BRIEFRansomwarelowP42
n0n ransomware lists California surveillance integrator
California smart-building & surveillance integrator (n0n victim, unnamed)
Detected11 October 2026 · 15:34 UTC
n0n ransomware listed a California smart-building and surveillance integration firm, with data slated to publish on 2026-10-14. Such integrators hold network access and camera/system credentials for many client sites, so a breach can cascade to downstream customers. It is fresh but outside Latin America, worth monitoring rather than escalating now.
CategoryRansomware
Severitylow
Priority score42
Detected11 October 2026 · 15:34 UTC
Ransomware● 40
Ransomware n0n publica a firma de arquitectura de Floridan0n ransomware listed a Florida architecture and design firm with a pending data release on 2026-10-14. Architecture firms hold sensitive client blueprints and often have access into partner networks, so leaked data can enable further intrusion. It is a fresh victim outside Latin America, ranking low for a regional alert but still a live leak.Ransomware● 74
Incransom publica al centro médico Health Sciences Centre de WinnipegThe Incransom ransomware group has listed the Health Sciences Centre in Winnipeg, one of Canada's largest medical institutions, claiming a major healthcare data breach. Healthcare ransomware victims face clinical disruption, patient-safety risk and regulatory exposure, and the leaked data fuels downstream fraud. Cross-border providers and LATAM health-sector defenders should watch for shared tactics.Ransomware● 50
Ransomware cifra los sistemas de rime Net GlobalA DarkForums post claims the systems of 'rime Net Global' have been encrypted, posted only minutes before collection. If legitimate, it indicates operational disruption at a corporate target that could affect partners and supply chains. The claim is unverified and the entity ambiguous, so confirm the victim's identity and sector before acting.Ransomware● 30
Ransomware publica a la empresa GOLDUNITED de BrunéiA forum post names GOLDUNITED SDN BHD, a Brunei-based company, as a ransomware victim, indicating a published extortion leak. It is a fresh victim disclosure but outside Argentina/LATAM, so its direct relevance to regional defenders is limited. Track only for regional supply-chain or affiliate-tracking context.Ransomware● 42
Ransomware Nightspire publica a la italiana Valvorobica IndustrialeThe Nightspire ransomware group posted Italian manufacturer Valvorobica Industriale S.p.A. to its leak site, a freshly-published victim in the manufacturing sector. While outside the AR-LATAM region, it confirms an active extortion campaign and offers TTPs (initial access, exfiltration patterns) defenders can track. No AR-LATAM entity is named, so relevance is indirect.Ransomware● 57
Ransomware RunSomeWares publica a la farmacia Morton LTCThe ransomware group RunSomeWares has listed Morton LTC Pharmacy, an independent family-owned pharmacy in Wisconsin (US healthcare sector), as a victim. The exposure may include patient and pharmacy operational data. This is a fresh victim notice relevant to healthcare and incident-response teams.