BRIEFRansomwarelowP30
Pear ransomware publishes Martin Lawrence Galleries
Martin Lawrence Galleries
Detected24 September 2026 · 22:47 UTC
The 'Pear' ransomware group published Martin Lawrence Galleries, a US art retail chain, as a fresh victim. Retail breaches expose customer data and can disrupt operations, though the extortion impact is lower than in healthcare or finance. Limited relevance to the Latin America region.
CategoryRansomware
Severitylow
Priority score30
Detected24 September 2026 · 22:47 UTC
Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.Ransomware● 45
Ransomware Everest publica a la japonesa UNIRITAThe Everest ransomware group listed UNIRITA, a Tokyo-listed IT and infrastructure-software vendor, as a victim on its leak site. Named corporate victims such as mid-size IT vendors matter because they can be supply-chain footholds into their customers. It is a real but lower-priority alert for a LATAM-focused feed.Ransomware● 69
Ransomware BLACKNET-00 contra el municipio de Tel Aviv-YafoThe BLACKNET-00 group claims to have breached the Tel Aviv-Yafo municipality, a government target, and is publishing it as a ransomware victim. A municipal compromise exposes citizen services, internal systems and sensitive records, and the same group is listing multiple victims, signalling an active campaign. Even though it is outside LATAM, government-targeting ransomware from an active crew is worth tracking for pattern awareness.Ransomware● 70
Blacknet-00 publica el robo de datos de SriLankan AirlinesThe Blacknet-00 group claims an official breach of SriLankan Airlines, the national flag carrier, typically meaning exfiltrated passenger and operational data. State-linked airlines hold passport, booking and employee data, making this a high-value leak with identity-theft and DDoS follow-on risk. Airlines and their partners should monitor for leaked customer credentials and extortion pressure.Ransomware● 48
Ransomware LockBit publica a la aseguradora de salud Taspen LifeThe LockBit5 group listed Taspen Life, a health and group insurance provider (listed under Kazakhstan), as a ransomware victim. Healthcare breaches disrupt patient and policyholder services and expose sensitive health and personal data. It lies outside Latin America but is a fresh victim relevant for sector and insurer monitoring.Ransomware● 68
Ransomware Qilin publica a la fabricante española Iberia CompositechQilin ransomware listed Iberia Compositech Manufacturing, a Spanish manufacturer, as a fresh victim on its leak site with no sample data published yet. An active extortion usually gives defenders a short window to contain, assess backups and check whether Ibero-American subsidiaries or shared credentials are exposed. Manufacturing is a frequent supply-chain entry point, so this warrants monitoring.