BRIEFRansomwarehighP55
Silent Ransom group publishes US law firm Clark Hill
Clark Hill
Detected22 September 2026 · 23:43 UTC
Silent Ransom Group has listed Clark Hill, a large US law firm, as a ransomware victim. Law firms hold privileged, confidential client data, so a breach can disrupt litigation and expose sensitive information. Outside the region, but a notable active victim publication to track.
CategoryRansomware
Severityhigh
Priority score55
Detected22 September 2026 · 23:43 UTC
Ransomware● 76
ShinyHunters amenaza con filtrar datos de Fresenius Medical CareShinyHunters has listed Fresenius Medical Care, a major German healthcare and dialysis provider, threatening to publish sensitive data unless contacted by 25 Sep 2026. Ransomware against healthcare can disrupt clinical operations and exposes protected health information. Outside Latin America, but a fresh, high-impact victim worth tracking.Ransomware● 33
Ransomware Anubis publica a la alemana Gaedke & PartnerThe ransomware group Anubis published German accounting firm Gaedke & Partner Steuerberatung on its leak site, claiming a breach of client information. Tax and accounting firms hold sensitive financial and personal records, making them high-value targets and a supply-chain risk for their clients. The victim is small and outside Latin America, but it is a freshly published extortion claim.Ransomware● 88
Ransomware Titan publica al prestador de salud argentino HospifarThe ransomware group Titan has listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on its leak site. Healthcare is critical infrastructure and exposure of patient records carries regulatory and safety consequences. Argentine health entities should treat this as an active, time-sensitive incident.Ransomware● 55
Ransomware Kairos publica a Krapf Group, operador de transporte escolar de EE. UU.The Kairos ransomware group has published Krapf Group, a US transportation firm running 2,500+ school buses with 3,500 employees. The stolen data reportedly includes personal information of thousands of bus drivers, raising safety and privacy concerns for a large workforce. Freshly listed victims signal an active campaign worth tracking for TTPs and regional spillover.Ransomware● 42
Ransomware Qilin publica al local estadounidense The Fifty/50Qilin ransomware lists The Fifty/50, a US-based victim, on its leak site. No data volume or record count was disclosed yet, so impact is unclear. A fresh extortion listing signals an active incident that defenders may want to track for naming and TTPs.Ransomware● 50
Ransomware Akira reclama a la textilera TDMIAkira claims textile firm TDMI, threatening to release 33GB including employee SSNs, driver's licenses, passports, credit cards and client data. The mix of PII and financial data raises fraud and account-takeover risk. Track the leak for reuse of credentials and identity documents.