BRIEFRansomwarehighP42
Qilin ransomware publishes Qatar National Import & Export
Qatar National Import & Export
Detected7 October 2026 · 20:07 UTC
Qilin added Qatar National Import & Export to its leak site, a trading/import-export firm likely tied to Gulf logistics and government supply chains. Fresh ransomware listings signal active data theft that could expose commercial records, partner data and operational details. It is relevant to regional defenders tracking Qilin activity spreading across the Middle East and beyond.
CategoryRansomware
Severityhigh
Priority score42
Detected7 October 2026 · 20:07 UTC
Ransomware● 66
Ransomware Qilin publica a la cárnica Matadero Frigorífico AvinyóThe Qilin ransomware group listed Matadero Frigorífico Avinyó, a Spanish meat-processing firm, on its leak site, threatening to publish stolen data. Freshly-named victims usually precede data dumps or follow-on extortion affecting operations, suppliers and food-supply chains. Defenders in Spain and across Spanish-speaking LATAM should monitor for leaked employee, customer and logistics data.Ransomware● 45
Ransomware Interlock publica a Riviera Healthcare CenterInterlock added Riviera Healthcare Center, a US skilled-nursing facility, to its leak site, claiming exposure of patient PHI including diagnoses, medical histories, treatment and payment records plus employee HR data. Healthcare breaches of this type carry regulatory and patient-safety consequences. It is outside the region and serves mainly as a TTP and victimology indicator.Ransomware● 48
Ransomware Panzer publica a la Universidad de RostockThe Panzer ransomware group listed the University of Rostock (Germany, education sector) as a victim on its leak site. Academic institutions hold sensitive research, student and staff records, so publication implies data theft and disruption. It is outside the LATAM region but signals an active ransomware campaign worth tracking for TTPs.Ransomware● 45
Ransomware umbra publica a la minera Tharisa (Sudáfrica)The umbra ransomware group listed Tharisa, a Cyprus-based platinum-group-metals and chrome mining group with major operations in South Africa, as a victim. Mining is critical infrastructure, so a ransomware intrusion on corporate and operational systems can disrupt production and downstream supply chains. It is outside Latin America, but shows continuing targeting of extractive-industry operators.Ransomware● 48
Ransomware n0n expone datos del MSP estadounidense ChibitekThe n0n group published US managed service provider Chibitek, leaking client financial records, network credentials and internal documents. MSP compromises cascade to downstream customers, amplifying the blast radius. A fresh, named supply-chain leak relevant to risk monitoring even outside the region.Ransomware● 50
Aviso de extorsión a la bangladesí Pathao LimitedA threat actor posted a 'notice' to Pathao Limited, a major Bangladeshi delivery and ride-hailing firm, signalling a data-leak extortion attempt. Fresh extortion posts often precede public leaks or ransomware activity, so they are worth tracking for confirmation and TTPs.