.The 'barracuda' ransomware group claims full access to Solucioning S.A., a small Argentine firm whose major clients operate in oil production, and threatens to publish confidential projects, documents and blueprints. This exposes the Argentine energy supply chain, so any organization linked to oil and gas operations should treat it as a fresh, time-sensitive alert and hunt for related access.Ransomware● 60
Ransomware Emperador publica a la transportista OnTracEmperador ransomware group published OnTrac, a major US last-mile delivery firm (LaserShip/OnTrac merger), leaking its full employee database of roughly 197,000 records with names, employee numbers and PII. The data enables targeted phishing, payroll fraud and identity theft against staff. Defenders should watch for credential stuffing and social engineering tied to OnTrac.Ransomware● 35
Ransomware barracuda publica a Abtach/Intersys como víctimaThe 'barracuda' ransomware group published Abtach Ltd. (renamed Intersys Ltd., Pakistan) as a victim, claiming it encrypted all virtual machines and snapshots. The group also alleges fraud and illicit opioid trafficking against the firm. A ransomware publication signals a confirmed disruptive incident, useful for tracking this group's targeting and TTPs.Ransomware● 55
Ransomware BrainCipher publica a la financiera Gold Star FinancialBrainCipher has listed a US financial-services firm, goldstarfinancial.com, as a new ransomware victim. Mortgage and lending data is highly sensitive and often fuels downstream identity fraud. The victim identity and sector details are unverified, so confirm before acting.Ransomware● 60
Ransomware SpaceBears publica al fabricante portugués TomixThe SpaceBears ransomware group has published Tomix / Grupo JOPER, a Portuguese manufacturer of agricultural equipment, as a victim. Manufacturing victims can disrupt supply chains and expose proprietary designs and client data. It is a fresh extortion listing outside Latin America but relevant to regional supply chains.Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.