BRIEFRansomwarehighP50
Ransomware kairos publishes French hospital center CNEH
Le Centre National de l'Expertise Hospitalière (CNEH)
Detected30 September 2026 · 20:31 UTC
The ransomware group kairos published Le Centre National de l'Expertise Hospitalière (CNEH), a French healthcare training organization, as a new victim on its leak site. Healthcare ransomware disrupts patient-facing services and exposes sensitive data. Health-sector defenders should verify exposure and prepare for leaked records and extortion pressure.
CategoryRansomware
Severityhigh
Priority score50
Detected30 September 2026 · 20:31 UTC
Ransomware● 36
Ransomware safepay publica a la belga Assist2EnjoySafepay listed Belgian appliance retailer Assist2Enjoy, a small wholesale/retail firm established in 2015. Impact is low, but it is a freshly published victim that shows the group's active campaign. Relevant mainly as a signal of ongoing ransomware activity in Europe.Ransomware● 44
Ransomware safepay publica a la alemana econ-tecThe safepay ransomware group published German industrial-engineering firm econ-tec, exposing design, automation and process-optimization project data. Industrial firms feed supply chains, so leaked schematics and client data can enable further downstream attacks. Outside Latin America but relevant to industrial-sector defenders.Ransomware● 62
Ransomware emperador publica a SitePro RentalsRansomware group emperador published SitePro Rentals as a victim, threatening to leak active employee details within 72 hours if not contacted. A referenced class-action filing dated 28 September 2026 confirms the incident is current. Leaked employee and departmental data can fuel phishing and insider targeting, so the victim's clients and partners should be alert.Ransomware● 70
Ransomware Lamashtu publica a la energética mexicana Vinco EnergyLamashtu ransomware published Vinco Energy Services, a Mexican oilfield services company providing wireline logging and telemetry for the oil and gas sector. As energy-sector infrastructure in Latin America, the exposure of operational and engineering data carries high impact. Regional energy and OT defenders should treat this as a priority and hunt for related access.Ransomware● 58
Ransomware lamashtu publica al contador argentino Dr. PuglieseThe lamashtu group published Argentine accountant Dr. Daniel Pugliese (UBA graduate, registered with CP.C.E.C.A.B.A.), exposing professional and client data. Scale is small, but it is an Argentina-based victim relevant to regional monitoring. Client financial records could feed fraud and further targeting.Ransomware● 58
Ransomware n0n publica a la hipotecaria canadiense MortgageHubThe n0n ransomware group published the complete borrower database of MortgageHub, a major Canadian mortgage company: seven years of records including social insurance numbers, dates of birth, full addresses, and loan and payment histories. It also includes the full national commercial servicing book with balances, interest rates, credit scores and insurer data. The scale and sensitivity of this personal and financial data make it a serious identity-theft and fraud risk for affected clients, though the victim is outside the LATAM region.