BRIEFRansomwarehighP55
Kairos ransomware lists Krapf Group, US school-bus operator
Krapf Group
Detected22 September 2026 · 16:43 UTC
The Kairos ransomware group has published Krapf Group, a US transportation firm running 2,500+ school buses with 3,500 employees. The stolen data reportedly includes personal information of thousands of bus drivers, raising safety and privacy concerns for a large workforce. Freshly listed victims signal an active campaign worth tracking for TTPs and regional spillover.
CategoryRansomware
Severityhigh
Priority score55
Detected22 September 2026 · 16:43 UTC
Ransomware● 42
Ransomware Qilin publica al local estadounidense The Fifty/50Qilin ransomware lists The Fifty/50, a US-based victim, on its leak site. No data volume or record count was disclosed yet, so impact is unclear. A fresh extortion listing signals an active incident that defenders may want to track for naming and TTPs.Ransomware● 50
Ransomware Akira reclama a la textilera TDMIAkira claims textile firm TDMI, threatening to release 33GB including employee SSNs, driver's licenses, passports, credit cards and client data. The mix of PII and financial data raises fraud and account-takeover risk. Track the leak for reuse of credentials and identity documents.Ransomware● 55
Ransomware Akira publica a la manufacturera Coe Press EquipmentAkira lists US manufacturer Coe Press Equipment, threatening to leak 25GB of corporate data. Claimed material includes employee SSNs, driver's licenses, passports, financials and confidential projects. Stolen HR and identity data can fuel fraud and follow-on intrusions, so monitor for reuse of these credentials.Ransomware● 42
Ransomware Akira publica a la italiana DI.C.S.EL. S.R.L.The Akira group listed DI.C.S.EL. S.R.L., an Italian electrical and measurement solutions firm in Lombardy, claiming it will leak 9 GB of corporate data including employee IDs, driver's licenses, financials and NDAs. The victim is outside Latin America, but the publication is fresh and confirms an active intrusion with exfiltration. It is a useful TTP/targeting signal for defenders in the industrial and electrical sector.Ransomware● 48
Ransomware n0n publica al proveedor retail FinSoftThe ransomware group 'n0n' published FinSoft, a retail back-office software vendor whose Kolibri platform serves 10+ retail chains (keddo, marc, lancaster and others). Client databases with sales, stock, pricing and financial records leak one per day after the deadline. It is a fresh supply-chain-style breach affecting many downstream retailers.Ransomware● 45
Ransomware publica a los despachos Hogan Lovells y CadwaladerThe SilentRansomGroup listed Hogan Lovells and Cadwalader, two prominent international law firms, on its leak site; the combined name is unusual and may indicate confusion or a hoax. Law firms hold highly confidential client and deal data, making them prized targets. Defenders should verify the claim before acting on it.