<?xml version='1.0' encoding='UTF-8' ?>
<rss version='2.0'>
<channel>
<title>Ransom Feed | RSS Complete USA</title>
<link>https://ransomfeed.it/</link>
<description>Ransomware victims RSS<img referrerpolicy="no-referrer-when-downgrade" src="https://matomo.ransomfeed.it/matomo.php?idsite=1&amp;rec=1" style="border:0" alt="" /></description>
<language>en-us</language>
<item xmlns:dc='ns:1'>
<title>Alaska-Electrical-Apprenticeship</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35823</link>
<guid>917c276fa853b6397c173f6e45655496</guid>
<pubDate>Tue, 08 Sep 2026 13:27:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alaska-Electrical-Apprenticeship</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>055ae67f5504eccc30b7f5934c3a4759bc8f7786261e40f169a13605a3fd3687</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.alaskaelectricalapprenticeship.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MEI-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35818</link>
<guid>93e5b66752efa4d74abf04d1883484b4</guid>
<pubDate>Mon, 07 Sep 2026 22:20:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>MEI-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5427157ffecc90935f5b6e44d21405489c3fa2772290b9710d5f5da2256dd173</i><br /><br />Threat actor <b>description</b>: <i>About MEI Architects MEI Architects is a firm based in San Francisco that specializes in commercial, residential, and public architecture. They provide elegant and pragmatic solutions tailored for government, nonprofit, and private clients. Their portfolio includes notable projects such as the Portsmouth Square Improvement Project and the VA Palo Alto Polytrauma Aquatic Therapy Center. The firm is committed to community-minded design and successful partnerships. As a result of the attack, 340 GB of data (approximately 130,000 files) was stolen: including Social Security numbers, passports, green cards, invoices, HR documents, and a vast number of architectural drawings—including those from past and current projects, as well as those currently under construction.</i><br />Target victim <b>website</b>: <i>www.meiarchitects.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-of-San-Francisco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35814</link>
<guid>99efe6e00320edb6fac7ab90e845bb3e</guid>
<pubDate>Mon, 07 Sep 2026 21:55:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>University-of-San-Francisco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>071d7eae79bbc29cd62cee2e17b5581a7e1c0e1a988a02c16038225cf0e28164</i><br /><br />Threat actor <b>description</b>: <i>usfca.edu zoominfo.com/c/university-of-san-francisco/346496443 is San Francisco's oldest university — a private Jesuit institution founded in 1855, with ~10,200 students, a $428M endowment, and a 55-acre hilltop campus near Golden Gate Park (plus downtown, Pleasanton and Tokyo sites). A 13:1 student-faculty ratio and #1-ranked online professional studies graduate program anchor its academics; 34% first-gen, 55% students of color, 92% on financial aid — mission-driven access defines it. Athletics: Division I Dons (WCC) with 3 national titles — home of Bill Russell's legendary 1955–56 back-to-back NCAA basketball championships. New president Salvador Aceves (2025) — the first Latino in the role — and an R2 "high research activity" Carnegie classification. Tuition ~$62K with average grants of $38K+; alumni median salary $115K. Bottom line: a mission-driven urban Jesuit university blending social justice, elite basketball history and top professional programs — "Change the World From Here.</i><br />Target victim <b>website</b>: <i>usfca.edu</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35805</link>
<guid>b331255031b0f8e8d15360850e445151</guid>
<pubDate>Mon, 07 Sep 2026 21:52:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Metro</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e15b1b87a8749578c7fab51d553bc87b992d60a4137894fa367c7ca533a3a8e</i><br /><br />Threat actor <b>description</b>: <i>metro.net zoominfo.com/c/metro/351518795 LA Metro is the Los Angeles County Metropolitan Transportation Authority (LACMTA) — the second-busiest transit system in the US, serving 9.6M residents across 1,433 sq miles (nearly a third of California's population), founded in 1993 by merging SCRTD and LACTC. Its network: 125+ miles of rail (2 subway + 4 light-rail lines, 110 stations), 117 bus lines, 2 BRT corridors, 2,000+ low-emission buses and the Metro Micro on-demand service — moving ~925,000 weekday boardings and 305.7M riders in 2025 (9 straight months of growth, +9% YoY, 87% satisfaction). It's run by a 13-member board (5 county supervisors + the LA mayor's bloc, chaired politically by Mayor Karen Bass) and led by CEO Stephanie Wiggins — the first woman and first African American to head the agency — with a $9.7B FY2026-27 budget and a $26B capital program, the largest rail construction program in the US.</i><br />Target victim <b>website</b>: <i>metro.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ritz-Safety</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35803</link>
<guid>fac06a9b23f0f7b5f0b065a77d2d821f</guid>
<pubDate>Mon, 07 Sep 2026 21:52:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Ritz-Safety</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a2d8986035e73ec97c67c11e8547c55cea26f9fafd1be00269a6246f3e6f124</i><br /><br />Threat actor <b>description</b>: <i>ritzsafety.com zoominfo.com/c/ritz-safety-llc/82166398 Ritz Safety Americas largest privately-held PPE & safety equipment distributors — founded in 1983 in Pompano Beach, Florida by Emily Ritz and her son Peter Merkl, selling work boots and gloves from a truck, now HQ'd in Dayton, Ohio with ~220–250 employees and 17–18 locations nationwide. Hidden twist: in 2006 the family's uniform-rental empire Van Dyne Crotty was sold to Cintas — but the brothers Dan and Bob Crotty kept Ritz Safety out of the deal and built it into a roll-up consolidator: 9 acquisitions (2015–2022), 5,000+ customers monthly, access to 200,000+ SKUs, private-label lines, equipment rental/repair, custom embroidery and free on-site safety training. Revenue: $100–150M (2025: +12% = +$20M growth, best Q2 in the company's 42-year history), 100% family-owned (Crotty family), no PE. Bottom line: a family dynasty that lost its parent empire to Cintas but turned the "leftover" safety distributor into a new national powerhouse</i><br />Target victim <b>website</b>: <i>ritzsafety.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>State-of-Florida-DMV</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35796</link>
<guid>dde5579a8906300056f1dcad56021c59</guid>
<pubDate>Mon, 07 Sep 2026 20:07:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>State-of-Florida-DMV</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>546064b4fdf7d23472ea87d2ab519a79e89656dc2799ffb1430c3563db83059c</i><br /><br />Threat actor <b>description</b>: <i>Contact us, you know how. or we will release the files. View download button below for proof (samples). Deadline : 9 11 2026 | Updated: 07 Sep 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>NorthShore-Health-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35795</link>
<guid>4ee8ca7221edcc2b35ec18f8b251e4fd</guid>
<pubDate>Mon, 07 Sep 2026 19:32:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>NorthShore-Health-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3df6bd3a2d789c646306e7dae28d35f1e06819607c0a932b0299425acfa5bf2d</i><br /><br />Threat actor <b>description</b>: <i>NorthShore Health Centers offers comprehensive care in Indiana, including behavioral health, dental, pediatrics, and women’s health. It runs multiple health centers and mobile units across Porter, Lake, La Porte, and Jasper counties.</i><br />Target victim <b>website</b>: <i>www.northshorehealth.org</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wellness-Partners-networkcombined-revenue</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35794</link>
<guid>6d51a99b41cd166309b1f1be618e8bee</guid>
<pubDate>Mon, 07 Sep 2026 18:59:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Wellness-Partners-networkcombined-revenue</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61a5b441c61e648082939bc8f4b911a08b49f65744d458199cbaad71c90552bf</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in Clinton, New York Community Wellness Partners is a faith based non-profit organization that provides healthcare, housing and community services. They also have 24/7 skilled-nursing care to older adults who require residential medical care and support services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Master-Manufacturing-Co.-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35792</link>
<guid>d2ce0c8b91e51a6bbda34c4bdc43ee54</guid>
<pubDate>Mon, 07 Sep 2026 17:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Master-Manufacturing-Co.-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8c6872be53fa10d3a88028f42e4c845699a41e1f8839448872e29548d07d800</i><br /><br />Threat actor <b>description</b>: <i>About Master Manufacturing Master Manufacturing Co., Inc. specializes in custom metal stamping and production services, leveraging over 200 years of combined design and engineering expertise. Founded in 1970 and located in southern Indiana, the company offers a range of services including laser cutting, wire bending, and heat treatment, all while maintaining a commitment to high-quality standards certified by IATF 16949. Their intended clients span various industries such as appliance, HVAC, lighting, automotive, and RV, with a focus on delivering innovative and efficient solutions. Master Manufacturing prides itself on quick turnaround times and the ability to meet specific customer needs through early design involvement and advanced manufacturing techniques. Master Manufacturing Co specializing in custom metal stamping and production services has fallen victim to a significant cyberattack. Hackers reportedly exfiltrated 36 gigabytes of sensitive data from the company’s servers. The stolen information includes SQL databases containing personal data, as well as technical plans and schematics for custom metal parts. The breach raises serious concerns regarding intellectual property theft and potential privacy violations for employees and clients.</i><br />Target victim <b>website</b>: <i>www.mastermfg.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alurwalls</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35791</link>
<guid>d361ccc5d896dfbad0fecfc1fe7fc9a1</guid>
<pubDate>Mon, 07 Sep 2026 17:51:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Alurwalls</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad4cab532616eb0edae7de99b37daadac9fb530da1de5cf5b75e05095572b195</i><br /><br />Threat actor <b>description</b>: <i>About Alurwalls ALUR specializes in innovative glass wall systems, offering both single glazed and double glazed options. Their products are designed to create modern and functional workplace environments. ALUR's solutions are aimed at businesses looking to enhance their office spaces with stylish and efficient modular dividing walls. The company is recognized for its award-winning designs that contribute to the future of workplace architecture. Alurwalls was attacked, resulting in the theft of approximately 17 GB of confidential data. The stolen information includes banking and other financial documents, client building plans, and other personal data belonging to the company and its partners. Currently, more than 16,000 files are no longer protected by Alurwalls.</i><br />Target victim <b>website</b>: <i>www.alurwalls.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Vehicle-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35790</link>
<guid>2bfd7c7985715037980235d588dc2e9e</guid>
<pubDate>Mon, 07 Sep 2026 17:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Precision-Vehicle-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8ac9684674557e1fe48a4ce3df6f605b40e2d67e448bca0aa0e549e38b90726</i><br /><br />Threat actor <b>description</b>: <i>Freight &amp; Logistics Services</i><br />Target victim <b>website</b>: <i>precisionvehiclelogistics.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rug--Home</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35789</link>
<guid>efd33731692792594017105dc0931699</guid>
<pubDate>Mon, 07 Sep 2026 17:01:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Rug--Home</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d282405a7b58d84819b473f27ebbe97f78a4ab865c6eadfccdf3a63701abc4c0</i><br /><br />Threat actor <b>description</b>: <i>Rug & Home Rug & Home is a leading destination in the USA for rugs, furniture, and home decor, offering a vast selection of unique designs and top brands.Database of 50,193 customers�full names, home addresses, email addresses, phone numbers, purchase amounts (CSV)~10,800 scans�signed delivery notes with customer addresses/phone numbersPlaintext passwords for ~60 B2B supplier portalsW-2, 1099, W-9 � tax forms with employees' and contractors' SSNsPayroll database for all employees (Sage EMPLOYEE/ESWAGE)Company bank details (First Citizens Bank deposits) and employee accounts (direct deposit)HR: background checks, terminations, workplace injuries, 401(k)And much more    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>NFM-Lending</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35787</link>
<guid>ed6738f60889256f8dc7d9114f6ba525</guid>
<pubDate>Mon, 07 Sep 2026 15:31:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>NFM-Lending</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b476031cdae65c0c47b646a4d5abe8245b1368501e79b064cf27140c58ffd2f8</i><br /><br />Threat actor <b>description</b>: <i>NFM Lending is a national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages in the past 12 months. The data breach exposed over 2.5 TB of sensitive personal customer information (names, Social Security numbers, bank accounts, credit information, loan terms, addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports), as well as proprietary pricing/profit formulas, in violation of federal GLBA/FCRA, state privacy laws, and the CFPB's data breach reporting rules. You also have access to data from the Encompass database, which contains information on more than 1 million clients, as well as internal databases, an extensive database of tax forms, and employees' personal information.</i><br />Target victim <b>website</b>: <i>https:nfmlending.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>GGS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35786</link>
<guid>768ebda0321d58a46779869f1ac760ac</guid>
<pubDate>Mon, 07 Sep 2026 15:29:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>GGS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10be010e79ab275d7342eaa4f9167989f14df131c7337b1eb5e54697c87fded6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lightcast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35783</link>
<guid>f05c20c525af354f220fdbac1d0a948f</guid>
<pubDate>Mon, 07 Sep 2026 14:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Lightcast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66b29024a0d93a3db361a41ff89d9f3b14b56916784e2b5c2c41fdae7fbe6b99</i><br /><br />Threat actor <b>description</b>: <i>Human Resources Software</i><br />Target victim <b>website</b>: <i>lightcast.io</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jinny-Beauty-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35782</link>
<guid>b948738d336d9db9f94f39c9a3c5f877</guid>
<pubDate>Mon, 07 Sep 2026 14:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Jinny-Beauty-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e3a1955e5f8db7eaf32b1dde33432264d3c969241bb6da00068e489b05ad2a3</i><br /><br />Threat actor <b>description</b>: <i>[distributors] Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors.

The exposed material includes:

A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email.
VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure.
911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states.
Complete employee compensation database — ~260 employees with Korean and English names, departments, salaries, bonuses, and 1099 contractor data spanning 2015–2018.
A 340 MB Shopify database backup — full customer table (names, emails, phones, addresses), product catalog, pricing, and warehouse assignments.
Active Directory domain enumeration — all 239+ user accounts including 17 admin accounts, the complete server topology across 7 geographic sites (50+ servers), and DPAPI-encrypted RDP passwords.
Employee tax documents — W-4 forms (SSN), I-9 forms (SSN + DOB + citizenship), direct deposit forms (bank account and routing numbers).
3.6 GB of SQL Server database backups — e-commerce customer/order/product data spanning November 2019 to March 2020.</i><br />Target victim <b>website</b>: <i>Jinny Beauty Supply</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Benshaw-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35781</link>
<guid>c56efcb8461a609417ef9da0d6bb6eb3</guid>
<pubDate>Mon, 07 Sep 2026 13:52:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Benshaw-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87b37289eb6f410be6111769997f7d72c7712f6852fd304e8246ef92d4a56534</i><br /><br />Threat actor <b>description</b>: <i>[manufacturer, research] Benshaw, Inc. (Pittsburgh) and affiliated UTG entities (Unico, Benshaw Canada, AuCom, Excel, Noble Victoria).

~100+ corporate Visa/PCard records with full PAN + SSN + DOB + home address
637 former employees with full SSN/DOB/address on one spreadsheet
88 active employee folders plus multi-year Canada payroll
<redacted>
<redacted>
Global bank account numbers (PNC, BMO, BNZ, St George, Commerzbank, JPM London, BBVA, GNB…)
ACH NACHA files with vendor routing/account numbers
UEdit source with hardcoded XOR key 4148865678 and date-based CalcBackDoor()
Oil & gas customer job packs (Chevron, Petrobras, EOG, Santos AU, KOC…)</i><br />Target victim <b>website</b>: <i>Benshaw, Inc.</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Semper-Laser</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35780</link>
<guid>176d8075d8edfcba778b54b6749fe43c</guid>
<pubDate>Mon, 07 Sep 2026 13:26:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Semper-Laser</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f20b767185357166780cf098b50b8359dfab8a1194ef06c310f2142a6b753946</i><br /><br />Threat actor <b>description</b>: <i>Spa and Salon Management · Florida</i><br />Target victim <b>website</b>: <i>semperlaser.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>SIFCO-Industries-INC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35777</link>
<guid>a7921ea22e084f4c3f660b30749325c3</guid>
<pubDate>Mon, 07 Sep 2026 12:03:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>metaencryptor</b> claims attack for <b>SIFCO-Industries-INC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88757c8c6b1662b4e18e8ed4ec1b232eac050d5a03f2dd137ac0bc2f37185390</i><br /><br />Threat actor <b>description</b>: <i>SIFCO Industries is a world-wide provider of highly engineered forged components to the Aerospace, Energy and Defense markets. We supply flight-critical forged components and machined assemblies to all of the leading aircraft and engine manufacturers in the world. These components can be found on virtually all of the commercial and military fixed-wing aircraft as well as helicopters and business jets. Our products are also supplied to the leading steam and gas turbine manufacturers and oil producers serving the energy sector.</i><br />Target victim <b>website</b>: <i>sifco.com</i>]]></description>
<category>metaencryptor</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hologic-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35775</link>
<guid>dd27f2bc962dc976d5e3115fdc6120ce</guid>
<pubDate>Mon, 07 Sep 2026 12:01:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>metaencryptor</b> claims attack for <b>Hologic-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8aa377874d6a2122143a8a01189c10bdc7d92d50d551be147fa93d9dc0d6b5ca</i><br /><br />Threat actor <b>description</b>: <i>Hologic, Inc. is a U.S.-based medical technology company specializing in women’s health. It develops and manufactures diagnostic, imaging, and surgical products, with a strong focus on breast health, gynecology, diagnostics, and osteoporosis assessment.</i><br />Target victim <b>website</b>: <i>www.hologic.com</i>]]></description>
<category>metaencryptor</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ben-Leeds-Properties-WARNING</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35771</link>
<guid>a7c1aed2ae6b6ced5c3e83fb7c74d65d</guid>
<pubDate>Mon, 07 Sep 2026 03:52:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ShadowByt3$</b> claims attack for <b>Ben-Leeds-Properties-WARNING</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>85d635a989fed9260f5929bcbd057dc54f802dc96f02a528e18dade2b8c889ea</i><br /><br />Threat actor <b>description</b>: <i>We have emailed the following

la@benleedsproperties.com
nikki@benleedsproperties.com
21736Roscoe@benleedsproperties.com
3327livonia@benleedsproperties.com
Accounting@BenLeedsProperties.com
Support@BenLeedsProperties.com
Management@BenLeedsProperties.com

Reply back and negotiate or all data that we said was stolen gets published. If you comply and negotiate then we won't leak the data that we say we have and could tear down your reputation like dominos. Were not bluffing and this is not a drill we have what we say we have and we are willing to publish it and let everyone accross La and Hollywood know since it affects some people there. You have till wednesday September 9th 2026 due to labor day for USA Companies.</i><br />Target victim <b>website</b>: <i>benleedsproperties.appfolio.com</i>]]></description>
<category>ShadowByt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>eAssist-Dental-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35768</link>
<guid>a0b54f42bf035d7f3ee941e0fae94669</guid>
<pubDate>Sun, 06 Sep 2026 16:55:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>eAssist-Dental-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b38fc1c461d7624c2984d7e44a7dc6e848109dcd4e272953a623c91ec66de21f</i><br /><br />Threat actor <b>description</b>: <i>Healthcare</i><br />Target victim <b>website</b>: <i>dentalbilling.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>evergenbio.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35766</link>
<guid>22ab54f07ab77a9bfffd6bbeae5ac19d</guid>
<pubDate>Sun, 06 Sep 2026 13:25:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>evergenbio.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73f1476f5535adfe118beca7da1c49b161cb7d1b86dc1cb9338397a7ae6fc7dc</i><br /><br />Threat actor <b>description</b>: <i>Evergen is a leading Contract Development and Manufacturing Organization (CDMO) specializing in biomaterial solutions for regenerative medicine. We work closely with OEM partners to deliver customized biomaterial solutions that meet specific clinical needs</i><br />Target victim <b>website</b>: <i>evergenbio.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>myLaurel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35764</link>
<guid>6d378c1d7df74d165c6b2ff5e33baa3b</guid>
<pubDate>Sun, 06 Sep 2026 11:53:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>myLaurel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4138a96d6bc61733ddc2fa7678a341633a1ef3301209cec286f73a05d397506d</i><br /><br />Threat actor <b>description</b>: <i>Elderly Care Services</i><br />Target victim <b>website</b>: <i>mylaurelhealth.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mission-Pet-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35761</link>
<guid>79eeb8ca96eec65fecbd9603c2b07a48</guid>
<pubDate>Sat, 05 Sep 2026 21:54:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Mission-Pet-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d08213f200dd74e56558526b6c801a29c1b7d0fe3c910e13d1b5d12eaab8ab63</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>missionpethealth.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spirit-Cultural-Exchange---US</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35760</link>
<guid>b8e84f9489fe4b25c50e7dd450e4be5d</guid>
<pubDate>Sat, 05 Sep 2026 21:29:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kazu</b> claims attack for <b>Spirit-Cultural-Exchange---US</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c39a621a12f83164d28400ed48f1845c9a1cbee2dfdf9575bfb50dec1e9a0f51</i><br /><br />Threat actor <b>description</b>: <i>Spirit Cultural Exchange is a U.S.-based organization that provides international cultural exchange and J-1 visa programs for students, young professionals, teachers, and international participants. Its programs include Summer Work and Travel, internships, professional training, and teaching opportunities in the United States</i><br />Target victim <b>website</b>: <i>www.spiritexchange.com</i>]]></description>
<category>kazu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leo-Schachter-Diamonds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35759</link>
<guid>884a06e5988eb41cfbd466142929bffe</guid>
<pubDate>Sat, 05 Sep 2026 18:30:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Leo-Schachter-Diamonds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c9b0beab96598731226b67f63b4593e55648a2d2075e9781692237ae7924a36</i><br /><br />Threat actor <b>description</b>: <i>leoschachter.com Leo Schachter Diamonds (USA/Global)
Family diamond house since 1952, four generations; De Beers sightholder for 60+ years.
Invented the branded diamond (THE LEO at Kay/Jared, ~2,000 stores) — a diamond sold like a Nike sneaker.
Owns one of Botswana's largest cutting factories: 90% women, trained from scratch, plus its own doctor when 60% of staff were HIV-positive.
Crisis context: lab-grown diamonds are squeezing the whole natural industry — the moat is now brand + story, not just stones.</i><br />Target victim <b>website</b>: <i>leoschachter.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Veradigm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35757</link>
<guid>f6f658b6c7f13e833d7f81797e9a0869</guid>
<pubDate>Sat, 05 Sep 2026 18:29:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Veradigm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43a0ea55679e075e0bf8da0ecb9baaa3267f9118b339cba793d0f07706f9538e</i><br /><br />Threat actor <b>description</b>: <i>veradigm.com zoominfo.com/c/veradigm-llc/471134180 
3.5+ million personal patient records with PII  full name, address, social security number, email, address, phone number,guarantors PII ,Score Veradigm Inc. is a publicly traded American healthcare technology and data analytics company (OTC: MDRX), the former Allscripts, founded in 1986 and renamed Veradigm in January 2023, headquartered in Chicago with about 2,300–2,600 employees. Its core asset is one of the largest multi-EHR data networks in US healthcare — over 450,000 connected providers and 200M+ patient records — which it monetizes through three segments: Provider (EHR, practice management, revenue cycle: $473M in 2024), Payer (quality and risk adjustment analytics: $67.3M) and Life Sciences (real-world data and AI-driven evidence: $54M).</i><br />Target victim <b>website</b>: <i>veradigm.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bauman-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35752</link>
<guid>7fc34eee4c21d2e8aacb9bb7774a27ea</guid>
<pubDate>Sat, 05 Sep 2026 13:45:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bauman-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b47cbb714a69de0691885b1865538e62f8f2eff8c05b2c7f301e5138b5124b2e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.baumanlawgroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>GS-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35748</link>
<guid>a6cae5623d9d6b8ab35132faf5e02bc1</guid>
<pubDate>Sat, 05 Sep 2026 13:44:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>GS-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3249f691f8b2780ef5b2ffe76d48830943a4d04625f8703de0ce74be9aa6be0f</i><br /><br />Threat actor <b>description</b>: <i>Energy, Utilities & Waste</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nolan-Consulting-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35749</link>
<guid>9f8e4b84f731020330443ee756a01dc4</guid>
<pubDate>Sat, 05 Sep 2026 13:44:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Nolan-Consulting-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3781cdf1f226200aec77a36ff4e480d871d475b840d602edf568324c975afdaf</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colonial-Hyundai</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35750</link>
<guid>62e2d6c7039cae71d31bfb49b2226b6a</guid>
<pubDate>Sat, 05 Sep 2026 13:44:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Colonial-Hyundai</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da08d75d2d09b595533ff7dbf563f72da1a15c9e9351d222b2d3d58f411a551f</i><br /><br />Threat actor <b>description</b>: <i>Automotive Parts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metrea-LLCCommuter-Air-Technology-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35746</link>
<guid>8d401cff908d8a2ffabf660860c3aee1</guid>
<pubDate>Sat, 05 Sep 2026 09:53:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Metrea-LLCCommuter-Air-Technology-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a9148051bc74ec13e49befb2a745154ac8ddce17d0944f9437bbfc1896ea42a</i><br /><br />Threat actor <b>description</b>: <i>[defence] Metrea LLC (formerly Meta Special Aerospace, LLC) and its subsidiary Commuter Air Technology, Inc. (CAT) are US defense contractors providing Contractor Owned, Contractor Operated (COCO) ISR aircraft services to US Special Operations Command. They operate modified King Air 350 surveillance aircraft in Niger, East Africa, the Philippines, and other theaters.

<redacted>
339 MB of Harris PRC-117G military tactical radio firmware including compiled waveform binaries for SINCGARS, HAVEQUICK II, ROVER, and 10 other ITAR-controlled waveforms (USML Category XI).
Named deployment data for 14+ operators at Sable Spear sites in Niger and East Africa, with rotation schedules, SIPRNet access documentation, and divert airfield planning.
Complete SOCOM contract pricing portfolios — labor rates, burn rates, TINA-certified cost data, and subcontractor pricing for SOCPAC C3PO, Sable Spear, and Sable Dagger programs.
232 employee personnel files including resumes, W-9 forms (SSN), SERE training certificates, security clearances, expense reports, and deployment records.
NSWDG (SEAL Team Six), MARSOC, and 75th Rangers training exercise documentation — 37 separately funded SOCOM training deliveries under the Alpha 28 program.
<redacted></i><br />Target victim <b>website</b>: <i>Metrea LLC/Commuter Air Technology, Inc.</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>D-MAX-Engineering-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35742</link>
<guid>6d59dac9480611cf3e9e9b0d64ec2cff</guid>
<pubDate>Sat, 05 Sep 2026 04:29:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>D-MAX-Engineering-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b82cf186b458a8511593f887d9aba1251c5c2857d09779fc6ba0ba1ae735265</i><br /><br />Threat actor <b>description</b>: <i>D‑MAX Engineering, Inc. is a San Diego-based environmental consulting firm specializing in storm water services, particularly for governmental agencies.  Our multidisciplinary team includes environmental scientists, engineers, chemists, and biologists. Our team is experienced with the National Pollutant Discharge Elimination System (NPDES) permit requirements in Southern California.Since 1996, when the company was founded, we have completed numerous storm water projects for 18 municipalities in San Diego, Orange, Imperial, and Riverside Counties. We have developed a reputation for practical solutions, cost-effectiveness, responsiveness, and flexibility.  D-MAX is recognized across the region for our expertise in jurisdictional storm water program development and reporting, water quality monitoring, Industrial General Permit compliance assistance, development and construction services, and inspections of businesses, municipal facilities, construction sites, and treatment control BMPs.Our experience has provided us with a comprehensive understanding of complex, countywide water quality issues and the ability to effectively address them. D-MAX adapts to our clients’ needs and provides a level of quality service that sets us apart. Our diverse team of professionals, central location, and familiarity with the region allows us to provide clients with a wide variety of services at affordable rates. We are a state-certified small business enterprise (SBE).-Personal information of employees and clients -Financial documents-Сommunications drawings https://www.dmaxinc.com/</i><br />Target victim <b>website</b>: <i>www.dmaxinc.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wolfram-Research</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35739</link>
<guid>2a081587c87c2f361a44876167336224</guid>
<pubDate>Fri, 04 Sep 2026 17:55:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Wolfram-Research</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fab4140c898ff2ce9427f6262f1511601c4f1320352843018e6f9ae3a7bfceed</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Wolfram Research is an American technology and software company founded in 1987 by Stephen Wolfram and headquartered in Champaign, Illinois. It operates in the computational software and artificial intelligence industry, best known for developing Mathematica, a powerful technical computing platform, and Wolfram Alpha, a computational knowledge engine. The company also produces the Wolfram Language, used widely in scientific research, education, and data analysis.</i><br />Target victim <b>website</b>: <i>wolfram.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sports-Endeavors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35738</link>
<guid>fd97bb50e4b07a520a0f4844554bdd4a</guid>
<pubDate>Fri, 04 Sep 2026 17:33:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Sports-Endeavors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2314640b6f74f29936aa6d68d4aabf0fea0d17c491801571a81cde24820faf95</i><br /><br />Threat actor <b>description</b>: <i>Sports Endeavors is a North Carolina company founded in 1984 by brothers Mike and Brendan Moylan. It owns Soccer.com, WorldSoccerShop, and 431 Sports, selling uniforms, gear, and apparel for soccer, baseball, softball, and volleyball to teams, players, and fans. The company is known for a large selection from brands such as Nike, adidas, and Puma, plus custom team uniforms. In April 2026 it was acquired by Varsity Brands / BSN SPORTS. https://www.sportsendeavors.com/</i><br />Target victim <b>website</b>: <i>www.sportsendeavors.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>pscindustries.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35727</link>
<guid>8616b9b1bd5d6274df7e0608bf7161bf</guid>
<pubDate>Fri, 04 Sep 2026 14:41:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>pscindustries.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d5e7b5e507be0c6866dc7daa36018cd0e4b74bfa0cd5631167d8ea2f8c57463</i><br /><br />Threat actor <b>description</b>: <i>For over 60 years, PSC Industries has been the number 1 supplier of nsulation, gasketing, seals, adh...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>SouthernCarlson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35729</link>
<guid>214bf5f943f8aa073d06965c1dd2fa86</guid>
<pubDate>Fri, 04 Sep 2026 14:04:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>SouthernCarlson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>217e1b03881563b784cf98ed6f9e848b672e1da15cfb81952fafca3d8c93bc87</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] SouthernCarlson is a U.S.-based distributor specializing in packaging, fastening, and installation solutions. The company serves industries such as construction, manufacturing, and retail, supplying tools, equipment, and materials including staples, nails, strapping, and related supplies. Operating primarily across the United States, SouthernCarlson functions as a key distribution partner for businesses requiring industrial packaging and fastening products.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Worrell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35728</link>
<guid>86d02f03357f848264de0b23a958398c</guid>
<pubDate>Fri, 04 Sep 2026 13:51:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Worrell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88f236679275dff0ff80ddf59f1f4f1a31f24a3d68302a5047abe85ef321ffc1</i><br /><br />Threat actor <b>description</b>: <i>Worrell Corporation is a family-owned business based in Indianapolis that specializes in promot
ional products, marketing, and print services. They assist clients in finding impactful promoti
onal items while offering tailored marketing strategies and webstore solutions.

We will upload 45gb of corporate data soon. Employee and client information, contacts and agree
ments, financials, projects and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Homewood-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35724</link>
<guid>1d1482e5b98498fb5c7784247734c3c8</guid>
<pubDate>Fri, 04 Sep 2026 11:35:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Homewood-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>703106badaf01d836d3a02b76290a93f885cff25174f3a21d1ace6245a067952</i><br /><br />Threat actor <b>description</b>: <i>Homewood Sales Corporation specializes in equipment life extension solutions, offering a wide range of products including automatic voltage regulators, control ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Norwood-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35725</link>
<guid>63c6182693644ee5d5724dc5103748cb</guid>
<pubDate>Fri, 04 Sep 2026 11:35:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Norwood-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f383158cb016af8554aefa4dc4e8e7689fed0c9636b1a607dec06c38eec8567</i><br /><br />Threat actor <b>description</b>: <i>Norwood Law is a Tulsa-based legal firm that specializes in personal injury law, criminal defense, business law, and family law. Founded by attorney Joe Norwood...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schwartz-Giannini-Lantsberger--Adamson-SGLA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35717</link>
<guid>d18bae1a26ca78b3f8b2212c7c7d101a</guid>
<pubDate>Fri, 04 Sep 2026 00:03:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Schwartz-Giannini-Lantsberger--Adamson-SGLA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93a4f903320d7bc91ad1f95f536cdd10eba2092a65845c9467ed4022daacd032</i><br /><br />Threat actor <b>description</b>: <i>Schwartz, Giannini, Lantsberger & Adamson (SGLA) Accountancy  Corporation is a full-service certified public accounting firm based in  Stockton, California, founded in 1988. The firm provides tax planning  and compliance, audits, reviews and compilations, bookkeeping, payroll,  outsourced CFO support, and business consulting for individuals and  companies. It has particular experience with real estate, healthcare,  nonprofits, affordable housing, common-interest realty associations, and  local government clients. SGLA positions itself as a hands-on local CPA  practice that combines traditional accounting work with practical  advice to help clients stay compliant and grow. https://www.sglacpas.com/</i><br />Target victim <b>website</b>: <i>www.sglacpas.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Katten-Muchin-Rosenman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35715</link>
<guid>af5ac7432f2b60611a2b2081da85bdc0</guid>
<pubDate>Thu, 03 Sep 2026 20:23:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Katten-Muchin-Rosenman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d0309418623e335e2e19f155c9a397f9b224cd94c65a5da654f5f010e8e9213</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Katten Muchin Rosenman is a full-service law firm headquartered in the United States. Operating across multiple offices in major American cities and internationally, the firm provides legal services in areas including corporate law, litigation, financial markets, real estate, intellectual property, and regulatory compliance. It serves clients across industries such as finance, entertainment, and healthcare, and is recognized as a prominent firm within the U.S. legal sector.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>myglobal.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35712</link>
<guid>f0fe8624ed77b0f2c7c5a6e6826021cd</guid>
<pubDate>Thu, 03 Sep 2026 18:25:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>myglobal.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3596c8a48a954b032e041bf4ea1d0002ddce06b88d9c37d25c9d50ef99a7a5ce</i><br /><br />Threat actor <b>description</b>: <i>My Global Services Sdn Bhd is the first authorized distributor of OLED LiFi in Malaysia, specializing in OLED LiFi technology, mechanical and electrical engineering, as well as civil and construction services. The company provides solutions for scientists and research workers, offering sales and support for scientific equipment. Their services include civil and structural engineering, ensuring a comprehensive approach to their clients' needs. With a focus on innovative lighting solutions, they aim to enhance the capabilities of their clients across various sectors. Employees: 10 Revenue: $5 Million Industry: Architecture, Engineering & Design Phone Number: +60 358922797</i><br />Target victim <b>website</b>: <i>myglobal.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maglin-Miskiv--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35710</link>
<guid>7cc59604599fcb316d7059ea5dc50115</guid>
<pubDate>Thu, 03 Sep 2026 14:27:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Maglin-Miskiv--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e506e8933b482f5c3d18099a20550d3a7a3276b2c409408073e228bb4db7fa8e</i><br /><br />Threat actor <b>description</b>: <i>Maglin Miskiv & Associates in Parsippany, NJ offers personalized accounting, tax planning, bookkeeping, payroll, financial consulting, tax prep, and audit support for individuals and businesses.</i><br />Target victim <b>website</b>: <i>none</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>hvlawfirm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35701</link>
<guid>069204aba7ba6d1dfdc36df6b398b69f</guid>
<pubDate>Thu, 03 Sep 2026 12:01:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>hvlawfirm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52c510aafcdc90f82f6d5b21bc4590e9b4171c6606488805b6761ec6fb98da94</i><br /><br />Threat actor <b>description</b>: <i>EXPOSURE OF MASSIVE DATA BREACH: HAGELGANS &amp; VERONIS, LLP PROLOGUE Hagelgans &amp; Veronis, LLP ...</i><br />Target victim <b>website</b>: <i>hvlawfirm.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>medevolve.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35699</link>
<guid>6d17745ad39541ad3f760e9c9b20058b</guid>
<pubDate>Thu, 03 Sep 2026 12:00:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>medevolve.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a6572918fc4d0e2dc6cccc0f57986e57e4110f4db01f1ef6402fc0dad253ee3</i><br /><br />Threat actor <b>description</b>: <i>MedEvolve: Internal Documents of an American Medical Billing Company PROLOGUE MedEvolve is an Americ...</i><br />Target victim <b>website</b>: <i>medevolve.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Americas-Food-Basket</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35695</link>
<guid>cc11d15b3f413bf76897f2b8cff222fa</guid>
<pubDate>Thu, 03 Sep 2026 11:22:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Americas-Food-Basket</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd2091c572889df9fa0779d3c5b7bfd8158a98fec0d97c617cb99c2ba2ec58cb</i><br /><br />Threat actor <b>description</b>: <i>America’s Food Basket is a U.S. cooperative grocery-store network. Its site, afbasket.com, provides store locations, weekly ads, online shopping, delivery, recipes, and job listings. It operates under the America’s Food Basket and Ideal Food Basket names.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Star-Aviation-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35691</link>
<guid>c422b5f0e1337440dd7da769a540770f</guid>
<pubDate>Thu, 03 Sep 2026 08:29:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Star-Aviation-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20a8d39f68c5e37a09b593649ec0826ca01a8f656bf18b4016c1291bb0646e1a</i><br /><br />Threat actor <b>description</b>: <i>Star Aviation, Inc. is a leading provider of engine wire harness repair services, including DER repairs and PMA, specifically tailored for the Commercial Aerospace Industry. They offer a comprehensive range of services such as wire harness inspection, testing, repair, overhaul, modification, and sales. The company is committed to enhancing reliability and reducing maintenance costs for their clients by utilizing advanced technology and a customer-focused approach. Star Aviation is recognized as the world's first full-service Electronic Wire Interconnect System (EWIS) Solution Center, ensuring high standards of quality, safety, and customer service. 
The company headquarters is located in 9001 W Highway 42, Goshen, KY 40026, United States.. 11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>GSAC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35689</link>
<guid>3761f19421dde49193924cdeece61636</guid>
<pubDate>Thu, 03 Sep 2026 08:28:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>GSAC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a04f22639c8f0f6017ca791da650fec9f47839b3ca9567b2560b41967069350</i><br /><br />Threat actor <b>description</b>: <i>GSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. 
The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Superior-Ag</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35688</link>
<guid>6172a70bcae942f431b48adcb4699db8</guid>
<pubDate>Thu, 03 Sep 2026 08:27:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Superior-Ag</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3432b2f7b364bbe5c1765f409cdca2b866412bc2c00d88e4d87ecacf42937790</i><br /><br />Threat actor <b>description</b>: <i>Superior Ag is a cooperative that provides a range of agricultural services and products, including agronomy, livestock nutrition, grain marketing, and energy solutions. Established from the merger of local cooperatives, it serves farmers in southwestern Indiana, northern and central Kentucky, and parts of Illinois. The company focuses on enhancing food production and supporting its member-customers through expert insights and tailored services. With a commitment to community and member success, Superior Ag emphasizes quality and safety in all its operations. 
The company headquarters is located in 901 N Main Street, PO Box 420, Huntingburg, IN 47542, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chicago-Partners-Wealth-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35687</link>
<guid>bf5a56c48b186ab2abf6b6fb0458643e</guid>
<pubDate>Thu, 03 Sep 2026 08:27:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Chicago-Partners-Wealth-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e8711177caf87c2df3c7ba77efc36b3db05ff8892dbb24dad934e1bbf4e17af</i><br /><br />Threat actor <b>description</b>: <i>Chicago Partners Wealth Advisors is a comprehensive, independent, and objective advisory firm which provides investment advisory services for over $850 million of investment assets from individuals, families, and endowments. Chicago Partners specializes in the area of enhanced indexing, alternative investments, and master limited partnerships. Chicago Partners is headquartered in Chicago, Illinois.. 
The company headquarters is located in 1 North Wacker Drive, Suite 4075, Chicago, IL 60606, United States. 11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>SITES-Medical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35685</link>
<guid>33fbe2a122144f50514b6049580d6577</guid>
<pubDate>Thu, 03 Sep 2026 08:26:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>SITES-Medical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07d66b9a163e4fb0274d92510d68aae91ca3f78dc0fe9487c02d0cd6d61aa04c</i><br /><br />Threat actor <b>description</b>: <i>SITES Medical is a trusted partner for orthopedic implant companies, offering innovative orthopedic technologies and a rapid product concept-to-launch process. They provide comprehensive R&D services, including regulatory filings, and contract manufacturing capabilities to ensure high-quality products at reduced costs. Their expertise spans various markets, including orthopedic, spine, dental, and more, with a focus on enhancing product offerings through advanced technologies like OsteoSync Ti. SITES Medical collaborates closely with clients to integrate these technologies into their product lines, supporting their success in the competitive medical market. 
The company headquarters is located in 4707 East Park 30 Drive, Columbia City, IN 46725, United States.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenberg-Traurig</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35684</link>
<guid>5ffeb4b17ffb5626bc964f2c8b4f9cf3</guid>
<pubDate>Wed, 02 Sep 2026 23:21:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Greenberg-Traurig</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d6be598f03440dfac0cba4d77a50ab239f9d5485a21e23f6e118e9b4cb98d45</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Greenberg Traurig is a large multinational law firm headquartered in the United States. It provides legal services across numerous practice areas including corporate law, real estate, litigation, intellectual property, and government affairs. Operating in the legal services industry, the firm serves clients globally with offices across the United States, Europe, Latin America, Asia, and the Middle East.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ormond-Beach-Florida</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35678</link>
<guid>0569715221d9e6147085bca7324be293</guid>
<pubDate>Wed, 02 Sep 2026 16:51:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Ormond-Beach-Florida</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2023f85d41505b46c9c34c648609c986a40cf5f45ffa2a11b1dc2e3af290ca23</i><br /><br />Threat actor <b>description</b>: <i>Ormond Beach, Florida, is a scenic coastal city just north of Daytona Beach, known for its beaches, relaxed atmosphere, historic charm, and outdoor activities.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westfield-Public-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35676</link>
<guid>ae586136fed585b47ccc2bc26537230e</guid>
<pubDate>Wed, 02 Sep 2026 14:57:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Westfield-Public-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>028a3ccbec62dafb0793a81e03b245d39615135531947f06bd213299efc035c6</i><br /><br />Threat actor <b>description</b>: <i>Westfield Public Schools is dedicated to educating all students to reach their highest potential as engaged citizens who value diversity. The district focuses on inclusivity, community engagement, wellness, and comprehensive financial planning to enhance the educational experience. Their strategic plan outlines long-term goals and strategies to align resources with the needs of students and staff. The intended clients include students, families, and the broader community in Westfield, NJ.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>PennFab</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35669</link>
<guid>bffe281d013c3653eac4c8a7737375ff</guid>
<pubDate>Wed, 02 Sep 2026 14:22:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>PennFab</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfee6bff3d88e0ac990edd0f20fd76639222e3ce6537d4fcb0f55298c859a9e0</i><br /><br />Threat actor <b>description</b>: <i>PennFab is a Pennsylvania-based steel manufacturing company specializing in structural steel fa
brication for various industries, including railroad and transportation. They offer a wide rang
e of services such as engineering, welding, and custom metal fabrication, ensuring high-quality
products made in the USA.

We will upload 40gb of corporate data soon. Employee personal information (scanned passports, D
Ls, SSNs and so on of 53 employees), clients information, contacts and agreements, financials, 
NDAs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ScrubaDub-Auto-Wash-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35668</link>
<guid>aa36f34f8e6457636146a39072acf955</guid>
<pubDate>Wed, 02 Sep 2026 13:52:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ScrubaDub-Auto-Wash-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>268153f8773df3a37254aa8e8ad53228c823b932620f54e47f682bdec4a0ced3</i><br /><br />Threat actor <b>description</b>: <i>ScrubaDub Car Wash is New England's leading auto wash, offering customizable tunnel and touchle
ss washes, interior cleaning, and detailing services across over 20 locations in Massachusetts,
New Hampshire, Maine, and Rhode Island.

We will upload corporate data soon. Employee personal information (passport numbers, DLs of 22 
employees, contact information), clients information (addresses, contacts and so on), company f
inancials, payment details.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seasia-Infotech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35663</link>
<guid>52c5200513f0865d340257d67b0c9768</guid>
<pubDate>Wed, 02 Sep 2026 10:30:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Seasia-Infotech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>198a6f92eb5c10e48698921715e2df082d968a1d0a0c9e23dbc850068b6895cc</i><br /><br />Threat actor <b>description</b>: <i>seasiainfotech.com zoominfo.com/c/seasia-infotech/353879170 Seasia Infotech — global IT services company, founded in 2000 in California, USA.
Delivery centers in India (Mohali/Chandigarh); offices in UK, Australia, UAE, Canada.
25+ years in business; completed 50,000+ projects in 36+ countries for 500+ clients.
Clients include HP, Harley-Davidson, Mahindra, Flipkart, Adani, NEC, Canon.
Holds CMMI Level 5 — the highest software process certification; also ISO 27001 and Microsoft Gold.
Services: custom software, web/mobile apps, AI & Generative AI, cloud, cybersecurity, QA, UI/UX.
2026 focus: "AI Pods" — ready-made expert teams with AI tools for HealthTech, FinTech, LegalTech.
Scale: ~300–680 employees, est. revenue $100–150M, fully bootstrapped — no external funding.
Risks: shrinking headcount (-9% YoY), unaudited revenue figures, too small for giant enterprise deals.</i><br />Target victim <b>website</b>: <i>seasiainfotech.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Proliance-Surgeons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35662</link>
<guid>310079ed28ae0df2bf9230b464f7f3bc</guid>
<pubDate>Wed, 02 Sep 2026 10:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Proliance-Surgeons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa4ddf18841ac02e8d26fc7e2143621dacf26040b3ef98c4ea542f974cbd4bc2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Proliance Surgeons is a large physician-owned surgical group based in the United States, primarily operating in Washington State. The organization brings together hundreds of independent surgeons across dozens of specialties, including orthopedics, general surgery, and sports medicine. It operates numerous clinics and surgical centers throughout the Pacific Northwest, providing outpatient and inpatient surgical care to patients across the region.</i><br />Target victim <b>website</b>: <i>proliancesurgeons.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>specialtytextile.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35661</link>
<guid>af536dee281164c88c729bd08be02043</guid>
<pubDate>Wed, 02 Sep 2026 09:58:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>specialtytextile.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff9c1a5a2f75e1c93aba4aee716a7ec9e6a1fc861c0bb802669662299f58ebbb</i><br /><br />Threat actor <b>description</b>: <i>Specialty Textile Services is a U.S. textile services company founded in 1996, specializing in linen rental and processing for the hospitality industry. Headquartered in Phoenix, Arizona, with a branch in San Diego, California, the company employs between 201 and 500 people.  Serving mid-to-high-end restaurants, hotels, and other hospitality providers, Specialty Textile Services offers flexible rental programs covering a full line of linens, kitchen textiles, uniforms, and dust control products — all delivered clean and ready for use. Key features include:  flexible pickup and delivery schedules, including multiple weekly service visits; all-inclusive service pricing with no upfront investment required from customers; an in-house commercial laundry facility operating 7 days a week, 365 days a year, with rapid emergency response available for special requests.</i><br />Target victim <b>website</b>: <i>specialtytextile.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chip-1-Exchange</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35659</link>
<guid>5105a11a2ab1ae9d7515e9ba9178d15e</guid>
<pubDate>Wed, 02 Sep 2026 06:52:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Chip-1-Exchange</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f899de813c135f9989f441735638c1a41cd26e357fe2b2959c1f7a13f684403f</i><br /><br />Threat actor <b>description</b>: <i>[distributor] Chip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg, Germany, with primary US operations in Laguna Hills, California.

The dataset spans 13 years (2013-2026) of corporate operations and encompasses:

40+ passport photographs, I-9 forms with SSNs, W-4 tax forms, payroll registers.
<redacted>
Complete 2026 financial intelligence — P&L through July, executive financial health assessment, AR/AP aging, chart of accounts revealing all bank account numbers.
15+ exclusive franchise manufacturer agreements with pricing terms, territory allocations, and per-customer gross profit margins.
ITAR registration and defense customer sales orders to Jabil Defense, Curtis-Wright, GEN3 Defense, and Cobham Remec.
5.7 GB of Outlook PST email archives spanning years of C-suite and employee correspondence.</i><br />Target victim <b>website</b>: <i>Chip 1 Exchange</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grayson-Rural-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35658</link>
<guid>8ba15caa35c7c7b77c15297ac0d39330</guid>
<pubDate>Wed, 02 Sep 2026 06:42:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Grayson-Rural-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>129731a87de0f372ec0c57995249e33614106d3da9736370953fc3f3c435c696</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quality-Resource-Pvt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35656</link>
<guid>1cccb6d5cd38e1c3e19e5bcaa50b13ab</guid>
<pubDate>Tue, 01 Sep 2026 22:21:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Quality-Resource-Pvt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23332bd2212b2fb022942c5073346d5ef5e5389a86e35715d5971ebb2caeb8b3</i><br /><br />Threat actor <b>description</b>: <i>Country: United States |
Website: qualityresourcepvt.com |
Revenue: $19 Million |
Industry: Advertising Networks |
Employees: 201–500 employees |
Properties: 60.1 GB (170,436 Files, 88,440 Folders)</i><br />Target victim <b>website</b>: <i>qualityresourcepvt.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Holland--Knight</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35655</link>
<guid>0decbbe8e7f4bbda5ecf7be75866985e</guid>
<pubDate>Tue, 01 Sep 2026 21:22:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Holland--Knight</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7659124862d4805728f6b4f36b6adfacc24ce7d4acebca0e18643ea9f46235ad</i><br /><br />Threat actor <b>description</b>: <i>Holland & Knight, headquartered in Tampa, Florida, and established in 1968, is a law firm that offers …</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>rubbermill.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35649</link>
<guid>5bd4093601dc99da1b9c0f43d37f3441</guid>
<pubDate>Tue, 01 Sep 2026 16:29:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>rubbermill.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>944caef8232277289557f59aee75e12b6b05b5590ac8eb552fd2e59478d1d7ea</i><br /><br />Threat actor <b>description</b>: <i>═════════════════ ═════════════════ ═════════════════
  RUBBERMILL, INC. DUMP: BREAKDOWN OF AN OEM MANUFACTURER LEAK
═════════════════ ═════════════════ ═══════...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Honeycomb-Programs-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35652</link>
<guid>034bec2c804e8d18f204d2ccdca64b15</guid>
<pubDate>Tue, 01 Sep 2026 15:54:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Honeycomb-Programs-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>485d2f13721d870bcd4acfe8ec504708c4168c6183d5e1dfe03bb451f9382cb9</i><br /><br />Threat actor <b>description</b>: <i>Insurance</i><br />Target victim <b>website</b>: <i>honeycombinsurance.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Congressional-Iron-Works</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35650</link>
<guid>2ca3d98d9a3e1a889ab612286310f272</guid>
<pubDate>Tue, 01 Sep 2026 15:21:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Congressional-Iron-Works</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54e22c2157a2cb1128866032765536ce22e477b9ebb0deefa48c6f1caedc00e4</i><br /><br />Threat actor <b>description</b>: <i>Congressional Iron Works is a full-service miscellaneous metals contractor serving the commerci
al construction industry in the greater Baltimore-Washington area. Established in 2004, the com
pany offers a range of services including estimating, drafting, fabrication, and project manage
ment, focusing on steel and architectural metals components such as structures, stairs, and can
opies.

We will upload 35gb of corporate data soon. Employee personal information (passport numbers, SS
Ns, DLs, financial information, health information), clients information, company financials, p
rojects, NDAs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>BYK-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35647</link>
<guid>e4e2602e040333a9d03277cf9312e1a7</guid>
<pubDate>Tue, 01 Sep 2026 14:23:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>BYK-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d93e87adc435a867792609b6882c45e99f3ad3b2c47ec2a7b3a31306a05f36d</i><br /><br />Threat actor <b>description</b>: <i>BYK Construction is a trusted home builder based in Mount Vernon, Washington, specializing in r
esidential and commercial construction, land development, property management, and home mainten
ance.

We will upload 27gb of corporate data and their client soon. Employee personal information (pas
sport numbers, SSNs, DLs, financial information), clients information, company financials, proj
ects (specifications) and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>SCHMIDT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35645</link>
<guid>3f80c6db49ee3b6965486b0a977bbdc2</guid>
<pubDate>Tue, 01 Sep 2026 12:53:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>SCHMIDT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08eff8fa54379f3a0ecde1f963c94c4b6d824f2a02f1e5a815d3d58b58fa2f65</i><br /><br />Threat actor <b>description</b>: <i>Abrasive Blasting Systems and Engineering Solutions for Industry.</i><br />Target victim <b>website</b>: <i>schmidtmfg.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>CareerSource-Palm-Beach-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35644</link>
<guid>58840eb65da053fbdea5f4d19dd3e00f</guid>
<pubDate>Tue, 01 Sep 2026 12:14:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>CareerSource-Palm-Beach-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a7889e70bf4a61f2f2e770110898450604a2521867f46a6644d467d39115dd0</i><br /><br />Threat actor <b>description</b>: <i>www.careersourcepbc.com https://www.zoominfo.com/c/careersource-palm-beach-county/359202628 Headquartered in West Palm Beach Florida. CareerSource Palm Beach County is a nonprofit organization chartered by the state to lead workforce development in the United States.</i><br />Target victim <b>website</b>: <i>www.careersourcepbc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nutex-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35643</link>
<guid>31a34dfbb1e21d2119711042f6731578</guid>
<pubDate>Tue, 01 Sep 2026 12:14:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Nutex-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>201342bae107c240c65ac029955bbed9a16f64bbaa716edfc77a9a1f246791c2</i><br /><br />Threat actor <b>description</b>: <i>nutexhealth.com zoominfo.com/c/nutex-health-inc/372032478 (NUTX, Nasdaq) — US healthcare company, based in Houston, Texas, founded in 2011 by Dr. Thomas Vo.
It runs 27 small "micro-hospitals" in 12 states — small hospitals with full 24/7 emergency rooms.
Model: fast, cheaper ER care between urgent care and giant hospitals; most revenue comes from Texas.
Q2 2026: net income $65.8M (vs loss a year ago), EBITDA $90M, cash $205M, debt only $31M.
Profit exploded because it wins 85%+ of insurance arbitrations (IDR) and got paid at higher out-of-network rates.
Plans: 7 new hospitals by 2027 plus two share buyback programs.
Main risk: the whole profit engine depends on the arbitration system — new regulation could cut it.
Cheap-looking: P/E around 6, but volatile small-cap with thin analyst coverage.</i><br />Target victim <b>website</b>: <i>nutexhealth.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Total-Education-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35638</link>
<guid>3d7a25751bbbd7c2cd582e7ab7d58844</guid>
<pubDate>Tue, 01 Sep 2026 09:51:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Total-Education-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>acbb6e9d0f8f0b2bd998f37959b0525d9b13249e140b34dce7291720c52b91ff</i><br /><br />Threat actor <b>description</b>: <i>TES IDEA provides personalized educational, therapeutic, and developmental solutions that help students, families, and schools achieve better outcomes.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35622</link>
<guid>68d14581775852c113997d94803a0855</guid>
<pubDate>Tue, 01 Sep 2026 04:27:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Lawter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c3ec7db0059d7af0132a20ef2831c85897b1326528cb81b8997b64696c1b998</i><br /><br />Threat actor <b>description</b>: <i>Organization with 150 emails extracted. Domain: lawter.com</i><br />Target victim <b>website</b>: <i>lawter.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>aeiconsultants.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35616</link>
<guid>6a44ca8a7a7268c20a11e16e707b8c04</guid>
<pubDate>Mon, 31 Aug 2026 19:54:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>aeiconsultants.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa176dfe3c627eca6cb3d4d5aa1da5f83f3463dc22219b6ede72ce7d23d3cfab</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>aeiconsultants.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>ahadandco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35613</link>
<guid>55f658d44bed8bd311ee72f40cde2ad4</guid>
<pubDate>Mon, 31 Aug 2026 19:52:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>ahadandco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74c2e4fb53b40ec6942bd0dd1266477bd660bf62ee6fb8260d9e9f25e0237554</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>ahadandco.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>sago.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35612</link>
<guid>fd570c27236250922768da413f3a90a4</guid>
<pubDate>Mon, 31 Aug 2026 19:52:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>sago.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>380049a83dc32b706bc4eba0b94a589b70d1d8e4e8366b93ee37065c1fcd07f2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Sago is a market research and insights company headquartered in the United States. It specializes in connecting brands and researchers with qualified participants for qualitative and quantitative research studies, including focus groups, online surveys, and in-depth interviews. Formerly known as Schlesinger Group, Sago serves clients across various industries seeking consumer and professional insights to inform business decisions.</i><br />Target victim <b>website</b>: <i>sago.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>crmeyer.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35611</link>
<guid>bcf541b8ef7299fc36ada53bbcf3e498</guid>
<pubDate>Mon, 31 Aug 2026 19:51:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>crmeyer.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29a209c959c29675b729e37fb90460efc63c9bbc5199404bab75793ddd4b59d3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>crmeyer.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>ccsperfusion.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35610</link>
<guid>0aff79643e0e8ce75a892aa9a9e736f4</guid>
<pubDate>Mon, 31 Aug 2026 19:50:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>ccsperfusion.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3caa47ce054b4c9cecf6ce49aefe4f0a22367bc6e397c00e8972a8b32a39ad33</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] CCS Perfusion is a US-based company operating in the medical and healthcare industry, specializing in perfusion services and cardiovascular surgery support. The company provides clinical perfusion professionals who operate heart-lung bypass machines during open-heart surgeries. It serves hospitals and surgical centers, ensuring patient safety during cardiopulmonary bypass procedures. The company operates within the United States healthcare sector.</i><br />Target victim <b>website</b>: <i>ccsperfusion.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Truckworx</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35608</link>
<guid>19baeb48db1931b5ca4b7a6a33e94d4c</guid>
<pubDate>Mon, 31 Aug 2026 19:01:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Truckworx</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fbcac4f542c4e3e16b11bd651c49cfed5bf2998338eb8f8b5f68aa033dffcb1</i><br /><br />Threat actor <b>description</b>: <i>- Financial records- Accounting records- Tax records- Business operations documents- Legal/corporate records</i><br />Target victim <b>website</b>: <i>truckworx.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>svfcu.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35597</link>
<guid>42d7ad8e490f91eef61abf055057d5b5</guid>
<pubDate>Mon, 31 Aug 2026 16:31:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>svfcu.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e08208b89e4f7988f1fb9ee82aba10051197b324706238be40a06cbbddb6e675</i><br /><br />Threat actor <b>description</b>: <i>Susquehanna Valley Federal Credit Union is a member-owned financial institution that offers a range...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>hoaattorneys.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35598</link>
<guid>a1573c3e4eeb08729fe342c7683d94bf</guid>
<pubDate>Mon, 31 Aug 2026 16:31:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>hoaattorneys.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c57668687424c838f012cbc96f9d7e5fb3708a50f184a7732820af5e55cb171</i><br /><br />Threat actor <b>description</b>: <i>For more than 40 years, Beaumont Tashjian has provided common interest developments with the legal e...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Super-Systems-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35602</link>
<guid>0a41cf40123f35dac58d66443fd55e51</guid>
<pubDate>Mon, 31 Aug 2026 15:57:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Super-Systems-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c3c6ed5489c454a5627bcc65ec6c229fa1c345a298e3b7b42627f4b5878577b</i><br /><br />Threat actor <b>description</b>: <i>Super Systems, Inc. develops and manufactures products for the heating industry. However, it is extremely negligent in its own security and that of its customers, resulting in data breaches. You can view documents revealing confidential control schemes and vulnerabilities in customer systems, SSi's entire client portfolio, and confidential financial information about outstanding customer accounts, which undermines trust and damages the company's reputation. You are also provided with a list of over 500 customers with their contact information and price lists for products and services. You are also provided with SSi's intellectual property, a full suite of software for process control, data collection, analysis, and product tracking.</i><br />Target victim <b>website</b>: <i>https:supersystems.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>WEMS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35581</link>
<guid>3cfd7328162ff668a881f7e275a1a01d</guid>
<pubDate>Mon, 31 Aug 2026 15:45:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>WEMS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06095616e12c5f74149bbee85f069f9ce7f75b3744f0db44b356fc83e08c9a0d</i><br /><br />Threat actor <b>description</b>: <i>WEMS Electronics is a full-service turn-key small business specializing in state-of-the-art EMIcustom filters, engineering, and manufacturing services. The company offers a completely integrated approach to the design and fabrication of precision electronic components, assemblies, and subsystems.We will upload 51gb of corporate data soon. Employee personal information, client information, lots of confidential HR files, projects, financials, projects, contrast and agreements, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>zonarsystems.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35601</link>
<guid>f9ac3ab178b7b9de8337a031856560ec</guid>
<pubDate>Mon, 31 Aug 2026 15:40:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>zonarsystems.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>768c9d2bb00bbed789f4d55c48de50b194136b32f7a8a7e2326e25b1fd115af9</i><br /><br />Threat actor <b>description</b>: <i>Zonar Systems The Company That Knows Where You Are Zonar Systems, Inc. — a Seattle-based company tha...</i><br />Target victim <b>website</b>: <i>zonarsystems.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hayward-Holdings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35600</link>
<guid>c6df737ba4bfc21229b35655ea99a97c</guid>
<pubDate>Mon, 31 Aug 2026 15:22:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Falcon</b> claims attack for <b>Hayward-Holdings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fd51822e0df5be6d4a1c7e54b29775beb69f9bec4109ced66be233ac6e1c0f5</i><br /><br />Threat actor <b>description</b>: <i>Pool & spa equipment Â· NYSE: HAYW - Our 848 GB extraction includes your Salesforce, 1+ million of each business and customer records with PII, distributor pricing lists, margin structures, detailed financial records, P&L statements, accounting ledgers, extensive personnel files, IT infrastructure blueprints, privileged account credentials, strategic board preparation materials and much more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Falcon</category>
</item>
<item xmlns:dc='ns:1'>
<title>New-Century-Ophthalmology-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35599</link>
<guid>ad2b5e729bc747066e6422cb6e1fa5da</guid>
<pubDate>Mon, 31 Aug 2026 14:55:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>New-Century-Ophthalmology-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f78d334bf89bac75b5021270e068a28fe5d38aaa04a27bee214bacdf7d4baa0</i><br /><br />Threat actor <b>description</b>: <i>New Century Ophthalmology is a leading ophthalmology practice located in Raleigh and Oxford, NC, specializing in advanced eye care services including cataract surgery, glaucoma treatment, and oculoplastic procedures. The practice is dedicated to providing personalized, high-quality care with a focus on patient well-being and innovative treatment options. Their team of fellowship-trained specialists utilizes state-of-the-art technology to ensure optimal outcomes for a variety of eye conditions. New Century Ophthalmology serves a diverse clientele seeking comprehensive eye health solutions and aesthetic enhancements</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Figgins-Family-Wine-Estates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35594</link>
<guid>ff5a32529137a0ce614e6a37307423c5</guid>
<pubDate>Mon, 31 Aug 2026 14:28:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Figgins-Family-Wine-Estates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b03fb9e05e85ad34bad6e29d59e603f61f9a2caecec0e393a199d1135453f954</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.figginsfamily.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>KRC-Machine-Tool-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35593</link>
<guid>c45d1a9464832225cdd3b555512657c3</guid>
<pubDate>Mon, 31 Aug 2026 14:27:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>KRC-Machine-Tool-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b333887a91e38968f64443e013d46b919675afcee7f6cac4598c8bc98fc7c0d7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.krcmachinetoolsolutions.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro-Tulsa-Foot</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35591</link>
<guid>be4b102d12d8b7041d5db84bb0aa7abb</guid>
<pubDate>Mon, 31 Aug 2026 14:24:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Metro-Tulsa-Foot</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10285afb26e5164627ad5df5d4d759fad62fede03258c79630f1e9fa6bf7b423</i><br /><br />Threat actor <b>description</b>: <i>A comprehensive foot and ankle treatment center with five locations in the Tulsa Metro area. They offer a range of services including treatment for common foot pains, deformities, and injuries, and provide same-day appointments for urgent needs.</i><br />Target victim <b>website</b>: <i>www.tulsafoot.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>diversifiedbodyandpaint.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35590</link>
<guid>62f0face795f84de82297b4dac2b3359</guid>
<pubDate>Mon, 31 Aug 2026 14:09:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>diversifiedbodyandpaint.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ea0928cf784be92ae345e5e7036cd88d15b7e15ac7b23f56dcfe03bf6e957d0</i><br /><br />Threat actor <b>description</b>: <i>Diversified Body Acquisition, LLC: Internal Documents of a Colorado Auto Body Company PROLOGUE Insid...</i><br />Target victim <b>website</b>: <i>diversifiedbodyandpaint.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>howardlumber.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35589</link>
<guid>6a08151ec9111529546d41050dbe8058</guid>
<pubDate>Mon, 31 Aug 2026 14:08:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>howardlumber.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebcc5df03321c7bd8a41a3ddb23a5fd0db22fe66a070031e7f8083e3dfdac762</i><br /><br />Threat actor <b>description</b>: <i>Howard Lumber Company and Augusta Sash &amp; Door: Internal Documents of a Building Materials Group ...</i><br />Target victim <b>website</b>: <i>howardlumber.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>zayo.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35587</link>
<guid>a617a439d2705ff5bec9814c3b887f45</guid>
<pubDate>Mon, 31 Aug 2026 14:07:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>zayo.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>622960e745aa689f6c957b2668ee5a044e8052886c42e4c0eccb57be973c5f72</i><br /><br />Threat actor <b>description</b>: <i>Zayo Group A cache of corporate data from telecommunications provider Zayo Group has been discovered...</i><br />Target victim <b>website</b>: <i>zayo.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>cfsnow.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35586</link>
<guid>c20f3fd71bd6e1b66d31a9dab6504ac8</guid>
<pubDate>Mon, 31 Aug 2026 14:07:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>cfsnow.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1f013f0a106a15f3849a7996a435fd607fb9173eaf915ec79a69e808600e619</i><br /><br />Threat actor <b>description</b>: <i>Challenge Financial Services, Inc.: Internal Documents of a California Auto Lending Company PROLOGUE...</i><br />Target victim <b>website</b>: <i>cfsnow.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>transcar.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35585</link>
<guid>a1ca316675d0768a5342071750b80a5f</guid>
<pubDate>Mon, 31 Aug 2026 14:06:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>transcar.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>058c75e5c30e29b33b9d1965207f9792e43fe3b9094c1a641f567c5bd5f3a990</i><br /><br />Threat actor <b>description</b>: <i>Documents Trans Global Auto Logistics / Transcar Auto Shippers PROLOGUE The archive of Trans Global ...</i><br />Target victim <b>website</b>: <i>transcar.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gale-Credit-Union</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35583</link>
<guid>545e38f2822c11face0c1d51fb1b15df</guid>
<pubDate>Mon, 31 Aug 2026 13:22:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gale-Credit-Union</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5a080c7ca98aa86f86916cd7e4cdf32c7d8826186d57772a3b6c7496479cbaa</i><br /><br />Threat actor <b>description</b>: <i>Gale Credit Union offers a variety of financial products and services including loans, savings 
and checking accounts, and credit cards. Their intended clients are individuals and businesses 
residing or working in ten counties in Illinois.

We will upload 50gb of corporate data soon. Employee personal information (passport, SSNs, DLs,
credit cards and so on), clients and partners information, projects, financials, contracts and
agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cedar-County-Memorial-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35582</link>
<guid>a733c7e8f35aab5ad6aa2a31a9b47ded</guid>
<pubDate>Mon, 31 Aug 2026 13:21:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Cedar-County-Memorial-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8c2916b9a8b059006303aca474e7b09c7a25e4d4f947b8797341509595dcd19</i><br /><br />Threat actor <b>description</b>: <i>Cedar County Memorial Hospital is a community hospital providing emergency, inpatient, outpatient, diagnostic, surgical, and rehabilitation services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.renorefractories.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35576</link>
<guid>2c7debea4e14b222afc99c5a7a17fc94</guid>
<pubDate>Mon, 31 Aug 2026 12:02:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.renorefractories.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9440e9e3f949dedad1b2f0766b90387a02eb3dddd599e1e58fa24f1eb4672a4b</i><br /><br />Threat actor <b>description</b>: <i>RENO Refractories, Inc. specializes in the manufacturing of refractory products and services for various industrial applications, including aluminum, iron and steel, cement and lime, foundries, mini mills, and hydrocarbon processing. With over 35 years of experience, the company is committed to innovation and quality, providing advanced research and development, technical support, and installation services. Their product offerings include a full range of monolithic products and the revolutionary ElectroCast product line. RENO aims to optimize the profits and safety of their clients by delivering superior refractory technology across North America.</i><br />Target victim <b>website</b>: <i>www.renorefractories.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ishbia--Gagleard-P.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35571</link>
<guid>b06ee722e5efe10c6852d6dc07b84616</guid>
<pubDate>Mon, 31 Aug 2026 10:22:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Ishbia--Gagleard-P.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78c9ecf2d4274148d902b2e9aa2ade21394a55c1258353fa4fb168938bed2eeb</i><br /><br />Threat actor <b>description</b>: <i>[law] Ishbia & Gagleard, P.C. — a boutique law firm in Birmingham, Michigan, founded in 1999 by Jeffrey A. Ishbia and Michael A. Gagleard. The firm practises real estate, corporate, estate planning, personal injury, medical malpractice, and commercial litigation for high-net-worth individuals and closely held entities.

The exposed material includes:

360+ client/matter folders — the complete attorney-client privilege corpus: litigation strategy memos, settlement agreements, case assessments, deposition notes, correspondence with opposing counsel.
<redacted>
<redacted>
Full Social Security Numbers for 25+ identified individuals — trust beneficiaries, family members, employees of client businesses, and a scanned Social Security card.
Protected Health Information — hospital admission records from Oakwood Hospital, University of Michigan Hospital, and William Beaumont Hospital. Also: 55+ employee files from a sexual health clinic client with SSN searches and scanned SS cards.
100+ client tax returns spanning 2003–2024, each containing SSNs, EINs, and income data.
11 email archive files (PST/OST) containing years of unfiltered attorney correspondence.
Personal legal matters of Mat Ishbia — CEO of publicly-traded UWM Holdings Corp. (NYSE: UWMC), the largest wholesale mortgage lender in the United States.</i><br />Target victim <b>website</b>: <i>iglawfirm.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crystalpharmatech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35556</link>
<guid>be745ec132d6b2f4db43aa8f94324ebf</guid>
<pubDate>Sun, 30 Aug 2026 15:30:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Crystalpharmatech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba166148b8fba6dd9b9b6e42bac083623d039f9fd23c3feb03d0dc78a6bf9b2b</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Andover</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35565</link>
<guid>d9e7c5c731d485cc970c44786f5e197c</guid>
<pubDate>Sun, 30 Aug 2026 15:21:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Andover</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01aa5deb77886b8ce9f67e04b960ed662918f09da2fee0fdd5d3d643ec671d7e</i><br /><br />Threat actor <b>description</b>: <i>The Town of Andover, Massachusetts, is a municipal government organization that provides public services, administration, community programs, education resources, infrastructure support, and civic information to residents and businesses in Andover.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Globus-Medical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35560</link>
<guid>c4e4e58273db0a045aa4e5715e137372</guid>
<pubDate>Sun, 30 Aug 2026 14:29:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Falcon</b> claims attack for <b>Globus-Medical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e288efbb8bdf4b99aba1eb6e0201ee4cebfceb95ab8ebf5212198753f1c9a917</i><br /><br />Threat actor <b>description</b>: <i>Medical devices Â· NYSE: GMED - Our 2.96 TB extraction includes your entire Microsoft PowerBi which contains over 51,000 records of your customers and more, FDA feedback, 510(k) submissions, PMA approval letters, TGA suspension proposals, product complaint logs, serious adverse event narratives, final CAPA investigation findings, merger diligence decks, integration plans, FTC antitrust review documents, combined P&L statements, deal models, budget spreadsheets, medical board of directors meeting minutes and agendas, executed NDAs, distribution contracts with named partners and medical institutions, patient demographics and history from clinical registries and much more.</i><br />Target victim <b>website</b>: <i>globusmedical.com</i>]]></description>
<category>Falcon</category>
</item>
<item xmlns:dc='ns:1'>
<title>DistributionNOW-DNOW-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35559</link>
<guid>c625dc1fd57f8d818b6718ee5ce9d27e</guid>
<pubDate>Sun, 30 Aug 2026 14:29:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Falcon</b> claims attack for <b>DistributionNOW-DNOW-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74158e3fbf48c37279bd5f33d9475f306e6b0070102f1a6e33e3afeaa1a7cc18</i><br /><br />Threat actor <b>description</b>: <i>Energy & industrial distribution Â· NYSE: DNOW - Our 344 GB extraction includes your corporate information, corporate bank statements, vendor payment instructions, detailed payroll records, employee compensation, tax documents, operational secrets, proprietary SCADA gateway backups, PLC logic programs, industrial automation project files, internal audit logs detailing unethical activity investigations, whistleblower reports regarding harassment and discrimination, employee disciplinary records, employee PII, passports, driving licenses, medical drug screen results and much more.</i><br />Target victim <b>website</b>: <i>dnow.com</i>]]></description>
<category>Falcon</category>
</item>
<item xmlns:dc='ns:1'>
<title>Glassdoor</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35555</link>
<guid>9e92c56b07777926189cdffe9110dffd</guid>
<pubDate>Sun, 30 Aug 2026 09:54:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Glassdoor</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07414e6bfec164178db6a9fa1bf185ea0484b0e98e59fd6ec7d46f7c3283cbe5</i><br /><br />Threat actor <b>description</b>: <i>glassdoor.com is a U.S. job platform (founded 2007) where employees anonymously review companies — culture, salaries, management. It's owned by Recruit Holdings/Indeed (acquired for $1.2B in 2018; legally merged into Indeed on July 1, 2026). It hosts millions of reviews for ~600,000 companies, plus salary data and job listings. Free for job seekers, monetized via employer branding tools; it also publishes the annual "Best Places to Work" awards.</i><br />Target victim <b>website</b>: <i>glassdoor.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northwest-Trophy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35553</link>
<guid>43b42857454720f741d62c1f5ddc1e90</guid>
<pubDate>Sun, 30 Aug 2026 09:53:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Northwest-Trophy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>70cb875713cb74cc6a0c61f60be2b13638b9428bc6e28736cb51551c086920bd</i><br /><br />Threat actor <b>description</b>: <i>nwtrophy.com rocketreach.co/northwest-trophy-inc-profile_b59c90e0f9bc4cf5 Northwest Trophy & Awards Inc is a fourth-generation, family-owned awards business operating since 1938, with a showroom in Woodinville, WA (Seattle area). It offers personalized awards and gifts: trophies, medals, plaques, crystal and art-glass awards, acrylics, clocks, drinkware and ceremonial items. All engraving and printing (laser, rotary, full-color) is done in-house, serving sports teams, schools and businesses. It sells both through its showroom and an online Shopify store with standard 5–7 day production; a Seattle location was closed in 2023, leaving Woodinville (and previously Bellevue) to serve customers.</i><br />Target victim <b>website</b>: <i>nwtrophy.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adkisson-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35546</link>
<guid>7c0d291483f96b28bcf34828e67b0404</guid>
<pubDate>Sun, 30 Aug 2026 09:51:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Adkisson-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fcb9bc1c386541f9a1c0353adcdd18a7099a2bb966484aa47be440c1726665b9</i><br /><br />Threat actor <b>description</b>: <i>adkissondevelopment.com Adkisson Group / Adkisson Development Group is a privately held industrial real estate development and investment firm founded in 2012 and based in Houston, Texas (4809 Westway Park Blvd / 1130 Enclave Pkwy, Houston, TX 77041). It specializes in office/warehouse, manufacturing and distribution properties — development sites of 10–250 acres and buildings from 6,000 to 455,000 sq ft (its largest current project is the 604,096 sq ft Willow Creek Business Park). Services span development, general contracting through its in-house Adkisson GC Partners (tilt-wall construction), design-build, build-to-suit and site planning. Managing partners are co-founders Steve Adkisson (35+ years in the industry) and Arturo Creixell, plus Anthony Sarao, who heads the GC division; the lean team of ~7–20 staff generates roughly $5.9M in annual revenue.</i><br />Target victim <b>website</b>: <i>adkissondevelopment.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>ESB-Puerto-Rico-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35545</link>
<guid>59a3e5c5684f2219aeba5934fc50e8bb</guid>
<pubDate>Sun, 30 Aug 2026 09:51:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>ESB-Puerto-Rico-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b9ffa318e7a83921da3e9cfda1280b697d4f5001af9b25a3044918078001d0c1</i><br /><br />Threat actor <b>description</b>: <i>esbpr.com ESB Puerto Rico Corp is a distributor of automotive and industrial products that has served Puerto Rico since 1965 ("Energizando a Puerto Rico desde 1965"); it is headquartered in Carolina, PR, is a Hispanic-/minority-owned small business and a federal contractor (CAGE 3DPU1). Its portfolio spans automotive, traction and stationary/backup batteries, tires, lubricants and DEF, AUTEL diagnostics, tools, plus Hyundai and EP forklifts, warehouse equipment, rental, maintenance, OEM parts and e-commerce — a "one-stop source" for material handling, automotive and industrial operations in Puerto Rico and the Virgin Islands, representing ~9 brands (including Eternity Technologies). The president is Omar Aponte; the company stays lean (under ~25 staff, ~$2M revenue) and handles ~150 sea import shipments a year, mostly from Asia.</i><br />Target victim <b>website</b>: <i>esbpr.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>esopartnerscpa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35537</link>
<guid>d35b790f94f3c38cffa277c67bd55da7</guid>
<pubDate>Sun, 30 Aug 2026 09:29:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ZaWoo</b> claims attack for <b>esopartnerscpa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e762959b95a4c4d38d5cdfe7bda8ee1c234c486319e695c992529d480da29088</i><br /><br />Threat actor <b>description</b>: <i>[Unpublished]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ZaWoo</category>
</item>
<item xmlns:dc='ns:1'>
<title>wmdn.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35523</link>
<guid>be6b2f6b6e7d72e528c6123f2cd5568e</guid>
<pubDate>Sun, 30 Aug 2026 09:10:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>wmdn.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04103541373d892d93ece8f26d7a05adc6a014c90a01f90f8cab2b662c7e3f22</i><br /><br />Threat actor <b>description</b>: <i>Twin States News is a media organization that provides comprehensive coverage of local, state, national, and world news. Their services include reporting on various topics such as crime, education, health, politics, and community events. The inten</i><br />Target victim <b>website</b>: <i>wmdn.net</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neogen-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35520</link>
<guid>5124ec804c4633ad5e127f3f9543bc10</guid>
<pubDate>Sat, 29 Aug 2026 21:01:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Neogen-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac1d8b8d04d0ee492e5a45c472b7fc67c33ef1296b70ef31a378dda9120b4256</i><br /><br />Threat actor <b>description</b>: <i>This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 30 Aug 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bandit-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35519</link>
<guid>f64053caa298ce3743d8852cb8510f55</guid>
<pubDate>Sat, 29 Aug 2026 19:28:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bandit-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c446ffdd7ee901e122784284d1c840204428f52cf21d5924a20536a12b68750</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.banditchippers.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>BLISS-1041</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35513</link>
<guid>65086f9dd032d3d47bd1a5e6e9db542a</guid>
<pubDate>Sat, 29 Aug 2026 12:03:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>BLISS-1041</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b981ed3ff6443a762a307be4ddcb3a881205496cc52721f957096f65fbe3454e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.bliss1041.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AUM-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35508</link>
<guid>107aca10b9fd0bb976953ad54c934f05</guid>
<pubDate>Sat, 29 Aug 2026 11:31:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AUM-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93400b5948b1e0e7b70b8c64a2b5a88d787b47dc8fbef97dd746cad92380e017</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.auminc.us</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>trc-companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35503</link>
<guid>5094a17b216782f9ac33129c50981303</guid>
<pubDate>Sat, 29 Aug 2026 06:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>iah6477</b> claims attack for <b>trc-companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fab94c1fe56ef3ba7570d637d7bb85eb30d94d711a9ac7eed50af54d0a02016</i><br /><br />Threat actor <b>description</b>: <i>Size: 4.2 TiB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>iah6477</category>
</item>
<item xmlns:dc='ns:1'>
<title>apatpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35496</link>
<guid>ea6800b170ae74a500d50a77c1cd2b0c</guid>
<pubDate>Sat, 29 Aug 2026 00:28:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>apatpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>730a74cefdbdf8a9864b85a3f127560fbabf2c41ca6ae92e4ffcd849978a1843</i><br /><br />Threat actor <b>description</b>: <i>American Plan Administrators offers smart self-funded healthcare solutions designed to maximize savi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>cutlercapital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35501</link>
<guid>67b291530eb3c8b5bcbbe0d931a59a87</guid>
<pubDate>Sat, 29 Aug 2026 00:28:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>cutlercapital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5aa6e7d8dfde514b2760a63608427dee0d52937e000541da48ed7e9798b9eb3f</i><br /><br />Threat actor <b>description</b>: <i>Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm registered with the Securities and Exchange Commission, specializing primarily in investing in convertible securities, community banks and real estate investment trusts to provide growth and income to high-net-worth investors, corporations, family offices, endowments and charitable foundations. Cutler currently manages $300 million in assets.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oilquip-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35500</link>
<guid>0383bd4aa37e8dd109be3864bc703eda</guid>
<pubDate>Sat, 29 Aug 2026 00:25:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Oilquip-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>670d653f1d136d83d0bb39e2e24302f26a80dfc8004638ebb369bc866ef8fdaa</i><br /><br />Threat actor <b>description</b>: <i>Oilquip Inc, established in 1960, is a comprehensive fluid power distributor that specializes in hydraulics, pneumatics, oil conditioning, and system integration. The company is dedicated to providing innovative electro-hydraulic and electro-mechanical solutions while exceeding customer expectations. Their services include design and engineering, fluid conditioning, power generation, and repairs and upgrades, catering to a diverse range of clients. Oilquip prides itself on its customer-focused approach, flexibility, and commitment to excellence in all aspects of its operations.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>McKesson-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35499</link>
<guid>92ce73519d6ef5260d6786d767e5181c</guid>
<pubDate>Fri, 28 Aug 2026 23:57:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>McKesson-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecabdc44d7693a5711984495064a99251201226d40fb2673ed885cb9bc1ecaba</i><br /><br />Threat actor <b>description</b>: <i>Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jack-Henry--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35494</link>
<guid>98ba58ed593acc910e5d68bfea9ff914</guid>
<pubDate>Fri, 28 Aug 2026 22:57:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Jack-Henry--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25a4e68efc5499a17c6a595eea1f0a5ebdc3359b878a90c46c1ba451d98dd92b</i><br /><br />Threat actor <b>description</b>: <i>This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>H.W.-Lochner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35493</link>
<guid>761cf01dbdd613109777a71dc0f611cb</guid>
<pubDate>Fri, 28 Aug 2026 22:23:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>H.W.-Lochner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d8fd95d71b2e09357ccc430f4b97e9d814ba4a1933fd04bfc89c0992ef5ecf0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] H.W. Lochner is a US-based civil engineering and infrastructure consulting firm. Founded in 1944 and headquartered in Chicago, Illinois, the company specializes in transportation planning, highway design, bridge engineering, environmental services, and construction management. It primarily serves state and local government clients across the United States, supporting public infrastructure projects including roads, transit systems, and related civil works.</i><br />Target victim <b>website</b>: <i>hwlochner.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Newton-County-School-System</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35489</link>
<guid>73ead3de69a5f3dbe5e6010b87e68727</guid>
<pubDate>Fri, 28 Aug 2026 19:34:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Newton-County-School-System</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>653df4b7a23a9fd81d5a19bc718b9edc3d8a5b798d7f438c4035c491534df542</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>corematerials.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35491</link>
<guid>03e3ae4dc11a6abfcd5683caea151a40</guid>
<pubDate>Fri, 28 Aug 2026 17:54:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>corematerials.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10a18b2841bf83b06eae01eda65e8d2666d0ee5a01382db5a8da4351ab4dad65</i><br /><br />Threat actor <b>description</b>: <i>Core Materials (corematerials.com) — Countdown to Publication

Management at Core Materials has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away.

Since leadership refuses to engage, we are m…</i><br />Target victim <b>website</b>: <i>corematerials.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>macallister.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35490</link>
<guid>3c06891375b688d31554f6770fbce90a</guid>
<pubDate>Fri, 28 Aug 2026 17:54:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>macallister.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>022a7bcaa06b1adb9a68553342667ae6cf7393c9ef75ff2a95b842237ac0237d</i><br /><br />Threat actor <b>description</b>: <i>MacAllister (macallister.com) — Countdown to Publication

Management at MacAllister has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away.

Since leadership refuses to engage, we are moving fo…</i><br />Target victim <b>website</b>: <i>macallister.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Health-Team</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35488</link>
<guid>9665de2e7418849f980048e2bf816d30</guid>
<pubDate>Fri, 28 Aug 2026 15:34:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Valley-Health-Team</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48b8e4b9f17cf7aba80bb1ed211e8922decf30e5523cb1a010aead538f0c03c1</i><br /><br />Threat actor <b>description</b>: <i>Valley Health Team 9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>BEPeterson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35481</link>
<guid>007619eedbdde16adf6849f0e993f245</guid>
<pubDate>Fri, 28 Aug 2026 14:22:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>BEPeterson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0660dbd771188b5dce4a2fce6547d769d79b512e550224dc33e248043516b1e</i><br /><br />Threat actor <b>description</b>: <i>BEPeterson is a full-service metal fabricator specializing in custom solutions for vessels, tan
ks, and heavy-gauge metal parts since 1935. The company serves a diverse range of industries in
cluding defense, medical, energy, and industrial sectors, providing high-quality products throu
gh advanced manufacturing techniques.

We will upload 20gb of corporate data soon. Employee personal information, client information, 
projects, financials, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>JRT-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35480</link>
<guid>c7e274f2fe950fbc3d82d36fb2f245f8</guid>
<pubDate>Fri, 28 Aug 2026 14:21:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>JRT-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>248f37b3b9fb2dee0357582b582fc9502d8156dad121bc7eedf2b45464f5b843</i><br /><br />Threat actor <b>description</b>: <i>JRT Mechanical is a full-service mechanical contractor specializing in plumbing, HVAC, hydronic
s, and mechanical insulation, serving the Pacific Northwest for over 30 years. Founded in 1992,
the company has expanded from a small plumbing business to a robust team of over 160 employees
, focusing primarily on commercial and industrial projects.

We will upload 46gb of corporate data soon. Detailed employee personal information (SSNs, passp
orts, DLs, resumes, and another personal docs scans), medical information, client information, 
projects, financials, confidential files, contrast and agreements, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ProCare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35479</link>
<guid>aa1ec9091310e2f702004015db05a86b</guid>
<pubDate>Fri, 28 Aug 2026 13:28:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>ProCare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75fd4561678329a1dc674276f55d083a9282da9f6833960a579de2ebeccc77c5</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

ProCare is a relatively common business name used by multiple unrelated companies across different industries and countries. Without additional context such as industry sector, country, or full legal name, it is not possible to identify a specific organization with confidence and provide accurate threat intelligence relevant information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hanwha-Renewables</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35475</link>
<guid>aa3e602dc876a6d7dccff51c07840900</guid>
<pubDate>Fri, 28 Aug 2026 12:20:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>emperador</b> claims attack for <b>Hanwha-Renewables</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afd50deb24778c800623e25660121f6ccde879c4aa09e5ff9e8f6b33ccc99445</i><br /><br />Threat actor <b>description</b>: <i>The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha.

We extracted around 12GB of highly sensitive information relating to the following projects:

-   Bonanza Peak (3GB)
-   Boulder Solar III (0.7GB)
-   Obreron Portfolio (4.8GB)
-   Project Sprout (3.7GB)

In the data we found highly sensitive information including:

-   PPAs
-   Financial models
-   Interconnection agreements
-   Engineering designs of the assets
-   Personal identifiable information
-   Sensitive reports, budgets, financial information

Reach out to prevent the leak.

Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after your practices and contracts are leak. Good luck looking for financing/investment for these assets with the data leaked. [Size: 11.7 GB | Sector: Energy]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>emperador</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinnium</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35471</link>
<guid>ddd3ac78a14a615e003287228c6ecff0</guid>
<pubDate>Fri, 28 Aug 2026 11:42:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Infinnium</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b075f7239d1eccd7583180e36dc4598b4c52b7feac648ab029123a388e13c678</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Whitehouse</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35472</link>
<guid>309e788d39ad52b4d43dd4001adecaad</guid>
<pubDate>Fri, 28 Aug 2026 11:42:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Whitehouse</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc51135163c3c6c53c406d6b64e1d4547cb7ad5b9b9d76d84bbb5324d42bb4fe</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>amzur.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35474</link>
<guid>bb2da85c47ec0d635ae708645f47475f</guid>
<pubDate>Fri, 28 Aug 2026 11:36:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>unsafe</b> claims attack for <b>amzur.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8dba1b3b4c48191882cf88a105c36b3183e7d9a9f458903d1229875359c39449</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $73.4 million</i><br />Target victim <b>website</b>: <i>amzur.com</i>]]></description>
<category>unsafe</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bayview-Real-Estate-WARNING</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35470</link>
<guid>4857c95f8baac1053d07c7ff89b527cb</guid>
<pubDate>Fri, 28 Aug 2026 06:52:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ShadowByt3$</b> claims attack for <b>Bayview-Real-Estate-WARNING</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0163c6bd3a2701f700f39ad6c0ad0a9e7f4ab4f79bc6d831ae4fdf2782059fa1</i><br /><br />Threat actor <b>description</b>: <i>Check your emails or we will leak the data we are not bluffing we stole 216.6 MB.

compromised email: ruff@livable.com
compromised site: https://pm.livable.com

The following emails below check your emails or spam for proof

- ruff@livable.com
- ir@bayview.com
- TroyGuinn-Bailey@bayview.com
- MichaelMagee@bayview.com
- DavidErtel@bayview.com

Your company has till August 29th 2026 to respond back or it gets leaked but can get extended to monday if your company responds back and negotiates.</i><br />Target victim <b>website</b>: <i>pm.livable.com</i>]]></description>
<category>ShadowByt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Caduceus-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35469</link>
<guid>308fa1ba116122db3d87cd0da6e145bb</guid>
<pubDate>Fri, 28 Aug 2026 03:53:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Caduceus-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4817118107128e4439f88e621799c61fe1fdc8cfb32c0cacd7f4ebd69901d51e</i><br /><br />Threat actor <b>description</b>: <i>Predictable but dangerous data exposed in a healthcare company breach.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>tnmed.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35456</link>
<guid>a631032a4ca53c968fd251959795ec39</guid>
<pubDate>Thu, 27 Aug 2026 21:28:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>tnmed.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba23ba2756b6086de1278510b94ebc92435cd1a8f6b8b8e2b0f8246cb3dad5aa</i><br /><br />Threat actor <b>description</b>: <i>The Tennessee Medical Association is a nonprofit organization that advocates for physicians in Tenne...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>ETNA-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35468</link>
<guid>ab06a50152f06f7f00b44b2189565b75</guid>
<pubDate>Thu, 27 Aug 2026 20:51:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Eclipse</b> claims attack for <b>ETNA-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91873ef3f3e1d3563c2be1050a60dc6d73ba4eee04607b2901dfb148217bf217</i><br /><br />Threat actor <b>description</b>: <i>ETNA Software is a company that provides white-label online trading solutions for brokers and FinTech firms, including mobile and web trading platforms. Their products are designed to help retail broker-dealers launch trading capabilities efficiently and cost-effectively.</i><br />Target victim <b>website</b>: <i>etnasoft.com</i>]]></description>
<category>Eclipse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Our-Hospice-Of-South-Central-Indiana</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35461</link>
<guid>d107823e8deaafd46ec69bba2601473e</guid>
<pubDate>Thu, 27 Aug 2026 18:24:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Our-Hospice-Of-South-Central-Indiana</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f725037756887a5c73a7ac4863bff603e899e6fa04dfbd11a5b925c3da9f833f</i><br /><br />Threat actor <b>description</b>: <i>Our Hospice provides compassionate end-of-life care and dedicated support to patients and their families in South Central Indiana. Their services include hospice care, personal care, palliative care, bereavement care, and specialized programs for veterans and pediatric patients. The organization is committed to ensuring comfort, dignity, and quality of care tailored to individual needs. With a focus on community and compassion, they serve 22 counties, offering 24/7 support to those in need.  2626 E. 17th Street, Columbus, IN 47201 , 51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Salvage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35460</link>
<guid>7052dac9f266e7843faf319350765a98</guid>
<pubDate>Thu, 27 Aug 2026 18:24:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>National-Salvage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e95693daec9ecc62b2ef0f136a01dfe36e8edfeebe7d8dd82fb5017de8a8963</i><br /><br />Threat actor <b>description</b>: <i>National Salvage is a leading treated wood recycler specializing in wood recycling, rail services, and environmental services. With over 40 years of experience, they offer services such as track demolition, bridge demolition, and asbestos abatement. Their product range includes used railroad ties, recycled rail, utility poles, and railroad tie fuel. The company primarily serves clients in need of sustainable solutions for wood and rail recycling. 
The company headquarters is located in 6755 S Old State Road 37, Bloomington, IN 47403, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zion-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35458</link>
<guid>c988286fe12719e8bb8c6e76c05e5963</guid>
<pubDate>Thu, 27 Aug 2026 17:59:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Zion-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fac2de095025d824d54d4dbc6ba4a80124ac115480a527534f64aab383a88aab</i><br /><br />Threat actor <b>description</b>: <i>zionconstructioninc.com Zion Construction Inc is a reputable general contracting and home building company based in Ephrata, Washington.With over three decades of industry experience, they specialize in custom homes, remodeling, and general construction services.The company is recognized for delivering high-quality residential projects and is highly rated among contractors in the region.</i><br />Target victim <b>website</b>: <i>zionconstructioninc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>BENCIVIL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35455</link>
<guid>18491156799c51080e55a1cc72ac93fd</guid>
<pubDate>Thu, 27 Aug 2026 17:55:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>BENCIVIL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1057bb64d238b4fd0de540583d6aa8ee64751e55f6c157b22332d1ca25d9f3cc</i><br /><br />Threat actor <b>description</b>: <i>Benchmark Civil Engineering Services, Inc. is a civil engineering firm based in Allentown, PA, specializing in civil engineering, traffic studies, forensic engineering, and land surveying. The company serves municipalities and clients in the Lehigh Valley and surrounding areas, providing expert services in traffic and transportation engineering, land development, and construction engineering. With a focus on professionalism and integrity, Benchmark is committed to guiding clients through the design, approval, and construction processes. Their highly trained staff utilizes state-of-the-art technology to ensure project success and compliance with regulations.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ipro.comrevealdata.com-customer-DB--full-database-backup</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35450</link>
<guid>d8577a104f9962cb3533946068f61dae</guid>
<pubDate>Thu, 27 Aug 2026 15:55:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>emperador</b> claims attack for <b>Ipro.comrevealdata.com-customer-DB--full-database-backup</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>153409018f9eae36d4509309a3293d7f81d6793a079c781b53dac6a20d8cf00b</i><br /><br />Threat actor <b>description</b>: <i>Yes, this data has been posted before by ME under a different alias, yes the individual that posted the data on cracked.st is a fraud.

I am posting this just for fun.

Data contains:
Customer identifiers, Contact & Location, Account metadata, Internal System IDS, Client relationships.

The full database backup contains everything such as transcripts, cases, though it is from 2023. [Size: 79.5 MB | Sector: Government, Law]</i><br />Target victim <b>website</b>: <i>revealdata.com</i>]]></description>
<category>emperador</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cetylite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35448</link>
<guid>bc2ed059241324f16bb08d020e634321</guid>
<pubDate>Thu, 27 Aug 2026 14:27:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cetylite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2cfa7d90c247beeaa71e1779807237765b903e88ebddcfacaf9b0947a3dc3e13</i><br /><br />Threat actor <b>description</b>: <i>Cetylite, Inc. specializes in dental and medical products aimed at enhancing patient comfort, s
afety, and satisfaction. Their offerings include exclusive specialty products like Cetacaine fo
r dental practices and proprietary Rx and disinfection products for the medical field.

We will upload 6gb of corporate data soon. Employee personal information (passports, DLs, SSNs,
credit cards), client information, detailed financials, confidential files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seabrook-Island</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35446</link>
<guid>54d69e23f13017d66d2d0a23415072ac</guid>
<pubDate>Thu, 27 Aug 2026 14:27:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Seabrook-Island</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d9230332fec34c46c7feaaf37142e253d63e4fb82887e371407d478b28fc6ad</i><br /><br />Threat actor <b>description</b>: <i>Seabrook Island and its stunning natural beauty create the perfect setting for luxury homes enj
oying oceanfront, riverfront, tidal marsh, golf course, and maritime forest views.

We will upload 55gb of corporate data soon. Employee personal information (passports, DLs, SSNs
, personal financials), client information, projects, financials, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ruby-Seven-Studios</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35445</link>
<guid>63d196328512c582293ce6c845521bb6</guid>
<pubDate>Thu, 27 Aug 2026 13:31:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Ruby-Seven-Studios</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5ea5c60988acc4cf850fb25f1f4cd7e1b42455d8d85d9327281e00e49063f1d</i><br /><br />Threat actor <b>description</b>: <i>Ruby Seven Studios Inc. https://www.rubyseven.com/  Total leak: 114 GB (123,463,823,360 bytes), 133,851 Files, 49,357 Folders.  Data: Source code, Games Rules, Game assets, Game math, GDD, IGT, Analytics report Finance doc's, Royalty Reports, Tax invoice,  Inventions Agreement - Employee intellectual property assignment, non competition and confidentiality agreement Personal ID/Passport, Share holders list.  Data type: Confifential   Partners: IGT (International Game Technology), Konami Gaming, Wazdan, Bluberi Gaming, CHAYOWO TECHNOLOGY, Everi & Aristocrat Bally's Corporation, Delaware North Gaming, Pechanga Resort & Casino, Mystic Lake Casino Hotel, Affinity Interactive, Choctaw Casinos & Resorts.  Full publication coming soon.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>DAB-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35437</link>
<guid>0521122bba3fdb214022c1533f268b4c</guid>
<pubDate>Thu, 27 Aug 2026 13:26:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>DAB-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db0cccb7d49ce6cf74e000d15c2d0f886aba761116f6c88f44c881fe9f25603f</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Providence-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35443</link>
<guid>c7c30fd0053ed68c64821a269de80267</guid>
<pubDate>Thu, 27 Aug 2026 11:59:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Providence-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48dab15676c5f0947fa75f1df64016ad1d32cc973af0037da9c3460931533c84</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.providenceinvestments.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capitol-Mechanics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35436</link>
<guid>7ef6e9e2590d825b45c68da5feceb641</guid>
<pubDate>Thu, 27 Aug 2026 08:50:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>emperador</b> claims attack for <b>Capitol-Mechanics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea0d0b03589d77b9774b3ee7a1e100be1754b4eb2c32f9fd61751f5aff1e4b70</i><br /><br />Threat actor <b>description</b>: <i>Capitol Mechanics , fresh databases, important docs [Size: 120.9 MB | Sector: Finance, Transportation]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>emperador</category>
</item>
<item xmlns:dc='ns:1'>
<title>NEXT-LEVEL-MEDICAL-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35421</link>
<guid>d6b7011e4b5b41fc4c9b0fc470013b0c</guid>
<pubDate>Wed, 26 Aug 2026 22:28:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>NEXT-LEVEL-MEDICAL-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>551d5764ec59a22407f186f8b9b6b1a9989d842f390ab2eefb7750ff2695c98d</i><br /><br />Threat actor <b>description</b>: <i>Affordable urgent care across Texas</i><br />Target victim <b>website</b>: <i>nextlevelurgentcare.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>theheartcenterofmemphis.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35418</link>
<guid>36116e9d1a175bb29a06812229468c09</guid>
<pubDate>Wed, 26 Aug 2026 22:27:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>theheartcenterofmemphis.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97f8ecc0826183b9299a704486aa0bbcc568aa423b169dd0416ca529132ab221</i><br /><br />Threat actor <b>description</b>: <i>The Heart Center of Memphis is a leading cardiology practice in the Mid-South, specializing in compr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>proampac</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35420</link>
<guid>53745c007d52b822a57d054c05f159c3</guid>
<pubDate>Wed, 26 Aug 2026 22:24:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>iah6477</b> claims attack for <b>proampac</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bc9644477bd65e4c331fd1622f7ed6bf8c07062296b25214e7f04bf89dc7b34</i><br /><br />Threat actor <b>description</b>: <i>Size: 745.3 GiB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>iah6477</category>
</item>
<item xmlns:dc='ns:1'>
<title>mat-holdings-inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35417</link>
<guid>ae618c0a3cb67308d7299886a7add4b6</guid>
<pubDate>Wed, 26 Aug 2026 20:25:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>iah6477</b> claims attack for <b>mat-holdings-inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30c3995a2c8613b0a04d9c8a0f20a124440c8568a470206a54f20f6823160e24</i><br /><br />Threat actor <b>description</b>: <i>Size: 148.2 GiB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>iah6477</category>
</item>
<item xmlns:dc='ns:1'>
<title>Party-Rental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35409</link>
<guid>d1aecc83b16d6eb76039fd5cad6d77a9</guid>
<pubDate>Wed, 26 Aug 2026 15:36:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Party-Rental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2935be4bcb0c9814f85b9343254c9e023ed13f9458d73a4fd21af39185f22eb2</i><br /><br />Threat actor <b>description</b>: <i>partyrentalltd.com zoominfo.com/c/party-rental-ltd/92603384 is a legitimate, family-owned U.S. event rental company founded in 1972 — one of the largest in the country. HQ and a 300,000 sq ft warehouse are in Teterboro, NJ, with locations in New York City, Philadelphia, Washington D.C., Boston, and the Hamptons.</i><br />Target victim <b>website</b>: <i>partyrentalltd.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oral-and-Maxillofacial-Surgery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35393</link>
<guid>b097988cc1a8beb65497bcbaef7af221</guid>
<pubDate>Wed, 26 Aug 2026 15:22:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Oral-and-Maxillofacial-Surgery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c3c4685fdf7bc72945001d6a218f6abf2d7c991d076f31f8ecece0080642f9a</i><br /><br />Threat actor <b>description</b>: <i>Oral and maxillofacial surgeons Dr. Catrambone and Dr. August , Brockton, MA practice a full scope of oral and maxillofacial surgery with expertise ranging from corrective jaw surgery to wisdom tooth removal.We will upload 14gb of corporate data soon. Employee personal information (passports, phone contacts), client information, financials, patients and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gill-Rock-Drill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35395</link>
<guid>ce1542ca94b4c1147ab2c8155fb41578</guid>
<pubDate>Wed, 26 Aug 2026 13:51:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gill-Rock-Drill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0956afdc217f1c6003893bcceec1db62c520998ca5f46b89d0be1c119d7ca36</i><br /><br />Threat actor <b>description</b>: <i>Gill Rock Drill Company, Inc., located in Lebanon, PA, is a family-owned manufacturer and distr
ibutor specializing in drilling equipment and tools for the drilling industry. The company offe
rs a range of services including contract drilling, rentals, and technical support, focusing on
building strong customer relationships based on integrity and trust. 

We will upload 5gb of corporate data soon. Employee personal information (passports, DLs, w-9 c
omplete forms), client information, financials, payment details, CCs, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ATF</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35383</link>
<guid>92ca5b52d16fb8dc75da8d84deacf408</guid>
<pubDate>Wed, 26 Aug 2026 13:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ATF</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5ea06a2f7ce1edfcaa2c17ea655105d4ab0958b9175522e24b1898b86e83272</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WireCo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35384</link>
<guid>4a481c12f9ce3441585bc800ae000fe8</guid>
<pubDate>Wed, 26 Aug 2026 13:28:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WireCo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>241dd8ec6243d24bf937983b75b054e7b2956872b430094cb930c9527f97691d</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metal-Conversions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35391</link>
<guid>de596bc2f2a21ed618ef73e8f5e9e58e</guid>
<pubDate>Wed, 26 Aug 2026 12:28:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Metal-Conversions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>acacf192b43e5034eb9811ee3d87e2114a1d018001857f60db74b5b168859db8</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.metalconversions.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>California-Truck-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35390</link>
<guid>90092a96d41dc90bde569b2383465360</guid>
<pubDate>Wed, 26 Aug 2026 12:28:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>California-Truck-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8de1a83a5130559a50786324bb3d187c457de0ec15413c9e15c444c7a7c30185</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ctec-truckbody.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Leasing-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35389</link>
<guid>ef1c4f561f75c36a2e9b3aa2892f4010</guid>
<pubDate>Wed, 26 Aug 2026 12:27:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Northern-Leasing-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d92718183c5b865977d971d706695c3170cb47137f497f6c94ed65ef61f92501</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.northerndirect.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ERPIS-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35385</link>
<guid>5c733bd63223c2d18f5d66f0c15a88cb</guid>
<pubDate>Wed, 26 Aug 2026 11:22:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>ERPIS-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecf90c83f0274f60bd87e792c08616abc37effb590bdfdca857c976226e552f7</i><br /><br />Threat actor <b>description</b>: <i>[software] ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by Boeing, Pfizer, NVIDIA, John Deere, Medtronic, and 83 other enterprise customers.

The exposed material includes:

Complete product source code — all versions (2.0–5.4) of ShipERP's ABAP source, the company's sole revenue-generating asset ($20.6M backlog)
<redacted>
Live QuickBooks financial database (705 MB) — complete payroll (SSN, bank accounts, salaries), vendor banking details, AR/AP, and general ledger
Full customer contract register — exact pricing for all 88 enterprise customers with $20.6M in deferred revenue
<redacted>
SAP installation media (245 GB) — full HANA, S/4HANA, and kernel distributions
<redacted></i><br />Target victim <b>website</b>: <i>ERPIS LLC</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>MEMSIC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35382</link>
<guid>9580d8d23af7f51eda1073b791a8c9cf</guid>
<pubDate>Wed, 26 Aug 2026 09:52:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>MEMSIC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90099ba1249666ed56640bd5a87f454a54d5d452638239985b582fa5066b8a13</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1999, MEMSIC is a company that designs, manufactures Flow sensors, Accelerometers, Sensing technology, Inertial systems, Magnetometers, Tilt sensors. MEMSIC is located in Massachusetts.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morgan-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35381</link>
<guid>3b09ac132d106b812e8343f7db0cf253</guid>
<pubDate>Wed, 26 Aug 2026 09:50:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Morgan-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b0fab530e8ed663a4212b5ff388e184f09d1baa9f28278b0f23b4fadddc0e4b</i><br /><br />Threat actor <b>description</b>: <i>Morgan Services, Inc. is a family-owned textile company in business since 1887, they specialize in linen and uniform rental services for all types of facilities. Morgan is headquartered in Chicago, Illinois.</i><br />Target victim <b>website</b>: <i>morganservices.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hamilton</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35380</link>
<guid>018a80ae81cfc70723bc64b08215ef11</guid>
<pubDate>Wed, 26 Aug 2026 09:50:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Hamilton</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b4c2e859741f8ef202f318bdac3f0346771d7263c46b44f099ca6acace1cddb</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1953 and headquartered in Reno, Nevada, Hamilton Company is a global provider in the design and manufacture of liquid handling, process measurement, robotics and automated storage solutions, serving customers in academic and private research laboratories, pharmaceutical and clinical diagnostic companies and government institutions.</i><br />Target victim <b>website</b>: <i>hamiltoncompany.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrex-RCM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35379</link>
<guid>852ff0553e01f89cfcf4efc730e6ba0d</guid>
<pubDate>Wed, 26 Aug 2026 06:24:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Integrex-RCM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8eb3035a6c8ee03331631aed62629cda17d474188bb7d66820c72fc24d583f4</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Air-International-Thermal-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35378</link>
<guid>521bdfc40f2f763bd9ccc267fde55653</guid>
<pubDate>Wed, 26 Aug 2026 01:57:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Air-International-Thermal-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8025f7f2e3417a690b5f5b6c509b88f9f8bb955b3d4c1794c742f24114d99b3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ai-thermal.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brazosport-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35372</link>
<guid>f9465e1db614d85b99594c5978e29d8c</guid>
<pubDate>Tue, 25 Aug 2026 23:30:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Brazosport-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78736c6733cc0853dfc67b056715748e78b3419720b4d03471f8bacbd7f2a735</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Central-Florida-Civil-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35377</link>
<guid>71b1f7deb752aa14e2168e080eccc306</guid>
<pubDate>Tue, 25 Aug 2026 23:23:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Central-Florida-Civil-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38384151ca74c7dfc32611e41ea4b9bd996aa2345c98fc87769713128a71eee9</i><br /><br />Threat actor <b>description</b>: <i>Central Florida Civil, a leading name in underground utilities and site development based in the vibrant city of Belleview, Florida. With a strong foundation built on professionalism, we are dedicated to delivering exceptional service. Demolition, Earthwork, Fire Suppression, General Construction Management.</i><br />Target victim <b>website</b>: <i>network.procore.com/p/central-florida-civil-llc-belleview</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>mswalker.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35370</link>
<guid>10c3aef33ff9c5cabc26fb95279af764</guid>
<pubDate>Tue, 25 Aug 2026 19:24:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>mswalker.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d7c7c5618cad6ef38b5d3af3d04f995ebe97dbd25285df664bce56ec7e21a2b</i><br /><br />Threat actor <b>description</b>: <i>MS Walker (mswalker.com) – Countdown to Publication

Management at MS Walker has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away.

Since leadership refuses to engage, we are moving forward o…</i><br />Target victim <b>website</b>: <i>mswalker.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>copcp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35369</link>
<guid>849c7b9fe5dfea5e93665c8bbfba04f0</guid>
<pubDate>Tue, 25 Aug 2026 19:23:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>copcp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41a15f2e2cdb5d42843b2e214b193fa094549584f18683981a772a5dc4391167</i><br /><br />Threat actor <b>description</b>: <i>Central Ohio Primary Care (copcp.com) – Countdown to Publication

Management at Central Ohio Primary Care has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away.

Since leadership refuses to en…</i><br />Target victim <b>website</b>: <i>copcp.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Kidney-Registry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35368</link>
<guid>60c8179fad5be6d39b73660ca24c8d65</guid>
<pubDate>Tue, 25 Aug 2026 15:57:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>National-Kidney-Registry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7de82453d1b3a90072dd8323551f2a2ddb7aaf5b9064ae178f68074e698a3b56</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] The National Kidney Registry is a nonprofit organization based in the United States that facilitates kidney paired donation programs. It operates within the healthcare and organ transplantation industry, connecting kidney donors and recipients across a national network of transplant centers. Its mission is to improve transplant outcomes, increase the number of living donor transplants, and reduce patient waiting times for compatible kidneys.</i><br />Target victim <b>website</b>: <i>kidneyregistry.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tiseo-Paving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35366</link>
<guid>691f453dee852ba0ea7222427a888edc</guid>
<pubDate>Tue, 25 Aug 2026 15:55:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Tiseo-Paving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60f2847950c8051e0f83a3cbd21acfb2a1df995f000c8d974dd90a303d370659</i><br /><br />Threat actor <b>description</b>: <i>Country: Texas, US |
Website: tiseopaving.com |
Revenue: $22.6 Million |
Industry: Construction, Commercial & Residential Construction |
Employees: 50-100 |
Properties: 457 GB (83,932 Files, 10,829 Folders)</i><br />Target victim <b>website</b>: <i>tiseopaving.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Johnson-City-Honda</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35365</link>
<guid>6c27f03d7e05fafe06f225bcbeb42d3a</guid>
<pubDate>Tue, 25 Aug 2026 15:53:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Johnson-City-Honda</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d0870574ba568d2c11aed12e53cf3e34b17364547ee9d3960cf1da5b7f5fd5d</i><br /><br />Threat actor <b>description</b>: <i>Country: Tennessee, United States |
Website: johnsoncityhonda.com |
Revenue: $6,5 Million |
Industry: Automobile Dealers |
Employees: 11-50 |
Properties: 32.9 GB(34,277 Files, 8,896 Folders)</i><br />Target victim <b>website</b>: <i>johnsoncityhonda.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lockheed-Architectural-Solutions-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35364</link>
<guid>c151e57162f490550b743e688a9abe1e</guid>
<pubDate>Tue, 25 Aug 2026 15:52:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Lockheed-Architectural-Solutions-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1fed3de9fc6c221f895b83ca3e34ae6bd0711739f115e4ccd6b2ea7ed417272</i><br /><br />Threat actor <b>description</b>: <i>Country: Pascoag, RI 02859, United States |
Website: lockheedsolutions.com |
Revenue: $31.2 Million |
Industry: Manufacturing, Construction, Building Materials |
Employees: 100-200 |
Properties: 1.3 TB (558,462 Files, 97,835 Folders)</i><br />Target victim <b>website</b>: <i>lockheedsolutions.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>STRUCTURED-SETTLEMENT-CAPITAL-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35356</link>
<guid>eda01615e3059a5471c9ff1a01559f40</guid>
<pubDate>Tue, 25 Aug 2026 12:28:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>STRUCTURED-SETTLEMENT-CAPITAL-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca48a42235a9ec6b81cf3a0bcf317b99bd63eb4c2428bc28ea0426434e0d0a9b</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.123lumpsum.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Davis--Ferber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35355</link>
<guid>ff778335dae5a3cd6faa7c9589985fdd</guid>
<pubDate>Tue, 25 Aug 2026 12:22:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Davis--Ferber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0488f34211ec92394c326d8061828c7590a3069eb9ebd5fdc9c9dcfb426e62c</i><br /><br />Threat actor <b>description</b>: <i>Davis & Ferber LLP is a personal injury and malpractice law firm based in New York, specializin
g in various legal areas including medical malpractice, motor vehicle accidents, nursing home a
buse, and family law.

We will upload 60gb of corporate data soon. Detailed personal client information (passports, DL
s, addresses, SSNs, death/birth certs, phones and so on for almost a thousand people), confiden
tial files, court files, hearings, police reports, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pump-Engineering-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35353</link>
<guid>9db8f0f4772ca5e1a6187c37826a60ac</guid>
<pubDate>Tue, 25 Aug 2026 09:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Pump-Engineering-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b9a9b574c21cfe10d23ec9d348b4402c614e4cd0757d7dc3d3b75eb34337f73</i><br /><br />Threat actor <b>description</b>: <i>About Pump Engineering Company Pump Engineering Company is a full-service distributor and supplier of industrial pumps, parts, and fluid handling systems, serving Southern California since 1946. During the cyberattack, 120,000 files (115 GB) were stolen, including an extensive customer database, insurance documents, confidential financial documents, and a vast number of project drawings.</i><br />Target victim <b>website</b>: <i>www.pumpengineering.net</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dentist-in-New-Britain-CT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35351</link>
<guid>5d9a211be011de4a592120e7cdbe585a</guid>
<pubDate>Tue, 25 Aug 2026 09:21:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Dentist-in-New-Britain-CT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24486e2e7973e1eddcb55f351fdbec7ac308fcccd3a3484a31cd0b6e115741a4</i><br /><br />Threat actor <b>description</b>: <i>About Dentist in New Britain, CT Dentist in New Britain has spent over a decade caring for families across New Britain—pairing modern technology with the kind of warmth you don't expect from a dental office. As a result of the attack, the following were compromised: the entire customer database, consisting of just over 8,000 files, as well as a small number of records containing Social Security numbers</i><br />Target victim <b>website</b>: <i>dentistinnewbritain.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cosmon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35350</link>
<guid>ba3fe3d296f3e7269b66f163d31b3dc3</guid>
<pubDate>Tue, 25 Aug 2026 06:24:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Cosmon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7cf9d5ae715ab837dbbc780af827b07635251424c74d05fdeae7f8f44b49bc1</i><br /><br />Threat actor <b>description</b>: <i>Cosmon develops agentic artificial intelligence software for mechanical engineering workflows, centered on its Nexus product for CAD, CAE, simulation, and PLM tasks. Its website presents the company as a software provider whose platform automates drawing creation, simulation setup, troubleshooting, design validation, and product lifecycle data tasks while integrating directly with major engineering tools. Although the offering is deeply technical and tailored to engineering environments, the core business shown is the development and delivery of proprietary engineering software rather than providing outsourced engineering services or general consulting. https://cosmon.com https://www.zoominfo.com/c/cosmon/5000578320</i><br />Target victim <b>website</b>: <i>www.cosmon.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>SHAHEEN-LAW-GROUP-PLC---Richmond-Virginia-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35348</link>
<guid>a41e84649fcc388f3e64a1f45a720c12</guid>
<pubDate>Mon, 24 Aug 2026 21:21:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Deadlock</b> claims attack for <b>SHAHEEN-LAW-GROUP-PLC---Richmond-Virginia-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80682b94da38727b4eda6adaf3d8fe93368a5a08b0fe5caa0c3329bcd2a4fbbb</i><br /><br />Threat actor <b>description</b>: <i>Family law firm, established 1995 by Victor A. Shaheen (†2025 - the General Assembly of Virginia honored him with a resolution; google it, it is touching). Now run by his three sons. 48 employees across four offices: Richmond, Midlothian, Virginia Beach, Newport News. What do they do? They close 150+ real estate transactions EVERY MONTH for some of the largest corporate relocation programs in America. When a Fortune-500 moves an employee to Virginia, this firm holds that employee's Social Security Number, bank wiring details, home address, family identities, and sometimes their medical clearance. They hold everyone's future in a shared folder. We now hold the folder. WHAT WE TOOK 36,788 files · 27GB · 21,789 fully read 67,000+ SSN patterns (their own dedup says 6,017 real people — we will let their customers decide which number to believe) EVIDENCE — SERIES PREVIEW (from their actual files) - S1 DEEDS WITH SOCIAL SECURITY NUMBERS File: "5053815 - Unsigned Deed.docx" (verbatim from their server): "***-**-XXXX B•••• H••• Social Security Number ***-**-XXXX J••••• H••• Social Security Number 10356 Ashburn Road, North Chesterfield, VA 23235" File: "Kelley 5042085 - DEED.docx": "PURCHASER(S): N••••• S••• SELLER'S NAME: S••• E. K•••• SS#: ***-**-XXXX ...including the withholding of twenty percent (20%) of the sales proceeds." ← FIRPTA: foreign sellers. IRS will want this list. We have it. Thousands of these. Every deed folder = a name, a number, an address, a transaction. Their client roster IS the leak. - S3 INSIDE THEIR BANKING & THEIR NETWORK File: "shared_Accounting/Banking/Other Banking/Shaheen DDA Statements SunTrust DDA" (email from SunTrustOnlineCourier to their own staff — headers verbatim): Received: from barracuda.shaheenlaw.com ([10.0.0.6]) by ricdcex1.shaheenlaw.com ... X-ASG-Debug-ID: 1291233029-... for ; Wed, 1 Dec 2010 Why we publish an email HEADER: their internal map is in it. Barracuda at 10.0.0.6. Exchange "ricdcex1". Domain SHAHEENWORLD. We did not forget how to enter. Neither will the next group, when we sell the map. 150 banking statement attachments ride along in this folder. - S5 THE CLIENT LIST, WRITTEN IN FOLDERNAMES They named folders after their customers. Verbatim paths: shared_PENDING_SALE/HENNY/Closed Files/ Wisniewski-Markel, Suzanne_5027384_12263 Eagle ... Merza, Jamal & Adrienne_5027826_811 Woodberry ... Name, file number, STREET ADDRESS — in the path itself. Marketing lists sell for money. This one is annotated with purchase history. Relocation buyers are premium leads. - S2 MEDICAL - S4 LITIGATION Held. 120 medical files exist (their own audit counted them). Litigation: we confirm their December escrow dispute is public (Porchlight Homes v. Almeida & Shaheen, Henrico — google it, BizSense covered it). Virginia residents: §18.2-186.6. Illinois relocations: BIPA. Opposing counsel and journalists: samples on request. Media & researchers: samples on request, we answer fast We keep our word to everyone who pays. We keep it also to everyone who does not.</i><br />Target victim <b>website</b>: <i>slgjustice.com</i>]]></description>
<category>Deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Liberty-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35345</link>
<guid>7c2410c8be77b896e8a5b26d1a994a23</guid>
<pubDate>Mon, 24 Aug 2026 18:21:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>The-Liberty-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf0067a857889c9a1a41f2b6a53be77ae939ef837c0a4b89609ce963f1ce2f73</i><br /><br />Threat actor <b>description</b>: <i>About The Liberty Group Companys offerings include local, long distance, and international moving, lab relocation services, and logistics solutions. They cater to a diverse range of clients, providing professional and comprehensive assistance to both residential and commercial customers. Investigators are working to identify the perpetrators and assess the full scope of the damage. A company has suffered a major cyberattack resulting in the theft of approximately 27,000 internal files. The leaked documents include financial records, internal working materials, and personal data of employees. Attackers encrypted the company's systems following the breach, severely disrupting operations</i><br />Target victim <b>website</b>: <i>libertygrp.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jones-Little--Co.-CPAs-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35344</link>
<guid>8146323ea464375d32c02c8df59d8c39</guid>
<pubDate>Mon, 24 Aug 2026 18:20:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Jones-Little--Co.-CPAs-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32adeba684be8cdc6a6138cd3cf97fe600bc977e8c8f7f3ef602af5d9d125ce7</i><br /><br />Threat actor <b>description</b>: <i>About Jones, Little & Co., CPAs, LLP Jones, Little & Co., CPAs, LLP is a professional accounting firm that offers a wide range of services including business accounting, tax preparation, and IRS problem resolution. They cater to small businesses, non-profit organizations, and specialized industries such as auto dealers and retailers. At least 100 gigabytes of company data—including financial records, internal files, and employee personal information—were stolen in a cyberattack. Hackers encrypted the firm's systems after exfiltrating the documents, leaving operations paralyzed.</i><br />Target victim <b>website</b>: <i>www.jonesandlittle.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Design-Aire-Engineering-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35343</link>
<guid>b4fb5bfbd950582c8c18e541406c66e6</guid>
<pubDate>Mon, 24 Aug 2026 17:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Design-Aire-Engineering-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b99e47b1cd2023497aaf31d18f6fbd387e012b6d2864ddcededf6922dc2bba1a</i><br /><br />Threat actor <b>description</b>: <i>About Design-Aire Engineering, INC Design-Aire Engineering specializes in mechanical, electrical, plumbing, and energy engineering services. They focus on providing innovative and sustainable solutions for their clients. The company serves a diverse range of clients, including those in the public and private sectors. With a commitment to green engineering practices, they aim to enhance energy efficiency and environmental sustainability. Design-Aire Engineering, INC has suffered a cyberattack on its service systems, resulting in the theft of approximately 377GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings.</i><br />Target victim <b>website</b>: <i>www.daengineering.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Furnished-Quarters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35342</link>
<guid>98ec5a26e93d3c0e9a96e525be06e014</guid>
<pubDate>Mon, 24 Aug 2026 17:51:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Furnished-Quarters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dba914a32e8355dee5cfa3594068b2734c62a790316cb758e19f5414d9f4a565</i><br /><br />Threat actor <b>description</b>: <i>About Furnished Quarters Headquartered in New York City, New York, Furnished Quarters, is to deliver exceptional residential experiences with passion, reliability and integrity always innovating and putting people first. They consider this in everything they do and every guest and client experience they deliver. The company "Furnished Quarters" was the victim of a successful cyberattack, as a result of which the company’s confidential data was stolen. The volume of data stolen amounts to 155 GB. The data stolen included the company’s customer details, as well as documents containing banking and financial information. Currently, around 198,000 files are no longer under the control of "Furnished Quarters".</i><br />Target victim <b>website</b>: <i>www.furnishedquarters.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bihl</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35336</link>
<guid>a8b49816330ad984a1948f4e9f883d93</guid>
<pubDate>Mon, 24 Aug 2026 17:29:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bihl</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>248a4a262586fda197810cc3ecbfba0b9773f5698116800b2dda2c30d368001f</i><br /><br />Threat actor <b>description</b>: <i>Boustead International Heaters (BIH) is a leading global designer and supplier of thermal process equipment, including direct fired heaters, waste heat recovery units (WHRUs), and heat recovery steam generators (HRSGs).We will upload 392gb of corporate data soon. Huge amount of detailed personal employee information (passports, DLs, addresses, SSNs, death/birth certs, phones, contacts), confidential financials and agreements and contracts, client information, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>FFKR-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35339</link>
<guid>ac3485ecf4fcd5d56323ed2373fd7e32</guid>
<pubDate>Mon, 24 Aug 2026 15:53:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>FFKR-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>592b173131df81cb501f8a297f6ef7e485343257e190160cd98885455f749fc9</i><br /><br />Threat actor <b>description</b>: <i>FFKR Architects is a leading architecture and interior design firm based in Utah, with additional offices in Arizona and Idaho. They offer a wide range of services including architecture, landscape architecture, interior design, and environmental graphic design. The firm is known for its design excellence and commitment to environmental leadership, serving various sectors such as healthcare, education, hospitality, and commercial projects. With a team of over 170 professionals, FFKR empowers clients through innovative visualization techniques, ensuring informed decision-making.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brookview-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35338</link>
<guid>abc58d2523df2aea708a509fbd201437</guid>
<pubDate>Mon, 24 Aug 2026 15:25:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Brookview-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d440dfa189571d710858dd38459b7b1736538c336d03c19a19e4198a674ac3a</i><br /><br />Threat actor <b>description</b>: <i>(data of many thousands of customers, including credit reports, SSNs, addresses, etc.) Brookview Financial is a boutique private lender specializing in quick-close financing solutions for real estate projects. Established in 1992, the company has served as a trusted capital partner for thousands of real estate investors across the nation. They offer a range of loan programs, including commercial bridge loans, fix & flip loans, and special situation financing, with amounts ranging from $75,000 to over $50 million. Known for their personal service and flexible terms, Brookview can close deals in as little as 7 days.</i><br />Target victim <b>website</b>: <i>www.brookviewfinancial.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wozair</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35337</link>
<guid>cf24f44a79866351337c1b317ffdc18d</guid>
<pubDate>Mon, 24 Aug 2026 15:24:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Wozair</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eef7a6c043a404882531223f06325369c8da98f151699b7475c69eddbff731e4</i><br /><br />Threat actor <b>description</b>: <i>Wozair specializes in the design, manufacture, and installation of heavy-duty heating, ventilating, and air conditioning (HVAC) products for various sectors including Marine, Naval, Military, Nuclear, Oil and Gas, Powergen, and Renewables. Their product range includes air handling units, dampers, filtration solutions, and refrigeration systems. Wozair also offers services such as system design, project management, manufacturing, commissioning, and maintenance. The company aims to provide bespoke solutions to meet specific client requirements while ensuring a safe working environment.</i><br />Target victim <b>website</b>: <i>wozair.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chernyy--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35334</link>
<guid>82bb153bc3037adf373b43babcfffd03</guid>
<pubDate>Mon, 24 Aug 2026 14:50:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Chernyy--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f290366522bc3e3766befab36028623db02f8c4336d6cee2ec831d49f89dbfd</i><br /><br />Threat actor <b>description</b>: <i>Law Practice Stolen data: 67 GB.</i><br />Target victim <b>website</b>: <i>www.chernyy-law.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>ManagementPro</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35333</link>
<guid>28ffe17ac4a1b39d5cf3b5405f1c1dc6</guid>
<pubDate>Mon, 24 Aug 2026 14:24:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>arcusmedia</b> claims attack for <b>ManagementPro</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e63f1e899309d7258d273d9b9840275e085afa217aadf4c0c9dd8573d40fa38d</i><br /><br />Threat actor <b>description</b>: <i>www.mproerp.comManagementPro Inc. is a Computer Software Company, specialized in ERP Solut Deadline: 2026-08-31 13:50:00.000000</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>arcusmedia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Country-Wide-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35327</link>
<guid>4c1ed2facc7f349e4810f522a6ea9990</guid>
<pubDate>Mon, 24 Aug 2026 13:50:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Country-Wide-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e81ffb14dbd7055f0d4de5df78946073757a798b1fd6040c6baab42a1122f13</i><br /><br />Threat actor <b>description</b>: <i>Insurance Stolen data: 92 GB.</i><br />Target victim <b>website</b>: <i>www.cwico.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>AE--SMA-Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35324</link>
<guid>5ec8b136da1b014682313777cb7a82ee</guid>
<pubDate>Mon, 24 Aug 2026 11:29:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AE--SMA-Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dba2be05706be95f6f3458a5949253f4ecc68160de436fa621a18843cc4d4073</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ae.design</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Mitchell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35322</link>
<guid>023eae08cd291f454a56b1a29084f1ea</guid>
<pubDate>Mon, 24 Aug 2026 04:51:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>City-of-Mitchell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce6de0932c470740556a4f94d8ec19b41d578264fd643358a2bae70505e970c3</i><br /><br />Threat actor <b>description</b>: <i>Mitchell is a city in and the county seat of Davison County, South Dakota, United States. Mitchell is the principal city of the Mitchell Micropolitan Statistical Area, which includes all of Davison and Hanson counties. 
The company headquarters is located in 612 N Main Street, Mitchell, SD 57301, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hospitality-Health-ER-Longview</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35320</link>
<guid>3a93c1c593e624d2d0a6ea4c55e9cfd2</guid>
<pubDate>Sun, 23 Aug 2026 21:27:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Hospitality-Health-ER-Longview</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd270c0541ac491f30746bc5072ea648b0cea0810cede2fa602c282900a40802</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>CyrusOne-LLC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35318</link>
<guid>f8efc7c14e9be56f00e682929c90beea</guid>
<pubDate>Sun, 23 Aug 2026 20:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>CyrusOne-LLC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4a4815b8fdfbe85f41bdb659519e9d7805f2065181de403e96e72c8214bd74c</i><br /><br />Threat actor <b>description</b>: <i>Update 23 Aug : We are removing the clients name off this post. They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records along with: Sharepoint:
(369.6 GB Compressed / 645 GB Uncompressed)
288,729 Files, 60,513 Folders

- More than 182,000 rows of Customer data Extracted from the "Contacts" Salesforce Object. - Over 8,300 Rows of Employee PII (Full Name, Email, Job Title, Phone Number, ect.) - Thousands of executed contracts, MSAs, NDAs, amendments, leases, and SOWs - Extensive physical key inventory logs, verification photos, and contractor Green Badge audits - Large collection of data center drawings, floor plans, electrical one-line diagrams, security system drawings, and site schematics - Full CERM (Critical Environment Reliability Management) process library - Physical and information security policy suite plus governance materials - Regional security scorecards, KPI workbooks, GAM sheets, and signed performance packages - Credential and access-control artifacts (including PasswordList.xlsx, Okta SSC Access lists, active badge reports, and multiple Data Center Access Control forms) This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>adt.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35316</link>
<guid>e0234fe2a53821ae8e5e90de581eeb81</guid>
<pubDate>Sun, 23 Aug 2026 19:30:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>adt.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6aefde123faa8e709f4594ad9ba7803ce65854427f1930391046eaf7aa5bd2e5</i><br /><br />Threat actor <b>description</b>: <i>ADT is a security company that offers security systems, cameras, alarms ad home automation services....</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>compendiumusa.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35310</link>
<guid>dd093b11f9127e9d7d591129be671183</guid>
<pubDate>Sun, 23 Aug 2026 13:51:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>compendiumusa.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e8ae481a597b084ea01c6f36504a01b74cc4e1f6815b042f410badba823b258</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>compendiumusa.net</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clear-Align</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35309</link>
<guid>6b72b336f3b704bf09040e76c23c8fb3</guid>
<pubDate>Sun, 23 Aug 2026 12:28:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Clear-Align</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b864810b502ca5169ecd63a55c9107295795062f35412f96d7f6997566c46e6f</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.clearalign.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trailer-Transit-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35295</link>
<guid>5cf0b0751a223522c722f87bc8a9628d</guid>
<pubDate>Sun, 23 Aug 2026 07:38:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>metaencryptor</b> claims attack for <b>Trailer-Transit-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59c276ded5211ed73df6791f0988ca526796b136063f450158e0ffe61be1e961</i><br /><br />Threat actor <b>description</b>: <i>Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dependable and accurate trailer transport solutions.
Revenue: $22 M</i><br />Target victim <b>website</b>: <i>www.trailertransit.com</i>]]></description>
<category>metaencryptor</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weber-Water-Resources</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35294</link>
<guid>f9eec82a0e93d4003e661c3bdc2518c3</guid>
<pubDate>Sun, 23 Aug 2026 07:37:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>metaencryptor</b> claims attack for <b>Weber-Water-Resources</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35110a07cc4e3808b9a2f24820dfffb3e0167c226f05c14d24855487fb421331</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1910, Weber Water Resources has been providing the widest range of water resource solutions at the lowest available risk to clients for over a century.
Through our superior problem solving ability, Weber Water Resources partners with public and private clients to achieve the most equitable outcome possible on each project.
revenue $25 M</i><br />Target victim <b>website</b>: <i>www.weberwaterresources.com</i>]]></description>
<category>metaencryptor</category>
</item>
<item xmlns:dc='ns:1'>
<title>FactoryFive</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35290</link>
<guid>14cecc84bfa6e02cce5e85d6e1aa4529</guid>
<pubDate>Sun, 23 Aug 2026 07:34:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>metaencryptor</b> claims attack for <b>FactoryFive</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af2860114e7b823f66ab4fefdf2c5bbe72a9dcf3ecff9cba8e1cf485918f766e</i><br /><br />Threat actor <b>description</b>: <i>Factory Five Racing Inc — kit-car manufacturer (Cobra replicas, GTM, Type 65 Coupe, 33 Hot Rod). 9 Tow Road, Wareham MA 02571-1086. ~90 employees, 158 endpoints. Revenue $5.5-6.5M/yr (credit card processing ~$4.3M, avg ticket $1245).

Exfiltrated data categories (~130GB): correspondence (PST archives), CRM contacts (GoldMine), ERP/pricing, engineering CAD (SolidWorks/Rhino), banking statements, insurance policies, tax documentation, legal contracts/NDAs, database backups. Includes detailed materials on several ongoing lawsuits — parties, witnesses, testimonies, and related case files, alongside private correspondence.

Risk zones: PCI DSS (card processing $4.3M/yr), MA 201 CMR 17.00 (Massachusetts personal data protection), GDPR (EU clients), CCPA (California clients), active IRS audit, active MA Sales Tax audit, FTC Safeguards Rule. Reputational: customer warranties, partner contracts (SEMA supplier), licenses, litigation exposure. CEO: David T. Smith.</i><br />Target victim <b>website</b>: <i>factoryfive.com</i>]]></description>
<category>metaencryptor</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clinical-Associates-of-the-Finger-Lakes-CAFL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35287</link>
<guid>d87b4975632db1483e0a987baef53574</guid>
<pubDate>Sun, 23 Aug 2026 07:06:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Barracuda</b> claims attack for <b>Clinical-Associates-of-the-Finger-Lakes-CAFL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fecb2e58154b9c175bbe53000ec2574b16f0e92646f4257644e4d2cc2974ae8f</i><br /><br />Threat actor <b>description</b>: <i>The company mishandled its clients' and employees' data, which is why it was leaked. We extracted all files and documents from the infrastructure. These documents included children's medical records, personal information of parents and employees, a full dump of all emails from the mail server, and much more.
Target website: https://www.clinassoc.com/
 | Severity: HIGH | Size: 447 GB | Status: selling | $1000</i><br />Target victim <b>website</b>: <i>clinassoc.com</i>]]></description>
<category>Barracuda</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ruggles-Sign-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35285</link>
<guid>947501a196966253d01a63be8a17e8cd</guid>
<pubDate>Sun, 23 Aug 2026 06:45:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Ruggles-Sign-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>befc530f3574b33683164dec8eeff6fede02f62adf4612dac0725cf48a31489a</i><br /><br />Threat actor <b>description</b>: <i>Ruggles Sign Company is a family-owned business with over 75 years of experience in providing personalized service in the signage industry. They offer a comprehensive range of services including project management, design, manufacturing, installation, rebranding, and maintenance for global, national, and regional signage. Their clients include well-known brands such as Nike, J. Crew, and Under Armour, showcasing their capability to handle diverse signage needs. Ruggles Sign is committed to excellence and sustainability, making them a trusted partner in bringing brands into view. 
The company headquarters is located in 93 Industry Drive, Versailles, KY 40383-1470, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>rugglessign.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>AutoDie</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35284</link>
<guid>54fe5a851b42e219fba334ed340defac</guid>
<pubDate>Sun, 23 Aug 2026 06:44:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>AutoDie</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58b4aba076da1f966dcd6d94fe55c10be72ef3fa5ed27134b6bb3e36e5dd8fba</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1962 and headquartered in Grand Rapids, MI, Autodie LLC is a company that specializes in design and manufacture large-scale dies for metal stamping. 
The company headquarters is located in 44 Coldbrook Street NW, Grand Rapids, MI 49503, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>autodie-llc.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Proveli</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35283</link>
<guid>f365c0e4bc0642c916d918d58d764f01</guid>
<pubDate>Sun, 23 Aug 2026 06:43:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Proveli</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a72612cc7ca6de6cdd38f659e790a737128ae612fc65ff28d334a0b4fb9fca5</i><br /><br />Threat actor <b>description</b>: <i>Proveli is a privately held business founded by two brothers: Reinhardt and Thomas. Proveli prides itself on having an entrepreneurial culture that encourages and rewards innovative thinking, collaboration, and ownership. The company's greatest asset is the company's passionate and dedicated team; it's their drive and passion for developing and executing strategies that have lead to the company being recognized for its accomplishments. Proveli is constantly searching for and evaluating organic and acquisition growth opportunities. If you have an investment opportunity that you feel would be a good fit for Proveli, please contact the company. The company encourage you to read about how we've cultivated a unique and dynamic culture at Proveli - one that helps the company build companies that make a difference. 
The company headquarters is 1900 S Liberty Drive, Bloomington, IN 47403, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>proveli.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pinnacle-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35282</link>
<guid>02cf7b95eaf630256990316ef6d5bcb3</guid>
<pubDate>Sun, 23 Aug 2026 06:42:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Pinnacle-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af6d5fd8e961aa93c1e7aa2008e3479fc29986fdf5bb27faf19ad968890b62ee</i><br /><br />Threat actor <b>description</b>: <i>Pinnacle Healthcare / Pinnacle Hospital is a physician-owned, patient-centered healthcare organization operating an 18-bed acute care hospital in Crown Point, Indiana. The company provides a wide range of medical and surgical services through a network of more than 150 physicians and medical specialists. Its services include family medicine, internal medicine, gastroenterology, general surgery, gynecology, orthopedics, pain management, urology, breast care, specialty clinics, and walk-in care. Pinnacle Healthcare focuses on delivering personalized, high-quality care in a smaller hospital environment, emphasizing patient satisfaction, efficient treatment, personal service, and respect for patients and their families. 
The company headquarters is located in 9301 Connecticut Drive, Crown Point, IN 46307, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>pinnaclehealthcare.net</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phoenix-Group-of-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35281</link>
<guid>f6026b2fee4a55c46ac4618a77825d6d</guid>
<pubDate>Sun, 23 Aug 2026 06:41:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Phoenix-Group-of-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2da1ae7478c88753cf1b3b03d575bbdd3ad40b5e0263949a92d6648ea966d2b7</i><br /><br />Threat actor <b>description</b>: <i>The Phoenix Group of Companies is a leading single-source provider of print solutions from concept to completion that produces high quality communications to help businesses rise above the competition and overcome everyday challenges. 
The company headquarters is located in 11631 Caroline Road, Philadelphia, PA 19154, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>phoenixlitho.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schardein-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35280</link>
<guid>b801759e5fe60c6715cdbb0a8a4574c1</guid>
<pubDate>Sun, 23 Aug 2026 06:41:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Schardein-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45819df908aa329f0a2afcb1e72b227d9bb1f7638d941dff6da3026aee3bfdb5</i><br /><br />Threat actor <b>description</b>: <i>Schardein Mechanical is a trusted mechanical contractor providing top-of-the-line engineering services to commercial clients in Kentucky and Southern Indiana. Their offerings include design, installation, maintenance, and replacement of HVAC, plumbing, and process piping systems, with 24/7 availability for emergency services. The company caters to a diverse range of industries, including healthcare, education, and manufacturing, ensuring high-quality installations by skilled professionals. With multiple locations in Louisville, Elizabethtown, and Bowling Green, Schardein Mechanical has been delivering innovative solutions since 1984. 
The company headquarters is located in 1810 Outer Loop, Louisville, KY 40219, United States.. 51-200 Employees</i><br />Target victim <b>website</b>: <i>schardein.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Cecilian-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35279</link>
<guid>a07574c09d0fbeffb49bdc14fed25be3</guid>
<pubDate>Sun, 23 Aug 2026 06:40:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>The-Cecilian-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3933474d07f8925353cea31604a03410a587e80541c65143d3b139c5bb14bf89</i><br /><br />Threat actor <b>description</b>: <i>The Cecilian Bank is an FDIC-insured financial institution that offers a wide range of personal and business banking services, including checking and savings accounts, loans, and online banking. Their services cater to individuals, small businesses, and large corporations, providing competitive rates and tailored financial solutions. The bank emphasizes convenience with features like online account opening and 24/7 access to banking services. With a commitment to community support, The Cecilian Bank aims to help clients achieve financial independence and business growth. 
The company headquarters is located in 104 East Main Street, Cecilia, KY 42724, United States.. 201-500 Employees</i><br />Target victim <b>website</b>: <i>thececilianbank.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crystal-Pharmatech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35278</link>
<guid>27f401111d659095fc1de22a7895585f</guid>
<pubDate>Sun, 23 Aug 2026 06:35:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Eclipse</b> claims attack for <b>Crystal-Pharmatech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>404aee7f2152256239814bf611edb0bf10e360624a0c28488c2acccc31d1ea00</i><br /><br />Threat actor <b>description</b>: <i>Crystal Pharmatech is a technology-driven contract research organization (CRO) that focuses on materials science and engineering for drug development. Established in 2010 and have R&D centers located in Suzhou (China), New Jersey, San Francisco (USA), and Toronto (Canada). Also its key differentiator is integrated and specialized services, including API solid-state research, crystallization, preformulation, formulation development and manufacturing, clinical supply.</i><br />Target victim <b>website</b>: <i>www.crystalpharmatech.com</i>]]></description>
<category>Eclipse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eyecare-Center-of-Snohomish</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35276</link>
<guid>40b28f4fc90cff423e2a75266497539f</guid>
<pubDate>Sun, 23 Aug 2026 06:34:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Eyecare-Center-of-Snohomish</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db9e75a1e94802bcf14da479f406d0902887294db8d3fd1087659b266d7e3fcc</i><br /><br />Threat actor <b>description</b>: <i>eyecarecenterofsnohomish.com zoominfo.com/c/eyecare-center-of-snohomish/442336650 Eyecare Center of Snohomish is a trusted optometry clinic in Snohomish, Washington, proudly serving its community since 1964.
They offer comprehensive vision and medical eye exams, diagnosing and treating various eye diseases to ensure long-term ocular health.
The clinic also features a full-service optical boutique offering custom-fitted contact lenses and designer eyewear frames from top global brands.</i><br />Target victim <b>website</b>: <i>eyecarecenterofsnohomish.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gould-Sherwood-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35275</link>
<guid>2db559a91e35ed06d98446aa9cbbcc73</guid>
<pubDate>Sun, 23 Aug 2026 06:34:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Gould-Sherwood-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efe78f1fc4a79cf3012c4de941f6ad8d4b2c3a73b908f6692bd8b7ab609767ab</i><br /><br />Threat actor <b>description</b>: <i>gouldsherwood.com zoominfo.com/c/gould-sherwood-consulting-llc/347553210 Gould-Sherwood Consulting is a boutique IT support and services firm based in Lexington, Massachusetts, serving the Greater Boston area since 2005.
They specialize in comprehensive computer and network support, including planning, maintenance, and troubleshooting for both Mac and PC environments.
The company primarily caters to small-to-medium businesses, creative professionals, and home users, ensuring their technology infrastructure runs smoothly and securely.</i><br />Target victim <b>website</b>: <i>gouldsherwood.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>ReliaQuest-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35271</link>
<guid>259e4f9d773fc3f47a8da903eb313bcf</guid>
<pubDate>Sun, 23 Aug 2026 02:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>ReliaQuest-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>caccdd3eaa461ac8204792ec957ade9d19bac7cff86298894209df84ff5eb46e</i><br /><br />Threat actor <b>description</b>: <i>This time the post is about you , not us. Let Mandiant report and advise on us accurately, go away. DISCLAIMER: This information is being provided "as is" for informational purposes only. We do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this post. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favour by us. | Updated: 23 Aug 2026</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>AmSpec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35269</link>
<guid>7888220d6fa80e0ba9f548a8ea9f1678</guid>
<pubDate>Sat, 22 Aug 2026 19:21:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>AmSpec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dad69e162d2344ec369ed95eac298443c74f13bd786e243d46192353e49613b</i><br /><br />Threat actor <b>description</b>: <i>AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>BOK-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35266</link>
<guid>e227a50c6ba35a28e0afe9be9727c6fe</guid>
<pubDate>Sat, 22 Aug 2026 14:13:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>BOK-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf5963a8866a26df0389ca82d4ffbb10c15a8f076b401b0dfae27a5bdeec6ba4</i><br /><br />Threat actor <b>description</b>: <i>This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>bokfinancial.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Health-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35265</link>
<guid>179762314bd6cebdd0921b95725eabe3</guid>
<pubDate>Sat, 22 Aug 2026 14:01:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Integrated-Health-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3da3b06c640d5468f1c7b7c219c9e9720e705f25296f86889337eb68ea4d689c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>ihs911.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Longhorn-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35260</link>
<guid>c8caec337df345589c23aa47ea6bb43b</guid>
<pubDate>Sat, 22 Aug 2026 13:57:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Longhorn-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5e6409ee5eeaea36b18d79dc376dcf8b93d4a102848d535f3360b2e7d190ff1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>longhorninvestments.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kessler-Creative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35259</link>
<guid>e7e83e3735e7cc2c714ab560f390af18</guid>
<pubDate>Sat, 22 Aug 2026 13:57:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Kessler-Creative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3444a9ed0706073ea7041e1357f2ff3ea5e57b375c479a0dae1e85446b72a091</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>kesslercreative.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Klasko-Immigration-Law-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35258</link>
<guid>cb0d7d065d3aeb0dbe63ff465dd1be1b</guid>
<pubDate>Sat, 22 Aug 2026 13:56:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Klasko-Immigration-Law-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21c308a91435aea87d4d10fed19daa4e90a98c6abbcbc1485a0ea17f10bc35af</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Klasko Immigration Law Partners is a US-based immigration law firm headquartered in Philadelphia, Pennsylvania. The firm specializes in business immigration law, assisting corporations and individuals with employment-based visas, green cards, and compliance matters. It serves multinational companies, healthcare organizations, and academic institutions, providing legal counsel on navigating US immigration regulations and workforce mobility challenges.</i><br />Target victim <b>website</b>: <i>klaskolaw.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Patel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35257</link>
<guid>e2baa26aab68689ff0f2eaa57bec64c3</guid>
<pubDate>Sat, 22 Aug 2026 13:55:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Patel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ad1453170e36efe4b067636916852c63011169ca3ae7ad2e4ac5398d349f477</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

The name "Patel" is too generic to identify a specific company with reliable information. It is a common surname and business name used by numerous unrelated entities across many industries and countries. Please provide additional context such as the full company name, industry, or country to allow for an accurate description.</i><br />Target victim <b>website</b>: <i>patelcpaoffice.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abacus-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35256</link>
<guid>69b86f4ce0394ef6d54f3033081bd3e1</guid>
<pubDate>Sat, 22 Aug 2026 13:54:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Abacus-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>15f3c3b02285b93f6b92bca0df16b106f99af38238732f4a53010fb6eb5b208a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>abacusadv.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mogren-Glessner--Ahrens-P.S.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35243</link>
<guid>b175d7621b125020bec85e7165144da9</guid>
<pubDate>Sat, 22 Aug 2026 07:57:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Mogren-Glessner--Ahrens-P.S.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e01e7025e52c34d4ce7d97ae310ca74cc8d40293752d58b440e41a38da2d9c7</i><br /><br />Threat actor <b>description</b>: <i>Services in family law</i><br />Target victim <b>website</b>: <i>mgrlaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>CRI-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35242</link>
<guid>a4ec5ed84d4b6512476aa2ab5dc1feb3</guid>
<pubDate>Sat, 22 Aug 2026 05:56:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>CRI-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3105810f33758f0b1b01ab4f05326d2be38d2dda485f08cbc1255b6ce268f61</i><br /><br />Threat actor <b>description</b>: <i>CRI Electric CRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial clients, offering services such as emergency electrical repairs, EV charger installations, and home rewiring. We are pleased to present:Employee's federal account artifacts** (`HR-Confidential\Israel's Forms`): Login.gov personal recovery key (VA identity), TSP (retirement savings), ID.me, DoD DS Logon, PIEE (DoD contract payments)151 vendor W-9 forms** (SSN/EIN), payroll docs, HR-lawyer (privileged) correspondence, OSHA-adjacent injury/incident reports with photos.Public-sector bid pricing** (2025�2026: SAWS HQ EV charging, SAISD, NISD) � bid-competitiveness and Davis-Bacon certified-payroll context.Corporate docs (SDVOSB certification, Articles, bylaws, stock ledgers), QuickBooks financials, a Power of Attorney    More</i><br />Target victim <b>website</b>: <i>crielectric.com</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Everglades-Boats</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35241</link>
<guid>1424a162cca536e450b014b300aaa1b6</guid>
<pubDate>Sat, 22 Aug 2026 05:45:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Everglades-Boats</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0e9def1e0b5a835aa5e913052737a49888059a678ed93399c7688d1eef79e9d</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2001, Everglades Boats is a manufacturer of offshore fishing boats. The company is headquartered in Edgewater, Florida.
</i><br />Target victim <b>website</b>: <i>www.evergladesboats.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Victory-Personal-Care-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35239</link>
<guid>4ac686be58f2df517e217d10c200b5fb</guid>
<pubDate>Sat, 22 Aug 2026 03:25:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Victory-Personal-Care-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0079049ef40a47fda2808ace74ceaee117a4731eba4d31f0b09107db03d12280</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>victorypersonalcare.weebly.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>cedarridge.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35238</link>
<guid>98df4e0ce8b3e458dddb60c61fe5a3b2</guid>
<pubDate>Sat, 22 Aug 2026 00:51:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>cedarridge.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ce831d4b3ba8d9a3793a947299349b3766bfafa982a20007c0a88a5076ff485</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>cedarridge.org</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>iPic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35235</link>
<guid>dd2dde535d322743ac08d65bf6df132d</guid>
<pubDate>Fri, 21 Aug 2026 14:55:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>iPic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b26571f7fb5404f08df8f3e781ba0f1d54171227bf940672ba0de4a2a445db53</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ipic.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>JC-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35234</link>
<guid>5361754d7fa731dc4608adc1ec4c335f</guid>
<pubDate>Fri, 21 Aug 2026 13:21:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>JC-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a3e8bf069cffb0dfda701a3cf182f4cfc7944b0867bfe58276bb474a8076152</i><br /><br />Threat actor <b>description</b>: <i>JC Sales is a leading full-service wholesaler based in Los Angeles, California, specializing in
a vast array of wholesale products including health and beauty items, food and beverages, gene
ral merchandise, and seasonal items.

