BRIEFRansomwarehighP60
Thegentlemen ransomware lists Colegio Humboldt in São Paulo
Colegio Humboldt (São Paulo)
Detected15 September 2026 · 08:12 UTC
The thegentlemen group lists Colegio Humboldt, the German binational school in São Paulo with ~1,200 students, claiming 300GB of stolen data. Schools hold student, family, health and staff records plus financial data. A leak of that volume at a high-profile institution raises serious privacy, extortion and reputational risk in Brazil.
CategoryRansomware
Severityhigh
Priority score60
Detected15 September 2026 · 08:12 UTC
Ransomware● 55
Ransomware thegentlemen publica a la heladería peruana GelartiThe thegentlemen ransomware group listed Gelarti, Peru's largest gourmet ice-cream chain with 39 outlets, as a victim. Retail and franchise operators hold customer loyalty, payment and supplier data. Encryption of POS or back-office systems could interrupt sales across Peru and expose customer and franchisee information.Ransomware● 52
Ransomware thegentlemen publica a la contable brasileña MultiplaThe thegentlemen group listed Multipla Contabilidade Empresarial, a family accounting firm in Piracicaba, São Paulo state, as a victim. Accounting firms concentrate tax, payroll and financial records of many client companies, so a breach can cascade to those clients. It is a smaller but real Brazilian data-exposure and extortion risk.Ransomware● 68
Ransomware thegentlemen publica al integrador guatemalteco SomitThe thegentlemen ransomware group listed Somit, a Guatemalan IT systems integrator serving banks, universities and government clients, as a victim. A compromised integrator is a supply-chain risk: its access to client networks, telemedicine platforms and data centers could enable downstream intrusions. This makes it relevant to Latin American critical-infrastructure defenders.Ransomware● 62
Ransomware thegentlemen publica a la librería argentina Santa FeThe thegentlemen ransomware group listed Librería Santa Fe APS S.R.L., an Argentine book retailer and B2B distributor in Buenos Aires, as a victim. Such firms hold customer, supplier and school-institution sales data plus payment records. Encryption or data theft could disrupt book distribution across Argentina and expose customer PII to extortion.Ransomware● 60
Ransomware Qilin publica a la empresa española GeiegThe Qilin ransomware group listed Geieg, a Spanish organisation, as a victim on its leak site. Publication signals a confirmed intrusion with data-theft extortion, exposing employee and client data. Spanish-speaking defenders should treat this as an active ransomware case in their region.Ransomware● 52
Ransomware Shadowbyt3 publica a HandyTrac (Greystar, Arizona)Shadowbyt3 listed HandyTrac, a tenant key-control and access-management provider used by Greystar's Litchfield Park property. Leaked data includes physical-to-digital key maps, employee identity and credential data, and financial/vendor records. Exposed key-control reports and staff credentials can enable physical intrusion and account abuse at managed sites, making this a fresh and actionable victim even though it is US-based.