Underground · what matters today
The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.
Distribution by category · window
- Gov / Military5
- Access sale8
- Ransomware31
- Leak85
- Stealer0
- Other1
Window
Category
Severity
Ransomware Akira publica 60 GB de datos del bufete Davis & Ferber
Davis & Ferber
The Akira ransomware group published Davis & Ferber, a New York personal injury law firm, and claims to leak 60GB of corporate data. The leak includes passports, driver's licenses, SSNs, and other sensitive client information for nearly a thousand people. This is a significant fresh leak with high impact for the firm's clients.
Ransomware Qilin publica a Structured Settlement Capital LLC
Structured Settlement Capital LLC
Qilin ransomware has added Structured Settlement Capital LLC, a US financial services company, to its leak site. The exposure could affect sensitive financial and personal data of clients. This is a fresh ransomware victim that should be monitored for data release.
Ransomware Qilin publica a Consultores de Seguros
Consultores de Seguros
The Qilin ransomware group has posted 'Consultores de Seguros' on its leak site, claiming the theft of corporate data. The company appears to operate in the insurance/financial services sector and the Spanish-language name suggests it may be based in Latin America or Spain. This is a fresh ransomware victim and should be monitored for potential data leak, as financial services is a high-risk sector.
Filtración de 100 GB de Jones, Little & Co., despacho contable
Jones, Little & Co., CPAs, LLP
The Dark Project ransomware group published over 100GB of data allegedly from Jones, Little & Co., a US accounting firm, including financial records. Accounting firms hold highly sensitive client financial data, making this leak a serious risk for identity theft and fraud. This incident is significant despite being outside the region due to the sensitive nature of the data.
Ransomware Dark Project publica a la empresa Liberty Group
The Liberty Group
The Dark Project ransomware group has publicly listed The Liberty Group, a US moving and logistics company, as a victim. The group typically leaks stolen data on their darknet blog. While the company is not in Latin America, the leak of corporate data can expose employee PII and client information, and indicates the threat group's ongoing activity.
Ransomware DragonForce publica datos de la empresa brasileña Frato
Frato
DragonForce listed Brazilian company Frato on its ransomware leak site, exposing financial documentation, shareholder information, and employee/client personal data across the group. This is a recent Latin American ransomware victim that could impact business partners and customers. Defenders should watch for leaked data and ensure response plans are ready.
Ransomware DragonForce publica datos de la constructora argentina Criba
Criba
DragonForce published data allegedly from Argentine construction firm Criba, including financial documents and client files covering Argentina and Uruguay. The leak may expose sensitive personal and corporate data of employees and partners. Organizations in the Argentine construction sector should verify potential exposure and increase monitoring.