BRIEFRansomwarehighP58
n0n ransomware publishes Canadian mortgage firm MortgageHub
MortgageHub
Detected30 September 2026 · 13:46 UTC
The n0n ransomware group published the complete borrower database of MortgageHub, a major Canadian mortgage company: seven years of records including social insurance numbers, dates of birth, full addresses, and loan and payment histories. It also includes the full national commercial servicing book with balances, interest rates, credit scores and insurer data. The scale and sensitivity of this personal and financial data make it a serious identity-theft and fraud risk for affected clients, though the victim is outside the LATAM region.
CategoryRansomware
Severityhigh
Priority score58
Detected30 September 2026 · 13:46 UTC
Ransomware● 36
Ransomware safepay publica a la belga Assist2EnjoySafepay listed Belgian appliance retailer Assist2Enjoy, a small wholesale/retail firm established in 2015. Impact is low, but it is a freshly published victim that shows the group's active campaign. Relevant mainly as a signal of ongoing ransomware activity in Europe.Ransomware● 44
Ransomware safepay publica a la alemana econ-tecThe safepay ransomware group published German industrial-engineering firm econ-tec, exposing design, automation and process-optimization project data. Industrial firms feed supply chains, so leaked schematics and client data can enable further downstream attacks. Outside Latin America but relevant to industrial-sector defenders.Ransomware● 56
Ransomware emperador amenaza con filtrar datos de SitePro RentalsThe 'emperador' ransomware group listed SitePro Rentals and gave a 72-hour ultimatum to leak active employee details such as names, departments and employee records. SitePro is a US equipment-rental firm, so the exposed data is staff PII. The short deadline leaves defenders little time to confirm the breach and notify affected personnel.Ransomware● 70
Ransomware Lamashtu publica a la energética mexicana Vinco EnergyLamashtu ransomware published Vinco Energy Services, a Mexican oilfield services company providing wireline logging and telemetry for the oil and gas sector. As energy-sector infrastructure in Latin America, the exposure of operational and engineering data carries high impact. Regional energy and OT defenders should treat this as a priority and hunt for related access.Ransomware● 58
Ransomware lamashtu publica al contador argentino Dr. PuglieseThe lamashtu group published Argentine accountant Dr. Daniel Pugliese (UBA graduate, registered with CP.C.E.C.A.B.A.), exposing professional and client data. Scale is small, but it is an Argentina-based victim relevant to regional monitoring. Client financial records could feed fraud and further targeting.Ransomware● 32
Ransomware Rhysida publica a la alemana clicks digital GmbHThe Rhysida ransomware group published clicks digital GmbH, a German online-marketing agency with over 40 employees, as a victim on its leak site. While it is a fresh ransomware victim, the target sits in the German technology sector and has no identified link to Latin America or regional critical infrastructure. It is included only as low-priority context and does not warrant a regional alert.