We will upload 206gb of corporate data soon. Detailed personal employee information (passports,
DLs, addresses, phones, contacts), confidential financials, contracts and agreements, client i
nformation, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Battle-Creek-Public-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35229</link>
<guid>cd57206be9022c27f6128ebdadabc8b4</guid>
<pubDate>Fri, 21 Aug 2026 10:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Battle-Creek-Public-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>881014f134177a01e9f31315e9bfc1fa88f03b91429f689d5ad2c2c65dc9aaf2</i><br /><br />Threat actor <b>description</b>: <i>Battle Creek Public Schools Battle Creek Public Schools in Nebraska provides educational services for students from pre-kindergarten through 12th grade. We are pleased to present:Student records of named minors:**  IEP/special-ed files, disability determination notices, discipline/suspension records.Federal funds compliance trail (ESSA/Title I application), staff health-spending claims (payflex/EHA)    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clifton-Architectural-Glass--Metal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35228</link>
<guid>22c64ea90b762e830ec7019dcfe43fd2</guid>
<pubDate>Fri, 21 Aug 2026 10:26:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Clifton-Architectural-Glass--Metal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d7c026cca31e89443a30e59ea323a5052a0698a6572984f68833e9ca9550f28</i><br /><br />Threat actor <b>description</b>: <i>A company that installs double-pane windows</i><br />Target victim <b>website</b>: <i>cliftonglass.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Commerce-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35227</link>
<guid>119653373afcc8c8f089832cb7eeb57e</guid>
<pubDate>Fri, 21 Aug 2026 10:26:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>First-Commerce-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebe305acf70a68ab7f436cca13d6ce1777cbc1ea7abc1b7646a2862bdc79da67</i><br /><br />Threat actor <b>description</b>: <i>Privately held real estate investment and development company</i><br />Target victim <b>website</b>: <i>firstcommercellc.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Pendas-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35226</link>
<guid>986bdd3d3beae0c7f63c1c771ff0e221</guid>
<pubDate>Fri, 21 Aug 2026 09:56:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Pendas-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f51b5f2f8fd32135031349580f9701b60e7633f5f47d65ca78d347925fa16a52</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.pendaslaw.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blake-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35225</link>
<guid>f0e6cbab5a5b7ea2821b2fe1c39d624a</guid>
<pubDate>Fri, 21 Aug 2026 09:56:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Blake-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>176174ecc7e7921c1d9dfac3f9a91a225172829b9d2ac6405f61d3d8f6967577</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.blakeservices.us</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Professional</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35224</link>
<guid>e4c9f7ec8caa4aca38efbbcae59b6472</guid>
<pubDate>Fri, 21 Aug 2026 09:55:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Professional</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8fd9beece1efb2f975aa9227c755f164d3bb753dfe35906feaa04d708b712fa3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.wwccpa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ESCON-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35216</link>
<guid>aab06e3e504518afa70bf9613e7e32e6</guid>
<pubDate>Fri, 21 Aug 2026 08:28:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>ESCON-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d52ce6b87a43cf8919ab49c6c180258c9dfb7d33671927434f3e7de4ce4c60e</i><br /><br />Threat actor <b>description</b>: <i>escon.us zoominfo.com/c/escon-group/352605618 ESCON Group is a veteran-owned electrical contracting company based in Bay City, Michigan, with a history tracing back to 1907.
They specialize in providing comprehensive commercial and residential electrical services, low voltage solutions, and fiber optics.
The company also offers advanced security systems, smart integrations, and robust commercial generator installations to ensure reliable power.</i><br />Target victim <b>website</b>: <i>escon.us</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aquasea</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35212</link>
<guid>c1873a205a7b7b021a082c65c7548d5d</guid>
<pubDate>Fri, 21 Aug 2026 08:26:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Aquasea</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6b2b22d11f1391f70ed9d86abc59e75d3ad5e2c7bc9c42a06ee5ee91a30366c</i><br /><br />Threat actor <b>description</b>: <i>aquasea.com rocketreach.co/aquasea-inc-profile_b468216cfc5c9f6e Aquasea Inc. is a clothing and apparel manufacturing company headquartered in Compton, California, operating since 1995.
The business specializes in full-package production, including cut and sew services, private label manufacturing, and screen printing.
They also operate nearshore textile manufacturing facilities to support their comprehensive apparel production capabilities.</i><br />Target victim <b>website</b>: <i>aquasea.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CAZ-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35211</link>
<guid>9dc4642d45e47e0c1799a55ac93b4a54</guid>
<pubDate>Fri, 21 Aug 2026 08:26:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>CAZ-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5c950d6511dd904bb3e696076976dbd3e2e3f9630870cf7db3a7ba9afc99357</i><br /><br />Threat actor <b>description</b>: <i>cazinvestments.com zoominfo.com/c/caz-investments-lp/16765398 CAZ Investments We have taken NDA files, HR data, user data, employee data, models, bank statements, tax and legal documents, confidential files, photos of your work and leisure time, screenshots, information about interactions with offshore accounts, your and your clients' dirty laundry, passport scans, VIP client data, and much more the total volume of data exceeds 478 GB. is a Houston-based wealth management and multi-family office firm founded in 2001.
They manage over $10.3 billion in assets, providing exclusive access to alternative investments like private equity, credit, and sports ownership.
The firm curates unique investment opportunities for a global network of individual investors, financial advisors, and institutions.</i><br />Target victim <b>website</b>: <i>cazinvestments.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hogan-Omidi-P.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35205</link>
<guid>65b15d7b1dbbaaecb9e2b33d681c5497</guid>
<pubDate>Fri, 21 Aug 2026 06:25:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Hogan-Omidi-P.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a5835e764af06431886de14dbff6108936421a5885a7e923ac0723dc69afde0</i><br /><br />Threat actor <b>description</b>: <i>Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division, with a focus on high-asset cases. The firm is led by experienced attorneys who have authored key reference materials on Colorado family law, providing them with a unique advantage in legal representation. They serve a diverse clientele, including executives, business owners, and professionals, ensuring personalized and strategic legal solutions. With offices in Denver and Aspen, they are dedicated to protecting clients' interests and achieving favorable outcomes in family law matters.</i><br />Target victim <b>website</b>: <i>hoganomidi.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>gt-tele.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35202</link>
<guid>613cec61b581b174c770c88a0dd578ee</guid>
<pubDate>Fri, 21 Aug 2026 05:49:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>gt-tele.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5363ba47d9fce529083bbf56f3388d3644c50624797e62d976880deb40af77d3</i><br /><br />Threat actor <b>description</b>: <i>MJR Technologies / GT Telecom &amp; GT Security: Internal Documents of an American Telecom Contracto...</i><br />Target victim <b>website</b>: <i>gt-tele.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>NorthStar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35200</link>
<guid>e950fc9a52cb6aeb451086da1c1cb8a8</guid>
<pubDate>Fri, 21 Aug 2026 02:30:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>NorthStar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd7838ac8cacd21918e934c03244daddec1a57dfd496f4fd04e59ebf0c232fef</i><br /><br />Threat actor <b>description</b>: <i>Enterprise Resource Planning</i><br />Target victim <b>website</b>: <i>cbsnorthstar.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aztec-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35199</link>
<guid>8d49e38a88f94747366a0072518dc6da</guid>
<pubDate>Fri, 21 Aug 2026 02:29:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Aztec-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb82d1ad7d80cf2e1af17fdee6d715fd7c93200d33839283789edf482e579791</i><br /><br />Threat actor <b>description</b>: <i>Engineering Software</i><br />Target victim <b>website</b>: <i>aztecsoftware.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Diaco-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35195</link>
<guid>4ae4da919fcc4087e6eea9a1e0ac90f0</guid>
<pubDate>Fri, 21 Aug 2026 02:27:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Diaco-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8632c9e4e16736a975ad4bb4e516fbff37c6558b338a1cb89c416683fa3e413a</i><br /><br />Threat actor <b>description</b>: <i>Jewelry &amp; Watch Retail</i><br />Target victim <b>website</b>: <i>diacoglobal.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deer-Creek-Mackinaw-CUSD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35193</link>
<guid>105080a6d9b902a81355dc79a51155c9</guid>
<pubDate>Fri, 21 Aug 2026 02:26:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Deer-Creek-Mackinaw-CUSD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f01ffc6611df479a6eb4bf3ae2f32f14131697511629f029f78ff29a6e1ae627</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>deemack.org</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allstar-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35192</link>
<guid>14c0c5f6f142833b2669dd20e70f03f5</guid>
<pubDate>Fri, 21 Aug 2026 02:25:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Allstar-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71b17521338f6630b6e298260aa46be22095899f034ad3cf71cbf7e017904982</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>allstarindustries.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>HP-Carriers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35191</link>
<guid>dbd3aefb04bc8f0da565968b2dd29fb6</guid>
<pubDate>Fri, 21 Aug 2026 02:25:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>HP-Carriers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5be6ae88a411b2f2fd3d10d818a4b7f85741101ccf10e2d4e9d20c68b296aac</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>hpcarriers.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>regencycenters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35208</link>
<guid>47928638e0167f68b16389775b44aebd</guid>
<pubDate>Thu, 20 Aug 2026 18:29:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>iah6477</b> claims attack for <b>regencycenters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7d27b5d1318cfa92cb292f8282285f5c31c39948b434b10ce8c12c85996d5dd</i><br /><br />Threat actor <b>description</b>: <i>Size: 219.5 GiB</i><br />Target victim <b>website</b>: <i>regencycenters.com</i>]]></description>
<category>iah6477</category>
</item>
<item xmlns:dc='ns:1'>
<title>acima</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35207</link>
<guid>244a1b49363236bde3930288883e8a18</guid>
<pubDate>Thu, 20 Aug 2026 18:29:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>iah6477</b> claims attack for <b>acima</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b9a75c563f69d8da9d6dbb95ed0fb3cea056dd3f3fe733ea7eae369d3b8de5e0</i><br /><br />Threat actor <b>description</b>: <i>Size: 2.1 TiB</i><br />Target victim <b>website</b>: <i>acima.com</i>]]></description>
<category>iah6477</category>
</item>
<item xmlns:dc='ns:1'>
<title>NetExam</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35182</link>
<guid>0a17a8c84fd8debe87250d1a0e44c7e9</guid>
<pubDate>Thu, 20 Aug 2026 17:50:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>emperador</b> claims attack for <b>NetExam</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8705821063f59ff18effd5acb4df074e293fe0fa5552fbad0bb702ef87b07002</i><br /><br />Threat actor <b>description</b>: <i>NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. [Size: 18.1 MB | Sector: Education, Retail, Other]</i><br />Target victim <b>website</b>: <i>netexam.com</i>]]></description>
<category>emperador</category>
</item>
<item xmlns:dc='ns:1'>
<title>Be-Media</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35181</link>
<guid>458f2f30b29105c76eb18b693f70ba68</guid>
<pubDate>Thu, 20 Aug 2026 17:28:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Be-Media</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed14b1c0884879d40ef41a51953c384b6bad1bc62285c5cdc09cd1692dbeb3dd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bemedia.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cascade-Coffee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35167</link>
<guid>8c44646b12108d3e1b2e0c547ecf7b7e</guid>
<pubDate>Thu, 20 Aug 2026 14:21:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cascade-Coffee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41a70e4640c26ebec88946d377a864d60303167c92a88f0026f95c35635be5bb</i><br /><br />Threat actor <b>description</b>: <i>Cascade Coffee is a premier gourmet coffee contract manufacturer based near Seattle, Washington
, specializing in roasting, grinding, flavoring, and packaging coffee. The company caters to so
me of the world's finest coffee brands, providing a wide range of products including whole bean
, ground, flavored coffees, and specialty blends.

We will upload corporate data soon. Detailed personal employee information (passports, DLs, add
resses, phones, car information), details, financials, contracts and agreements, NDAs and so on
.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>P-R</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35165</link>
<guid>64329af3e5dc362feda36f2bb623a515</guid>
<pubDate>Thu, 20 Aug 2026 14:15:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>P-R</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1a9aa8e3a8fe7d3a598de0866f852f921c72436b00340438e8acaddf1c5fb7c</i><br /><br />Threat actor <b>description</b>: <i>full-service event rental company established in 1972, specializing in high-quality items and equipment for special events. They serve the Northeast and Mid-Atlantic regions along the East Coast, offering an extensive selection of furniture, linens, and decor. The company is dedicated to helping clients bring their unique event visions to life with professional customer care and design support. With its main facility in Teterboro, New Jersey, and a showroom in New York City, it remains a leading provider in the event services industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deas-Millwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35158</link>
<guid>70b98536f7f2cff5c36df2424787d87b</guid>
<pubDate>Thu, 20 Aug 2026 13:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Deas-Millwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93e6904894fdfc2e20096d700776c3d6c6422a614f4a9264160af169356ad615</i><br /><br />Threat actor <b>description</b>: <i>Deas Millwork specializes in architectural design elements, offering custom millwork solutions 
for various projects. They focus on creating high-quality craftsmanship that serves as the cent
erpiece of any design.

We will upload corporate data soon. Employee personal information (passports, DLs, addresses, p
hones, emails and other information), financials, contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medical-Arts-Chemists-and-Surgicals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35155</link>
<guid>df3d1ee1216eabb1b772f28ffa71fa54</guid>
<pubDate>Thu, 20 Aug 2026 11:30:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Medical-Arts-Chemists-and-Surgicals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4372b7c5ec6ae62f8934ef5e1c83b0b83e607c60a8dabaead649ea0709f2917</i><br /><br />Threat actor <b>description</b>: <i>Prescriptions and Home Medical Equipment</i><br />Target victim <b>website</b>: <i>medarts.net</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Club-One-Casino</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35154</link>
<guid>303ff9c6f340aee89c6f030af3168137</guid>
<pubDate>Thu, 20 Aug 2026 11:30:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Club-One-Casino</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>600eaab9d6d8289117efc8995fc5876d78860da2d502da87d13545bab400bccb</i><br /><br />Threat actor <b>description</b>: <i>A Place to Play Cards in Central California</i><br />Target victim <b>website</b>: <i>clubonecasino.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Practi-Cal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35153</link>
<guid>d6500c5982c82edcc2e2b62a32bd9081</guid>
<pubDate>Thu, 20 Aug 2026 11:29:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Practi-Cal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1010b18ab9f96039fadee6f4e5c12939da9a9b537f1d3581a890698e5c1bf1c5</i><br /><br />Threat actor <b>description</b>: <i>Comprehensive platform to manage Medi-Cal billing, LEA BOP, and CRCS submissions efficiently</i><br />Target victim <b>website</b>: <i>practi-cal.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Austin-Plastic-Surgery-Institute</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35152</link>
<guid>788304097fce3e5d98c48cb17ebf155c</guid>
<pubDate>Thu, 20 Aug 2026 11:29:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Austin-Plastic-Surgery-Institute</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a672f302343c415d408f24b1e4c80e4d2063e06e4efeadd9b903a75d1c2f0b3</i><br /><br />Threat actor <b>description</b>: <i>A center staffed by highly skilled plastic surgeons</i><br />Target victim <b>website</b>: <i>austinpsi.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kingston-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35144</link>
<guid>729f48eb079c2f9bd8aac4d8f6dfbfd5</guid>
<pubDate>Thu, 20 Aug 2026 03:54:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Kingston-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>567c477118722bb88ec702935901276b9aafe7e9155184db3f7f6d24fc782932</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Kingston Technology is a privately held American company founded in 1987 and headquartered in Fountain Valley, California. It is one of the world's largest manufacturers of memory products, including DRAM modules, flash storage, USB drives, and solid-state drives. Kingston serves consumer, enterprise, and embedded markets globally, supplying components to major OEMs and retail customers across the technology industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>usbank.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35139</link>
<guid>776f2133216e85c918fc4ca650118d24</guid>
<pubDate>Thu, 20 Aug 2026 01:40:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>usbank.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f352239f820c5b84e9ad8bebdef84b6a73f1c2215debc02e10871bb587372e99</i><br /><br />Threat actor <b>description</b>: <i>U.S. Bank is a multinational financial institution that provides banking, lending, payment, and inve...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Delek-US</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35137</link>
<guid>46fdfe1db7a6965ac41dee2308681ae1</guid>
<pubDate>Wed, 19 Aug 2026 18:21:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>Delek-US</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c30b19a7d66cab1fd71ae4557415213cd94c6d6e558edaf609d4d13fe59edb05</i><br /><br />Threat actor <b>description</b>: <i>Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ericksen-Krentel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35130</link>
<guid>66c3f86ac905496e4ab21a2bc5fb33f1</guid>
<pubDate>Wed, 19 Aug 2026 17:43:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ericksen-Krentel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34126df7401688747a858cbf35243b5d6db94941f7ed99b3d226ee75e1ec5934</i><br /><br />Threat actor <b>description</b>: <i>Ericksen Krentel CPAs and Consultants is a New Orleans-based CPA firm offering a wide range of services including tax, accounting, audit, advisory, and consulting for both businesses and individuals. Their expertise spans various industries such as construction, healthcare, hospitality, maritime, and nonprofit sectors.We will upload 30gb of corporate data soon. Detailed client and employee personal information (passports, DLs, SSNs, addresses and other information), detailed financials, confidential documents, contracts and agreements, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crowe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35132</link>
<guid>683ebb557d4e37fcc017bcf793aa67f3</guid>
<pubDate>Wed, 19 Aug 2026 15:24:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Crowe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2357dfc19073967e7add917883ef2a3ef0335eb5baf98bff61a5cde1f18e2da</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Crowe is a public accounting, consulting, and technology firm headquartered in the United States. It provides audit, tax, advisory, risk, and performance services to clients across various industries, including financial services, healthcare, and government. Crowe operates globally through its membership in Crowe Global, a network of independent accounting and advisory firms spanning over 140 countries.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Engineering-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35131</link>
<guid>f98ed89220998643e9ae4fd4d9ebc981</guid>
<pubDate>Wed, 19 Aug 2026 15:23:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Advanced-Engineering-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2aa1dff1388d40d50a07d1d48e15b5d8558da0356ba2bf348bf2bb7fc1a76ad3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aurora-Health-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35129</link>
<guid>2f5ee755b7427661b5cdf239ccb371d9</guid>
<pubDate>Wed, 19 Aug 2026 14:57:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Aurora-Health-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0487697834eee820a9e07c85bc44398d6f4199e15286772e929ad97f3bc97d33</i><br /><br />Threat actor <b>description</b>: <i>Aurora Health Management, LLC operates a skilled nursing and rehab center in Frederick, MD. With nearly 25 years in long-term care, it improves troubled facilities through comprehensive management, programs, and Medicare/Medicaid standards.</i><br />Target victim <b>website</b>: <i>www.aurorahealthmgt.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southeastern-Oklahoma-State-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35126</link>
<guid>5134cb3d435ee631ad39aaa79f8874d0</guid>
<pubDate>Wed, 19 Aug 2026 13:56:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Southeastern-Oklahoma-State-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84235b41d139aeed4f888281bae4e5ed7e02a1453b14dc8bcb6e55d455fe76ef</i><br /><br />Threat actor <b>description</b>: <i>Southeastern Oklahoma State University is a public, four-year university located in Durant, Oklahoma. A data breach exposed student educational records (including names, contact information, Social Security numbers, grades, enrollment data, financial aid information, disciplinary records, and medical information contained in educational records). This breach violates the Family Educational Rights and Privacy Act (FERPA), the HIPAA Privacy Rule, and students' common-law privacy rights. The breach affected employee personal data and injury information, including employee name, date of birth, date of injury, as well as Social Security number, Medicare card, and child custody/consent status. More than 90,000 student names, Social Security numbers, and student identification numbers, as well as Forms 1095-C and more than 490 documents.</i><br />Target victim <b>website</b>: <i>se.edu</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>UNIPLASTICS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35124</link>
<guid>ee0e73fb83714a265451153b803ff57f</guid>
<pubDate>Wed, 19 Aug 2026 13:55:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>UNIPLASTICS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04fac306a28acb455686b9ffec8c91bedb8b9585bf5a4c15cb3431c60760df6a</i><br /><br />Threat actor <b>description</b>: <i>Universal Plastics Inc. is a family-owned commercial specialty subcontractor with over 50 years of experience, specializing in custom wall panel systems, wall protection, and high-impact wall coverings. They serve a diverse clientele, including commercial projects such as airports and medical facilities, providing innovative solutions with materials like FRP, stainless steel, and plastic laminates. As a master distributor for Marlite in Northern California, they also offer a wide range of products including solid surfaces and decorative wall panels. Their commitment to quality and customer service makes them a leader in the industry.</i><br />Target victim <b>website</b>: <i>UNIPLASTICS.COM</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CDGARVINLAW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35123</link>
<guid>8a34f184173d7b37cc58aab79bcd034a</guid>
<pubDate>Wed, 19 Aug 2026 13:54:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>CDGARVINLAW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b44a6ee155c27f4fffcbfd50e42dc6fea95ee115ee57838adc69b85a51bb5d49</i><br /><br />Threat actor <b>description</b>: <i>CHRISTOPHER D. GARVIN (Docket #2352300) is a Wood-Ridge attorney admitted to New York State in 1990 and registered with the Office of Court Administration (OCA) of the New York State Unified Court System. Employer - CHRISTOPHER D. GARVIN, ESQ. COUNSEL AT LAW. The attorney graduated from SETON HALL UNIVERSITY. The registered office is located at 268 Valley Blvd, Wood Ridge, NJ 07075-1202, contact telephone: (201) 804-7681. Current lawyer status: registered.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thrifty-Building-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35113</link>
<guid>212ad7bb06e34ce8eff54540c30efdff</guid>
<pubDate>Wed, 19 Aug 2026 12:29:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Thrifty-Building-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b661882bc005facfd74b812527894e19b17299be57f03201bfdca167ac17a2e2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.thriftybuilding.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WIS-LOGISTICS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35105</link>
<guid>c9e0a053ec8653f51da4623e0c26e74b</guid>
<pubDate>Wed, 19 Aug 2026 11:31:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WIS-LOGISTICS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71fa89771fcd06b40d604230f5426df85d0e2ce1bdf747234c5cd263d2ddebe0</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.wislogistics.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Senvest-Capital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35096</link>
<guid>e1c60d74120b7d2257c1f2a7561dfe41</guid>
<pubDate>Wed, 19 Aug 2026 08:11:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Senvest-Capital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c86941e005e2a4de95318a338207ddfc4c78d2bb6e2c872c38c99a96e75c1c2</i><br /><br />Threat actor <b>description</b>: <i>senvest.com zoominfo.com/c/senvest-capital-inc/91423931 Senvest (including Senvest Capital and Senvest Management) is a major international investment firm and hedge fund sponsor managing billions of dollars in assets.
Founded by Richard Mashaal, it specializes in contrarian value investing strategies across public equities, private markets, and real estate.
Headquartered in New York and Montreal, the firm focuses on discretionary investment advisory services and direct capital deployment for institutional clients.</i><br />Target victim <b>website</b>: <i>senvest.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roadvision-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35095</link>
<guid>d251117be5243e4560b18c0ccc41ccf8</guid>
<pubDate>Wed, 19 Aug 2026 08:10:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Roadvision-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4f888e7035bd301fc538b186e308b588d39178d1a20ff29b08f061ab149200c</i><br /><br />Threat actor <b>description</b>: <i>roadvision.com zoominfo.com/c/roadvision-systems-llc/358950436 Roadvision is a cloud-based trucking management software (TMS) designed to help logistics companies and carriers, particularly in the less-than-truckload (LTL) sector, operate more efficiently.
Headquartered in Hanover, New Hampshire, it provides an all-in-one platform to automate workflows, reduce operational costs, and modernize fleet management.</i><br />Target victim <b>website</b>: <i>roadvision.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Photon-Health-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35093</link>
<guid>e019c9de73f6441a1e1d8b26404fdb6f</guid>
<pubDate>Wed, 19 Aug 2026 00:55:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Photon-Health-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93baed70868ae13f0cc5306044a01f00308038c8aaa5fa4920b98a4b210d6e24</i><br /><br />Threat actor <b>description</b>: <i>Healthcare</i><br />Target victim <b>website</b>: <i>photonhealth.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>PayUp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35091</link>
<guid>1613d4862f2a54d215d260b5080a0289</guid>
<pubDate>Wed, 19 Aug 2026 00:54:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>PayUp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da9bf240e47b8f274c1e0aff9d2e66f134bc41943d7dc6272a3d016b0b0b563c</i><br /><br />Threat actor <b>description</b>: <i>Financial Software</i><br />Target victim <b>website</b>: <i>payup.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Troutman-Pepper-Locke</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35089</link>
<guid>9ac7bf7de1d8e0ecd5a956eebfc4316d</guid>
<pubDate>Tue, 18 Aug 2026 22:51:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Troutman-Pepper-Locke</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0731ebb5658f94f74113dfb1e254118ceb6820b9a70629e9fa3fe9d142fc86af</i><br /><br />Threat actor <b>description</b>: <i>2nd time we attacked them in a year (first time through physical intrusion), will continue our attacks…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>R--D-Machine-and-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35087</link>
<guid>3adfed0a226eb2f6fbb6b7ed1e394421</guid>
<pubDate>Tue, 18 Aug 2026 17:55:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>R--D-Machine-and-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecdb53dcf0eb5f8d819a3646c2dc8141ecb6f4a5022afcbe28b5bc5129fd83f7</i><br /><br />Threat actor <b>description</b>: <i>&D Machine and Engineering, LLC specializes in CNC machining of precision metal components primarily for the aerospace, defense, and space industries. The company is known for its ability to maintain tight tolerances and produce complex geometries using advanced 5-axis milling and coordinate measuring machines. With a commitment to quality, R&D Machine has built a strong customer base that includes respected blue-chip companies like NASA. Acquired by Compass Precision in 2022, the company continues to focus on manufacturing mission-critical components for demanding applications.</i><br />Target victim <b>website</b>: <i>rdmachine.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Borchert--LaSpina</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35085</link>
<guid>2a3228854c6f47213f364faafb149166</guid>
<pubDate>Tue, 18 Aug 2026 17:43:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Borchert--LaSpina</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4ca2e26edb2df6f68f686c6ec73c3cca6401eef6b2267a716610786b0056a16</i><br /><br />Threat actor <b>description</b>: <i>Borchert & LaSpina, P.C. is a respected law firm located in Queens, New York, with a team of six experienced attorneys specializing in various areas of law including real estate, mortgage foreclosure, commercial litigation, personal injury, and elder law.We will upload corporate data soon. Client personal information (lots of passports, DLs, SSNs and other information), financials, confidential legal files, contracts and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Coltrane-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35086</link>
<guid>75a8729c48081089d01e242f39d32c0c</guid>
<pubDate>Tue, 18 Aug 2026 17:31:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Coltrane-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a0c2fe8037a90945a38d31d68cd7cd44ca7fcf23d3b86ac4e69ab3b2f0f77ff</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.coltranesystems.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valor-Defense-Solutions-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35074</link>
<guid>f2434fc79708299558694ed0f21c6d84</guid>
<pubDate>Tue, 18 Aug 2026 04:22:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Valor-Defense-Solutions-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a590a86e9185bf61af48b16ec2d1fdbaf90dbca336f09f3bea10fed922db65ef</i><br /><br />Threat actor <b>description</b>: <i>Valor Defense Solutions, Inc. is a woman-owned small business and defense contractor headquartered in Odon, Indiana. Founded in 2018, the company provides customized solutions to government, military, and commercial customers. Its services include logistics, engineering support, electronic module and cable manufacturing, military equipment refurbishment, protective coatings, sandblasting, painting, and powder coating. Valor Defense Solutions supports U.S. Department of Defense projects and has worked with government agencies and defense contractors on equipment manufacturing, maintenance, and sustainment. The company focuses on delivering reliable, high-quality products and technical services that support military operations and the broader public sector. 
The company headquarters is located in 15484 N 1350 E, Odon, IN 47562, USA. 11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Standard-Tool--Die</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35073</link>
<guid>30f6bd459b8c1cead8a32021a97890ef</guid>
<pubDate>Tue, 18 Aug 2026 04:21:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Standard-Tool--Die</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca51b4dc93584f3ed0a2bc2a0101782aafc87b963fb8d5df017cbe0849bcb90c</i><br /><br />Threat actor <b>description</b>: <i>Standard Tool & Die specializes in designing and manufacturing die cast dies, plastic molds, and trim dies for various industries including automotive, appliance, furniture, and household goods. The company offers single source manufacturing solutions and focuses on precision machining for both domestic and international clients. They are committed to developing cost-effective and time-saving strategies while continually investing in advanced equipment. Standard Tool aims to provide effective solutions to industry challenges through innovative design and strategic thinking. 
The company headquarters is located in 2950 Johnson Road, Stevensville, MI 49127, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>standardtool.net</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>WindRose-Health-Network</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35071</link>
<guid>b7dc383be23271e021efa4b0a81c0573</guid>
<pubDate>Tue, 18 Aug 2026 04:20:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>WindRose-Health-Network</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41a0cc473d16b285679fd0f8f4a17210e3b688fb064e67811b5fb22d0f45eb5d</i><br /><br />Threat actor <b>description</b>: <i>WindRose Health Network (WHN) is dedicated to providing affordable, quality healthcare services, focusing on family medicine, pediatrics, prenatal care, and behavioral health. The organization aims to improve the health of underserved communities by offering personalized and innovative healthcare solutions, including financial assistance programs. WHN operates multiple health centers and emphasizes compassionate care and preventative services. Their mission is to ensure that everyone, particularly the poor and vulnerable, has access to essential medical care.. 
The company headquarters is located in 163 Butner Drive, Hope, IN 47246, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>windrosehealth.net</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scholle-IPN--SIG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35068</link>
<guid>a60d05725fe3891716ad214ef47b2937</guid>
<pubDate>Tue, 18 Aug 2026 03:21:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Scholle-IPN--SIG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a562288bb44bf01c092222071b57ee36ffda8a77ab68321fc99354540e4bce6a</i><br /><br />Threat actor <b>description</b>: <i>Data breach at a global leader in packaging manufacturing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Third-Coast-Bancshares</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35064</link>
<guid>49cd70349fd46e2251b90c6009945469</guid>
<pubDate>Tue, 18 Aug 2026 00:26:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Third-Coast-Bancshares</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cec7007a546ee37698e209b2d539ab2e1372324012504c16b7f8a0bb600c4794</i><br /><br />Threat actor <b>description</b>: <i>While Third Coast Bancshares (NASDAQ:TCBX) shares continue to rise rapidly and reach new highs, its leadership is concealing one of the largest data breaches in the history of the U.S. financial sector. This situation raises serious questions about the company’s conduct. In the near future, we intend to publish a comprehensive analytical report examining the TCBX activities. The public will then have an opportunity to assess the practices carried out by the company, including violations of applicable laws and regulations, as well as the conduct of certain shareholders and business partners. Our report will also examine allegations involving individuals connected to financial-sector regulators and law enforcement. Corruption, manipulation of data, regulatory non-compliance, and the submission of potentially misleading reports represent only a small part of the concerns we intend to address. We believe the time has come to initiate short positions. Our forthcoming publications are expected to raise significant questions about the company and could have broader implications for confidence in the U.S. financial sector. As for clients and stakeholders of the financial institution, We strongly recommend that clients safeguard their funds and consider withdrawing them in the near term. Stay tuned for further updates and the release of our detailed findings.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-contractors-insurance-group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35084</link>
<guid>2de39d164c7807c1be5cad819d978cf2</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>American-contractors-insurance-group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42f4d2940e3c9efee6e7a971caa0bec2bbb2ae10e08fa5fcc6c3c6d548056cd4</i><br /><br />Threat actor <b>description</b>: <i>American Contractors Insurance Group (ACIG) is a member-owned insurance company founded in 1981, specializing in providing insurance policies and risk management services tailored for the construction industry. Their offerings include workers' compensation, general liability, automobile liability, and subcontractor default insurance. ACIG's mission is to save lives, prevent injuries, and reduce the overall cost of risk for its members. Website: https://www.acig.com/</i><br />Target victim <b>website</b>: <i>acig.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wcmanagement.info</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35114</link>
<guid>736af97802ac911f1b7f454489821925</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>Wcmanagement.info</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5ef7ae29ee702f828813191b274037ea831ad96df5e967f8e2a32ac8f194249</i><br /><br />Threat actor <b>description</b>: <i>Westcoast Management and Realty, Inc., established in 2001, offers HOA/COA management, rental management, and real estate sales services in the Tampa Bay area. They manage over 90 associations and 500+ rentals, serving Hillsborough, Pinellas, and Pasco counties. Website: https://www.wcmanagement.info/</i><br />Target victim <b>website</b>: <i>wcmanagement.info</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alphanumeric.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35115</link>
<guid>c726062049174dd685bbb960958fa1c1</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Settra</b> claims attack for <b>Alphanumeric.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>794c8daaed34a9a82c4a86dd9ea58b4ab6c72fbc94bef3aa9efd3c9b2728c9c5</i><br /><br />Threat actor <b>description</b>: <i>Alphanumeric Systems, Inc., founded in 1979, specializes in providing comprehensive IT services, including managed IT services, service desk outsourcing, and enterprise technical support. The company operates globally with offices in the United States, Canada, United Kingdom, Spain, Poland, Portugal, Philippines, Colombia, and Brazil. Website: https://www.alphanumeric.com/</i><br />Target victim <b>website</b>: <i>alphanumeric.com</i>]]></description>
<category>Settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grecosteel.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35117</link>
<guid>efd0919de22a21bc3c9ee3e4cefb97d6</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>Grecosteel.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>934eaf342c1f497d4ec9992025b609968b09d57f908ffb6f8eba95a7fc8da79f</i><br /><br />Threat actor <b>description</b>: <i>Greco Steel Products, Inc., established in 1961, is a family-owned business specializing in structural steel fabrication and erection services. With over a century of experience, they offer comprehensive solutions including detailing, fabrication, and erection of structural steel for large-scale construction projects. Their in-house fabrication facility and crane/trucking services enable them to efficiently meet diverse building needs and deadlines. Website: https://www.grecosteel.com/</i><br />Target victim <b>website</b>: <i>grecosteel.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adl-embedded-solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35119</link>
<guid>db1e17980ba89a803d856142c1035e50</guid>
<pubDate>Tue, 18 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>securotop</b> claims attack for <b>Adl-embedded-solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2231b658f1895bae1d865b366a1311ce23b9e6c8bdd7b5ac675a80c070492c0</i><br /><br />Threat actor <b>description</b>: <i>ADL Embedded Solutions, Inc., founded in 1994, specializes in customizable, high-performance embedded computing solutions for demanding thermal and rugged environments. Their product portfolio includes embedded SBCs, peripherals, power supplies, and custom system design services. Website: https://www.adl-usa.com/</i><br />Target victim <b>website</b>: <i>adl-usa.com</i>]]></description>
<category>securotop</category>
</item>
<item xmlns:dc='ns:1'>
<title>White-Daters--Associates-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35060</link>
<guid>1ef14ce4ee3294e6a1214136ce45e85b</guid>
<pubDate>Mon, 17 Aug 2026 23:32:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>White-Daters--Associates-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0890cea63e55172cfe9b467ada4054fbf66b4bf0eadd3875fa4256085e2a20b3</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>EmpireWorks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35062</link>
<guid>36179605b136215afcba7b1344c136a8</guid>
<pubDate>Mon, 17 Aug 2026 23:32:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>EmpireWorks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74979a4b816fe25a10ba808ea6c59a4135e14c02e7a28dbde54fcca405d54706</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Codinter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35063</link>
<guid>397b233c06ba97b635731d222783217e</guid>
<pubDate>Mon, 17 Aug 2026 21:56:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Codinter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32edb3d2199cce4abfbd1909f89005da029619c1ff4cc7257b60f709b361d854</i><br /><br />Threat actor <b>description</b>: <i>Private company supplying welding, cutting, finishing products and services across North/Central/South America. Offers equipment, tools, accessories, consumables - from mobile units to robotic systems. Oil industry: pipeline, tanks, refinery, platforms.</i><br />Target victim <b>website</b>: <i>www.codinter.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bridgeport-Capital-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35058</link>
<guid>9ff016546e872eb88257008651af50ef</guid>
<pubDate>Mon, 17 Aug 2026 20:27:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Bridgeport-Capital-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12c9c4ebc6171739638326e598b6ed2282170445b6ff4d3e68befd42d984de6d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bridgeportcapital.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sam-Pack-Auto-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35057</link>
<guid>d457c0235036396f11714cb337bc0445</guid>
<pubDate>Mon, 17 Aug 2026 20:26:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sam-Pack-Auto-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>470cfc54922e6438885312064930d0f742bcdd92654b822497448e6ccf9bcdd7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sampack.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodhaven-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35056</link>
<guid>e3acae64e67d7f9356d29d7b617bf110</guid>
<pubDate>Mon, 17 Aug 2026 20:26:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Woodhaven-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7367df0e1ada62eae2e11f8c47749adbe795f768113959d6696f9e7fdb9cd2c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.woodhavenassociation.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>terra-petra.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35050</link>
<guid>8f9b9fd0f3d4fdb8e07c3c7b1640d9b7</guid>
<pubDate>Mon, 17 Aug 2026 18:35:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>terra-petra.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3766b8ef27f92b4a8bc1db347c4e1dc09980a0c5ae9ff8b4757fc8ad4f3b46f5</i><br /><br />Threat actor <b>description</b>: <i>Terra-Petra is an environmental engineering firm specializing in contaminated soil and groundwater c...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lansing-Urgent-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35054</link>
<guid>96ecbfadac55a39b8909822f91399f00</guid>
<pubDate>Mon, 17 Aug 2026 18:25:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Lansing-Urgent-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f1d83c77188e26dd066abb9e6feb12ae99bf88ac9d52b430b3677ce053a439c</i><br /><br />Threat actor <b>description</b>: <i>Lansing Urgent Care provides a range of urgent care services for both adults and children, including on-site medications, lab tests, and X-rays. Their facilities are designed for quick visits, with an average wait time of under one hour, and they offer telemedicine options for added convenience. The company caters to patients seeking immediate medical attention, sports physicals, and occupational health services. With multiple locations in Lansing, Okemos, and surrounding areas, they aim to deliver friendly and efficient healthcare.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Rubber-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35053</link>
<guid>f86bb0bfe24918427cf1b171fb3c5d8d</guid>
<pubDate>Mon, 17 Aug 2026 18:22:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>The-Rubber-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d4de081ee406ae6b0a2c5067b1580fa17d3995f55bdad4446d98733999bbefb</i><br /><br />Threat actor <b>description</b>: <i>Country: New Hampshire,US |
Website: www.rubber-group.com |
Revenue: $19.4 Million |
Industry: Plastics Manufacturing, Tires & Rubber, Manufacturing |
Employees: 50-100 |
Properties: 162 GB (207,203 Files, 21,624 Folders)</i><br />Target victim <b>website</b>: <i>www.rubber-group.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>4M-REALTY-COMPANY</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35051</link>
<guid>5aae68270b448da2adfa823502b512a8</guid>
<pubDate>Mon, 17 Aug 2026 17:21:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>4M-REALTY-COMPANY</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a280ae898440056f7abc0391fc13bb5e98adcf972e591176fefac722a4a02e56</i><br /><br />Threat actor <b>description</b>: <i>Country: Texas, US |
Website: 4mrealty.com |
Revenue: $5 Million |
Industry: Real Estate Brokerage, Real Estate Sales, Property Sales, Commercial Real Estate |
Employees: 20-50 |
Properties: 237 GB (54,995 Files, 4,600 Folders)</i><br />Target victim <b>website</b>: <i>4mrealty.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arizona-State-University-ASU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35048</link>
<guid>9fae7f55b59b284b106e7be7c783054c</guid>
<pubDate>Mon, 17 Aug 2026 14:54:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Arizona-State-University-ASU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06e80f8377489df68059dcda28ea49f89b4e65e84329d7b96d09b0b91654030e</i><br /><br />Threat actor <b>description</b>: <i>Colleges,Universities</i><br />Target victim <b>website</b>: <i>asu.edu</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Natco-Home-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35043</link>
<guid>79557cb93066f4470b8cee6e9110f757</guid>
<pubDate>Mon, 17 Aug 2026 14:22:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Natco-Home-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be78a014af7e0d4a0c95e1d191b0946c89023dff7c8f35760c71eac6d2cd4064</i><br /><br />Threat actor <b>description</b>: <i>[manufacturer] Natco Home Group — a fourth-generation, family-owned home furnishings manufacturer headquartered in West Warwick, Rhode Island, with ~800 employees, ~$100M annual revenue, and facilities across seven US states.

The exfiltrated dataset spans the company's entire corporate history and includes:

Social Security numbers in plaintext for 100–120 legacy employees dating back to 1979 in an unencrypted PayUSA payroll database, plus 10 years of ADP payroll data (2017–2026) covering 700–1,000 current and former employees — pay stubs, W-2s, W-4s, 401k records, drug test results, background checks, and medical leave records.
<censored>
<censored>
<censored>
<censored>
Years of divisional financial statements, income tax records, customer credit data for major retailers, 18 years of bad-debt reserve calculations, and acquisition-related materials.</i><br />Target victim <b>website</b>: <i>Natco Home Group</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Otter-Tail-County-Minnesota</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35039</link>
<guid>fec422f02a5eb32c4d69dec4d8c6ed68</guid>
<pubDate>Mon, 17 Aug 2026 09:28:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Otter-Tail-County-Minnesota</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abc4fdfd39c0cbbe65154eb1201df69ad2e645654788a5ef3afdf8140c052c85</i><br /><br />Threat actor <b>description</b>: <i>https://ottertailcounty.gov/</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Teikoku-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35034</link>
<guid>f04c67050a9d82baa7f3cdbe5a084f2a</guid>
<pubDate>Sun, 16 Aug 2026 18:58:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Teikoku-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9233958bd8f16381db6a4afca748e5aef0661a65da705544a395177ff80b97a0</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.teikokuusa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spoonful-of-Comfort</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35031</link>
<guid>98fe179807288d2f5b33d1b87e42a694</guid>
<pubDate>Sun, 16 Aug 2026 18:56:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spoonful-of-Comfort</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8469d91293f818fd88c05ce3e0912e771b0d2ba0646baff3975e202f8f3eabba</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.spoonfulofcomfort.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>airoyal.biz</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35027</link>
<guid>208528088dc87a4bd6b73796b96b0085</guid>
<pubDate>Sun, 16 Aug 2026 15:27:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>airoyal.biz</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1681403a583aafc12ad947648326470439a5c19e7e67554578b3f81c4387b6f3</i><br /><br />Threat actor <b>description</b>: <i>AIROYAL COMPANY: Internal Documents of an American Industrial Components Distributor PROLOGUE We hav...</i><br />Target victim <b>website</b>: <i>airoyal.biz</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>tiltstudio.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35026</link>
<guid>86cdc69dedab1cd08a93e76e89632a7d</guid>
<pubDate>Sun, 16 Aug 2026 15:26:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>tiltstudio.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e39716027fefa2cbfc70cc756c51df513b547d7aead619816c7c0233d3fcfa7d</i><br /><br />Threat actor <b>description</b>: <i>The Tilt Studio Archives Investigation of a Corporate Archive Leak from an Entertainment Network PRO...</i><br />Target victim <b>website</b>: <i>tiltstudio.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Idex-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35023</link>
<guid>16757f4d90fa4e95156541c44c6c6ec9</guid>
<pubDate>Sun, 16 Aug 2026 15:20:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Idex-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3a03ce86276f1de0c5021fc6bbe557c159728a3fbc0a7cce0a9c17d49fe1fb4</i><br /><br />Threat actor <b>description</b>: <i>Organization with 30 emails extracted. Domain: idex-group.com</i><br />Target victim <b>website</b>: <i>idex-group.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kennedy-Jenks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35020</link>
<guid>8cfedb72223f684bcf764f9b79078740</guid>
<pubDate>Sun, 16 Aug 2026 15:00:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>Kennedy-Jenks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e71c1385e80915e22765cbd5058710db4f3da3135803ead4b07ca31d877b8b04</i><br /><br />Threat actor <b>description</b>: <i>Kennedy Jenks is live. T1 is unlocked. T2 in 24 hours, then one day each through T4.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arnall-Golden-Gregory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35003</link>
<guid>c94b9c32bee1951814f79c9646777742</guid>
<pubDate>Sun, 16 Aug 2026 09:31:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Arnall-Golden-Gregory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83794b1e12057241a204daf5d61357745ccd169cc0f8f89f273c639310cd4841</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.agg.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ASCII-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35002</link>
<guid>83b7b19e6be902a7bab8244f0d83481f</guid>
<pubDate>Sun, 16 Aug 2026 09:31:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ASCII-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>92ea3599bc61d559318b825cd1b1799146a10e08e2b5f956712cce630c79679a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.asciigroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Double-H-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34999</link>
<guid>860cf4d40df09a27bbfaa2c3c3ccd26e</guid>
<pubDate>Sun, 16 Aug 2026 09:29:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Double-H-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe6103017d2d49b011121bcccf927ab79caf6b053a280e4e87f3cd3a93ea2738</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.doublehequip.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dynatrace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34994</link>
<guid>a060a959e2593a9036a4a9a449f9b304</guid>
<pubDate>Sat, 15 Aug 2026 21:44:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>xpl0itrs</b> claims attack for <b>Dynatrace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b29c2116fa76e43cc1aa5ba7aba6ac2c74b6686c12bd0f6d3cf97ffce743b098</i><br /><br />Threat actor <b>description</b>: <i>AI observability platform</i><br />Target victim <b>website</b>: <i>dynatrace.com</i>]]></description>
<category>xpl0itrs</category>
</item>
<item xmlns:dc='ns:1'>
<title>RapidFort</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34991</link>
<guid>e304076961ce84eeec9e5d066edd87b5</guid>
<pubDate>Sat, 15 Aug 2026 21:42:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>xpl0itrs</b> claims attack for <b>RapidFort</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47f0708501f32d9a30b1ffb21caba08863eb4c2f56825a186dcc5ef73d6cc21</i><br /><br />Threat actor <b>description</b>: <i>Software supply chain security</i><br />Target victim <b>website</b>: <i>rapidfort.com</i>]]></description>
<category>xpl0itrs</category>
</item>
<item xmlns:dc='ns:1'>
<title>DodoPayments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34990</link>
<guid>74b846eb2dcd22fe703bebcd75a3aff1</guid>
<pubDate>Sat, 15 Aug 2026 20:27:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>DodoPayments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3daff9adad7d50a66e20bb64df886c79f54010d750bb8cc4629651d5f12625ec</i><br /><br />Threat actor <b>description</b>: <i>Financial Software</i><br />Target victim <b>website</b>: <i>dodopayments.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>AAMHOA-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34989</link>
<guid>a16adb956f28c621d4e83cb0ec9616cf</guid>
<pubDate>Sat, 15 Aug 2026 20:26:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>AAMHOA-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71d980e79e98b4d55ac19a070e15ddd69a6d1e5b627d1553a173f8a98a1036de</i><br /><br />Threat actor <b>description</b>: <i>HOA Management</i><br />Target victim <b>website</b>: <i>associatedasset.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colla-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34987</link>
<guid>d62bd5e1be9a157e45aed37bd98743c2</guid>
<pubDate>Sat, 15 Aug 2026 20:24:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Colla-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5354aa2eae6f1ff620e5808ab37e205146dfa3d2124919145bdca4d92f2da9f6</i><br /><br />Threat actor <b>description</b>: <i>Healthcare</i><br />Target victim <b>website</b>: <i>collahealth.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>PayrHealth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34986</link>
<guid>c253727b5fb33bbcbab7fd7153739e03</guid>
<pubDate>Sat, 15 Aug 2026 20:24:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>PayrHealth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>442d18e8efd663eac5e983784adbc09134cfb51bfb4a121c4a22f098748648e0</i><br /><br />Threat actor <b>description</b>: <i>Healthcare</i><br />Target victim <b>website</b>: <i>payrhealth.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Interim-HealthCare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34979</link>
<guid>fdb03908325703d7e57e8f86a86c233e</guid>
<pubDate>Sat, 15 Aug 2026 04:22:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Interim-HealthCare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ccaa4abde5be4dd282e1b9aebd64b8c1d811c3224614649d5838f9ad12d0270b</i><br /><br />Threat actor <b>description</b>: <i>Home Healthcare Agency & Medical Staffing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Columbia-University-Information-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34975</link>
<guid>432a0df9f5145cd66bfd2d8ecc40ba7d</guid>
<pubDate>Fri, 14 Aug 2026 16:21:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Columbia-University-Information-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1d29ad300d354bb5733f0d543a7d4258c60dd793aa6479577ddd92a2a4b1929</i><br /><br />Threat actor <b>description</b>: <i>Country: New York, US |
Website: columbia.edu |
Revenue: $6.6 Billion |
Industry: Colleges & Universities |
Employees: 20.000-25.000 |
Properties: 296 GB (283,387 Files, 11,268 Folders)</i><br />Target victim <b>website</b>: <i>columbia.edu</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sweet-Water-Holdings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34971</link>
<guid>5ea40273e56bd87ec62c0a113f20fdc2</guid>
<pubDate>Fri, 14 Aug 2026 13:54:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Sweet-Water-Holdings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8003568881c68248d35348741afaae46f86528110345448ddf0e7e2a3dccf0f8</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keystops</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34970</link>
<guid>ebd9cedc5ac9828d71c03c72377a0992</guid>
<pubDate>Fri, 14 Aug 2026 13:52:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Keystops</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1831e2839586abb2fc836a455f71ae593edfeb34710b65bd2f16edc7c48b0adf</i><br /><br />Threat actor <b>description</b>: <i>Key Oil Company is the largest distributor of branded motor fuels for Marathon Petroleum Compan
y and also holds contracts with major brands like ExxonMobil and ConocoPhillips. They provide a
wide range of products including lubricants, diesel exhaust fluid, antifreeze, and various fue
l delivery solutions.

We will upload 15gb corporate data soon. Employee and client personal information (NAME, PASSPO
RT, DL, SSN and so on), financials, payment details, contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cozad-Asset-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34969</link>
<guid>9731dd75499eaebe738e9e1dc00151d0</guid>
<pubDate>Fri, 14 Aug 2026 13:51:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cozad-Asset-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d64bb6ce858491912c6c1238ed6653d2717d6961f1bc453b96f7dbf692c2a14</i><br /><br />Threat actor <b>description</b>: <i>Cozad Asset Management, Inc. provides the highest quality professional and personalized financi
al services and advice to individuals, families and institutional investors throughout the coun
try.

We will upload 13gb corporate data soon. Employee personal information (passport, DLs, SSN), fi
nancials, confidential files, contracts and agreements, legal files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pierce-Township</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34964</link>
<guid>502c4afdfeedb869dd6c8c1496e7da0f</guid>
<pubDate>Fri, 14 Aug 2026 10:00:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Pierce-Township</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>00aa0c56cff66a4f69996473cc10ab980bfd782fe73639db0355043cb4b6ca41</i><br /><br />Threat actor <b>description</b>: <i>Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with suburban living, covering 23.5 square miles and home to over 16,000 residents.We are pleased to present:Judicial materials - Grand Jury subpoena response incl. hospital records (Mercy Hospital), public records requests, fire investigation reportsEmployee PII - Social Security numbers (SSA-1945, W-4, Ohio Tax forms), CDL licenses, health insurance waivers, new-hire packetsLegal settlements - Logan Creek v. Pierce Township, Purdue opioid settlement, easement and lease agreementsFinancial records - budgets, tax levies, appropriation reports, invoices, paymentsInternal email archives of township officials and administration    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Radiant</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34963</link>
<guid>e6bebc499c445570ecbe7829ae23b881</guid>
<pubDate>Fri, 14 Aug 2026 09:59:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Radiant</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ec5698e148a6bf2c8bdf46449ef447b052680652d80bb7a804d0cb41900718d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.radiants.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>PenLink</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34953</link>
<guid>cfc0f51c3e5d754e57558f4d79ca1637</guid>
<pubDate>Fri, 14 Aug 2026 09:50:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PenLink</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56222073190fa7a594c3bdcb249953d8824643d0da1a5576ffc30e2b706c6fd5</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Urban-Worldwide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34962</link>
<guid>224ba67f6723dc76cf944c925faeba24</guid>
<pubDate>Fri, 14 Aug 2026 08:31:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Urban-Worldwide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc3b07b0c7d460900d5465c7e9283d19b72ecfd549060b29534261199e7f1ad5</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.urbanworldwide.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hinman-Straub</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34960</link>
<guid>cdb36ea731ecf2d69881eaff7220b10e</guid>
<pubDate>Fri, 14 Aug 2026 07:13:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Hinman-Straub</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f9c4793353ca02d222b6db9778c5ec6d021e78a855441940493480e42c8d69e</i><br /><br />Threat actor <b>description</b>: <i>Hinman Straub is a full-service law firm located in Albany, New York, offering a comprehensive range of legal and lobbying services. The firm caters to a diverse clientele, including Fortune 500 companies, associations, and local governments, providing expertise in areas such as Labor and Employment, Corporate Law, Real Estate, and Healthcare. With a team of experienced professionals, they guide clients through complex legal matters at various governmental levels, leveraging strong relationships with key decision-makers. Additionally, their public affairs partner, Corning Place Communications, enhances their clients' communication strategies to effectively convey their messages to the public. 
The company headquarters is located in 121 State Street, Albany, NY 12207, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>hinmanstraub.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rood--Riddle-Equine-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34958</link>
<guid>0ff768b9aec0057b915265fb8fccbe3a</guid>
<pubDate>Fri, 14 Aug 2026 07:12:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Rood--Riddle-Equine-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd8cce3e248599f179e4b0eeb25c53658ae61cd754e780777a5747392297b7ad</i><br /><br />Threat actor <b>description</b>: <i>Rood & Riddle Equine Hospital was established in Lexington, Kentucky in 1986 as a partnership between veterinarians William Rood and Thomas Riddle. The facility offers a range of services for the treatment of horses. They have cared for many famous Thoroughbreds both at the racetrack and on the farm. They also provide support for other equine sporting events such as the 2010 FEI World Equestrian Games held in Lexington. Rood & Riddle operates branches in Saratoga Springs, New York and Wellington, Florida. 
The company headquarters is located in 2150 Georgetown Road, Lexington, KY 40511, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>roodandriddle.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metabase</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34950</link>
<guid>767474c706888300885c4662c26fc30c</guid>
<pubDate>Fri, 14 Aug 2026 06:01:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Metabase</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c28625c9af546c9bd30e557fdc260175374dd7d92931340a9d0060001928c41d</i><br /><br />Threat actor <b>description</b>: <i>:P | Updated: 12 August 2026 | SHA256: 84daf8f33954a0b03238a1e0da3ee109d5bc32acc134cfdddfac36b4b75d2480</i><br />Target victim <b>website</b>: <i>metabase.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sharecare-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34949</link>
<guid>842b53175644d13105e79978677b933f</guid>
<pubDate>Fri, 14 Aug 2026 06:00:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Sharecare-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d4ff0bcdaecacf4e0fb1ff3343caf824cf28dc45a04f30c3b9adebb4527f313</i><br /><br />Threat actor <b>description</b>: <i>This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to negotiate for you, that is on you. We will be publishing companies data who are negotiating with us, without a warning if negotiators continue to take us as misinformed individuals and BS us. Over 3.4 million Salesforce records containing some PII and 28GB+ of internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 25GB+ (compressed) | Updated: 13 August 2026 | SHA256: 195842b8a53e8d7fe63238dbed753c1c28a86034ca98f99527ef743528b6cc45</i><br />Target victim <b>website</b>: <i>sharecare.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carhartt-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34947</link>
<guid>3469f647707d7517364600b07bd45816</guid>
<pubDate>Fri, 14 Aug 2026 05:59:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Carhartt-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e33f093ffe84083f8f439e92481eb57d661ec878259565321342953a472fe95</i><br /><br />Threat actor <b>description</b>: <i>Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate. If The Company attempted to negotiate with us The Company would've ended up saving a good chunk of money. Instead they decided to do (see blow); this is also because The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published. [21:24:22] carhartt: After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process. There is millions of customers of data involved here. As we always say, these companies don't care. Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 50GB+ (compressed) | Updated: 13 August 2026 | SHA256: 6b37f770382ce82bfa4677466cc51d9269e5a70436eecf101fae6fa9d5d8e8ac</i><br />Target victim <b>website</b>: <i>carhartt.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cook-Medical-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34945</link>
<guid>788d4162bb33b3dd36f14cb9fdc14905</guid>
<pubDate>Fri, 14 Aug 2026 05:59:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Cook-Medical-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b15261b24bd6f74b73a63d2fd9f111bc0aee3d7b3d428af2e842cbc370e83b6e</i><br /><br />Threat actor <b>description</b>: <i>Customer data, employee data, and other internal corporate data was compromised. The Company engaged with us but made several paltry offers, did not want to pay what we asked for and decided they are okay with the data leak to happen instead of increasing their offer by a little, then we'd likely have accepted and this post would not have gone up. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 182GB+ (compressed) | Updated: 14 August 2026 | SHA256: 8a87ba511f25f20a193f05a6578a620b02302c2075a6f2dff428d1f1a826ba63</i><br />Target victim <b>website</b>: <i>cookmedical.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gravity-Coffee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34944</link>
<guid>a398c3759c3f93514ebf11f0386caa3c</guid>
<pubDate>Fri, 14 Aug 2026 05:59:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Gravity-Coffee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc1ae2a0b23a9d94b93e9006a1b69edd31bca8cda4ab0c56cb0176d25fab17ea</i><br /><br />Threat actor <b>description</b>: <i>gravitycoffee.com zoominfo.com/c/gravity-coffee-company-llc/373342412 Gravity Coffee is a premium coffee brand known for serving high-quality beverages in its physical cafes and through retail products. Their signature medium roast blends feature a bold, smooth flavor profile with popular notes of hazelnut and chocolate. The company operates multiple locations and focuses on providing an exceptional coffee experience for its customers</i><br />Target victim <b>website</b>: <i>gravitycoffee.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baxter-International-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34943</link>
<guid>9e10e59fd190b3890cc225bafcf3a918</guid>
<pubDate>Fri, 14 Aug 2026 05:59:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Baxter-International-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9244574f2076f978c9ad6d88fea13f728600d01fd0983987058d5e0f367f2159</i><br /><br />Threat actor <b>description</b>: <i>Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 14 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>baxter.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Coast-Heart-Vascular-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34939</link>
<guid>b66db79f2f2507f17b72e103e6e02beb</guid>
<pubDate>Fri, 14 Aug 2026 05:57:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>First-Coast-Heart-Vascular-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>119e91e86e089325523759b1c4c8a21cea567498957fd79f39f54a3916687bf6</i><br /><br />Threat actor <b>description</b>: <i>firstcoastheart.com zoominfo.com/c/first-coast-heart--vascular-center/356606344 First Coast Heart & Vascular Center is a premier cardiovascular care provider serving patients across Northeast Florida. Their website highlights a comprehensive range of services, including expert cardiology, electrophysiology, advanced imaging, and vascular surgery. The medical center focuses on delivering innovative, evidence-based treatments and minimally invasive procedures to ensure the highest standard of heart health.</i><br />Target victim <b>website</b>: <i>firstcoastheart.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cityside-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34938</link>
<guid>46b9cf2d91977c26d75e1edd363ab08b</guid>
<pubDate>Fri, 14 Aug 2026 05:57:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Cityside-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d16cdcf5513b35cb33ac1d552b03972b2a34c3e18703ae283e5947e9e803b9b2</i><br /><br />Threat actor <b>description</b>: <i>citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in Houston, Texas, specializing in developing homeowner-focused residential communities. Since 2011, the company has built over 100 distinct neighborhoods, offering modern living spaces tailored to local buyers. Their website serves as a primary resource for exploring floor plans, browsing model homes, and discovering available properties across the greater Houston area.</i><br />Target victim <b>website</b>: <i>citysidehomes.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Retail-Business-Management-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34937</link>
<guid>1b56cc9502e48c2d42cbb7262dab2f8c</guid>
<pubDate>Fri, 14 Aug 2026 05:57:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Retail-Business-Management-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29a3652181bde5f6d46505eb7b9f0b732a5519dd8af065adba3430819c8c55f9</i><br /><br />Threat actor <b>description</b>: <i>rbms.com zoominfo.com/c/retail-business-management-systems-inc/101712744 Retail Business Management Systems (RBMS) is a specialized technology provider that has delivered Point of Sale and retail management solutions for over 25 years. Focusing heavily on NCR Counterpoint software and hardware integrations, the company supports retail businesses of all sizes primarily across the New York and New Jersey regions. Their platform serves as a central hub for merchants seeking comprehensive tools to optimize store operations, inventory tracking, and overall customer experience.</i><br />Target victim <b>website</b>: <i>rbms.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tempel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34935</link>
<guid>932db12621be9343f71934895bcd4b06</guid>
<pubDate>Fri, 14 Aug 2026 05:56:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Tempel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73c9455bda5216e041460b82f1485f37c1856c7afc679b5c42c544a6820da41f</i><br /><br />Threat actor <b>description</b>: <i>tempel.com zoominfo.com/c/tempel/87867666 Tempel Steel Company, a division of Worthington Steel, is a leading global manufacturer of high-precision electrical steel laminations. Established in 1945, the company provides essential components for motors, generators, and transformers used across the automotive, eMobility, and energy sectors. Their platform showcases advanced precision metal stamping and overmolding services designed to improve product performance and efficiency.</i><br />Target victim <b>website</b>: <i>tempel.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plaza-Auto-Mall</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34934</link>
<guid>faa67cda86f6134f05275319f3e3251b</guid>
<pubDate>Fri, 14 Aug 2026 05:56:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Plaza-Auto-Mall</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95a39ba3990d406eaab85208356ca0934a3a5450721c5e034f9d28dd8904585b</i><br /><br />Threat actor <b>description</b>: <i>plazaautomall.com zoominfo.com/c/plaza-auto-mall/194512238 Plaza Auto Mall is a family-owned dealership group based in Brooklyn, New York, that has been serving local drivers since 1975. They offer an extensive inventory of over 1,000 new, used, and certified pre-owned vehicles across multiple automotive brands all in one location. The platform also provides comprehensive automotive services, including financing options, vehicle maintenance, parts sales, and a dedicated body shop.</i><br />Target victim <b>website</b>: <i>plazaautomall.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Connections</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34930</link>
<guid>cbeb7c97ec2f127b9ee1488844409153</guid>
<pubDate>Fri, 14 Aug 2026 05:54:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Community-Connections</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e99a424cbd14fc008b15776bc022934720ffa54927cc463226ad94c463feaae0</i><br /><br />Threat actor <b>description</b>: <i>comconnections.org zoominfo.com/c/community-connections-inc/350834294 Community Connections is a non-profit organization based in Ketchikan, Alaska, dedicated to providing individualized support for children, seniors, and individuals with disabilities. Founded over 40 years ago, their core mission focuses on encouraging independence, community belonging, and improving the overall quality of life for those they serve. The organization offers a wide range of specialized programs, including early childhood learning, mental health support, and comprehensive disability services.</i><br />Target victim <b>website</b>: <i>comconnections.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reminger</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34926</link>
<guid>32d08e8dcd9a87d9d786d9540ff76a50</guid>
<pubDate>Thu, 13 Aug 2026 23:52:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Reminger</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75bb021a19306567b4015f7fc9f59590a2f51d2bac1bfb9b213cbf947efdb0db</i><br /><br />Threat actor <b>description</b>: <i>Reminger Attorneys at Law is a law firm with a strong presence in Ohio, Kentucky, and Indiana, operati…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>ZEBRA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34922</link>
<guid>2565f4991d36ea1847c721cc6080be27</guid>
<pubDate>Thu, 13 Aug 2026 20:21:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ZEBRA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4847c9c4b3e513be462410fd28934b9032728f07e93b19c3bc2011aea8d794d2</i><br /><br />Threat actor <b>description</b>: <i>Data exfiltrated included the following: Database, Project - files, CAD - files
Total size: 8Tb
Revenue: $5,600,000,000</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GB-Group-S.A</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34920</link>
<guid>cdeb4894869cbdaf5b55ed25012c0c10</guid>
<pubDate>Thu, 13 Aug 2026 14:23:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>GB-Group-S.A</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6703f999871df0cb3ec8733cf676cac23f6489f38554236e06bbbc6431e7baaf</i><br /><br />Threat actor <b>description</b>: <i>GB Group is one of Haiti’s largest private industrial and trading conglomerates. Headquartered in Port-au-Prince, it operates across nine core industries including construction materials, consumer goods, and energy. Recently, the organization transitioned its corporate identity to B|G|O (Builders of Great Opportunities).</i><br />Target victim <b>website</b>: <i>gbgroup.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>D--J-Beverage-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34919</link>
<guid>3c3961f8fc1f905eb7d2a9d96cd84298</guid>
<pubDate>Thu, 13 Aug 2026 13:29:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>D--J-Beverage-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0f7bf2709438ec33a5e77a509fb853f1a362835f97dbcb7477d37a3fe03889e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.dandjbeverage.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CF-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34918</link>
<guid>b4a01c90ca6ccef9b1f361162024b873</guid>
<pubDate>Thu, 13 Aug 2026 13:24:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CF-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>438f4bae138b887937828a7bf8d59f73883edffc041188c00f1dd356d1331091</i><br /><br />Threat actor <b>description</b>: <i>CF Supply is a Texas-based company that offers a wide range of construction products including 
drywall, metal framing, insulation, and door hardware. They provide services such as free estim
ates and 24-hour online account access, ensuring convenience for their clients.

We will upload corporate data soon. Client information (projects, personal information and so o
n), contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Safeware</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34914</link>
<guid>71e1d046417f3682dffa6f8f294da241</guid>
<pubDate>Thu, 13 Aug 2026 07:29:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Safeware</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>934ee035a191f1aeec77ad76668bad4b6291f3230a0df91644df7522b429937c</i><br /><br />Threat actor <b>description</b>: <i>safewareinc.com Safeware Inc. is a national leader providing safety and security solutions for first responders, schools, and government agencies.
For over 40 years, they have supplied advanced protective equipment and public preparedness training across the United States.
The company simplifies government purchasing by offering specialized gear through competitive cooperative contract pricing.</i><br />Target victim <b>website</b>: <i>safewareinc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>clgroup</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34913</link>
<guid>26728ef2438df2dd3d5b60a235d27513</guid>
<pubDate>Thu, 13 Aug 2026 05:25:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>clgroup</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20e02b01d9d51ecf693ce44e7d94f89b5a54bfb43d0bbc5c671ea00744934fad</i><br /><br />Threat actor <b>description</b>: <i>Compunnel, founded in 1994 and headquartered in Plainsboro, New Jersey, provides information technology consulting and staffing, custom business application development, and eLearning services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hightech-Signs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34909</link>
<guid>1aace02b1dc7a9ee987286a90bbef89c</guid>
<pubDate>Wed, 12 Aug 2026 20:25:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Hightech-Signs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7178415123d48a40f2417f4a5c8f0ba95e644a26fa51a35dbd3454ffa6a392a</i><br /><br />Threat actor <b>description</b>: <i>Hightech Signs, Inc. is a full-service sign shop located in Charlottesville, Virginia, specializing in custom sign production and creative consultation. They offer a wide range of products including engraving services, banners, vehicle graphics, and window lettering. Their services cater to clients in Central Virginia, providing fast turnaround and excellent customer service. Hightech Signs aims to meet the diverse signage needs of businesses and organizations in the region.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Riker-Danzig-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34908</link>
<guid>e4c446f4b7669022a2bd89128a7dbc1f</guid>
<pubDate>Wed, 12 Aug 2026 19:51:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Riker-Danzig-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c60ef699dd9b499d956d4755b026c64f047e3126913cfee52c1050355465dcbd</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Riker Danzig LLP is a prominent full-service law firm based in the United States, primarily operating in New Jersey. Founded in 1882, the firm provides legal services across a wide range of practice areas including litigation, corporate law, real estate, environmental law, and insurance. It serves clients spanning industries such as finance, healthcare, and manufacturing, and is recognized as one of New Jersey's leading law firms.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>gamaus.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34907</link>
<guid>bbe4bffdb46a85d01137ad4638d846a9</guid>
<pubDate>Wed, 12 Aug 2026 19:25:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>gamaus.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e82a099f7b4d9255b5de935bad106c42ae31f3126b046ca92eedf59dbcb2f90</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/greater-austin-merchants-cooperative-association/98978085 greater-austin-merchants-cooperative-association 400gb</i><br />Target victim <b>website</b>: <i>gamaus.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Enteroptyx-Ophthalmology-Products-www.enteroptyx.com-serviced-by-an-IT-company-Computer-Co...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34903</link>
<guid>fb52538ee970026501864b2272852dc4</guid>
<pubDate>Wed, 12 Aug 2026 16:22:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Enteroptyx-Ophthalmology-Products-www.enteroptyx.com-serviced-by-an-IT-company-Computer-Co...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c9551ad23704d8b12ade9563b4b3d4102e88ffbd07eba98c5e4d055adb1a4a5</i><br /><br />Threat actor <b>description</b>: <i>There is very little public information available about this company. Judging by its name, it is a small supplier or manufacturer of ophthalmology products (equipment, consumables, or instruments for eye care). There is virtually no detailed data regarding its operations, location, or history in open sources.</i><br />Target victim <b>website</b>: <i>www.enteroptyx.com</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Association-Local-Union-345</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34901</link>
<guid>6203f1dde486c7e691c5438115e54e0e</guid>
<pubDate>Wed, 12 Aug 2026 15:57:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>United-Association-Local-Union-345</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b3dc9fa27ae57ecf135423a84320cc3d43a879eb7bd3732db7107828e3a9052</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ua345.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>diabetesandmetabolism.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34899</link>
<guid>63b3366f01d511d8bb4eab0b3ae50f2e</guid>
<pubDate>Wed, 12 Aug 2026 15:53:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>diabetesandmetabolism.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53ec0b73998fc83e0fbab139e50b45575523b81a9261cd2122513e1efcf1408b</i><br /><br />Threat actor <b>description</b>: <i>Diabetes and Metabolism Specialists is a specialty medical clinic located in San Antonio, TX, focused on the diagnosis and treatment of endocrine-related medical conditions. The clinic is staffed by board-certified endocrinologists, nurse practitioners, and certified diabetes educators who provide comprehensive care and education for chronic conditions such as diabetes, hyperparathyroidism, and metabolic syndrome. They emphasize professionalism and patient education, ensuring that clients understand their diagnoses and treatment options. The intended clients are individuals seeking specialized care for endocrine disorders and metabolic conditions. Employees: 50 Revenue: $5.5 Million Industry: Hospitals & Physicians Clinics Phone Number: (210) 494-3739 </i><br />Target victim <b>website</b>: <i>diabetesandmetabolism.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>GATE7LLC.COMGBBEV.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34897</link>
<guid>db120c26cd221825b31fcdb62f740192</guid>
<pubDate>Wed, 12 Aug 2026 15:51:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GATE7LLC.COMGBBEV.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc47ba26b1d64fc051c248d34c1c2d0e38704269907876f1e6fd15d724b5e2ea</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>GATE7LLC.COMGBBEV.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENTERATEK.MXESBERBEVERAGE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34896</link>
<guid>33acaba956e30e1494c5b84d48694e0e</guid>
<pubDate>Wed, 12 Aug 2026 15:50:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ENTERATEK.MXESBERBEVERAGE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac6feeaadfc11149a9ad70fb927e4f358d6ab8b9d737704feffb214deaa2337c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>ENTERATEK.MXESBERBEVERAGE.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ECCELLENT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34893</link>
<guid>3af9c18dfa6098d8ec01d3bebcd7a956</guid>
<pubDate>Wed, 12 Aug 2026 15:48:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ECCELLENT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9e90fa774b899149941757c9a81ff119fba22b69f613a3861a4f740ebe5ee40</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>ECCELLENT.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FLUIDLOGIC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34890</link>
<guid>f386f35a4c15acb710fd7bf4f00110a3</guid>
<pubDate>Wed, 12 Aug 2026 15:46:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FLUIDLOGIC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc3b5c9d4f30b3b5635e6a13f32b5dc030caa761ff41a7c769dfd871d0c5bc56</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] FluidLogic is a US-based technology company specializing in advanced fluid management systems. It develops innovative hydration and fluid delivery solutions, primarily used in sports, military, and outdoor applications. The company is known for engineering pressurized hydration systems that allow hands-free fluid delivery. Operating in the sporting goods and defense equipment industry, FluidLogic serves both consumer and government markets across the United States.</i><br />Target victim <b>website</b>: <i>FLUIDLOGIC.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>G3AEROSPACE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34887</link>
<guid>cbfa268b9f76e19d0531ddbdff46c2f2</guid>
<pubDate>Wed, 12 Aug 2026 15:45:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>G3AEROSPACE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>295ec307c68dfdc5627235ecdaa63ba915612565aff3c1bbe482db7674c1c02b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>G3AEROSPACE.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ARCHERGREY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34886</link>
<guid>b9f7c99a62433ab681f7e97cdc4bd107</guid>
<pubDate>Wed, 12 Aug 2026 15:44:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ARCHERGREY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8fe842685a07f202fc8b71d2685ccea078884b167a177e87e7071e026346cb3f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>ARCHERGREY.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LIFESTRAW.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34884</link>
<guid>b2f1234b9a029e7a40211c6b4773c5bd</guid>
<pubDate>Wed, 12 Aug 2026 15:43:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LIFESTRAW.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e5b776f1329dcda732bd338a4cb316aed694c0655c17b1cc6e8b98ff9a90021</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] LifeStraw is an American consumer goods company specializing in portable water filtration and purification products. Founded in Switzerland and now headquartered in the United States, it produces filters, straws, bottles, and pitchers designed to remove bacteria, parasites, and microplastics from water. The company serves outdoor enthusiasts, travelers, and humanitarian relief efforts globally, making safe drinking water accessible in both recreational and emergency contexts.</i><br />Target victim <b>website</b>: <i>LIFESTRAW.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SPKAA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34883</link>
<guid>ac5dd1eff7e0349bfd4b10e182577707</guid>
<pubDate>Wed, 12 Aug 2026 15:43:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SPKAA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0feaf7ab302af3a672ca3c7655d00361b1fa003287f797d2c482a1ce09eee9a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>SPKAA.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>THERMOS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34880</link>
<guid>c736b91eecdcfc795549afee33c96ce4</guid>
<pubDate>Wed, 12 Aug 2026 15:41:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>THERMOS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a176bf201d7533457a0075563987c88354542b11de819d36b38bef2927868f60</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Thermos.com is the official website of Thermos LLC, a well-known American consumer goods company specializing in insulated food and beverage containers. Operating in the housewares and outdoor products industry, the company sells vacuum-insulated bottles, lunch kits, and food jars. Originally founded in Germany in 1904, Thermos is now headquartered in the United States and serves global markets through retail and e-commerce channels.</i><br />Target victim <b>website</b>: <i>THERMOS.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INTELLIHOT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34877</link>
<guid>c6c65000e8d245e161471faa4801208c</guid>
<pubDate>Wed, 12 Aug 2026 15:39:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INTELLIHOT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4be2821bdf5c0a7dc665abb7f962b910da5728691c4b6f4b32ecc5fc1b81495d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Intellihot is a US-based company specializing in commercial and residential tankless water heating solutions. Founded in Illinois, the company designs and manufactures smart, gas-fired tankless water heaters that use proprietary modular technology for energy efficiency and scalability. Intellihot serves hospitality, multifamily, and commercial sectors, emphasizing IoT connectivity and remote monitoring capabilities to optimize performance and reduce energy consumption.</i><br />Target victim <b>website</b>: <i>INTELLIHOT.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>CLOVER.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34873</link>
<guid>91ca7ff824876a675d873fe72d715f49</guid>
<pubDate>Wed, 12 Aug 2026 15:37:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CLOVER.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03d08d7792a35fb480b491511b04a76526cd5e2640ccefcdc8359a1a7cb21c6a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Clover.com is a US-based financial technology company that provides point-of-sale systems and business management solutions primarily for small and medium-sized businesses. Operated under Fiserv, Clover offers hardware terminals, software, and payment processing services. Its platform supports inventory management, employee tracking, customer engagement, and sales analytics, making it a comprehensive commerce solution across the retail and hospitality industries.</i><br />Target victim <b>website</b>: <i>CLOVER.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMAPCENTER.UAH.EDU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34869</link>
<guid>63f09a36c9b6d5895f2279b5fc497a71</guid>
<pubDate>Wed, 12 Aug 2026 15:34:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SMAPCENTER.UAH.EDU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87082c3013bfe7eafc11247e7d13f6504799988b59a348dc31af8a7c528735e8</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

The identifier "SMAPCENTER.UAH.EDU" appears to be a subdomain associated with the University of Alabama in Huntsville (UAH), likely related to a specific research center or project. However, there is insufficient reliable information available to provide a factual and accurate description of this specific entity's scope, activities, or industry focus without risk of providing inaccurate details.</i><br />Target victim <b>website</b>: <i>SMAPCENTER.UAH.EDU</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRISTAR.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34868</link>
<guid>759a19b71fb33f978ce71ce24932e9b7</guid>
<pubDate>Wed, 12 Aug 2026 15:34:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>TRISTAR.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd20ad607c132544eeda3d1aedbab491a01ae53c4c7c86a767fedde5a6fc7665</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>TRISTAR.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>CORNELIUS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34866</link>
<guid>add26ffac48a0fcd634781f1a041e4ac</guid>
<pubDate>Wed, 12 Aug 2026 15:33:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CORNELIUS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0582d0339cd005357bc7d64929c62144127cba3c84ca5c010357eef63fcb496e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>CORNELIUS.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>STARKEY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34863</link>
<guid>e736230e56126b2bc4440320989aa6a7</guid>
<pubDate>Wed, 12 Aug 2026 15:31:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>STARKEY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ca27dee51c20c81d216ea18e033fe4a64d2bec2e24b0651ce862ac85849a1e1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Starkey is a leading American hearing technology company headquartered in Eden Prairie, Minnesota, USA. Founded in 1967, it designs, manufactures, and distributes hearing aids and related hearing health solutions. Starkey is one of the few remaining privately held hearing aid manufacturers in the world and is known for innovation in smart hearing technology, including AI-powered and health-monitoring hearing devices.</i><br />Target victim <b>website</b>: <i>STARKEY.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TOASTTAB.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34861</link>
<guid>946fe5c21087bcb5ed3f73eace856a61</guid>
<pubDate>Wed, 12 Aug 2026 15:30:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>TOASTTAB.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>874318c0eb0d5b4a6aeef7a5a4ea71bcf1ec8845b39161dd0f6f5b5b35cbb310</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] ToastTab.com is the online platform for Toast, Inc., a US-based restaurant technology company headquartered in Boston, Massachusetts. Toast provides cloud-based point-of-sale software, payment processing, and restaurant management solutions tailored for the food service industry. Its platform supports ordering, payroll, inventory, and customer engagement tools, serving restaurants of all sizes across the United States and internationally.</i><br />Target victim <b>website</b>: <i>TOASTTAB.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>IRCO.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34860</link>
<guid>5d80f41d392a2f39804eae9eb91fe770</guid>
<pubDate>Wed, 12 Aug 2026 15:29:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>IRCO.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01c929d27ce28c2e2e320c829261007a4cf94ccc2d247fa6aff5689ffa1b3c3d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] IRCO.COM appears to be associated with the Industrial Rubber Company (IRCO), a U.S.-based manufacturer and distributor specializing in industrial rubber products, seals, gaskets, hoses, and related components. The company serves sectors such as manufacturing, oil and gas, and construction. Operating primarily in the United States, it supplies both standard and custom rubber solutions to industrial clients across various markets.</i><br />Target victim <b>website</b>: <i>IRCO.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FISERV.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34857</link>
<guid>a1ba7595d9f1fa2fa235ba97c977a78a</guid>
<pubDate>Wed, 12 Aug 2026 15:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FISERV.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f316b6ebaa5002f25ecd30bd2130aa317b4b108068a9f205a67317d05f5a9109</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Fiserv is a leading American financial technology company headquartered in Milwaukee, Wisconsin. It provides payment processing, banking software, and financial services technology to banks, credit unions, merchants, and other financial institutions worldwide. Its services include core banking systems, digital payments, card processing, and data analytics. Fiserv operates globally and is listed on the NASDAQ stock exchange.</i><br />Target victim <b>website</b>: <i>FISERV.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34856</link>
<guid>9dec88b3772c35708f47db386b2f487e</guid>
<pubDate>Wed, 12 Aug 2026 15:27:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02b788d74d1daf58f21fdd920191db0452f05abb29ac0309c0996f8cf6a62841</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] General Electric (GE) is a American multinational conglomerate headquartered in Cincinnati, Ohio, USA. Operating across multiple industries, GE focuses on aviation, healthcare, and energy sectors. The company manufactures jet engines, medical imaging equipment, and power generation technologies. GE has undergone significant restructuring in recent years, spinning off several business units to sharpen its focus on industrial operations globally.</i><br />Target victim <b>website</b>: <i>GE.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>NETPOWER.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34855</link>
<guid>90a5a12198b43cd185f76c1674f140ca</guid>
<pubDate>Wed, 12 Aug 2026 15:26:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NETPOWER.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35c9abfd403774879c548ffe67ec657de60023b728e2bc7fef7fa64ce5c4cb70</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>NETPOWER.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>stuartandassociates.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34853</link>
<guid>719bdf36f0352752837458a9d1b16bc8</guid>
<pubDate>Wed, 12 Aug 2026 15:03:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>stuartandassociates.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f19ad800cbddf0d578225d772484872c78d5c1acdb2fbe3bf60dc98db9fc1def</i><br /><br />Threat actor <b>description</b>: <i>Stuart & Associates Commercial Flooring, Inc. specializes in providing high-quality commercial flooring solutions designed to enhance customer experiences. They offer a three-year warranty on new installations when clients purchase maintenance programs, ensuring satisfaction and value throughout the process. The company features a design center with extensive product samples and emphasizes delivering projects on budget and on schedule. Their target clients include businesses seeking safe, comfortable, and aesthetically pleasing flooring options. Employees: 50 Revenue: $6.4 Million Industry: Construction Management  Phone Number: (316) 267-0743 </i><br />Target victim <b>website</b>: <i>stuartandassociates.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>ALTAIR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34844</link>
<guid>0629fccd9ea3789671acab64a17ed21a</guid>
<pubDate>Wed, 12 Aug 2026 14:46:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>majinahanashi</b> claims attack for <b>ALTAIR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>900b46c736f8c506929e9638d86701a947223107e98cdc36b5e9f8734d42aa45</i><br /><br />Threat actor <b>description</b>: <i>PUBLICATION SCHEDULED. [LEAK / 84251 FILES]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>majinahanashi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Holstrom-Block--Parke-A-Professional-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34835</link>
<guid>f8548a8d98a27fe73f2558a90f989c5c</guid>
<pubDate>Wed, 12 Aug 2026 07:49:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Ethics</b> claims attack for <b>Holstrom-Block--Parke-A-Professional-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>427864687b4389f78bb822a57646bfd4d0d3a2f44d2b0f0b45d6deb60b2057b8</i><br /><br />Threat actor <b>description</b>: <i>Our attorneys have experience handling cases in all areas of family law, estate planning, appeals, and probate law</i><br />Target victim <b>website</b>: <i>hbplaw.com</i>]]></description>
<category>Ethics</category>
</item>
<item xmlns:dc='ns:1'>
<title>Philadelphia-Insurance-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34834</link>
<guid>b83ca5c7a4724ec553b7a9b8b6024a98</guid>
<pubDate>Wed, 12 Aug 2026 07:49:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Ethics</b> claims attack for <b>Philadelphia-Insurance-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06c4903a56720473ebcb2ac8b6fc5c35fbcfa63c1e7e73775d091c3b3fabaac8</i><br /><br />Threat actor <b>description</b>: <i>Philadelphia Insurance Companies (phly.com) is a premier national Property/Casualty and Professional Liability insurance carrier that designs</i><br />Target victim <b>website</b>: <i>phly.com</i>]]></description>
<category>Ethics</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hahn-loeser</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35709</link>
<guid>cc4d91edae41488c825cc05a61fc4452</guid>
<pubDate>Wed, 12 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spycorp</b> claims attack for <b>Hahn-loeser</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06e86604d3e954b1a14ecd9dafc74c686ea902b713cea19b996d273763509522</i><br /><br />Threat actor <b>description</b>: <i>Hahn Loeser & Parks LLP is a full-service law firm headquartered in Cleveland, Ohio, offering legal services across various practice areas including business law, litigation, and intellectual property. Website: https://www.hahnlaw.com/</i><br />Target victim <b>website</b>: <i>hahnlaw.com</i>]]></description>
<category>spycorp</category>
</item>
<item xmlns:dc='ns:1'>
<title>powdr.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34826</link>
<guid>32ff692bedd4cd4764741dd4b347d5b4</guid>
<pubDate>Tue, 11 Aug 2026 17:33:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>powdr.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3cfd7b7ac0edaba7d8361943c5caec55731875b2c49f2b50f381d88d0ee3a9dd</i><br /><br />Threat actor <b>description</b>: <i>Point of No Return: What the Ski Empire Is Hiding A company that sells adventure, family memories, a...</i><br />Target victim <b>website</b>: <i>powdr.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>firstdigital.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34825</link>
<guid>4fbab5b4444f903987961d84f9821488</guid>
<pubDate>Tue, 11 Aug 2026 17:32:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>firstdigital.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0d79a3a053b73f9f377e6f874fb67e3c83f960d043697548daffb30808c2cf05</i><br /><br />Threat actor <b>description</b>: <i>The Digital Cartel: How a Telecom Empire Robs Its Own Customers and Employees A company that sells c...</i><br />Target victim <b>website</b>: <i>firstdigital.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>flowco-inc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34824</link>
<guid>6d1d663a5fc0fb709ecd336753450cac</guid>
<pubDate>Tue, 11 Aug 2026 17:31:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>flowco-inc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65c33a6e2bf80fe21d7f9fa04ab1c4991319ac67e06086380b227de4d07e18bb</i><br /><br />Threat actor <b>description</b>: <i>DEEP WELL: Flowco Production Solutions Documents PROLOGUE Payroll records with employee names and po...</i><br />Target victim <b>website</b>: <i>flowco-inc.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Service-Evaluation-Concepts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34811</link>
<guid>76daf89ce28106580694a0eea18a27ee</guid>
<pubDate>Tue, 11 Aug 2026 15:33:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Service-Evaluation-Concepts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25493da1732a528f21ff3ec5a54578739920ed3bdcd42b5edef4492a4ca768b6</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>advancedtaxsolutions.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34818</link>
<guid>3de809f0da843c4f73fbff60159632be</guid>
<pubDate>Tue, 11 Aug 2026 15:27:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>advancedtaxsolutions.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67b3156595c7716d7838d57d35e40cb7a4d7f6d9a704bad85bb53d452052a337</i><br /><br />Threat actor <b>description</b>: <i>Frank Rim &amp; Associates: Archive of a Tax Consulting Practice PROLOGUE Every tax case. Initial cl...</i><br />Target victim <b>website</b>: <i>advancedtaxsolutions.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>AngMar-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34817</link>
<guid>c6aae98722a05d2a1a2370faef8b1b66</guid>
<pubDate>Tue, 11 Aug 2026 15:24:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>AngMar-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>992e3b034ed389a38388f5eedc444d0768473911b0876f0cd772135d93de518d</i><br /><br />Threat actor <b>description</b>: <i>AngMar is a private organization comprised of numerous corporate holdings, LLCs, and companies, operating a network of home health care facilities. They disregard the safety of their clients and the people they care for. As a result, 710 GB of confidential information about the companies they serve has been exposed. Most importantly, patient data has been leaked, including their medical records, medical histories, personal information such as Social Security numbers, home addresses and phone numbers, and much more.</i><br />Target victim <b>website</b>: <i>angmarcompanies.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baya-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34814</link>
<guid>54f3fa6166fe3b6fbc596defb3ebd78b</guid>
<pubDate>Tue, 11 Aug 2026 14:28:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>Baya-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fea721397379faf599668f366969bd4dbd2b66eba7411b43f418f8253f0a79e5</i><br /><br />Threat actor <b>description</b>: <i>Baya offers end-to-end solutions for complex challenges, specializing in technology and distribution services. The company operates under the brands baya-zicon technologies and baya-zicon EMS, providing a wide range of technological services and electronic manufacturing services (EMS). Their target audience includes companies seeking comprehensive solutions in technology and distribution.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>tommer-construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34810</link>
<guid>3a532033aa5b0c64d1a7b2b13e4b5d33</guid>
<pubDate>Tue, 11 Aug 2026 12:31:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>tommer-construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32c2f9753e304fbbeb0779a0925e691a89765e5822bc1565960fa1e5ef4515d9</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.tommerconstruction.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leafwell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34809</link>
<guid>e36d6304f09fa1673f3477b4b01eb4c9</guid>
<pubDate>Tue, 11 Aug 2026 05:55:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Leafwell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa51003f8b74b256bf3290ef8afd8106e3ff91cf71d593c8faa6ed0272f8f8f7</i><br /><br />Threat actor <b>description</b>: <i>Hospitals &amp; Physicians Clinics</i><br />Target victim <b>website</b>: <i>leafwell.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Turner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35707</link>
<guid>bb5acdd12f1b38cff9b475186aadd33d</guid>
<pubDate>Tue, 11 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Turner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57c1fff15bb9a179986034a67c7c0ec5447b7eb2d3fc82d055fecc37be07113a</i><br /><br />Threat actor <b>description</b>: <i>Turner Construction Company, founded in 1902 by Henry C. Turner, is a leading North American-based international construction services firm. Specializing in diverse market segments, Turner has earned recognition for undertaking large and complex projects, fostering innovation, and embracing emerging technologies. The company operates in 20 countries and completes more than 1,500 projects annually. Website: https://www.turnerconstruction.com/</i><br />Target victim <b>website</b>: <i>turnerconstruction.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ginger-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35708</link>
<guid>0990a0c05a2837d3f8c632453278008a</guid>
<pubDate>Tue, 11 Aug 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kraken</b> claims attack for <b>Ginger-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d35a5da4a644dea27857caabbb2beef417aae1a0525e93bf4eab816ee4a99af0</i><br /><br />Threat actor <b>description</b>: <i>Ginger Consulting, founded in 2007 and based in Minneapolis, Minnesota, specializes in brand strategy and custom market research. Their services include brand positioning, marketing strategy, and ideation, catering to modern business needs. Website: http://www.gingerminneapolis.com/</i><br />Target victim <b>website</b>: <i>gingerminneapolis.com</i>]]></description>
<category>kraken</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cleaver-Brooks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34805</link>
<guid>9b784280afc36c74b271d8af5ec9e534</guid>
<pubDate>Mon, 10 Aug 2026 22:22:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Cleaver-Brooks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8a7d0cbc3c2a02db583eb26132e7e02c53d8870e79e7671a843b425272af81d</i><br /><br />Threat actor <b>description</b>: <i>Major data breach at a leading industrial manufacturer.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Consolidated-Medical-Practices-of-Memphis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34803</link>
<guid>599430bd25e315dd79020a112a1593da</guid>
<pubDate>Mon, 10 Aug 2026 21:58:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Consolidated-Medical-Practices-of-Memphis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8858605c78640f412226344576c4ec0aaf4cfc669a72568818c9786ac0fa4302</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Interim-HealthCare-Oklahoma-and-Tulsa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34802</link>
<guid>7595b2be04baf3bd1171d20c6d3a7ff7</guid>
<pubDate>Mon, 10 Aug 2026 21:57:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Interim-HealthCare-Oklahoma-and-Tulsa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d44fc25aa31cb4626c2e190ced9e831012e939af123dcb42580e6ff166c7d41</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization dealing with elderly care services</i><br />Target victim <b>website</b>: <i>interimhealthcare.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swyft-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34798</link>
<guid>b7e06877d36a4adf8619d79a01233983</guid>
<pubDate>Mon, 10 Aug 2026 19:34:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Swyft-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2af1f221ae656db2cc66db8404ddca1e4dde692dc2806226ebcfab49befe0cf1</i><br /><br />Threat actor <b>description</b>: <i>Retail Technology &amp; SaaS</i><br />Target victim <b>website</b>: <i>swyft.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>AliveCor-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34797</link>
<guid>59c53d894d899733cf74c51da615234c</guid>
<pubDate>Mon, 10 Aug 2026 18:58:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>AliveCor-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e9a2c42728eb647ad58543085d4d0d7904a73ea548d713c8f3bef5c31b596d0</i><br /><br />Threat actor <b>description</b>: <i>medical device and artificial intelligence</i><br />Target victim <b>website</b>: <i>alivecor.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Health-Carousel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34794</link>
<guid>f032df87b5453794c2c6aa442ccc1412</guid>
<pubDate>Mon, 10 Aug 2026 18:56:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Health-Carousel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfbc1e638398309f276cf1b77a2fa33750da4c5696c0e3279fa2af5d30a73bb9</i><br /><br />Threat actor <b>description</b>: <i>Business Services · Ohio</i><br />Target victim <b>website</b>: <i>healthcarousel.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fondo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34793</link>
<guid>9ca23f6f5db0679c61be4b1818cb6a26</guid>
<pubDate>Mon, 10 Aug 2026 18:56:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Fondo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efcc80c19a27e86d3268813e27607a02aaf323d57c42de3555075eaa36f9cb86</i><br /><br />Threat actor <b>description</b>: <i>Financial Software</i><br />Target victim <b>website</b>: <i>fondo.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Coggins-Insurance-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34790</link>
<guid>56a5739ae918ad4bfbfac3cb50658476</guid>
<pubDate>Mon, 10 Aug 2026 17:21:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Coggins-Insurance-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14fa7e3cc94eee8c156860c8298cffa96df8dce8259a5935a3450d76996f15c3</i><br /><br />Threat actor <b>description</b>: <i>Country: Florida, United States |
Website: cogginsinsurance.com |
Revenue: $5 Million |
Industry: Insurance |
Employees: 1-10 |
Properties: 85.9 GB (245,768 Files, 26,563 Folders)</i><br />Target victim <b>website</b>: <i>cogginsinsurance.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alcast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34787</link>
<guid>ef241cf07da90f707eaf0a3a08b64d0c</guid>
<pubDate>Mon, 10 Aug 2026 14:21:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Alcast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>347af8e9ba5bae1d2763f2c223fa1e67b6ea51c7f059c8d448700eae5ab72849</i><br /><br />Threat actor <b>description</b>: <i>ALCAST is a leading aluminum casting company specializing in precision casting, sand casting, a
nd die casting. They provide high-quality aluminum castings for various industries, including a
griculture, defense, heavy equipment, and marine.

We will upload 170gb corporate data soon. Employee personal files (passport, DLs, SSNs, address
es and so on), projects, customers information, contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>i4-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34784</link>
<guid>ae42100894109a63e44a3e4420d19793</guid>
<pubDate>Mon, 10 Aug 2026 13:22:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>i4-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ca532f0b393b160ff33c7dc8d5218c6ee2362cd888885ae16a02761b9102b13</i><br /><br />Threat actor <b>description</b>: <i>i4 Solutions has created thousands of Websites for companies all over the world! i4 Solutions c
reates custom websites and prides itself that all work is done by i4 employees not outsources c
ontractors.

We will upload 170gb corporate data soon. Lots of working files, projects and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Winchester</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34782</link>
<guid>7cf2ee86200c2a3b1b376f2681e63985</guid>
<pubDate>Mon, 10 Aug 2026 12:01:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Winchester</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8df20747ffa922cad046fb7fe395ae44b98f930c608e5bacf0d1cf9018d4a31</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.winchesterky.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cook-Remodeling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34780</link>
<guid>6884af248368375ac72575ca240bb843</guid>
<pubDate>Mon, 10 Aug 2026 11:51:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Cook-Remodeling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>400e8ee1ac2797a9d4c4216e3b57c4ef08a4cc4cad217cefe5bee28fa610e3dc</i><br /><br />Threat actor <b>description</b>: <i>Country: Arizona, United States
Website: cookremodeling.com |
Revenue: $5 Million |
Industry: Construction Management |
Employees: 11-50
Properties: 23.2 GB (47,193 Files, 8,323 Folders)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Metals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34779</link>
<guid>9fcc8beb3e7cd46714d8fa78eb705ad5</guid>
<pubDate>Mon, 10 Aug 2026 11:23:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Southern-Metals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a27925d0ab4a6ba340cd4d0ef6be781def67d4eaa0663e915ed7d43cdb67500</i><br /><br />Threat actor <b>description</b>: <i>Southern Metals Company, based in Charlotte, NC, specializes in the recycling of ferrous and non-ferrous metals, including steel, brass, copper, aluminum, and automobile bodies. Established in 1938, the company is committed to responsible recycling, superior customer service, and providing exceptional value for recyclable products. Serving a diverse clientele throughout the Carolinas, Southern Metals has built a reputation for integrity and efficiency over its long history. The company continues to uphold the principles set by its founders while adapting to modern recycling needs. 
The company headquarters is located in 2200 Donald Ross Road, Charlotte, NC 28208, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>southernmetalscompany.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRP-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34778</link>
<guid>c53fdeb4367f55e43161bf45eedee613</guid>
<pubDate>Mon, 10 Aug 2026 11:23:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>TRP-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>613cd21024d77b98c6578d6c25beb847519f89bb27df73118150fa904478a535</i><br /><br />Threat actor <b>description</b>: <i>TRP International, LLC specializes in the distribution of high-quality components for various markets, including axle manufacturers, boat trailer manufacturers, and specialty vehicle manufacturers. The company utilizes state-of-the-art technology and strategically located distribution centers to ensure efficient order processing and delivery across the U.S., Canada, and Mexico. With a strong focus on engineering, quality, and lean manufacturing principles, TRP is committed to meeting and exceeding customer specifications. Their ISO 9001:2015 certification underscores their dedication to quality and continuous improvement in their product offerings. 
The company headquarters is located in 22420 Challenger Drive, Elkhart, IN 46514, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>trpintl.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Supportive-Insurance-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34777</link>
<guid>6a86f3d6652d5ef40c954176b71f263c</guid>
<pubDate>Mon, 10 Aug 2026 11:22:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Supportive-Insurance-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6276f6b121c93651c72024a87f881630e7113817ecc96086e883b0666703c2de</i><br /><br />Threat actor <b>description</b>: <i>Supportive Insurance Services is a specialized insurance compliance firm that provides comprehensive licensing solutions for agents, agencies, adjusters, and carriers across the United States. The company helps clients navigate complex, state-specific regulatory requirements, ensuring full compliance while reducing administrative burdens and operational risk. By managing every aspect of the licensing process with precision and personalized service, Supportive Insurance Services enables insurance professionals to focus on client service and business growth. The firms expertise, deep industry knowledge, and client-centered approach make it a trusted partner for insurance organizations seeking efficient and reliable licensing support. 
The company headquarters is located in 1610 S Old Decker Road, Vincennes, IN 47591, United States.
11-50 Employees</i><br />Target victim <b>website</b>: <i>supportiveis.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>T.RAD-North-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34776</link>
<guid>9d55db9e54e6dfb6ae280528ee34a0a1</guid>
<pubDate>Mon, 10 Aug 2026 10:52:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>T.RAD-North-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33e03a177ba77de085c1a7ea892a78fba55da6771bdd0813b89bc3e07efbbb8f</i><br /><br />Threat actor <b>description</b>: <i>T.RAD North America (tradna.com) is a Hopkinsville, Kentucky-based manufacturer focused on heat exchangers for thermal-management applications such as vehicle powertrains, HVAC/architectural systems, and emerging technologies like battery and fuel-cell cooling.</i><br />Target victim <b>website</b>: <i>tradna.com</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Black-Hills-Bentonite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34775</link>
<guid>18fb593b37b32fa30b2142c6e155578b</guid>
<pubDate>Mon, 10 Aug 2026 10:51:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Black-Hills-Bentonite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc62e076ac29453aed467c87dc8b89ec20552b266b125fc4a13dd1512005f4b6</i><br /><br />Threat actor <b>description</b>: <i>Black Hills Bentonite LLC (bhbentonite.com) is a Wyoming-based producer of high-quality sodium bentonite, along with lignite-related products, supplying global industrial and commercial uses such as drilling fluids, environmental/civil engineering sealing, absorbents (including cat litter), and metal casting/foundry applications</i><br />Target victim <b>website</b>: <i>bhbentonite.com</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>AnMed</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34767</link>
<guid>88561cd999906a644093dd56a0a0c821</guid>
<pubDate>Mon, 10 Aug 2026 08:10:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>AnMed</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>531b6d82da2a3bc81c893b885eba6be0b975a114df1ebeb5c968666c212ac2d6</i><br /><br />Threat actor <b>description</b>: <i>anmed.org zoominfo.com/c/anmed/1238269198 AnMed is an independent, not-for-profit health system founded in 1908, serving Upstate South Carolina and northeast Georgia.
Its anchor facility, AnMed Medical Center, is a 461-bed acute care hospital located in Anderson, South Carolina.
The network provides comprehensive medical services, including emergency care, cardiovascular surgery, advanced imaging, and specialized outpatient clinics.</i><br />Target victim <b>website</b>: <i>anmed.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eva-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34762</link>
<guid>8a16b0e6d2a3ccdf8996b058c26af476</guid>
<pubDate>Mon, 10 Aug 2026 08:09:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Eva-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78113480286f44b805c72f5697a3e19f56fdd8adbcd2ab08ccf1d453dc4bd383</i><br /><br />Threat actor <b>description</b>: <i>evacare.com rocketreach.co/eva-care-profile_b7a227f8c53b4785 Eva Care Group is a healthcare provider specializing in the post-acute care industry, headquartered in Los Angeles, California.
With over 50 years of combined experience, the company operates and manages a network of nursing homes and rehabilitation facilities.
They deliver comprehensive solutions encompassing clinical, financial, operational, and environmental management to ensure high-quality patient care.</i><br />Target victim <b>website</b>: <i>evacare.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zion-Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34760</link>
<guid>6301041b4a6f1cc0d222bb6c02fcbe55</guid>
<pubDate>Mon, 10 Aug 2026 08:08:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Zion-Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6ff846c6a4dfdf35476e67906fd7fccfa254c16ee1d2aaa6e0d91a9a4a900a8</i><br /><br />Threat actor <b>description</b>: <i>zioncontracting.com Zion Contracting LLC is a trusted general contractor based in New York, specializing in complex infrastructure and transportation projects. As a certified MBE, DBE, and SBE firm, they partner with government agencies to help fulfill minority and diversity contracting goals. Their main focus is delivering essential public works projects that strengthen communities across the state</i><br />Target victim <b>website</b>: <i>zioncontracting.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>MIE-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34759</link>
<guid>d3fe245c816bf7c5eae0d27d2c005c86</guid>
<pubDate>Sun, 09 Aug 2026 19:26:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>MIE-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de7db4dbebbf11767e889146be7e6fc37a438ff22b8bd0ff5b47622416e1b01b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mie-solutions.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Synergy-Interactive</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34756</link>
<guid>ef482c2b5df361ebe176e3bade57d833</guid>
<pubDate>Sun, 09 Aug 2026 18:32:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Synergy-Interactive</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4eb296256cc61ff35ffbba830fde46c03de01f720be15f92233ac057b46eb621</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sinyc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Price-Shoes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34747</link>
<guid>9339be1158aa50c53147b3b53bf0f259</guid>
<pubDate>Sun, 09 Aug 2026 15:34:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Price-Shoes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff6e2fb26c783448b1d66e592ab19311eed02dbafd7691af8814f8e827fd0687</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lucidmotors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34742</link>
<guid>bc931d478676400884a7371ff4b9b0f5</guid>
<pubDate>Sun, 09 Aug 2026 09:21:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Sovcali</b> claims attack for <b>Lucidmotors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6d25859951fac91a23312d6e52089e9bab50a52d6ca9f740ca59e7cbd4729f3</i><br /><br />Threat actor <b>description</b>: <i>Lucid Motors & eShocan Engineering Archive in Our Possession. The complete engineering archive of Lucid Motors and eShocan is now available: 5.078 terabytes of CATIA and STEP models, FEA and NVH analyses, multi-gigabyte CFD simulations of the LiDAR washing system, topology optimization studies, static and modal results for the Gravity and Midsize enclosures, BOMs, and internal progress reports.</i><br />Target victim <b>website</b>: <i>lucidmotors.com</i>]]></description>
<category>Sovcali</category>
</item>
<item xmlns:dc='ns:1'>
<title>Louisville-Bar-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34736</link>
<guid>e0f9e8ce4809cc21c3d636686bcdd99d</guid>
<pubDate>Sat, 08 Aug 2026 14:25:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Louisville-Bar-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>513f13077c2c6931bbf0e101d85b395258fdd60223860d6502064e7095905b6a</i><br /><br />Threat actor <b>description</b>: <i>The Louisville Bar Association (LBA) provides a range of services including membership benefits, legal job placement, continuing legal education (CLE), and public service initiatives. It aims to support legal professionals at all stages of their careers while promoting diversity and community engagement within the legal field. The LBA also offers resources for individuals seeking legal representation and hosts various events and awards to recognize outstanding contributions in the legal community. Their intended clients include legal professionals, law firms, and individuals in need of legal assistance in the Louisville area.</i><br />Target victim <b>website</b>: <i>loubar.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ingersoll-Rand</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34733</link>
<guid>983e9d76e1db559f224d6ab1f0dfeb3c</guid>
<pubDate>Sat, 08 Aug 2026 12:24:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Ingersoll-Rand</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f2bdd02df123af4eee2b290ca62dae155e42d646c5413d4f8a9d016b18cadb1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Ingersoll Rand is an American industrial manufacturing company headquartered in Davidson, North Carolina. It designs and produces a wide range of industrial equipment including air compressors, power tools, fluid management systems, and HVAC solutions. The company serves diverse sectors such as manufacturing, construction, and energy. Formerly part of a larger conglomerate, it operates globally across multiple countries and markets.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Omnicell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34732</link>
<guid>dc65c7b3e6b2ea3a7c5aac41eeb8fbe0</guid>
<pubDate>Sat, 08 Aug 2026 12:23:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Omnicell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27eb1fb1411472cc370c3b3c8bde67fc09941e04c412e1509c888fe98beaa3b3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Omnicell is a United States-based healthcare technology company founded in 1992 and headquartered in Austin, Texas. It specializes in medication management solutions, providing automated pharmacy systems, dispensing cabinets, and software platforms to hospitals, pharmacies, and healthcare facilities. Its products aim to improve medication safety, reduce errors, and streamline pharmacy workflows across the healthcare industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Group-of-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34731</link>
<guid>d94e6cd8cf7e612bd8fd4096156eab2f</guid>
<pubDate>Sat, 08 Aug 2026 09:21:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>United-Group-of-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef4e800208a93be2a76e207d94867838127570ce3c48e7ab342ee347926e32ea</i><br /><br />Threat actor <b>description</b>: <i>Since 1972, The United Group of Companies, Inc. has specialized in all phases of real estate: development, financing, construction, and management. Their specialties include independent senior living, student apartment communities, multi-family (including affordable) housing, commercial properties, and mixed-use neighborhoods. The United Group of Companies is headquartered out of Troy, New York. 
The company headquarters is located in 300 Jordan Road, Troy, NY 12180, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>ugoc.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sawyer-Savings-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34730</link>
<guid>9b3e5c1c0754bc6a379163afabe2af79</guid>
<pubDate>Sat, 08 Aug 2026 09:20:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Sawyer-Savings-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2456e05aac2ef64e6f397d265566cb94baa4d90bbe913a060bbe92028a8917f</i><br /><br />Threat actor <b>description</b>: <i>Sawyer Savings Bank is a community-focused financial institution with over 150 years of experience, offering a range of personal and business banking services. Their products include personal checking, savings accounts, business loans, and digital banking solutions designed to enhance customer convenience and security. The bank is dedicated to supporting local communities through various initiatives, including scholarships and volunteerism. Their target clients include individuals seeking personal banking solutions and businesses looking for comprehensive banking support. 
The company headquarters is located in 87 Market Street, Saugerties, NY 12477, United States.11-50 Employees</i><br />Target victim <b>website</b>: <i>sawyersavings.bank</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Astro-Electroplating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34718</link>
<guid>0528dea9bbc7d49632849e66267cefd4</guid>
<pubDate>Fri, 07 Aug 2026 14:44:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Astro-Electroplating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c63cb3f768a6d6009803019abe42cadafd3006d919aa32b02b8d9176ac5910dd</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>John-C-Saunders-CPA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34721</link>
<guid>0289fc9e3bcd6db0d9a8dbfe050fa406</guid>
<pubDate>Fri, 07 Aug 2026 14:44:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>John-C-Saunders-CPA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37c1da537ae4705db94661374eda764209f1fd9b068f2938f0f9eafb0adf3e12</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pioneer-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34726</link>
<guid>fe21067b5bd2406e6a8f449af946d61b</guid>
<pubDate>Fri, 07 Aug 2026 13:53:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Pioneer-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75df7ccda257237a0bb526fb9915a786d0c37bafe29154ae0bfd341e0cf314fa</i><br /><br />Threat actor <b>description</b>: <i>Pioneer Bank is a leading financial institution in New York's Capital Region, recognized as one of the 'Best Places to Work' by the Albany Business Review. The bank is committed to providing a world-class working environment and continually evolves to meet customer needs by offering new products, services, and leading technologies. Through the Pioneer Bank Charitable Foundation, the bank supports nonprofit organizations that enhance the quality of life for children in the Capital Region. 
The company headquarters is located in 652 Albany Shaker Road, Albany, NY 12211, United States. 201-500 Employees</i><br />Target victim <b>website</b>: <i>pioneerny.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hartfiel-Automation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34725</link>
<guid>56acc3070ab7205fcdb09ec5c8071dac</guid>
<pubDate>Fri, 07 Aug 2026 13:42:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hartfiel-Automation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f0bd95aff118672fb15f4fcf9770ca1dc581f5bf9931fc96a7311a9fa391caf</i><br /><br />Threat actor <b>description</b>: <i>hartfiel.com zoominfo.com/c/hartfiel-automation-inc/27608695 Hartfiel Automation is an industrial automation company providing comprehensive manufacturing solutions like pneumatics, robotics, motion control, and hydraulics. For over 60 years, they have been a specialized high-tech provider supporting the American manufacturing sector. Headquartered in Minnesota, the company employs hundreds of professionals dedicated to engineering and optimizing production processes</i><br />Target victim <b>website</b>: <i>hartfiel.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CONTINENTAL.AERO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34717</link>
<guid>95595258ccedb3f8183500f93cd36f5a</guid>
<pubDate>Fri, 07 Aug 2026 12:51:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CONTINENTAL.AERO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af3cb3a3513494b810b8b892cb91ce5cf157a79c2e3821dc5564d920d0c43c13</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>CONTINENTAL.AERO</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>rosekennedygreenway.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34711</link>
<guid>3b5b763dc11cde2494f3089e199d4803</guid>
<pubDate>Fri, 07 Aug 2026 08:43:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>rosekennedygreenway.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>477801ad136ea267b5266cbdb6278fe7215ead6075354bf8eb73e6ae146792fc</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] The Rose Kennedy Greenway Conservancy is a nonprofit organization based in Boston, Massachusetts, USA. It manages and maintains the Rose Kennedy Greenway, a series of parks and open spaces built atop the underground Interstate 93 highway in downtown Boston. The conservancy oversees programming, public art installations, gardens, and community events along the corridor, operating within the nonprofit parks and urban green space management sector.</i><br />Target victim <b>website</b>: <i>rosekennedygreenway.org</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>nokotapackers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34697</link>
<guid>a2ff20730c919c3c30bcfa4aac8b4314</guid>
<pubDate>Fri, 07 Aug 2026 08:34:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>nokotapackers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d9160e00a1641702ec3920dc9b31a63071fdf12b38891bbbb966b8a5dc4ec9b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>nokotapackers.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>gslusa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34695</link>
<guid>5d4bacc197021d46db1445d67072835e</guid>
<pubDate>Fri, 07 Aug 2026 08:33:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>gslusa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>673f49ffb5c8d867ea642db44c93c75b46b6f3174ddfec8277fb6dabae578279</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>gslusa.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>coastproduce.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34693</link>
<guid>d3e185f50dcdc22eea2dc03829bb4c6d</guid>
<pubDate>Fri, 07 Aug 2026 08:32:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>coastproduce.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac71995f042fc6388f45bbe28d190a69d05655142e0bb1ca6cbe65a3b3fc723b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Coast Produce Company is a wholesale produce distributor based in the United States, primarily operating in California. The company supplies fresh fruits and vegetables to retailers, restaurants, foodservice operators, and other commercial buyers. It operates within the agricultural distribution and food supply industry, serving clients across the West Coast and broader domestic markets with a focus on quality and reliable cold chain logistics.</i><br />Target victim <b>website</b>: <i>coastproduce.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>zuckers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34692</link>
<guid>63d37ad90673f036d66e310f2b5cc768</guid>
<pubDate>Fri, 07 Aug 2026 08:31:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>zuckers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8482c131128c361ffd4ef332a528a4f5a4de9cae28e3e421c594ed61b45efb8c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>zuckers.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>doclv.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34690</link>
<guid>2d425507027fe5ccf5e23dc6bf98af4b</guid>
<pubDate>Fri, 07 Aug 2026 08:30:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>doclv.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0522d459379e903cbff9309f9c289fc7c7632d1f2becadb41ae8257f00c1cfee</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>doclv.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.upbrand.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34689</link>
<guid>387fc7868a72d0c8387a6ea1ac011eb7</guid>
<pubDate>Fri, 07 Aug 2026 08:29:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>www.upbrand.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e94f30426c4134db46aa3e597176262d613dac4ac76309d7036beecce4bc5380</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>www.upbrand.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>cookieskids.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34688</link>
<guid>0ce5eb1682917fc391e592aff20c35af</guid>
<pubDate>Fri, 07 Aug 2026 08:28:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>L Group</b> claims attack for <b>cookieskids.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adf6ad8df85e2cbe9cb236c9fc55a7e6e9db800dea82220f6ce4dd71eb3d36b3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Cookies Kids is a retail company based in the United States that specializes in children's clothing, footwear, and accessories. Operating primarily through its website and physical stores in New York, it offers affordable apparel for infants, toddlers, and teens. The company carries a wide range of brands and serves budget-conscious families. It has been a recognized name in children's retail for several decades.</i><br />Target victim <b>website</b>: <i>cookieskids.com</i>]]></description>
<category>L Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mdj-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34684</link>
<guid>2af6b176d618fcdcd130d32fcf2a14c0</guid>
<pubDate>Fri, 07 Aug 2026 08:08:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Mdj-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1798d3a06087f3ebe5f72c4841fd061e616bf44ee436bd729d01b4b0eddfc0b7</i><br /><br />Threat actor <b>description</b>: <i>appliedbizinvest.com zoominfo.com/c/mdj-management-llc/410565499 Applied Business Investments, Inc. (operating alongside MDJ Management LLC) is a private US-based management and finance consulting firm registered in Florida. Founded in the late 2000s, the company focuses on business investments, corporate management strategies, and financial advisory services. It operates as a boutique entity providing specialized support and investment structuring for various commercial projects</i><br />Target victim <b>website</b>: <i>appliedbizinvest.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hst</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34683</link>
<guid>694385500bdfc505ba0a4a8e3d81af19</guid>
<pubDate>Fri, 07 Aug 2026 08:08:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hst</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>945c23ba5ad9f7b2538f550d8c3f47a5758907ac5f501c9a4e40dae73db8660c</i><br /><br />Threat actor <b>description</b>: <i>hstechnology.com zoominfo.com/c/hst/352516154 digital platform for Healthcare Solutions Team (HST), a US-based healthcare cost-containment company now operating as Claritev. The company specializes in value-driven health plans, reference-based pricing solutions, and patient advocacy to reduce medical expenses. Through its HST Care Connect portal, it helps employers and individuals seamlessly find quality healthcare providers and optimize their medical benefits</i><br />Target victim <b>website</b>: <i>hstechnology.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hoang-Chiropractic-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34678</link>
<guid>7fb0e93718cc2bbf2ad75d2dfb497c77</guid>
<pubDate>Fri, 07 Aug 2026 08:06:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hoang-Chiropractic-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea6a0582fc15ddb4ea3ef19d553e317829f966b71c182705dc2978b60e6e69e4</i><br /><br />Threat actor <b>description</b>: <i>hoangchiro.com zoominfo.com/c/hoang-chiropractic-center/357138190 Hoang Chiropractic Center is a specialized healthcare clinic located in Metairie, Louisiana, led by Dr. Kim Hoang. The practice focuses on non-surgical pain relief and holistic wellness, offering services like AccuSpina spinal decompression, chiropractic adjustments, and custom orthotics. They are dedicated to helping patients relieve back pain and restore the body's natural ability to heal itself through personalized care</i><br />Target victim <b>website</b>: <i>hoangchiro.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Furniture-Outlet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34675</link>
<guid>24b486d95a59702839d3a4a2ce8c63cb</guid>
<pubDate>Fri, 07 Aug 2026 08:05:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>National-Furniture-Outlet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96c57e12194a4f9dc98eb8631c0c234aaf7d5a5a93c4bbe0b50ad8b9bd6baeed</i><br /><br />Threat actor <b>description</b>: <i>nationalfurnitureoutlet.com National Furniture Outlet is a family-owned retail store in Westwego, Louisiana, serving the Greater New Orleans area for over three decades. They specialize in selling affordable living room, bedroom, and dining room furniture, as well as mattresses and appliances at highly competitive, discounted prices. The business is well-known locally for its frequent overstock sales and flexible financing options to support the community</i><br />Target victim <b>website</b>: <i>nationalfurnitureoutlet.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phase-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34668</link>
<guid>e8609464e1813ad2494416cb12676159</guid>
<pubDate>Fri, 07 Aug 2026 08:03:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Phase-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b156deab36f243f4834c8adc050c2130dd11598109a10efa48e202bb359aa75</i><br /><br />Threat actor <b>description</b>: <i>phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase Technologies is a leading American manufacturer of advanced power electronics, specializing in digital phase converters, variable frequency drives (VFDs), and motor protection. Founded in 1999 and headquartered in Rapid City, South Dakota, the company engineers and assembles its products entirely in the USA. Their innovative solutions generate high-quality three-phase power from single-phase sources, maximizing energy efficiency and system reliability for industrial and agricultural applications</i><br />Target victim <b>website</b>: <i>phasetechnologies.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Halliday-Watkins-Mann</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34665</link>
<guid>c90425d6f7d882fb67038702d155e16b</guid>
<pubDate>Fri, 07 Aug 2026 08:02:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Halliday-Watkins-Mann</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0ef4b1cd4416cfead51fc09ebe4be73c0636abbe02ab1a826b39c46a5901e49</i><br /><br />Threat actor <b>description</b>: <i>hwmlawfirm.com zoominfo.com/c/halliday--watkins--mann-pc/42929145 Halliday, Watkins & Mann, P.C. (HWM) is a Salt Lake City-based law firm founded in 1935, now operating as a fourth-generation family practice. The firm exclusively serves the mortgage banking industry, specializing in creditor remedies such as foreclosures, bankruptcies, replevins, evictions, and REO closings. With a team of 51–200 employees, HWM provides full-service legal support and title curative work to financial institutions across multiple states</i><br />Target victim <b>website</b>: <i>hwmlawfirm.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>YY-Business-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34664</link>
<guid>1364de8a601e80b366df4c0a722b73b2</guid>
<pubDate>Fri, 07 Aug 2026 08:01:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>YY-Business-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d50d0f27605c24934650df58dbbcf1fa6dff4d2aa2e5341e943865e8ca35105f</i><br /><br />Threat actor <b>description</b>: <i>Y&Y Business Solutions (YYB Business Solutions Inc.) is a Bronx-based company located at 169 Lincoln Avenue, Suite 208, Bronx, NY 10454, reachable at (347) 270-1283. Founded and led by Valerie and Yerlin, the firm specializes in income taxes, immigration services, business license & registration, DMV & TLC services, and document translation. The company primarily serves Spanish-speaking immigrants and small business owners, helping them navigate U.S. immigration processes and tax requirements. They are most active on Instagram (@yybsolutions) and Facebook, where they share updates and client guidance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>NCA-Alarms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34663</link>
<guid>15d000a7bcd6e773b955d9dfbd2ac556</guid>
<pubDate>Fri, 07 Aug 2026 07:47:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>NCA-Alarms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2109e79ed0388e0bb6d644a55596ac16063a0ec6ab9443346746ab1fbab80203</i><br /><br />Threat actor <b>description</b>: <i>NCA Alarms specializes in home and commercial security systems, offering a range of products including security cameras and alarm systems. The company prioritizes customer service and transparency, providing no long-term contracts and clear pricing for their services. Their intended clients include both residential and commercial customers in Nashville, Tennessee, looking for reliable security solutions. NCA Alarms also offers remote access options and system conversion services to enhance existing security setups. 
The company headquarters is located in 3304 Charlotte Ave, Nashville, TN 37209, United States. 11-50 Employees</i><br />Target victim <b>website</b>: <i>nca-alarms.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nelson-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34662</link>
<guid>5a562b1ecd3433001cad71b66be9bb6d</guid>
<pubDate>Fri, 07 Aug 2026 07:47:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Nelson-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53a67343f767565fa2368fb988b5137c0ad6d49ff031c036df7ecafac28d8d60</i><br /><br />Threat actor <b>description</b>: <i>Nelson Manufacturing Company specializes in the design and production of innovative trailers and crane attachments tailored for various industries, including aerospace. Their product range includes custom-made crane attachments, hydraulic goosenecks, and specialty trailers, ensuring efficient transportation solutions for heavy equipment. The company serves clients in the aerospace sector, providing transport trailers that meet stringent quality requirements for aircraft and spacecraft components. Founded in 1947, Nelson Manufacturing is recognized as a leading manufacturer of multi-axle trailers in the United States. 
The company headquarters is located in 6448 State Route 224, Ottawa, OH 45875, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>nelsontrailers.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Indiana-Radiological-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34661</link>
<guid>01949fe85ea9c64f1a9ee2dee805ae50</guid>
<pubDate>Fri, 07 Aug 2026 07:46:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Southern-Indiana-Radiological-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7bc0ba9c4c537e462570d8139132509952ee776ec101e431c261760da08bfd0</i><br /><br />Threat actor <b>description</b>: <i>Southern Indiana Radiological Associates provides a comprehensive range of diagnostic imaging services including CT, MRI, PET scans, and various breast imaging procedures. Established in 1964, SIRA focuses on delivering high-quality medical imaging to diagnosis disease or injury while ensuring patient comfort and reassurance. Their target clients include individuals seeking imaging services in Bloomington and Southern Indiana, with a commitment to providing test results to healthcare providers within 48 hours. SIRA is recognized as a Breast Imaging Center of Excellence, emphasizing their dedication to women's health and advanced imaging technology. 
The company headquarters is located in 500 S Landmark Ave, Bloomington, IN 47403, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Liberty-Healthcare-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34660</link>
<guid>bc6bcd392b617578f9aca2c29cae7036</guid>
<pubDate>Fri, 07 Aug 2026 07:46:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>Liberty-Healthcare-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c8e93178f9ed3b5db09f0ab7d0641bc9fafa61009182acf8790f140265a8aa2</i><br /><br />Threat actor <b>description</b>: <i>Liberty Healthcare Corporation is a prominent health and human services management company that has been addressing complex healthcare challenges for over 30 years. They specialize in health workforce outsourcing, program management, and population health management, focusing on supporting specialized and vulnerable populations. Their innovative, person-centered solutions aim to improve quality and performance in healthcare organizations. With expertise in behavioral health, aging, and intellectual developmental disabilities, Liberty Healthcare is dedicated to transforming challenges into opportunities for success. 
The company headquarters is located in 401 East City Avenue, Suite 820, Bala Cynwyd, PA 19004, United States.</i><br />Target victim <b>website</b>: <i>libertyhealthcare.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>EvansPetree</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34659</link>
<guid>611ba5ef155b93d1cc990c1e3dfebe03</guid>
<pubDate>Fri, 07 Aug 2026 07:45:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>EvansPetree</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9da4c6989b8199212a933faa3300c8aa62c877a2e1bb747469088faaac6b9c0e</i><br /><br />Threat actor <b>description</b>: <i>Evans Petree has maintained a strong and effective dispute resolution/litigation practice for over 100 years. The company's dispute resolution/litigation attorneys are skilled at negotiation, mediation, arbitration and other dispute resolution mechanisms in hopes of resolving your disputes and issues quickly and economically. "Preventive maintenance" and early discussion about resolution can often lead to the success of your objectives. If litigation becomes unavoidable, Evans Petree can handle the most complex cases at all levels of the court systems, from administrative matters to federal and state court trials and appeals. The company's objective is to provide you with aggressive, value-conscious representation and work together to successfully advocate your position. 
The company headquarters is located in 1715 Aaron Brenner Drive, Suite 800, Memphis, TN 38120, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>evanspetree.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>OVP-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34658</link>
<guid>d572f68116e37b6e798fd9260c43efe3</guid>
<pubDate>Fri, 07 Aug 2026 07:45:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Storm</b> claims attack for <b>OVP-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2d43011d54d3a7d1c298df53d7bc49639d13214550bb45c00190277e89a785e</i><br /><br />Threat actor <b>description</b>: <i>OVP Health is a physician-owned company with over 20 years of experience in healthcare, specializing in emergency department and hospitalist staffing and management. The company offers a wide range of services including addiction treatment, behavioral health care, primary care, and telemedicine across West Virginia, Kentucky, Ohio, and Virginia. OVP Health is dedicated to addressing the needs of patients suffering from severe drug and alcohol addiction, providing both inpatient and outpatient care. Their facilities are CARF-accredited, ensuring high-quality treatment and support for individuals and families in crisis</i><br />Target victim <b>website</b>: <i>ovphealth.com</i>]]></description>
<category>Storm</category>
</item>
<item xmlns:dc='ns:1'>
<title>Venture-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34657</link>
<guid>64f9b199132a3f597af54f875ba0078d</guid>
<pubDate>Fri, 07 Aug 2026 07:21:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>Venture-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d4e1cb138c0f5c12b5c60e7733dd6942a0c7d6a4a7b0904b93c65e9d3aa2645</i><br /><br />Threat actor <b>description</b>: <i>SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>Uber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34656</link>
<guid>abcffd70f48bd3ddae7d048a0789eebf</guid>
<pubDate>Fri, 07 Aug 2026 07:21:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>Uber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10d65c9439246e0cd5e72d697d48f3f1ea9faea9d30771b4a787ca0bf1e34407</i><br /><br />Threat actor <b>description</b>: <i>SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.</i><br />Target victim <b>website</b>: <i>uberfreight.com</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>Highwoods-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34655</link>
<guid>89e7d05d94977c776e5200e7f24ba989</guid>
<pubDate>Fri, 07 Aug 2026 07:20:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Helix</b> claims attack for <b>Highwoods-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8da4e7dbdbc4bb1ca0fe4d061b1cd08cb034721dbbbce7594b30409544508df3</i><br /><br />Threat actor <b>description</b>: <i>SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.</i><br />Target victim <b>website</b>: <i>highwoods.com</i>]]></description>
<category>Helix</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crystal-Pharmatech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34646</link>
<guid>37fe435a1d7956df247dde078074254b</guid>
<pubDate>Fri, 07 Aug 2026 00:31:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Crystal-Pharmatech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c55cbbed94638eac00b45670545c36b227b6a41772c46f5ba0d060e521ddf640</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mayer-Brown</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34647</link>
<guid>dcbf540f6a9056d33884b1f54a610c1b</guid>
<pubDate>Fri, 07 Aug 2026 00:20:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Mayer-Brown</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81eff9ec2be6b172d90bd2c066aedeea9d6b216dddbcf1fc88bff5b11a31205c</i><br /><br />Threat actor <b>description</b>: <i>Mayer Brown is a distinctively global law firm, uniquely positioned to advise the world's leading comp…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Signature-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34645</link>
<guid>ec8989a0f0984e9fae61e7937ffada8c</guid>
<pubDate>Thu, 06 Aug 2026 19:56:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Signature-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d292cdc0ef03d66bcf43205a7e698bf0aeb82cb629f1dbe4e59b8bf0ffbf999e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.signatureservices.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>GCATS-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34644</link>
<guid>9424b0565195c27cdbeda8ab7a2f508e</guid>
<pubDate>Thu, 06 Aug 2026 19:56:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GCATS-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>425c50b69992edf62211e26837f1c0e9427f714f6bf6bde7cc58d6349961d75d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gcatstx.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Platinum-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34643</link>
<guid>fa9462ba01ad26f19535be3c4c462a5e</guid>
<pubDate>Thu, 06 Aug 2026 19:55:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Platinum-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>266d37abf8e98e25e6baebd4ab09cd6860e6449e2127a8300ee5b7296e166fa1</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.platinum-grp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.jerryleigh.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34641</link>
<guid>bc9e8957f418b0f2a0bb86f026534734</guid>
<pubDate>Thu, 06 Aug 2026 19:52:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.jerryleigh.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea9da5823eae5734b65f3228b6ba37e0592aeede1bce640d17bea261b580dbca</i><br /><br />Threat actor <b>description</b>: <i>Jerry Leigh is a family-owned women's, men's, and children's clothing manufactur...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.talbotdes.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34642</link>
<guid>e8c3ffce73ea28b5d4874789c5828145</guid>
<pubDate>Thu, 06 Aug 2026 19:52:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.talbotdes.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0967ad8aed05874b2f1a734f99df79acee887f565a46a9c5ed3a03603230fbf1</i><br /><br />Threat actor <b>description</b>: <i>Talbot County Department of Emergency Services provides essential emergency serv...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>King-International-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34640</link>
<guid>7e25dde4a60b2f3c7425e5df88815c30</guid>
<pubDate>Thu, 06 Aug 2026 16:51:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Gammax</b> claims attack for <b>King-International-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6234999a42debebc0fb00ac311ba5abaa083573fc1ea330fbf1f26a0ef79b818</i><br /><br />Threat actor <b>description</b>: <i>King International LLC (DL International) is a fresh-fruits-and-vegetables wholesaler/distributor that supplies produce for ongoing needs in retail an...</i><br />Target victim <b>website</b>: <i>www.kingsinternational.us</i>]]></description>
<category>Gammax</category>
</item>
<item xmlns:dc='ns:1'>
<title>AmSpec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34639</link>
<guid>765070fb45e2b95f4352c9172c2e2edb</guid>
<pubDate>Thu, 06 Aug 2026 15:27:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AmSpec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a9fcc69752dfbaae880f07b4f911d9781e2642b59efaf3120c4b88f63b8c419</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.amspecgroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jakle--Alexander</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34637</link>
<guid>69393e0aa40214df0daa7329ceec46d7</guid>
<pubDate>Thu, 06 Aug 2026 15:26:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jakle--Alexander</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0be664983ee2782e8b12247737c536d93ff6c9eb1c4f2166193da50d4f8e29c0</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.jaklelaw.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Park-Place-Behavioral-Health-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34636</link>
<guid>5108f29ef876e5ad51474f192925bb0b</guid>
<pubDate>Thu, 06 Aug 2026 14:54:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Park-Place-Behavioral-Health-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7946b90d44e0f6ec2b4737b6fb8e159fd9ce3d7401684018a8d6b886707f0b9</i><br /><br />Threat actor <b>description</b>: <i>PPBHC provides mental health and substance use services in Osceola County, Florida, with 40+ years’ experience. They offer crisis intervention, therapy, recovery-oriented care, telehealth, and partner with GENOA for medication access.</i><br />Target victim <b>website</b>: <i>www.ppbh.org</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Beacon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34632</link>
<guid>a544abb197a74a4fce50a04e5537c39f</guid>
<pubDate>Thu, 06 Aug 2026 13:26:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>City-of-Beacon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3aa992cffa08bef5e2b0aee01cf98d65c43b63ea5f8aa74baa6bc67c945bfda</i><br /><br />Threat actor <b>description</b>: <i>The City of Beacon is committed to protecting online users' privacy. If you send the company an electronic mail message with a question or comment that contains personally identifying information, or fill out a form that e-mails the company this information, the company will only use the personally identifiable information to respond to your request and analyze trends. The company may redirect your message to another government agency or person who is in a better position to answer your question. The company's server logs automatically collect electronically generated information about your visit to the company's site, such as the date, type of browser used, and technical Internet protocol data. The company may collect this information about each user session and refer to it in summary form for statistical purposes. The company do not use 'persistent' cookies to collect permanent information.</i><br />Target victim <b>website</b>: <i>www.beaconny.gov</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Basic-Grain-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34629</link>
<guid>2fead7741ca97f623c68f07fb4bc3809</guid>
<pubDate>Thu, 06 Aug 2026 12:21:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Basic-Grain-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba374126e1235a7fb2ed945805a587176ecdf97688b926947232ad089e7629cd</i><br /><br />Threat actor <b>description</b>: <i>TasteMorr is a culinary platform that offers a variety of gourmet food products and cooking ser
vices. The company aims to cater to food enthusiasts and home cooks looking for high-quality in
gredients and unique recipes.

We will upload 104gb corporate data soon. Employee personal information (passports and SSNs, w9
forms and so on), detailed financials, contracts and agreements, NDA, clients information and 
so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Baptist-Church-of-Belleview</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34627</link>
<guid>f2d7f80cad08f03745aa10c8b375c9e0</guid>
<pubDate>Thu, 06 Aug 2026 11:20:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>First-Baptist-Church-of-Belleview</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4aa02ccff50793ed23cfee5db4d9d2de9f398140dea2e8dd66952f450db255fd</i><br /><br />Threat actor <b>description</b>: <i>First Baptist Church Belleview is dedicated to fostering devoted followers of Jesus Christ through worship and community engagement. They offer Sunday services at 10:45 a.m. and provide opportunities for learning and connection through various ministries and events.</i><br />Target victim <b>website</b>: <i>www.fbcbelleview.org</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-McMinnville-OR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34626</link>
<guid>8f1fbc45b8d10f3bc00d82ad450c8a6c</guid>
<pubDate>Thu, 06 Aug 2026 10:58:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>City-of-McMinnville-OR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc94f2dc38e92d927d6d2937854a015cebdfa71046d015841f31d4c82b558db7</i><br /><br />Threat actor <b>description</b>: <i>The City of McMinnville provides a range of municipal services including public works, parks and recreation, and community development. It aims to serve the residents and businesses of McMinnville, Oregon, by facilitating community events, maintaining public facilities, and ensuring public safety. The city also engages in urban renewal and economic development initiatives to enhance the quality of life for its citizens. Additionally, it offers resources for job applications, permits, and community involvement opportunities.</i><br />Target victim <b>website</b>: <i>www.mcminnvilleoregon.gov</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hilliards-Air-Conditioning--Heating-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34625</link>
<guid>f965ce468b3afc578525cd9758975cc2</guid>
<pubDate>Thu, 06 Aug 2026 10:51:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Hilliards-Air-Conditioning--Heating-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17587203f30cff0415b4f8515bf408637c2bbdf8b1a3f7e011e4b87d2dce24ac</i><br /><br />Threat actor <b>description</b>: <i>Since 1988 customers have trusted Hilliard's Air Conditioning & Heating, Inc. as their air conditioning and heating specialist. As a family run business, Hilliard's takes great pride in serving Central Florida and is state licensed and insured.</i><br />Target victim <b>website</b>: <i>www.hilliardsairandheat.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hopes-Windows</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34623</link>
<guid>c76daa000da32fc0e450bc0527a165b1</guid>
<pubDate>Thu, 06 Aug 2026 10:23:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cry0</b> claims attack for <b>Hopes-Windows</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>035e567bc19a5172b9bfa55f619c15afde5cc3450e3fe16005df373111ba3d22</i><br /><br />Threat actor <b>description</b>: <i>Coming soon....</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cry0</category>
</item>
<item xmlns:dc='ns:1'>
<title>Primary-Eye-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34621</link>
<guid>7cc273e8acc02886b2c4c65da1a74663</guid>
<pubDate>Thu, 06 Aug 2026 09:55:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Primary-Eye-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac483faf8e7ee80a6d1df48d1e8956dcee0f45bed2225df2a7f7be5369ff4440</i><br /><br />Threat actor <b>description</b>: <i>We offer a full range of options to meet your eyecare needs. From advanced custom LASIK laser vision correction and cataract surgery to glasses, contact lens fittings and routine eye tests, we can provide the treatment that is right for you.</i><br />Target victim <b>website</b>: <i>primaryeyecareneworleans.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Theresa-Catholic-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34620</link>
<guid>994252186323cee9c2a1f1b607ec4a91</guid>
<pubDate>Thu, 06 Aug 2026 09:52:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>St-Theresa-Catholic-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12eca427ddb78b5dd19a34d5f98069cc78c2d2af4d1e215c8f56a8a4f0bf9f6c</i><br /><br />Threat actor <b>description</b>: <i>Today we have broadened our network and capability to provide services by partnering with other individuals, groups and churches through the Belleview Area Social Services (BASS) Network. BASS works to bring a coordinated approach to providing services to those in need.</i><br />Target victim <b>website</b>: <i>mystcc.org</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stoneybrook-West-Master-Association-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34619</link>
<guid>cb1a4be230da30b1a88d3d0904815fb0</guid>
<pubDate>Thu, 06 Aug 2026 09:51:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Stoneybrook-West-Master-Association-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ce14beddbeddd6a7d56c065f2e90a6a641b1242c093352f445b6f2e518db5a7</i><br /><br />Threat actor <b>description</b>: <i>At Stoneybrook West, we plan regularly scheduled group physical fitness and after school classes, personal fitness training, swimming classes, tennis instruction, and music lessons are just to name a few.</i><br />Target victim <b>website</b>: <i>stoneybrookwest.sites.townsq.io/0</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stonecrest-POA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34618</link>
<guid>b2c6dec66eada0847015737371ffa928</guid>
<pubDate>Thu, 06 Aug 2026 09:50:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Stonecrest-POA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8990afa999ec627d57cdaf39cdc8357bf0b7d9ba981ba1e4f2e5ea32b7ed142</i><br /><br />Threat actor <b>description</b>: <i>Stonecrest POA is the mandatory property owners association for Stonecrest, a large gated 55+ residential community in Summerfield, Marion County, Florida. It is a nonprofit community-governance organization, not a conventional profit-making company.</i><br />Target victim <b>website</b>: <i>stonecrestpoa.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Magnolia-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34617</link>
<guid>b801445d202a77bcc2cc688e2c07c3d1</guid>
<pubDate>Thu, 06 Aug 2026 09:22:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Magnolia-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25590b8e778e91414a686b345b7c784d76b74ba742d344901655dae79cb1b481</i><br /><br />Threat actor <b>description</b>: <i>Our practice is dedicated to providing exceptional dental services to Summerfield, FL, and the surrounding areas. As a patient-centered practice, we treat you like family, prioritizing your comfort and well-being above all else.</i><br />Target victim <b>website</b>: <i>www.magnoliadentalclinic.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Country-Oaks-Veterinary-Clinic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34616</link>
<guid>c0277973332b3692beae52448f71f787</guid>
<pubDate>Thu, 06 Aug 2026 09:22:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Country-Oaks-Veterinary-Clinic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69a60842041b15baf100a4c2d7498b5e87fcb13b7861ce9fd638b8b2f06f9549</i><br /><br />Threat actor <b>description</b>: <i>Country Oaks Veterinary Clinic is a full-service hospital established in 1976. We provide high-quality veterinary care in a modern, welcoming environment. Our experienced doctors and staff treat your pets like family.</i><br />Target victim <b>website</b>: <i>vetstopets.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>David-King-Architect</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34615</link>
<guid>90c0f9bdcc0baee52fc7928a6548af9b</guid>
<pubDate>Thu, 06 Aug 2026 09:21:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>David-King-Architect</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c00e542d3d5aa41bad8225ec29267767f9af72c540bdb7e50c8aba939aff3df7</i><br /><br />Threat actor <b>description</b>: <i>We are an Architectural Firm and Design and prepare plans for almost any low rise structure. We have designed Assisted Living Facilities, Offices, Warehouses, manufacturiing facilities and Car dealerships.</i><br />Target victim <b>website</b>: <i>www.mapquest.com/us/florida/david-king-architect-427495503</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodside-Ranch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34614</link>
<guid>b5b236b0397d625da2a23cacae4114fc</guid>
<pubDate>Thu, 06 Aug 2026 09:20:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Woodside-Ranch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bc430aaa6a9e599d2a822c22a7443844f5a915191997ba35810312656132c44</i><br /><br />Threat actor <b>description</b>: <i>Bryan and Holley Beattie Rice own and operate Woodside Ranch, a family run Thoroughbred Training Center in Ocala, Florida. Our motto is hard work and attention to detail. We are committed to giving young prospects the best possible start. We take great pride in our relentless effort to advance our methods and our facilities.</i><br />Target victim <b>website</b>: <i>www.ricewoodside.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ferrell--Skyline-Implants--Periodontics--Dr.-Scott-Ferguson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34613</link>
<guid>8f2525ca728c98defbd9adc55c7ef3fc</guid>
<pubDate>Thu, 06 Aug 2026 09:03:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Barracuda</b> claims attack for <b>Ferrell--Skyline-Implants--Periodontics--Dr.-Scott-Ferguson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>064daaccdc5ed0924cee3739babaf703a354e7760c61f956965fffda53834a52</i><br /><br />Threat actor <b>description</b>: <i>Full personal and servers files dumps from Skyline Implants & Periodontics company. The data files contain: medical documents of patients (including MRI scans of various parts of the body — files with the .dcm extension), personal photos, and the personal data of the doctor, Scott Ferguson, as well as documents from the company Skyline Implants & Periodontics — in particular, information on equipment and pharmaceutical procurement and other related materials. | Status: free | Size: 800 GB | Now free</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Barracuda</category>
</item>
<item xmlns:dc='ns:1'>
<title>Micro-Comm-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34611</link>
<guid>77264695a901fc9441dd2ee7b7b51b8d</guid>
<pubDate>Thu, 06 Aug 2026 08:32:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Barracuda</b> claims attack for <b>Micro-Comm-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e55f6a716c29613ae8b856a69005720094a0cb8bffbed8a20017d4a081e5262</i><br /><br />Threat actor <b>description</b>: <i>Micro-Comm, Inc. is an industrial automation company based in Olathe, Kansas, that provides water and wastewater control systems, manufacturing control panels, micro-controllers, and SCADA software. [http://www.micro-comm-inc.com]. Tree of all files: https://www.filemail.com/d/vpqdvykqwssupsw. Files count: 894 963, documents type: maps, schemes, personal employers information, personal citizens information, work photos, emails, partners personal information | Status: selling | Size: 643 GB | Starting at $30000.00</i><br />Target victim <b>website</b>: <i>micro-comm.com</i>]]></description>
<category>Barracuda</category>
</item>
<item xmlns:dc='ns:1'>
<title>clubonecasino.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34608</link>
<guid>42544f171b32ad2c2897a5498963a3d9</guid>
<pubDate>Thu, 06 Aug 2026 08:22:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>clubonecasino.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05efddc4b3447ca1161fd8863fb77f8942cb07b6e1605e5e54e8bcd32ec8cff0</i><br /><br />Threat actor <b>description</b>: <i>Club One Casino is the premier poker room in Central California, featuring 51 table games, a 24-hour restaurant, and extensive non-gaming entertainment options such as sporting events and e-Sports. Catering to both seasoned players and newcomers,</i><br />Target victim <b>website</b>: <i>clubonecasino.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>vprj.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34607</link>
<guid>6ec6bb3422418bd6a33bbfe1df28450f</guid>
<pubDate>Wed, 05 Aug 2026 23:53:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>vprj.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f9165694fd393b639408e07dc052f88fe508d09f6dd0660d67c7ddd4a0fb4df</i><br /><br />Threat actor <b>description</b>: <i>The Virginia Peninsula Regional Jail (VPRJ) is a state-authorized, regional correctional facility located in Williamsburg, Virginia, USA. Opened in 1997, VPRJ provides short-to-medium-term detention services, ensuring public safety and order across the Virginia Peninsula region under the governance of a multi-jurisdictional jail board.</i><br />Target victim <b>website</b>: <i>vprj.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pavillon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34589</link>
<guid>9df6283891d965d6c7ffc0f8084b98e1</guid>
<pubDate>Wed, 05 Aug 2026 18:21:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Pavillon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8958b6b08e2d66974acea20ff1fe26bc236d3a30319fff8f0d712c95db929d8</i><br /><br />Threat actor <b>description</b>: <i>Country: Mill Spring, North Carolina, United States |
Website: pavillon.org |
Revenue: $8.5 Million |
Industry: Alcoholism Treatment, Hospitals & Clinics, Healthcare |
Employees: 100-200 |
Properties: 646 GB (47,950 Files, 7,750 Folders)</i><br />Target victim <b>website</b>: <i>pavillon.org</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>P.-A.-Inc.-Performance-Alloys</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34588</link>
<guid>13c8eb07b2dc376126e669fbc4a57f73</guid>
<pubDate>Wed, 05 Aug 2026 17:53:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>P.-A.-Inc.-Performance-Alloys</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b432698c046093695ca696c23aa05ef70b36513af4a1b2349ef3fae57b557177</i><br /><br />Threat actor <b>description</b>: <i>P.A. Inc. is a leading distributor of high nickel alloy and specialty stainless steel piping products, based in Houston, Texas. The company offers a comprehensive inventory of materials including Nickel 200, Alloy 400, Alloy 600, and various titanium grades, catering to industries requiring high-temperature and corrosion-resistant solutions. Their services include custom fabrication and a qualitative specification assurance process to ensure product quality. P.A. Inc. serves clients in sectors such as specialty chemicals, oil and gas, and petrochemicals, providing efficient and effective procurement solutions.</i><br />Target victim <b>website</b>: <i>painc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mike-Graham-Heating-And-Air-Conditioning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34587</link>
<guid>30c79ab1cb1bb865fe03120da341ee09</guid>
<pubDate>Wed, 05 Aug 2026 17:52:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Mike-Graham-Heating-And-Air-Conditioning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4fb1aa6be516ea35a20a196fd2c17ae8e3dfdb15ec06952c86a01517b48b2bb6</i><br /><br />Threat actor <b>description</b>: <i>Mike Graham Heating, Air Conditioning & Plumbing is a trusted HVAC and plumbing service provider based in Wichita Falls, Texas, serving the local community since 1994. The company offers a wide range of services including air conditioning, heating, indoor air quality solutions, and comprehensive plumbing services. Their target clients include homeowners and businesses in Wichita County and surrounding areas, seeking reliable and professional home service assistance. With a commitment to customer satisfaction, they provide upfront estimates, emergency services, and tailored solutions to meet individual needs.</i><br />Target victim <b>website</b>: <i>mgpcomfort.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>tomorrowsoffice.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34585</link>
<guid>7e4bb8c8f3bdcbece5996f24ba507120</guid>
<pubDate>Wed, 05 Aug 2026 16:23:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>tomorrowsoffice.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84b3fb0a5af8d21fe6d9f7f065e7b79e97088b9c822df3036d0f49001ec6e6b1</i><br /><br />Threat actor <b>description</b>: <i>URGENT DATA LEAK NOTICE: TOMORROW'S OFFICE

Target: Tomorrow’s Office (tomorrowsoffice.com)

Status: Ongoing Data Publication Countdown

Security researchers have successfully exfiltrated 125 GB of critical and confidential data from the internal infrastructure of Tomorrow’s Office (tomorrowsoff…</i><br />Target victim <b>website</b>: <i>tomorrowsoffice.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Long-Lewis-Automotive-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34584</link>
<guid>760a5ceedca28c03525c58cbdb59b5d5</guid>
<pubDate>Wed, 05 Aug 2026 16:21:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Long-Lewis-Automotive-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3372e414eb3d57f074e318748d870a90048e19924cff8c6e030f0f521c9ed16b</i><br /><br />Threat actor <b>description</b>: <i>About Long-Lewis Automotive Group The Long-Lewis Auto Group is Alabama’s largest automotive retailer, with origins tracing back to a hardware store founded in Bessemer, Alabama, in 1887. It became one of the nation's very first Ford dealerships in 1915 and operates multiple dealerships across the state. Following a successful cyberattack on Long Lewis, more than 500 GB of confidential information was stolen. More than 15,000 records containing personal data of the organization’s customers and employees, important financial and banking documents, and other valuable company information were compromised. Currently, Long Lewis lost control of more than 650,000 files.</i><br />Target victim <b>website</b>: <i>www.longlewis.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henshaw-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34541</link>
<guid>192beb199bc41714bc563f5a0cc7e9a5</guid>
<pubDate>Wed, 05 Aug 2026 14:50:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Triple X</b> claims attack for <b>Henshaw-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f444b281957cba945b2b33eb3c0c7020cf5464c54b77dcafa988aafa460b9032</i><br /><br />Threat actor <b>description</b>: <i>1 terabytes of people's data https://henshawlawak.com/
Henshaw Law,
Despite repeated recommendations, no action was taken. The problem remains unresolved, the system is full of bugs, people's documents are at risk, and they won't take any responsibility.
Multiple people could commit suicide, what important information has been leaked about them, and who is responsible for why the recommendations weren't taken seriously.
what data will leak ?
-Personal family files
-Passports and licenses
-Court ruling and public complaint forms
-Documents scans
-Forms and emails scans
sample :
Full download data link :
Download</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Triple X</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Metropolitan-Entertainment--Convention-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34536</link>
<guid>f9bb88cb2d9202153dcf693faf0b0eea</guid>
<pubDate>Wed, 05 Aug 2026 13:15:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>The-Metropolitan-Entertainment--Convention-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f9fc3344d9c57d8488d570b357fdb137440b558130bb68a6c521aefb741ce49</i><br /><br />Threat actor <b>description</b>: <i>About MECA Omaha MECA is a organization that manages public event venues in Omaha, Nebraska, including the CHI Health Center, Charles Schwab Field, and The RiverFront. Established in 2000, it plays a crucial role in hosting world-class events and fostering community engagement through its facilities. As a result of a successful cyberattack on the company, MECA suffered damage; more than 500 GB of confidential information was stolen, specifically the company’s customer data, important financial documents, and the personal data of the organization’s employees. About 100 000 files are not secured by domain for now. Download here: http://667k2ck7qlzoqt52i6dq7evcfzko2ezfrhgv6zziccjet2cc653kvbid.onion/</i><br />Target victim <b>website</b>: <i>omahameca.org</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Formulatrix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34535</link>
<guid>a3730c053af5cc03c79a0ec559f404c5</guid>
<pubDate>Wed, 05 Aug 2026 13:15:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Formulatrix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22cb06c106980a7f507d6a18a009cdcfa164067ae0aed88fdbf1ce242b8370e9</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Formulatrix is a US-based company headquartered in Bedford, Massachusetts, that designs and manufactures laboratory automation instruments primarily for the life sciences industry. The company specializes in liquid handling robotics, imaging systems, and automation solutions used in drug discovery, protein crystallography, and genomics research. Its products are widely adopted by pharmaceutical companies, biotechnology firms, and academic research institutions worldwide.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Laurel-Institutes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34534</link>
<guid>52746115ed4579e191e8a82c2c6682b5</guid>
<pubDate>Wed, 05 Aug 2026 13:14:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Laurel-Institutes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8d367a4b3ea6a424b55be935a3013f11cd3998cb346824b037a3405ce7720a5</i><br /><br />Threat actor <b>description</b>: <i>About Laurel Institutes Laurel Institutes offers focused education and professional certifications across various fields, including business, healthcare, trades, cosmetology, and culinary arts. The institution emphasizes hands-on training and small class sizes to foster student engagement and skill development. Their programs are designed to prepare students for successful careers in industries they are passionate about. With multiple campuses and online options, Laurel Institutes aims to connect students with local employers and provide resources for career advancement. A "Laurel Institutes" company suffered a cyberattack that led to the theft of approximately 50+ GB of sensitive data. Exposed files include financial confidential papers, bank records and medical personal information. Personal data of more than 1,000 students and staff members was leaked Download here: http://tjaaioz32salcoj63ttxra6nfqggwbcezkzpwnhyoiwq5tuimzmsb3qd.onion</i><br />Target victim <b>website</b>: <i>www.laurel.edu</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oasis-Legal-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34533</link>
<guid>bc3e6127ca2263a0a9375a2efab8dae4</guid>
<pubDate>Wed, 05 Aug 2026 13:14:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Oasis-Legal-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fcb083c583d761c1e211c2f6a6d0ce5cb870b1b317a9c1ddb287b924cc60fda2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conway-Analytics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34532</link>
<guid>652d0eea3ab8a9afd8719cc584253a4c</guid>
<pubDate>Wed, 05 Aug 2026 13:14:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Conway-Analytics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>954e7edef4df9e66cad512766cb0932ba2ad0458c272e36d295d694b8625c1df</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ohio-Living-Home-Health--Hospice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34531</link>
<guid>62f0ccd9ecceb9655f5cc3c805fa8ec7</guid>
<pubDate>Wed, 05 Aug 2026 13:14:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Ohio-Living-Home-Health--Hospice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>424ac56485d925051c673587b7b7cb1417c7061e515ae94214bc4543e99f793c</i><br /><br />Threat actor <b>description</b>: <i>About Ohio Living Founded in 1922, Ohio Living is an experienced not-for-profit provider of life plan communities and services in Ohio. Due to cyberattack at least 600Gb of sensitive data leaked in "Ohio Living Home Health & Hospice" in April 2026. It known that at least 5000 files with personal data were stolen, among whole it contained employee records, driver licenses, patient personal documents including photos, medical records, social security numbers, insurance information, also files with confidential company financial information and bank records covering period for 2022-2026. Download here: http://3i5px2hibsyityv6jixnqba35yz25jekbwwumjdxjqzt3euqsygjx5id.onion/</i><br />Target victim <b>website</b>: <i>ohioliving.org</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Labpharma</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34529</link>
<guid>2027b3d8d3a2a87ef879af0feaad8100</guid>
<pubDate>Wed, 05 Aug 2026 13:13:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Labpharma</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>317b66a32c3afe19cb3a03a1d8f9010b999e11d58700f22e72141fe886108226</i><br /><br />Threat actor <b>description</b>: <i>Labpharmacorp Labpharma is a Clinical Laboratory in Miami dedicated to delivering dependable, high-quality laboratory services for clinical trials and research. About Labpharma Labpharma is a laboratory data company supporting clinical research trials. Company offers Local and Central Laboratory testing and data management. Standard Services: Laboratory Manual (electronic and hardcopy), kit production, door to door shipping (IATA certified), research trained and certified (CGP certified), while testing menu includes the following disciplines: Hematology, Clinical Chemistry, Immunochemistry, Infectious Disease, Hemostasis, and Toxicology. From end to end all samples are barcode, tracked and managed to ensure reliable laboratory services for research studies. Download here: http://t2ru74fbgut26xnagtrl4ajeh5vqytrl6cpr6cubmr6sqdxk5guh5mqd.onion/</i><br />Target victim <b>website</b>: <i>labpharmacorp.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thermo-King</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34527</link>
<guid>498a4339f96d1949476f4b857c3729c2</guid>
<pubDate>Wed, 05 Aug 2026 13:12:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Thermo-King</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09dcf4992082e781f5450aa6352ba87f6f13ae7033fdcccfdbac6b816bb81617</i><br /><br />Threat actor <b>description</b>: <i>Due to cyberattack on Genesis more than 70 Gb of company data was stolen. Leakage contains big amount of sensitive data such as company's customers data, bank and financial information documents. About 10 000 files are not secured by THERMO KING for now. Download here: http://wjcml4mxpcvsmjxm33zhjb46nzutxk6g3f5w23fopgpwj6pqjcidiyqd.onion</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Storer-Transportation-and-Storer-Coachways</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34526</link>
<guid>42f67ee6edf8958816e38b124609c38f</guid>
<pubDate>Wed, 05 Aug 2026 13:11:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Storer-Transportation-and-Storer-Coachways</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3cc425db7836da17b6cb3a05bffeb17476f93aca06d50ac20ea07f200f4b499a</i><br /><br />Threat actor <b>description</b>: <i>The company "Storer Transportation" and "Storer Coachways" was attacked, resulting in the theft of more than 50,000 folders (240+ GB) of the company’s confidential information, including more than 1,500 pieces of employee personal data, financial and banking documents, credit card information and a large amount of confidential incident data. Download here: http://pokttabd2hod47ladeeoin22wmq4remyo3wshwvxfuhgqygcbezq2qqd.onion</i><br />Target victim <b>website</b>: <i>www.storerbus.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Genesis-Engineering-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34524</link>
<guid>378271842c95b7894122b598f9874a14</guid>
<pubDate>Wed, 05 Aug 2026 13:10:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Genesis-Engineering-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e0d4083d963fe4db383f54f0b5408b03a3772fd1356dcf8484602b49b6c69e2</i><br /><br />Threat actor <b>description</b>: <i>Due to cyberattack on Genesis more than 75Gb of company personal data was stolen. Leakage contains big amount of sensitive data such as personal emlpoyes documents, company's customers data, bank and financial information documents. About 50 000 files are not secured by Genesis for now. Download here: http://x2jz63qemhcbhyskzt3pie757oicdkctk2rh5dpykmxsw2yoayeqs5yd.onion/</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dharma-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34523</link>
<guid>3de5c311d2344047c6c7b879d3ca8d60</guid>
<pubDate>Wed, 05 Aug 2026 13:10:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Dharma-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>425a4c3b4e4ebb27c431b6e73b565e144d64b61d969468520ebe8e52aeb1c244</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

