Skip to content

🏭 Industrials & Manufacturing

Manufacturing, construction, engineering, aerospace & defense, agriculture, mining · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D12▼ −18
Prior 30D30
Active actor L90DQilin · 23
Active actor L90DThe Gentlemen · 12
Active actor L90DSETTRA · 10

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

This week's run of pre-auth RCE zero-days across N-able, MikroTik, ConnectWise, Adobe Commerce and now SAP, landing inside the same seven-day span as a record-breaking Patch Tuesday, is a capacity problem the defense industry has not priced.CriticalTechnology & SoftwareIndustrials & ManufacturingEach vendor individually is manageable; five simultaneous emergency-patch cycles across the infrastructure stack that MSPs, e-commerce operators and ERP shops all depend on is not. Security teams sized for a steady drip of monthly patching are structurally unable to absorb a week like this one without deferring something — and attackers know which categories of infrastructure (RMM consoles, edge network gear, ERP kernels) get deferred longest because they're hardest to take offline. Insurers underwriting operational-technology and ERP-dependent businesses should be pricing patch-cycle capacity, not just patch-cycle intent. BleepingComputer
Boston Scientific — no material change since Sep 7; shipping restoration continuing toward Piper Sandler's mid-September estimate.MediumHealthcare & Life SciencesIndustrials & ManufacturingMajor distribution centers have resumed shipping for most products; Cork remains at reduced capacity. No new intrusion activity reported since Aug 25. MedTech Dive
Metaencryptor claims ST Engineering — Singapore's state-linked aerospace and defense conglomerate — on its leak site Sep 7CriticalIndustrials & ManufacturingST Engineering operates across aerospace, smart-city, defense, and public-security segments, including as a UK Ministry of Defense-adjacent and US critical-infrastructure supplier (its TransCore subsidiary was separately claimed by Qilin in June). 🟥 DLS claim only; no data scope or authenticity confirmed. A confirmed intrusion at a defense-conglomerate scale would warrant government-level attention given ST Engineering's customer base. ransomware.live
Additional DLS claims Sep 7: Lightcast (US, HR/labor-market software) claimed by Direwolf; United Group (India, diversified conglomerate) claimed by newly-emerged group Vexy; Master Manufacturing (US, metal stamping) claimed by Dark Project with 36GB allegedly exfiltrated.HighProfessional & Business ServicesIndustrials & Manufacturing🟥 All unverified DLS claims; verify before treating as breaches. RedPacket Security
Leonardo's March acquisition of UK cybersecurity firm Becrypt, surfaced this run as part of routine M&A back-fill, is a small but telling data point in Europe's push toward sovereign cyber-defense capability.HighIndustrials & ManufacturingCybersecurityAn Italian state-linked aerospace-and-defense prime buying a British encryption and secure-device specialist that already serves UK Ministry of Defense programs keeps sensitive government-grade cryptography inside the NATO-aligned industrial base rather than leaving it exposed to acquisition by a non-European or less-vetted buyer. As European governments increase defense spending amid the Ukraine war and reassess dependency on non-European technology suppliers, expect more of this pattern: national defense primes absorbing small, mission-critical cyber specialists rather than relying on the open market. UK Defence Journal
Boston Scientific — Day 13 of recovery; no new adverse network activity; Cork manufacturing remains at reduced capacityMediumHealthcare & Life SciencesIndustrials & ManufacturingNo material change since Sep 6. Distribution shipping restored at major global centres; Cork site partially restored. CrowdStrike and third-party experts leading investigation confirm no new intrusion activity since Aug 25. Piper Sandler mid-September full-restoration estimate unchanged. 🟥 Threat actor and attack vector not publicly disclosed. Boston Scientific · SecurityWeek
Boston Scientific — Day 13 recovery; no new adverse network activity since Aug 25; mid-September full-restoration estimate unchangedHighHealthcare & Life SciencesIndustrials & ManufacturingNo material change from Sep 5. Shipping capabilities restored for the majority of product lines at major distribution centres globally; Cork manufacturing remains at reduced capacity. The Piper Sandler mid-September restoration estimate stands. 🟥 Threat actor and attack method not disclosed; no confirmed data exfiltration. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. Boston Scientific · SecurityWeek
Boston Scientific — day 12 recovery; Piper Sandler mid-September restoration estimate; no new network activity since Aug 25HighHealthcare & Life SciencesIndustrials & ManufacturingNo change in status since Sep 4. Cork manufacturing remains at reduced capacity; partial order processing resumed for select product lines. Mid-September is the Piper Sandler restoration estimate. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim; no data-exfiltration scope disclosed. Boston Scientific
EDIF S.p.A. / Aurora ransomware — Italian wholesale electrical-equipment distributor claimed Sep 4; attack estimated Aug 27HighIndustrials & ManufacturingAurora posted EDIF S.p.A. (Italian wholesale distributor of electrical equipment, plumbing, and lighting systems) on its DLS September 4. Exposed files reportedly include system passwords, certified email credentials, customer invoices, tax numbers, shipping records, CCTV configurations, databases, financial records, and a detailed 2024 financial report. Attack estimated August 27. 🟥 DLS claim; verify before treating as a breach. DeXpose · RedPacket Security
Boston Scientific — day 11 recovery; Piper Sandler projects full shipping restoration mid-September; CrowdStrike found no new network intrusion activity since Aug 25HighHealthcare & Life SciencesIndustrials & ManufacturingAs of Sep 3–4, Boston Scientific reports no new unauthorized activity since containment on August 25. Partial order processing has resumed for some product lines; Cork, Ireland manufacturing facility remains at reduced capacity. Piper Sandler's three-week recovery estimate from August 25 places full restoration around September 15. The company has not attributed the attack or disclosed data exfiltration scope. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing into next week. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim. SecurityWeek · Boston Scientific
Boston Scientific — partial order processing confirmed restored for select product lines (day 10); full recovery timeline still undisclosedHighHealthcare & Life SciencesIndustrials & ManufacturingBoston Scientific confirmed on Sep 2 that partial order processing and shipping has resumed for some product lines following the Aug 25 cyberattack; the Cork, Ireland cardiovascular manufacturing facility remains in reduced-capacity mode. CrowdStrike confirmed no new malicious network activity since containment; forensics focus is now on scoping data access. Hospital procurement planners for elective cardiac procedures (stents, defibrillators, EP catheters) should continue contingency sourcing planning. 🟥 Server Killers attribution remains an unconfirmed hacktivist claim. SecurityWeek
Boston Scientific — partial order processing expected to resume "this week" (day 9); CrowdStrike investigating; Server Killers attribution remains unconfirmedHighHealthcare & Life SciencesIndustrials & ManufacturingBoston Scientific's incident response team (CrowdStrike) reports no signs of malicious network activity since August 25, and the breach appears contained to some on-premises systems. The company expects to resume partial order processing and shipping for some product lines this week, but a full restoration timeline has not been given. The Cork, Ireland cardiovascular manufacturing facility (stents, defibrillators, electrophysiology catheters) remains in reduced-capacity mode. Hospital procurement planners for elective cardiac procedures should continue contingency sourcing. 🟥 Server Killers attribution remains an unconfirmed claim by the hacktivist group; Boston Scientific has not confirmed any attacker identity. SecurityWeek · Supply Chain Dive

