Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale8
- Ransomware31
- Leak85
- Stealer0
- Other1
Window
Category
Severity
Ransomware Wallstreet publica datos del municipio de Andover, Massachusetts
Town of Andover, Massachusetts (USA)
The Wallstreet ransomware group listed the Town of Andover, Massachusetts, a U.S. municipal government, as a victim. Municipal data, including citizen records and infrastructure details, may be exposed. Although outside Latin America, this fresh ransomware victim is relevant for tracking current ransomware activity.
Ransomware Falcon publica a DistributionNOW (distribuidor de energía de EE. UU.)
DistributionNOW
Falcon ransomware claims 344 GB exfiltrated from energy distributor DistributionNOW, including financial records, SCADA gateway backups, and PLC logic. Loss of OT-related data indicates potential impact on industrial operations. This case is relevant to Latin American energy and critical infrastructure sectors as a warning of similar attack patterns.
Ransomware Falcon publica a Globus Medical (fabricante de dispositivos médicos de EE. UU.)
Globus Medical
Falcon ransomware claims to have exfiltrated 2.96 TB from medical device maker Globus Medical, including customer records, FDA submissions, and product complaint logs. The incident exposes sensitive healthcare and regulatory data, raising supply-chain concerns. Even though the victim is in the US, this type of attack highlights TTPs relevant for Latin American healthcare and critical infrastructure defenders.
Ransomware Qilin publica a la constructora qatarí Black Cat Engineering
Black Cat Engineering Construction Wll
Qilin ransomware has added Black Cat Engineering Construction Wll, a Qatari manufacturing/construction company, to its leak site. The publication may expose project documents and corporate data. This fresh ransomware incident highlights the group's ongoing activity in the Gulf region.
Ransomware Qilin publica a la consultora británica Absolute Consultancy Services
Absolute Consultancy Services
Qilin ransomware has published Absolute Consultancy Services, a UK-based professional services firm. The leak may include client data and corporate documents. This is a fresh victim post, indicating active ransomware operations targeting the professional services sector.
Ransomware Qilin publica a la farmacéutica Crystalpharmatech
Crystalpharmatech
The Qilin ransomware group has added Crystalpharmatech to its leak site. The company is in the healthcare sector, and the publication likely includes sensitive corporate and possibly patient-related data. This is a fresh ransomware incident that requires immediate attention.
Filtración de 1 TB de datos técnicos de i-one (Corea del Sur)
i-one
The South Korean auto parts maker i-one was listed by the Black X ransomware group, which claims to have exfiltrated 1 TB of technical data, including drawings and supply chain information. The exposure of industrial intellectual property is critical for the company and its customers. Organizations should verify if this campaign affects their supply chain.
Filtración de datos de millones de clientes de FE Credit (Vietnam)
FE Credit
FE Credit, a Vietnamese financial institution, was published by the Black X ransomware group, which claims to hold personal data of millions of customers. The exposure of a financial database at this scale could enable large-scale fraud and targeted phishing. This warrants monitoring and CERT coordination.
Fábrica de Rodamientos FRM (Brasil) listada por ransomware zawoo
FRM - Fábrica de Rolamentos e Mancais Ltda
The Brazilian bearing manufacturer FRM was listed as a victim of the zawoo ransomware group, indicating a recent compromise and possible data theft. This is a fresh ransomware victim in Latin America, and industrial organizations in the region should check for exposure to this campaign.
Ransomware Qilin publica a la empresa estadounidense Bandit Industries
Bandit Industries
Ransomware group Qilin published Bandit Industries, a US company, on its leak site. The entry is fresh on ransomware.live, indicating an active campaign. Although the victim is outside Latin America, it confirms Qilin's current operations and can inform defensive monitoring for similar attacks in the region.
Ransomware Qilin publica a AUM Construction
AUM Construction
The Qilin ransomware group has published AUM Construction as a victim on its leak site. The company is a US-based manufacturing firm, and the breach may involve data theft and operational disruption. While not in Latin America, it signals Qilin's active targeting of manufacturing and should prompt defenders to assess similar exposure in the region.
Ransomware Rhysida publica datos de Valley Health Team
Valley Health Team
The Rhysida ransomware group has published what it claims is Valley Health Team's data, including 9 million files (3.28 TB) with 160,870 patient records and 7.6 million unencrypted EHR scans, plus financial and tax documents. This is a confirmed healthcare data breach with sensitive medical and personal information exposed. Affected individuals face identity theft and privacy risks, and the organization needs immediate incident response.