The name "Dharma Group" is not associated with a uniquely identifiable, well-documented company in reliable threat intelligence or business databases. Multiple unrelated entities may use this name, and without additional context, providing an accurate factual description risks confusion or misinformation.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mayco-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34522</link>
<guid>3157af1a70015446ab7a3e92d4ae7582</guid>
<pubDate>Wed, 05 Aug 2026 13:10:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Mayco-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7757f5e7fc88f39cf1fefc8fcc579ac3b636fa4590b3679edc5a92a8deedcda2</i><br /><br />Threat actor <b>description</b>: <i>About Mayco International At least 2Tb of sensitive data were exfiltrated from the company’s control following a cyberattack. The compromised dataset leaked from Mayco internatioins company infrastructure includes internal organizational documents, proprietary technical schemas, employee personally identifiable information, and a substantial volume of financial records.</i><br />Target victim <b>website</b>: <i>www.maycointernational.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sutherland-Packaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34521</link>
<guid>d499871897037516f52fb1042946e4a9</guid>
<pubDate>Wed, 05 Aug 2026 13:09:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Sutherland-Packaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65f524a3a9b34f6312518ee6a8de49c20154b1932684b74fbfa94ec71a7d357f</i><br /><br />Threat actor <b>description</b>: <i>About SPI Sutherland Packaging LLC is a leading manufacturer specializing in creative digitally printed full-color point-of-purchase displays for brands worldwide. The company offers a range of services including digital printing, retail packaging, and turnkey fulfillment, focusing on delivering custom-blended solutions that meet client demands. With over 50 years of experience, Sutherland Packaging is trusted by global brands for its high-quality and cost-effective solutions. Due to cyberattack on Sutherland Packaging more than "200" Gb of company data was stolen. Leakage contains big amount of sensitive data such as company's customers data, bank and financial information documents. About 250 000 files are not secured by Sutherland Packaging for now.</i><br />Target victim <b>website</b>: <i>www.sutherlandpackaging.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leviton</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34518</link>
<guid>f5b49df0ec42774c1c13ef6f93d7865c</guid>
<pubDate>Wed, 05 Aug 2026 13:08:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Leviton</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f35b06fdbdfc486b55c79172df05f1d7c2bab345da4fdc4d41292bdc65a34c0f</i><br /><br />Threat actor <b>description</b>: <i>About Leviton Founded in 1906 and headquartered in Melville, New York, Leviton is a privately held global provider of electrical wiring devices, data center connectivity solutions, and lighting energy management systems. A major cyber attack has resulted in the Leviton company losing control over its entire repository of sensitive data, totaling approximately 1.4 terabytes. The massive breach exposed a wide range of highly confidential information, including internal financial records, proprietary project schematics and working documents, as well as the personal data of employees. Additionally, a significant quantity of other unclassified but highly sensitive information was exfiltrated in the breach, painting a stark picture of a total system compromise.</i><br />Target victim <b>website</b>: <i>www.leviton.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aptara</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34517</link>
<guid>7714989f1eab891378be494cd68c96e0</guid>
<pubDate>Wed, 05 Aug 2026 13:08:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Aptara</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4817c3f756f3bf7a7ab89a5559d5aba263d53936a39a7d6fd5bf0d8258f6a417</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Aptara is a US-based digital content transformation company specializing in publishing, learning, and content solutions. Operating primarily in the publishing and e-learning industries, it provides services such as content conversion, instructional design, digital publishing, and XML/DITA authoring. Founded in 1988 and headquartered in Falls Church, Virginia, Aptara serves clients in education, government, and corporate sectors globally, helping organizations transition traditional content into digital formats.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Family-Medicine-Clinic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34516</link>
<guid>92cdc3666b7883ebeed2973e70725bb1</guid>
<pubDate>Wed, 05 Aug 2026 13:07:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>The-Family-Medicine-Clinic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd24cc2996a1c3f431267e331eb0d95ce0f1056835b74e8ef9b94a23a2665a51</i><br /><br />Threat actor <b>description</b>: <i>About FMC The Family Medicine Clinic (Louisiana) suffered a serious cyberattack, which resulted in the encryption of a vast data archive and left the company without access to its own online systems. The leak of more then 250Gb FMC medical data encompasses a wide range of document types, including patient registration forms, lab test results, treatment plans, prescription records, and personal insurance information. In addition, employee personnel files were leaked, along with the full names, home addresses, and Social Security numbers of hundreds of customers. Download here: http://x4emye5homuwkrvrfaoql53hc5spbazkvcw3m4pv6jaj5tjqmjizleqd.onion</i><br />Target victim <b>website</b>: <i>www.facebook.com/familymedicineclinicnewiberia</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rocky-Mount-Recyclers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34514</link>
<guid>442465f5282183631234848d916ce365</guid>
<pubDate>Wed, 05 Aug 2026 13:06:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Rocky-Mount-Recyclers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cdcc96d47e55a70db56ffbeb03f8b05974fc26bffd767e9768a18b7170139c5c</i><br /><br />Threat actor <b>description</b>: <i>Due to cyberattack on Rocky Mount Recyclers more than 40Gb of company personal data was stolen. Leakage contains big amount of sensitive data such as personal emlpoyes documents, company's customers data, bank and financial information documents. About 12,000 files are not secured by RMR for now. Download here: http://2zl5qc3mqap7vziqfis65oyjcgdiedigoequxbqsn6uwian7ieozvoqd.onion/</i><br />Target victim <b>website</b>: <i>www.rmrnc.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mansfield-Family-Dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34513</link>
<guid>012632d2b06f515409d7accd2fe1d6cb</guid>
<pubDate>Wed, 05 Aug 2026 13:06:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Mansfield-Family-Dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1056e7577018a0081202fe6db87330722d1f3f00e371a8e1ed94475da5eba9c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Mansfield Family Dentistry is a dental practice operating in the United States, likely located in Mansfield, Ohio or a similarly named city. The practice provides general and family dentistry services, including routine cleanings, examinations, fillings, and preventive care for patients of all ages. It operates within the healthcare and dental services industry, serving local community members in a private practice setting.</i><br />Target victim <b>website</b>: <i>mansfielddentistry.com</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Miller-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34512</link>
<guid>de1e7f6da2c60b9bb6768ba10c8ebc28</guid>
<pubDate>Wed, 05 Aug 2026 13:06:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>The-Miller-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bda489d80d325558f71ac285258a205420eac7a6087fa365f3bd110fc16e608c</i><br /><br />Threat actor <b>description</b>: <i>About The Miller Group The Miller Group refers to The Miller Group - Multiplex Division, a retail display manufacturer with operations spanning Dupo, Illinois and Richmond, Virginia As a result of the cyberattack, the company lost control of 500 GB of confidential data, including: employees’ Social Security numbers, email addresses, home addresses, and ZIP codes—plain Excel spreadsheets; financial documents in PDF format—budgets, transactions, and internal reports; complete project drawings—working diagrams and perspective sketches.</i><br />Target victim <b>website</b>: <i>www.miller-group.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>TSC-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34510</link>
<guid>a9bd402e9971cc6f171e5694a2e6c941</guid>
<pubDate>Wed, 05 Aug 2026 13:05:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>TSC-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>285f748e26ccede6797d9624741ced03889f14e2ec261188195c40f73d9c9fad</i><br /><br />Threat actor <b>description</b>: <i>About TSC Logistics TSC Logistics specializes in providing advanced transportation solutions that prioritize speed and cost-effectiveness for their clients. A cyberattack has resulted in the exfiltration of nearly 600 gigabytes of highly sensitive data, exposing a vast trove of internal records. The compromised material includes personal employee documents, confidential company financial records, invoices, taxpayer statements, and extensive client information. More than 10,000 PDF files have been leaked, containing unredacted Social Security numbers, driver’s licenses, payroll records, and other protected identifiers, raising the spectre of widespread identity theft and regulatory scrutiny.</i><br />Target victim <b>website</b>: <i>www.tsclogistics.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keysight</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34509</link>
<guid>5f4f25d269af35abf542f09062624683</guid>
<pubDate>Wed, 05 Aug 2026 13:05:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Keysight</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a52a55852f4c0cb1e1753b661ecf7f3261d9b7f54fe831d028519e81e5bfdd9</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Keysight Technologies is an American electronic test and measurement company headquartered in Santa Rosa, California. It designs and manufactures instruments, software, and services used to design, emulate, and test electronic equipment. Its solutions support industries including aerospace, defense, communications, semiconductors, and automotive. Formerly part of Agilent Technologies, Keysight became an independent public company in 2014.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reid-Electric-Service-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34508</link>
<guid>b41c4f7033be375e42caaf30b64a46a3</guid>
<pubDate>Wed, 05 Aug 2026 13:05:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Reid-Electric-Service-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f84846ccbfdd2c3c997b1b1730408664c42a101938d4bfaf0b2a0cd2709a92b6</i><br /><br />Threat actor <b>description</b>: <i>About Reid Electric Service, Inc At Reid Electric Service, Inc. we realize the safety, and reliability of your electrical system is important to you. We take pride in exceeding your expectations to perform work on your electrical system on time, safely and on budget. Reid Electric Service, Inc has suffered a cyberattack on its service systems, resulting in the theft of approximately 50 GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings.</i><br />Target victim <b>website</b>: <i>reidelectricservice.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mile-Bluff-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34507</link>
<guid>55ad99b84c3aaccd084b169df2893207</guid>
<pubDate>Wed, 05 Aug 2026 13:04:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Dark Project</b> claims attack for <b>Mile-Bluff-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f28a89dca77b081517caa5f52633be5f585dd3f4343988bc8aaec4b7c750a520</i><br /><br />Threat actor <b>description</b>: <i>About Mile Bluff Medical Center Located in Mauston, Wisconsin, Mile Bluff Medical center has been in operation since 1912. Its services include acute emergency care, as well as long term nursing and rehabilitation A "Mile Bluff Medical Center" company suffered a cyberattack leading to the theft of over 550 GB of sensitive data. Exposed files include a full SQL database backup, employee records, confidential company financial information, bank records, patients' personal documents, Social Security numbers, medical records, medical histories, and surgical records. As a result, the personal data of more than 25,000 patients and staff members was leaked. Download here: http://7iphetz64a7iihcpwr3nirjioghyt6lrku62gu4z7f3zo7rcz5qrgvad.onion/</i><br />Target victim <b>website</b>: <i>www.milebluff.com</i>]]></description>
<category>Dark Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>FixIT-Tek</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34504</link>
<guid>ad2aea3bbd1050e84e2a0f0b9fdeea1d</guid>
<pubDate>Wed, 05 Aug 2026 07:21:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>FixIT-Tek</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0f936ea89d34ddcfcccd7435e66ec1b81b33636d1e656f065957486678db9b7</i><br /><br />Threat actor <b>description</b>: <i>Providing the best possible IT services to businesses of all sizes in Central Florida and Surrounding Areas.   ##### FixIT Tek's Syncro MSP panel has been hacked and stolen big data of many clients from their network. #####</i><br />Target victim <b>website</b>: <i>fixittek.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>lantisnet.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34503</link>
<guid>c073bb4e8333b2af406951b0e96ad3eb</guid>
<pubDate>Wed, 05 Aug 2026 00:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>lantisnet.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>820ced53df0b4f6f4264287a9c26916120e4bb54deeaa45eea34a44f6778e518</i><br /><br />Threat actor <b>description</b>: <i>Lantis Enterprises, Inc. is an American consulting and management organization historically rooted in rural healthcare, skilled nursing, and senior living operations. Headquartered in Spearfish, South Dakota, the firm has expanded its focus to cross-industry advisory services</i><br />Target victim <b>website</b>: <i>lantisnet.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Galvin-Brothers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34500</link>
<guid>696e8c935c8ce98badc28242fad73dfb</guid>
<pubDate>Tue, 04 Aug 2026 18:01:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Galvin-Brothers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c69a484054665bf823812c569b6c5416ba9dc683fe1130cf35dcb4fc3bbf47eb</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.galvinbrothers.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRULITE-GLASS--ALUMINUM-SOLUTIONS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34497</link>
<guid>d77de86dc8bd445f5227875182805a61</guid>
<pubDate>Tue, 04 Aug 2026 17:57:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>TRULITE-GLASS--ALUMINUM-SOLUTIONS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be675410fa9ca29d706f1ca6d65af47c2a0b1967d6ae80ebbdc55986735af6ef</i><br /><br />Threat actor <b>description</b>: <i>TRULITE GLASS & ALUMINUM SOLUTIONS Date: August 2026 Overview Trulite Glass & Aluminum Solutions, a portfolio company of Truelink Capital (Los Angeles, CA), is a leading North American fabricator and distributor of architectural glass and aluminum systems. Headquartered in Alpharetta, Georgia, the company operates 40+ fabrication and distribution facilities across the United States and Canada, serving the commercial construction industry. Trulite was founded in 1978 and has undergone significant expansion through acquisitions — including Vitro America, Western States Glass, AGC Fabrication, Super Sky Products, American Insulated Glass, and others. In October 2022, Truelink Capital acquired Trulite from Sun Capital Partners. The company generates estimated annual revenue of $800M–$1.2B and employs 2,000–3,500 people. Incident We have obtained full and unrestricted access to Trulite's internal infrastructure. The total volume of exfiltrated data exceeds 8 terabytes. Data in Our Possession The dataset includes but is not limited to: - Complete corporate databases — ERP system (Microsoft Dynamics AX), CRM, operational databases - Financial records — multi-year Profit & Loss statements by branch, EBITDA schedules, debt covenant compliance calculations, 13-week cash flow forecasts, weekly and monthly financial reporting packages prepared for private equity ownership - M&A documentation — Confidential Information Memorandums (CIM), executed Stock Purchase Agreements, acquisition pipeline documents, due diligence materials, corporate structure charts with ownership percentages - Private equity communications — internal correspondence and reporting between Trulite management and fund ownership (Sun Capital Partners, Truelink Capital) - Board of Directors materials — governance records, board presentations, strategic planning documents - HR and employee data — personnel records, payroll, benefits information - Customer and vendor data — contracts, pricing agreements, project documentation, accounts receivable/payable - IT infrastructure documentation — network architecture, system configurations, credentials - Operational data — production records, logistics, fleet management, facility documentation across all 40+ locations Proof of Access Sample data will be published to confirm the scope and authenticity of the breach. Full data publication will follow if no resolution is reached. Contact The Trulite management team has been contacted directly and provided with instructions to initiate private negotiations. A deadline has been communicated. This is the only public statement at this time. Further updates — including data samples — will follow according to the established timeline.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Tek</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34496</link>
<guid>9293eb98abb2abe316a3598a83c70514</guid>
<pubDate>Tue, 04 Aug 2026 16:26:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>First-Tek</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d85f7e52aafe0975de5fb95954c38d928b9934310335702d19e3546b1751c581</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.first-tek.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Preferred-Financial-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34495</link>
<guid>8fad6d7e58542a344408f83a0a73e11b</guid>
<pubDate>Tue, 04 Aug 2026 16:25:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Preferred-Financial-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3f75895e22cd882d4050754ff1bb9a981783dfb523b5a0ccdc471f096573285</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.preferredfinancial.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>TopMark-Funding</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34494</link>
<guid>43542e3a42df9043e6a500e1c2564fc6</guid>
<pubDate>Tue, 04 Aug 2026 16:03:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>TopMark-Funding</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73e09c743bee2b950cb9773e0ee777a6df878ff27a783d16d764895a1a13c1b4</i><br /><br />Threat actor <b>description</b>: <i>topmarkfunding.com zoominfo.com/c/topmark-funding-llc/368696312 TopMark Funding is a nationwide commercial financing company specializing in fast funding solutions for semi-trucks, trailers, and heavy construction equipment. Headquartered in California, they help trucking and construction businesses acquire machinery ranging from $25,000 to $500,000. The company is recognized for providing quick approvals, flexible terms, and risk-free quotes without impacting the client's credit score</i><br />Target victim <b>website</b>: <i>topmarkfunding.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Control-Concepts-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34493</link>
<guid>1c6ae2e3522e87b5f0eba1e226dc5029</guid>
<pubDate>Tue, 04 Aug 2026 16:03:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Control-Concepts-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1bc7acf6fa7a54e822b78b46c32065466d153edf75db825403190930785ae3e8</i><br /><br />Threat actor <b>description</b>: <i>controlconceptstexas.com zoominfo.com/c/control-concepts--technology/356919279 Control Concepts is a Texas-based industrial automation and electronics repair company established in 1984. They specialize in servicing, repairing, and installing AC/DC motor drives, PLCs, and industrial motor controls. Operating as a certified UL508a Panel Shop, the company also provides 24-hour emergency service, system upgrades, and custom automation solutions</i><br />Target victim <b>website</b>: <i>controlconceptstexas.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>healthcarehighways.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34492</link>
<guid>dcf05231c492569270f19d3f1780e475</guid>
<pubDate>Tue, 04 Aug 2026 15:57:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>healthcarehighways.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f2ffc727e7f44f06262635aab5e1588c1412d4b52503014831af7236d29641f</i><br /><br />Threat actor <b>description</b>: <i>WARNING / DATA LEAK NOTICE

    Target: Healthcare Highways (healthcarehighways.com)
    Countdown: 24 Hours

    If corporate representatives do not establish contact via chat within the next 24 hours, a massive internal data cache comprising 235 GB of sensitive company and client records will be p…</i><br />Target victim <b>website</b>: <i>healthcarehighways.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeastern-Communications--Electrical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34489</link>
<guid>939aba147bd1077514a5d2022505783f</guid>
<pubDate>Tue, 04 Aug 2026 15:54:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Northeastern-Communications--Electrical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>213d9bfb321ab4ad544b55fc34d1894ff3ebced6b41fd9c99a8deca70e82b0b1</i><br /><br />Threat actor <b>description</b>: <i>Northeastern Communications & Electrical LLC, based in Middletown, Connecticut, specializes in the installation of voice, data, and video systems for various building types, including small, medium, and large-scale projects. The company prides itself on delivering high-quality and professional services, backed by years of technical expertise.</i><br />Target victim <b>website</b>: <i>www.northeastcne.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Texas-Medical-Screening</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34486</link>
<guid>1d10712905e2faf91de6700424d443f6</guid>
<pubDate>Tue, 04 Aug 2026 15:53:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Texas-Medical-Screening</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad9661c2a6d01ed4ed450194cae08b128302f762514e40cc1b9700c2c089a89a</i><br /><br />Threat actor <b>description</b>: <i>Texas Medical has helped organizations deliver health screenings without the overhead. Our self-service kiosks are trusted in workplaces, pharmacies, and community spaces across the country.</i><br />Target victim <b>website</b>: <i>www.texasmedical.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sc-Regional-Housing-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34485</link>
<guid>e86fdb256522aa912cbff6c9ee251fa4</guid>
<pubDate>Tue, 04 Aug 2026 15:52:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Sc-Regional-Housing-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebf200659ad7e424ea06495458a9d08b88f97d6e01810a25b5b4cfefae6c74e0</i><br /><br />Threat actor <b>description</b>: <i>SCRHA3 provides affordable housing solutions across South Carolina, focusing on public housing, homeownership, and rental assistance programs. With over 15 years of experience, they offer subsidized housing assistance to qualified families and help low-income families access the private rental market through the Section 8 program.</i><br />Target victim <b>website</b>: <i>www.scrha.net</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bjs-Insurance--Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34484</link>
<guid>e0ecf7947469da3dc03f0977ffbbf417</guid>
<pubDate>Tue, 04 Aug 2026 15:51:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Bjs-Insurance--Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9bb2acf33d6c6975542f98adda666e79cb2612293cfb239178785ee52662ec2</i><br /><br />Threat actor <b>description</b>: <i>BJS Insurance Services, Inc. was established upon two underlying principles that continue to define the company today.... Integrity and Stability. We're all about Service, we just do what we say we're going to do. We listen to our clients and suggest what plans fit your needs and budget.</i><br />Target victim <b>website</b>: <i>www.bjsinsurance.net</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wisdom-Oral-Surgery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34483</link>
<guid>6188d67c7355d4166b6d12db43485400</guid>
<pubDate>Tue, 04 Aug 2026 15:51:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Wisdom-Oral-Surgery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8dfbf4579ff6c2c35fdc93bc02c4fe394f3a6e9d6719f3b931267307d20145e6</i><br /><br />Threat actor <b>description</b>: <i>Wisdom Oral Surgery, located in Fair Lawn, NJ, specializes in a wide range of oral surgery services including dental implants, wisdom teeth extractions, bone grafting, and facial trauma care. The clinic is dedicated to providing exceptional patient comfort and care, utilizing advanced technology for accurate diagnoses and treatments.</i><br />Target victim <b>website</b>: <i>www.wisdom-oralsurgery.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>WD-Masonry--Concrete</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34473</link>
<guid>064e87109460140e9fb07541986229f3</guid>
<pubDate>Tue, 04 Aug 2026 15:32:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WD-Masonry--Concrete</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9a6b888ed57548f0cd11f24a9d51415622ef533056fb4db2af76a5117c39105</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SBI-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34479</link>
<guid>ab3c3351517e17a8b2561ee2227dae11</guid>
<pubDate>Tue, 04 Aug 2026 12:28:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>SBI-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e4ecb373097ca36a86e49085f00ce0f5a5a08a6633eb2c940a898eda4702102</i><br /><br />Threat actor <b>description</b>: <i>SBI Manufacturing is a family-owned company based in Sioux Falls, SD, specializing in metal fabrication and machine welding. They provide services primarily to the agricultural, industrial, and transportation sectors.</i><br />Target victim <b>website</b>: <i>sbimfg.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Agricultural-Chemical-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34478</link>
<guid>312ec7f8d4615d6dd78477a4f581c612</guid>
<pubDate>Tue, 04 Aug 2026 12:27:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Agricultural-Chemical-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f6901fef95b6de858a97acb7d8e578c2427d45c77c49ce8533dc256d3bd73d4</i><br /><br />Threat actor <b>description</b>: <i>Agricultural Chemical Solutions, Inc. provides high-quality agricultural chemicals and a comprehensive marketplace aimed at enhancing farming operations. They offer a wide range of products including pesticides, herbicides, fungicides, and micro nutrients, with competitive pricing and expert recommendations.</i><br />Target victim <b>website</b>: <i>agchemicalsolutions.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cardiology-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34475</link>
<guid>d52e1bd0f9d78d2709b4bc78c7e0f5a2</guid>
<pubDate>Tue, 04 Aug 2026 12:24:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Cardiology-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d89de07c4839c4cebe720e74e73a0b6cca3c5753e88f049e635c8e8f94ba623f</i><br /><br />Threat actor <b>description</b>: <i>Serving the community for over 45 years, Cardiology Associates of Port Huron, P.C. offers the latest in cardiac procedures and technology, helping our qualified physicians to detect and provide comprehensive treatment for a wide variety of adult heart and artery conditions.</i><br />Target victim <b>website</b>: <i>porthuronheartcenter.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yost-Home-Improvements</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34474</link>
<guid>fd04ecf4077388816a37d6ac193c3152</guid>
<pubDate>Tue, 04 Aug 2026 12:23:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Yost-Home-Improvements</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd6418947b3a935ceb499c2aae2075fb1b30e3f9a6966c35da2e5bead26417bc</i><br /><br />Threat actor <b>description</b>: <i>Yost Home Improvements is a family-owned exterior remodeling and construction company based in Waterford, Connecticut, serving the southeastern CT region for over 50 years. They specialize in installing vinyl siding, windows, doors, gutters, roofing, and sunrooms.</i><br />Target victim <b>website</b>: <i>yosthomeimprovements.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Site-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34468</link>
<guid>846b2b6dd5703bd41a6cd0e1601900f8</guid>
<pubDate>Tue, 04 Aug 2026 12:21:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Integrated-Site-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0940df83978866cfb438c22088c0c9074fa8ae5b0705e22dad0635bcbf40a2ab</i><br /><br />Threat actor <b>description</b>: <i>Integrated Site Management is a full service site consulting company with our foundation reinforced by developing partnerships with clients, vendors & suppliers. Partnerships built from professionalism, honesty, integrity, respect, and open communication. Integrated Site Management listens, researches, identifies, and then provides solutions for our clients needs.</i><br />Target victim <b>website</b>: <i>www.ism-sc.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conceptual-Designs-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34467</link>
<guid>79b76a2914b0e5d228c7ad1ab7e700c2</guid>
<pubDate>Tue, 04 Aug 2026 12:20:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Conceptual-Designs-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80673f5a76b9f172dfb57065f9b4d7a3a01a7621823bbd9fa76d25363b5dabec</i><br /><br />Threat actor <b>description</b>: <i>Conceptual Designs, Inc. proudly provides interior design services for businesses across the Quad Cities from our studio in Bettendorf, Iowa. No matter what kind of business you own, we can help make your space match your company’s culture and values in a creative way. With over 35 years of experience, our team of designers can help bring your vision to life.</i><br />Target victim <b>website</b>: <i>www.conceptualdesignsinc.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Friction-Products-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34465</link>
<guid>d6d5125f2d5e36115d2fe90d1a4d4225</guid>
<pubDate>Tue, 04 Aug 2026 12:19:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Orova</b> claims attack for <b>Global-Friction-Products-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76d1153f1b809bc77a05863d310c53ab8f7e495ca8607adc31bdc7c366cb77ed</i><br /><br />Threat actor <b>description</b>: <i>GLOBAL FRICTION PRODUCTS, INC is a company that manufactures, repairs, and /or re-arcs brake and clutch bands back to original drum for even wear on friction material.  We specialize in the construction, mining, marine and offshore industries, i.e., cranes, draglines, clamshells, barges, dredges, ships, tugs, winches and more.</i><br />Target victim <b>website</b>: <i>globalfrictionproducts.com</i>]]></description>
<category>Orova</category>
</item>
<item xmlns:dc='ns:1'>
<title>US-Installation-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34463</link>
<guid>1989d2d0108af415ac8a9a3b13090a95</guid>
<pubDate>Tue, 04 Aug 2026 05:51:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>US-Installation-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c204edc04436ad1ce354b23eb6a046ca6410e2be70127671abbd0fae7553016e</i><br /><br />Threat actor <b>description</b>: <i>Founded by Bruce DeLuca in Boca Raton, Florida, USIG operates through 15+ legal entities under MRS Holdings, performing over 100,000 installations annually across 33 markets in 14 states.</i><br />Target victim <b>website</b>: <i>US Installation Group, Inc.</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>clintonhealthaccess.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34459</link>
<guid>216db3e862df3fb6d8b3efa5b09a8a59</guid>
<pubDate>Tue, 04 Aug 2026 02:24:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>clintonhealthaccess.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80eb0f34ff17c6ef4eb08e88344a002c403b8c9e2a54dfa2080536e2ea084db9</i><br /><br />Threat actor <b>description</b>: <i>This Clinton foundation sponsors the sterilization of women in Africa and South America. With the help of this foundation, organs harvested criminally by transplant surgeons from people in Third World countries are legalized to improve the quality of life of the rich in capitalist countries, including the United States. We have irrefutable evidence of their secret accounts, including transactions in cryptocurrency, from which transplanted organs were purchased to replace Bill Clinton's wife, Hillary Clinton.</i><br />Target victim <b>website</b>: <i>clintonhealthaccess.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>pradotuylaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34456</link>
<guid>e53a38d5db38103ca6c1a7511ba64fd9</guid>
<pubDate>Mon, 03 Aug 2026 18:29:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>pradotuylaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6cb1aade3540b6bc3263bfe1d793f4578f15f025208d9432a52dd942455b8253</i><br /><br />Threat actor <b>description</b>: <i>The firm focuses on practice areas including personal injury, wrongful death, workplace harassment, business litigation, civil settlements, and environmental litigation. …</i><br />Target victim <b>website</b>: <i>pradotuylaw.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>naskdoorinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34455</link>
<guid>fe6a68822b44d9bcaa8c858f62f06f34</guid>
<pubDate>Mon, 03 Aug 2026 18:28:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>naskdoorinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d89cccfe0445904dea29a12a02b43dba442b1572a6a6d6de1b922eb836de603</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in West Chester, Pennsylvania, the company has served customers throughout southeastern Pennsylvania and northern Delaware for several decades. Although …</i><br />Target victim <b>website</b>: <i>naskdoorinc.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cameron-Regional-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34450</link>
<guid>23ba3338bd270b4ac1d714eeb8dcdb66</guid>
<pubDate>Mon, 03 Aug 2026 18:21:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Cameron-Regional-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af988c60b117b9dce1fed59661f3b5000e7d533959b3948323f929d37f5039a6</i><br /><br />Threat actor <b>description</b>: <i>Patient and employee data breach at a healthcare provider.</i><br />Target victim <b>website</b>: <i>cameronregional.org</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>southshorerecycling.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34448</link>
<guid>047973d4ae66ca988048b8eb53788ead</guid>
<pubDate>Mon, 03 Aug 2026 17:58:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>southshorerecycling.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2fbe269114f0498d0ead59587c0c620bb920cbdaf0767c7b19d23062a85526e</i><br /><br />Threat actor <b>description</b>: <i>The company specializes in metal recycling, concrete and asphalt recycling, aggregate production, and construction waste processing for commercial, industrial, and …</i><br />Target victim <b>website</b>: <i>southshorerecycling.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>multiaqua.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34446</link>
<guid>f2904d6b4000d5402b14177a4f8704f3</guid>
<pubDate>Mon, 03 Aug 2026 17:57:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>multiaqua.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4da537c591951f173d86e2f9e823644cd1000564ca187b9a299e4e256a7e659f</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1999, the company specializes in the design, engineering, and production of air-cooled water chillers, heat pump chillers, hydronic …</i><br />Target victim <b>website</b>: <i>multiaqua.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Winn-Dixie</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34445</link>
<guid>8b49217b4e704d2c40e5908ebd53eda5</guid>
<pubDate>Mon, 03 Aug 2026 17:52:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Winn-Dixie</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc30ae3d72c5cc2b5953ff63270d0e2a21763a0b4b01fedcf6ae596684d6be2e</i><br /><br />Threat actor <b>description</b>: <i>Inside a multibillion-dollar retail giant.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>BLACKBURNS-Physicians-Pharmacy-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34444</link>
<guid>db5c56b36f6575e4cd690ccefd938884</guid>
<pubDate>Mon, 03 Aug 2026 17:51:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>BLACKBURNS-Physicians-Pharmacy-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d69a02ffd8ddd0f290a26872a411698452a6ab7d502a6a5b920ec61fed52a9f4</i><br /><br />Threat actor <b>description</b>: <i>Major home healthcare provider data breach.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Service-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34442</link>
<guid>22ac437b43b81f0422091bd2e88624e3</guid>
<pubDate>Mon, 03 Aug 2026 13:25:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Service-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34b30ad1d661511d08d7ac5dce5f5c5c342bb7d65c38e9c1be5ffe2e647eb30f</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.secv.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Albers-Mechanical-Contractors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34441</link>
<guid>b5d9495c042fdc8ca455806700d6eff0</guid>
<pubDate>Mon, 03 Aug 2026 12:50:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Albers-Mechanical-Contractors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>899eee490966ecf76f0c2e9ec1ce8662aa6957b71ad7b084c767dc2a7b1b0bcb</i><br /><br />Threat actor <b>description</b>: <i>Albers Mechanical Contractors specializes in custom fabrication, welding, stainless steel fabri
cation, and dust collection HVAC solutions. With over 54 years of experience, they provide desi
gn and on-site consultations, positioning themselves as leaders in facility solutions.

We will upload 30gb corporate data soon. Employee information, financials, contracts and agreem
ents, NDA, customers information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Belasco-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34440</link>
<guid>cad5a325c48a0e53242ee2079a4bbca2</guid>
<pubDate>Mon, 03 Aug 2026 12:21:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Belasco-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca74699d30c777d704abc031ce2577adf7ef90105e4eea601fd359418b3a96f8</i><br /><br />Threat actor <b>description</b>: <i>Belasco Electric is a reliable electrical service provider based in Muskegon, Michigan, caterin
g to both residential and commercial clients. They offer a wide range of services including eme
rgency generator systems, fire alarm security systems, HVAC wiring, and EV installation.

We will upload 16gb corporate data soon. Employee information (name, home addresses, passport, 
SSN, DL numbers, photos, credit card scans and so on), financials, contracts and agreements, ND
A, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Freedom-Claims-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34436</link>
<guid>ccd986d2de4c75133c049e26005b3dbc</guid>
<pubDate>Mon, 03 Aug 2026 03:56:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Freedom-Claims-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23900e0ff259757bb474acf775e44dfcf66704464bd267a9790951c9270df7ec</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.freedomclaimsinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>microphase.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34432</link>
<guid>e353b610e9ce20f963b4cca5da565605</guid>
<pubDate>Sun, 02 Aug 2026 23:27:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>microphase.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e68c4f228e371d8fddefa0ffb486223c29c89579cc1c5ea6c1707a89f4f95c2d</i><br /><br />Threat actor <b>description</b>: <i>Microphase Corporation is an innovative and trusted customer-driven supplier of advanced electronic...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>ecfa.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34434</link>
<guid>5bd7f2feff1f11170a507fcd0c0e9734</guid>
<pubDate>Sun, 02 Aug 2026 21:28:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>ecfa.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ea870fe3fe8e24b9ca389cd2bc6907765d857988836887eb0cb554c28816421</i><br /><br />Threat actor <b>description</b>: <i>The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in collective revenue.</i><br />Target victim <b>website</b>: <i>ecfa.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moses--Singer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34422</link>
<guid>b4cf1000ee57d756b58dc7c8a5936c26</guid>
<pubDate>Sun, 02 Aug 2026 13:50:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Moses--Singer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cae325ec8def64d3f67f59453d83d95e746e99efba3a6119ca2d8aafe047369c</i><br /><br />Threat actor <b>description</b>: <i>Moses & Singer LLP is a full-service law firm specializing in corporate transactions, intellectual pro…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wire-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34417</link>
<guid>c27cb025c4befa0319116806faebb82e</guid>
<pubDate>Sun, 02 Aug 2026 12:30:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wire-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>548254582c1de947ff0960356362c5828175e0956ec9d77c3e39beee870b1607</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.wireproducts.us</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Encore-Enterprises-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34416</link>
<guid>c5af15be85875ccc7fdd2d6e415347c4</guid>
<pubDate>Sun, 02 Aug 2026 03:50:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Encore-Enterprises-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77c0012696e32ab8ed50976dcd2ebca0fa1e6186aaa03788bb41bf285a7bc804</i><br /><br />Threat actor <b>description</b>: <i>Sector: Commercial Real Estate | Data leaked: 700.0 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Butcher-Brothers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34414</link>
<guid>895a699ee499c9e2141d030d61c32ad1</guid>
<pubDate>Sat, 01 Aug 2026 19:04:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Butcher-Brothers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10d4b8586519e69f216acd7964bb7bacd451b08ef9140bb52c8e7548b1774f35</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.thebutcherbrotherscorp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sigma-Plastics-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34413</link>
<guid>fcff94e3a5fc07b69e42a97584a5b761</guid>
<pubDate>Sat, 01 Aug 2026 19:04:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sigma-Plastics-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7681eb8258edd682777e3613b4667061f501b35822cdac3ed065f2f46c87110c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sigmaplasticsgroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cambridge-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34412</link>
<guid>5bdce57749b0e471923d707d7a47385a</guid>
<pubDate>Sat, 01 Aug 2026 19:03:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cambridge-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b562a328898de0c2eb3862d790b6ab5a5fd3f237629e36df1039099c6ac05d05</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cambridgemgmt.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>quantinuum.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34411</link>
<guid>55a706dbc200a848d7147319ef0476f9</guid>
<pubDate>Sat, 01 Aug 2026 16:29:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>quantinuum.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16f9c50e547de8dcbcf114acea6ec2a20ac6ebc5f7c9facb14189f5909bc8df2</i><br /><br />Threat actor <b>description</b>: <i>Quantinuum is a quantum computing company that develops advanced quantum computers, software, and cybersecurity solutions to solve complex scientific and industrial challenges. The company provides full-stack quantum technologies for areas such as materials science, drug discovery, encryption, artificial intelligence, and optimization, helping enterprises and researchers accelerate innovation through quantum computing.   The leak dates back to pre-IPO.   QUANTINUUM deliberately withheld this information from investors.  The exact amount of stolen data will be revealed after publishing.</i><br />Target victim <b>website</b>: <i>quantinuum.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vernon--Waldrep</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34410</link>
<guid>11eed2e8a05bbbb4508ffa229a7b84c0</guid>
<pubDate>Sat, 01 Aug 2026 15:53:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Vernon--Waldrep</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f1baa6346fecef5a1b28d5b77bc80a2e7dd81814c6cf39cc5e3fe5ea64e2de7</i><br /><br />Threat actor <b>description</b>: <i>Country: Texas, United States |
Website: vernonwaldrep.com |
Revenue: $5 Million |
Industry: Physicians, Mental Health Specialists |
Employees: 21–50 |
Properties: 274 GB (56,006 Files, 3,421 Folders)</i><br />Target victim <b>website</b>: <i>vernonwaldrep.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Saturday-Evening-Post</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34409</link>
<guid>721d2344f7d2bfbe7a90c257f8d961df</guid>
<pubDate>Sat, 01 Aug 2026 13:54:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Saturday-Evening-Post</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d026acc002ad26f2cb5e4e8ba5008351d7be4057bf331cc250a3a12b5c57b2ec</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.saturdayeveningpost.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Commercial-Furniture-Interiors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34408</link>
<guid>8f8f63800cdf54a776ba9c14b2059ec0</guid>
<pubDate>Sat, 01 Aug 2026 13:53:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Commercial-Furniture-Interiors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5015d8636283961c551fc85d67f4450b8e1baa69d5feb8823f758db991acdfcd</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cfioffice.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pointe-Property-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34405</link>
<guid>7f65773388773297001c0c7394d8a75f</guid>
<pubDate>Sat, 01 Aug 2026 13:50:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pointe-Property-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26057e431022d3a4e003865b92ab8ee7ccbba58b54e1b378f9e5ddd132a65a90</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.pointecre.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MIM-Fertility</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34401</link>
<guid>821b56bbd7c4ce329a0b7664561b30e7</guid>
<pubDate>Sat, 01 Aug 2026 05:29:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>MIM-Fertility</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31927b04935273d93ca602c82273787830df40792b08587c2d4cde05ea60d43f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] MIM Fertility is a US-based fertility clinic network specializing in reproductive medicine and assisted reproductive technologies. The company provides services such as in vitro fertilization, egg freezing, preimplantation genetic testing, and fertility preservation. Operating within the healthcare and reproductive medicine industry, MIM Fertility focuses on personalized patient care and works with fertility specialists to help individuals and couples achieve pregnancy.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>M.-B.-Kahn-Construction-Co.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34400</link>
<guid>667ea75a7895da024f6298f05f3b658d</guid>
<pubDate>Sat, 01 Aug 2026 05:29:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>M.-B.-Kahn-Construction-Co.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07dd62b3249decc06e01911d34c4a935848b07047f34c6dff588f933ce413f1e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] M. B. Kahn Construction Co. is a general contracting and construction management firm based in the United States, headquartered in Columbia, South Carolina. Founded in 1926, the company operates primarily across the southeastern United States. It serves sectors including commercial, industrial, healthcare, education, and government markets, delivering services such as design-build, preconstruction planning, and facility construction.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>JOHNSON--JOHNSON</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34394</link>
<guid>7799957d4da397731b4a8d105933e57c</guid>
<pubDate>Fri, 31 Jul 2026 23:51:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>JOHNSON--JOHNSON</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>807592b1a5a79701352e1e69a8ac41e5a88eb98c48a447fd12d764b030bbdcd4</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Pharmaceutical | Data leaked: 1.9 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Management-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34386</link>
<guid>98f67d0c03e88f22c2d9f2930848b8fa</guid>
<pubDate>Fri, 31 Jul 2026 21:51:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Community-Management-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd43255b5d0b3899b77ae948402b9f14697b2b0f4b27a9a33e93352d28241df2</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Merritt-Woodwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34388</link>
<guid>9822beb9602ea7ea2f9791e1dc2faebc</guid>
<pubDate>Fri, 31 Jul 2026 20:24:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Merritt-Woodwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a4bd94e122e28ee315558055214b52f0df9430fa367f470083adb4eb4a083fa</i><br /><br />Threat actor <b>description</b>: <i>Merritt provides strategic interior solutions for global estates and superyachts, from concept to execution. With precision planning and careful craftsmanship, it partners with top designers and craftsmen to deliver unparalleled results for generations.</i><br />Target victim <b>website</b>: <i>www.merrittwoodwork.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Laempe-Reich</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34387</link>
<guid>5ebcc5d6380763e7fbaadf4270357929</guid>
<pubDate>Fri, 31 Jul 2026 20:24:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Laempe-Reich</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b251b02535b060608c35fbf3fd223615598071ea1302347a761fcc9a334fe808</i><br /><br />Threat actor <b>description</b>: <i>Laempe Reich is North America’s leading foundry core machine supplier, providing sand core equipment and technology for metal casting. As partner of Laempe Mössner Sinto, it serves the industry for over 80 years.</i><br />Target victim <b>website</b>: <i>www.laempereich.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kenaitze-Indian-Tribe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34384</link>
<guid>f5685cb5d80c3249a9770cfd98cf71eb</guid>
<pubDate>Fri, 31 Jul 2026 18:30:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Kenaitze-Indian-Tribe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60af93d54453d090d9d907f412f6382891751a900cda0e7553ae2b8350cfeb20</i><br /><br />Threat actor <b>description</b>: <i>kenaitze.org The Kenaitze Indian Tribe is a federally recognized sovereign nation of the Kahtnuht'ana Dena'ina people located on Alaska's Kenai Peninsula. Its core mission is "to assure Kahtnuht'ana Dena'ina thrive forever" through holistic, culturally grounded support. The Tribe operates the Dena'ina Wellness Center, providing comprehensive medical, dental, and behavioral health services, alongside education, elder care, and tribal fisheries to preserve their heritage and promote community well-being</i><br />Target victim <b>website</b>: <i>kenaitze.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Additive-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34383</link>
<guid>d3d92bc35d062c83f89b7ea87d99dca9</guid>
<pubDate>Fri, 31 Jul 2026 18:30:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Additive-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82e7029655aa4217ae1db5b802dd38abc26001e630a099d7c1a1ffe41db4c1e6</i><br /><br />Threat actor <b>description</b>: <i>additivemanufacturingllc.com zoominfo.com/c/additive-manufacturing-llc/369228736 Additive Manufacturing LLC is a U.S.-based company headquartered in Las Vegas, Nevada, specializing in 3D printing, rapid prototyping, and short- to mid-run production of metal and plastic parts. Backed by over a century of combined industry experience, the company bridges digital fabrication and traditional manufacturing, offering services like CNC machining, production tooling, and assembly. By leveraging a global network of partners and on-demand digital factories, they ensure scalable, high-quality, and cost-effective solutions with reliable lead times</i><br />Target victim <b>website</b>: <i>additivemanufacturingllc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acosta-Sons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34377</link>
<guid>c9591e48b02f541835a646cb10794668</guid>
<pubDate>Fri, 31 Jul 2026 18:28:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Acosta-Sons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6371395e27c77e382fa8d29f39472ec9c199bb18d22b964a256c258bb25ab533</i><br /><br />Threat actor <b>description</b>: <i>acostaandsons.com zoominfo.com/c/acosta--sons-inc/398811105 Acosta and Sons is a family-owned appliance sales and repair company based in The Bronx, New York, with additional locations serving the broader New York area. They specialize in providing a wide range of home appliances at discounted prices, catering to both individual customers and property management or landlord accounts. The company is known for its reliable customer service, offering comprehensive solutions from appliance sales to professional repair and maintenance.</i><br />Target victim <b>website</b>: <i>acostaandsons.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CFS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34376</link>
<guid>f136cbc6bfca2fc13d46f42b44d450c6</guid>
<pubDate>Fri, 31 Jul 2026 18:28:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>CFS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60b2e3adc8ea8ca3da72d8cc51d3320f52c10600f24989068cd4e8122637769d</i><br /><br />Threat actor <b>description</b>: <i>cfsinc.com zoominfo.com/c/cfs-inc/12944410 CFS Inc. is a Massachusetts-based marketing support services company with over 30 years of experience in print management, direct mail, kitting, promotional items, and fulfillment. Acting as a single-source solution, they handle projects from initial design to final execution, helping businesses streamline their marketing and logistical operations. The company is known for its flexible, customer-centric approach and a strong commitment to delivering high-quality, reliable results for clients of all sizes</i><br />Target victim <b>website</b>: <i>cfsinc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hutch-Paving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34374</link>
<guid>d083e59bc7e9e9c441d88bc1a067ad31</guid>
<pubDate>Fri, 31 Jul 2026 18:27:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hutch-Paving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61106748596ba0d833881295186a6b665053e754ce072c33c311251ad27b2f2c</i><br /><br />Threat actor <b>description</b>: <i>hutchpaving.com zoominfo.com/c/hutch-paving-inc/38258180 Hutch Paving is a highly respected asphalt and concrete paving contractor based in Southeast Michigan, serving the region since 1993. The company specializes in comprehensive pavement solutions, including resurfacing, maintenance, sealcoating, and new construction for commercial, municipal, industrial, and residential clients. Known for its safety-first approach, modern equipment, and attention to detail, Hutch Paving is committed to delivering durable, high-quality infrastructure with exceptional customer service</i><br />Target victim <b>website</b>: <i>hutchpaving.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CRB-group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34373</link>
<guid>ef2550dfd2612e0b454f6f6914b68335</guid>
<pubDate>Fri, 31 Jul 2026 18:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>CRB-group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>723ff901ba210abe63b8ba5cda0119704d5ba482e31e44e6b0e6e24ae8503d93</i><br /><br />Threat actor <b>description</b>: <i>crbgroup.com zoominfo.com/c/crb-group-gmbh/23317692 CRB is a leading global provider of sustainable engineering, architecture, construction, and consulting solutions, primarily serving the life sciences and food & beverage industries. Headquartered in Kansas City, Missouri, the company specializes in designing and building advanced facilities, such as cell and gene therapy laboratories and high-quality food manufacturing plants. With a strong international presence, CRB is dedicated to delivering innovative, safe, and efficient infrastructure that improves patient outcomes and advances scientific breakthroughs worldwide</i><br />Target victim <b>website</b>: <i>crbgroup.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Partition-Specialties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34372</link>
<guid>dec0f433860ff18f2df8be7cac5437ef</guid>
<pubDate>Fri, 31 Jul 2026 18:27:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Partition-Specialties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c9df1c4c9a9c98e393a47b6c213b944e784e8c00ecc346497520068ecef2fab</i><br /><br />Threat actor <b>description</b>: <i>psi3g.com zoominfo.com/c/partition-specialties-inc/90587733 Partition Specialties, Inc. (PSI), founded in 1958, is a leading commercial interior contractor based in California, serving clients across California and Northern Nevada. The company specializes in tailored architectural space management solutions, including high-quality movable partitions, demountable wall systems, and acoustic dividers. With decades of expertise, PSI helps corporate, hospitality, and industrial clients optimize their interior layouts with flexible, functional, and aesthetically pleasing design products</i><br />Target victim <b>website</b>: <i>psi3g.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Preferred</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34371</link>
<guid>dc17d9b4862d86f8054735577c04462a</guid>
<pubDate>Fri, 31 Jul 2026 18:26:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Preferred</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14886a56f6530990ac3fc27d3a62f408f3ab5912eb23288a456c2642ec8f0bb5</i><br /><br />Threat actor <b>description</b>: <i>preferredtool.com Preferred Tool & Die is a precision manufacturing company based in Shelton, Connecticut, specializing in custom metal and plastic injection molds as well as complex stamped components. The company serves demanding sectors, including the medical, electrical, consumer products, and automotive industries. Holding ISO and FDA registrations, they are committed to delivering high-quality, reliable, and innovative manufacturing solutions tailored to exact client specifications</i><br />Target victim <b>website</b>: <i>preferredtool.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Concrete-Pumping</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34368</link>
<guid>8230258b576f81e8dec86997100d1bfb</guid>
<pubDate>Fri, 31 Jul 2026 18:25:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Precision-Concrete-Pumping</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c557c29fa331b6deeb46739b9c5075a5204876a9d91b3330a735a3b904f5cbfb</i><br /><br />Threat actor <b>description</b>: <i>precisionconcretepump.com zoominfo.com/c/precision-concrete-pumping-inc/356699459 Precision Concrete Pumping, Inc. is an MBE-certified concrete pumping company established in 1988, with branches across New York and New Jersey. The company specializes in providing high-quality concrete pumping services, including boom pumps, line pumps, and telebelts, utilizing a modern fleet of Putzmeister and Schwing equipment. With over 25 years of experience, they serve commercial, industrial, and municipal projects throughout the Northeast, ensuring reliable performance and exceptional customer service</i><br />Target victim <b>website</b>: <i>precisionconcretepump.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clear-Vision-Signs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34367</link>
<guid>95b2a1df756b9e6e67bfacd25c2c6110</guid>
<pubDate>Fri, 31 Jul 2026 18:25:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Clear-Vision-Signs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7029e9d6c209ac62f38c3b7460577b0fd739a644fe17535c7b91a95548d76aa6</i><br /><br />Threat actor <b>description</b>: <i>clearvisionsigns.net zoominfo.com/c/clear-vision-signs/365480092 Clear Vision Signs is a full-service architectural signage and graphics company based in Dade City, Florida, serving clients nationwide. They specialize in turnkey solutions, including wayfinding systems, ADA-compliant signage, environmental graphics, and comprehensive project management. By acting as a single trusted partner for developers and property managers, they ensure efficient, safe, and visually impactful signage programs from initial concept to final installation</i><br />Target victim <b>website</b>: <i>clearvisionsigns.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Known</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34361</link>
<guid>995e869dac6a1eb7a46c430768a04db3</guid>
<pubDate>Fri, 31 Jul 2026 18:23:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Known</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>830c9c3c974030007ddf2d39b12a5980ec36a1b913af843b2dd215d43b118ae0</i><br /><br />Threat actor <b>description</b>: <i>known.is zoominfo.com/c/known/480652891 Known is an award-winning, data-driven marketing, creative, and media agency headquartered in New York. The company uniquely combines PhD data scientists with world-class creatives to deliver measurable performance and breakthrough brand strategies for major clients like Microsoft, TikTok, and Grubhub. Recognized by Ad Age and Adweek as a top-tier agency, Known is dedicated to setting a new standard for modern marketing through science-led innovation and rigorous analytics</i><br />Target victim <b>website</b>: <i>known.is</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peachtree-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34360</link>
<guid>bc55ea9e207158cae19485c14e573efd</guid>
<pubDate>Fri, 31 Jul 2026 18:23:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Peachtree-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b5f98a8f08a14e1f8272df2345bfdf6f39e42d7fb8c6a4233f4dbedf1459307</i><br /><br />Threat actor <b>description</b>: <i>peachtreegroup.com zoominfo.com/c/peachtree-group/5000000011 Peachtree Group is a vertically integrated investment management firm headquartered in Atlanta, Georgia, with a history dating back to 1979. The company specializes in identifying mispriced risk and capitalizing on dislocated market opportunities across private credit, real estate, and equity investments. Managing billions in assets, Peachtree Group provides comprehensive financing solutions—including permanent loans, bridge financing, and mezzanine capital—while offering dedicated services to protect and grow its investments</i><br />Target victim <b>website</b>: <i>peachtreegroup.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>World-Wide-Fittings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34358</link>
<guid>16c07e910397fb3910aad491c8c25e55</guid>
<pubDate>Fri, 31 Jul 2026 18:22:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>World-Wide-Fittings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b59fb598d697ae5f927575b10518f03d3669ed525491e5b693e80dc715c2ac95</i><br /><br />Threat actor <b>description</b>: <i>worldwidefittings.com zoominfo.com/c/world-wide-fittings-inc/42729844 World Wide Fittings, Inc. is a global manufacturer of precision-engineered steel and stainless steel hydraulic tube and pipe fittings, founded in 1950 and headquartered in Vernon Hills, Illinois. Operating from nine facilities across three continents, the company supplies over 150 million components annually to OEMs and distributors in industries like automation, manufacturing, and fluid power. With a strong focus on in-house manufacturing, strict quality control, and vast in-stock inventory, they ensure reliable, on-time delivery of specialized fittings worldwide</i><br />Target victim <b>website</b>: <i>worldwidefittings.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chemco-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34357</link>
<guid>fc234a34937d7459d1f0518f37e1a7b1</guid>
<pubDate>Fri, 31 Jul 2026 18:22:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Chemco-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3fcf345d5244c86aff3bca77cfffd696420994660c961b476a8c211a4f4fc52</i><br /><br />Threat actor <b>description</b>: <i>chemcosystems.net zoominfo.com/c/chemco-systems-lp/39588004 Chemco Systems is a world leader in the design and manufacturing of bulk chemical storage, handling, and feed systems for air and water pollution treatment, operating since 1980. The company provides tailored engineering, fabrication, and installation services, delivering innovative and cost-effective solutions without compromising safety or quality. With decades of industry experience, Chemco Systems is committed to superior product reliability, efficient customer service, and the continuous professional growth of its team</i><br />Target victim <b>website</b>: <i>chemcosystems.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Total-Auto-Business-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34356</link>
<guid>e800acf8774c816fa0156944bb45bf74</guid>
<pubDate>Fri, 31 Jul 2026 18:21:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Total-Auto-Business-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43e6237719c625a11ea8084d2af15d13536632b16684f348741d7387fae5c1fc</i><br /><br />Threat actor <b>description</b>: <i>autorepairsoftware.com Total Auto Business Solutions, Inc. (TABS) is a leading provider of comprehensive shop management software, best known for its flagship product, AutoFluent. Founded in 2001 and based in Northern California, the company serves auto repair shops, tire dealers, and fleet operators across the US and Canada. Their all-in-one platform streamlines daily operations by seamlessly integrating scheduling, inventory management, accounting, and customer relationship tools into a single, user-friendly system</i><br />Target victim <b>website</b>: <i>autorepairsoftware.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gardiner-Family-Chiropractic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34351</link>
<guid>e12612acc5951b13ed502266385b8108</guid>
<pubDate>Fri, 31 Jul 2026 14:56:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Gardiner-Family-Chiropractic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f02994ce56564a36daad9e3d90c63cd6d368c095ffbb826c9aee682ff5482b9</i><br /><br />Threat actor <b>description</b>: <i>Gardiner Family Chiropractic has been providing medical services to residents of Gardiner and the surrounding area since 1989. However, it is not responsible for its patients and makes no attempt to ensure the security of its stored information. Therefore, patient data, client records, medical histories, and internal company financial information have been compromised and are being made available to you.</i><br />Target victim <b>website</b>: <i>gardinerfamilychiropractic.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>RUS-Industrial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34350</link>
<guid>0832a7d7b55992260bda1b1c6b2fd924</guid>
<pubDate>Fri, 31 Jul 2026 13:28:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>RUS-Industrial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8bc818c3de238840d49a8be1ea2654a69d5b01298485ff168b30f529b9fdb9b7</i><br /><br />Threat actor <b>description</b>: <i>RUS Industrial specializes in heavy industrial construction services, catering to sectors such as chemical refineries, petrochemical plants, oil and gas facilities, and mission-critical data centers.</i><br />Target victim <b>website</b>: <i>rusindustrial.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.mbmlawsc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34349</link>
<guid>a8833cd4d827a1bd3e3a22f2709aa7d9</guid>
<pubDate>Fri, 31 Jul 2026 13:27:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>www.mbmlawsc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4127223118f9d25a27454be983f4d7cb0f71cc9f00e3339e994ba945b3ebe4e2</i><br /><br />Threat actor <b>description</b>: <i>MBM Law (Moore Bradley Myers) is a South Carolina-based law firm founded in 1971. For over half a century, the firm has represented individuals, families, and businesses across a wide range of legal matters</i><br />Target victim <b>website</b>: <i>www.mbmlawsc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Betz-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34348</link>
<guid>5a55d6ee22db450394f6f4ff698ce7f9</guid>
<pubDate>Fri, 31 Jul 2026 12:50:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Betz-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ce45990de475c345bbc395927a87aedf5628145b2789fb3fbee6b027e973b2b</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery Manufacturing Stolen data: 7 GB.</i><br />Target victim <b>website</b>: <i>www.betzindustries.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hawaii-Family-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34345</link>
<guid>910c8aa6d76100df69a6ea11c2a39ed1</guid>
<pubDate>Fri, 31 Jul 2026 03:58:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hawaii-Family-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6067a7f3d910829aa5d15dd7590ec85c0bdde2bd2fbfafc68be513fb58ff5349</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.hawaiifamilydental.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>BLUEVISTALLC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34344</link>
<guid>f2abae2c6442359b27db5cf70be05da4</guid>
<pubDate>Fri, 31 Jul 2026 00:36:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BLUEVISTALLC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16a828bac7cfacb06c78d95ad5ae7bc215b164e34d8f5f6520f4bce464d925e1</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>C.A.-Walker-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34342</link>
<guid>54b1d475ba3398d7bfd516304215d53d</guid>
<pubDate>Thu, 30 Jul 2026 21:25:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>C.A.-Walker-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f74800684f34a3199466041d6e7f8bdee5fbc7be94687a616f28f983631d3fd</i><br /><br />Threat actor <b>description</b>: <i>A construction management company</i><br />Target victim <b>website</b>: <i>cawalkerconstruction.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>L3HARRIS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34341</link>
<guid>6b1c2c6ae8329093b3caeda72fe569a9</guid>
<pubDate>Thu, 30 Jul 2026 20:32:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kyber</b> claims attack for <b>L3HARRIS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4f028bdb88ac37421ac552a28d39e6fdc2fb022360e18a944bef013c85aa0c5</i><br /><br />Threat actor <b>description</b>: <i>L3Harris is a global aerospace and defense technology innovator that provides mission-critical solutions for government, defense, and commercial sectors.</i><br />Target victim <b>website</b>: <i>l3harris.com</i>]]></description>
<category>kyber</category>
</item>
<item xmlns:dc='ns:1'>
<title>Audio-Precision-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34340</link>
<guid>29728f99c3104f0ee7efac0f90eb2788</guid>
<pubDate>Thu, 30 Jul 2026 20:29:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Audio-Precision-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8fbfb80da55d22eda7f3a0035323c60a36c3ff6cb11b8ab4f508dde7a6f296bc</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ap.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>REMAX-1st-Choice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34339</link>
<guid>562eec4ba9b07078010e6d03345f031f</guid>
<pubDate>Thu, 30 Jul 2026 20:10:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Gammax</b> claims attack for <b>REMAX-1st-Choice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e38e62ad4be1e829809ca5564322abfcfde5a9f65293e0d0bbab38f6f6837224</i><br /><br />Threat actor <b>description</b>: <i>RE/MAX 1st Choice Florida was established in 2005 and is managed by Katy and John Martinelli, who serve as the owners and operators and hold the compa...</i><br />Target victim <b>website</b>: <i>www.remax-1stchoice.com</i>]]></description>
<category>Gammax</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sonitor-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34334</link>
<guid>d9749cf32d4dfe38ddc695572dd948b9</guid>
<pubDate>Thu, 30 Jul 2026 14:01:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Sonitor-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e3110edad2d481f7ed10ea16127d5532b1e9c1f764bf22f44cfc8341e011e18</i><br /><br />Threat actor <b>description</b>: <i>Sonitor’s platform and technologies deliver the accurate and reliable data required to optimize care delivery</i><br />Target victim <b>website</b>: <i>sonitor.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>sslf.local</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34333</link>
<guid>c110f3fd3ee12cc12d7334c8a3e53c74</guid>
<pubDate>Thu, 30 Jul 2026 12:57:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>sslf.local</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b033c803192085b06d3e2e4843a7312fe223ec34ed522e1adb15bd5c31ec1e0c</i><br /><br />Threat actor <b>description</b>: <i>Samuels & Thornton is a law firm based in New Orleans, specializing in medical malpractice and personal injury cases. They provide personalized legal guidance to individuals, families, and businesses facing legal challenges, ensuring that each client receives dedicated attention from experienced attorneys. Their practice areas include medical malpractice, product liability, auto accident litigation, and more. The firm is committed to delivering proven results and effective representation throughout Louisiana.</i><br />Target victim <b>website</b>: <i>sslf.local</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Affinity-Capital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34328</link>
<guid>5dbb759bbdae5f1c53e792747488ff52</guid>
<pubDate>Thu, 30 Jul 2026 11:56:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Affinity-Capital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>929646b91ead89314580b218b9e88e4521e25e195fb50f93749e78acd1253ee3</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TenSparrows</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34332</link>
<guid>f4fb3ad46ed38e0582c16fb84b610897</guid>
<pubDate>Thu, 30 Jul 2026 10:59:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TenSparrows</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fc8ce72589794c7055547f613c5b68e7e67cb94d48b53af1d8c0524f9c4bc0e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.tensparrows.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rondout-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34329</link>
<guid>f9825fce3f80c8c387aea3be5e387179</guid>
<pubDate>Thu, 30 Jul 2026 09:20:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Rondout-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f483c705c66cc19f1d1222844512c7042d4a8606774d50ebb8adc60728406776</i><br /><br />Threat actor <b>description</b>: <i>Rondout Electric Inc. is a leading electrical contracting company with over 50 years of experience, specializing in a wide range of projects including health care facilities, schools, industrial complexes, and public sector projects. With a dedicated team of approximately 100 employees, they are known for their disciplined approach to ensuring projects are completed safely, on time, and within budget. The company has built long-standing relationships with clients who appreciate their commitment to integrity and customer satisfaction. Based in Highland, NY, Rondout Electric serves clients across the eastern part of New York State.</i><br />Target victim <b>website</b>: <i>www.rondoutelectric.net</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Promatrix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34315</link>
<guid>a3db9614f393be410bad6e26f6ef5ac0</guid>
<pubDate>Thu, 30 Jul 2026 06:50:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Promatrix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0b6c356d48bc0a60a5139d944a4b117e81028cdccad552c3dfd5c773b595af8</i><br /><br />Threat actor <b>description</b>: <i>promatrixcorp.com zoominfo.com/c/promatrix-corp/347777611 Promatrix Corp is a rapidly growing IT consulting and outsourcing company based in New Jersey, USA. They deliver comprehensive global technology solutions, including web application development, managed IT services, and staff augmentation. The company also specializes in enterprise resource planning (SAP) support and HR outsourcing to help businesses optimize their operations and scale efficiently</i><br />Target victim <b>website</b>: <i>promatrixcorp.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Garfield-County-Sheriff-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34307</link>
<guid>57990ea703eff0f2408e8bac75f342d3</guid>
<pubDate>Thu, 30 Jul 2026 06:47:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>The-Garfield-County-Sheriff-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>888052e3ba1dffb26a6c5b26ef0b392ad12e7f2e99251c7c0bb7b072ea8c10a5</i><br /><br />Threat actor <b>description</b>: <i>garcosheriff.com The Garfield County Sheriff's Office is the primary law enforcement agency serving Garfield County, Colorado. Its mission is to deliver exceptional service and problem-solving solutions to the community through professional, ethical, and compassionate conduct. The office provides comprehensive public safety services, including patrol, detentions, criminal investigations, and community outreach programs like "Shop with a Cop" and emergency mass notifications</i><br />Target victim <b>website</b>: <i>garcosheriff.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northwood-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34301</link>
<guid>fb329817e3ca2132d39134dd26d894b2</guid>
<pubDate>Wed, 29 Jul 2026 13:50:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northwood-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3a6fbb57f2960092d3d3229ea3481de886c0cf111cf3b3f1b2a3036bb9204fe</i><br /><br />Threat actor <b>description</b>: <i>Northwood Country Club is a private club located in Meridian, Mississippi, known for its beauti
ful facilities and convenient city location. The club offers a range of amenities including cha
mpionship golf, clubhouse dining, swimming pool, tennis, and fitness services.

We will upload corporate data soon. Employee information (name, home addresses, contacts (emerg
ency ones) and so on), financials, contracts and agreements, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>StellarRAD-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34299</link>
<guid>c652aee4df4084c621a094692ee6f6c9</guid>
<pubDate>Wed, 29 Jul 2026 11:03:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>StellarRAD-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66cfd2e6b116e2c48cf0b91fe4828d18d83e45f8466bb089aa30813fc55d2b34</i><br /><br />Threat actor <b>description</b>: <i>Since 1981, StellarRAD Systems exists to solve the critical issues facing our clients, both large and small. We provide a broad range of services and solutions to help telecommunications providers around the world facilitate change and achieve their vision while optimizing performance and productivity. Our unique, customer focused approach ensures a level of service that you will quickly come to appreciate.Our family of GIS products and conversion services provides an industry leading toolset for engineers managing fiber and copper networks, including the ability to import GPS data, manipulate coordinate systems, identify network components with physical and logical connectivity and much more. Do you need all of this information plus the associated subscriber data available to every employee in your organization via desktop, notebook, tablet and smartphone? Done.  -SQL Data-DWG plan-Personal information of employees and clients-Financial documents-APP files https://www.stellarrad.com/</i><br />Target victim <b>website</b>: <i>www.stellarrad.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bretford-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34298</link>
<guid>e089f46f54a3f4123a6cd11cc45fb64e</guid>
<pubDate>Wed, 29 Jul 2026 06:51:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Bretford-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b3123a8f71e886f647ec638808787f27f609e9ea6cfe4e3d94e5aa02a772b39</i><br /><br />Threat actor <b>description</b>: <i>Bretford Manufacturing, Inc. is a privately held manufacturer of charging solutions for mobile devices, founded in 1948 and headquartered in Franklin Park, Illinois. With ~60 employees and ~$10M annual revenue, it serves education, healthcare, retail, and government sectors.

The exposed material includes:

Social Security Numbers for the entire workforce (current + 200–400 historical employees + dependents) via ACA Census files, 1099 forms, and payroll records spanning 2010–2026.
Corporate and vendor bank accounts — Bretford's own checking account (routing + account number) plus 26+ vendor bank accounts from NACHA ACH batch files.
Complete network architecture — VPN gateway IP, internal topology diagram, IP allocation tables, infrastructure inventory, disaster recovery plan, and Active Directory domain name.
20 years of HR records including medical leave, disability accommodations, drug tests, garnishments, pension, 401(k), insurance enrollment, and termination records.
Complete product engineering library — SolidWorks CAD files for all products, CNC/laser programs, and manufacturing process documentation.</i><br />Target victim <b>website</b>: <i>Bretford Manufacturing</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buck-Knives</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34293</link>
<guid>c24a32c563290f4347f8225282b56247</guid>
<pubDate>Tue, 28 Jul 2026 20:41:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Buck-Knives</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62829d9b223fe012625798241645240c586717c54dfbf7afddb3523c8ee706a0</i><br /><br />Threat actor <b>description</b>: <i>buckknives.com zoominfo.com/c/buck-knives-inc/16223110 Buck Knives is a historic American knife manufacturer founded in 1947 by Hoyt Buck, originating from a family blacksmith business dedicated to superior steel tempering. The brand revolutionized the knife industry in 1964 with the introduction of the iconic Model 110 Folding Hunter. Now headquartered in Post Falls, Idaho, this four-generation family company is renowned for its rugged durability, traditional American craftsmanship, and a lifetime "Forever Warranty"</i><br />Target victim <b>website</b>: <i>buckknives.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>B-K-Tool--Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34290</link>
<guid>7baa3894c1163d4ecd5acc9b4cda2c4a</guid>
<pubDate>Tue, 28 Jul 2026 16:50:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>B-K-Tool--Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b13bc05e9bbb67b9c9ee9223d1b23bf2374741f1777a4a9dc437250ca83f2933</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1981, B-K Tool & Design has transformed from a small machine shop into a turn-key automation solutions provider, operating from an 80,000 square foot facility in Kalida, Ohio. The company specializes in designing and building cost-effective equipment to replace inefficient processes, offering a range of services including electrical and mechanical engineering, control integration, and custom machine fabrication. Their product lines feature hot plate welding, high-speed projection welding, and other custom machines tailored to client needs. B-K Tool & Design serves a diverse customer base that relies on their expertise for both new and existing designs.</i><br />Target victim <b>website</b>: <i>www.bktool.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oklahoma-Manufacturing-Alliance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34287</link>
<guid>bd898b3aa551025f930aa4638ab497c8</guid>
<pubDate>Tue, 28 Jul 2026 14:50:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Oklahoma-Manufacturing-Alliance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>331b417d46452bd86a8e330327b4caeae58cf0d94b783260073120a9f6524002</i><br /><br />Threat actor <b>description</b>: <i>Business Consulting and Services Stolen data: 10 GB.</i><br />Target victim <b>website</b>: <i>www.okalliance.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpseclmn.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34285</link>
<guid>82034d7a5bdc3b8a2d2d08e9c9ab5c8c</guid>
<pubDate>Tue, 28 Jul 2026 13:26:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpseclmn.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>216c71f2220c20aa56b84ee61ed9cdc5aebf4c958ecb04dc6b95fd85648cb260</i><br /><br />Threat actor <b>description</b>: <i>A family-run health and residential care organization in Minnesota. They provide adapted housing, professional in-home support, and daily living solutions for adults with physical disabilities and limited mobility</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Incredible-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34283</link>
<guid>9fabfa2db6d33c9f4721d725e0269a42</guid>
<pubDate>Tue, 28 Jul 2026 12:50:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Incredible-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48a4a6950578b6d82f814dc0cc0c2c72c95918f4104303e43d346774a0af6b14</i><br /><br />Threat actor <b>description</b>: <i>Entertainment Providers Stolen data: 25 GB</i><br />Target victim <b>website</b>: <i>www.itsgames.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Affinia-Healthcare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34280</link>
<guid>827a1fd7a77a96b4c3a3cd36b431f878</guid>
<pubDate>Tue, 28 Jul 2026 02:07:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Affinia-Healthcare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c12e64caca01d58609944db71f4f696843a3e04327d4720235a940349124772f</i><br /><br />Threat actor <b>description</b>: <i>Affinia Healthcare is dedicated to providing high-quality medical care and exceptional services across multiple locations in the St. Louis area. They offer a comprehensive range of health services including primary care, dental, behavioral health, and specialized programs for all family members, particularly focusing on underprivileged communities.
</i><br />Target victim <b>website</b>: <i>affiniahealthcare.org</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>DUCON</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34278</link>
<guid>5c7768be6ec1b2cd22387346d1bf6388</guid>
<pubDate>Tue, 28 Jul 2026 01:58:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>DUCON</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05ee57338cccdc8b87503345728559d20819982f3791e4b81e49ff484e92bfa0</i><br /><br />Threat actor <b>description</b>: <i>Unauthorized access has been gained to the company's confidential files, including client data, proprietary R&D, and financial documentation.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>greenecountyga.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34277</link>
<guid>3a92b4654f299c75c507ce37ec1c0c4d</guid>
<pubDate>Tue, 28 Jul 2026 01:04:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>greenecountyga.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>517484ec81d3bd6b11fd55770020da42e12c853bfc76072166dd94e47b07e784</i><br /><br />Threat actor <b>description</b>: <i>Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is widely known for its combination of rural heritage, historic architecture, and upscale resort living centered around Lake Oconee.</i><br />Target victim <b>website</b>: <i>greenecountyga.gov</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>foundationstofreedom.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34276</link>
<guid>6ded8940f3bcd34111d2e673d4bf5780</guid>
<pubDate>Tue, 28 Jul 2026 01:03:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>foundationstofreedom.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>13a85162e8cd14481dc2e2050f5675728e32e1f7521c99fe0369980bad8a4e3d</i><br /><br />Threat actor <b>description</b>: <i>Foundations to Freedom is a US-registered 501(c)(3) non-profit organization that provides recovery housing, social adaptation programs, and comprehensive therapeutic support for individuals overcoming alcohol and substance abuse, as well as survivors of domestic violence.The organization is dedicated to offering a safe, structured environment for individuals to rebuild their lives from the ground up and maintain long-term sobriety. It is headquartered in DeLand, Florida, USA</i><br />Target victim <b>website</b>: <i>foundationstofreedom.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>JD-Young</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34274</link>
<guid>acfb944f17391575205a32619e3f9d37</guid>
<pubDate>Mon, 27 Jul 2026 23:21:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>JD-Young</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd31071c5c2ba87e085ad4669e603f44536d92f8d7624e208ed2519e20ddff6c</i><br /><br />Threat actor <b>description</b>: <i>JD Young helps financial institutions simplify workflow processes, automate the flow of information, adhere to compliance and determine suitable document hardware for multiple locations. The company&#x27;s document solutions include electronic document management, lock box, hardware fleet management, SaaS (software as a service), multi-function hardware, printing services and more.
</i><br />Target victim <b>website</b>: <i>www.jdyoung.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>bnpdist.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34264</link>
<guid>9af90570766dc67878480baabf2ae95a</guid>
<pubDate>Mon, 27 Jul 2026 18:59:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>bnpdist.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>282a085465f649873d05323aa870d2064c0a478625c7003b2b64b4e8ddb3f1ad</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in New York City, the company has been operating since 1979 and supplies restaurants, hotels, retailers, and wine merchants …</i><br />Target victim <b>website</b>: <i>bnpdist.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kates-Nussman-Ellis-Earle--Landolfi-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34262</link>
<guid>15c58997f6690dddb7c501e062a2d1ab</guid>
<pubDate>Mon, 27 Jul 2026 18:56:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Kates-Nussman-Ellis-Earle--Landolfi-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f192e723ea0a88bf8fc243e1e91b30951be8e6e10e2adad6e36f41b22785f081</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>katesnussman.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>vit-best.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34261</link>
<guid>ec470ad3d3fb68337b14d514b9e73238</guid>
<pubDate>Mon, 27 Jul 2026 18:51:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>vit-best.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a46d78cb4b35ddd8b26d09c00142feddd106cc140e1e2b5c18add5a0594abf66</i><br /><br />Threat actor <b>description</b>: <i>DATA BREACH NOTICE: VIT-BEST.COM

    Status: The first 3% of the total data (100%) has been published

    Countdown: 48 hours until the remaining 97% is published

Situation Overview

We have successfully breached VIT-BEST’s infrastructure and extracted a complete set of critical data. At this t…</i><br />Target victim <b>website</b>: <i>vit-best.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>KSL-Dirtworks-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34253</link>
<guid>a0e862b5c2de0352aeb851d943e6046c</guid>
<pubDate>Mon, 27 Jul 2026 17:55:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>KSL-Dirtworks-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a8c7ad28e3a858306559e7b391216f670df35d93552123a52e77248354fe49a</i><br /><br />Threat actor <b>description</b>: <i>- HR Documents- Financial Documents- Contracts- Bids & Proposals- Project Documents- Office Documents- Construction Standards- Insurance Documents</i><br />Target victim <b>website</b>: <i>www.ksldirtworks.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>TFG-Benefits-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34251</link>
<guid>765be53f0233ac540e58b3a6c1ffdecb</guid>
<pubDate>Mon, 27 Jul 2026 17:54:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>TFG-Benefits-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90f9eb05cc32b8d2680bfd09576e3383ae56748caaf6a5cd326e28523cb7ab61</i><br /><br />Threat actor <b>description</b>: <i>- Employee PII- Payroll- Benefits- Financials- Client HR- Identity Docs</i><br />Target victim <b>website</b>: <i>www.tfgbenefits.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wilberts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34246</link>
<guid>c091c668b03abceaef7ef656d431228a</guid>
<pubDate>Mon, 27 Jul 2026 13:54:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wilberts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>230ffef1ce667c196edb06f04a5ac8b1451284bf7cbf632f1fdef74225e4f38e</i><br /><br />Threat actor <b>description</b>: <i>Automotive Parts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>BH-Security-LLC.-brinkshome.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34249</link>
<guid>22852db60a3406b42630a69fbc08e4a2</guid>
<pubDate>Mon, 27 Jul 2026 12:59:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>BH-Security-LLC.-brinkshome.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e0ba1187bcebf656c4e298370d81c3422c44e3a7fd2b28d26fc47d1013b9dde</i><br /><br />Threat actor <b>description</b>: <i>Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>brinkshome.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>RingCentral-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34248</link>
<guid>367c9ae075bd4d63b91356f0206bebe5</guid>
<pubDate>Mon, 27 Jul 2026 12:59:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>RingCentral-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53ec340eb14221a1d5324b01fb929c03375fe8682fc9cf83491db75480dd1d5a</i><br /><br />Threat actor <b>description</b>: <i>Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>ringcentral.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>IPTV-Platform</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34244</link>
<guid>00c37b7a1f13daf967813da9b68937f3</guid>
<pubDate>Mon, 27 Jul 2026 04:57:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>IPTV-Platform</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e47a0d8962149df9a87dda7ae04b8d48c15857059d96dc725b0e3109f28f101f</i><br /><br />Threat actor <b>description</b>: <i>Sector: Technology / Video Streaming | Data leaked: 3.2 GB</i><br />Target victim <b>website</b>: <i>IPTVPlatform.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Hospice--Home-Health-Services-Ahhh-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34242</link>
<guid>73907fed82d21d4b3700c31aefb6b3c0</guid>
<pubDate>Mon, 27 Jul 2026 04:56:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>American-Hospice--Home-Health-Services-Ahhh-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>903c72e04c5c323d086874a5609c5a144360b0db8963c1d14b4354814cb511a5</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Hospice | Data leaked: 11.3 GB</i><br />Target victim <b>website</b>: <i>americanhomehealthservices.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bright-Star-Partners-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34241</link>
<guid>32904f10e22018404170f6ed3b5bd5a2</guid>
<pubDate>Mon, 27 Jul 2026 04:55:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Bright-Star-Partners-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef9ec00ae8cc4cbc943d822c94441d6cc3453f054fa6fa725e5337ddd9a42966</i><br /><br />Threat actor <b>description</b>: <i>Sector: Insurance / Financial Services | Data leaked: 41.8 GB</i><br />Target victim <b>website</b>: <i>brightstarinsurancepartners.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>eCare-Platform</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34240</link>
<guid>4f7ef7308c8eb7e5e3730a15a66c0fb3</guid>
<pubDate>Mon, 27 Jul 2026 04:55:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>eCare-Platform</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3545cd83161636a3a24400d94c03989830103bdd0816155f136a5eca3279322b</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Technology | Data leaked: 14.2 GB</i><br />Target victim <b>website</b>: <i>ecareplatform.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dignity-Phoenix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34239</link>
<guid>bceae4e660518105326a313513671bf9</guid>
<pubDate>Mon, 27 Jul 2026 04:54:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Dignity-Phoenix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b55321fbfec6fda0cca18f09a23c5691bbc4001c70564f00981699e1c2d6fba1</i><br /><br />Threat actor <b>description</b>: <i>Sector: Non-Profit / Social Services | Data leaked: 5.4 GB</i><br />Target victim <b>website</b>: <i>dignityphoenix.org</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schorr-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34238</link>
<guid>f8c00b149cb2143e3a8dd8c86d8c258b</guid>
<pubDate>Mon, 27 Jul 2026 04:54:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Schorr-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42a6c6de541cf4c176f4273d3eac3664af25fa56709c7010c34ff909d8a01d65</i><br /><br />Threat actor <b>description</b>: <i>Sector: Legal / Real Estate | Data leaked: 27.6 GB</i><br />Target victim <b>website</b>: <i>schorr-law.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leah-Walker-Orthodontics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34236</link>
<guid>11cc47e70933d4d928498869e747950a</guid>
<pubDate>Mon, 27 Jul 2026 04:52:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Leah-Walker-Orthodontics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10dfa60c842d8180ba5d000f8630c350b9213e070761ca1a3057d8544371dded</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Orthodontics | Data leaked: 8.3 GB</i><br />Target victim <b>website</b>: <i>socalbraces.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elko-Dental-Specialists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34235</link>
<guid>28a32c20769baa8373833005b125864b</guid>
<pubDate>Mon, 27 Jul 2026 04:52:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Elko-Dental-Specialists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59968ebf1a131703770bdc816946852fab5d36e73371595f89da1d9e5e329bab</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Dental | Data leaked: 7.8 GB</i><br />Target victim <b>website</b>: <i>elkosmiles.com</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Louisiana-Coalition-Against--Domestic-Violence</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34231</link>
<guid>dec2236203d220c20de58dc2a0040258</guid>
<pubDate>Mon, 27 Jul 2026 03:20:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Louisiana-Coalition-Against--Domestic-Violence</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a52a271fdf369f4f3a0d79bd2f119cb076d211cf697c86ad63ac05156f025e87</i><br /><br />Threat actor <b>description</b>: <i>Country: US |
Website: lcadv.org |
Revenue: $13.3 Million |
Industry: Non-Profit & Charitable Organizations |
Employees: 201-500 |
Properties: 241 GB (287,451 Files, 31,100 Folders)</i><br />Target victim <b>website</b>: <i>lcadv.org</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>ProSmile-Family-Dental-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34230</link>
<guid>f1ee743dc0a992a08cf2e192c586168c</guid>
<pubDate>Mon, 27 Jul 2026 01:56:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>ProSmile-Family-Dental-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0cfa3663e6705079ef68da5fc5558a34a613d56d9e9631a981bb2557d0d2553</i><br /><br />Threat actor <b>description</b>: <i>Sector: Healthcare / Dental | Data leaked: 9.6 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Qube-Aviation-Catering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34229</link>
<guid>2448f48c086548deacdad3a56a3c0215</guid>
<pubDate>Mon, 27 Jul 2026 01:56:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Qube-Aviation-Catering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2656c65d31ddb4d530fd101c2c21262fce4ca91dfd0b97e774323a73dc574ee2</i><br /><br />Threat actor <b>description</b>: <i>Sector: Aviation / Catering | Data leaked: 22.5 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Performance-Data-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34228</link>
<guid>84037c86334bb0dc014f73da6bb04dca</guid>
<pubDate>Mon, 27 Jul 2026 01:55:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Performance-Data-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a801650ead9941e543cd6c2c55e52a907970fba6ad69791b267c11345c43f85</i><br /><br />Threat actor <b>description</b>: <i>Sector: Motorsport / Data Acquisition | Data leaked: 12.8 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>RnnR-Cloud</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34226</link>
<guid>3741c35b468fdcbcb872b68404a28ae9</guid>
<pubDate>Mon, 27 Jul 2026 01:54:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>RnnR-Cloud</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3829f14a9648de38d32621f1407cd723cc5bae56cc0775c0ca3c7d008827d12d</i><br /><br />Threat actor <b>description</b>: <i>Sector: Technology / Cloud Services | Data leaked: 68.9 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>CodeConductor.ai</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34225</link>
<guid>0febd8884d4018ef0f494a74d24b63a3</guid>
<pubDate>Mon, 27 Jul 2026 01:53:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>CodeConductor.ai</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b706b248f79061947923cc4ad3600178b46830c13fca7b2758cb623e9b9c2fa</i><br /><br />Threat actor <b>description</b>: <i>Sector: Technology / AI / SaaS | Data leaked: 52.4 GB</i><br />Target victim <b>website</b>: <i>CodeConductor.ai</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prei-Capital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34224</link>
<guid>94ae78261adc94a727c0a99edd823f7d</guid>
<pubDate>Mon, 27 Jul 2026 01:52:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Prei-Capital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54c11254588ba6621ea64f5562de3dc0bc3e143c4f27f04ef410c454f53f6934</i><br /><br />Threat actor <b>description</b>: <i>Sector: Financial / Capital | Data leaked: 18.7 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>FLP-Law-Group-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34223</link>
<guid>90f2041eeb835d118c1b6d02904b6e3a</guid>
<pubDate>Mon, 27 Jul 2026 01:52:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>FLP-Law-Group-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7dcde8c36532dc340f4b57abcbe90249b7ac712bad23ffcc0731dd4a230abb2</i><br /><br />Threat actor <b>description</b>: <i>Sector: Legal / Bankruptcy | Data leaked: 42.1 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Summit-Hill-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34222</link>
<guid>01f11b1dc7251b4dad589e664e28aaf6</guid>
<pubDate>Mon, 27 Jul 2026 01:51:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Summit-Hill-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8472837884ceafddace7dd239ddf9bf0914167dd72e0b8e9ca8e4bf5318058b4</i><br /><br />Threat actor <b>description</b>: <i>Sector: Insurance | Data leaked: 34.5 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>MRO-Aerospace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34221</link>
<guid>b02ec300f88363cac4572b8084bad604</guid>
<pubDate>Mon, 27 Jul 2026 01:50:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>MRO-Aerospace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54ac0619f51203c59ab33b9a12425182dbdb35122b1a5faaed9de529f9be71b8</i><br /><br />Threat actor <b>description</b>: <i>Sector: Aerospace / Defense | Data leaked: 87.3 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>takethehop.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34220</link>
<guid>d02a0679e1ed95b5961f798794c6f54a</guid>
<pubDate>Mon, 27 Jul 2026 00:25:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>takethehop.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94846ecbaf5b39b4620730f504d8edd84b222b31adcfa33060f13e6679ea5e1a</i><br /><br />Threat actor <b>description</b>: <i>The HOP, an American regional public transit system operated by the Hill Country Transit District (HCTD). Founded in the 1960s in the state of Texas (USA) as a voluntary transportation service, the organization has grown over the decades into a major public public-transport network.</i><br />Target victim <b>website</b>: <i>takethehop.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Park-Manufacturing-Corp.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34219</link>
<guid>da067f61c42e2e1562894e4afcfee191</guid>
<pubDate>Mon, 27 Jul 2026 00:20:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Park-Manufacturing-Corp.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab946c275c3f655f23b80bc424010985d4c771a8123062ce80320f22167e4964</i><br /><br />Threat actor <b>description</b>: <i>Country: Cambridge, Minnesota 55008, US |
Website: parkmfg.com |
Revenue: $17.9 Million |
Industry: Appliances, Electrical, and Electronics Manufacturing |
Employees: 50-100 |
Properties: 195 GB (411,109 Files, 48,413 Folders)</i><br />Target victim <b>website</b>: <i>parkmfg.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wesco-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34218</link>
<guid>dbfc43b5a635df63a2448f9c979d9bf5</guid>
<pubDate>Sun, 26 Jul 2026 23:50:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Wesco-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b81e7c3e76179661842c1bc5423920b714ab1aff9eaa2099bbd20d5ac8a5597f</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $24B

DATA SUMMARY:
2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>JJP-Slip-Forming-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34216</link>
<guid>532c149348a870668e12c8abb53bf651</guid>
<pubDate>Sun, 26 Jul 2026 23:26:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>JJP-Slip-Forming-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a46e2ec8a8c95ddcdfc08283d5a8973c857b0e7a3858a6d670531101759aedda</i><br /><br />Threat actor <b>description</b>: <i>A company that operates in the Restaurants industry</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westlake-Realty-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34214</link>
<guid>92bb070d6bb28ed865642b5721b91b11</guid>
<pubDate>Sun, 26 Jul 2026 23:25:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Westlake-Realty-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57be6710d06e5b729104d003fe26549992465216078a0074aa93e0d7904b659c</i><br /><br />Threat actor <b>description</b>: <i>A full-service real estate development company</i><br />Target victim <b>website</b>: <i>westlake-realty.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinity-PipelineInc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34212</link>
<guid>65b2bc9eb35261e785fdb1a9bc02b6b1</guid>
<pubDate>Sun, 26 Jul 2026 23:23:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Infinity-PipelineInc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77572a2a3695868f28f6f92f9c0c96cbb85160ae5a4409cc1df872f81e8c3f00</i><br /><br />Threat actor <b>description</b>: <i>A family owned, local construction company.</i><br />Target victim <b>website</b>: <i>infinitypipeinc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Syntron-Bioresearch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34159</link>
<guid>9d43928b9e007bf34b0d8eadb3d0393f</guid>
<pubDate>Sun, 26 Jul 2026 19:54:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Syntron-Bioresearch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6acc0d55f9622c8eaddf739b126fdca377effd662b5e62f68b21feb2fb723373</i><br /><br />Threat actor <b>description</b>: <i>Syntron Bioresearch, Inc. specializes in manufacturing rapid in vitro diagnostic tests and detection readers, focusing on fertility and over-the-counter tests f...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deluxe-Medical-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34160</link>
<guid>1cfcd321eb8bcb1c38c8bde2ccf50eee</guid>
<pubDate>Sun, 26 Jul 2026 19:54:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Deluxe-Medical-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b183d27a49051daa41619e0d1190d4b9a4c404fe71e54fd62d2333b5bd71209</i><br /><br />Threat actor <b>description</b>: <i>Deluxe Medical Supply is a distributor of healthcare supplies that focuses on delivering quality home healthcare products and services. They provide a wide rang...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pro-Tuff--Decals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34210</link>
<guid>f2162f0713c4aa4c3c9a843febf03e56</guid>
<pubDate>Sun, 26 Jul 2026 19:51:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Pro-Tuff--Decals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a213b5573a44ac232c5a80783b254f265a01d97b329e01f765ef080731975c8f</i><br /><br />Threat actor <b>description</b>: <i>Country: Crystal Lake, US |
Website: protuffdecals.com |
Revenue: $9.6 million |
Industry: Business Services General, Business Services |
Employees: 10-20 |
Properties: 412 GB (589,623 Files, 40,081 Folders)</i><br />Target victim <b>website</b>: <i>protuffdecals.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>High-Class-Car-Limo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34209</link>
<guid>460d5587441bf82dbf2acd8a7f56ef86</guid>
<pubDate>Sun, 26 Jul 2026 19:50:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Deadlock</b> claims attack for <b>High-Class-Car-Limo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78fc01d83507f22bf0a9c2dce631b279c6f9234ae33180e203533acd36caa8c8</i><br /><br />Threat actor <b>description</b>: <i>High Class Limousine & Car Service Corp. is a licensed private passenger transportation service in New York City, founded in 1995, specializing in non-emergency medical transportation . The company provides rides to medical appointments, dialysis sessions, and rehabilitation facilities, and has locations in Manhattan and the Bronx.</i><br />Target victim <b>website</b>: <i>www.highclasscarlimo.com</i>]]></description>
<category>Deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eagle-Crest-Communities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34208</link>
<guid>be5ebf2a77cde6f3cea317989a3c2de5</guid>
<pubDate>Sun, 26 Jul 2026 19:24:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Eagle-Crest-Communities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae4f1504112dba80a13ffc1a94e8eceb670b7e7f5839e6753ce6ecf5349e9041</i><br /><br />Threat actor <b>description</b>: <i>Patient and employee data breach at elderly care service.</i><br />Target victim <b>website</b>: <i>eaglecrestlife.org</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>OmniLink-AG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34183</link>
<guid>25fe6badb36e64955bfe1e6c8de816aa</guid>
<pubDate>Sun, 26 Jul 2026 18:13:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>OmniLink-AG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>506864033f18ae2dbaeb07a13f26448a20cc6ba5bc642dc1cc00813fb2d1751e</i><br /><br />Threat actor <b>description</b>: <i>Full-scope penetration testing of financial transaction processing pipeline and API gateway.</i><br />Target victim <b>website</b>: <i>omnilink.software</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vertex-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34182</link>
<guid>4e746882294308d42eeed71ba0aacbf8</guid>
<pubDate>Sun, 26 Jul 2026 18:13:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Vertex-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffb3a48abc43a5cca714d60916a63998c2cedc4cdf259541414327a005f4c711</i><br /><br />Threat actor <b>description</b>: <i>Ongoing analysis of cloud-native architecture and microservice communication protocols.</i><br />Target victim <b>website</b>: <i>vertexsystems.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Farmers-Mutual-Fire-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34180</link>
<guid>22ac201ea93f69238146ea4b854bbe89</guid>
<pubDate>Sun, 26 Jul 2026 18:04:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Farmers-Mutual-Fire-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c37a806ab120b3e01c0d0871d2b6e7983124ec8606471da6fe4160abeacb671</i><br /><br />Threat actor <b>description</b>: <i>Country: Pennsylvania, United States |
Website: farmersofmarble.com |
Revenue: $5.2 Million |
Industry: Insurance |
Employees: 11-50 |
Properties: 5.72 GB (18,699 Files, 2,631 Folders)</i><br />Target victim <b>website</b>: <i>farmersofmarble.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>West-Sixth-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34179</link>
<guid>1e1e0a784f4f71196868b5854a68c804</guid>
<pubDate>Sun, 26 Jul 2026 18:03:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>West-Sixth-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3384255ccbe0679a289cb011ab6d1434f30075e853c7b08eddd924e3bc0e2f3b</i><br /><br />Threat actor <b>description</b>: <i>Country: Columbus, Indiana, United States |
Website: agslawyers.com |
Revenue: $5 Million |
Industry: Law Firms & Legal Services |
Employees: 11-50 Employees |
Properties: 328 GB (708,816 Files, 47,925 Folders)</i><br />Target victim <b>website</b>: <i>agslawyers.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baker-Business--Tax-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34178</link>
<guid>f6776ebe9d67d050761071500b104544</guid>
<pubDate>Sun, 26 Jul 2026 18:02:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Baker-Business--Tax-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2320ece713fe7530d0b0097613ee8bb8f9075ed3ee2af0ef86447603336fef3</i><br /><br />Threat actor <b>description</b>: <i>Country: Kentucky, United States |
Website: bakerbusinessandtax.com |
Revenue: $1 Million |
Industry: Accounting for Legal Practices |
Employees: 1-10 Employees |
Properties: 213Gb (817,209 Files, 48,866 Folders)</i><br />Target victim <b>website</b>: <i>bakerbusinessandtax.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carpets-Direct</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34177</link>
<guid>200edb216d1a2e3e08b69b903d6608fc</guid>
<pubDate>Sun, 26 Jul 2026 18:01:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Carpets-Direct</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>385eede53cec11f92934fd21b41c110accba0801156500ded5b38a5bec4fec22</i><br /><br />Threat actor <b>description</b>: <i>Country: Ohio, United States |
Website: carpetsdirectfindlay.com |
Revenue: $5 Million |
Industry: Retail,Furniture |
Employees: 11-50 |
Properties: 31.1 GB (1,442 Files, 788 Folders)</i><br />Target victim <b>website</b>: <i>carpetsdirectfindlay.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>AnyWeather</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34176</link>
<guid>4d28e74f86094725e098c6b7d10b449c</guid>
<pubDate>Sun, 26 Jul 2026 18:01:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>AnyWeather</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>223e6a6bb487228a9614cae226bec44a394abf3e35f516900a96c9a579599d07</i><br /><br />Threat actor <b>description</b>: <i>Country: Kentucky, United States |
Website: ohrestorationservices.com |
Revenue: $6 Million |
Industry: Construction |
Employees: 30 Employees |
Properties: 301 GB (33,041 Files, 4,133 Folders)</i><br />Target victim <b>website</b>: <i>ohrestorationservices.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Middendorf-Animal-Hospital--Laser-Centre</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34175</link>
<guid>aa22b2803b8e7d32e53ac9c29e14845e</guid>
<pubDate>Sun, 26 Jul 2026 18:00:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Middendorf-Animal-Hospital--Laser-Centre</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>504d4930314cc38909e7c9beee0ff7fa2e7341565da770d2e150d67214d4d5c7</i><br /><br />Threat actor <b>description</b>: <i>Country: Kentucky, United States |
Website: middendorfanimalhospital.com |
Revenue: <$5 Million |
Industry: Healthcare Services,Veterinary Services |
Employees: 11-50 |
Properties: 28.1 GB (34,237 Files, 8,806 Folders)</i><br />Target victim <b>website</b>: <i>middendorfanimalhospital.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chappell-Supply--Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34174</link>
<guid>62c8d075dc4cffa2b9e0796f43bc1c2a</guid>
<pubDate>Sun, 26 Jul 2026 17:59:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Chappell-Supply--Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>86bb999f79a88f8f2c2476947e198767167c6ae569f2da77f87b10c87b03d38c</i><br /><br />Threat actor <b>description</b>: <i>Country: Oklahoma, United States |
Website: chappellsupply.com |
Revenue: $9.2 Million |
Industry: Consumer Services,Retail,Manufacturing,Repair Services |
Employees: 11-50 |
Properties: 160 GB (268,758 Files, 30,522 Folders)</i><br />Target victim <b>website</b>: <i>chappellsupply.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nourison--Home</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34166</link>
<guid>6b8f07de11c0e35342e3b77bfea692ed</guid>
<pubDate>Sun, 26 Jul 2026 17:53:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Nourison--Home</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>080f837fdf81b6026fbd5adc6e33c00d5261b60ba39169c89260e14007237b74</i><br /><br />Threat actor <b>description</b>: <i>Country: New Jersey 07663, US |
Website: nourison.com |
Revenue: $59.4 Million |
Industry: Wholesale, Furniture, Home Decor, Retail, Real Estate |
Employees: 100-300 |
Properties: 799 GB (93,941 Files, 13,733 Folders)</i><br />Target victim <b>website</b>: <i>nourison.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cold-Front-Distribution</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34165</link>
<guid>7a769d43321df14f25c7a2318bb8c4a5</guid>
<pubDate>Sun, 26 Jul 2026 17:53:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Cold-Front-Distribution</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f72596405266144d37c342b53ce0d917e96c1a0f6870db5a03122766f9de1b4</i><br /><br />Threat actor <b>description</b>: <i>Country: Colorado, United States |
Website: coldfrontdist.com |
Revenue: $120.1 Million |
Industry: Transportation |
Employees: 201-500 Employees |
Properties: 473 GB (890,775 Files, 51,621 Folders)</i><br />Target victim <b>website</b>: <i>coldfrontdist.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>OFS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34163</link>
<guid>de1fb4320bf96081f57d24d85be4bbb8</guid>
<pubDate>Sun, 26 Jul 2026 17:51:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>OFS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d97682257aed5cc5b6289c2c615c53680d2f148f78189c419e19824816fbf9b4</i><br /><br />Threat actor <b>description</b>: <i>Country: Indiana, United States |
Website: ofs.com |
Revenue: $517.1 Million |
Industry: Furniture,Manufacturing,Transportation |
Employees: 1K - 5K |
Properties: 321 GB (322,742 Files, 18,081 Folders)</i><br />Target victim <b>website</b>: <i>ofs.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>Novum-Energy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34161</link>
<guid>eeb8bd69599e56bdd8f4be95933ff5e2</guid>
<pubDate>Sun, 26 Jul 2026 17:47:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Global Secret Group</b> claims attack for <b>Novum-Energy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a38b9d6ff84951fd42afff241862fa2695ec5ae8bc4407070ac4117cf0cb963c</i><br /><br />Threat actor <b>description</b>: <i>Country: Texas, United States |
Website: novumenergy.com |
Revenue: $966 Million |
Industry: Convenience Stores, Gas Stations & Liquor Stores |
Employees: 51-200 |
Properties: 842 GB (971,325 Files, 117,085 Folders)</i><br />Target victim <b>website</b>: <i>novumenergy.com</i>]]></description>
<category>Global Secret Group</category>
</item>
<item xmlns:dc='ns:1'>
<title>servicebypremier.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34153</link>
<guid>bd439194e7f892d3052e0a47eb0ffbf7</guid>
<pubDate>Sun, 26 Jul 2026 11:27:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>servicebypremier.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d024db90964b14f8e7752209660fcaa180d64795cfa7f0bcb0248d4b97ef4420</i><br /><br />Threat actor <b>description</b>: <i>+1(954) 646-0016 , This local HVAC and Refrigeration company, established in 2007, provides services across South Florida, from Florida City to Port St. Lucie. They specialize in commercial HVAC and refrigeration repairs, including maintenance for A/C and refrigeration equipment. The company prides itself on delivering honest service at reasonable prices, ensuring complete customer satisfaction. Their commitment to integrity and efficiency makes them a trusted choice for businesses in the region. Stolen: --</i><br />Target victim <b>website</b>: <i>servicebypremier.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Analog-Devices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34152</link>
<guid>4b1e14f32e85dc7b48a2ef9bb1cac0a4</guid>
<pubDate>Sun, 26 Jul 2026 10:26:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Analog-Devices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf88362d79a21a2dfd0e034116c765e0f82d704bc8de7c1768f3a3dfd42111e5</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $12.7B

DATA SUMMARY:
570K~ records containing: customer PII and addresses.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Atlanta</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34150</link>
<guid>73e353a345caabdf1e9c46ec7b7edcfe</guid>
<pubDate>Sun, 26 Jul 2026 10:25:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>City-of-Atlanta</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efbfdbba6778dd5ba9748778db65799de7a2b1a157a5f4e59d03b5f27a0eb632</i><br /><br />Threat actor <b>description</b>: <i>DATA SUMMARY:
3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.</i><br />Target victim <b>website</b>: <i>atlantaga.gov</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Houston</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34149</link>
<guid>1f42e9148d92052e09e08f8874979d12</guid>
<pubDate>Sun, 26 Jul 2026 10:25:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>City-of-Houston</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03a66f7f7443b3a53497ea67e07d1082e2804eacd6e7efe3b8b03ed00858ec54</i><br /><br />Threat actor <b>description</b>: <i>DATA SUMMARY:
6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.</i><br />Target victim <b>website</b>: <i>houstontx.gov</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>Viavi-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34148</link>
<guid>e1f27a3eba8e89570965166a129933ec</guid>
<pubDate>Sun, 26 Jul 2026 10:25:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Viavi-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21e395714231bae4659e36b87982c15e32d3655a146672e7509afb97d92a08bf</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $1B

DATA SUMMARY:
430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>District-of-Columbia-Public-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34146</link>
<guid>a6cd8b85105e31ee5647b65a973f3205</guid>
<pubDate>Sun, 26 Jul 2026 10:24:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>District-of-Columbia-Public-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44e29aaf54054f0f6a683745cfe3550dbefd24e23579caf138f8f70299af9f01</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] District of Columbia Public Schools (DCPS) is a public school district serving Washington, D.C., USA. It operates as the primary government-run K-12 educational system for the nation's capital, overseeing dozens of schools, thousands of students, and a large workforce of educators and administrators. DCPS falls under the education sector and is governed by the D.C. government, focusing on curriculum development, student achievement, and community engagement.</i><br />Target victim <b>website</b>: <i>dcps.dc.gov</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>Frontier-Airlines</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34144</link>
<guid>22faad819c7d2f9739083b503674694e</guid>
<pubDate>Sun, 26 Jul 2026 10:23:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Frontier-Airlines</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49b241a365f047f3b068709c2309b36bef7c2589073173cd822172f21914ccc3</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $1.5B

DATA SUMMARY:
2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>TaylorMade--Sun-Day-Red-golf</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34143</link>
<guid>7c7b9ebf8078f2004a859430d599a622</guid>
<pubDate>Sun, 26 Jul 2026 10:23:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>TaylorMade--Sun-Day-Red-golf</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e4b35d6dbbe98f31202de3ec06137cb3e9eee6447f7a2cd8d8b9b907bf5fd95</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $1.5B

DATA SUMMARY:
2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial/account information, internal notes, attachments, and AI support chat transcripts.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allstate</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34142</link>
<guid>33807476351b4d1295b34aa9dce30273</guid>
<pubDate>Sun, 26 Jul 2026 10:23:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Allstate</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>795af2f1b114280ad1b408cf343c02b09d7bfbbb3c7874bdcaa15b2fb3e1f6f5</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $67B

DATA SUMMARY:
657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>Microsoft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34141</link>
<guid>4b9ba87e0fa64737feea24fe89169f3e</guid>
<pubDate>Sun, 26 Jul 2026 10:22:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ExfilSquad</b> claims attack for <b>Microsoft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11da10ed14c5760cf1b3dad7b5da15fb1517cc33ae8955ac5657c63b19f02ce5</i><br /><br />Threat actor <b>description</b>: <i>Revenue: $318B

DATA SUMMARY:
8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ExfilSquad</category>
</item>
<item xmlns:dc='ns:1'>
<title>healthlawadvocates.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34135</link>
<guid>96c38b959c1e40beeb302b9ca2edbfc2</guid>
<pubDate>Sun, 26 Jul 2026 01:56:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>healthlawadvocates.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a04fcb728d2c5e75d2d6eeead53346cc7e0fb2bbe6386bedfcbb3857456228f0</i><br /><br />Threat actor <b>description</b>: <i>Health Law Advocates (HLA), an American non-profit, public interest law firm based in Boston, Massachusetts. Founded in 1996, HLA provides free (pro bono) legal representation to low-income residents and vulnerable populations who face barriers to accessing or paying for healthcare.</i><br />Target victim <b>website</b>: <i>healthlawadvocates.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jubilee-Jobs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34128</link>
<guid>62b13042064da04e84da9adb4af5c341</guid>
<pubDate>Sat, 25 Jul 2026 15:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jubilee-Jobs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f5aa0c41eede8d8a908fb1a12a951d58cdb1cd6f6372efb016175d5547b41f0</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Myers-Y-Cooper</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34130</link>
<guid>f2fedf501c8f8271e520e3301cc25605</guid>
<pubDate>Sat, 25 Jul 2026 15:51:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Myers-Y-Cooper</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa2c4c755afacdeab58da00873788bc64f4ed2ba235af5a2e0be21c323313832</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thermalex-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34133</link>
<guid>c6bc115044e002e815f108534568bb90</guid>
<pubDate>Sat, 25 Jul 2026 13:54:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Thermalex-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2f32a6663c0bf84cbcc6207e29c4f471191b2d3332f6af03262ab642b3fc2f7</i><br /><br />Threat actor <b>description</b>: <i>Thermalex specializes in aluminum extrusion solutions, offering high-efficiency and corrosion-resistant products since 1985. Based in Montgomery, Alabama, the company serves various industries including HVAC, automotive, battery cooling, and industrial applications. With advanced manufacturing systems and a commitment to quality, Thermalex is recognized as a global leader in the aluminum extrusion industry. Their expertise includes the fabrication of microchannel tubes and complex extrusions tailored to meet diverse client needs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Guntert--Zimmerman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34125</link>
<guid>6ca757657eb93d1f04d87b4de35f4a7e</guid>
<pubDate>Sat, 25 Jul 2026 13:54:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Guntert--Zimmerman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>baf931df301f6c194339cfb1bb62aaacc13c3bc0b86875ca9d27714a195cee49</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AA-Safety</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34131</link>
<guid>0f8409da923cef50541f7df4e6f8450d</guid>
<pubDate>Sat, 25 Jul 2026 13:21:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>AA-Safety</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f736ee0ed6b5c010f057b74e70980b829602fbb28e52f67d9a35c9306ceea0a</i><br /><br />Threat actor <b>description</b>: <i>Traffic Control and Road Safety Services.</i><br />Target victim <b>website</b>: <i>aasafetyinc.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>Principle-Diagnostics-Laboratory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34127</link>
<guid>de0d969fa05ce77bb4f5d11b23f0c2fd</guid>
<pubDate>Sat, 25 Jul 2026 11:30:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Principle-Diagnostics-Laboratory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4816fe0996a7ae691e40388933347443945a82d19d188fc9e8b5f923fb299500</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.principlediagnostics.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yourway-Transportation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34126</link>
<guid>c1537c9ed39baee3476c6fdd666b5fd8</guid>
<pubDate>Sat, 25 Jul 2026 11:28:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>Yourway-Transportation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>495fbb91fd44317bdea4a6d05ae021593228f9681733d063f8ffa2b707423b1f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Yourway Transportation is a US-based specialty transportation and logistics company operating primarily in the pharmaceutical and life sciences industries. It provides temperature-controlled, time-sensitive courier and freight services, ensuring compliant transport of clinical trial materials, biological samples, and sensitive cargo. The company serves biotech, pharmaceutical, and healthcare clients across North America and globally.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>GOP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34121</link>
<guid>fb1dc1367f429a50b497eb473bb0d23e</guid>
<pubDate>Fri, 24 Jul 2026 22:59:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>GOP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ed01e2b03b09da95a1c448bb593c6064ca72137a5b65c7fdaf13037337a3f52</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.gopltd.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>upland.k12.ca.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34118</link>
<guid>b69719d0f5c4234e6be19ff63d7f0ff5</guid>
<pubDate>Fri, 24 Jul 2026 21:59:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>upland.k12.ca.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a651450e0f9d1878778d8af99efcbfb13e3236134113c32d8413b725d567a489</i><br /><br />Threat actor <b>description</b>: <i>The district provides comprehensive education from kindergarten through twelfth grade and operates 14 schools, including elementary, junior high, and high …</i><br />Target victim <b>website</b>: <i>upland.k12.ca.us</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>gvsurgicalarts.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34117</link>
<guid>39a3bf984fee57c76835745e7e59a062</guid>
<pubDate>Fri, 24 Jul 2026 21:59:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>gvsurgicalarts.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7bcca3b610fd3b590c8d3082c8b366089b01c38d40eec6b1433f4fe1ec5eaa2f</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2004 by Dr. Brian R. Chisdak, the practice has grown into one of Montana's leading surgical centers and …</i><br />Target victim <b>website</b>: <i>gvsurgicalarts.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brooklyn-Defender-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34115</link>
<guid>f6734cf968bed6b1fb2bd1b6166becf0</guid>
<pubDate>Fri, 24 Jul 2026 16:56:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Brooklyn-Defender-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c42d9fb2d8bd391cef2e016363099649bc386d6454e2325f31fb3c9b4bb8e0c</i><br /><br />Threat actor <b>description</b>: <i>Brooklyn Defender Services is a public defense office providing free, client-centered representation and advocacy in and out of court, protecting people from loss of freedom, family separation, and serious legal harm by unjust, racist systems.</i><br />Target victim <b>website</b>: <i>www.bds.org</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stryker</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34110</link>
<guid>aa68e93925a4e69aa7e3950feb5fbbda</guid>
<pubDate>Fri, 24 Jul 2026 12:59:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Stryker</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1bcab8a3f0c3736166a5056081ea9d39e39fb7d1ed7611614612b660ffc47888</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metropolitan-Construction-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34112</link>
<guid>ffdd909cdb7fa6ea26c328488c4b8b76</guid>
<pubDate>Fri, 24 Jul 2026 12:33:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Metropolitan-Construction-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a29f698743fbe2249e69e844ac730de77f17ce9647a7233cf38c060713be514</i><br /><br />Threat actor <b>description</b>: <i>Leading commercial roofing company based in New York City</i><br />Target victim <b>website</b>: <i>metropolitanroof.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kean-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34108</link>
<guid>8287ab1732631d0908d6ec134bd2592b</guid>
<pubDate>Fri, 24 Jul 2026 10:36:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kean-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d811af15e0ae8bd4b12fe27072a99642b07e13421b42701c46bb55e1c64373a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.kean.edu</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Highline-Community-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34107</link>
<guid>8552de0210a22e464a92e2d550533910</guid>
<pubDate>Fri, 24 Jul 2026 10:36:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Highline-Community-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c9ff707df38a3f97506900c2d35da7f24e4d767491001e96a0b635a2033dd9c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.highline.edu</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Restaurant-Depot</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34101</link>
<guid>4477a406f8c4020079fcf5cfeaf9fe96</guid>
<pubDate>Thu, 23 Jul 2026 20:29:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Restaurant-Depot</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>387d1433de3b62214cb07d849f0ab100aade4ac7130e8762115f524c73f4bbe5</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.restaurantdepot.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>cabincreekhealth.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34099</link>
<guid>dc3ee4a3c1e198876fa8db57d3e5a7bd</guid>
<pubDate>Thu, 23 Jul 2026 20:26:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cabincreekhealth.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72113d390edb5dccf58c3239879e181ed201d5678dc88d69695d17e3432b47c7</i><br /><br />Threat actor <b>description</b>: <i>Cabin Creek Health Systems (CCHS), a non-profit community healthcare organization founded in 1973 by coal miners in West Virginia. It operates as a Federally Qualified Health Center (FQHC), providing comprehensive medical services to rural and urban residents across Kanawha County</i><br />Target victim <b>website</b>: <i>cabincreekhealth.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>T-Simon-Jewelers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34098</link>
<guid>fd2fe825d8c4b42755883f2d99966c17</guid>
<pubDate>Thu, 23 Jul 2026 18:50:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>T-Simon-Jewelers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>452879b4112ca3a5ad1497c0863ab5d606511612d91f812238e66ad43e1e8753</i><br /><br />Threat actor <b>description</b>: <i>T. Simon Jewelers is Door County's premier jeweler, known for its extensive collection of diamonds and gemstones, offering both traditional and contemporary designs. The store features exclusive designer lines and custom pieces crafted by the owner, catering to clients looking for unique jewelry experiences. Their services include custom jewelry design, repairs, and personalized consultations to b ring clients' visions to life. With a focus on craftsmanship and attention to detail, T. Simon Jewelers aims to provide exceptional quality and service to all jewelry enthusiasts.</i><br />Target victim <b>website</b>: <i>www.tsimonjewelers.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bulwark-Exterminating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34096</link>
<guid>63a6cfc9c917b4133ce3f8d000cb9a8e</guid>
<pubDate>Thu, 23 Jul 2026 16:26:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Bulwark-Exterminating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f308c1713d12f17e13786b6aebf208d891d6b13e1671f4e95127725f7b572b1f</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>MK-Jewelry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34092</link>
<guid>86773a39ba758c892d3fa03b2e3cf711</guid>
<pubDate>Thu, 23 Jul 2026 15:14:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>MK-Jewelry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0052d041aaec339636b49ff84c3419bc257464550af24e4082fd3cff9da929b</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/mk-jewelry-inc/346982894 MK Jewelry, Inc. is a fine jewelry manufacturing and distribution company based in Midtown Manhattan, established in 1986. They specialize in producing and supplying a wide range of jewelry, including bridal and bridge collections. The company serves both independent and major retailers across the US, Canada, and the Caribbean. As a premier industry supplier, they offer extensive private label and branded diamond jewelry lines</i><br />Target victim <b>website</b>: <i>mkjewel.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Title-Resources</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34085</link>
<guid>4bfc7637274e584b7752e3fd7bd275e7</guid>
<pubDate>Thu, 23 Jul 2026 15:12:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Title-Resources</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df94ebfa57ab7b0849d190f9eb7f87b46582a5483038eac1928d753e3b7a8b5b</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/title-resources-llc/1137777688 Title Resources is a locally owned title company based in Denton, Texas, founded in 1989. They specialize in real estate transactions, comprehensive title searches, and title insurance across North Texas, including Denton, Dallas, and Collin counties. Their team of fully trained professional title officers thoroughly examines each property to identify and resolve any title issues, ensuring secure and smooth real estate closings</i><br />Target victim <b>website</b>: <i>titleresourcesnt.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henry-Frerk-Sons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34077</link>
<guid>5bcd64be156de0ead98f17c3e8738885</guid>
<pubDate>Thu, 23 Jul 2026 15:09:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Henry-Frerk-Sons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79ce25de7083132bb8a28d69c54bbce0d21ce3ec08d4cfb4d629813f8ea0c37d</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/henry-frerk-sons-inc/44255454 Henry Frerk Sons (HFS Materials) is a premier masonry and plaster restoration supplier based in the Chicago region, with over 140 years of history. They specialize in custom matching and blending of historic mortars, concrete, and stone patching materials, alongside offering on-site volumetric ready-mix concrete services. The company provides a comprehensive range of building materials, including natural hydraulic lime, specialized cleaners, sealers, and preblended mortars for both historic preservation and new construction projects</i><br />Target victim <b>website</b>: <i>hfsmaterials.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMRTR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34076</link>
<guid>6dcfff2b73388f6307994658463a9341</guid>
<pubDate>Thu, 23 Jul 2026 15:09:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>SMRTR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39784c491c6c19ad96b2c1a4f9d54731770163a120119a4a63b2096489a5bc4b</i><br /><br />Threat actor <b>description</b>: <i>***.com rocketreach.co/s4i-systems-profile_b5c16403f42e08fa SMRTR is a document and workflow automation company with over 20 years of experience, specializing in ERP-driven industries such as manufacturing, food & beverage, and distribution. They provide cloud-based solutions for document management, accounts payable automation, and supplier regulatory compliance. Operating as a remote-first, environmentally conscious organization, SMRTR focuses on seamless integration with existing financial and operational systems to improve efficiency and reduce manual tasks.</i><br />Target victim <b>website</b>: <i>smrtrsolutions.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Affinity-Designs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34074</link>
<guid>f3498e568e0bb45515779d6bd47e20f4</guid>
<pubDate>Thu, 23 Jul 2026 15:08:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Affinity-Designs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>305444d78643ebfdeb033042be2a36469a0efae7b606fd800d8c42088f2146f8</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/affinity-designs/374939106 Affinity Designs LLC is a fine jewelry wholesaler and manufacturer based in New York, specializing in the design, production, and marketing of elegant gemstone jewelry collections. The company offers a wide range of high-quality pieces crafted in 925 Sterling Silver and 10K, 14K, or 18K gold. Led by CEO Meir Sanandaji, who brings over 40 years of industry experience, the business caters to retailers seeking premium, trend-forward jewelry lines</i><br />Target victim <b>website</b>: <i>affinitydesignsllc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Velum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34072</link>
<guid>6a30bf1cd3a822b858025a0b1f861330</guid>
<pubDate>Thu, 23 Jul 2026 15:07:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Velum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68aa855130b77ed9ccc53c80bc2a5b2d4076379454f4d22f7d90f6fa9195da97</i><br /><br />Threat actor <b>description</b>: <i>***.biz zoominfo.com/c/velum-inc/372599932 We are making some files publicly available. We have hundreds of gigabytes of your files, including database projects, client contracts, personal data, and documents. If you do not want to face the consequences of a data breach, please contact us; otherwise, everything will be published. VELUM is a French manufacturer of professional lighting solutions based in Bischoffsheim, Alsace, operating since 1975. The company specializes in designing, developing, and manufacturing custom LED lighting fixtures for both indoor and outdoor environments. As a family-owned business, VELUM provides comprehensive support, including lighting studies, technical advice, and tailored solutions for professionals across various sectors</i><br />Target victim <b>website</b>: <i>velum.biz</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Optiforms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34068</link>
<guid>dd6096012cbf345790335c13d8898490</guid>
<pubDate>Thu, 23 Jul 2026 15:06:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Optiforms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb420f89a15de1d221de3b1ebf88f415264bd65e0440c437b1087cd33bb94da5</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/optiforms-inc/67340558 Optiforms, Inc. is a precision manufacturing company based in Temecula, California, specializing in electroforming, CNC machining, and enhanced surface finishes. Founded in 1984, the company produces custom metal components and high-performance optical coatings for demanding applications. They primarily serve the aerospace, defense, medical, semiconductor, and specialty lighting sectors with advanced, vertically integrated manufacturing solutions.</i><br />Target victim <b>website</b>: <i>optiforms.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>MatTek</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34067</link>
<guid>9527f862774325cefd158e74c3045c1e</guid>
<pubDate>Thu, 23 Jul 2026 15:05:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>MatTek</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c5b6fdc6abe9e9dcd2e3938bd280baee25f4904d6355ed53c46fa27fcfb7e93</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/mattek-corp/109184324 MatTek Corporation is a pioneering biotechnology company founded in 1985 and headquartered in Ashland, Massachusetts, specializing in the development of innovative in vitro 3D reconstructed human tissue models. They produce advanced microtissues and cell culture products that are widely used by researchers to accelerate drug development, conduct toxicity testing, and replace traditional animal testing. Originally an independent leader in tissue engineering, the company was recently acquired by the global life science supplier Sartorius and now operates as a key part of their advanced biological models portfolio</i><br />Target victim <b>website</b>: <i>mattek.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conecsus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34066</link>
<guid>b6ef5d5380d88cee64653c50b098b245</guid>
<pubDate>Thu, 23 Jul 2026 15:05:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Conecsus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b346e22afe82870edcb93048b188019c5d9f8b3ec0664de272877f1b31cb231f</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/conecsus-llc/358895914 Conecsus LLC is a global "green" metals recycler and refiner founded in 1980 and headquartered in Terrell, Texas. The company specializes in processing complex industrial residues and electronic wastes, particularly those containing tin, lead, silver, gold, and copper, such as SMT solder and solder paste wastes. Recognized as the largest secondary tin-lead recycler in the Western Hemisphere, Conecsus converts these materials into reusable metal products using state-of-the-art technology.</i><br />Target victim <b>website</b>: <i>conecsusllc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>royalchain.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34059</link>
<guid>47c8176547772f53c4d7144baaf843c4</guid>
<pubDate>Thu, 23 Jul 2026 11:03:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>royalchain.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3015840f305bc2fe8d3939a8c7a92c1a941c56ed35b6ea7a0f7e8e78fa113c8</i><br /><br />Threat actor <b>description</b>: <i>Royal Chain Group: Jewelry Business with Infrastructure for Bypass Operations PROLOGUE The archive f...</i><br />Target victim <b>website</b>: <i>royalchain.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indigo-Energy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34050</link>
<guid>06d2cbe86d50e46350c9cfe53a7e1356</guid>
<pubDate>Thu, 23 Jul 2026 07:58:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>Indigo-Energy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83708a1814c76e9c6405d677b85f4afdb38647c0af69d1c147112f0924976b2a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>indigoenergy.com</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>P--A-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34037</link>
<guid>9adf3fead0348d61f962f6b9e0d8644b</guid>
<pubDate>Wed, 22 Jul 2026 19:52:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>P--A-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c4b09a094f022753ceb1cecff94524f8adc06cf856206641a7e8a793b49b18f</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zuni-Shopping-Center-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34045</link>
<guid>0d970b78ccd6d4614e74903eea91ca55</guid>
<pubDate>Wed, 22 Jul 2026 19:23:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Zuni-Shopping-Center-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f5902376e4a9c9e0ffc4bfe9def54ad9816c9dba84d3b76f5d1ac309c304fbf</i><br /><br />Threat actor <b>description</b>: <i>A family-owned commercial corporation incorporated in New Mexico, USA, that owns and operates Halona Plaza, a multi-purpose retail and tourism hub in the heart of the Zuni Pueblo reservation.The business dates back to 1910 and was formally incorporated as Zuni Shopping Center, Inc. in 1961. Over the decades, the enterprise has expanded significantly to serve as a vital economic and community pillar, ensuring the remote region has access to high-quality goods and services.Today, the corporation manages several distinct business units on its property:Halona Marketplace: A modern, full-service grocery supermarket providing the local community with fresh produce, quality meats, bakery items, and household essentials.Halona Plaza Restaurant: A popular local dining spot famous in the region for its signature Halona Chicken, hot fast-food options, and specialty burgers.The Inn at Halona: A historic, southwestern-style Bed &amp; Breakfast featuring 8 custom-designed guest rooms. It stands as the premier lodging destination for tourists, tribal guests, and business travelers visiting the Zuni Pueblo.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>PinnPACK</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34038</link>
<guid>c5944749c722d4cf1dc5c0528c9b59ab</guid>
<pubDate>Wed, 22 Jul 2026 18:56:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>PinnPACK</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b98f411a30207a768b5be51c37759341d5cb0a9aff77a69783b52a386108c84</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>St.-Francis-Xavier-Catholic-School-System</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34039</link>
<guid>569946dc65c3ff896c21399ba5384e0f</guid>
<pubDate>Wed, 22 Jul 2026 18:56:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>St.-Francis-Xavier-Catholic-School-System</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b85bd502fb6bbdba82a763704892105af72071dd8d32abfe63c1eee2364916d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Salida-Union-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34042</link>
<guid>0de95629f8faacd3fa1695c6bdb5e019</guid>
<pubDate>Wed, 22 Jul 2026 18:56:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Salida-Union-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c18a02583a8cd9712ba7262209313aa1a16e41e6c4297699d167b76508d129ae</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cpcg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34036</link>
<guid>c187a286b7bb1ed4b50c1fac266bfc78</guid>
<pubDate>Wed, 22 Jul 2026 16:08:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cpcg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25ed7ce296c776c102d91805467f391e00372e62e473fefbc13cddd2bb2be815</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cpcgr.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infina-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34034</link>
<guid>fafdf1720f4df1d41c6eacbd2429a06b</guid>
<pubDate>Wed, 22 Jul 2026 16:05:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Infina-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9083dbed5d82fe39ead2c6721ad630af13002575dd38d7acce3499fc7ddfeac</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.infinahealth.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kruse-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34030</link>
<guid>d67b0a628cc9727b29afb0cee4c77501</guid>
<pubDate>Wed, 22 Jul 2026 13:53:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kruse-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4034be8f8e774076fef569044e101a3747198b45b496964c4d14bef04d28a486</i><br /><br />Threat actor <b>description</b>: <i>Kruse Construction is a mechanical contractor with over 50 years of experience in the petroleum
and petrochemical industry, specializing in the construction and maintenance of liquid petrole
um truck, rail, and pipeline terminals. The company also provides services for bulk plants, pip
eline pump stations, lube oil plants, and underground pipelines.

We will upload 10gb corporate data soon. Employee information (passports, lots of DLs), project
s, contracts, financials, customer files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pelli-Clarke-Pelli-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34028</link>
<guid>b12d76b26667a03f5c8bc14f650626bc</guid>
<pubDate>Wed, 22 Jul 2026 13:20:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Pelli-Clarke-Pelli-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>784e1f1cc93c2fdbb18cc23e7b956dea134bb5b3ee861e9481f36e319bba570e</i><br /><br />Threat actor <b>description</b>: <i>Architecture and Planning Stolen data: 45 GB.</i><br />Target victim <b>website</b>: <i>www.pcparch.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Koshkaryan-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34027</link>
<guid>24826fc186de435324b417a145c1def8</guid>
<pubDate>Wed, 22 Jul 2026 09:01:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Koshkaryan-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e33ef72cbff602cb72e291e18aa427c108c55da1c724d9553756154581e7087a</i><br /><br />Threat actor <b>description</b>: <i>Koshkaryan Law Group is a legal firm specializing in personal injury and criminal defense cases. They prioritize client service and provide personalized attention to ensure favorable outcomes for their clients. The firm offers free initial consultations and is dedicated to keeping clients informed about their legal options. With a strong track record of recovering over $138 million for clients, they aim to advocate vigorously on behalf of those they represent.</i><br />Target victim <b>website</b>: <i>koshlaw.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>issvc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34026</link>
<guid>f469d652f14a20c7e37428beecda9654</guid>
<pubDate>Wed, 22 Jul 2026 08:58:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>issvc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59bef726bcc7780c66f802ae1d440bfb3313e4f3f46639bb2a6e4623c9361ecc</i><br /><br />Threat actor <b>description</b>: <i>issvc.com

Official Notice to Management and Stakeholders

The time window has expired. Exactly 24 hours remain until the final deadline. If an agreement is not reached by the end of this period, the complete confidential dataset totaling 262 GB will be published into the public domain.

Compromised…</i><br />Target victim <b>website</b>: <i>issvc.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evergreen-Title</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34023</link>
<guid>961eb5387637cb09f5565841f9f37619</guid>
<pubDate>Tue, 21 Jul 2026 20:16:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Evergreen-Title</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7e6a154f5dcecffdc2fbb532df211c60bc071c453ec5ea097a4483eba02ea62</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.evergreentitlecompany.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tax-MT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34022</link>
<guid>6e26ead8e11c36ab6aeb096c3b162f42</guid>
<pubDate>Tue, 21 Jul 2026 20:15:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Tax-MT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b83552fa529bb6a4f8f51bfc3e5a6ecd04eed3172db847a3242b1e5b8933ad9a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.tax-mt.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kreysler--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34021</link>
<guid>4e1da5211a7142efd9897c4ae30ec9ad</guid>
<pubDate>Tue, 21 Jul 2026 18:10:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kreysler--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f96b2436e36426d98a17231ad51d9b8a85055e8105c0b3f363dc0937979c8f5</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kreysler.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>argonautms.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34019</link>
<guid>f9eca5038949eae460da07906408a092</guid>
<pubDate>Tue, 21 Jul 2026 17:57:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>argonautms.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>019af3bb25413f3b5e7eb3188c6a30ba49ec27a731fcd059c321c3fc9bb4075f</i><br /><br />Threat actor <b>description</b>: <i>Target Organization: argonautms.com (Argonaut Manufacturing Services)

Status: Unauthorized Access & Data Exfiltration Confirmed

Volume: 295 GB of Critical Corporate, Technical & Operational Data

Countdown: 48 Hours to establish contact before public release.
Executive Summary

The internal infras…</i><br />Target victim <b>website</b>: <i>argonautms.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>One-Community-FCU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34018</link>
<guid>4157f23167c3094e65f8465be8f65f1e</guid>
<pubDate>Tue, 21 Jul 2026 16:00:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>One-Community-FCU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db29f6417c46aebc3a80a9fd23f1d08b6a658223304e41893044038bb550cbb6</i><br /><br />Threat actor <b>description</b>: <i>One Community FCU offers a range of financial services including loans, savings accounts, and online banking solutions. Their products cater to individuals seeking personal, auto, mortgage, and credit card loans, as well as those interested in savings and checking accounts. In this release we provide a portion of the documentation we obtained from the company: databases, internal documentation, client data, client documents, client financial information (including statements that clients supplied to One Community FCU from other banks), documentation on delinquent payments. Additionally, the release contains reports and documentation produced by TraceSecurity LLC (6300 Corporate Blvd, Suite 200, Baton Rouge, LA 70809). TraceSecurity LLC handled security matters for One Community FCU. In our view, that work was performed very poorly. These shortcomings contributed to the data breach, though they were not the sole cause, so we believe it is necessary to publish them.</i><br />Target victim <b>website</b>: <i>onecommunityfcu.org</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Finer--Finer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=34011</link>
<guid>d3b1db304152af564f2675ca8e5ac45f</guid>
<pubDate>Tue, 21 Jul 2026 11:53:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Finer--Finer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0993c383473e4566471ac631e38ac2cd5f7ca65111b1c73e894f4d558f70f38</i><br /><br />Threat actor <b>description</b>: <i>Finer & Finer CPA is a leading accounting firm based in Randolph, MA, offering a wide range of 
services including tax preparation, personal financial planning, and business accounting. They 
cater to business owners, executives, and independent professionals, providing personalized and
professional attention to each client.

We will upload 50gb corporate data soon. Employee information (personal docs and health informa
tion, tests and so on), contracts, client information and other internal information.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Caterpillar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33992</link>
<guid>485b551f4f68d315b9a0856bd3c92195</guid>
<pubDate>Mon, 20 Jul 2026 17:56:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Caterpillar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c3acb81bd03fd45eeb13a05301c32aab7422e537415db5967d8f5c9be54cf29</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Caterpillar Inc. is an American multinational corporation headquartered in Irving, Texas. It is the world's leading manufacturer of construction and mining equipment, diesel and natural gas engines, industrial gas turbines, and diesel-electric locomotives. Operating in over 190 countries, Caterpillar serves industries including construction, mining, energy, and transportation through its equipment, financial services, and aftermarket parts divisions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bath-Fitter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33991</link>
<guid>57362b724248d953ff60c2d627e7dafa</guid>
<pubDate>Mon, 20 Jul 2026 15:24:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Bath-Fitter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d117ee8246d9f1708910f5ef5426c67196e89b8a09a93ef943d30bad8fe459bf</i><br /><br />Threat actor <b>description</b>: <i>Employee data breach at a major manufacturing company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fairlife--Coca-Cola</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33990</link>
<guid>0aa009391d33cae0536040843c3f6735</guid>
<pubDate>Mon, 20 Jul 2026 15:23:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Fairlife--Coca-Cola</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a64e64b41b1b5e677254a8398ebdbde60a8683817762217555d155e4e1afee9</i><br /><br />Threat actor <b>description</b>: <i>www.fairlife.com</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>McKeever--Varga--Senko</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33985</link>
<guid>6e62eb1cd9d42ec8bfba3d4624597524</guid>
<pubDate>Mon, 20 Jul 2026 13:53:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>McKeever--Varga--Senko</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec4d64ccc2e2deadfb8362148bab8b58b7a555dc4e773b5b3a8817edd5a80696</i><br /><br />Threat actor <b>description</b>: <i>McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio
r client service and professional guidance. They offer a range of services including informativ
e articles, interactive financial calculators, and links to external resources to assist their 
clients.

We will upload 12gb of corporate data soon. Detailed client internal data, employee personal in
formation, contracts and agreements, confidential files, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LA-Transport</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33984</link>
<guid>eaeab49ac116abe88580249769561a21</guid>
<pubDate>Mon, 20 Jul 2026 13:53:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>LA-Transport</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2dcae2fa7d0ad4bee25fae3812f4c79c5662f91d77d5a75f429019d94d5a8c5</i><br /><br />Threat actor <b>description</b>: <i>L & A Transport is a reputable trucking company with over 50 years of experience in providing a
wide range of shipping services, including international shipping, white glove handling, and l
ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads,
less than container truckloads, and offer warehousing services in Union, NJ.

We will upload corporate data soon. Detailed financials, employee information (DLs and so on), 
contracts, client information, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>wikoff.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33981</link>
<guid>2029ecd2552569728dc1a9825542fd40</guid>
<pubDate>Mon, 20 Jul 2026 09:26:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>wikoff.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24a6f46d4736406804f0c1af8bae969cef2c537d796aa679668655b14497d55a</i><br /><br />Threat actor <b>description</b>: <i>[PUBLIC DISCLOSURE]

Target: Wikoff Color Corporation (wikoff.com)
Data Volume: 650 GB
Status: Full Compromise Confirmed

We are officially confirming that the entire internal infrastructure of Wikoff Color Corporation—ranging from Board of Directors financial reports and proprietary R&D formulas…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/wikoff-color-corp/76070928</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>PPK</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33971</link>
<guid>d8e917c6af68b61ef2b3ba045c3436f4</guid>
<pubDate>Sun, 19 Jul 2026 18:10:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PPK</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dfbd60cbb77cf98f70d557e689649cbc23b439e0e8ab1eec0632a9666ceb6ba</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.uniteppk.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Synergy-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33969</link>
<guid>2b611b37e4ce4ae0a2c5070494e06aec</guid>
<pubDate>Sun, 19 Jul 2026 18:09:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Synergy-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10dfcac924751b1fc7237c6ef25eac0a89454d0acf54b4db66ae2fb4c94e1de9</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.synergy-trt.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Associated-Theatrical-Contractors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33962</link>
<guid>e20dd8dbc9d9a3e0f0396c27a38df6aa</guid>
<pubDate>Sun, 19 Jul 2026 17:48:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Associated-Theatrical-Contractors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>904b51cbe56445c895b96c1e0f5401d71343ce89e72f5d9bf35d495479993f6b</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.miatech.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33961</link>
<guid>cc1293b4eae66aa4fa2960e6ccb8ae96</guid>
<pubDate>Sun, 19 Jul 2026 12:22:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackout</b> claims attack for <b>www.miatech.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59fd90fb9b2c1f7df64f30dda64aed733ec58a6c4235d670a143adb205dced81</i><br /><br />Threat actor <b>description</b>: <i>Miatech is a US-based company that provides passenger travel services for...</i><br />Target victim <b>website</b>: <i>www.miatech.net</i>]]></description>
<category>blackout</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-Ambulance-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33958</link>
<guid>a854d36a4afe77df29f4c42eb35af078</guid>
<pubDate>Sun, 19 Jul 2026 09:06:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-Ambulance-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4fdde808bb0400c832794396692520adc0053e869b2d53e79a549200a17859a8</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cityambu.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heartland-Catfish</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33947</link>
<guid>fcd8fefbf2b5dd996ad37e6ffc99234a</guid>
<pubDate>Sat, 18 Jul 2026 14:00:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Heartland-Catfish</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a66415e4d0277a800efd5706a657a378b4462441530f56ea2518dcccb5417ce5</i><br /><br />Threat actor <b>description</b>: <i>Agriculture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Salina-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33948</link>
<guid>f8decd07ac3bcdb30bc816319f3287de</guid>
<pubDate>Sat, 18 Jul 2026 14:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Salina-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b209d2a8afcea89a59e6d23375bcf711019e57b1fd1dcf5cd674907434af06e2</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Martha-Catholic-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33949</link>
<guid>36b4d177a19e927d87aee12201d43153</guid>
<pubDate>Sat, 18 Jul 2026 13:59:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>St-Martha-Catholic-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d6a60551f8788d230f599c135c4616147043a30633e92ad9207ed348ccb1bca5</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Nueva-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33954</link>
<guid>b4a1dbf2668db2f4e1e14a6bd25e28b1</guid>
<pubDate>Sat, 18 Jul 2026 13:34:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Nueva-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78268e1df419868ffa522319222acee7e2cffe32bd5132d637df76e1d96fc955</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.nuevaschool.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>KLD-Labs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33952</link>
<guid>39d2e7e346cf746bb1e11dca3ece9b8e</guid>
<pubDate>Sat, 18 Jul 2026 11:38:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>KLD-Labs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66fb9b07ef5fede5615a3c95ad8d1f2be6ba3429e111a23800f3b04c30803306</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.kldlabs.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AK-Preparedness</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33946</link>
<guid>070151fbdb4fa874242f4d03fe75c57c</guid>
<pubDate>Sat, 18 Jul 2026 10:38:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AK-Preparedness</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e38844769d614b8b5c6bb425c0f9c9d02ac3e82b0e009000af0bedaebad219e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.akpreparedness.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>tws-tac.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33945</link>
<guid>a1677f67c9e0342b5dd4dd69762a0c43</guid>
<pubDate>Sat, 18 Jul 2026 09:58:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>tws-tac.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc2d275d7f98c9c7e5aeadb3fc46896a291dec81d705ee600905cbfef432e3f6</i><br /><br />Threat actor <b>description</b>: <i>While ownership has changed over the years, the company has remained locally owned for over 65 years and family-owned for almost 40 years. The company is proud of the company's history and look forward to the future as the company continue to serv</i><br />Target victim <b>website</b>: <i>tws-tac.net</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>VP-Nurseries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33938</link>
<guid>2bd19fb4009ffc10edd430e6191f8421</guid>
<pubDate>Sat, 18 Jul 2026 02:00:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>VP-Nurseries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcbba7ccd789a001e7f3217cd377d8526d6a3bf14ae93ed62a5b47f31f942b51</i><br /><br />Threat actor <b>description</b>: <i>V&P Nurseries is an Arizona-based wholesale grower specializing in drought-tolerant, subtropical, and desert-adapted plants for landscapes across the Southwest. Established in 1978, the company operates production facilities and a tissue culture lab focused on sustainable, water-conservative horticulture. For more information, </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Powder-River-Heating--Air-Conditioning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33936</link>
<guid>72b8ade48bd53ac615b67923ece11593</guid>
<pubDate>Fri, 17 Jul 2026 23:54:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Powder-River-Heating--Air-Conditioning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e954a3775456241237558d9adacd8aa1c02b177db1e910d587de12f2c48bf71</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Military-Sealift-Command</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33935</link>
<guid>0f81bcb0a7f4fa5f08a42d60b4b119c3</guid>
<pubDate>Fri, 17 Jul 2026 19:20:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Military-Sealift-Command</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edbeb0a88e572bf046f349675f18903a7edb502c998a3bc6a845bb81cc38d16d</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/military-sealift-command/149045906 We attempted to contact the managers regarding the leaked documents (ITAR documentation, personal data, cargo manifests—including ESSM shipments—vessel blueprints, and both disclosed and undisclosed information)/ We managed to reach only Jennifer Miller , Todd Phillips and Dain Costlow However, these individuals dismissed the entire matter as a joke, ignoring all warnings about leaks and the importance of internal documents, and refused to provide any contact details for anyone authorized to handle such issues or to pass the information on to management, despite the availability of conclusive evidence. If you do not get in touch in the near future, the data will be published.</i><br />Target victim <b>website</b>: <i>sealiftcommand.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advantage-Home-Health-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33934</link>
<guid>5650c82d95b90731ab2d2bc4016e036d</guid>
<pubDate>Fri, 17 Jul 2026 19:19:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Advantage-Home-Health-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb30d4414d09ec1d1ac8c75fa64d8a25233a1962b2a1152a1393679c85a9d558</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/advantage-home-health-care-inc/357944466 Advantage Home Health Care, a leading Indiana-owned provider of in-home care services with over 30 years of experience.The company operates multiple locations across Indiana, serving dozens of counties with post-procedure recovery and long-term home assistance.</i><br />Target victim <b>website</b>: <i>advantagehhc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Paragon-Store-Fixtures</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33929</link>
<guid>614484a1c3d62905498f756ee2a85010</guid>
<pubDate>Fri, 17 Jul 2026 14:25:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Paragon-Store-Fixtures</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90aed479906cd30c1e80391fe32d17302938dd9c23f71a0088f3cd1b3ab514d4</i><br /><br />Threat actor <b>description</b>: <i>Paragon Store Fixtures specializes in custom display cases, retail fixtures, and interior design elements for luxury stores, beauty salons, offices, restaurants, and entertainment venues. A security breach resulted in the breach of partnership agreements, resulting in the intellectual property of both the company and its clients. Internal design files were exposed, including work completed for clients in the high-end retail sector and luxury brands. Due to the company's negligence, contracts, architectural plans, and confidential design documentation became public. The identities of clients and projects have now been revealed.</i><br />Target victim <b>website</b>: <i>https:paragonstorefixtures.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westcoast-Communication-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33928</link>
<guid>708985cc1d6977124e38b27ee7cba1f2</guid>
<pubDate>Fri, 17 Jul 2026 12:51:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Westcoast-Communication-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55963d14fe98c2be7093172e1526ae139b0784bafbd18c4914a26f5779de0dcd</i><br /><br />Threat actor <b>description</b>: <i>Westcoast Communication Services is a leading expert in low voltage and structured cabling, spe
cializing in voice and data cabling solutions across Florida. They offer a range of services in
cluding network integration, telecommunication networks, and access control systems. 

We will upload 20gb of corporate data soon. Employee personal information (DL, passports, SS ca
rd scans and so on), contracts and agreements, customer info, financials, confidential agreemen
ts, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nesco-Bus-Maintenance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33927</link>
<guid>97a34e8859e946b5313f18f5f5f4c9f6</guid>
<pubDate>Fri, 17 Jul 2026 12:22:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nesco-Bus-Maintenance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e501812c45e3777ba3e1403abddbd45bfb61349ea501805679d578c4b1a379b3</i><br /><br />Threat actor <b>description</b>: <i>Nesco Bus specializes in manufacturing and maintaining a wide range of buses, including school,
childcare, activity, commercial, and specialty buses. With over three decades of experience, t
hey are committed to providing exceptional customer support and ensuring the safety and comfort
of their passengers.

We will upload 26gb of corporate data soon. Employee personal information (DL scans and so on),
contracts and agreements, customer info, payment details and other financial docs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Marketing-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33921</link>
<guid>5f1517b532a2dd760f7d865e4d4146c6</guid>
<pubDate>Fri, 17 Jul 2026 01:30:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Integrated-Marketing-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65591dad417e368111a648eaadf3b1064fa8991ee8c50bc06d557dc0d99caa2f</i><br /><br />Threat actor <b>description</b>: <i>Integrated Marketing Services is a company that operates in the Commercial Printing industry. It employs 20to49 people and has 5Mto10M of revenue. The company is headquartered in Liverpool, New York - Nova Provide tree and samples from stolen data + decrypt sample to the company when its get in touch with support department.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>formasuniversales.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33919</link>
<guid>44485793cae806cfc853649f75b55b2b</guid>
<pubDate>Fri, 17 Jul 2026 00:30:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>krybit</b> claims attack for <b>formasuniversales.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33243546efa87fa192bd3479350b203f87a3b6eed7abfaa64ece0f416be23dd6</i><br /><br />Threat actor <b>description</b>: <i>Formas Universales, S.A. is a Panamanian company founded in 1985, specializing in the production and commercialization o...</i><br />Target victim <b>website</b>: <i>formasuniversales.com</i>]]></description>
<category>krybit</category>
</item>
<item xmlns:dc='ns:1'>
<title>District-of-Columbia-Housing-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33916</link>
<guid>973e871484054975ff69b4d23627e376</guid>
<pubDate>Thu, 16 Jul 2026 23:54:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>District-of-Columbia-Housing-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68418090db7fe758ba14f5cbe334cb1d03380df1ebb549e55fcd083ccf9f5826</i><br /><br />Threat actor <b>description</b>: <i>DC Housing, the organization entrusted with the powers of the District of Columbia Housing Authority, was completely compromised due to its negligence and greed in security, and all confidential information, databases, passports, and personal data of clients were stolen. We offer you 1.6 TB of confidential information, including all data of District residents and large databases.</i><br />Target victim <b>website</b>: <i>dchousing.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dissinger-and-Dissinger-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33915</link>
<guid>09add3fd59925533c1bfa9c3048f5b96</guid>
<pubDate>Thu, 16 Jul 2026 18:57:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>gunra</b> claims attack for <b>Dissinger-and-Dissinger-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56ba75e8a6431a8dedafe76410ad3d393e5c08e3a3817b7f2daf0b038a6ce6e8</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>dissingerlaw.com</i>]]></description>
<category>gunra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Boston-Electric-and-Telephone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33914</link>
<guid>fc8d5986a039ea16ecfd79ac1c20a0b1</guid>
<pubDate>Thu, 16 Jul 2026 18:31:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Boston-Electric-and-Telephone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1039e485c9e8c5aeca386c19a4bb6dd977662fcff32edc62d6a25c1f5cca56a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.betcorp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Andorra-Life</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33910</link>
<guid>b42c89dec51b42acdff36745c8a4109a</guid>
<pubDate>Thu, 16 Jul 2026 17:57:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Andorra-Life</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ad893f1f2584956f211e3c52c6ec59695b307514e560996742817f9328d8e2b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.andorralife.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>radiax.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33908</link>
<guid>bf56d3ff4ea20391eeb73af2dc7e0d07</guid>
<pubDate>Thu, 16 Jul 2026 17:22:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>radiax.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f35120565ea9ecf95ee49c25919cadc4060cf6d4106303202a17a56cfff0ca0</i><br /><br />Threat actor <b>description</b>: <i>NOTICE OF DATA BREACH: RADIAX.COM

We are officially announcing that we have gained full access to the internal network and sensitive data infrastructure of Radiax.com.

To prove the authenticity of our access, we have published an initial 5% of the total exfiltrated data. This is merely a sample. W…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/radia-inc-ps/70369787</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Converting-Equipment-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33906</link>
<guid>b90b1b71d03d17c8af3e78947fa87a0a</guid>
<pubDate>Thu, 16 Jul 2026 14:25:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Converting-Equipment-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4517d2c4067a85b62df5639731f462a6de9af5bbd1ec607157f6b90c713fbf0f</i><br /><br />Threat actor <b>description</b>: <i>CEI's mission is to produce high-quality equipment for the manufacturing industry through innovation, collaboration, and integrity. However, the company has a history of neglecting its own security, putting its customers and employees at risk. This negligence has resulted in the leakage of confidential information and personal data. We provide confidential information regarding equipment development, contracts, and customer relationships. We also have information about their subsidiaries and their entire financial structure.</i><br />Target victim <b>website</b>: <i>slitandrewind.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tangram-Interiors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33904</link>
<guid>b11712a557efbc1dda47d9024b28fc78</guid>
<pubDate>Thu, 16 Jul 2026 13:01:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Tangram-Interiors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67d01edc78cc86ff75c154cdbe394b449d977235e48426ea27c43b6be388d44a</i><br /><br />Threat actor <b>description</b>: <i>www.***.com Revenue $245.1 Million Founded in 1963, At Tangram Interiors, we've spent decades transforming spaces to inspire and empower. As industry leaders, our reputation stands on top-notch craftsmanship and innovative design. Tangram Interiors is a prominent commercial interior solutions provider and Steelcase dealer, specializing in integrated workspaces, including furniture, technology, and design. Serving Southern California, the Central Valley, and Texas, the firm offers comprehensive services ranging from space planning to custom, bespoke furniture solutions. Client pesonal data included. 400+gb</i><br />Target victim <b>website</b>: <i>www.tangraminteriors.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Customs-Watch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33902</link>
<guid>a0f2c291f44a631ce0ebf71f7e02b3b9</guid>
<pubDate>Thu, 16 Jul 2026 13:01:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Customs-Watch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83d397144f8efac008537f46ced8d0806cf5717e8ea51737459b3a2d30a2ba3e</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/customs-watch/467458469 is an intelligence and IT consulting company specializing in anti-counterfeiting and product protection strategies throughout their lifecycle. The company primarily serves the pharmaceutical sector, working with 22 of the 25 largest pharmaceutical companies globally. Founded in 2001, it employs 51 to 200 people and is an active member of the International AntiCounterfeiting Coalition.</i><br />Target victim <b>website</b>: <i>customswatch.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.statebankofnauvoo.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33891</link>
<guid>e0652a0045dbc0b14d016619158789ce</guid>
<pubDate>Thu, 16 Jul 2026 12:57:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpswww.statebankofnauvoo.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3830a6a38d233f7332f2ebabce3fb31a8b297c67f3aaebeee1abb5cbf257206d</i><br /><br />Threat actor <b>description</b>: <i>State Bank of Nauvoo offers a range of banking services including deposit accounts, loans, and online banking solutions</i><br />Target victim <b>website</b>: <i>statebankofnauvoo.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Terry-P-Moosmann-CPA-PC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33885</link>
<guid>a5220ac660ce8c78e452e5edc69d33cf</guid>
<pubDate>Thu, 16 Jul 2026 12:55:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Terry-P-Moosmann-CPA-PC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>276a2e2791382d1d01024478f59b886fcc44170f6a68588b457872aab9d01f5d</i><br /><br />Threat actor <b>description</b>: <i>Terry P. Moosmann CPA PC is a local accounting and tax preparation firm based in Washington, Missouri. Owned by Terry Moosmann, the company provides professional financial, accounting, and tax services tailored to individuals and small businesses in the surrounding communities. The firm is recognized for its personalized approach and long-standing presence in the local business community</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plumley-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33884</link>
<guid>5549f6da5ec3b191b672e682e4735d71</guid>
<pubDate>Thu, 16 Jul 2026 12:52:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Plumley-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7d18d874b645d768e4bc589f9642d8ec72e0de26ae13918cf641de0401074dc</i><br /><br />Threat actor <b>description</b>: <i>Plumley Engineering is a firm specializing in civil, environmental, and geotechnical engineerin
g services. They prioritize client service and quality, focusing on problem-solving and design 
with a common-sense approach.

We will upload 11gb of corporate data soon. Client and employee personal information, projects 
information, contracts and agreements, confidential files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petrini-Valores</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33883</link>
<guid>cfe12d07973eb647d2ba40f76257ce1a</guid>
<pubDate>Thu, 16 Jul 2026 12:25:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Petrini-Valores</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e31d492e667a0cc6482b849765aceaf00cb11305ac80998a8ca07cf3a74b54f</i><br /><br />Threat actor <b>description</b>: <i>Petrini Valores S.A. specializes in personalized wealth management and financial planning, offering tailored financial solutions for individuals, families, and businesses. They provide private banking services, corporate solutions, and sales & trading expertise, ensuring clients can access both local and international markets. The company focuses on creating customized portfolios aligned with clients' profiles and objectives, utilizing innovative strategies and technology. With a commitment to exploring capital market opportunities, Petrini Valores aims to deliver flexible and disruptive financial strategies.</i><br />Target victim <b>website</b>: <i>www.petrini.com.ar</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro-Design-Cente</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33879</link>
<guid>0038c2d25686470c660de62bf5466fe3</guid>
<pubDate>Thu, 16 Jul 2026 10:27:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Metro-Design-Cente</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f488f4fadb8f43278b52ecc70ae58ee1b4e3c12a4fcfbebe5ca4b9e8c1fa304f</i><br /><br />Threat actor <b>description</b>: <i>Metro Design Center offers a variety of design ideas through its room settings, creating an experience reminiscent of Architectural Digest. The center is conveniently located in the Lehigh Valley, making it accessible to a wide range of clients</i><br />Target victim <b>website</b>: <i>metrodesigncenter.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>samuelkoon.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33877</link>
<guid>3c8caa1e965921a89815a28123be4692</guid>
<pubDate>Thu, 16 Jul 2026 09:31:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>samuelkoon.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff0a2912fca35faf879a839695f9e170d081361220304f16090358858e92e7ca</i><br /><br />Threat actor <b>description</b>: <i>How Samuel D. Koon &amp; Associates Controls a $25 Million Portfolio and 350+ Bank Accounts PROLOGUE...</i><br />Target victim <b>website</b>: <i>samuelkoon.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>acilab.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33876</link>
<guid>3de78319f256b3060f1b8e51fd0fe727</guid>
<pubDate>Thu, 16 Jul 2026 08:35:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>acilab.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2109b83c334a8a8d4e698081630e16ea43d48b88dfefc546186d224b33229944</i><br /><br />Threat actor <b>description</b>: <i>How ACI Financed Its Owners' Companies — and Paid Them Rent PROLOGUE Inside the archive of American ...</i><br />Target victim <b>website</b>: <i>acilab.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>International-Delights</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33873</link>
<guid>8fd2aa96c03c97513ead09138475efd9</guid>
<pubDate>Wed, 15 Jul 2026 19:52:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>International-Delights</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ab35b36e4f1edb9d3f93a15cdc92947c14ab06972e282e05cac3d525b447e47</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>intdelights.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>PanasonicAero</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33870</link>
<guid>b01b2f6715785729f0a278f4674a9733</guid>
<pubDate>Wed, 15 Jul 2026 17:01:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>PanasonicAero</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4c7b092f488dd16f28c900043dc43918a1417e1b6e87c15655bd09a08fc26da</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Panasonic Avionics Corporation, commonly known as Panasonic Aero, is a US-based subsidiary of Panasonic Corporation specializing in in-flight entertainment and connectivity systems for commercial airlines. The company designs and supplies seatback screens, Wi-Fi connectivity, and cabin management solutions. Headquartered in Lake Forest, California, it serves major global airlines and operates within the aerospace and aviation technology industry.</i><br />Target victim <b>website</b>: <i>panasonic.aero</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hughes-Atwood--Mullaly-pllc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33865</link>
<guid>a4a87e583804c00a14032b615ae88f53</guid>
<pubDate>Wed, 15 Jul 2026 15:53:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Hughes-Atwood--Mullaly-pllc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f19ae6fa1da8fc97b96d8971c99107560a8320dc071b89a59e3c4ccf597a259</i><br /><br />Threat actor <b>description</b>: <i>Hughes Atwood & Mullaly PLLC is a full-service law firm that offers professional legal services to individuals, businesses, and institutions in the Upper Valley...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shillen-Mackall--Seldon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33866</link>
<guid>0602cae8eddc659a9064d8c7fb2bfaed</guid>
<pubDate>Wed, 15 Jul 2026 15:53:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Shillen-Mackall--Seldon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba83a8f96ed7fbfd9ed2cf0e537abb9e9fbfc1766c0e345f0eb261a14c6ef17b</i><br /><br />Threat actor <b>description</b>: <i>Shillen Mackall Seldon Spicer & Fraas is a law firm dedicated to representing personal injury victims primarily in Vermont, New Hampshire, and Florida since 198...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stephens-Precision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33867</link>
<guid>b3a43b25c749c0af22ba14f87794479f</guid>
<pubDate>Wed, 15 Jul 2026 15:53:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Stephens-Precision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75cd1eb50244dd6fe4793bdef8e568fba5bbfb7d38310b1ec55345ff7c1e01c2</i><br /><br />Threat actor <b>description</b>: <i>Stephens Precision, Inc. is a versatile HUBZone manufacturing facility in Vermont, specializing in the machining of mechanical assemblies, components, and tooli...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heritage-Mechanical-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33869</link>
<guid>97598856bc91a074e91cd741550ee379</guid>
<pubDate>Wed, 15 Jul 2026 13:53:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Heritage-Mechanical-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78cf215e8cb3894ccca1c45e88e33e6a6bdc1c385f870823bed29e0391462751</i><br /><br />Threat actor <b>description</b>: <i>Built on a family legacy of proud steamfitters dating back to over 100 years, Heritage Mechanical was established in 2012 to provide quality mechanical service to the commercial construction industry. Opening its doors with only three employees and a master plan, the company has since grown rapidly to become one of the fastest growing mechanical construction firms serving the DMV.</i><br />Target victim <b>website</b>: <i>heritagemechanical-llc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jani-King</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33863</link>
<guid>b3d535661b8f07d8a9fc36fa6c7b05c8</guid>
<pubDate>Wed, 15 Jul 2026 12:20:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Jani-King</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7ad5578d94a7a227c85cf299b395e7dc86b9e6b78b6f6734b09c4f5d3c4b0cf4</i><br /><br />Threat actor <b>description</b>: <i>Facilities Services Stolen data: 12 GB.</i><br />Target victim <b>website</b>: <i>www.janiking.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carient-Heart--Vascular</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33862</link>
<guid>d40e8b592e9c23339fed96f2ff63ae4a</guid>
<pubDate>Wed, 15 Jul 2026 11:00:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Carient-Heart--Vascular</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c73df9a66b8e1daa80d7c5c2e0a0139ce9ba028717d68b38cd993c02bdc24c0</i><br /><br />Threat actor <b>description</b>: <i>Expert resource for heart and vascular care in Northern Virginia</i><br />Target victim <b>website</b>: <i>carient.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Plains-Rural-Health-Services-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33861</link>
<guid>429b0e69b87e2517efea925bab949a63</guid>
<pubDate>Wed, 15 Jul 2026 10:59:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>South-Plains-Rural-Health-Services-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b79e477b51f7633b3ace4d2c65a1cfeef4b1c814f2b0d84cff95772869cc1b8</i><br /><br />Threat actor <b>description</b>: <i>Comprehensive and family care in West Texas</i><br />Target victim <b>website</b>: <i>sprhs.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Levin-Furniture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33856</link>
<guid>c9bc2a9cbd599fcd2e77e5063989f898</guid>
<pubDate>Wed, 15 Jul 2026 07:55:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Levin-Furniture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4fd2eb8ff8a29776d9b3311c549fb3180ae54838090d7abf52cb3fcaeb62cff0</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abbott-owned-Exact-Sciences-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33855</link>
<guid>c08f0c801bd312c3d2358c1ed0bc1bea</guid>
<pubDate>Wed, 15 Jul 2026 00:00:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Abbott-owned-Exact-Sciences-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f3234fb8d8c9a62e73729f38623589af0410af1fc4eb6005e19e87dac3bbab1</i><br /><br />Threat actor <b>description</b>: <i>You wouldn't want us to describe what was exfiltrated from you publicly. This is a final warning to reach out by 18 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 15 July 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prodirectional-drilling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35386</link>
<guid>e992292ea6314d710f2274e6df3ed9d0</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Securotop</b> claims attack for <b>Prodirectional-drilling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6abe0d39fb1ac3a5d111c0b069604a0d75badfb1efcadf9f26c2ec59dab7e70c</i><br /><br />Threat actor <b>description</b>: <i>ProDirectional, founded in 2001 and headquartered in Conroe, Texas, specializes in directional drilling services, including Measurement While Drilling (MWD) and high-performance mud motors. The company operates across major U.S. shale basins, offering services such as MWD tool rentals, coring, and remote operations monitoring. Official website: https://www.prodirectional.com/</i><br />Target victim <b>website</b>: <i>prodirectional.com</i>]]></description>
<category>Securotop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Galaxy-precision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35387</link>
<guid>adb98634c81cffdb29526e5fff9b47c6</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>PrinzEugen</b> claims attack for <b>Galaxy-precision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>832c5e596ac72035c7a7429d163541c2c8dc2c7504c28a80853925103374a0f0</i><br /><br />Threat actor <b>description</b>: <i>Galaxy Precision, Inc., founded in 1990, specializes in CNC turning, milling, and Swiss machining, delivering high-quality solutions for components of all sizes. The company is ISO 9001:2015 certified and serves manufacturers across Minnesota and beyond. Website: https://galaxyprecisionmn.com/</i><br />Target victim <b>website</b>: <i>galaxyprecisionmn.com</i>]]></description>
<category>PrinzEugen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Albany-manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=35388</link>
<guid>1df134a4343e125344de1e920a01ff80</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>PrinzEugen</b> claims attack for <b>Albany-manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f19b3d0b7280e18b24176daf31b99ee45e3627dae90661eb0bf42a749c6490b5</i><br /><br />Threat actor <b>description</b>: <i>Albany Manufacturing Inc., established in 1993, specializes in precision laser cutting, fabrication, and welding services. The company offers full-service precision laser cutting up to 1-inch thick steel plate and press brake forming, with certified welders meeting strict requirements. Website: https://www.albanymfginc.com/</i><br />Target victim <b>website</b>: <i>albanymfginc.com</i>]]></description>
<category>PrinzEugen</category>
</item>
<item xmlns:dc='ns:1'>
<title>THL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33843</link>
<guid>29e71551bb5b6c041b895a9fdb6db557</guid>
<pubDate>Tue, 14 Jul 2026 21:54:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>THL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03ccc80329a0ae1a67399d14a659ab7e8db34f87dabd52dafdefe56704290454</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Axiom-GlobalNEW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33854</link>
<guid>f625c0ef85e8e6d96ec0a1bc16c2741d</guid>
<pubDate>Tue, 14 Jul 2026 20:53:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Axiom-GlobalNEW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6817daa9ad29e4690cbb1a730a7d31f56b561b3db3ee4174530ee778cb6cd7cb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>axiom-global.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>spectrumchemical.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33852</link>
<guid>d722e24995a776f6fef5c1654eb42596</guid>
<pubDate>Tue, 14 Jul 2026 20:22:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>spectrumchemical.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c06e9532718d0adee40ddb70a36056781fe034ae6d275b67b65ffb368036fd8f</i><br /><br />Threat actor <b>description</b>: <i>Public Notice: Final Ultimatum to Spectrum Chemical Management

To the Management of Spectrum Chemical:

We have provided you with sufficient time to engage in a productive dialogue regarding the security breach of your infrastructure. Your refusal to communicate and your attempt to ignore the sever…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/spectrum-chemical-mfg-corp/112197980</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cedar-Crest-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33845</link>
<guid>0ca28c19a7db0b4d5e3f17829bbe29b8</guid>
<pubDate>Tue, 14 Jul 2026 19:30:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Cedar-Crest-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c07f8eabec4995cd34d170d80c673728b2c764edc9645b6a70fe6964afb3739</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.cedarcrest.edu</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Golden-Glasko--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33844</link>
<guid>34571ad4ab328f2e87f24657505a6a3e</guid>
<pubDate>Tue, 14 Jul 2026 19:27:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Golden-Glasko--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c80deac8986b31260ab417e66e676352a301d151dd104df04328a2dbe9398d92</i><br /><br />Threat actor <b>description</b>: <i>Golden Glasko Haddy and Associates, P.A. is a law firm based in Miami specializing in estate law, probate, guardianship, and trust issues. With over 70 years of combined experience, they provide services including estate planning, probate litigation, and trust administration. The firm aims to offer personalized legal strategies and tenacious advocacy to support clients throughout South Florida. They also offer free initial consultations to prospective clients seeking legal guidance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>aphenapharma.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33840</link>
<guid>998331528fa83423269d7650120521a9</guid>
<pubDate>Tue, 14 Jul 2026 15:23:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>aphenapharma.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84889ec2bb698af7db71420c3381a2891163ed447be9cd1bb160b5f8bc809e16</i><br /><br />Threat actor <b>description</b>: <i>Aphena Pharma Solutions

We have gained full access to your corporate infrastructure. During this operation, we stole 142 GB of your most critical corporate data.

