Skip to content

💼 Professional & Business Services

Legal, accounting, consulting, staffing, marketing, real estate services · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D8▼ −5
Prior 30D13
Active actor L90DQilin · 16
Active actor L90DINC Ransom · 5
Active actor L90DAkira · 4

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

SAP discloses "OVERPASS," a CVSS 10.0 buffer overflow in SAP Kernel's Extended Passport Protocol library — Onapsis estimates 10,000+ internet-facing SAP systems are exposed.CriticalTechnology & SoftwareProfessional & Business ServicesCVE-2026-44756 lets an unprivileged attacker run arbitrary OS commands with administrative privileges, fully compromising the SAP host and the business data on it. No in-the-wild exploitation confirmed yet, but the flaw affects a wide kernel-version range (7.22 through 9.20) and internet exposure at this scale makes it a KEV-catalog candidate the moment PoC code surfaces. Patch immediately rather than wait for that signal. BleepingComputer · cybersecuritynews.com
N-able N-central CVE-2026-86218 (CVSS 10.0) — pre-auth RCE in RMM platform, exploited before the Sep 5 hotfix shippedCriticalTechnology & SoftwareProfessional & Business ServicesA static code-injection flaw lets an unauthenticated attacker execute arbitrary code with root-level control on the N-central server. N-able's customer notice said the flaw "has been observed being exploited in the wild," and it is the vendor's third zero-day in six weeks. Shadowserver counted roughly 1,500 internet-facing N-central servers, concentrated in the US and Europe. Because a single MSP typically manages hundreds of client networks from one N-central console, a breach here is a supply-chain event, not an isolated incident — on-premises deployments still on Hotfix 3 must apply Hotfix 4 (build 2026.3.1.14) immediately. Help Net Security · Huntress
ConnectWise ScreenConnect file-transfer flaw enables worm-like malware spread across MSP client networks — CVE and fix due this weekHighProfessional & Business ServicesTechnology & SoftwareHuntress documented three unrelated incidents (Quick Assist tech-support scam, phishing MSI installer, fake Geek Squad refund lure) all converging on the same four-stage VBScript chain that installs rogue ScreenConnect clients and propagates to newly connected hosts — cryptomining, tunneling, and security-control tampering payloads observed. ConnectWise confirmed the file-transfer flaw affects both Cloud and On-Premise deployments in a Sep 3 advisory and recommends disabling technician file transfers until a fix ships. Help Net Security · The Hacker News
Additional DLS claims Sep 7: Lightcast (US, HR/labor-market software) claimed by Direwolf; United Group (India, diversified conglomerate) claimed by newly-emerged group Vexy; Master Manufacturing (US, metal stamping) claimed by Dark Project with 36GB allegedly exfiltrated.HighProfessional & Business ServicesIndustrials & Manufacturing🟥 All unverified DLS claims; verify before treating as breaches. RedPacket Security
The N-able N-central zero-day is a reminder that RMM platforms are now systemic infrastructure, and the market has not priced that risk correctly.CriticalTechnology & SoftwareProfessional & Business ServicesA single compromised console reaching hundreds of downstream client networks is functionally identical to a nation-state's preferred "one access point, many targets" playbook — except here the access point is a commercial product with 1,500 internet-facing instances and no operator-level segmentation requirement. This is the same structural weakness that made SolarWinds and, more recently, ConnectWise attractive footholds: the MSP model concentrates trust in a small number of vendors that most portfolio companies never audit directly. Insurers and PE diligence teams underwriting companies that outsource IT management should be asking which RMM platform their vendor runs and how quickly it patches, not just whether the vendor itself has a security program. Help Net Security
SilentRansomGroup — three US AmLaw law firms claimed in three days; attorney-client privilege data at riskHighProfessional & Business ServicesSilentRansomGroup posted Holland & Knight (Sep 1), Greenberg Traurig (Sep 2), and Katten Muchin Rosenman (Sep 3) on its DLS in rapid succession. All three are major US-headquartered Am Law 100 or Am Law 200 firms with significant M&A, IP, regulatory, and litigation practices. The group has threatened data publication unless contact is made. 🟥 All three DLS claims; data scope and authenticity unverified. Contact with sensitive corporate, litigation, and government-facing client data is the primary risk. DeXpose / Greenberg Traurig · RedPacket / Katten Muchin · HookPhish / Holland & Knight
SilentRansomGroup — confirmed as active US law firm extortion actor; three Am Law claims Sep 1–3HighProfessional & Business ServicesSilentRansomGroup appears to operate a targeted law-firm vertical, systematically posting large US firms with complex client data. The three-claim cluster in 72 hours is consistent with a coordinated campaign against a specific sector, not opportunistic individual attacks. The group's MO (DLS listing + contact-or-publish ultimatum) mirrors established RaaS playbooks. No CISA advisory yet.
SilentRansomGroup's coordinated targeting of three Am Law firms in 72 hours is the clearest indication yet that a ransomware operator has explicitly prioritised attorney-client privileged data as a separate, higher-value extortion commodity.HighProfessional & Business ServicesGreenberg Traurig, Holland & Knight, and Katten Muchin Rosenman collectively hold privileged communications, litigation strategy, M&A deal documents, and regulatory filings for hundreds of Fortune 500 and government clients. A group that publishes this data does not merely breach a law firm — it potentially pierces attorney-client privilege for every client whose matter is in the exfiltrated files. The reputational and legal-liability exposure for affected firms is structurally different from a healthcare or retail breach. Law firm clients with active litigation, ongoing M&A transactions, or pending regulatory proceedings should be assessing whether their counsel's matter files are in scope. DeXpose · HookPhish
Qilin — continues rank 1; Complete Packaging Solutions (UK) added to DLS Sep 3; YTD pace unchanged at 546CriticalProfessional & Business ServicesQilin posted Complete Packaging Solutions, a UK business services provider, on September 3. The group maintains approximately 140 victims/month pace. YTD: 546 victims; L3M: 335. The ATF major-incident claim (Aug 26) remains under DOJ investigation. 🟥 DLS claim for Complete Packaging Solutions; verify before treating as a breach. DeXpose

