BRIEFRansomwarehighP45
EndZone ransomware publishes Philander Smith University
Philander Smith University
Detected6 October 2026 · 08:08 UTC
The EndZone ransomware group listed Philander Smith University as a victim, claiming 500GB+ of exfiltrated data. It is a fresh education-sector ransomware publication, but the victim is in the US, outside our Latin America focus. Useful for tracking the group's activity and TTPs.
CategoryRansomware
Severityhigh
Priority score45
Detected6 October 2026 · 08:08 UTC
Ransomware● 42
Ransomware BYOD publica a Standpointe / Trinite SolutionsThe 'byod' ransomware group published Standpointe / Trinite Solutions, a professional-services firm, claiming financial statements, bank accounts, customer and employee data. The data categories indicate a serious business-data breach. It is a fresh victim post, but the country is unstated.Ransomware● 45
Ransomware Insomnia publica a Praxis EMR, proveedor sanitario de EE. UU.Ransomware group 'insomnia' has published Praxis EMR, a US healthcare EHR provider, on its leak site. Healthcare victims face patient-safety and regulatory impact plus extortion. It is a fresh victim publication, though outside the AR-LATAM region.Ransomware● 76
Ransomware Safepay publica a la IT alemana T-SystemsThe Safepay ransomware group listed T-Systems, the IT services arm of Deutsche Telekom with over 26,000 employees across 26 countries, as a victim. If confirmed, a breach at such a large managed-IT and cloud provider could cascade into downstream enterprise and public-sector clients. Defenders relying on T-Systems services should urgently assess third-party exposure.Ransomware● 47
Ransomware publica al minorista de autopartes Turn5The 'global secret group' ransomware crew published US auto-parts retailer Turn5, claiming 328 GB exfiltrated across 26,503 files. This reflects an active extortion operation against a mid-size e-commerce/retail firm with customer and order data at risk. It sits outside the LATAM region but helps defenders track the actor's targeting and TTPs.Ransomware● 62
Grupo endzone amenaza a Momentum Telecom por fuga de 7,5M de clientesThe endzone group published a warning claiming Momentum Telecom exposed PII of 7.5 million customers and suffered outages as a result of its security failures, threatening further attacks. If accurate, this is a telecom (critical-infrastructure) breach with major customer-data and availability impact. Defenders should corroborate the claim and monitor the group.Ransomware● 72
Ransomware safepay publica a la chilena anwo.clThe safepay ransomware group listed anwo.cl, a Chilean HVAC distribution company founded in 1984, on its leak site. The posting points to a confirmed intrusion with data theft and extortion against a regional industrial supplier. Chilean enterprises and their supply-chain partners should treat this as an active campaign indicator.