The stolen data includes:

    Financial statements: capital expenditures (CAPEX), fixed assets, accounts receivable and accounts payabl…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/aphena-pharma-solutions-inc/96862903</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>WBF-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33829</link>
<guid>5e8900c415afdd93abdc76e826e3a51f</guid>
<pubDate>Tue, 14 Jul 2026 12:20:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>WBF-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6882e6ea10a35d7860bcb23c21bc7dccce4401782c75dc61e98b15fb10d363a</i><br /><br />Threat actor <b>description</b>: <i>WBF Construction LLC is a company that operates in the Commercial & Residential Construction industry. It employs 1to4 people and has under500K of revenue. The company is headquartered in New Haven, Connecticut.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Counts--Dobyns</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33820</link>
<guid>d4b42304f98e8c0760723c747006a5a4</guid>
<pubDate>Mon, 13 Jul 2026 23:01:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Counts--Dobyns</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a02a022aaa3e5a38e4b2e250e52845d5795060c3e51f2f3f222b88aba3101e53</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hillebrand-Home-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33815</link>
<guid>f7c5213a8ce1cfc32b697f9e70e1b3b7</guid>
<pubDate>Mon, 13 Jul 2026 21:51:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hillebrand-Home-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64bb0995d4f0193b40727b2128e6f4aa7f5c2dd9fcaa0b18a00c5b0ebf890e10</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TitanTV-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33813</link>
<guid>693d963c5bc8ff46b4351667b3c4a663</guid>
<pubDate>Mon, 13 Jul 2026 18:26:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TitanTV-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2b430912a3bdff5c343e200dd0665660e98ca1d4600d15f8b000ffdc30a3779</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.titantvinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>shuttlemeadowcc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33812</link>
<guid>a419a784903b00f0621174cbe8f7a4ce</guid>
<pubDate>Mon, 13 Jul 2026 16:58:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>shuttlemeadowcc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f61ecd83ad3bc0d69fa67770a341d3165ccc0acdb450370263358896aaa922c</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1917, the club is one of the oldest and most prestigious private golf clubs in New England. It …</i><br />Target victim <b>website</b>: <i>shuttlemeadowcc.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeast-Rescue-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33811</link>
<guid>b8986492278e5864d6b7107734bcbcdf</guid>
<pubDate>Mon, 13 Jul 2026 15:52:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Northeast-Rescue-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>000bfee7a0bfb008cfba8f6a96985d5ebdc9dfa49390ce654cf17212abcc6e43</i><br /><br />Threat actor <b>description</b>: <i>Northeast Rescue Systems is a dedicated provider of specialized rescue, safety, and protective equipment serving emergency services and industrial safety communities throughout the New England region. The company is known for supplying a wide selection of highquality gear, including protective clothing, technical rescue tools, detection instruments, and missioncritical hardware tailored to the demanding needs of first responders and safety professionals. With a focus on reliability, expert guidance, and personalized service, Northeast Rescue Systems supports teams that operate in hazardous environments by equipping them with trusted products from reputable manufacturers and fostering strong relationships built on professionalism and trust</i><br />Target victim <b>website</b>: <i>northeastrescue.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ironmark</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33801</link>
<guid>f3d801966e7e0d77863c9f8b31d02529</guid>
<pubDate>Mon, 13 Jul 2026 13:23:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ironmark</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>378f88b9fa73958f071542f751585d4daa09acb8a20bcf5f416b4c0b67efa1d0</i><br /><br />Threat actor <b>description</b>: <i>Founded and headquartered in Annapolis Junction, Maryland, Ironmark is a provider of marketing,
creative, printing and communications services. They specialize in marketing strategy, creativ
e & web development, digital marketing, printing services, and more.

We will upload 190gb of corporate data soon. Employee personal information (passports, DLs and 
other personal information), projects information, detailed financials, client internal informa
tion, contracts and agreements, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>ironmarkusa.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Synopsys</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33796</link>
<guid>cdebf2bdf97feb83d4ecdc46f7c4630a</guid>
<pubDate>Mon, 13 Jul 2026 11:32:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>D1R</b> claims attack for <b>Synopsys</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d67208ce6deea756b34938cb6039029f33287759604f26e0c85e415e631e948</i><br /><br />Threat actor <b>description</b>: <i>Data, Leak</i><br />Target victim <b>website</b>: <i>Synopsys.Com</i>]]></description>
<category>D1R</category>
</item>
<item xmlns:dc='ns:1'>
<title>Els-for-Autism</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33792</link>
<guid>88757d44d1e0a2bf33e366fe78461e31</guid>
<pubDate>Sun, 12 Jul 2026 23:50:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Els-for-Autism</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe8ec1d71355919913fd61ec111c937b07d2ae90e08e48999e5784407fd2d5d4</i><br /><br />Threat actor <b>description</b>: <i>Els for Autism Foundation, founded by Liezl and Ernie Els, offers programs and resources for adults and children with autism spectrum disorder (ASD). The Els Center of Excellence campus is a world-class site hosting leading-edge programs and services for individuals with autism. Based in Jupiter, Florida, The Els Center of Excellence is on track to be a global leader in the field of autism and a leading example of what can be available to individuals on the spectrum.</i><br />Target victim <b>website</b>: <i>www.elsforautism.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Casper-Orthopedics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33791</link>
<guid>db8878e70972845cfb00cebc25b2edae</guid>
<pubDate>Sun, 12 Jul 2026 22:22:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Casper-Orthopedics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5aebedf3e2c724981f4536920d85300bf6c10880a69ec8c9a1d25eca3cd6f8d7</i><br /><br />Threat actor <b>description</b>: <i>Orthopedic clinic patients' data and medical records exposed.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Advocates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33789</link>
<guid>3b029d4810ab62194de14d4e511ba6fa</guid>
<pubDate>Sun, 12 Jul 2026 22:22:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Community-Advocates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83dca7fd61b8358e88b0231eb8335603732b7b3a32f6ff55560b5afe546d4dcd</i><br /><br />Threat actor <b>description</b>: <i>Law firm clients' personal data exposed.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>foreconinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33785</link>
<guid>0068416e55804a4dd11b5ebbdde1386b</guid>
<pubDate>Sun, 12 Jul 2026 13:01:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>foreconinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8257a5f73911297246b0ce5caa49875fe78111d53db6b2fba675dd5325843067</i><br /><br />Threat actor <b>description</b>: <i>+1 (716) 664-5602 , FORECON Inc. specializes in custom-crafted forest management, due diligence, appraisal, analytics, and rural brokerage services across New York, Pennsylvania, and West Virginia. Established in 1954, the company focuses on balancing the needs of people and the environment through sustainable forestry practices. Their services include technical, advisory, and valuation support for forestry projects, land management, and conservation solutions. Additionally, FORECON offers a HuntLease program that connects landowners with hunters to promote wildlife management and forest health. Stolen: 860 Gb 437,048 Files</i><br />Target victim <b>website</b>: <i>foreconinc.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>wrtworld.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33784</link>
<guid>0c39bcfdf3238e1db81e5e452f02470e</guid>
<pubDate>Sun, 12 Jul 2026 13:00:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>wrtworld.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac791efdc25a918d27cb138895df6b66818c0a0e3df5ae7c2bad2a48215b6015</i><br /><br />Threat actor <b>description</b>: <i>+1 (305) 884-3700 , WRT World Enterprises is a leading provider of purchasing and logistics services tailored for major retailers in Latin America. The company specializes in streamlining supply chain management through services such as shipping, storage, purchasing, and vendor management. With a focus on innovative solutions, WRT helps its clients remain competitive by offering order purchasing technology and comprehensive logistics services. Their extensive network and established relationships with suppliers enable them to negotiate favorable prices, ensuring their clients have access to the best products in the market. Stolen: 377 GB 267,891 Files</i><br />Target victim <b>website</b>: <i>wrtworld.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eureka-Construction-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33782</link>
<guid>95276ef6535840ec6e432a7fc28688cb</guid>
<pubDate>Sun, 12 Jul 2026 09:22:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>titan</b> claims attack for <b>Eureka-Construction-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e427f9d364f245a310ca2af1db0138801438cbc52ecc8280a9ed2a4cc02b438c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>eurekaconst.com</i>]]></description>
<category>titan</category>
</item>
<item xmlns:dc='ns:1'>
<title>Century-Equities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33780</link>
<guid>ef11c94847ffdaae6df84356ee27cf20</guid>
<pubDate>Sat, 11 Jul 2026 13:35:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Century-Equities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea663f3bae69b223bd2fd12e069e15fc1374cf9b1e35b58cedbb295d199cc4d3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.centuryequities.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carolina-Agri-Power</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33778</link>
<guid>dd5ae592370924172fe1ffeb2ebfa577</guid>
<pubDate>Sat, 11 Jul 2026 13:33:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Carolina-Agri-Power</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9550d4ed34ed193da2c88082e0e62c92621906cb52f3da09c8402e60bb8654fc</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.carolinaap.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allied-Plumbing--Heating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33777</link>
<guid>731f9cd690d0b31e36353cb70553f541</guid>
<pubDate>Sat, 11 Jul 2026 13:32:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Allied-Plumbing--Heating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>159e4245e8172cf92814a5afcbb66a3eaea30469b799898b71d537c31af6e4bf</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.alliedpnh.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pharma-Wholesale</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33774</link>
<guid>4b06516e2c5d9c7432a55e9c0fb4cec6</guid>
<pubDate>Sat, 11 Jul 2026 07:19:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Pharma-Wholesale</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a7cff01a3f7eb92331329d44c249c758c9d43fcbaec71fec826a6fd862c3cfbe</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/pharma-wholesale/353577758 Pharma Wholesale Corp. is a licensed pharmaceutical wholesaler and distributor headquartered in Florida, USA, with over 24 years of industry experience. The company specializes in the global distribution of prescription and OTC medications, vitamins, supplements, and health and beauty products. Operating as a mid-sized enterprise, they supply affordable healthcare solutions to pharmacies and medical facilities both domestically and internationally</i><br />Target victim <b>website</b>: <i>pharmawholesale.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Welders-Supply-Equipment-Rentals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33773</link>
<guid>dfa7868c9f76acaf214a28eaea294b08</guid>
<pubDate>Sat, 11 Jul 2026 07:19:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Welders-Supply-Equipment-Rentals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c03d496db6a3818b598a602ff5808c93ba0cef706da6c86e2af90af656a5618b</i><br /><br />Threat actor <b>description</b>: <i>***.com  zoominfo.com/c/welders-supply--equipment-rentals/355927450 WSE Rentals (Welders Supply & Equipment Rentals) is a specialized equipment rental company headquartered in Port Allen, Louisiana. They focus on providing a comprehensive range of high-quality, reliable welding tools and machinery from well-known industry brands for various industrial projects. The company serves contractors and businesses by offering tailored rental solutions and dedicated delivery services to support their operational needs</i><br />Target victim <b>website</b>: <i>wserentals.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gene-Codes-Forensics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33771</link>
<guid>7cffa284a0d3d40546080317906c45eb</guid>
<pubDate>Sat, 11 Jul 2026 07:18:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Gene-Codes-Forensics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57df5e6c221f1a94994188b33a1645c6c4060f07c816b5a8a02e7ec9808e0371</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/gene-codes-forensics-inc/1208843964 Gene Codes Forensics is a Michigan-based technology company and a global leader in disaster victim identification and human DNA matching. They provide specialized forensic software, such as Sequencher and M-FISys, which are utilized by numerous states and countries as central DNA resources for identifying remains in mass disasters. In addition to providing software and consulting services, the company operates a one-million-dollar Humanitarian Grant Program to support non-profit organizations conducting forensic DNA testing</i><br />Target victim <b>website</b>: <i>genecodesforensics.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lopes-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33770</link>
<guid>8b48ea597d2862688e4aa8a2b28651a3</guid>
<pubDate>Sat, 11 Jul 2026 07:18:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Lopes-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd4e8d47996250e7fb398b0bc9f4cbedb86cf97db7221ac12bdfa35da1c96134</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/lopes-law-llc/449811320 Lopes Law LLC is a Philadelphia-based law firm founded by Anthony Lopes that specializes in franchise law, representing both franchisees and franchisors nationwide. The firm provides comprehensive legal services including Franchise Disclosure Document (FDD) reviews, franchise agreement negotiations, and dispute resolution using transparent flat-fee pricing. In addition to franchise expertise, the practice acts as fractional general counsel for businesses and offers specialized tax law services to help companies navigate complex legal landscapes</i><br />Target victim <b>website</b>: <i>lopeslawllc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dash-Door-Glass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33767</link>
<guid>226d3fde8cc7cbbb2067395e806570a6</guid>
<pubDate>Sat, 11 Jul 2026 07:17:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Dash-Door-Glass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23ea15f28e8febcf7a7e51dd8fab3ce3857ca3b4b8efdfcc5ea358d610643421</i><br /><br />Threat actor <b>description</b>: <i>***.com Dash Door & Glass is a prominent commercial contractor and facility support specialist headquartered in Doral, Florida, with a rich history dating back to 1955. The company specializes in the supply, installation, and maintenance of commercial doors, glass, and architectural hardware for large-scale construction projects across South Florida. Operating with a dedicated team of professionals, the firm has established itself as a major industry player, generating an impressive annual revenue of approximately $113.3 million</i><br />Target victim <b>website</b>: <i>dashdoor.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Schuett-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33766</link>
<guid>2c41e54c1a31849f56aa0686fa09759d</guid>
<pubDate>Fri, 10 Jul 2026 21:57:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Schuett-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8144a51aa445aa903064c729cf3693c55850e7db1296888ab6905463dc8011b</i><br /><br />Threat actor <b>description</b>: <i>The Schuett Companies, Inc. is a family-owned business with over 50 years of experience specializing in affordable housing for seniors, individuals with disabilities, and families. They manage approximately 1,600 housing units across Minnesota, North Dakota, and South Dakota. Since 1968, they have also offered Home Health Care services through their CompassionCare program, ensuring residents can age in place comfortably. The company's commitment to providing a supportive community emphasizes the importance of a stable home for a healthy life.</i><br />Target victim <b>website</b>: <i>www.schuettcares.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Borger-ISD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33764</link>
<guid>74493ea055c0d8689c449bba56feea7c</guid>
<pubDate>Fri, 10 Jul 2026 15:26:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Borger-ISD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf3f6c01cc0eec5f2075ffcbeb6e917a226fbafec076cdf4c131d57475048eb6</i><br /><br />Threat actor <b>description</b>: <i>Borger Independent School District serves approximately 2,500 students on six campuses in Hutchinson County, Texas. The district fails to foster a collaborative environment for students, parents, and the community. They are not responsible or committed to ensuring the security of your data. This is not the first time they have neglected their students, with confidential information about staff, students, and their parents, as well as all incidents, the district's financial situation, and other information they concealed, leaking online. We offer you 330 GB of this information.</i><br />Target victim <b>website</b>: <i>borgerisd.net</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vandalia-Rental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33763</link>
<guid>f485dffb4597230ac63901784d2917ff</guid>
<pubDate>Fri, 10 Jul 2026 13:51:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Vandalia-Rental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>287e0d6b222846a89401135ea59ac4f3919fd36ff6939aa1ed8687c849dffc04</i><br /><br />Threat actor <b>description</b>: <i>Vandalia Rental has served the Greater Dayton and Greater Cincinnati and Northern Kentucky mark
ets since 1961. Vandalia Rental proudly services construction rental accounts ranging from smal
l businesses to large publicly traded corporations, government agencies, and municipalities thr
oughout the Ohio, Indiana, and Kentucky regions, and sales accounts throughout the country.

We will upload 40gb of corporate data soon. Detailed employee and client personal information (
SSN numbers, name, DOB and so on), projects files, financials, client internal information, con
tracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Strategic-Business-Process-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33757</link>
<guid>adcf964dc675106763e656dcd371299f</guid>
<pubDate>Fri, 10 Jul 2026 12:32:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Global-Strategic-Business-Process-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>235720ab5fff4db2e1ae645d433d7eb978ed15da3473bef650dd195a2b21bf91</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.globalstrategic.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>bancrofteng.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33736</link>
<guid>ab84023d2681764cd01815f779c22729</guid>
<pubDate>Fri, 10 Jul 2026 05:38:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>bancrofteng.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c1e9219b33e4903c285ede36f42cef34f56e33fedc0f836b0a86f402cd07e3e</i><br /><br />Threat actor <b>description</b>: <i>Bancroft Engineering specializes in the design and manufacturing of automated welding equipment and...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Open-options</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33751</link>
<guid>813c113f572fe454d93e55e4403d8ac8</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Open-options</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddbd6c29b49291e28b394cbbd96be6b2669bea84c1f5ab2ab15f668222cf8e99</i><br /><br />Threat actor <b>description</b>: <i>Open Options, founded in 1997, specializes in open-platform access control solutions, notably their DNA Fusion software. In 2018, they were acquired by ACRE, enhancing ACRE's access control portfolio. Website: https://www.ooaccess.com/</i><br />Target victim <b>website</b>: <i>ooaccess.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crossroads-medical-management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33753</link>
<guid>194191c15060e323bb610faf147e1700</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Crossroads-medical-management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c10734da79fedaf20d52b1a4343e3e8c01eb29bce607443ec1ce62240bc64050</i><br /><br />Threat actor <b>description</b>: <i>Crossroads Medical Management, established in 1993, is a healthcare management company specializing in senior services. With a legacy spanning three generations, they operate six skilled nursing facilities in Georgia, employing over 700 staff members. Their services include financial, clinical, and operational management, focusing on enhancing the quality of life for the senior community. Website: https://crossroadsmedicalmgmt.com</i><br />Target victim <b>website</b>: <i>crossroadsmedicalmgmt.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Envision-Unlimited</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33734</link>
<guid>b7a7c709ce0c55992d8cab2c9d2cef7d</guid>
<pubDate>Thu, 09 Jul 2026 17:27:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>Envision-Unlimited</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32db3e6f9ec0f9d304c141ee11be7e9f0d269b32f1a48f58fbeedfd5d42848de</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Envision Unlimited is a nonprofit human services organization based in the United States, primarily operating in Illinois. Founded in Chicago, it provides support services for individuals with intellectual and developmental disabilities. Its programs include residential services, day programs, employment support, and behavioral health services, aimed at promoting independence, inclusion, and quality of life for the people it serves.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>robroy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33733</link>
<guid>60793eb1cf4738fc67df0a93d57ada14</guid>
<pubDate>Thu, 09 Jul 2026 15:21:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>robroy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01d7a6a372a6e2694b789677bb98eeb9df1a6283eadb91bb0cfdab623aa71348</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Rob Roy Industries, operating through robroy.com, is a US-based manufacturer specializing in electrical conduit systems and enclosures. The company produces PVC-coated steel conduit, fiberglass conduit, and industrial enclosures used in corrosive and hazardous environments. Headquartered in Verona, Pennsylvania, Rob Roy serves industries such as oil and gas, chemical processing, wastewater treatment, and utilities, providing durable electrical protection solutions across North America.</i><br />Target victim <b>website</b>: <i>robroy.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>iac-intl.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33732</link>
<guid>cb1f1e892b2602ef829df6f10ecd7a9f</guid>
<pubDate>Thu, 09 Jul 2026 15:20:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>iac-intl.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11304c7d1592ae8a44b29c902016dd9c66a462a1988d717929eef801a32323ab</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>iac-intl.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>gvfsinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33728</link>
<guid>adba8655a172abad7782f03d08c9abf3</guid>
<pubDate>Thu, 09 Jul 2026 11:58:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>gvfsinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fec67ff83ef9b2b4d1333476d8382f80d6b603ab164e23fbe0346839ffa4ea6c</i><br /><br />Threat actor <b>description</b>: <i>GREEN VALLEY: SELF-LEASE SCHEME How a California agricultural distributor pays rent to companies con...</i><br />Target victim <b>website</b>: <i>gvfsinc.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>bergdemo.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33727</link>
<guid>41504ebfe4dfc72fdf5f95920f193dee</guid>
<pubDate>Thu, 09 Jul 2026 10:33:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>bergdemo.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>222c6cf88ef541855987baa2ef1a1cf56c2c17a50e3fc3eea3337dcf6129e378</i><br /><br />Threat actor <b>description</b>: <i>Berg / Crushing Corporation of America: Demolition on Federal Money PROLOGUE In our possession are i...</i><br />Target victim <b>website</b>: <i>bergdemo.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sun-Dolphin-Boats</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33725</link>
<guid>41f4893a58fba89b8e7535aadb39ccf4</guid>
<pubDate>Thu, 09 Jul 2026 10:30:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sun-Dolphin-Boats</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c9bbfc17e2e89f89575eb7e0ba7537a9adf642d40954b622bc0b3301f5ac365</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sundolphin.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bronkens-Dist</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33724</link>
<guid>698936639e27b2bc038e0d7b4ea464b2</guid>
<pubDate>Thu, 09 Jul 2026 10:30:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bronkens-Dist</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a793057e1def15f231953145151ab3a904503c6325e62509f350f0ecd19288c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.bronkens.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alan-F-Burke</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33723</link>
<guid>227d64572b003dba122532f9e2da77e7</guid>
<pubDate>Thu, 09 Jul 2026 10:29:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alan-F-Burke</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>950341a55a924f0646612fae6ecdde3096b7ab3078db1bacf385456195011522</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.alanburkecpa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hum--Jacoby</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33722</link>
<guid>1dec579f2996d9974e0777084bb8ab2c</guid>
<pubDate>Thu, 09 Jul 2026 08:30:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hum--Jacoby</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fe06183b265d386bd1170d4f8d24716aef22dcc79688f0031c0962a93cedff7</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.hhjcpas.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peligro-Sports</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33714</link>
<guid>4f6e1bfb01ad1e44d8c958c58cd22051</guid>
<pubDate>Thu, 09 Jul 2026 07:54:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Peligro-Sports</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc9811db3b00e354e596685499ff53c34c91ab415e0e82b5ab1c9c93e4def9d0</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Creative-Smiles-Pediatric-Dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33720</link>
<guid>ffb51c2a27a66718f1ba1515c250c722</guid>
<pubDate>Thu, 09 Jul 2026 06:44:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Creative-Smiles-Pediatric-Dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6af6a99cd1d51555fc006137c651934f7e6180091530b99ed5555ee1a8318215</i><br /><br />Threat actor <b>description</b>: <i>Sector: Pediatric Dentistry | Data leaked: 2.5 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>SF-Smile-Doctor</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33718</link>
<guid>da7966481086a4e3a2dde7c2ccbc49e3</guid>
<pubDate>Thu, 09 Jul 2026 06:42:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>SF-Smile-Doctor</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>786bd98d3c1712c3c73ea2cba94e5934ebcdab7e92276e89fb5279df55114d22</i><br /><br />Threat actor <b>description</b>: <i>Sector: Medical | Data leaked: 100.0 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bishop-Arts-Dental-PLLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33717</link>
<guid>af523c5d4c1038a5f074c4320af0ce78</guid>
<pubDate>Thu, 09 Jul 2026 06:41:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Bishop-Arts-Dental-PLLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a53697e4f2e1237ac456bfc304331b57da2e2aaacbe7e45fd7a0af62306e27d</i><br /><br />Threat actor <b>description</b>: <i>Sector: Medical | Data leaked: 24.6 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Top-Notch-Dentistry-of-Dallas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33716</link>
<guid>b1c22d171a128f2defc188ce786fbbf8</guid>
<pubDate>Thu, 09 Jul 2026 06:41:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>CRPxO</b> claims attack for <b>Top-Notch-Dentistry-of-Dallas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d8564efb4a3767791cd2ba41829d62704e63dd84fe1d78668af5c788a791920</i><br /><br />Threat actor <b>description</b>: <i>Sector: Medical | Data leaked: 2.0 GB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>CRPxO</category>
</item>
<item xmlns:dc='ns:1'>
<title>Techcorr</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33804</link>
<guid>06b7476ec66a0df253337fbbbc39f2da</guid>
<pubDate>Thu, 09 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Techcorr</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40671a9669c47e669ecc01d5dde14aeac4aae61fa88dbe62bed83cc4ca0907d9</i><br /><br />Threat actor <b>description</b>: <i>TechCorr is a U.S.-based company specializing in non-destructive testing (NDT) and inspection services for the oil and gas industry. They offer a range of services including radiographic inspection, quality assurance/quality control (QA/QC), and engineering support. Website: https://techcorr.com/</i><br />Target victim <b>website</b>: <i>techcorr.com</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>S.J.-Louis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33711</link>
<guid>32931aa4a3c83357456f32cd508a115b</guid>
<pubDate>Wed, 08 Jul 2026 17:49:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>S.J.-Louis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>363a3749a9a3604bf70576c1ce83b79dc7a219b1916a57fbe65d7d13c40814c5</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wades-Dairy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33710</link>
<guid>553b5b9ed7e16c3f3d6bcb4094024b27</guid>
<pubDate>Wed, 08 Jul 2026 15:54:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wades-Dairy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a447359e2dd35b842aac579a1288853a1ebcf9380eb0cc3949302a7614b7200e</i><br /><br />Threat actor <b>description</b>: <i>A family-owned business for over a century, Wade's Dairy has been a staple in the Connecticut community.We will upload corporate data soon. Detailed employee personal information (name, DOB, SSN, DL,height, weight, race, sex, eyes and hair color, tattoo information, emails, phones and so on),projects files, financials, customers, contracts and agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tostrud--Temp-S.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33708</link>
<guid>6903df7077db0e82dc39246b45ae1f0d</guid>
<pubDate>Wed, 08 Jul 2026 11:01:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Tostrud--Temp-S.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91f498d6f44043d75978d61edda2641747371e6b92e104315a1b4eb193ebbedc</i><br /><br />Threat actor <b>description</b>: <i>Full service CPA firm serving La Crosse</i><br />Target victim <b>website</b>: <i>tntcpas.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>opportune.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33707</link>
<guid>cc6177dae9053807361351c19dee7af7</guid>
<pubDate>Wed, 08 Jul 2026 07:22:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>opportune.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99a0aa19a011335b5144a895ede7929e275fd0b6e28e1c21eee93560e701f6a7</i><br /><br />Threat actor <b>description</b>: <i>DATA EXPOSURE: Opportune LLP – Full Operational Transparency

We are officially announcing that our security team has successfully breached the internal network of Opportune LLP. As of this moment, we are in possession of the entire Opportune internal data environment—an massive archive containi…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/opportune-llp/147440067</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>corepharma.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33706</link>
<guid>e6ca77b059a8ec5a7842944270fbe749</guid>
<pubDate>Wed, 08 Jul 2026 07:22:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>corepharma.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b744c0de2a5b9bba5149a4f758bc0dc02712c881ee22970e6faca1e9fd89289d</i><br /><br />Threat actor <b>description</b>: <i>DATA EXPOSURE: CorePharma – Full GMP & Regulatory Compromise

We are officially announcing that our security team has successfully breached the internal network of CorePharma. We are currently in possession of a comprehensive archive of the company’s internal operations, including sensitive regu…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/corepharma-llc/30217761</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aesthetic-Surgical-Images</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33704</link>
<guid>4765d45744dee05d7409cbfa36da40d9</guid>
<pubDate>Tue, 07 Jul 2026 19:56:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Aesthetic-Surgical-Images</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee78d3b38fb4c0bae181c47c598bfd3eb9697c9e3c2d7d28e4c4d5b0881258d9</i><br /><br />Threat actor <b>description</b>: <i>Aesthetic Surgical Images, a plastic surgery practice based in Omaha, NE, has been serving patients since 1968 and is known for its commitment to quality and integrity. The practice's medical records are managed by Morgan Records Management, which ensures compliance with state and federal laws regarding record retention and confidentiality. Patients can request their medical records through the practice's website, with a focus on providing a secure and efficient experience. Aesthetic Surgical Images aims to educate patients about their records and the importance of proper management.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Technical-Solutions-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33699</link>
<guid>2fc06d277e31a5df872ac04eb7e75cd2</guid>
<pubDate>Tue, 07 Jul 2026 18:29:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Technical-Solutions-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4667ee401f390e5e5cb062bda145e39389c89797824e58c2e3a9ab5ac5a26a3b</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/medical-data-rx/346985484 Technical Solutions Group, LLC, an IT services company headquartered in Gladwin, Michigan, which also operates the specialized division Medical Data Rx.The organization provides comprehensive technology solutions, including networking, data backup, and hardware services, assisting both small businesses and medical professionals across the United States and Canada.As a diversified technology services provider, the company focuses on delivering reliable technical support and tailored IT management to its clients</i><br />Target victim <b>website</b>: <i>tsgpc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Welldyne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33697</link>
<guid>99c3c828637e01c4337451ab836f62ef</guid>
<pubDate>Tue, 07 Jul 2026 18:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Welldyne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>151217a0cce05846784f64e5fcd54a780e8b4225a2ee5974065adde21db47c49</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Welldyne is a pharmacy benefit management (PBM) company based in the United States. It provides prescription drug management services to health plans, employers, and government programs. The company focuses on improving medication adherence and controlling prescription costs through its pharmacy network, mail-order pharmacy services, and data-driven clinical programs. Welldyne operates primarily across the US healthcare sector.</i><br />Target victim <b>website</b>: <i>welldyne.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Preneed-Funeral-Programs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33695</link>
<guid>369fdaa2741244f57b484d8ac1828fd3</guid>
<pubDate>Tue, 07 Jul 2026 17:56:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Preneed-Funeral-Programs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fa1a1c3642b860d1e974887fcc306e31f57f26367547698ba6f72fba2e8cb7b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.preneed.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kevin-Bao-Lenguyen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33694</link>
<guid>db081d0be20a8fa9ca917616ab79b456</guid>
<pubDate>Tue, 07 Jul 2026 17:30:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kevin-Bao-Lenguyen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>947a72c7ce1f9cae1100f205a4e478b3231c97b4acfa02970a933dd989ac185f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kblaa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Excalibur-Rentals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33685</link>
<guid>d52fb9ba46bed38c94a319bcd6df32b7</guid>
<pubDate>Tue, 07 Jul 2026 15:55:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Excalibur-Rentals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be94b29f0b5558ba98c28857ca46d251a507b263722f762e9b2ff6e9d232c15f</i><br /><br />Threat actor <b>description</b>: <i>Excalibur Rentals is dedicated to providing reliable rental equipment services, ensuring that clients can complete their jobs safely, on time, and within budget. They offer a range of equipment including boom lifts, telehandlers, and light towers.We will upload 45gb of corporate data soon. Employee personal information (name, addresses, SSNs and so on), contracts and agreements, a bit of financials, customers info, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>YMCA-of-Western-North-Carolina</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33691</link>
<guid>82deedbd02182db7aea66208a6a7e414</guid>
<pubDate>Tue, 07 Jul 2026 15:27:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>YMCA-of-Western-North-Carolina</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e142ac6ee62a746c876b8979e670fcef720f7c01e5e20e2d3cf3e40a7afbef24</i><br /><br />Threat actor <b>description</b>: <i>The YMCA of Western North Carolina operates seven fitness centers, a summer camp, dozens of food trucks, youth sports programs, and many other initiatives. They are also the state's largest provider of licensed school-age childcare.
However, they don't ensure security and aren't responsible for it, and you can gain access to confidential client information (complete sets of documents, even fingerprints), contracts, and incidents (of which they have many!), as well as to employee personal data and financial documents.</i><br />Target victim <b>website</b>: <i>ymcawnc.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>URA-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33690</link>
<guid>f1a860c4306a9bf87570bf8491809064</guid>
<pubDate>Tue, 07 Jul 2026 14:50:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>URA-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>160751656edb308a2a265a489ec67300127009e8f95a5be94e86e9dea07c691c</i><br /><br />Threat actor <b>description</b>: <i>Stolen data: 5 GB</i><br />Target victim <b>website</b>: <i>uragroup.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chisholm-Persson--Ball</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33687</link>
<guid>81e2e0ba9d2d6634849095fa6a997eae</guid>
<pubDate>Tue, 07 Jul 2026 13:51:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Chisholm-Persson--Ball</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c63f365b6dc4772a1d155e7b44240243a9769a9bfd4d39a079fb91da737e5eb5</i><br /><br />Threat actor <b>description</b>: <i>Chisholm, Persson & Ball, PC is a law firm located in Laconia, NH, specializing in various lega
l services including Estate Planning, Probate Administration, Family Law, Business Law, and Civ
il Litigation. The firm has been recognized for its excellence, winning multiple awards in the 
Lakes Region for Best Law Firm and other categories.

We will upload 45gb of corporate data soon. Client and employee personal information (client pa
ssports, visas, DLs, SSNs and so on), confidential client docs, financial, contracts and agreem
ents,  court files, police reports and other legal files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edge-Solutions--Stone-Ridge-Payments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33683</link>
<guid>51cb4d36ac390e5bd8d30919a78e336e</guid>
<pubDate>Tue, 07 Jul 2026 12:21:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Edge-Solutions--Stone-Ridge-Payments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd4778bf648fcf018a0f5b2c2977bc93efbe5ca8507ccecba7123658067b1f9a</i><br /><br />Threat actor <b>description</b>: <i>Edge Solutions is dedicated to leveraging technology to create a better world. With a focus on 
integrity, they offer top-notch services to help clients achieve their business objectives. The
ir team is committed to future-proofing businesses through innovative solutions.

We will upload 67gb of corporate data soon. Employee personal information (400  passports and D
L scans, SSNs, w9 forms and so on), financials, contracts and agreements, confidential document
s, lots of NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stone-Ridge-Payments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33742</link>
<guid>70e12d315a19ad3e37b2593a58f37459</guid>
<pubDate>Tue, 07 Jul 2026 12:21:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Stone-Ridge-Payments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>758c0bc2dcc0f9855dc6058cd2ca03b964bb7d25a82025a5915926f02fe3448c</i><br /><br />Threat actor <b>description</b>: <i>We will upload 67gb of corporate data soon. Employee personal information (400  passports and D
L scans, SSNs, w9 forms and so on), financials, contracts and agreements, confidential document
s, lots of NDAs, etc.</i><br />Target victim <b>website</b>: <i>stoneridgepayments.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Richmont-Graduate-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33680</link>
<guid>b1848fc4e4d316fe2105f1228418a8bd</guid>
<pubDate>Tue, 07 Jul 2026 08:20:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Richmont-Graduate-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>966473520dc64e7b210e111d8027945009cc1f0371cd8d6f86d70b8248afeecc</i><br /><br />Threat actor <b>description</b>: <i>Richmont Graduate University is a Christian graduate institution offering master's programs in counseling and ministry, available both online and on-campus.</i><br />Target victim <b>website</b>: <i>richmont.edu</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fitcrunch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33676</link>
<guid>04221815070349c0923cd85e6957bfb3</guid>
<pubDate>Tue, 07 Jul 2026 01:32:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Fitcrunch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff1aca80c9fae5dbab10fe61e94315a270d3ec6a13eb9497ade2f58e5bf866a3</i><br /><br />Threat actor <b>description</b>: <i>FITCRUNCH® makes getting protein more enjoyable than ever before. Satisfy your cravings with a variety of delicious chef-inspired products from co-founder and owner Robert Irvine.Find the perfect fit with our baked protein bars, wafer bars, protein powder, and more-Personal information of employees and clients -Financial documents -Other files https://***.com/</i><br />Target victim <b>website</b>: <i>fitcrunch.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>matrixwebagency.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33673</link>
<guid>715ae832afe204daf1e24c00aafd5418</guid>
<pubDate>Mon, 06 Jul 2026 19:43:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>matrixwebagency.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e529a03c2c0e64b42a31639b44c06669688a5a786f37bbeb26fe7179e56ebce</i><br /><br />Threat actor <b>description</b>: <i>The company specializes in providing integrated digital solutions that help businesses improve their online visibility, customer engagement, and revenue growth. …</i><br />Target victim <b>website</b>: <i>matrixwebagency.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>gisy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33665</link>
<guid>34bba8a30dd89834c698d76e7e4fa833</guid>
<pubDate>Mon, 06 Jul 2026 19:22:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>gisy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>370667d8a5a4580649088955dcc8fbd2bc67d05f92ac6ff0988880dbd6f75831</i><br /><br />Threat actor <b>description</b>: <i>Target: Gisy.com
Status: Data Exfiltration Confirmed
Volume: 1.1 TB (341,712 files)
Deadline: 24 Hours

We have successfully exfiltrated 1.1 Terabytes of internal data from Global Industries’ (gisy.com) primary network servers. This archive contains comprehensive documentation covering every layer…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/grand-isle-shipyard-inc/50466057</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keystone-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33661</link>
<guid>d0509bdcf257b525756b981d54351da6</guid>
<pubDate>Mon, 06 Jul 2026 14:02:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Keystone-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bdc0d5d7f445464419f5107e0e8586faa14488812aafc635cfe40586acca2393</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.gokeystone.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Steel-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33660</link>
<guid>5e6ff78d8ffefe5f71bfa7d5574614d6</guid>
<pubDate>Mon, 06 Jul 2026 14:02:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Precision-Steel-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d683c6a1becbfc2f774602c6b96429c1e16246076dfa89ea815f03279bddfb3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.precisionsteel.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wood-Ellis--Wood-CPA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33652</link>
<guid>a2a52743471fc9d71744e35fa3625217</guid>
<pubDate>Mon, 06 Jul 2026 12:55:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wood-Ellis--Wood-CPA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76b70d3be3509cfd359f1b4dc0dfc871b4117b6abf42dcccac94e1ecb4201ea8</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Upstaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33658</link>
<guid>7923554f3401e7aaadf9466f121ce1a4</guid>
<pubDate>Mon, 06 Jul 2026 12:50:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Upstaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f19f060ac36b068b5e9aff65424608a8c78b3b514cf62ffa596b16678ccd8525</i><br /><br />Threat actor <b>description</b>: <i>Entertainment Providers Stolen data: 10 GB</i><br />Target victim <b>website</b>: <i>www.upstaging.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>LabelDaddy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33641</link>
<guid>0ed04c5f61b5459b009b5b663c43bf94</guid>
<pubDate>Mon, 06 Jul 2026 11:55:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LabelDaddy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb79e3e96c6e80e7eda2108597ec7311cd1562702497f5fd380d07dfdedbb6f0</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Logiquip</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33624</link>
<guid>9ea2a3d45a641fd927eda133e9c1c248</guid>
<pubDate>Mon, 06 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Logiquip</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f0befdb6a55c77f9eee73f4f64b41713ddec201812269d1a34df13ce05cf57e</i><br /><br />Threat actor <b>description</b>: <i>LogiQuip, founded in 1992, specializes in innovative healthcare storage solutions, offering products like medical storage carts and wire shelving to enhance inventory management and supply chain efficiency for healthcare professionals. Website: https://www.logiquip.com/</i><br />Target victim <b>website</b>: <i>logiquip.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Virginia-historical-society</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33625</link>
<guid>fa08b98c6ab37ef6b323c886b46d4104</guid>
<pubDate>Mon, 06 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Virginia-historical-society</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7db0b2c774f4ad20fcb9679013cc8ac7cf676fcd3443c8f0a1a582c89d4f684f</i><br /><br />Threat actor <b>description</b>: <i>The Virginia Historical Society, founded in 1831, is a private, non-profit organization dedicated to preserving and interpreting Virginia's history. In 2018, its headquarters was renamed the Virginia Museum of History & Culture, located at 428 N. Arthur Ashe Boulevard, Richmond, VA. The museum features over 25,000 square feet of exhibition space, showcasing artifacts spanning 16,000 years of Virginia's history. Website: https://www.virginiahistory.org/</i><br />Target victim <b>website</b>: <i>virginiahistory.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apex-Agro-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33619</link>
<guid>1ab9f53c53dc087056a99065861a6f65</guid>
<pubDate>Sun, 05 Jul 2026 13:59:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Apex-Agro-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa7c5aac66738ac4e5773d312e341445a0f8375d28121424116b1f62dbc69eb3</i><br /><br />Threat actor <b>description</b>: <i>A Chemical Production Company</i><br />Target victim <b>website</b>: <i>apexagchem.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mirage-Endoscopy-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33618</link>
<guid>49f6321164c59eff662bb05fc149d094</guid>
<pubDate>Sun, 05 Jul 2026 13:58:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Mirage-Endoscopy-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c722aac6253b3bc7edc82481407a97174a5b7f3a8379fabc1cb59095451d3880</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization</i><br />Target victim <b>website</b>: <i>mirageendoscopycenter.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bri-Tech-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33617</link>
<guid>985638dc60b4effd06b091e80f0b42eb</guid>
<pubDate>Sun, 05 Jul 2026 13:57:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Bri-Tech-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>641a0ac4317be440b645066b91a407b2f46f900862a76123de56a89e319c37df</i><br /><br />Threat actor <b>description</b>: <i>A technology design and integration firm</i><br />Target victim <b>website</b>: <i>bri-tech.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>SBI-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33616</link>
<guid>cfc1e52b72ce346b6ca748f650432953</guid>
<pubDate>Sun, 05 Jul 2026 13:57:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>SBI-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba410b3283701b5fed6300c656b2c475fc425065e5a94d882f1943eba1a1e87c</i><br /><br />Threat actor <b>description</b>: <i>An Enterprise Resource Planning Software Provider</i><br />Target victim <b>website</b>: <i>sbigrower.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>DICON</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33615</link>
<guid>4aa6cce872668388d1a3187f047a7572</guid>
<pubDate>Sun, 05 Jul 2026 13:56:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>DICON</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3a136db5592942dbd6c64a6dc6d56cf2044ac9b517e76c01eea545581afd433</i><br /><br />Threat actor <b>description</b>: <i>A general contracting construction firm</i><br />Target victim <b>website</b>: <i>dicon.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westgate</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33614</link>
<guid>0d8a89515fe89cd53cdedd3c039a15b0</guid>
<pubDate>Sun, 05 Jul 2026 13:55:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Westgate</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef7d2928821ea714f18f312ac2b9ec66bfd6dcfbeb6c8274eab2795535a7ce38</i><br /><br />Threat actor <b>description</b>: <i>A construction management company</i><br />Target victim <b>website</b>: <i>westgatellc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dunagan-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33613</link>
<guid>d957c740b68c99460027ce006a09d2ba</guid>
<pubDate>Sun, 05 Jul 2026 13:54:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Dunagan-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc35f7d76d58b1af5acff9e95f128b23628d410420a42ff5a86f60b001caf4f9</i><br /><br />Threat actor <b>description</b>: <i>Provides services in residential real estate and insurance</i><br />Target victim <b>website</b>: <i>dunaganassociates.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Synergy-Interactive</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33612</link>
<guid>804d1c035371d0119be83a57d690b58f</guid>
<pubDate>Sun, 05 Jul 2026 13:54:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Synergy-Interactive</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bcf96419f3981b1ceff4e5068dd2bbdff19abf3f04e898f63868de34f4451fb6</i><br /><br />Threat actor <b>description</b>: <i>A provider of staffing services</i><br />Target victim <b>website</b>: <i>sinyc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>East-Texas-Family-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33611</link>
<guid>a776d3cf1b33e6e4a43d00a11c2fa783</guid>
<pubDate>Sun, 05 Jul 2026 13:53:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>East-Texas-Family-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>802052643458baa574821f5b3a21a173011e0eaceefdc34e1feb8c0a70d27e99</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization</i><br />Target victim <b>website</b>: <i>etfmed.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gold-Standard-Automotive</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33610</link>
<guid>ef152a79c2f6111858309f64e2d68ebd</guid>
<pubDate>Sat, 04 Jul 2026 20:50:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Gold-Standard-Automotive</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f996f60b4fbf8718d046bfa1a357dff5a0dac52525e36c37ff2cae162981d1b1</i><br /><br />Threat actor <b>description</b>: <i>Gold Standard Automotive Network administers vehicle service contracts sold through dealerships, offering coverage for repairs after your factory warranty ends, with claim approvals handled through the company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baraga-County-Memorial-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33609</link>
<guid>7398bb10be5667e31a146489d65cf5f6</guid>
<pubDate>Sat, 04 Jul 2026 20:50:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Baraga-County-Memorial-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01b329e5ff84ed2101a2f1027c943f30ff1913c864b0a42ec737f4944a867315</i><br /><br />Threat actor <b>description</b>: <i>Baraga County Memorial Hospital is a critical access hospital serving Baraga County with emergency, surgery, imaging, rehab, and outpatient care.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edgewood-Police-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33608</link>
<guid>41974ba26aec1036c02ecd1d7647c37d</guid>
<pubDate>Sat, 04 Jul 2026 18:20:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Wallstreet</b> claims attack for <b>Edgewood-Police-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89db9f8f13633dcc7223a7cb287efd25a9a5dc7d49c94d07e9f84f927719670f</i><br /><br />Threat actor <b>description</b>: <i>The Edgewood Police Department is part of the Pierce County Sheriff’s Department, providing public safety and law enforcement services for the city.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Wallstreet</category>
</item>
<item xmlns:dc='ns:1'>
<title>Locati-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33605</link>
<guid>06eba2d012953dea388012e907110fc4</guid>
<pubDate>Sat, 04 Jul 2026 07:56:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Locati-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ddf5002b95ab1a5e0420ebfd90b68e709fb6766495f377886f59fb7e61bff68</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.locatiarchitects.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Silvestri--Associates-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33604</link>
<guid>ff7c6b322d982194ef32e74820a3fff4</guid>
<pubDate>Sat, 04 Jul 2026 07:55:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Silvestri--Associates-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5df41a8ca463427c40637bd03a18688b591c9d58c924acfa87377f4cf8a53e20</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.silvestriandassociates.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medic-rescue</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33623</link>
<guid>e17d00b154831f31866ad96f6b352596</guid>
<pubDate>Sat, 04 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Medic-rescue</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6aa5a3048cf79c5d30000ee209d88824f3c58e95b2287ce0fd1fa654fd4f4315</i><br /><br />Threat actor <b>description</b>: <i>Medic Rescue, established in 1978, provides comprehensive emergency medical services in Beaver County, Pennsylvania. Their offerings include on-site emergency care, non-emergency transports, stretcher van trips, and wheelchair van services, all available 24/7. The company operates with a dedicated team and an extensive fleet to ensure swift and effective medical responses. Website: https://www.medicrescue.org/</i><br />Target victim <b>website</b>: <i>medicrescue.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>TQ-Financial-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33603</link>
<guid>7438845b5943e3d61cb4964f2bc218ad</guid>
<pubDate>Fri, 03 Jul 2026 20:54:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TQ-Financial-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e52491b24f3f5b94e0e69517f20842a43777d68831ae16f759e26fa4c0f50c07</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Md-Lewis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33602</link>
<guid>54e0f485f4daf036e45e7ec3e246ef67</guid>
<pubDate>Fri, 03 Jul 2026 18:30:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Md-Lewis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95e8101bd696f0fe72bd1abd77d9c4eb6f50e0ad7d6aba1fef03afc132b7b7d2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mdlewiscpa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goodwill-Manasota</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33601</link>
<guid>d15505e6d277a01b10c86b9137f57d69</guid>
<pubDate>Fri, 03 Jul 2026 18:29:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Goodwill-Manasota</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5a586cf32e7c5f5d3e3ee7dac97a6653d9af61bdbaacd9e56cf69793df82cc6</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.experiencegoodwill.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sitmatic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33600</link>
<guid>4424206bb5705836a4bced27f9dfa350</guid>
<pubDate>Fri, 03 Jul 2026 18:28:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sitmatic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20c64908b3f681270231af32fd642a24b4faf8dbedca7566d7fa42d2906953e1</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sitmatic.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AC-Beverage-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33583</link>
<guid>baa0ceb9d3bf8583d22479f67f86d67d</guid>
<pubDate>Fri, 03 Jul 2026 10:58:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>AC-Beverage-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67e23f57fd13b225dd9c3853125b7a795c44b4a9e3a8b518ac2edd3c774e5b63</i><br /><br />Threat actor <b>description</b>: <i>Provider in the draft beer service industry, specializing in the installation of high-quality systems and beer line</i><br />Target victim <b>website</b>: <i>acbeverage.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>oakparkmi.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33579</link>
<guid>9640700c442214957adbe5aa77e2ace3</guid>
<pubDate>Fri, 03 Jul 2026 00:55:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>oakparkmi.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3e62b18c6a5087c597e353e7d853bda2ba3e57f21a244bd4996bc66bd6690cf</i><br /><br />Threat actor <b>description</b>: <i>Oak Park, Michigan, is a vibrant, diverse inner-ring suburb of Metro Detroit located in Oakland County. Incorporated as a city in 1945, it spans 5.5 square miles and is home to roughly 30,000 residents. The city is currently experiencing a renaissance, transforming areas like the 11 Mile Road corridor into bustling hubs with breweries, restaurants, and new community spaces.</i><br />Target victim <b>website</b>: <i>oakparkmi.gov</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>tricountyhs.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33576</link>
<guid>11ae7bbc40d97d9fdf8f375606198ebb</guid>
<pubDate>Thu, 02 Jul 2026 16:54:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>tricountyhs.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b438f0fcea7cfbd45546518806c2e57583797810530de18e0354b6895be555b1</i><br /><br />Threat actor <b>description</b>: <i>Flowers Early Learning (formerly known as Tri-County Head Start) is a non-profit 501(c)(3) organization providing free, high-quality early childhood education and family support services across Berrien, Cass, and Van Buren counties in Southwest Michigan. Funded by a federal grant through the Office of Head Start, the organization serves eligible families with children from birth to age five, as well as expectant mothers.</i><br />Target victim <b>website</b>: <i>tricountyhs.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>acworth-ga.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33575</link>
<guid>73ea78729d717e6a435948b8912a67cf</guid>
<pubDate>Thu, 02 Jul 2026 16:32:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>acworth-ga.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>50e5bd03c57a1324dc186c6913a571464c57a9e1465057d98c1026463cddfd70</i><br /><br />Threat actor <b>description</b>: <i>Acworth is located in the foothills of the North Georgia mountains and is nestled along the banks of Lake Acworth and Lake Allatoona, hence its nickname “The Lake City.” The city boasts a rich history, a charming downtown, abundant outdoor recreational activities, a vibrant restaurant scene, and an active festival and events calendar. Acworth is one of the best, family-friendly destinations in the Atlanta region.</i><br />Target victim <b>website</b>: <i>acworth-ga.gov</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>hamilton-eye.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33572</link>
<guid>41220f414a6e40d921767181f83ae321</guid>
<pubDate>Thu, 02 Jul 2026 16:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>hamilton-eye.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5eb9d0a9cb30703ef6f10ca8cab496e071f6dc479ba7a1192ba20aa662b07ee</i><br /><br />Threat actor <b>description</b>: <i>Hamilton Eye Institute is a comprehensive vision care practice operating out of two Pennsylvania locations: Allentown and Easton. They provide routine eye exams, medical/surgical eye treatments, and an in-house MediSpa.</i><br />Target victim <b>website</b>: <i>hamilton-eye.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Salters-propane</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33562</link>
<guid>975d9f0ff98ed5bc3f6c862609372b59</guid>
<pubDate>Thu, 02 Jul 2026 06:33:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Salters-propane</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2c2185076571ec74d7824bb818f9ba499241cbd3204571190b41a3473604c9b</i><br /><br />Threat actor <b>description</b>: <i>Salter’s Propane is excited and proud to be joining the Salter’s Family of businesses with competitive pricing, excellent customer service, and 65 combined years of industry experience. We are ready and more than capable to service all of your propane needs.From residential to commercial and everything in between we are confident that your experience with us will be nothing short of spectacular.We have many options available to suit your needs including a variety of tank sizes, and we offer competitive lease or purchase options.-Personal information of employees and clients -Financial documents -Other files https://***.com/</i><br />Target victim <b>website</b>: <i>salterspropane.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeast-Pediatrics--Adolescent-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33561</link>
<guid>0401ed6796f1f9b637d18a4ba337e1d6</guid>
<pubDate>Thu, 02 Jul 2026 03:21:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Northeast-Pediatrics--Adolescent-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bac4004f21ed1805a9cfa7c6e16af3f237934b997397ea263dfe8c66f6f4905d</i><br /><br />Threat actor <b>description</b>: <i>Data breach exposes employees and patients of a pediatric clinic.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colorado-Rehabilitation-and-Occupational-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33560</link>
<guid>6bca76cea8f3c180cd035d70f9bc7b0c</guid>
<pubDate>Thu, 02 Jul 2026 00:28:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Colorado-Rehabilitation-and-Occupational-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a20dc3f379b3efbdfc1339cf69c76457d0d2ab16074db4afac008f72196f741b</i><br /><br />Threat actor <b>description</b>: <i>Colorado Rehabilitation & Occupational Medicine (CROM) is a leading Denver-area physiatry practice specializing in non-surgical treatments for musculoskeletal and neurological conditions. Founded in 1992, CROM operates multiple clinics across the Front Range, focusing on helping patients recover from sports, work, and auto injuries without narcotics or surgery.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shamrock-holdings-inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33597</link>
<guid>96b7e445281a191b3922d814aae420ce</guid>
<pubDate>Thu, 02 Jul 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Shamrock-holdings-inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53064202e5a8294d37bdb350bd79bc8071d9487ae4436332b062836af632c5ec</i><br /><br />Threat actor <b>description</b>: <i>Shamrock Holdings, Inc. is an investment firm founded by Roy E. Disney in 1978, primarily serving the investment needs of the Disney Family. The company emphasizes integrity, responsibility, and transparency in its operations. In addition to its investment activities, Shamrock manages various real estate investment programs through a subsidiary. Website: https://www.shamrock.com/</i><br />Target victim <b>website</b>: <i>shamrock.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dadolighting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33556</link>
<guid>e4896488c5652d4055ab54948d9a6284</guid>
<pubDate>Wed, 01 Jul 2026 22:32:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Dadolighting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3eeedaf1cf830a596e118f17f43c1d2c0695e0cb37c60eb711ee03ec16974d8</i><br /><br />Threat actor <b>description</b>: <i>Organization with 17 emails extracted. Domain: dadolighting.com</i><br />Target victim <b>website</b>: <i>dadolighting.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bell-Hardware</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33548</link>
<guid>fb4f401f943fac2830a81ac63178e9a4</guid>
<pubDate>Wed, 01 Jul 2026 22:21:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Bell-Hardware</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2ca00b03da16461ccf50c365af5d5b17ab003dca0ba41fd783a1ade25874998</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/bell-hardware/353995383 Bell Hardware is a premier supplier of premium commercial doors, frames, and architectural hardware, operating out of seven locations across Oregon and Northern California.They act as a comprehensive one-stop shop for contractors, providing high-quality building products alongside expert on-site installation and modification services.Furthermore, the company partners with design and construction teams during the early planning stages to evaluate project elements and streamline the building process</i><br />Target victim <b>website</b>: <i>bellhardware.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Natren</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33546</link>
<guid>2bf720f77d3874e07949cfcd1f75e91e</guid>
<pubDate>Wed, 01 Jul 2026 22:21:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Natren</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91f1e1103dcd473e52770a1b558743853de444305495403ffa61ca70cc91aa55</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/natren-inc/26870087 Natren is a leading manufacturer of premium probiotic supplements with over 30 years of experience, dedicated to improving gut health and overall well-being.Based in California, the company offers a comprehensive range of natural, non-GMO formulas tailored for men, women, children, and even pets.They are highly regarded for their flagship "Healthy Trinity" 3-in-1 system and their strict cold-chain shipping process, which guarantees 100% potency through the expiration date</i><br />Target victim <b>website</b>: <i>natren.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ayres-Carr--Sullivan-P.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33544</link>
<guid>be5b7dd09833f473d70afbf4c2f8642b</guid>
<pubDate>Wed, 01 Jul 2026 22:21:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Ayres-Carr--Sullivan-P.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>432bd69bc0c83d9ac5d890aadfa31d39533f9d4809148b50acbb49650a830c7e</i><br /><br />Threat actor <b>description</b>: <i>Ayres Carr & Sullivan, P.C. is a longstanding, general civil practice and trial law firm based in Indianapolis, Indiana. Tracing its roots back to 1914, the firm serves clients across the state with a focus on civil litigation, trial practice, and specialized matters including probate, bankruptcy, and corporation law. Primary Location: 251 E. Ohio St., Suite 500, Indianapolis, IN 46204 Primary Practice Areas: Civil Litigation, Trial Practice, Personal Injury, Corporation Law, Probate, and Bankruptcy Key Attorneys: William S. Ayres, John R. Carr III, and Bret Clement https://www.***.com/company/ayres-carr-&-sullivan-pc</i><br />Target victim <b>website</b>: <i>www.linkedin.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-City-of-Boyne-City</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33531</link>
<guid>3cce7df3fe2fd70bd214726f58d08fa4</guid>
<pubDate>Wed, 01 Jul 2026 22:18:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>The-City-of-Boyne-City</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>727e90eb8f1b93b4d831171f20f24e3e5eb9da023a86fc136076c6d6d9028db4</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/the-city-of-boyne-city/368244116 City of Boyne City, a community located in Charlevoix County, Michigan. It serves as a central hub for residents, providing essential information on local government, city departments, utility services, and community events. The portal also highlights the city's parks, recreation programs, and local initiatives, reflecting its vibrant lakeside lifestyle on Lake Charlevoix</i><br />Target victim <b>website</b>: <i>cityofboynecity.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wacha-Justen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33529</link>
<guid>8b5b6156bcba19118b7e25c945d8b5b6</guid>
<pubDate>Wed, 01 Jul 2026 22:18:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Wacha-Justen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>450a0991bd7f85301887d87eb0ba7cadc4ef6e1dd9f55f05a80341bb09fa56f0</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/wacha--justen-llc/357327144 Wacha & Justen, LLC, a dedicated law firm based in Napoleon, Ohio. The firm provides comprehensive legal services, including estate planning, personal injury, car accident claims, and general civil litigation. With a strong local presence, their experienced attorneys offer reliable representation to individuals and businesses throughout the region</i><br />Target victim <b>website</b>: <i>nwohlaw.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CUI-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33528</link>
<guid>8f6a418c8c78d211e6fc70c05546f422</guid>
<pubDate>Wed, 01 Jul 2026 22:17:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>CUI-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5672c348d370bcd8518ddb5427fe728a3a13d95fbacfa24c4ba804f5834afc5</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/cui-agency/397459082 CUI Agency, a family-owned independent insurance firm founded in Utah in 1969. Headquartered in the Salt Lake City area, the company specializes in risk management, offering comprehensive commercial insurance, employee benefits, personal lines, and bonds. They provide tailored insurance solutions designed to mitigate risks and protect the assets of businesses and families across the region</i><br />Target victim <b>website</b>: <i>cuiagency.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>eaglecrestlife.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33521</link>
<guid>6111d0bb6f0c295edd4fd332d23328d5</guid>
<pubDate>Wed, 01 Jul 2026 20:34:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>eaglecrestlife.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb383b806461618d2cc536b7412e7b85f745495f9384a5437327f15b06f46c2f</i><br /><br />Threat actor <b>description</b>: <i>Operating under Bethany Lutheran Homes, Inc., the organization has served the region since 1946 and is recognized as the largest …</i><br />Target victim <b>website</b>: <i>eaglecrestlife.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>COMHAR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33518</link>
<guid>5e7ce02afd479a1ff12bc405e3af182a</guid>
<pubDate>Wed, 01 Jul 2026 18:01:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>COMHAR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>898d5c17ccf5d8585246f9c158e26c83a3ad291db288b1b3774e07f6cd21f7b7</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Refinery-Hotel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33497</link>
<guid>3ab8ead9635bb05d63b15c8ce9623d9e</guid>
<pubDate>Wed, 01 Jul 2026 15:58:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Refinery-Hotel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e3a66567f8282481cb61a2b9955674aaa01e0773d9bf29736011ada44838927</i><br /><br />Threat actor <b>description</b>: <i>Refinery Hotel is a luxury hotel located near Bryant Park in New York City, offering a modern reinterpretation of a historic hat factory. The hotel features 197 stylish rooms with industrialaccents and modern amenities, alongside dining options such as the Parker & Quinn restaurant and the Refinery Rooftop bar.We will upload 15gb of corporate data soon. Employee personal information (passports, DLs, SSNs, w9 forms), guests information, financials, contracts and agreements, lots of NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>digitaldynamics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33516</link>
<guid>86a2cd9c81622bc127010daa5acce587</guid>
<pubDate>Wed, 01 Jul 2026 15:51:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>digitaldynamics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56cf3b295e1239096440e0dbd076e4ecbe9dd3f9f74aa80d6ae38655f6f5a36c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>digitaldynamics.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>goldenstateortho.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33515</link>
<guid>b2c2fc5ac884cfbbf3f384adbacf2195</guid>
<pubDate>Wed, 01 Jul 2026 15:51:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>goldenstateortho.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dff7a669754b18805e58dde441d0af1d84067853124c268f1b64b2b3cad5aaef</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Golden State Ortho appears to be an orthopedic medical practice or orthopedic supply company based in the United States, likely California given the "Golden State" reference. It operates in the healthcare industry, potentially offering orthopedic surgical services, prosthetics, orthotics, or related medical products and patient care. Specific verified details about this company are limited, so full operational details cannot be confirmed with certainty.</i><br />Target victim <b>website</b>: <i>goldenstateortho.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>printronix.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33514</link>
<guid>ca3f6e75176256acc0e0756a3f8eccea</guid>
<pubDate>Wed, 01 Jul 2026 15:50:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>printronix.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c05eb0e456f4e75507340d8156dfe6e32baabb5aed3a2c26abd91240d7570d4</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Printronix is a US-based company specializing in industrial printing solutions. Founded in 1974 and headquartered in Irvine, California, it manufactures line matrix printers, thermal printers, and related accessories primarily for enterprise and industrial environments. Its products serve industries such as manufacturing, logistics, and supply chain management, offering high-volume, mission-critical printing capabilities used in warehouses and distribution centers worldwide.</i><br />Target victim <b>website</b>: <i>printronix.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dennis-Waters-Rental-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33498</link>
<guid>a237b92992583b53799e534ee1e915fc</guid>
<pubDate>Wed, 01 Jul 2026 14:59:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dennis-Waters-Rental-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5bdc8e3c180700ab824e4dbba84c0ad37f228365de8de5cef8da78f13c2a5ff</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mattatuck-Industrial-Scrap-Metal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33499</link>
<guid>5b9e3317e97a8e48fd98477d8d0f22e4</guid>
<pubDate>Wed, 01 Jul 2026 14:59:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mattatuck-Industrial-Scrap-Metal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a9fe23bc3f8aec9e66a98d0fc04c51617a8ed14541995681092bc72c1a72246</i><br /><br />Threat actor <b>description</b>: <i>Energy, Utilities & Waste</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Laughlin-Nunnally-Hood--Crum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33500</link>
<guid>0cd5d9d528e8f06f787079c89480f5dc</guid>
<pubDate>Wed, 01 Jul 2026 14:59:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Laughlin-Nunnally-Hood--Crum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e7b1d3c2f68c99c0922a1a1e02d617ecf29a147c1b34dd0e20d61b327356504</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dixie-Beverage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33503</link>
<guid>40ee0aa7de905226c097acc8c6b76d7f</guid>
<pubDate>Wed, 01 Jul 2026 14:59:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dixie-Beverage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3611ca0968aeb47147cebedc1b91b1480180b02d5923e5f6a488280a2faeab8f</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.northern-access.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33506</link>
<guid>9717b5c8bd4b8dc15925b7d42a7a9c0d</guid>
<pubDate>Wed, 01 Jul 2026 13:55:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>krybit</b> claims attack for <b>www.northern-access.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8cce2dbb3639f907a81b52f7b59598b377b5266bebca7957e5c3d11a97f68b6</i><br /><br />Threat actor <b>description</b>: <i>Northern Access Transportation, Inc. is a locally owned American company founded in Duluth, Minnesota, USA, dedicated to...</i><br />Target victim <b>website</b>: <i>www.northern-access.com</i>]]></description>
<category>krybit</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fluke-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33496</link>
<guid>4428d361dbb6f73f849bf17d85c0aee7</guid>
<pubDate>Wed, 01 Jul 2026 10:29:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Fluke-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d787cec84f46a2c513f1dd9093ce4cc57213d291941d737298fc5d0384e9670</i><br /><br />Threat actor <b>description</b>: <i>Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 100GB+ | Updated: 02 July 2026 | SHA256: 6ee9bd06756efceb56e5c56fd4e8ab3a8006b9cb80e7c0b4405ed15b996c05fe</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ingram-Content-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33495</link>
<guid>29858c81fe45027d55d1d2c79841ab9a</guid>
<pubDate>Wed, 01 Jul 2026 10:29:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Ingram-Content-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e608f3f8d321f8b1588152a5a2e28d5909efdc644d6021532e733101aebce4f</i><br /><br />Threat actor <b>description</b>: <i>The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Updated: 02 July 2026 | SHA256: f3c961b709bcff8f70dbb8361116831d2c86361754a09658115b9efed39308e5</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Western-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33466</link>
<guid>dc07e93076253017193100356d788742</guid>
<pubDate>Tue, 30 Jun 2026 18:58:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Western-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66fd63cc5bd38a73a091835a24ee08e6b53f21774baaf16825c115c32385e9cd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wciboise.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>universalplant.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33465</link>
<guid>e72c36d5e1c698671c7bda2da9938f89</guid>
<pubDate>Tue, 30 Jun 2026 16:54:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>universalplant.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9435dc055030b2a987f0eeb45084d5616062325775ea6a548a792914d77d85f5</i><br /><br />Threat actor <b>description</b>: <i>FINAL NOTICE: UNIVERSAL PLANT SERVICES (UPS)

We are in possession of 315 GB of your corporate, financial, and operational data. Our analysis confirms that this archive contains highly sensitive information, including:

    Financial & Accounting: Full audits, tax filings (ADP), payroll, bank transa…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/universal-plant-services-inc/353963066</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>paipharma.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33464</link>
<guid>180933be379609eaf8430b56c790acda</guid>
<pubDate>Tue, 30 Jun 2026 16:50:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>paipharma.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4be78eee0ac3af2eaa9bab7ebf032ebe7cedd465ee4f9167a8d4721b97417e21</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>paipharma.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brooklyn-Defender-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33463</link>
<guid>884b3aa9e6d34c33acd37f08fc85a2e3</guid>
<pubDate>Tue, 30 Jun 2026 15:55:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Brooklyn-Defender-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c11c82df1014d3e270702b02496bd8b7d15ea5264a6835304fdcfb795a040ad6</i><br /><br />Threat actor <b>description</b>: <i>A legal organization dedicated to safeguard the rights of its clients</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>orion4value.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33461</link>
<guid>c07be9421fc64b8e8ca2ebc12fcbd59d</guid>
<pubDate>Tue, 30 Jun 2026 13:28:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>orion4value.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1bbb933c9a0b841b2ab36ec029867d1d32f6bf300a571bb4dcb5742985a4898a</i><br /><br />Threat actor <b>description</b>: <i>THE CERTIFICATE AS A VULNERABILITY: Documents of Orion Registrar Inc. PROLOGUE Financial reports and...</i><br />Target victim <b>website</b>: <i>orion4value.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>clc-tn.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33459</link>
<guid>9b949ed09d89d211938bc18620855069</guid>
<pubDate>Tue, 30 Jun 2026 12:57:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>clc-tn.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>022f1036a4f061d99e9766c166933db94db0f934f3f90bbec77bb089b859376c</i><br /><br />Threat actor <b>description</b>: <i>City Lumber Company: Building Materials in Tennessee — What Lies Behind the Small Sign PROLOGUE In o...</i><br />Target victim <b>website</b>: <i>clc-tn.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>joyconstructionnyc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33458</link>
<guid>e9fd517b70fc6eb73427f2a01e672d22</guid>
<pubDate>Tue, 30 Jun 2026 12:35:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>joyconstructionnyc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ec6f279b252d2fbca77b03518acf5350af191699bfe80a1b33387038f95271e</i><br /><br />Threat actor <b>description</b>: <i>Joy Construction Corp: $1.3 Billion in Affordable Housing — and $8.7 Million to a Shareholder in Six...</i><br />Target victim <b>website</b>: <i>joyconstructionnyc.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>wilfley.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33457</link>
<guid>5a68e6cc0195b878aa5ff70df000cd5c</guid>
<pubDate>Tue, 30 Jun 2026 12:34:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>wilfley.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea4fc73e0a2d3ab0b7d5eb332103173e667e01f9e660c1346740e3d06040f3c0</i><br /><br />Threat actor <b>description</b>: <i>SEAL FAILURE A company that builds pumps for chemical and defense production — and undertakes to con...</i><br />Target victim <b>website</b>: <i>wilfley.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spector-and-Lenz-PC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33456</link>
<guid>4012e4ca51f4f19e7d001e568a7f4394</guid>
<pubDate>Tue, 30 Jun 2026 12:29:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Spector-and-Lenz-PC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c5ff24b0687ef3a9b805833a25a37eb2f25a9117d41a777bf7c8fe53adbbfcc</i><br /><br />Threat actor <b>description</b>: <i>Firm provides legal representation to clients facing disability, injury, or serious illness</i><br />Target victim <b>website</b>: <i>spectorandlenz.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sociedad-Latina</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33454</link>
<guid>29eaedf7193718f69931e38f593c37fd</guid>
<pubDate>Tue, 30 Jun 2026 12:28:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Sociedad-Latina</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82bb927d6076f141155ed6105055b0e9a0f0af1afd47b29e12f0854cd5c561f5</i><br /><br />Threat actor <b>description</b>: <i>Support in education, civic engagement, workforce development, and arts and culture, specifically tailored for multilingual learners</i><br />Target victim <b>website</b>: <i>sociedadlatina.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>on-us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33452</link>
<guid>a14404ebc4ea86cc65ac48f671cc203e</guid>
<pubDate>Tue, 30 Jun 2026 12:25:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>gunra</b> claims attack for <b>on-us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5eee5db3fcd29c5ac7a213d9699ce5468618b16b10cec32db5826821dbe42a72</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>on-us.com</i>]]></description>
<category>gunra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yuditec-S.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33451</link>
<guid>5e7cefa9b606dcd7b0faa082d82cdb1d</guid>
<pubDate>Tue, 30 Jun 2026 12:24:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>gunra</b> claims attack for <b>Yuditec-S.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aded4c863c7544b228d960ecebee098412f0550dbce1e7b40bf209bc17532824</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>yuditec.com</i>]]></description>
<category>gunra</category>
</item>
<item xmlns:dc='ns:1'>
<title>About-Todd-Hamaker--Johnson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33450</link>
<guid>e8f3e46d6d09f9b4ab31ab13ad69b841</guid>
<pubDate>Tue, 30 Jun 2026 12:20:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>About-Todd-Hamaker--Johnson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c35fe721a148d2fe509b6e5f47d07f8cbb34557504559be81cde966ebdf69a1e</i><br /><br />Threat actor <b>description</b>: <i>Todd, Hamaker & Johnson, LLP is a professional tax and accounting firm based in Lufkin, Texas, 
dedicated to providing personalized services to both individuals and businesses. The firm offer
s a comprehensive range of services including tax, accounting, audit, and financial guidance.

We will upload 40gb of corporate data soon. Lots of client and employee personal information (p
assports, SSNs, DLs and other information), detailed financials, client financials and other co
nfidential client docs, contracts and agreements, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>rcfassoc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33449</link>
<guid>06524331e2c63c0ed3479bf1be85ce3b</guid>
<pubDate>Tue, 30 Jun 2026 12:03:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>rcfassoc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>943d156f56c3bbb201c0e179245b1e52030faca870df8eb909e00ae12cc01da5</i><br /><br />Threat actor <b>description</b>: <i>R.C. FIELDS &amp; ASSOCIATES: Client Data, Hidden Development Risks, and Uninvestigated Security Inc...</i><br />Target victim <b>website</b>: <i>rcfassoc.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Business-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33448</link>
<guid>1d26b569fd3472b83bde7bbeb161ddfa</guid>
<pubDate>Tue, 30 Jun 2026 11:50:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Advanced-Business-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17846cf18b4fe7a64e0d94bcdcf9d3857fec31164e5bf28464acec5ccfdcf863</i><br /><br />Threat actor <b>description</b>: <i>Advanced Business Systems, Inc. is a locally owned business serving the Quad Cities area, speci
alizing in a wide range of office products and solutions including copiers, printers, IT servic
es, phone systems, and furniture.

We will upload 31gb of corporate data soon. Employee personal information (88 SSNs, passports a
nd other docs), NDA, projects, contracts and agreements, customer information and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>owensborograin.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33447</link>
<guid>0dc852c25b04feeb7c607e85fbafe724</guid>
<pubDate>Tue, 30 Jun 2026 11:32:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>owensborograin.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fca081718e3b136277ef30d950dd69cb0ed5e703a7d83dafb4dee2482fca742c</i><br /><br />Threat actor <b>description</b>: <i>PROCESSING: GRAIN IN SOMEONE ELSE'S MILL PROLOGUE Tax returns filed with the IRS under threat of "fi...</i><br />Target victim <b>website</b>: <i>owensborograin.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>touredge.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33445</link>
<guid>dd2123d4ed992ad5710750cfbae4414b</guid>
<pubDate>Tue, 30 Jun 2026 11:03:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>touredge.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>868dfb9d92c194cf4ad024bbcfe3b57932e7dcb74ceaf02a77e6b1538fd841ed</i><br /><br />Threat actor <b>description</b>: <i>The Breaking Point A golf club manufacturer sells precision, durability, and control as a philosophy...</i><br />Target victim <b>website</b>: <i>touredge.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>vcnyhome.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33444</link>
<guid>13c82439d5287ddb2a87783e3d19c965</guid>
<pubDate>Tue, 30 Jun 2026 11:02:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>vcnyhome.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffbcf92fcf3a143374d52821cdfe40699eeb31c3d32b2bf13dca2f1376a61a70</i><br /><br />Threat actor <b>description</b>: <i>THE VCNY HOME ARCHIVE The company that sells home comfort failed to protect its own home — its inter...</i><br />Target victim <b>website</b>: <i>vcnyhome.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>infinedi.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33443</link>
<guid>c9627679e7b2b548560221d9c07ca79b</guid>
<pubDate>Tue, 30 Jun 2026 11:01:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>infinedi.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08fef109dbeebb75b484b31f8700998a6c170809d25240cfc595d6c8827f8454</i><br /><br />Threat actor <b>description</b>: <i>Clearinghouse The company doctors pay to keep their patients' data safe. This article presents only ...</i><br />Target victim <b>website</b>: <i>infinedi.net</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medlink-Georgia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33440</link>
<guid>90cb3ed89c2f43d306361df547bfd25d</guid>
<pubDate>Tue, 30 Jun 2026 08:20:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Medlink-Georgia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bc52351164d27235bce27ed84342bf343ffa63b92582f12b96f4c7ac3cbf6ef</i><br /><br />Threat actor <b>description</b>: <i>We have proudly been serving northeast Georgia since 1976. As a federally qualified health center, we are able to offer uninsured and underinsured patients a sliding fee scale. No one is denied services due to lack of income or insurance status.At MedLink Georgia, we strive to provide comprehensive, coordinated, and continuous care to all our patients. We offer a broad array of primary and preventive care services for patients of all ages, including screening, diagnosis, and management of chronic illnesses.</i><br />Target victim <b>website</b>: <i>www.medlinkga.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Port-Angeles-Composite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33439</link>
<guid>73161ae4a44563cfc1f24c15232bb3f0</guid>
<pubDate>Tue, 30 Jun 2026 06:20:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Port-Angeles-Composite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95633b082ca2ebbee61f1f74a3ea339814696851fb8d9f4edcdd0aa174dcd231</i><br /><br />Threat actor <b>description</b>: <i>Port Angeles Composite LLC (PAC) is a leading supplier of advanced structural composite assemblies and components, serving the global commercial and business aerospace markets. Originally founded in 1996 as Angeles Composite Technologies, PAC was acquired by Honda Aircraft Company in October 2025. The company operates from a state-of-the-art manufacturing facility on Washington State’s Olympic Peninsula, supporting customers such as Boeing, Bombardier, and Honda Aircraft with high-quality composite structures for new aircraft systems. PAC's advanced manufacturing processes and technology ensure the highest quality composite products, offering tailored solutions to meet the unique requirements of each aerospace customer.</i><br />Target victim <b>website</b>: <i>www.pacomposite.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arkin-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33438</link>
<guid>87eb9d4eaa03cf39630cf48a920d1920</guid>
<pubDate>Tue, 30 Jun 2026 05:51:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Arkin-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd2e42102ecc0d620b291a0b9f294e51112b7d05ccdb27a564d517c9c158eebf</i><br /><br />Threat actor <b>description</b>: <i>CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach in Northern Cyprus. According to preliminary assessments, the attackers managed to exfiltrate over one terabyte of internal documents, customer databases, and transaction logs, including confidential information from the Arkın Palm Beach Casino.▎Attack detailsAnalysts have established that the attackers gained initial access through a compromised employee account in the reservations department. Using legitimate remote administration tools, they gradually expanded their privileges, bypassed network segmentation, and exfiltrated a dataset totalling approximately 1.4 TB. Some of the stolen information has already surfaced on underground forums and darknet marketplaces.The stolen data includes:• Full guest profiles (passport details, phone numbers, addresses, stay history);• Financial details of bookings and payment credentials;• The internal CRM system with staff notes on VIP clients;• Casino database: player IDs, deposit amounts, visit frequency, records of chip exchange transactions and fund movements;• Scanned passports, compliance check forms (KYC/AML), including source-of-funds questionnaires for high rollers.▎Objective and likely operatorBased on the intrusion characteristics and tactics used, experts link the incident to the threat group “CryptoRex” (tracked since 2023), which specialises in attacking hospitality and gambling businesses in the Mediterranean region. A combination of financial extortion and data sale to multiple buyers is considered likely. So far, no official ransom demand has been received, but portions of the archives have been put up for auction with a starting price of 8 bitcoins.▎Potential consequences of the leakThe leakage of confidential guest and especially casino client data entails a cascade of risks that go far beyond reputational damage.1. Personal security of high-net-worth guestsThe VIP casino player database, containing passport details, habits, and financial capabilities, serves as a direct “directory” for kidnappers, extortionists, and organised crime groups. Affected individuals may face real threats to their physical safety, as well as targeted blackmail (e.g., threats to expose gambling activity to business partners or family members in countries where gambling is stigmatised).2. Financial fraudPayment data from hotel guests and credit/debit cards linked to casino accounts will enable unauthorised transactions. Given the high credit limits of casino patrons, the scale of potential phishing and card fraud is assessed as very significant.3. Compliance nightmare and regulatory finesAlthough the international casino operators in Northern Cyprus do not directly fall under GDPR, many guests are citizens of the EU, the UK, and CIS countries. The breach demonstrates a flagrant failure to meet personal data protection standards. Lawsuits by affected individuals in national courts and scrutiny by international payment systems (Visa, Mastercard) are possible, which could suspend acquiring services.4. Risks to the casino itself and the jurisdiction[6/9/2026 1:09 PM] ChatGPT 5 | Deepseek | Claude: The exposure of internal AML records documenting the origin of funds and possible links to politically exposed persons could spark money-laundering investigations. For Northern Cyprus’s gambling zone, already under close watch by the FATF, this could lead to tighter international financial monitoring and being placed on grey lists.5. Reputational ruinNo wealthy client will entrust their data to a hotel incapable of protecting basic IT infrastructure. Trust in the Arkın brand, which for decades has built an image of secluded luxury, will be undermined for years. Competitors in the elite leisure market, especially in Dubai, Monaco, and the Maldives, will immediately exploit the situation to poach wary clientele.▎Analysts’ recommendationsCyclops Threat Intelligence strongly advises all individuals who have ever stayed at Arkın hotels or visited Arkın Palm Beach Casino to:• Immediately block and reissue any bank cards used;• Monitor credit reports for new applications;• Enable additional authentication factors on email and financial services;• Be highly critical of any incoming calls or messages demanding identity confirmation or fund transfers — these could be targeted attacks using contextual details from the leaked staff notes.The Arkın Group press office has not yet responded to official inquiries. The company’s website remains operational, but online booking sections are temporarily unavailable. Northern Cyprus authorities stated that they are “aware of the incident” and have begun consultations with EU experts under a cyber-resilience programme.Report prepared by the Thomson Reuters cybersecurity desk based on the Cyclops Threat Intelligence analytical brief.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.maytrucking.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33437</link>
<guid>34da6a962eea0b40287791e44c671be6</guid>
<pubDate>Tue, 30 Jun 2026 04:54:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>www.maytrucking.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fea8e116c68810a1b53539257b2409b9a020c2214b4ce0e721094e170f66893e</i><br /><br />Threat actor <b>description</b>: <i>May Trucking Company is a family-owned interstate transport carrier founded in 1945, headquartered in Brooks, Oregon. They provide dry freight and temperature-c... - TOTAL QUANTITY OF DATA 1 TB</i><br />Target victim <b>website</b>: <i>www.maytrucking.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>guardianbarrierservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33436</link>
<guid>2a0cd96109ce91ee405ae528cf582e19</guid>
<pubDate>Mon, 29 Jun 2026 21:51:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>guardianbarrierservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3537e36e1af393ec129df1dc8e7f4923dc576dba5e6e97db0bdf7daac43ad79b</i><br /><br />Threat actor <b>description</b>: <i>Guardian Barrier Services provides a wide range of products and services for events, including crowd control barriers, cable ramps, truss structures, and temporary flooring. Their experienced team supports clients from the planning stage to the ex</i><br />Target victim <b>website</b>: <i>guardianbarrierservices.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bristol-Place</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33418</link>
<guid>6fad521eccb011f87db75444e82f0b70</guid>
<pubDate>Mon, 29 Jun 2026 15:54:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bristol-Place</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4b0b5b2b3dc5e515ab2f613d0c6c611bb2c4da39c188440c6285007e711470d</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gsma</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33419</link>
<guid>4d2cb51e2b2bd88889ce18c38d865a8d</guid>
<pubDate>Mon, 29 Jun 2026 15:54:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Gsma</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>088d81ea423aa182dea2c7aa9a6fd874b57b85e9b94e8c74f4d35bfeaeafc72a</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>vipimaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33423</link>
<guid>e817d8f1c167c64e069ef31d3e8826c2</guid>
<pubDate>Mon, 29 Jun 2026 15:53:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>vipimaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd921444ee0fc82b4a646caae18459d81a7925669233e8ddb19bcc93fc7e5086</i><br /><br />Threat actor <b>description</b>: <i>VIP Imaging is the largest mobile nuclear imaging company in Southern California, specializing in cardiac PET/CT and SPECT studies for cardiologists. The compan...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bonacio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33427</link>
<guid>a8a12a71805851cf6052a8eaa344dbff</guid>
<pubDate>Mon, 29 Jun 2026 15:28:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Bonacio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>faefd4553f7b5d3c822ff7edb1c596cda7d0e73128c8e2b0e7873775dbff6601</i><br /><br />Threat actor <b>description</b>: <i>Bonacio Steel is a division of Bonacio Construction that provides comprehensive steel design and fabrication services, specializing in both commercial and residential projects in the Northeast. With a 35-year history of construction accomplishments, they offer innovative solutions including structural steel fabrication, installation, and custom ornamental metals. Bonacio Steel caters to a variety of industries such as equine, medical, retail, and residential, ensuring quality and timely delivery through their skilled team. Committed to integrity and community impact, Bonacio Steel continuously improves its processes to meet the diverse needs of general contractors, developers, and custom home builders.</i><br />Target victim <b>website</b>: <i>www.bonacio.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Boston-Orthotics--Prosthetics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33425</link>
<guid>8f4d106e0d6a2b29d5646210aa2b797a</guid>
<pubDate>Mon, 29 Jun 2026 14:21:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Boston-Orthotics--Prosthetics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2462494a132c009c6656bd620f0c4ae661b3f55d435de95153b022d9dc0766c</i><br /><br />Threat actor <b>description</b>: <i>Patient data breach at yet another negligent clinic.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abans-Finserv</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33504</link>
<guid>17987b65d867645b75e0218b503e2377</guid>
<pubDate>Mon, 29 Jun 2026 13:22:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Abans-Finserv</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df717cb72818f015ebd01fb7da6bb3584c84c7ad23ac122a148e31e5f7dcaaaa</i><br /><br />Threat actor <b>description</b>: <i>The Abans Group is a globally diversified organization engaged in Investment Management, Trading, Broking, Gold Refining, Non-Banking Financial Services, Agricultural Trading, Software Development, and Real Estate Development.We are globally diversified organisation engaged in Financial Services, Gold Refining, Jewellery, Commodities Trading, Agricultural Trading and Warehousing, Pharmaceuticals Distribution, Software Development and Real Estate. The group is founded by young entrepreneur - Mr. Abhishek Bansal who leads a global team of over 300 people operating growing businesses from multiple locations including India, United Kingdom, Dubai, Shanghai, Hong kong, Mauritius and Singapore.Our Company represents the financial services arm of the Abans Group. We operate a diversified global financial services business, headquartered in India, providing NBFC services, multi-asset global institutional trading in equities,Since the inception of our Company in 2009-10, we have grown from being a commodities trading company into a diversified multi-asset and multi-national financial services company having varied financial services businesses which are mainly organised under:NBFC Business: We are a Non Banking Financial Company registered with RBI and having a Total Loan Book of ₹ 35,263 lakhs as on March 31, 2021.Our NBFC business is primarily focused on lending to private traders and other small and medium businesses involved in the commodities trading market.Agency Business: We are SEBI registered Stock and Commodity Exchange Brokers with memberships across all the major stock exchanges in India, including BSE, NSE, MSEI, MCX, NCDEX, ICEX and IIEL and further we have memberships in various international exchanges like DGCX (Dubai), LME (London), INE (Shanghai) and DCE (China). We are also a SEBI Registered Portfolio Management company as well as a SEBI Registered Category-I FPI and Category-III AIF. We offer various client-based institutional trading services, wealth management and private client brokerage services, mainly in equity, commodities and foreign exchange.Capital and other Business: Our Capital Business includes our internal treasury operations which manage our excess capital funds. We do so by investing our capital in what we believe to be low / medium risk strategies, maintaining positions in physical as well as exchange traded commodities and other instruments which we can liquidate economically within a specified days based on our strategy of short term or long term holding. We structure our treasury investments to maintain sufficient liquidity in our portfolio to support the capital needs of our other businesses. Further we provide Warehousing Services to commodity market participants.</i><br />Target victim <b>website</b>: <i>abansfinserv.com</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>METCO-Services-Metco-Southeast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33414</link>
<guid>706e79e774e8345ecccc7ed401793d9e</guid>
<pubDate>Mon, 29 Jun 2026 12:20:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>METCO-Services-Metco-Southeast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0140390de29a4d2f1235fbd838e8f87ba3bf28256ecf4719c4549d5e57312a5</i><br /><br />Threat actor <b>description</b>: <i>Metco Services is a multi-disciplined consulting firm specializing in engineering services for the water and wastewater industry. They provide study, design, and construction engineering services to publicly owned water and wastewater collection and treatment systems. With over 100 years of combined industry experience, their team focuses on efficient system utilization to optimize value. Their clientele includes municipalities in Michigan, Ohio, Pennsylvania, and Florida.</i><br />Target victim <b>website</b>: <i>www.metcoservices.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>NASCO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33410</link>
<guid>da5ac2a4989f1ac70e4dec5ae331f9ca</guid>
<pubDate>Mon, 29 Jun 2026 05:54:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>NASCO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0853aff1f723a0a69437208c04c7f3e27951ad06891029ab916302ca9f7001f</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>1-800-dentist</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33382</link>
<guid>1da5ca963ae4930bda1e0a19cc88ae87</guid>
<pubDate>Sun, 28 Jun 2026 23:01:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>1-800-dentist</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5fbec245e75e2c86009f2663d13c1f5ebc0b0ad8978b222451817ead5921bc20</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Transcore</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33383</link>
<guid>bd8af78a63f6fee6292cc0d34960e53d</guid>
<pubDate>Sun, 28 Jun 2026 23:01:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Transcore</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3fe4ae9dc22f00c95a9800d28c5972b2ea2960a8710333df672194ccd45ed889</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>eshacloudqa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33401</link>
<guid>eea8374d4f01af690cc2879d01ae78d4</guid>
<pubDate>Sun, 28 Jun 2026 21:29:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>stormous</b> claims attack for <b>eshacloudqa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc2af8be070b70723863802b8d19014bb6594d0062e7b067d433d3d714c6924f</i><br /><br />Threat actor <b>description</b>: <i>We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry secrets and formulation data Complete intellectual property containing secret product designs, manufacturing blueprints, and recipes (⁠SupplementFormula⁠, ⁠PureFood⁠, ⁠FoodGroup⁠).Deep laboratory data, nutritional testing breakdowns, and allergen classification records (⁠SupplementIngredient⁠, ⁠Analysis⁠, ⁠AllergenGroup⁠, Sensitive registries containing client profiles, user metrics, and market consumer data (⁠Consumer⁠, ⁠Activity⁠).</i><br />Target victim <b>website</b>: <i>eshacloudqa.com</i>]]></description>
<category>stormous</category>
</item>
<item xmlns:dc='ns:1'>
<title>Driving-School-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33398</link>
<guid>ae6f24091ebb1f5a9bf5da61a248fc0c</guid>
<pubDate>Sun, 28 Jun 2026 21:21:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>PrinzEugen</b> claims attack for <b>Driving-School-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d592692f9b731ec274ff263f3a78321bb4ab4e8582154a24b633e245d13f81c9</i><br /><br />Threat actor <b>description</b>: <i>Hundreds of driving schools impacted.

16 Million rows of SQL, 8000 FULL credit cards, and more.

Full leak post + data available on the new PRINZ EUGEN site.

prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid.onion</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>PrinzEugen</category>
</item>
<item xmlns:dc='ns:1'>
<title>canopybrands.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33397</link>
<guid>23322e28bac2158412abd7bb0c7c4229</guid>
<pubDate>Sun, 28 Jun 2026 19:56:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>canopybrands.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e31eceb3563ba32533a3676a2aa5ab3c218a9bd8fa0a16cdf8525d9e8ba72e6</i><br /><br />Threat actor <b>description</b>: <i>Limit of Travel A holding company that sells people safety at height failed to keep its own data saf...</i><br />Target victim <b>website</b>: <i>canopybrands.us</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>hmcfarms.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33395</link>
<guid>66085beee49294dd1e8bff0eca7c13ee</guid>
<pubDate>Sun, 28 Jun 2026 19:54:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>hmcfarms.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0fd177a1063ad72d5d33a29e600bbac05920d2a13566d01d52fc1f87a32d82a</i><br /><br />Threat actor <b>description</b>: <i>THE HMC GROUP: OPEN FIELD A California Central Valley agricultural holding feeds America peaches. It...</i><br />Target victim <b>website</b>: <i>hmcfarms.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>tmscentral.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33393</link>
<guid>1940d1c94e7b75208ddc9dca5db18bb0</guid>
<pubDate>Sun, 28 Jun 2026 19:52:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>tmscentral.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dc077526470d64751f959e985a54837d56cbd44a60cd62d2e3a8e8430caa47f</i><br /><br />Threat actor <b>description</b>: <i>A SIGNAL WITH NO BACKUP: How Total Monitoring Services Sells Multi-Channel Protection and Routes the...</i><br />Target victim <b>website</b>: <i>tmscentral.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>va-glass.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33392</link>
<guid>653a0ef6ee24175eaa9cd0eb4392eacb</guid>
<pubDate>Sun, 28 Jun 2026 19:52:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>va-glass.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54a25864f806121328d314f8cafb2dfe8c7e3b3460269fbee6619b64a71dcc59</i><br /><br />Threat actor <b>description</b>: <i>THE TRANSPARENT MIRROR A company that sells people glass and reflections failed to protect its own r...</i><br />Target victim <b>website</b>: <i>va-glass.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>qdi.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33389</link>
<guid>53db352e1b55aec7cd103d263221fe95</guid>
<pubDate>Sun, 28 Jun 2026 19:48:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>qdi.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2fe2a871cac5158c4338a098241f3d511e46f14e86ce0d5471a5b5f3800ac2b2</i><br /><br />Threat actor <b>description</b>: <i>HOW QUALITY DINING CONVERTS LOSS INTO PROFIT PROLOGUE: ONE STORY ABOUT FINANCIAL ADJUSTMENTS Quality...</i><br />Target victim <b>website</b>: <i>qdi.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>turbodata.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33388</link>
<guid>f76db9efd8037dc91175b255083fc623</guid>
<pubDate>Sun, 28 Jun 2026 19:47:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>turbodata.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec64eb99ed111e345804bb731d85a2c7ec13e1f5c324df16803b65b59f43c12b</i><br /><br />Threat actor <b>description</b>: <i>TICKET ISSUED: How Turbo Data Systems Built a Dossier on Half of California From a Slip of Paper Und...</i><br />Target victim <b>website</b>: <i>turbodata.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>lifevantage.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33387</link>
<guid>57533f8ad8e0fb861b0057eb2a143c51</guid>
<pubDate>Sun, 28 Jun 2026 19:46:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>settra</b> claims attack for <b>lifevantage.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5339de0c7955e25348a307d64cfd576f3b6e09b4252db767d0aea9eb4cb65de</i><br /><br />Threat actor <b>description</b>: <i>THE NEUTRALIZING FACTOR: How LifeVantage Corporation Profits from Hope and Buries the Truth PROLOGUE...</i><br />Target victim <b>website</b>: <i>lifevantage.com</i>]]></description>
<category>settra</category>
</item>
<item xmlns:dc='ns:1'>
<title>acemacon.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33386</link>
<guid>f62cc9a5c2e8242b15ec3cd88f4e4afe</guid>
<pubDate>Sun, 28 Jun 2026 19:30:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>acemacon.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52a8a19b8c51d254901f27ac0068cd37c281e3d82613f54c0dd19d262a353c8a</i><br /><br />Threat actor <b>description</b>: <i>The Academy for Classical Education is dedicated to fostering knowledge and critical thinking skills in children, preparing them to be independent learners for life. It offers a comprehensive educational experience that includes fine arts, athleti</i><br />Target victim <b>website</b>: <i>acemacon.org</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hologic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33380</link>
<guid>1184c4797d205c765f40d0b490ebd619</guid>
<pubDate>Sun, 28 Jun 2026 08:38:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Redact</b> claims attack for <b>Hologic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6bb3bca38d76f0e935b3d5580f19c4ba4c8933dc822d1d4518db105f2f639f83</i><br /><br />Threat actor <b>description</b>: <i>Sector: Medical Supplies | Revenue: $4B USD</i><br />Target victim <b>website</b>: <i>hologic.com</i>]]></description>
<category>Redact</category>
</item>
<item xmlns:dc='ns:1'>
<title>FCCI-Insurance-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33379</link>
<guid>4f10ac32425eaa39b2f93cd9c67ff456</guid>
<pubDate>Sun, 28 Jun 2026 08:37:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Redact</b> claims attack for <b>FCCI-Insurance-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28f11c334ea35244090713eec3669192bbd410fc430710a04a1e706c7430c427</i><br /><br />Threat actor <b>description</b>: <i>Sector: Insurance</i><br />Target victim <b>website</b>: <i>fcci-group.com</i>]]></description>
<category>Redact</category>
</item>
<item xmlns:dc='ns:1'>
<title>JJ-Gaming</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33377</link>
<guid>f0deea2c51b15d312a1c8de8bcf81a62</guid>
<pubDate>Sat, 27 Jun 2026 18:27:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>JJ-Gaming</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a53c2fd232c1389f45f7a37ddc2467f22ae30c693000eaf56e4e476c75105d59</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jjgaming.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kuhnline</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33376</link>
<guid>7714ab6ab1ea68593e80de97752745e8</guid>
<pubDate>Sat, 27 Jun 2026 18:27:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kuhnline</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3fbdfee816b8c2ee264d9472d1546891937d5e33d4f9f631261621611f2519f6</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kuhnline.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aptora</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33375</link>
<guid>56034e3017a60728e3f1ce4ba40aeeeb</guid>
<pubDate>Sat, 27 Jun 2026 03:55:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Aptora</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8387f333ab01cabaf6c55283fc4075df35079e362ae6a66606940ab7327e611</i><br /><br />Threat actor <b>description</b>: <i>Aptora is an aggressively growing software company in Lenexa, KS. The company offers award-winning software and consulting services to the service and contracti...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Onlinesatis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33588</link>
<guid>bb64c74f463ee92e6f877c47a130d645</guid>
<pubDate>Sat, 27 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dreamfyre</b> claims attack for <b>Onlinesatis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60fcb740b34d4ef7aabf6f98b4e0087ffb1f34d95b036d9b727ac95f80e76053</i><br /><br />Threat actor <b>description</b>: <i>Online-SAT LLC is a software development company specializing in SAP consulting services, including SAP SuccessFactors, SAP Master Data Governance, and SAP S/4HANA. Founded in 2016, the company focuses on digital transformation and offers services such as project management, SAP support, and IoT solutions. Website: http://www.online-SAT.com</i><br />Target victim <b>website</b>: <i>online-SAT.com</i>]]></description>
<category>dreamfyre</category>
</item>
<item xmlns:dc='ns:1'>
<title>callhorton.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33374</link>
<guid>a162d5eaf59d4935d3f6196f03f7b994</guid>
<pubDate>Fri, 26 Jun 2026 20:27:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>callhorton.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c5cf416a189777924ffb5b56bd17d6e4b3178903ede22011e8255a0e5c94141</i><br /><br />Threat actor <b>description</b>: <i>Horton Personal Injury Lawyers is the premier law firm at not protecting it's clients confidential data.</i><br />Target victim <b>website</b>: <i>callhorton.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>johndufourlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33373</link>
<guid>0175d23af8e2d1e2bbdce27998c98aeb</guid>
<pubDate>Fri, 26 Jun 2026 19:23:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>johndufourlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab2cecb18b0137c884bd0322ce2c9affb97a64baa1ede7ef1739c53ace0f7419</i><br /><br />Threat actor <b>description</b>: <i>If you find yourself injured, disabled or deep in debt, the Law Office of John Dufour is ready to help. John brings 25 years of focused experience and favorable outcomes. Our success is built on attentive service and attention to the legal details.</i><br />Target victim <b>website</b>: <i>johndufourlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>theswansonlawgroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33372</link>
<guid>27a335b95070796b6b5dcb5b1e8cabd9</guid>
<pubDate>Fri, 26 Jun 2026 19:22:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>theswansonlawgroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96bf96e0ef417a71cf43f3971bf2aceaeb7cb384c1ddb1d8b347b7db1f10c9bf</i><br /><br />Threat actor <b>description</b>: <i>Meet Ben Swanson. The clients confidentiality worst nightmare.</i><br />Target victim <b>website</b>: <i>theswansonlawgroup.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Benchmark-Industrial-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33370</link>
<guid>291ed4a3e93cdca112eef1dd0ca26bed</guid>
<pubDate>Fri, 26 Jun 2026 15:24:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Benchmark-Industrial-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2836c03cebfe4b42d70e0e0798a2850382daab7e2c70324f315e162f187d36e4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.benchmarkinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precise-Forms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33366</link>
<guid>1ce018a9cf7f2480f079ce6bdd49af8a</guid>
<pubDate>Fri, 26 Jun 2026 12:50:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Precise-Forms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9aec79da4177c1c18ffa68ce813d707d8cae5fed13a46a0ba4372fc78d46fb28</i><br /><br />Threat actor <b>description</b>: <i>Precise Forms, Inc. specializes in manufacturing high-quality aluminum forms for concrete const
ruction, offering a complete line of standard and decorative forms along with necessary accesso
ries. Their products cater to a variety of applications including residential homes, commercial
buildings, and swimming pools, designed for rapid setting and stripping to meet the needs of c
ompetitive contractors.

We will upload 10gb of corporate data soon. Employee personal information (DLs (at least 15 num
bers), 75 SSNs, and other personal docs), NDAs, projects, contracts and agreements, customer in
formation and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ingerman.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33343</link>
<guid>f7fadee7981a4eb09971187ead481451</guid>
<pubDate>Fri, 26 Jun 2026 09:24:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>ingerman.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc41a9198387c20151ec550121f944866b75224e593b4a006049e082dceb7e4a</i><br /><br />Threat actor <b>description</b>: <i>Ingerman is a developer, builder and manager of multifamily housing communities throughout the Mid-Atlantic region.</i><br />Target victim <b>website</b>: <i>ingerman.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hokua</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33341</link>
<guid>d3bc387894c78ab0d27bac6be81b244a</guid>
<pubDate>Fri, 26 Jun 2026 08:50:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Hokua</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63291860f07f0f7847b9322995f27c16b3817285ffa61fc92ccb5eabb35613f3</i><br /><br />Threat actor <b>description</b>: <i>Hokua Suites is a luxury resort-style residential condominium located in Honolulu, Hawaii. The complex offers upscale apartments with ocean views and a full range of premium amenities.</i><br />Target victim <b>website</b>: <i>hokua.net</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Life-Bridges</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33336</link>
<guid>da32d205fc113251e52c40213cf9a78d</guid>
<pubDate>Thu, 25 Jun 2026 23:23:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Life-Bridges</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e1bece57cebdf47c1305357d74e20a25050064f559eb591ea76db9ae62f6f25</i><br /><br />Threat actor <b>description</b>: <i>Life Bridges is a non-profit organization dedicated to supporting individuals with intellectual and developmental disabilities, providing a range of services including residential support, healthcare, and community living services. Established in 1973, the organization focuses on promoting independence and dignity for its clients through tailored support and therapeutic services. Their intended clients include individuals with various developmental disabilities, as well as their families, ensuring a holistic approach to care and community involvement. Life Bridges is committed to bridging the gap between abilities and disabilities, fostering an inclusive environment where all individuals can thrive.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>roofdepot.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33330</link>
<guid>26c236095f0e9fc4a4e0af7edf6fa9f0</guid>
<pubDate>Thu, 25 Jun 2026 15:46:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>roofdepot.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>794b04e290867edec9529df2b0f28c379068b3010f1d652cfc1d959acd878e65</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1998 and headquartered in Alpharetta, GA, Roof Depot is a roofing manufacturer that specializes in roof installation, repairs & replacement</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/roof-depot-inc/348637856</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>JMS-Southeast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33327</link>
<guid>63ec03727a772694ec3d65026d0e8ff0</guid>
<pubDate>Thu, 25 Jun 2026 12:20:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>JMS-Southeast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>390233ae6d97988f7c35180026a254cabe3d73d13aae28a3da4a2641f13a3230</i><br /><br />Threat actor <b>description</b>: <i>JMS Southeast, Inc. specializes in high-quality temperature measurement and control products, i
ncluding thermocouples, RTDs, thermowells, and transmitters, catering to various industries suc
h as aerospace, pharmaceuticals, and oil and gas.

We will upload 25gb of corporate data soon. Employee personal information (name, addresses and 
so on), payment details, NDAs, projects, contracts and agreements, agreements with government, 
customer information and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Padget-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33326</link>
<guid>7f27d1bf305b28410986fefe0943b77a</guid>
<pubDate>Thu, 25 Jun 2026 11:50:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Padget-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ee1c3e312d686e2e9e511a65c4c823c29854918f67dbf9e0c7d4cfaeb67d6f3</i><br /><br />Threat actor <b>description</b>: <i>Padget Technologies specializes in advanced robotics and automation solutions tailored for effi
cient and cost-effective production. Their services include designing and fabricating custom ma
chinery, assembly systems, and pre-engineered robotic palletizing cells.

We will upload corporate data soon. Employee personal docs (DLs, SSNs, w9s and other sensitive 
docs), payment details, lot of NDAs, projects, contracts and agreements, client information, et
c.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Delegal-Poindexter--Underkofler-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33325</link>
<guid>bc1f015249c3cf61633174c93943648b</guid>
<pubDate>Thu, 25 Jun 2026 08:22:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>morpheus</b> claims attack for <b>Delegal-Poindexter--Underkofler-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12c8fc663ca922782000a2f164c18954936fa69a7ced0a459b1cdd1d2ddce51e</i><br /><br />Threat actor <b>description</b>: <i>**Website**: protectingcareers.com

**Revenue**: $5 Million

Delegal Poindexter & Underkofler provides highly specialized legal services to employees with employment law concerns.They represent profes</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>morpheus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Telewave-inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33368</link>
<guid>52eeaf9f1eb952e476fe29e3d9eae992</guid>
<pubDate>Thu, 25 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Telewave-inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b9239b1f75f0cdb8db358f5ec176626a92f466417c8a6d14d870670aacc0a92</i><br /><br />Threat actor <b>description</b>: <i>Telewave, Inc., founded in 1972, designs and manufactures high-quality RF system products for wireless system operators, public safety providers, and government agencies. Their products support various services, including Cellular, SMR, GSM, Trunking, Paging, and Broadcast. Website: https://www.telewave.com/</i><br />Target victim <b>website</b>: <i>telewave.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Frosty-acres-brands</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33369</link>
<guid>fdd877d9c3ca4eaf91d22d2b2ba54f52</guid>
<pubDate>Thu, 25 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Booba Project</b> claims attack for <b>Frosty-acres-brands</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>15a5b849d16bb1597ec7ff7e59dfe8f89261dcb8709fbc2c9e2838d8b5cf76ec</i><br /><br />Threat actor <b>description</b>: <i>Frosty Acres Brands is a national sales, marketing, and foodservice purchasing cooperative founded in 1954. It aligns and unifies the sales, marketing, and procurement activities of its members to produce sustainable growth and member business wealth. The cooperative provides national and private brands, such as Restaurant's Pride®, to its members, which include independent food distributors in the U.S., Canada, Cayman Islands, Puerto Rico, and Bermuda. Website: https://www.frostyacres.com/</i><br />Target victim <b>website</b>: <i>frostyacres.com</i>]]></description>
<category>Booba Project</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quest-Health-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33322</link>
<guid>a3209347dfea2ac488fc4595df350a9a</guid>
<pubDate>Wed, 24 Jun 2026 21:51:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Quest-Health-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5398f8369a2d82ced3c8456b0775791b14859c8881af116937e2fc648c104a87</i><br /><br />Threat actor <b>description</b>: <i>Employee data, internal files, and a few unexpected discoveries.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jit-Ex</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33311</link>
<guid>b6e16e5df709e3386d7df8c34dccb1d2</guid>
<pubDate>Wed, 24 Jun 2026 12:50:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Jit-Ex</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9eecf3e55eb41d637b031cc021b3efa605884dba2fd13f8d6e23170c29bc0665</i><br /><br />Threat actor <b>description</b>: <i>JIT-EX, LLC is a privately owned for-hire trucking fleet based in Memphis and Nashville, specia
lizing in regional and local truckload services, dedicated fleets, and crossdock solutions. The
company offers a variety of services including transloading, dock services, and storage traile
rs, aiming to be a one-stop solution for transportation needs.

We will upload 40gb of corporate data soon. Employee personal docs (passports, DL numbers of 31
7 persons, SSNs, w9s and so on), credit card details, payment details, lot of NDAs, projects, c
ontracts and agreements, customer information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miami-Machine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33309</link>
<guid>2c9ec71f040ae43b350159093c4401bd</guid>
<pubDate>Wed, 24 Jun 2026 12:20:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Miami-Machine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51cd9280cc5fd7fb0348dd1f4483591f5899a2d26269078fa33e66446bb02912</i><br /><br />Threat actor <b>description</b>: <i>Miami Machine Inc. specializes in machining, fabrication, and engineering services tailored for
the paper, power, steel, and OEM markets. With over 50 years of experience and a manufacturing
space of 86,000 sq. ft, they provide high-quality, custom machinery and equipment solutions.

We will upload corporate data soon. Employee personal docs (passports and other docs, photos), 
NDAs, projects, contracts and agreements, client information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>horizoneye.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33305</link>
<guid>e2561e23fb2d5dae50b0ce6c62959fed</guid>
<pubDate>Wed, 24 Jun 2026 00:32:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>horizoneye.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b296449ad2ffe98a3e35d79b56d7442e6346e5bc5270eb8fac6a435992058b4e</i><br /><br />Threat actor <b>description</b>: <i>Horizon Eye Care operates as a group of independent optometric clinics and medical practices across North America. Depending on your specific location, they offer comprehensive eye examinations, surgical procedures (like LASIK and cataracts), contact lens fittings, and a wide variety of designer eyeglasses.</i><br />Target victim <b>website</b>: <i>horizoneye.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beran-concrete</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33361</link>
<guid>b5bde7db296c1837f75b77a2e4e6013b</guid>
<pubDate>Wed, 24 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Beran-concrete</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8990e7045bc6656c83dfb3790313da276c94fc2b153fb1593affc10f0a51d2b</i><br /><br />Threat actor <b>description</b>: <i>Beran Concrete, Inc., founded in 1980 by Ken Beran, specializes in concrete construction services for commercial and residential projects across Wichita, Kansas, and the broader Midwest. The company offers services including commercial concrete, residential concrete, and ready-mix concrete. Website: https://beranconcrete.com/</i><br />Target victim <b>website</b>: <i>beranconcrete.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plateau-excavation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33365</link>
<guid>ebbef3b7bea693ae9aa25f2885a828cc</guid>
<pubDate>Wed, 24 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Plateau-excavation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6edd07f4b8ea4b9f0aaf85469ab5725132b15d3920293cad85549c526ad67307</i><br /><br />Threat actor <b>description</b>: <i>Plateau Excavation, Inc., founded in 1983, is a leading site infrastructure contractor based in Kennesaw, Georgia. Specializing in large-scale site development projects across the Southeast, the company offers comprehensive services including excavation, grading, and pre-construction planning. Plateau Excavation operates as a subsidiary of Sterling Infrastructure, Inc. (NASDAQ: STRL). Official website: https://plateauexcavation.com/</i><br />Target victim <b>website</b>: <i>plateauexcavation.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Coldstat-Refrigeration</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33301</link>
<guid>15577bd89f95fbe74ff708dd9d3c49a8</guid>
<pubDate>Tue, 23 Jun 2026 19:20:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Coldstat-Refrigeration</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62c51277dcc0c1daa3dbf115bdd8fa0fe53f78f1966ad5b4cff720a573b84b17</i><br /><br />Threat actor <b>description</b>: <i>Coldstat Refrigeration offers a full range of industry-proven refrigeration services. From large restaurant chains to individual stores and cafes—Coldstat is ready to meet all your needs. The company’s qualified staff will help you determine the best solution based on your individual needs. Coldstat’s refrigeration services include: sales of commercial refrigeration equipment, installation, maintenance and repair, layout planning, custom system design, and removal of old equipment.Translated with DeepL.com (free version)</i><br />Target victim <b>website</b>: <i>www.coldstat.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leo-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33296</link>
<guid>6e32552fae821c2e1fe753571df9844f</guid>
<pubDate>Tue, 23 Jun 2026 12:20:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Leo-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82763f0b6bdd17cbe9801e5396ccd59899148e1c0a67bf16351c82b6943c43ec</i><br /><br />Threat actor <b>description</b>: <i>Leo International, established in 1986, serves as a comprehensive source for the PVF, HVAC, and
Plumbing Industry. The company specializes in manufacturing products through Forging, Casting,
and Injection Molding processes.

We will upload 10gb of corporate data soon. Employee personal docs (passports, SSNs, DLs, medic
al information, phones, photos, doc scans, addresses and so on), confidential internal files an
d so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>IH-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33295</link>
<guid>565b7e1332c5d26362dd2487ea625746</guid>
<pubDate>Tue, 23 Jun 2026 12:20:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>IH-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f9cdfd5443e32a0aeb1492377721f37aca031b0d5a945f63499f4906bcfb521</i><br /><br />Threat actor <b>description</b>: <i>IH Engineers, P.C. is a consulting firm with over 25 years of experience, dedicated to providin
g innovative and technically excellent services in design, construction, and structural evaluat
ion. The firm operates primarily in New Jersey, New York, and Pennsylvania, serving a diverse r
ange of clients.

We will upload 65gb of corporate data soon. Employee personal docs (passports, SSNs, DLs and ot
her HR information), confidential internal files, NDAs, projects, contracts and agreements, dra
wings and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>randa.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33281</link>
<guid>b14d48ede1f7c2f7779585ef3f9102f0</guid>
<pubDate>Tue, 23 Jun 2026 05:20:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>randa.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aced4a266be397653b2f7d752156f087487ce8160eb5ef084ae840741c2ee045</i><br /><br />Threat actor <b>description</b>: <i>Randa Apparel & Accessories is a global powerhouse and one of the world's leading apparel and lifestyle accessories companies, headquartered in New York City at 417 Fifth Avenue, 11th Floor. Founded in 1910, with the founder's family having been in the neckwear business since that time and the curre…</i><br />Target victim <b>website</b>: <i>www.randa.net</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schumacher-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33273</link>
<guid>bfa9c5c62c08a0db763e2a2284e3d1b2</guid>
<pubDate>Mon, 22 Jun 2026 23:52:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Schumacher-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcec3f6c019574044a9569dc2652bd57d9465218c201a35b545fa9b8aaa4a9d0</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>belpointeasset.com--belpointe.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33280</link>
<guid>0bb275959bab94a82b9d376d39efdace</guid>
<pubDate>Mon, 22 Jun 2026 23:32:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>belpointeasset.com--belpointe.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e03db1ecc0fdb8d77d3c47a6d28ce3dcaa8169d7da20e75b6458814d9e814ab2</i><br /><br />Threat actor <b>description</b>: <i>400gb</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huntress</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33278</link>
<guid>5143b1a03753e9634ad9395eb18e0417</guid>
<pubDate>Mon, 22 Jun 2026 21:21:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Icarus</b> claims attack for <b>Huntress</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f3d10d8303088f4df66d3ba579b49c5fec7e9ca00e7270c65d26b05064dc050</i><br /><br />Threat actor <b>description</b>: <i>Salesforce data of Huntress.

Data stolen: SF data - Compressed</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Icarus</category>
</item>
<item xmlns:dc='ns:1'>
<title>HDS-Hdscorp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33277</link>
<guid>f831547ec73855ada56ccfd6ee45364d</guid>
<pubDate>Mon, 22 Jun 2026 21:21:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Icarus</b> claims attack for <b>HDS-Hdscorp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9dea9f8adfbb7380975907b94772f4288d92702555928a33c1d555a3e9f8551</i><br /><br />Threat actor <b>description</b>: <i>Salesforce data for this corp.

Data stolen: SF data - compressed</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>Icarus</category>
</item>
<item xmlns:dc='ns:1'>
<title>NationsBuilders-Insurance-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33259</link>
<guid>31bd2c1425f9766a5081c75efff468bd</guid>
<pubDate>Mon, 22 Jun 2026 09:22:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>NationsBuilders-Insurance-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7641d7fd61d27d8e9393428e36727148cb1a0c2f131e6db1474d775a250b40e2</i><br /><br />Threat actor <b>description</b>: <i>[insurance] *** (NBIS) is the premier US underwriter of crane & rigging, concrete-pumping, heavy-haul, and residential-builder insurance — a specialty managing general underwriter founded in Atlanta in 2001, acquired by Align Financial / DUAL North America (Howden Group) in August 2021. 2,748,845 filetree entries across 24 shares (AIM, IMAGERIGHT, the claims and policy-admin stores, HR, finance, IT, and a decade of M&A diligence rooms).</i><br />Target victim <b>website</b>: <i>NationsBuilders Insurance Services</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>International-freight-services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33351</link>
<guid>6f85adccb998c7a7840b3548fe19ffda</guid>
<pubDate>Mon, 22 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>International-freight-services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bcbd9a14d666a7db550f1f45286b849fee06aeb415ea2ec923c0c48fd0e985c0</i><br /><br />Threat actor <b>description</b>: <i>International Freight Services, Inc. (IFS) is a logistics company established in 1971, offering services such as air and ocean freight forwarding, customs brokerage, warehousing, and trucking. Headquartered at 350 Harbor Way, South San Francisco, CA 94080, IFS specializes in time-critical and high-touch cargo, serving industries including technology, life sciences, automotive, and retail. Website: https://www.ifsworldwidelogistics.com/</i><br />Target victim <b>website</b>: <i>ifsworldwidelogistics.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hooke-laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33353</link>
<guid>20a1f94e0e45384e8e08872de5a5e545</guid>
<pubDate>Mon, 22 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hooke-laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16213aa258b3dd8cb4732dd289fc43049588a0c0c054afda94bb74e97b654415</i><br /><br />Threat actor <b>description</b>: <i>Hooke Laboratories is a biotechnology company based in Lawrence, Massachusetts, specializing in biological products for medical and pharmaceutical research. They are best known for their 'Hooke Kits™,' ready-to-use emulsions used to induce animal models of autoimmune diseases, such as EAE, in laboratory rodents. The company operates strictly as a preclinical research supplier, working only with rodents and in vitro, and does not offer any products for human clinical use. Website: https://hookelabs.com/</i><br />Target victim <b>website</b>: <i>hookelabs.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gia-partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33354</link>
<guid>6f9966c340aa4f47dc1bd7520a7b2b59</guid>
<pubDate>Mon, 22 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Gia-partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>221e31c0894afd5b15c3668726942747667f2908fafe195c570228b74e3f4f04</i><br /><br />Threat actor <b>description</b>: <i>GIA Partners, LLC is an independent investment manager specializing in yield-enhanced fixed income solutions. The firm offers strategies including Core, High Yield, and Emerging Market Corporate Debt, focusing on credit risk management. Website: https://giallc.com/</i><br />Target victim <b>website</b>: <i>giallc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rowley-properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33355</link>
<guid>34e0ace0f37f8857eba8e3531c96fa06</guid>
<pubDate>Mon, 22 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Rowley-properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52a2d47b22c5bfc911ef9d5efcdefb2e1c10331f63731c4e513f3d345792ae5d</i><br /><br />Threat actor <b>description</b>: <i>Rowley Properties is a multi-generational, family-owned real estate company based in Issaquah, Washington, founded in 1954. The firm specializes in owning, developing, and managing approximately 80 acres of commercial and residential properties, including office spaces, apartments, and storage facilities in downtown Issaquah. They are deeply committed to local community development, focusing on long-term projects that help businesses succeed and families thrive. Website: https://www.rowleyproperties.com/</i><br />Target victim <b>website</b>: <i>rowleyproperties.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ergomed</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33357</link>
<guid>bdebe2f12a1bc7a473f1520a583918c0</guid>
<pubDate>Mon, 22 Jun 2026 00:00:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Ergomed</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>86bb288430c6753a0ccbd456bb38ef34995d3381b1ea428f548df5baaf9179aa</i><br /><br />Threat actor <b>description</b>: <i>ErgoMed Work Systems, established in 1992, specializes in occupational health and employment testing services. Their offerings include physical demand evaluations, post-offer employment testing, fitness-for-duty assessments, drug screening, safety programs, ergonomic programs, and wellness programs. These services aim to help businesses reduce workplace injuries and associated costs. Website: https://ergomed.net/</i><br />Target victim <b>website</b>: <i>ergomed.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tri-tec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33255</link>
<guid>517fc8ecad583e1ddb8f5764ddf8834f</guid>
<pubDate>Sun, 21 Jun 2026 19:45:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tri-tec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0e0c769111e2432b372e3f7ef2c6852e4c5d7eacb9df55e1d63c7b1503d7fb2</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-Engineering-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33256</link>
<guid>3664940859edd8b28137801625a24524</guid>
<pubDate>Sun, 21 Jun 2026 18:46:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Florida-Engineering-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fba48b7703a39fc13db6fdc879c728c03c6dc4f6773654aa78deb62339e3daf5</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wall-ISD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33257</link>
<guid>9b063c87efaca632b17a2a59a522f988</guid>
<pubDate>Sun, 21 Jun 2026 17:50:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Wall-ISD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7710510174afdd15d02112f535554417e6453467136930da9076fa7ba62370f</i><br /><br />Threat actor <b>description</b>: <i>Wall ISD is an educational institution that serves students in the Wall, Texas area, providing a range of programs and activities for elementary, middle, and high school students. The district emphasizes inclusivity and equal access to education, ensuring that all students, regardless of their background, have the opportunity to participate in school activities. Wall ISD is committed to fostering a supportive learning environment and offers resources for both new and returning students. The intended clients are students and their families within the Wall community.</i><br />Target victim <b>website</b>: <i>www.wallisd.net</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>jaggroup.com-UPDATE-FULL-DATA-DUMP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33253</link>
<guid>1821ea1543b5ea73c52fc5c746840b16</guid>
<pubDate>Sun, 21 Jun 2026 13:36:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>stormous</b> claims attack for <b>jaggroup.com-UPDATE-FULL-DATA-DUMP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe530155c2137295f2029356ac5b1d640d7fe64a92e4d3b3d59cc8944e5df68c</i><br /><br />Threat actor <b>description</b>: <i>Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages), SQL server connection data, and ⁠IM.mdb⁠ database files.Internal project management sheets (⁠Jag Project.xlsx⁠), user listings, purchasing, and sales import logs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>stormous</category>
</item>
<item xmlns:dc='ns:1'>
<title>Artistic-Smiles</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33250</link>
<guid>e3dbd39e932ac0d5ab824361d92cba34</guid>
<pubDate>Sun, 21 Jun 2026 08:06:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Artistic-Smiles</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9551e8b02f53a6ea6b675800901a520ed4dfcba1682ebca49482f1670633acbc</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>artisticsmiles.org</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Newspaper-Media-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33248</link>
<guid>33363f7b038639dc7ecf8c4a2d17de66</guid>
<pubDate>Sat, 20 Jun 2026 19:35:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Newspaper-Media-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c00a2043ac2c010b07911d93420762e104dbf8a0978ac23fc252cf3f756ee036</i><br /><br />Threat actor <b>description</b>: <i>Newspaper Media Group is a local news organization that provides comprehensive coverage of news, sports, entertainment, and community events across various regions, including Central Jersey and South Jersey. They publish multiple newspapers and magazines, ensuring that they reach more households than their competitors in nearly every zip code they cover. Their services are aimed at local communities, delivering news that is often not found elsewhere. With a commitment to connecting readers to the communities they care about, NMG stands out for its focus on local reporting.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pacific-Lamp--Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33242</link>
<guid>8654dcb584db9ca8715397c5e0aa9407</guid>
<pubDate>Sat, 20 Jun 2026 17:48:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pacific-Lamp--Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f40513493f2aec7729188f537a4685bae7bec7bb6d52a11e1f87342f56e9ddb</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Preferred-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33243</link>
<guid>593b67e33629da61d6b95433e2db89a1</guid>
<pubDate>Sat, 20 Jun 2026 15:04:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>Preferred-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1388e55fd739e5172dd6848f5a262d06631f1360022162b7770f09eead5c421c</i><br /><br />Threat actor <b>description</b>: <i>Preferred Properties, Inc. is a dynamic and progressive housing development and property management company based in Toledo, Ohio. We specialize in the development of affordable and accessible housing opportunities, and to create integrated housing options for persons living with disabilities. Our development program reflects where we are today with programs under management, and new projects in development.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>TERRIO-Therapy-Fitness</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33228</link>
<guid>877f8395efda54ec44a890080c4e4fc0</guid>
<pubDate>Sat, 20 Jun 2026 08:52:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>TERRIO-Therapy-Fitness</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0de2cdcce4a3d5fed53c9934ea8488f421d6502706dd32ae74b8a095310cb729</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/terrio-therapy-fitness-inc/351115575 TERRIO Physical Therapy & Fitness is the largest rehabilitation and wellness provider in California's Central Valley, operating numerous clinics across the region.Founded in 1998, the company specializes in outpatient orthopedics, aquatic therapy, neuro-rehabilitation, and acute inpatient care.Recognized for its exceptional patient satisfaction, TERRIO has been repeatedly voted the Best Physical Therapy Company in Kern County</i><br />Target victim <b>website</b>: <i>terriotherapy.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burris-MacOmber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33224</link>
<guid>9eaffedaf21e53232baf69748ec96457</guid>
<pubDate>Sat, 20 Jun 2026 08:51:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Burris-MacOmber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc151582e972f6f17ad42f4bc2b7e5dade56863c0c85f2c125817e2e1b7620bf</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/burris--macomber-pllc/368834075 Burris & MacOmber, PLLC is a reputable law firm based in Tucson, Arizona, recognized for its commitment to excellence and integrity in legal practice. The firm provides a comprehensive range of services, including civil litigation, international business law, real estate transactions, and estate planning. Backed by a team of experienced attorneys and knowledgeable support staff, they deliver tailored legal solutions to effectively meet their clients' diverse needs</i><br />Target victim <b>website</b>: <i>burrismacomber.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>themintgaming.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33218</link>
<guid>f338ee966b0240a58cc1dbf24855dd26</guid>
<pubDate>Fri, 19 Jun 2026 21:20:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>themintgaming.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72c584ada5baa7560c28f9acfa1006e3acd279b41b9dc402b0cca89bb8e70523</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>themintgaming.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sparkle-Pools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33214</link>
<guid>6264104f24cbc6849b7e6ad298862a24</guid>
<pubDate>Fri, 19 Jun 2026 18:04:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sparkle-Pools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3b0ab9ffcaa3632c67d3fc92f703e1cccf8d9aff7be76b6a452186ccd87dc24</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sparklepoolsinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Desert-Micro</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33210</link>
<guid>8a47e6bee13f2b5cbd289c8471ff7ace</guid>
<pubDate>Fri, 19 Jun 2026 15:00:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Desert-Micro</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b504ea21e6210bc9c79146cd23e7585b930bf68bd9dae242368e8996bca4ed05</i><br /><br />Threat actor <b>description</b>: <i>DesertMicro.net is a Software & Internet based company located in Jacksonville, Florida, United States with over 25 - 100 employees, data included large sums of costumers data who use the company software service, such curbside waste company invoices and Storage data, foothillsSanitation + GreenEnviromnetal + InlandService + QC + FusionSite companies the same, credit cards Details and payments billings Documents, databases backups and more - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hagerman--Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33208</link>
<guid>3cfc6b2b7432c074eea2bd2ad6b0851d</guid>
<pubDate>Fri, 19 Jun 2026 13:52:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Hagerman--Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07d1778680f2a54bdd1924fb708e049855528a3bcd84fde0ebf3a16c509e6917</i><br /><br />Threat actor <b>description</b>: <i>*** — a 40-year-old Autodesk Platinum Partner headquartered in Mt. Zion, Illinois, serving 250+ enterprise customers across manufacturing, energy, defense, healthcare, and education.
The exposed dataset includes:

Complete proprietary source code for 15+ commercial products including the HNC Licensing System (License Generator, License Server, License Manager) — enabling unlimited piracy of all Hagerman products.
8+ plaintext database credentials in .udl files, including an Oracle SYS (DBA superuser) account with password "Hagerman@1!" reused across multiple systems.
Engineering vault databases for 14+ critical infrastructure entities — NYPA (7 power plants including Niagara Falls), Kinder Morgan (Elba Island LNG terminal), HydroOne (Ontario electricity), Phillips 66, Chevron, and 8+ petroleum refineries.
Defense/government data — NASA IT Security Requirements, Lockheed Martin configurations, Boeing-SVS vault data, JPL configurations.
Azure DevOps transaction logs (1.6 GB) containing complete source code version history and potentially CI/CD deployment secrets.
Third-party database credentials for Michigan State University (3 databases), Cal State Long Beach, and Beth Israel Deaconess Medical Center infrastructure.</i><br />Target victim <b>website</b>: <i>Hagerman & Company</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>KTR-Real-Estate-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33207</link>
<guid>5330f5fa350679fb680ac438824048bd</guid>
<pubDate>Fri, 19 Jun 2026 13:51:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>KTR-Real-Estate-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3bdafba9472bb528c3ae535a0b701221ca1fe533fc7e8b7ab8064391777d2ad0</i><br /><br />Threat actor <b>description</b>: <i>Real estate client database exposed.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Optimum-First-Mortgage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33206</link>
<guid>726a0cb64be7fda938f73af62259c7e0</guid>
<pubDate>Fri, 19 Jun 2026 11:31:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Optimum-First-Mortgage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1373e177315003ec1fffd9fdb15a69c0f08384747621310f6394a3eda919cf9d</i><br /><br />Threat actor <b>description</b>: <i>Providing fast and reliable mortgage solutions, including home purchases and refinancing options</i><br />Target victim <b>website</b>: <i>optimumfirst.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>ALS-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33204</link>
<guid>fc48e06c4fca7cc5930efad3aba784b8</guid>
<pubDate>Fri, 19 Jun 2026 09:52:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>ALS-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1cbf78c8bdbc9ef207a142f208e450ccc78c90a769c5fa5ee455efc1cdec3cad</i><br /><br />Threat actor <b>description</b>: <i>[certification, inspection] ALS Limited (ASX:ALQ) — a global testing, inspection, and certification company with AUD 3.19B revenue, 20,500+ employees, and operations in 65+ countries — identified unauthorised access to its IT systems.

~400–500 employee home directories — personal documents, cached credentials, email settings, family photos, personal finance files for employees from Australia to Peru to Sweden to Romania.
The company's 1Password team vault emergency recovery kit — a single 45 KB PDF that enables total recovery of every shared credential in ALS's enterprise password vault.
291 plaintext password files including administrator credentials, FTP passwords, portal passwords, and the document control system master password.
1,018 passport and identity document scans — Swedish passports, Mexican passports, Australian passports — each one a 10-year identity-theft enabler.
601 bank account detail files including IBAN, SWIFT routing codes, BSB numbers, and sort codes for employees across 15+ countries, plus Russian-language SWIFT salary payment files.
1,986 salary, payroll, and compensation files — named individuals, exact amounts, pay scales, negotiation records across AU, US, EU, UK, CA, BR, SE, RO.
453 medical, drug test, and workplace injury records — GDPR Art. 9 special category data.
57 complete Outlook email archives (PST files) — years of correspondence, attachments, privileged communications.
7,327 client laboratory results — mining assay data, certificates of analysis, and geochemistry results held under NDA.
20 GB of proprietary analytical method development — ALS's core competitive IP: PFAS, dioxin, acrylamide, glyphosate LC-MS/GC-MS method packages representing years and millions of AUD in R&D. For a TIC company, analytical methods are the product.
7.2 GB of Internal Research reports — 68+ formal research reports (IR153–IR287+) spanning 15 years, including IsaMill grinding R&D, GlyLeach joint-venture process IP (with mutual NDA), flotation, mineralogy, and QEMSCAN data.
The FY2025–2026 innovation roadmap — "ALS Environmental Innovation — Priority projects for 2024-25" (10 MB PPTX) and Nordic Innovation Business Plans revealing which methods ALS plans to develop and which markets it plans to enter.
3.7 GB of Cryptosporidium water-testing methods (WA_Crypto) — UKAS-accredited, DWI-regulated detection methods where few UK labs hold accreditation.
QuickBooks live bookkeeping, AR aging reports, and stock sale records — taken 12 days before FY26 results announcement.
111 PKI certificates with private keys — corporate WiFi, TLS server certs, personal signing certificates.
A compiled Chrome password extraction tool with source code — credential harvesting infrastructure resident on ALS systems.</i><br />Target victim <b>website</b>: <i>ALS Global</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>legendsmnBlue-Ox-Paul-Bunyan-Lumberjack-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33202</link>
<guid>49e75662bca429cc0e0ee3597a1becce</guid>
<pubDate>Thu, 18 Jun 2026 19:54:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>legendsmnBlue-Ox-Paul-Bunyan-Lumberjack-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8edb23aef9de55f2cca3ebe8ca95da2a1203ab1a888abe65de705a66fd4e44e3</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>legendsmn.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>dean-cosmetic-dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33201</link>
<guid>9807a1e7fdb9edcc283f59dae4bcdc43</guid>
<pubDate>Thu, 18 Jun 2026 19:53:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>dean-cosmetic-dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ea7f87d957cd2295f0193943c8b06db45657868cb887ba5547eaeba42a654dc</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>deancosmeticdentistry.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Homes-By-J-Anthony</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33199</link>
<guid>e42411f064786c51abac608d51afa607</guid>
<pubDate>Thu, 18 Jun 2026 19:45:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Homes-By-J-Anthony</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f816f4d5fac234c80c346c25a899c6f3965134fb787740d6c13856a0f6b3ce0</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>icsecurity.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33197</link>
<guid>cfefe028584e7a3f406e1096e7daaaff</guid>
<pubDate>Thu, 18 Jun 2026 15:26:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>icsecurity.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cbbb722cd0fc8eeee5d738d4adc3d3d80ef58bfb94ef5b683b455768962485be</i><br /><br />Threat actor <b>description</b>: <i>Over 2.7 million records and other internal corporate data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>icsecurity.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawson-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33195</link>
<guid>3b6ce24f63bbcaab1fc221c5fafe9e47</guid>
<pubDate>Thu, 18 Jun 2026 14:29:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Lawson-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>266758b2b9588709a19a202211953af9f979c5c1b8ebe5ff482b9100441a7770</i><br /><br />Threat actor <b>description</b>: <i>Lawson Roofing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>B--B-Trading</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33193</link>
<guid>1a551b7323fefa14d9b4ac09bd73ee49</guid>
<pubDate>Thu, 18 Jun 2026 14:28:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>B--B-Trading</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1089d5ba6e5e97b0d5d60244b8a1624497c3ca0ed584986a58bcfa292af9050</i><br /><br />Threat actor <b>description</b>: <i>Largest independent food wholesale distributors in New England</i><br />Target victim <b>website</b>: <i>bandbtrading.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Release-Marine-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33192</link>
<guid>a8c5a73459631beb2cbe6af3c74628e8</guid>
<pubDate>Thu, 18 Jun 2026 14:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Release-Marine-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f38c4a7a4e661e075e5e3f98f48384df1e62c251a6392cf84e7170c286ad796</i><br /><br />Threat actor <b>description</b>: <i>Handmade sport fishing equipment and yacht furnishings</i><br />Target victim <b>website</b>: <i>releasemarine.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kirbor-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33191</link>
<guid>632e3ccec223290601ef00e26aa62bd0</guid>
<pubDate>Thu, 18 Jun 2026 14:27:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Kirbor-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>add1836bd3f9d7c9e91136597508be8e13b250ab9b74560d35dd33bebbd670c9</i><br /><br />Threat actor <b>description</b>: <i>Kirbor Homes is a reputable home builder located in the Mid-Atlantic region</i><br />Target victim <b>website</b>: <i>kirbor.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.someco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33154</link>
<guid>d9ca1ef9c649e555f1ef4ad853f55202</guid>
<pubDate>Thu, 18 Jun 2026 13:46:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.someco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4af649da4e9bd825ab918ace9f23e15f5792c6905c30a217769cd26f26c11186</i><br /><br />Threat actor <b>description</b>: <i>Southern Mechanical Contractors is a merit shop mechanical and industrial constr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.eastersealsia.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33155</link>
<guid>297b51d372955449d68d0b67ffda8c80</guid>
<pubDate>Thu, 18 Jun 2026 13:46:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.eastersealsia.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d3bff1a44981d6fbadd384748903a12490354fc040e0b546529de72935870e5</i><br /><br />Threat actor <b>description</b>: <i>Easterseals Iowa provides an Assistive Technology Program that supports Iowans o...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>abandw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33159</link>
<guid>07dadbe48b0d9d6724c1e6ecacf0f8c9</guid>
<pubDate>Thu, 18 Jun 2026 12:41:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>abandw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b55b214d3c17908d7f1ce7f03f2ffad1b6d6c7f504c755c83c24ce30b0f46ae</i><br /><br />Threat actor <b>description</b>: <i>AB&W Innovation Co., Ltd еhe aluminum door and window system industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Berg-Lilly</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33189</link>
<guid>15256a6b7f55e835d0d50a20833b11bb</guid>
<pubDate>Thu, 18 Jun 2026 12:20:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Berg-Lilly</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a2686a8fb92f29c5dd425ae5ec7b704bf859ebca41d970aaaa1803bcf8fb9b6</i><br /><br />Threat actor <b>description</b>: <i>Berg Lilly PC is a trusted law firm based in Bozeman, Montana, with over 60 years of experience
providing quality legal representation to both local and national clients. The firm specialize
s in various areas of law, including business entity law, civil litigation, commercial transact
ions, construction law, employment law, estate planning, personal injury, and real estate law.

We will upload 50gb of corporate data soon. Clients personal information (passports, SSNs, DLs,
addresses, phones, confidential files, medical information, financials and so on), court heari
ngs, police reports and other legal documents.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apptricity</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33188</link>
<guid>3f0b954a086bb1bdcc2af1ffa99022f4</guid>
<pubDate>Thu, 18 Jun 2026 12:20:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Apptricity</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>767e8995e1a0a68101b07e3b01cca940dcac96ff459487229ff5146402b63cdc</i><br /><br />Threat actor <b>description</b>: <i>Apptricity Corporation is a global enterprise software provider for Supply Chain and Spend Mana
gement. Apptricity differs from other manufacturers by offering platform-agnostic, secure solut
ions that optimize inventory, asset and expense tracking processes while still being easily int
egrated with existing systems.

We will upload 12gb of corporate data soon. Employee personal docs  (passports, SSNs, DLs, w9s,
and other personal information), lots of projects, source codes, NDAs, client and partner file
s, agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Horizon-Family-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33153</link>
<guid>5e26566dffe850373e9a5121703034a1</guid>
<pubDate>Thu, 18 Jun 2026 07:23:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Horizon-Family-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e3f759136670984f79391167814759ea1af730031b0b9f2518ce3e3b64ea509</i><br /><br />Threat actor <b>description</b>: <i>Horizon Family Medical Group  A deep dive into 7 terabytes of internal data: from patient records to QuickBooks financial databases  In the modern world, data is the new oil. For a medical organization like Horizon Family Medical Group, it is also the foundation of trust between doctor and patient. We have conducted an independent and complete audit of this organization's data security. The results are catastrophic. We are in possession of the company's entire digital footprint, totaling **7 terabytes**, which includes 1TB of file data and 6TB of mission-critical SQL and QuickBooks databases.  The management of Horizon Family Medical Group was notified of their complete loss of data control. They chose silence. This blog exists to illuminate what they are desperately trying to hide. We will not be publishing the files. Yet. Instead, we will explain exactly what this data contains, so that every patient, employee, and partner can appreciate the full scale of the threat.  The Patient, Dissected. What We Know About You  Horizon Family Medical Group prides itself on a wide range of services, from primary care to specialized treatments. This range of services has now become a detailed vulnerability map for every single patient. Our data includes, but is not limited to:  Primary Care: Complete visit histories, diagnoses, prescriptions, lab results, and physicians' private notes about your lifestyle, habits, and family status. Women's Health: Detailed information on gynecological exams, pregnancies, abortions, Pap smear results, STD diagnoses, and prescribed treatments. Everything you trusted only to your doctor. Behavioral Health: The most sensitive category. Diagnoses related to depression, anxiety disorders, bipolar disorder, and addiction. Full session notes from psychotherapists. Every antidepressant and antipsychotic prescription. This information can destroy careers, families, and social standing. Allergy and Immunology: Data on all your allergies, including reactions to specific medications. What happens when this information is lost or altered in your official medical file? Ophthalmology & Nutrition: Your eyeglass prescriptions, diagnoses like glaucoma and cataracts, as well as all your attempts to manage weight, documented eating disorders, and private recommendations from nutritionists.  This isn't just 'data'. This is your life, cataloged and ready for use.  Anatomy of a Business. A Financial Teardown of Horizon Family Medical Group  It's a paradox that clinics, while collecting mountains of information, often fail to see the real picture of their own business. We see it. The 6 terabytes of SQL and QuickBooks databases represent the complete financial and operational model of Horizon Family Medical Group.  We have analyzed:  SQL Databases: These contain complete patient information, doctor schedules, office utilization, patient flow, average revenue per department and per doctor. We know which doctor is profitable and which is a liability. We see every operational metric management uses to make decisions. QuickBooks Databases: This is the financial heart of the company. Every transaction, employee salaries (including hidden executive bonuses), tax reports, debts, loans, and settlements with insurance companies and suppliers. We can see the true profit margin of every service, the customer acquisition cost (CAC), and their lifetime value (LTV).  Horizon's management hasn't just lost patient data. They have lost complete control of their business. Any competitor with this information could dismantle their company by poaching their most profitable doctors and patients.  Eternal Memory. Why This Data Will Never Disappear.  Some believe a data breach is a temporary problem. In this case, it is not. We drew inspiration from the Arctic Code Vault project, where humanity's most critical code is preserved in permafrost for a thousand years.  Your 7 terabytes of data are no longer just files on a server. They have been prepared for archival and distributed storage. They will become a digital monument to the negligence of Horizon Family Medical Group. This data cannot be 'deleted'. It will exist forever, as proof that the company's leadership failed to protect what is most sacred—your health and your privacy.   To the management of Horizon Family Medical Group, we remind you: the clock is ticking. Your silence only magnifies the damage. Contact us. Your patients and your business deserve it.  </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.wolfconstruction.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33152</link>
<guid>fd0bf11c4c1bb2e15892a0683bcd2c5d</guid>
<pubDate>Thu, 18 Jun 2026 05:53:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.wolfconstruction.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>475d23b1ede87e634b429e1b17abe3824bfd8c601668afbfd13064fa84801823</i><br /><br />Threat actor <b>description</b>: <i>Wolf Construction Services, Inc specializes in commercial wood framing, framing carpentry, wood trims, trim carpentry, and pitched roofing. The company also offers residential re-roofing services in Des Moines and Central Iowa. Their intended clients include both commercial and residential property owners seeking quality construction services. Wolf Construction is currently hiring to expand their team.</i><br />Target victim <b>website</b>: <i>www.wolfconstruction.net</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Amazon-owned-OneMedical.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33151</link>
<guid>1322df5fefe9d16cff399438c09c3fb4</guid>
<pubDate>Thu, 18 Jun 2026 04:25:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Amazon-owned-OneMedical.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d845f001d8452c0aa61d974be802270931ee418f235eeac4e2934103090ebcf5</i><br /><br />Threat actor <b>description</b>: <i>Over 8.8TB of data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>NAIC.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33150</link>
<guid>7f8f6aaedd457e94d650576248b8c469</guid>
<pubDate>Thu, 18 Jun 2026 04:25:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>NAIC.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f1a673709e8cf4457828ec58bcc24b96d182103278294a708b95820f0213dcf</i><br /><br />Threat actor <b>description</b>: <i>Over 3.1 terabytes of National Association of Insurance Commissioners data (105,000+ files) was compromised across the INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems (NAIC, all fifty state insurance departments, and thousands of licensed insurers), including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company data, 45,000+ licensed rating agency files from Moody's, Fitch, S&P, Kroll, DBRS, and AM Best with CUSIP and ISIN identifiers, statutory annual and quarterly financial statements, premium and loss statistics, and HR Ratings master data. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>NAIC.org</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Personnel-a-division-of-Masis-Staffing-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33148</link>
<guid>fde673a94858caaadb505ab52c682786</guid>
<pubDate>Wed, 17 Jun 2026 23:53:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>United-Personnel-a-division-of-Masis-Staffing-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a12f023a52bfcd6bdc22b65806c4fbaa4e32381b2549ba1f6ece38194910f2d</i><br /><br />Threat actor <b>description</b>: <i>A provider of staffing services</i><br />Target victim <b>website</b>: <i>msastaffing.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Associated-Builders-and-Contractors-of-IndianaKentucky</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33147</link>
<guid>414a17613b27acc54d1ee7d56cc7346f</guid>
<pubDate>Wed, 17 Jun 2026 23:52:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>The-Associated-Builders-and-Contractors-of-IndianaKentucky</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2f884f67b96fe2dc8bcfd67ed20a716d3bf46d70f4aa3dbcd7ed7e80b3c113e</i><br /><br />Threat actor <b>description</b>: <i>A trade association</i><br />Target victim <b>website</b>: <i>abcindianakentucky.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greg-Crosslin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33141</link>
<guid>d79c868179307f1cf78d0a12c56e2bf9</guid>
<pubDate>Wed, 17 Jun 2026 18:26:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Greg-Crosslin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a90977fa553ef16b64009275224f2dd8a8d43536573c0048bb3cfcc28aad1fa</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.destinlegal.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33139</link>
<guid>6c1e751ccd093d6fecc68ea485e32c99</guid>
<pubDate>Wed, 17 Jun 2026 17:54:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Integrated-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4edae4ef97002fae94fa1cda907eef6b1f0bf55fc91dca99d3483d3e7edc97a6</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.itc4u.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>eurOptimum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33138</link>
<guid>c4829296d8ff463d96c343cc0682c6fb</guid>
<pubDate>Wed, 17 Jun 2026 17:54:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>eurOptimum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f5b2b6b9b3a9337a29aa82b56cee694ed74fa3dbb1fa8390ba89e878e5e46d6</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.europtimum.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prince-George-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33137</link>
<guid>1a4461e3ca15c1b7c5b322f161cdcf0b</guid>
<pubDate>Wed, 17 Jun 2026 17:25:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Prince-George-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b181b933e635d0fd25ff09a098683b5855d045bd61f41f09d1a9572bef0dc0e8</i><br /><br />Threat actor <b>description</b>: <i>Prince George County is a local government entity focused on providing essential services and fostering community development. It offers a range of services including public safety, waste management, parks and recreation, and social services to its residents. The county aims to embrace its rural character while planning for a prosperous future. Its intended clients include local residents, businesses, and visitors seeking information and services related to the county.</i><br />Target victim <b>website</b>: <i>www.princegeorgecountyva.gov</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smith-Filter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33136</link>
<guid>228872c6bcbb4ba580cc93345e2c6775</guid>
<pubDate>Wed, 17 Jun 2026 12:50:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Smith-Filter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d60e79e2faabe296e8dba7fe6925f95d8cdde979028b0b059814a2642dfc43e3</i><br /><br />Threat actor <b>description</b>: <i>Smith Filter is a leading manufacturer of high-quality air and grease filters, established in 1
939. They offer a wide range of products including permanent, disposable, and high-efficiency f
ilters, catering to both OEM and custom orders.

We will upload 10gb of corporate data soon. Employee personal information (passports, SSNs, DLs
and other docs scans), credit cards information, projects info, clients information, NDAs, etc
.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>jasperplastics.info</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33127</link>
<guid>d31659eda7c840776f9caf88e48fd6dd</guid>
<pubDate>Tue, 16 Jun 2026 17:22:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>jasperplastics.info</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>daf11c9858c33a004b0db8267ac57367c17f0f82a0a1eb41d3d94ae0c7457475</i><br /><br />Threat actor <b>description</b>: <i>Jasper Plastics Solutions specializes in providing turn-key plastic and polyurethane solutions primarily for OEM manufacturers in the RV, Marine, Automotive, and Construction industries. Their product offerings include polyurethane thermal column blocks, fiberglass components, and innovative design boards that are weather-resistant and customizable. With nearly 20 years of experience, they utilize advanced manufacturing techniques, including a new HD Digital Division for large format printing, to create high-quality parts that mimic natural materials. Jasper Plastics is committed to delivering practical and innovative solutions tailored to the specific needs of their clients. Employees: 10 Revenue: $5 Million Industry: Manufacturing  Phone Number: (574) 457-2062</i><br />Target victim <b>website</b>: <i>jasperplastics.info</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>framesiprofessional.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33126</link>
<guid>1df46b08d20c24e4a93cfa88131b4185</guid>
<pubDate>Tue, 16 Jun 2026 15:23:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>framesiprofessional.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd8e0d90cf029db224c2ea6e0d39cf91a9e6ac1b0008fe5428959c69d7ddc6cb</i><br /><br />Threat actor <b>description</b>: <i>Framesi specializes in creating and distributing professional hair products, including styling tools, color dyes, and hair treatments, exclusively for licensed stylists and salons. The company is dedicated to supporting the professional beauty industry by ensuring high-quality formulations that deliver reliable results. Framesi does not sell its products to retail chains or discount beauty outlets, maintaining a focus on professional use. Their offerings include a wide range of color products, care items, and styling solutions tailored for expert hands Employees: 200 Revenue: $25.1 Million Cosmetics, Beauty Supply & Personal Care Products Phone Number: (800) 321-9648</i><br />Target victim <b>website</b>: <i>framesiprofessional.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allan-Brothers-Fruit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33124</link>
<guid>2e874776f1f92f702ba41b53941ccdc8</guid>
<pubDate>Tue, 16 Jun 2026 13:22:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Allan-Brothers-Fruit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ac160ed7df76963a9944ade77b3bb7e9874f530268a6904ebe94f32bcb8c472</i><br /><br />Threat actor <b>description</b>: <i>[food] Allan Brothers, Inc. — a third-generation, family-owned tree-fruit operation headquartered in Naches, Washington. Allan Brothers packs and ships apples and cherries from a 300,000 sq ft cold-storage facility, employing roughly 45 full-time staff and up to 2,000 seasonal workers during peak harvest.

