BRIEFRansomwarecriticalP88
Titan ransomware publishes Argentine healthcare provider Hospifar
Grupo Hospifar S.R.L.
Detected22 September 2026 · 20:43 UTC
The ransomware group Titan has listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on its leak site. Healthcare is critical infrastructure and exposure of patient records carries regulatory and safety consequences. Argentine health entities should treat this as an active, time-sensitive incident.
CategoryRansomware
Severitycritical
Priority score88
Detected22 September 2026 · 20:43 UTC
Ransomware● 55
Ransomware Kairos publica a Krapf Group, operador de transporte escolar de EE. UU.The Kairos ransomware group has published Krapf Group, a US transportation firm running 2,500+ school buses with 3,500 employees. The stolen data reportedly includes personal information of thousands of bus drivers, raising safety and privacy concerns for a large workforce. Freshly listed victims signal an active campaign worth tracking for TTPs and regional spillover.Ransomware● 42
Ransomware Qilin publica al local estadounidense The Fifty/50Qilin ransomware lists The Fifty/50, a US-based victim, on its leak site. No data volume or record count was disclosed yet, so impact is unclear. A fresh extortion listing signals an active incident that defenders may want to track for naming and TTPs.Ransomware● 50
Ransomware Akira reclama a la textilera TDMIAkira claims textile firm TDMI, threatening to release 33GB including employee SSNs, driver's licenses, passports, credit cards and client data. The mix of PII and financial data raises fraud and account-takeover risk. Track the leak for reuse of credentials and identity documents.Ransomware● 55
Ransomware Akira publica a la manufacturera Coe Press EquipmentAkira lists US manufacturer Coe Press Equipment, threatening to leak 25GB of corporate data. Claimed material includes employee SSNs, driver's licenses, passports, financials and confidential projects. Stolen HR and identity data can fuel fraud and follow-on intrusions, so monitor for reuse of these credentials.Ransomware● 42
Ransomware Akira publica a la italiana DI.C.S.EL. S.R.L.The Akira group listed DI.C.S.EL. S.R.L., an Italian electrical and measurement solutions firm in Lombardy, claiming it will leak 9 GB of corporate data including employee IDs, driver's licenses, financials and NDAs. The victim is outside Latin America, but the publication is fresh and confirms an active intrusion with exfiltration. It is a useful TTP/targeting signal for defenders in the industrial and electrical sector.Ransomware● 48
Ransomware n0n publica al proveedor retail FinSoftThe ransomware group 'n0n' published FinSoft, a retail back-office software vendor whose Kolibri platform serves 10+ retail chains (keddo, marc, lancaster and others). Client databases with sales, stock, pricing and financial records leak one per day after the deadline. It is a fresh supply-chain-style breach affecting many downstream retailers.