BRIEFRansomwarehighP74
Endzone ransomware publishes stolen AT&T data
AT&T
Detected18 September 2026 · 08:12 UTC
The Endzone ransomware group claims to have breached AT&T through a CX contractor, holding VPN and internal VDI access for a prolonged period without detection and exporting certificates. AT&T is Tier-1 telecom infrastructure, so any confirmed intrusion risks customer and operational data at massive scale. Defenders should treat this as a live third-party/VPN access vector and review remote access controls.
CategoryRansomware
Severityhigh
Priority score74
Detected18 September 2026 · 08:12 UTC
Ransomware● 52
Ransomware Spirals publica a la empresa ITAD ANYTHINGITSpirals ransomware listed ANYTHINGIT, an IT asset disposition and e-waste firm serving federal agencies, defense contractors and enterprises under strict chain-of-custody requirements. The victim's role in handling sensitive federal hardware and data creates real supply-chain risk. Defenders should assess downstream exposure to any agency data passing through this provider.Ransomware● 64
Ransomware Endzone publica datos de la gubernamental AccelaEndzone published over 50 GB allegedly from Accela, a cloud platform used by US state and local governments, including 2 million lines of PII and 6 million citizen-service requests. Compromise of a government-services vendor can cascade into many public agencies that depend on it. Public-sector defenders should verify exposure and monitor Accela downstream dependencies.Ransomware● 42
Ransomware KillSec publica a la manufacturera Giti Corp (Singapur)The KillSec ransomware group listed Giti Corp, a manufacturing company in Singapore, on its leak site, threatening to publish stolen data. This is a confirmed fresh victim, but Singapore is outside the Argentina/LATAM focus, so direct impact for regional defenders is limited. It is still worth noting as evidence KillSec remains active and is targeting industrial/manufacturing firms that may have Latin American operations or supply-chain links.Ransomware● 62
Ransomware Panzer publica a la tecnológica Inovapy (Latinoamérica)The Panzer ransomware group has published Inovapy, a technology firm providing software and digital-transformation services across Latin America. Freshly naming a regional vendor signals an active intrusion with potential downstream impact on its clients. Latin American defenders should check for exposure and supply-chain risk.Ransomware● 38
Ransomware krybit publica a la residencia alemana Diakoniewerk ApoldaThe krybit ransomware group listed Diakoniewerk Apolda, a German non-profit healthcare and social welfare organization, on its leak site. Healthcare ransomware is high-impact and can disrupt patient services, but this victim is outside the Argentina/LATAM region, so it is mainly of trend-tracking value.Ransomware● 34
Ransomware krybit publica a la constructora turca Harput YapıThe krybit ransomware group published Harput Yapı, an Istanbul-based residential real estate and construction firm, on its leak site. A fresh construction-sector victim matters for extortion trends and supply-chain visibility, though it is outside the Argentina/LATAM region and of limited direct impact.