Eight server volumes:

14,228 employee records from ADP Workforce Now — names, dates of birth, phone numbers, gender, employment history, photos — covering every person who has ever worked at Allan Brothers, including seasonal cherry pickers, H-2A visa workers, and office staff.
W-2 tax filings with full Social Security Numbers for employees across eight legal entities (ALLAN, ABMEXICO, ABSAGE, ABSAGEMOOR, ABVINEYARD, ABAG, ABSHELTON, ABFROST).
Direct deposit forms with bank routing numbers and account numbers for named individuals — the raw ingredients for ACH fraud.
H-2A visa worker tracking spreadsheets listing which workers have or are missing Social Security Numbers, plus I-9 employment eligibility audits — exposing immigration status for the most vulnerable members of the workforce.
A complete Oracle RMAN database backup of the Famous Software production system — the company's grower settlement, customer pricing, and lot-tracking engine.
1.3 GB of employee badge photos — facial images linked to names and employee IDs for hundreds of workers.
COBOL-era accounting databases spanning 8 legal entities — GL, AP, AR, payroll, and W-2 filing data going back years.
OSHA incident logs naming workers who sustained injuries, with injury descriptions and treatment details.</i><br />Target victim <b>website</b>: <i>Allan Brothers Fruit</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Golfview-Developmental-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33118</link>
<guid>12c39d8d04046a8099182c4d83191291</guid>
<pubDate>Tue, 16 Jun 2026 12:25:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Golfview-Developmental-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b076a6bdd6515cb1592c91d82e09bc2ca74167f75997143e2048bbf9a1e2c4ed</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.golfview.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>thecreditpros.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33110</link>
<guid>3c393443d24e71aeb3557011787c11cd</guid>
<pubDate>Tue, 16 Jun 2026 09:50:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Icarus</b> claims attack for <b>thecreditpros.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfe4103c506d4130df6d110c76d9b059db79d47f8fda07c80af288e631702d12</i><br /><br />Threat actor <b>description</b>: <i>TheCreditPros' Salesforce instance was breached and 263MB of data were taken from it, including:

01_input_fullcards.csv - 51,691 lines of full-info credit/debit cards: Id,First_Name__c,Last_Name__c,Middle_Name__c,Email__c,Credit_Card__c,CCV__c,Exp_Month__c,Exp_Year__c,SSN__c,DOB__c,Street_Address__c,City__c,State__c,Zip_Code__c,Mobile_Number__c,IP_Address__c,Transaction_ID__c,Status__c,CreatedDate

02_contacts_ssn.csv - 847,990 lines: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,HomePhone,SSN_hidden_field__c,Birthdate,MailingStreet,MailingCity,MailingState,MailingPostalCode,Status__c,Bank_Account_Number__c,Bank_Name__c,Bank_Account_Type__c,CreatedDate

03_creditcards.csv - 722,403 lines: Id,Card_number__c,card_number_hidden__c,cvv__c,expiration_month__c,expiration_year__c,Active__c,BIN__c,Issuing_Bank__c,Prepaid__c,CreatedDate

04_leads.csv - 3,598 liens: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,Street,City,State,PostalCode,Status,CreatedDate

Pay or leak!

Data stolen: PII, Credit cards</i><br />Target victim <b>website</b>: <i>thecreditpros.com</i>]]></description>
<category>Icarus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Q-Link-Wireless</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33106</link>
<guid>e03cba77a01e29e49e8fe0d2fd26d577</guid>
<pubDate>Tue, 16 Jun 2026 01:56:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Q-Link-Wireless</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f1836d33086c4cb384904ee729b549d8a42427bcd8060862e11561fffbf43cf</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.qlinkwireless.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>smithassociatescpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33103</link>
<guid>7b28169ffebdd960282bcc01252a8302</guid>
<pubDate>Mon, 15 Jun 2026 20:54:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>smithassociatescpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c69c8c7fd0f10f82fba9828b8316b0d9ed4388bad0405597bb3dea528e229d06</i><br /><br />Threat actor <b>description</b>: <i>smithassociatescpa.com
 
 
 Smith and Associates is a Certified Public Accounting Firm based in Maine, offering a comprehensive range of services including accounting, auditing, tax planning, and management advisory services. The firm caters to a diverse clientele, including individuals, corporations, partnerships, and non-profits in Maine and New Hampshire. They provide specialized support for business start-ups and QuickBooks, along with professional consulting in various areas of tax and accounting practices. Established in 1987, Smith and Associates is committed to being personable, knowledgeable, and responsive to their clients' needs.</i><br />Target victim <b>website</b>: <i>smithassociatescpa.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>MAVA-Healthcare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33085</link>
<guid>5b92e4945eb3a04990671a4da604ff17</guid>
<pubDate>Mon, 15 Jun 2026 19:51:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>MAVA-Healthcare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21d40277f19e3444365c9d14389756a3e8e52965ac12cf0dc81b7392628f5944</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>icc.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33101</link>
<guid>c1d51344306860ede1fca0e6fbae369d</guid>
<pubDate>Mon, 15 Jun 2026 19:28:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>icc.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>737fbdf8a21ca39181c364ec14e7f97dc0ac6f27b2383124e3d25aee631c56c7</i><br /><br />Threat actor <b>description</b>: <i>Over 28 gigabytes of Illinois Central College data (122,000+ files) was compromised across PeopleSoft Campus Solutions and Human Resources (ICC, SURS pension reporting, Workday costing, and ICCB curriculum systems), including 9,200+ employee payslip PDFs, 500+ SURS payroll files with Social Security numbers, direct deposit records with bank account and routing numbers, student financial aid and grade roster exports, enrollment CSVs with @icc.edu accounts, and Workday salary allocation data spanning 2021 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>icc.edu</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>moody.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33100</link>
<guid>7b1b6d2fdf573b01058f16f6e398b69c</guid>
<pubDate>Mon, 15 Jun 2026 19:28:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>moody.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0df034a71858bb944343acf36c46eb694de6e9a649359d86a1d57408f85a0380</i><br /><br />Threat actor <b>description</b>: <i>Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of millions of records) was compromised across enrollment, donor relations, payroll, and communications systems (MBI, EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS, WHPD donor database, and Cadence admissions), including 46 million communication records, 2.2 million enrollment lead records, 108,000 biodemographic master files with addresses and birthdates, 3.3 gigabytes of donor gift data, employee payroll XML with home addresses and earnings, 1,100+ admissions outreach files, and student housing assignment records. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>moody.edu</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>glendale.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33099</link>
<guid>e40d1c91705e98a59715fd4bb89d5e39</guid>
<pubDate>Mon, 15 Jun 2026 19:28:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>glendale.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>822ec22096c987d3c770aeb2981af6897863bb8bcb5b0f9520a509c02db25932</i><br /><br />Threat actor <b>description</b>: <i>Over 62 gigabytes of Glendale Community College data (304,000+ files) was compromised across PeopleSoft Campus Solutions (GCC, integrations, financial aid, and admission processing), including 150,000+ student records with names, dates of birth, and @student.glendale.edu emails, login and enrollment mapping files, new student enrollment CSVs, immunization compliance logs, admission checklist reports, financial aid batch exports, and transcript PDFs spanning September 2020 through June 2026. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>glendale.edu</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>hoodriversheriff.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33092</link>
<guid>2f4933c1afab8024d9f80a42a58c9c67</guid>
<pubDate>Mon, 15 Jun 2026 19:24:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>hoodriversheriff.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a85ce9b8344331bfbfa8359d723ece8a2c085d880e447947a9a6dab5168214d3</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in Hood River, the organization provides a broad range of services, including patrol operations, criminal investigations, emergency communications, search …</i><br />Target victim <b>website</b>: <i>hoodriversheriff.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>hccs.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33080</link>
<guid>842bdb242c777d40703b4eb991322bb9</guid>
<pubDate>Mon, 15 Jun 2026 14:24:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>hccs.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f7dca0dff6213fe6a19ee383db8a3b36ef8c18bc3e65dbaf5c278f0bc9a5fab</i><br /><br />Threat actor <b>description</b>: <i>Hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses. Daily and full student roster exports library credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000 financial aid and bursar reports including FAFSA/ISIR suspense data with names, birthdates, emails, phones, and home addresses. Class rosters with birthdates, grades, academic programs, and contact information for tens of thousands of enrolled students per term. Over 344,000 international student documents including SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits, and acceptance letters. Over 14,000 student immunization and vaccination records including meningitis compliance documentation. Over 15,000 additional health and immunization documents across report archives and A LOT more was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>hccs.edu</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>kodak.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33079</link>
<guid>95753ccc84f42b133d6db84a22df8dd4</guid>
<pubDate>Mon, 15 Jun 2026 14:24:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>kodak.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78d22270996942247187395121616fcac49303d5cc92b5b72d7326fa85aaa2c8</i><br /><br />Threat actor <b>description</b>: <i>Over 2.2 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>kodak.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deep-Well-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33078</link>
<guid>5e6ade62cb178a509b3e10431c34dffe</guid>
<pubDate>Mon, 15 Jun 2026 14:23:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Deep-Well-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a64e0d99c3aa0abfd0359b4fe5fc71d53f1c5874622e66b40a8c7c96461db962</i><br /><br />Threat actor <b>description</b>: <i>Over 7k records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sysco-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33077</link>
<guid>32bb9f32e97807c36a1b1a881b31d33b</guid>
<pubDate>Mon, 15 Jun 2026 14:23:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Sysco-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d1e4cd37d69c5b8d6028e04e2f19c056eec9c18ef8674f481ea81ec5c5a7e4a</i><br /><br />Threat actor <b>description</b>: <i>Over 61 million Salesforce records across several tables, some containing customer data/PII, employee data, and other internal corporate data was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Texas-Spinal-Clinic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33075</link>
<guid>46433ef1f34731171c310acd7957a45c</guid>
<pubDate>Mon, 15 Jun 2026 13:02:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>South-Texas-Spinal-Clinic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ec53d9c69603b498d42387e68382d6bf0201a212f10196635f059b52c8684d2</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/south-texas-spinal-clinic-pa/57099280 South Texas Spinal Clinic has been a trusted regional leader in orthopedic care since 1986, specializing in comprehensive spine, bone, and joint treatments across San Antonio and South Texas. Their team of board-certified specialists focuses on delivering exceptional, patient-centered care ranging from advanced pain management to targeted bone health therapies. They are dedicated to improving mobility and quality of life through expert prevention, education, and innovative medical solutions</i><br />Target victim <b>website</b>: <i>spinaldoc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Palmer-Sicard</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33071</link>
<guid>0f3a2f98e96a7814843c08149489dc12</guid>
<pubDate>Mon, 15 Jun 2026 13:01:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Palmer-Sicard</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b533eda164d99061155e644e302ec3f4259485a49fd72fc7c0d6687eeb5a23c2</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/palmer--sicard-inc/43926372 Palmer & Sicard is a premier, 100% employee-owned mechanical contractor established in 1954 and headquartered in Exeter, New Hampshire. For over 70 years, they have proudly served Northern New England, specializing in comprehensive HVAC systems, commercial plumbing, and custom sheet metal fabrication. Driven by a commitment to excellence, this trusted team delivers dependable, top-tier mechanical solutions from initial project conception through final installation and ongoing service</i><br />Target victim <b>website</b>: <i>palmerandsicard.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Executive-Coach</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33068</link>
<guid>f3be427f0ac1afb683a16c324f740515</guid>
<pubDate>Mon, 15 Jun 2026 13:00:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Executive-Coach</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>087a1946f30f54ddad18a722fbed8cd80a93907d6d54c3378ba7d62056fcb825</i><br /><br />Threat actor <b>description</b>: <i>***.net zoominfo.com/c/executive-coach-inc/32002101 Executive Coach Inc. is a premier group transportation and luxury motorcoach charter company based in Lancaster, Pennsylvania, proudly serving clients since 1979. Despite its corporate-sounding name, the company does not offer leadership training; instead, it specializes in comfortable charter bus rentals, airport transfers, and customized group tours. They provide reliable, high-end travel solutions across Pennsylvania, Maryland, and beyond, seamlessly accommodating groups of all sizes with a modern and well-maintained fleet</i><br />Target victim <b>website</b>: <i>executivecoach.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cole-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33058</link>
<guid>1f163d2cf1782152bdd7333dbd880b46</guid>
<pubDate>Mon, 15 Jun 2026 12:56:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Cole-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edf605bc6799d621f51f5bae789f7d28d09a84ee86bd29396b2b9d609c7aacc4</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/cole-manufacturing-corp/344188464 Cole Manufacturing is a specialized metal fabrication and custom tooling company based in West Bend, Wisconsin, dedicated to delivering high-quality, cost-effective solutions for the metal forming industry.They offer a comprehensive range of services, including precision tool and die making, metal stamping, prototyping, and both manual and robotic welding.With versatile capabilities and advanced equipment, the company expertly handles projects of any size, providing reliable manufacturing support from custom fixtures to high-volume production runs</i><br />Target victim <b>website</b>: <i>colemfg.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maine-Oxy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33057</link>
<guid>d1d8b9bbeefe2d37fc12e8aa4abf7e86</guid>
<pubDate>Mon, 15 Jun 2026 12:56:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Maine-Oxy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4771ad6eda2cc8805f405370e6a4e4b7b96817cd2d77b268454e8857e1bd47fa</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/maine-oxy/59165071 Founded in 1929, Maine Oxy is a trusted, family-owned leader in supplying industrial, medical, and specialty gases alongside premium welding equipment.Growing from a single location in Auburn to over 20 branches across New England, they provide comprehensive industry solutions and reliable services.For nearly a century, their unwavering dedication to innovation has made them an essential, customer-focused partner for businesses across nine states</i><br />Target victim <b>website</b>: <i>maineoxy.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buechel-Stone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33056</link>
<guid>e44324e95c8c533a9216ad03ee0f6932</guid>
<pubDate>Mon, 15 Jun 2026 12:56:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Buechel-Stone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9212fc8964759650d974715561095770c45f5a19424096097a4234ab511e91ae</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/buechel-stone-corp/5800461 Founded in 1964 as a family-owned business, Buechel Stone is a premier natural stone quarrier and fabricator based in Wisconsin. Specializing in over a hundred varieties of natural stone, they provide exceptional building veneers, custom cut stone, and landscape products for architectural projects. As a third-generation company with a nationwide presence, they pride themselves on delivering unparalleled expertise and a guaranteed, dependable experience in the natural stone industry</i><br />Target victim <b>website</b>: <i>buechelstone.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sky-devices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=33052</link>
<guid>c46b5638a51848602d84d27b2d741133</guid>
<pubDate>Mon, 15 Jun 2026 10:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Sky-devices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c190823360bec3c91a682627b70360072c372d29219e8340673fdb4dec09049</i><br /><br />Threat actor <b>description</b>: <i>SKY Devices offers a diverse range of technology products including smartphones, tablets, wearables, and laptops. Their portfolio features various series such as the ELite and Platinum series, catering to different consumer needs. The company targets a young and tech-savvy audience looking for smart and stylish devices. With a focus on innovation and quality, SKY Devices aims to provide accessible technology solutions - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>frey.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32976</link>
<guid>e78c666d9e6c8aaf2cb2044b8960c4d2</guid>
<pubDate>Sun, 14 Jun 2026 20:22:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>krybit</b> claims attack for <b>frey.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e86057c63df2fa82c84af6c1566a86a8ad4871cde59d5313e7ed9266e4e02964</i><br /><br />Threat actor <b>description</b>: <i>FREY (Frey Brothers, Inc.) is an American eco-friendly laundry care products company founded in 2017 by brothers Erin an...</i><br />Target victim <b>website</b>: <i>frey.com</i>]]></description>
<category>krybit</category>
</item>
<item xmlns:dc='ns:1'>
<title>Silsbee-Police-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32974</link>
<guid>01bbd8f95cd042e965e53b0a85354bd3</guid>
<pubDate>Sun, 14 Jun 2026 11:23:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Silsbee-Police-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a20d085afd595fa7676483c5605660c86b33927c60119f1ce49a5dd6d9be4e57</i><br /><br />Threat actor <b>description</b>: <i>Court Information</i><br />Target victim <b>website</b>: <i>www.silsbeeisd.org/departments/silsbee-isd-police-department</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blue-Nile-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32971</link>
<guid>6e6b932765a4acb23ea40e12b4adbbac</guid>
<pubDate>Sun, 14 Jun 2026 10:55:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Blue-Nile-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d54a68077d2abe1d665026f6e58be0e6e98013263ba4c6fa8ab6a8d69dfb3ff</i><br /><br />Threat actor <b>description</b>: <i>More than 3000+ Patient's EHR Records</i><br />Target victim <b>website</b>: <i>bluenilemedical.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-US-immigrationonline.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32965</link>
<guid>42799134f1278558546a42770711ed62</guid>
<pubDate>Sat, 13 Jun 2026 10:07:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Triple X</b> claims attack for <b>Law-Offices-US-immigrationonline.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a96cfee9b0cb3671915da9d589db767e151aab13f0dffbc105d44d9feaafa970</i><br /><br />Threat actor <b>description</b>: <i>https://immigrationonline.com/
1.5 terabytes of people's data in a immigrationonline law firm.
Server overload and lack of updates have caused important data to be exposed to potential leaks.
At the same time, many of these financial and tax documents also contain sensitive personal information, including full names, home addresses, Social Security numbers, banking details, and contact information.
what will leak ?
Confidential court cases : Details of lawsuits, complaints, or defenses that have not yet been filed in court.
Financial and banking information : Sensitive client accounts, contracts, or transactions.
Intellectual property documents : Such as patents, designs, or business contracts that have not yet been made public.
Private correspondence and emails : Communications between the attorney and the client that should remain strictly confidential.
what data will leak ?
24,900 passport files
sample
Tax forms of employees and colleagues
sample
ID cards and driver’s licenses
sample
few sample pics:
pic 1
pic 2
pic 3
pic 4
pic 5
This is probably the right moment to point out that, at a certain stage, virtually any data breach is still a reversible situation. Companies are usually given an opportunity to contain the damage and resolve the issue albeit at a price.
But despite knowing exactly what was happening, and fully understanding that it was putting the security and privacy of its own employees at risk, the company made a calculated decision to let it happen.
And now the company will tell its employees: “Sorry, we’ve experienced a data breach, and your passports are now publicly available online.”
But they will never say: “We were offered a chance to pay to prevent your passports from being published, but we decided it wasn’t worth it so now they’re on the internet. Sorry.”
download data link :  http://6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion/immigrationonline.com/</i><br />Target victim <b>website</b>: <i>immigrationonline.com</i>]]></description>
<category>Triple X</category>
</item>
<item xmlns:dc='ns:1'>
<title>GITHUB-INTERNAL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32963</link>
<guid>491991572cf97170a77cc98cc908684b</guid>
<pubDate>Sat, 13 Jun 2026 10:02:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lapsus$</b> claims attack for <b>GITHUB-INTERNAL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2ccc1f59c2bb7be094f4ef3306fe02973eba1c8f9717dcd7cc431d61bd2756b</i><br /><br />Threat actor <b>description</b>: <i>Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free.</i><br />Target victim <b>website</b>: <i>github.com</i>]]></description>
<category>lapsus$</category>
</item>
<item xmlns:dc='ns:1'>
<title>jetmachprod.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32959</link>
<guid>ad95ec9b8ae9bbcc28244c0c00f8089d</guid>
<pubDate>Fri, 12 Jun 2026 20:07:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>jetmachprod.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73488e9ef83f86b9f563632c87338fad3fbd73eda48b03752b0c256d30fb90b9</i><br /><br />Threat actor <b>description</b>: <i>Jet Machined Products specializes in high-performance milled and turned components for the aerospace, instrumentation, robotics, and other specialized industries. With decades of experience, they focus on precision manufacturing to meet exacting t</i><br />Target victim <b>website</b>: <i>jetmachprod.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>mgrlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32948</link>
<guid>2d76ad7ae5fb13d95eb34c39c6fb59b0</guid>
<pubDate>Fri, 12 Jun 2026 19:59:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>mgrlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>36782c4720741bfc5cb80b56d3b5aab4c9508c7ff7c4ba35541ff794d7d8c368</i><br /><br />Threat actor <b>description</b>: <i>Mogren, Glessner & Ahrens Law Firm is a full-service law firm located in King County, specializing in family law, divorce, probate, wills, criminal defense, personal injury, and adoption. Established in 1942, the firm is dedicated to providing com</i><br />Target victim <b>website</b>: <i>mgrlaw.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>DDC-Domus-Design-Collection</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32941</link>
<guid>040fec70955253769acc94f134177c63</guid>
<pubDate>Fri, 12 Jun 2026 15:43:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DDC-Domus-Design-Collection</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>192aa4a3adc20e62226ce003b91b003daf69395778d585ffe6b04c8af21469e5</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1991 and headquartered in New York City, New York, DDC Domus Design Collection is a company that manufactures as well as sell furniture items.We will upload 55gb of corporate data soon. Detailed financials, employee personal information (passports, addresses, phones, emails and so on), credit cards information, projects, clients info, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Madison-Square-Garden-Sports-Corp.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32934</link>
<guid>71f0603a717117b0bc2df3f784862801</guid>
<pubDate>Fri, 12 Jun 2026 06:58:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Madison-Square-Garden-Sports-Corp.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0760ef1b69a5a64fd45c90981e3b74d95616fd8c47b869ea1b4221c91d5f0bb</i><br /><br />Threat actor <b>description</b>: <i>Over 26 million records containing customer PII and other internal corporate data was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Tower-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32932</link>
<guid>95c14ff9ca2c5d8ead4a18b1e830d504</guid>
<pubDate>Fri, 12 Jun 2026 06:57:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>American-Tower-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>914f9632f40771423ca1177f136479011945db4774cba4b4ed8e05921cd72c58</i><br /><br />Threat actor <b>description</b>: <i>Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other companies such as T-Mobile, Verizon, and the US DHS, several tower asset records containing GPS data and plaintext physical access/gate codes for cell tower compunds across the United States, thousands of internal corporate data, and a lot more were compromised. We urge you to reach out. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zayo.com--Allstream.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32931</link>
<guid>ccb946faf2ff655ccffee7f306a81888</guid>
<pubDate>Fri, 12 Jun 2026 06:57:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Zayo.com--Allstream.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c86c845589eb9917d44537377e9ebbe0a9eceb53758b29c99965e035243c00da</i><br /><br />Threat actor <b>description</b>: <i>You wouldn't want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms of criticality is a 9/10. We urge you to reach out. Read our emails. Failure to do so will result in the full publication and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Vant-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32928</link>
<guid>e3d45a69ec2fe85434bc276b0994e088</guid>
<pubDate>Fri, 12 Jun 2026 04:51:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>The-Vant-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>622b0258ae21de7b3fc57f429807f8a32896548f79d60ae09bc08a5f503325b4</i><br /><br />Threat actor <b>description</b>: <i>The Vant Group, founded in 1999, is an M&A advisory firm serving businesses up to $250M in revenue. It provides valuations, sell/buy-side advisory, and employee/partner buyouts, leveraging experienced professionals. Clients are mainly entrepreneurs and owners.</i><br />Target victim <b>website</b>: <i>www.thevantgroup.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>CCS-GLOBAL-TECH</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32927</link>
<guid>84634b38369065bd59d7093454b8d8d5</guid>
<pubDate>Fri, 12 Jun 2026 02:50:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>CCS-GLOBAL-TECH</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95d8d6e9017c6747ac3a5e6078c1ed7b4974744172a122b2f0df357bebe152e2</i><br /><br />Threat actor <b>description</b>: <i>They provide digital and cloud solutions for business processes.</i><br />Target victim <b>website</b>: <i>ccsglobaltech.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sierra-West-Jewelers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32925</link>
<guid>e276f77f5eb4b51b5852dc9a08092d47</guid>
<pubDate>Fri, 12 Jun 2026 02:24:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Sierra-West-Jewelers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1838862c20f8e5eb9823d06849fe8a6e5a20a61302dd66237af936edab8f7f3</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clnica-Vida</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32923</link>
<guid>81fc53c51059936bda7ac43bdcb32449</guid>
<pubDate>Fri, 12 Jun 2026 01:22:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Clnica-Vida</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fc79c27ca3216e467db0fa58bfb97e34af1be22a98dd40efe5c84697a91fb7a</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>clinicavida.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nueva-Pescanova-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32921</link>
<guid>08faa15558a741e7cc59f718a5cc6213</guid>
<pubDate>Fri, 12 Jun 2026 01:21:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Nueva-Pescanova-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d727a894e4ba0df41ba5dd981dd3823bf54e479b338f62b6b0140d36da9c3af5</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>nuevapescanova.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kewaunee-Scientific</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32919</link>
<guid>db35739b2480ba8a3aadbbf1999a2382</guid>
<pubDate>Thu, 11 Jun 2026 19:23:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Kewaunee-Scientific</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f6c31e57c10d424d8d08e574743ec783c3345344932f35f14a5642d3a83363b</i><br /><br />Threat actor <b>description</b>: <i>Total data: 504GB Contains: 852,141 Files, 120,670 Folders  Documents: Clients KYS & NDA, Financial documentation, Contracts, Drawings, Audit reports,  Personal data, Contractors and subcontractors information, Scanned documents and much other important information. Tape: confidential Clients: Pfizer, Rusan Pharma Ltd., Samsung and many other world-famous laboratories.  full information will be released in a few weeks</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>SignazonUSA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32918</link>
<guid>5ce47c81e96cb7483a0c79502cd8c571</guid>
<pubDate>Thu, 11 Jun 2026 18:52:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>SignazonUSA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eefec29e57e2f5d31e1a2fe54b9a8c0e7cccf77fae87e674adac35005bd238ea</i><br /><br />Threat actor <b>description</b>: <i>Signazon.com was founded with the mission of providing the company's customers with the very best in printing. It's one thing to print fast and cheap - it's another thing to do that and do it well. The company believes in getting the little details right. From asking the company's customers the right questions to picking out different weights of paper, fine-tuning the company's printers for optimal quality to hand-checking every order several times throughout the production process, no stone is left unturned. And the company works hard every day to make sure that each and every customer gets the highest-quality, personalized products and service. With thousands of customers around the country, ranging from Fortune 500 companies to small business owners and even personal consumers, we've embraced the company's place as leaders at the innovative edge of the industry. We're constantly looking to improve and grow by streamlining the company's website, adding new products, and more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>maringoodman.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32917</link>
<guid>523d6984fa5aa355c0f4b63b564ce892</guid>
<pubDate>Thu, 11 Jun 2026 18:24:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>maringoodman.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f46683744684046bf825560b9e2f1e74e4fdc49ad5656fa00502bbd5de844724</i><br /><br />Threat actor <b>description</b>: <i>+1 9144127301 Fredric Goodman , +1 9144127331 Mr. Richard Marin. Marin/Goodman LLP is a full-service litigation firm based in New York, providing sophisticated and practical legal services to businesses and high net worth individuals. With over 17 years of experience, the firm specializes in various practice areas including business law, entertainment, technology, and personal injury. They offer creative legal and business advice, manage national risks, and serve as concierge counsel to their clients. The firm prides itself on its responsiveness and dedication to achieving client goals while maintaining long-term relationships with leading corporations. Stolen: 2.33 TB 1,612,094 Files</i><br />Target victim <b>website</b>: <i>maringoodman.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scenic-Hudson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32909</link>
<guid>41b69f211dd5617d041802a8813d6d66</guid>
<pubDate>Thu, 11 Jun 2026 17:28:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Scenic-Hudson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>215afc897898e5dd13532349b880b631b3ea2ec2036550298e383a427b634a2e</i><br /><br />Threat actor <b>description</b>: <i>***.org zoominfo.com/c/scenic-hudson-inc/61506079 Scenic Hudson is a U.S. nonprofit environmental organization founded in 1963 to protect the Hudson River Valley’s natural beauty. It preserves scenic landscapes, creates public parks, and fights industrial pollution. Today, Scenic Hudson also champions clean energy, climate resilience, and environmental justice throughout the region</i><br />Target victim <b>website</b>: <i>scenichudson.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.commonwealth-partners.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32904</link>
<guid>1876af03cdc28f1b1d02014a0b91a7c9</guid>
<pubDate>Thu, 11 Jun 2026 15:52:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.commonwealth-partners.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89d4617a705d6a1668bc5b5d4a093650df3dc8d4dedb44f98d74c8d4d9d0c13c</i><br /><br />Threat actor <b>description</b>: <i>CommonWealth Partners Properties specializes in a range of real estate services including investment transactions, portfolio management, asset management, and property management. The company is committed to environmental, social, and governance (ESG) principles and emphasizes stakeholder engagement. Their intended clients include property owners and tenants seeking comprehensive management and development solutions. With a focus on delivering value and sustainability, they aim to enhance the performance of their real estate assets.</i><br />Target victim <b>website</b>: <i>www.commonwealth-partners.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>TeleFinity</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32993</link>
<guid>85ce4663aea037e030d72a4d88f83010</guid>
<pubDate>Thu, 11 Jun 2026 14:11:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>deadlock</b> claims attack for <b>TeleFinity</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i></i><br /><br />Threat actor <b>description</b>: <i>TeleFinity is a global provider of computer telephony integration (CTI) and unified contact center software, offering solutions like LogFinity call recording, WebRTC-SIP gateways, and omnichannel contact center platforms. Founded in 2005, the company delivers enterprise-grade,, AI-driven, and CRM-integrated communication products with on-premises or cloud deployment options.</i><br />Target victim <b>website</b>: <i>https://tele-finity.com/</i>]]></description>
<category>deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maui-Divers-Jewelry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32898</link>
<guid>b325f6f5597950ec6ba7cce1e82f04d2</guid>
<pubDate>Thu, 11 Jun 2026 12:24:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Maui-Divers-Jewelry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae06a4166e1046967e26b86c28d35857f1e18f22e514c4dacc484c3ed2f4f256</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mauidivers.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nexstar.tv</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32896</link>
<guid>f8cd71b7b469f15bd03947f8493a7259</guid>
<pubDate>Thu, 11 Jun 2026 09:54:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Nexstar.tv</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>256b078b38d90d164d66b0d5fcc91db3d0be808838df0b279f6fc6ac8786ea40</i><br /><br />Threat actor <b>description</b>: <i>Over 1 million Salesforce records and other internal corporate data containing PII was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>Nexstar.tv</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ralph-Lauren-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32895</link>
<guid>7c2dccff2cb6e946fb068f6b604ea868</guid>
<pubDate>Thu, 11 Jun 2026 09:54:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Ralph-Lauren-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>160ea713ca188c925c66d7ea13ad9501bc918af47d23b101e6e2092f97b11e70</i><br /><br />Threat actor <b>description</b>: <i>Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>delano.k12.mn.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32892</link>
<guid>a784627b0f726b9e6b4bd5ab99904afb</guid>
<pubDate>Thu, 11 Jun 2026 07:12:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>delano.k12.mn.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>057641114b9aae4f6fc13721f0a16707bfa2cc25d053eab5846e4ac79168f86b</i><br /><br />Threat actor <b>description</b>: <i>Delano Public Schools is dedicated to providing systemic growth toward educational excellence for ev...</i><br />Target victim <b>website</b>: <i>delano.k12.mn.us</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>JV-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32868</link>
<guid>8b21b1c01bd1ec137671219ab3696da6</guid>
<pubDate>Wed, 10 Jun 2026 23:54:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>JV-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b64e343a2d3ff7b062b48218236b8243ed322cd705748604f6e20100d10a356</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SAMES</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32869</link>
<guid>ea56b27fc27978cc94666af12740f6f3</guid>
<pubDate>Wed, 10 Jun 2026 23:53:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SAMES</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2bfb4ac5420e846f7e9eddb845e8df85b65a31f130176c8a7a08aa0118ae2cc</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>C.C.-Creations</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32870</link>
<guid>c336fcef7e3edebda3f4df29549bf5fb</guid>
<pubDate>Wed, 10 Jun 2026 23:53:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>C.C.-Creations</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>baf48135e804d8f1a65428b6af0b94888bd68d40951dc350eddfc803904fcb0b</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>dbHMS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32871</link>
<guid>0ddb0ca1ac0fe9a9899a14c8da505d02</guid>
<pubDate>Wed, 10 Jun 2026 23:51:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>dbHMS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffd866f139c6f192aaab2a227f4e76ae9b23c0a713c4e85fa108657eeaa2b2a7</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Teserra-Outdoors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32872</link>
<guid>db923cfd3b8b67f23a1b6dee06f1f66c</guid>
<pubDate>Wed, 10 Jun 2026 23:51:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Teserra-Outdoors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e73ce201987dbfb9f219cd1378e4270c9ed89e38c1dd7ae9c4aa01eedb6ddd7b</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wright-Constable--Skeen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32873</link>
<guid>b20eef1fea97cb4e1913531f8b3d0176</guid>
<pubDate>Wed, 10 Jun 2026 23:49:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wright-Constable--Skeen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5deba00d3d72b051606b36b7ee3ef9377a7c94f90d7e5296fabeb6b0e3512142</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Milstein-Siegel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32874</link>
<guid>561eaa108c9074d4c16da3186f2b9be0</guid>
<pubDate>Wed, 10 Jun 2026 23:48:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Milstein-Siegel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>480cf23d71e801f499be2e82b17f4ea209c4a7e79b422643c78c47d6504dd718</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AltaVista-Strategic-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32888</link>
<guid>9d8709eb61c5b9a0a8f6afe1db57119e</guid>
<pubDate>Wed, 10 Jun 2026 22:54:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AltaVista-Strategic-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3861a64cc60e4852e29dd4d01e4c4c2e1c1dab1938a1466b0dd984b1bfd55550</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.altavistasp.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plaxen--Adler</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32887</link>
<guid>8d2cbe9d22a199026ddcbae5f0f67ef0</guid>
<pubDate>Wed, 10 Jun 2026 22:53:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Plaxen--Adler</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da0fc8652fd047c93e76265192bf2adb3bd8bc54485dd084c08eceb901b77e5a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.plaxenadler.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TagleRock-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32875</link>
<guid>17063277217449d39e2328a007ffb4fa</guid>
<pubDate>Wed, 10 Jun 2026 22:46:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TagleRock-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61f6224d3e95eb5a1c50951e76a09a3701e6c63dd6a512e905411e5b225fcb29</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32876</link>
<guid>71afb186ca8924414be94770dba45137</guid>
<pubDate>Wed, 10 Jun 2026 22:44:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Metro-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7ed4781281da7017f8c52f7adf179551f2f75db92c4118d38e99840130227996</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miller--Zois</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32885</link>
<guid>9ffe7d903de2691357188406c25cadf8</guid>
<pubDate>Wed, 10 Jun 2026 21:57:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Miller--Zois</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a09ad5f68e1079c559321d298c903ed0d48fef7efa213761302ca05fd6787957</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.millerandzois.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Efficient-Home</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32883</link>
<guid>d996e31032e7c288d7e20e7b82221c20</guid>
<pubDate>Wed, 10 Jun 2026 21:56:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Efficient-Home</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5499d55a63117cac0ed61d4e24e822c9118ff2d862e4c8f961e02cfc3665079</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.efficienthomellc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bekman-Marder-Hopper-Malarkey--Perlin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32882</link>
<guid>90918c5b8c17f80e32d5b155a7bf6197</guid>
<pubDate>Wed, 10 Jun 2026 21:55:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bekman-Marder-Hopper-Malarkey--Perlin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f9897dcaae46cb4258828e8bb6066e027a5698aa047dc653476100214384e22</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mdtrialfirm.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dulany-Leahy-Curtis--Brophy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32881</link>
<guid>326a8605975106f1672c912bd16b4e7b</guid>
<pubDate>Wed, 10 Jun 2026 21:54:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dulany-Leahy-Curtis--Brophy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca91eb66448a3ee3bf1ac5cdfd94af300f567a4d9b0e3cbc12f340ed61ef0239</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.dulany.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mundt-and-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32878</link>
<guid>891565c4dbecf15e2cd7f7f737931518</guid>
<pubDate>Wed, 10 Jun 2026 15:54:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Mundt-and-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82657ca5d367d345c9b23c4692bb3bf3eeedc7144818237d79718288ea65f10f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mundtinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rainbow-Distributors-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32877</link>
<guid>ee50567c32d7c2e693df4a6206c71b00</guid>
<pubDate>Wed, 10 Jun 2026 15:53:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Rainbow-Distributors-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>229740244e65d3f2f61dacc87efb3008c89cf9dcbfeec9aacf150549cf34a1e4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rainbowdistributorsusa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Port-Air-Express</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32867</link>
<guid>7f95080e8eda3a6ca81ca314500535f8</guid>
<pubDate>Wed, 10 Jun 2026 13:50:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Port-Air-Express</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ede3decdfaadffdd6af4357869bd7ed305c85a48f382b6d2025d29c20e652a03</i><br /><br />Threat actor <b>description</b>: <i>Port Air Express Inc. specializes in reliable logistics and transport solutions, negotiating co
mpetitive rates with airlines and shipping companies globally. Their services include domestic 
and international shipping, containerized shipping, breakbulk cargo handling, heavy lift operat
ions, and customs clearance.

We will upload 15gb of corporate data soon. Employee personal information (passports, DL scans,
SSN cards and more), financial information payment details, credit cards, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Midland-Theatre</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32864</link>
<guid>c2e4a009b0acaea484f4384134824c69</guid>
<pubDate>Wed, 10 Jun 2026 12:20:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Midland-Theatre</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74f680cd963be65ae61e4b024f628a7a068b9cbcb71e2d19a0e20d3305472b0a</i><br /><br />Threat actor <b>description</b>: <i>The Midland Theatre originally opened in December of 1928 in Newark, Ohio. The theatre draws te
ns of thousands of visitors each year to a wide array of programming from family-friendly event
s and holiday specials to top artists in every genre.

We will upload corporate data soon. Employee personal information (w-9 forms and other docs), f
inancials, credit cards, client, partners and guests information, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Associated-Investor-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32863</link>
<guid>18c578f830e2897ac30e2c72e6e122a1</guid>
<pubDate>Wed, 10 Jun 2026 11:50:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Associated-Investor-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4181918316b19e8f22d3a14fc6c11709b8fb3a01bae0f98459d14340f20517ef</i><br /><br />Threat actor <b>description</b>: <i>Associated Financial Consultants & Investor Services is an independent boutique firm dedicated 
to creating, growing, and protecting wealth since 1972. They offer a range of services includin
g wealth management, life planning, retirement planning, and insurance for families and individ
uals, as well as customized retirement and employee benefit plans for businesses.

We will upload 77gb of corporate data soon. Employee personal information (passports, DLs, SSNs
and so on), financials, confidential legal documents, client and partners information, NDAs, e
tc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Federal-Savings--Loan</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32860</link>
<guid>2e04188d8d66a5db2663dc798cbb64ff</guid>
<pubDate>Wed, 10 Jun 2026 11:45:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>First-Federal-Savings--Loan</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d04beb86d63de892cdf3825153f9054636f5d969371ed20ec312c80cfbc980b8</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Centra-Sota-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32862</link>
<guid>d1b611ebe627df0447e9f3fafc4f14cf</guid>
<pubDate>Wed, 10 Jun 2026 10:46:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Centra-Sota-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>260f711dded555332fb4274481c5654810c4267f6aa9ca9cf355cf68f429ce4a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bayou-Electrical-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32857</link>
<guid>85e9b5dce4f9484f6731b0d778f8cc2e</guid>
<pubDate>Wed, 10 Jun 2026 07:00:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Bayou-Electrical-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e50f6b4a7006981348622ac8bd0b197e46cba0f49a97925056cd48da400a2f1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>bayouelectrical.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Health-Fund</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32856</link>
<guid>f630930295f2102fb56edc9f88de45fb</guid>
<pubDate>Wed, 10 Jun 2026 07:00:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>National-Health-Fund</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ede5f9398cbf92bba6ea45b73cf62759f92e4e98df4ecedacc57f7bec04ea5e6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

The name "National Health Fund" is generic and used by multiple organizations across different countries. Without more specific context such as country of origin or additional identifiers, I cannot reliably attribute this name to a single, verifiable entity and provide accurate threat intelligence information.</i><br />Target victim <b>website</b>: <i>nhf.org.jm</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sayre-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32854</link>
<guid>0acecb86d3b3fab2fea045403bedfb1f</guid>
<pubDate>Wed, 10 Jun 2026 06:22:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Sayre-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8604e39315c20d6017e1644d138853613a664540fb7c9fc8214b5c51bab0d91e</i><br /><br />Threat actor <b>description</b>: <i>(Including clients, projects, emails and financial documents) Sayre Associates, Inc. is a civil engineering and land surveying firm based in Sioux Falls, South Dakota, established in 1969. The company offers a range of services including land development planning, parks and recreation facilities design, drainage and erosion control, and construction administration. They focus on delivering high-quality solutions through collaboration and innovation, serving clients in South Dakota, Iowa, and Minnesota. Their talented team of engineers and surveyors is dedicated to improving community efficiency and quality of life.</i><br />Target victim <b>website</b>: <i>sayreassociates.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cal-Fresh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32851</link>
<guid>5de7a22a52cdc12c0725ff2d2df5bf41</guid>
<pubDate>Tue, 09 Jun 2026 21:54:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Cal-Fresh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f46a8dc1a5144b9d548de14602611d1b81c1c6fb84a4bbaf158e2af2159f537</i><br /><br />Threat actor <b>description</b>: <i>The California Association of Food Banks (CAFB) is committed to ending hunger in California and aims to provide clear, up-to-date information about CalFresh for people who are interested in applying. Since 2003, CAFB has partnered with food banks and other community-based organizations throughout the state to educate consumers about CalFresh and provide application assistance.
</i><br />Target victim <b>website</b>: <i>calfresh.ca.gov</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mid-Cumberland-Human-Resource-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32850</link>
<guid>875dbe9e8d6e7a08b546eee88a3bddd3</guid>
<pubDate>Tue, 09 Jun 2026 20:53:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Mid-Cumberland-Human-Resource-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c520083a4a9bc4c250b0c487e51590d0a0d02d03231f849d6d51b167e55b8566</i><br /><br />Threat actor <b>description</b>: <i>MCHRA is a nonprofit promoting self-sufficiency via Meals-on-Wheels, public transit, in-home services, and community corrections. It serves adults needing care, transit users, and long-term care residents, emphasizing inclusivity and translation services.</i><br />Target victim <b>website</b>: <i>www.mchra.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Auburn-Electrical-Construction-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32843</link>
<guid>4860f5cbea5e5dbb3b1d6d94c2157df5</guid>
<pubDate>Tue, 09 Jun 2026 18:21:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>Auburn-Electrical-Construction-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ca5c99b5decda4910f97fdf448f52757f3184e04951a9921f376ed0065962ae</i><br /><br />Threat actor <b>description</b>: <i>Auburn Electrical Construction Company, Inc. is an innovative contracting firm that profitably provides electrical-related services to our customers. Our goal i... - </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>airespring.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32842</link>
<guid>398d0beebc2a1c91e7696c92ba188715</guid>
<pubDate>Tue, 09 Jun 2026 16:21:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>airespring.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3b7d17cbf259bb78ad004ac8712939b1222b9851cc37d613ca022b09d5003cc</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2001, AireSpring is a Managed Services Provider specializing in Unified Communications, Managed Network, and IT Services, serving thousands of businesses nationwide. AireSpring provides fully managed and connected end-to-end, next-generation solutions for multi-location enterprise custome…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/airespring-inc/5739766</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>columbiaorthogroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32823</link>
<guid>33410819536ec64f62d77277c4af5c66</guid>
<pubDate>Tue, 09 Jun 2026 14:50:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>columbiaorthogroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3fc8fdef36677110e4eee2ec2248f8c0a64f6c4679dce142273138fa8a7d4911</i><br /><br />Threat actor <b>description</b>: <i>Columbia Orthopaedic Group is a healthcare provider located in mid-Missouri that specializes in the...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spray-Equipment--Service-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32841</link>
<guid>62dee803f4071bd95a11e66e9b8324a7</guid>
<pubDate>Tue, 09 Jun 2026 14:50:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Spray-Equipment--Service-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31efbe30a3cb0d53498484cd92959461507cf7bb85ed61d6a0c1bb9525e84e70</i><br /><br />Threat actor <b>description</b>: <i>Spray Equipment & Service Center is a leading provider of consultation, turnkey industrial fini
shing equipment, and training services for coating applications. They cater to clients seeking 
efficient and high-performance coating solutions, enhancing product quality and streamlining pr
oduction processes.

We will upload 26gb of corporate data soon. Employee personal information (DLs, w-9 forms and s
o on), financials, contracts, projects info, drawings, partners information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>hollandbulbfarms.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32829</link>
<guid>a4bbee2cb160b062774d395dac7280a2</guid>
<pubDate>Tue, 09 Jun 2026 14:50:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>hollandbulbfarms.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2632220a8dd4e8e8bd0cbd55866833d2ce54b54b913dfcfd7c727553bb7279b</i><br /><br />Threat actor <b>description</b>: <i>Holland Bulb Farms is an online store specializing in bulbs, rhizomes, and seedlings
The downloaded...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>wessels.group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32834</link>
<guid>3d4375c2cc0fd3842600003f183bd34c</guid>
<pubDate>Tue, 09 Jun 2026 14:50:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>wessels.group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b90eba177217da2e8fd56c59d32aff1335995d392587482f43a6db49c89258f5</i><br /><br />Threat actor <b>description</b>: <i>Mission & Vision
The focus of Wessels Logistics is on 24-hour transport in the Benelux and Germany,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>sierravistahospital.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32835</link>
<guid>9f76ca9de39c2906f5e1e3f3ba38e255</guid>
<pubDate>Tue, 09 Jun 2026 14:50:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>sierravistahospital.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>404e50a79ae05b8e6855b00bd26d5a65091ee63ae65374d1a5fe2d5820585fdc</i><br /><br />Threat actor <b>description</b>: <i>Sierra Vista Hospital is a private behavioral health facility located in Sacramento, California, off...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rockaway-River-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32840</link>
<guid>e7d62ad090f4fdb69fe7f4f2277acc33</guid>
<pubDate>Tue, 09 Jun 2026 14:20:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rockaway-River-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b849d81dc5212ac97a9b03ab2f74b3c1bf40f565ea77ba60844c91f0e38cff3</i><br /><br />Threat actor <b>description</b>: <i>Rockaway River Country Club is a premier country club located in Denville, NJ, offering a range
of amenities including golf, dining, and facilities for racquets and aquatics. The club has a 
rich history of excellence, celebrating 100 years of service to its members.

We will upload 25gb of corporate data soon. Employee personal information (DLs and other docs, 
contracts with personal information), financials, contracts and agreements, projects info, draw
ings, clients and partners information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMPC-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32839</link>
<guid>86c1dedbd4a728cf270c4d7af3798b03</guid>
<pubDate>Tue, 09 Jun 2026 13:50:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>SMPC-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5fbc49af53f7da8867659a49b8735b3808467e53a7a4725ae047988126fb9af6</i><br /><br />Threat actor <b>description</b>: <i>SMPC Architects is an architecture firm based in Albuquerque, New Mexico, specializing in creat
ing innovative and sustainable spaces. The firm focuses on community-oriented projects and coll
aborates closely with clients to meet their needs.

We will upload 163gb of corporate data soon. Employee personal information (passports, DLs, SSN
cards and so on), financials, lots of contracts and confidential settlements, NDAs, clients an
d partners information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wiese-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32816</link>
<guid>6a27685d602a50fe587c4ab6cfb07d90</guid>
<pubDate>Mon, 08 Jun 2026 23:56:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Wiese-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8045c1e8a3cbeec270a1b4944a64c64d6df5d3da89d464814827fa98f62b69e</i><br /><br />Threat actor <b>description</b>: <i>Wiese Inc is a material handling machinery company. It offers forklifts, railcar movers, yard trucks, dock equipments, and other machinery. The company was established in 1944 and is based in St. Louis, Missouri.</i><br />Target victim <b>website</b>: <i>www.wieseusa.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roland-Machinery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32815</link>
<guid>44374c1f0ebad6dc48951e6c20c25806</guid>
<pubDate>Mon, 08 Jun 2026 22:57:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Roland-Machinery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>950c27693b3e53831dda4c9c65fe6ebf810b46b99b2487e52d01cfaabf6a0ce2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1958 and headquartered in Springfield, Illinois, Roland Machinery Co. provides wholesale distribution of construction equipment. The Company offers forestry, aggregate, and paving equipment, as well as rents construction, road maintenance, and crushing equipment.</i><br />Target victim <b>website</b>: <i>www.rolandmachinery.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>SatCom-CX</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32809</link>
<guid>fd86085221addaf63ba670a35e027acf</guid>
<pubDate>Mon, 08 Jun 2026 19:46:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SatCom-CX</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e172e02720051816381b32f2ae9749083b7e7d52f773ed8c5f96218ab2f59d31</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aegle-Aviation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32813</link>
<guid>efe2d4536fbb724f90ef5135b2899251</guid>
<pubDate>Mon, 08 Jun 2026 19:24:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Aegle-Aviation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60392970e7a4b388408d1ced922e3997d96754783ab1e00cfbca2c33f0617bd7</i><br /><br />Threat actor <b>description</b>: <i>Aegle Aviation was founded in 2019. The company specializes in aircraft asset management, trading of commercial aircraft and engines, as well as aftermarket parts distribution. Its core operations include aircraft disassembly, end-of-life component harvesting, and lease management for mid-life narrow-body and wide-body jets.</i><br />Target victim <b>website</b>: <i>www.aegleaviation.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shipping-Association-of-NY-and-NJ</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32807</link>
<guid>0cb5bbd38e65f8df5c422232fe758c5d</guid>
<pubDate>Mon, 08 Jun 2026 14:23:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shipping-Association-of-NY-and-NJ</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>773719e3174f58d7a93073a8fa58ff9862e66cb8f784c6634dfba02530c8cb68</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sanynj.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>GRIP-Outreach-For-Youth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32805</link>
<guid>9a7c22ed48340ab6cd2a273912d51767</guid>
<pubDate>Mon, 08 Jun 2026 13:00:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>GRIP-Outreach-For-Youth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80fedb8be234e5a82ef9d7dadf7036c6396b8cdbe0631f5ad47e7ff883706bdd</i><br /><br />Threat actor <b>description</b>: <i>- Financial & Accounting Records- Sensitive Employee- Youth Participant & Child Protection Records- Governance & Legal Documents</i><br />Target victim <b>website</b>: <i>www.gripyouth.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Unique-Litho-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32804</link>
<guid>17cec10e671b521138ee3d5b5e9e4514</guid>
<pubDate>Mon, 08 Jun 2026 12:59:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Unique-Litho-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28c15b743fab7f7bd62d3ed60c6ea7314c7ec094ce8e285ea874af41cc97e459</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>uniquelitho.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>IP-Rings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32800</link>
<guid>74a190a673b9880b825416fd36a44eb3</guid>
<pubDate>Mon, 08 Jun 2026 09:58:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>IP-Rings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1a2aee3fc7eeea2a072159a218be1754013b50d39f111bb2b33d8ce5c0f84d2</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/ip-rings-ltd/62719470 IP Rings Ltd is an India-based automotive component manufacturer and a member of the Amalgamations Group, founded in 1991. The company specializes in producing piston rings, high-precision forgings, and crank pins using advanced orbital cold forming technology. It is a publicly traded corporation with over 500 employees, serving global clients with cutting-edge surface treatments and high-quality parts</i><br />Target victim <b>website</b>: <i>iprings.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Central-Arkansas-Pediatrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32799</link>
<guid>37d7465c1cf6b226541c17d5b92034c1</guid>
<pubDate>Mon, 08 Jun 2026 09:58:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Central-Arkansas-Pediatrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b76b72c7c0bc0ed34788a1e03dc955092bf7c60910aebe4cae8eff892eb6a71</i><br /><br />Threat actor <b>description</b>: <i>***.edan.io zoominfo.com/c/central-arkansas-pediatrics/1340337263 Central Arkansas Pediatrics is a specialized healthcare provider based in Conway, Arkansas, dedicated to pediatric special needs care. The clinic offers comprehensive services, including developmental preschool programs and therapy support for children across the state. Their digital presence is hosted on edan.io, a streamlined platform used by medical practices to provide accessible online resources for patients</i><br />Target victim <b>website</b>: <i>central-pediatrics.edan.io</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trigon-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32793</link>
<guid>5fc624523b2074a3440e9312f271d68c</guid>
<pubDate>Mon, 08 Jun 2026 09:57:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Trigon-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>508ff77d93ac32219b7ecbe6d88ed4a8974f0615995a5bc7e8858a8cbf830720</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/trigon-america/560898982 Trigon America is a premier contract manufacturer based in Aurora, Illinois, specializing in precision-machined complex components and assemblies. Founded in 2000, the company serves the highly regulated Medical Device and Aerospace industries, holding both ISO 13485 and AS9100 certifications. With decades of expertise, they focus on delivering world-class manufacturing solutions for intricate instrumentation and critical medical equipment</i><br />Target victim <b>website</b>: <i>trigonamerica.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Clinic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32791</link>
<guid>d65598b7a583ff113467d5b6f693a031</guid>
<pubDate>Mon, 08 Jun 2026 09:57:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>The-Clinic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1cc0140f01fc8a6ad435d36dda5e601d6fede849b49cb3287c8e63f23bd6ade</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/the-clinic/537916104 The Clinic: Family and Sports Chiropractic is a specialized healthcare facility located in West Fargo, North Dakota, dedicated to providing patient-focused chiropractic care</i><br />Target victim <b>website</b>: <i>wfsportscare.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Distribution</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32790</link>
<guid>a286be2b8cb6de66943d8025b3fa7e33</guid>
<pubDate>Mon, 08 Jun 2026 09:57:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Integrated-Distribution</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f364abb388a4deb3c7b40dfde7ab85384a5723efe0f6a971f184be95cbf8f85</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/integrated-distribution-inc/348479499 ntegrated Distribution Inc. is a prominent industrial distributor based in Comstock Park, Michigan, serving local manufacturers since 1998. The company specializes in fast-response sourcing, technical support, and the supply of critical components such as bearings, belts, motors, and power transmission parts. With a strong focus on minimizing equipment downtime, IDI provides tailored industrial solutions for diverse sectors, including automotive, food processing, and packaging</i><br />Target victim <b>website</b>: <i>int-dist.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Danzo-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32787</link>
<guid>314f19f082e69886c20e31c70fe6dceb</guid>
<pubDate>Mon, 08 Jun 2026 09:56:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Danzo-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1de7d5a336a14188074237a2b1939b2b17b3b6c383a09d44a980a601d1adc81</i><br /><br />Threat actor <b>description</b>: <i>***.com zoominfo.com/c/danzo-group-inc/437505508 Danzo Group is a premier commercial and residential contracting company based in the Los Angeles area, specializing in custom cabinetry and high-end woodworking solutions. Founded in 2005 and operating from a 7,000-square-foot facility in Pomona, California, the company delivers bespoke millwork, custom furniture, and interior storage systems. With a strong focus on fine craftsmanship, they serve diverse clients by providing comprehensive general contracting and tailored design services</i><br />Target victim <b>website</b>: <i>danzogroup.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pearson-Ford</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32781</link>
<guid>3bc8f7011e08bfe6830c967b497bdf6d</guid>
<pubDate>Sat, 06 Jun 2026 13:23:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Pearson-Ford</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1621a43a0df6dd1289554f4ec58fcb8beb0cb0dbe4d1b7090bf5d330c126a93f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.pearsonford.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>kelmreuter.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32780</link>
<guid>131654a371fe35dc9ca1f15c72f13e0e</guid>
<pubDate>Sat, 06 Jun 2026 12:22:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>kelmreuter.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6de8ba9408af3c6dab7e69f1a595e548a294a3b6a49719d758cfc1229e0a638b</i><br /><br />Threat actor <b>description</b>: <i>www.personadental.com  Persona Dental offers personalized dental care for families in Sartell, MN, focusing on both general and specialized services such as cosmetic dentistry, dental implants, and solutions for snoring and sleep apnea. The clinic prides itself on creating a comfortable environment and empowering patients to make informed decisions about their dental health. With a friendly and experienced team, they provide comprehensive care under one roof, ensuring convenience for their clients. Persona Dental is dedicated to building confidence and achieving the best smiles for their patients</i><br />Target victim <b>website</b>: <i>kelmreuter.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jeffrey-Burr</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32776</link>
<guid>87ec54ef27e93908a8397eb3a6bbb45b</guid>
<pubDate>Fri, 05 Jun 2026 22:20:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Jeffrey-Burr</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52674e64dbc8f706feef8e5194198f2ca3747343e7bf5e8660a07aa352591ab9</i><br /><br />Threat actor <b>description</b>: <i>[www.jeffreyburr.com]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>obrieneng.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32772</link>
<guid>7d8bfb447a72415af33c7817b3c7e9dc</guid>
<pubDate>Fri, 05 Jun 2026 20:23:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>obrieneng.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b022441cf5d5213f1462d0c892f95839fd87cbfb2aa571405c63931e853f393</i><br /><br />Threat actor <b>description</b>: <i>contract nda confidential   gov\dot\military\va\sam.gov other</i><br />Target victim <b>website</b>: <i>obrieneng.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Demand.ioNEW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32771</link>
<guid>c2d2db7da651df36ea69da7bee48304b</guid>
<pubDate>Fri, 05 Jun 2026 19:21:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Demand.ioNEW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0af30daf3d862bee001cf9eecd9f2b7413b837a7a6413a1e4f151c1e52022a2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>Demand.ioNEW</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>TCCI-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32764</link>
<guid>bfd6afd4eceeb6586229fc477d77ab09</guid>
<pubDate>Fri, 05 Jun 2026 15:45:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TCCI-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ebbbe9089f97f2026467f9643b1599286a43b9b67a023dfc16d3b9e07abdf56</i><br /><br />Threat actor <b>description</b>: <i>T/CCI is a world leader in compressor technology including reciprocating, swash plate, wobble plate, variable compressor and air brake compressor designs. We are an Original Equipment Manufacturer for trucking, off-highway, agriculture/construction, specialty vehicle and transport refrigeration markets.We will upload 35gb of corporate data soon. Employee personal docs (passports, DLs, SSNs, payment details, credit cards and so on), contracts and agreements, client and partners information,NDAs, financials, lots of confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kennon-Worldwide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32768</link>
<guid>f43764367fa4b73ba947fae71b0223a4</guid>
<pubDate>Fri, 05 Jun 2026 14:20:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kennon-Worldwide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>395e846c49bc2ccfd42175ee59e133a0f767f33d587d10130f6c13f3f6add164</i><br /><br />Threat actor <b>description</b>: <i>Kennon Worldwide offers a wide range of telecommunications services including PRI, VoIP, and in
tegrated services, representing over 40 service providers to ensure the best pricing and soluti
ons for clients.

We will upload 30gb of corporate data soon. Contracts, client information, NDAs, and other inte
rnal files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oaks-Park</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32767</link>
<guid>7cf91b300ff3ecef82c59dd47b89253a</guid>
<pubDate>Fri, 05 Jun 2026 14:20:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Oaks-Park</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3edec1a992075ce0f9f677fefcdee69bf58f50e56d6a77c01c0f7dcfdfed17a2</i><br /><br />Threat actor <b>description</b>: <i>Oaks Amusement Park, located in Portland, Oregon, has been a family-friendly entertainment dest
ination since 1905, offering a variety of attractions including rides, a roller rink, and a min
i golf course.

We will upload 10gb of corporate data soon. Employee information, credit cards, payment details
, lots of contracts and agreements, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pro-MEC-Engineering-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32760</link>
<guid>abfd09c1c6bea74a2f45e5ebe7f5c92f</guid>
<pubDate>Fri, 05 Jun 2026 13:48:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pro-MEC-Engineering-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1de7655b9897586347f08fc83ad1c68acc536c63a347708ad6c8075415854800</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jays-Catering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32761</link>
<guid>4531d349d3269ac4f3e1d34864ba4bd6</guid>
<pubDate>Fri, 05 Jun 2026 13:48:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jays-Catering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1825e9344e6f2a26ded29ef062cf9158040bea1fb587d93350cb42b733d84264</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Krum-Public-Library</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32765</link>
<guid>62e125fde0037ef78106973d7d91c94e</guid>
<pubDate>Fri, 05 Jun 2026 13:24:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Krum-Public-Library</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7bb65ae4c8b6a2215d42b97a63bc0133cb88904ee92b7a31f6c76e1c3cdaba95</i><br /><br />Threat actor <b>description</b>: <i>- Financial Documents- HR Data- Supervisor's Information</i><br />Target victim <b>website</b>: <i>www.krumlibrary.org</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Central-Florida-Cosmetic--Family-Dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32763</link>
<guid>2f67c31ef2232270b2cbcc57d98b23e2</guid>
<pubDate>Fri, 05 Jun 2026 12:24:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Central-Florida-Cosmetic--Family-Dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19f17281bfbcc5ec58e20a654e93ccb0347a4d3ffe53da9eabcee9cf4527e0f9</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.kissimmeesmile.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Auto-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32756</link>
<guid>bebd2716e83d7472b111e5fef377b46e</guid>
<pubDate>Fri, 05 Jun 2026 11:46:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>United-Auto-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60d19050115074993235fdb87906aa43b80d6db4fff7aa7f5623574134bddabd</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swim-Mor-Pools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32758</link>
<guid>5df3a42ebea611e314771d5e1bafca74</guid>
<pubDate>Fri, 05 Jun 2026 10:53:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Swim-Mor-Pools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76c2f5aad6cd092eb1bba026f7b78f8ecb6275e4e1d0616606d2c8a64e8c1788</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.swimmor.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Urschel-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32751</link>
<guid>0200a91354cdcc7e7f803af641b0a56c</guid>
<pubDate>Thu, 04 Jun 2026 21:57:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Urschel-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa546087023e7f44ad137cfbf2f4fba260fab7a7d829f269eefe09b1350e18e3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.urschel.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dallis-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32750</link>
<guid>223b8a4bd884f01d8f1f94a8b0b1f97b</guid>
<pubDate>Thu, 04 Jun 2026 21:57:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Dallis-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>925d3c001a3a1cfe66c551fe44a4054f410178341bd126fe3129df82be5b2780</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dallislawfirm.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Chapel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32749</link>
<guid>80ebbb3510090df5521e42994353a471</guid>
<pubDate>Thu, 04 Jun 2026 21:56:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Chapel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1335ff6a2fe9f3d84a1892a87912d84c6cdbb9f49e4fb933563b2376500ad079</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.thechapel.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Corley-MFG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32748</link>
<guid>72abaa8894cb6f7d827ac8e157b722f0</guid>
<pubDate>Thu, 04 Jun 2026 21:56:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Corley-MFG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3ee08dd19a17e156e0510d3c600ea185cf94bf9dfe2b08ff96acf32e5bccc21</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.corleymfg.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Ohio-Regional-Multiple-Listing-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32742</link>
<guid>093311adaeb0998a580ee5222ca63f28</guid>
<pubDate>Thu, 04 Jun 2026 15:51:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northern-Ohio-Regional-Multiple-Listing-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7af4b78cfef0a55c1205c827ee3d9ac6a4f0219d73513585d77676b43e1b8269</i><br /><br />Threat actor <b>description</b>: <i>MLS Now operates on advanced technology to provide members with timely, accurate, and meaningful data and services. The company offers hands-on education, extensive online documentation, anda robust support help desk staffed by local professionals.We will upload corporate data soon. Board members information, contracts, NDAs, detailed financials, confidential files, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Standard-Parts-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32744</link>
<guid>6174526bec27e6cf9343ff9b2585e67c</guid>
<pubDate>Thu, 04 Jun 2026 13:50:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>National-Standard-Parts-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f539639aaa1f14393eff02bf40bbd8ed90a625b77f2b8fff8a2e65a3b86b8456</i><br /><br />Threat actor <b>description</b>: <i>NSPA is an American manufacturer specializing in heat shrink terminals and connectors, as well 
as heat shrink tubing and installation tools. Their product offerings cater to industries requi
ring reliable sealed electrical systems.

We will upload 53gb of corporate data soon. Employee personal docs (passports, DLs, SSNs and ot
her information), contracts and agreements, a bit of client and partners information, lots of N
DAs, detailed financials, confidential files, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anandji-Haridas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32740</link>
<guid>4db9c75f6a31c73414ad84fdd101b5d7</guid>
<pubDate>Thu, 04 Jun 2026 09:10:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Anandji-Haridas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27455c27f58ea426a678535fad7807212e5287a6fc622105efa829a4339d5694</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.com/c/anandji-haridas--co-ltd/354316069 Anandji Haridas & Co. (AHCPL) is a pioneering Indian manufacturer with over seven decades of expertise in cold forming, tool design, and advanced sheet metal ***.As a fully certified OEM supplier, they specialize in producing high-precision, cost-effective critical automotive components and spun pulleys through integrated in-house ***.With a steadfast commitment to world-class quality, AHCPL remains a trusted partner for innovative and reliable sheet metal forming solutions</i><br />Target victim <b>website</b>: <i>ahcpl.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harrell-Martin-Peace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32735</link>
<guid>0e7adb08b43a589df528d2bdd69b6b03</guid>
<pubDate>Thu, 04 Jun 2026 09:09:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Harrell-Martin-Peace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e143192f59aa9af207525f25c200ade19c22b8a83f813d81ccc2d846c8096f8f</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.com/c/harrell-martin--peace-pa/347464411 Established in 1995, Harrell, Martin & Peace, P.A. is a highly regarded full-service law firm based in Chapin, South Carolina, celebrated for its community-focused approach and deep client relationships. The firm delivers comprehensive legal expertise across diverse practice areas, including real estate, corporate law, estate planning, and family law. Backed by a dedicated team of experienced attorneys, they are committed to providing personalized, strategic, and exceptional legal representation to both individuals and businesses</i><br />Target victim <b>website</b>: <i>harrellmartinpeace.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Soniva-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32731</link>
<guid>175e9308ea835facdc5c74c75acc450f</guid>
<pubDate>Thu, 04 Jun 2026 09:09:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Soniva-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>056b1702a86ca5c858ec4ea1779bd3fcfca608f903281c6f4cc9a3f0c2a8afa8</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.co/soniva-dental-care-profile_b73bd863c7ef0f15 Soniva Dental is a premier Texas-based dental clinic recognized for setting a benchmark in excellence and comprehensive oral healthcare. With over 15 years of trusted experience, the practice integrates 13 branches of dentistry under one roof, supported by state-of-the-art equipment and a world-class CAD-CAM dental laboratory. From routine check-ups to advanced dental implants, their dedicated team is committed to delivering high-quality, patient-focused care that creates healthier, beautiful smiles</i><br />Target victim <b>website</b>: <i>sonivadental.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Suburban-Water</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32730</link>
<guid>87a6f9a7b759a6d0282612c014a33b0c</guid>
<pubDate>Thu, 04 Jun 2026 09:09:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Suburban-Water</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d48c4fee2fad063c687401e18e85862d6a9492375d1de37359904ce717611778</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.com/c/suburban-water-inc/350908787 Suburban Water, Inc. is a dedicated public water utility based in Basehor, Kansas, committed to delivering safe and reliable drinking water to local residential and commercial communities. Operating as a vital part of the regional infrastructure, the company prioritizes strict water quality standards, sustainable resource management, and exceptional customer service. Through continuous system maintenance and proactive operations, they ensure the long-term health, safety, and well-being of the neighborhoods they proudly serve</i><br />Target victim <b>website</b>: <i>suburbanwaterinc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Downriver-Medical-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32729</link>
<guid>41de90c717ed710bbfc3e3a37b5f430a</guid>
<pubDate>Thu, 04 Jun 2026 09:09:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Downriver-Medical-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c407e3dd97393a64c2570e3f8cff148fb33a08f7a3e99d8ebab0b5a05df68df2</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.com/c/downriver-medical-associates/357511215 
Downriver Medical Associates is a full-service medical office and urgent care center located in Wyandotte, Michigan. Specializing in internal medicine and family practice, they provide comprehensive primary care for patients of all ages. The clinic focuses on holistic healthcare, emphasizing wellness, disease prevention, and improving the overall quality of life for the local community</i><br />Target victim <b>website</b>: <i>downrivermedicalassociates.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edgewood-Surgical-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32723</link>
<guid>fcaae931422688b8a0134e51a7a2fb12</guid>
<pubDate>Thu, 04 Jun 2026 09:09:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Edgewood-Surgical-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe8f559aca99ae5971b3eda10d4c6db0c505209237c3b08f06448a17504b37c5</i><br /><br />Threat actor <b>description</b>: <i>***.com ***.com/c/edgewood-surgical-hospital/52612741 Edgewood Surgical Hospital is a state-of-the-art specialty medical facility located in Transfer, Pennsylvania USA.

We have your data filles ~500gb

SURGICAL CASE REVIEWS 2025-2026
2026 January SURGICAL CASE REVIEW
2026 March Surgical Case ***.docx
2025 JANUARY PEER SURGICAL CASE REVIEW
2025 MARCH SURGICAL CASE REVIEW
2025 MAY SURGICAL CASE REVIEW
2025 JULY SURGICAL CASE REVIEW
2025 SEPTEMBER SURGICAL CASE REVIEW
2025 NOVEMBER SURGICAL CASE REVIEW

GOODMAN HP STI pdf Name + sexually transmitted infection

(~300+ Anesthesia Records Anesthesia Records) Massive PHI leak — names + medical data of hundreds of patients

MRI SCANS / EMPLOYEE HEALTH

HISTORY & PHYSICAL (HP)

Narcotic outdates + INPATIENT NARCOTIC INVENTORY</i><br />Target victim <b>website</b>: <i>edgewoodsurgical.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Michigan-Surgical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32721</link>
<guid>53e05338ce6abee9ef68c74d76a50ec4</guid>
<pubDate>Thu, 04 Jun 2026 09:09:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Michigan-Surgical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c05c5e3dfac255a4c47f532e35b83364110b2104972484061ed2b8df4fd6ce2e</i><br /><br />Threat actor <b>description</b>: <i>www.***.com https://www.***.com/c/michigan-surgical-center-llc/90769926 Michigan Surgical Center is an outpatient surgical facility specializing in ophthalmic and plastic surgeries, with over 25 years of experience. The center is physician-owned and has received multiple awards for quality care, including recognition as one of America's Best Ambulatory Surgical Centers by Newsweek. Their mission focuses on providing high-quality, patient-centered care with an emphasis on value-based services. They aim to lead in outpatient surgical care through innovative methodologies and a commitment to integrity and respect. 2075 Coolidge Rd, East Lansing, Michigan</i><br />Target victim <b>website</b>: <i>www.michigansurgicalcenter.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CUSTOMSIGN</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32718</link>
<guid>2a39b5110caf02b3ca7e545d509be7e6</guid>
<pubDate>Thu, 04 Jun 2026 00:56:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>CUSTOMSIGN</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1389feb39f0810616c1914448f2b5a60d27fb9e78a1fcb89a278ef376f8690f0</i><br /><br />Threat actor <b>description</b>: <i>About Custom Sign & Engineering Custom Sign & Engineering, Inc. specializes in creating high-quality, custom commercial digital signs and billboards in Evansville, Indiana. The company offers a wide range of products, including LED dimensional letters, monumental signs, and information displays, all designed to meet the specific needs of businesses. The company is committed to providing customer-focused services at competitive prices and with free estimates. It serves clients in three states—Illinois, Indiana, and Kentucky—helping businesses enhance their visibility and brand image through eye-catching signage.  Translated with ***.com (free version)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>SeeWriteHear</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32717</link>
<guid>7b5ad0c52e58076e34f393efe9019ed2</guid>
<pubDate>Wed, 03 Jun 2026 20:50:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>SeeWriteHear</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a87904d46bfb31235481bdffb0f87791a8cbdcee6665be186ab3c149a409989</i><br /><br />Threat actor <b>description</b>: <i>SeeWriteHear specializes in providing print and digital accessibility solutions, including Braille, large print, and web accessibility services. Their offerings cater to various industries such as education, government, and publishing, ensuring compliance with usability standards. The company focuses on innovative technology to enhance accessibility for individuals with disabilities. With a commitment to information equality, SeeWriteHear serves clients by creating accessible content and providing consulting and training services.</i><br />Target victim <b>website</b>: <i>www.seewritehear.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>PB-White--Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32716</link>
<guid>3e80fb1c17b97791d5bcdd3e91c617a7</guid>
<pubDate>Wed, 03 Jun 2026 20:27:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>PB-White--Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27b57b11483fc7a7f1b1ccac3ecc8f800bcd238bd203f741f81a67006dbddb47</i><br /><br />Threat actor <b>description</b>: <i>A provider of financial services</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Family-Medical-Associates-of-Raleigh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32715</link>
<guid>735701335a53e5b70d7465c28eed4088</guid>
<pubDate>Wed, 03 Jun 2026 20:25:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Family-Medical-Associates-of-Raleigh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22159763fd9fe0f05b3ab100af824789863e1f29cf0b702ea68828c266ada87d</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Singing-River-Health-System</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32714</link>
<guid>663cbae89ccfbb0ab05119a672fb1b9e</guid>
<pubDate>Wed, 03 Jun 2026 20:20:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Singing-River-Health-System</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>617ba0e3be4cf3ac7390502b949fdbf8756e955e271c914210576c182d289999</i><br /><br />Threat actor <b>description</b>: <i>New data breach at a large health system provider.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pyramid</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32712</link>
<guid>ee30a32aa22e90e9af21101206b54248</guid>
<pubDate>Wed, 03 Jun 2026 18:49:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Pyramid</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa6880d2b822bf378a1dec817a53f5d2359637055abe795df0a1c83ea10ebdef</i><br /><br />Threat actor <b>description</b>: <i>Ownership and management of shopping center. Development and redevelopment of real estate properties.  Leasing of space to retail chains, restaurants, and entertainment venues</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cherokee-Distributing-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32706</link>
<guid>8d3d7e8ca2dc7c98b0effe01f0b1fccb</guid>
<pubDate>Wed, 03 Jun 2026 15:50:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cherokee-Distributing-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>803fb1e7875a754f6dbd0954dbd43649f2ed092416681ae0dad3e13165505959</i><br /><br />Threat actor <b>description</b>: <i>Cherokee Distributing Company offers the leading brands of beer and other nonalcoholic beverages. In addition to their headquarters in Knoxville, they manage distribution centers in Chattanooga, Cookeville, Kingsport, Pulaski and Tullahoma.We will upload 40gb of corporate data soon. Employee personal docs (passports, DLs, SSNs), contracts and agreements, partner and client files, detailed financials, projects, NDAs, confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colina-Financial-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32707</link>
<guid>b33e197c4fdad374692ca3d65509d771</guid>
<pubDate>Wed, 03 Jun 2026 13:28:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Colina-Financial-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec4a69a2f68014465eb4290b260ff7882e7045a05407b7f98bcc11b1323a659d</i><br /><br />Threat actor <b>description</b>: <i>Colina Financial Advisors Limited (CFAL) is a prominent, independent wealth management and investment advisory firm based in Nassau, The Bahamas. Established in 1997, it serves as the investment arm of Colina Holdings Ltd.. The firm provides diverse financial services to both individual and institutional clients.  While customers continue to entrust the company with their money, senior executives are actively working to cover up a major data breach involving approximately 500 GB of highly confidential data. The leak includes, but is not limited to: 1. Client Personally Identifiable Information (PII) 2. Client Financial Profiles & Asset Data 3. Proprietary Business Intel & System Data 4. Holistic Estate & Legal Planning 5. Regulatory & Compliance Records Stay tuned for further updates.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hal-Otey-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32704</link>
<guid>29ccd48e559a99dc8054041bc90be347</guid>
<pubDate>Wed, 03 Jun 2026 12:50:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hal-Otey-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02ad540e5ad29e66545094d079c396a1ae2d725efc243761535f2b30c267b212</i><br /><br />Threat actor <b>description</b>: <i>Hal Otey Financial offers a range of financial services including wealth management, financial 
planning, retirement planning, investment management, estate planning, and tax planning.

We will upload corporate data soon. Lots client data (passports, DLs, social security numbers, 
health and insurance files and so on), contracts and agreements, detailed financials, projects,
etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MarketJoy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32700</link>
<guid>e1ea274b18a0e5bde67da64ea2010562</guid>
<pubDate>Wed, 03 Jun 2026 10:47:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>MarketJoy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b4335ded4bd511d06d66c5b308625b0010f5f36ce092f63a8c411994efb6e78</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>trrac.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32693</link>
<guid>55b631a083678b1748313493a183a42b</guid>
<pubDate>Tue, 02 Jun 2026 19:37:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>trrac.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3892d142fccb643f024e03ed8e260d0901a7fd407e05d8e02c1b40ff7e664e6</i><br /><br />Threat actor <b>description</b>: <i>150gb</i><br />Target victim <b>website</b>: <i>trrac.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nova-Medical-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32691</link>
<guid>bbd5901c24b54f8de73557dc4c264c53</guid>
<pubDate>Tue, 02 Jun 2026 16:53:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Nova-Medical-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37a8b769fcc2c893b68b2479636821bab8d4c48e188977c9b9be0b1640930882</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cold-Front-Distribution</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32688</link>
<guid>110e71dd8e23f87f715956349fdd0fd7</guid>
<pubDate>Tue, 02 Jun 2026 13:53:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Cold-Front-Distribution</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca0fc182be3913f4e6599ecdc030255236766f08565172baa9a4da9cd5d8585a</i><br /><br />Threat actor <b>description</b>: <i>Cold Front Distribution is a leading DSD supplier specializing in grocery and foodservice supply chain solutions across a fifteen-state region. Due to their negligence in the area of security, we are providing you with a complete set of confidential documents, specifically the pricing grids of major partners sold through the Cold Front system, discount agreements, information on new product launches, and other confidential partner documents, as well as personal information about employees and the companys financial status...</i><br />Target victim <b>website</b>: <i>https:coldfrontdist.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cambridge-Mobile-TelematicsNEW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32685</link>
<guid>d5a1930d166cd2bc2ca54b3405e641d0</guid>
<pubDate>Tue, 02 Jun 2026 12:21:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Cambridge-Mobile-TelematicsNEW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3aa98e9adc6ebaa9d2d3e8887a8f6c87f3b39677d69a9c8790bc99f3ce9bf458</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Cambridge Mobile Telematics (CMT) is a US-based technology company headquartered in Cambridge, Massachusetts. It operates in the telematics and insurtech industry, providing mobile sensing and data analytics solutions. CMT specializes in measuring driving behavior using smartphone sensors and AI to help insurers, fleets, and enterprises improve road safety and reduce risk through usage-based insurance and driver safety programs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>case.law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32680</link>
<guid>b8f5a378adbebec3b6fb49840d4adb21</guid>
<pubDate>Tue, 02 Jun 2026 09:31:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>Black X</b> claims attack for <b>case.law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4812ab4d923407db87fab504bf5cb23fbd106e66a1329590f260dbd2684aa315</i><br /><br />Threat actor <b>description</b>: <i>Since incorporation in 1972, CRS has delivered services to a diverse group of clients, primarily in the corrections and detention fields, at the local, regional, state, and national levels.  &nbsp;   We stole passport data from over 300 customers at CRS.</i><br />Target victim <b>website</b>: <i>correction.org</i>]]></description>
<category>Black X</category>
</item>
<item xmlns:dc='ns:1'>
<title>Power--Tel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32675</link>
<guid>fd77f82bcd91a751a0d0c8941f0b2ab1</guid>
<pubDate>Mon, 01 Jun 2026 23:20:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Power--Tel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>841ca9b806a3c023daceca99d09d68379a5d9fe239282467563722782298734c</i><br /><br />Threat actor <b>description</b>: <i>Data breach  exposes ecommerce platforms’ dirty laundry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mortensenlawoffices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32668</link>
<guid>e25e74105b0ea8f9e8403033b7444f34</guid>
<pubDate>Mon, 01 Jun 2026 15:53:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Mortensenlawoffices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d38e55427c2e8d9f6d695065d499d4c6fe4e36d5b18234857a9f16343bb0d10</i><br /><br />Threat actor <b>description</b>: <i>Mortensen Law Offices, PLLC
offers legal services, particularly bankruptcy, and provides consultations via Zoom, phone, or in-office for clients in the Phoenix/Mesa and Tucson areas, focusing on clear, empathetic guidance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Synex-International-Pvt-Ltd</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32666</link>
<guid>7e90c4b14a5e2e62f0323f94b6db015e</guid>
<pubDate>Mon, 01 Jun 2026 14:51:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Synex-International-Pvt-Ltd</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdfc8c31c6b23b897085734cc870987d3196adae9b904dafad96e1d8a3497e76</i><br /><br />Threat actor <b>description</b>: <i>Mechanical, Electrical, and Plumbing (MEP) systems, Extra Low Voltage (ELV) solutions, and Solar energy.</i><br />Target victim <b>website</b>: <i>www.synexint.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>School-Facility-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32665</link>
<guid>4aa8dd9a08fdc32d53eac21cf46e79c0</guid>
<pubDate>Mon, 01 Jun 2026 14:50:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>School-Facility-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e91922c5ca4a80d57c30bf888972a9c189d6cb64665efb7511557097bb47bc8</i><br /><br />Threat actor <b>description</b>: <i>School Facility Consultants (SFC) is a full-service company that provides expert guidance in school facility planning and funding for School Districts, County Offices of Education, and Charter Schools across California.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>Taos-Mountain-Casino</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32664</link>
<guid>4e688af00e7dcc3aa74cf59301228626</guid>
<pubDate>Mon, 01 Jun 2026 14:23:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Taos-Mountain-Casino</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11f0540f357dd689bcfe7b2118559d2c701e072e02feb51920b874e2059ceab0</i><br /><br />Threat actor <b>description</b>: <i>Taos Mountain Casino is a Native American gaming casino located in Taos, New Mexico. It is owned and operated by the Taos Pueblo, a federally recognized tribe known for its ancient, historic adobe pueblo.</i><br />Target victim <b>website</b>: <i>taosmountaincasino.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Panorama-BPO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32663</link>
<guid>3c0efc7a60a85e233fb20c2e475c7970</guid>
<pubDate>Mon, 01 Jun 2026 14:22:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Panorama-BPO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20df8e1bad2badc32cf439d6179111252f6f9f85b93b0badd58959497069ea8d</i><br /><br />Threat actor <b>description</b>: <i>Panorama BPO is a large international company specializing in business process outsourcing (BPO) and providing comprehensive operational services for businesses.</i><br />Target victim <b>website</b>: <i>www.panoramabpo.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bradley-law-firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32662</link>
<guid>a451ee22deede109dbb5b96fd7aae4e8</guid>
<pubDate>Mon, 01 Jun 2026 12:23:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Bradley-law-firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad00c50b02a2e8031fdae0c8f0918890d62eecfbdb177ef04e1c9bed10c75f83</i><br /><br />Threat actor <b>description</b>: <i>Bradley Law Personal Injury Lawyers is a law firm dedicated to representing clients who have suffered injuries due to accidents, medical malpractice, and other forms of negligence. With over 30 years of experience, they have successfully recovered more than $100 million in settlements and verdicts for their clients across Missouri and Illinois. Their services include free case consultations and a commitment to fight for maximum compensation on behalf of accident victims. The firm is known for its expertise in personal injury law, including vehicle accidents, workplace injuries, and wrongful death cases.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Champaign-Urbana-Public-Health-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32661</link>
<guid>ebd9eb6819ab10ef417c8e52fe96cc94</guid>
<pubDate>Mon, 01 Jun 2026 11:54:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Champaign-Urbana-Public-Health-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2392dd5903b73dfa3b5b8fc961de06bd11258a6242e3bd25e1f6cbb2281119e</i><br /><br />Threat actor <b>description</b>: <i>Champaign Urbana Public Health District provides a wide range of health services including dental care, nutrition assistance, mental health support, and food safety inspections. Their programs cater to various demographics, including adolescents, women, infants, and families, focusing on preventive health and education. The district also offers resources for substance abuse treatment, sexual health, and community food initiatives. Their intended clients include residents of Champaign County seeking health services, food assistance, and educational resources.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hightower-Communications</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32659</link>
<guid>7acf9a6623c2769fa83a79e5340ab394</guid>
<pubDate>Mon, 01 Jun 2026 09:22:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Hightower-Communications</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3af82c2ae4459001af4f762f5b4c482eabb6eccb09eae6addbe0594639b3f57a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hightowernc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>MERCOR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32654</link>
<guid>13d29e6e8cf1bcf427da3e7bd696a73f</guid>
<pubDate>Sun, 31 May 2026 20:24:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lapsus$</b> claims attack for <b>MERCOR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a83034503bc8e20291676d05afa7e1327acb933be5acb1f0f14c66a80d931a25</i><br /><br />Threat actor <b>description</b>: <i>This data has been acquired by a private party. No public leak will occur.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lapsus$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lake-Washington-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32652</link>
<guid>1ef3fd934ccdc49332e769d5fe78898c</guid>
<pubDate>Sun, 31 May 2026 10:50:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Lake-Washington-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff0897707b404b4d3f5439027efb91983c9ca213f7f45e28674212bb0d1a93e2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1914, Lake Washington School District is the administrative body responsible for planning and managing public education for 33 elementary, 14 middle, and 9 high schools. It serves communities of Kirkland, Redmond and about half of Sammamish. The company is headquartered in Redmond, Washington.</i><br />Target victim <b>website</b>: <i>lwsd.wednet.edu</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cavalier-Flooring-Systems-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32650</link>
<guid>8cf639fc4bb4f35a2bb4105e85ff9957</guid>
<pubDate>Sat, 30 May 2026 18:54:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Cavalier-Flooring-Systems-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>115fe5b5c07877cd8b6f4000ef5c7f18af5f2f9336308632f54676a698b9ef63</i><br /><br />Threat actor <b>description</b>: <i>A flooring and tile contractor</i><br />Target victim <b>website</b>: <i>cavalierflooring.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wentworth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32649</link>
<guid>19db090dc300e7c94c75231aa830dfee</guid>
<pubDate>Sat, 30 May 2026 18:53:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Wentworth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d17b44fe853bf5f47413d93424f6ba333dc14ff547df05c6553473c4a7d29c1a</i><br /><br />Threat actor <b>description</b>: <i>the DC Metro area's premier design-build firm</i><br />Target victim <b>website</b>: <i>wentworthstudio.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Green-Resource</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32648</link>
<guid>a8353138eed2be888ebeb5c321b187d4</guid>
<pubDate>Sat, 30 May 2026 18:53:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Green-Resource</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ea826d51b837f627e0aee8d0ea23b18dcef4430ebdb14d2e8a6628833793ece</i><br /><br />Threat actor <b>description</b>: <i>A leading distributor of professional fertilizers, chemicals, and seeds for local and lawn grasses</i><br />Target victim <b>website</b>: <i>green-resource.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cedar-Street-Capital-A-part-of-a-Cynvestors-Limited-Partnership</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32647</link>
<guid>27c20a93c89bfd0336394f370163d43c</guid>
<pubDate>Sat, 30 May 2026 18:52:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Cedar-Street-Capital-A-part-of-a-Cynvestors-Limited-Partnership</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72f3f5af5f4fd4e783c40026bf4cc4e718ea2fe4c690529c695b6d04b82c4961</i><br /><br />Threat actor <b>description</b>: <i>A private investment entity associated with Cynthia Stiehl</i><br />Target victim <b>website</b>: <i>cedarstreetcapital.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-Roettgers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32646</link>
<guid>d0741765bc4b0480823a98cf49ed061a</guid>
<pubDate>Sat, 30 May 2026 18:52:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>A-Roettgers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bdd519224eaf9306a59078489e87844c0de0c234b11ae118b6a8f3a64b0532d</i><br /><br />Threat actor <b>description</b>: <i>Fuel distributor and gas station operator</i><br />Target victim <b>website</b>: <i>arc-rci.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indiana-Mills-and-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32642</link>
<guid>3f8ee098f1300beb0464a8a8288ab931</guid>
<pubDate>Sat, 30 May 2026 14:17:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Indiana-Mills-and-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>433fc07008b1a78ad9a48d1609e5dba71af43a5a13510c4b45eb5cbfb4356973</i><br /><br />Threat actor <b>description</b>: <i>You have 24 hours to contact us.</i><br />Target victim <b>website</b>: <i>www.imminet.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>UEI-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32641</link>
<guid>6e9feef0d48ead6730ce88ecc22b34cc</guid>
<pubDate>Sat, 30 May 2026 14:17:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>UEI-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53344d746215d9012d64e8fe6f84c6628f44b4bd766faa57a040c63353751f31</i><br /><br />Threat actor <b>description</b>: <i>UEI College is a private for-profit career college with locations in the US states of California, Washington, Arizona, Nevada, Texas, New Mexico, and Georgia. It specializes in short-term technical and vocational education to prepare students for entry-level positions in industries such as healthcare, business, and skilled trades.
</i><br />Target victim <b>website</b>: <i>www.uei.edu</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>LTI-Services-and-Larick-Towing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32639</link>
<guid>005b0c27e7224dabb8c1c7346ceea228</guid>
<pubDate>Sat, 30 May 2026 12:53:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>LTI-Services-and-Larick-Towing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>595383db8de243de98f9a146f053ca2dab8ba8904b142c58a4c0b42f519f7cf9</i><br /><br />Threat actor <b>description</b>: <i>ltiservices.com - laricktowing.com - LTI Services is a leading customization and accessory shop specializing in customizations, repairs, and aftermarket parts for the heavy-duty trucking industry. They work with major truck brands such as Peterbilt, Kenworth, Volvo, International, Freightliner, and Western Star, offering a wide range of services including collision repair, custom fabrication, and electrical repairs. The company prides itself on providing quality parts and accessories while collaborating closely with customers to bring their design visions to life. With a focus on transparency and comprehensive service, LTI Services ensures that clients are informed and confident throughout the project process - 
Larick Towing Inc. is a family-owned and operated business that has been providing vehicle transportation services since 1978. They offer nationwide vehicle transportation, including pick-up and delivery services for transporters, as well as transport to all ship ports and terminals. Their services cater to both individual clients and auto dealers, facilitating vehicle transport to and from auctions and dealer swaps. The company is known for its customer-focused approach and commitment to quality service - Nova provide free decrypt 2 files as proof, we will leak only DBs, not source code because company may recover from leak) 11 days available to reach us or no recover possible, both sites seized.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lee-Law-Offices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32638</link>
<guid>a53b9972c1c68ce19a65dbfc61d6e87d</guid>
<pubDate>Sat, 30 May 2026 12:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Lee-Law-Offices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45c8954444be39b0f7f5cbf9aea23af9484f74df9d3f74d536cd9f81b402d0e5</i><br /><br />Threat actor <b>description</b>: <i>Lee Law Offices is a well-established law firm serving clients in North and South Carolina for over 30 years, specializing in personal injury, workers compensation, and social security disability cases. The firm is dedicated to advocating for individuals affected by auto accidents, workplace injuries, and other forms of negligence, ensuring that clients receive the compensation they deserve. With a no-fee guarantee, they focus on representing the best interests of their clients rather than insurance companies or corporations.</i><br />Target victim <b>website</b>: <i>www.leelawoffices.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plexsupply-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32636</link>
<guid>48f7170b9b4bc029d38adcc2d157027a</guid>
<pubDate>Sat, 30 May 2026 07:54:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Plexsupply-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f93df7d5febdedf615d423a02b2f899fe3b76e98d3022361110affb5636a1f0b</i><br /><br />Threat actor <b>description</b>: <i>A private wholesale and distribution company offering the highest-quality brand-name products</i><br />Target victim <b>website</b>: <i>plexsupply.net</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.labexpress.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32631</link>
<guid>c7036563a002af316014430acdcfa78c</guid>
<pubDate>Sat, 30 May 2026 00:22:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.labexpress.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58c5352a9e5a4677b35d2e85cd76108ba6ad4a33d17f2017c8b9bb6dd070522a</i><br /><br />Threat actor <b>description</b>: <i>LABEXPRESS & GARONIT PHARMA: 200 GB OF SHARED INFRASTRUCTURE  We have obtained 200 GB of internal data from a US-based group operating under two legal entities: Labexpress and Garonit Pharma. The materials show a single Active Directory domain (LABEXPRESS1.local), a shared file server, and extensive cross‑company records. This data will be made publicly available in the near future.  Active Directory Overview  - 65 computers, 142 user accounts, 98 groups, 11 organizational units (OUs). - Domain controllers: DC01 (Server 2019), LABXDC01 (Server 2012 R2). - A single AD domain serves both Labexpress and Garonit Pharma.  Notable account:   cn: Troy Austin   sAMAccountName: Taustin   memberOf: QuickBooks, LABEXPRESS, LABEXPRESSUSERS   The same person appears in Exchange mailboxes as taustin@garonitpharma.com.  Weak Passwords and Brute‑Force Indicators  - Administrator account: 3,193 failed logon attempts, last successful logon 2026-04-30. - Computer accounts FRONTDESK$, DEV$, LABEL$ – more than 3,000 failures each. - Cleartext password found on FILE01\passwords.txt:     Admin: LabExpress2024! - The Domain Admins group includes: Administrator, labadmin, adminiss, Protect, xtratech, LAE009-CT. - Password for user Protect: Password123! - Outdated password templates in the “SBSUsers” OU are still in use.  Mail Servers and Exchange  - LABSERVER2 runs Windows Server 2003 SP2 with Exchange 2007. - Full mailbox export performed using the built‑in Export-Mailbox cmdlet – no special exploit required.  Contents of the Obtained Data (200 GB)  We have data from drive E:\, including:  1. Financial & Accounting    - QuickBooks Enterprise 2021 installer and data files (QB2021.DSN, QB2021.ND).    - Folder: E:\Garonit Documents\Clients 2022\ – hundreds of invoices, COAs, and COCs (e.g., Amtrade International INV# 50268.pdf for ~21M USD, Estee Lauder Inv# 24.pdf).    - Folder: E:\Garonit Documents\ACCOUNTS PAYABLES 2022 09 22\ – detailed accounts payable records for 50+ vendors.  2. Quality & Production    - Thousands of COA/COC files (e.g., CHG 20% Lot 429012 CoA.pdf, COC CHG 20%, Lot# 705103.docx).    - Complete batch records for 2023–2026 (folders Batch Records\2023, 2024, 2025, 2026).    - Stability study protocols and raw HPLC data for CHG 0.12% Oral Rinse.  3. ANDA & Regulatory Documentation    - Folder “00 Oral Rinse ANDA-Old One” – complete ANDA dossier, including DMF, method validation, stability, and correspondence with the FDA.    - Files: ANDA Checklist-Oral Rinse.docx, DMF Assessment in advance.pdf.  4. Vendor & Customer Records    - Folder: E:\Garonit Documents\Vendor from 2022 07 19 TO 2022 09 21\Vendor\ – dossiers on each supplier (contracts, invoices, assessments).    - Folder: E:\LABEXPRESSDATA\ALL LEI ORDERS\ – customer purchase orders and sales quotations.  5. Human Resources (HR)    - Folder: E:\LABEXPRESSDATA\HUMAN RESOURCES\ – employment contracts, W‑9 forms, tax deductions, resignation letters.    - Passport scans, Green Card copies, health insurance records for many employees.    - Files: Employee Handbook.pdf, PTO Request Form.docx, Time off request form.pdf.  6. Internal Communications & Scans    - Directory “C224E BIZHUB SCANNER DUMPS” containing subfolders named after employees (Burcu, Frank, Iliany, Kelvin, Dave, Randy, Sudhir, etc.).    - Scans include: Green Cards, IDs, credit card authorization forms, bank letters, and correspondence with the IRS.    - Examples: Burcu Green Card.pdf, Rohit Garg X-Ray.pdf, SKM_C250i... (thousands of scanned documents).  7. Tax & Banking Documentation    - Correspondence with the IRS, State of New Jersey, Valley National Bank, Citibank.    - Files: IRS Notice Lab Express.pdf, Valley Bank Garonit Deceember 2020.pdf, Credit Application, Bank instructions.pdf.  Shared Infrastructure – Observed Facts  - The same Active Directory domain and file server (drive E:\) store data for both Labexpress and Garonit Pharma. - Cross‑company records reside in the same folders (e.g., “Garonit Documents” and “LABEXPRESSDATA” coexist on the same drive). - User Troy Austin has an AD account (Taustin) and also uses the email address taustin@garonitpharma.com. - Purchase orders, invoices, COA/COC files refer to both companies interchangeably. - At the IT level, there is no separation between the two legal entities.  The obtained data demonstrates that Labexpress and Garonit Pharma operate on a single, shared IT infrastructure. All files, accounts, mailboxes, and production records are stored on the same systems. A 200 GB archive will be publicly released in the near future.</i><br />Target victim <b>website</b>: <i>www.labexpress.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shoreline-Sightseeing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32628</link>
<guid>7c294b263646ae5cff036e366de104cf</guid>
<pubDate>Fri, 29 May 2026 21:52:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Shoreline-Sightseeing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ad20a4216d35f10ac9b5a2cadfaf8fb9a525cf11c3cc2f765d3b0e6fa25f056</i><br /><br />Threat actor <b>description</b>: <i>Shoreline Sightseeing offers guided boat tours and water taxi services in Chicago, focusing on architecture and skyline views. Their popular tours include the Architecture River Tour, Skyline Lake Cruise, and Fireworks Tour, showcasing over 40 landmarks. The company caters to tourists looking for unique perspectives of the city and offers packages like the Chicago CityPASS for additional savings on attractions. Established in 1939, Shoreline operates the largest and most diverse fleet of cruise boats in Chicago</i><br />Target victim <b>website</b>: <i>shorelinesightseeing.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henry-Molded-Products-Likely-to-Engage-tag.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32627</link>
<guid>a89ab5f7e8a7f0419b5d07e00c521668</guid>
<pubDate>Fri, 29 May 2026 21:51:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Henry-Molded-Products-Likely-to-Engage-tag.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f29528f6d0ecbc43a88452b0b6766479d378f777eb0fb6516665360ce92f8aa5</i><br /><br />Threat actor <b>description</b>: <i>Henry Molded Products specializes in the manufacturing of custom molded pulp fiber products and packaging solutions. The company is recognized for its eco-friendly offerings, which are biodegradable, compostable, and recyclable, catering to a growing demand for sustainable packaging. Their products are designed for various clients, including government, industry, and environmentally conscious consumers. Henry Molded Products is committed to providing cost-effective solutions while leading in technology, design, and engineering in the molded fiber sector.</i><br />Target victim <b>website</b>: <i>henry-molded.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>AcademyHealth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32624</link>
<guid>cb138c0ea6e0ec0ac07cb501db562b47</guid>
<pubDate>Fri, 29 May 2026 20:21:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>AcademyHealth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1d0684d5ce0b0c17ff00f3d2d727a23ed3773288bf504e74ab90a3dd9a9e7a4</i><br /><br />Threat actor <b>description</b>: <i>They research and promote policy and innovations in healthcare.</i><br />Target victim <b>website</b>: <i>academyhealth.org</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capital-Family-Physicians</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32622</link>
<guid>61cd29e0ffa769ecebb1acfc6748b4fe</guid>
<pubDate>Fri, 29 May 2026 15:20:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Capital-Family-Physicians</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fbbc6bd1a14a412dad3fcc95a3323a9022f30703d8851627a6f6f2f90469880</i><br /><br />Threat actor <b>description</b>: <i>Capital Family Physicians provides quality healthcare services for families, focusing on comprehensive care for all ages. They offer same-day appointments and a patient portal for convenient access to medical records and billing. The practice emphasizes pediatric services, ensuring that children's health is prioritized. With over 15 years of experience, they are dedicated to supporting patients through every stage of life.</i><br />Target victim <b>website</b>: <i>www.capitalfamilymd.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schacht-Law-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32621</link>
<guid>15f68be0f9f23b4653ab81fa42161a4a</guid>
<pubDate>Fri, 29 May 2026 14:20:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Schacht-Law-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a58119c682b571c49922a6ab31f9b858f7f11346359ff08149a9000f3d9c737</i><br /><br />Threat actor <b>description</b>: <i>Schacht Law Office specializes in intellectual property legal services, focusing on the protect
ion of patents, trademarks, copyrights, and trade secrets. They assist clients in defining and 
safeguarding their ideas to ensure the prosperity of their intellectual property and brand.

We will upload 20gb of corporate data soon. Lots of clients data (credit cards, name, addresses
, phones and so on), contracts and agreements, NDAs, projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>BCD-Travel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32618</link>
<guid>9ef7e0399a77b6c92061f717b147db71</guid>
<pubDate>Fri, 29 May 2026 13:24:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>BCD-Travel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7961589cb60bb1e1e87669ecb657f436d58ba526e33704006faa1d44dbdfae64</i><br /><br />Threat actor <b>description</b>: <i>Over 700k Salesforce records and various Sharepoint sites corporate data has been compromised. This is a final warning to reach out by 1 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 29 May 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Interstate-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32617</link>
<guid>e76346bd12c68c698d4800fd00be9533</guid>
<pubDate>Fri, 29 May 2026 12:50:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Interstate-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>538bd6644273b0ff6e902b3e3aeab226449e096214b2465d00e7512d62724bfb</i><br /><br />Threat actor <b>description</b>: <i>Interstate Roofing brings its customers the best in quality and service. Since 1988, Interstate
has established itself as one of the largest and most trusted exterior-improvement companies i
n the Northwest.

We will upload 16gb of corporate data soon. Employee personal docs (scanned passports and LDs, 
60  SSNs and so on), contracts and agreements, clients info, projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Restorative-Therapies-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32613</link>
<guid>8de1db0c3bd1ffe5fa7383a7bfee2beb</guid>
<pubDate>Fri, 29 May 2026 09:20:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Restorative-Therapies-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55289816d192345cc6980a013198d71015fc54e03e7dec7480dda6b42bb0b87f</i><br /><br />Threat actor <b>description</b>: <i>Restorative Therapies was established in 2004 as a partnership between researchers, engineers, and patient advocates to develop and promote Advanced Rehabilitation Technologies (ART).</i><br />Target victim <b>website</b>: <i>restorative-therapies.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>powerhousenow.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32609</link>
<guid>4699df1b3d138637154b348ac946c963</guid>
<pubDate>Thu, 28 May 2026 21:51:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>powerhousenow.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>249b199dd45ac414e47078f294714519c9dea9eaf1a553402b4debb1c8926c4d</i><br /><br />Threat actor <b>description</b>: <i>STATUS: PENDING PUBLICATION | TIME REMAINING: 72 HOURS
ENTITY: Powerhouse (powerhousenow.com)
THE REALITY OF POWERHOUSE

We have been in possession of your internal data for some time. We have attempted to engage with your management to resolve this incident professionally, but their silence speaks…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/powerhouse-retail-services/346278435</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>entransinternational.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32608</link>
<guid>555ed9de909ff98b3a9de74ed0be9ecf</guid>
<pubDate>Thu, 28 May 2026 21:21:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>entransinternational.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ed17f2b3d0f972e7c52e1249c5ad008f70d5125d481658f6bbace49cdce2c29</i><br /><br />Threat actor <b>description</b>: <i>STATUS: PENDING PUBLICATION | TIME REMAINING: 72 HOURS
ENTITY: Entrans International (entransinternational.com)
THE REALITY OF ENTRANS INTERNATIONAL

We have been in possession of your internal data for some time. Throughout this period, we have attempted to engage with your management, but their si…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/entrans-international-llc/368177586</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pea--Bromberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32607</link>
<guid>fc8bdffcd745cc1b8556a8868469a55b</guid>
<pubDate>Thu, 28 May 2026 20:22:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Pea--Bromberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f42a5b0ae1777e4afba241a04c92b0e551b5380a809a37a23715dcf107285261</i><br /><br />Threat actor <b>description</b>: <i>A legal firm dedicated to safeguard the rights of its clients</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Battery-Factory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32599</link>
<guid>8b58bfa9e198667418d251769277200c</guid>
<pubDate>Thu, 28 May 2026 19:49:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>American-Battery-Factory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b807965a01698f618dc7fa24ba720c8dbf728b72ff710eded8ea65a225adecf</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heartland-Growers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32602</link>
<guid>e143deaaa05532392f9ab5ca2af8fd2c</guid>
<pubDate>Thu, 28 May 2026 18:54:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Heartland-Growers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5b656119a5b872e345b1093f31c8683bdce76f2509b8db097a6ffb479e20c25</i><br /><br />Threat actor <b>description</b>: <i>heartlandgrowers.com zoominfo.com/c/heartland-growers/48466328 Heartland Growers is a family-owned wholesale greenhouse in Westfield, Indiana, operated by the Gapinski family since 1984. They supply spring annuals, holiday plants, and hydroponic produce to garden centers, florists, and retailers across the Midwest. Their 30-acre modern facility features advanced automation and a skilled workforce of up to 175 employees. Committed to innovation and quality, they combine decades of expertise with sustainable growing practices</i><br />Target victim <b>website</b>: <i>heartlandgrowers.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fox-Rothschild-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32600</link>
<guid>1808917e7c89cc5483dc318bcbbf8d0f</guid>
<pubDate>Thu, 28 May 2026 18:20:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Fox-Rothschild-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90d319449a29d248aa8855da2bf28c5bff99bfb0e942cf8b2b31aff228e003ff</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Fox Rothschild LLP is a national law firm headquartered in the United States. Founded in 1907, it operates across numerous offices throughout the country, providing legal services in areas including corporate law, litigation, employment law, real estate, and finance. The firm serves a broad range of clients, from individuals and startups to large corporations, operating within the legal services industry in the United States.</i><br />Target victim <b>website</b>: <i>foxrothschild.com</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Psychiatry-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32596</link>
<guid>8f414eeae19bc5ccd69f544fce81f5a6</guid>
<pubDate>Thu, 28 May 2026 15:25:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Advanced-Psychiatry-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>835004f1964d54ad937b66118c77eb8b5cb55a9db0a564ee8811f2ab297b46d7</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Advanced Psychiatry Associates is a psychiatric medical practice based in the United States. The company provides comprehensive mental health services, including evaluation, diagnosis, and treatment of psychiatric conditions such as depression, anxiety, ADHD, and bipolar disorder. It operates within the healthcare and behavioral health industry, offering both medication management and therapy services to adult and adolescent patients across its clinic locations.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>AKM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32593</link>
<guid>8b2c2c9ec76699e630613862e62a06de</guid>
<pubDate>Thu, 28 May 2026 15:24:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>AKM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5436cdb11d1bf5fefda1479a5d1bff8a2524e7f207dba8fe1049ada4452bb609</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

There are multiple companies with the acronym "AKM" across various industries and countries, and without additional context (such as full company name, industry sector, or country), I cannot reliably identify which specific organization is being referenced or provide accurate threat intelligence details.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sinomax-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32592</link>
<guid>2aa9c1afdc1323b9c19b35a4a09b989b</guid>
<pubDate>Thu, 28 May 2026 13:40:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sinomax-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc20715b2c6b0c2cde2d5384f0d313ca09b65e63d3f47a6d2616e8d01710cb6b</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sinomax-usa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mindpath-College-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32591</link>
<guid>f0eefcbcfb4afc1b3fbef0018e0773a0</guid>
<pubDate>Thu, 28 May 2026 13:40:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mindpath-College-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac78c31282e3e5451a745435e7aea2d23d7185350bf26f1f6782337f7b0749c6</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>college.mindpath.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carton-Craft-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32590</link>
<guid>c0c8c5f98f7b646f6dd7213b19e68475</guid>
<pubDate>Thu, 28 May 2026 13:39:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Carton-Craft-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6f6876aaddb7d92ad463219b9146199e85e3f73a9d309b0b67c4fe4f2383a0c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cartoncraftsupply.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gallun-Snow-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32589</link>
<guid>5b1bf4359bd2ebb370a47bf756b07e92</guid>
<pubDate>Thu, 28 May 2026 13:38:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Gallun-Snow-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5c2c8cefb63a3a42b7dc2a61648a55dab9dd072a5c52ab2bd97f7b453641a65</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.gallunsnow.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>HumanEdge</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32587</link>
<guid>0bb0846327772451045bd30dd347821b</guid>
<pubDate>Thu, 28 May 2026 13:33:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>HumanEdge</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a453e3a2f9355dd9adcfdfc1763c933374b76df8a6ab83ece356cc89181f634</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.humanedge.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Providence-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32586</link>
<guid>280981b2e6e1056c242165eb901cf649</guid>
<pubDate>Thu, 28 May 2026 13:32:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Providence-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61b6d936d0c359e767e1f7a0320867edb81d1c2c2a42ab0271ac965d224d9699</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.provmedgroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Martinez--Shanken</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32582</link>
<guid>95c766b269cff1633ad91f9f0e870da7</guid>
<pubDate>Thu, 28 May 2026 13:27:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Martinez--Shanken</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d37c35367167761493713a178a9a877071bcafaedde59e7a8296c221f89b588c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.aztaxcpa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>LP-Aesthetics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32580</link>
<guid>842625dc46b85b5a25f333e5ce7f3f42</guid>
<pubDate>Thu, 28 May 2026 12:51:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>LP-Aesthetics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfe5670952a60ab00e46fea0dea0fcdac4c1e25df7daaa6d9d9c1e54b33593be</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>GS-Yuasa-Lithium-Power</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32579</link>
<guid>465ecc6b3833a9cd97ebf3561b10753c</guid>
<pubDate>Thu, 28 May 2026 12:50:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>GS-Yuasa-Lithium-Power</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>695dedec5359e0d8036494e795c26e2bfba035115810fb3051ba0264cee57cbc</i><br /><br />Threat actor <b>description</b>: <i>GS Yuasa Lithium Power specializes in advanced batteries and battery systems, primarily serving
clients in the Aerospace, Industrial, Military, and Specialty markets across North America. Wi
th decades of research and development, their lithium-ion cells are known for proven performanc
e and reliability, particularly in demanding applications such as satellites and undersea techn
ologies.

We will upload corporate data soon. Lots of project data (BOEING satellite and other interestin
g directories), contracts and agreements, lots of drawings and specifications, clients info, ND
A, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>General-Doors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32578</link>
<guid>15a0f9a3d4cae6bdfdb879afead2f39c</guid>
<pubDate>Thu, 28 May 2026 12:20:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>General-Doors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23e67386cf17eabc64b03b13d735b1f581732103755c8ae056b6c94d1395c6c8</i><br /><br />Threat actor <b>description</b>: <i>General Doors Corporation has been manufacturing overhead sectional garage doors since 1947, or
iginally focusing on wood doors before expanding to commercial and residential steel doors.

We will upload corporate data soon.Financials, a bit of projects info and other files etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hospice-Savannah</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32575</link>
<guid>33c91699c1849207f81bf13a7210a5ec</guid>
<pubDate>Thu, 28 May 2026 11:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Hospice-Savannah</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>769ab5603ebcbc4c0ed8d800aba3494e3cad0eed0765628a95c30cef03fc5b5b</i><br /><br />Threat actor <b>description</b>: <i>Hospice Savannah provides comprehensive hospice and palliative care services to individuals facing serious illnesses, including specialized programs for pediatric patients and advanced cardiac care. Their services extend to in-home care, nursing home assistance, and inpatient hospice units, ensuring a dignified and comfortable end-of-life experience.</i><br />Target victim <b>website</b>: <i>www.hospicesavannah.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>President-Container-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32561</link>
<guid>5f937e78a9f11802066ba28a4f8d959f</guid>
<pubDate>Wed, 27 May 2026 21:51:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>President-Container-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>963ce4d88ee31b7f0f6234f77811dea3d79c20d6af68783fea4fe234c3b8f3e8</i><br /><br />Threat actor <b>description</b>: <i>President Container Inc., founded in 1947 by Marvin and George Grossbard, not only grew into one of the largest independent manufacturers of corrugated products...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mainstreet-Organization-of-REALTORS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32558</link>
<guid>5288cea98051f543db9fed5c03f6e29c</guid>
<pubDate>Wed, 27 May 2026 18:49:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mainstreet-Organization-of-REALTORS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1db203a5d5cc974dc215b8939932445f1db3ade3cfb8045e193030072fbf0c8d</i><br /><br />Threat actor <b>description</b>: <i>Membership Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shocco-Springs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32559</link>
<guid>89d2a536c6219081a9985ba58f5c3ad6</guid>
<pubDate>Wed, 27 May 2026 18:49:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shocco-Springs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>635ce104272cb6a70d265707a11330a65f537828c9dd1c470feb53b27696e7e8</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roofing-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32560</link>
<guid>36203d7da31576b98485dc648ee525e2</guid>
<pubDate>Wed, 27 May 2026 18:49:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Roofing-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ca547614be390df786e2b433ffad299449d72e871cef3b8cc3b22353a6af2fa</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>fabbricausa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32543</link>
<guid>23ec211d0365be0665abf1354689014d</guid>
<pubDate>Wed, 27 May 2026 17:49:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>fabbricausa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bae77cc79013acb34a5783ae2cfdb6410682fb4e5e489c115d2c5f22da1ae041</i><br /><br />Threat actor <b>description</b>: <i>Fabbrica LLC specializes in design, development, and manufacturing,
focusing on high quality standards and a creative approach.
It serves clients seeking innova...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>waypointsolutions.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32545</link>
<guid>0a78d9f8a1d2c2289e4410bcb0657b73</guid>
<pubDate>Wed, 27 May 2026 17:48:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>waypointsolutions.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>295ea724bbf3ca82b66800524c289c059804eba87e850bd4a048d2b0fede7bb3</i><br /><br />Threat actor <b>description</b>: <i>Waypoint Business Solutions partners with Dell Technologies to provide comprehensive IT solutions, including hardware, software, and professional services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>jcripberger.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32547</link>
<guid>8423dd87983400be28badfcfaed92b99</guid>
<pubDate>Wed, 27 May 2026 17:48:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>jcripberger.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec0e48052e5f35c22b3329bf2519b8124c2c1691222fb37cac91aaf1c70e6c6a</i><br /><br />Threat actor <b>description</b>: <i>J.C. Ripberger Construction Corporation is a full-service General Contractor, which self-performs Buildings/Structural Concrete, Carpentry, and Selective/Mass D...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>nemd.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32549</link>
<guid>ea83bad32870765c79d8745c5ae7e0c2</guid>
<pubDate>Wed, 27 May 2026 17:48:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>nemd.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6fcbd9aef0256415a1d431aa85818abe92647d34ad0ef7056a82a9d7bc6be1b1</i><br /><br />Threat actor <b>description</b>: <i>NEMD Architects, Inc. specializes in innovative, functional, and sustainable architectural solutions that address the unique challenges of each project.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>northbridge.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32554</link>
<guid>e0d04159c4304a1f2a5e191f551f3a94</guid>
<pubDate>Wed, 27 May 2026 15:52:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>northbridge.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39d519c9935cac389daec3c92ae6e17ca39a9a3b40848de033ebc7b116e0c9c2</i><br /><br />Threat actor <b>description</b>: <i>North Bridge Venture Partners invests in outstanding individuals
whose innovative ideas have the potential to transform entire industries.

The firm provides funding from seed to growth stages,
helping these ideas grow into successful companies.

Their goal is to transform startups into market leaders. They work with clients
seeking investment and support for their entrepreneurial projects.</i><br />Target victim <b>website</b>: <i>northbridge.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>jichasa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32552</link>
<guid>e6098d5b1d94ff8ff653522c48a3a327</guid>
<pubDate>Wed, 27 May 2026 15:25:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>jichasa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0413fa251642669d9b359c2e506a805b9dc2be3b82ac30b1b0fb762d4be5a799</i><br /><br />Threat actor <b>description</b>: <i>+1 (915) 881-8883. Jichasa Smart Logistics specializes in providing comprehensive solutions in foreign trade and logistics, with a focus on door-to-door services. Established in 1980, the company boasts over 30 years of experience and offers a wide range of services including customs consulting, inventory management, and supply chain management. Their intended clients span various industries such as automotive, aerospace, electronics, and agriculture, ensuring personalized attention through dedicated account executives. With a strong presence across Mexico and advanced technology for real-time operations, Jichasa aims to exceed client expectations in logistics and legal consulting. Stolen: 116gb 98k files</i><br />Target victim <b>website</b>: <i>jichasa.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ramos-Rheumatology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32541</link>
<guid>4eef0e56a2db6b4950e05778b5351717</guid>
<pubDate>Wed, 27 May 2026 13:52:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Ramos-Rheumatology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4cde7a4d3a5cabc6fcc299ea7ab058ecdb4574fbfcc70292720af67048f23369</i><br /><br />Threat actor <b>description</b>: <i>Ramos Rheumatology is a leading care center in Avoca, PA, specializing in the diagnosis and treatment of autoimmune diseases such as lupus, rheumatoid arthritis, and fibromyalgia. The practice emphasizes personalized care, ensuring that each patient receives tailored treatment plans in a compassionate environment. Their team, including local specialists, collaborates closely with primary care providers to deliver comprehensive rheumatology services. With a commitment to patient autonomy and immediate appointment availability for emergencies, Ramos Rheumatology prioritizes the well-being of its clients</i><br />Target victim <b>website</b>: <i>ramosrheumatology.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northwest-Woodworks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32540</link>
<guid>f2fe423b71e1f13b47c8da3aebd12ad1</guid>
<pubDate>Wed, 27 May 2026 13:50:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northwest-Woodworks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83e7e74cc861c0a56eeec16ae00039dd5eeef6695ab009b841c3fe834c2b786d</i><br /><br />Threat actor <b>description</b>: <i>Northwest Woodworks is a trusted partner of contractors for over 30 years, specializing in cust
om cabinets and architectural woodwork for various commercial spaces. They combine cutting-edge
technology with skilled craftsmanship to create cost-effective solutions that bring clients' v
isions to life.

We will upload 31gb of corporate data soon. Employee personal information (passports, DLs, SSNs
and other information), contracts and agreements, financials, clients information, confidentia
l drawings, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gone-Fishin-Marine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32538</link>
<guid>251ac3d1e0619a1166fa15753157ea11</guid>
<pubDate>Wed, 27 May 2026 13:20:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gone-Fishin-Marine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32b4ff449ae626d0fb6dd87ca7b7ca6bdf390c1e8f599ca210c2853304a77be1</i><br /><br />Threat actor <b>description</b>: <i>Gone Fishin' Marine specializes in offering a wide range of new and used boats from top brands 
such as Ranger, KingFisher, Sea Ray, and more.

We will upload corporate data soon. Employee information, contracts and agreements, financials,
clients information, projects and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>hbroch.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32537</link>
<guid>c1f0986fd7eefc02708427c7b8fada90</guid>
<pubDate>Wed, 27 May 2026 12:53:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>hbroch.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e0b30dc42ee4dd8798e2b8f77c86e038fe969bef8990ded8d685b8e1c847c64</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1941, Henry Broch Foods is an American international food ingredient manufacturer, processor, and packaging company, sourcing high-quality natural ingredients from producers worldwide.
Our suppliers produce vegetables, fruits, herbs, spices, and natural colors, which are then concentrated, dehydrated, frozen, extracted, or pasteurized.
The company's products are used in a wide range of applications, including: spice and seasoning blends,
batters and coatings, bakery mixes, sauces, soups, salad dressings, flavorings,
extracts and colors, fruit juices, flavored beverages, jams and jellies,
ready-to-eat meats, entrees, ethnic dishes, pasta,
rice and grains, pizza, and snack foods.</i><br />Target victim <b>website</b>: <i>hbroch.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>dentonfirm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32533</link>
<guid>3caea4d9bcdd5cde2b1a1f338a06a086</guid>
<pubDate>Wed, 27 May 2026 12:22:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>dentonfirm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1304f31a34e82e5e5ca23ffa4f8dcf90365124516bfdf9e5541ebbc163898e68</i><br /><br />Threat actor <b>description</b>: <i>Denton Law Firm is committed to rapid response and providing real solutions.</i><br />Target victim <b>website</b>: <i>dentonfirm.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenway-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32532</link>
<guid>372f8774202fcaef20fb3917607999a8</guid>
<pubDate>Wed, 27 May 2026 07:53:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Greenway-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba02e88a427ed4a31dd7e1c5e7099e4f2fdfa40d448760d94851c446467b4494</i><br /><br />Threat actor <b>description</b>: <i>Greenway Technologies is a leading fire protection company based in Phoenix, AZ, specializing in a comprehensive range of services including fire suppression systems, alarms, sprinklers, and smoke control. Established in 2010, the company provides tailored fire protection design, installation, maintenance, and inspection services aimed at ensuring the safety of properties across the federal and commercial sectors. With a strong commitment to innovative, code-compliant solutions, Greenway Technologies aims to protect lives and property through their top-tier services. Their expert team is dedicated to delivering reliable, high-quality fire protection systems that meet the unique needs of their clients</i><br />Target victim <b>website</b>: <i>greenway-technologies.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ridge-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32529</link>
<guid>7c8150213491f29a32e41242e2fdf55a</guid>
<pubDate>Wed, 27 May 2026 03:03:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Ridge-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3599b5196e8cd26e5b1ff54326f7ff70f42b0ed2c8f0949fc35b6be2d771e7ca</i><br /><br />Threat actor <b>description</b>: <i>Ridge Law Firm (ridgelawfirm.com) is a personal injury law firm based in the Bronx, New York. Led by attorney Michael T. Ridge, the firm has been serving injured clients in the Bronx for over 20–30 years. They operate under the memorable brand 1-800-THE-BRONX and focus heavily on accident victims. The firm offers no fee unless they win (contingency basis), free consultations, and even free Uber rides for in-person meetings. They emphasize aggressive representation and have recovered millions of dollars for clients in compensation for medical bills, lost wages, pain and suffering, etc.- Client medical records- Financial records- Expert witness reports- Etc More than 1.6 TB of data https://ridgelawfirm.com</i><br />Target victim <b>website</b>: <i>ridgelawfirm.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hamister-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32524</link>
<guid>d15ff2db80a89807d24869fd9ffb1700</guid>
<pubDate>Tue, 26 May 2026 15:50:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hamister-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14ee52f0477a16cb21ace1d04ba8a8ddaf8e496f9a3daf86190432fb53a68c91</i><br /><br />Threat actor <b>description</b>: <i>Holding Companies & Conglomerates</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sunrise-Toscana-Country-ClubAndalusia-Country-Club.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32525</link>
<guid>64157a370a2257ee6c20f26f14ba3583</guid>
<pubDate>Tue, 26 May 2026 15:50:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sunrise-Toscana-Country-ClubAndalusia-Country-Club.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25ef09b5e49ed4ae2a61280f4269365de2a233c22413d64ec9384a8427bbc994</i><br /><br />Threat actor <b>description</b>: <i>Sunrise Company is a renowned real estate developer and builder specializing in resort and golfcourse communities. Established in 1963, the company has developed over 16,000 homes and condominiums, along with creating multiple resort hotels and commercial structures. Toscana Country Club is a luxury private equity club and residential community located in Indian Wells, California, offering an exceptional lifestyle amidst beautiful olive and cypress landscapes.Andalusia Country Club is a luxurious community near Palm Springs, offering distinctive golf course homes and a premier country club experience.We will upload 13gb of corporate data of the above mentioned entities. Employee personal information including family of the CEO (passports, DLs, death records and so on), contracts and agreements, detailed financials, clients information, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hunter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32519</link>
<guid>6e07b8256ccd2356be4cc9c07fc5e739</guid>
<pubDate>Tue, 26 May 2026 05:27:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Hunter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2efe9b6eba78cb3fb0fea60e7c3e22b5b095a581f3c837d67218a6e6a7449b49</i><br /><br />Threat actor <b>description</b>: <i>Hunter was created by Antoine Finkelstein and François Grante in 2015. Freshly graduated, they saw the untapped potential of cold emails and wanted to address the challenges of prospecting and finding contact information. To achieve great success rate while complying with privacy regulations, they decided to use emails found on the public web. Email Hunter was born. Soon rebranded as Hunter, the tool quickly became a game-changer in business intelligence. Within weeks, it attracted thousands of users thanks to its user-friendly interface, handy browser extension, affordable pricing, and data accuracy. Unlike its peers, Hunter aimed not at large enterprises but at making cold emailing accessible to all. Over time, Hunter grew into a comprehensive email outreach platform, offering everything from finding contact information to sending cold emails. Antoine and François, with a focused team, continued to empower professionals with simple, powerful tools.-Personal information of employees and clients-Databse-Financial documents-Other files  https://hunter.io/</i><br />Target victim <b>website</b>: <i>hunter.io</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>PILLER-AIMMCO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32516</link>
<guid>3985c3f6f10fa559cb7403cd0121d5c1</guid>
<pubDate>Mon, 25 May 2026 23:22:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>PILLER-AIMMCO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2b439dfff5475c96c19e3ec509864d59d5161bc97d99c5c71d55a2f44ffc527</i><br /><br />Threat actor <b>description</b>: <i>PILLER AIMMCO is a leading vertically integrated custom plastic injection molding and tool-making company based in Woodland and Washougal, Washington. The company serves as a "one-stop shop" by managing the entire manufacturing lifecycle under one roof—from initial part design and engineering to mold production, automated high-volume manufacturing, and secondary assembly. PILLER AIMMCO holds ISO 9001:2015 certifications across both its tooling and molding operations, enabling it to support rigorous industrial regulations:  1. Medical Devices & Biotech: Fluid management components, orthodontic instruments, and lab devices that meet FDA, biocompatibility, and sterilization metrics. 2. Aerospace & Defense: Specialized tooling, gauges, fixtures, and finished components requiring absolute traceability. 3. Consumer Electronics: Complex enclosures, wearable technology components, and carbon-fiber-filled metal replacements. 4. Industrial & Agriculture: Heavy-duty commodities, nursery containers, large housings, and automotive/heavy trucking aftermarket parts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>GW-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32515</link>
<guid>039b28c0e2a52524890797e9e0f29899</guid>
<pubDate>Mon, 25 May 2026 20:25:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GW-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d8fdd58505d91e7d056b3b02e146669e15ae0aab909e4b64ba0234eaa83c80e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gwmechanical.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Round-Hill-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32513</link>
<guid>b597976c3ce6012f3a07e9f5c71a3c8c</guid>
<pubDate>Mon, 25 May 2026 20:24:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Round-Hill-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>70c4a3bce43c40d857f56a61013a64663c9a4f0fc1debf609b3e3c00d017333a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rhcountryclub.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Legend-Networking--Telecom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32512</link>
<guid>b91f491a5ad27382b54abe58f8dd31a3</guid>
<pubDate>Mon, 25 May 2026 20:24:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Legend-Networking--Telecom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c34ed8d6effbff3380c29694fc71266421a46322fb8380176330c7fda5edb81c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.legendnt.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>MyPillow</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32511</link>
<guid>414c9626ffcaf80a72e69de63d2f7487</guid>
<pubDate>Mon, 25 May 2026 20:23:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>MyPillow</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8db0c15fed7de1b4b6a79388594e588d153f763ff30c8aeec151f76c6a60a005</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mypillow.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Open-Door-Health-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32510</link>
<guid>0e22aa2a44e7e297c6365f23dbedd92c</guid>
<pubDate>Mon, 25 May 2026 20:22:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Open-Door-Health-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09aff2971a3ffe1d24c3fd8a6ad407feaa4d9a2b57368c82ff2471a4a69e0985</i><br /><br />Threat actor <b>description</b>: <i>Open Door Health Center of Illinois offers a comprehensive medical home approach to primary health care, focusing on improving community health since 1977. Their services include medical assistance, HIV programs, behavioral health, case management, and community outreach, catering especially to LGBTQI individuals and those living with HIV/AIDS. The center aims to provide affordable and accessible healthcare without discrimination, while also engaging in education and training initiatives. Their intended clients include patients in need of medical care, community members seeking support, and volunteers looking to contribute to health equity.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Dallas-Shared-Ministries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32504</link>
<guid>bf851291196d497a5bd64847085f5603</guid>
<pubDate>Mon, 25 May 2026 18:50:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>North-Dallas-Shared-Ministries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71799d3f3ff11ae7465ffcb5055a086060d77e22eb31ac301ade0da21fac07e8</i><br /><br />Threat actor <b>description</b>: <i>Now-Forward is a non-profit organization based in Dallas that provides a range of essential services such as financial aid, medical and dental care, food, clothing, and ESL classes to low-income families. Established to effectively serve the urgent needs of the community, they have been a trusted resource for over 40 years, assisting residents facing unexpected life challenges. The organization supports their mission through donations, volunteer work, and partnerships with local entities, ensuring that 96% of their funds are directed toward client services. Their extensive offerings also include tax preparation and school supply assistance, enabling families to achieve greater stability and self-sufficiency.</i><br />Target victim <b>website</b>: <i>www.ndsm.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>IDS-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32503</link>
<guid>deee7af4f21266a3e8e85d593107aa89</guid>
<pubDate>Mon, 25 May 2026 17:25:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>IDS-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5bd82b03d2eb97069221923623326d690c5ed5fd66dd0f0cadcb7fd514cf95b</i><br /><br />Threat actor <b>description</b>: <i>IDS Group IDS Group is an award-winning multi-discipline design, engineering, and management consulting firm based in Southern California.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>sphvalue.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32491</link>
<guid>ea0bce2346d589ebc1fa3030b0e97044</guid>
<pubDate>Mon, 25 May 2026 13:51:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>sphvalue.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd4a9185021dbddb4af228edcadf1ca2e65a92e5b466f1f4e0c8937222c4b281</i><br /><br />Threat actor <b>description</b>: <i>Since 1992, our team of experts in economics, accounting, finance, and valuation has earned an impeccable reputation for relentless analysis and exemplary quali...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>arsenalscaffold.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32493</link>
<guid>e77d89a5cfa17ff55d0b928bf21b2d0f</guid>
<pubDate>Mon, 25 May 2026 13:51:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>arsenalscaffold.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad85629c5ab7df0a0d85c5cf6fcb01e3cf51453246cc635a174fe5e5f7612511</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1998, Arsenal Scaffold Inc. specializes in providing professional scaffolding and vertical access solutions, including tubular and system scaffolding...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>epbinsurance.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32495</link>
<guid>f65d22c53bba4ccf77df86be93a43d5a</guid>
<pubDate>Mon, 25 May 2026 13:50:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>epbinsurance.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68d5c424761ebbc0f70ee5a23c61f23be5661299fe39661d9865607000c77a91</i><br /><br />Threat actor <b>description</b>: <i>Ekblad, Pardee & Bewell, Inc. is an independent insurance agency licensed in Minnesota, Wisconsin, South Dakota, and Arizona, offering a wide range of insurance...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>jakn.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32496</link>
<guid>b3116cab8fe07b8045c68492c5f43682</guid>
<pubDate>Mon, 25 May 2026 13:50:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>jakn.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>786b8c3289b8d490862d510f00bcf1080031a8c4c8de5d45466500c40d0b547c</i><br /><br />Threat actor <b>description</b>: <i>JAKN Network Support & Services LLC operates in the custom software development and IT services industry. It employs 10 to 19 people and generates revenues of $...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>allianceadjustment.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32502</link>
<guid>aa827be8f6b291a77a8bf45f2bdbac78</guid>
<pubDate>Mon, 25 May 2026 11:55:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>allianceadjustment.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51bc1f022c8905f3d11ee9eb703e9df38bd5bafe481680ed2d605f1c0410b0ce</i><br /><br />Threat actor <b>description</b>: <i>Alliance Adjustment Group is a leading independent insurance claims adjuster serving Pennsylvania and New Jersey, specializing in handling a variety of insurance claims, including water damage, fire, storm damage, theft, and vandalism.</i><br />Target victim <b>website</b>: <i>allianceadjustment.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>vegfresh.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32499</link>
<guid>ee45c5e7b878c30a7f870d4024076553</guid>
<pubDate>Mon, 25 May 2026 11:53:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>vegfresh.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1dbe09b20de0abeb45e959ddcdce619abc29efefbdf7e6b7ff81a7d5ffe8b167</i><br /><br />Threat actor <b>description</b>: <i>Veg-Fresh Farms is a family-owned business committed to providing its customers with the freshest and healthiest produce. The company offers a wide range of products, including organic potatoes and exclusive vine-ripened tomatoes.</i><br />Target victim <b>website</b>: <i>vegfresh.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ggroupcpas.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32498</link>
<guid>fb08f0198304439175f357d1d543e6e3</guid>
<pubDate>Mon, 25 May 2026 11:52:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>ggroupcpas.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a2db24ac98a39ded30018caae25cce29207ad584a79fa111d528e80ec1a39e2</i><br /><br />Threat actor <b>description</b>: <i>Goldklang Group CPAs specializes in audit and tax services for homeowners associations, condominiums, and housing cooperatives. With over 40 years of experience, the firm strives to deliver superior results to clients through tailored audit and tax procedures. They emphasize expert knowledge and attention to detail in their work, saving clients over $3 million in just three years. Their target audience is homeowners associations seeking reliable and competent financial services.</i><br />Target victim <b>website</b>: <i>ggroupcpas.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>businessrecord.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32497</link>
<guid>6e908d2f26ba44f68ca184d2696ec807</guid>
<pubDate>Mon, 25 May 2026 11:51:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>businessrecord.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7cebf7860349836dad865dae7617cc49d9c24bc5c929e26c1e925a8a8f6b696d</i><br /><br />Threat actor <b>description</b>: <i>BusinessRecord.com provides RSS feeds free of charge for personal, non-commercial use. If you embed an RSS feed on a personal website, please include a link back to Business Record. Business Record reserves the right to request that you cease distributing these feeds at any time and for any reason.</i><br />Target victim <b>website</b>: <i>businessrecord.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alpert-Slobin--Rubenstein</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32475</link>
<guid>6f3d86720d498a0f707dc24326038c8a</guid>
<pubDate>Sun, 24 May 2026 19:50:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alpert-Slobin--Rubenstein</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aacf923d446967b7850f26e5b623e233662ccbf1da81f7c32c000143b747bdaf</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>P--G-Trading</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32476</link>
<guid>dcdca98a68d012618ce17d4fe3c87f34</guid>
<pubDate>Sun, 24 May 2026 19:50:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>P--G-Trading</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b1aabfa3ebd2526cd7480fe0b794ae29f820eb45f6081e83802d6a3b8d554fd</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sponseller-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32487</link>
<guid>a3cf6b51ac04a41f0875755cca6fdc5e</guid>
<pubDate>Sun, 24 May 2026 18:24:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sponseller-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05c4228c72481c5744c32ef4cb6dc7d2709043f4a2c48cb5462b7889824405a9</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sponsellergroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ExpoCredit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32485</link>
<guid>f8e6960b1cf865c3002b712383c4cfc2</guid>
<pubDate>Sun, 24 May 2026 17:53:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ExpoCredit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31a4c9fc7f576031b71ee8343e90b77e4ccc9550bbdf272fe040c0a41de53a0d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.expocredit.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Retool-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32484</link>
<guid>39e1057382425c5ceab4d8702ffdf7bd</guid>
<pubDate>Sun, 24 May 2026 17:53:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Global-Retool-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>845e283b59dedc83c64d7f02651115d983ab10138a72a6fc7c1c4afd63aed84b</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.global-retool-group.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>la-familia-adualt-day-center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32481</link>
<guid>b084aaefa0a2f7ab72363110bcda458e</guid>
<pubDate>Sun, 24 May 2026 17:26:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>la-familia-adualt-day-center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecf3d0bc74cd2f5907d5fe61689103d09a8e75670bbc33970353242f60a921af</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.lafamiliaadultdaycenter.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heartland-Growers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32471</link>
<guid>2f8ad0a8b0f357680b14408c30c53a11</guid>
<pubDate>Sun, 24 May 2026 09:52:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Heartland-Growers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df3a1f03c511cbcb3092e0bd41596441a3e0ae5451c0a8deb4dd2fef8f66b459</i><br /><br />Threat actor <b>description</b>: <i>Heartland Growers is a full-service wholesale greenhouse located in Westfield, Indiana, owned and operated by the Gapinski Family since 1984. The company supplies wholesale plants to independent garden centers, florists, landscapers, and national chain stores throughout the Midwest. With a modern and capital-intensive facility covering over 30 acres, Heartland Growers produces a variety of plants including bedding plants, geraniums, lilies, and hanging baskets. The company is committed to maintaining quality and service as top priorities for its customers</i><br />Target victim <b>website</b>: <i>heartlandgrowers.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>HELIX-INTERNATIONAL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32470</link>
<guid>1ba2e3e63336e31e2474cac0fd74bb40</guid>
<pubDate>Sun, 24 May 2026 09:52:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>HELIX-INTERNATIONAL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad7e78284720ec1ed03349863c17674fe146508c24cbad05a4717b2080793ea0</i><br /><br />Threat actor <b>description</b>: <i>Helix International is a software platform and managed services provider specializing in enterprise content management and data migration. They cater to medium, large, and Fortune 500 companies across various industries, including healthcare, finance, retail, and entertainment. The company offers a variety of solutions, such as custom development, hosting, and GDPR compliance, enabled by their advanced software platform and proprietary extraction tools. With a track record of 100% project success and partnerships with major firms like IBM, Helix International is recognized for its ability to manage and optimize complex data environments.</i><br />Target victim <b>website</b>: <i>helix-int.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seeley-Office-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32467</link>
<guid>6d6072ea730f062537e458a1e7d47e78</guid>
<pubDate>Sun, 24 May 2026 09:02:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Seeley-Office-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c6ba0f34a8fa894edaa4186b60e9134fbbecb06c1bab5d6d44bfa66554d1f87</i><br /><br />Threat actor <b>description</b>: <i>seeleyoffice.com zoominfo.com/c/seeley-office-systems-inc/347773140 family-owned business since 1981, based in Glens Falls, New York. They deliver comprehensive office solutions: from printers and MFPs to managed print services and supply procurement. Focused on boosting business productivity through personalized service and competitive pricing across the Capital and Adirondack regions</i><br />Target victim <b>website</b>: <i>seeleyoffice.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baker-Distributing-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32451</link>
<guid>68b1b41b63dd1d4bb13ef7c59076be56</guid>
<pubDate>Sat, 23 May 2026 00:24:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Baker-Distributing-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc8b0b55cdded40f757eda22ad570c61744e51bb615aba1c6284f2be6adff7f8</i><br /><br />Threat actor <b>description</b>: <i>Over 260k Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charter-Communications-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32450</link>
<guid>b2483c130839641db1e7badbfbe9240b</guid>
<pubDate>Sat, 23 May 2026 00:24:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Charter-Communications-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b331ccc2809f782bc1607c9f5b47b7d5f462ccde559d95ada839b433c025a01b</i><br /><br />Threat actor <b>description</b>: <i>Over 42M records containing PII have been compromised. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>DentaQuest.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32449</link>
<guid>fdf645aecfe402b2d8297ab009bbef0b</guid>
<pubDate>Sat, 23 May 2026 00:24:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>DentaQuest.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1057be8875bc84768690532522a24afef1ea3d467297b2aa5b914c9b265abd0</i><br /><br />Threat actor <b>description</b>: <i>You wouldn't want us to describe what data and how much data was compromised publicly. It is in your best interests to reply to us or we are leaking it all by the deadline. This is a final warning to reach out by 27 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Pay or Leak. | Updated: 23 May 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>DentaQuest.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hoy-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32445</link>
<guid>39aca26227b4762cf59f50e09159ca84</guid>
<pubDate>Fri, 22 May 2026 19:25:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Hoy-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0cc06417c70258feaad0c555e62a826a207630c047e426c487ba28de09d40879</i><br /><br />Threat actor <b>description</b>: <i>Since 1933, Hoy Construction has specialized in commercial construction management for commercial, industrial, and institutional facilities in Hampton Roads, VA. As a 100% employee-owned company, they emphasize a design-build approach, preconstruction services, and open-book transparency. Their experienced team collaborates with owners and architects to effectively manage costs and schedules while delivering high-quality, durable buildings. Hoy Construction is dedicated to building strong partnerships and ensuring accountability and communication throughout the construction process - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Semgrep</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32439</link>
<guid>7b4e82cb855801d7098534835e2ca260</guid>
<pubDate>Fri, 22 May 2026 17:51:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Semgrep</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f44d7623c1932cf3291c103846508cafc51304657961bdf5886c14218cc942a6</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Function-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32436</link>
<guid>6c777229ea7df5098a0a57a29558ed31</guid>
<pubDate>Fri, 22 May 2026 15:49:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Function-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>18c958105d7d88d95c7f92523db555edefef28b26411843ca25cb8950d10bfa2</i><br /><br />Threat actor <b>description</b>: <i>Function Enterprises, Inc. is a trusted roofing company based in Springfield, VA, offering a range of services including roofing construction, commercial roofing, infrared inspection, and dumpster rentals. They prioritize client trust and satisfaction, providing a free one-hour consultation for new clients.We will upload corporate data soon. Employee personal information (passports, DLs), contracts and agreements, clients info, financials, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buffalo-Niagara-Convention-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32437</link>
<guid>3faebb27540633c9d2065e5131ddf2a5</guid>
<pubDate>Fri, 22 May 2026 15:49:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Buffalo-Niagara-Convention-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a548daa71b29f9145df648adbd3dff6c602025dc2945139fc692e5930374da35</i><br /><br />Threat actor <b>description</b>: <i>The Buffalo Convention Center is a premier meetings and convention space located in downtown Buffalo, NY, easily accessible from major interstate highways. It caters to event planners, exhibitors, and attendees, offering a beautiful venue surrounded by vibrant city life, including restaurants, shopping, and entertainment.We will upload 46gb of corporate data soon. You are going to get precious data. You will find employee personal information (passports, DLs), client and partners information (personal data of 180,000 people), contracts and agreements, financials, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Karlin-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32441</link>
<guid>840b3c96fad34c1bc64bb26038c3841e</guid>
<pubDate>Fri, 22 May 2026 15:20:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Karlin-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4a86e92e30d2ca1398cc432619b520ae83338e699567172cc24a21c67570f92</i><br /><br />Threat actor <b>description</b>: <i>Karlin Foods is a private label food manufacturer that offers a wide range of products includin
g potato and rice side dishes, skillet dinners, dips, sauces, and premium items.

We will upload corporate data soon. Employee and clients, contracts and agreements, financials,
projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Le-Pain-Quotidien-US</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32434</link>
<guid>5211bda24f5c44114c473a74b8bdf361</guid>
<pubDate>Fri, 22 May 2026 10:51:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Le-Pain-Quotidien-US</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0aeab7ad8e979d0c4bc96c7113e69f2249011713212c28e190b58085f24adba1</i><br /><br />Threat actor <b>description</b>: <i>Established in 1990 and headquartered in New York, New York, Le Pain Quotidien US is a chain of bakery restaurants specializing in baked goods, bread, salads, sandwiches, beverages, tartines, and more.</i><br />Target victim <b>website</b>: <i>lepainquotidien.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vernon--Ginsburg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32431</link>
<guid>be068d693cfefdf2afe808d90e2a9031</guid>
<pubDate>Thu, 21 May 2026 20:49:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Vernon--Ginsburg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>928238ab1a443a3bbbdf062d2311be96fe41fae89a2067191bbd8465c5b93118</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Snyder-Packaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32430</link>
<guid>bd91a434de99fb29e2a74a181f06560f</guid>
<pubDate>Thu, 21 May 2026 18:25:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Snyder-Packaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49b61fc8ebb02bf76efc6fef8734ff5cd92df8dd8c6c236996928c2130220ce3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.snyderpkg.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ungererandcompany.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32416</link>
<guid>496ad1139911eeb014d31dce575faa61</guid>
<pubDate>Thu, 21 May 2026 11:51:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>apt73/bashe</b> claims attack for <b>ungererandcompany.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee1a9d772d7531c4c79f4fbbf909cd20d46a62ea337aa22cdb004b0c9eadf1ec</i><br /><br />Threat actor <b>description</b>: <i>Ungerer & The Company is an American company founded in 1893 that develops and manufactures flavo...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>apt73/bashe</category>
</item>
<item xmlns:dc='ns:1'>
<title>Internal-Medicine-and-Pediatrics-of-Cullman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32421</link>
<guid>9191b0a3b4c41e6732dbb644bd52d6fc</guid>
<pubDate>Thu, 21 May 2026 10:26:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>Internal-Medicine-and-Pediatrics-of-Cullman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6860f8ba6b96dd49b912fd7b03e428eca49cc1abd1976fc82eac34663d582795</i><br /><br />Threat actor <b>description</b>: <i>Internal Medicine and Pediatrics of Cullman provides comprehensive healthcare services for families, focusing on both internal medicine and pediatrics. The practice is staffed by board-certified physicians dedicated to delivering high-quality care using modern medical equipment. They offer a range of services including preventative medicine, in-house lab and radiology, and same-day appointments.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>MBM-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32418</link>
<guid>b17817e6bd62910a6e9016c9a58ee9bb</guid>
<pubDate>Thu, 21 May 2026 09:53:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>MBM-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43487e26c8d6f160ccd6b282495d481cabf5c3bc35bb991cabef8ecb234c9ec0</i><br /><br />Threat actor <b>description</b>: <i>mbmcorp.com rocketreach.co/mbm-corp-profile_b5efe288f42e7251 MBM Corporation, founded in 1936 and headquartered in Charleston, South Carolina, is a trusted leader in professional print finishing and document security solutions. Renowned for Destroyit® shredders, Triumph™ cutters, and AeroCut® digital finishing systems, MBM empowers print shops and businesses with precision-engineered equipment backed by expert support and industry-leading warranties</i><br />Target victim <b>website</b>: <i>mbmcorp.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>YMCA-of-Columbia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32417</link>
<guid>12c7c68e4e25a6bb27bcdbccf500b5fd</guid>
<pubDate>Thu, 21 May 2026 09:53:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>YMCA-of-Columbia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f635be55b283e505cca269001593a7e89632fdf4946a29d1780fced37bba015d</i><br /><br />Threat actor <b>description</b>: <i>columbiaymca.org zoominfo.com/c/ymca-of-columbia/8912958 Founded in 1854, the YMCA of Columbia is a cornerstone charitable organization dedicated to building healthy spirit, mind, and body for all across South Carolina's Midlands. Through five community branches, they deliver impactful youth development, wellness programs, and social responsibility initiatives rooted in Christian values of caring, respect, and inclusion. Every day, the Y empowers neighbors of all ages and backgrounds to learn, grow, and thrive together</i><br />Target victim <b>website</b>: <i>columbiaymca.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hotelogix-Company-Hotelogix.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32415</link>
<guid>5003307d211c815c97cc8bada9c6edec</guid>
<pubDate>Thu, 21 May 2026 06:22:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shadowbyt3$</b> claims attack for <b>Hotelogix-Company-Hotelogix.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3cc866474d5b0a84543208ddee986e02071a58dc2670b4ebc21ef37437383c3</i><br /><br />Threat actor <b>description</b>: <i>Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed with payment but you decided to fuck around and you found out. Any company that contacts us because you had a warning or we leaked proof should look at what we got if your concerned then contact us for payment if everything matches up. It's that simple and don't think twice or it can lead to what happened with this company. Don't be like Hotelogix and wait till the last Minute. It's best to pay first to so you don't end up like these companies to name a few University Of Georgia, Hotelogix, starBucks, and more mega link conversations: https://mega.nz/file/mwAGQDaA#TX0wXzN2JmzehD1WxV234_QiHaK7AzSA1PumfWq_HCU</i><br />Target victim <b>website</b>: <i>Hotelogix.com</i>]]></description>
<category>shadowbyt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>StarBucks-Company-StarBucks.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32414</link>
<guid>5928ecabcdc8f26faaa44e79476af2f0</guid>
<pubDate>Thu, 21 May 2026 05:52:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shadowbyt3$</b> claims attack for <b>StarBucks-Company-StarBucks.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed24de8fc9dd6c9b435304783fb213405cef55da288ce2db890aeaee6796df16</i><br /><br />Threat actor <b>description</b>: <i>StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shadowbyt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Porter-W-Yett</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32412</link>
<guid>efc7802abcfcabf60cf5abe86e9b0465</guid>
<pubDate>Wed, 20 May 2026 20:25:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Porter-W-Yett</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04006a1f49c25f1ba938892b07a0f24a8eecc496fc53e24f8bdc81eb47d2ec74</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.porteryett.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WNS-Lowery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32409</link>
<guid>929ba3c615223cf7248590ae175fcce7</guid>
<pubDate>Wed, 20 May 2026 17:53:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WNS-Lowery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4065190ecac8a03fbecfa026992aace9e0aafcfedca8778f669ff4623476d3be</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cz-Collections</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32410</link>
<guid>10e8bd26bb63fead09767e79b7ee4326</guid>
<pubDate>Wed, 20 May 2026 17:53:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cz-Collections</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b029f8b49198d4c472b86559dfe809dfbafdf89494139191728e9399f611218</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CJ-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32411</link>
<guid>d3ac43d9713bf1e9d37a453da0385b3b</guid>
<pubDate>Wed, 20 May 2026 17:53:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CJ-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b73022e55510f14ae231e753870367cd4574a2061393ec7355dbe1e61ab0aa9e</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Air-Conditioning-Florida--Mrdsllc--RTE-Stucco--MR-Drywall-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32408</link>
<guid>a8fc21015db4f75ac1bc2269f1e2a58e</guid>
<pubDate>Wed, 20 May 2026 14:55:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Air-Conditioning-Florida--Mrdsllc--RTE-Stucco--MR-Drywall-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3629aab10eb122a8c25a9a49fe091e8bdfacb585fab3d1d0196c5d8a56c4a33</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.airconditioning-florida.com, www.mrdsllc.com, www.rtesllc.com, www.mrdrywallservices.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sid-Harveys</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32406</link>
<guid>50ff2b95b8b53b5f12b4dd19575edf62</guid>
<pubDate>Wed, 20 May 2026 13:52:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sid-Harveys</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16a29999d423f4dbe42f7444d7573367e022afe1436e6ac377476b0d851482e4</i><br /><br />Threat actor <b>description</b>: <i>Sid Harvey Industries is a wholesale distributor of refrigeration, air conditioning, and heatin
g equipment and parts for contractors in the United States.

We will upload 740gb of corporate data soon. Detailed employee personal information (~500 ppl p
assports, DLs, SSNs, personal financials, death certs, confidential agreements, credit cards an
d so on), contracts and agreements, financials, clients and partners, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pro-Farm-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32405</link>
<guid>3cab6b8b2708f469275039d7ad17380c</guid>
<pubDate>Wed, 20 May 2026 13:25:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Pro-Farm-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d4d0ab5968931c06d43486a872e0feff5369f565cf6266c88da6ac6f07ca25f</i><br /><br />Threat actor <b>description</b>: <i>Experts at discovering, developing, and commercializing naturally derived technologies</i><br />Target victim <b>website</b>: <i>profarm.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fana-Jewelry-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32404</link>
<guid>bde4a681eceb6f2c6d01c533b80a7a6e</guid>
<pubDate>Wed, 20 May 2026 13:25:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Fana-Jewelry-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed9cafeca550ffcfccb2e35a889e038f325f1ffc9e545cc98d3567619e3c8b40</i><br /><br />Threat actor <b>description</b>: <i>Crafting jewelry for countless generations</i><br />Target victim <b>website</b>: <i>fanajewelry.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indian-Creek-Valley-Water-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32403</link>
<guid>3e24e1901a29469d0f6060cb1324482c</guid>
<pubDate>Wed, 20 May 2026 13:25:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Indian-Creek-Valley-Water-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>caf20ae3aa321fda5f9794008f5859e7c50ea8024f349e1c0ab93937498837b8</i><br /><br />Threat actor <b>description</b>: <i>Indian Creek Valley Water Authority</i><br />Target victim <b>website</b>: <i>icvwater.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vega</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32401</link>
<guid>f454a7da12c2fbfc12dae505f59f304b</guid>
<pubDate>Wed, 20 May 2026 12:53:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Vega</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31bd6cd2936478ee252a7442cf273534f20d57585b61f7ccf7d10964f75fd7de</i><br /><br />Threat actor <b>description</b>: <i>Vega combines elite technical skills with personalized customer service and environmental stewardship to excel in the industrial and manufacturing sector. From the loading docks through the warehouse, assembly line, raw product processing, storage, distribution and into the administration areas, the company's work is designed to support the company's customer's operations in the production of everything from fabrication to perishables. "I/the company continue to use Vega not because the company has to but because the company want to. Vega brings a lot of knowledge and experience with them to the table and adds a great amount of value to the company's projects. The company value the company's relationship with them and expect it to continue for a long, long time</i><br />Target victim <b>website</b>: <i>vega-corp.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>TAURUS-INVESTMENT-HOLDINGS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32397</link>
<guid>65d6b3b69c9122e98cfb9c6487f8438c</guid>
<pubDate>Tue, 19 May 2026 19:57:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>TAURUS-INVESTMENT-HOLDINGS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fb8dbd55166ce1a52be1eea6ca1c4c4511068e7b389bb7daf62916a5d54fc20</i><br /><br />Threat actor <b>description</b>: <i>Established in 1976, Taurus is a global real estate private equity firm with over 40 years of experience as a general partner, investor, and operator. Currently...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>TSG-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32393</link>
<guid>dfaf0f333b6b70de28eaf291774d94db</guid>
<pubDate>Tue, 19 May 2026 16:57:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TSG-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99667a40c03877135f040a47c590d50337558c5c687bc0bd301b9cbd0504390c</i><br /><br />Threat actor <b>description</b>: <i>TSG Enterprises, LLC empowers entrepreneurs and businesses through expert consultations, strategic guidance, and customized solutions. Their mission is to provide the knowledge, resources, and innovation essential for thriving in today's market. The company focuses on building strong partnerships that drive growth and support long-term success, enabling clients to achieve theirgoals with clarity and confidence.We will upload 18gb of corporate data soon. Detailed employee and clients personal information (name, addresses, SSN numbers, DLs and passport scans), contracts and agreements, detailed financials, NDAs and other confidential docs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barclay-Damon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32395</link>
<guid>f08bc848e028e7f9d65567f2ddc15951</guid>
<pubDate>Tue, 19 May 2026 16:51:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Barclay-Damon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9162e6217817a793ba44dea6451b672a355bbfd3d12a824c794e781c7cb36f88</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Barclay Damon is a full-service law firm headquartered in the United States, with offices across New York and other northeastern states. The firm operates in the legal services industry, providing counsel in areas including business law, litigation, real estate, healthcare, energy, and public finance. It serves clients ranging from businesses and municipalities to individuals, offering both transactional and dispute resolution services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>harrisoncountywv.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32373</link>
<guid>bf9b2fc7786695d23d420b323f28c613</guid>
<pubDate>Mon, 18 May 2026 20:24:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>harrisoncountywv.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>618502c461383498c43bffd9022b29c17850016541a24b2feb4afe5ed8a0eb2f</i><br /><br />Threat actor <b>description</b>: <i>The Commission functions as the executive administrative body for the county and is responsible for overseeing public infrastructure, fiscal management, …</i><br />Target victim <b>website</b>: <i>harrisoncountywv.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vantage-Energy-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32367</link>
<guid>403ce9727d471b1f704be4396af294ac</guid>
<pubDate>Mon, 18 May 2026 18:55:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Vantage-Energy-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d625ca7ab4f6f8ae6cb9fd499800e36c855183eba553b1c9b80fc599191d3aa0</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.vantageenergy.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Internal-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32364</link>
<guid>d89775f1bee30df5043cf5673a197ce0</guid>
<pubDate>Mon, 18 May 2026 18:54:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Internal-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4951b44921f8fdc179f542f212a16d8918a242aa7ea957ad4e119f46a2b838f7</i><br /><br />Threat actor <b>description</b>: <i>internalmedicineofswf.com zoominfo.com/c/internal-medicine-of-southwest-florida/559515842 a private, physician-owned primary care practice founded in 1998 and located in Fort Myers, FL . The site provides patient resources, contact information, office hours, and details about their proactive, preventative healthcare services. They focus on quality, patient-centric care for both wellness visits and urgent medical needs</i><br />Target victim <b>website</b>: <i>internalmedicineofswf.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>E-Control-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32361</link>
<guid>ea7fe912d5c09bd9597f4b03217e8fff</guid>
<pubDate>Mon, 18 May 2026 18:54:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>E-Control-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0fe7a53141813a1185ffb2b43853142ccf2effe6efa69862cacb129fcab20a3e</i><br /><br />Threat actor <b>description</b>: <i>econtrolsystems.com zoominfo.com/c/e-control-systems-inc/34461104 E-Control Systems is a California-based technology leader founded in 1998, specializing in IoT-powered wireless temperature monitoring solutions for critical environments. Their turnkey FusionLive™ platform delivers real-time alerts, cloud-based dashboards, and regulatory compliance tools for food service, healthcare, life sciences, and retail industries. With 5,000+ installations nationwide, ECS combines custom-engineered hardware and intuitive software to safeguard products, ensure safety standards, and streamline operations 24/7</i><br />Target victim <b>website</b>: <i>econtrolsystems.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Modern-Display</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32359</link>
<guid>6ffbb022729a7e0f41cf74c280927314</guid>
<pubDate>Mon, 18 May 2026 18:53:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Modern-Display</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>379814c63b365d9d9859540d19b5b5bd03017fc24eeaff554de82b6377118ad8</i><br /><br />Threat actor <b>description</b>: <i>moderndisplay.com zoominfo.com/c/modern-display/25347032 odern Display is a beloved family-owned retail destination in Salt Lake City, Utah, founded in 1946 and specializing in seasonal décor, holiday treasures, and home accents. With 150+ team members and a 300,000 sq. ft. facility, they offer everything from Christmas trees and patriotic flags to floral arrangements and parade float supplies. Beyond retail, they power expo services, wholesale floral, and graphic design—helping customers celebrate life's special moments with beauty and joy for nearly 80 years</i><br />Target victim <b>website</b>: <i>moderndisplay.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huse-Incorporated</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32357</link>
<guid>3e43837dc774ebfbd1ccc4801237041d</guid>
<pubDate>Mon, 18 May 2026 18:24:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Huse-Incorporated</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed8cc3d08f1abb9b3d5963c8ba12fea77fe1172e24762d99a9e863321ca96f1e</i><br /><br />Threat actor <b>description</b>: <i>- MSSQL-DB- HR Documents- Contracts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>DFI-AMERICA-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32353</link>
<guid>0028a24e18e166c292689023e6c22e09</guid>
<pubDate>Mon, 18 May 2026 17:58:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>titan</b> claims attack for <b>DFI-AMERICA-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad00e3a3d12d44b5da20c8d778c6edb64ed1c66092da95eb05c9ccb0b55c99cb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] DFI AMERICA, LLC is a U.S.-based company operating in the financial services and investment industry. It functions as an American subsidiary or affiliate of a broader financial group, providing investment advisory, asset management, and related financial services. The company operates within the United States and serves institutional and corporate clients, supporting capital markets and financial consulting activities in North America.</i><br />Target victim <b>website</b>: <i>www.dfi.com</i>]]></description>
<category>titan</category>
</item>
<item xmlns:dc='ns:1'>
<title>ETM-ELECTROMATIC-INC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32350</link>
<guid>7f945d34e708a2a6a192697de248fd77</guid>
<pubDate>Mon, 18 May 2026 17:56:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>titan</b> claims attack for <b>ETM-ELECTROMATIC-INC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddbb6cdc01176b1408badc07185a18a1a7518c4774fdf044a7dd79d20265d07f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] ETM-Electromatic, Inc. is a U.S.-based company specializing in the design and manufacture of electronic and electromagnetic equipment. The company operates in the defense and industrial electronics sector, producing products such as traveling wave tubes and related microwave power modules used in radar, electronic warfare, and communications systems. It serves government, military, and commercial clients primarily within the United States.</i><br />Target victim <b>website</b>: <i>www.teledyneetm.com</i>]]></description>
<category>titan</category>
</item>
<item xmlns:dc='ns:1'>
<title>Healthtrax-Fitness--Wellness</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32345</link>
<guid>2877b49ebb731389a1a583bda03540bd</guid>
<pubDate>Mon, 18 May 2026 13:50:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Healthtrax-Fitness--Wellness</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0036021d030d532723563e5d33cab938dddce355801d436a7b0e95cd4994774d</i><br /><br />Threat actor <b>description</b>: <i>Healthtrax, founded in 1979 and headquartered Glastonbury, CT, offers facilities and programs t
hat integrate fitness, wellness education, traditional medical services and rehabilitation. Hea
lthtrax forms partnerships with leading health care systems to create a welcoming, centralized 
place for members of the community to achieve their personal fitness and health goals.

