BRIEFRansomwarehighP60
n0n ransomware publishes Houston Thyroid & Endocrine clinic
Houston Thyroid & Endocrine Specialists
Detected30 September 2026 · 23:53 UTC
Ransomware group n0n published Houston Thyroid & Endocrine Specialists, listing 14,441 patient document scans with lab results, diagnoses, insurance and billing data, plus SSNs and dates of birth. The leak exposes protected health information of thousands and fuels downstream medical-identity fraud. A deadline of 2026-10-04 marks an active, time-sensitive extortion.
CategoryRansomware
Severityhigh
Priority score60
Detected30 September 2026 · 23:53 UTC
Ransomware● 50
Ransomware kairos publica al centro hospitalario francés CNEHThe ransomware group kairos published Le Centre National de l'Expertise Hospitalière (CNEH), a French healthcare training organization, as a new victim on its leak site. Healthcare ransomware disrupts patient-facing services and exposes sensitive data. Health-sector defenders should verify exposure and prepare for leaked records and extortion pressure.Ransomware● 36
Ransomware safepay publica a la belga Assist2EnjoySafepay listed Belgian appliance retailer Assist2Enjoy, a small wholesale/retail firm established in 2015. Impact is low, but it is a freshly published victim that shows the group's active campaign. Relevant mainly as a signal of ongoing ransomware activity in Europe.Ransomware● 44
Ransomware safepay publica a la alemana econ-tecThe safepay ransomware group published German industrial-engineering firm econ-tec, exposing design, automation and process-optimization project data. Industrial firms feed supply chains, so leaked schematics and client data can enable further downstream attacks. Outside Latin America but relevant to industrial-sector defenders.Ransomware● 62
Ransomware emperador publica a SitePro RentalsRansomware group emperador published SitePro Rentals as a victim, threatening to leak active employee details within 72 hours if not contacted. A referenced class-action filing dated 28 September 2026 confirms the incident is current. Leaked employee and departmental data can fuel phishing and insider targeting, so the victim's clients and partners should be alert.Ransomware● 70
Ransomware Lamashtu publica a la energética mexicana Vinco EnergyLamashtu ransomware published Vinco Energy Services, a Mexican oilfield services company providing wireline logging and telemetry for the oil and gas sector. As energy-sector infrastructure in Latin America, the exposure of operational and engineering data carries high impact. Regional energy and OT defenders should treat this as a priority and hunt for related access.Ransomware● 58
Ransomware lamashtu publica al contador argentino Dr. PuglieseThe lamashtu group published Argentine accountant Dr. Daniel Pugliese (UBA graduate, registered with CP.C.E.C.A.B.A.), exposing professional and client data. Scale is small, but it is an Argentina-based victim relevant to regional monitoring. Client financial records could feed fraud and further targeting.