BRIEFRansomwarehighP60
SpaceBears ransomware lists Portuguese manufacturer Tomix
Tomix / Grupo JOPER (Portugal)
Detected23 September 2026 · 18:51 UTC
The SpaceBears ransomware group has published Tomix / Grupo JOPER, a Portuguese manufacturer of agricultural equipment, as a victim. Manufacturing victims can disrupt supply chains and expose proprietary designs and client data. It is a fresh extortion listing outside Latin America but relevant to regional supply chains.
CategoryRansomware
Severityhigh
Priority score60
Detected23 September 2026 · 18:51 UTC
Ransomware● 35
Ransomware barracuda publica a Abtach/Intersys como víctimaThe 'barracuda' ransomware group published Abtach Ltd. (renamed Intersys Ltd., Pakistan) as a victim, claiming it encrypted all virtual machines and snapshots. The group also alleges fraud and illicit opioid trafficking against the firm. A ransomware publication signals a confirmed disruptive incident, useful for tracking this group's targeting and TTPs.Ransomware● 55
Ransomware BrainCipher publica a la financiera Gold Star FinancialBrainCipher has listed a US financial-services firm, goldstarfinancial.com, as a new ransomware victim. Mortgage and lending data is highly sensitive and often fuels downstream identity fraud. The victim identity and sector details are unverified, so confirm before acting.Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.Ransomware● 40
Ransomware Spirals publica al grupo logístico Asyad (Omán)The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.Ransomware● 76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.