We will upload 10gb of corporate data soon. Employee and clients personal information (name, Dl
and passport numbers, SSNs), contracts and agreements, personal records, financials, NDA and o
ther confidential docs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Design-Engineering--Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32342</link>
<guid>06ef2caafa6e7dff1bb9e4a480ded51f</guid>
<pubDate>Mon, 18 May 2026 10:50:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Design-Engineering--Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ee7cc41b45f17fe5c1d8ac45671f38cf46040771930fe2dc163da7e17d95ab8</i><br /><br />Threat actor <b>description</b>: <i>Design Engineering & Consulting provides façade system design, shop drawings, engineering, and consulting services in a cost – effective and professional manner across the world.</i><br />Target victim <b>website</b>: <i>decusa.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>bergen1.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32338</link>
<guid>5f9491903a313d3a99f8f9bb101d1b89</guid>
<pubDate>Mon, 18 May 2026 01:22:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>bergen1.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71b63c5e05fb9847b3ec8d637fe4a8b74abe7ad1c180fefb30d2766107b3f03b</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1965, Bergen Community College is a comprehensive higher education institute that offers academic degree programs to students. Bergen Community College is located out of Paramus, New Jersey  We will publish all the data(1TB) in a week</i><br />Target victim <b>website</b>: <i>bergen1.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>challenge-mfg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32337</link>
<guid>93c89a4b9cb44ca5abe30785d226d695</guid>
<pubDate>Sun, 17 May 2026 19:52:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>challenge-mfg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d94302e0042cc228a0c7019be79dee5d9d9347e54da4d1b9b348f893fbf54cd8</i><br /><br />Threat actor <b>description</b>: <i>Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out.

Challenge Manufacturing is a leading Tier 1 automotive sup…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/challenge-manufacturing-co/1137810885</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>wtitransport.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32336</link>
<guid>9917c3b8ac1b209796960d2a2f0f7931</guid>
<pubDate>Sun, 17 May 2026 19:51:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>wtitransport.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bde6d4fb114ca19aea46f1378c067ea0866ed7fad98508a3c76bdd6b60d997e6</i><br /><br />Threat actor <b>description</b>: <i>Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out.

WTI Transport is a flatbed trucking company headquartered…</i><br />Target victim <b>website</b>: <i>www.wtitransport.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>cstindustries.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32335</link>
<guid>74061f08793737e9374dd85cd2233d3c</guid>
<pubDate>Sun, 17 May 2026 19:51:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>cstindustries.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5d8ae5ec1f26bcc0bba28f2147620285649d0732a3a49c6a89f168b20f098ad</i><br /><br />Threat actor <b>description</b>: <i>Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out.

Founded in 1893, CST is a manufacturer and construction co…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/cst-industries-inc/28282428|</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>fallprotect.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32334</link>
<guid>fddb49982f360e8a94aa8642ed545a16</guid>
<pubDate>Sun, 17 May 2026 19:50:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>fallprotect.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af5ca961e769ab2094a855aa24b2327fa5347207ca042c41c3ed6bdf586cb187</i><br /><br />Threat actor <b>description</b>: <i>Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out.

Diversified Fall Protection specializes in the design, fab…</i><br />Target victim <b>website</b>: <i>www.fallprotect.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buckeye-Paper</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32333</link>
<guid>ec43638b66e16a5bbede9b710b12b0c7</guid>
<pubDate>Sun, 17 May 2026 18:25:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Buckeye-Paper</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e8d4205cfe871aacbdb08a48b434fbf98636e76029eff19bc6a9e4dce92f45e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.buckeyepaper.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Taylor-Provisions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32330</link>
<guid>0507ea3f897987f62fc8619ae288236f</guid>
<pubDate>Sun, 17 May 2026 17:53:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Taylor-Provisions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1252a3c5478d016d708ee7a614004636a882fed7c4866b6c1aaa80484f586b07</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.originaltaylorporkroll.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>soft-inc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32323</link>
<guid>5f6eb0809f31e88067e51bfd2bb0c50e</guid>
<pubDate>Sun, 17 May 2026 14:53:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>soft-inc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>315c68ad66d1150007bc150399932d5f4a264748a1b26c71833f9d2c8ea4f4a4</i><br /><br />Threat actor <b>description</b>: <i>+1 212-633-1515. SOFT Inc. is an established American technology consulting and professional staffing firm founded in 1981 and headquartered in New York City. The company specializes in building critical technology solutions, IT services, and supplying top-tier engineering and technical talent for Fortune 500 companies across the United States Stolen: 49.8gb 9289 files</i><br />Target victim <b>website</b>: <i>soft-inc.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Holy-Name-of-Jesus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32318</link>
<guid>e5f6c8ca67571d3496e7e6609a197521</guid>
<pubDate>Sun, 17 May 2026 13:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Holy-Name-of-Jesus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f81f437a8e5ac36d5d1500b022573ff58eb1aaa6288ac7402083947966af32b2</i><br /><br />Threat actor <b>description</b>: <i>The Holy Name of Jesus Catholic Community is a Roman Catholic parish located in Redlands, California, serving over 3,500 families from 14 cities in the East Valley and Banning Pass area. The community focuses on glorifying Christ’s Holy Name by inviting, nourishing, and forming disciples to share the Gospel through prayer, service, and financial support. They offer a variety of worship services, sacraments, and faith programs for all ages, including youth and adult enrichment. The parish is committed to building a future home for their community and engaging in social concerns and creation care initiatives.</i><br />Target victim <b>website</b>: <i>www.theholynameofjesus.org</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trivantage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32313</link>
<guid>ed1c1607401e06c70d9e92918ddd9934</guid>
<pubDate>Sat, 16 May 2026 21:50:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Trivantage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>873bacee65731c532a8401cb812b6409c1dfef371a50c30d002512732e909b37</i><br /><br />Threat actor <b>description</b>: <i>Trivantage is a wholesale supplier specializing in awning, marine, and upholstery fabrics, offering over 9,000 products for makers. The company provides built-for-purpose materials and hardware for shade systems, durable materials for custom marine builds, and stylish furnishings. With a commitment to customer success, Trivantage ensures quick delivery, dedicated expert help, and exclusive benefits through its Trivantage Plus membership. Their extensive selection and reliable service make them a trusted partner for businesses in need of quality supplies.</i><br />Target victim <b>website</b>: <i>www.trivantage.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>RAMAR-FOODS-INTERNATIONAL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32311</link>
<guid>081858e42df3e2ac683f842e34831256</guid>
<pubDate>Sat, 16 May 2026 18:54:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>RAMAR-FOODS-INTERNATIONAL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a10fd8c6ef98e3236b5b43cb30adc0819b7fe76c0036f87ca05636a8584b0eb5</i><br /><br />Threat actor <b>description</b>: <i>Ramar Foods is a leading manufacturer and distributor of Filipino frozen food products, established in 1969. The company is committed to bringing the flavors of the Philippines to consumers through its portfolio of brands, which include iconic offerings like Magnolia, Orientex, Manila Gold, and Frescano.
</i><br />Target victim <b>website</b>: <i>www.ramarfoods.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ross-Yerger-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32310</link>
<guid>0183e4f6ecf3efd66438a27cb4ec2d68</guid>
<pubDate>Sat, 16 May 2026 18:00:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Ross-Yerger-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a40bf1bde50c9c2ef0db1c5f204954550381516bc365d6958f4b01243de0662e</i><br /><br />Threat actor <b>description</b>: <i>rossandyerger.com zoominfo.com/c/ross--yerger-insurance-inc/101253758 Ross & Yerger is an employee-owned independent insurance agency founded in 1860, specializing in personalized risk management and insurance solutions for businesses and individuals. Their "Lighthouse" approach offers holistic protection beyond traditional policies, prioritizing client needs over shareholders. With a culture centered on relationships, community, and expertise in sectors like oil & gas and construction, they help clients protect what matters most</i><br />Target victim <b>website</b>: <i>rossandyerger.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>AdvancedHEALTH</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32305</link>
<guid>16f541b005e91cd15bf516c1961ea0b0</guid>
<pubDate>Sat, 16 May 2026 11:52:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>AdvancedHEALTH</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26c07960436de341e303938ce35eb754a11b0776d6ac9bd32dd4a50db9a08c01</i><br /><br />Threat actor <b>description</b>: <i>The leak contains 2,300,000 Lines of FULL patient data, partner agreements, management, payroll and HR files.
Screenshot attached :)

We Will Leak 1,000 Lines o...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Turner-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32302</link>
<guid>d3102a0b7413aa55427210bbd83624b4</guid>
<pubDate>Fri, 15 May 2026 22:52:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Turner-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddae4889daf3171930c16c89cea107ff8630800926d8e794f8f6fdcf303dab0a</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zywave</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32304</link>
<guid>87d76d9c72d0b437182d4c27536b43c2</guid>
<pubDate>Fri, 15 May 2026 20:57:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Zywave</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdd92b59deea4b58d7ec263d2c845a54237ace5ec85107a59ea04097bdb73181</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Zywave is a US-based software company headquartered in Milwaukee, Wisconsin. It operates in the insurance technology sector, providing cloud-based software solutions to insurance brokers, carriers, and agencies. Its platform offers tools for sales enablement, client delivery, analytics, and agency management. Zywave serves thousands of insurance professionals across North America, helping them streamline operations and improve client engagement.</i><br />Target victim <b>website</b>: <i>zywave.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grafana</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32303</link>
<guid>25cd125f8916019a9d5909d771fdef61</guid>
<pubDate>Fri, 15 May 2026 20:57:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Grafana</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>570635f005259b2fdeab0d6e300bbcc3bf7a8b30f0a4e2b40b0a0f6cc53f260a</i><br /><br />Threat actor <b>description</b>: <i>We can cause you more damage then you would ever imagine,contact us.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>LeRoy-Surveyors--Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32297</link>
<guid>c52376a1820e868235b1851b87492a39</guid>
<pubDate>Fri, 15 May 2026 17:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>LeRoy-Surveyors--Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e299c59a73aa4ecca70e15de029a489419e39557c3be1f2a3b84dbda77d1090</i><br /><br />Threat actor <b>description</b>: <i>LeRoy Surveyors & Engineers, INC. specializes in property boundary surveying, topographic surveys, and subdivision surveys, primarily serving clients in the Puyallup area. With a commitment to quality and a history of excellence since 1958, they provide comprehensive surveying and engineering services to both public and private sectors. Their expertise includes civil engineering, geotechnical services, and environmental engineering, ensuring compliance with local regulations and effective project planning. The company aims to support architects, engineers, developers, and municipalities in making informed decisions about land development.</i><br />Target victim <b>website</b>: <i>lseinc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Raise-the-Bottom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32296</link>
<guid>936a96a77c3eca882a69ec04c94372b4</guid>
<pubDate>Fri, 15 May 2026 17:50:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Raise-the-Bottom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb4486ce5d80f9b98132befc90a7b0334f8770a8b5ac83bdb106e71e6efab212</i><br /><br />Threat actor <b>description</b>: <i>Raise The Bottom is an opioid treatment center in Idaho, offering outpatient medication-assisted treatment (MAT) programs and therapy. The center provides services including Suboxone, Methadone, and Vivitrol, with locations in Boise, Nampa, and Pocatello. Their mission is to support Idaho residents in reclaiming their lives from opioid addiction through comprehensive care that involves family and community. With a focus on personalized treatment and a whole-person approach, Raise The Bottom aims to foster lasting recovery and stability for individuals and their families.</i><br />Target victim <b>website</b>: <i>www.raisethebottomidaho.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Common-Part-Groupings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32293</link>
<guid>ae482b6bae6b28e5f1631932d6e5c382</guid>
<pubDate>Fri, 15 May 2026 16:54:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Common-Part-Groupings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de9ecb31fd31883c0154244949fb6b4c28c9425104a55fab5bbaf4d85e4e08f7</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.commonpartgroupings.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Foot-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32292</link>
<guid>ee90b45cf1106fef95ee81de63d7a322</guid>
<pubDate>Fri, 15 May 2026 16:54:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Foot-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>705a6b2a507f719b6a53bfb8e5fb544c86136fac0e00f7308e0ada013c6eeeac</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.footsolutions.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Medical-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32291</link>
<guid>37e0eaaff0973a8ab20092edeacf2ff0</guid>
<pubDate>Fri, 15 May 2026 16:51:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Advanced-Medical-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f83dca9e9c66227a506a33bd949e3744449f995e598e36fcfe852f59b008020</i><br /><br />Threat actor <b>description</b>: <i>The leak contains 2,300,000 Lines of FULL patient data, partner agreements, management, payroll and HR files.
Screenshot attached :)

We Will Leak 1,000 Lines of patient data a day, until we've been paid or the timer hits 0. Check this description for Fresh leaks everyday.

Day 1 :  https://temp.sh/aLnBB/ADI-Day1.zip</i><br />Target victim <b>website</b>: <i>ouradvancedhealth.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fox-Valley-Tax-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32290</link>
<guid>613594054b1f1c7911d9f9fc9c795477</guid>
<pubDate>Fri, 15 May 2026 15:50:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fox-Valley-Tax-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6abe64995db55bd2a4fdd1e74d6006b91e5d4e6dd986f3be1c0d952c7e1c6013</i><br /><br />Threat actor <b>description</b>: <i>Fox Valley Tax Solutions is a full-service tax firm located in Saint Charles, Illinois, special
izing in personalized tax preparation and strategic planning services. They cater to individual
s, businesses, trusts, and estates, offering a range of services including tax consultation, IR
S issue resolution, and notary services.

We will upload 95gb of corporate data soon. Detailed client personal information (passports, DL
s, SSNs, financial information), contracts and agreements, NDAs and other confidential docs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>McCarthy-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32288</link>
<guid>68f8b8440b1eb96b97995c5efb6856a9</guid>
<pubDate>Fri, 15 May 2026 14:24:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>McCarthy-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27cf66a4f869438e8a03284b3169da9a63bbeedeed5ca1dbad2a4b420cbd915f</i><br /><br />Threat actor <b>description</b>: <i>McCarthy, Inc., based in Savannah, Georgia, has been providing quality doors, frames, hardware, and related products since 1955. The company specializes in metal and wood doors, including architectural-grade flush doors and custom stile and rail units, along with a variety of specialty items. McCarthy, Inc. offers comprehensive services from project inception to completion, aiming to build lasting relationships with clients across various industries such as healthcare, education, and hospitality. Their commitment to customer satisfaction is reflected in their extensive product offerings and dedicated service.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>defenseisready.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32287</link>
<guid>358680ef4f169bc21f0eec123b85119d</guid>
<pubDate>Fri, 15 May 2026 14:23:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>defenseisready.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2291a191a8e7730c7e7afd0a3733d31a4a1b012ef26550ae918f88cd008c1498</i><br /><br />Threat actor <b>description</b>: <i>Deandra Grant Law is a Texas criminal defense and DWI firm with a practice exclusively concentrated on DWI, federal and criminal defense. The firm has defended clients across North and Central Texas for more than 30 years, with more than 500 cases tried to verdict.</i><br />Target victim <b>website</b>: <i>defenseisready.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>lafj.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32285</link>
<guid>1e4e35498ab5ae64e2c32576328487ba</guid>
<pubDate>Fri, 15 May 2026 12:23:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>lafj.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>339bff0315c68dcc45226ea8215b05883a721b64078eebfc4ba24dedfc442523</i><br /><br />Threat actor <b>description</b>: <i>Louisiana Association for Justice is a voluntary bar association whose statewide membership is composed mostly of lawyers who have a trial practice. Both defense and plaintiff attorneys belong to the association; however, most LAJ members represent consumer plaintiffs in civil actions. LAJ attorney-members are small business owners, maintaining a practice and supporting an office staff of fewer than 20 people.Customer data, contracts, payment documents, internal company documentation.</i><br />Target victim <b>website</b>: <i>lafj.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>WholeHealth-Chicago</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32284</link>
<guid>285c44427d4b422ed19d9ea061943a12</guid>
<pubDate>Fri, 15 May 2026 11:50:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>WholeHealth-Chicago</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e11710afefe9c280c73c13e9cfb3ae3ec5a79bfb9bd306ec62730a54690a28fb</i><br /><br />Threat actor <b>description</b>: <i>WholeHealth Chicago is a leading healthcare practice specializing in integrative, functional, and alternative medicine. They offer a wide range of services including internal medicine, chiropractic care, nutritional counseling, and various therapies aimed at promoting overall health and well-being. Their intended clients include individuals seeking personalized and holistic approaches to health, particularly those interested in combining conventional and alternative treatments. The practice is known for its patient-centered care, where providers work collaboratively with patients to develop tailored treatment plans.</i><br />Target victim <b>website</b>: <i>www.wholehealthchicago.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Quality-Cooperative--www.uqcoop.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32279</link>
<guid>f4667a2fccf527dad06cc706baf81a70</guid>
<pubDate>Fri, 15 May 2026 01:23:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>United-Quality-Cooperative--www.uqcoop.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45133ddd027b92640ba3ba5e98cfa79a43c5e3badf27e6401bee48ff2d4d0f8b</i><br /><br />Threat actor <b>description</b>: <i>United Quality Cooperative provides a range of services including bulk fuel, propane, lubricants, and agricultural products.  We have at our disposal internal corporate correspondence, financial documents, personal data of company employees and much more.  All stolen information will be published in the public domain in a week, if the company's management does not pay.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Houston-Eye-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32278</link>
<guid>8e1ba2fadecb9dc939750d1104c8a7f2</guid>
<pubDate>Thu, 14 May 2026 20:20:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Houston-Eye-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>478f8507c2525b64fb69d20c637c4c069c35433c58aaba73e4372443fa50e307</i><br /><br />Threat actor <b>description</b>: <i>Houston Eye Associates is a team of board-certified ophthalmologists and board-licensed optometrists with advanced fellowship and specialty training in the fields of ophthalmology and optometry. With 20 locations across Greater Houston, there is a location near you.</i><br />Target victim <b>website</b>: <i>www.houstoneye.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ellucian-PowerCampus-Warning-Contact-Us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32276</link>
<guid>b12b646e693cbf411f8eaae5204ffdfe</guid>
<pubDate>Thu, 14 May 2026 16:48:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shadowbyt3$</b> claims attack for <b>Ellucian-PowerCampus-Warning-Contact-Us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9dbce14775591a70a51c86f72db6e3a5b246f2bb958159a6d231b36ca64f73ff</i><br /><br />Threat actor <b>description</b>: <i>This is a warning for ellucian PowerCampus. Due to not people paying much for are breach we will give you 48 hours to contact us. If you don't it will get published instead of sold. To all researchers to verify the data is real you can go to the mega.nz leak below. Also we put 2 reports from 2025 and 2026 for a sample. Due to company not contacting us it would be great if you could let them know so there aware. You have till May 20th to contact us and reach an agreement or all data gets leaked and posted. mega.nz: https://mega.nz/folder/f8B2QKAI#WC6QVl2VmhgP_PWR6DsUUw also the link below is for all affected schools and how to access tor and download tor for companies. https://telegra.ph/All-The-affected-Schools-By-Ellucian-PowerCampus-and-how-to-download-and-use-tor-browser-05-14</i><br />Target victim <b>website</b>: <i>ellucian.com</i>]]></description>
<category>shadowbyt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stride-Learning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32275</link>
<guid>4c9f17e01c03106d9117905e58eb0951</guid>
<pubDate>Thu, 14 May 2026 16:47:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shadowbyt3$</b> claims attack for <b>Stride-Learning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e9322d5185b370361e15aebcd7917d907e1b1ad8e312ae31fa2d5737d144fcd</i><br /><br />Threat actor <b>description</b>: <i>Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's not that hard. This is a warning to all companies that if you don't pay it will get leaked. If you pay you have are word that it's deleted also with a picture before and after. If you want we will also take a video.</i><br />Target victim <b>website</b>: <i>stridelearning.com</i>]]></description>
<category>shadowbyt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-Of-Georgia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32273</link>
<guid>01065cc12a9d7a950be0386ba0e43157</guid>
<pubDate>Thu, 14 May 2026 16:47:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shadowbyt3$</b> claims attack for <b>University-Of-Georgia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ac104dfad4a4ff110e982f3d27acf978e801e6983d7ebe68f0a57174f040b7b</i><br /><br />Threat actor <b>description</b>: <i>ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approximately 3.2 MB in raw text files. No customers were affected just exployees the following was stolen. - Physical Locations: Home addresses (like the Columbus, GA residential home) and specific office numbers (like Office 2207). - Private Contact Info: Personal cell phone numbers and home phone numbers (e.g., the 404-736-xxxx). - Employee Information: This often includes full names, contact details, and institutional identification photos. - Project Documentation: Information regarding internal university projects, including tracking logs and administrative data for various departments. - Workforce Data: Internal metadata such as position numbers, departmental assignments, and work schedules. - Technical Details: Notes regarding system maintenance and development that could potentially highlight internal processes - Critical Infrastructure: Active project maps for GEMA (Emergency Management), Georgia Broadband, and GDOT (Transportation) through 2026. - Government Records: Access to Asset Forfeiture logs and County-level GIS (Athens-Clarke, Bibb) that underpins 911 dispatch and land taxes. - Leadership Secrets: The UGA Office of the President Mail Tracker and Gov360 anonymous executive coaching logs. - The "SME" Map: we have identified the "Subject Matter Experts" like Noah Abouhamdan, Chad Rupert, and Pat Russell. we know exactly how many hundreds of hours these people have spent on specific pieces of code. - Security Clearances: we know who is a "Benefited" full-time employee (high-value target) versus a "Student Assistant" (low-value entry point).</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shadowbyt3$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fab-Masters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32269</link>
<guid>8158fa3e4de806e614f7ff02e7b22fde</guid>
<pubDate>Thu, 14 May 2026 11:54:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Fab-Masters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b68cdeb79cc276bc0b5271cbe6a635d946679e7e768e8c53820053584614a46</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.fabmastersinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>technic.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32268</link>
<guid>e2d83dd47948dde10750f0b7031dcb5e</guid>
<pubDate>Thu, 14 May 2026 11:20:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>technic.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>788ef2f608f0d7656e9684cb0f76f5a01b372a852e39c02cb17468fcc41a1271</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1944 and headquartered in Woonsocket, Rhode Island, Technic Inc. is an international supplier of electroplating chemicals and equipment.</i><br />Target victim <b>website</b>: <i>technic.com</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ira--Larry-Goldberg-Coins--Collectibles</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32265</link>
<guid>d4debfe3d5694f7b8a997233f02f3273</guid>
<pubDate>Thu, 14 May 2026 08:20:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Ira--Larry-Goldberg-Coins--Collectibles</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>523a3baba6f5f08cb86ae3a58a9699244fdaf67fae0d2ecbbe53b697da07f465</i><br /><br />Threat actor <b>description</b>: <i>Goldberg Coins & Collectibles Inc. is a family-owned business specializing in numismatic auctions and collectibles, with a legacy dating back to 1930. The company offers expert auction services, personal consultations, and has a strong reputation for achieving record-breaking prices for consignors. Their intended clients include coin collectors and investors looking to sell or acquire high-quality numismatic items. With over 80 years of combined experience, Ira and Larry Goldberg provide a professional and personalized service, ensuring client satisfaction and exceptional results.</i><br />Target victim <b>website</b>: <i>www.goldbergcoins.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>dsdlawfirm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32264</link>
<guid>4ddd8fd5a3e8489671ff1733c1dd0eae</guid>
<pubDate>Thu, 14 May 2026 02:53:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>dsdlawfirm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24623bb402d957a63f52abb8f515b18c6db405c314e23bd7c66345803080885d</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>example.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>John-G-Yphantides-A-Professional-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32249</link>
<guid>524e7d08e755cc664226b3d4b8660cd7</guid>
<pubDate>Wed, 13 May 2026 19:52:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>John-G-Yphantides-A-Professional-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfad1f77feb87d8bc373bac4a93e630b44d1c125c2755445ed62d5ac3d6cc602</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brand-X-Hydrovac-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32250</link>
<guid>8e601923e77ae1ddf71ec316a9ddefc7</guid>
<pubDate>Wed, 13 May 2026 19:52:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Brand-X-Hydrovac-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>105782867a0ab1ea6ccbb3601a2abae42f7775746b0e20ebf6bd9489ab34e5eb</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>LTJ-Industrial-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32251</link>
<guid>4533c3b629f51a3e981e909506c0b5cc</guid>
<pubDate>Wed, 13 May 2026 19:52:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LTJ-Industrial-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>949f6b217196264a47bef2117573223e51750781e3b2dae2de2e31b4c1b76376</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Johnson-Carter-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32252</link>
<guid>2bae3b53c279ec401567724ae89d6c4b</guid>
<pubDate>Wed, 13 May 2026 19:52:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Johnson-Carter-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>221bc906ee104c892709c5158392843e82f47f092e344762a5d848f051dae581</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spirit-Medical-Transport</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32260</link>
<guid>884738b4332ababd678ca505f4e04f4d</guid>
<pubDate>Wed, 13 May 2026 18:25:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spirit-Medical-Transport</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39f23d67b49ebf573226b2744b57f37490efda310e85235d9597566f9732628b</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.spiritmedicaltransport.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mayer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32259</link>
<guid>e3f13b88bedd3f0c9346814b957bb0f9</guid>
<pubDate>Wed, 13 May 2026 18:24:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mayer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb3a47e7a2007a6cebab8daa41faee03edff13cfc4745d4445e6e5389f73ce1d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mayerllp.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MicroMarketing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32256</link>
<guid>139ccdbf5a1b8401e93441d7f174ad00</guid>
<pubDate>Wed, 13 May 2026 17:53:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>MicroMarketing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7977c83b69ee83f206ed589697f5177dda608bde4088fc9fb8156b76823df9b7</i><br /><br />Threat actor <b>description</b>: <i>MicroMarketing specializes in expert title selections for books, audio CDs, and DVDs, catering primarily to librarians and libraries. The company is known for its personalized service, ensuring that clients receive timely and efficient support without automated responses. They offer valuable services such as downloadable invoices and MARC records, along with a strong price-value proposition. MicroMarketing's commitment to quality and customer satisfaction has garnered positive testimonials from clients who appreciate their reliable and responsive service</i><br />Target victim <b>website</b>: <i>micromarketing.org</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Belz-Institutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32248</link>
<guid>2462b9b1bd83b589c5b262d72a395c4f</guid>
<pubDate>Wed, 13 May 2026 16:54:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Belz-Institutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce2c2243bb16105e6777476ffa7814c444b1db92fb9a072d4599cccf76ad7aa2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.worldofbelz.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allele-Diagnostics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32246</link>
<guid>7c3aa93f86af77d8b1071d5fd2b4c91a</guid>
<pubDate>Wed, 13 May 2026 15:51:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Allele-Diagnostics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4736f3afe10f5ee89f928bfa7da6462f6dbb8cb1103974adedba19cbf4394b99</i><br /><br />Threat actor <b>description</b>: <i>Allele Diagnostics specializes in providing exceptional microarray and cytogenetic testing services, including neonatal, pediatric, and prenatal testing. The company is dedicated to delivering accurate, fast, and reliable results, leveraging the extensive experience of its laboratory staff to optimize testing performance.We will upload corporate data soon. Detailed employee personal information (passports, DLs, SSNs, I9 forms, credit card details and so on), patients information (personal docs and medical information), contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>NTN-Bearing-Corporation-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32241</link>
<guid>dcdd0d62a00c7ccf110885b9275419cf</guid>
<pubDate>Wed, 13 May 2026 00:24:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>NTN-Bearing-Corporation-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a1497f8a12d73fc961c43d4c820a54e1616823429b48af800077e77da5af9c5</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] NTN Bearing Corporation of America is a US-based subsidiary of Japan's NTN Corporation, operating in the industrial manufacturing sector. The company produces and distributes precision bearings, driveshafts, and related mechanical components used in automotive, aerospace, and industrial machinery applications. Headquartered in Mount Prospect, Illinois, it serves customers across North America with engineering support and distribution services.</i><br />Target victim <b>website</b>: <i>ntnamericas.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Gravity-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32240</link>
<guid>09d565939e10290bb5cb27596845f186</guid>
<pubDate>Tue, 12 May 2026 22:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Gravity-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>883ac3bef946c562eef6448c0bf488c297343a0455be7fbcd6aee6edf422e289</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.thegravitygroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Porter-Wright</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32239</link>
<guid>85e04222fe1714e379c3061e65193a35</guid>
<pubDate>Tue, 12 May 2026 22:20:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Porter-Wright</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59e58353123dbf7b902693e7732ff207885721686e595122474ee8d9cb2a9821</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1846, Porter Wright is a full-service law firm offering legal helo for the community specia…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marshall-Dennehey</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32238</link>
<guid>d6c93ba90d7a0b63fc8143ff18cab6f1</guid>
<pubDate>Tue, 12 May 2026 22:20:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Marshall-Dennehey</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f0539b1ae5a92e0c2b666a94115e2e7d941ae788a81aa58ad1763132ea7d483</i><br /><br />Threat actor <b>description</b>: <i>They offered $100,000 to keep the data from being published. Founded in 1962 and headquartered in Phil…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infoworld-Membership-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32236</link>
<guid>a4700f244723a6277a576f50af1d387b</guid>
<pubDate>Tue, 12 May 2026 20:26:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Infoworld-Membership-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c589f01b9bee03f38a00ad48df957df67c315f72067fda5e1d2ba0d82fbf5cfa</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.imsmars.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Town-Car-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32235</link>
<guid>76607c8d892045f92be8094007e338f5</guid>
<pubDate>Tue, 12 May 2026 20:26:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Town-Car-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40ea66924b204d811b1305fa6d9c6cb6db04a527bfde116158f2ee9529726d63</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.towncarinternational.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Mechanical-Contractors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32234</link>
<guid>b1211abafb24dcd0eea6ef6e8f4790a6</guid>
<pubDate>Tue, 12 May 2026 20:25:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Northern-Mechanical-Contractors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e1ff3dc4d94359b5108e8d9c3053b20ee6f3537d35fc00280e6993ce3995434</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.northernmc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>ACC-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32233</link>
<guid>f047575e706451ca0ed912cf3d11daba</guid>
<pubDate>Tue, 12 May 2026 20:25:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ACC-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e34346efdfda968b233513d1eb0681b3fbf032e6a4519080b7ecfaa461c8ef45</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.acc-construction.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>IWC-Food-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32232</link>
<guid>c2f34ed953fbaf32dc52ccca8afc4389</guid>
<pubDate>Tue, 12 May 2026 20:25:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>IWC-Food-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>927fad677606c929c6ba297e8aa9c8f42c022170f2feb5428ab35e7a82fc6fdc</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.goiwc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>DURAND-WAYLAND</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32230</link>
<guid>5bf73f0ab50f712f61880e1254f1b723</guid>
<pubDate>Tue, 12 May 2026 20:24:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>DURAND-WAYLAND</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6f833f012f25498f9f5b095ae5c2e6d9dcb74413473f18066d901b1afb6022e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.durand-wayland.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>dentoncalvary.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32219</link>
<guid>1395b2ad1a4545fade286875936703da</guid>
<pubDate>Tue, 12 May 2026 19:22:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>dentoncalvary.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38c337af7e1d804f080d634fb2bcbc73f0cbced947db7e73d3a000045c8a9974</i><br /><br />Threat actor <b>description</b>: <i>Denton Calvary Academy is a K-12 University-Model school that focuses on fostering a love of learnin...</i><br />Target victim <b>website</b>: <i>dentoncalvary.org</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Taylor-Clay-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32216</link>
<guid>8da60ddc961c6ee8b17d41858f80bb2c</guid>
<pubDate>Tue, 12 May 2026 14:20:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Taylor-Clay-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>accd14363aadb7cd5fdb57515f9227c52bc6946354990c7aadbaa26eaa0bcc73</i><br /><br />Threat actor <b>description</b>: <i>Taylor Clay Products specializes in premium architectural brick, thin brick, and custom masonry
solutions, catering to architects and builders for over 75 years. The company offers a wide se
lection of colors, textures, and finishes, including custom blends tailored to specific project
s.

We will upload 72gb of corporate data soon. Employee personal information (DL and other persona
l docs), contracts, client information, drawings and specifications.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kaplan-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32215</link>
<guid>1392acc99e36fc31f3033a8b0e90b4d6</guid>
<pubDate>Tue, 12 May 2026 14:20:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kaplan-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5d8c183217abb1e25b9cd819be1914523a1e92c078b215344bac443dd4ebf94</i><br /><br />Threat actor <b>description</b>: <i>Kaplan Companies specializes in providing rental and commercial properties, focusing on new hom
es and maintenance services for current residents. The company aims to cater to individuals and
families seeking quality housing solutions.

We will upload 45gb of corporate data soon. Employee and owners personal information (passports
, DLs, SSNs, and other personal docs), contracts and agreements, client information, financials
, payment details, projects files, drawings and specifications and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Manhattan-Broadcasting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32212</link>
<guid>124c6149f09717e388e1f286163b130b</guid>
<pubDate>Tue, 12 May 2026 12:50:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Manhattan-Broadcasting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fff8bb601e00a0162cea40d4e3a8f55c46a6369e2fa0558bdf98238625c28fa</i><br /><br />Threat actor <b>description</b>: <i>Manhattan Broadcasting Company is a leading source of local and regional news, sports, weather,
and entertainment in Northeast Kansas, engaging over 100,000 listeners weekly.

We will upload of corporate data soon. Employee personal informatics, contracts, lots of pictur
es and other files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vision-3-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32211</link>
<guid>761b59a8e028e110dec4be2114ee567d</guid>
<pubDate>Tue, 12 May 2026 12:20:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Vision-3-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bac7939350656f6049ec3182f4ec922c1d40477cc792869c30a3c2ef9986d432</i><br /><br />Threat actor <b>description</b>: <i>Vision 3 Architects is a collaborative and responsive design studio specializing in architectur
e and interior design projects. They focus on crafting spaces that reflect each client's vision
and values, ensuring a design environment that fosters creativity and collaboration.

We will upload 31gb of corporate data soon. Detailed employee personal information (passports, 
DLs, SSNs and so on), contracts and agreements, client information, projects, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Avanti-Windows--Doors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32210</link>
<guid>97f7f89d26319a464bf6584c3d9d7051</guid>
<pubDate>Tue, 12 May 2026 11:20:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Avanti-Windows--Doors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a051fdf90e1770383cba1dbb75f0c0c7f3b54f645ce36110cae30ef96e9e8b8e</i><br /><br />Threat actor <b>description</b>: <i>Avanti Windows & Doors — a vinyl window manufacturer headquartered in El Mirage, Arizona, with regional offices across Nevada, Texas, California, and Florida.

The exposed material includes:

Plaintext SQL Server SA (system administrator) credentials — the master key to the FeneVision ERP database containing every customer order, every price, every financial record the company has ever processed.
Employee SSNs, W-4s, I-9s, and E-Verify data — the complete identity package for the entire workforce, from new-hire packets through payroll records spanning 2014–2016+.
1099-MISC/INT forms — SSNs/EINs and payment amounts for 50–200+ contractors and vendors across two tax years.
Direct deposit authorizations — bank account and routing numbers for employees who enrolled in ACH payroll.
24+ months of Chase bank statements and 28 months of AMEX corporate card statements — full account numbers, transaction details, and spending patterns.
The complete proprietary pricing algorithm — source code for the FastAPI backend that determines window pricing for every builder contract, plus 41+ builder Master Service Agreements with exact pricing terms.
CPA-reviewed financial statements, partnership returns, K-1s, and budget forecasts — the company’s full financial anatomy, from cost structure to profit allocation.
OSHA 300 logs, workers’ compensation audit files, and UHC health insurance invoices — employee medical and injury data, names of injured workers, treatment details.
Attorney-client privileged ADOSH settlement correspondence — OSHA settlement negotiations between outside counsel and the CEO.
~80 Windows roaming profiles — employee desktops, documents, AppData, Outlook .ost/.pst files, browser caches, and cached credentials.</i><br />Target victim <b>website</b>: <i>Avanti Windows & Doors</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>NorthWest-Handling-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32206</link>
<guid>93a4b4ee0ca79c5060ae88ef7b2faf70</guid>
<pubDate>Tue, 12 May 2026 09:50:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>NorthWest-Handling-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61eb87712fd005d8fbee6999d72ed36f77bbb3b8fbeea7c74f59cef48128cd2a</i><br /><br />Threat actor <b>description</b>: <i>[warehouse] NorthWest Handling Systems — a 55-year-old forklift and warehouse equipment company headquartered in Renton, Washington, with branches across WA, OR, and AK. The dump is the entire corporate file share going back to 1988. 337,000+ files spanning every branch, every department, every era of the company. It includes: Plaintext credit card numbers in an Excel spreadsheet literally titled “C.O.D. info (CREDIT CARD INFO).xlsx” — stored at the root of the file server, unencrypted, for years. Social Security numbers and Taxpayer IDs on W-9 forms and certified payroll documents for government-contract work (USPS, Oregon DHS, public schools). 3+ years of plaintext passwords for Target Corporation’s vendor portal (TARS), stored in Word documents titled “TARGET PASSWORD & SECURITY QUESTIONS.” Each password rotation was saved as a new file. Home Depot Maximo DC billing credentials — plaintext, in a Word document, enabling fraudulent invoicing against a Fortune 50 company. Albertsons/Safeway Corrigo facility-management portal credentials — again, plaintext in a .docx file. 33 GB of customer warehouse CAD files — facility layouts, equipment placement, security-zone dimensions, and fire-protection drawings for approximately 50–200 companies including Nike, Google, Costco, and Umpqua Bank. 24,669 rows of fixed-asset data in ExportFile.csv — the complete equipment inventory, revealing the company’s financial structure, depreciation schedules, and capital-investment history. Corporate bank routing and account numbers (ACH authorization forms), employee direct-deposit details, time cards, disciplinary records, accident reports, and decades of invoices.</i><br />Target victim <b>website</b>: <i>NorthWest Handling Systems</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>SmilePoint-Dental-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32204</link>
<guid>26e49cf53d47b35b4527160c7aacd2df</guid>
<pubDate>Tue, 12 May 2026 04:55:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>SmilePoint-Dental-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b245dd854a2e324e57a3bc1efe2b7d48622d8bcc8d82824eda58cafa666bd698</i><br /><br />Threat actor <b>description</b>: <i>SmilePoint Dental Group is a fast-growing dental organization operating 26–28 offices across Texas and New Mexico.The group runs multiple family dental clinics and orthodontics practices in smaller communities under various brands such as Crosby Family Dental, Liberty Family Dental, Jasper Family Dental, SmilePoint Dental, and others.They offer comprehensive services including general dentistry, orthodontics, cosmetic care, implants, and preventive treatments with modern equipment.- Patient database with social security numbers and medical histories- Access to the local EagleSoft database- Financial reportsThe data provided will allow you to deploy the company's database on any PC with full access to SmilePoint's EagleSoft functionality. https://www.smilepoint.us</i><br />Target victim <b>website</b>: <i>www.smilepoint.us</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>rbh-aerospace-inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32202</link>
<guid>dec3b026b81ee6d890a8f82f75c94a2e</guid>
<pubDate>Mon, 11 May 2026 23:52:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>rbh-aerospace-inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24736b32cfe94eb907e0336b3eeecc84048d6726133f487897c386c518f23d50</i><br /><br />Threat actor <b>description</b>: <i>RBH Aerospace, Inc.  -is a manufacturing company located in Long Beach, California, specializing in the production of aerospace components. Established in January 2005, the company focuses on providing high-quality parts for both commercial and military aircraft. Their product offerings include aircraft frames, fuselages, wings, and various metal alloy components such as steel, aluminum, and titanium.  2708 Seaboard Lane, Long Beach, CA 90805 http://www.rbhaerospace.com/   Leaked data 240 GB: Corporate information, including electronic correspondence with counterparties, contracts including NDAs, transactions and payments related to them, STP (STEP) files, part drawings (including those for F-15, F-22), manuals and instructions. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bideawee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32201</link>
<guid>535464f977a45ab62af2578604d3f9f2</guid>
<pubDate>Mon, 11 May 2026 23:26:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Bideawee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c29a1bd3872c258a58904c82f5823e47b7465766b178b82b96656efec3f65c4</i><br /><br />Threat actor <b>description</b>: <i>Bideawee is a no-kill animal rescue and shelter located in NYC, Wantagh, and Westhampton. The organization offers a variety of services including adoptions, medical care, pet therapy, and fostering opportunities. Bideawee aims to strengthen the human-animal bond through compassionate care for both pets and their owners. Its targeted clients include individuals and families seeking to adopt or foster pets, as well as volunteers looking to support animal welfare.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fargo-Moorhead-West-Fargo-Chamber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32199</link>
<guid>e069a65788839872ffe1902a16286563</guid>
<pubDate>Mon, 11 May 2026 23:24:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Fargo-Moorhead-West-Fargo-Chamber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abca34a46529ad68e4958b4ff8b485183f1110b02ec39502534bd37ee3a4081e</i><br /><br />Threat actor <b>description</b>: <i>A business services provider.</i><br />Target victim <b>website</b>: <i>fmwfchamber.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Process-Engineers--Constructors.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32198</link>
<guid>082925bd6347f8309fa790aa78d86f34</guid>
<pubDate>Mon, 11 May 2026 23:24:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Integrated-Process-Engineers--Constructors.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef399a019d298d810e93bc28c718351aa9ce3fc3b5914407127d0cd87367c8fb</i><br /><br />Threat actor <b>description</b>: <i>Specializes in custom modular process systems, offering a wide range of products including bioreactors, filtration systems, and utility stations.</i><br />Target victim <b>website</b>: <i>ipec-inc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ben-F.-Barcus-and-associates-pllc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32197</link>
<guid>0c31dda78664045d19fd1c04dc76abab</guid>
<pubDate>Mon, 11 May 2026 23:23:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Ben-F.-Barcus-and-associates-pllc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ccb2545d93e498721d2d4a9053cbd61bf5b26a75bdd89f09e46e0e6994ec085</i><br /><br />Threat actor <b>description</b>: <i>A law firm from Tacoma, WA.</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Palo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32196</link>
<guid>0ad3140ed0cf59e84008db87c8c1106c</guid>
<pubDate>Mon, 11 May 2026 23:23:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Palo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40debf5ea17f9023b75b14fee804c2b2e6ba7e9f7ea3949b7b55cec5c1d4dec3</i><br /><br />Threat actor <b>description</b>: <i>Architecture and Planning.</i><br />Target victim <b>website</b>: <i>palo.us</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>AppDirect</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32192</link>
<guid>0729480724847e6fde22501c8360f5af</guid>
<pubDate>Mon, 11 May 2026 21:55:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AppDirect</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>463c8bb15d5544aeb590a41bb8bd973d480650a08febe1583cfac37fc515a88a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.appdirect.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Software-Products-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32188</link>
<guid>6c571f6008a9d6b943f8eba0dbaac3c8</guid>
<pubDate>Mon, 11 May 2026 18:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Advanced-Software-Products-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b04987cfb9047d984352d850b974096877add322e462a788b65b03e66080caa</i><br /><br />Threat actor <b>description</b>: <i>ASPG Inc. specializes in enterprise and mainframe software solutions that focus on secure access, data protection, and system management. Their product offerings include comprehensive cryptography tools, access management solutions, and systems administration utilities tailored for various industries such as education, government, healthcare, and finance. Since 1986, ASPG has been dedicated to providing the IT community with cutting-edge software and support services.</i><br />Target victim <b>website</b>: <i>www.aspg.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keller-Williams-Real-Estate---Exton</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32187</link>
<guid>d97abcf66ea8d5818ebf5eb128f0de13</guid>
<pubDate>Mon, 11 May 2026 18:24:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Keller-Williams-Real-Estate---Exton</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6953cf11015d0f955f1de8b29f6b672f671095f3cf7f4a6191fe92d95e221fe5</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.kwphillysuburbs.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Forestdale</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32184</link>
<guid>f54fd264edeb6c5043be90f1570d4ea3</guid>
<pubDate>Mon, 11 May 2026 17:23:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>Forestdale</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>626c1b4ccfa021ccefd9cec5db413ebf472e5c90e1bfd54522c376ed8ea1bd4e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-United-Methodist-Church-Boerne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32181</link>
<guid>5a7a6185f07dab689218c182fcf3b4ae</guid>
<pubDate>Mon, 11 May 2026 16:52:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>First-United-Methodist-Church-Boerne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c95d1878594a41651373bc4057dc611f1400c506e1402282eadd2096a5e73388</i><br /><br />Threat actor <b>description</b>: <i>The First United Methodist Church in Bern offers a variety of programs for all age groups, including preschool, childrens, youth, and adult ministries. However, it does not ensure the protection of your personal data and does not seek to protect it; due to its negligence, there has been a leak of personal data including phone numbers, email addresses, and home addresses of staff, parishioners, and children attending the church, as well as financial and other confidential documents.</i><br />Target victim <b>website</b>: <i>https:fumc-boerne.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kent-District-Library</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32179</link>
<guid>7fbeed7afa97cfc6f75f36fee05ac024</guid>
<pubDate>Mon, 11 May 2026 13:54:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Kent-District-Library</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2de97414e264ea12192e6d802e96aecb27c0b60c8abe3a9eae340cc4d36f9555</i><br /><br />Threat actor <b>description</b>: <i>Kent District Library (KDL) is a public library system that owns and operates libraries throughout Michigan. However, it does not manage its own security, which is damaging its reputation. We are providing you with confidential financial documents, contact information for organizations, personal data on customers and employees, building plans and blueprints, as well as information about various incidents that they are concealing.</i><br />Target victim <b>website</b>: <i>https:kdl.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Park-Dental-Research</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32178</link>
<guid>8aa168167e983b0cb8b753e7ce8f0307</guid>
<pubDate>Mon, 11 May 2026 13:54:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Park-Dental-Research</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>457422b4fd9b0291be64772befed51a961e6ef05144d6af5ad314ae07d1b52ac</i><br /><br />Threat actor <b>description</b>: <i>Park Dental Research is a supplier of technologies and materials for dental laboratories and orthodontic clinics; however, when it comes to security, it has proven to be an unreliable partner. As a result of its negligence, partner and customer data, financial documents, and login credentials for various web resources were compromised and made publicly available on the Internet.</i><br />Target victim <b>website</b>: <i>https:shop.pdrus.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Waterford-Hotel-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32177</link>
<guid>980023eafc2c419180916d7eb6d29599</guid>
<pubDate>Mon, 11 May 2026 13:54:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Waterford-Hotel-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d658f48e019abd05944464664dbb0c0715ab8ae1e012c469425808fd8739d94</i><br /><br />Threat actor <b>description</b>: <i>Waterford Hotel Groupa company that manages hotels and conference centersfailed to implement adequate security measures, resulting in a data breach. We are providing you with a dataset containing information about the hotel chain and its other divisions, including personal and confidential data, partner contact information, and financial information.</i><br />Target victim <b>website</b>: <i>https:waterfordhotelgroup.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tab-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32174</link>
<guid>8e09c1416fa221eafaacbb6c60e11f02</guid>
<pubDate>Mon, 11 May 2026 13:51:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Tab-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c9ff9ad38b431a5d62cf95fb3d87d9edadd163f4d54224abfa9044f4294f4f0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>tabservice.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cass-information-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32173</link>
<guid>f7464066678a4b2b73cd89da6c7c161c</guid>
<pubDate>Mon, 11 May 2026 13:51:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Cass-information-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa0730974f7b98629632a1b79500f1797ddfc91e6fcf317df122655bd7d90a3e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Cass Information Systems is a US-based company specializing in payment and information services. It provides freight invoice processing, auditing, and payment solutions, along with utility and telecom expense management. Operating primarily in the financial technology and business process outsourcing industry, Cass serves large corporations across North America and globally, helping clients manage and analyze invoice data to optimize spending and operational efficiency.</i><br />Target victim <b>website</b>: <i>cassinfo.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clarkson-Walsh--Coulter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32172</link>
<guid>ffd5a146054a13ce7bd23f9ed8612e7c</guid>
<pubDate>Mon, 11 May 2026 12:50:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Clarkson-Walsh--Coulter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>98923ec7bcff291fd0199ea622183d427b43a15669256c2409f3e969d5603aac</i><br /><br />Threat actor <b>description</b>: <i>Clarkson Walsh & Coulter provides innovative legal solutions and aggressive litigation services
to clients of all sizes across South Carolina. The firm specializes in various areas including
general liability, employment, medical malpractice, and commercial matters, representing indiv
iduals, corporations, and insurance carriers in both State and Federal Court.

We will upload 236gb of corporate data soon. Client personal information (passports, DLs, and s
o on), contracts and agreements, lots of legal confidential docs (court records, police reports
, etc), employee information, financials and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Circle-U-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32171</link>
<guid>d0deaa11f4e5050a6b9ff605ed3864fb</guid>
<pubDate>Mon, 11 May 2026 12:20:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Circle-U-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a38368c40ca9171c1fe4f7f95b227f3aae79b91fb5921263ceb2b53bb583287</i><br /><br />Threat actor <b>description</b>: <i>Circle U Foods, Inc. is a manufacturer of custom seasonings and flavored food grade oils based 
in Fort Worth, TX. The company serves domestic and international restaurant chains, distributor
s, and food manufacturers.

We will upload 13gb of corporate data soon. Employee personal information (phones, addresses, e
mails, SSNs, passports numbers and so on), client data, financials, payment details, projects i
nformation (drawings, specifications, etc), NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accretech-America-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32167</link>
<guid>67614aacd469da7f9d611c9be60462f1</guid>
<pubDate>Mon, 11 May 2026 07:20:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Accretech-America-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c11b6e2e70a62dc55eac98d1542561c852e78d6d125d4a9e29935972e2ce29a</i><br /><br />Threat actor <b>description</b>: <i>Accretech America Inc. is the U.S. division of Tokyo Seimitsu Co., Ltd. of Japan, a Japanese corporation specialising in semiconductor equipment and precision instrumentation.</i><br />Target victim <b>website</b>: <i>accretechsbs.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>lifelongaccess.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32153</link>
<guid>fc815a0b7bc84dce6b9c6f8ca4c28ad5</guid>
<pubDate>Sun, 10 May 2026 11:49:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>lifelongaccess.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f92fb7f73ec3744243f4307ab71d928a556a6c31bb4d2c509c138ddc17198ca</i><br /><br />Threat actor <b>description</b>: <i>Lifelong Access is a dedicated organization that supports individuals with disab...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>bayareaherbs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32165</link>
<guid>df2a3e9e504593d5b2dc0c84d1c0cf02</guid>
<pubDate>Sun, 10 May 2026 09:52:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>bayareaherbs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99f7017c22a56f6f9a0b78d3ae32417212bd52cc2654d33907a9223777cd55f9</i><br /><br />Threat actor <b>description</b>: <i>Bay Area Herbs & Specialties is a leading supplier of fresh culinary herbs and specialty produce, serving the US market for nearly 20 years. They collaborate with top growers to provide high-quality products to retailers, foodservice distributors, and wholesalers. The company is committed to sustainability and innovative packaging, ensuring efficient delivery and customer satisfaction. Their expertise in the specialty produce category positions them as a trusted partner for chefs and businesses alike.</i><br />Target victim <b>website</b>: <i>bayareaherbs.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>jacksoncountyin.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32164</link>
<guid>6b6e273c60c290056cfa83fcd20130c8</guid>
<pubDate>Sun, 10 May 2026 09:52:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>jacksoncountyin.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fc78993ecfde7ca18bb3c21ae3245785743d007c0d0d37a42f466881dcc196d</i><br /><br />Threat actor <b>description</b>: <i>Jackson County Visitor Center serves as a gateway for travelers seeking to explore the scenic beauty, rich history, and vibrant community of Jackson County, Indiana. The center offers a variety of outdoor recreational activities, cultural experiences, and local events, catering to families, adventure seekers, and history enthusiasts alike. Visitors can enjoy hiking, biking, local dining, and numerous festivals that celebrate the region's heritage and community spirit. Conveniently located near major cities, the center is an ideal resource for planning memorable getaways and discovering hidden gems in Southern Indiana.</i><br />Target victim <b>website</b>: <i>jacksoncountyin.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>funkychunky.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32149</link>
<guid>af8e3c349612f1af5aa0509b16bae3cc</guid>
<pubDate>Sun, 10 May 2026 08:25:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>funkychunky.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad5099980da383c441d83290c675cd7c4ec681949dc8b0655630f61d41917687</i><br /><br />Threat actor <b>description</b>: <i>Funky Chunky offers gourmet caramel corn and popcorn snacks, providing unique gift options perfect for various occasions such as business gatherings, birthdays, and holidays. Their product range includes snack bags, tins, pails, canisters, and premium gifts with a variety of flavors including Sea Salt Caramel and Peanut Butter Cup. They also specialize in corporate gifting and wholesale solutions. Funky Chunky emphasizes customer convenience with features like free shipping on orders over $75 and the ability to send gifts to multiple addresses.</i><br />Target victim <b>website</b>: <i>funkychunky.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Langenberg-Strubberg-Arand--King-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32148</link>
<guid>c5fb163f824e9eeed5086689a8a905d9</guid>
<pubDate>Sun, 10 May 2026 07:56:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Langenberg-Strubberg-Arand--King-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41e696b07371ed1e5b4c40897c1b080b4ed66ae41ce5ceef4c1f0e4632860925</i><br /><br />Threat actor <b>description</b>: <i>Firm that specializes in providing accounting, tax, and advisory services</i><br />Target victim <b>website</b>: <i>lsakcpa.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpssibillacapital.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32146</link>
<guid>e2123ce4618e73fa5a9070258528a905</guid>
<pubDate>Sun, 10 May 2026 03:52:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpssibillacapital.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5615652ac503fac102fb8ab2055f3d3bf1754d14e9df2d8cd5bb5ef8fccf0ee2</i><br /><br />Threat actor <b>description</b>: <i>data</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>lopezlawfl.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32145</link>
<guid>ad846fd1138e66a1cacd0fb4b8644671</guid>
<pubDate>Sun, 10 May 2026 03:22:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>lopezlawfl.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14dffd49c783c761d628befbbd720419c1464fe639b3df1d04e6ad291ccb11bf</i><br /><br />Threat actor <b>description</b>: <i>full data </i><br />Target victim <b>website</b>: <i>lopezlawfl.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-American-Board-of-Preventive-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32140</link>
<guid>e2d988c728d061b916697ba7f095f98c</guid>
<pubDate>Sat, 09 May 2026 10:23:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>The-American-Board-of-Preventive-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61c362b78ff85d947e1751c2886ddc29ac0c0fcc404169fc8b383384711f675e</i><br /><br />Threat actor <b>description</b>: <i>A healthcare certification organization.</i><br />Target victim <b>website</b>: <i>theabpm.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prescott--Holden</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32139</link>
<guid>54ed85e7af8edc78637654cb4a89040e</guid>
<pubDate>Sat, 09 May 2026 10:23:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Prescott--Holden</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de3b16a80caee424011b6776fc8c5d81d719cd2024f6ac1619887660c1aa6733</i><br /><br />Threat actor <b>description</b>: <i>A legal firm dedicated to safeguard the rights of its clients</i><br />Target victim <b>website</b>: <i>familylaw.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Van-Atta-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32138</link>
<guid>82b02f59d83397a4f6851822234ef138</guid>
<pubDate>Sat, 09 May 2026 10:22:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Van-Atta-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6adee4b7f622b01eb80befa7486cd4f1628f0f8ee3d6edb08ead4b7e9f2b28aa</i><br /><br />Threat actor <b>description</b>: <i>A civil engineering and surveying firm located at 570 Congress Park Dr, Dayton, Ohio.</i><br />Target victim <b>website</b>: <i>vae.cc</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rain-Makers-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32137</link>
<guid>b3b0b34ebdc9b8ba6bd98224365ed43d</guid>
<pubDate>Sat, 09 May 2026 10:22:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Rain-Makers-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>047218f138bbfa45e2e4a560c2b183a2a0b331aa05eb54645fd2f54ad44a0239</i><br /><br />Threat actor <b>description</b>: <i>Conducting training sessions, engaging with stakeholders, and organizing meetings and events.</i><br />Target victim <b>website</b>: <i>rainmakerssolutions.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hillside-Lumber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32135</link>
<guid>0a61ca65b273db8211e9c20d35ebfd4a</guid>
<pubDate>Sat, 09 May 2026 09:17:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hillside-Lumber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19be1ef2ab6533042503a5164b3b5a6a075bf4e3a771ac15e97a499d1a60b5c5</i><br /><br />Threat actor <b>description</b>: <i>hillsidelumber.com Hillside Lumber is a family-owned full-service building materials supplier established in 1979, based in Westbrook, Maine. The company serves builders, contractors, and DIY enthusiasts throughout Southern Maine with high-quality lumber, saw mill products, kitchen design, and building supplies. With 38 employees, they provide professional service to both construction professionals and homeowners.</i><br />Target victim <b>website</b>: <i>hillsidelumber.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arizona-Professional-Painting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32132</link>
<guid>c4df13cad905bbff4cfd811606745cd8</guid>
<pubDate>Sat, 09 May 2026 09:16:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Arizona-Professional-Painting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba035c41c6ef64b8e57877669a64e2bc85bc99547415074b9fe909453542cb10</i><br /><br />Threat actor <b>description</b>: <i>azpropaint.com Arizona Professional Painting is a family-owned and operated commercial and industrial painting contractor established in 1994, based in Phoenix, Arizona. The company specializes in diverse sectors including data centers, healthcare facilities, sports facilities, industrial projects, and tenant improvements across the state. With SBE, WBE, MBE, and DBE certifications, they maintain an exceptional safety record with a .66 EMR rating and zero recordable on-the-job incidents. Their experienced team provides comprehensive interior and exterior painting, industrial coatings, floor coatings, and ongoing facility maintenance services.</i><br />Target victim <b>website</b>: <i>azpropaint.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>McCarthy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32131</link>
<guid>544f4e7aceeab82ffab9301d2d72a625</guid>
<pubDate>Sat, 09 May 2026 09:16:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>McCarthy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a1826440789144a17ade26033c9aa4b3fcbb1608874953e6d49cc64d2ecc8a6</i><br /><br />Threat actor <b>description</b>: <i>mccarthyinc.com McCarthy, Inc., founded in 1955 and based in Savannah, Georgia, specializes in supplying metal doors and frames, wood doors, builder's hardware, toilet partitions, signage, louvers, and specialty accessories. The company serves diverse industries including healthcare, education, commercial, government, manufacturing, and hospitality sectors across the region. McCarthy provides comprehensive products and services from project inception through completion, focusing on building lasting relationships with project teams to ensure utmost client satisfaction.</i><br />Target victim <b>website</b>: <i>mccarthyinc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>TDS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32128</link>
<guid>13616b9ad93bd3ff7f45556ad117f48a</guid>
<pubDate>Sat, 09 May 2026 09:15:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>TDS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b91fad795d53aaedf15ac583ea54b5fcb9e80441f9cbcd769be7aef8dcc9350</i><br /><br />Threat actor <b>description</b>: <i>tdstelecom.com TDS Telecommunications LLC, founded in 1969 and headquartered in Madison, Wisconsin, is a leading U.S. telecommunications provider serving residential and business customers across urban, suburban, and rural communities. The company delivers high-speed fiber-optic internet (up to 8 Gigabit), IP-based TV entertainment, and traditional phone services, alongside business solutions like VoIP, dedicated internet, and data networking. With over 1.1 million connections, TDS is a wholly owned subsidiary of Telephone and Data Systems, Inc. (NYSE: TDS), committed to enhancing communities through reliable, innovative communications technology.</i><br />Target victim <b>website</b>: <i>tdstelecom.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Office-Furniture-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32124</link>
<guid>8f2a580cb0f40eab3546cdf886ee0797</guid>
<pubDate>Sat, 09 May 2026 08:55:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Office-Furniture-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d7c0ba997a802518eefad707a159062c407e2e93407ee0011704337b1dc6bb6</i><br /><br />Threat actor <b>description</b>: <i>Interior workplace solutions provider</i><br />Target victim <b>website</b>: <i>ofginc.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Calsoft-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32123</link>
<guid>e557bfa4e959dc5025f60ee6f5cb4298</guid>
<pubDate>Sat, 09 May 2026 08:53:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Calsoft-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af089ba9b17ba3f4a6c9aa02eae96fc968f08f373f0a3b8b80a52ddf45a10dbc</i><br /><br />Threat actor <b>description</b>: <i>CalSoft Inc.  is a company focused on providing digital transformation and AI services tailored for enterprises. Their offerings are designed to enhance operational efficiency, accelerate product delivery, and ensure robust data security, AI-Powered Solutions, Cloud and Infrastructure Services, Data Management, Product Development  1762 Technology Dr, San Jose, California, 95110  calsoftinc.com   Leaked data 24.4 Gb  Technical information of clients, logs, software and its instructions, contracts including NDAs, client lists, personal data of employees with passports and personal photos, accounting records, and other corporate information.</i><br />Target victim <b>website</b>: <i>calsoftinc.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CF-Evans-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32120</link>
<guid>ed08ffe048c32cd55986623fd0aac732</guid>
<pubDate>Fri, 08 May 2026 23:55:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>CF-Evans-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83be8dc2dac766d2f3b59453147007626966dfeb486c94ef7a75605082df154c</i><br /><br />Threat actor <b>description</b>: <i>A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lindabury</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32121</link>
<guid>640a443672e27069a68471d5b3b5bd63</guid>
<pubDate>Fri, 08 May 2026 22:56:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lindabury</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23a13bdff218eee28e38124dc9ffabc7394e572de84909d70b12f68488f7279b</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>DL-Cohen-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32116</link>
<guid>c5677f71b1968b865a1570e182b7a18e</guid>
<pubDate>Fri, 08 May 2026 20:55:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>DL-Cohen-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3efb7640319445e2280ecf992eb1cec8c8fcac628a785f7ecc118b2e75e1e5ff</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fogel-Capital-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32118</link>
<guid>12967cc2a03871bd9eef46ed6da69398</guid>
<pubDate>Fri, 08 May 2026 20:55:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Fogel-Capital-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c42ae1faacfea96ce1755b8a989ca9dc681f723ff806530405c037d8b479dd6</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neurotrials-Research-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32119</link>
<guid>d7528f9dcfa7877af9e4f86af207c469</guid>
<pubDate>Fri, 08 May 2026 20:26:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Neurotrials-Research-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5712f9f29570334bd3365a527701c0e743d2bdf85d60fb314299103a4fc312c7</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1997, NeuroTrials Research is an outpatient and inpatient research facility located in Atlanta. The clinic occupies 12,000 square feet, including a 15-bed, state-of-the-art sleep lab and inpatient clinical research unit, which is designed specifically for the comfort and safety of subjects participating in its clinical trials. Today, NeuroTrials has conducted more than 175 clinical trials on over 2,500 volunteers throughout the Atlanta metro area.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Laundry-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32109</link>
<guid>e2494a7edccd9fc5418f59234d55eecf</guid>
<pubDate>Fri, 08 May 2026 19:57:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Advanced-Laundry-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d616983bfd63f059f50a4407d04efb166efa9d3a3cb50f8a160525aeae8d9496</i><br /><br />Threat actor <b>description</b>: <i>Consumer Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CCD-Interiors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32110</link>
<guid>82de976eb77f1ad870248833660fdff8</guid>
<pubDate>Fri, 08 May 2026 19:57:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CCD-Interiors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d13ccf038c326d7c716cc0657b4b1e3ca5d8d5af66cca34121cfc7e689fb4c14</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenwoods-Dental-Centre</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32103</link>
<guid>75ac9cb08d882b4af19c2ac94b536bfa</guid>
<pubDate>Fri, 08 May 2026 14:20:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Greenwoods-Dental-Centre</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20765ab691c8479beb7b6c18645a30a30f9331149ebcc8d51e7324adf4c3011e</i><br /><br />Threat actor <b>description</b>: <i>Greenwoods Dental & Surgical Centre has been a cornerstone of dental care in Winnipeg.

We will upload 90gb of corporate data soon. Detailed employee personal information (passport, D
Ls and other personal information), financials, patient information, payment details, NDAs and 
so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PennEastern-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32098</link>
<guid>85b7cea7bb6a5ba1e65d7f41c8090f61</guid>
<pubDate>Fri, 08 May 2026 07:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>PennEastern-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04b04e142670c4b45fd62e0179b34eb0dcdcf45fcf37306ca3525cd618f4f45c</i><br /><br />Threat actor <b>description</b>: <i>The principals of PennEastern Engineers, LLC are Paul Pasonick, Andrew Pasonick, Michael Amato and Daryl Pawlush. All principals have extensive experience in commercial and residential land developments, municipal projects, sanitary sewer projects, storm water projects, pavement projects, flood control projects and soil erosion and sedimentation control plans. In addition, each has assisted in design, specification writing, cost estimating, project bidding and bid review, construction observation and project management of the various projects. The Principals of PennEastern Architects, LLC are Andrew Pasonick, Emil Jarolen and Norman Manovsky. Design Principal Emil Jarolen has been practicing Architecture since 1974 and has been a Registered Architect in the State of Pennsylvania since 1978. In addition, Mr. Jarolen is Registered as an Architect in the States of Maryland, New York, New Jersey and the District of Columbia.</i><br />Target victim <b>website</b>: <i>www.penneastern.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>cmswpc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32097</link>
<guid>7b594fddae646cc544e30eead3d1852c</guid>
<pubDate>Fri, 08 May 2026 07:32:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cmswpc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b77dc754ae7bf96433c90895501e9586f79c8f08c84d405ee4540c3144a61404</i><br /><br />Threat actor <b>description</b>: <i>All patient medical records in their entirety. All data from the medical center, including personal and confidential information, will be stolen. The data will be divided into 7 parts, with each part containing 200–300 GB</i><br />Target victim <b>website</b>: <i>cmswpc.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>autorisk.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32096</link>
<guid>0369b73b76b40cb95ff9168746896768</guid>
<pubDate>Fri, 08 May 2026 07:31:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>autorisk.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0b7e9c7df72529c82d2e448855a7e291f2bcd83a105906eefb4c92a8d269cb3</i><br /><br />Threat actor <b>description</b>: <i>client data</i><br />Target victim <b>website</b>: <i>autorisk.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>egnyte.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32094</link>
<guid>c53015e875a2e796bc25ca874a294d03</guid>
<pubDate>Fri, 08 May 2026 07:31:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>egnyte.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5945092411fe9183eb8680c37887a365dd16ab3966e57ee9d5a323c5363e06ad</i><br /><br />Threat actor <b>description</b>: <i>development department  EU  pl</i><br />Target victim <b>website</b>: <i>egnyte.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trellix-McAfee--FireEye</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32093</link>
<guid>8fd67f6517ba75e90f1491c11b758a77</guid>
<pubDate>Fri, 08 May 2026 07:29:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Trellix-McAfee--FireEye</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c072c57214c02de65e7c9b068f60e7a688ce8a7464b366fe45b492a9f4f2b382</i><br /><br />Threat actor <b>description</b>: <i>Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security</i><br />Target victim <b>website</b>: <i>www.trellix.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>K--E-Distributing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32092</link>
<guid>62e11dcfe1cca7274439efccbdaa8c40</guid>
<pubDate>Fri, 08 May 2026 07:26:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>K--E-Distributing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5febe82f60935ebb5fc40b753a2ef88a2f810ca93559c7be8211f94bd371558</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kedistributing.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>EMA-Engineering--Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32090</link>
<guid>1f710d07916bb3151c453c764cfaf1ca</guid>
<pubDate>Fri, 08 May 2026 07:25:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>EMA-Engineering--Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0cc90b136c3e51d92155b88cc281a97fccaaa6297acf7865792ebfe2a9061a43</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.emaengineer.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stuf-Storage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32089</link>
<guid>e8792705b5cea2f03388f86885f645a3</guid>
<pubDate>Fri, 08 May 2026 07:18:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Stuf-Storage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8dd3189d7733758a34e2a0e1d337bcd9c3e94eb582e7a32d0498b4595af44ecd</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Stuf Storage is a US-based company operating in the self-storage industry. It offers on-demand, flexible storage solutions primarily in urban markets, allowing customers to rent storage units without long-term commitments. The company focuses on converting underutilized urban spaces such as basements and parking structures into storage facilities. Stuf operates across several major US cities and targets city dwellers seeking convenient, accessible storage options.</i><br />Target victim <b>website</b>: <i>stufstorage.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Norcal-Training-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32081</link>
<guid>c3a83e015935188821aa9ee65e6b322f</guid>
<pubDate>Thu, 07 May 2026 17:59:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Norcal-Training-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7b4df7626ee44d253e9946f9cc4920d9699a1651bfbcda52ee3d87bee787355</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elia-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32082</link>
<guid>8ea38887f092b8d42ab30baf36bc70e5</guid>
<pubDate>Thu, 07 May 2026 17:58:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Elia-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d640747d99a72ef9050c15a0eaa7f1f4ad8f6170598819fe631bc196adfb1b5</i><br /><br />Threat actor <b>description</b>: <i>Elia Law Firm APC is a top San Diego law firm specializing in personal injury, civil litigation, and business law. They are dedicated to fighting for their clients' rights and maximizing recovery for physical, mental, and financial losses.We will upload 100gb of corporate data soon. Detailed employee personal information (passport, DLs, SSN, death and birth certificates, financial information, payment details and so on), lotsof legal files (court hearings, police reports and so on), financials, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jacobs-Doland-Beer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32079</link>
<guid>3d61b1986be3ad573facc7b43a602178</guid>
<pubDate>Thu, 07 May 2026 14:50:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Jacobs-Doland-Beer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1837f453e307ea224f42c66c4be39cffc21f9a296c67f8ebcb499cad616b3272</i><br /><br />Threat actor <b>description</b>: <i>Jacobs Doland Beer (JDB) is a specialized foodservice design firm based in New York City, focus
ing on foodservice consulting for various projects across the country. The firm has worked on n
otable projects such as Eleven Madison Park, Mutual of America, and several food halls in New Y
ork City.

We will upload 170gb of corporate data soon. Employee personal information, client documents (D
OB, name, address and so on), financials, credit card statements, contracts and agreements, NDA
s, internal confidential files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>datasavior.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32074</link>
<guid>197b422c8f32c16605c5a4a1b25659b5</guid>
<pubDate>Wed, 06 May 2026 22:23:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>datasavior.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>686d368e7b2d990503c4603b63b2385345f0dac03036c1a9503e48231d66003d</i><br /><br />Threat actor <b>description</b>: <i>+1 (512) 707-0026. Datasavior is a full-service systems integration company based in Austin, Texas, specializing in IT support and fiber cable installations. They offer comprehensive solutions for medical and dental office IT, including practice management, data backup services, and advanced antivirus software. Their target clients include businesses in need of reliable technology solutions and support, particularly in the healthcare sector. With a team of skilled technicians, Datasavior aims to help clients optimize their technology for current and future needs. Stolen: 540mb 1,410 Files</i><br />Target victim <b>website</b>: <i>datasavior.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>gingerichtrucking.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32070</link>
<guid>ab9989d9b7160b800aaa1251b561c14d</guid>
<pubDate>Wed, 06 May 2026 21:24:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>gingerichtrucking.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5414c6e3198963fca397e4b2cecd4d585a04e2de3b3489241adb65385d849c62</i><br /><br />Threat actor <b>description</b>: <i>Is a U.S.-based freight transportation company operating primarily in interstate logistics. The company specializes in hauling general freight, agricultural products …</i><br />Target victim <b>website</b>: <i>gingerichtrucking.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>jmige.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32069</link>
<guid>5aae6cf6035cf23bdcb50896a46889b1</guid>
<pubDate>Wed, 06 May 2026 21:23:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>jmige.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b23e29da48153d12ec29aef926d62da9f2755823964c22141fede3c79ffa9b26</i><br /><br />Threat actor <b>description</b>: <i>JMIGE appears to be a company with limited publicly available information, making precise classification difficult. Based on naming conventions and …</i><br />Target victim <b>website</b>: <i>jmige.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Farella-Braun--Martel-LLP-Information</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32067</link>
<guid>32012097fe8ac018cf0586ee96bb9227</guid>
<pubDate>Wed, 06 May 2026 20:50:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Farella-Braun--Martel-LLP-Information</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a6df21ba97db6df79a6a3c2c739d944dcacdef4af8e7409d42eb85f1bdec767</i><br /><br />Threat actor <b>description</b>: <i>Farella Braun + Martel LLP is a leading Northern California law firm representing corporate and privat…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sandberg-Phoenix-Information</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32066</link>
<guid>21d6a4526873e2cf7d6afc4b79cea5c5</guid>
<pubDate>Wed, 06 May 2026 20:50:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Sandberg-Phoenix-Information</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77e916767c734da8656ad0c0e8b8732784c9b22608df3b1628c4faab7f90e15d</i><br /><br />Threat actor <b>description</b>: <i>Over 45 years providing superior legal services to clients of every size throughout the Midwest and ac…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>globalmerchservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32061</link>
<guid>e05ce76c744d3b3b877a935bb99b8a80</guid>
<pubDate>Wed, 06 May 2026 19:55:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>globalmerchservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8a9d16fcb5f948e35c26c90507637bc39c55c76df8968c20ff87afb81bd938e</i><br /><br />Threat actor <b>description</b>: <i>Global Merchandising Services (GMS) is an international entertainment merchandising company founded in 2008. It specializes in developing and managing merchandise …</i><br />Target victim <b>website</b>: <i>globalmerchservices.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Houk-Air-Conditioning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32055</link>
<guid>f9a9c6e884276feb6760da3befc80ef8</guid>
<pubDate>Wed, 06 May 2026 18:22:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Houk-Air-Conditioning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26fa1fd6edad68a0b57fe96e3e30cea17cea976f4e829b198f434728c5d0291a</i><br /><br />Threat actor <b>description</b>: <i>Houk AC is a leading HVAC repair and installation service based in Texas, operating in areas such as DFW, Austin, Houston, and San Antonio since 1962. The company offers a variety of services including air conditioning and heating repairs, installations, maintenance, and commercial HVAC solutions. Known for their commitment to customer satisfaction, Houk AC provides special financing options, discounts, and a comprehensive maintenance program to meet the needs of both residential and commercial clients. With a family-owned approach, their dedicated technicians are focused on delivering reliable and energy-efficient solutions to ensure optimal comfort for Texans.</i><br />Target victim <b>website</b>: <i>houkac.com</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Time-Cap-Labs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32053</link>
<guid>a6ff5a63d43e7fb68e9e4b6613abdef2</guid>
<pubDate>Wed, 06 May 2026 17:54:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Time-Cap-Labs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09a4cb66a82d7377ba07b2ae9aedf986fb6be11bc341124963d5c99666c491ba</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.timecaplabs.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Asphalt-Specialists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32036</link>
<guid>a082c0a47eb5379353243b15bf77c560</guid>
<pubDate>Wed, 06 May 2026 15:55:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Asphalt-Specialists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b625c1566e11887454737796035c26c546c30f2026ababfad948ecad63146ae5</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clinical-Registry-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32052</link>
<guid>dde2cbd066f964bf63dcc323945aecae</guid>
<pubDate>Wed, 06 May 2026 14:50:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Clinical-Registry-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cde1c73d1b07234ed8989a908d52d179db71124b842ea47853a536f577d2c07e</i><br /><br />Threat actor <b>description</b>: <i>Clinical Registry Solutions (CRS) is a healthcare data management company based in New York, Un
ited States, formerly operating as Cardiac Registry Support. The company specializes in clinica
l data abstraction, medical record abstraction, and registry support services for hospitals, he
alth systems, contract research organizations, and clinical staffing firms across the United St
ates and Canada.

We will upload 41gb of corporate data soon. Detailed employee personal information (passports, 
DLs, SSNs, health information, and other docs), client documents and personal information, fina
ncials, payment details, contracts and agreements, NDAs, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gator-Cases</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32046</link>
<guid>4600fac20e73cc30e734c8201ae46d5c</guid>
<pubDate>Wed, 06 May 2026 13:35:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Gator-Cases</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6d44acb2d62e8931e929ce085d5c89c7e666df9257a56b373be1c3bf0ac029d</i><br /><br />Threat actor <b>description</b>: <i>gatorcases.com zoominfo.com/c/gator-cases/20824928 Gator Cases is a leading American manufacturer of protective cases, bags, stands, and accessories for musicians and audio/visual professionals, founded in 2000 by father-daughter team Jerry Freed and Crystal Morris in Tampa, Florida. Starting with a small lineup of molded plastic guitar cases at the Summer NAMM show, the company has grown to offer over 1,000 product solutions across categories including pro audio, IT, DJ, percussion, band instruments, and AV equipment. With an annual revenue of approximately 27 million and ~96 employees, Gator operates a major 180,000 sq. ft. manufacturing and distribution facility in Columbia City, Indiana, and backs all products with a Limited Lifetime Warranty</i><br />Target victim <b>website</b>: <i>gatorcases.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>FMS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32043</link>
<guid>b603b38a17f369ddc973b3a9045943de</guid>
<pubDate>Wed, 06 May 2026 13:34:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>FMS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1ff89741252424cbff59280a5114e52ae98cd8b409a319740d152bdf4e262d5</i><br /><br />Threat actor <b>description</b>: <i>fmsinc.com zoominfo.com/c/fms-inc/14729979 FMS, Inc. is a privately held American software company founded in 1986 by Luke Chung (Harvard graduate), headquartered in Vienna, Virginia, near Washington DC. The company is the world's leading developer of tools for Microsoft Access, and a top vendor for SQL Server, Visual Studio .NET, and Visual Basic communities, with tens of thousands of customers across 100+ countries, including 90 of the Fortune 100 and every US federal government department. FMS is a Microsoft Gold Certified Partner, has won over 40 industry awards, and is recognized as one of the SD Times Top 100 most innovative software firms. It also offers custom software development consulting and its own Sentinel Visualizer link analysis product, used by intelligence and law enforcement agencies</i><br />Target victim <b>website</b>: <i>fmsinc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clark-Fixture-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32042</link>
<guid>0a51f21be1788c647ab965b12af2820c</guid>
<pubDate>Wed, 06 May 2026 13:34:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Clark-Fixture-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83c37933be59c42193c9cc6f5a66e58b12b09d44944d45729c1e7c5c04e0c28f</i><br /><br />Threat actor <b>description</b>: <i>clarkfixtures.com zoominfo.com/c/clark-fixture-technologies-inc/31954083 Clark Fixture Technologies, Inc. is a privately held American manufacturer founded in 1978, headquartered at Bowling Green, Ohio, with an estimated annual revenue of $42.9 million and a staff of 51–200 employees. The company designs, manufactures, and inspects quality check fixtures and gages for bent tube, hose, wire, and weld products, serving industries including automotive, aerospace, space, medical, and agriculture. Clark Fixtures operates globally with facilities in the US, Mexico (Saltillo), and India (Bangalore), servicing clients across 11 countries, including a prestigious roster of aerospace and space clients who rely on its orbital weld tooling for propulsion and life support assemblies. It also offers CMM inspection services and advanced automated robotic cell fixture solutio</i><br />Target victim <b>website</b>: <i>clarkfixtures.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Manhattan-Fire-Safety-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32041</link>
<guid>4c43f887265915a671a25d08b07f1e51</guid>
<pubDate>Wed, 06 May 2026 13:34:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Manhattan-Fire-Safety-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a0dcf4348e289ae01b5e2177076ec3147f11b4ea03be48f68487436f2d289c0</i><br /><br />Threat actor <b>description</b>: <i>mfsnyc.com rocketreach.co/mfs-nyc-profile_b4779b17fc5cb39e Manhattan Fire & Security (MFS) is a licensed fire alarm and security services firm based in New York City, with over 15 years of experience serving commercial and industrial clients across NYC and surrounding areas. The company employs NICET-certified engineers and licensed fire alarm contractors who design, install, inspect, and maintain fire alarm and ARC (Auxiliary Radio Coverage) systems fully in compliance with FDNY requirements. Beyond fire safety, MFS also provides IT communication systems, structured cabling, and security solutions, offering 24/7 monitoring and maintenance to eliminate downtime and ensure continuous operational safety for businesse</i><br />Target victim <b>website</b>: <i>mfsnyc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aerodiagnostics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32038</link>
<guid>3310199d4a42bc84d71ce62d2d260379</guid>
<pubDate>Wed, 06 May 2026 13:22:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Aerodiagnostics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66e61874a1b62cdaa0f6ae01d79de55cb1cfc437c775c23168170becf8838c8d</i><br /><br />Threat actor <b>description</b>: <i>Aerodiagnostics, LLC is a Massachusetts-based laboratory specializing in advanced diagnostic testing for gastrointestinal disorders, including Small Intestinal Bacterial Overgrowth (SIBO), fructose malabsorption, sucrose intolerance, and lactose intolerance.  The company utilizes state-of-the-art technology and non-invasive breath tests to provide accurate results while ensuring a high level of customer service  Laek: 50GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>aerodiagnostics.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moorman-Harting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32035</link>
<guid>f8ace07a82a8c427a24248210e8f783b</guid>
<pubDate>Wed, 06 May 2026 12:50:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Moorman-Harting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5b89ab282d12ac7d6c7b51c2d1eba8dff2c1a2013b979d0e91d6fa5d2965d67</i><br /><br />Threat actor <b>description</b>: <i>Moorman, Harting & Company is a comprehensive wealthcare firm that provides a variety of soluti
ons for tax, accounting, and financial needs. Their services include accounting, payroll, tax p
reparation, retirement planning, and personalized financial coaching.

We will upload 21gb of corporate data soon. Employee personal information (passport numbers, Dl
s, SSNs and other sensitive information), client files, financials, contracts and agreements, i
nternal confidential files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>moormanharting.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ABI-and-Ideal-Tape</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32034</link>
<guid>f1a5c7d32bac9f6ac84f5aadb1d8a94b</guid>
<pubDate>Wed, 06 May 2026 12:20:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ABI-and-Ideal-Tape</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edc4b6e4fa71500b51f8b6c0a22d8c5252b30e6dec2eb06e3032aa6b478d7939</i><br /><br />Threat actor <b>description</b>: <i>From the creation of our very first line of friction tapes in 1908, we have stuck to our belief
in developing quality products, holding ourselves to the highest standards. ABI Tapes products
are primarily sold through a worldwide network of select industry-focused distributors and con
verters. ABI and Ideal Tape are subsidiaries of American Biltrite Inc.

We will upload 11gb of corporate data soon. Employee personal information, customer files, proj
ects, contracts, internal confidential files, etc.
</i><br />Target victim <b>website</b>: <i>abitape.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heatherwood-Golf-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32027</link>
<guid>31f16d3ab7ac2c7e89fc56fe45eae7e1</guid>
<pubDate>Wed, 06 May 2026 10:08:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Heatherwood-Golf-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a5334583f1829d1c0868597eaee2267c3237ca00352fe2eec5b224cabc16a59</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/heatherwood-golf-club/46681078 www.heatherwood.com For more than 60 years, Heatherwood has been committed to building upscale residential rental communities, commercial property and luxury urban spaces. Heatherwood is a privately owned, family run company founded on the principles of exemplary service, striking design, quality construction and appreciation for natural beauty. It is the company's commitment to these principles that has made Heatherwood one of the most highly regarded leaders in the industry. The company's formidable portfolio spans rental property from Brooklyn and Queens to the east end of Long Island. Heatherwood made its mark in the construction industry in the 1950's; building 5,000 homes across Long Island. The company has maintained the company's presence in the "for sale" real estate market with the completion of two senior communities; The Meadows at Valley Stream (2000) and Dutchgate Condominiums (2006).</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Engineered-Advantage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32017</link>
<guid>45d95af3e246cc5a1514a05b6c5a172a</guid>
<pubDate>Wed, 06 May 2026 10:07:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Engineered-Advantage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b1bfd9c670112d792d60b08826b91591c87989cb6be5533e26d13634400a30a</i><br /><br />Threat actor <b>description</b>: <i>eapsc.net zoominfo.com/c/engineered-advantage/1292942990 Engineered Advantage, PSC (EA) is a multidisciplinary architecture and engineering (A/E) firm founded in 2011 and headquartered in San Juan, Puerto Rico, serving both public and private sector clients. The company's expertise spans architecture, civil and structural engineering, forensic engineering, water resources, field inspections, damage assessments, and construction management. EA operates across Puerto Rico, Florida, and the U.S. Virgin Islands, and notably provided post-hurricane recovery engineering services following Hurricanes Irma and Maria in St. Thomas, St. Croix, and St. Maarten</i><br />Target victim <b>website</b>: <i>eapsc.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Millennium-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32014</link>
<guid>d765ecd5a294f535f8e41969d0319e06</guid>
<pubDate>Wed, 06 May 2026 10:07:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Millennium-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3224723567d8ebfb829c6c6616990e5b0612fbc825eca9982a742726a52843f6</i><br /><br />Threat actor <b>description</b>: <i>millenniumptrs.com zoominfo.com/c/millennium-partners-inc/483051874 Millennium Partners is a premier luxury real estate developer founded in 1991 and headquartered in New York City, with over three decades of transforming urban neighborhoods through landmark mixed-use developments in gateway cities such as New York, Boston, San Francisco, and Washington D.C.. The company has pioneered the luxury branded residential experience by forging first-of-their-kind partnerships with Ritz-Carlton and Four Seasons, and today owns a portfolio worth over $5 billion encompassing 3,200+ condominiums, 10 hotels, 2 million sq ft of office space, and 1 million sq ft of retail. In 2023, Millennium Partners opened Winthrop Center in Boston — the world's largest Passive House office building — setting a new global benchmark for sustainability and human-centered design</i><br />Target victim <b>website</b>: <i>millenniumptrs.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sysco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31985</link>
<guid>a5f8cafb26aa3fd483c73e20ddf07858</guid>
<pubDate>Wed, 06 May 2026 01:56:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sysco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30a31d39181597b1b953c3d93b6cd784ba381e16c285bcbe54489c73a69821af</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ropers-Majeski</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31987</link>
<guid>7909706a139205d2861549e24ac45dda</guid>
<pubDate>Wed, 06 May 2026 01:20:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Ropers-Majeski</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d346d9d48c1585287c459e536c351a7c47340662acef35c460076b2ca946861</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Ropers Majeski is a law firm based in the United States, operating primarily in California. The firm provides legal services across a range of practice areas including litigation, insurance defense, business law, employment law, and professional liability. It serves corporate clients, insurers, and individuals, with offices in multiple California cities. The firm is known for its work in complex civil litigation and risk management counsel.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scales-and-Associates-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31986</link>
<guid>7c47a747dc24980c953a0cbe15e6c60b</guid>
<pubDate>Wed, 06 May 2026 00:24:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Scales-and-Associates-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b89313f9b8b5145dd9d4445ad116ee0bae30556ea9af4720a7e853cf6f23e1bb</i><br /><br />Threat actor <b>description</b>: <i>Scales & Associates, Inc. is a firm that specializes in engineering and architecture, focusing on creating intelligent and economical solutions for their clients. They adopt a strategic, big-picture perspective, ensuring that all components of a project work together efficiently for overall success. Their services are designed to meet both current needs and future demands. The company is DBE certified and operates from Detroit, MI.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trimble-Inc--Gerrard-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31980</link>
<guid>cc004e653cc78176c82cba30329b1c68</guid>
<pubDate>Tue, 05 May 2026 20:34:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Trimble-Inc--Gerrard-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94a4b0ec56e3ed946ee910bac34e17e2929f9aabc4b7ab15494e6def2ef313e0</i><br /><br />Threat actor <b>description</b>: <i>Technology company Trimble (trimble.com) and Gerrard Inc (gerrardinc.com). ~18 Trimble email addresses.</i><br />Target victim <b>website</b>: <i>trimble.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atencio-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31979</link>
<guid>dd363b260a3b26e9ebdc93193730e961</guid>
<pubDate>Tue, 05 May 2026 20:34:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Atencio-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>18b2e46980bde4b7e17f6c30ba62d540d8642d6f5177341ed28d215c07959d04</i><br /><br />Threat actor <b>description</b>: <i>Civil engineering & land surveying firm. Services: site plans, boundary surveys, OWTS (septic) design, fire line design, elevation certificates, flood plain analysis. Clients in Las Animas County, Pueblo County, Florence CO area.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Desert-Christian-Schools-DCS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31977</link>
<guid>523b96f500fcb4459aa8718e387c9b23</guid>
<pubDate>Tue, 05 May 2026 20:33:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Desert-Christian-Schools-DCS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e87a17365884b31b5793d561e82c401a348f41610f180bd3819b7ffdae619c7d</i><br /><br />Threat actor <b>description</b>: <i>K-12 Christian school affiliated with First Baptist Church of Lancaster, CA. ADP payroll, DCFS childcare program, City of Lancaster Water Safety program. Financial docs: P&L, Balance Sheet, Trial Balance, 1099s. School Board minutes 2025.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>CourtSmart</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31976</link>
<guid>9c41f284776f06b72aab705c9fdcde86</guid>
<pubDate>Tue, 05 May 2026 20:33:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>CourtSmart</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c88a434131005ce1d3bd7ab6d8ec6937cd2951b30084492222c0e4ffe5d6f818</i><br /><br />Threat actor <b>description</b>: <i>Court technology company. Domain courtsmart.com / COURTSMART2. Dev server: dev-rich20.courtsmart.com. Connections to JIS.org, nashville.org.</i><br />Target victim <b>website</b>: <i>courtsmart.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Raycolighting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31969</link>
<guid>fc0a485cf6784acc2104ec94f7dcb07d</guid>
<pubDate>Tue, 05 May 2026 20:30:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>Raycolighting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed5c4ebee719b626e7663a03a5291fcbdd54a10c31e809cfc88e5bd9a29db4ef</i><br /><br />Threat actor <b>description</b>: <i>Organization with 2 emails extracted. Domain: raycolighting.com</i><br />Target victim <b>website</b>: <i>raycolighting.com</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Celeris-Networks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31965</link>
<guid>dbc4d971889417b0f4cb0434de170a51</guid>
<pubDate>Tue, 05 May 2026 19:54:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Celeris-Networks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>543cf3ee25dbe0d47464b7aa656ad0aa718a98305d5a2846c133c5478ebffb1b</i><br /><br />Threat actor <b>description</b>: <i>Celeris Networks is a business IT support provider based in Knoxville, specializing in managed IT services, cybersecurity solutions, and cloud managed services. The firm serves various industries, including accounting, distribution, legal services, nonprofits, and professional services. Composed of expert technology specialists, Celeris Networks aims to alleviate IT challenges and help local businesses maximize productivity. With a commitment to personalized service, they ensure that clients receive dedicated support tailored to their needs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bay-State-Land-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31964</link>
<guid>0cc4cb598660e0a7f3a5679e218c0328</guid>
<pubDate>Tue, 05 May 2026 19:54:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bay-State-Land-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9d88f9e867870435577cd851cf4d285885989e87245e351f91b73670d074462</i><br /><br />Threat actor <b>description</b>: <i>Bay State Land Services Inc is a company that operates in the Architecture, Engineering & Design industry. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maximum-Mold</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31962</link>
<guid>3f41d2337b29507d20a2fdd7f8305110</guid>
<pubDate>Tue, 05 May 2026 15:50:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Maximum-Mold</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad0fed5c63c803ab4f33b75d4c3f46d6faaa20547090b90394344b7c47c28b8d</i><br /><br />Threat actor <b>description</b>: <i>Maximum Mold is a specialized provider of tooling and machining solutions, focusing on the des
ign, engineering, and manufacturing of die cast dies, trim dies, and plastic injection molds.

Here is the access to upload company data. Employee personal information (passports, and other
docs), customer files, contracts and agreements, projects, NDAs, etc.

You will find several password-free archives. Click on any of them to start the download.

Download link

https://3i7uisihrgv3v7kjafmhahhcmtjfepckhw5vournekuamhbt37liplid.onion/LEAKS_1/maximummold.com
/
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Punch--Associates-Investment-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31961</link>
<guid>8069a0ddc3a9e6fbcce919955738fc73</guid>
<pubDate>Tue, 05 May 2026 15:20:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Punch--Associates-Investment-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63a5244ec5ff78f5f4c543d264ee98e8a6ca160d6f9b7f8fb8d8b1105f4cbba1</i><br /><br />Threat actor <b>description</b>: <i>Punch & Associates is a boutique investment advisory firm based in Edina, MN. They offer specia
lized investment advisory services tailored for private clients and institutions. The firm focu
ses on providing personalized financial strategies to meet the unique needs of their clients. W
ith a commitment to excellence, Punch & Associates aims to help clients achieve their financial
goals.

We will upload 10gb of corporate data soon. Detailed client personal information (passports, SS
Ns, DLs and so on for almost 80 ppl), employee personal files, lots of confidential files (fina
ncials and personal docs), contracts and agreements, projects, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>EXPEDITOR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31958</link>
<guid>5f447df2f1d70893e3805f3dab9183c4</guid>
<pubDate>Tue, 05 May 2026 12:52:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>EXPEDITOR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>beac0dc4bf2ef0f01be68b46c7a19b1715cb66a3b356140b16bcc1d37f6ed187</i><br /><br />Threat actor <b>description</b>: <i>Expeditor Systems specializes in improving patient flow through innovative light signaling systems designed for medical practices and institutions.  Their solutions, including the LEAN Patient Flow System and Life Safety Nurse Call Systems, aim to enhance patient experience, increase operational efficiency, and boost revenues.  With over 40 years of experience and a client base exceeding 8,000  Laek: 50GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>brittanyresidential.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31957</link>
<guid>8e9240a9f16db317677aa70bfeb6f560</guid>
<pubDate>Tue, 05 May 2026 11:53:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ms13089</b> claims attack for <b>brittanyresidential.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1676b14dfb5e53264db86d1ce1c23bf8eeba89aadf5c5f5425d59e1346d3c42</i><br /><br />Threat actor <b>description</b>: <i>At Brittany Residential, Inc., we believe in creating a world where individuals with developmental disabilities are supported, valued, and empowered to live fulfilling lives. Our dedicated team provides compassionate, person-centered care that...</i><br />Target victim <b>website</b>: <i>brittanyresidential.com</i>]]></description>
<category>ms13089</category>
</item>
<item xmlns:dc='ns:1'>
<title>childplace.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31951</link>
<guid>53b61f754a98bc9eb3d87cd3aa6f053f</guid>
<pubDate>Tue, 05 May 2026 01:53:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>childplace.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef4ec948b1e5b6a677df1cf4810374bfcdad108856d1a37198c6cc6edb2736f7</i><br /><br />Threat actor <b>description</b>: <i>Childplace Family Services is dedicated to nurturing children and empowering families through a range of services including fostering, adoption, counseling, and community support. The organization aims to serve children and families at risk, particularly those who have experienced abandonment, abuse, or neglect. With a history of over 50 years, Childplace has successfully helped thousands of children find loving homes and provided essential support to families in need. Their mission is rooted in promoting hope and healing within the community, guided by a spirit of Christian love. Employees: 100 Revenue: $7.2 Million Industry: Non-Profit & Charitable Organizations  Phone Number: (812) 282-8248 </i><br />Target victim <b>website</b>: <i>childplace.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seagate-Capital-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31942</link>
<guid>68043a653a7d7658480e1f4743660067</guid>
<pubDate>Mon, 04 May 2026 20:55:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Seagate-Capital-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1051fd5aa47f5efe10b06772919fb1e55042509c1bb04f7ae275d06c82602f1</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Office-of-Steven-R-Smith</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31933</link>
<guid>83cbc5e9ad9b537435036c2cdc4b0074</guid>
<pubDate>Mon, 04 May 2026 19:54:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Law-Office-of-Steven-R-Smith</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca50f90b72a58d2b9f2e0894df882a508db7d471506e2f7b3e0a872c9b858867</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Foxstone-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31934</link>
<guid>f2d457c33287d2cfe8320b10942aa5b9</guid>
<pubDate>Mon, 04 May 2026 19:54:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Foxstone-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5359e9b952d77151548790e9abb218ae5a78bde5686c3d0f2f4e9a500c99540</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rizzuto-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31936</link>
<guid>2cd019e887a1ef10c8c8b3ccd92f2f9b</guid>
<pubDate>Mon, 04 May 2026 19:54:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rizzuto-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e3e8c904edfa313283227e15b33c13b9a57be7435df5291b3b6a4726219bf24</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morning-Star-Tours</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31941</link>
<guid>64a45edd9346a078f0d17405a9028424</guid>
<pubDate>Mon, 04 May 2026 18:23:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Morning-Star-Tours</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>566c020f1cbd07f1b2535664309bf1c6064524cead493389c09ef316bbf1c5b4</i><br /><br />Threat actor <b>description</b>: <i>Journeys that can change lives</i><br />Target victim <b>website</b>: <i>morningstartours.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cushman--Wakefield</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31940</link>
<guid>afbf2f0865f2c7e1b1cb8ebc4914915c</guid>
<pubDate>Mon, 04 May 2026 17:55:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cushman--Wakefield</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae9f16f2a2d28146d29b659213f1765d825d9b699becc13aeb3aa95d2c2e30f1</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cushmanwakefield.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.cswindustrials.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31938</link>
<guid>0c6d3f65c999673f0cc19ecc99e81f20</guid>
<pubDate>Mon, 04 May 2026 17:51:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>www.cswindustrials.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83e60fff6ed5536ee5f0d2d3a033d2c3147bef49d281a7d8542bfb4156489bf2</i><br /><br />Threat actor <b>description</b>: <i>If the company's management does not contact us within 24 hours, we will publish 540 GB of the company's internal files. 

CSW Industrials, Inc. is a diversified industrial growth company that operates across contractor solutions, specialized reliability solutions, and engineered building solutions.…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/csw-industrials-inc/370826515</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lonestar-Truck-Group--Tag-Truck-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31932</link>
<guid>7f6e7707c60d6274e2e0ce07bad488de</guid>
<pubDate>Mon, 04 May 2026 16:52:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Lonestar-Truck-Group--Tag-Truck-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecccbf77bc5564e23aa0b213e8458e3165bc22d9a34c10bf364bb9a3196a95fc</i><br /><br />Threat actor <b>description</b>: <i>Lonestar Truck Group consists of multiple dealerships that sell new and used trucks and trailers, as well as providing service and parts. They work with a vast number of customers and businesses, yet they have failed to prioritize security. As a result, personal data of employees, contact information for the companies they work with, and a significant number of customer records have been leaked online. We are also presenting their confidential and financial documents for your review.</i><br />Target victim <b>website</b>: <i>tntxtruck.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Sandstone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31927</link>
<guid>5c8010125583d79426b73845df9f57f6</guid>
<pubDate>Mon, 04 May 2026 14:55:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Sandstone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df75404f2746068b2e5a1bf5ce39e75cd4347f82bedebf31ef9ac138f6faf610</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Johnson--Johnson-Innovative-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31930</link>
<guid>e25f42d74afdf8c6ca6a3b7ece3af051</guid>
<pubDate>Mon, 04 May 2026 13:26:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Johnson--Johnson-Innovative-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9813704dab3e3c7835cb149a0522cf1462972b38f05ae0fb1bce6c2205dae42</i><br /><br />Threat actor <b>description</b>: <i>Johnson & Johnson Innovative Medicine (formerly known as Janssen Pharmaceuticals) is the pharmaceutical division of the American corporation Johnson & Johnson, specializing in the development and production of revolutionary medicines. The company focuses on creating treatments for the most complex diseases, transforming the future of healthcare.-CAR-T Research https://www.jnj.com/innovativemedicine/</i><br />Target victim <b>website</b>: <i>www.jnj.com/innovativemedicine</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>emtco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31923</link>
<guid>909c71100210781d37a568c5fc14e627</guid>
<pubDate>Sun, 03 May 2026 04:26:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>emtco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b578ae1c87e4ec59b8fd4de1e085d07af770712006fe0d155bb2169742f1edca</i><br /><br />Threat actor <b>description</b>: <i>+1 3169426147 . Engineered Machine Tool, Inc., based in Wichita, Kansas, specializes in providing manufacturing firms with custom machinery and tooling designed to enhance production efficiency. Since 1987, the company has developed a range of automated machines and equipment, including Automatic Storage and Retrieval Systems and Large Tool Palletizing Systems. EMT offers comprehensive services from initial concept through to complete installation, ensuring tailored solutions for their clients' specific needs. Their focus is on delivering high-performance automation tools for various industrial applications Stolen: 180gb 698k files</i><br />Target victim <b>website</b>: <i>emtco.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cushman--Wakefield-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31920</link>
<guid>b1f4cf3abb5cca5187cc8e102e99e02a</guid>
<pubDate>Sun, 03 May 2026 03:25:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Cushman--Wakefield-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffa73e20f26c33ffdec07356b8f74838337b0b50f31e647943d8cc7fb6f12b94</i><br /><br />Threat actor <b>description</b>: <i>Over 500k Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 3 May 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fiserv</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31919</link>
<guid>b32ea661205e379f9457cb730f76413d</guid>
<pubDate>Sun, 03 May 2026 03:21:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Fiserv</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9024fc0b33710ad12a091197972a6a1c4767388960c57872a4cd509d2b9f74f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Fiserv is a global financial technology company headquartered in Milwaukee, Wisconsin, United States. It provides financial services technology solutions including payment processing, core banking systems, digital banking platforms, and merchant acquiring services. Serving banks, credit unions, retailers, and businesses worldwide, Fiserv operates across the fintech and banking technology industry and is one of the largest providers of financial services infrastructure globally.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Standard-Examiner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31909</link>
<guid>d82c11ec1571cc49a9e5d67285a26668</guid>
<pubDate>Sat, 02 May 2026 19:54:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Standard-Examiner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a93f6d89555f254ed201391aa4b2494a800fce0939c00a2117c4e5de2511adb</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Star-Signs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31910</link>
<guid>29a3d252405fb67dcf7e17e04522fff0</guid>
<pubDate>Sat, 02 May 2026 19:54:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>North-Star-Signs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a05efbadd4008703a1281c569810ae35ea9ad9884d4ddede0d573d4261d6044</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Armstrong-George-Cohen-Will-Ophthalmology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31911</link>
<guid>36686212b9b05b73736f0d77f98377bb</guid>
<pubDate>Sat, 02 May 2026 19:54:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Armstrong-George-Cohen-Will-Ophthalmology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6591bebe4a276ef7ef4bab11d33a0ae48a4170b6bcf913323e5bd26ef1055322</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Star-Precision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31913</link>
<guid>18a24c035870fcbdbcda39e4ecf71401</guid>
<pubDate>Sat, 02 May 2026 19:54:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Star-Precision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0fb17fdcb7b5eebb4084ff23eb32330dc55b13818e473633028342110af6412</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beyond-Measure--Associates-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31908</link>
<guid>28ca2a3ef786a75109a9e2af23c1a4f7</guid>
<pubDate>Sat, 02 May 2026 10:25:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Beyond-Measure--Associates-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38999af7eaaf6b3ddb3d8ec9a189854da82770fd4690e973eaeedbb11ceda7aa</i><br /><br />Threat actor <b>description</b>: <i>Church Design, Engineering, Financial & Construction Services</i><br />Target victim <b>website</b>: <i>churchdesign.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cytek-Biosciences</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31906</link>
<guid>6107f0a7614917c3c78a74ebe45f00ca</guid>
<pubDate>Sat, 02 May 2026 08:54:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Cytek-Biosciences</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28ab2589fe35d1fbc61c189db44d9d735608081848ffbdd6e0dc6b346c33dd67</i><br /><br />Threat actor <b>description</b>: <i>A biotechnology firm that develops and supplies advanced, cost-effective flow cytometry instruments and related services used worldwide by researchers and clinicians. Its compact systems and streamlined workflows enable high-throughput, single-cell analysis for applications such as cancer immunology, leukemia and lymphoma diagnosis, and transplant monitoring. Distinguished by offering high-end capabilities at lower cost, the company accelerates scientific discovery through technical innovation, exceptional customer support, and a commitment to ethical practices and community engagement. Headquartered in Fremont, California, it has been publicly traded on NASDAQ since 2021. We have 7.36 TB of downloaded data.</i><br />Target victim <b>website</b>: <i>cytekbio.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zampell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31905</link>
<guid>bd41a065d4640c9dd3c1e06ce9c820dc</guid>
<pubDate>Sat, 02 May 2026 08:53:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cmdorganization</b> claims attack for <b>Zampell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>418b112f15b9de980fdb4df925b78ba74d699ee4ac55f0a270bd062ff1b776da</i><br /><br />Threat actor <b>description</b>: <i>Zampell Ltd is a leading provider of refractory services, offering comprehensive solutions from design to ongoing maintenance. They cater to various industries, including power generation, biomass, fossil fuel, and petrochemicals, ensuring safety and efficiency in their operations. The company specializes in both standard and bespoke refractory products, delivering tailored services to meet client needs. With a commitment to quality and safety, Zampell aims to exceed customer expectations in all aspects of their service.</i><br />Target victim <b>website</b>: <i>www.zampell.com</i>]]></description>
<category>cmdorganization</category>
</item>
<item xmlns:dc='ns:1'>
<title>Minidoka-Memorial-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31904</link>
<guid>42aa61c7ccfa95dc4db4d894530def8a</guid>
<pubDate>Sat, 02 May 2026 08:48:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackwater</b> claims attack for <b>Minidoka-Memorial-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fe9e3e2506542d2e36ce2fab2aff99541c7b04fe34a505a2ebc675378e6d57f</i><br /><br />Threat actor <b>description</b>: <i>Data will be published after 7 days.</i><br />Target victim <b>website</b>: <i>minidokamemorial.org</i>]]></description>
<category>blackwater</category>
</item>
<item xmlns:dc='ns:1'>
<title>Compass-Housing-Alliance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31901</link>
<guid>ea2486be22140cf8214932e344a07215</guid>
<pubDate>Sat, 02 May 2026 08:47:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackwater</b> claims attack for <b>Compass-Housing-Alliance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf393b14dda1c93dc4e4aea96b3ce3c9ee4fff60147821bb82cce9954eb80cd7</i><br /><br />Threat actor <b>description</b>: <i>Compass Housing Alliance is dedicated to developing and providing essential services, shelter, and affordable housing to ensure that everyone in the community has a safe place to call home.</i><br />Target victim <b>website</b>: <i>compasshousingalliance.org</i>]]></description>
<category>blackwater</category>
</item>
<item xmlns:dc='ns:1'>
<title>Site-Design-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31897</link>
<guid>14b14c86550a0d4c618b4764e11d49db</guid>
<pubDate>Sat, 02 May 2026 06:50:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Site-Design-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ebf53247d6caf9201524e06ea4ccdee5162d4dcfafa7d5e930f59bad1fa3390</i><br /><br />Threat actor <b>description</b>: <i>Site Design Group Ltd. is a Chicago-based firm specializing in landscape architecture and urban design.</i><br />Target victim <b>website</b>: <i>site-design.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>TSYS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31895</link>
<guid>4bbc7449ca4ad63ba9e6094180cc65cb</guid>
<pubDate>Sat, 02 May 2026 03:54:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>TSYS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc311e3c26faf3e61b140466ba62614ba979c6ebab2937452b05d78492908549</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TSYS, or Total System Services, is a US-based payment solutions company headquartered in Columbus, Georgia. It operates in the financial technology and payment processing industry, providing services such as credit and debit card processing, merchant services, and payment management solutions to financial institutions, businesses, and consumers worldwide. TSYS became a subsidiary of Global Payments following a merger in 2019.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epiq-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31894</link>
<guid>ca50333df78f2f7bd42ac688af0af3e9</guid>
<pubDate>Sat, 02 May 2026 03:54:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Epiq-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffe7daa39e26de8aa1a6703c62018e1014bfed361c7a10b97573a8024558bd50</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Epiq Global is a US-based legal services company specializing in technology-driven solutions for complex legal matters. It provides services including class action and mass tort administration, bankruptcy case management, eDiscovery, document review, and legal notification. Operating across multiple countries, Epiq serves law firms, corporations, and government entities, helping manage large-scale legal proceedings efficiently.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>northshoreenv.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31893</link>
<guid>67a5bfdf2c0a67f87eb46b3e9a4a7a38</guid>
<pubDate>Sat, 02 May 2026 00:23:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>northshoreenv.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c7f6bffa81382f316eb880df9a1cd4f8c0f43cada7153389e42f912fd6e34aa</i><br /><br />Threat actor <b>description</b>: <i>North Shore Environmental Consultants is a progressive environmental company that provides a wide range of environmental management and consulting services to help clients navigate complex environmental and regulatory challenges. With over 20 years of experience, they offer solutions in areas such as remediation, emergency spill response, air quality, and corporate consulting. Their client base spans various industries across western Canada, and they are recognized for their innovative operational programs and commitment to client satisfaction. North Shore is dedicated to fostering a sustainable future while continuously expanding their expertise and services. Employees: 200 Revenue: $23.5 Million Industry: Business Services Phone Number: (780) 467-3354</i><br />Target victim <b>website</b>: <i>northshoreenv.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Avnet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31889</link>
<guid>6cea18e92877f11b15280b17416ac030</guid>
<pubDate>Fri, 01 May 2026 17:13:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Avnet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a7d58cea1b86edafb7ef73a38424936d49130048695dd191e7598a5af47c369</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Avnet is a global electronic components distributor and technology solutions provider headquartered in Phoenix, Arizona, USA. Founded in 1921, it operates in the technology and electronics distribution industry, serving manufacturers and designers worldwide. Avnet supplies semiconductors, interconnects, passives, and electromechanical components, while also offering supply chain management, design, and engineering services across North America, Europe, and Asia.</i><br />Target victim <b>website</b>: <i>avnet.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lena-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31888</link>
<guid>01e651518630062d985188c1f0dbd83a</guid>
<pubDate>Fri, 01 May 2026 17:11:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Lena-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79eeff4e9e0427c4444776f179f3695e90d23c6813590cf90708c6ee9ee0489e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>lena.io</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woundtech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31887</link>
<guid>3445ee86ba8817378a8577a75444f5d7</guid>
<pubDate>Fri, 01 May 2026 17:11:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Woundtech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fc042efd10e2b20c05462be84130d884410d599e325c58e1696e355f063d187</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Woundtech is a US-based healthcare company specializing in advanced wound care management services. It provides in-home and facility-based wound care treatment to patients, primarily serving Medicare and Medicaid populations. The company employs clinicians who deliver specialized wound care directly to patients in skilled nursing facilities and home settings, focusing on chronic and complex wound treatment across the United States.</i><br />Target victim <b>website</b>: <i>woundtech.net</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>LexisNexis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31885</link>
<guid>6b1e4ccdd469e7c0f4411a468b7910f7</guid>
<pubDate>Fri, 01 May 2026 17:09:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>LexisNexis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5c6bdb75054a1eb47d6331077ccf4b301dc8e8200e1ab8ec56f6434727e2c45</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] LexisNexis is a global information and analytics company headquartered in the United States. It operates in the legal, regulatory, and business intelligence industries, providing research tools, data analytics, and risk management solutions. Its platforms are widely used by legal professionals, law enforcement, and enterprises to access vast databases of legal documents, news, public records, and compliance information.</i><br />Target victim <b>website</b>: <i>lexisnexis.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>MCO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31884</link>
<guid>2f2025ae2e57e71843298d80bed5cfde</guid>
<pubDate>Fri, 01 May 2026 17:08:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>MCO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e738266b452f0aaa092e213583ba33927a5f83d6d3c427180c7139d26cf6302f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

The acronym "MCO" is too ambiguous to identify a specific company with confidence. Multiple organizations share this abbreviation across different industries and countries. Please provide additional context such as the full company name, industry, or country of operation to allow for an accurate and reliable description.</i><br />Target victim <b>website</b>: <i>mycomplianceoffice.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>ReFocus-AI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31883</link>
<guid>a100e66d10d9f367ba4dcc5917657159</guid>
<pubDate>Fri, 01 May 2026 17:06:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>ReFocus-AI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8eefef75047dd351df76b75749851c214a81368503fac5df95e8dddb5f6db58</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>refocusai.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hatica</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31882</link>
<guid>60b4471e1fb1e8e0d266d97071669ccb</guid>
<pubDate>Fri, 01 May 2026 17:06:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Hatica</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90ddb7cb5d113094d1dc418569a2512ee894687a07ba7d18c6ca43a2db7d28fe</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Hatica is an engineering analytics platform founded in India that helps software development teams improve productivity and well-being. It aggregates data from tools like GitHub, Jira, and Slack to provide insights into developer workflows, sprint performance, and team health metrics. Operating in the developer productivity and engineering management industry, Hatica serves engineering leaders seeking data-driven decisions to reduce burnout and optimize delivery.</i><br />Target victim <b>website</b>: <i>hatica.io</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMTA-Sherwood-Mutual-Telephone-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31865</link>
<guid>c4211b6fddf7ddf821087989ae514550</guid>
<pubDate>Fri, 01 May 2026 16:56:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>SMTA-Sherwood-Mutual-Telephone-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4899e4e4b60b8924c44898f6ad163ab84b75ebc611e3873621a328a5ad6d0003</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peyton-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31867</link>
<guid>a65b920e6ce1070509a476e3b48aa56f</guid>
<pubDate>Fri, 01 May 2026 16:56:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Peyton-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>307b5d6e823513cf12524b9b8b973ac24ba7369bdf34551b96a6ec665038a791</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accurate-Nursing-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31868</link>
<guid>c732e4cb57268226f297e389d8382baf</guid>
<pubDate>Fri, 01 May 2026 16:56:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Accurate-Nursing-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad27d4e0dc1c29493b39d9e717ee55cfd4b772199aace4eb6cd9fb9383161965</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nordstern-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31880</link>
<guid>c0b9b187cfd326a101efae8da2a1936e</guid>
<pubDate>Fri, 01 May 2026 16:51:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Nordstern-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc6dcc5170252c001306866d0f8ba41bcc5c174c42d299a50df8c26dc781ad29</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>nordsterntech.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>ParkEngage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31879</link>
<guid>b7c45703742d291cecb044204f548f8d</guid>
<pubDate>Fri, 01 May 2026 16:51:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>ParkEngage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ae01a894fc8e58081b7f99bc46c9d56aa8e1d315d8efd7fd5d8c001a2744017</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] ParkEngage is a US-based technology company specializing in smart parking solutions. It provides cloud-based software platforms that help parking operators manage reservations, payments, and customer engagement. Its services cater to airports, hospitals, universities, and commercial facilities. The company focuses on enhancing the parking experience through digital tools including mobile apps, contactless payments, and data analytics to optimize parking operations and revenue management.</i><br />Target victim <b>website</b>: <i>parkengage.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saleskido</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31878</link>
<guid>9d57a1e06a731e1b2377de6781e881b1</guid>
<pubDate>Fri, 01 May 2026 16:50:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>fulcrumsec</b> claims attack for <b>Saleskido</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75bf2ac57126b97479f200fa38ea149e5ca9aae70c800be8e230126462a6f49d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>saleskido.com</i>]]></description>
<category>fulcrumsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>wyomingcountyny.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31863</link>
<guid>80a3f634893bdf5d63c679e5f99182b2</guid>
<pubDate>Fri, 01 May 2026 13:35:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>wyomingcountyny.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfd06f35947645e8a0de536eb663cc47e6f8ac591d54db6822535eb8719e65e9</i><br /><br />Threat actor <b>description</b>: <i>Wyoming County provides various government services to its residents, including job opportunities, economic development initiatives, and electronic forms for managing county affairs. The county actively organizes community events, such as pop-up f</i><br />Target victim <b>website</b>: <i>wyomingcountyny.gov</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>sequoiadental.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31862</link>
<guid>92699ee8e81849b1817a5d73d3bf8e02</guid>
<pubDate>Fri, 01 May 2026 13:34:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>sequoiadental.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3fd9143086dd7a1706f67c09690322898c74222f72c0bff95fd77e8c5ed8040</i><br /><br />Threat actor <b>description</b>: <i>Sequoia Dental Office provides a wide range of dental services including general, cosmetic, orthodontic, and restorative dentistry. Located in Visalia, CA, they are dedicated to patient comfort and use advanced technology to enhance care, offering</i><br />Target victim <b>website</b>: <i>sequoiadental.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>townofnorwell.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31861</link>
<guid>b96c50b7b132bacf5adba4adca9a4f10</guid>
<pubDate>Fri, 01 May 2026 13:34:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>townofnorwell.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07dbee19aaf55fc29d13ee0f2646289506818c0a58d639eea1aceece1f14feb0</i><br /><br />Threat actor <b>description</b>: <i>The Town of Norwell MA offers a variety of municipal services including animal control, building permits, health clinics, and recreational programs. It serves the residents of Norwell by ensuring public safety, facilitating community events, and p</i><br />Target victim <b>website</b>: <i>townofnorwell.net</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>curedentalbeltontx.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31860</link>
<guid>e8d0467189fccf2dff63796aa47202fc</guid>
<pubDate>Fri, 01 May 2026 13:34:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>curedentalbeltontx.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06256cdd024c13d5693a6fd2e3a0ee2352190da7757f2bf417b7f8a448538508</i><br /><br />Threat actor <b>description</b>: <i>Cure Dental is a company that operates in the Dental Offices industry. It employs 10to19 people and has 1Mto5M of revenue. The company is headquartered in Belton, Texas.</i><br />Target victim <b>website</b>: <i>curedentalbeltontx.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>austinplasticandreconstructivesurgery.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31859</link>
<guid>4585ad1e2cbe41891c011a3e0e73e1d4</guid>
<pubDate>Fri, 01 May 2026 13:34:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>austinplasticandreconstructivesurgery.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d910c2459a8293862b857af4bfed15d7c8ae2687818a9162b30333c84fbe3e0</i><br /><br />Threat actor <b>description</b>: <i>Austin Plastic Reconstructive Surgery, led by Board-Certified Plastic Surgeon Dr. Christine Fisher, specializes in breast reconstruction and a variety of cosmetic surgery procedures. The clinic caters to individuals seeking to enhance their beauty</i><br />Target victim <b>website</b>: <i>austinplasticandreconstructivesurgery.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>hsjlawyers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31858</link>
<guid>27adbf7fc9dd2c144f5cee93569fe2c1</guid>
<pubDate>Fri, 01 May 2026 13:33:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>threeam</b> claims attack for <b>hsjlawyers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aada07bd47a9a2f9067febda6a4fb50648968842f892fb5834ea778ac66e34c4</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1971, HSJ Lawyers is a prominent law firm located in Prince George, British Columbia, serving the legal needs of clients throughout Northern BC. With a team of 15 lawyers and 25 staff members, the firm specializes in various areas inclu</i><br />Target victim <b>website</b>: <i>hsjlawyers.com</i>]]></description>
<category>threeam</category>
</item>
<item xmlns:dc='ns:1'>
<title>Winona-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31849</link>
<guid>4021e2f19e21f8263b768cc19dd8ba70</guid>
<pubDate>Fri, 01 May 2026 10:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Winona-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b319cc3acbbf9714f37d2ed786ab0e68b6ca68bf37223ec4a2d8cfbfc0de1a00</i><br /><br />Threat actor <b>description</b>: <i>Winona County is located in the Mississippi River blufflands of southeastern Minnesota. They have been negligent regarding security and the data they store, which has resulted in a breach and the public disclosure of all the confidential data they held. As a result, we are now able to offer you a large database containing resident records, tax and budget documents, police records, and data from other institutions.</i><br />Target victim <b>website</b>: <i>winonacounty.gov</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roger-D.-Mason-II-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31848</link>
<guid>4882ab9f0909835c444fb6d4ce6d56f0</guid>
<pubDate>Fri, 01 May 2026 10:07:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Roger-D.-Mason-II-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c0d2990289740575ea75f58e7575e5825773e8cb51cdae040100011913ed3b5</i><br /><br />Threat actor <b>description</b>: <i>Florida Auto Dealership Fraud Attorney</i><br />Target victim <b>website</b>: <i>flautolawyer.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mesquite-Plumbing-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31846</link>
<guid>0ac9a79e4aa15b44845b6b553cfcddbd</guid>
<pubDate>Fri, 01 May 2026 10:06:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Mesquite-Plumbing-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27ac7e9c4d62915c881e6cc9613c5c28d702946e53b1bd7e9bf9606471de2967</i><br /><br />Threat actor <b>description</b>: <i>Plumbing Experts</i><br />Target victim <b>website</b>: <i>mesquiteplumbing.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fox-Broermann-Pediatric-Dentistry-of-Tulsa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31845</link>
<guid>a3ad705733dff104469abefd400c670c</guid>
<pubDate>Fri, 01 May 2026 10:06:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Fox-Broermann-Pediatric-Dentistry-of-Tulsa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e33a2b6bc6a84114e27b02d059a97fb4e27e4dbe3bcefdd4197a70f661e3f68f</i><br /><br />Threat actor <b>description</b>: <i>Pediatric dentistry of Tulsa</i><br />Target victim <b>website</b>: <i>foxbroermann.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>flbgroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31844</link>
<guid>1a08d68b5124c82c0131d4e61c85dd8a</guid>
<pubDate>Fri, 01 May 2026 09:57:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>flbgroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc528625ad9a1e2355325bc4c3732184158d0da117f7729cb805e7ff8e53eddc</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>flbgroup.com</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Country-Club-of-Darien</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31834</link>
<guid>27230ac1c8d9d2828e1ff531bec85d37</guid>
<pubDate>Fri, 01 May 2026 09:51:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>The-Country-Club-of-Darien</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1066177cc8722c93920cc02c584ea43e64f8c84acce500888ab55396de3813f</i><br /><br />Threat actor <b>description</b>: <i>- Sales / agent / commercial operations- Industrial / manufacturing / tooling business data- Research & development / technical project data- Business admin / office operations- Software / digital assets / branding</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colorado-Dental-Wellness-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31833</link>
<guid>0bff2aa05a6d99cad062133e6c589de1</guid>
<pubDate>Fri, 01 May 2026 01:21:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Colorado-Dental-Wellness-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65d1ded481ce91f7affe0442a1faeee24b2e15ff001e48d88a5ad661f8410aae</i><br /><br />Threat actor <b>description</b>: <i>Clients’ medical data breach.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carrera-Casting-Corp.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31826</link>
<guid>7e0a4d112e3f40b8f6decb2a7c365f91</guid>
<pubDate>Thu, 30 Apr 2026 23:11:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Carrera-Casting-Corp.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b6e2d9e56b94c2eb27f6433b71da36329c1f81a8fdb0e8fb619a3e1b971cc79</i><br /><br />Threat actor <b>description</b>: <i>• 3 terabytes of corporate data for free. Download it now while it's still available.• Please wait 2 -3 days while files are uploaded to the site.• Brief Overview of Carrera Casting• Carrera Casting is one of the premier jewelry manufacturing and casting companies, located in the heart of New York City. It provides a full range of services for jewelry designers, brands, and retailers.• Core Activities:• Precious Metal Casting: Working with gold of various karats and colors, silver, platinum, and palladium.• 3D Printing and CAD: Converting digital 3D models (CAD) into high-precision wax or resin prototypes for subsequent casting.• Mold Making: Creating high-quality rubber and silicone molds for jewelry mass production and reproduction.• Finishing and Preparation: Basic processing and finishing of cast pieces prior to final polishing and stone setting.• Company Features:• The company is known for its strict quality control, commitment to client design confidentiality, and use of cutting-edge technologies. It is a reliable partner for both emerging independent jewelers and major global brands, offering scalable solutions for jewelry manufacturing.</i><br />Target victim <b>website</b>: <i>arreracasting.com</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>TOWERPOINT-WEALTH-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31824</link>
<guid>d4d9dd228996e12e46d286639eccd3e1</guid>
<pubDate>Thu, 30 Apr 2026 22:27:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>TOWERPOINT-WEALTH-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b71900e177cff797785d2603dc3828d3d5d3e1a306409e5594809f1067da264b</i><br /><br />Threat actor <b>description</b>: <i>Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 4 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 1 May 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Follett-Software-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31823</link>
<guid>3124f20ae7f8b97d325e86b1acfb7d3c</guid>
<pubDate>Thu, 30 Apr 2026 22:27:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Follett-Software-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64e4f0510d2742a38c917c674f63c0b40a4b2579217b01d7dc51dba927187e4e</i><br /><br />Threat actor <b>description</b>: <i>Over 4M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 4 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 1 May 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zinkan--Barker-Development</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31814</link>
<guid>6bbd49be0c3cea3467da28178487f9db</guid>
<pubDate>Thu, 30 Apr 2026 19:55:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Zinkan--Barker-Development</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52f360e9f8730041b56407ce85c90fd7723282a0d1243b071cc0163dfb49550d</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Switch-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31817</link>
<guid>f1ada790ce8f26ed12d4f2070b44bc81</guid>
<pubDate>Thu, 30 Apr 2026 18:55:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Switch-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3233062892bfb829be397fe36de263a9d83fede00c87369967e85a4985363bda</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sees-Candies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31818</link>
<guid>ba224f2bcea2cdd76611b651c3c78069</guid>
<pubDate>Thu, 30 Apr 2026 18:55:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sees-Candies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2b48c2bba4841b4d837f042f2686d5f15e25f7326290eeebdd6ac5ac8660662</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jayeff-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31819</link>
<guid>a570d1a9488ae63742a5d82c946a44ea</guid>
<pubDate>Thu, 30 Apr 2026 18:55:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jayeff-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a95b5fde8f1e1e56a95b520eacdf9ea7ce1f0523ba42d837b34494c12929048</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Progressive-Oral-Surgery--Implantology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31820</link>
<guid>2c86a217e06d86e3db130723abd90fff</guid>
<pubDate>Thu, 30 Apr 2026 17:25:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Progressive-Oral-Surgery--Implantology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a7fa85b45ea35f8a2b106d75f0cdd752bd91774aaa3c0fd3ef5f911650fdd15f</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Liberty-Mutual-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31813</link>
<guid>73618455b2f727ad8fe055241b6b06bd</guid>
<pubDate>Thu, 30 Apr 2026 16:53:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Liberty-Mutual-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8792ff3392f7414251cf83a38060b6aa3d12a050170cd2912b23c66c2247fce9</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Liberty Mutual Insurance is a leading American insurance company headquartered in Boston, Massachusetts. Founded in 1912, it operates in the property and casualty insurance industry, offering products such as auto, home, life, and commercial insurance. The company serves individuals and businesses across the United States and internationally, making it one of the largest global insurers by premium revenue.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>ATF-Aerospace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31810</link>
<guid>a7d3154ed40d4dbebf306630991b11a7</guid>
<pubDate>Thu, 30 Apr 2026 13:50:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ATF-Aerospace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52180d59e86bb9518f7d10cc472e3d531d8a1338b95156fb649b61cedc9cfb2b</i><br /><br />Threat actor <b>description</b>: <i>ATF Aerospace specializes in aerospace manufacturing and distribution, offering high-quality me
chanical and electrical components sourced from leading manufacturers. Their manufacturing capa
bilities focus on CNC milling and lathe operations, emphasizing short runs and quick turnaround
projects.

We will upload 45gb of corporate data soon. Detailed employee personal documents (passports, SS
Ns, DLs and so on), client information (BOEING files again and other confidential projects and 
specification), contracts and agreements, insurance files, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morae</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31805</link>
<guid>a4cfa38878b278bbe2f6f5172474f86b</guid>
<pubDate>Thu, 30 Apr 2026 02:51:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Morae</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>767e1a1eaaf503d85590a3a1f3b049d980aafa9287a93b8cb2f8aaa9360e9311</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Morae is a US-based professional services company specializing in legal, compliance, and technology consulting. It serves law firms, corporate legal departments, and financial institutions by providing managed services, litigation support, contract lifecycle management, and legal operations solutions. The company combines legal expertise with advanced technology to help clients improve efficiency, reduce costs, and manage risk across their legal and compliance functions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arban--Carosi</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31804</link>
<guid>70e57e78fd611128e6e6212c59c28b59</guid>
<pubDate>Thu, 30 Apr 2026 01:23:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Arban--Carosi</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0800798b74f1daebb348c4ffb75b00f5bfbb1923f689b1bf55e3ea9ec601b198</i><br /><br />Threat actor <b>description</b>: <i>Arban Carosi: 1TB customer and company data leaked due to negligence.       * * Full employee base: Including names, positions, personal and work email addresses, phone numbers.     * * Financial Documentation: Contracts, Invoices, Revenue Data     * * Customer base: Customer contact details, project details     * * Internal correspondence: Service emails and documents disclosing internal processes and company plans.   !! In the screenshots, you can see that we have accessed detailed plans of various buildings, including U.S. Army buildings!!  We will publish all the data in a week and everyone can use it for their own purposes.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vortex-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31800</link>
<guid>907426606e10139de6617963c3e73cff</guid>
<pubDate>Thu, 30 Apr 2026 00:57:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Vortex-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>059da878137e6ff54d6fe8f0fc1335e15aaa1a749aae287f990c05c3299e9482</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Vortex Companies is a US-based infrastructure rehabilitation firm specializing in trenchless technology solutions for underground pipe and sewer systems. Operating in the water and wastewater industry, the company provides services including pipe lining, manhole rehabilitation, and structural repair. It serves municipalities and utilities across North America, helping extend the life of aging infrastructure without extensive excavation.</i><br />Target victim <b>website</b>: <i>vortexcompanies.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Del-Monte-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31796</link>
<guid>45e7200bd1dbaf868c1b69de0dec23b9</guid>
<pubDate>Thu, 30 Apr 2026 00:55:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Del-Monte-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e90848fd2a8825a1b443d33a18b2f56701a37712e36174282c727fbd721b1916</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Del Monte Foods is a leading American food company headquartered in Walnut Creek, California. It operates in the packaged food industry, producing and distributing canned fruits, vegetables, tomatoes, and broths under well-known consumer brands. The company supplies products to retail grocery chains, foodservice operators, and industrial customers across the United States and international markets.</i><br />Target victim <b>website</b>: <i>delmontefoods.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>UFP-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31793</link>
<guid>738d7deb467d69ea5d6c8aacb9613245</guid>
<pubDate>Thu, 30 Apr 2026 00:55:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>UFP-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f8a7438d97261c9684a760724ced0f8c1716c3623a4558e81074b345bb337c3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] UFP Technologies is a US-based company specializing in the design and manufacturing of highly engineered custom packaging, components, and specialty products. Operating in the advanced materials and manufacturing industry, it serves sectors including medical, automotive, aerospace, and consumer goods. The company uses materials such as foam, plastics, and composites to create protective and functional solutions for its clients.</i><br />Target victim <b>website</b>: <i>ufpt.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peachtree-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31789</link>
<guid>0493033a1c9575336529c17abf994b52</guid>
<pubDate>Thu, 30 Apr 2026 00:54:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Peachtree-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed7077f735d647390d7329bcf355e9fe2c022aa9c4bc5612553fbbbe6bc26491</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Peachtree Group is a US-based hospitality-focused investment and management firm headquartered in Atlanta, Georgia. The company operates across real estate private equity, credit, and hotel management, specializing in acquiring, developing, and managing hotel properties. It serves institutional and private investors and is active across the United States hospitality and commercial real estate sectors.</i><br />Target victim <b>website</b>: <i>peachtreegroup.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eyemart-Express</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31786</link>
<guid>499cb2ee42a8be29ad10e4afa28e0af8</guid>
<pubDate>Thu, 30 Apr 2026 00:42:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Eyemart-Express</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1e18a29cfd1e6d7851f18fc5b1bfba4491b3bfd84c435bc4cee8308ff706679</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Eyemart Express is a United States-based retail optical chain specializing in prescription eyeglasses and contact lenses. Founded in 1990 and headquartered in Farmers Branch, Texas, the company operates hundreds of stores across the country. It offers eye exams, frames, and lenses with an emphasis on fast turnaround times. Eyemart Express competes in the optical retail industry alongside brands like LensCrafters and Visionworks.</i><br />Target victim <b>website</b>: <i>eyemartexpress.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kichler-Lighting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31783</link>
<guid>79d60d2defe0e8a228ed1fd7fab86e23</guid>
<pubDate>Thu, 30 Apr 2026 00:39:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Kichler-Lighting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfb68bb9e8dbd65c5c81ee747c6d3e712e41de8bb95d74232d03b3499884e23a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Kichler Lighting is an American company headquartered in Garland, Texas, specializing in the design and distribution of decorative lighting fixtures, ceiling fans, and landscape lighting products. Founded in 1938, it operates within the residential and commercial lighting industry, offering a wide range of indoor and outdoor lighting solutions. Kichler sells its products through wholesale distributors and retail partners across the United States and internationally.</i><br />Target victim <b>website</b>: <i>kichler.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Powell-Electronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31782</link>
<guid>660bc121513a9d5442e97c5cef85786e</guid>
<pubDate>Thu, 30 Apr 2026 00:38:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Powell-Electronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ef18b24363127230ce2646e9f499e9523ffe859e53acb266e8fa75ca5279a6d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Powell Electronics is a US-based authorized distributor of electronic components and assemblies. Founded in 1946 and headquartered in Camp Hill, Pennsylvania, the company serves aerospace, defense, industrial, and commercial markets. It supplies connectors, cables, electromechanical components, and custom assemblies from leading manufacturers, offering supply chain solutions, engineering support, and value-added services to customers across North America.</i><br />Target victim <b>website</b>: <i>powell.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Central-National-Gottesman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31781</link>
<guid>7d6ff84af104d3d7a8e3b9f86dc7a030</guid>
<pubDate>Thu, 30 Apr 2026 00:36:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Central-National-Gottesman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68abf3b02a7be66d8344a762e81710f26789cc7bdb61a4d0b6c2ba3559d69fdf</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Central National Gottesman is a privately held global pulp and paper merchant headquartered in Purchase, New York, USA. Founded in 1886, the company distributes printing and writing papers, packaging materials, pulp, and tissue products. It operates across multiple continents, serving publishers, printers, and converters. It is one of the largest independent paper distribution companies in the world.</i><br />Target victim <b>website</b>: <i>cng-inc.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-East-Coast-Railway</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31780</link>
<guid>0801dafc88d3117e0db830a42ddf944c</guid>
<pubDate>Thu, 30 Apr 2026 00:35:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Florida-East-Coast-Railway</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f21a20bc7bc93ddb88d53eaa589f65f4082d7436d6a71c3918f6a489962f241e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Florida East Coast Railway is a regional freight railroad operating in the United States, primarily serving the state of Florida. Founded in the 1890s by Henry Flagler, it runs approximately 351 miles of track along Florida's eastern corridor from Jacksonville to Miami. The company transports intermodal containers, vehicles, and various commodities, playing a key role in Florida's freight logistics and supply chain infrastructure.</i><br />Target victim <b>website</b>: <i>fecrwy.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blanchard</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31779</link>
<guid>a39878ae282a18ea051ad89e7875a272</guid>
<pubDate>Thu, 30 Apr 2026 00:34:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Blanchard</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>86f28fc1f8907084cc0e54639d90250993cd0e136f60eac976d62aa1052f1f49</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Blanchard is a US-based professional development and leadership training company founded by Ken Blanchard, co-author of "The One Minute Manager." Operating in the corporate training and consulting industry, it offers leadership development programs, coaching services, and organizational effectiveness solutions to businesses worldwide. Headquartered in Escondido, California, the company serves clients across various sectors globally.</i><br />Target victim <b>website</b>: <i>blanchard.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grace-Design-Studios</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31778</link>
<guid>7f1b9e870ce469ea8f20e0a89bbc9ef8</guid>
<pubDate>Thu, 30 Apr 2026 00:33:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Grace-Design-Studios</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>185dee0ff0e77e17921e558a68fa9c50645251f069b42bc8961041b25fdb5837</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>grace-design.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>TESSCO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31777</link>
<guid>9a5a511ca4f18a61719b12acf46f14c0</guid>
<pubDate>Thu, 30 Apr 2026 00:32:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>TESSCO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7481a6c3ab00154d9a1a920aa158dbac627075e7a27a27cbef03581d882f423b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TESSCO Technologies is a United States-based company operating in the wireless technology distribution industry. Founded in 1982 and headquartered in Hunt Valley, Maryland, TESSCO serves as a value-added distributor and solutions provider for wireless networking products, infrastructure equipment, and mobile devices. The company supplies carriers, contractors, system integrators, and government agencies with products from leading manufacturers across the telecommunications sector.</i><br />Target victim <b>website</b>: <i>tessco.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Englewood-Lab</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31776</link>
<guid>1c0708af4331df1a35dfbdaf8e252d6e</guid>
<pubDate>Thu, 30 Apr 2026 00:31:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Englewood-Lab</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12e0273f84137cfd8e469b4cbacbe682c1e9e7dcc451c440c486fe6f2555b2ee</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Englewood Lab is a contract development and manufacturing organization (CDMO) based in the United States, operating out of Englewood, New Jersey. The company specializes in the development and manufacturing of topical, sterile, and liquid pharmaceutical products. It serves clients in the pharmaceutical and personal care industries, offering formulation development, stability testing, and regulatory support services.</i><br />Target victim <b>website</b>: <i>englewoodlab.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lc-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31775</link>
<guid>b3df435f52be5287d9ace3b28e2dcac9</guid>
<pubDate>Thu, 30 Apr 2026 00:30:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Lc-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2f5a2a3a457f0c3b9701d50ca0d7bd717778d70888391eb09cd4878120a8eb6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] LC Industries is a nonprofit organization based in the United States that provides employment and training opportunities for people who are blind or visually impaired. Operating primarily in North Carolina, it manufactures and supplies a range of products including military and government goods, fulfilling contracts through the AbilityOne Program, which connects nonprofit agencies with federal procurement opportunities.</i><br />Target victim <b>website</b>: <i>lcindustries.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>SCS-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31774</link>
<guid>2ab0ebde9cc0cd85fc47ce045d440caf</guid>
<pubDate>Thu, 30 Apr 2026 00:29:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>SCS-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e44b3c4246f4a6d8f55fd1882f9a1bd0607fc6b312c6fdce7512156918350b7a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] SCS Engineers is a United States-based environmental consulting and engineering firm. Founded in 1970, the company specializes in solid waste management, landfill design and operations, environmental remediation, and sustainability services. It serves municipal, industrial, and government clients across the country, offering technical solutions related to waste infrastructure, gas collection systems, and environmental compliance.</i><br />Target victim <b>website</b>: <i>scsengineers.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epcon-Communities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31773</link>
<guid>1f910e9557e4fa6c8f9156e96a02d40a</guid>
<pubDate>Thu, 30 Apr 2026 00:28:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Epcon-Communities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73c30884a045fd3435beb0b401f9af0588dc2ca07d8af8d0a14917414c415c7c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Epcon Communities is a US-based homebuilding and franchise company founded in 1986 and headquartered in Dublin, Ohio. It specializes in developing and selling single-story, low-maintenance homes primarily targeting active adults aged 55 and older. Operating in the residential real estate and construction industry, Epcon also franchises its community development model to builders across the United States.</i><br />Target victim <b>website</b>: <i>epconcommunities.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Data-Exchange-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31772</link>
<guid>e8305639398f2f0c3d9cf3af2dd09aeb</guid>
<pubDate>Thu, 30 Apr 2026 00:27:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Data-Exchange-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94e9c971b65ca40226b5d91a256eef2a4a9042dc626cd8479daeb72a05b08efb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>dex.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>SunSource</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31771</link>
<guid>9d5d697ea9ea179f7633708d5478c28f</guid>
<pubDate>Thu, 30 Apr 2026 00:26:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>SunSource</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e02228968b64bf8f3773b6387abab9d1a948d2dc98b36ffebae6825131914bff</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] SunSource is a US-based industrial distribution company specializing in the supply of fluid power, fluid process, and motion control components and systems. It serves a wide range of industries including manufacturing, agriculture, and construction. The company provides products such as hydraulics, pneumatics, and related technical services, helping businesses maintain and optimize their industrial equipment and operations.</i><br />Target victim <b>website</b>: <i>www.sun-source.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Color-Communications-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31764</link>
<guid>42751fb669b1fe8b899c5a70deb061d8</guid>
<pubDate>Wed, 29 Apr 2026 23:51:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>secpo</b> claims attack for <b>Color-Communications-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>652d72f8a5127bbfceb122b5b0f8799aafc9f201449faba0c70a93808653d179</i><br /><br />Threat actor <b>description</b>: <i>The exposed dataset includes over 200,000 unique files containing sensitive information on more than 4,500 individuals and over 5,500 organizations...</i><br />Target victim <b>website</b>: <i>ccicolor.com</i>]]></description>
<category>secpo</category>
</item>
<item xmlns:dc='ns:1'>
<title>Iowa-Spring-Manufacturing--Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31763</link>
<guid>e834628a514af2290509181bf4348c6d</guid>
<pubDate>Wed, 29 Apr 2026 23:23:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Iowa-Spring-Manufacturing--Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>727ca76913809c4005afe5de03b47b78b8365dec9921d987b814efe6478c0c28</i><br /><br />Threat actor <b>description</b>: <i>Iowa Spring 
 
 is a well-established manufacturer specializing in a variety of springs, including those for overhead garage doors, mechanical applications, and agricultural equipment. Founded in 1977 and based in Adel, Iowa, the company has built a strong reputation for quality and reliability in the spring manufacturing industry.
 
 2112 Greene Street
 P.O. Box 130
 Adel, IA 50003, US
 
 www.iowaspring.com
 
 Leaked data: 49,4Gb 
 Accounting, product development and testing, laboratory defect analysis, supply logistics, contracts, NDA, financial indicators, corporate information, and much more</i><br />Target victim <b>website</b>: <i>iowaspring.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Karl-Chevrolet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31762</link>
<guid>ae4b023d09c50fbd267176ede23a3fa7</guid>
<pubDate>Wed, 29 Apr 2026 22:00:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Karl-Chevrolet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5f204c1d1a158f50d105552a7da0b3db6bf94adee67970f560aba4e64bb784a</i><br /><br />Threat actor <b>description</b>: <i>Karl Chevrolet, Inc. operates a Chevrolet car dealership. It offers new and used cars, commercial vehicles, SUVs, trucks, and vans. The company also provides automotive parts and accessories, such as brake pads, oil filters, and others; and services, which include vehicle maintenance, repair, inspection, and other services. It also allows customers to order parts online.</i><br />Target victim <b>website</b>: <i>www.karlchevrolet.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bentley-Capital-Ventures</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31761</link>
<guid>b667279b6400b4c05f3b5c4241e8bf7f</guid>
<pubDate>Wed, 29 Apr 2026 21:59:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>Bentley-Capital-Ventures</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>565d0f881d5e2adec5d3cc26589ceff60e1318b6877bd2541ba4fd3d36ee1608</i><br /><br />Threat actor <b>description</b>: <i>https://www.linkedin.com/company/bentley-capital-ventures
We started  Bentley Capital Ventures in 2012 to facilitate small business owners across the country in the process of obtaining capital.  We know a simple trip to the local bank doesnt always provide the results many are looking for and as business owners ourselves we know how challenging it can be to obtain capital when you dont fit within the guidelines of the traditional banking world.

At Bentley Capital we use the relationships we have built over the last 25 years in both the consumer and commercial banking markets to provide our clients with the very best options available for their specific situation.

Whether you have perfect or less than perfect credit our goal will always be to provide you with options that promote growth and properity for your business.</i><br />Target victim <b>website</b>: <i>bentleycapitalventures.com</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanta-Genetics-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31758</link>
<guid>decff3a1f694fccd108d4ce07b2587b5</guid>
<pubDate>Wed, 29 Apr 2026 21:37:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Advanta-Genetics-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1a719e68510bf201bd59ec98df948a5eb0ed8355bff3bd7eb1090f036243254</i><br /><br />Threat actor <b>description</b>: <i>[health] Advanta Genetics LLC — a respected CLIA/CAP-accredited clinical toxicology and molecular diagnostics laborator. The exposed material includes: Tens of thousands of real patient lives — including highly sensitive chronic opioid therapy charts flagged by the Texas Medical Board and elderly Medicare audit records. Provider identities and prescribing power — SSNs, DEA numbers, and state licenses from 20+ states that can be turned into black-market "script pads". Gold-standard identity theft kits — W-2s, I-9s with passport scans, and full employee packages for 50+ staff. 102 complete QuickBooks company files exposing every vendor, payroll run, bank link, and financial secret across the Advanta/RedLeaf/OSPRI empire. High-value trade secrets — OSPRI Biopath investment decks, valuation models, FDA pre-submission packets, and the proprietary "The Brain" AI diagnostic architecture. Explosive privileged attorney-client memos on active regulatory battles (Texas Medical Board Remedial Plan #19-153 and a federal NORA subpoena). Active Directory domain controller data (NTDS.dit and SAM hives).</i><br />Target victim <b>website</b>: <i>aalabs.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-of-Michael-A.-Freedman-P.A.-maflaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31755</link>
<guid>4ecb8876b622f561d9d13161071f518c</guid>
<pubDate>Wed, 29 Apr 2026 21:35:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Law-Offices-of-Michael-A.-Freedman-P.A.-maflaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ccae79ff2f69b86f92875aade4b1ea4e43c4615198787600903509dde72493c</i><br /><br />Threat actor <b>description</b>: <i>[law] Law Offices of Michael A. Freedman, P.A. (maflaw.com). The exfiltrated corpus is 579 GB used / 143 GB at root level / 196,701 files / 19,231 directories, dated as recently as a year-2026-in-progress client matter.

What this means for a plaintiffs' PI firm of ~25 staff:

656 client-matter folders organised across eight yearly parents from June 2019 through 2026-in-progress. Per-client medical records, HIPAA authorisations, police reports, settlement releases, IOLTA distribution sheets, retainer agreements, and treating-provider correspondence.
Two staff Outlook archives at 2.1 GB each, plus a 505 MB Outlook backup, plus 27 enumerated .pst files — years of attorney–client privileged correspondence, settlement strategy, opposing-counsel comms.
The complete Sage ACT. Pro v18 contact universe — the live database plus eight historical ZIP backups going back to 2013 plus a 9.3 MB plaintext export (ACT!-Contacts.txt) that any text editor can open. Estimated 5,000–12,000 contacts.
The firm's master credential vault in a Word document called Woodywoody78!.docx (the filename is itself the vault password). Plaintext credentials for M&T Bank multi-identity business + commercial accounts (with electronic-payment-approval authority), Bank of America, Paychex, QuickBooks, and the firm's federal EIN. Plus the senior partner's phone-unlock PIN.
A staff browser-exported password CSV (32 plaintext credentials) including the M365 tenant, the Slack tenant, hospital portals (MedStar, GBMC, Allstate secure mail), MoveDocs, ChartRequest, MSHC Legal portal — plus residual credentials from prior employers SLF Law and Bailey Law, creating cross-firm contamination liability.
The Universal Licensing / Freedman Consulting invention-promotion operation — a second line of business under the same EIN, with hundreds of inventor folders. Per-inventor unpublished invention disclosures, “Internet Presentation of Invention” decks, NDAs, Exclusive Patent License Agreement drafts, patent-art renderings, and per-managed-mailbox client-company passwords. 
A criminal-defense sub-practice (“SLF criminal” out of Janice's working folder) with retainer agreements and per-client court documents, carrying 6th-Amendment-attorney–client uplift on the privileged-track scoring.
An Axon evidence.com MPIA-released body-worn-camera package (449 MB total; a 448 MB clip from the 2020-12-20 Park Baltimore incident).</i><br />Target victim <b>website</b>: <i>maflaw.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlas-Metal-Industries-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31754</link>
<guid>0207ceaa30eeb7df0c51ed30959480ec</guid>
<pubDate>Wed, 29 Apr 2026 21:35:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Atlas-Metal-Industries-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f38ee012b560f6a27ddcdf3075aaec18f8e8c61645ae53d683af54bbf5cb455f</i><br /><br />Threat actor <b>description</b>: <i>[food, metal] Atlas Metal Industries Inc. — a privately held commercial-foodservice-equipment manufacturer headquartered in Miami, Florida.

The dataset is a complete Microsoft Dynamics GP environment: production databases, payroll records, system credentials, Autodesk Vault product-design backups, CNC fabrication programs, and all supporting infrastructure configuration. The exfiltration occurred on or about April 8, 2026; the attack was identified April 22, 2026.

The exposed material includes:

    15.8 GB of payroll-records database (PYREC) — full Employee Master with SSNs, DOBs, addresses, direct-deposit bank routing numbers, salary, W-4 tax data, garnishments, and check history dating to at least 2018.
    30+ SQL Server login accounts with password hashes in a sp_help_revlogin dump — named employees, system admins (DYNSA, sa), service accounts, and Active Directory domain accounts.
    74 GB of Autodesk Vault Professional backup — complete product-design history from 2019 through 2026, covering every product line Atlas Metal manufactures.
    Hundreds of CNC fabrication programs — laser-cutter and Amada punch-press G-code for the full catalogue of sheet-metal components.
    A base64-encoded SQL credential for the TimeClock Plus timekeeping system, stored in plaintext XML.
    8 SQL Server databases with full backup chains — ATLAS (primary), PYREC (payroll), DYNAMICS (system), TEST (18 GB dev clone), TWO, AMIT, plus system databases (master, msdb, DynamicsGPSecurity).</i><br />Target victim <b>website</b>: <i>atlasfoodserv.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Costa-Solutions-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31753</link>
<guid>56fe38b77cb4f52e8f2770e874f57875</guid>
<pubDate>Wed, 29 Apr 2026 21:35:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Costa-Solutions-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21fbe7230b2f36501ab4dee782a10be1fd439a28fa0ef2a9ebdebacd0561e92d</i><br /><br />Threat actor <b>description</b>: <i>[warehouse] Costa Solutions, LLC — a privately held managed-labor and warehousing company headquartered in San Antonio, Texas, with ~$140M annual revenue and 200–1,000 employees.

The file server contained the complete operational, financial, legal, and human resources infrastructure of the company:

3,000–8,000+ individuals' personal data — current employees, former employees (12 years of records), independent contractors, employee dependents, and job applicants. SSNs on W-2s, W-4s, 1099s, I-9s, background checks. Bank account and routing numbers on 200+ direct deposit forms.
Medical and injury records — 150+ employee injury/medical files from 2013–2026, FMLA medical certifications, drug test results (random, reasonable suspicion, post-incident, promotional), and workers' compensation claims for 23+ named individuals.
CEO's entire file system — Josh Wean's Documents folder (5.3 GB) including P&L statements, a 17-subfolder "Confidential" directory, legal correspondence, strategic plans, a C-12 peer advisory group archive, and a $RECYCLE.BIN with 60+ deleted items.
Client contracts and competitive intelligence — pricing, SLAs, and contract terms for HEB, CVS, Sysco, Amazon, McLane, Labatt, Valvoline. Competitor pricing intelligence. RFP bid documents with cost models.
Active legal case files — litigation records (2021–2022), HR internal investigation notes (2018–2021), arbitration files, active investigations marked "DO NOT DELETE" — all subject to attorney-client privilege.
Infrastructure secrets — an HEB production server TLS certificate, a Cisco AnyConnect VPN installer, and the CEO's Remote Desktop connection file.
Corporate financials — multi-year budgets, valuation & sale documents (indicating possible M&A activity), PPP loan forgiveness records, Form 5500 ERISA filings, and annual reporting.</i><br />Target victim <b>website</b>: <i>costasolutions.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bayou-Title-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31752</link>
<guid>4371a529ba9a419a1dc903bcd8856251</guid>
<pubDate>Wed, 29 Apr 2026 21:34:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>aurora</b> claims attack for <b>Bayou-Title-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0205491ff52497df3d511d8cd992285d644580c55357f2c19db850bb0c6af916</i><br /><br />Threat actor <b>description</b>: <i>[insurance] Bayou Title, Inc. — the largest title insurance agent and closing/settlement services provider in Louisiana, with 19 full-service locations statewide.