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 07 ST Engineering Metaencryptor Ransomware · aerospace & defense · Singapore Singapore-based multinational technology, defence and engineering group (aerospace, smart city, defence and public security segments); Metaencryptor DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.ransomware.live/id/U1QgRW5naW5lZXJpbmdAbWV0YWVuY3J5cHRvcg==
Sep 07 United Group Vexy Ransomware · conglomerate · India Indian diversified business group (food ingredients, nutraceuticals, industrial machinery, infrastructure, fashion, digital branding, packaging, automotive accessories); Vexy DLS claim Sep 7, 2026; Vexy is a newly emerged group (first seen Sep 2026); data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/vexy-ransomware-ransomware-victim-united-group/
Sep 07 Master Manufacturing Co., Inc. Dark Project Ransomware · manufacturing · US Southern Indiana custom metal stamping, laser cutting, and wire bending manufacturer (founded 1970, IATF 16949 certified); Dark Project claims 36GB exfiltrated, including SQL databases with personal data and technical schematics; data-exfiltration claim, no encryption reported. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/dark-project-ransomware-victim-master-manufacturing-co-inc/
Sep 04 EDIF S.p.A. Aurora Ransomware · wholesale/electrical equipment · Italy Italian wholesale distributor of electrical equipment, plumbing, and lighting systems; Aurora DLS claim Sep 4, attack estimated Aug 27; exposed data includes system passwords, certified email credentials, customer invoices, tax numbers, shipping records, CCTV configurations, financial databases, and a detailed 2024 financial report; 🟥 DLS claim only; verify before treating as a breach · Sources: https://www.dexpose.io/aurora-targets-italian-wholesale-distributor-edif-s-p-a/ · https://www.redpacketsecurity.com/aurora-ransomware-victim-edif-s-p-a/

