BRIEFRansomwarehighP40
Spirals ransomware publishes logistics group Asyad (Oman)
Asyad Group
Detected23 September 2026 · 16:51 UTC
The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.
CategoryRansomware
Severityhigh
Priority score40
Detected23 September 2026 · 16:51 UTC
Ransomware● 32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.Ransomware● 76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.Ransomware● 60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.Ransomware● 52
Ransomware Clop publica a la marca finlandesa SuuntoClop lists Suunto.cn, the Chinese storefront of Finnish sports-instrument maker Suunto, as a victim. Clop runs large-scale extortion campaigns, so the involvement of a recognized global brand is notable even if the listed domain is the China site. Exposure could include customer orders and account data.Ransomware● 58
Ransomware 'endzone' publica al operador móvil Trump MobileRansomware group 'endzone' lists Trump Mobile, a US MVNO, as a victim, claiming exposure of eSIM QR codes and customer PII. The brand's political profile makes it a notable target, though the operator reports only about 4,000 users, limiting impact. Watch for downstream SIM-swap and account-takeover attempts.Ransomware● 54
Ransomware Clop publica a la aseguradora PALIG (PLM)Clop lists PALIG (Pennsylvania Lumbermens Mutual Insurance / PLM), a US specialty insurer. Insurance records include policyholder PII and claims data valuable for fraud and identity theft. Flag for confirmation of scope and data types.