Nueva víctima de Silent Ransom Group (nombre pendiente de divulgación)
The Silent Ransom Group has published a redacted ransomware victim entry with the full data timer already active, indicating an imminent or fresh leak. The victim's name, country, and sector are still hidden, so the impact cannot be fully assessed. Monitor the group's leak site for the full disclosure and prepare incident response if the victim is identified as relevant.
Ransomware iah6477 publica datos de Mat Holdings Inc
Mat Holdings Inc
The US manufacturing company Mat Holdings Inc has been listed on a ransomware data-leak site by the group iah6477, with 148.2 GiB of data claimed to be published. Although the victim is outside Latin America, this is a fresh ransomware incident that may indicate the group's current targeting. Monitoring the leaked data is advisable to identify any impact on business partners or supply chain.
Ransomware Qilin publica a la financiera canadiense Northern Leasing Systems
Northern Leasing Systems
Qilin listed Northern Leasing Systems, a Canadian financial services company, on its leak site, signaling a confirmed ransomware incident. The financial sector impact raises the risk of sensitive customer data exposure. Immediate defensive review and communication with sectoral CERTs is recommended.
Ransomware Qilin publica a la empresa estadounidense California Truck Equipment
California Truck Equipment
Qilin has added California Truck Equipment, a US transportation company, to its ransomware leak site. This confirms a recent compromise and likely data exfiltration. Transportation organizations should review their defenses and watch for similar ransomware activity.
Ransomware Qilin publica a la empresa británica Metal Conversions
Metal Conversions
The Qilin ransomware group has listed Metal Conversions, a UK-based manufacturing company, on its leak site. The publication indicates the company was compromised and sensitive data may have been exfiltrated. Although not in Latin America, the victim should be monitored and relevant parties should be notified.
Ransomware Aurora expone código fuente de ShipERP (ERPIS LLC)
ERPIS LLC (ShipERP)
Aurora ransomware claims to have breached ERPIS LLC (ShipERP), a Texas-based SAP integrator serving Boeing, Pfizer, NVIDIA, and other major enterprises. The leak allegedly includes full source code across all versions of ShipERP, the company's main revenue asset, plus potential customer data. This is a high-impact software supply-chain incident, though not in Latin America.
Ransomware Qilin publica a WireCo (manufacturera de EE. UU.)
WireCo
WireCo, a US manufacturing company, has been posted by the Qilin ransomware group. The compromise likely includes exfiltration of corporate data and operational disruption. It is not in the Latin American region, reducing its priority for local defenders.
Qilin ransomware publica a ATF, agencia del gobierno de EE. UU.
ATF
Qilin has listed ATF, categorized as US Government & Defense, on its ransomware leak site. If confirmed, this would be a significant breach of a federal entity, potentially involving sensitive government data. The impact is global due to the nature of the agency, though it does not directly target Latin America.
Ransomware Qilin publica a Integrex RCM (EE. UU.)
Integrex RCM
Qilin ransomware listed Integrex RCM, a US professional services firm, on its leak site. The specific data exposed is not yet detailed, but confirmed ransomware victims indicate potential data theft and network compromise. Outside Latin America, so lower priority, but still a real incident to track.
Ransomware OROVA publica al despacho contable taiwanés Bai-chi CPA
Bai-chi CPA Firm
The OROVA ransomware group has published Bai-chi CPA Firm, a registered Taiwanese accounting practice, on its leak site. The victim publication indicates a confirmed compromise and likely exposure of client financial data. While small and outside Latin America, it is a fresh ransomware victim relevant to third-party risk tracking.
Ransomware OROVA publica a la farmacéutica taiwanesa Arich Enterprise
Arich Enterprise Co., Ltd.
Arich Enterprise, a Taiwanese pharmaceutical distributor serving medical centers and pharmacies, has been published by the OROVA ransomware group. This indicates a confirmed ransomware compromise with potential business and supply-chain data exposed. The incident merits monitoring because of the critical healthcare sector and the victim publication being recent.
Ransomware OROVA publica a la empresa Central Florida Civil LLC
Central Florida Civil LLC
OROVA has listed Central Florida Civil LLC, a US underground utilities and site development company, on its ransomware victim site. This confirms a recent breach and likely exposure of company data. It is a smaller non-regional victim, but still requires tracking for data leaks and supply-chain impact.