BRIEFRansomwarelowP45
Ransomware group lists law firms Hogan Lovells and Cadwalader
Hogan Lovells / Cadwalader
Detected21 September 2026 · 23:01 UTC
The SilentRansomGroup listed Hogan Lovells and Cadwalader, two prominent international law firms, on its leak site; the combined name is unusual and may indicate confusion or a hoax. Law firms hold highly confidential client and deal data, making them prized targets. Defenders should verify the claim before acting on it.
CategoryRansomware
Severitylow
Priority score45
Detected21 September 2026 · 23:01 UTC
Ransomware● 50
Ransomware Metaencryptor publica al proveedor automotriz AstemoThe Metaencryptor group published Astemo, a Japanese automotive mega-supplier with roughly 80,000 employees worldwide, on its leak site. Such a tier-1 supplier sits deep in global automotive supply chains, so a data-theft incident can ripple to OEMs and partners. It matters for defenders tracking ransomware against manufacturing, even though the victim is outside LATAM.Ransomware● 68
Ransomware Play publica a la fabricante brasileña MetallcoThe Play ransomware group has listed Metallco, a Brazilian manufacturing company, on its leak site. Manufacturing is part of Brazil's critical supply chain, and Play typically exfiltrates data before encrypting, so stolen corporate data may soon surface. Latin American defenders should treat this as an active regional ransomware incident.Ransomware● 38
Nightspire publica un colegio de EE. UU. como víctima de ransomwareNightspire ransomware listed a US school as a victim, though no data samples were published at the time of collection. Education victims hold student and staff PII, making them attractive for downstream identity fraud if the leak is confirmed. It signals an active ransomware campaign and a sector pattern worth monitoring despite the limited detail.Ransomware● 44
Ransomware Nightspire publica a la consultora italiana 360 ConsulenzaNightspire ransomware listed 360 Consulenza S.r.l., an Italian professional-services firm, claiming theft of client documents, project files and software source code. Publishing source code and client data enables follow-on fraud, IP theft and phishing against the firm's customers. It sits outside Latin America but shows an active group and a pattern regional defenders should track.Ransomware● 45
Ransomware Global Secret Group publica al fabricante Allied Supply Co.The ransomware group 'Global Secret Group' published Allied Supply Co., a US industrial machinery and wholesale firm, claiming about 25.3 GB of stolen files. The leak exposes internal business data and pressures the victim to pay. It is outside Latin America, but the TTPs and victim profile remain useful context.Ransomware● 50
Ransomware Global Secret Group publica a la emisora estadounidense KJLAThe ransomware group 'Global Secret Group' published KJLA, a US broadcasting company, claiming roughly 783 GB across more than 500,000 files. Such a large haul can expose corporate, employee and programme data and pressures the victim. It is outside Latin America, but the group's activity is worth tracking for future regional targeting.