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 07 Lightcast Direwolf Ransomware · hr software · US US-based provider of human resources / labor-market analytics software; Direwolf DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/direwolf-ransomware-victim-lightcast/
Sep 04 Blanco & Etcheverry Gunra Ransomware · law/professional services · Uruguay Uruguayan law firm (~$5M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/QmxhbmNvICYgRXRjaGV2ZXJyeUBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-blanco-etcheverry/
Sep 03 Complete Packaging Solutions Qilin Ransomware · Professional Services · UK Qilin DLS claim Sep 3 2026; UK business services and packaging solutions provider. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/qilin-ransomware-targets-complete-packaging-solutions/
Sep 03 Katten Muchin Rosenman SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 3; full-service US law firm; data scope and authenticity unverified. · Sources: https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-katten-muchin-rosenman/
Sep 02 Greenberg Traurig SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 2; data scope and authenticity unverified; threat to publish if no contact made. · Sources: https://www.dexpose.io/silentransomgroup-compromises-greenberg-traurig/
Sep 01 Holland & Knight SilentRansomGroup Ransomware · law firm · US Am Law firm claimed by SilentRansomGroup; DLS Sep 1; data scope and authenticity unverified; threat to publish if no contact. · Sources: https://www.hookphish.com/blog/ransomware-group-silentransomgroup-hits-holland-and-knight/

