BRIEFRansomwarehighP58
Ransomware group 'endzone' lists US MVNO Trump Mobile
Trump Mobile
Detected23 September 2026 · 15:47 UTC
Reposts collapsed2
Ransomware group 'endzone' lists Trump Mobile, a US MVNO, as a victim, claiming exposure of eSIM QR codes and customer PII. The brand's political profile makes it a notable target, though the operator reports only about 4,000 users, limiting impact. Watch for downstream SIM-swap and account-takeover attempts.
CategoryRansomware
Severityhigh
Priority score58
Detected23 September 2026 · 15:47 UTC
Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.Ransomware● 52
Ransomware Clop publica a la marca finlandesa SuuntoClop lists Suunto.cn, the Chinese storefront of Finnish sports-instrument maker Suunto, as a victim. Clop runs large-scale extortion campaigns, so the involvement of a recognized global brand is notable even if the listed domain is the China site. Exposure could include customer orders and account data.Ransomware● 54
Ransomware Clop publica a la aseguradora PALIG (PLM)Clop lists PALIG (Pennsylvania Lumbermens Mutual Insurance / PLM), a US specialty insurer. Insurance records include policyholder PII and claims data valuable for fraud and identity theft. Flag for confirmation of scope and data types.Ransomware● 62
Clop publica al bufete internacional Kirkland & Ellis como víctimaClop named Kirkland & Ellis LLP, one of the world's highest-grossing law firms, as a ransomware victim. Law firms concentrate highly sensitive client, litigation and M&A material, so a breach can cascade to many corporate and financial clients. It is a notable out-of-region victim useful for tracking Clop victimology and third-party risk.Ransomware● 68
Clop publica a Columbia Banking System (Umpqua Bank) como víctimaClop listed Columbia Banking System, the US financial holding company behind Umpqua Bank, as a ransomware victim. A regional bank breach risks customer financial data, lending and wealth-management systems, and raises fraud and regulatory concerns. It is a solid out-of-region financial-sector victim worth monitoring for leaked customer records.Ransomware● 66
Clop incluye a Transport for NSW, agencia estatal de transporte de AustraliaClop listed Transport for NSW (transport.nsw.gov.au), the Australian state agency running trains, buses, ferries, roads and traffic systems. A ransomware hit on a government transport operator raises risks for public-safety and mobility infrastructure and potential exposure of citizen and operational data. Though outside Latin America, it is a genuine critical-infrastructure victim worth tracking for TTPs and victimology.