BRIEFRansomwarelowP43
ScarlettGroup ransomware targets Yale University Press site
Yale University Press
Detected8 October 2026 · 06:07 UTC
The ScarlettGroup ransomware operation published yalebooks.yale.edu, the book retail site of Yale University Press. While it is an education/e-commerce target rather than core university systems, a compromise could expose customer accounts, orders and payment data. Worth monitoring for credential and payment-card leaks.
CategoryRansomware
Severitylow
Priority score43
Detected8 October 2026 · 06:07 UTC
Ransomware● 50
Ransomware Storm publica al proveedor sanitario estadounidense TheraCareStorm ransomware listed TheraCare, a New York-based multi-service healthcare, rehabilitation and education provider serving children and families across the US Northeast. Healthcare ransomware can halt clinical and educational services and expose sensitive patient records. Monitor the incident for data-leak volume and victim-notification obligations.Ransomware● 52
Ransomware Storm golpea a la cooperativa de ambulancias CETAM de CanadáThe Storm ransomware group published CETAM, a Canadian cooperative of over 400 ambulance technicians and paramedics handling nearly 20,000 calls a year. A healthcare ransomware victim of this type can disrupt emergency dispatch and expose patient and employee data. Track the incident for leaked records and downstream fraud risk.Ransomware● 48
Ransomware LockBit publica a la firma legal Consilio (EE.UU.)LockBit5 has listed Consilio, a global legal software and services provider, as a new ransomware victim. Legal-services vendors often hold highly sensitive client and litigation data, making any breach a serious confidentiality and third-party risk. Organizations relying on Consilio or similar providers should assess supply-chain exposure.Ransomware● 60
Ransomware LockBit publica al banco haitiano Capital BankLockBit5 has listed Capital Bank SA, a Haitian retail and online bank, as a ransomware victim. A hit on a national bank can expose customer accounts and loan data and disrupt payments in an already fragile financial environment. Regional financial defenders should monitor for leaked data and follow-on fraud.Ransomware● 84
Ransomware LockBit publica a Argentina Valores S.A. (AVSA)LockBit5 has listed Argentina Valores S.A. (AVSA), an Argentine capital-markets and financial services firm, as a fresh ransomware victim. This directly targets Argentine financial infrastructure, so exfiltration or encryption could disrupt securities operations and expose counterparty and client data. Defenders in the Argentine financial sector should treat this as an active regional incident.Ransomware● 80
Nightspire publica al instituto brasileño INI FiocruzThe Nightspire group listed INI Fiocruz, the infectious-disease institute of Brazil's government-linked Oswaldo Cruz Foundation, as a ransomware victim. Healthcare and public-health research data are highly sensitive, and disruption can affect patient care and studies. Brazilian and regional defenders should verify and treat it as critical infrastructure.