August 2026

Aug 29 Bandit Industries Qilin Ransomware · Manufacturing · USA Qilin DLS claim Aug 29, 2026; US industrial equipment manufacturer; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 26 Air International Thermal Systems Qilin Ransomware · Manufacturing · USA Qilin DLS posting Aug 26. Air International Thermal Systems is a US provider of thermal management and HVAC solutions for industrial and defense applications. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-air-international-thermal-systems/
Aug 26 Metal Conversions Qilin Ransomware · Manufacturing · USA Qilin DLS posting Aug 26. Metal Conversions is a US metals manufacturing company. Unverified DLS claim; no data samples published. · Sources: https://www.dexpose.io/qilin-ransomware-strikes-metal-conversions/
Aug 25 Johnson City Honda Global Secret Group Ransomware · Automotive · US Car dealership, Tennessee. DLS claim Aug 25. 🟥 Unverified DLS claim. · Sources: https://ransomware.live/
Aug 24 Espac The Gentlemen Ransomware · Construction · Chile Chilean construction company; The Gentlemen DLS claim Aug 24 threatening sensitive data exposure · Sources: https://www.dexpose.io/thegentlemen-ransomware-attack-on-espac/
Aug 21 NTE Italia Panzer Ransomware · Engineering / Telecommunications · Italy Panzer ransomware DLS claim August 21 2026; NTE Italia is an engineering and telecommunications service provider based in Catanzaro, Italy; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 19 Babcock Africa The Gentlemen Ransomware · Engineering / Asset Management · South Africa TheGentlemen ransomware DLS claim August 19 2026; Babcock Africa is a major engineering and asset management company serving critical infrastructure and heavy equipment across Africa; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://ransomware.live/id/QmFiY29ja0B0aGVnZW50bGVtZW4=
Aug 18 R&D Machine and Engineering DragonForce Ransomware · Aerospace & Defense · USA DragonForce ransomware group posted R&D Machine and Engineering (rdmachine.com) on its DLS Aug 18; US aerospace and defense manufacturer; sensitive engineering data threatened for release. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/dragonforce-strikes-r-d-machine-and-engineering/
Aug 13 General Electric Clop Extortion · Industrial / Aerospace · USA Clop listed GE on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed engineering data. GE has made no public statement. DLS claim — breach not confirmed. · Sources: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
Aug 12 B Wright Drywall Qilin Ransomware · Construction · CAN DLS claim by Qilin (Aug 11-13 posting); Canadian construction firm; scope and data volume unverified · Sources: https://www.ransomware.live/group/qilin
Aug 10 Astro Electroplating Qilin Ransomware · Manufacturing · US Qilin DLS posting August 10, 2026; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Chung Tai Shin Chemical Industry Co. Qilin Ransomware · Chemicals · TW Qilin DLS posting August 10, 2026; chemicals and manufacturing sector; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 AIMS Group The Gentlemen Ransomware · Conglomerate · AE TheGentlemen DLS posting August 10, 2026; UAE-based conglomerate; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 10 Actini Group KRYBIT Ransomware · Industrial Machinery · FR KRYBIT ransomware DLS posting August 10, 2026; French industrial machinery manufacturer; data scope unconfirmed · Sources: https://www.redpacketsecurity.com/krybit-ransomware-victim-www-actini-com/
Aug 08 Filtronic plc Qilin Ransomware · Manufacturing / Defence Electronics · UK Qilin DLS claim August 8 2026; UK-listed manufacturer of RF/microwave components for defence and telecoms infrastructure; no statement from Filtronic; data scope and impact unconfirmed · Sources: https://www.hendryadrian.com/ransom-filtronic-aug-2026/
Aug 08 Clausing Industrial Qilin Ransomware · Manufacturing / Machine Tools · US Qilin DLS claim August 8 2026; Michigan-based metalworking machinery manufacturer; no statement from Clausing; data scope and impact unconfirmed · Sources: https://www.ransomware.live/group/qilin
Aug 07 IEH Corporation Unknown Ransomware · Defense Manufacturing · US SEC cybersecurity disclosure; producer of components for military satellites, missiles, fighter jets; cyberattack discovered early August, containment actions taken · Sources: https://therecord.media/military-device-manufacturer-discloses-cyber-incident
Aug 04 Trulite Glass and Aluminum Solutions INC Ransomware Ransomware · Manufacturing / Glass and Aluminium · US INC Ransomware DLS claim August 4 2026; US glass and aluminium manufacturer; attack via SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410 CVSS 10.0); no statement from Trulite; data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 04 RUPP Spritzguss Qilin Ransomware · Manufacturing / Plastics · Germany Qilin DLS claim approximately August 4 2026; German plastics injection-moulding manufacturer; no statement from RUPP; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 01 Sigma Plastics Group Play Ransomware · Manufacturing · US Play DLS claim August 1 2026; major US plastics manufacturer. No victim statement; no data published. · Sources: https://www.redpacketsecurity.com/play-ransomware-victim-sigma-plastics-group/

