
Ransomware Hits Mexico and US in LATAM
KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM added victims in Mexico and the United States, with signs of regional expansion.
Sep 4, 2026 · 3 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM added victims in Mexico and the United States, with signs of regional expansion.
Sep 4, 2026 · 3 min

Greenberg Traurig appeared in multiple leak posts, but there is no official verification of a breach or of who was behind it.
Sep 4, 2026 · 2 min

The Justice Department said several named agencies were targets, not confirmed victims, in a campaign attributed to QTFY.
Sep 3, 2026 · 3 min

KRYBIT, LOCKBIT5, and INC Ransom added new victims, with most activity centered on the United States and fresh listings in 48 and 24 hours.
Sep 2, 2026 · 3 min

Security Arsenal linked new victims to CHAOS, DragonForce, KRYBIT, STORM and GLOBAL SECRET GROUP, including cases in the U.S.
Aug 31, 2026 · 3 min

Frato, neooftalmo.com.br and sysconth.com appear among new DragonForce and KRYBIT victims, with outside checks refining the claims.
Aug 29, 2026 · 3 min

A joint FBI, CISA and HHS notice says Medusa has hit more than 500 victims since 2021, with healthcare a frequent target.
Aug 28, 2026 · 3 min

ATF said an isolated system was affected and reported no signs of impact to eForms, its corporate network or other systems.
Aug 28, 2026 · 3 min

CoinbaseCartel, Storm, Qilin, DragonForce and SilentRansomGroup posted new victims in the US and Canada across health, finance
Aug 27, 2026 · 4 min

INCRANSOM, THEGENTLEMEN, METAENCRYPTOR and EVEREST added victims in the U.S. across health, finance, technology
Aug 25, 2026 · 3 min

CISA expanded its alert on Siemens S7 PLCs and said more than 100 water systems were hit in July, with limited but real impacts.
Aug 24, 2026 · 4 min

FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
Aug 22, 2026 · 2 min

Security Arsenal tracked new U.S. victims from DIREWOLF, COINBASECARTEL and XPL0ITRS across health, tech and professional services.
Aug 19, 2026 · 2 min

US agencies warned on Gunra, while Unlimited Technology Systems raised its breach tally to 3.8 million patients.
Aug 16, 2026 · 3 min

California’s Suisun City shut down its computer network after an attack disrupted 911 routing, police, fire and other services.
Aug 14, 2026 · 2 min

Change Healthcare, OSF Healthcare and Unlimited Technology Systems surfaced in recent ransomware and breach reports tied to U.S. health care.
Aug 13, 2026 · 2 min

Fraud complaints and related amounts rose in Argentina’s banking sector in H1 2026, according to the central bank.
Aug 11, 2026 · 2 min

Suisun City declared an emergency after a malware attack disrupted 911 and other essential services. The FBI and EPA also warned of water incidents.
Aug 10, 2026 · 2 min

OSF Healthcare settled with HHS OCR over a 2021 Nephilim-linked breach. A separate report names a possible INCRANSOM health victim.
Aug 7, 2026 · 2 min

Interlock added Gardiner Family Chiropractic to its victim list, alleging patient data and internal financial information were exfiltrated.
Aug 5, 2026 · 2 min

More than 30 Minnesota water systems and nine in Michigan were targeted, as the FBI and EPA warned of activity in at least seven states.
Aug 4, 2026 · 3 min

CISA and the FBI report a rise in OT attacks on water and wastewater systems, including lockouts and password changes in several states.
Aug 1, 2026 · 2 min

Shieldworkz, the IDB and Cryptonomist warn of growing pressure on OT/ICS in water, energy and manufacturing, with exposure in focus.
Aug 1, 2026 · 2 min

ransomware.live lists several U.S. local governments as alleged victims, while Minnesota says a coordinated attack hit more than 30 water systems.
Jul 31, 2026 · 3 min

Attacks on key U.S. health players disrupted claims, prescriptions and services. Ahhh Care appears in a possible ransomware case.
Jul 30, 2026 · 2 min

Coca-Cola confirmed a Fairlife attack that suspended U.S. production and led to a data breach. Anubis claimed the intrusion.
Jul 29, 2026 · 3 min

The Change Healthcare attack exposed how U.S. healthcare depends on a single intermediary and added an estimated $2.87 billion in losses.
Jul 28, 2026 · 2 min

The DOJ expanded a case over bulletproof hosting tied to LockBit, Cl0p, BlackSuit, Play and other ransomware groups.
Jul 21, 2026 · 2 min

US and allies warned of a Russia-attributed campaign exploiting routers with weak SNMP, default passwords and unpatched firmware.
Jul 19, 2026 · 2 min

Fairlife paused U.S. production after a ransomware attack. A later analysis linked the case to CitrixBleed 2.
Jul 19, 2026 · 2 min

The Treasury sanctioned First VPN Service and its administrator for facilitating ransomware operations, with hospitals among the cited targets.
Jul 18, 2026 · 2 min

Paraguay and the United States found Flax Typhoon on Paraguayan state networks after a joint review. Deputies asked for reports.
Jul 15, 2026 · 3 min

Karen Vardanyan pleaded guilty in Ryuk attacks on U.S. hospitals, bringing renewed scrutiny to ransomware's impact on healthcare.
Jul 11, 2026 · 2 min