August 2026

Aug 29 LAPoco Architects Qilin Ransomware · Professional Services · USA Qilin DLS claim Aug 29, 2026; architecture firm; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 23 Aurore Development S.p.A. Qilin Ransomware · Professional Services · Italy Italian business services company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-targets-aurore-development-s-p-a-in-ransomware-attack/
Aug 10 ATMS & Co. LLP INC Ransom Ransomware · Professional Services · IN Chartered accountant firm; INC_RANSOM DLS posting August 10, 2026; part of INC's SonicWall SMA 1000 exploitation campaign (CVE-2026-15409/CVE-2026-15410 CVSS 10.0); data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 09 Studio Associato Tibaldi Unknown Ransomware · Professional Services · ITA DLS claim posted August 9 on ransomware.live; Italian professional firm based in Rome; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 08 Louisville Bar Association INC Ransom Ransomware · Legal / Professional Association · US INC Ransom DLS claim August 8 2026; Kentucky-based legal professional association; consistent with INC Ransom sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed · Sources: https://www.ransomware.live/group/incransom
Aug 07 Morguard Corporation Helix Ransomware · Real Estate · CA Helix ransomware group (emerged July 2026; Microsoft OAuth/SharePoint data exfiltration, no custom malware) posted DLS claim Aug 7; 160GB claimed exfiltrated; negotiations broke down. Helix uses voice phishing and OAuth abuse targeting SharePoint. · Sources: https://ransomware.live/id/TW9yZ3VhcmRASGVsaXg=
Aug 06 Signature Services Play Ransomware · Business Services · US Play ransomware DLS listing, Aug 6 2026; files encrypted, data exfiltrated · Sources: https://ransomware.live/id/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=
Aug 02 Encore Enterprises CRPxO Ransomware · Real Estate · US CRPxO DLS claim August 2 2026; US commercial real estate firm; attacker claims 700 GB exfiltrated. No victim statement; data not yet published. · Sources: https://www.ransomware.live/id/RW5jb3JlIEVudGVycHJpc2VzLCBJbmMuQENSUHhP
Aug 01 Questel SAS ShinyHunters Extortion · Intellectual Property Management · France ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 21M+ Salesforce records plus 147 GB internal corporate data; Questel is a major IP and patent management firm serving global enterprise clients; no statement from Questel; data not yet published · Sources: https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/ https://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/