July 2026

Jul 31 Hyundai Motor Türkiye CRPxO Ransomware · Automotive / HR Data · Turkey CRPxO DLS claim July 31: 1.5 GB of recruitment and personnel data including interview answers, evaluation scores, and tracking logs. Part of the broader July 31 CRPxO Turkish wave. 🟥 DLS claim only; no victim statement. · Sources: https://gbhackers.com/crpx0-ransomware-claims-hyundai-turkey-breach/amp/ · https://cyberpress.org/crpx0-ransomware-claims-hyundai-turkey-breach/
Jul 30 Indus Protech Solutions The Gentlemen Ransomware · industrial supply chain / MRO · India TheGentlemen DLS claim July 30, 2026; Chennai-based bulk MRO and supply chain services provider for global trade; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-indus-protech-solutions/ · https://www.ransomware.live/
Jul 30 MicroPhase Corporation The Gentlemen Ransomware · defense electronics / IT · US TheGentlemen DLS claim July 30, 2026; US defense electronics and IT company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 30 Kontact Consortium India INC Ransom Ransomware · engineering and manufacturing · India INC_RANSOM DLS claim July 30, 2026; Indian engineering and manufacturing company; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 29 Bretford Manufacturing Aurora Ransomware · Manufacturing · US Posted to Aurora ransomware DLS July 29; data scope unconfirmed · Sources: https://www.ransomware.live/
Jul 25 Guntert & Zimmerman Qilin Ransomware · Manufacturing · DE DLS posting July 25 2026 by Qilin. Guntert & Zimmerman manufactures heavy concrete paving equipment. Country inferred from name. · Sources: https://www.ransomware.live/
Jul 25 GURR Abdichtungstechnik GmbH Qilin Ransomware · Construction · DE German waterproofing/sealing technology firm. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 22 Nidec Corporation Blackfield Ransomware · manufacturing · JP Blackfield ransomware group claimed Nidec Corporation (major Japanese manufacturer of electronic components for automotive and computing sectors) on DLS July 22, 2026; M ransom demand; full encryption plus exfiltration model; 🟥 unverified DLS claim only · Sources: https://www.bleepingcomputer.com/
Jul 22 Ingersoll Rand Everest Ransomware · Industrial Manufacturing / HVAC · US Everest ransomware DLS claim posted August 8 2026, estimated attack date July 22 2026; attribution disputed — separate DeXpose report attributes incident to '0apt ransomware'; Ingersoll Rand has not issued a statement; this is at least their second ransomware-related incident of 2026 (ALP-001 March 2026) · Sources: https://x.com/FalconFeedsio/status/2079991407490851128 · https://www.dexpose.io/0apt-ransomware-attack-targets-ingersoll-rand/
Jul 21 Stadler Rail Everest Ransomware · manufacturing · Switzerland Everest data-theft gang breached supplier-shared data-exchange platform; CHF 10M (~2.3M) ransom demand rejected; criminal complaint filed; technical/manufacturing data targeted, no personal data claimed. Stadler refused to pay and terminated the compromised platform July 21-23, 2026. · Sources: https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
Jul 20 Caterpillar Inc. CoinbaseCartel Ransomware · manufacturing · US CoinbaseCartel (pure data-theft/extortion, no encryption; 160+ victims since Sept 2025) claimed Caterpillar Inc. July 20, 2026; initial access via credential reuse from infostealer logs; data scope unconfirmed; 🟥 unverified · Sources: DeXpose · HookPhish
Jul 20 Stroebel Gruppe SafePay Ransomware · manufacturing · Germany SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 19 Synergy Products Qilin Ransomware · manufacturing (industrial products) · United States Qilin DLS posting July 19; data claimed exfiltrated; unverified — no public statement from Synergy Products · Sources: https://www.ransomware.live
Jul 19 MER-AL Nova Ransomware · manufacturing (automotive components) · Turkey Nova DLS posting July 19; data claimed exfiltrated; unverified — no public statement from MER-AL · Sources: https://www.ransomware.live
Jul 18 D.MAG New Material Technology INC Ransom Ransomware · manufacturing (advanced materials) · China INC Ransom DLS posting July 18; data claimed exfiltrated; unverified — no public statement from D.MAG · Sources: https://www.ransomware.live
Jul 18 PCL Holding Public Co. Ltd RansomHouse Ransomware · Holding / Diversified · Thailand RansomHouse DLS claim; Thai holding company; estimated attack date July 18 2026; no statement from PCL; data scope unconfirmed · Sources: https://www.ransomlook.io/recent
