BRIEFRansomwarelowP48
metaencryptor ransomware lists accounting firm PKF Hadiwinata
PKF Hadiwinata
Detected25 September 2026 · 20:05 UTC
metaencryptor has listed PKF Hadiwinata, a top-10 Indonesian accounting and audit firm, as a ransomware victim. Such firms hold sensitive client financial and tax data, so a breach can ripple to many downstream companies. Monitor for client-data exposure and follow-on fraud against those customers.
CategoryRansomware
Severitylow
Priority score48
Detected25 September 2026 · 20:05 UTC
Ransomware● 45
Ransomware metaencryptor publica a Platinum Healthcare Staffingmetaencryptor has listed Platinum Healthcare Staffing, a U.S. nursing and allied-health staffing agency, as a ransomware victim. Staffing firms hold worker PII and protected health information plus client hospital data. Exposure raises the risk of identity theft and targeted phishing against staff and partner facilities.Ransomware● 72
Ransomware metaencryptor publica a la energética GE VernovaThe metaencryptor group has listed GE Vernova, a global energy equipment maker tied to roughly a quarter of world electricity generation, as a ransomware victim. A successful intrusion against energy-sector suppliers can cascade to utilities and grid operators. The listing signals potential data theft and operational disruption across critical energy infrastructure.Ransomware● 63
Ransomware Emperador publica a Electrolux y OnTracThe 'Emperador' group has listed Electrolux and logistics firm OnTrac as victims, threatening to release employee data within a week. Electrolux is a major global appliance manufacturer, so a real breach would expose corporate systems, HR records and supply-chain data. Multinationals and their logistics partners should treat this as an active extortion campaign.Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.Ransomware● 45
Ransomware Everest publica a la japonesa UNIRITAThe Everest ransomware group listed UNIRITA, a Tokyo-listed IT and infrastructure-software vendor, as a victim on its leak site. Named corporate victims such as mid-size IT vendors matter because they can be supply-chain footholds into their customers. It is a real but lower-priority alert for a LATAM-focused feed.Ransomware● 69
Ransomware BLACKNET-00 contra el municipio de Tel Aviv-YafoThe BLACKNET-00 group claims to have breached the Tel Aviv-Yafo municipality, a government target, and is publishing it as a ransomware victim. A municipal compromise exposes citizen services, internal systems and sensitive records, and the same group is listing multiple victims, signalling an active campaign. Even though it is outside LATAM, government-targeting ransomware from an active crew is worth tracking for pattern awareness.