July 2026

Jul 29 Accenture 888 Ransomware · Professional Services / Consulting · US Threat actor 888 (PwnForums) claimed theft of 35 GB including Azure DevOps source code, Azure access keys, tokens, RSA/SSH keys, and config files; Accenture confirmed incident was contained with no operational impact; disclosed approximately July 29 2026 · Sources: https://www.securityweek.com/accenture-confirms-data-breach-after-hacker-claims-source-code-theft/ https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
Jul 27 Ernst and Young ShinyHunters Extortion · Professional Services · US Supply-chain compromise of third-party IT service management platform Mar 28-Apr 12 2026; yielded credentials to EY Jira, GitHub, Azure; client tax documents with SSNs and financial data; July 31 2026 deadline issued · Sources: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Jul 25 Jubilee Jobs Qilin Ransomware · Business Services/Staffing · Unknown DLS posting July 25 2026 by Qilin. Employment/staffing services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25 The Myers Y Cooper Qilin Ransomware · Professional Services · Unknown DLS posting July 25 2026 by Qilin. Professional services firm; sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25 Health Law Advocates INC Ransom Ransomware · legal-nonprofit · US Boston non-profit legal organization; INC Ransom DLS posting July 26 2026, estimated attack date July 25; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.ransomware.live/
Jul 15 Ernst & Young (EY) Unattributed Breach · professional services (accounting/consulting) · United Kingdom EY disclosed on July 15 that client data was accessed via a compromised third-party IT support platform used for UK client engagements; breach window estimated March-April 2026; exposed data includes client tax records, investment data, and Social Security Numbers for affected individuals; EY notified affected clients directly; investigation ongoing with external forensics; no ransomware group has claimed the breach; attack vector believed to be credential theft at the third-party vendor · Sources: https://www.bleepingcomputer.com/news/security/ey-discloses-data-breach-exposing-client-tax-and-financial-records/
Jul 13 Allied Plumbing Heating & Cooling Qilin Ransomware · services · US HVAC/plumbing services company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 13 Access Group International DragonForce Ransomware · business services · US Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 12 Century Equities Qilin Ransomware · real estate · US Real estate company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 11 Alan F. Burke CPA Qilin Ransomware · accounting · US Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 The Schuett Companies Qilin Ransomware · real estate · construction/US Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 Sintax Qilin Ransomware · legal services · Belgium Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 08 HIVE360 DragonForce Ransomware · HR · payroll services/UK DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08 PCCC Realty LLC NightSpire Ransomware · real estate · US NightSpire DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/nightspire · Sources: [ransomware.live]
Jul 08 Greenbotz Everest Ransomware · services · unknown region Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 07 Chisholm, Persson & Ball, PC Akira Ransomware · legal · law firm/US Akira DLS claim July 7, 2026; 45 GB claimed including client passports, visas, SSNs, court files, and police reports; data scope unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-akira-hits-chisholm-persson-and-ball/ · https://www.ransomware.live/group/akira · Sources: [HookPhish] · [ransomware.live]
Jul 06 Wood Ellis & Wood CPA Qilin Ransomware · professional services · accounting/US Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-wood-ellis-wood-cpa/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 Max Fordham Qilin Ransomware · professional services · building engineering/UK independent building engineering consultancy (MEP/sustainability; clients include museums, schools, housing); Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-max-fordham-in-uk-cyberattack/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06 CSEC RATP The Gentlemen Ransomware · services · France The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 02 Amtivo SETTRA Ransomware · ISO certification · professional services/US ANAB-accredited ISO and management system certification body (formerly Orion, ASR, CMA, Audit3, QSR, ISA in North America); offers ISO 9001, 14001, 27001, 45001 certification and training; SETTRA DLS claim July 1–2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071991911431426416 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jul 02 X-Copper Professional Corporation MoneyMessage Ransomware · legal services · Canada Canadian law firm specialising in traffic ticket defence, minor criminal charges, and licence-related legal matters; MoneyMessage DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ · Sources: [hendryadrian.com]
Jul 01 Dennis Waters Rental Properties Qilin Ransomware · real estate · US residential rental property company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Laughlin Nunnally Hood & Crum Qilin Ransomware · legal services · US US law firm; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Gies Dienstleistungen LockBit Ransomware · facility management · Germany German facility management and building services company; LockBit 5.0 DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 CBAssociates Icarus Ransomware · professional services · unknown Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01 Orion Registrar Inc. SETTRA Ransomware · certification body · professional services/US US-based management system certification registrar; SETTRA DLS claim June 30–July 1, 2026; claimed exposure of sensitive financial documents; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-targets-orion-registrar-inc/ · Sources: [DeXpose]
Jul 01 Dolrad MedusaLocker Ransomware · services · UAE 69 emails claimed exfiltrated; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-dolrad/ · https://ransomware.live/id/RG9scmFkQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]