Jul 16 Converting Equipment International Interlock Ransomware · Manufacturing · GB UK-based manufacturing company (converting equipment). Attack date July 16 2026; DLS posting July 2026. Data leaked to Interlock's Worldwide Secrets Blog. · Sources: https://socradar.io/free-tools/ransomware-intelligence/victims/converting-equipment-international-interlock-bc57bbfc
Jul 15 Ferrovial AiLock Ransomware · Infrastructure/Construction · Spain Global infrastructure and mobility operator claimed on AiLock DLS July 15; 147 compromised employees and 16 users listed, 106 third-party credentials. No public statement from Ferrovial. · Sources: https://ransomware.live/id/RmVycm92aWFsQEFpTG9jaw==
Jul 12 Carolina Agri-Power Qilin Ransomware · agriculture · US Agricultural equipment dealer claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 10 Robroy Industries Brain Cipher Ransomware · manufacturing · US US manufacturing company; Brain Cipher DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 09 IAC International Brain Cipher Ransomware · industrial services · US US industrial services company; Brain Cipher DLS claim July 9, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/braincipher · Sources: [ransomware.live]
Jul 08 S.J. Louis Construction Qilin Ransomware · construction · US Qilin DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/qilin · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Ample Surveyor Services DragonForce Ransomware · land surveying · professional services/unknown region DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08 Shelby Manufacturing de México KRYBIT Ransomware · manufacturing · Mexico KRYBIT DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/krybit · Sources: [SharkStriker] · [ransomware.live]
Jul 07 Excalibur Rentals Akira Ransomware · equipment rental · US Akira DLS claim July 7, 2026; 45 GB claimed including employee PII (SSNs, passports), contracts, and customer data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/akira-ransomware-strikes-excalibur-rentals/ · https://www.ransomware.live/group/akira · Sources: [DeXpose] · [ransomware.live]
Jul 07 RISE Architecture Akira Ransomware · architecture · US Akira DLS claim July 7, 2026; 57 GB claimed including employee PII, client files, financial records, and project documents; data scope unconfirmed; 🟥 unverified · https://www.galaxywarden.com/blog/breach/rise-architecture-akira-2026-07 · https://www.ransomware.live/group/akira · Sources: [GalaxyWarden] · [ransomware.live]
Jul 06 Precision Steel Services Qilin Ransomware · manufacturing · steel service center/US Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-precision-steel-services/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 Grupo Inteca Qilin Ransomware · construction · Mexico Qilin DLS claim July 6, 2026; internal files claimed exfiltrated; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 06 Ahmet Aydeniz Group APT73 Ransomware · conglomerate · Turkey APT73/Bashe DLS claim July 6, 2026; data scope and impact unconfirmed; APT73 noted for fabricating some high-profile claims — 🟥 unverified pending independent confirmation · https://www.ransomware.live/group/apt73 · Sources: [ransomware.live]
Jul 06 CNW Electronics Pte Ltd Unattributed Breach · manufacturing · electronics/Singapore PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 06 Apex Agro LLC Genesis Ransomware · agri-chemicals · US Genesis DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/genesis · Sources: [ransomware.live]
Jul 04 Chemco Qilin Ransomware · manufacturing · Canada Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Locati Architects Play Ransomware · architecture · construction/Australia Play DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/play · Sources: [ransomware.live]
Jul 04 Gold Standard Automotive Wallstreet Ransomware · automotive services · US Wallstreet DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 03 Estrutural Zortéa INC Ransom Ransomware · construction · Brazil Brazilian construction and infrastructure company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 Ferrum AG Anubis Ransomware · manufacturing · Switzerland one of the largest family-owned manufacturing companies in Switzerland; Anubis DLS claim July 3, 2026; Anubis now totals 91 claimed victims (11 in June alone); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/anubis · https://www.ransomlook.io/group/anubis · Sources: [ransomware.live] · [RansomLook]

← All industries · Victim database →