BRIEFRansomwarelowP32
Rhysida ransomware lists German firm clicks digital GmbH
clicks digital GmbH
Detected30 September 2026 · 13:05 UTC
The Rhysida ransomware group published clicks digital GmbH, a German online-marketing agency with over 40 employees, as a victim on its leak site. While it is a fresh ransomware victim, the target sits in the German technology sector and has no identified link to Latin America or regional critical infrastructure. It is included only as low-priority context and does not warrant a regional alert.
CategoryRansomware
Severitylow
Priority score32
Detected30 September 2026 · 13:05 UTC
Ransomware● 58
Ransomware n0n publica a la hipotecaria canadiense MortgageHubThe n0n ransomware group published the complete borrower database of MortgageHub, a major Canadian mortgage company: seven years of records including social insurance numbers, dates of birth, full addresses, and loan and payment histories. It also includes the full national commercial servicing book with balances, interest rates, credit scores and insurer data. The scale and sensitivity of this personal and financial data make it a serious identity-theft and fraud risk for affected clients, though the victim is outside the LATAM region.Ransomware● 58
Ransomware Interlock publica al contratista Tekko EnterprisesInterlock listed Tekko Enterprises, a Utah contractor holding a U.S. Air Force contract at Mountain Home AFB (>$5M) plus Army Corps of Engineers work. The leak allegedly exposes confidential project and financial data tied to government contracts. Defense suppliers are high-value targets; watch for data reuse and supply-chain phishing.Ransomware● 42
Ransomware Qilin publica a la víctima estadounidense Arnold CenterThe Qilin ransomware group has published a new victim, Arnold Center, a US organisation, on its leak site. Although outside LatAm, a fresh ransomware listing signals an active intrusion with data-theft and double-extortion risk. Defenders should watch for the leaked data and cross-reference any regional or sector links.Ransomware● 50
Ransomware 'blacklocks' publica a la firma de arquitectura ARCA UnlimitedRansomware group blacklocks has listed ARCA Unlimited Architects (South Africa, professional services) as a victim on its leak site. Fresh victim postings give defenders a short window to hunt for the listed TTPs and to warn linked third parties. The professional-services sector is a common pivot into larger client networks.Ransomware● 58
Ransomware Termite publica a la transportista de combustible CrossettThe Termite ransomware group has listed Crossett Home, a US fuel/petroleum transporter, as a victim. Hitting a fuel logistics operator raises supply-chain and critical-infrastructure concerns across energy and transport. Security teams in these sectors should track related TTPs and any leaked operational data.Ransomware● 45
Ransomware metaencryptor publica a Platinum Healthcare Staffingmetaencryptor has listed Platinum Healthcare Staffing, a U.S. nursing and allied-health staffing agency, as a ransomware victim. Staffing firms hold worker PII and protected health information plus client hospital data. Exposure raises the risk of identity theft and targeted phishing against staff and partner facilities.