June 2026

Jun 30 KALIACT ANCHETA et Associés Qilin Ransomware · legal services · France French legal advisory firm; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/kaliact-ancheta-et-associs-67e467e9 · https://www.ransomware.live/id/S0FMSUFDVCBBTkNIRVRBIGV0IEFzc29jaXNAcWlsaW4 · Sources: [SOCRadar] · [ransomware.live]
Jun 30 Advanced Business Systems Akira Ransomware · office solutions · technology/US regional office technology solutions and managed services provider; Akira DLS claim June 30, 2026; 31 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jun 30 Melcor Developments Ltd The Gentlemen Ransomware · real estate · construction/Canada diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30 Brooklyn Defender Services Genesis Ransomware · legal services · US New York City public defender organization providing legal representation to low-income individuals; Genesis DLS claim June 30, 2026; estimated attack date June 23, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30 Ilex Paysages et Urbanisme SETTRA Ransomware · landscape architecture · urban planning/France distinguished French landscape architecture and urban planning firm; SETTRA DLS claim June 30, 2026; estimated attack date June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-attack-targets-ilex-paysages-et-urbanisme/ · https://www.redpacketsecurity.com/settra-ransomware-victim-ilex-paysages-com/ · https://www.ransomware.live/id/aWxleC1wYXlzYWdlcy5jb21Ac2V0dHJh · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30 Cedrick Frank Associates SETTRA Ransomware · professional services · US SETTRA DLS claim June 30, 2026; sector and data scope unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 26 callhorton.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 johndufourlaw.com INC Ransom Ransomware · legal services · US personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26 Ingerman Chaos Ransomware · multifamily housing · real estate/US multifamily developer and property management company; Chaos DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/chaos-strikes-ingerman-in-ransomware-attack/ · https://www.redpacketsecurity.com/chaos-ransomware-victim-ingerman-com/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26 Hokua Suites AiLock Ransomware · real estate · luxury residential condominium/US upscale resort-style ocean-view residential condominium on the Oahu coast; AiLock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ailock-ransomware-group-attacks-hokua-luxury-condominiums/ · https://www.redpacketsecurity.com/ailock-ransomware-victim-hokua/ · https://www.ransomware.live/id/SG9rdWFAQWlMb2Nr · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 25 JMS Southeast Akira Ransomware · business services · industrial distribution/US temperature measurement and control products distributor (thermocouples, RTDs, thermowells, transmitters); Akira DLS claim June 25, 2026; ~25 GB claimed including employee PII (names/addresses), payment data, NDAs, project contracts, agreements with government entities, and customer information · https://www.redpacketsecurity.com/akira-ransomware-victim-jms-southeast/ · https://malware.news/t/akira-ransomware-attack-targets-jms-southeast/108233 · Sources: [RedPacket Security] · [malware.news]
Jun 25 BDS CZ The Gentlemen Ransomware · real estate · Czech Republic Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25 Delegal Poindexter & Underkofler, P.A. Morpheus Ransomware · legal · employment law/US employment law firm; Morpheus DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-morpheus-hits-delegal-poindexter-and-underkofler-p-a/ · https://www.dexpose.io/morpheus-ransomware-targets-delegal-poindexter-underkofler-p-a/ · Sources: [HookPhish] · [DeXpose]
Jun 22 Klue Icarus Ransomware · market intelligence · Canada OAuth integration credential compromised June 11-12; malicious code pushed to harvest customer OAuth tokens; Salesforce integrations revoked June 12; CrowdStrike engaged for IR · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [SecurityWeek] · [BleepingComputer]
Jun 21 JAG Group Stormous Ransomware · business services · US US-based business services company; corporate emails (@jaggroup.com), Active Directory domain logins with clear-text passwords, complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration data exfiltrated; full data dump published June 29, 2026 (new link posted after June 24 initial dump); estimated attack date June 20 · https://www.dexpose.io/stormous-ransomware-breach-exposes-jag-group-data/ · https://www.redpacketsecurity.com/stormous-ransomware-victim-jaggroup-com-update-full-data-dump/ · https://www.ransomware.live/id/amFnZ3JvdXAuY29tIFVQREFURS1GVUxMIERBVEEgRFVNUEBzdG9ybW91cw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 20 One Believing Interiors Nova Ransomware · interior design · US interior design studio specializing in built spaces including National Gallery projects; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-one-believing-interiors/ · https://www.ransomware.live/id/T25lIEJlbGlldmluZyBJbnRlcmlvcnNAbm92YQ== · Sources: [HookPhish] · [ransomware.live]
Jun 20 Preferred Properties Payload Ransomware · housing development · property management/US DLS claim June 20, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/payload-ransomware-victim-preferred-properties/ · Sources: [RedPacket Security]
Jun 19 ALS Global Limited Aur0ra Ransomware · testing · inspection/certification/Australia ASX-listed global testing, inspection, and certification firm (est. 1863; ~70 countries; mining, environmental, food safety, life sciences, materials testing); attack May 2026 (disclosed June 11 via ASX filing); Aur0ra DLS claim June 19, 2026; data published dark web June 22; 500+ employees' home directories including cached credentials; hundreds of plaintext password files; passport scans; bank account details; payroll data; workplace injury records; client laboratory results and analytical data; ALS confirmed breach, engaged cybersecurity specialists, and notified ACSC and relevant regulators · https://www.cyberdaily.au/security/13794-exclusi · https://www.dexpose.io/aurora-ransomware-strikes-als-global/ · https://www.breachsense.com/breaches/als-global-data-breach/ · Sources: [Cyber Daily] · [DeXpose] · [Breachsense]

← All industries · Victim database →