The exfiltrated data spans 20+ years of operations (2004–2026) and includes:

70,000–100,000+ Social Security numbers paired with names, addresses, and sale proceeds from 1099-S real-estate closing worksheets covering all 19 offices across three tax years (2018–2020), plus W-2 and 1099-MISC filings.
Complete employee payroll databases — 10+ instances of Sage 50 EMPLOYEE.DAT files containing SSNs, bank account numbers, routing numbers, pay rates, tax withholding, and direct deposit details for current and former employees.
103 GB of title abstracts — ~34,000+ PDFs documenting ownership chains, liens, and mortgages for properties across Louisiana.
44 GB of GreenFolders DMS transaction packages (2012, 2013, 2019) — complete closing file archives containing HUD-1 settlement statements, identity verification documents, SSN cards, and tax records. Filenames contain encoded tags (ssn, hud, soc, tax).
Plaintext credentials for government portals — a file literally named Lafayette Assessors lcmenard Password4321.url, plus a PDF containing Orleans Parish system login credentials.
Attorney-client privileged documents — wills, attorney engagement letters, and legal opinions prepared by licensed Louisiana attorneys.</i><br />Target victim <b>website</b>: <i>bayoutitle.com</i>]]></description>
<category>aurora</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eduporium</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31747</link>
<guid>3066b11b58eb7fb925b67d25c54e3234</guid>
<pubDate>Wed, 29 Apr 2026 19:55:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Eduporium</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>190800a1c011e724e9b72cd358a67444d01b56c27a80b3ae452dda48cb73f287</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Probity-Contracting-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31748</link>
<guid>144679b5d1ddb8650c3155c645a1d976</guid>
<pubDate>Wed, 29 Apr 2026 19:55:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Probity-Contracting-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc6bb6e7e013507fb7e6abdc5e74547bef9e24ba2bf0cdb0e4709cdb3a5586ee</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro-ILA-Funds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31749</link>
<guid>4295cd213a56a1c6ec066caf5dd08f16</guid>
<pubDate>Wed, 29 Apr 2026 19:55:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Metro-ILA-Funds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce0a1b79713ec1f9e67ed76313b4830c37c4e1f3441f3301b6ae1d87eafe40fb</i><br /><br />Threat actor <b>description</b>: <i>Insurance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>stllc.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31743</link>
<guid>59b6525364c77d1e6f9c79c53e387954</guid>
<pubDate>Wed, 29 Apr 2026 10:32:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>stllc.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0520082af8a0475d5acd9b6d6911926bd240f59270f23b1aacd612139f46495b</i><br /><br />Threat actor <b>description</b>: <i>Welcome to St. Luke Lutheran Community St. Luke Lutheran Community is a not-for-profit, continuing...</i><br />Target victim <b>website</b>: <i>stllc.org</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>rainforestclean.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31738</link>
<guid>dbaebce9c842f6aa7482517597c75c8c</guid>
<pubDate>Wed, 29 Apr 2026 10:09:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>m3rx</b> claims attack for <b>rainforestclean.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f50728ec93640d5ca8341cf1fcdfb7c89444d919e9e44db1e1dbfde3edc44e9a</i><br /><br />Threat actor <b>description</b>: <i>Rainforest Carwash and Oil Change, along with it’s owner, enjoys giving back to our local community. Hopefully you are inspired to help after seeing the ways in which we try to help others. Stolen: 259gb 77k files</i><br />Target victim <b>website</b>: <i>rainforestclean.com</i>]]></description>
<category>m3rx</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.fulcrumre.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31734</link>
<guid>effa3b908aaa9f8744b980829a6bfd15</guid>
<pubDate>Wed, 29 Apr 2026 02:23:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpswww.fulcrumre.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2624000b9d0697a2c75c098e7aa0deeab6591c3f3d6afb8ef02a9862db149c8b</i><br /><br />Threat actor <b>description</b>: <i>2tb data all company data</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>nbd3pl.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31732</link>
<guid>407688b935e4079fecd2b2daefb6432e</guid>
<pubDate>Wed, 29 Apr 2026 00:22:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>nbd3pl.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78da6e95ee46e433a61c2da1b393c0d490abc104747e81c0d2f82f86f35d37a8</i><br /><br />Threat actor <b>description</b>: <i>North Bay Distribution has been in the warehousing, order fulfillment, and shipping industry for more than 30 years. They are a full service outsourcing logistics service provider. They are based in northern California's City of Vacaville. The proximity of their facility provides streamlined deliveries from the Port of Oakland for goods manufactured and arriving from the Pacific Rim</i><br />Target victim <b>website</b>: <i>nbd3pl.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>cadencepetroleum.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31730</link>
<guid>306ee6a27d95b01dd69ee72920cf25ed</guid>
<pubDate>Tue, 28 Apr 2026 20:51:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>cadencepetroleum.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ab47fb118b99fa27aef1f6db70e77d24d5699c10d82d089c40e4ce5a8a7867b</i><br /><br />Threat actor <b>description</b>: <i>Company management has 48 hours to reach an agreement with us. If no agreement is reached, the files—totaling 400 GB—will be published.

Our objective is to provide our customers with the best products and services. Cadence Petroleum and our suppliers stand behind the products we offer. Regardle…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/cadence-petroleum-group/476578914|</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nephrology-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31729</link>
<guid>2325577fcece567803aff8703a899116</guid>
<pubDate>Tue, 28 Apr 2026 20:25:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Nephrology-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bdd582a3ffc7fd61131d94c4bf85f39678f2c4b6cbbdbced918c88aaa82bad14</i><br /><br />Threat actor <b>description</b>: <i>Nephrology Associates, PA is a leading central Arkansas nephrology practice with seven highly trained physicians across seven locations. They provide compassionate kidney care, accept all insurances, and aim to create a welcoming environment for patients.</i><br />Target victim <b>website</b>: <i>www.arnapa.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Basch--Keegan</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31724</link>
<guid>045723a2e194ae8b07890dace311b402</guid>
<pubDate>Tue, 28 Apr 2026 19:54:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Basch--Keegan</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04dc432059295e32e5667769cee15a3cf6d59bcc02f284e9a0ff14446dbf64e5</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>KarmaData</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31726</link>
<guid>0f7a529e4a851625fee72161a84b4ca1</guid>
<pubDate>Tue, 28 Apr 2026 19:54:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>KarmaData</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5c653ead4aaff95fedc38e1129fbafeaee5aeb9a0012839a282242910378eec</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>INJURYLAWYERS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31722</link>
<guid>27e34e1093ba7e24075b9f5b25dcf5a7</guid>
<pubDate>Tue, 28 Apr 2026 14:39:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INJURYLAWYERS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a345134aeb76fb1259b28b56032389b60a8af1fdba09920529da9207ef96295f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.durable-tech.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31717</link>
<guid>1dbdb6a977dd83e68f9078c05da938c6</guid>
<pubDate>Tue, 28 Apr 2026 09:41:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.durable-tech.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b43e7e1578c15621ae1ca00c07785536c683837525027916de1ea26a2c3257ef</i><br /><br />Threat actor <b>description</b>: <i>Durable Mecco is a small company (1-10 employees) operating in the HR & Staffing industry, located at 176 Thorn Hill Rd, Warrendale, Pennsylvania, 15086. This entity is distinct from "Durable Technologies," which focuses on industrial marking equipment.</i><br />Target victim <b>website</b>: <i>www.durable-tech.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vimeo-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31716</link>
<guid>3d1ed124d48ac4f12106b32decf840b0</guid>
<pubDate>Tue, 28 Apr 2026 05:38:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Vimeo-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>435fc106f5766671d53c12474f0f4b98708d661eba1cf427fa7f28462dd852c9</i><br /><br />Threat actor <b>description</b>: <i>Your Snowflake and Bigquery instances data was compromised thanks to Anodot.com. Pay or Leak. This is a final warning to reach out by 30 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 28 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Super-AI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31715</link>
<guid>4c24085bb62faf1e7e113767f837802d</guid>
<pubDate>Tue, 28 Apr 2026 04:12:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Super-AI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>36cb8516e57efdc7d17d4111f7c579d415407da7a43cff9d714fe10d453a21e5</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>sumacinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31714</link>
<guid>4635d9474a5ef94cd03d40e385f4b177</guid>
<pubDate>Tue, 28 Apr 2026 03:26:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>sumacinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b62dc48929cd018938f15baf643fee1294f347acc26a62c4bd1521ce61c5b70e</i><br /><br />Threat actor <b>description</b>: <i>all client data 2tb</i><br />Target victim <b>website</b>: <i>sumacinc.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lifeline-PCS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31712</link>
<guid>872def1eaad20180f042ac8764629220</guid>
<pubDate>Mon, 27 Apr 2026 22:53:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lifeline-PCS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb5f2e924603d680ad8f8e67b004e3b147e5305e517135af965956222b27c295</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Birtcher-Anderson--Davis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31710</link>
<guid>c070bfe7f385b5bdda1dcd920c4965a6</guid>
<pubDate>Mon, 27 Apr 2026 21:52:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Birtcher-Anderson--Davis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>069fd3e918853fcea8e00d079438753a56c58ef60323a49b30c342b0bb9283a8</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Floyd-Skeren-Manukian-Langevin-LLP-Information</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31709</link>
<guid>b96a8bcf64591ca8e9c43f114de1daba</guid>
<pubDate>Mon, 27 Apr 2026 18:38:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Floyd-Skeren-Manukian-Langevin-LLP-Information</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd1756132e6fdd7242c9378bb9401a893e89cf84a3d97fca100c151c8a4485d2</i><br /><br />Threat actor <b>description</b>: <i>Floyd Skeren Manukian Langevin, LLP is a multi-service law firm with ten offices throughout California…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>jgpetrucci.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31702</link>
<guid>ac3811a6c6bb180aa7db3e94fdab42cc</guid>
<pubDate>Mon, 27 Apr 2026 16:51:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>apt73/bashe</b> claims attack for <b>jgpetrucci.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a698caa8b43ed7752cc9d269e9ecf687ae6ec9cb5cd553afe02ac28950f7d1e6</i><br /><br />Threat actor <b>description</b>: <i>J.G. Petrucci Company, Inc. is a real estate development and construction company in the United S...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>apt73/bashe</category>
</item>
<item xmlns:dc='ns:1'>
<title>ibswebsite.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31685</link>
<guid>f65c00c041bab77ab44874be15c53276</guid>
<pubDate>Mon, 27 Apr 2026 15:51:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>ibswebsite.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1556a04f6783639e890500240ad81b8d6bb0dbbe9ff92e9cf35320b6a005b4f</i><br /><br />Threat actor <b>description</b>: <i>The company helps commercial organizations invest in technology solutions for their businesses by offering technology consulting,
as well as the design and inte...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>delonhampton.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31686</link>
<guid>1f034ade6c58fc442a66e4b2b71abbf8</guid>
<pubDate>Mon, 27 Apr 2026 15:51:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>delonhampton.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c03949c9ca0f1c023dd72d19ae1fa7d6ba492ecf76fd52532ef907fa669354e4</i><br /><br />Threat actor <b>description</b>: <i>An engineering and consulting firm specializing in civil and structural engineering, program management, and construction, delivering complex infrastructure pro...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>aotco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31687</link>
<guid>14f97b191b6fa0838c21882579b1e65a</guid>
<pubDate>Mon, 27 Apr 2026 15:51:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>aotco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>547f9db4159e02d7f7d2b3e608b1df5b55a4a66436292696347e6686d1425715</i><br /><br />Threat actor <b>description</b>: <i>AOTCO specializes in metal finishing solutions, offering a wide range of services, including electroplating, anodizing, and passivation,
and has over 45 years o...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>wmsopko.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31688</link>
<guid>7d1fb6b4eec12bee96b88020c7afadb8</guid>
<pubDate>Mon, 27 Apr 2026 15:51:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>wmsopko.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c260d31e80835044d03281beb46ea2ff83ad93fb96e23093f041382add25186b</i><br /><br />Threat actor <b>description</b>: <i>Wm. Sopko & Sons Co. supplies and distributes the full line of Dumore automatic self-feeding drilling and threading equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>andrewtjohnson.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31689</link>
<guid>4538579b59251aec5bda1a4dce588ba4</guid>
<pubDate>Mon, 27 Apr 2026 15:51:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>andrewtjohnson.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e3bfae404f6e8ccfc424ab9d482794a272744f87e901da9790fdfb3e5f466ff</i><br /><br />Threat actor <b>description</b>: <i>The company is a leading provider of printing and reprographic services, offering image processing, printing, graphic design for exhibitions, copying, offset pr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>fatbrands.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31690</link>
<guid>f33c64866907e92c0fe0ed10fcb56c9f</guid>
<pubDate>Mon, 27 Apr 2026 15:51:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>fatbrands.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e49a298ed1c3c0732f880fad136108dacc2b91938e4f5333f8308a335f98603</i><br /><br />Threat actor <b>description</b>: <i>FAT Brands is a leading global franchising company that strategically acquires, promotes, and develops quick-service, fast-casual, 
and casual dining concepts a...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>mopec.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31691</link>
<guid>3218b56a27cc5d3acdac4a6b99195f75</guid>
<pubDate>Mon, 27 Apr 2026 15:51:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>mopec.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09d01f576a5f0b76ae0053f56c0cc89111bca5c5bd2a776957de657cb171b408</i><br /><br />Threat actor <b>description</b>: <i>Mopec supplies American-made medical equipment and laboratory products for pathological, histological, autopsy, and morgue services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>avalonflooring.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31692</link>
<guid>cb2934ae5683eff802277d627c0ed3d3</guid>
<pubDate>Mon, 27 Apr 2026 15:51:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>avalonflooring.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8f62cfb2b4dc65c971d64290125195d9eeca749b497b2a07dc9c7ff3d44be13</i><br /><br />Threat actor <b>description</b>: <i>Avalon Flooring, founded in 1958 and located in Cherry Hill, New Jersey,
specializes in installing flooring in both residential and commercial spaces.
In additi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>rosehillgardens.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31694</link>
<guid>afcf99a084ec63c94f1cf5094ba2b133</guid>
<pubDate>Mon, 27 Apr 2026 15:51:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>rosehillgardens.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8aab7f602bf113457c861de2b2a6da6874fb39777a08ebdceb0c77a62b4c2a8</i><br /><br />Threat actor <b>description</b>: <i>Rosehill Gardens is a professional landscaping company based in Kansas City, employing over 150 specialists in landscape design, maintenance, irrigation, lighti...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>massdevelopment.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31695</link>
<guid>36ab35b3020f5896ae18fc41567b76a1</guid>
<pubDate>Mon, 27 Apr 2026 15:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>massdevelopment.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24feb4b1d9d3938427ce90f67ea7b33c93d4c0ed06f4ff5337f67fd660ab12d4</i><br /><br />Threat actor <b>description</b>: <i>MassDevelopment, a state agency for finance and development, partners with businesses, 
nonprofit organizations, financial institutions, and local communities t...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ldisolutions.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31683</link>
<guid>cd6539b09d112a53ba4098fe605df806</guid>
<pubDate>Mon, 27 Apr 2026 12:49:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>ldisolutions.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8cd356bccd1407b59c7d3ab6e91793b2cefbeaa0474981ca89cace11e2b31381</i><br /><br />Threat actor <b>description</b>: <i>Pneutronics, a division of Parker Hannifin Corporation's Instrumentation group, is a New Hampshire-based designer and manufacturer of pneumatic and electronic control systems serving diverse industrial markets. Founded in 1977 with the mission of combining pneumatics and electronics into modular package control solutions, Pneutronics has evolved from its initial focus on semiconductor equipment subsystems to become a trusted component supplier across kidney dialysis, patient monitoring, gas chromatography, automotive paint spray, and semiconductor equipment applications. Located in Hollis, New Hampshire, approximately one hour north of Boston, the company operates as part of Fortune 500 Parker Hannifin Corporation, headquartered in Cleveland, Ohio, providing access to world-class resources and global distribution capabilities.  Employees: 50 Revenue: $5 Million Industry: Industrial Machinery & Equipment  Phone Number: (866) 332-0700</i><br />Target victim <b>website</b>: <i>ldisolutions.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>MTCI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31676</link>
<guid>7974a38b2a42268066c03442b2cc922b</guid>
<pubDate>Mon, 27 Apr 2026 07:38:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>MTCI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>949fe514cdc98979390f2420c0f4d69d1266241c83905df417ee361a57214b42</i><br /><br />Threat actor <b>description</b>: <i> MTCI  Telecommunications and IT Consulting . Specializes in VoIP, structured cabling, network protection, and cloud services.  They highlight being an independent consultant (vendor-agnostic) and offer 24/7/365 support . They have won the Cincinnati US Regional Chamber of Commerce Small Business of the Year award.  11260 Chester Road, Cincinnati, Ohio, USA mtci.com  Leaked data: 320 Gb  company projects (including special projects of devices with drawings, air bridges, Wi-Fi bank and many other projects), information about employees with personal data, insurance, medical secrets; corporate information with guidance documents and correspondence with counterparties; finance; employee Video surveillance Files</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>reddycardiology.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31675</link>
<guid>f7652e68e0da3f415d7a0cb66da9c510</guid>
<pubDate>Mon, 27 Apr 2026 07:38:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>reddycardiology.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88390be8ed5deffa0e6c3759aa0ae21409f6b12768f3abadde1dfcb7501df700</i><br /><br />Threat actor <b>description</b>: <i>Reddy Cardiology provides comprehensive cardiovascular care and diabetes management services in Sugar Land, TX. The clinic specializes in the prevention and treatment of heart disease, high blood pressure, and diabetes, utilizing state-of-the-art technology and personalized treatment plans. Their intended clients include adult patients referred by primary physicians for various cardiac symptoms and those seeking preventive care. Reddy Cardiology also offers a unique diet plan, the Reddy Diet, aimed at promoting heart health and managing diabetes. Employees: 50 Revenue: $5 Million Industry: Hospitals & Physicians Clinics Phone Number: (281) 491-0044</i><br />Target victim <b>website</b>: <i>reddycardiology.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>A--A-Building-Material</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31670</link>
<guid>031f41342d850a9c4e0997d626ffe73c</guid>
<pubDate>Sun, 26 Apr 2026 19:56:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>A--A-Building-Material</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4516b1c49818427da816103e9b5fbd6f12eb54782fd9411bf5a61f6ae3b2c506</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Walman-Optical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31664</link>
<guid>3484575740e7d74362f6a1ab0ac89a50</guid>
<pubDate>Sun, 26 Apr 2026 16:15:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Walman-Optical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e97395d1328a60673af8058e74a743606b0e48f537e9966de494d76953cbb18f</i><br /><br />Threat actor <b>description</b>: <i>Walman Optical who is owned by well-known Company EssilorLuxottica is a U.S.-based optical company founded in 1915 and headquartered in Minneapolis, Minnesota. It is a leading manufacturer and distributor of ophthalmic products, including prescription lenses, frames, and optical equipment. The company primarily serves eye care professionals such as optometrists and ophthalmologists by providing advanced lens technologies, coatings, and laboratory services. With multiple locations and production facilities across the United States, Walman Optical has built a strong reputation in the vision care industry. As part of EssilorLuxottica, the company benefits from global resources, innovation, and an expanded market presence. 
The company headquarters is located in 801 12th Avenue North, Minneapolis, Minnesota 55411, United States with 1K - 5K Employees.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>bladex.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31663</link>
<guid>47c95199b010148056eda6ac6f961c63</guid>
<pubDate>Sun, 26 Apr 2026 09:55:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>bladex.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a98eb4c40ac2c332770595e141390839afd7d5ae3cc209b4fdcf8be96e0a9611</i><br /><br />Threat actor <b>description</b>: <i>Bladex, a multinational bank originally established by the central banks of Latin-American and Carib...</i><br />Target victim <b>website</b>: <i>bladex.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>CHECKMARX</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31660</link>
<guid>d279b7b85cdc6930ed48a94c79f7a92d</guid>
<pubDate>Sat, 25 Apr 2026 21:11:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lapsus$</b> claims attack for <b>CHECKMARX</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a90be54023228a5102bed05400e6d88166bd2511a3ba6e94156dfeea16381e3</i><br /><br />Threat actor <b>description</b>: <i>Source Code, Employee DB, API Keys, MongoDB/MySQL Creds</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lapsus$</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chase-Cooper-Limited-RiskLogix-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31658</link>
<guid>29aaf96073ec131b599f9b6cee22199e</guid>
<pubDate>Sat, 25 Apr 2026 16:56:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chase-Cooper-Limited-RiskLogix-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9320c7525ecc64a1fde74748942303c1fb2a43df9352b2f01655ddf714beb0b6</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>LA-Woodworks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31644</link>
<guid>1441f32b14b8433d109f166d7668c4ce</guid>
<pubDate>Sat, 25 Apr 2026 15:56:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LA-Woodworks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1dd89dc7ddf93705b85973d9f82dcf255f3f3ef5ca32fc3f6921fd159d82290</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buckley-Powder</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31645</link>
<guid>4ebcff140cef36926eddf245293c8f5b</guid>
<pubDate>Sat, 25 Apr 2026 15:56:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Buckley-Powder</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa6444cdd2741b17fd402ba8c0eec7a1ac54cc0141ccaacd92c855f5dab99908</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dillon-Family-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31648</link>
<guid>d54c1acef541c844cc5d47d6a25cb029</guid>
<pubDate>Sat, 25 Apr 2026 14:57:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dillon-Family-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6495c0558f8baedf9f53f8faa78f2e40e36bc560b6068412bdee7ef347c37683</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>KEMBA-Indianapolis-Credit-Union</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31657</link>
<guid>42bf85e14dc95c0ad727255443108b73</guid>
<pubDate>Sat, 25 Apr 2026 14:47:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>KEMBA-Indianapolis-Credit-Union</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a29bb8de9fc322dbf08a29eb616a65cfcaf16d083970680a5d6e8ab6e9e8d47</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mykemba.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-County-FCU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31655</link>
<guid>0f09698017af107026ad0b0be011fa73</guid>
<pubDate>Sat, 25 Apr 2026 14:47:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>First-County-FCU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ce79e2d35da18769c71e5727c3bf35dde12066b7c7641a6afa81ff58c7c6cd8</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.firstcountyfcu.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chelten-House</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31654</link>
<guid>26079c271736e881b2c523644f8de690</guid>
<pubDate>Sat, 25 Apr 2026 14:46:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chelten-House</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83df1290a01f680f0c5954242b051437f85b6d6f2a1edede13760e0b32a308cb</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cheltenhouse.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mid-Florida-Dermatology--Plastic-Surgery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31651</link>
<guid>7829e6d847f0b9d897d940aa3f3b7b46</guid>
<pubDate>Sat, 25 Apr 2026 14:45:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mid-Florida-Dermatology--Plastic-Surgery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7997f25789c5c1835c15781cd1a369d83867e0710aa79ca68075f95b96e74ea2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.midflmed.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swansea-Ambulance-Corps</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31650</link>
<guid>05205552655b321c2b5eb6c76daeea63</guid>
<pubDate>Sat, 25 Apr 2026 13:35:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Swansea-Ambulance-Corps</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32e2f8f6dfab8ff4faa88ba4aff45c1b958bd5889f555bd497b4169ee76d823f</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Progressive-Propane</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31638</link>
<guid>3ad980cc442688dcd2cb1052725e2683</guid>
<pubDate>Fri, 24 Apr 2026 19:56:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Progressive-Propane</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0101e93b8b91997919d7d90e36962e3cb4ae9176f81ec9af73953729f83952ab</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Priests-for-Life</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31639</link>
<guid>66f870cbf6b7ef5d6d1c8a3d4671e775</guid>
<pubDate>Fri, 24 Apr 2026 18:56:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Priests-for-Life</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49649700e681ef44f2253d993b93da27ae62df2921be91bcfb8d2b9efddfb682</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Flipo-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31640</link>
<guid>00b0b4deb1406b3141a6de7c3950a424</guid>
<pubDate>Fri, 24 Apr 2026 18:56:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Flipo-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22c5cecbb6a880ab5348518d959761b82fb55364438dd33dd2410ea6fb6251ee</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>METO-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31634</link>
<guid>d01d080783ec584fbcdeda594b17b442</guid>
<pubDate>Fri, 24 Apr 2026 15:11:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>METO-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee1d96a796c729a7c3b847321a00976a9f05140b217cd1705f8e6a50aef39f7b</i><br /><br />Threat actor <b>description</b>: <i>METO Systems designs and manufactures stainless-steel industrial material‑handling equipment for regulated industries. Products include lifts, blenders, transporters, and docking systems, they offer installation, training, customization, and support.</i><br />Target victim <b>website</b>: <i>www.metosystems.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>tlctrialteam.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31633</link>
<guid>0dd552b30e0889e7fffcc386e3508484</guid>
<pubDate>Fri, 24 Apr 2026 15:08:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>tlctrialteam.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c08e26a93cbe3406fc36ea779ce25b2e6580d6b6dc9853cc0b151714a1c51792</i><br /><br />Threat actor <b>description</b>: <i>TLC Trial Team is a personal injury law firm based in Winter Haven, Florida. The firm handles accident and injury-related cases.</i><br />Target victim <b>website</b>: <i>tlctrialteam.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rockville-Fuel--Feed</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31632</link>
<guid>a2ee868039973701dbacf41a3c5af4ba</guid>
<pubDate>Fri, 24 Apr 2026 13:28:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rockville-Fuel--Feed</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c60d681826565b4a172a3a6b3b75bf5c070cace44405823489ba355480d853d1</i><br /><br />Threat actor <b>description</b>: <i>Rockville Fuel & Feed Co., Inc. is a premier supplier of ready mix concrete serving the Marylan
d suburbs of Washington DC. With multiple plants across five major counties and a fleet of over
65 trucks, the company caters to construction projects of all sizes, ensuring timely and relia
ble delivery.

We will upload corporate data soon. Employee personal documents (passports, DLs (over 100), med
ical and financial information), client information, contracts and agreements, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Udemy-Inc.-udemy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31628</link>
<guid>6c982c9657a6661e773e6cc2b48250aa</guid>
<pubDate>Fri, 24 Apr 2026 07:59:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Udemy-Inc.-udemy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8709c54c32faadf2429bc74626f916d1c1e884d64978719b38e47d281ed5368</i><br /><br />Threat actor <b>description</b>: <i>Over 1.4M records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 24 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>udemy.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>ADT-Inc.-adt.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31627</link>
<guid>8ecb8ebb08e20837963e95b2d8eded47</guid>
<pubDate>Fri, 24 Apr 2026 07:58:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>ADT-Inc.-adt.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>348a1e1684299b16bba7a05cb9ad54b132fa8caf1ab5b6b025de405a74316aa0</i><br /><br />Threat actor <b>description</b>: <i>Over 10M records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 27 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 24 Apri 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>adt.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chartwell-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31626</link>
<guid>51e04cd4e55e7e415bf24de9e1b0f3ff</guid>
<pubDate>Thu, 23 Apr 2026 20:18:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Chartwell-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48224849d44aebd7c385c3b8bccb95df39e13e011528e970fa8a92bc1c2a9bd7</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Chartwell Law is a United States-based law firm specializing in insurance defense litigation. Operating primarily across multiple states, the firm represents insurance companies, self-insured entities, and businesses in matters including workers compensation, general liability, professional liability, and coverage disputes. It is known for providing legal counsel and courtroom representation within the broader insurance and legal services industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mothers-Market--Kitchen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31625</link>
<guid>8ad2f16f1cfd0d6443a089c0624042b4</guid>
<pubDate>Thu, 23 Apr 2026 20:18:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Mothers-Market--Kitchen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d940c8190f04c138cf029fc83a35f0ab59eb3969b5adc30118caf07c946f6ef9</i><br /><br />Threat actor <b>description</b>: <i>Mother's has gained a reputation for having a wide selection for specialized diets, top quality local and organic produce, the county's largest selection of supplements.The data archive contains personal data of employees: ssn+dob+name+home address+phone</i><br />Target victim <b>website</b>: <i>mothersmarket.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>B-to-B-Visions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31616</link>
<guid>fd982f3faf6faa7b8049fcb713afb2b7</guid>
<pubDate>Thu, 23 Apr 2026 19:51:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>B-to-B-Visions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90b72bc2b7de5faf940b72c55f0b8f8535de98d57d7f6d99c23fc45ff3de47b3</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-FAFS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31618</link>
<guid>ec04a75ca6302d347df2f803efe8c5bd</guid>
<pubDate>Thu, 23 Apr 2026 19:51:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-FAFS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9e38127da1e69faa84bbcdb290921eced6c95c66e6a2e74e9542564c2b27ea7</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Napoleon-Ohio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31624</link>
<guid>493c8b3821e768713a4d1c5b1e7f5ad4</guid>
<pubDate>Thu, 23 Apr 2026 18:06:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Napoleon-Ohio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>297db35b92cfe762bbf6a189b5c983dc38e2bf5d0db9ad2de72023976ba9b2a5</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.napoleonohio.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alkegen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31615</link>
<guid>3a68abc388606a36771c8c8b8bf64129</guid>
<pubDate>Thu, 23 Apr 2026 15:57:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Alkegen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09a5f6c2fe3a68c10f6809f5cd9d3dbf925335683ee2e4d1bc51c094824b1c3d</i><br /><br />Threat actor <b>description</b>: <i>Alkegen creates high performance specialty materials used in adva
nced applications including electric vehicles, energy storage, fi
ltration, fire protection and high-temperature insulation, among 
many others.

We will upload 57gb of corporate data soon. Employee personal doc
uments (passports, DLs, contacts, addresses, medical information 
and so on), client personal information, lots of confidential fil
es, projects, contracts and agreements, detailed financials, NDAs
, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Virginia-Health-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31611</link>
<guid>30de3848a3d427de6774066e0b9b09bc</guid>
<pubDate>Thu, 23 Apr 2026 12:53:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Virginia-Health-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>916d0c5fdb21f42deec278f80597a87b21f69a28eaa44b3be9b286ba994d9e7e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Coating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31608</link>
<guid>4f2bed48f31aa4f70b89c5e87a60e3e9</guid>
<pubDate>Thu, 23 Apr 2026 09:57:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Precision-Coating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f09e86b13e15fcf4401b5cd6535489e6d0f42ea366c2502ea93574e16cb86449</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A

There are multiple companies operating under the name "Precision Coating" across various industries and countries, and without additional context such as location or sector, I cannot reliably identify a specific organization to provide an accurate and factual description without risking confusion or misinformation.</i><br />Target victim <b>website</b>: <i>precisioncoating.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integer-Holdings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31607</link>
<guid>a71f9f47d27e10623154025319152a82</guid>
<pubDate>Thu, 23 Apr 2026 09:56:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Integer-Holdings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5861980b43c9589f07070fa0b0984f4c68cee4a0601eba3ab3cea926bb6a4e0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Integer Holdings is a US-based medical device manufacturer headquartered in Frisco, Texas. The company specializes in producing advanced technologies for the medical, non-medical, and portable medical markets, including batteries, power systems, and implantable components. It serves original equipment manufacturers across cardiac, neuromodulation, and vascular sectors, making it a key supplier in the global medical device industry.</i><br />Target victim <b>website</b>: <i>integer.net</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aptim</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31604</link>
<guid>7e64ef4e0d891aed100893d4ba43bb15</guid>
<pubDate>Thu, 23 Apr 2026 09:54:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Aptim</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62d3d395006ab7e87afd40d6b212d617e965bf3b6423d81617327137be00f8e5</i><br /><br />Threat actor <b>description</b>: <i>$krb5pa$23$APTIM.COM$APTIM.COM$$9936cd67a6d3d8560aaa25bb4a7a03b0bb8dfbbdbac8fed06e9262c41dce5ee567d0f7b52928d3626e43c0a7cfac4fb1a9b90887
$krb5pa$23$aptim.com$aptim.com$f7a8e75a2c6d3610fe9f4b34bec2a...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>SmartSystems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31603</link>
<guid>913c130aa3a3e9780ee459eadf80c05c</guid>
<pubDate>Thu, 23 Apr 2026 06:28:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>SmartSystems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1988557ae972b9c75fb4bece45d536f6b4983ba2decac7e23223e27727288921</i><br /><br />Threat actor <b>description</b>: <i>iesmartsystems.com zoominfo.com/c/smart-systems/139592895 Technology integrator since 2000 — Founded in Houston, Texas by Gary and Doug Colvin, i.e. Smart Systems has over 25 years of experience delivering design-build technology solutions for commercial clients.Core services: A/V, Cabling & Security — The company specializes in audio/video systems, structured cabling (fiber optic, voice, network), security systems (video surveillance, access control), wireless networks, and video conferencing solutions.Strong client loyalty — More than 90% of their business comes from repeat customers, ranging from small municipalities to large publicly-traded corporations; they serve universities, oil & gas campuses, banks, and more across Texas.Award-winning company — i.e. Smart Systems is a four-time Houston Business Journal Fast Tech 50 award recipient, with ~94 employees and revenue of approximately $18.7 million.</i><br />Target victim <b>website</b>: <i>iesmartsystems.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tractial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31599</link>
<guid>5342cfbc5928c7c95d2b1843f4ae9531</guid>
<pubDate>Thu, 23 Apr 2026 02:59:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Tractial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfa6d5b03c465ffad6a0a155834f3b25fd496ff28ad40472ee226f0fe19aefa1</i><br /><br />Threat actor <b>description</b>: <i>A small but substantial data breach at a fintech company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marnell-Financial-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31598</link>
<guid>d5fc93640233c90c41c729d8b185bd56</guid>
<pubDate>Thu, 23 Apr 2026 02:58:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Marnell-Financial-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfc59e32d2980709708a2c01f8d872888baf60cd25eed949073399ce376dc220</i><br /><br />Threat actor <b>description</b>: <i>Data breach at financial company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>trugreen.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31597</link>
<guid>63fe372a44401791d215daa2eedb8b7c</guid>
<pubDate>Wed, 22 Apr 2026 22:50:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>trugreen.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee2d6c99ec9d8b9f72cef9931d91c30da8610b25d4b266114195206d4b40b567</i><br /><br />Threat actor <b>description</b>: <i>TruGreen is the nation's leading lawn care provider offering neighborhoods across the country tailored lawn, tree and shrub care along with protection against mosquitoes and other pests. As a company rooted in scientific expertise with a customer-centered approach, TruGreen helps homeowners achieve an outdoor living space that brings them pride. Employees: 10k+ Revenue: $2.9 Billion Industry: Consumer Services Phone Number: (833) 830-2305</i><br />Target victim <b>website</b>: <i>trugreen.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>teamster773.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31596</link>
<guid>7570fece02991134d0785190d9e5a4eb</guid>
<pubDate>Wed, 22 Apr 2026 22:50:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>teamster773.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1b05f2e62d742e79ccfe78708436696265d998d295a9441852cd29c66d002be</i><br /><br />Threat actor <b>description</b>: <i>Teamsters Local 773 is a union dedicated to building unity and power for working people in the Greater Lehigh Valley. They focus on educating and engaging members, organizing unorganized workers, and mobilizing them to stand in solidarity. The union advocates for strong contracts, better pay, job security, and dignity in the workplace, empowering employees to effect positive changes in their work environments. With over a century of experience, Teamsters Local 773 provides support and resources to ensure that every member has the opportunity to thrive. Employees: 50 Revenue: $5 Million Industry: Membership Organizations Phone Number: (610) 434-4451</i><br />Target victim <b>website</b>: <i>teamster773.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jackson-Lewis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31595</link>
<guid>196f47aa4d2237535c1c559def28e60f</guid>
<pubDate>Wed, 22 Apr 2026 22:40:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Jackson-Lewis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef0d06c7d24759fde8f4cb689f02cd82b2ee34698f914d686bb4c89ab9a61125</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Jackson Lewis P.C. is a United States-based law firm specializing exclusively in workplace law and employment-related legal services. Founded in 1958 and headquartered in New York, the firm operates across numerous offices throughout the country. It advises employers on labor relations, workplace safety, litigation, immigration, and employee benefits, serving clients across a wide range of industries nationwide.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>INCYTE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31591</link>
<guid>680fd12be44eee12aee2a2e023438a5d</guid>
<pubDate>Wed, 22 Apr 2026 21:55:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>INCYTE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab033df56a873c42bec4501078bc33e8978f60651480fbf67d5a7a1d7e40aee5</i><br /><br />Threat actor <b>description</b>: <i>Incyte Corporation, a biopharmaceutical company, focuses on the discovery, development, and commercialization of various therapeutics in the United States. The ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>alexandergroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31593</link>
<guid>14b5caec7ac6a9609e748d56a17c174b</guid>
<pubDate>Wed, 22 Apr 2026 21:28:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>alexandergroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b9d3ecb8821ed4bdc06403814978d41f17b4ca0badf70572f432d7fdcdeec2b7</i><br /><br />Threat actor <b>description</b>: <i>The company is disregarding its customers' data. If a deal is not reached within 48 hours, the files will be made public.

The Alexander Group is a revenue growth and sales management consulting company. It is headquartered in Scottsdale, Arizona</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/the-alexander-group-inc/3639791</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>krwlawyers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31592</link>
<guid>cc7146d26842552ef3ae620e96a796ec</guid>
<pubDate>Wed, 22 Apr 2026 19:52:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>krwlawyers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b358a536d1f7daf1985ce788722884d49212e627504beb1db64039d5c65462c</i><br /><br />Threat actor <b>description</b>: <i>At KRW Lawyers, we understand the profound impacts that an unexpected accident can have on your physical, emotional, and financial well-being. Our personal injury and mass tort lawyers are dedicated to holding negligent parties accountable and recovering a comprehensive settlement for all your current and future care needs.   With decades of experience and over $1 Billion recovered, you can trust our attorneys to represent your best interests in and out of the courtroom. Our firm is proud to have its members recognized by Super Lawyers and Martindale-Hubbell, underscoring our impressive record of results and commitment to excellence, integrity, and service.</i><br />Target victim <b>website</b>: <i>krwlawyers.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>S4K-Entertainment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31590</link>
<guid>a5937eff64a8a3846e8e578938ba5629</guid>
<pubDate>Wed, 22 Apr 2026 16:39:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>S4K-Entertainment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84f595b45c3a9a394026c21bfd18344bbb4a11ecc65316441263182f297812c1</i><br /><br />Threat actor <b>description</b>: <i>S4K Entertainment is producing a series of Shakespeare 4 Kidz mov
ies for theatrical release.

We will upload 28gb of corporate data soon. Employee information 
(passports, DLs and so on), contracts and agreements, projects, f
inancials, NDAs, partners and client data and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kubiak-Melton--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31589</link>
<guid>e25499084e50b281cfc663be51ad40ef</guid>
<pubDate>Wed, 22 Apr 2026 16:39:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kubiak-Melton--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48b2304728f000f259a3ba5a2f4df2170c64ff54a5f7aa8749fac535baeb8b5e</i><br /><br />Threat actor <b>description</b>: <i>Kubiak & Melton, LLC provides audit, tax and bookkeeping services
. We prepare monthly financial statements, governmental complianc
e forms, payroll, and tax returns.

We will upload 12gb of corporate data soon. Client personal infor
mation (passports, DLs, birth and death certs, SSNs, addresses, p
hones, CC statements and much more), client financial information
, financials, NDAs, numerous internal confidential files, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Galliher-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31581</link>
<guid>a714b6bada5e4ad469abf003c9d2c3d8</guid>
<pubDate>Wed, 22 Apr 2026 11:55:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Galliher-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc395e4743232876ad7cd6bb46937d44c55b286ae99cbadd304f71687d08b638</i><br /><br />Threat actor <b>description</b>: <i>The Galliher Law Firm, established in 1974, specializes in personal injury law, providing dedicated legal representation to clients in Las Vegas and surrounding...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rutan--Tucker-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31580</link>
<guid>7c7994618ab9ec08e3e913145fcbab5e</guid>
<pubDate>Tue, 21 Apr 2026 23:18:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Rutan--Tucker-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a45f8ac9cc4956026418aa9416bb1ef909d17d30ecb2fdb9d8365e38fb6c8820</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1909 and headquartered in Costa Mesa, California, Rutan & Tucker, LLP. is a law firm. The F…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>K2-Electric-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31579</link>
<guid>e2ffe6e3efad872631508762c767e73b</guid>
<pubDate>Tue, 21 Apr 2026 20:34:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>K2-Electric-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e734712a74256ab1d8285cd75af0fcde2ea1b09d2ae5d85311015e192fbf4af4</i><br /><br />Threat actor <b>description</b>: <i>Commercial and industrial electrical contractor.</i><br />Target victim <b>website</b>: <i>k2elec.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>PTS-Office-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31575</link>
<guid>ee36a2060ec0721650bf82c39619ab88</guid>
<pubDate>Tue, 21 Apr 2026 19:56:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PTS-Office-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24a420404c064c46b5e7d80ab9296a3251b806d2b2a3a6a3d27c8d6918a3eec6</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heartland-Steel-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31577</link>
<guid>ce65aa143183d7336a8e77d192e7e44e</guid>
<pubDate>Tue, 21 Apr 2026 18:14:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Heartland-Steel-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>13222eec190965218e49dcc86c19c2961766be14737f87873c79ae7850b86d61</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ferguson-Timar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31565</link>
<guid>cdcd90c0088d9a4cb0f2bae4a4480a8d</guid>
<pubDate>Tue, 21 Apr 2026 17:55:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ferguson-Timar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbb50033cd5817506e96d7979dff7d3483f1e79ca94bd65256d4fd5e56e05b47</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Safety-Engineering-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31566</link>
<guid>cfbc4c656854352ff0ed6f6975d35c4c</guid>
<pubDate>Tue, 21 Apr 2026 16:55:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Safety-Engineering-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8856f427c151bf6a7928948c759f7b42e498e27a4bcff48bb30201a86063fb8</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ruskcountywi.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31567</link>
<guid>9f5a7b69549df5b26dcb95a74bae98eb</guid>
<pubDate>Tue, 21 Apr 2026 16:55:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ruskcountywi.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aeae8d5fa80b1a03b516978a0f421bb167a68cfafd968912c2a9ec4bcbcb4739</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Salimetrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31571</link>
<guid>71395be63174d9842f3e2b0c3520ed5e</guid>
<pubDate>Tue, 21 Apr 2026 15:49:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Salimetrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7311157e65b689d737b0c649fe35a3993e62f694a324c4909c45b1c6d63309f7</i><br /><br />Threat actor <b>description</b>: <i>Salimetrics specializes in salivary bioscience, offering industry
-standard saliva collection methods, salivary assay kits, and tes
ting services for reliable results. Their products cater to resea
rchers and clinicians involved in biobehavioral research and diag
nostics, providing tools for sample collection and analysis. 

We will upload corporate data soon. Employee information, patient
s information (blood tests and other health information), financi
als, internal confidential files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alva-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31570</link>
<guid>1c8dcf919f8a604f3a488b0e4b0f1420</guid>
<pubDate>Tue, 21 Apr 2026 15:49:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Alva-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bad3792abd4f2fe409fc3fe98e3e651f77ba74f2d6f16cdd117947942c4135fd</i><br /><br />Threat actor <b>description</b>: <i>Alva Manufacturing specializes in CNC precision machining, focusi
ng on milling and multi-axis turning for high-tech industries suc
h as defense and space. They utilize state-of-the-art automated m
achining centers and advanced measuring technology, including Hex
agon CMM and Keyence systems.

We will upload corporate data soon. Employee information (passpor
ts, SSNs, addresses, phones, photos and so on), projects (BOEING 
and Lockheed Martin files and so on), financials, lots of NDAs an
d so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MAC-Construction--Excavating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31564</link>
<guid>e69cf84ed41fbe71985972c027190b49</guid>
<pubDate>Tue, 21 Apr 2026 14:20:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MAC-Construction--Excavating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e26a893a1a91072d84bb21af06131d35eccb8c023836c2c5d2f64f76e4535f80</i><br /><br />Threat actor <b>description</b>: <i>MAC is a diversified construction company with integrated divisio
ns working closely together to provide a wide variety of quality 
construction and excavation services, quality workmanship - produ
ced by quality people. 

We will upload 30gb of corporate data soon. DB data (Salary / Inc
ome 2490386 rows, Physical Address 223606 rows,Online Account 123
070 rows, Phone / Fax 111784 rows, Bank / Financial 73100 rows, I
P / Device 5923 rows, Password / Secret 1783 rows, Tax ID 1686 ro
ws, Name (Person) 1074 rows, Email 967 rows, Photo / Biometric 13
7 rows, FR - Contact 100 rows, Property 28 rows, Employment 18 ro
ws, SSN / National ID 8 rows) and a lot of other internal files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arctic-Home-Living</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31562</link>
<guid>4b1905cff5bc8b47ae1c9d92e2c759df</guid>
<pubDate>Tue, 21 Apr 2026 12:49:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Arctic-Home-Living</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5752df38a92037c39f1cb847e2be31f50f7c7385d9ff9d67ab5d28a47c6c6bf3</i><br /><br />Threat actor <b>description</b>: <i>Arctic Home is Alaska's locally owned hot tub dealer with over 25
years of experience, specializing in premium hot tubs, spas, sau
nas, and cold plunges designed for the unique Alaskan environment
.

We will upload corporate data soon. Employee information (scanned
passports, DLs, I9s, SSNs, credit cards information and so on), 
customer data, agreements, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Samuel-I.-White-PC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31558</link>
<guid>20c26296a2b1def8331cd4c4a604dd41</guid>
<pubDate>Tue, 21 Apr 2026 03:51:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Samuel-I.-White-PC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f795a52aa1b723b4e6c4b7e330ae067f327d082fee21e624986e77ee8ad986f</i><br /><br />Threat actor <b>description</b>: <i>Significant breach at a law firm.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Be-Juice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31546</link>
<guid>c695c406dd17d2fc9dbfe917adaf9e33</guid>
<pubDate>Mon, 20 Apr 2026 20:56:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Be-Juice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d886ccdaa2f265f3a8f3a810bdd67b504d2cd8b2af28fded2424e5a4a4db9c5</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>rheem</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31554</link>
<guid>f427810d6c49d16a865d20c29ac11e61</guid>
<pubDate>Mon, 20 Apr 2026 20:36:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>rheem</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57cf47c3500b90905430934fd6c9d6700f7efb51e482920f4cc4f9946729a6e3</i><br /><br />Threat actor <b>description</b>: <i>Rheem Manufacturing Company   1100 Abernathy Road, Suite 1700 Atlanta, GA 30328, United States www.rheem.com  is a well-established manufacturer specializing in heating, cooling, and water heating products. Founded in 1925, the company has its headquarters in Atlanta, Georgia, and has grown to become a global leader in its industry. Company Overview. Rheem produces a wide range of products, including residential and commercial water heaters, boilers, air conditioning units, and heating, ventilation, and air conditioning (HVAC) equipment. The company is particularly noted for its commitment to energy efficiency, offering numerous ENERGY STAR® certified products.   Leaked data: 320 GB (479,856 Files, 76,897 Folders) includes developments: technical documentation, drawings, test reports and other technical information, employee data containing personal information, corporate information, contracts and agreements (including non-disclosure agreements), financial information and metrics, and much more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Commscope</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31552</link>
<guid>4c7e17f10bce99f0c3df0f414eb9165c</guid>
<pubDate>Mon, 20 Apr 2026 20:30:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Commscope</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abdbabe6da9fc78fb54665fc68d8aac5a4412ba85d5b825a5c2f96128d7269a8</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] CommScope is an American telecommunications infrastructure company headquartered in Hickory, North Carolina. It designs and manufactures network infrastructure solutions including cables, connectivity systems, wireless equipment, and data center infrastructure. The company serves telecommunications providers, enterprises, and government clients worldwide. Founded in 1976, CommScope operates globally across the broadband, wireless, and enterprise networking industries.</i><br />Target victim <b>website</b>: <i>Commscope.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>SEL-Safety-Engineering-Laboratory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31544</link>
<guid>0628fc4708a87a5ad6fa86481d86836b</guid>
<pubDate>Mon, 20 Apr 2026 19:54:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SEL-Safety-Engineering-Laboratory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6fab8bcd3542e68e7b5721ecdf99df76e7441d77418d79d7b94ba50c122b37f</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Go-Solution</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31543</link>
<guid>5cfcbafd768519bce51371aae5cac8fb</guid>
<pubDate>Mon, 20 Apr 2026 17:44:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Go-Solution</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>001eab12d7945993de732265aa78d00cd19e2ac2199da246888b6d946317cad4</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>imbriefamilylaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31540</link>
<guid>b16a06a5ea94028944a81ad5bbdbb8ca</guid>
<pubDate>Mon, 20 Apr 2026 14:39:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>krybit</b> claims attack for <b>imbriefamilylaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d757dabe290020eaaa47af89ee0ea64d6394f640b250e3c9a9c9cb08cd772dc6</i><br /><br />Threat actor <b>description</b>: <i>The attorneys at the Imbrie Law Firm practice primarily in the following counties: Brazos, Robertson, Burleson, Lee, Gri...</i><br />Target victim <b>website</b>: <i>imbriefamilylaw.com</i>]]></description>
<category>krybit</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nutrabio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31534</link>
<guid>f5680c1280b1c59b6bf77b0f5b3d92d6</guid>
<pubDate>Mon, 20 Apr 2026 02:34:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Nutrabio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30c4e06f4ac3f6d25e214b65246cf9a767eca54bb5257768c0fb28928cb0421a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] NutraBio is a US-based dietary supplement manufacturer founded in 1996 and headquartered in Middlesex, New Jersey. The company operates in the health and wellness industry, producing sports nutrition products including protein powders, pre-workouts, vitamins, and recovery supplements. NutraBio is known for its commitment to transparency, using fully disclosed labels and manufacturing products in an FDA-registered, cGMP-certified facility.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Citizens-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31530</link>
<guid>855574f497fe975ae99d6b7d5353c0e8</guid>
<pubDate>Mon, 20 Apr 2026 02:32:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Citizens-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6de7233f272222aa89df9d97aaa3b6c983b8ffff8e02fe12070328e6bbf49386</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Citizens Bank is a major American retail and commercial bank headquartered in Providence, Rhode Island. Operating within the financial services industry, it offers a wide range of products including personal and business banking, loans, mortgages, credit cards, and wealth management services. It serves millions of customers across the United States through branches, ATMs, and digital banking platforms.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Frost-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31529</link>
<guid>7d3d99bab1c841a23a2d7b50ebd7b7bb</guid>
<pubDate>Mon, 20 Apr 2026 02:32:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Frost-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6171cb97c88843cbdf26266e90a2ee96676824eaeeb7956615cfefe4931bac5</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Frost Bank is a Texas-based financial institution and a subsidiary of Cullen/Frost Bankers, Inc. Founded in 1868 and headquartered in San Antonio, it operates across major Texas cities offering personal and commercial banking, wealth management, insurance, and investment services. As one of the largest independent banks in Texas, it serves individuals, businesses, and institutions within the United States financial services industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pitney-Bowes-Inc.-pb.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31526</link>
<guid>357eef2143cfb46c8d49017ebd7689b5</guid>
<pubDate>Sun, 19 Apr 2026 18:06:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Pitney-Bowes-Inc.-pb.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a720471705f49ea790d62ac5839dfad92524d12d3c0f850deba4924cde403edb</i><br /><br />Threat actor <b>description</b>: <i>Over 25M Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>pb.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>7-Eleven-Inc.-7-eleven.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31525</link>
<guid>92b5eb942a693af473d741b2c487fdd5</guid>
<pubDate>Sun, 19 Apr 2026 18:06:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>7-Eleven-Inc.-7-eleven.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b87d2062b4b04bbbc11cd22319da9a5356f14db6a37a8241dab26980fed07a5</i><br /><br />Threat actor <b>description</b>: <i>Over 600k Salesforce records containing PII and other internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>7-eleven.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carnival-Corporation--plc-carnivalcorp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31524</link>
<guid>ce20169db964e41ea7518836aab50628</guid>
<pubDate>Sun, 19 Apr 2026 18:06:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Carnival-Corporation--plc-carnivalcorp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c16f736b1ca85bdb8a88ceddf44ad87b464e577161718edcd9069a89b78e638c</i><br /><br />Threat actor <b>description</b>: <i>Over 8.7M records containing PII and other terabytes of internal corporate data have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>carnivalcorp.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alert-360-Opco-Inc.-alert360.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31522</link>
<guid>0bf1ace74c80d5a941676918831d37e9</guid>
<pubDate>Sun, 19 Apr 2026 18:05:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Alert-360-Opco-Inc.-alert360.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57e0384a6545334f15e81c3432813ac66f2ba9774f5082393fe279a7f0477638</i><br /><br />Threat actor <b>description</b>: <i>Over 2.5M records containing PII and other internal corporate data have been compromised. Please read the chatlog of the negociation by cliking the Download button below to see why this data was leaked. | Size: 10GB+ (compressed) | Updated: 18 Apr 2026 | SHA256: 9c5c8225f27a23f1a03526bfd15dad02b5976797664a92bdd53b23f5f9ef3fe3</i><br />Target victim <b>website</b>: <i>alert360.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Marton-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31499</link>
<guid>34d9646a6c7d6c0de3ece3de6f06a91f</guid>
<pubDate>Sun, 19 Apr 2026 16:59:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>The-Marton-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0deb64ea329476ab926184690e74fb68639e30335a94e6e6a037d4175d17a4d3</i><br /><br />Threat actor <b>description</b>: <i>martonagency.com The Marton Agency, Inc. is a New York-based international theatre rights agency founded in 1953 by Elisabeth Marton, currently run by her niece Tonda Marton since 1992, and headquartered at 307 West 82nd Street, Manhattan. The agency handles foreign-language rights for American plays and musicals, helping theaters and producers worldwide acquire production rights to US theatrical works. It operates through a global network of associate agents in each country and serves both overseas producers and foreign literary agents as a full-service rights licensing agency</i><br />Target victim <b>website</b>: <i>martonagency.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Great-Cookie</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31498</link>
<guid>3fc6ae40bfc04ae4123761055e639bc2</guid>
<pubDate>Sun, 19 Apr 2026 14:55:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Great-Cookie</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28fa2ab82da07d41167ef430e0dcdd4cc3e00a973541aeb7e5cd6c0d449a1f9f</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henley</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31497</link>
<guid>1dcfee25dedf7c8e7e25a9b588299f84</guid>
<pubDate>Sun, 19 Apr 2026 13:55:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Henley</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7465dfe4803fb18700c761f9364d97f76fc03e89cb36e8dc312f8ad233a7ca2b</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>HS-Technology-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31491</link>
<guid>25d80b451b5c76cf01048f4b1d367e35</guid>
<pubDate>Sat, 18 Apr 2026 19:55:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>HS-Technology-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae6102a532b7490b749598096439e6e5bf5f6085372f5bd231f148ee103b764d</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evict-them-for-me</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31490</link>
<guid>1894ea678da89602948e674a85fbfe09</guid>
<pubDate>Sat, 18 Apr 2026 15:31:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Evict-them-for-me</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e42c692d901edea171207db7ffb6ea23f1e854d8d7a7987ce4051845d8dd5cf</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>evictthemforme.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Winnitex-Americas-Limited</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31487</link>
<guid>20906d510c44acb485fbf89daca562ac</guid>
<pubDate>Fri, 17 Apr 2026 19:13:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Winnitex-Americas-Limited</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e64e369d1d8680a02cb9c867f97229c2fae9db2f818f2558a1ec9aba1a88a217</i><br /><br />Threat actor <b>description</b>: <i>Winnitex (Americas) Limited is primarily engaged in the trading of textile products, including yarns, garment fabrics, and finished textile goods. The company sources textiles from related parties and external suppliers and sells them to customers both within its corporate group and on the open market. Through its wholly-owned subsidiary in Mainland China, Zhejiang Qing Mao Weaving, Dyeing & Printing Co., Ltd., it also participates in the manufacturing, dyeing, and printing of garment fabrics. In 2024, the company reported HK$ 740 million in revenue from textile sales.</i><br />Target victim <b>website</b>: <i>www.winnitex.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Millennium-Dental-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31481</link>
<guid>5a897c4ac62db0e169de0b47ae9c2842</guid>
<pubDate>Fri, 17 Apr 2026 16:34:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Millennium-Dental-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b52f1bd8dd6e0a3971a0cc48887bffd96bd42fe75f66c077ec9ebb8e676fdad3</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1994 and Headquartered in Cerritos, California. Millennium Dental Technologies, Inc manufactures and distributes dental products. It offers PerioLase MVP-7, a laser designed especially for laser periodontal therapy that performs soft and hard tissue laser procedures.
</i><br />Target victim <b>website</b>: <i>www.lanap.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>bbalawgroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31480</link>
<guid>87688e644bd630526fedd4f22613cef9</guid>
<pubDate>Fri, 17 Apr 2026 16:29:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>bbalawgroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bf4530a8ef158c9d59812d74b086d71fe04c27dd6527c59c5c21ea6036b3315</i><br /><br />Threat actor <b>description</b>: <i>Also referred to as BBA Immigration, is a boutique U.S. legal practice headquartered in Houston, Texas, specialising in immigration law …</i><br />Target victim <b>website</b>: <i>bbalawgroup.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>thruwayplumbingservice.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31474</link>
<guid>a33b40c5c94f754663bba65e02fae22b</guid>
<pubDate>Fri, 17 Apr 2026 16:25:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>thruwayplumbingservice.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6af074d40b7adb4269b000382e02cb781d476ef4d832dfdab0bdebce5e0862de</i><br /><br />Threat actor <b>description</b>: <i>The business provides standard residential and commercial plumbing services, including: - Leak detection and pipe repair - Drain cleaning and …</i><br />Target victim <b>website</b>: <i>thruwayplumbingservice.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fagen-Friedman--Fulfrost-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31470</link>
<guid>1504d56c70e614417b8d1aec1090fec5</guid>
<pubDate>Fri, 17 Apr 2026 15:33:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Fagen-Friedman--Fulfrost-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41fbd8f02465c01273423b4391ff56dd6d68a5bddb3307aaa6882cc6ec1a9de0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Fagen Friedman & Fulfrost LLP is a California-based law firm specializing in education law. The firm provides legal services exclusively to public educational agencies, including K-12 school districts, community colleges, and county offices of education throughout California. Its practice areas include labor and employment, special education, student matters, governance, and litigation. The firm operates entirely within the United States.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>treelawoffice.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31469</link>
<guid>54a96ac32645d07ae686344a55414be1</guid>
<pubDate>Fri, 17 Apr 2026 14:48:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>treelawoffice.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bcba6026337592b9ad22e9ffee42493b2dc1c14b9f3b92b793743d4a72a947c9</i><br /><br />Threat actor <b>description</b>: <i>Tree Law is a Social Security Disability law firm with 25 years of experience, dedicated to representing claimants in their pursuit of Social Security disability benefits. The firm specializes in assisting disabled individuals who are unable to work, guiding them through the entire Social Security process from initial applications to federal court. With a proven track record of helping thousands of clients, Tree Law aims to provide financial and medical benefits to those in need. Their services are available in Yakima and Tri-Cities, WA. Employees: 50 Revenue: $5 Million Industry: Law Firms & Legal Services Phone Number: (509) 452-1700</i><br />Target victim <b>website</b>: <i>treelawoffice.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>bgcsnv.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31468</link>
<guid>90a562851e9222030339fcf2960c15e9</guid>
<pubDate>Fri, 17 Apr 2026 14:47:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>bgcsnv.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28b9b85c63b2428f6aa34d31bd3bb372fbf97271e39a9838c67186c95833834d</i><br /><br />Threat actor <b>description</b>: <i>Boys & Girls Club of Southern Nevada provides a safe and engaging environment for youth through various programs, including early childhood learning, summer camps, and mental health services. With 13 clubhouses across the region, they aim to support children in achieving their potential regardless of their background. The organization encourages community involvement and offers opportunities for volunteering and sponsorship. Their mission is to create a positive impact on the lives of young people in Southern Nevada. Employees: 200 Revenue: 15.3 Million Industry: Membership Organizations Phone Number: (702) 367-2582</i><br />Target victim <b>website</b>: <i>bgcsnv.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-of-JamesC-Shields</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31466</link>
<guid>a7b8e43297034e90611ce98d9b6efcfe</guid>
<pubDate>Fri, 17 Apr 2026 14:32:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Law-Offices-of-JamesC-Shields</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>685171ed363178a0f2cb599d4021ed23d9e4702829c1bb5f18136a7399d0f8cc</i><br /><br />Threat actor <b>description</b>: <i>The Law Offices of James C. Shields specializes in bankruptcy, es
tate planning, and probate services, providing tailored legal sol
utions to clients in Southern California. With over 15 years of e
xperience, the firm has assisted thousands in navigating financia
l difficulties and planning for the future.

We will upload corporate data soon. Personal data of clients (pas
sports, DLs, SSNs, death/birth certificates, financials and other
docs), detailed financials, court files, investigations, police 
reports, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>R-Roese-Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31464</link>
<guid>49030e99dc6676fa7a0ae152ce0c68c7</guid>
<pubDate>Fri, 17 Apr 2026 14:32:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>R-Roese-Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c56a661397af02336702c477aea0a3ba004511f8ddc21d455cdc6c5a64481c6</i><br /><br />Threat actor <b>description</b>: <i>R. Roese Contracting Company Inc. is a leading provider of underg
round and aerial construction services, specializing in telecommu
nications, water and sewer, electric, and gas transmission and di
stribution.

We will upload 61gb of corporate data soon. Personal data of empl
oyees (passports, phones, emails and so on), financials, client d
ata, lots of project files, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harris-Beach-Murtha</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31453</link>
<guid>e1d96dd51f6c61a48b3af39333626766</guid>
<pubDate>Wed, 15 Apr 2026 22:25:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Harris-Beach-Murtha</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a902152d8f3e648bc3e5bc7f047e3bf691db91189c7009ab91a9527423087f2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Harris Beach Murtha is a full-service law firm operating in the United States, primarily in the northeastern region. Formed through the merger of Harris Beach and Murtha Cullina, the firm provides legal services across areas including corporate law, litigation, real estate, healthcare, and public finance. It serves clients ranging from businesses and municipalities to nonprofits and individuals across Connecticut, New York, and nearby states.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clearwater-Marine-Aquarium</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31451</link>
<guid>9c7441bc759cf5c713a4c14044747778</guid>
<pubDate>Wed, 15 Apr 2026 20:26:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Clearwater-Marine-Aquarium</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fedaac869689eeeb81b5cfad7018bc23907b98460d6a26d213672ea7952813fc</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cmaquarium.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SPGLOBAL-LiteLLMTrivy-campaign-TeamPCP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31449</link>
<guid>f36c95070399e5d69f5ae982b8b664f6</guid>
<pubDate>Wed, 15 Apr 2026 19:08:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>vect</b> claims attack for <b>SPGLOBAL-LiteLLMTrivy-campaign-TeamPCP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6202fe042f4fa5e4a5978f836353c1da0f153d9dbdc17f3d53247ac69efbd56</i><br /><br />Threat actor <b>description</b>: <i>Status: STATUS: NEGOTIATING | Sector: Business Services | Internal projects, secrets, api keys etc DATA SIZE: 250GB | Deadline: 8d 8h</i><br />Target victim <b>website</b>: <i>www.spglobal.com/en</i>]]></description>
<category>vect</category>
</item>
<item xmlns:dc='ns:1'>
<title>Truckload-Carriers-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31440</link>
<guid>31429ccef08e1dfc4839ba23a3d2443a</guid>
<pubDate>Wed, 15 Apr 2026 14:58:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Truckload-Carriers-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66e54378cc5337937195b7c69fce6effa9eeb19d629d40ce85d7fa39ce7043ff</i><br /><br />Threat actor <b>description</b>: <i>Truckload Carriers Association is a national trade association fo
cused on the truckload segment of the motor carrier industry.

We will upload 21gb of corporate data soon. Personal data of empl
oyees, detailed financials, contracts and agreements, customer an
d partner files, projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vluznet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31436</link>
<guid>8abb69b3d54bf7e21e4aff5f1047801e</guid>
<pubDate>Wed, 15 Apr 2026 13:42:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Vluznet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe194d2954a893f33f5a2b11efa5f82ce986611c312486fe324a7b5ef6129188</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>vluznet.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epoch-Times</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31435</link>
<guid>7f982c526e15dfa8be4c3eaa864c56ee</guid>
<pubDate>Wed, 15 Apr 2026 13:41:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Epoch-Times</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>262690727c0b6c3d5efde254f5ee78db4e614b2afabf42f69fdd9764dcac15fe</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Epoch Times is an American media company founded in 2000 by Chinese-American Falun Gong practitioners. It operates newspapers, websites, and video content across multiple countries, publishing in numerous languages. The company covers news, politics, health, and culture, but has drawn scrutiny from researchers and platforms for spreading misinformation and promoting far-right narratives. It is headquartered in New York, USA.</i><br />Target victim <b>website</b>: <i>epochtimes.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wayne-Brothers-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31432</link>
<guid>9802a535bbdbcec203871db6d9595586</guid>
<pubDate>Wed, 15 Apr 2026 13:40:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Wayne-Brothers-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbdb49d92aa0514206739267526be2b2299a5fd44ffe582e15190dfc7cf34326</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>waynebrothers.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Questivity</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31431</link>
<guid>5242ef6f489fc9c35ba357927f91a59f</guid>
<pubDate>Wed, 15 Apr 2026 13:39:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Questivity</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d4573d04af94168d2a95895cf439832e2325fe7b1fe7e7513696ee694e90896</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>questivity.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Millenium-Packaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31430</link>
<guid>8c4e1000e86191ffd2a27a253c0aad82</guid>
<pubDate>Wed, 15 Apr 2026 13:38:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Millenium-Packaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e391356d36a36e9dcc2c66133ad13b4e9256db41f2e6a5e6db5b5ba82eb28ebd</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>mil-pkg.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Astreya</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31425</link>
<guid>d79f7940be5afa4e3fa70cd73295878f</guid>
<pubDate>Wed, 15 Apr 2026 13:35:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Astreya</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6a16ebfe8129176acaf92be6ad1a58b7ab9998ce2026f935f3a2a661f37b3d4</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Astreya is a US-based IT managed services company headquartered in Sunnyvale, California. It provides technology workforce solutions, IT support, infrastructure management, and digital workplace services to large enterprises. Operating primarily in the information technology services industry, Astreya partners with major technology firms globally, delivering staffing and managed IT services across multiple countries while maintaining its core operations in the United States.</i><br />Target victim <b>website</b>: <i>astreya.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cognizant</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31424</link>
<guid>e0c79d99ee375ed5ae7f77eb0e469957</guid>
<pubDate>Wed, 15 Apr 2026 13:34:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Cognizant</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7bb88d61f35c8f7eeac4b35caad95f891f191d82f60e86f13f1d3e75e418e5e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Cognizant is a multinational information technology and professional services company headquartered in Teaneck, New Jersey, USA. It operates in the IT services and consulting industry, offering digital transformation, technology, and business process outsourcing services. Founded in 1994, Cognizant serves clients across healthcare, financial services, manufacturing, and retail sectors globally, with major delivery centers in India.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fletcher-Chrysler-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31420</link>
<guid>a637b51c944078205e237f8694399ddc</guid>
<pubDate>Wed, 15 Apr 2026 12:03:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fletcher-Chrysler-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ff553941ce9a295bc05e6ef28595706958ebecc06bcebd2810d79c6ef2b7b8a</i><br /><br />Threat actor <b>description</b>: <i>Fletcher Chrysler Dodge Jeep Ram is a dealership located in Frank
lin, IN, offering a wide selection of new and used Chrysler, Dodg
e, Jeep, and Ram vehicles. They serve clients in Franklin, Indian
apolis, Shelbyville, and surrounding areas, providing assistance 
in vehicle purchasing, financing options, and automotive services
.

We will upload 28gb of corporate data soon. Personal data of empl
oyees (passports, DLs, SSNs and others), financials, contracts an
d agreements, client files, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Curtis-Design-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31418</link>
<guid>c219b83bdbd3fc9bf4fa8526d4368ea1</guid>
<pubDate>Wed, 15 Apr 2026 10:43:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Curtis-Design-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2961c17c78626c0cffa2a35b260a11a8551f63cead5fc8255547099e9b19a435</i><br /><br />Threat actor <b>description</b>: <i>Curtis Design Group specializes in home architecture and design, creating beautiful and livable spaces tailored to the needs of families and developers. They focus on understanding client dreams and site specifics to produce detailed blueprints that reflect those visions. The company emphasizes a collaborative approach, ensuring clients are delighted with the final designs before working with builders. Their services extend beyond Utah, aiming to create homes that endure and bring joy for generations.</i><br />Target victim <b>website</b>: <i>curtisdesigngroup.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Flash-Charm-INC---IDERA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31415</link>
<guid>fd80c4b06025c38f9d6958ebe4f14532</guid>
<pubDate>Tue, 14 Apr 2026 21:35:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Flash-Charm-INC---IDERA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e71ae1dc5cc591f1d4ace5d9536b0391dbe869d12fe428ed3d557d57d948e28</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Flash Charm Inc is a software company associated with Idera, Inc., a US-based technology firm headquartered in Houston, Texas. Idera develops and provides database management, developer tools, and test management software solutions. Its products support database administrators and developers across multiple platforms. Flash Charm Inc appears to operate as a subsidiary or affiliated entity within Idera's broader portfolio of software brands serving enterprise IT markets.</i><br />Target victim <b>website</b>: <i>idera.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gastroenterology--Hepatology-of-CNY</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31412</link>
<guid>63d01849974fcec145c71b5ebb80e184</guid>
<pubDate>Tue, 14 Apr 2026 20:06:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>exitium</b> claims attack for <b>Gastroenterology--Hepatology-of-CNY</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8f832738966d019660397ff62a7babc4763da8e1ec802bda15e8f22430adbee</i><br /><br />Threat actor <b>description</b>: <i>Website: gandhofcny.com
Zoominfo: https://www.zoominfo.com/c/gastroenterology--hepatology-of-cny-pc/346091487

Data sample, whole internal data will be sold if they wouldn't pay ransom.

Also Digestive Disease Center of CNY, LLC (ddcofcny.com)

GI practice + AAAHC-accredited endoscopy center. Syracuse, New York, USA.

Full database for sale — 167,303 patients, 124,761 SSN, 49,798 with sensitive diagnoses:
- 167,303 patients — 124,761 with SSN, 166,402 (99%) with address, 164,296 (98%) with phone, 85,318 (51%) with email
- 1,093,863 diagnoses (ICD-10), 1,547,142 medications, 186,246 pathology specimens with narrative reports
- Sensitive (dx + meds): 49,798 patients — 44,861 with SSN. Mental health: 43,902 | Substance/Alcohol: 5,111 | STIs: 2,779 | Cancer: 2,708 | Hepatitis C: 1,906
- Includes notable individuals (politicians, businesspeople, public figures)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>exitium</category>
</item>
<item xmlns:dc='ns:1'>
<title>D-Troy-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31410</link>
<guid>5994cf5ebd61f4806932d5f226cb64d0</guid>
<pubDate>Tue, 14 Apr 2026 17:35:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>D-Troy-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6f380ad5e0398784ef16cb566af3dd508b643f30a3331c0291fd7368ff5ebf7</i><br /><br />Threat actor <b>description</b>: <i>- Internal Documents- Employee Data</i><br />Target victim <b>website</b>: <i>www.dtroylogistics.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>imadesign.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31388</link>
<guid>1f8ac4a305f85a4b617655db27206fe1</guid>
<pubDate>Tue, 14 Apr 2026 15:52:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>imadesign.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a469011751187f2fa10257e8cfbeb157fe30d85c858e86ba2be1511af7de2055</i><br /><br />Threat actor <b>description</b>: <i>IMA Design Group, Inc. specializes in master planning, development services, and landscape architecture, with a particular focus on creating exceptional spaces ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>novafp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31390</link>
<guid>452dee7ed3aac40e980602f275eec5e5</guid>
<pubDate>Tue, 14 Apr 2026 15:52:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>novafp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7319390202bd5920e9ca8af34094636c814c23cf9fdf68fcd435cddbd79fb69f</i><br /><br />Threat actor <b>description</b>: <i>Nova Fire Protection Inc. specializes in sprinkler fire suppression systems, 
offering design, installation, repair, inspection, and testing services to homeown...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ppiplastics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31391</link>
<guid>4b997c95a3cd22f4f5a45903bc4f319a</guid>
<pubDate>Tue, 14 Apr 2026 15:52:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>ppiplastics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57a84508ebe371a18aafee386da8029fb78bb2b637b03d574a91dc47552d3303</i><br /><br />Threat actor <b>description</b>: <i>Preproduction Plastics Inc. is a company specializing in structural foam injection molding and gas-assisted injection molding.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>je-nyc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31392</link>
<guid>b1a535724274b293f9623a791919c16e</guid>
<pubDate>Tue, 14 Apr 2026 15:52:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>je-nyc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8701e2e88ac570c4ef249673d3a7b69a8c4d28cd1b11cb715620b25c80a6e511</i><br /><br />Threat actor <b>description</b>: <i>Jacmel Enterprise Inc. offers a wide range of IT services, including Microsoft Dynamics solutions, project services such as data cabling and server configurati...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>breslinbuilders.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31393</link>
<guid>0c394f0bd80e37fa0d8873166e556457</guid>
<pubDate>Tue, 14 Apr 2026 15:52:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>breslinbuilders.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e5674ebdfe619067ace3dca495a210f417527646ac738932a6a98ecf2b70fc0</i><br /><br />Threat actor <b>description</b>: <i>Breslin Builders is a general contractor specializing in design and construction, based in Las Vegas, Nevada, and serving the Las Vegas Valley and Southern Neva...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>tulsachamber.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31394</link>
<guid>0f4a21d571adbe663374dbe676987dbc</guid>
<pubDate>Tue, 14 Apr 2026 15:52:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>tulsachamber.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2cc6d6a514edb6dc4a3a6cf9d168336e61d5437c2efe4816a8840abcdbdce9d9</i><br /><br />Threat actor <b>description</b>: <i>The Talsi Regional Chamber of Commerce is committed to serving as a leading business-oriented organization and improving the quality of life in the community by...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>milliondollarbabyco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31395</link>
<guid>5f2397a240ce3565d4d3b82b0db2fc65</guid>
<pubDate>Tue, 14 Apr 2026 14:52:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>milliondollarbabyco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d601cc74b74d887d84a2788ea6677d26d3878f09819dc30736008907c1bf7094</i><br /><br />Threat actor <b>description</b>: <i>Million Dollar Baby Co. was founded in 1990 and is a proudly family-owned business based in Los Angeles. Since then, MDB has grown to include seven distinct chi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>graphicinfo.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31396</link>
<guid>47e7fdb0ab1113aaef1f5029de4792b0</guid>
<pubDate>Tue, 14 Apr 2026 14:52:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>graphicinfo.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de946ef96699aea508098ede086491bc081e1985eb880dfe53477947d16196e6</i><br /><br />Threat actor <b>description</b>: <i>Graphic Information Systems Inc. specializes in the custom production of barcode labels, product number/identification labels, and warehouse signage, serving bu...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>gtlcompany.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31397</link>
<guid>344da4009ef2bab9620f67c8e3a337b5</guid>
<pubDate>Tue, 14 Apr 2026 14:52:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>gtlcompany.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1e39f5519a7c5b4aa811dfb1c86946a3a4dd94e8e4d622ab9a34dafca02070d</i><br /><br />Threat actor <b>description</b>: <i>Gloyer-Taylor Laboratories, Inc. (GTL) is a high-tech company specializing in providing revolutionary technologies for the aerospace industry. Its product portf...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ServiceMaster-Clean-services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31399</link>
<guid>75179ec48bcbbdd4fbd025a4db2dc3b8</guid>
<pubDate>Tue, 14 Apr 2026 14:07:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ServiceMaster-Clean-services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>86f0b780a5ee059382ca3fd030a9dd290f7368056c83111a93fb67bd8f97fe54</i><br /><br />Threat actor <b>description</b>: <i>ServiceMaster Services, Inc. is a privately owned and operated co
mmercial contract cleaning company. Founded in 1974, ServiceMaste
r specializes on servicing office buildings and other large facil
ities. It is headquartered in Memphis, Tennessee.

We will upload corporate data soon. Personal data of employees (p
assports, 20  DLs, SSNs and others), financials, contracts and ag
reements, client files, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>R-L-Larson-Excavating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31386</link>
<guid>4e6bdf8e5aed24d7a26d7318e0c87417</guid>
<pubDate>Tue, 14 Apr 2026 12:49:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>R-L-Larson-Excavating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25834a8f7701350e86ec9afc2166169f5ebeec1ca78a92b23d901b8e79f25620</i><br /><br />Threat actor <b>description</b>: <i>R. L. Larson Excavating Inc., is an excavating contractor based i
n St. Cloud, MN. 

We will upload 30gb of corporate data soon. Personal data of empl
oyees (DLs, w9 forms and others), financials, drawings and specif
ications, contracts and agreements, projects, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>decaturdiagnosticlab.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31379</link>
<guid>02ff9da844ffbab5c01c0cd06386b958</guid>
<pubDate>Tue, 14 Apr 2026 10:45:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>decaturdiagnosticlab.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>92d04df70e798ad05d9bfaabe777ae576522a9c4580b3a54265b22853388ffa9</i><br /><br />Threat actor <b>description</b>: <i>Located inside the Med-Surg Complex; Decatur Diagnostic Lab is a privately owned lab servicing the D...</i><br />Target victim <b>website</b>: <i>decaturdiagnosticlab.net</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>PsychPlus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31378</link>
<guid>4fa0a0925c9527b40fb2353fc03e2bf0</guid>
<pubDate>Tue, 14 Apr 2026 10:29:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>PsychPlus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87ffc3bd53f959d83023b442551df02285eec38368e466a2fc78fe353c4a7ab6</i><br /><br />Threat actor <b>description</b>: <i>psychplus.com zoominfo.com/c/psychplus/1319245304 PsychPlus is a Houston-based mental health company founded in 2019–2020, offering virtual and in-person care via licensed psychiatrists and therapists. It focuses on accessibility by accepting 99% of commercial insurances (including Medicare/Medicaid), providing same/next-day appointments, and enabling 24/7 online booking through its app and EHR platform, with over 200 providers and plans to expand into 20 new U.S. markets in 2025</i><br />Target victim <b>website</b>: <i>psychplus.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harlem-Stage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31372</link>
<guid>2990a21222c7eeb833f2fdf82aacf400</guid>
<pubDate>Tue, 14 Apr 2026 10:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Harlem-Stage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22a1b9e86813ffe1e2ec7ce9ef52d1ab37f3ffd692ee822f65e681ccd85ec9d8</i><br /><br />Threat actor <b>description</b>: <i>harlemstage.org zoominfo.com/c/harlem-stage/109888723 Founded in 1983, Harlem Stage is a New York-based performing arts organization dedicated to empowering artists of the Global Majority — amplifying stories that have been whispered, silenced, or erased. Operating under the motto "Harlem is our home; the world is our stage," it supports dance, music, theater, film, and visual arts through commissions, festivals, education programs, and global partnerships.</i><br />Target victim <b>website</b>: <i>harlemstage.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Double-C-Farm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31370</link>
<guid>d73e1b0064831ecbe5d9d9b80b93e05d</guid>
<pubDate>Tue, 14 Apr 2026 10:26:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Double-C-Farm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfa1a390309423eba00b4ab97ac73b7ea23f02dbd61e808569a63d393c0d4723</i><br /><br />Threat actor <b>description</b>: <i>doublecfarm.net zoominfo.com/c/double-c-farm-llc/356570449 Double C Farm is a private equestrian facility in Montgomery County, Maryland, near Sugarloaf Mountain, owned and operated by Cridder Halle. It features an Extreme Mountain Trail Obstacle Course with 30+ obstacles (bridges, balance beams, water obstacles, trenches) and offers Ranch Riding clinics, group/private lessons, and schooling shows for all skill levels — approved by the East Coast Ranch Riding Association (ECRRA).</i><br />Target victim <b>website</b>: <i>doublecfarm.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>JM-Bozeman-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31361</link>
<guid>e6e9d37a0f6a79c25564cade197a8e3c</guid>
<pubDate>Tue, 14 Apr 2026 05:58:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>secpo</b> claims attack for <b>JM-Bozeman-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>857a4473fee56aa8bd47fc451c07ee5d0d58483af80fec53b515ebc2f9ea1fa0</i><br /><br />Threat actor <b>description</b>: <i>The exposed dataset includes over 100,000 unique files (192,993 with duplicates) containing sensitive information on more than 4,000 individuals and over 4,500 organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>secpo</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mike-Brandner-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31358</link>
<guid>8072e512102b794c08f3479a856c0796</guid>
<pubDate>Tue, 14 Apr 2026 05:57:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>secpo</b> claims attack for <b>Mike-Brandner-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f825537e4c0de3ce458759ea5a9d906b4fca76121034da3da54f6193be4b22ab</i><br /><br />Threat actor <b>description</b>: <i>The total volume of extracted data amounts to approximately 489 GB (459,391 files total). The files contain references to more than 4,000 unique individuals...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>secpo</category>
</item>
<item xmlns:dc='ns:1'>
<title>cwwcontractors.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31354</link>
<guid>97652673df105b7ad2ba940585e53500</guid>
<pubDate>Tue, 14 Apr 2026 01:50:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>cwwcontractors.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04451190a42bde68c1e99bb5b6cc86d7e007ff0ba647269024a72cd25f7e877e</i><br /><br />Threat actor <b>description</b>: <i>CW&W Contractors is a leading civil construction contractor specializing in infr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jersey-Fabrication-Group-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31355</link>
<guid>105dce1d1aed88877f7b1097e978f99e</guid>
<pubDate>Tue, 14 Apr 2026 00:52:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Jersey-Fabrication-Group-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21552b16ddc44b8a6d931f61a6bb9abd00af1489d3db424322eed08bebb6faef</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>sentrydynamics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31342</link>
<guid>723b06b9337aafbd3b995b1cd5da5e72</guid>
<pubDate>Mon, 13 Apr 2026 21:52:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>sentrydynamics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8079c98da9e551262dc375291e4a6cd17b3976dc402d23388e65c7154593dc4</i><br /><br />Threat actor <b>description</b>: <i>Sentry Dynamics, Inc. provides a powerful integrated suite of data solutions tai...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beaver-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31350</link>
<guid>2d02a252e43e9717a88413651fdddf4c</guid>
<pubDate>Mon, 13 Apr 2026 21:41:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lamashtu</b> claims attack for <b>Beaver-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44e876eb5eed0994301b43f1a80b76bb66aa861b14d0e60040b7eeba10ca9da1</i><br /><br />Threat actor <b>description</b>: <i>Beaver Engineering, Inc. is a Nashville-based geotechnical engineering firm founded in 1968, specializing in construction observation, materials testing, and sinkhole investigation throughout the southeastern United States.</i><br />Target victim <b>website</b>: <i>beaverengineering.com</i>]]></description>
<category>lamashtu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pullen-Moving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31345</link>
<guid>14c15aaec95f9b40f00007e6336d3e08</guid>
<pubDate>Mon, 13 Apr 2026 21:02:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Pullen-Moving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bad70260bcc4890ca7960d942ae62a3ef8939c7a220ee02656da828e663a5ab0</i><br /><br />Threat actor <b>description</b>: <i>Pullen Moving Company owns and operates two warehouses for storing household goods, office furniture, and industrial equipment in Woodbridge, VA as well as a fleet of vehicles for local, long distance, and international moving. We are proud members of the American Trucking</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colorado-Pulmonary-Intensivists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31344</link>
<guid>886551d6661c7e64f03ecdc16f7eae8b</guid>
<pubDate>Mon, 13 Apr 2026 20:08:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Colorado-Pulmonary-Intensivists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>373534c72f23cc1cb8ca3e8a8dc583ebe4def9221c7af6d47b82de11f91e75f8</i><br /><br />Threat actor <b>description</b>: <i>Specializes in services related to pulmonology and critical care, including outpatient pulmonary care and sleep medicine</i><br />Target victim <b>website</b>: <i>cpimedicine.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>PGDIS.PAPETIQUE-PRO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31335</link>
<guid>6dfbdd2796f306866bd7fa91b79f2339</guid>
<pubDate>Mon, 13 Apr 2026 19:51:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PGDIS.PAPETIQUE-PRO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a730af703e9ff8c560e48b401d1746370fc10172b3cebcfb3e2488ecedc4f93</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Basalt-Dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31338</link>
<guid>f512bcc142683f9185ea27c41855ed64</guid>
<pubDate>Mon, 13 Apr 2026 19:51:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Basalt-Dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b97df27e66b811a39e012d55b14a6bee9230cd09819c47c0609b6333b523d56</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colonial-Presbyterian-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31343</link>
<guid>4ecca9950b8e48cca47014655c2c4789</guid>
<pubDate>Mon, 13 Apr 2026 19:36:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Colonial-Presbyterian-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b34ad77e3eb2f629564a7ca9c18fcfc6e5fee3cade77f8a0340e7bda45d0e93</i><br /><br />Threat actor <b>description</b>: <i>We are a community of believers who seek to be the Light of Christ in a hurting culture so that the lost are found, the broken are made whole, the fatherless find hope and our city is blessed.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeast-Missouri-Rural-Telephone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31341</link>
<guid>0c0e943e54b33403a001386b2c3da054</guid>
<pubDate>Mon, 13 Apr 2026 18:15:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Northeast-Missouri-Rural-Telephone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0cff9f3e1d61cdb0be13ed0883ed51d2b95afb1c5e7d5107ecffc1d290353e5</i><br /><br />Threat actor <b>description</b>: <i>NEMR provides high-speed and reliable internet services tailored for various customer needs, including residential and business clients. They offer multiple broadband plans, such as Gigzilla for heavy data usage and Surfer for smaller households, ensuring options for every type of user. Alongside internet services, NEMR also provides phone and TV services, establishing itself as a comprehensive provider of communication solutions. Their commitment to service quality makes them an ideal choice for consumers in Northeast Missouri seeking fast connectivity. 
The company headquarters is located in 718 S West St, Green City, MO 63545, USA. 11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>DeMera-DeMera-Cameron</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31332</link>
<guid>65903d6bc9979bfb4817643c0e12b11e</guid>
<pubDate>Mon, 13 Apr 2026 14:49:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DeMera-DeMera-Cameron</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f43c11ccfbaeda051b3f22aa662ee339e7afbb8f78ef0ae50226f254aab829dd</i><br /><br />Threat actor <b>description</b>: <i>DDC CPA is a trusted CPA firm based in Fresno, specializing in co
rporate tax services and audit advisory for businesses across var
ious industries. With over 80 years of experience, they provide a
comprehensive range of accounting services including bookkeeping
, tax planning, and financial forecasting.

We will upload 260gb of corporate data soon. A bit of personal da
ta, financials, client financials (international ones), contracts
and agreements, corporate confidential documents, NDAs and so on
.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>phb.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31324</link>
<guid>5b347a27844fa303dd8c02b7da1c9206</guid>
<pubDate>Mon, 13 Apr 2026 12:53:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>apt73/bashe</b> claims attack for <b>phb.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b836de154c636d20bfd118cc00ed22eed589941c168372b5b83f9053bca57b10</i><br /><br />Threat actor <b>description</b>: <i>PHB Inc. is an industrial company in the United States that manufactures equipment and metal stru...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>apt73/bashe</category>
</item>
<item xmlns:dc='ns:1'>
<title>edtg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31325</link>
<guid>b8a8ace231fae55cbad834ad5b66e3d6</guid>
<pubDate>Mon, 13 Apr 2026 12:53:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>edtg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c8445d20f8567d17f99f5354902c2d2adda5bdab9a0978cfba3519654b4b75f</i><br /><br />Threat actor <b>description</b>: <i>The Eldorado Trading Group is a company that operates in the Banking industry. It employs 10to19 people and has 1Mto5M of revenue. The company is headquartered ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Travel-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31326</link>
<guid>13019fc8997b04326425e0c525115724</guid>
<pubDate>Mon, 13 Apr 2026 12:53:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Travel-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62c7083d34bd078b7265fb9c3d978ea9e595eb9d3ef31d4988c1f36560acc213</i><br /><br />Threat actor <b>description</b>: <i>Travel of America specializes in luxury ocean, river, and expedition cruises, as well as hotels, resorts, guided tours, and custom land arrangements for both in...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Transaction-Packing-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31323</link>
<guid>fc7acef4b85e5816052c710a655dbc47</guid>
<pubDate>Mon, 13 Apr 2026 10:33:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Transaction-Packing-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b779029148fa4a2a3da5156548ff912413fcd1cc3b33b27c10a04a537fd336c5</i><br /><br />Threat actor <b>description</b>: <i>Transaction Packing, Inc. (TPI) specializes in freight handling services, including receiving, packing, crating, locating, and shipping cargo. They focus on providing durable and dependable packaging solutions to ensure safe and timely transportation of goods. TPI operates multiple facilities in the Houston area, allowing for expedited transit of shipments. The company emphasizes strong customer partnerships and dedicated account management to enhance service quality.</i><br />Target victim <b>website</b>: <i>www.transactionpacking.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Affordable-Oil</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31316</link>
<guid>ef4fc148f9ea60330eb0df54b1349a2d</guid>
<pubDate>Sun, 12 Apr 2026 23:54:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Affordable-Oil</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e144c266bacd054e65b82c42818782b494ca7826554619871e19666b5b37d95e</i><br /><br />Threat actor <b>description</b>: <i>The goal of Affordable Oil is in our name. We strive to provide the best heating oil delivery service at the lowest cost. Our friendly office staff is here Mond...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Helzberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31319</link>
<guid>365aa6ebdc3dbf28e7b9ea1c1b4d2908</guid>
<pubDate>Sun, 12 Apr 2026 22:24:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Helzberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43eb6b3eb3d1b6f79cc2288c75c0b178afa40208b71da9047d97aa84597317de</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Helzberg Diamonds is a American retail jewelry company headquartered in North Kansas City, Missouri. Founded in 1915, it operates a chain of jewelry stores across the United States, selling diamonds, engagement rings, wedding bands, and fine jewelry. The company is a subsidiary of Berkshire Hathaway, having been acquired in 1995. Helzberg operates hundreds of retail locations in shopping malls and centers nationwide.</i><br />Target victim <b>website</b>: <i>Helzberg</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ralph-Lauren</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31318</link>
<guid>81bfe052679288bbb4558009aab788f9</guid>
<pubDate>Sun, 12 Apr 2026 22:24:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Ralph-Lauren</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b61def8eeefa593549ce3698c7e5aa7e394ff990e7bf297abd55b2e051189a6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Ralph Lauren Corporation is an American fashion and lifestyle company headquartered in New York City. Founded in 1967 by designer Ralph Lauren, it designs, markets, and distributes luxury apparel, accessories, home furnishings, and fragrances. Operating globally across North America, Europe, and Asia, its portfolio includes brands such as Polo Ralph Lauren, Ralph Lauren Purple Label, and Lauren Ralph Lauren.</i><br />Target victim <b>website</b>: <i>www.ralphlauren.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31317</link>
<guid>01cc9bcfcd567d83304a3843b7169ba1</guid>
<pubDate>Sun, 12 Apr 2026 22:23:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Carters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc8eab938b2c1a5a2b54e4873698f8c3757df4c18640f285364a003f2fdf3d45</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Carter's is a leading American children's apparel brand headquartered in Atlanta, Georgia. Founded in 1865, the company designs, sources, and markets clothing, accessories, and related products for babies and young children. It operates through multiple retail channels including its own stores, e-commerce platforms, and wholesale partnerships. Carter's also owns the OshKosh B'gosh brand and sells products across the United States, Canada, and internationally.</i><br />Target victim <b>website</b>: <i>carters.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rockstar-Games</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31312</link>
<guid>5464028132750fc3d9705f63c4804a09</guid>
<pubDate>Sun, 12 Apr 2026 02:10:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Rockstar-Games</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a744698893a09a31b39a56b58d8be0ebf13a0b594b335d22bda7239fa095ccb1</i><br /><br />Threat actor <b>description</b>: <i>Your Snowflake instances metrics data was compromised thanks to Anodot.com. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marcus--Millichap-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31310</link>
<guid>68f049a23ab109c6a0f6989bb9a02994</guid>
<pubDate>Sun, 12 Apr 2026 02:10:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Marcus--Millichap-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9ba58ebe6b589bd8fb4c8dbec38ebab2c16b89f220f50105d87124e675b6ec4</i><br /><br />Threat actor <b>description</b>: <i>Over 30M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kemper-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31309</link>
<guid>60d9dfb17fc8bdbb3de0a14aed009ce6</guid>
<pubDate>Sun, 12 Apr 2026 02:10:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Kemper-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2562f0752e5070a4ad123d6056c0c258c006d416fc706a546cf8e7a8286066fe</i><br /><br />Threat actor <b>description</b>: <i>Over 13M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ryan-LLC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31308</link>
<guid>1e273c3efad61af89a37f8403b84efd4</guid>
<pubDate>Sun, 12 Apr 2026 02:10:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Ryan-LLC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25503c77abb289c76b374bccb4cfa10e7cc05a62f6e74c81f75fd9d6ebb67cdb</i><br /><br />Threat actor <b>description</b>: <i>Over 4.8M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>McGraw-Hill-Inc.-mheducation.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31307</link>
<guid>66b0cd925d80e64555a2babbb2ccddc2</guid>
<pubDate>Sun, 12 Apr 2026 02:10:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>McGraw-Hill-Inc.-mheducation.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a865a68aa7d0c1bd634e3484fe0dc86ff437b8cc16de98c232efc319ab391f7</i><br /><br />Threat actor <b>description</b>: <i>Over 45M Salesforce records containing PII data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>mheducation.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Railroad-Passenger-Corporation-amtrak.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31306</link>
<guid>5f4d36824abbbe0b96729728d035a7ae</guid>
<pubDate>Sun, 12 Apr 2026 02:09:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>National-Railroad-Passenger-Corporation-amtrak.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c9d606c51789d845b605517ecf382bda347df0bdb3d53926fd07229549cfb03</i><br /><br />Threat actor <b>description</b>: <i>Over 9.4M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK</i><br />Target victim <b>website</b>: <i>amtrak.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>morgancountyga.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31303</link>
<guid>2fd888270070d2f794ec95b2075f8a29</guid>
<pubDate>Sat, 11 Apr 2026 23:58:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>morgancountyga.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>222fd1498590584af9aba7578046d50535aec61a49066b84878ebd97c7213093</i><br /><br />Threat actor <b>description</b>: <i>Morgan County offers a range of government services and community resources, including public safety through the Fire Rescue and Sheriff's Office, as well as a Public Transit System. The county actively engages with residents by providing updates on meetings, events, and community initiatives. It features recreational facilities, such as a Recreation Complex, aimed at enhancing community well-being. The intended clients include local residents, visitors, and anyone needing access to county services. Employees: 50 Revenue: $23 Million Industry: Government   Phone Number: (706) 342-1507</i><br />Target victim <b>website</b>: <i>morgancountyga.gov</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sahara-Air-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31302</link>
<guid>2cf7926aeec52fbe4f1a6ae2a1770329</guid>
<pubDate>Sat, 11 Apr 2026 16:59:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Sahara-Air-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>836a2bd59607e6cb6fa5e77267b32eac71563df3e8385286b8b0791b52822ffa</i><br /><br />Threat actor <b>description</b>: <i>- Confidential Technical Drawings- Documents- Customer invoices- Shipment Histories</i><br />Target victim <b>website</b>: <i>saharahenderson.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.campbell.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31300</link>
<guid>c7602768a214451d3d91346fed37176b</guid>
<pubDate>Sat, 11 Apr 2026 02:17:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.campbell.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>939799d408a151c0e5ebdc3af8da77249e04ba59702337a569b9a90ca0890eac</i><br /><br />Threat actor <b>description</b>: <i>In the university data leak, there will be incidents related to teachers' pedophilia, sexual abuse of students by other students, drug use, personal data, military recruitment of students, and other things   500gb</i><br />Target victim <b>website</b>: <i>www.campbell.edu</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>wright-ryan.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31296</link>
<guid>754da7dc2ed681cb2084a83124fc63cf</guid>
<pubDate>Fri, 10 Apr 2026 18:38:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>wright-ryan.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16903140594923e5e410ff3a89cc52acb1d95f58f4a53d8ff1d29915e3cf52c4</i><br /><br />Threat actor <b>description</b>: <i>600gb  project nda personal client contract  all corp data</i><br />Target victim <b>website</b>: <i>wright-ryan.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Turbo-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31294</link>
<guid>889b262e03e28a9f19e72f08ab1ec3f0</guid>
<pubDate>Fri, 10 Apr 2026 13:57:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Turbo-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c6c552885c77f5ae6a5dd47377afced64090ccd29f55ccec03d0be23b05a2a0</i><br /><br />Threat actor <b>description</b>: <i>Turbo International was founded in 1989 as one of the first manuf
acturers of turbocharger component parts in North America. Origin
ally focused on producing compressor wheels and balancing service
s for local rebuilders, the company quickly expanded its product 
line to include all major turbocharger components and service kit
s.

We will upload 48gb of corporate data soon. Employee personal doc
uments (passports, DLs, 29 forms, addresses, phones, emails and o
ther information), client information, financials, contracts and 
agreements, corporate confidential documents, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arkansas-Oral--Maxillofacial-Surgeons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31293</link>
<guid>692f4a795f36e4289fd2626f6dca152c</guid>
<pubDate>Fri, 10 Apr 2026 13:21:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Arkansas-Oral--Maxillofacial-Surgeons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f87f2afb563dc7a1a203332cc41947e288a009cdbb30da7672903b95205a0d1e</i><br /><br />Threat actor <b>description</b>: <i>Offers a wide range of services in the field of maxillofacial surgery</i><br />Target victim <b>website</b>: <i>arsurgeons.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colonial-Presbyterian-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31292</link>
<guid>d64991fabf71644c5859e7a54ff1e716</guid>
<pubDate>Fri, 10 Apr 2026 13:20:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Colonial-Presbyterian-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a04d2df0421fd3f03d449746e8c0394cdd9ce436e7c5e0b320bf27fe60fadf75</i><br /><br />Threat actor <b>description</b>: <i>Colonial Presbyterian Church operates two campuses in Overland Park and South Kansas City</i><br />Target victim <b>website</b>: <i>colonialkc.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Netgain-Networks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31291</link>
<guid>d0ceaba6d228fd9ad99831d5df783c7c</guid>
<pubDate>Fri, 10 Apr 2026 12:32:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Netgain-Networks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1029bbea023e0162f373568f933ac866a2752b3f70ead42a0031cca2a0921c51</i><br /><br />Threat actor <b>description</b>: <i>Netgain Networks, Inc. is an information technology service compa
ny that focuses on computing, networking, and application needs o
f small/midsize businesses and branch offices of large corporatio
ns in Southern California.

We will upload corporate data soon. Employee personal documents (
passports and other HR files), client health information, financi
als, a lot of project information, contracts and agreements and s
o on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alvi-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31290</link>
<guid>da6227556cac5e27703ef56a6015cb50</guid>
<pubDate>Fri, 10 Apr 2026 09:28:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Alvi-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3951eae21c12afe54a387633b88729e1367900b064f611159f0bc73f1b6b6e2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1979, Alvi Associates, Inc. specializes in integrated engineering services for infrastructure projects, including structural, water resources, transportation, and geotechnical engineering.</i><br />Target victim <b>website</b>: <i>alviassociates.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goulston--Storrs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31288</link>
<guid>1146d96286ade57a9fa715376dae4c20</guid>
<pubDate>Fri, 10 Apr 2026 00:58:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Goulston--Storrs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2899684e11a30ccbd376da8197a2b4dbcd590a05dd47bc6bcad0b1b3b3f8c146</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Goulston & Storrs is a full-service law firm headquartered in Boston, Massachusetts, USA, with additional offices in New York, Washington DC, and Beijing. The firm operates in the legal services industry, advising clients on real estate, corporate transactions, litigation, and finance matters. It serves a diverse range of clients including businesses, institutions, and individuals, with particular strength in commercial real estate law.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kannarr-Eye-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31287</link>
<guid>0982d54d18a026163f76888c0d226166</guid>
<pubDate>Fri, 10 Apr 2026 00:33:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Kannarr-Eye-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b83abeb385480f7c5d2042de6ef0b4b79f1ce22ad0ffaa95f389c05a856f554</i><br /><br />Threat actor <b>description</b>: <i>Kannarr Eye Care is a full-service optometry provider located in Pittsburg, Kansas, dedicated to improving lives through advanced eye care. They offer a wide range of services including eye exams, contact lens fittings, cataract surgery, and treatment for ocular diseases. The clinic serves patients in the four-state area, ensuring personalized attention and professional care. Kannarr Eye Care also provides vision financing options and works with various insurance providers to promote good eye health.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chalmers--Kubeck</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31281</link>
<guid>9c87b4fa747d4b5675c82f561eb9cd4c</guid>
<pubDate>Thu, 09 Apr 2026 21:57:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chalmers--Kubeck</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57446b0f85c28c6f2bc101b215ef3e4e119237eee291415aeda6b38e2fea919e</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Guerin-Glass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31282</link>
<guid>add4f684a678d13d0ce8b389da309842</guid>
<pubDate>Thu, 09 Apr 2026 21:57:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Guerin-Glass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c028375bde0063ab121796f5249efb24dbddb69ec661139047c071f1b8a4ad1</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cox-Castle--Nicholson-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31285</link>
<guid>e2edf8a3b6635786b076e998ffdd1052</guid>
<pubDate>Thu, 09 Apr 2026 21:18:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Cox-Castle--Nicholson-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e1ddad5699caec027269444b3d6032b431a0409fbdce434d18dbc0ae9dd9b5e</i><br /><br />Threat actor <b>description</b>: <i>Cox, Castle & Nicholson is a leading law firm specializing in real estate and related services, with o…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Florida-Injury-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31284</link>
<guid>dd17ee9e2355df4f69fd072a5bd3334d</guid>
<pubDate>Thu, 09 Apr 2026 20:42:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>South-Florida-Injury-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dec5bbd519b150818cf6bfffcd56288e1f5e04a171e3b72cd985e8f3ebcbcccf</i><br /><br />Threat actor <b>description</b>: <i>South Florida Injury Centers was founded in 2000 by Dr. Brian Wilner, DC, a graduate of Life University College of Chiropractic. In his 24 years of experience with personal injury and auto accident cases, he has treated and managed conditions of the musculoskeletal system as well as Traumatic Brain Injuries. Conditions treated in the office include whiplash, herniated discs, torticollis, cervical strains, headaches, sciatica, and general low back pain.  We pride ourselves in providing both South Florida and the Treasure Coast with great service in Chiropractic care.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sonn-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31272</link>
<guid>dafe0a22bfe43bc5f925ad398d6f90c2</guid>
<pubDate>Thu, 09 Apr 2026 19:54:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sonn-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4482580f330bda681dd69a149026bfdb946be1ce0aede8b4398516b8590ccf0d</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alamo-Heights-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31274</link>
<guid>bbb747080230bd2ed4070dfdf6d846f4</guid>
<pubDate>Thu, 09 Apr 2026 18:54:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alamo-Heights-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b61fc296dad01f2e7f8d273a6d802d41777a79018b5a9c5b15dcd31cfa18103</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Siegel-Lewitter-Malkani</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31280</link>
<guid>dacb8cf07e5031179a2da26abd616327</guid>
<pubDate>Thu, 09 Apr 2026 16:54:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Siegel-Lewitter-Malkani</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3653831e114f6362da0ca40fb6f8af669f7fdbad9b5dc1f2095398e6686c79b3</i><br /><br />Threat actor <b>description</b>: <i>A highly respected law firm in the San Francisco Bay Area, specializing in employment law</i><br />Target victim <b>website</b>: <i>sl-employmentlaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Family-Psychological-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31279</link>
<guid>53787d42c3aacb84dd97baa865a42eab</guid>
<pubDate>Thu, 09 Apr 2026 16:53:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Family-Psychological-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02ef386df15e1e6d26ea90156c8a41ffb04a0133a0e80564a45a9d325fa2c355</i><br /><br />Threat actor <b>description</b>: <i>Provides mental health services</i><br />Target victim <b>website</b>: <i>kcifpa.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Powell-Powell--Powell-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31278</link>
<guid>57cb680116490a4c6c0bb57a8fa476f1</guid>
<pubDate>Thu, 09 Apr 2026 16:53:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Powell-Powell--Powell-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05c966db490b9b65e5e0005fa0c1aa31bda67a27fa676676a59cfb9f90663d27</i><br /><br />Threat actor <b>description</b>: <i>A law firm specializing in personal injury cases</i><br />Target victim <b>website</b>: <i>powelllawfirm.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-McLamb-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31277</link>
<guid>9957d0d6c13e2cb00518c92af0df3b96</guid>
<pubDate>Thu, 09 Apr 2026 16:52:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>The-McLamb-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12819fffe305fd2c637bf1aaa5b39e8340643c702a747338a8675396dbd1bd5e</i><br /><br />Threat actor <b>description</b>: <i>Specializ in warehousing and fulfillment, direct mail services, inventory management, printing and graphic design, and builder services</i><br />Target victim <b>website</b>: <i>themclambgroup.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Medical-Doctors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31271</link>
<guid>0ab605102670807b661d9a1a4e618745</guid>
<pubDate>Thu, 09 Apr 2026 16:16:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>United-Medical-Doctors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8088062201697f06cf254977af10878313db55f234a85cb8830a3122a2ca2fda</i><br /><br />Threat actor <b>description</b>: <i>United Medical Doctors (UMD) is an independent multi‑specialty medical‑surgical group with 70+ Southern California locations and 40+ specialties. They focus on high‑quality, compassionate care, patient satisfaction, process improvement, outpatient surgery, clinical research.</i><br />Target victim <b>website</b>: <i>www.unitedmd.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>ImageMaster</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31266</link>
<guid>5909e98016c8d94baefc6def4f5b785e</guid>
<pubDate>Thu, 09 Apr 2026 14:30:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ImageMaster</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3eb91b85016b7eba67b89e08936eefafdf14ac297c16e286a1f2e137cd726ea1</i><br /><br />Threat actor <b>description</b>: <i>ImageMaster, LLC is a leading provider of official statement docu
ments and roadshow services tailored for the municipal bond marke
t. They utilize advanced technology and a unique quality assuranc
e process to ensure accurate and secure document preparation and 
distribution.

We will upload 49gb of corporate data soon. Employee personal fil
es, clients information, projects, financials, contracts and agre
ements, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MN-Health-Insurance-Network</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31265</link>
<guid>fa68a633df6169bb2bf730da98faff59</guid>
<pubDate>Thu, 09 Apr 2026 14:30:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MN-Health-Insurance-Network</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ccdadfeae2fb89ca4416e103d5b69ac2a5c10732ad4b9917700dc865cf71371</i><br /><br />Threat actor <b>description</b>: <i>Minnesota Health Insurance Network specializes in providing a wid
e range of health insurance products, including individual and fa
mily plans, group and small business plans, Medicare plans, denta
l and vision insurance, and short-term health insurance.

We will upload 23gb of corporate data soon. Client and employee p
ersonal information (passports, addresses, phones, emails and so 
on), projects, financials, contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shingle--Gibb-Automation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31264</link>
<guid>56909640f93a509bda9494a0178e091e</guid>
<pubDate>Thu, 09 Apr 2026 13:03:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Shingle--Gibb-Automation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a422aecce50ee6ded4f28852f483415589fc369f93e5fddfabe7570e4b53f40</i><br /><br />Threat actor <b>description</b>: <i>Shingle & Gibb Automation follows a time-honored commitment of pr
oviding the finest Industrial Automation & Networking, Motion Con
trol, Machine Safety and Power Transmission products from world l
eading manufacturers, including Siemens, Banner Engineering, Turc
k and Rittal.

We will upload 25gb of corporate data soon. Employee files (passp
orts, DLs and other files), HR files, detailed financials, client
information, NDAs, internal confidential files, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Newman--Marquez</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31262</link>
<guid>face3ee8cd23d4e678783e668802b7a6</guid>
<pubDate>Thu, 09 Apr 2026 13:02:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Newman--Marquez</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e0ac08e44655ef8022f6f6eb879481de443b59b136809954b816db6a8e50437</i><br /><br />Threat actor <b>description</b>: <i>Sehlmann Fensterbau GmbH specializes in wooden and wood-metal win
dows in the Hamburg metropolitan area. They offer optimal window 
solutions for innovative new constructions and stylish renovation
s, providing services from consultation and planning to productio
n and installation.

We will upload 95gb of corporate data soon. Employee personal fil
es, large amount of client personal files (passports, DLs, death 
certs, visas, credit cards and other files), financials, court fi
les, police reports, hearings, lawsuits and other files, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Signature-Healthcare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31260</link>
<guid>08115ea8e8a940675023870ddead8842</guid>
<pubDate>Thu, 09 Apr 2026 11:22:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Signature-Healthcare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23040d1f382d99fdc3c248db07a7cfab0f84343ff9e95efb39728d2a570db85f</i><br /><br />Threat actor <b>description</b>: <i>Will there be a release? Keep an eye on the timer.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-Roettgers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31257</link>
<guid>ee091bf8c15bf02e47ba4b69d587fd03</guid>
<pubDate>Thu, 09 Apr 2026 00:55:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>A-Roettgers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fca7af0085dc3a2a40fa4c041daf7730cb1d1e9ae28dd147cafaf4818e55dc81</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>nepgroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31247</link>
<guid>092e9c75b6d721231d7a3b23bfbc88fd</guid>
<pubDate>Wed, 08 Apr 2026 18:46:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ALP-001</b> claims attack for <b>nepgroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4a8fa195cd9a45981559f84e079d207205ce0af43ca3f7e6a5d6242f03062cd</i><br /><br />Threat actor <b>description</b>: <i>Country: USA Revenue: $2.1 Billion Storage: 70GB Description: NEP Group, founded in 1984 and headquartered in Pittsburgh, Pennsylvania, offers outside broadcast, studio production, audio and lighting, host broadcast support, and media management services ** WE UPLOADED 10GB As Samples ** ** You Can Download Samples From Leak Page **
Deadline: 2026-04-18 17:22:11</i><br />Target victim <b>website</b>: <i>nepgroup.com</i>]]></description>
<category>ALP-001</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sajet-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31244</link>
<guid>eba9940b6dcffe49a14de9a4899ab466</guid>
<pubDate>Wed, 08 Apr 2026 17:35:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>linkc</b> claims attack for <b>Sajet-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96b2fe085d4bc15c91a1fa9fbf9ac1dac3f66617d98b18069eea94978cf84cab</i><br /><br />Threat actor <b>description</b>: <i>700mb of blueprints including Amazon LEO (satellite) Project Kuiper scheme, Airbus, Boeing engines and metal alloy technologies.  Enjoy. 

https://amber-wooden-prawn-35.mypinata.cloud/ipfs/bafybeic5m7e3dvlunitnv6vxzbcvqqgm4pybgc3ykn3jo62jipshf6bjve</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>linkc</category>
</item>
<item xmlns:dc='ns:1'>
<title>StrongLink</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31243</link>
<guid>fa4c202fbc0421c1d4e317cbbbcac5a2</guid>
<pubDate>Wed, 08 Apr 2026 17:35:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>linkc</b> claims attack for <b>StrongLink</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3069744b639cc5c7001cc75ff70892cc487c35deac71a5a11c2634169bf425c</i><br /><br />Threat actor <b>description</b>: <i>DOWNLOAD SAMPLE: https://amber-wooden-prawn-35.mypinata.cloud/ipfs/bafybeian2lxaye6gwvi2kztzfpyr2lokzfngai3d4zjmtgqhhv74ixsvi4</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>linkc</category>
</item>
<item xmlns:dc='ns:1'>
<title>Network-Technology-Services-of-New-Jersey</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31242</link>
<guid>19ddc61af8f213d2c43c17204efab297</guid>
<pubDate>Wed, 08 Apr 2026 17:35:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>linkc</b> claims attack for <b>Network-Technology-Services-of-New-Jersey</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f546cdf7c87fbd6779cdcfead88135e24666771c7493d30a901968d0b404e92</i><br /><br />Threat actor <b>description</b>: <i>Whole datacenter is encrypted. Waiting for you in chat.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>linkc</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scholle-IPN---1.7-TB-Data</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31238</link>
<guid>4c4aa2205676a162ba900d37ea48e67d</guid>
<pubDate>Wed, 08 Apr 2026 17:18:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Scholle-IPN---1.7-TB-Data</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27be8277d0743caebdb1e9bbf4d23dfd73e31f363faf240b67c16ad2f2d3dcd1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Scholle IPN is a global packaging manufacturer headquartered in the United States. The company specializes in flexible packaging solutions, including bag-in-box systems, spouted pouches, and aseptic packaging. It serves industries such as food and beverage, chemicals, and industrial markets. Scholle IPN operates manufacturing facilities across multiple countries and is recognized for its innovations in liquid and semi-liquid product packaging.</i><br />Target victim <b>website</b>: <i>scholleipn.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Idera---1.5-TB-data</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31237</link>
<guid>2ca2f2883873b256532b5e0cba354cff</guid>
<pubDate>Wed, 08 Apr 2026 17:17:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Idera---1.5-TB-data</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0262eb54a4fe7d9b7fb2ad79b55a75fe65fe6356f1eaa75310d2b883eced2122</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Idera is a US-based software company specializing in database management, developer tools, and test management solutions. It serves IT professionals and enterprises across industries, offering products for database performance monitoring, administration, and DevOps workflows. Its portfolio includes tools supporting SQL Server, MySQL, and other platforms. Idera operates globally with headquarters in Houston, Texas.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deaconess-Health-System</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31192</link>
<guid>f230c4cd39d680d4cde59248861bdf9d</guid>
<pubDate>Wed, 08 Apr 2026 16:40:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Deaconess-Health-System</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>496dbf8bbda79ffcbc00fb3ef10ab33e5c4054cd1c811234fa79c0c4d1405fb4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eric-Davis-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31228</link>
<guid>e5654b80531b9a7338900193f90fbba5</guid>
<pubDate>Wed, 08 Apr 2026 16:28:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>gunra</b> claims attack for <b>Eric-Davis-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6fe5f51350f77965a92f1176baad7f1b2895e651763c16826a80a2b89c8fe571</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Eric Davis Dental is a dental practice based in the United States. The company operates in the healthcare and dental services industry, providing a range of oral health services to patients. These typically include general dentistry, cosmetic dental procedures, and preventive care. As a private dental practice, it serves local communities and focuses on patient-centered care and dental wellness.</i><br />Target victim <b>website</b>: <i>ericdavisdental.com</i>]]></description>
<category>gunra</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metropolitan-Pediatrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31207</link>
<guid>3ee84a1d752ef2d6bf779aa019023863</guid>
<pubDate>Wed, 08 Apr 2026 15:32:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Metropolitan-Pediatrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6ad8e46d327769494cd7539a4c95021339310080e8f5e5454eba7e4ea3f6eac</i><br /><br />Threat actor <b>description</b>: <i>metropeds.com zoominfo.com/c/metropolitan-pediatrics/51350701 Metropolitan Pediatrics is an independent pediatrician practice with a 51-year history of providing quality care to Metropolitan Pediatrics's community. Metropolitan Pediatrics's pediatricians are all trained to manage and prevent health problems in infants, children, teens and young adults in the most friendly and cost effective manner possible</i><br />Target victim <b>website</b>: <i>metropeds.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Structures-Stucco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31204</link>
<guid>7850e0be9549edeb7b9746e02e4229ae</guid>
<pubDate>Wed, 08 Apr 2026 15:31:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Structures-Stucco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26c06039c6298f521829f18954fe9b9c9d03eff8c458f8e99b317155aff6b453</i><br /><br />Threat actor <b>description</b>: <i>structuresstucco.com zoominfo.com/c/structures-stucco-llc/398264895 Structures Stucco, LLC is a stucco subcontractor based in Phoenix, Arizona, specializing in multi-family homes, single-family homes, and commercial buildings. The company is committed to providing quality work, honest service, and great value, ensuring customer satisfaction through top-quality stucco services. They offer written quotes with accurate estimates of time and budget before starting any project. Structures Stucco prioritizes delivering quality jobs without compromising affordability or speed of implementation</i><br />Target victim <b>website</b>: <i>structuresstucco.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>DGS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31195</link>
<guid>16a153a27394122922a55fb102f602e3</guid>
<pubDate>Wed, 08 Apr 2026 15:27:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>DGS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc7850eed980a6256d227816e2937bba57beee716d2bdb32c977aa0738a35ef8</i><br /><br />Threat actor <b>description</b>: <i>dgsts.com DGS Technical Services is a structural steel and mechanical engineering firm that has been providing comprehensive design, detailing, and 3D modeling services since 2004. Based in Elgin, Illinois, they serve a variety of industrial and commercial clients, including those in the semiconductor and vending machine industries.</i><br />Target victim <b>website</b>: <i>dgsts.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>EMCO-Holding</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31194</link>
<guid>b6622e4ef1a8d811316fe50fd2975faf</guid>
<pubDate>Wed, 08 Apr 2026 15:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>EMCO-Holding</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d2196aa2379a1970e4eeef4a7dfa762b0a923b578e6c28c5b8f0aae48f01fe0</i><br /><br />Threat actor <b>description</b>: <i>emcoholding.com Grupo EMCO Holding is a conglomerate of prestigious companies operating in different areas, guided by a philosophy of excellence and responsibility, with significant investments in Central America. In recent years, the group has diversified and has strongly positioned itself in fields such as the airport sector, cargo terminals, steel production, and steel manufacturing, and is currently developing energy generation projects. Thanks to its major projects, rapid growth, and investments, Grupo EMCO has established itself as one of the most important, strongest, and most prestigious groups in Central America.</i><br />Target victim <b>website</b>: <i>emcoholding.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>pacificwestinjury.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31180</link>
<guid>869984f8baf167efc8123bf85fc1ccb4</guid>
<pubDate>Tue, 07 Apr 2026 22:08:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>pacificwestinjury.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ad11d3b891c3586f7e1e648d493ae852e557a62934e525a7405b4494021d1f7</i><br /><br />Threat actor <b>description</b>: <i>Pacific West Injury Law opened its doors with the singular mission of providing its clients with the best possible representation when handling personal injury cases.</i><br />Target victim <b>website</b>: <i>pacificwestinjury.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Noble-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31179</link>
<guid>a3577dabfbc7a0e6685b1a3b68a0ac84</guid>
<pubDate>Tue, 07 Apr 2026 20:39:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Noble-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60772e3329a1f4ebcbd00795040a8c3a1fa00cdf9554ac3c1e78cf435d39b9a3</i><br /><br />Threat actor <b>description</b>: <i>Noble Casing, Inc., founded in 2009, provides casing running and conductor drilling services in the Rocky Mountain region, emphasizing safety, training and equipment upkeep. Subsidiaries Noble Drilling and Noble Trucking support production and rig moves.</i><br />Target victim <b>website</b>: <i>www.nobleoilfieldservices.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.smithdollar.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31178</link>
<guid>c230257fc8994f9835dc50c0b267db0e</guid>
<pubDate>Tue, 07 Apr 2026 16:38:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.smithdollar.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>813c767c3a5f3742664fb37438a9223c5e2a5cbda035350979acbbfbf030953e</i><br /><br />Threat actor <b>description</b>: <i>Smith Dollar is a Santa Rosa law firm that provides comprehensive legal services to businesses and individuals throughout Northern California. The firm specializes in various practice areas including construction law, employment and labor law, business law, personal injury, real estate law, and estate planning. With a team of experienced attorneys, Smith Dollar is dedicated to offering strategic legal counsel and representation tailored to the needs of its clients, which range from contractors and business owners to individuals facing legal challenges. Established in 2005, the firm prides itself on its commitment to excellence and client-oriented service.</i><br />Target victim <b>website</b>: <i>www.smithdollar.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>CMD-Outsourcing-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31177</link>
<guid>58e473658c4b6757ec8379817d35e6fa</guid>
<pubDate>Tue, 07 Apr 2026 15:48:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CMD-Outsourcing-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3183618243575044b9670c0d7b9cab7c4286258064be1d60b71dd38159432750</i><br /><br />Threat actor <b>description</b>: <i>CMD Outsourcing Solutions specializes in multi-channel customer s
ervice solutions tailored for higher education institutions, exte
nding support to departments such as Financial Aid, Admissions, B
ursar, Registrar, and Housing.

We will upload corporate data soon. Scanned employee documents (p
assports, DLs, SSNs, medical files and so on), financial files, N
DAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Research--Planning-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31176</link>
<guid>127449db06658be5e1bc1cd51bde8b78</guid>
<pubDate>Tue, 07 Apr 2026 15:48:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Research--Planning-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>18d788f97f0d460df8a7e2cf944d9e7ef83c96c8c64aa44da4523cb91c1f4439</i><br /><br />Threat actor <b>description</b>: <i>Research & Planning Consultants, L.P. specializes in providing ex
pert analysis and consulting services in personal injury and comm
ercial litigation.

We will upload 33gb of corporate data soon. Projects, financials,
client and employee information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>AnchorsGordon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31175</link>
<guid>5796f99c5d3c7bac8c90cc042869a7ea</guid>
<pubDate>Tue, 07 Apr 2026 14:26:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>AnchorsGordon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1bdd7675faa5bfe18a7910f3f96697b4f908c728e8c0347dba3938cac51a156</i><br /><br />Threat actor <b>description</b>: <i>AnchorsGordon is a law firm based in Northwest Florida with decades of experience in various legal fields. They specialize in complex business and commercial litigation, business and corporate law, real estate litigation, community association law, alternate dispute resolution, government affairs, and labor and employment law. The firm aims to serve a diverse clientele, providing expert legal services tailored to their needs. With a team of experienced attorneys, AnchorsGordon is recognized as a leader in the legal community of Northwest Florida</i><br />Target victim <b>website</b>: <i>anchorsgordon.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bit-Wizards</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31174</link>
<guid>ae71f3fbfec5315779741343d709648c</guid>
<pubDate>Tue, 07 Apr 2026 14:25:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Bit-Wizards</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d82aaaca7ff3be0442b071079708a949786d3a20fcd579aac509b2215c58ec65</i><br /><br />Threat actor <b>description</b>: <i>Bit-Wizards is a technology company that develops an application, builds a brand, or move to the cloud. This company is headquartered in Florida</i><br />Target victim <b>website</b>: <i>bitwizards.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Star-Fuels</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31173</link>
<guid>85c19375f0c12c6793bf66b4e2666dc4</guid>
<pubDate>Tue, 07 Apr 2026 14:18:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Star-Fuels</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0429a644b92914260428909bdf975dfcc4a5b200dd61438b1a7a2c5d0c50188d</i><br /><br />Threat actor <b>description</b>: <i>Data breach at a small fuel company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accent-Dental-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31172</link>
<guid>3e06c5b828dcafa030c827d58b2cc858</guid>
<pubDate>Tue, 07 Apr 2026 14:17:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Accent-Dental-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84b9090babd3b0c826c2d2df06d2f93b69a841559af1083c311d496251696e62</i><br /><br />Threat actor <b>description</b>: <i>Accent Dental Center On Forum is a general dentistry practice loc
ated in Columbia, MO, dedicated to providing high-quality and aff
ordable dental care. The center offers a range of services includ
ing exams, cleanings, cosmetic dentistry, dental implants, and tr
eatments for TMJ and oral facial pain.

We will upload corporate data soon. Detailed patients (name, DOB,
passport numbers, medical information, addresses and so on (more
than 1000 ppl)), employee personal documents, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>School-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31170</link>
<guid>93a819cbd635bd1505ef0f804c21cc2a</guid>
<pubDate>Tue, 07 Apr 2026 12:47:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>School-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f7358300cb7c46ac264006a95976bb715e11f2594e3abf3b5102e82b39d6dd9</i><br /><br />Threat actor <b>description</b>: <i>School Health was founded in 1957. This company provides the reta
iling of health and wellness supplies to K-12 schools. Their head
quarters are located in rolling Meadows, Illinois.

We will upload 15gb of corporate data soon. Financials, a bit of 
HR files, drawings, projects, customer info, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adrian-Jules</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31169</link>
<guid>13a0e2e9d803e8072b0d637d16f5fdb9</guid>
<pubDate>Tue, 07 Apr 2026 12:47:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Adrian-Jules</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2df53fba12c61f489d4beaebd44b26d6a83d6ddd2b5d02ccf72dbf566b3626a5</i><br /><br />Threat actor <b>description</b>: <i>Adrian Jules Ltd. specializes in the design, manufacturing, and w
holesaling of custom clothing made in America, focusing on bespok
e garments crafted by hand. The company offers a range of men's c
lothing styles and provides a private label service for those loo
king to create their own luxury clothing brand.

We will upload 15gb of corporate data soon. HR files (employee em
ails, phones and so on), financials (personal financial statement
s, payment details, credit cards and so on), drawings, projects, 
detailed customer info (addresses, contacts, even height, weight 
and so on), NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ARC-Dialysis-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31168</link>
<guid>5a1c75edbbb57641d5479f233810a798</guid>
<pubDate>Tue, 07 Apr 2026 12:09:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>ARC-Dialysis-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2404d134967e2e4a518b4fbfb82783b52dfff517dea7183920a40e3c7be2ad32</i><br /><br />Threat actor <b>description</b>: <i>Independent dialysis service provider</i><br />Target victim <b>website</b>: <i>arcdialysis.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>academyhealth.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31165</link>
<guid>a0fb781fa35dbce6299c291eb39e0022</guid>
<pubDate>Mon, 06 Apr 2026 21:16:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>academyhealth.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d57b5ed0285086bd011df4c02b08ccd916cec59485067fcfd06a87244ba2d41</i><br /><br />Threat actor <b>description</b>: <i>Is a U.S.-based nonprofit professional organization headquartered in Washington, D.C., dedicated to advancing the fields of health services research and …</i><br />Target victim <b>website</b>: <i>academyhealth.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crystal-Point</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31164</link>
<guid>f925a12c1605eac85a75144b0043c343</guid>
<pubDate>Mon, 06 Apr 2026 19:43:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Crystal-Point</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed42c6d18961db285a05a3cadd530dfa6541d4b5b59ae6220be9535397371bd3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.crystalpoint.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morphosis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31163</link>
<guid>6392877325fd73711329e5df268cc96e</guid>
<pubDate>Mon, 06 Apr 2026 19:42:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Morphosis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ccff39b13aff69a3b3e1c76635099d2cc6511f346cc7170a903b5fd5abe60f3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.morphosis.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aqua-Serv-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31162</link>
<guid>cc6a03346a8c24eacf57bdf97c1f9c9e</guid>
<pubDate>Mon, 06 Apr 2026 16:25:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Aqua-Serv-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bae3e23b8dfded69fd7c3621882f648678e8ccbaa045e4d1069c8e1c60d4953e</i><br /><br />Threat actor <b>description</b>: <i>Aqua-Serv Engineers, Inc. is one of the largest independent regio
nal industrial water treatment companies in the United States, he
adquartered in Fontana, California. They provide a wide range of 
water treatment products and services to various industries, incl
uding healthcare, government, food and beverage, and hospitality.

We will upload 17gb of corporate data soon. Employee personal doc
uments (passports, driver licenses and other docs), drawings and 
specifications, client information, detailed financials, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>AKM-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31159</link>
<guid>bfd6bb38a2386fbab71d56ecdb552b42</guid>
<pubDate>Mon, 06 Apr 2026 14:53:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>AKM-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64dbc8452eadc9d209e91126bb9ae7440aaf41bf7ad636121a858b5de2c9327d</i><br /><br />Threat actor <b>description</b>: <i>AKM Consulting Engineers specializes in providing expert engineer
ing solutions for public agencies, focusing on water and wastewat
er systems, infrastructure, and flood control projects.

We will upload 17gb of corporate data soon. HR files, drawings an
d specifications, client docs, detailed financials, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>douglasstruckbodies.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31136</link>
<guid>e988d81b705df34d7735e84bdd0220f9</guid>
<pubDate>Mon, 06 Apr 2026 13:59:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>douglasstruckbodies.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d4fbd2133e82759d88fe8e4a01051f24304cda27c309f54361a40e97e2783fb</i><br /><br />Threat actor <b>description</b>: <i>Douglass Truck Bodies specializes in the manufacturing and design of standard and custom truck bodie...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carmelo-Candy-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31128</link>
<guid>e348c1b446fae14bfcf5ae20ee4c23f0</guid>
<pubDate>Mon, 06 Apr 2026 07:00:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Carmelo-Candy-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da21b249a9a21d08482459db093192b84a715c243066d25afee3b66cc0638bfb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>www.shop.caramelo-candy.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>VirtaHealth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31119</link>
<guid>498b71407ed107b5a3f83951be5b4df4</guid>
<pubDate>Sun, 05 Apr 2026 06:14:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lapsus$</b> claims attack for <b>VirtaHealth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>292901f28b82ed1c78ec6940b962b7f1865c69e2fe76a4fd8bb959c019d69c7e</i><br /><br />Threat actor <b>description</b>: <i>Healthcare research</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lapsus$</category>
</item>
<item xmlns:dc='ns:1'>
<title>GCA-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31114</link>
<guid>608e170b60b7fd6f11914a4ec9dfedbd</guid>
<pubDate>Sat, 04 Apr 2026 22:47:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>GCA-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a05c590700bfb8c88693e8c6e6735ce1dbe4f3d8bae4984b51318614298ac6c</i><br /><br />Threat actor <b>description</b>: <i>gcagroupllc.com zoominfo.com/c/gca-group-llc/539618075 GCA Group LLC (Global Capital Advisors Group LLC) is an international business development and capital formation advisory firm focused on start-ups, early-stage businesses, alternative asset managers, and philanthropic organizations worldwide. Their services include capital introductions, marketing, brand management, new product development plans, and event coordination and logistics. The company is privately held, headquartered in Houston, Texas, with approximately 6 employees and annual revenues of around $7.2 million</i><br />Target victim <b>website</b>: <i>gcagroupllc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>jrk.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31103</link>
<guid>cef65a145c54dbe0f1ea8ad16a331421</guid>
<pubDate>Sat, 04 Apr 2026 22:43:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>jrk.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>906ce6e1777a5a14d60425827eb0075926ce4c8e1eb61c394abf8c5e4501328f</i><br /><br />Threat actor <b>description</b>: <i>A leading real estate investment and property management company specializing in multifamily and commercial assets. The data includes a breach involving 111,000 Social Security numbers from the company jrk.com.

Responsibility for the publication will lie with both the company itself and the insurance providers servicing it - mash.com (the intermediary) and the primary insurer beazley.com - which fails to properly value its clients’ data and is deliberately ignoring communications in an attempt to avoid payment, thereby putting the company at risk.</i><br />Target victim <b>website</b>: <i>jrk.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sokolin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31100</link>
<guid>77c33d0fb152118e33778d34ae8a0473</guid>
<pubDate>Sat, 04 Apr 2026 19:57:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sokolin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24410a51b0f91f9805119d438ecc0fea8787ad80c77fa1d24cd07b23d9b40ec6</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sokolin.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>EMCO-Electric-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31095</link>
<guid>3c12c84af346626dc2f1b77e52bb301e</guid>
<pubDate>Sat, 04 Apr 2026 16:54:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>EMCO-Electric-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>433f9d7551a0891d422ea481ab2ea182f6f9dbd0a67724cb92669e262673f339</i><br /><br />Threat actor <b>description</b>: <i>Electrical Resource International specializes in manufacturing a wide range of electrical installation products, including conduit, fittings, and accessories. With over 40 years of experience, they cater to various industries such as food and beverage, pharmaceuticals, and water treatment. Their product offerings include stainless steel fittings, liquid-tight connectors, and metal framing channels, designed to meet strict sanitary and corrosive requirements. The company aims to serve clients in residential, commercial, and industrial sectors, providing reliable solutions for electrical system needs. - corp you have 10 days to contact and get in touch for recover.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Connections</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31091</link>
<guid>c36214df5bdf67eaf55e6620f468b0ec</guid>
<pubDate>Sat, 04 Apr 2026 01:16:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Community-Connections</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>481a3d5ecddb7456714ef8ca1b767914301126428939a3ed23b7c82bc50dcc75</i><br /><br />Threat actor <b>description</b>: <i>Community Connections operates as a non-profit behavioral health organization dedicated to serving vulnerable populations including women, men, youth, and children who face systemic barriers to healthcare access. The organization addresses critical gaps in mental health and substance use treatment by providing comprehensive services tailored to the specific needs of marginalized communities. The organization delivers an integrated continuum of care that combines behavioral health treatment, residential support services, and primary health care coordination. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Vehicle-Assemblies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31090</link>
<guid>58117c3bd751aef482be0d07b465f6a5</guid>
<pubDate>Sat, 04 Apr 2026 00:25:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Advanced-Vehicle-Assemblies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1caf58bcd5a469af5cff602f24284dae7ec0a2145a98a04fbc322609b8bc3ee3</i><br /><br />Threat actor <b>description</b>: <i>- Banking & Financial Systems- Accounting & Tax Records- Customer & Sales Data- Engineering & Manufacturing IP</i><br />Target victim <b>website</b>: <i>www.avabuilt.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>coronapa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31089</link>
<guid>c73edcecd97f8e999b5cd937d5e6827e</guid>
<pubDate>Fri, 03 Apr 2026 23:48:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>coronapa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2694f7a61a7f485b0404895e10d6a24ba18c8bf0dbd03b0c753b7e931ec7bd9</i><br /><br />Threat actor <b>description</b>: <i>Corona Law Firm is a proud excellent client service and skillful representation. Established in 1997,  well-known in the Florida legal community.</i><br />Target victim <b>website</b>: <i>coronapa.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harman-Fitness</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31083</link>
<guid>b6843321325fae220b98267172f2f0ba</guid>
<pubDate>Fri, 03 Apr 2026 20:21:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>netrunner</b> claims attack for <b>Harman-Fitness</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7336a30b97b25b9daacda424f786f2bf5ab5e016badbaf7751b8429cf691ffe7</i><br /><br />Threat actor <b>description</b>: <i>Harman Fitness is a multi-unit franchise operator and management company that owns and runs dozens of Crunch Fitness clubs across the U.S. — operating Crunch locations under franchise agreements with over 40 gyms nationwide</i><br />Target victim <b>website</b>: <i>crunchfitness.com</i>]]></description>
<category>netrunner</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westamerica-Communications</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31073</link>
<guid>683768cf9ad8eecfd2e847498002cd29</guid>
<pubDate>Fri, 03 Apr 2026 17:53:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Westamerica-Communications</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46b4c13d5a1d44e8c260df9221922bed84f57078da89519afc49a074344a4ea7</i><br /><br />Threat actor <b>description</b>: <i>Westamerica Communications services include commercial lithographic and digital printing, direct mailing and online marketing, strategy and branding, distribution and fulfillment.We will upload over 70gb of corporate data soon. Employee personal information (DLs and so on), customer files, detailed financials, payment details, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charles-River-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31074</link>
<guid>004acbc8eefec9fe0629b15f52b94bcf</guid>
<pubDate>Fri, 03 Apr 2026 17:53:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Charles-River-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2170434d25235dc608bbd2a67e9e62dca4d8c8f89dcf626fd084b649855f1d0</i><br /><br />Threat actor <b>description</b>: <i>Charles River Insurance is an independent insurance agency headquartered in the state of Massachusetts that focuses on delivering personalized risk management and insurance solutions to individuals and businesses.We will upload 63gb of corporate data soon. Detailed employee andcustomer personal information (passport, DLs, SSNs, addresses, phones, emails and so on), detailed financials, payment details, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-College-of-Beaver-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31076</link>
<guid>0d4c864bca956a5d20efbe942d6cf993</guid>
<pubDate>Fri, 03 Apr 2026 16:20:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Community-College-of-Beaver-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c719eb2d3c8ebcb8c829e3f7254c698f792b02478c759eb853dd7c717f7f311</i><br /><br />Threat actor <b>description</b>: <i>The college serves a diverse student body, including recent high school graduates, adult learners, and those seeking career advancement. By focusing heavily on workforce development but neglecting its security, the college compromised hundreds of records containing personal and confidential information, as well as financial documents, projects, and contracts, which were subsequently leaked to the public.</i><br />Target victim <b>website</b>: <i>https:ccbc.edu</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodland-Trade</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31075</link>
<guid>e80a5fcb147d23edaed26cc0c74f47ab</guid>
<pubDate>Fri, 03 Apr 2026 16:03:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Woodland-Trade</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f21a53fcf7327ae2503a7301abc960b0c4e2158e1624e3d19b79d677fd2e4be7</i><br /><br />Threat actor <b>description</b>: <i>Woodland Trade Company is a full-service tool design and manufact
uring firm based in Tacoma, Washington, specializing in tool desi
gn and fabrication using composites, metals, and 3D printed hardw
are. The company serves a diverse range of industries including a
erospace, automotive, marine, medical, and space, and is recogniz
ed for its engineering design, CNC machining, and additive manufa
cturing capabilities.

We will upload 13gb of corporate data soon. Detailed employee inf
ormation (passport, DLs, SSNs, addresses, phones, emails and so o
n), financials, payment details, credit card information, project
s, drawings and specification contracts with government facilitie
s and big names like BOEING and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Vintage-Home-Briggs-Plumbing-Products-Genco-Manufacturing-American-Vintage-Hom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31071</link>
<guid>6705d77f2d837e528fb0edd21579e9c0</guid>
<pubDate>Fri, 03 Apr 2026 15:47:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>American-Vintage-Home-Briggs-Plumbing-Products-Genco-Manufacturing-American-Vintage-Hom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>089d3cb1c9a6fa63317315e0bf9cc7eb6ee81e7ad2006519bef12242da19155e</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 11gb of data of the following companies:American Vintage Home specializes in heating, air conditioning, and plumbing services tailored for vintage homes in the Chicago North Shore area. Their expert technicians focus on preserving the charm of older homes while providing modern HVAC solutions, including high-velocity and ductless systems.Briggs Plumbing Products, Inc. manufactures and markets enameled steel products, vitreous china, and faucets for residential, hospitality, and commercial applications. Founded in 1908 and headquartered in Goose Creek, SC.Genco Manufacturing specializes in high-quality, American-made utility truck beds, offering a range of products including the Genco Royal Utility Truck Bed and Genco Sporting Flatbed Body.American Vintage Home specializes in heating, air conditioning, and plumbing services tailored for vintage homes in the Chicago North Shore area.Associates of Clifton Park offers a range of insurance products including long-term care insurance, Medicare supplements, life insurance, and group disability insurance. You will find personal employee personal data, HR files, medical information, client information, project files, confidential files, accounting and financials, contracts and agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Vintage-Home-Briggs-Plumbing-Products-Genco-Manufacturing-American-Vintage-Hom...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31072</link>
<guid>9e106e26d5ec709ce1b63d12c5447791</guid>
<pubDate>Fri, 03 Apr 2026 13:06:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>American-Vintage-Home-Briggs-Plumbing-Products-Genco-Manufacturing-American-Vintage-Hom...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c6ca9c4c3209ddb8f15e1b137b87cfb31bab61284613c3c424f6d85c6e85664</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 11gb of data of the following companies:

American Vintage Home specializes in heating, air conditioning, a
nd plumbing services tailored for vintage homes in the Chicago No
rth Shore area. Their expert technicians focus on preserving the 
charm of older homes while providing modern HVAC solutions, inclu
ding high-velocity and ductless systems.

Briggs Plumbing Products, Inc. manufactures and markets enameled 
steel products, vitreous china, and faucets for residential, hosp
itality, and commercial applications. Founded in 1908 and headqua
rtered in Goose Creek, SC.

Genco Manufacturing specializes in high-quality, American-made ut
ility truck beds, offering a range of products including the Genc
o Royal Utility Truck Bed and Genco Sporting Flatbed Body.

American Vintage Home specializes in heating, air conditioning, a
nd plumbing services tailored for vintage homes in the Chicago No
rth Shore area.

Associates of Clifton Park offers a range of insurance products i
ncluding long-term care insurance, Medicare supplements, life ins
urance, and group disability insurance. 

You will find personal employee personal data, HR files, medical 
information, client information, project files, confidential file
s, accounting and financials, contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southeastern-Conference-of-Seventh-day-Adventists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31070</link>
<guid>1c05021910bd1385d5bb4ea2ae8fe585</guid>
<pubDate>Fri, 03 Apr 2026 12:48:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Southeastern-Conference-of-Seventh-day-Adventists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>697da0fb19544022897988cb45d39ea6d886a9a4c13b2b12fe4d27b3af18ea1b</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.secsda.org</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Siena-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31068</link>
<guid>03abddc67647f4283654c0503482e74b</guid>
<pubDate>Fri, 03 Apr 2026 12:47:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Siena-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f79f67f26171ada972e6aa2841c9f91a5014f8c4bd43d52bfdc2f8c2deb13595</i><br /><br />Threat actor <b>description</b>: <i>- QBOOK Data- Project Records- Employee Information- Finance Records- Technical Data- Suppliers Information- Bid Documents</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neptune-Mechanical-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31066</link>
<guid>9e5238f97bcf5cbfe605cdbed7f4e26d</guid>
<pubDate>Fri, 03 Apr 2026 12:47:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Neptune-Mechanical-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ca42b02ee22a2dc5079554bc17992d4ae47fc29eebd598ae3f677811066c2b2</i><br /><br />Threat actor <b>description</b>: <i>- Banking & Financial Systems- Accounting & Tax Records- Payroll & Employee Financial Data- HR & Employee Personal Data- Real Estate & Tenant Data</i><br />Target victim <b>website</b>: <i>callneptune.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>roodtrucking.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31062</link>
<guid>5b648f859eb8adc0121e6a1bf7f6aa98</guid>
<pubDate>Fri, 03 Apr 2026 12:14:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>roodtrucking.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e63755d1e4d226c947567100866ab68214d5dfa7119cf9609c372b0155b02fe</i><br /><br />Threat actor <b>description</b>: <i>Employees: 20 Revenue: $5 Million Industry: Transportation and Warehousing</i><br />Target victim <b>website</b>: <i>roodtrucking.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Asmar-Schor--McKenna</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31057</link>
<guid>b8d1200c2569eb9ce9c29e1698dbc84e</guid>
<pubDate>Fri, 03 Apr 2026 06:30:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Asmar-Schor--McKenna</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a57b49b9d17fe75cd74916e544c69b741789bbdc35434d98773ea40375693d8</i><br /><br />Threat actor <b>description</b>: <i>Asmar, Schor & McKenna is a leading construction law firm specializing in construction law, government contracts, commercial real estate transactions, and corporate law. Their clients range from Fortune 100 companies to national and international contractors, subcontractors, homebuilders, and design professionals. The firm provides legal guidance for projects on regional, national, and international scales, handling matters in courts and tribunals across the United States and globally. They are recognized for their expertise and have received numerous accolades, including rankings in Chambers USA and Best Lawyers.</i><br />Target victim <b>website</b>: <i>asm-law.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Faulkner-County-Sheriffs-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31053</link>
<guid>dc238c9533597a8cc2a9738ebde4bfcb</guid>
<pubDate>Fri, 03 Apr 2026 00:44:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Faulkner-County-Sheriffs-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6ab10bc28f43e4bcbe22f2710226910a58c025624801792a4362a9d3b313977</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wolf-Technology-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31054</link>
<guid>7c0d5fe6c602bc990fb88b539bc3a45e</guid>
<pubDate>Thu, 02 Apr 2026 23:15:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Wolf-Technology-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b638775e87285dc884524cae886e2e32e4bc7efcdcaae89673f68d4064c5ba03</i><br /><br />Threat actor <b>description</b>: <i>Wolf Technology Group specializes in providing cost-effective IT solutions and services for small businesses, helping them manage their technology needs without the expense of in-house support. Their offerings include Broadband, Infrastructure, VoIP, and managed IT services tailored to individual client requirements. The company focuses on enhancing business performance through improved IT systems and ensuring business continuity with expert support. With a team of certified IT professionals, they provide personalized strategies to optimize technology infrastructure while saving time and money - corp you have 10 days to contact us or everything will be leaked and no recover and will take actions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>cesimaging.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31037</link>
<guid>6f39194d3df14d057e8ba796fcae6942</guid>
<pubDate>Thu, 02 Apr 2026 15:38:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>cesimaging.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6791ac5a99a9a858eedc73a70da152f13706f98e2b31313bfada8fb7e99bfe3</i><br /><br />Threat actor <b>description</b>: <i>The company is an authorized dealer for Canon, Sharp, Oce, KIP America, and HP</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Center-for-Hearing--Speech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31046</link>
<guid>eb8348943495b531aad669701d56f569</guid>
<pubDate>Thu, 02 Apr 2026 14:23:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>The-Center-for-Hearing--Speech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b4a1bed51d5b12321902aaad1ef867d4030ee4106b70fb7f1ca9655c0009a8c</i><br /><br />Threat actor <b>description</b>: <i>The Hearing and Speech Center provides comprehensive services in hearing diagnostics, speech therapy, and screening for people of all ages.
However, it is not responsible for the security of your personal data; as a result of their negligence, a large amount of personal data belonging to clients and employees, as well as their confidential information, projects, and incident reports, was leaked online.</i><br />Target victim <b>website</b>: <i>https:thecenterforhearingandspeech.localsearch.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>acmealliance.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31044</link>
<guid>e72aceb00e6097c55a790d4e7ae23a9c</guid>
<pubDate>Thu, 02 Apr 2026 14:05:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>acmealliance.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40922b2ba2da4289dd771ca545545b73db944b39ac1c6ac31a9eda4cbe4700ef</i><br /><br />Threat actor <b>description</b>: <i>It is a global manufacturer specializing in the custom production of die-cast components for various industries, including the automotive, marine, and agricultural sectors.</i><br />Target victim <b>website</b>: <i>www.acmealliance.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>northstarmetal.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31043</link>
<guid>c8167cf7f61157655b7248284b413b6f</guid>
<pubDate>Thu, 02 Apr 2026 14:04:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>northstarmetal.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>281890d6d8de46cbb7c87da33d709d4fc6e3bb1b124c31aa98144efcb11f83d1</i><br /><br />Threat actor <b>description</b>: <i>Northstar Metal Products is a manufacturer of metal products. Services: CNC machining, laser cutting, robotic welding, powder coating, and prototyping. Industries: telecommunications, manufacturing, transportation, energy, healthcare, and home goods.</i><br />Target victim <b>website</b>: <i>northstarmetal.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>kleankanteen.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31042</link>
<guid>fca68f4dff3920d202186d63f9048dfa</guid>
<pubDate>Thu, 02 Apr 2026 14:03:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>kleankanteen.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>926f76d00ac842a696ca2a9f8418b64c5f7fcd1683abb33ea6c2fd6d66f7d2c2</i><br /><br />Threat actor <b>description</b>: <i>Klean Kanteen was founded in 2004. The company manufactures reusable stainless steel water bottles. The company's headquarters are located in Chico, California.</i><br />Target victim <b>website</b>: <i>kleankanteen.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>greenwayfence.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31033</link>
<guid>9fdf913312884f2e344898dfdda3409f</guid>
<pubDate>Thu, 02 Apr 2026 12:33:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>greenwayfence.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6255dec14131657140eaaf3a0541f1f0a8f08c5686a8438be9fa89b0f8525ccd</i><br /><br />Threat actor <b>description</b>: <i>A wholesale supplier of fencing and railings serving both private homeowners and contractors throughout the East Coast. They offer a wide range of 
custom fencing materials, including vinyl and aluminum options, as well as decking and specialty products.</i><br />Target victim <b>website</b>: <i>greenwayfence.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>congoleum.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31032</link>
<guid>1ff4dc549f35ef8cbdcb51f0dc4972a8</guid>
<pubDate>Thu, 02 Apr 2026 12:32:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>congoleum.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5ece0d1c6269e4ab56592a03424fd06f75198cd6a0e9dc3c51338b81f9fe0c5</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1886 and headquartered in Mercerville, New Jersey, Congoleum develops and manufactures flooring for residential and commercial spaces.</i><br />Target victim <b>website</b>: <i>congoleum.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>atpkg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31031</link>
<guid>8c711b2a61cccea42c643ce986dc203a</guid>
<pubDate>Thu, 02 Apr 2026 12:32:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>atpkg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e18ea78d128f87e0ec4b53e3138578a0d7caafe7d651c0b96b293ac3aa32479</i><br /><br />Threat actor <b>description</b>: <i>At AT Packaging, employees play a key role—dedication, a commitment to quality, and team spirit are at the core of the company’s business philosophy. If you are a dynamic, customer-focused individual, there may be a career opportunity for you at AT Packaging.
The following positions are available: Warehouse Operations — the company’s operations must be based on an organized and efficient warehouse to ensure high-quality customer service.</i><br />Target victim <b>website</b>: <i>www.atpkg.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>TouchSource</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31028</link>
<guid>f40ef5fc5d2ac8911c6a5362f89a06ab</guid>
<pubDate>Thu, 02 Apr 2026 09:15:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>TouchSource</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9090af053a71198cb735adf891c6424cc95f7e597078a2a531b4f169f03c778</i><br /><br />Threat actor <b>description</b>: <i>TouchSource delivers simple solutions for smart spaces that engage people. Our captivating digital displays and IoT-connected directory solutions improve the experience of tenants, visitors, and shoppers. We create intelligent digital experiences in residential, business, retail, healthcare, and public spaces with relevant, engaging content that moves people where it matters. Our digital signage solutions in the TouchSource ActiveSpaces portfolio are simple to deploy, easy to use and low effort to maintain. 
The company headquarters is located in 1370 Miners Drive, Suite 103, Lafayette, Colorado 80026, USA.
11-50 Employees.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neurologic-Associates-Of-Central-Brevard</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31026</link>
<guid>e5f733249a6f0dc11a6b1d4568c786da</guid>
<pubDate>Wed, 01 Apr 2026 22:31:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Neurologic-Associates-Of-Central-Brevard</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9033b8b48445564c331bd27e12f83ba1d2d0cc84d14c8519f0b715e2b7beef67</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.neurologicassociatesofbrevard.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elara-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31021</link>
<guid>7c019f69abfc6be1b8a91b27e41d2f77</guid>
<pubDate>Wed, 01 Apr 2026 21:33:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Elara-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31fd307655028332a43592da8320639c49f42f2d4ed4582a7f42a95988452b5a</i><br /><br />Threat actor <b>description</b>: <i>Elara Engineering is a full-service Mechanical, Electrical, Plumbing, Fire Protection, and Technology consulting engineering firm based in Chicago, Illinois. With 25 years of experience, the company specializes in the design, costing, delivery, and oversight of building and utility systems, offering both pre-design and post-construction services. Their clients include educational institutions, municipal entities, and residential developers, focusing on sustainable and innovative engineering solutions. Elara Engineering is committed to reducing energy consumption and carbon footprints through its projects and embraces diversity within its workforce</i><br />Target victim <b>website</b>: <i>elaraeng.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>blossmangas.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31019</link>
<guid>28a1faa9dd2f69eeef4279da40dcdfe0</guid>
<pubDate>Wed, 01 Apr 2026 19:30:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>blossmangas.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69b7757e222215230106cbdf7db526829c099db28eeab8b5b95794f0da49891f</i><br /><br />Threat actor <b>description</b>: <i>Blossman Gas, founded in 1951 and located in Ocean Springs, Mississippi, is a family-owned business that provides a wide range of services in the  liquefied pet...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lincoln-Property-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31020</link>
<guid>5f59e50d07465cc328132f91bc67f486</guid>
<pubDate>Wed, 01 Apr 2026 18:33:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Lincoln-Property-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b773453ee64f070d51ccb25aceeb937046ead2ff7ef6ccdfcfe139c8e1d2efb0</i><br /><br />Threat actor <b>description</b>: <i>    Lincoln Property Company  www.lpc.com  Total data in the leak: : 800GB  Leaked data: - Clients: Rockhill Capital & Investments, FOCUS FINANCIAL PARTNERS, LLC, IMA Financial Group, Provident Partners RE, Deutsche Bank AG, Government…. - Data Classification: confidential - Special data: Contracts, NDAs, CONFIDENTIAL Closed Deals,Personal data,  INVESTMENTs, Projects, Drawing... - Financial data: financial planning documents, accounting, CONFIDENTIAL INVESTMENT   MEMORANDUMs, Fin. Audits 2021-2026, investors information and VERY IMPORTANT information!    </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>State-Road-and-Tollway-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31014</link>
<guid>6b8df87e67318f5c70bf4ffad3485829</guid>
<pubDate>Wed, 01 Apr 2026 17:24:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>State-Road-and-Tollway-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc290f967e99b10a3032a5752331fca2c7606b47c2b6450430ea945848aa7434</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swagelok</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31015</link>
<guid>d7df9a10a3bb2c94ef6f35d90282702f</guid>
<pubDate>Wed, 01 Apr 2026 17:24:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Swagelok</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afef334ecc56495f1d58510be45bd49756e4f0585810ad71da750b179e59fbbb</i><br /><br />Threat actor <b>description</b>: <i>Swagelok is a worldwide leader in industrial fluid system manufacturing and support. Since the introduction of the revolutionary, leak-tight Swagelok® tube fitting in 1947, they have applied a passion for making high-quality products and an unwavering focus onmeeting customer needs to help a wide range of industries safely, efficiently, and reliably move liquids and gases in demanding applications.We will upload 90gb of corporate data soon. Employee passports, and other personal information, detailed client information (financials, agreements with Nikon, Kawasaki, Mitsubishi and others), projects, HR files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Builtrite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31018</link>
<guid>fd04261dba31ac3aca7bed16b57444b8</guid>
<pubDate>Wed, 01 Apr 2026 16:48:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Builtrite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf4b67afe4584fee7206ce839d480e015fe4d01e31294653bece13266ef4da88</i><br /><br />Threat actor <b>description</b>: <i>Northshore Manufacturing offers 3 main product lines that are mar
keted under the Builtrite Brand. The company also produce compone
nts for several O.E.M.'s and tackle custom projects within the co
mpany's realm of expertise.

We will upload 40gb of corporate data soon. Detailed employee pas
sports, DLs (13 persons), SSNs and other personal information, fi
nancials, violations, police records, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plunkett-Cooney</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31017</link>
<guid>e321abd135c19b6d4cee4da276d4970e</guid>
<pubDate>Wed, 01 Apr 2026 16:45:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Plunkett-Cooney</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b373419e576e01a5a413358160091e996a4b10300ff8f969c2d7a552174d1958</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1913 and headquartered in Bloomfield Hills, Michigan. Plunkett Cooney is a law firm with of…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alamo-Heights-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31008</link>
<guid>0972350bc45d5d235a2e01d7a1a5b43c</guid>
<pubDate>Wed, 01 Apr 2026 15:52:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Alamo-Heights-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>462a054cf907a7e52ad56e61492509b70c0ec001e665a617f4c157691b8896d6</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Trinity-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31009</link>
<guid>27c8efa32c0738c9d83b37d1882d97ea</guid>
<pubDate>Wed, 01 Apr 2026 15:51:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>First-Trinity-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c45a71532865f17e436d559e936c7e89a47e425c0a1e634793c68ce43d22c95a</i><br /><br />Threat actor <b>description</b>: <i>FTFC is an insurance holding company based in Tulsa, Oklahoma. FTFC operates two life insurance companies, Trinity Life Insurance Company (TLIC), Tulsa, Oklahom...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tange--Mann--Garza</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31010</link>
<guid>4d5392d91f16d558eef803211e81f4f2</guid>
<pubDate>Wed, 01 Apr 2026 15:51:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Tange--Mann--Garza</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b683fba83bc708a0e83380379d4bc6375283dd71d49ec5e6e868bca3066f3c9f</i><br /><br />Threat actor <b>description</b>: <i>Tange , Mann & Garza is a full-service accounting firm offering abroad range of services for individuals, business owners, executives, and independent professionals. We will upload 40gb of corporate data soon. Employee passports DLand so on, detailed client information (financials, agreements and so on), NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Starr-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31016</link>
<guid>46093577f6da15ca5de89e2752b62b6a</guid>
<pubDate>Wed, 01 Apr 2026 15:20:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Starr-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c39746725fd12e7f0be2b608f2713be173a22293659c899128810506a29d46f</i><br /><br />Threat actor <b>description</b>: <i>Starr Insurance Inc. is an independent insurance agency based in 
Chambersburg, Pennsylvania, offering a wide range of insurance pr
oducts including car, home, business, and commercial insurance. T
he agency serves over 18,000 individuals and businesses across Pe
nnsylvania and neighboring states, providing clients with tailore
d coverage options from a selection of reputable insurance carrie
rs.

