PULSE
FEED
ransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomqilin reclama a Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi · TR · Manufacturingransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomqilin reclama a Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi · TR · Manufacturingransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Production
Kalir Brief · Item7 October 2026 · 01:07 UTC
BRIEFRansomwarehighP70

Qilin ransomware publishes Spanish engineering firm EPTISA

EPTISA

Detected7 October 2026 · 01:07 UTC
Why it matters

The Qilin ransomware group listed Spanish engineering and infrastructure consultancy EPTISA as a victim on its leak site. EPTISA works on water, transport and public-sector infrastructure projects across Spain and Latin America, so stolen engineering data and credentials could expose government clients. Defenders should treat this as a regional critical-infrastructure supply-chain risk.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score70
Detected7 October 2026 · 01:07 UTC
Related items6
Ransomware● 55
Ransomware Termite publica a la aseguradora estadounidense AonThe Termite ransomware group posted Aon plc, a global insurance and risk-management broker, to its leak site. Aon handles large volumes of sensitive client risk, financial and HR data, so any exfiltration is significant for downstream corporate and public-sector clients. There is no regional-specific angle, but the victim's scale and data sensitivity make it worth monitoring.
1h
Ransomware● 40
Andersen Group publicada como víctima de ransomware por SilentRansomGroupThe SilentRansomGroup has listed Andersen Group, a professional-services firm, as a ransomware victim. The victim's country is unconfirmed, so regional relevance is unclear. If the company has LATAM or Argentine operations, this is a fresh extortion event worth tracking.
2h
Ransomware● 52
Ransomware Umbra publica a la universidad egipcia BTUThe Umbra ransomware group listed Beni Suef Technological University (BTU), Egypt's first technological university with programs in ICT, renewable energy and railway technology, on its leak site. This implies compromise of academic systems and theft of student and research data, with extortion underway. It matters as a fresh ransomware publication against an education institution, though outside the Latin America region.
3h
Ransomware● 48
Ransomware Panzer publica a la firma polaca EDFelectronicsThe Panzer ransomware group listed EDFelectronics, a Polish engineering company making specialized electronics and plasma technology for industrial and research use, on its leak site. A named victim means its systems are likely encrypted and data stolen, with extortion ongoing. It matters as a freshly published ransomware victim, though it is outside the Latin America region and scale is unconfirmed.
3h
Ransomware● 40
Ransomware Qilin publica a la constructora turca Ciftay InsaatQilin published Ciftay Insaat, a Turkish manufacturing and construction firm, as a ransomware victim. The listing indicates data theft and extortion against an industrial company, with likely exposure of project and contractual data. It is lower priority for LATAM defenders but confirms continuing Qilin activity against industry.
5h
Ransomware● 40
Ransomware Vexy publica al fabricante de zumos Kookabarra JuiceVexy ransomware listed Kookabarra Juice, an Australian fresh-juice manufacturer in the retail sector, as a victim. It is a small company outside Latin America, but the fresh listing shows ongoing extortion activity. Food-sector victims can face both operational disruption and exposure of customer and commercial data.
5h