BRIEFRansomwarehighP80
Incransom ransomware publishes Argentine wholesaler Diarco
Diarco
Detected17 September 2026 · 08:12 UTC
Incransom ransomware group listed Diarco, a large Argentine wholesaler headquartered in Buenos Aires with up to 5,000 employees, on its leak site. The listing signals data theft and extortion against a key regional retail and logistics player. Defenders should watch for Incransom intrusion TTPs against Argentine supply-chain firms.
CategoryRansomware
Severityhigh
Priority score80
Detected17 September 2026 · 08:12 UTC
Ransomware● 42
Ransomware Incransom publica a la estadounidense Appliance FactoryIncransom published Appliance Factory & Mattress Kingdom, a US appliance and mattress retailer operating across Colorado, Kentucky, Wyoming and Indiana, on its leak site. The listing indicates stolen data and extortion, but the victim is outside Latin America. It is relevant mainly as an indicator of Incransom's active campaign tempo.Ransomware● 70
ShinyHunters publica nueva víctima de ransomware con aviso finalRansomware group ShinyHunters published a new victim with a FINAL WARNING and an 18 September negotiation deadline, signalling imminent data release. ShinyHunters targets large enterprises and has leaked sensitive data in past campaigns. The short deadline makes this time-sensitive despite the masked victim name.Ransomware● 74
Ransomware 'auditteam' publica a la víctima argentina krimax.orgThe ransomware group 'auditteam' has listed Argentine organization krimax.org as a fresh victim, indicating an active compromise of an entity in Argentina. Defenders in the region should confirm what data and access the attackers hold and watch for downstream impact on connected services or partners.Ransomware● 52
Ransomware Qilin publica a la víctima canadiense In The Company of HuskiesQilin ransomware has listed Canadian victim In The Company of Huskies as a freshly published victim, indicating a recent intrusion and likely data exfiltration. Leak-site appearances typically precede negotiation pressure and further data release. Track for Qilin TTPs and possible impact on the victim's partners and customers.Ransomware● 52
Ransomware Qilin publica a la víctima australiana Reddrop GroupThe Qilin ransomware group has freshly published Australian victim Reddrop Group on its leak site. A new Qilin listing signals an active intrusion with data-theft leverage and possible downstream supply-chain exposure. Relevant as an out-of-region victim for tracking Qilin's targeting and extortion pressure.Ransomware● 40
Ransomware WallStreet publica a Odyssey Charter SchoolThe WallStreet ransomware group has listed Odyssey Charter School, a US education nonprofit, as a victim. Fresh victim postings are an early signal that stolen data may soon be dumped, giving defenders a short window to contain access, notify families and prepare for extortion.