BRIEFRansomwarehighP76
Safepay ransomware lists German IT provider T-Systems
T-Systems (Deutsche Telekom)
Detected5 October 2026 · 20:08 UTC
The Safepay ransomware group listed T-Systems, the IT services arm of Deutsche Telekom with over 26,000 employees across 26 countries, as a victim. If confirmed, a breach at such a large managed-IT and cloud provider could cascade into downstream enterprise and public-sector clients. Defenders relying on T-Systems services should urgently assess third-party exposure.
CategoryRansomware
Severityhigh
Priority score76
Detected5 October 2026 · 20:08 UTC
Ransomware● 47
Ransomware publica al minorista de autopartes Turn5The 'global secret group' ransomware crew published US auto-parts retailer Turn5, claiming 328 GB exfiltrated across 26,503 files. This reflects an active extortion operation against a mid-size e-commerce/retail firm with customer and order data at risk. It sits outside the LATAM region but helps defenders track the actor's targeting and TTPs.Ransomware● 62
Grupo endzone amenaza a Momentum Telecom por fuga de 7,5M de clientesThe endzone group published a warning claiming Momentum Telecom exposed PII of 7.5 million customers and suffered outages as a result of its security failures, threatening further attacks. If accurate, this is a telecom (critical-infrastructure) breach with major customer-data and availability impact. Defenders should corroborate the claim and monitor the group.Ransomware● 72
Ransomware safepay publica a la chilena anwo.clThe safepay ransomware group listed anwo.cl, a Chilean HVAC distribution company founded in 1984, on its leak site. The posting points to a confirmed intrusion with data theft and extortion against a regional industrial supplier. Chilean enterprises and their supply-chain partners should treat this as an active campaign indicator.Ransomware● 42
Ransomware doommageddon amenaza a las escuelas ENKA de TurquíaThe doommageddon group has published Turkish education group ENKA Schools with a deadline of October 15, 2026. It is a recent ransomware victim but outside Latin America and the regional critical sector. Its value to a local operator is low, though it confirms the group is active and worth tracking.Ransomware● 66
Ransomware BYOD publica a Franklin Empire con 700 GB de datosThe BYOD ransomware group has published Franklin Empire, claiming over 700 GB exfiltrated, including AWS keys, Moonshot AI API keys, SMTP credentials, and customer PII. It is a high-impact victim with highly sensitive data, partly rotated already. Though outside Latin America, the vector and leaked cloud keys are relevant threat intelligence.Ransomware● 62
Ransomware emperador publica a la logística panameña Pan CaribbeanThe 'emperador' ransomware group posted Pan Caribbean Logistics Group, a Panamanian international cargo and freight company, claiming financial documents plus personal and customer data. This is a fresh regional ransomware victim in the transportation/logistics sector, which is heavily targeted for its operational dependencies. LATAM logistics and supply-chain defenders should treat it as an active sector and third-party risk.