We will upload 15gb of corporate data soon. Employee passports, D
Ls, SSNs and other personal information, financials, customers' i
nformation, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alliance-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31012</link>
<guid>f81b2a1d75d01e35b2ac8c0f6a8ec78b</guid>
<pubDate>Wed, 01 Apr 2026 13:41:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Alliance-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b83f6bb4bc4d8e381303082203fa28200813bb76bc915a7d4b92069969507544</i><br /><br />Threat actor <b>description</b>: <i>Alliance Roofing Company Inc is a national leader in commercial r
oofing and waterproofing services with more than 27 years of indu
stry experience. Founded in 1986 and established in San Jose, the
company has expanded its geographic footprint to serve the Centr
al Valley and Northern California region, including Sacramento, R
eno, and Modesto, providing comprehensive roofing and waterproofi
ng solutions to corporate enterprises, small businesses, and prop
erty owners across diverse market segments.

We will upload 170gb of corporate data soon. Employee passports, 
DL, phones, addresses and so on, detailed client information (fin
ancials, agreements and so on), projects, drawings and specificat
ions, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Publishers-Clearing-House</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=31006</link>
<guid>446ce3c52d4376f1e86faa0c9edd702d</guid>
<pubDate>Wed, 01 Apr 2026 10:37:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Publishers-Clearing-House</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9caf32d5a31bd4c714dc37b723c145690ee354aed4cf22d67d20631a9d59ab9</i><br /><br />Threat actor <b>description</b>: <i>The fall of a sweepstakes giant.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cox-Design--Metal-Fabrication</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30980</link>
<guid>b54f0f8b3b75a8b7486c9adedf28f361</guid>
<pubDate>Tue, 31 Mar 2026 15:59:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cox-Design--Metal-Fabrication</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e31d958429b4efa3f4cb1ae262cffa2b03c84e2bc131cdf47697a9d4d5797b27</i><br /><br />Threat actor <b>description</b>: <i>Cox Design and Metal Fabrication, Inc. specializes in custom metal design and fabrication, offering a wide range of services including aluminum fabrication, architectural steel design, and customfood trucks.We will upload 20gb of corporate data soon. Employee personal document, financials, projects, contracts and agreements, NDA, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dean-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30981</link>
<guid>3d2515739e79e2d0700e7b6b75f6b2a1</guid>
<pubDate>Tue, 31 Mar 2026 15:59:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Dean-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47ae156b4c42fdba5f3893e6fda9fe36ba12e0cf35813a56bcafbf37ed40de4</i><br /><br />Threat actor <b>description</b>: <i>Dean Supply specializes in providing a comprehensive range of restaurant supplies and equipment, including kitchenware, dining essentials, and janitorial products. We will upload 15gb of corporate data soon. Employee medical information and other docs, NDAs, financials, projects, contracts andagreements, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Excel-Healthcare-Receivable-Management-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30982</link>
<guid>d70f093b1afc45db0022c13d1acba36e</guid>
<pubDate>Tue, 31 Mar 2026 15:59:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Excel-Healthcare-Receivable-Management-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e21d781df302a9ef10c9b445d2973e3446db84dee76352850ac302c8dcb028a5</i><br /><br />Threat actor <b>description</b>: <i>Excel Healthcare is a specialized firm focusing on revenue cycle management and consulting services for healthcare professionals, including hospitals and medical practices of all sizes. They offer comprehensive services such as accounts receivable management, insurance follow-up, denial auditing, and consulting on workflow optimization to enhance cash flow and operational efficiency.We will upload 54gb of corporate data soon. Employee and customerpersonal information, project information, lots of contracts andagreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Catalyst-Learning-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30993</link>
<guid>9aade22d3f397b10afdf6efcb920dea9</guid>
<pubDate>Tue, 31 Mar 2026 15:27:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Catalyst-Learning-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5aa687e3b4e4094aa33e07ecf484d381c1ef8c00f0a29201d458b7aba9b4d13</i><br /><br />Threat actor <b>description</b>: <i>Specializes in healthcare training and employee development, aiming to empower staff for better patient outcomes and organizational success.</i><br />Target victim <b>website</b>: <i>catalystlearning.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>BR-Sheet-Metal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30992</link>
<guid>d62c2838344637ce8ad67f74ed98c45a</guid>
<pubDate>Tue, 31 Mar 2026 15:26:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>BR-Sheet-Metal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2c7ced452c713dcd788c8a6e5a63ba06c318543579c96f79ef36ee35fe0cb98</i><br /><br />Threat actor <b>description</b>: <i>Specializes in industrial construction projects, offering design, fabrication, and installation services for pneumatic, mechanical conveying, and filtration systems</i><br />Target victim <b>website</b>: <i>brsheetmetal.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Raphael-Ortho</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30991</link>
<guid>f7b49030b84b97848504c5f439564b69</guid>
<pubDate>Tue, 31 Mar 2026 15:25:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Raphael-Ortho</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ba6dd44eec6c2b348fcd34069ed6cdf09291172924172d1f2db13a67a6c3e22</i><br /><br />Threat actor <b>description</b>: <i>A Dental Practice Management Company.</i><br />Target victim <b>website</b>: <i>morethanstraightteeth.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Green-Giftz</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30990</link>
<guid>83672563a735a0e086c45ca392adf13f</guid>
<pubDate>Tue, 31 Mar 2026 15:25:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Green-Giftz</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d32011655e2630601e8b23b3036483398a73d67b1c16767bcbee6dfda6451db4</i><br /><br />Threat actor <b>description</b>: <i>A certified branded merchandise agency based.</i><br />Target victim <b>website</b>: <i>greengiftz.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>MC-Rx</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30988</link>
<guid>781875806d0ec961e50faa879b057e97</guid>
<pubDate>Tue, 31 Mar 2026 15:24:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>MC-Rx</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71f0c469d994bcaae43c696346f97f45592e38c1bd7d4c5a9ebea24937f335cb</i><br /><br />Threat actor <b>description</b>: <i>Formerly MC-21 and ProCare PBM</i><br />Target victim <b>website</b>: <i>mc-rx.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Modern-Advanced-Print-Solutions-MAPS-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30987</link>
<guid>bbe0c3bf910dea29774c3926f51b7f91</guid>
<pubDate>Tue, 31 Mar 2026 15:23:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Modern-Advanced-Print-Solutions-MAPS-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99116a9b43e84013ce311ae0e2648450527322a8c8f42fcee71c90f9fdf76777</i><br /><br />Threat actor <b>description</b>: <i>Modern Advanced Print Solutions (MAPS, Inc.).</i><br />Target victim <b>website</b>: <i>mapsweb.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Secure-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30986</link>
<guid>4b8d760a3ddf003fc8fd3cc36b5b87c4</guid>
<pubDate>Tue, 31 Mar 2026 15:22:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Secure-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6699bf8e287865e3f223f9b304ff9c83d7e2c9282645e27fc25178d252fabb48</i><br /><br />Threat actor <b>description</b>: <i>Provides administrative, care management, and healthy lifestyle services to employers with self-funded, group health care plans</i><br />Target victim <b>website</b>: <i>shpg.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>delapazlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30984</link>
<guid>9379824b37bdf1d40d517e0a8e4ea024</guid>
<pubDate>Tue, 31 Mar 2026 13:59:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>delapazlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c41f945ecbde45f961b4f5241527cf01c3957d4b6d85f5a372a6073ff9f275c</i><br /><br />Threat actor <b>description</b>: <i>When you work with the Law Office of Michael R. De La Paz, the only thing you have to worry about is recovering from your injuries. Mr. De La Paz will go to bat for you with the insurance companies and fight them in court to get you the compensation you deserve.</i><br />Target victim <b>website</b>: <i>delapazlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chickasaw-Holding</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30976</link>
<guid>aa16b1e36967dda0f92705a0a1beb710</guid>
<pubDate>Tue, 31 Mar 2026 12:58:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chickasaw-Holding</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81fe8aec95b4f8a1c19dec0a40f0b7359ea4869c6bc1c17dbde4e64b7108b387</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.lagoonpark.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30978</link>
<guid>b5403b2d202b8fe1db69b68b2c0c5e2b</guid>
<pubDate>Tue, 31 Mar 2026 12:15:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>httpswww.lagoonpark.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f471f56910f9a81d3b3de25c80ad26230534cf4ea5d3321d7435a374d9da826f</i><br /><br />Threat actor <b>description</b>: <i>Lagoon Amusement Park
, located in Farmington, Utah, is a historic family-owned park operating since 1886. It features a combination of roller coasters (includ... - TOTAL QUANTITY 6 TB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>MerchNOW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30977</link>
<guid>84e126c81be5b857ebddb2619860007c</guid>
<pubDate>Tue, 31 Mar 2026 12:05:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MerchNOW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff8bab271ccfb9196a76839b3ea0b4746a033821349ba34896eb89c40957f4b4</i><br /><br />Threat actor <b>description</b>: <i>MerchNow is a music merchandising company with over 20 years of e
xperience, specializing in a wide range of products including mus
ic, apparel, accessories, and custom merchandise for bands. They 
offer services such as screen printing, record pressing, embroide
ry, and fulfillment to help artists create unique merchandise.

We will upload corporate data soon. Great amount of employee pers
onal documents (passports, DLs, SSNs and other scanned docs), fin
ancials, contracts and agreements, client files, NDA, projects, e
tc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>San-Felipe-Del-Rio-CISD-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30974</link>
<guid>ba1ded3b4a24fb934f53571fb56151d6</guid>
<pubDate>Tue, 31 Mar 2026 11:58:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>San-Felipe-Del-Rio-CISD-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>411ab5ad707ba31b36089545b78baf1a0ac8e7e5a777973415b7f895b5aacd70</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Q-Lab</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30975</link>
<guid>bd082db9d2511ac2195e984d6eee33b8</guid>
<pubDate>Tue, 31 Mar 2026 11:58:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Q-Lab</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>405314718d661f8e9017d740d66dac76dd1130c8dd9c266addf7dd0cf0dfa478</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hallmark-Cards-Inc.--Hallmark-Plus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30972</link>
<guid>b1f3af7a68db79361a5e30b972f50ae1</guid>
<pubDate>Tue, 31 Mar 2026 02:16:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Hallmark-Cards-Inc.--Hallmark-Plus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>972fb782170e570bff3c59b091010007ce0fde3943ee0887fa8a9802d5b7f735</i><br /><br />Threat actor <b>description</b>: <i>Over 7.9M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 2 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 31 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>JT-ATFP-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30969</link>
<guid>e624ee446bd5711b139afe335485a2d8</guid>
<pubDate>Tue, 31 Mar 2026 02:08:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>JT-ATFP-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e60d5e5c35ba59e8446f50093a42256da141f71447bbd257efbcbed216567ba</i><br /><br />Threat actor <b>description</b>: <i>- Classified Contracts- Employee Information- ATFP Projects- Vulnerability Assessment Docs- FOUO Files- DOD Projects</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>domingogarcia.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30966</link>
<guid>7b6f112e7e54968fd8c34d5727e4996d</guid>
<pubDate>Mon, 30 Mar 2026 22:42:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>domingogarcia.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88b123e87429a7dd61010a83e9a3b78f967e1425580530465d4cf75cd38da009</i><br /><br />Threat actor <b>description</b>: <i>Domingo Garcia’s has been representing accident victims for over 35 years! One of Domingo’s first legal victory happened in 1995 when a jury awarded his client, a car-accident victim, $1,100,000. As the years passed Domingo has surrounded himself with highest skilled and qualified legal team who have recovered millions for victims of injury and wrongful death.</i><br />Target victim <b>website</b>: <i>domingogarcia.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>millersteelelaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30965</link>
<guid>ce916a6c3a313e568546f66654ee5ee1</guid>
<pubDate>Mon, 30 Mar 2026 21:13:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>millersteelelaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1d4a42b03cf2f8ca8ab18bd525557f990e363e361ede96a6b66f3782743d99a</i><br /><br />Threat actor <b>description</b>: <i>At Miller & Steele Law Firm, we believe in protecting and fighting for those who have been affected by the negligence of others. David Miller started this firm in 1978 to fight for those who could not fight their own battle. When he was a young man, he saw a family member involved in a lawsuit who was poorly represented by a bad lawyer which resulted in a poor outcome.</i><br />Target victim <b>website</b>: <i>millersteelelaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Straight-Line-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30964</link>
<guid>3946286620b2e1ed380a77193fb7add7</guid>
<pubDate>Mon, 30 Mar 2026 21:10:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Straight-Line-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1237c9faf3656d3809efa9cab5b3aa1276d2ff07a56a2b53f92e6b0d83567ce</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Straight Line Logistics is a Houston based company, specializing in transportation and logistics solutions. They offer a wide range of services, including truckload freight, intermodal transportation, warehousing, and supply chain management. Their team of experienced professionals focuses on providing efficient, reliable, and cost-effective solutions to their clients' logistic needs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Net-Solace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30962</link>
<guid>3de36aabe0a47900e74f4a55a03db1fc</guid>
<pubDate>Mon, 30 Mar 2026 21:06:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Net-Solace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35fbe47d9d7eb836edbd00a8e75425663c6ec5bd5533afd33ec56d7a07cdaa94</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Net Solace is a technology solutions company that specializes in providing support and software development services. They offer a multitude of services including IT consulting, software development, project management, and network design. The company aims to provide affordable technological solutions to businesses of all sizes. They have expertise in various information technologies and aim to provide peace of mind for clients with their IT needs.</i><br />Target victim <b>website</b>: <i>netsolace.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Silver-Peak</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30957</link>
<guid>01ee2e65c1b26551bda7abb393ac860c</guid>
<pubDate>Mon, 30 Mar 2026 21:02:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Silver-Peak</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be00009397cceebd0f9ba5a52af80b406550320827c5831895d8484902e2fdd1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Silver Peak is a global software-defined Wide Area Network (SD-WAN) solutions provider. The company develops advanced technologies that route data traffic and help reduce the cost of network hardware. Founded in 2004 and headquartered in Santa Clara, California, Silver Peak serves thousands of customers worldwide, improving their data and application performance across wide area networks.</i><br />Target victim <b>website</b>: <i>silverpeak.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buffalo-Neuroimaging-Analysis-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30956</link>
<guid>4e62ef3e34c3922e68f90b9358f8be0b</guid>
<pubDate>Mon, 30 Mar 2026 21:02:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Buffalo-Neuroimaging-Analysis-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a44fd1c9ba1732d83b001130f5b7cde6f3b365a604479725d0b1ee84d1f86c6c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Buffalo Neuroimaging Analysis Center, based in Buffalo, New York, is a pioneer in the application of neuroimaging methods in clinical trials for neurological diseases. It focuses on MRI and MRI-related research, collecting and analyzing results from numerous clinical trials to help develop treatments for diseases such as multiple sclerosis, Alzheimer's, and Parkinson's.</i><br />Target victim <b>website</b>: <i>bnac.net</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>barrypgoldberg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30953</link>
<guid>ed5b3698e25bc1b85b239a4cea69f48b</guid>
<pubDate>Mon, 30 Mar 2026 19:39:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>barrypgoldberg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39fef1ef2172725efe19c631683d2632377e1743d7d4ea2bb5aa318ed987d289</i><br /><br />Threat actor <b>description</b>: <i>Barry P. Goldberg is truly committed to client satisfaction. We strive to obtain the largest possible result the law will allow and at the same time maximizing our clients’ net amount. We will take your phone calls whenever possible, return all communication promptly and answer each and every question. At Barry P, Goldberg, A Professional Law Corporation, we strive to handle our cases aggressively, ethically and “transparently” for our clients.</i><br />Target victim <b>website</b>: <i>barrypgoldberg.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jones-Day</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30952</link>
<guid>1354b98ee215d7231701d300a7b4451c</guid>
<pubDate>Mon, 30 Mar 2026 19:24:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Jones-Day</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89be37ec2cd86ef20a534ae6a350df1294dd4cd0cb60900cb527c20444d768da</i><br /><br />Threat actor <b>description</b>: <i>Jones Day founded in 1893 and headquartered in Cleveland Ohio, is a global law firm with locations acr…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weber-Kracht--Chellew</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30948</link>
<guid>a41b7c188df8001c036825089b562709</guid>
<pubDate>Mon, 30 Mar 2026 18:51:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Weber-Kracht--Chellew</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9fe954ab8c9df45bb298f35e4abf153398b2f5de84526cdf865f4d89ffe6782</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wkclaw.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dock-Pros</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30945</link>
<guid>bdba92535c1d9e8d4c4bf739243bb546</guid>
<pubDate>Mon, 30 Mar 2026 18:49:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Dock-Pros</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fe4156c36e91c99fb3e0a2fd9b89542187d80a8aba3e746033e39cb83ea80ac</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dockprosinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ampex-Data-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30944</link>
<guid>f72522e7430464a9c1ad922562815c1a</guid>
<pubDate>Mon, 30 Mar 2026 18:49:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Ampex-Data-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69adc01cd4483dae167877af89e5300ad40bac1adff7826c4977888a8ac87904</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ampex.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Plating-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30943</link>
<guid>f9ed45b93dd4614775806adf05661bfe</guid>
<pubDate>Mon, 30 Mar 2026 18:48:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Valley-Plating-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8aad55e6626dde03b7de235043d27d76fb0ba729ad29b635ec23fb06aeb8ff1c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.valleyplatinginc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Parkway-Reality-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30938</link>
<guid>db525c87bd3c69102f83450fbf2c684c</guid>
<pubDate>Mon, 30 Mar 2026 17:34:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Parkway-Reality-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63cbb8295a086958be537954581fa743fed3175fa5e24c91e795a6f3684b6fb2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>Parkway Reality Group</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dow</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30932</link>
<guid>fdb8081426eb791cab369832567f7715</guid>
<pubDate>Mon, 30 Mar 2026 16:00:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dow</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9b7ec3c9e8a9b36be446a9585fb385be9ece3b6574af5ea2c27a776effac69f</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wm-Erath--Son</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30933</link>
<guid>8ed16b12adc574bb06ec2cb2f5479952</guid>
<pubDate>Mon, 30 Mar 2026 16:00:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wm-Erath--Son</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>699a630811c9e64abaf6baae6616f0eea333ebdda6e59f1ccda444247bb56c96</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Richard-J.-Hackerman-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30935</link>
<guid>00fae5fc28cb7bd60be9ab6609b9bbf7</guid>
<pubDate>Mon, 30 Mar 2026 15:11:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Richard-J.-Hackerman-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dcb3e758f9f96b49cad701f0c090ee2410e1a99d729018f7fb60e5b886ff8ce</i><br /><br />Threat actor <b>description</b>: <i>Tax Attorney and Bankruptcy Lawyer in Baltimore</i><br />Target victim <b>website</b>: <i>richardhackerman.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wyatt-Insurance-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30934</link>
<guid>a64f23737e72f85b8fc0eb8ad5b36458</guid>
<pubDate>Mon, 30 Mar 2026 15:11:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Wyatt-Insurance-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d213c98c0dfcece397993c4ed5031adc16d46392723b37c4162b803e7e8b8cd4</i><br /><br />Threat actor <b>description</b>: <i>Auto Insurance, Home Insurance, Renters Insurance, Motorcycle Insurance</i><br />Target victim <b>website</b>: <i>wyattinsuranceca.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Summit-Tax-Advisory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30927</link>
<guid>2da833ec155de138b47062d56c60fbd8</guid>
<pubDate>Mon, 30 Mar 2026 14:36:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Summit-Tax-Advisory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d2d16de50c0430a1c16b53b2bd842e24bd14717580fdc3d3b8ffa39f2bb7658</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Office-Peeps-Nappies-Food-Service-Janome-America-IT-Supporten-A-1-Pools.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30931</link>
<guid>ba5d35769aa3568f9333a89fa8796938</guid>
<pubDate>Mon, 30 Mar 2026 14:21:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Office-Peeps-Nappies-Food-Service-Janome-America-IT-Supporten-A-1-Pools.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08f77d385791d3d07dee38de45b0f57fb9c80f6db5022ec7b88e5b01d310f83c</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 13gb of data of the following companies:

Office Peeps offers a wide range of over 50,000 office supplies, 
including general office supplies, ink and toner, coffee and brea
kroom items, and janitorial supplies.

Nappie's Foods is a family-owned food service provider and restau
rant supply expert based in Pittsburgh. The company emphasizes qu
ality, service, and loyalty, aiming to maintain superior customer
service while operating with a friendly, family-owned mentality.

Janome America is the largest subsidiary of Janome Sewing Machine
Company of Japan, which produces nearly two million sewing machi
nes annually as well as a line of related sewing products and emb
roidery software.

IT-Supporten provides tailored IT solutions for both private and 
business markets, ensuring optimal results for each client. They 
are a comprehensive supplier of IT equipment, offering competitiv
e pricing and a range of services including consultation and oper
ational agreements.

A-1 Pools is a family-owned business based in Wisconsin, speciali
zing in above-ground pools, hot tubs, swim spas, and saunas. They
serve clients in Waukesha County, Washington County, and Milwauk
ee County, offering high-quality products and exceptional custome
r service.

You will find personal employee personal data, lots of HR files, 
medical information, client information, numerous project files, 
confidential files, accounting and financials and other internal 
operational files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miles-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30930</link>
<guid>9bb9377f105d4c666ac02b8d1b5d9d59</guid>
<pubDate>Mon, 30 Mar 2026 13:44:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Miles-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d140d9ddc6b626c1bb8b692e4e762bfbabb450eb70dcf8d8ea2b598ac9766de</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.mileselectric.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Motleys-Asset-Disposition-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30929</link>
<guid>ecdf4779a8c72e348171c5a7523c067e</guid>
<pubDate>Mon, 30 Mar 2026 12:53:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Motleys-Asset-Disposition-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bafeb7e043000895fee7a75cc9ce8d9d34c6486b93dc9de96ff3d3b8393444b0</i><br /><br />Threat actor <b>description</b>: <i>Based in Richmond, VA, Motleys Asset Disposition Group offers sal
es, appraisal and acquisition services. The company offers real e
state services, auction services, appraisals and more.

We will upload 11gb of corporate data soon. Employee personal doc
uments (passports, DLs, SSNs and so on), project files, detailed 
financials, contracts and agreements, client and partner files, N
DA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conveyors-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30921</link>
<guid>295fd4bf7e3292b97e341d8eb21b82ea</guid>
<pubDate>Mon, 30 Mar 2026 02:33:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Conveyors-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1b2f9759bf9271e29d7a442b4ce004897bb993d434341dadde78214015e94fc</i><br /><br />Threat actor <b>description</b>: <i>Conveyors, Inc. is a family-owned manufacturer of bulk material handling equipment, established in 1974, with over 40 years of experience in the industry. The company offers a wide range of products including screw conveyors, bucket elevators, and drag conveyors, designed to efficiently handle bulk materials. Their intended clients span various industries such as commercial, industrial, oil & gas, and governmental sectors. With a commitment to quality and superior service, Conveyors, Inc. aims to exceed customer expectations in every project.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenology-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30917</link>
<guid>7f272b86ea4f734837b281ad960be2f7</guid>
<pubDate>Sun, 29 Mar 2026 17:29:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Greenology-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b027083116bbb2077572192b1e3d3ccdee9c7acd9c51afe7149489de28ce76a</i><br /><br />Threat actor <b>description</b>: <i>Since 2008, Greenology Products has been on a mission to create household and personal care products that do not harm our environment or human health. Our motto is Good, Clean, Honest.  We create a superlative customer-centric experience by producing household and personal care products that deliver performance, delight the senses, and solve everyday needs while using plant-based and responsible ingredients and materials that do not hard people, pets, or our precious planet.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Doctor.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30916</link>
<guid>e37d9170a3efe711ce2a5eb3df2253dd</guid>
<pubDate>Sun, 29 Mar 2026 15:40:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Doctor.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d7f47622435903c79244d5d18d8cfee576bf067c6c37d8e56a2cea5d1cdb426</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>kob.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30910</link>
<guid>69c89914e702d2abe840bd751f5b59c5</guid>
<pubDate>Sun, 29 Mar 2026 01:38:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ALP-001</b> claims attack for <b>kob.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f5fd2901353690599d2213fda38333bd3a68e0d7c4b135eec45cf9d0978388b</i><br /><br />Threat actor <b>description</b>: <i>Country: USA Revenue: $22 Million Storage: 1.127TB Description: KON (KOB 4, Eyewitness News 4 is your best source for Albuquerque news, Santa Fe news and New Mexico news, weather and sports.
Deadline: 2026-04-02 23:23:40</i><br />Target victim <b>website</b>: <i>kob.com</i>]]></description>
<category>ALP-001</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-Therapy-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30906</link>
<guid>c4f48c98a227f6dd2cdbd6a30dac6082</guid>
<pubDate>Sat, 28 Mar 2026 20:17:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Florida-Therapy-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e1a5ea651a6365c975cd077f2285e413ef0b4968999f2c4dfe0f1ef30b67978</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Florida Therapy Services is a mental health organization based in Florida, USA. It provides psychiatric services, psychotherapy, and substance abuse counseling, among other services for children, adolescents, adults, and families. The organization specializes in home, school, community, and office-based treatment, aiming to support individuals struggling with various mental health issues.</i><br />Target victim <b>website</b>: <i>flatherapy.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Don-Nan</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30904</link>
<guid>d1e40981bafcf2c263607fbc27e7a34e</guid>
<pubDate>Sat, 28 Mar 2026 18:56:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>Don-Nan</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1ec599a5f35b5ccc1c6f02057a66d0ef9f85c1263e678f82e5b6dd5a5243675</i><br /><br />Threat actor <b>description</b>: <i>Q2 Artificial Lift Services specializes in the sales, service, engineering, and manufacturing of down hole rod pumps, positioning itself as a leader in artificial lift technology. The company operates from a state-of-the-art 118,000 sq. ft. facility and boasts over 40 service and repair locations across Canada and the USA. Q2 offers a comprehensive range of products, including API pumps, specialty tubing, and production tools, combined with supportive engineering and technical services. Their commitment to quality and innovation enables them to provide tailored solutions that maximize productivity for their clients in the oilfield sector.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>kdmpop.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30896</link>
<guid>4b3da53a463251707e72fcb84e48b6ed</guid>
<pubDate>Fri, 27 Mar 2026 21:05:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>kdmpop.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51d66c74e8bd9a7d6c5b6d10fe3836a35f1f5d92dea91473a880db51c5968315</i><br /><br />Threat actor <b>description</b>: <i>KDM P.O.P. Solutions Group, headquartered in Cincinnati, Ohio, with additional facilities in Cincinnati, Nashville, Atlanta and Cleveland, has been in business since 1970. KDM specializes in custom, innovative retail solutions at the point of purchase: P.O.P. print solutions</i><br />Target victim <b>website</b>: <i>www.kdmpop.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>meridenct.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30895</link>
<guid>80baf0c8e70acc8c0a70d5befedf754f</guid>
<pubDate>Fri, 27 Mar 2026 19:52:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>meridenct.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8cf62a3907e1ea5c8b1582a63959d7df7e57a26d4bf7089025219553325dc460</i><br /><br />Threat actor <b>description</b>: <i>Meriden 2020 provides a variety of government, business, recreational, educational, and transportation resources for residents and visitors of Meriden, Connecticut (CT). Employees: 200 Revenue: $23 Million Industry: Government Phone Number: (203) 630-4000</i><br />Target victim <b>website</b>: <i>meridenct.gov</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sheraton-Hotel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30893</link>
<guid>aa37b70bbe5a37d659bf67dee2ca9492</guid>
<pubDate>Fri, 27 Mar 2026 19:34:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Sheraton-Hotel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>060a318492ebd5a6c4197e5786fdf9da4449ddb28bcdae20761e39d2433fff7a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>GeoMechanics-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30889</link>
<guid>fd537f53e8f93d331a3cf6a0f5f1e748</guid>
<pubDate>Fri, 27 Mar 2026 16:33:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>GeoMechanics-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a7dd7b507c76f7883abac8cde81a436b4f5f7b9d18a007a498d5a814e9819b9</i><br /><br />Threat actor <b>description</b>: <i>GeoMechanics Technologies, formerly called Terralog Technologies 
USA, was founded in 1994 by Dr. Michael S. Bruno. It originally o
perated as the US subsidiary of Terralog Technologies Inc in Cana
da. The new name, adopted August 1, 2012, reflects our primary an
d expanding focus on Advanced Geomechanics from the wellbore to t
he reservoir scale.

We will upload corporate data soon. Employee personal documents (
passports, driver licenses, SSNs and so on), project files, medic
al information, financials, contracts and agreements (Bentley and
others), client files, NDAs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edward-Beiner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30885</link>
<guid>4a9afaeb2472f426769ee7fe737f82ff</guid>
<pubDate>Fri, 27 Mar 2026 15:59:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Edward-Beiner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4efaa7e437a67c16bae5379a5a33b398d3691e0c590a341ec7252f876283f42b</i><br /><br />Threat actor <b>description</b>: <i>Edward Beiner specializes in designer sunglasses and luxury eyewear, offering a blend of fashion and vision. Their product range includes sunglasses and eyeglas...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quality-Carton-and-Converting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30887</link>
<guid>863ba2e194ab526fbb9c54d80873abcd</guid>
<pubDate>Fri, 27 Mar 2026 15:59:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Quality-Carton-and-Converting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34927496da0b7e61720bca1f6b58cec79675985cc2675e1c741f952bca1573a0</i><br /><br />Threat actor <b>description</b>: <i>Quality Carton and Converting, LLC. specializes in food and beverage paperboard packaging, offering both in-stock items and customfolding carton solutions. Their product range includes various types of bakery and donut boxes, pizza boxes, cupcake inserts, andutility trays.We will upload corporate data soon. Employee personal documents (credit cards, DLs and so on), HR files, project files, financialsdocs, payment details, contracts and agreements, client files, confidential files, NDAs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sheladia-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30888</link>
<guid>38db417df0ff3f93630307983ebb21f8</guid>
<pubDate>Fri, 27 Mar 2026 15:59:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sheladia-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9f05bae8c395aba6267769e5451dc4593709034f50c4497a4c07bd804856a06</i><br /><br />Threat actor <b>description</b>: <i>Sheladia Associates, Inc. is a multidisciplinary consulting firm specializing in architectural, engineering, and development consulting services. Established in 1974, the company focuses on infrastructure projects in sectors such as transportation, water supply, sanitation, and energy across various regions including Asia, Africa, and the Americas.We will upload corporate data soon. Big amount of employee personal documents (passports, driver licenses, credit cards, immigration docs and so on), project files, medical information, financials, contracts and agreements, client files, internal confidential files, NDAs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ACR1.COM-Commercial-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30884</link>
<guid>3fbe25e98c055443d115ff2eda3e76a7</guid>
<pubDate>Fri, 27 Mar 2026 13:50:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ACR1.COM-Commercial-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b94f1e1fe99b94008f61828658d28dd616a39181c0da5646bf3894e4189c495</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Big-Thumb</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30876</link>
<guid>f4a5d99730ab736c45838ef0ed2fcd37</guid>
<pubDate>Fri, 27 Mar 2026 10:15:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Big-Thumb</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>92e71dd21492d4891354442b65644bbcf03c1bdedabedea9dec4f86cabd7a779</i><br /><br />Threat actor <b>description</b>: <i>BigThumb IT Consultants provides a range of IT solutions including managed real-time professional support and cybersecurity services tailored to meet individual business needs. They focus on helping organizations manage their IT across mobile devices, ensuring optimal pricing and plans through dedicated account management. The company emphasizes the importance of agility in business, enabling clients to adapt to market shifts and growth opportunities with a digital workspace. Their security experts specialize in compliance with PCI, HIPAA, and GLBA, addressing the increasing threats of cyber attacks for businesses of all sizes. 
The company headquarters is located in 6235 Enterprise Ct, Dublin, OH 43016-3293, United States.
201-500 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schlam-Stone--Dolan-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30878</link>
<guid>1c931a87157b62c0e7412bcb263eb6ac</guid>
<pubDate>Fri, 27 Mar 2026 08:53:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Schlam-Stone--Dolan-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78d420875eb4c81b05935246d92ad375c29bee2a49c36b5164b344df8fe5fe5a</i><br /><br />Threat actor <b>description</b>: <i>Data breach at a law firm representing clients ranging from government institutions to Fortune 500 companies.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>carlysle.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30870</link>
<guid>e8d6b501bfa2981bd4c4a7a2eb822b28</guid>
<pubDate>Thu, 26 Mar 2026 23:47:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>carlysle.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0fe02bdcd29737abd621ae4a11993f16553cb77e92ab613a0ac719b7764f128</i><br /><br />Threat actor <b>description</b>: <i>Carlysle.net belongs to Carlysle Engineering, Inc., an engineering firm based in Boston. The company specializes in designing, installing, and maintaining fire protection systems such as sprinklers. They also provide building inspections and consulting services to ensure compliance with safety and insurance requirements.</i><br />Target victim <b>website</b>: <i>carlysle.net</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>njpcs.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30866</link>
<guid>a55ab2526717b7d51f169efdb32d0b41</guid>
<pubDate>Thu, 26 Mar 2026 22:39:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>njpcs.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38813de073d5ba024b0dedcb6fefede253af72b304eb6c4514ad9250222623b6</i><br /><br />Threat actor <b>description</b>: <i>NJ Pain Care Specialists is a leading interventional pain management practice lo...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Durable-Superior-Casters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30868</link>
<guid>e5b565ee90394bde9f504d9c6ef027d1</guid>
<pubDate>Thu, 26 Mar 2026 21:36:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Durable-Superior-Casters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7664837aa4f1b9af25dd65a324475642dcfd5aa66d92c46752445ebce4f8e221</i><br /><br />Threat actor <b>description</b>: <i>Durable Superior Casters, Inc. was established in 1991. In a relatively short period of time Durable USA has become the finest manufacturer and importer of casters and wheels in North America. We provide "Quality without Compromise" at very competitive prices and prompt shipment from an inventory in excess of 20 million dollars. We also attribute our success to our loyal customers, experienced and knowledgeable staff, and innovative leadership. We offer one of the broadest caster and wheel selections in the world. In addition to our ongoing new product development program we offer custom built casters for manufacturers that have a large unique or special requirement. Our corporate headquarters, largest US assembly plant with onsite Testing Lab and Engineering Department is in Arlington, Texas. Our assembly plant in Ohio helps to service our customers in New England and the upper Midwest</i><br />Target victim <b>website</b>: <i>durablesuperior.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ludlums.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30865</link>
<guid>51d7eab534fbc97552ecb39280168cc5</guid>
<pubDate>Thu, 26 Mar 2026 20:16:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>ludlums.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90dc18bd22a0759397aaeff24d39b1cfad08c372545123fc6566732ddc03fc75</i><br /><br />Threat actor <b>description</b>: <i>Ludlum Measurements, Inc.
(LMI), founded in 1962 in Sweetwater, Texas, designs, manufactures, and supplies radiation detection and measurement equipment used w... - We have 5 TB data including full source codes, client data, and more. </i><br />Target victim <b>website</b>: <i>ludlums.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>TPIS-Industrial-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30864</link>
<guid>518a0d4fdd28c9875618b3d7833831e2</guid>
<pubDate>Thu, 26 Mar 2026 19:25:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>TPIS-Industrial-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd9d49b167c6f42a3e10d3253619dad31b81ff73637980f2f1b4d9ab0539396a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.teamtpis.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bedrosians-Tile--Stone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30851</link>
<guid>b89bd6465f1baed1810a82e1d5138f52</guid>
<pubDate>Thu, 26 Mar 2026 18:38:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bedrosians-Tile--Stone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c2daf1a527e9d5207f3f3d4a5fadd95a85c2f1f0564234bdddbefc243b94b68</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Washoe-Tribe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30853</link>
<guid>27ac0ca86e06d1822d546ed038ea33ae</guid>
<pubDate>Thu, 26 Mar 2026 18:38:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Washoe-Tribe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1b1d9175ababa7061e079eae439570ed1e5d75b38dac72d5438aaf6bc2f3b5f</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kaemmerlen-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30858</link>
<guid>252a3893179658de41f437d975468205</guid>
<pubDate>Thu, 26 Mar 2026 17:37:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kaemmerlen-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99c8620a6f33768c8ef5cdad8d16ba119783c6e3d2ca2cb1da8ebce6c95c4ad1</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.davidhelfandlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30863</link>
<guid>443615ca6b28402752eb646cc6f51ae7</guid>
<pubDate>Thu, 26 Mar 2026 17:17:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.davidhelfandlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd63713191d8cdc8d062219e302330fb4da849d258dcff8be8807ceb2b35d28e</i><br /><br />Threat actor <b>description</b>: <i>David A. Helfand, P.A. is admitted to practice in all the state courts of the state of Florida as well as the U.S. District Court in the Southern District of Florida. Mr. Helfand graduated from St. John’s University in 1989 and from Nova Southeastern University Law School in 1992. He formed the Law Offices of David A. Helfand, P.A. in 1998. He is a member of the Miami-Dade County Bar Association and the Association of Trial Lawyers of America.</i><br />Target victim <b>website</b>: <i>www.davidhelfandlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goodwill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30848</link>
<guid>1b80bd6703c274cdb50d8d1fd2a020ab</guid>
<pubDate>Thu, 26 Mar 2026 11:09:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Goodwill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb03dc484e5ed0db081f3b54ae71660901a6b4a09e55748da170b667164d324c</i><br /><br />Threat actor <b>description</b>: <i>Goodwill Industries of North Central Pennsylvania is dedicated to turning donations into jobs, providing employment for more than 700 people across 15 counties in Pennsylvania and one county in New York.
However, they have been extremely negligent and irresponsible regarding security, resulting in the compromise and online leak of hundreds of pieces of personal data belonging to employees and partners, as well as financial documents.</i><br />Target victim <b>website</b>: <i>https:goodwillinc.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Monmouth-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30845</link>
<guid>6dd2f7fb9018bfcd8c3be1f8e65224ae</guid>
<pubDate>Thu, 26 Mar 2026 10:13:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Monmouth-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f79edbeeedfe64c9023613d17c8dc859689bb501eb55287690ccd903dac2333</i><br /><br />Threat actor <b>description</b>: <i>Private university in West Long Branch, New Jersey</i><br />Target victim <b>website</b>: <i>monmouth.edu</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>pridesol.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30841</link>
<guid>d501091236ae1875a06c4fa666166697</guid>
<pubDate>Thu, 26 Mar 2026 08:26:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>pridesol.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8464e5d0edcc98fc1e84b148804f534fd3e39df724366da6713f11c7e57e5ba1</i><br /><br />Threat actor <b>description</b>: <i>Pride Solvents & Chemical Co. is an authorized distributor of the largest and most reputable global manufacturers of chemical products and solvents.
This list includes companies such as Dow, Exxon, BASF, Sasol, ADM, Penreco, P&G, and Stepan—just to name a few.
With an advanced production facility, a fully equipped analytical laboratory, extensive warehouse inventory, and a modern transportation fleet, the company is able to provide an unmatched level of service to customers across all industries—from the state of Maine to Virginia, and westward as far as Ohio.</i><br />Target victim <b>website</b>: <i>pridesol.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ZenBusiness-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30837</link>
<guid>fc75bd9622425bbc421653770069faf5</guid>
<pubDate>Thu, 26 Mar 2026 04:54:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>ZenBusiness-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a90fc4ceb400bc17609f39731c4a251ac686e7ff54a93eaa675b7dd0ed69de01</i><br /><br />Threat actor <b>description</b>: <i>Several terabytes from Snowflake, Mixpanel, Salesforce, and ect. have been compromised. This is a final warning to reach out by 30 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 26 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>pulpdent.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30835</link>
<guid>5f8de67cee1da1d3e613285a57f69f4f</guid>
<pubDate>Wed, 25 Mar 2026 19:10:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>pulpdent.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c204267fe7afa54aa39fddc7940d0cdc451fd1c877856afd83991af6680d2fb9</i><br /><br />Threat actor <b>description</b>: <i>PULPDENT® Corporation is a family-owned dental research, manufacturing company and leader in bioactive and biomimetic dental materials. ACTIVA BioACTIVE, developed by Pulpdent, is a bioactive restorative material that behaves much like natural teeth and helps stimulate the formation of apatite, chemically bonds to teeth and helps protect against decay. For over 70 years, Pulpdent has been committed to product innovation, clinical education and patient-centered care. Employees: 100 Revenue: $20.1 Million Industry: Retail    Phone Number: +(617) 926-6666</i><br />Target victim <b>website</b>: <i>pulpdent.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Live-Casino</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30834</link>
<guid>eb47593d2d06ea177c0fdb7013b1707b</guid>
<pubDate>Wed, 25 Mar 2026 17:15:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Live-Casino</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d8a1503254e78c9d651fcef0a2199b2704bbc6b0f574fd644493201cd9a1f03</i><br /><br />Threat actor <b>description</b>: <i>Live! Casino is a premier gaming and entertainment company located in Greensburg, Pennsylvania. Opened in 2020, the property was developed and is operated by The Cordish Companies, a privately held, family-owned real estate and entertainment firm founded in 1910. The casino operates under the nationally recognized “Live!” brand, which integrates gaming, dining, and live entertainment into a single destination experience. The facility features hundreds of slot machines, table games, a poker room, and a sportsbook, alongside several restaurants and event spaces. It serves as a major regional entertainment hub, supporting tourism, employment, and economic growth in western Pennsylvania. 
The company headquarters is located in 7002 Arundel Mills Cir #7777, Hanover, MD 21076, USA.
1K - 5K Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eastex-Environmental-Laboratory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30831</link>
<guid>a389e350f007b3dc1ae27b920d1cacf8</guid>
<pubDate>Wed, 25 Mar 2026 15:35:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Eastex-Environmental-Laboratory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc41536ff9276002108d42e7cbc3029dfeb2b2e8c88af7286f721f1fdab369e6</i><br /><br />Threat actor <b>description</b>: <i>- Experimental Reports- Internal Documents- Financial & HR Documents</i><br />Target victim <b>website</b>: <i>www.eastexlabs.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>PWNA-Plains</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30819</link>
<guid>4bf6d29c0783b2ae052eb3f684995821</guid>
<pubDate>Tue, 24 Mar 2026 22:48:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>PWNA-Plains</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8161c14cb1cf432e02807ec42ed5408c5d5b5dde12b95f91efa1d24f9d51c126</i><br /><br />Threat actor <b>description</b>: <i>Partnership With Native Americans is a 501 (c)(3) nonprofit organization committed to championing hope for a brighter future for Native Americans living on remote, isolated and impoverished reservations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>cerboniservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30817</link>
<guid>6a1fbf6a6315721b9e8931e69112c21e</guid>
<pubDate>Tue, 24 Mar 2026 19:53:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cerboniservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da628e2f841f0686fac75493745734d06db642d871bda22a08c5bc8565612a41</i><br /><br />Threat actor <b>description</b>: <i>Cerboni specializes in providing expert bookkeeping, tax, and CFO services tailored for the restaurant and hospitality industries, while also serving a diverse range of sectors including retail, healthcare, and construction. The company focuses on optimizing profitability, strengthening financial controls, and driving sustainable growth for its clients. With a commitment to delivering clear financial insights and strategic support, Cerboni partners with businesses to enhance their operational efficiency and long-term success. Their comprehensive services include payroll management, inventory control, tax compliance, and IRS audit support.</i><br />Target victim <b>website</b>: <i>cerboniservices.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>jenningsk12.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30816</link>
<guid>78cfc36b921a50fba024eca72d6a458e</guid>
<pubDate>Tue, 24 Mar 2026 19:52:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>jenningsk12.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10745fa7fd8ee8a81e3290b930b990e3e582aca50e6eaf2d36f641a4d1198a21</i><br /><br />Threat actor <b>description</b>: <i>The Jennings School District strives to provide students with learning experiences and opportunities that prepare the company's students for college and careers and for the 21st century. The company is a community of learners committed to excellence in education. The company want students to plan and prepare for life after Jennings High School. The company want Jennings students to leave the Jennings School District with the opportunity to take college classes, earned college credit, or have taken career and technical education classes that allow them to start working in their desired career field after graduation. The company is developing community partnerships that will benefit Jennings students and the Jennings community. Please take the time to explore the College and Career link and resources available. It is an honor to serve the families and students of the Jennings School District. CLICK HERE to visit the College and Career Advising page. Employees: 500 Revenue: $28.5 Million Industry: Education   Phone Number: +(314) 653-8000</i><br />Target victim <b>website</b>: <i>jenningsk12.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aroostook-Mental-Health-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30807</link>
<guid>81190ee016c56828c2f2c3f2cd94db77</guid>
<pubDate>Tue, 24 Mar 2026 19:40:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Aroostook-Mental-Health-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b1cbbb0b63253fa3570f08f9df6c3a6d23193df6430e252b648971aa5949ff6</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>All-Real-Estate-Title-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30815</link>
<guid>4d991fb80216eb56bab6d06f6f292a0e</guid>
<pubDate>Tue, 24 Mar 2026 19:27:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>All-Real-Estate-Title-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65f8820337c95721d601779bf5e048efbacca6024823b0f0d62a25c108dcb7a4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.aretsifl.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roxiticus-Golf-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30814</link>
<guid>f186e7fae622a7798ce7f1bccac9a247</guid>
<pubDate>Tue, 24 Mar 2026 19:26:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Roxiticus-Golf-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb67e1f19c70862a5fe81e5fb9e775fcd212d054240807bcd5b340714ef5378c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.roxiticus.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pinnacle</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30813</link>
<guid>9f07f48cb91caf26dc0e4d76caac2826</guid>
<pubDate>Tue, 24 Mar 2026 19:26:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Pinnacle</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81ec58e0a2e07193427fbb73963001dfeaa7a4633c5700bd9b975afaaa7585a4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.pinnacle.tax</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ascent-Asset-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30812</link>
<guid>5c1917d0afc16d36b7b2471ae6a664ad</guid>
<pubDate>Tue, 24 Mar 2026 19:25:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Ascent-Asset-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb32cf0f0228cc83eec70404d65c16214911761ab31ff83b8d5eb793c8e50fc9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ascentasset.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capital-Wholesale-Drug</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30811</link>
<guid>b54732be9ea48e497ad2813b4cb8930f</guid>
<pubDate>Tue, 24 Mar 2026 19:25:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Capital-Wholesale-Drug</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89ec930600708389e89d3c1e48d663b70f7d03daa526ae0a22e80f5a5aeb0c7e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.capital-drug.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Block-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30810</link>
<guid>4b34cc1bf1623b6d6532ed63ff6ae276</guid>
<pubDate>Tue, 24 Mar 2026 19:24:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Block-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d6a8b0a940232f7816ffe1510caa9bde39b307ac12eb773caa213422e6d9fbb2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.blockeng.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Window--Door-Design-Center-of-Florida</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30809</link>
<guid>33b2260650d881180c21b62b4de5f3d2</guid>
<pubDate>Tue, 24 Mar 2026 19:23:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Window--Door-Design-Center-of-Florida</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>684054c17460e2e75c7e30c03f7af39ef8c4975c3a4aea80af3ad34661583392</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wddcfl.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Concord-Components-Wefapress-Environment-Masters-FairmontHot-Springs-ResortRoad-Americ</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30804</link>
<guid>ed0ec47d9ace176c75820740b17aa553</guid>
<pubDate>Tue, 24 Mar 2026 15:38:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Concord-Components-Wefapress-Environment-Masters-FairmontHot-Springs-ResortRoad-Americ</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a5dc57922e1b04554f58e366330a0c57e65a7eb8b6246984b05de31cc653043</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 17gb of data of the following companies:JConcord Components, Inc. was founded in 1995 in Concord, Nebraska as a retail catalog company, supplying hard-to-find electronic components. Wefapress is a leading manufacturer of plastic products, specializing in high-quality semi-finished products, custom plastic parts, and various profiles and guides. At Environment Masters, the company prides ourselves on delivering honest, reliable service. If the company tell you, you'll be better off with Crystal Springs HVAC repair, you can believe what the company say.Fairmont Hot Springs Resort, home to Canada's largest natural mineral hot springs, is a year-round destination nestled in the heart of the British Columbia Rocky Mountains and the stunning Columbia Valley.Road America, located in Elkhart Lake, Wisconsin, is one of the world's fastest permanent road racing tracks, offering a variety of motorsport events and experiences. The company provides a rangeof services including driving schools, karting, and various racing events such as the MotoAmerica Superbikes and the INDYCAR Grand Prix. You will find personal employee personal data (hundreds of SSNs and so on), medical information, client information, numerous project files, confidential files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mooers-Immigration</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30805</link>
<guid>3340d90f2875506693f0c0a8e693be86</guid>
<pubDate>Tue, 24 Mar 2026 15:35:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mooers-Immigration</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b0776eff1ce6b640cd2edddf88b489a9ae6b843454b50ce8aac6a4991ff0163</i><br /><br />Threat actor <b>description</b>: <i>Mooers Immigration is dedicated to the practice of immigration an
d nationality law, offering services such as employment-based and
family-based immigration, naturalization, and strategic complian
ce planning. The firm focuses on delivering cost-effective soluti
ons to help individuals and families achieve their American dream
s and navigate complex immigration processes.

We will upload 138gb of corporate data soon. Lots of client docum
ents (passports (LIONEL MESSI, LUCIANO ACOSTA passports and visas
and other interesting documents), DLs, SSNs, visas, credit cards
and so on), financials, confidential docs, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>M3-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30803</link>
<guid>74b4db7ecf4ff1770156d20fd45a7a6e</guid>
<pubDate>Tue, 24 Mar 2026 14:07:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>M3-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>169e798e47f916a29749fc8572dec19b5387e4fb598f30f34be960807fafc467</i><br /><br />Threat actor <b>description</b>: <i>Founded in Lansing more than 11 years ago by Dowling, M3 Group prides itself on being the only local agency that offers the most comprehensive array of integrated branding, marketing and advertising services in the mid-Michigan region. M3 Group has grown into one of the largest and most respected agencies in the area. For more than a decade, M3 Group has built and refined strong brands through integrated marketing strategies that keep the client's goals and its bottom line in mind. M3 Group's award-winning staff works across traditional and nontraditional platforms, offering an array of market research and consulting, media planning and buying, website development, social and digital media marketing, public relations and promotions, video and audio production, corporate brand development, and graphic design. Take your brand to the next level by visiting M3Group.biz</i><br />Target victim <b>website</b>: <i>m3group.biz</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>French-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30802</link>
<guid>0ee7cdb0c30e70bdb04b5c35d009d541</guid>
<pubDate>Tue, 24 Mar 2026 13:59:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>French-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>70553a5a7b3dbb1c6b62a2e65678712a486d3c2d60b09e4c7c183d6588d8f4d3</i><br /><br />Threat actor <b>description</b>: <i>French Engineering offers a range of services in Traffic Engineer
ing, Water Resources Engineering, and Sustainable Planning and De
sign Consulting in Pennsylvania, West Virginia, and Maryland. The
ir services include traffic data collection, traffic signal desig
n, roadway safety audits, and transportation impact studies, aime
d at supporting new commercial, industrial, and residential devel
opments.

We will upload 72gb of corporate data soon. Employee documents (p
assports, DLs, addresses, phones, emails, medical records, credit
cards), financials, confidential docs, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gustavo-Preston</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30801</link>
<guid>0718aac22ecc8481c33c38f79ba7f5bb</guid>
<pubDate>Tue, 24 Mar 2026 13:59:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gustavo-Preston</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ca9d3f0c40b483a635a595e6de23921c0e2dbf66a731ab7995842a791f17c92</i><br /><br />Threat actor <b>description</b>: <i>Gustavo Preston Company specializes in designing, selling, and se
rvicing commercial pump solutions, including water boosters, wast
ewater pumps, and circulator pumps. They offer a range of product
s such as packaged pumping systems, elevator pumps, and commercia
l water heaters, along with comprehensive pump equipment services
like maintenance and repairs.

We will upload 31gb of corporate data soon. Employee documents (p
assports, DLs, addresses, phones, emails, medical records, credit
cards), financials, client information, confidential docs, NDAs,
etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Russells-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30800</link>
<guid>0b668d973688aeb13be05aab06902066</guid>
<pubDate>Tue, 24 Mar 2026 12:58:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Russells-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f7485a1adf48cbd4e61f5dd97de31295520c2056bd3a7a55b49374f90a8eb4a</i><br /><br />Threat actor <b>description</b>: <i>The Russell's Law Firm specializes in personal injury, wrongful d
eath, criminal defense, and DUI cases, offering expert legal repr
esentation for their clients. They aim to support individuals who
have been harmed due to negligence or charged with crimes, empha
sizing that everyone deserves fair treatment under the law.

We will upload 15gb of corporate data soon. We took a lot of pers
onal data of their clients (passports, DLs, SSNs, death\birth cer
ts, addresses, phones, emails, medical records, and so on), polic
e reports, court docs, lots of confidential files, financials, et
c.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlas-Ocean-Voyages</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30795</link>
<guid>80f2ef940c5fbde8721e90963c00c8c0</guid>
<pubDate>Mon, 23 Mar 2026 16:53:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Atlas-Ocean-Voyages</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>721d1125d198cebc563e1a336ceacdc81ab8a977147e548b5c3c27e9857d7ac0</i><br /><br />Threat actor <b>description</b>: <i>Atlas Ocean Voyages offers year-round all-inclusive expedition cruises for under 200 guests, led by expert guides and caring crew. Luxurious yachts sail pole‑to‑pole to pristine, hard‑to‑reach destinations for nature, culture, and culinary exploration.</i><br />Target victim <b>website</b>: <i>www.atlasoceanvoyages.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nafco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30790</link>
<guid>621396ff1c6baf6578a381d65f2773ad</guid>
<pubDate>Mon, 23 Mar 2026 16:40:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nafco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c60fe10c7f387e9bcae5b67943ddc90743ffc882310a06278830dd3a7c07436</i><br /><br />Threat actor <b>description</b>: <i>NAFCO Fish is an industry innovator specializing in responsibly sourced seafood, providing high-quality products and services to brick-and-mortar stores, meal kit companies, and e-commerce food retailers. With over 30 years of experience, they offer a full range of seafood products including frozen, fresh, live, salted, andsmoked options, all processed with a focus on safety and quality. We will upload 150gb of corporate data soon. Employee personal information (passports, IDs, medical information), financials, contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marion-Military-Institute</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30783</link>
<guid>417cce83a9373223e4aae3b833114354</guid>
<pubDate>Mon, 23 Mar 2026 14:40:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Marion-Military-Institute</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b714b12fd45dc98ba578694f30ec62242a8f56eb0f21c39744039873e25a9937</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schmiede</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30784</link>
<guid>0a19bcfcc6385bfbdda771533cd7f694</guid>
<pubDate>Mon, 23 Mar 2026 14:40:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Schmiede</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0c2aeb10394970a75f6499d7bd266def1e53b47815aa2ad134860340d0d76bd</i><br /><br />Threat actor <b>description</b>: <i>Schmiede Corporation specializes in high-precision contract machining, focusing on complex and difficult-to-machine components with tight tolerances. The company offers a range of services including rebuilding, retrofitting, remanufacturing, and the productionof specialty machines, fixtures, and gages.We will upload corporate data soon. Employee personal information, projects, contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Distritech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30786</link>
<guid>5f0d57632c4ac1fac07a1fc7b2c449fb</guid>
<pubDate>Mon, 23 Mar 2026 14:35:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Distritech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6fd64b229f7b0efab4b9a46f814af87a9e91c7c2e6a8d888194bc68a7ed3e8bc</i><br /><br />Threat actor <b>description</b>: <i>distritech.com zoominfo.com/c/distritech-llc/358799326 DISTRITECH LLC offers a wide range of consumer electronics and accessories, including audio and video equipment, computers, cameras, mobility devices, gaming products, wearables, smart home solutions, and home living items. The company targets technology enthusiasts and everyday consumers seeking high-quality electronic products and personalized service. With a commitment to providing updated inventories and quick warranty support, DISTRITECH emphasizes exceptional customer experience and market insights. Additionally, they provide options for vendor registration and a range of weekly deals, making technology accessible and affordable to their clients</i><br />Target victim <b>website</b>: <i>distritech.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dixon-Electrical-Systems--Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30782</link>
<guid>4bf5d7d2a1bc51d753fecf97244464a2</guid>
<pubDate>Mon, 23 Mar 2026 12:32:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Dixon-Electrical-Systems--Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ca648210f28432af71cc78494c0f2573d4736391eb2a765ecaf679da308376f</i><br /><br />Threat actor <b>description</b>: <i>Dixon Electrical is a one-stop, full service electrical contracti
ng firm that installs industrial work, as well as any size commer
cial project. The company provides preventative maintenance, incl
uding Infrared Thermography, and install all levels of telecommun
ications, fiber, CATV, sound, Information Transport Systems (ITS)
, security, fire alarm and Building Automation Systems (BAS), as 
well as service work.

We will upload corporate data soon. Detailed employee personal in
formation (passports, DLs, credit cards details for more than 100
employees and so on), financials, contracts and agreements, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>JDV-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30778</link>
<guid>5d7b0538ea08741711041a1e67526b11</guid>
<pubDate>Mon, 23 Mar 2026 01:01:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>JDV-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f451f32f16a5c121db9472349674a799bf669a21400d4040e26556f2facbdea</i><br /><br />Threat actor <b>description</b>: <i>JDV Products, Inc. specializes in providing a wide range of tools and equipment for wire wrapping, including wire wrap guns, wrap tools, and wire handling solutions. The company also features a selection of gas-powered tools and fiber optic tools, ensuring comprehensive support for electrical projects.  We have 700GB of data at our disposal, in a week we will publish everything.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ameriprise-Financial-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30777</link>
<guid>9e9b3b34947bc8343f4f63f6e53ac7c4</guid>
<pubDate>Sun, 22 Mar 2026 21:09:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Ameriprise-Financial-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6bd722075878da0dba21ffaecda9ff8e22c5b5fdb1ac648c858e82a8124806e</i><br /><br />Threat actor <b>description</b>: <i>Salesforce records containing PII and over 200GB compressed Sharepoint internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinite-Campus-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30776</link>
<guid>f1a90e1c055459c26e3280c607f8fe5e</guid>
<pubDate>Sun, 22 Mar 2026 21:08:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Infinite-Campus-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>925cd163bc45e8d4451a168dd91dc1185a314c96aecfad44f1df80f232156de6</i><br /><br />Threat actor <b>description</b>: <i>Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Commercial-Real-Estate</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30773</link>
<guid>63fb561c81923bcdbb86140a1801305d</guid>
<pubDate>Sun, 22 Mar 2026 19:42:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Southern-Commercial-Real-Estate</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3088dcd26fa7c1e81eba749ff0e551a0ab32a75b45b92d99c86aa329c2737624</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southwire</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30774</link>
<guid>da58e2e4f4f6251d74b3a3fa11339e21</guid>
<pubDate>Sun, 22 Mar 2026 19:42:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Southwire</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e423382207e051cddd8cbdb0b23f651fc2380db6332273344ebc130c98360586</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>nPower-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30769</link>
<guid>6f31b4d25c2e143714d8f7d78bde7deb</guid>
<pubDate>Sun, 22 Mar 2026 18:42:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>nPower-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e66ea9f0fd5f1c8952757be995523615469a359e109df6d369105c1fa06e31b4</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elite-Limousine-Plus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30770</link>
<guid>20818537cc5cb1fe3dd50baf7c362808</guid>
<pubDate>Sun, 22 Mar 2026 18:42:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Elite-Limousine-Plus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb51776db14e50c6d1205b40b5dddfc3cc08f103fc62f0dba81e3778d96994ba</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phelps-Dunbar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30771</link>
<guid>9e550bb1034a12dea7d970c623dbd9e6</guid>
<pubDate>Sun, 22 Mar 2026 17:19:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Phelps-Dunbar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4f4c4e05b292b81ca8f77a5a20985a83def9e9db8b11d8b8606bc043156cf79</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1853 and headquartered in New Orleans, Louisiana, Phelps Dunbar is a law firm practicing in…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cannavative-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30767</link>
<guid>8b65e7a34bd7f333588177e3580aa7a9</guid>
<pubDate>Sun, 22 Mar 2026 15:01:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Cannavative-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f382933d768632f9179a5abd8119b8eada564aa7660fe22c31a1cbb5f2213a6</i><br /><br />Threat actor <b>description</b>: <i>- QuickBook Files- METRC DB-Employeement & Clients Documents</i><br />Target victim <b>website</b>: <i>www.cannavativegroup.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>breastcare.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30748</link>
<guid>c81779aa7f1a0eafd914ba5aea36416c</guid>
<pubDate>Sat, 21 Mar 2026 21:14:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>breastcare.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5dbf8705d852ff436019d4018de3c8a7e8ef30fb2404268d85a8aaec76e1a19a</i><br /><br />Threat actor <b>description</b>: <i>Dr. John G. West is a pioneering general surgeon who established Orange County&#039;s first breast c...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>irco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30737</link>
<guid>67a4b0f54d720a47e18a5c99ba191a06</guid>
<pubDate>Sat, 21 Mar 2026 18:05:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ALP-001</b> claims attack for <b>irco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1c40abcb8906a58bc7efff1b7513a05f0cb3fe44f12cd79360fb36b6c38c1d8</i><br /><br />Threat actor <b>description</b>: <i>Country: USA Revenue: $7.7 Billion Storage: 5.9 TB Ready: 5.9 TB
Deadline: 2026-03-29 17:41:30</i><br />Target victim <b>website</b>: <i>irco.com</i>]]></description>
<category>ALP-001</category>
</item>
<item xmlns:dc='ns:1'>
<title>Millerfoto</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30731</link>
<guid>b16f0d705b8c4fff87d26abff7c6d17a</guid>
<pubDate>Sat, 21 Mar 2026 16:37:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Millerfoto</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d33c0063add87d44a34a8b18ad1f3a6aa5e35d909e53688f927395023df0ef8</i><br /><br />Threat actor <b>description</b>: <i>Consumer Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edifice-Design--Architecture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30721</link>
<guid>ad6ef80344efaf6f632432640463941a</guid>
<pubDate>Fri, 20 Mar 2026 20:41:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Edifice-Design--Architecture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81e27ddc3edb0010493c8dd0d3599e54c5bfd92346c149beff9d1b431dc0c7ff</i><br /><br />Threat actor <b>description</b>: <i>We shape our buildings, and afterward our buildings shape us - Winston Churchill At Edifice, we believe architecture and design have a unique physical, spiritua...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Farese-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30722</link>
<guid>00becd45cce07f2cc996fc254f2fcfc0</guid>
<pubDate>Fri, 20 Mar 2026 20:41:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Farese-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfeb8f553d30f328b7ad74b75bb2ded6c8e833a1a4920f14eda67f0c7ad41d79</i><br /><br />Threat actor <b>description</b>: <i>The Farese Group specializes in retirement income planning, investment management, and financial planning, focusing on the distribution phase of retirement. Wit...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Savvy-Hawk</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30711</link>
<guid>5b768a6943e0867ed0a8825406908b91</guid>
<pubDate>Fri, 20 Mar 2026 16:41:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Savvy-Hawk</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e49279c8fe84c116b964c86ca8dc05d515af93bc15fb614d3f9929c8081f91e</i><br /><br />Threat actor <b>description</b>: <i>Savvy Hawk is a Miami-based IT service provider that specializes in business-focused communication solutions for small to enterprise-level clients. They offer services such as custom cloud solutions, data backup and recovery, and VoIP telephone services, all designed to enhance productivity and business continuity.We will upload 941gb of corporate data soon. Detailed employee personal information (passports, DLs, SSNs, medical records and so on), HR files, client's credit cards and other information, financials, contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>wardencc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30713</link>
<guid>0898bae5662b8c4a9cd8ea2db1fa7ee4</guid>
<pubDate>Fri, 20 Mar 2026 16:41:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>wardencc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b281364a3242e99610669f1e81faffd9715fd91824c03de3c30c8732ad825014</i><br /><br />Threat actor <b>description</b>: <i>Warden Construction is a general contractor based in Jacksonville, Florida, specializing in design-build, construction management, renovation, and new construct...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>odayequipment.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30714</link>
<guid>7b3678e568c812fa368f74671eaac799</guid>
<pubDate>Fri, 20 Mar 2026 16:41:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>odayequipment.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee8fb68bab7291a7b66a985e7d0c93b65e3292fbd48bc70dde0a20a114b40a16</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1935, ODay Equipment specializes in supplying and maintaining equipment for the oil and gas industry, serving customers in the U.S. Midwest.The compa...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>sopower.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30716</link>
<guid>fee6e6bfe55024e4ae92983d776ecd56</guid>
<pubDate>Fri, 20 Mar 2026 15:40:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>sopower.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8a29baf060554e70bb8c400c9ad3bd67dc169d66e6526aa971807355c5f0832</i><br /><br />Threat actor <b>description</b>: <i>industrial electrical service provider located in Baton Rouge, LA. Founded in 1994, it specializes in electrical testing, commissioning, maintenance, switchgear...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>centreconcrete.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30718</link>
<guid>5a7acc9324aeef65925024a66800c015</guid>
<pubDate>Fri, 20 Mar 2026 15:40:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>centreconcrete.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6dcebe6a8fdc7233cf99f8d928a62c2fcf1eb74de9929955b0b53e2f3aa04456</i><br /><br />Threat actor <b>description</b>: <i>Centre Concrete has been a leader in the production and delivery of ready-mix concrete in central Pennsylvania since 1956, operating seven production sites. The...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Matthews-Real-Estate-Investment-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30698</link>
<guid>5d599fc8f46d75efc30d93e0c500bf6f</guid>
<pubDate>Fri, 20 Mar 2026 11:42:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Matthews-Real-Estate-Investment-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d58d8287c05ce49fdd38b6eba5ce0404eb155875e84d5a279122c8a030a8cc0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Winmate-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30699</link>
<guid>34ce78b239697c8e7bacce545b6bdd02</guid>
<pubDate>Fri, 20 Mar 2026 11:42:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Winmate-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d990150f2a4c9e929bf0633da276249abe865d2e88f7dbb4c79540bfe819069f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Finance-of-America-Companies-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30701</link>
<guid>56bc2ffafe5268122fb8c00807dea91f</guid>
<pubDate>Fri, 20 Mar 2026 11:42:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Finance-of-America-Companies-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6b65cba5dfbfa43b63875d22f9c0863fb1d0ce28d2d2096d7ac48e63ff43294</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Los-Angeles-LA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30702</link>
<guid>c0bf581dc5c2abecaf2385d8845f0c91</guid>
<pubDate>Fri, 20 Mar 2026 11:42:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>City-of-Los-Angeles-LA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbb3bf6acfd195b352ea1ab32f39ccdf16bc2bf0c9bd54f84f3eca55c6cda0d1</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Town-of-Blacksburg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30703</link>
<guid>86113dc59e768c1d1a462f18a5d458a0</guid>
<pubDate>Fri, 20 Mar 2026 11:42:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Town-of-Blacksburg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0d803bd56cef1f76a0298e351eb395018e3f14632dced21f855f38344a8a5980</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pearce-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30704</link>
<guid>95d40515d78b92d75f485224d51a7ea6</guid>
<pubDate>Fri, 20 Mar 2026 11:42:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Pearce-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>120f246bf576c582b773076c16349db3ba90e37cf035b92ffdd34c1df00b1a3e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oriska-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30706</link>
<guid>af6e8730844faa627625a6c3fa98f0fc</guid>
<pubDate>Fri, 20 Mar 2026 11:09:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Oriska-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7502dcd0dc743b85d7f78149d5f84915de968f5e321a0160188f1b8fa1857704</i><br /><br />Threat actor <b>description</b>: <i>Oriska Insurance specializes in providing surety bonding, workers compensation, health insurance, and disability insurance tailored for small and minority-owned businesses. The company positions itself as a single source solution for multi-policy requirements, ensuring competitive pricing and comprehensive protection. With a commitment to reliability, Oriska Insurance has a track record of never failing to pay a claim or abandoning an employer. Their services are designed to help clients meet job requirements while staying within budget and legal constraints</i><br />Target victim <b>website</b>: <i>www.oriskainsurance.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Berkadia-Commercial-Mortgage-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30695</link>
<guid>5ed9dcf3d3d3dd8712866e81ddeaa03d</guid>
<pubDate>Fri, 20 Mar 2026 05:50:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Berkadia-Commercial-Mortgage-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c555ae073d05fcca6f11ba0383cdddc4f92d4f4fe19a4fe04eb5d0bb493ebca5</i><br /><br />Threat actor <b>description</b>: <i>Over 5M Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 22 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 19 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mercedes-Benz-of-Arlington</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30693</link>
<guid>eca85870ec8b6d70a888d143988d8a4b</guid>
<pubDate>Fri, 20 Mar 2026 00:46:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Mercedes-Benz-of-Arlington</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9bed772bdfca492f59518f72866e3db337c99fff22bb2f33ec1e6583854a7eb5</i><br /><br />Threat actor <b>description</b>: <i>Mercedes-Benz of Arlington is a premier dealership specializing in new and pre-owned Mercedes-Benz vehicles, offering a wide selection of luxury cars, SUVs, and...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accolend</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30689</link>
<guid>98d27eaef365d1710da5106ffbabf73c</guid>
<pubDate>Thu, 19 Mar 2026 20:45:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Accolend</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>938bb8719e74c5b7c5d9bcacfb774c139efece1298faeffdad8f7b7f1ff8a5a2</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>vatractor.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30687</link>
<guid>bd689c29167187a5b0a27f7be2c915b5</guid>
<pubDate>Thu, 19 Mar 2026 18:42:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>vatractor.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a2aa05906b168f96d52ab3bcac2bd2d0e83e0789be08057c1bdfe5d6c91a210</i><br /><br />Threat actor <b>description</b>: <i>Virginia Maryland Tractor specializes in John Deere equipment,  offering a wide selection of new and used machinery, financing options, parts, and service.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Angus-Young-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30686</link>
<guid>b3d2a9a2985c5a32c669cc33c885e6c8</guid>
<pubDate>Thu, 19 Mar 2026 16:49:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Angus-Young-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a9d501c1bd173f6a91f2060a283ee5b978351566b2b3b6398014dfd1de8e6ac</i><br /><br />Threat actor <b>description</b>: <i>Angus-Young is a full-service architectural, landscape architectu
re, engineering, and interior design firm that offers high-qualit
y design solutions, construction documentation, bid management, a
nd construction services. With over 60 years of experience, the f
irm collaborates on a diverse range of project types, ensuring in
formed decisions and integrated designs.

We will upload 50gb of corporate data soon. Employee personal inf
ormation (w9 forms, docs scans), HR data, financials, a bit of cl
ient data, contracts and agreements, projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Decorative-Paving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30683</link>
<guid>8b56c8b87edf9345d07cf9c20f418a1f</guid>
<pubDate>Thu, 19 Mar 2026 16:41:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Decorative-Paving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e4531f5a2ec7670933f3dbbc45a86798267c2b35c115dc74a7aa137f43d54f42</i><br /><br />Threat actor <b>description</b>: <i>Decorative Paving Company specializes in the manufacturing, installation, and distribution of high-quality paving systems. With over twenty years of experience, the company has established a strong international reputation for excellence in its services.We will upload 20gb of corporate data soon. Employee personal information (passports, DLs and other HR files), projects, financials and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Career-Adventures</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30684</link>
<guid>07c42ce3e98e0db4ff14b35b32d870a8</guid>
<pubDate>Thu, 19 Mar 2026 16:41:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Career-Adventures</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82610fb4c443d6b7855c2595e43ef0cfaadc149d71f43ad9038a1e0732c5fe8b</i><br /><br />Threat actor <b>description</b>: <i>Career Adventures, Inc is a leading employment agency in Shreveport and Bossier City, Louisiana, specializing in temporary and full-time staffing solutions for start-up manufacturing facilities. With over 30 years of experience, they provide tailored programs that enhance employee performance and reduce turnover.We will upload 8gb of corporate data soon. Employee personal information (passports, DLs and so on), lots of HR data, financials, a bit of client data, projects, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Onyx-Graphics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30676</link>
<guid>c56aa2102f060ad7471fbefe5e296c92</guid>
<pubDate>Thu, 19 Mar 2026 12:58:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Onyx-Graphics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e93b975a1295797605cf29d1457b7d60430382479335069573565c5841f1661</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Onyx Graphics is a technology company that specializes in developing software solutions for wide and grand-format digital color printers. Founded in 1989, the company's core products include Onyx production and RIP software that optimize output and provide end-to-end control for print applications. The company serves a global market through an extensive network of authorized resellers.</i><br />Target victim <b>website</b>: <i>onyxgfx.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petra-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30672</link>
<guid>2e904afa80a8ca949f187f64ff2d15b2</guid>
<pubDate>Thu, 19 Mar 2026 12:55:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Petra-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6523c8a1be6a636916d4bda8fcaa522d0cb0c0ed7ddbf5bc82f402b4bea1e7c3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Petra Industries is a leading wholesale distributor of consumer electronics, custom installation products, mobile audio/video accessories, and appliance connection supplies. Founded in 1985, it is based in Edmond, Oklahoma. Petra's goal is to provide the best ordering process, the best customer service, and the best delivery system to customers nationwide.</i><br />Target victim <b>website</b>: <i>petra.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Amerinational-Management-Services-AMS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30669</link>
<guid>9a3f34a2d6ad7dcd61c116f52e398d81</guid>
<pubDate>Thu, 19 Mar 2026 00:20:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Amerinational-Management-Services-AMS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5359b794d6308e8e234233fb4a91287347ab481fca155359490aecf46611f86</i><br /><br />Threat actor <b>description</b>: <i>Amerinational Management Services, Inc. specializes in providing comprehensive business solutions for martial arts schools, including marketing, software, and tuition management services. Their offerings encompass ATLAS Martial Arts Software, lead funnel websites, merchant accounts, and after school/summer camp programs. The company targets martial arts school owners looking to enhance their business operations and profitability. With over 40 years of experience, AMS is dedicated to helping martial arts professionals achieve their goals through effective management and marketing tools.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Construction-Equipment-Parts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30664</link>
<guid>253491938bb22e1044113ffca7e322ee</guid>
<pubDate>Wed, 18 Mar 2026 20:43:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Construction-Equipment-Parts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5f90fa8c35ef8dffd99c5010ec83bdf172fef2c8968ba7f0ac8a485ca98941a</i><br /><br />Threat actor <b>description</b>: <i>Construction Equipment Parts, LLC is a dismantler specializing in heavy equipment parts for various brands, including wheel loaders, excavators, and articulated...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>DynexRivett</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30665</link>
<guid>eaac424dcec03df14c2f5f946c128de4</guid>
<pubDate>Wed, 18 Mar 2026 19:42:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>DynexRivett</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3746273cec739afbab6648005c4b75bb142f8673bb97c39773eebd24abd1e85</i><br /><br />Threat actor <b>description</b>: <i>Dynex/Rivett Inc. specializes in high-pressure hydraulic components and systems, including piston pumps, power units, motors, and valves, designed for demanding...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Delta-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30668</link>
<guid>47026a9738cc32d4dab7475daa0c050d</guid>
<pubDate>Wed, 18 Mar 2026 19:16:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Delta-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>287dd868acd473aa7c42ee51a448aaad5f1bbaa08f72028e8f7da8166608c5a7</i><br /><br />Threat actor <b>description</b>: <i>Delta Manufacturing specializes in custom electric heating elements. They serve a variety of industries, including aerospace, medical, food, and chemical, ensuring fast turnaround of custom orders. However, they failed to prioritize security, resulting in the compromise of customer and employee data and contracts, as well as the exposure of all accounting records and invoices.</i><br />Target victim <b>website</b>: <i>deltamfg.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conrad-Capital-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30661</link>
<guid>cf37368a5897a76478650a7eea56cfc1</guid>
<pubDate>Wed, 18 Mar 2026 18:44:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Conrad-Capital-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a989a45740b87e01549407d4c01066de7ff36c22b2ab146af14d1b1b6c2876be</i><br /><br />Threat actor <b>description</b>: <i>(including customers personal information and financial data) Conrad Capital Management (CCM) is an independent Registered Investment Advisory firm that provide...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>loopcap.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30662</link>
<guid>1f3a4f7715b9fd855595b4836101ec30</guid>
<pubDate>Wed, 18 Mar 2026 17:32:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>loopcap.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c3c5b46ea9a1e5126414c42c902883ee323438c1ba64ac04ffa4ff78517a993</i><br /><br />Threat actor <b>description</b>: <i>We provided the management of Loop Capital with ample time and opportunity to protect their clients, their employees, and their shareholders. However, the company chose a path of total ignorance, opting for silence and bureaucratic delays instead of accountability.

For an investment firm of this ca…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/loop-capital-holdings-llc/70616391</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Family-Health-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30660</link>
<guid>9b35d1de15050fd1b8e1be886fe6f22b</guid>
<pubDate>Wed, 18 Mar 2026 16:16:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Valley-Family-Health-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33bc7a590615ad5575e95c85a57d9de5d0106413e51efd510c38e04b24a745db</i><br /><br />Threat actor <b>description</b>: <i>Valley Family Health Care is a Community Health Center offering medical, dental, behavioral health, and nutrition services. With 12 locations (including a mobile unit), they accept major insurances and provide income-based sliding fees to ensure accessible care.</i><br />Target victim <b>website</b>: <i>www.vfhc.org</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>BTX-Global-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30657</link>
<guid>b2e65e738c327d1a8c3c27092d00b6c1</guid>
<pubDate>Wed, 18 Mar 2026 15:45:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>BTX-Global-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42a2d1f18523d93a6011980b50cff5e7b058976bad73ffc8e55f70e2d7e32a7d</i><br /><br />Threat actor <b>description</b>: <i>Freight & Logistics Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elite-Flower</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30649</link>
<guid>58589b2f5ef1c0bbfdcd09c6fb0b47b7</guid>
<pubDate>Wed, 18 Mar 2026 14:44:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Elite-Flower</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>846d03b1f848a3105bcdccc1289d6449aae634dabb924a8013794633b496a028</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jacobs--Sons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30650</link>
<guid>33f68c58d409a7d8a1524d062a44b5d8</guid>
<pubDate>Wed, 18 Mar 2026 14:44:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jacobs--Sons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c732fddeec3f533ff6d7425acc39265fbfa1c03113510bc6b13f08a83ce39d0</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sievert-Electric-Service-and-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30651</link>
<guid>7663416bc80da19bd0bb21d16003b0f0</guid>
<pubDate>Wed, 18 Mar 2026 14:44:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sievert-Electric-Service-and-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>087607d2ce1a3e70aa314eed912db9fe416e6c6fcdf40eaf0ec3bb07d9a642bc</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>L-H-Lacy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30653</link>
<guid>2d69a2b7a27852c89b6bcafc83d1ec72</guid>
<pubDate>Wed, 18 Mar 2026 14:43:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>L-H-Lacy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24c11b1f145c8cfa93ea068ffa01da54fb080b00a4d0dfd1f579eb2f2ff1ad11</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rainbow-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30655</link>
<guid>0f7521a9b9e2084f08cf6adf4cdd8c21</guid>
<pubDate>Wed, 18 Mar 2026 14:43:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rainbow-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e4ea036dfb5de4c1a08c87cd480d51f44f4a7f17510d6da0d574cf4ab4ac4ae</i><br /><br />Threat actor <b>description</b>: <i>Rainbow Technology specializes in providing a wide range of products and services tailored for the utility and industrial markets,including safety items and specialty products. Their offerings include adhesives, sealants, cleaning supplies, personal protection equipment, and tools, aimed at delivering superior performance and value for money.We will upload corporate data soon. Employee passports and DLs and other information, HR files, financials, client information, credit card information, contracts and agreements, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Texollini</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30648</link>
<guid>80f36a558ab7295d37bc67fbb7737963</guid>
<pubDate>Wed, 18 Mar 2026 12:50:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Texollini</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79bff9f0919c69c190010fba5ba4a8626f386588edd7ea0b433b10ac0421d9ed</i><br /><br />Threat actor <b>description</b>: <i>Texollini is a textile manufacturer that combines fashion and tec
hnology to create innovative materials and advanced performance t
extiles. They offer a wide range of products including activewear
, athleisure wear, swimwear, and intimate apparel, catering to va
rious markets. 

We will upload 20gb of corporate data soon. Employee passports an
d DLs, medical records, HR forms, financial files, a bit of clien
t files, contracts and agreements, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Interpack-Northwest</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30639</link>
<guid>78d7ed505d7e3ea21b2479fa7c1503d8</guid>
<pubDate>Wed, 18 Mar 2026 00:52:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Interpack-Northwest</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b20578d8429e786c21dbcb320381ee3d44b77d8a3ea94e233fcef25b89447a8e</i><br /><br />Threat actor <b>description</b>: <i>Interpack Northwest Frozen Foods operates from Bainbridge Island, Washington, serving a diverse clientele ranging from small local businesses to large multinational corporations across North America and beyond. The company specializes in supplying frozen fruit, puree, and juice concentrates to various industries, including beverage, bakery, confectionary, jam/preserves, wine, marinades/toppings, snack foods, and dairy & ice cream. Interpack emphasizes the importance of connecting customers with suppliers, fostering open and cooperative communication between buyers and independent packers. This unique approach distinguishes Interpack as a broker in the frozen food market.</i><br />Target victim <b>website</b>: <i>www.interpacknorthwest.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wood-Smith-Henning--Berman-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30638</link>
<guid>71dd874ff78e42aa8050469380bea669</guid>
<pubDate>Wed, 18 Mar 2026 00:17:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Wood-Smith-Henning--Berman-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7236a9591ea9371eaadb1d520788b565115d9e5cc1869344db96fecf75a2c422</i><br /><br />Threat actor <b>description</b>: <i>Wood Smith Henning & Berman (WSHB) is renowned globally for our exceptional trial results and expertis…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fannin-CAD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30637</link>
<guid>7fbaa471e85a13aada114a4b1065215a</guid>
<pubDate>Tue, 17 Mar 2026 23:01:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>exitium</b> claims attack for <b>Fannin-CAD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64535726e90e78c4701a920504fd41f6d5eb30876e5689a3635f17eb0c7be124</i><br /><br />Threat actor <b>description</b>: <i>Zoominfo: https://www.zoominfo.com/pic/fannin-central-appraisal-district/1117264519

Exfiltrated: 400 GB of data</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>exitium</category>
</item>
<item xmlns:dc='ns:1'>
<title>---</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30634</link>
<guid>cb4342a6105501a33df7163f7c84bf26</guid>
<pubDate>Tue, 17 Mar 2026 22:38:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>---</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43af6034fcc0d9a049bc02c8aafa320ac582f3d4c6f1efedec1a6479c8746188</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services · South Carolina, United States</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>brookercg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30633</link>
<guid>4297ef5f39f4aeb86d80ec9744cd2990</guid>
<pubDate>Tue, 17 Mar 2026 20:22:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>brookercg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8729fb32050ae13dd0a4600831e8dbe8ea22b763c237cc9995517ead36b8154</i><br /><br />Threat actor <b>description</b>: <i>Is a privately held general contracting and construction management company headquartered in Chattanooga, Tennessee, United States. The firm specializes in …</i><br />Target victim <b>website</b>: <i>brookercg.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>briwaycarriers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30631</link>
<guid>682729665dc6ec09884880147d77fa1f</guid>
<pubDate>Tue, 17 Mar 2026 20:21:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>briwaycarriers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39fde2ae15ef2267671cd798178505d84342949c8400b7b8fd33989a1c4557f1</i><br /><br />Threat actor <b>description</b>: <i>Ontario-based transportation company specializing in specialized freight, including a dedicated glass division and agricultural services. They offer global supply chain …</i><br />Target victim <b>website</b>: <i>briwaycarriers.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>mattandsteve.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30630</link>
<guid>d7f79e4ae177cbfeb8cacea78283c327</guid>
<pubDate>Tue, 17 Mar 2026 20:20:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>mattandsteve.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>145a68dc9f492aaea6a90070e3fd324e836091336d62787be34ccc3f4c9c1934</i><br /><br />Threat actor <b>description</b>: <i>Is a Canadian food manufacturer based in Mississauga, Ontario, founded in 2000 by Matthew Larochelle and Steve McVicker. Known for …</i><br />Target victim <b>website</b>: <i>mattandsteve.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eco-Sound-Builders</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30628</link>
<guid>f9148ba9f7fe304fd171caff200636ab</guid>
<pubDate>Tue, 17 Mar 2026 18:52:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Eco-Sound-Builders</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30ea643a6cf676f2b2eb11185aeea0b1c7293033d843adf7bc543db219b38cbe</i><br /><br />Threat actor <b>description</b>: <i>EcoSound Builders, LLC specializes in crafting high-performance custom homes, focusing on both new constructions and renovations to enhance environmental responsibility. With decades of experience and a commitment to quality craftsmanship, they collaborate with clients to create sustainable homes that meet modern standards. Their services include building net-zero homes and historic remodels, utilizing traditional building principles alongside innovative conservation practices. The company aims to deliver exceptional results that ensure long-lasting performance and client satisfaction.</i><br />Target victim <b>website</b>: <i>www.ecosoundbuilders.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>McAfee-Tool--Die</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30627</link>
<guid>a59aff30810b066bbe31d1fae79596af</guid>
<pubDate>Tue, 17 Mar 2026 18:52:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>McAfee-Tool--Die</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eed07bdcf8fe5f43de1a345f2632a8070e1232c51d1bd7025c6188aef251c552</i><br /><br />Threat actor <b>description</b>: <i>McAfee Tool & Die, Inc. is a company specializing in the manufacturing of precision components through tool and die processes. They offer a variety of services including engineering, CNC machining, laser cutting, wire EDM, and stamping production. McAfee values customer relationships and aims to ensure project success through their comprehensive service offerings and technical expertise. Their intended clients are businesses seeking reliable and high-quality manufacturing solutions in various industries.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Teco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30626</link>
<guid>8385583a61497aa5d15857e068482a65</guid>
<pubDate>Tue, 17 Mar 2026 18:51:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Teco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>587bce10a020372f0b3f326e8303471cab5d451fbddadf7e1d2278d94c61b84b</i><br /><br />Threat actor <b>description</b>: <i>Teco HVAC, LLC is a full-service HVAC and plumbing company serving the Baltimore-Washington and Northern Virginia areas. They are dedicated to providing high-quality service and customer satisfaction, specializing in heating, cooling, and plumbing solutions. The company emphasizes quick and reliable service, ensuring that clients receive prompt assistance for their HVAC and plumbing needs. With a commitment to integrity, quality, and trust, Teco HVAC has been a trusted provider in the region since 2002.</i><br />Target victim <b>website</b>: <i>www.teco.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Knights-Site-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30625</link>
<guid>50f0a48e0c1f60f822f218c3e419d1a4</guid>
<pubDate>Tue, 17 Mar 2026 17:15:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Knights-Site-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8286a13e8981198cd7127c0d1530c5ccaef0209bcea25501604621e086140d9d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.knightsservices.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gsolutionz</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30624</link>
<guid>76b71cfebcc527cb7357246d9c4ff726</guid>
<pubDate>Tue, 17 Mar 2026 17:15:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Gsolutionz</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f62e75d49719eadf851a29b276828224d427c9a390cf733606bbcbc53da464ad</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gsolutionz.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shwapno</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30616</link>
<guid>dd813fde7c3bf5f3b947d7d401d8fba4</guid>
<pubDate>Tue, 17 Mar 2026 16:44:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shwapno</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1a8e37ccca847616d9edf14ea8da7908ea9153c05e6d82aff249902b2e3e0de</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bonanza-Casino</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30620</link>
<guid>8505785391a374b0d4f3b0e05b8f42c2</guid>
<pubDate>Tue, 17 Mar 2026 15:15:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Bonanza-Casino</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5999725464499d7daf9b58f11f04ca44f5d73b23872c156fd5c2816c49e9e30d</i><br /><br />Threat actor <b>description</b>: <i>Bonanza Casino is a vibrant entertainment venue in Reno that offers gaming, dining, and community-focused events. It features award-winning restaurants such as Cactus Creek Prime Steakhouse and Branding Iron Cafe, serving a variety of cuisines. The casino is dedicated to supporting local initiatives, including scholarships for students and fundraising for prostate cancer research. With a commitment to creating a fun and friendly atmosphere, Bonanza Casino aims to provide exceptional experiences for its guests. 
The company headquarters is located in 4720 North Virginia Street, Reno, Nevada 89506, United States.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>bestgraphics.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30612</link>
<guid>0b90a0b15fcbc6b66311f9ef1fed6c89</guid>
<pubDate>Tue, 17 Mar 2026 14:43:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>bestgraphics.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1299c75726baea0fddf602a4286127856fa4923762b61222c87d1eb855d57e3</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1977, Best Graphics Group offers a full range of equipment for printing, bookbinding, finishing, and packaging</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Solutions-Extreme-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30614</link>
<guid>cd6aef0440b5fb73723ba5d5819a5e84</guid>
<pubDate>Tue, 17 Mar 2026 13:44:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Solutions-Extreme-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56b79da3e408eca979628b3d7f2820f16dcb23ac9c50481bbc06852d2ae060c6</i><br /><br />Threat actor <b>description</b>: <i>Solutions Extreme is an IT services company that provides cloud computing, managed services, and business continuity solutions to help businesses maintain reliable operations and protect against data loss.</i><br />Target victim <b>website</b>: <i>solutionsextreme.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Passaic-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30613</link>
<guid>21c6d7a1fc87615fa44ae7657a773566</guid>
<pubDate>Tue, 17 Mar 2026 13:15:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Passaic-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1e4a3652e2f8c67f24e42a6226d970342486c309a99984ed12d0efa9a4ebf21</i><br /><br />Threat actor <b>description</b>: <i>Passaic County was created out of parts of Essex and Bergen Counties with the same legislation that created Atlantic County in 1837. Passaic County borders New York State on the north and is surrounded on the other sides by Sussex, Morris, Essex and Bergen counties in New Jersey. Passaic County has 186 square miles of land area, making it the 18th in size among New Jerseys counties. On the basis of population, it ranks as the 9th most populous county in New Jersey. The 2020 Decennial Census estimated the population of Passaic County to be 524,118. Passaic County is shaped like a bent hourglass with the area above the neck running generally north and south and the portion below, east to west. The upper half of Passaic County is characterized by large lakes and watershed areas with low-density development. The lower half of Passaic County contains more than 85% of the population in a third of the area. Passaic County has 16 municipalities. 
The company headquarters is located in 401 Grand Street, Paterson, NJ 07505, United States.
1K - 5K Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cape-May-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30609</link>
<guid>32153e1da6193298c513fbac96c77241</guid>
<pubDate>Tue, 17 Mar 2026 12:15:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Cape-May-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>18d2701bba4fbc88d2fc95069cde8a7022267af7cb339ab7de817eaa096bc03b</i><br /><br />Threat actor <b>description</b>: <i>Cape May County Government is the official governing body of Cape May County, located in New Jersey. It is responsible for managing public services, infrastructure, and administrative operations for county residents and businesses. The government oversees departments such as public safety, corrections, health and human services, public works, and emergency management. It also manages county facilities, parks, transportation systems, and social service programs. Led by elected commissioners and constitutional officers, the organization works to ensure community development, regulatory compliance, and fiscal responsibility while supporting economic growth, tourism, and quality of life across the county. 
The company headquarters is located in 4 Moore Road, Cape May Court House, New Jersey 08210, USA.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lehigh-Carbon-Community-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30610</link>
<guid>b757aa8b4d5f403e9c6c0a50a8cef71f</guid>
<pubDate>Tue, 17 Mar 2026 12:15:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Lehigh-Carbon-Community-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e646ed61e4475240413fa306fdff69f262158ad261061ea450fb2f444faa9a9</i><br /><br />Threat actor <b>description</b>: <i>Lehigh Carbon Community College provides affordable, quality education through both online and in-person formats across multiple campuses in Lehigh and Carbon Counties. The college offers over 90 programs, including associate degrees, workforce certificates, ESL, and GED courses, catering to a diverse range of academic and professional goals. LCCC aims to support students in achieving their educational aspirations and career development, with resources for financial aid and transfer opportunities to four-year institutions. The intended clients include local residents seeking higher education, workforce training, and English language learning support. 
The company headquarters is located in 4525 Education Park Drive, Schnecksville, PA 18078, United States.
201-500 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Noll-and-Tam-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30605</link>
<guid>eb6ee4b36cdf23e8167e10a47e340fed</guid>
<pubDate>Tue, 17 Mar 2026 00:20:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Noll-and-Tam-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25f2c0bd2cf1d3d7ed8db69a8febe24ad18a4620520f695f6c0d3a13744503a8</i><br /><br />Threat actor <b>description</b>: <i>Noll &amp;amp; Tam Architects specializes in creating innovative architectural designs that serve the common good. Their projects range from community centers and libraries to veterinary hospitals and educational facilities, emphasizing sustainability and empathy in their approach.
</i><br />Target victim <b>website</b>: <i>www.nollandtam.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Von-Weise-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30604</link>
<guid>7c9d8efa5f0fc84385730c20b6a569e3</guid>
<pubDate>Mon, 16 Mar 2026 22:45:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Von-Weise-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87d2375b3ef61098f30654a1eefea2c48e80c887ed57b938a5e4c9c4a4dd7941</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>mcquaidinjurylaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30602</link>
<guid>0c2b52a946ce2657e1af75ee6cb84898</guid>
<pubDate>Mon, 16 Mar 2026 20:35:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>mcquaidinjurylaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b34cc1450e7113ffcae820b6cc079d02618de29f301ce140a32071d2863c71c</i><br /><br />Threat actor <b>description</b>: <i>Get justice with McQuaid Injury Law. No fees until we win your case in Denver and Phoenix. Your recovery is our priority.</i><br />Target victim <b>website</b>: <i>mcquaidinjurylaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Singleton-Schreiber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30601</link>
<guid>755945a59ff256394631b079277ab8bc</guid>
<pubDate>Mon, 16 Mar 2026 20:23:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Singleton-Schreiber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b940c44632001ca07e40f31255cc39e588b8b536afe6c31b0d71d71555a205e</i><br /><br />Threat actor <b>description</b>: <i>This page contains attorney advertising. Singleton Schreiber fight for regular people who have been ha…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>PINNACLE-TAX-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30599</link>
<guid>33bd495470ddcf80911ca403ad6e3dd6</guid>
<pubDate>Mon, 16 Mar 2026 18:42:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PINNACLE-TAX-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0571800ff07fa7a43eb3a07e4118e2b137ae0f06c1e2779b4d0d79ffba6cd2d6</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>frazercenter.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30600</link>
<guid>8cbf1695be0572428dbb70f41f833783</guid>
<pubDate>Mon, 16 Mar 2026 17:34:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>frazercenter.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d83e495608c012f41044bd8384f0f8ab05aa8cead5964d26efc013135a5940d7</i><br /><br />Threat actor <b>description</b>: <i>Frazer Center is a non-profit organization dedicated to supporting children and adults with developmental disabilities. Their services include a Child Development Program for children aged six weeks to five years and an Adult Program that offers individualized programming for those with intellectual disabilities. The center aims to foster learning, social opportunities, and lasting friendships for all participants. Located in Atlanta, Georgia, they welcome donations and volunteers to support their mission. Employees: 200 Revenue: $9.7 Million Industry: Education Phone Number: (404) 377-3836</i><br />Target victim <b>website</b>: <i>frazercenter.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tax--Accounting-Plus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30597</link>
<guid>ca66c4195dbebc6f59ceaf0e10629664</guid>
<pubDate>Mon, 16 Mar 2026 16:41:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Tax--Accounting-Plus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06c17539dc84e724aac925aee9e86450cf09c01d53b5f7f256396b12cfb0558e</i><br /><br />Threat actor <b>description</b>: <i>Tax & Accounting Plus, Inc. offers a range of personal and professional tax and accounting services with a focus on a low-pressureapproach. The firm prides itself on its high client-retention rate and the quality of its services. They provide various resources, including financial calculators and tax-related guides, to assist clients.We will upload 85gb of corporate data soon. Great amount of clients' and employees personal documents (scanned passports, DLs, SSNs, medical records and so on), contracts and agreements, detailedfinancials, NDAs, partners files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Steve-Quick-Jeweler</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30598</link>
<guid>6fb41c898918ad5a0df0e50f3790f057</guid>
<pubDate>Mon, 16 Mar 2026 15:53:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Steve-Quick-Jeweler</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4901b95cd99de9bdc0cf4772fa04896b65f7c99fb77e909e2fe9e465c5045867</i><br /><br />Threat actor <b>description</b>: <i>Steve Quick Jeweler is a Chicagoland-based jeweler that has been 
offering unique, handcrafted jewelry since 1986. They specialize 
in engagement rings, wedding bands, and a variety of other jewelr
y pieces, ensuring a personalized shopping experience for their c
ustomers.

We will upload corporate data soon. HR files, financials, client 
files, contracts, NDAs, partners files and and other business fil
es.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Broadway-National</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30596</link>
<guid>ad627bf5fd6966693e97a7349d85589c</guid>
<pubDate>Mon, 16 Mar 2026 14:28:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Broadway-National</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3abd4056a95099c133eef345c8285d520815a2785779b6a79386cdb982b9ffc</i><br /><br />Threat actor <b>description</b>: <i>Broadway National is a service provider for big box retailers, re
staurants, and bank industries. They are located in Hauppauge, Ne
w York.

We will upload corporate data soon. Lots of HR files and employee
information, clients information, financials, contracts and agre
ements, drawings, projects, NDA and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Caribbean-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30594</link>
<guid>397dcbbb8a93272b66300d4126b4f9e9</guid>
<pubDate>Mon, 16 Mar 2026 13:51:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Caribbean-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c9a5a9492689d5c941eaf9700c6d0ace84353458a665a06fc2a4e3fb47ecba4</i><br /><br />Threat actor <b>description</b>: <i>www.caribbeanmedicalcenter.com https://www.zoominfo.com/c/caribbean-medical-center/402918703 Hospital Caribbean Medical Center provides emergency services and inpatient care, catering to pediatric, adult, and geriatric patients. The emergency room operates 24/7, ensuring continuous medical coverage tailored to patient needs. The facility offers a range of specialized services, including internal medicine, infectious diseases, cardiology, radiology, obstetrics and gynecology, pediatrics, and surgery. With a commitment to exceptional medical care, the center emphasizes quality and patient satisfaction. Last chance before full data disclosure.</i><br />Target victim <b>website</b>: <i>www.caribbeanmedicalcenter.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ruhnau-Clarke</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30584</link>
<guid>d82815d548d98ff14d95120eef2e6a3c</guid>
<pubDate>Mon, 16 Mar 2026 12:43:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ruhnau-Clarke</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0217f5a553aea8d9be74861a7fdf8c1e355cad585f6403f1c5dc9206cadb4d34</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Executive-Aviation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30580</link>
<guid>607f81b73375b618f549c6c8692c4e88</guid>
<pubDate>Sun, 15 Mar 2026 19:42:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Executive-Aviation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6bf2e67debe69ea0fd56369a8484ccd2a6a9f94430fb3d12a2318a318d2d8e2b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.executive-aviation.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evaluate-a-Norstella-company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30579</link>
<guid>918b71f2ac42210cfae2f82b777c1f27</guid>
<pubDate>Sun, 15 Mar 2026 17:38:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Evaluate-a-Norstella-company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eabfcd23ddc593be0b325a5f9dcd77c2faeffcbdf62ca35396b752c46d2445fe</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aura-Group-Inc.-aura.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30575</link>
<guid>315b1acf4b02f647bee12e61eff66c05</guid>
<pubDate>Sun, 15 Mar 2026 09:23:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Aura-Group-Inc.-aura.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9acf2951eede900647585302cc52f20deb9d13898cecd9a873d2825fe3b0280</i><br /><br />Threat actor <b>description</b>: <i>Over 2M records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care. | Size: 12GB (compressed) | Updated: 15 Mar 2026 | SHA256: 0d5bf85c7865b023266adc95a7449dd1bff6b208b4634976441ce5ee650894d0</i><br />Target victim <b>website</b>: <i>aura.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Private-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30574</link>
<guid>7c693e489c92c0c82ad4c5c7dca411d8</guid>
<pubDate>Sun, 15 Mar 2026 09:19:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Private-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33468a5250d150b38d4e854ac817d4ecfd11a4712c1fc2b29860d27517432d58</i><br /><br />Threat actor <b>description</b>: <i>New Jersey Private University</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>ILLUMINA---Data-uploaded</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30572</link>
<guid>cb1e16cc03588ff5bf4dd506f5f54cc1</guid>
<pubDate>Sun, 15 Mar 2026 02:10:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>ILLUMINA---Data-uploaded</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca857a883b709b838aae161dedb8029e3e03021880eb9d932152f5b659d1fe7f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Illumina Inc. is a leading global genomics company, focused on the development of innovative sequencing and array technologies. With their high-throughput sequencing and genotyping services, Illumina enables researchers from various fields to understand genetic variation and function effectively. The data uploaded by the company relates to these genetic studies and research outcomes.</i><br />Target victim <b>website</b>: <i>illumina.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Augenomics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30570</link>
<guid>e265b71426b39bb25ccf6eca0a578a03</guid>
<pubDate>Sun, 15 Mar 2026 02:08:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Augenomics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04643f8200728f2ef2f811142d256dce287dfa02154a762687baf0f1d93b8a39</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "Augenomics" is a pioneering healthcare technology company. It uses Artificial Intelligence (AI) and genomics to transform how diseases are diagnosed and managed. Its advanced predictive models disentangle complex bio-information, enabling personalized therapeutic strategies and improving patient outcomes.</i><br />Target victim <b>website</b>: <i>autogenomics.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>nChroma-Bio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30569</link>
<guid>2c61f304e5c71379e0af1cd15197a96e</guid>
<pubDate>Sun, 15 Mar 2026 02:08:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>nChroma-Bio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0c15096c0b94697242500c3957a2e7a61b042b69967c56bd39a57824af675c5</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] nChroma Bio is a biotechnology company that specializes in metabolomics and synthetic biology. They use innovative technology to engineer microbes for the production of valuable chemical products in various markets, such as pharmaceuticals, food additives, and biofuels. Their goal is to develop sustainable, cost-effective methods to produce these chemicals, while minimizing environmental impact.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Geno-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30568</link>
<guid>7f29f58980570546b1ae814455bdcc31</guid>
<pubDate>Sun, 15 Mar 2026 02:08:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Geno-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a064abb4632bae4d9e80c4ebd72742f2474418d03375776b78c323e5032eed1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] GenoBank.io is a company that provides a secure platform for DNA data storage and transfer, prioritizing privacy and user control. Their blockchain-based system aims to build trust among customers while enabling them to access personalized medical, ancestry, or lifestyle recommendations.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neochromosome</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30567</link>
<guid>fa1dcf25e93feabd8335f5d20bff7172</guid>
<pubDate>Sun, 15 Mar 2026 02:07:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Neochromosome</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a87d933e448bc36888ed28e5471c16088d4945a182f2b5b1a773793653556f11</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Neochromosome is a bio-tech startup and a synthetic biology company based in San Francisco, California. Their primary focus is on designing and constructing synthetic chromosomes, which could find applications in various industries. The company utilizes machine learning to design synthetic chromosomes, with a vision of building transformative synthetic biology systems that can solve global challenges.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tyler-Media</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30558</link>
<guid>cfc654d4f929d2d23ed18e061daa90f6</guid>
<pubDate>Sat, 14 Mar 2026 20:37:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payload</b> claims attack for <b>Tyler-Media</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>50a31d664d3f187058a309f30abd3ad476fab4a0f920a357d87f3398352c9cad</i><br /><br />Threat actor <b>description</b>: <i>Tyler Media is a comprehensive media company in Oklahoma, offering a variety of services that include radio, television, and outdoor advertising. With several radio stations and partnerships with prominent television networks, they cater to a diverse audience, showcasing both English and Spanish content. Their key clients range from local businesses to larger organizations seeking effective marketing solutions and brand awareness.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>payload</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trinity-Catholic-High-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30554</link>
<guid>f811fcdc741bd7a5403aabf55e041d1e</guid>
<pubDate>Sat, 14 Mar 2026 12:31:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Trinity-Catholic-High-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f8297b112c2039d1401101ea7abd59b3cd8da3c0962830d61626816c710f010</i><br /><br />Threat actor <b>description</b>: <i>Trinity Catholic High School offers a full array of co-curricular activities and sports programs. Our athletic programs include football, cheerleading, cross country, golf, swimming, tennis, weight lifting, basketball, volleyball, baseball, bowling, girls flag football, softball, lacrosse and track and field. Our State Championships include: football, women's soccer, baseball, wrestling and track.</i><br />Target victim <b>website</b>: <i>www.trinitycatholichs.org</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mid-America-Export-Experts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30551</link>
<guid>614a24f6c582e220ada177041bab94fa</guid>
<pubDate>Sat, 14 Mar 2026 07:13:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Mid-America-Export-Experts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f639355b8c09bca4a9a7f7f1bf8dd9d6cac102db7fd0875f9257967ce9d24aa</i><br /><br />Threat actor <b>description</b>: <i>Mid-America experts is an organizations that provide support to organizations exporting goods in the MidWest USA. They work with many transportation and logistics providers with strong presence in the Midwest.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Duffys-Sports-Grill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30548</link>
<guid>a2cb4cbee5d6634c4c73ab1e333b3772</guid>
<pubDate>Sat, 14 Mar 2026 06:41:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Duffys-Sports-Grill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0eb139b2cfa9495c86fa4b6739326886960d5cf154c4bd0e8da8e4860f48fc3c</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.integer.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30546</link>
<guid>37107d39373c202221d6672722f514cf</guid>
<pubDate>Fri, 13 Mar 2026 18:41:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.integer.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>359c1ca3d8da0d76def414fe87ef158a6308181b9a5c8640d9be16b7c01c9197</i><br /><br />Threat actor <b>description</b>: <i>Integer® Holdings Corporation (NYSE:ITGR) is one of the largest medical device outsource (MDO) manufacturers in the world serving the cardiac, neuromodulation, vascular and portable medical markets. The company provides innovative, high-quality technologies and manufacturing to Medical Device OEMs to enhance the lives of patients worldwide. In addition, it develops batteries for high-end niche applications in energy, military, and environmental markets. Greatbatch Medical®, Lake Region Medical® and Electrochem® comprise the companys brands. Our story is one filled with 80 years of industry-changing innovations and exemplary manufacturing. Its a legacy we are proud of as we continue to provide customers with unparalleled expertise, innovation and manufacturing excellence. We are guided by our values of Innovation, Collaboration, Inclusion, Candor, Integrity and Customer.</i><br />Target victim <b>website</b>: <i>www.integer.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>KLA-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30544</link>
<guid>9fee6abfcc2bc7fed8f66f3fbb5c4d07</guid>
<pubDate>Fri, 13 Mar 2026 18:32:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>KLA-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55a6f72d76cb8ea83d6d28dedcd83df98007735502a572326b3c832a9f7a155c</i><br /><br />Threat actor <b>description</b>: <i>How a single data breach exposed contracts, credentials, and critical infrastructure details.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alarmco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30539</link>
<guid>5b16eb4fe129666677e683ee4594ae38</guid>
<pubDate>Fri, 13 Mar 2026 16:41:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alarmco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d370491bc1dcb8972581bc6f95bf3c37a93b3bd1e9a4e8acbfed76f9d2a6ec1</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>FMRS-Health-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30541</link>
<guid>43900cc8434685fe6937a619d4246be5</guid>
<pubDate>Fri, 13 Mar 2026 15:43:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>FMRS-Health-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79f1d33ddba61746cfb065ad15b1ffb03728227c5f927a42e4d90a4207780c3e</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wills-Point-Chevrolet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30542</link>
<guid>79c512312810d47d64a72e7b7a97789d</guid>
<pubDate>Fri, 13 Mar 2026 15:33:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wills-Point-Chevrolet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>192b6efa29b6ea016dc782ac337a473f6620b0fc751060291557576b9c4fc056</i><br /><br />Threat actor <b>description</b>: <i>Wills Point Chevrolet is a dealership located in Wills Point, Tex
as, serving clients from Forney, Mineola, and Terrell. They offer
a wide selection of new and pre-owned Chevrolet vehicles, includ
ing electric models, along with financing options and certified s
ervice.

We will upload corporate data soon. Lots of scanned personal empl
oyee docs (passports, Dls, w9 forms, bank statements and other do
cs), financials, various agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Millard-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30538</link>
<guid>a768922976dd05cd372dde028932ad91</guid>
<pubDate>Fri, 13 Mar 2026 14:44:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Millard-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4aa728b5a1fe4e0e335f70fc3e7e0fc3dd5d5610b686f52b5a152ec5041c5c89</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>atrium.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30514</link>
<guid>a874ab8ce08044d1637a5be4d8b096f9</guid>
<pubDate>Fri, 13 Mar 2026 12:23:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>atrium.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>112c5aaf49f99fe43b218c6ac69442bba65a2bd9297dc94f7a568416a99a1ab0</i><br /><br />Threat actor <b>description</b>: <i>Since 1946 Atrium Windows and Doors has produced tens of millions of exceptional products throughout...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>elmwoodhomecare.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30523</link>
<guid>d613ca9ece1fec54ec026f15b9a000b2</guid>
<pubDate>Fri, 13 Mar 2026 12:23:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>elmwoodhomecare.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>256a713791974a49b36a44d270ce06a23953f64741b2749488191da338964f7b</i><br /><br />Threat actor <b>description</b>: <i>Elmwood Healthcare is a Medicare certified, nationally accredited home-based care organization opera...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>townoforangeva.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30524</link>
<guid>a1d053a71264ae005d047b2a7a14efae</guid>
<pubDate>Fri, 13 Mar 2026 12:23:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>townoforangeva.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4eb6145323f2c0b251905af17105fca1094fa29447052309d8c6927f75132f1</i><br /><br />Threat actor <b>description</b>: <i>The Town of Orange, Virginia, is the seat of Orange County and serves as its business center, offeri...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>pkmsteel.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30525</link>
<guid>fffe9f664c2ddba4a37bcd35936c7422</guid>
<pubDate>Fri, 13 Mar 2026 12:23:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>pkmsteel.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8844b019d4087ef69ade8ba32dd1d9e2b729ae0c150fcd97062cefd023ed2173</i><br /><br />Threat actor <b>description</b>: <i>PKM Steel Service, Inc. is a global producer of heavy and intermediate structural steel, specializin...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>ikron.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30528</link>
<guid>bf3b50067c565f050a653d29f443ccf8</guid>
<pubDate>Fri, 13 Mar 2026 12:23:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>ikron.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59282675a21e94050465255fb0261dd221490de9a873b93e8077699b1bb12034</i><br /><br />Threat actor <b>description</b>: <i>IKRON (Integration of Knowledge and Resources for Occupational Needs) was founded in 1969 as the Uni...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>webster-schools.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30529</link>
<guid>402b557b7f364abc0ac961e1dda262cd</guid>
<pubDate>Fri, 13 Mar 2026 12:23:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>webster-schools.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0461e6b7ff6a933585fd2f66ef1d3df20dca36d3e187ff6829d637f46158cb5</i><br /><br />Threat actor <b>description</b>: <i>Webster Public Schools is a company that employs 250 to 499 people and has 10M to 25M of revenue. Th...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>alcornschools.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30533</link>
<guid>f624e6558a372d9cdd49406b1a8eaf6c</guid>
<pubDate>Fri, 13 Mar 2026 12:23:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>alcornschools.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35488276366e54b2547b654e9e4eb1ab30f542de033089126a84c4067a2afb96</i><br /><br />Threat actor <b>description</b>: <i>Alcorn School District is dedicated to fostering a safe and positive learning environment that promo...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>frasierlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30534</link>
<guid>cb6e4ab9086bdc74d116e31e79f4eb9c</guid>
<pubDate>Fri, 13 Mar 2026 12:23:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>frasierlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45f4a0b8555f1b22619f125488d97825ca67e4bceb6ea4af722764fa448b6035</i><br /><br />Threat actor <b>description</b>: <i>Frasier, Frasier & Hickman, LLP is a law firm based in Tulsa, Oklahoma, founded in 1952, dedicated t...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>cognitivehealthit.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30535</link>
<guid>97beec5643d7199a4c74875b33aebb31</guid>
<pubDate>Fri, 13 Mar 2026 12:23:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>cognitivehealthit.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>468012d919ea1beee04417aecfad9a5027b00c00012294ad726048c04634ccaf</i><br /><br />Threat actor <b>description</b>: <i>CognitiveHealth Technologies develops and deploys iCAN, a platform purpose-built for healthcare by e...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>phoenixlabs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30511</link>
<guid>febb75eccd1101d84a2aa5eb87859ce0</guid>
<pubDate>Fri, 13 Mar 2026 09:43:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>phoenixlabs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8b5fd9c73dfde116c7380847cdb59ae958d3066c3a8129e443ac392bd36ff03</i><br /><br />Threat actor <b>description</b>: <i>Phoenix Environmental Laboratories specializes in high-quality analysis of soil, water, air, sediment, and solids, complying with EPA, state environmental prote...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Fabian-Catholic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30505</link>
<guid>0b5f533ccd0dc1c08ef24364cc70a0eb</guid>
<pubDate>Thu, 12 Mar 2026 22:12:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>St-Fabian-Catholic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>003f643d38645ed0e5016a899d37e08354173cd06c83f8b9b1e72c6ae48a8600</i><br /><br />Threat actor <b>description</b>: <i>stfabian.org zoominfo.com/c/st-fabian-catholic-church--school/152879338 St. Fabian Catholic Church and School in Farmington Hills, MI offers a range of religious services and educational programs. Their services include various sacraments such as Baptism, Confirmation, and Eucharist, along with community involvement through worship and youth ministries. They aim to provide a welcoming environment for parishioners and students, encouraging participation and growth within the church community. The intended clients are families and individuals seeking spiritual guidance and quality education in a Catholic setting</i><br />Target victim <b>website</b>: <i>stfabian.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Syed-Professional-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30503</link>
<guid>b899aa15c56fee62bcea0903b59b18fe</guid>
<pubDate>Thu, 12 Mar 2026 19:42:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Syed-Professional-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d49ef60e21345b3bd8ee9e26e94217633e49b8b03cc3dd3c486244f2a9707e0</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TDS-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30496</link>
<guid>471c96afb06d58297ee23ae23d6e18fd</guid>
<pubDate>Thu, 12 Mar 2026 18:41:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TDS-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>532c89a63d51280f5a87960c30336e10cd0e49bdcb74487dc8702dd2e7b52a00</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Silvon-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30497</link>
<guid>c74305e736bb51926e0f568d7ae72545</guid>
<pubDate>Thu, 12 Mar 2026 18:41:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Silvon-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d3c855d61517fcb002278eae616279238fab74b16aeec71e387e9d1a9b3ec47</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Financial-Brokerage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30498</link>
<guid>4504a21322621ea6e8b2af2f6564e81a</guid>
<pubDate>Thu, 12 Mar 2026 17:43:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Financial-Brokerage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>343bd753ed7eaccbd9dc6cddf0b7b4854bd5bf3308834c597a264c0d8d2bf8de</i><br /><br />Threat actor <b>description</b>: <i>Financial Brokerage Inc. collaborates with top insurance carriersto provide a variety of financial products including Life Insurance, Fixed Annuities, Long Term Care, Disability Insurance, and Medicare Supplement plans. The company targets insurance agents and brokers looking to enhance their product offerings and client services.We will upload corporate data soon. Employee personal documents, detailed personal information of hundreds clients and companies, confidential financial and other docs of their clients, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Circle-Floors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30501</link>
<guid>443fbc49b4ab9988d64065d7e2fddf1a</guid>
<pubDate>Thu, 12 Mar 2026 17:37:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Circle-Floors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61a8156bebfbfa3aebd12587e2888f66a2fc0e9e96483e78d27a5b82f58a39f0</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.circlefloors.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eagle-Industrial-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30500</link>
<guid>62081c7c52ec30c556d6c558896983ee</guid>
<pubDate>Thu, 12 Mar 2026 17:36:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Eagle-Industrial-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>839bd68be43e55185e6cb3e721c003a1a48cbfc669cb2b92052ec4b890572968</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.eagleie.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>flad.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30499</link>
<guid>2a305437dff38f3b83f52900567a91ed</guid>
<pubDate>Thu, 12 Mar 2026 16:52:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>flad.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08514bbcb9cf27a3d86fe1eadeeadbdb15a133f991b4eb38fbe081c99d318fc1</i><br /><br />Threat actor <b>description</b>: <i>We are announcing a major security breach and data exfiltration from Flad Architects, a leading national firm specializing in high-stakes science and technology infrastructure.

Total volume of exfiltrated data: Over 2.2 TB

The leaked archive includes critical and sensitive information across the f…</i><br />Target victim <b>website</b>: <i>flad.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Extreme-Trailers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30493</link>
<guid>7dd9884b559f0344c9254ce81e001ae4</guid>
<pubDate>Thu, 12 Mar 2026 16:42:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Extreme-Trailers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>92f8c0b68a12d970b45e10075941cae07af589ed1768a717c4e367db492107f4</i><br /><br />Threat actor <b>description</b>: <i>Extreme Trailers, LLC is located in Dover, Ohio and is a leader in innovative design and high-quality manufacturing of equipment for the flatbed trailer market. Established in 2016 in Dover, Ohio, the company manufactures a diverse range of products, including: an innovative, patent-pending design trademarked as the X-Lite flatbed trailer, aluminum drop deck trailers, aluminum and customdesigns.We will upload 15gb of corporate data soon. Lots of employee scanned docs (passports, DLs, SSNs, w9, i9 forms, medical informationfor a few dozens of people), project docs contracts and agreements, a bit of client information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-of-Mississippi-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30489</link>
<guid>c70370bf064170a05f1e3e95de3ea26f</guid>
<pubDate>Thu, 12 Mar 2026 13:47:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>University-of-Mississippi-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44e2201930adb20609e3ffda2b5f2329bd55a1c26c9bcced9aab8b8b92778d93</i><br /><br />Threat actor <b>description</b>: <i>The University of Mississippi School of Medicine (UMSOM) is the medical school of the University of Mississippi in the U.S. state of Mississippi. The UMSOM was created in 1903 on the Oxford campus. In 1955, it was moved from the Oxford campus to the state capital of Jackson and was expanded to include the third and fourth years of training. The University of Mississippi Medical Center, the health sciences campus of the University of Mississippi, houses the School of Medicine. As of 2006, there were 413 students enrolled in UMSOM. This includes students enrolled in the four-year M.D. program as well as students enrolled in the seven-year M.D./Ph.D program. 
The company headquarters is located in 2500 North State Street, Jackson, Mississippi 39216, United States.
5K - 10K Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>AbelZeta</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30483</link>
<guid>fb22fb2b63ebd0f8261cbfc4809cd152</guid>
<pubDate>Thu, 12 Mar 2026 06:40:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>AbelZeta</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1edf494474fe46deb447c53a7ad8366577116bbce030c4d8164e610f2e4bef2</i><br /><br />Threat actor <b>description</b>: <i>AbelZeta Pharma is a global cell therapy leader focused on discovering, developing and manufacturing therapeutics to address unmet medical needs across hematologic malignancies, inflammatory and immunological diseases and solid tumors.Partners: AstraZeneca, Janssen (J&J), NovartisInvestors: HSG, Yunfeng Capital, GIC, TF Capital, CICC Capital, Sailing Capital, Dangdai Group, AstraZeneca-CICC Fund170,000+ different files670+ separate archives with experiments on various candidates All studies: CAR032, CAR39, CAR66, CAR168, TIL, CD, Tcell, etc. There are a huge number of files and studies, all of which are confidential and valuable for competitive research. https://www.abelzeta.com/</i><br />Target victim <b>website</b>: <i>www.abelzeta.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aura-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30481</link>
<guid>1e3e117ae63d39e67bf9f008bb122a6f</guid>
<pubDate>Thu, 12 Mar 2026 00:04:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Aura-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e67b8183d1d242c21e6a5127f7cb29bf5f2b2189f7f5e2b895194096f2c1b649</i><br /><br />Threat actor <b>description</b>: <i>Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 14 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stryker-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30476</link>
<guid>b53c87a7be4dc51411e59867566d1c71</guid>
<pubDate>Wed, 11 Mar 2026 20:14:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>handala</b> claims attack for <b>Stryker-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>296488dac801eef2ae9269afa8e5636669d1e233dc904e3550bb336fa2b10326</i><br /><br />Threat actor <b>description</b>: <i>We announce to the world that, in retaliation for the brutal attack on the Minab school and in response to ongoing cyber assaults against the infrastructure of the Axis of Resistance, our major cyber operation has been executed with complete success. The Zionist-rooted corporation, Stryker, one of the key arms of the global Zionist lobby…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>handala</category>
</item>
<item xmlns:dc='ns:1'>
<title>Staples</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30472</link>
<guid>4da79a45c5e5c96760be4d8673c0aefd</guid>
<pubDate>Wed, 11 Mar 2026 20:07:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Staples</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1de5ba03534447e8a59e611aed4c9614517a1c1180602f542a561a77d8084b1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Staples, Inc. is an American office retail company primarily involved in the sale of office supplies and related products through retail channels and business-to-business (B2B) oriented delivery operations. Its offerings include promo products, IT consulting, office furniture, printing services, and more. Its headquarters are located in Framingham, Massachusetts.</i><br />Target victim <b>website</b>: <i>staples.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>JJR-Engineering--Fabrication</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30470</link>
<guid>bd50f363001990ee1fe5d798702b1d5b</guid>
<pubDate>Wed, 11 Mar 2026 19:13:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>JJR-Engineering--Fabrication</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3128f2d652e8e052a58d3e66b8e92d00ffb38db766126883339a7eea922a7506</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>jjrfabrication.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alef-Realty-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30467</link>
<guid>41ba1eaf157e7afc806e65229667f255</guid>
<pubDate>Wed, 11 Mar 2026 18:39:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alef-Realty-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f90248044925a407c97255357fce472130d5f32f06ea6ab00b3fff373c967c1</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>seclore.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30469</link>
<guid>08d18210f962e39780ba7f1e45d51c7c</guid>
<pubDate>Wed, 11 Mar 2026 18:37:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>seclore.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01cce3c4f872b727815d3fb7811cffff63f2943eafd57ac7d13503b99713fc94</i><br /><br />Threat actor <b>description</b>: <i>At Seclore, we believe that cybersecurity should revolve around what matters most—your data. Traditional security perimeters are no longer enough in today’s hyp... - TOTAL QUANTITY 1.3 TB


</i><br />Target victim <b>website</b>: <i>seclore.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>D3-Embedded</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30468</link>
<guid>e3ccd20199b9c2d6faa5eb83259a84cd</guid>
<pubDate>Wed, 11 Mar 2026 17:41:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>D3-Embedded</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03827ce1289e79dd34ecc22cb2692a6b093a3e62b788a649b9add679b326c7b1</i><br /><br />Threat actor <b>description</b>: <i>D3 Embedded is a U.S.-based company specializing in the development of end-to-end solutions for performance-critical embedded systems, integrating sensors, connectivity, embedded processing, and AI. Their product offerings include camera modules, radar sensors, and various boards and cards designed for applications in robotics and autonomous machines.We will upload 415gb of corporate data soon. Lots of projects andrelated documents, agreements, licenses and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Big-Brothers-Big-Sisters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30466</link>
<guid>1895037c0fa55110b0e0e20d2e68a0d7</guid>
<pubDate>Wed, 11 Mar 2026 16:21:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Big-Brothers-Big-Sisters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fff70d0f75bf9cdcd95890cac0698a46629ebb23c0860903896231001957b10</i><br /><br />Threat actor <b>description</b>: <i>- Students List- Background Check Records- Internal Documents</i><br />Target victim <b>website</b>: <i>www.bbbs.org</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chartre-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30445</link>
<guid>e642e53491d96d64124a4d5800c43b5f</guid>
<pubDate>Wed, 11 Mar 2026 16:18:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Chartre-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61ea572407f71f9fb8dd5aa95e8a5090293649ed5a742fb02686c9fcf618edf6</i><br /><br />Threat actor <b>description</b>: <i>Chartre Consulting is a U.S.–based professional services and management consulting company headquartered in Oxford, Mississippi. Founded in the early 1990s, the firm operates within the business services sector and provides consultancy related to corporate management, development projects, and real-estate-related activities. The company advises organizations on operational planning, project development, and business improvement while also being connected to construction and property development work, including commercial and residential projects. Chartre Consulting serves private clients and businesses seeking guidance on management decisions, organizational strategy, and development initiatives. The company is privately owned and employs a small-to-mid-sized workforce, generating multi-million-dollar annual revenue from its consulting and development services. 
The company headquarters is located in 2330 University Ave, Suite C, Oxford, MS 38655, United States.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>ToolpartsPro</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30446</link>
<guid>f26b5ed6b73a60f4883462d0e2779207</guid>
<pubDate>Wed, 11 Mar 2026 16:18:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>ToolpartsPro</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94ea6afa45ec822d0a39e96229f19657c3d4f5150b8be7733248ec7b124f1241</i><br /><br />Threat actor <b>description</b>: <i>ToolpartsPro specializes in providing a vast inventory of genuine OEM power tool parts, replacement parts, and accessories for various brands including DeWalt, Makita, and Milwaukee. The company caters to both DIY enthusiasts and professional tradesmen, ensuring they have access to high-quality parts at competitive prices. With a commitment to customer satisfaction, ToolpartsPro offers expert diagnosis and repair services for faulty tools. Their user-friendly online platform enhances the shopping experience, featuring a comprehensive parts finder and regular promotions. 
The company headquarters is located in 2117 Industrial Ct, Vista, CA 92081-7957, United States.
51-200 Employees.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Internation-Planning-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30448</link>
<guid>72215f7896ee90dfda83e7803a3c08db</guid>
<pubDate>Wed, 11 Mar 2026 16:18:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Internation-Planning-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5b1207cf9ff21a782f78badcc5c58289d9ff5ec8ee8b0ff8d17f350da027a70</i><br /><br />Threat actor <b>description</b>: <i>IPG has served clients residing in multiple Asian countries including China, Guam, Hong Kong, Indonesia, Japan, Macau, Malaysia, Singapore, Taiwan, Thailand and Vietnam, for over 10 years. International Planning Group Ltd is a registered member of the Hong Kong Confederation of Insurance Brokers. IPG Financial Services, PTE, located in Singapore (a subsidiary of International Planning Group, Ltd.) is licensed under the Financial Advisers' Act and regulated by the Monetary Authority of Singapore. IPG Asia has developed strategic partnerships with local and global private banks to assist in providing their clients with appropriate wealth structuring and transfer planning strategies and solutions. With over 40 employees operating out of the company's Singapore and Hong Kong offices, IPG has 10 local, highly trained and professional sales producers, support staff including field underwriting personnel and product specialists and local senior management to oversee the company's Asia operations. IPG has placed more than $9 billion of life insurance coverage in Asia and has more than 450 clients residing in the region. Because IPG has several years experience in the market, fully staffed regional offices and the support of the Home office in Boston Massachusetts, the company understands the tax and regulatory environment for each individual jurisdiction in which the company operates. As such, the company has developed specific strategies to meet the needs of the company's Asian clients, provide access to the world's life insurance capacity through IPG's open architecture philosophy and operate under strict protocols to provide best in class access to life insurance solutions for the high net worth market. 
The company headquarters is located in 62 Walnut Street, First Floor, Wellesley, MA 02481, United States.
201-500 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shaft-Drillers-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30449</link>
<guid>e9433fc14b27c2c907dad393b9c2626d</guid>
<pubDate>Wed, 11 Mar 2026 16:18:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Shaft-Drillers-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7239c5201aafb8396cd2dc97b6203bd05bdedd7dd7afe3f9011267e637f66c0d</i><br /><br />Threat actor <b>description</b>: <i>Shaft Drillers International is a U.S.-based construction and drilling services company headquartered in Mt. Morris, Pennsylvania. It is a leader in specialized geotechnical construction, large-diameter shaft drilling, and complex infrastructure projects, offering solutions in ground stabilization, deep foundations, dam construction and rehabilitation, and water resource development. The company operates through a network of subsidiaries that provide a broad range of services including drilling, earthwork, structural support systems, soil stabilization, and well services. Known for innovative technology and experienced teams, Shaft Drillers International serves civil, mining, energy, and industrial sectors with durable, cost-effective construction solutions. 
The company headquarters is located in 130 Meadow Ridge Road, Mount Morris, PA 15349, United States.
501-1,000 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acme</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30450</link>
<guid>e9b0945085eb3961bc04529c0f09e15c</guid>
<pubDate>Wed, 11 Mar 2026 16:18:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Acme</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af3e60ed56a23255e0f11e8ab76544255a77fb74ba9a0f036053c0a40291de8e</i><br /><br />Threat actor <b>description</b>: <i>Acme Truck Line, Inc. (from www.acmetruck.com) is a U.S. transportation and freight carrier specializing in hauling equipment, materials, and supplies across the country. Founded in 1960, this employee-owned trucking company serves a wide range of industries — especially the oil and gas sector — with services including expedited freight, heavy haul, drive-away, 3PL logistics, and more. Its fleet operates more than 1,500 trucks across 40 service markets in over 15 states, running 24/7 to ensure safe, on-time deliveries. Acme emphasizes safety, integrity, and personalized customer service through its full-service terminals and certified drivers. 
The company headquarters is located in 200 Westbank Expressway, Gretna, Louisiana 70053, United States.
1K - 5K Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Frauenshuh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30451</link>
<guid>3af7e700968700884b9da655b280a267</guid>
<pubDate>Wed, 11 Mar 2026 16:18:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Frauenshuh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a297f01b05dbb98a84904affc4ca57a5e4dc2b855e1f1c969f0feba2fb5b7a2</i><br /><br />Threat actor <b>description</b>: <i>Frauenshuh Commercial Real Estate has been a leader in the commercial real estate sector for over forty years, offering a wide range of services including corporate real estate solutions, development, and healthcare real estate solutions. The company prides itself on building long-term relationships and utilizing innovative tools to provide comprehensive real estate services. Their expertise extends to leasing and sales brokerage, project management, and property and asset management. Frauenshuh aims to create enduring value for its clients through professionalism and financial depth. 
The company headquarters is located in 7101 W 78th St, Suite 100, Minneapolis, MN 55439.
51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Priderock-Capital-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30454</link>
<guid>2649b36f54ee6080dd7e2c057585bce6</guid>
<pubDate>Wed, 11 Mar 2026 16:15:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Priderock-Capital-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5d29275d393a358d9d11d52d2ccec24bc38d44ca6fe9520b46c21bc1bb0159f</i><br /><br />Threat actor <b>description</b>: <i>Priderock Capital Partners is a private multi-family asset management and development firm. Priderock's principals have over 100 years of experience in acquiring, developing, financing, managing and renovating apartment communities across the continental U.S.We will upload 110gb of corporate data soon. Employee files (passport numbers, DL number, scanned w9 and i9 forms and other personal information), financials, clients and partners files, lots of contracts and agreements, reports and violation docs so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>thethibeauxfirm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30463</link>
<guid>dfa13c18f92edfde61bf8b57d4539351</guid>
<pubDate>Wed, 11 Mar 2026 15:42:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>thethibeauxfirm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd94716507a23c9b4d1c17ef6a54d6526435bbc72075fdfaf2810cfabcbc03ab</i><br /><br />Threat actor <b>description</b>: <i>At The Thibeaux Firm, our top priority is you. We are a Lafayette, Louisiana-based personal injury law firm committed to high-quality representation, outstanding client support, and the pursuit of maximum compensation for accident victims.  Omar Thibeaux started our law firm on the belief that advocacy means more than just negotiating a settlement from those responsible for your accident. It also involves listening to you, understanding your problems, keeping in frequent contact with you, and never losing sight of what your case is worth. Our goal is to get the most return on your accident claim — and to never charge excessive fees in doing so.  Whether you’ve been in an accident in Lafayette, New Orleans, Baton Rouge, or anywhere else in the Pelican State, you’re never another claim number to us. You’re part of our community and our family.</i><br />Target victim <b>website</b>: <i>thethibeauxfirm.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kentucky-Injury</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30462</link>
<guid>6be412e46a02d4bd7115c929f91a36cd</guid>
<pubDate>Wed, 11 Mar 2026 15:41:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Kentucky-Injury</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e076bdb93e611192447c785b4981bfc8b16f1821807fb5a1a598bfc310d9f64</i><br /><br />Threat actor <b>description</b>: <i>When you're dealing with an injury, you need more than just legal representation — you need someone who truly understands what you're going through and will stand by your side. That’s where I come in.   I'm John Byrnes, a Louisville-based personal injury lawyer dedicated to helping people across Kentucky when they’ve been hurt due to someone else’s negligence. With over 25 years of legal experience and a passion for serving my community, I focus exclusively on personal injury law so I can give every client the time, attention, and strong advocacy they deserve.   Whether you were injured in a car accident, harmed by a defective product, or suffered due to medical malpractice, my goal is to help you recover the maximum compensation and care you need to move forward.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Special-Shapes-Refractory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30455</link>
<guid>5596a1c3cefe922da3cfd3244c02133a</guid>
<pubDate>Wed, 11 Mar 2026 15:38:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Special-Shapes-Refractory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23f10e73d88ce508f2ed81690d4102e3473b9d3439c073ec81318fbfef9571b3</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Powers-HVAC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30456</link>
<guid>f6b50ff60e962a4d29e02759470b2d79</guid>
<pubDate>Wed, 11 Mar 2026 15:38:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Powers-HVAC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79e665c2c580d6189c6bf95f73ec8fbf3bae7e9ad51c84b0396b4212381792b6</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jadtec-Security-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30457</link>
<guid>e58e99e7d2a26e1f5a2143e49351536a</guid>
<pubDate>Wed, 11 Mar 2026 15:38:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jadtec-Security-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24cf091129afb3d88c772903c8bf683afc4c3e004a6fdc6c91879cf8e5f5f35e</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Omega-Optical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30458</link>
<guid>5fbcf70d27063b784f44cac35923997b</guid>
<pubDate>Wed, 11 Mar 2026 15:38:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Omega-Optical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40a1b1bf727aca95590dc2f51d058ddc505219ed94180732aa1e339da519fb5c</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Robinson-Nursery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30460</link>
<guid>28b1723af782c5ebb1f6522d19c6df31</guid>
<pubDate>Wed, 11 Mar 2026 15:31:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Robinson-Nursery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28540c993733c361e416828d4cb0290a0327c8e1be37e55ebb06b8c60e16adb9</i><br /><br />Threat actor <b>description</b>: <i>Robinson Nursery sells wholesale bare root trees & shrubs as well
as container trees. The company offers over 300 different variet
ies of shade trees, ornamental trees and shrubs. The company grow
plants that are hardy for zones 3 through 9. As a licensed growe
r of many named cultivars the company is able to offer a great se
lection of some of the most asked for varieties of trees and shru
bs.

We will upload corporate data soon. Employee files (scanned passp
orts, DLs, SSNs and so on), financials, clients and partners file
s, contracts and agreements, projects, recipes and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Murrays-Cheese</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30459</link>
<guid>897c1eac194eb7db41acc4c73d04bf9e</guid>
<pubDate>Wed, 11 Mar 2026 15:31:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Murrays-Cheese</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>238ab46124c62dfb0b150e4b20189800ba6282ee53d54e847db582f77f463fe4</i><br /><br />Threat actor <b>description</b>: <i>Murray's Cheese, founded in 1940 in Greenwich Village, is the old
est cheese shop in New York City. The company specializes in reta
il grocery with a focus on premium cheese products. Murray's has 
earned recognition for its quality offerings and has expanded to 
multiple locations. The business operates both B2B and B2C models
, providing specialty cheese and related products to consumers an
d businesses alike.

We will upload corporate data soon. Very detailed employee (more 
than 300 employees) information (passports, DOB, DLs, and so on),
financials, clients files, contracts and agreements, projects, i
nternal confidential files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peak-Toolworks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30438</link>
<guid>29524de15c2dd7ad71bcec153fcb3717</guid>
<pubDate>Wed, 11 Mar 2026 14:38:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Peak-Toolworks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90fd731ee223d367e8676f8a582f1482c5ae5aaa43653d6b2da6f4436e30d3b7</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yuma-Sun</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30440</link>
<guid>549561a1b1b3127d0849484c0c7d4462</guid>
<pubDate>Wed, 11 Mar 2026 14:38:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Yuma-Sun</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac65290dde3e92b067facf44272b1a664c37b17363ae168bf3303148b4f6d2dc</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Composition-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30441</link>
<guid>9061cb6ece930b623c92d43061cca24e</guid>
<pubDate>Wed, 11 Mar 2026 14:38:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Composition-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1d22b430fac68dae35fab657855dc3057a5a2a1a39c79ffd929c68ec951d3d5</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elliott-Lewis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30434</link>
<guid>9e29fd3777fb2934d59a9522b5bfa87b</guid>
<pubDate>Wed, 11 Mar 2026 10:14:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Elliott-Lewis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>140752dc3020b41820aa699472be52b4c88e5a394cd0420802aebb72490e320c</i><br /><br />Threat actor <b>description</b>: <i>Since 1905, Elliott-Lewis Corporate has provided comprehensive solutions for maintenance, repair and operations, engineering, design, installation, and energy consumption. In addition, Elliott-Lewis' Facilities Management team provides individual on-site operations management but does not provide security to its customers, resulting in a large database of confidential contracts and projects, as well as personal customer and employee data.</i><br />Target victim <b>website</b>: <i>https:elliottlewis.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>L.-S.-King-and-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30423</link>
<guid>ae9f22c1a98cf769e89facdc1cd7dec9</guid>
<pubDate>Tue, 10 Mar 2026 23:24:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>L.-S.-King-and-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed72c3fa7cc55c8e47fd0f12fdd299583dddca4813353549037e87c4a4343a64</i><br /><br />Threat actor <b>description</b>: <i>www.cpageorgia.com - accounting firm data breach. Small dataset, big consequences.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>csi-ri.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30421</link>
<guid>dfd5301dee688bb803b008e9db07b715</guid>
<pubDate>Tue, 10 Mar 2026 16:00:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>csi-ri.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fbd366e8eabe7e1dbf2ed9fb91f65bb49a47d747ab104f0997f584a769e1907</i><br /><br />Threat actor <b>description</b>: <i>Contractors Supply stocks and distributes only top quality products and materials that conform to the latest DOT, ASTM, and Federal Specifications. In addition, the company only partner with manufacturers and representatives who stand behind their products and prove to be invaluable resources in product selection, technical service, price and availability. Contractors Supply prides itself on partnering with contractors, architects, engineers as well as with the company's manufacturers to continually solve problems and provide solutions to the company's customers' needs. The company strives to share the company's expertise with the company's customers to generate successful results and solutions in all phases of construction. Contractors Supply's goal is to continue to be the company's customers' First Choice supplier by: - Stocking a wide variety of quality material, supplies, and equipment - Delivering the items you need, when and where you need them - Providing accurate and factual  Employees: 50  Revenue: $5 Million Industry: Industrial Machinery & Equipment Phone Number: (203) 553-4300</i><br />Target victim <b>website</b>: <i>csi-ri.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Exhibit-Network</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30417</link>
<guid>24e87062155973c97360089add8e19d7</guid>
<pubDate>Tue, 10 Mar 2026 14:41:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Exhibit-Network</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ddd1c37482e2e418b9bfce0905e436435cc35459ec3050bb79149dd1f82279e</i><br /><br />Threat actor <b>description</b>: <i>From the company's headquarters in Houston, Exhibit Network handl
es all the details involved in your custom trade show display, lo
gistics, and show services, allowing you to focus on the big pict
ure. The company offers extensive expertise at competitive prices
.

We will upload almost 50gb of corporate data soon. Employee files
(passports and some other scanned documents), financials, client
s' files, contracts and agreements, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>netCOMPONENTS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30414</link>
<guid>6789a028871524be3a84e0c3490b4177</guid>
<pubDate>Tue, 10 Mar 2026 14:39:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>netCOMPONENTS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5c7be8364bff9f8c7ed6619cf8833778d1471c3dcd47b6d73d645777ff622de</i><br /><br />Threat actor <b>description</b>: <i>netCOMPONENTS is a market leader in sourcing services for the global electronic components industry, connecting buyers and suppliers in a vendor-neutral environment. The platform offers extensivefeatures for purchasing agents and procurement professionals, including part searches, supplier quality ratings, and multilingualmessaging systems.We will upload corporate data soon. Detailed employee files (passports, DLs, a bit of medical files), clients' files, financials, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Animations</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30411</link>
<guid>8bb30d678ae46c02570c83038ef64980</guid>
<pubDate>Tue, 10 Mar 2026 11:41:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Advanced-Animations</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>85f47f452c1c11573b5deeeb0e5b61131acd8e98d65fd881f3e3b1944000cf61</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.advancedanimations.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-Fast-Tile--Coping</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30410</link>
<guid>b75f4cd91723baa6327b03ddf0b8ebf6</guid>
<pubDate>Tue, 10 Mar 2026 11:41:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>A-Fast-Tile--Coping</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba64c3dc0eb3c19bb00fc7e564aa34d5b3094305461ba45b1f1a2211258f43bf</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.afaststone.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>RetireRight-Financial-Planning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30409</link>
<guid>b6a243747ce4d20eaf2cf025e7176662</guid>
<pubDate>Tue, 10 Mar 2026 11:40:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>RetireRight-Financial-Planning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6bc899dfafd6bccdd6593498367b8db4c812cc924893b98c93874816412a0d6</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.retirerightfp.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Taylor-County-Property-Appraisers-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30405</link>
<guid>e6c439226a0bde3e060ac5ce39b7d0f2</guid>
<pubDate>Tue, 10 Mar 2026 03:25:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Taylor-County-Property-Appraisers-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>449e87895ac2cd58180c3f0fe845f7ff3671141b6c7c35cf043ea5b67a083420</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>qpublic.net/fl/taylor</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Priority-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30404</link>
<guid>e1b0e6b958ea38f4dae5f9d24730ef05</guid>
<pubDate>Tue, 10 Mar 2026 02:48:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>First-Priority-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ece378254213ad863fb80e351f298d97498d20e76fc42022c8d5d9e44d19650a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] First Priority Group is a diversified manufacturer, dealer, up-fitter, and service provider of emergency and specialty vehicles. The company provides ambulance remounts, emergency vehicle parts, and services. It also designs and manufactures vehicle command centers for the law enforcement and public safety sectors. Based in New Jersey, it has been serving customers across the USA since 1998.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wagon-Mound-Public-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30399</link>
<guid>080ed12b1c4e12ed722a00592a033080</guid>
<pubDate>Mon, 09 Mar 2026 22:15:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Wagon-Mound-Public-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6dec616027edda0b6b156355f888f1b58393c3771500c541a17159b93cfb1b0d</i><br /><br />Threat actor <b>description</b>: <i>Wagon Mound Public Schools provides education to students in the Wagon Mound area, providing resources and support for both elementary and middle schools. However, they neglected to address the security of their materials, resulting in the compromise of all their personal data, including the school's blueprints. We present to your attention a 80 GB of data, which includes staff and student information, their phone numbers, residence addresses, and passport numbers.</i><br />Target victim <b>website</b>: <i>wm.k12.nm.us</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>RWB-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30395</link>
<guid>ec4b2e408e41a86f2fd70cc17c564994</guid>
<pubDate>Mon, 09 Mar 2026 21:40:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>RWB-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>732259a2c4722ea250740014f98b218a31e1247d2139a281fa4d4aa4eb02ae1b</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vertex-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30397</link>
<guid>2b26cd1908760b63ea7268209d1750db</guid>
<pubDate>Mon, 09 Mar 2026 21:18:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Vertex-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>029be70fedb0d021569a359b7ae8bd37c81b3290a7e5271dbf85fd7eaff78085</i><br /><br />Threat actor <b>description</b>: <i>Over 2M records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 12 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>altaortho.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30394</link>
<guid>6ead95f03fc10ada537a2c9a21098d16</guid>
<pubDate>Mon, 09 Mar 2026 20:37:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>altaortho.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bfda67adbfe6b58cd67769c84971a402460aa084415ce3b0dac13e299b5ca92d</i><br /><br />Threat actor <b>description</b>: <i>Alta Orthopaedics specializes in orthopaedic surgery, pain management, and sports medicine, serving clients in Santa Barbara, Solvang, Oxnard, and Santa Maria, CA. They offer a range of services including treatment for ACL injuries, meniscus tears, elbow tendon pathology, rotator cuff disease, fractures, and various types of surgical procedures. The practice boasts a convenient online booking system and a focus on patient education and care, as reflected in positive customer testimonials. Their team of specialists includes physicians and physician assistants experienced in various orthopaedic disciplines. Employees: 50 Revenue: $8.9 Million Industry: Hospitals & Physicians Clinics Phone Number: (805) 688-8821 </i><br />Target victim <b>website</b>: <i>altaortho.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>tupeloeye.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30393</link>
<guid>5557b67c89b4ff20c165303cfa98a81a</guid>
<pubDate>Mon, 09 Mar 2026 20:36:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>tupeloeye.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fa62d287cf2cc5b983c39d67f3b54339b7934eb1320ce9e07d677e495e30779</i><br /><br />Threat actor <b>description</b>: <i>It is home to Tupelo Eye Clinic (Joseph J. Chappell, M.D., William C. Brawner, M.D., and Lee H. Walker, M.D.) and Tupelo Eye Center Optical Shop. Located at 610 Brunson Drive, is the home of the Tupelo Eye Clinic & the Tupelo Eye Center Optical Shop. Our Services Employees: 50 Revenue: $5 Million Industry: Hospitals & Physicians Clinics Phone Number: (662) 844-7211 </i><br />Target victim <b>website</b>: <i>tupeloeye.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>arbd.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30392</link>
<guid>63e8e9536fbbf4d06828cb7958a93d58</guid>
<pubDate>Mon, 09 Mar 2026 20:36:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>arbd.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8a8636b933e13b89889a1395c1604469f642eac0766bc1376566bdab1ee943b</i><br /><br />Threat actor <b>description</b>: <i>Abramson Brown & Dugan is a leading law firm in New Hampshire specializing in medical malpractice and personal injury cases. With a reputation for securing the highest number of settlements in the state, they cater to clients who have suffered injuries due to medical negligence or accidents. Their team of experienced attorneys is committed to providing compassionate support during what can be a traumatic time for their clients. The firm also emphasizes their mission to restore trust and advocate fiercely for those affected by serious legal matters. Employees: 20 Revenue: $5 Million Industry: Law Firms & Legal Services  Phone Number: (603) 627-1819</i><br />Target victim <b>website</b>: <i>arbd.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Comprehensive-Orthopaedics-and-Musculoskeletal-Care-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30391</link>
<guid>c3be0a55f6361e9a215d06fe83166945</guid>
<pubDate>Mon, 09 Mar 2026 20:30:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>crypto24</b> claims attack for <b>Comprehensive-Orthopaedics-and-Musculoskeletal-Care-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>756a2d9987f1d5a760567ae20d67bdb99440f48f0e18995b290f9ba8b66f4a1d</i><br /><br />Threat actor <b>description</b>: <i>HIPAA personal information for over 100,000 people...</i><br />Target victim <b>website</b>: <i>comprehensiveorthopaedics.com</i>]]></description>
<category>crypto24</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinity-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30384</link>
<guid>b9b42240909f825c24ca520d8d28255e</guid>
<pubDate>Mon, 09 Mar 2026 19:25:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Infinity-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2c30d1cc198a2e74e40b94ede979a9da4958ddb447aff27f508badb074b02b0</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.infinity-tx.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Serrano-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30383</link>
<guid>20c0b09862be4732462010cf42039ae5</guid>
<pubDate>Mon, 09 Mar 2026 19:24:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Serrano-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3a9ebed435c234cbc6fefa30a9a2276d431b8194f95b70fd5828aec1b4b38e4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.serrano-ind.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Helen-Kaminski</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30382</link>
<guid>f4b2ff812230c43a7977b366e1fcc6f1</guid>
<pubDate>Mon, 09 Mar 2026 19:23:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Helen-Kaminski</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23d77af77134befd24887596ed6505d7678d15dd061ce2b6e4a60abdd95c540c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.helenkaminski.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Byard-F-Brogan</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30381</link>
<guid>72e0a400c7b6e0beb7f2992c5378b3f6</guid>
<pubDate>Mon, 09 Mar 2026 19:23:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Byard-F-Brogan</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5fe8a94bdb8c801010841bc711e54b369c9170cfd76b84615653635d99d5a17</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bfbrogan.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Facilities-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30380</link>
<guid>e4950445cc79fe6c0144a2372626ef1a</guid>
<pubDate>Mon, 09 Mar 2026 19:22:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Facilities-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c9dbd0690d30201ef6f8ea1d1f38e20ed67abed4f89856e0bd84536fe8700de</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.facilitiesusa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Concrete-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30379</link>
<guid>2d818880a4d72c14f185cbef3fc6061a</guid>
<pubDate>Mon, 09 Mar 2026 19:22:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Southern-Concrete-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>982468dd57e21aabf93715a0cd4f88fa4156c432d01934462a3ca328a2759470</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.southern-concrete.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>nch.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30375</link>
<guid>f5d0adbd21d9afa3d701967462202f4b</guid>
<pubDate>Mon, 09 Mar 2026 18:45:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>nch.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b8d6fb9b0c5632a746720dd7032dcab5957867c16bf2825413a80e2a507926b</i><br /><br />Threat actor <b>description</b>: <i>Your leading global experts in industrial solutions.

At NCH Corporation, we don’t just sell products—we deliver solutions that keep businesses moving. For ov... - More than 7.3TB of data has been downloaded.</i><br />Target victim <b>website</b>: <i>nch.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peninsular-Electric-Distributors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30373</link>
<guid>047471c151b6f90ac3a4ffeaddadf03c</guid>
<pubDate>Mon, 09 Mar 2026 15:39:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Peninsular-Electric-Distributors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f23816ded812a5cb3d24f277f8c4155427b86d31ca0d56bc3ad261be45c57112</i><br /><br />Threat actor <b>description</b>: <i>Peninsular Electric offers a wide range of products including electrical equipment, heavy construction machinery, cleaning supplies, and safety gear. Their services cater to various sectors such as residential, commercial, and industrial clients.We will upload 60gb of corporate data soon. Employee files, customer information, financials, confidential agreements, projects and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fiberglass-Hawaii</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30370</link>
<guid>2418c4e3de622a573d9233ad9ab707a3</guid>
<pubDate>Mon, 09 Mar 2026 14:38:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fiberglass-Hawaii</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d96941cb487cdaea87c521607ffe08e14e076a04393ee358d85bfc0e43918e57</i><br /><br />Threat actor <b>description</b>: <i>Fiberglass Hawaii specializes in high-quality products tailored for the marine and surf industries. Their offerings include fiberglass, resin, blanks, tools, and various accessories.We will upload corporate data soon. Customer information, financials, projects and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colliers-International-Idaho</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30372</link>
<guid>2e8b0ad62c8a9f3c5af58a346076e638</guid>
<pubDate>Mon, 09 Mar 2026 13:40:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Colliers-International-Idaho</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b68c2e96439bc4f9b6d52ce33d1e53a74332b06c41600bd2c09c39ccef07a586</i><br /><br />Threat actor <b>description</b>: <i>Colliers Idaho specializes in commercial real estate, offering a variety of properties for sale or lease throughout Idaho. Their portfolio includes options for retail, office, medical, and industrial spaces, catering to diverse client needs.We will upload 42gb of corporate data soon. Employee passports, DLs, SSNs, w9 forms, medical information. Financials, projects, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sagent-Pharmaceuticals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30363</link>
<guid>6eef686c3fc818179f5be661698fb8e7</guid>
<pubDate>Sun, 08 Mar 2026 11:40:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Sagent-Pharmaceuticals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8de70ccc799a75d5f60c024066f1ed60d3eea55fe8a201ee27ec1a8d1c7e676</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Artemedica</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30358</link>
<guid>14fe29ea31af2e4d7daa0dfa803df05c</guid>
<pubDate>Sat, 07 Mar 2026 18:39:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Artemedica</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4f53eb05e795b1e90756c56bfd988ad8e197cbd09559d4ee3488280582c401f</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kuzco-Lighting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30359</link>
<guid>1633b2e8d8d39ecaf5fd05fd16b4ffd0</guid>
<pubDate>Sat, 07 Mar 2026 18:39:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kuzco-Lighting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44d6e33d8a416265aa5fce14a9de0839b2d9d0fe8e2d34416e5f703ed2c92372</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brothers-Produce</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30360</link>
<guid>8d9a15b55c2ac9becb69a52624396966</guid>
<pubDate>Sat, 07 Mar 2026 17:39:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Brothers-Produce</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b40e1bbfa7e9bd1662553365b03657480b293b9fa525f988744ccfde9dc5a44</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stalwart-Development-Group-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30356</link>
<guid>2c573a074732c9dad456e1e9f9ffc238</guid>
<pubDate>Sat, 07 Mar 2026 13:40:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Stalwart-Development-Group-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdd9918cff87eec331310ceb335270902b9f9f8b1120892d6ea43a7cebd7f50a</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.stalwartdg.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>crescentenergyco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30355</link>
<guid>e35ca2aa785ca87355449938e1450f9b</guid>
<pubDate>Sat, 07 Mar 2026 13:02:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>crescentenergyco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>446c9d4916495a437f42fd6b710a330d9aba92d28fe556b290e255a86aaf873d</i><br /><br />Threat actor <b>description</b>: <i>Crescent is a growth-oriented U.S. independent energy company engaged in the acquisition, development and operation of oil and natural gas properties. Crescents portfolio of low-decline, cash-flow oriented assets comprises both mid-cycle unconventional and conventional assets with a long reserve lif…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/crescent-energy/560087910</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sileno-Companies-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30354</link>
<guid>5231f53ee04409d2d652039077794382</guid>
<pubDate>Sat, 07 Mar 2026 12:36:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tengu</b> claims attack for <b>Sileno-Companies-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdcd1088741c7eaecd0f80040bb1147c100d0841f3929f047355c90acea07d18</i><br /><br />Threat actor <b>description</b>: <i>Sileno Companies Inc. A US company primarily operating in the hospitality and real estate sectors, its activities include: Hotel operation Property management Management of hotels' restaurants and bars Hospitality project development 22.9TB was encrypted in 14 hours on 3/5/2026 More than 67.07 GB was extracted</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tengu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Griswold-Controls</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30353</link>
<guid>6a12f449790ed7be96d77aa4c7d9c1c1</guid>
<pubDate>Sat, 07 Mar 2026 11:45:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Griswold-Controls</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6fa7a0412676b97c9d806bc50bc7089f9aa70ce94163109ad332789674f200d</i><br /><br />Threat actor <b>description</b>: <i>A leader in flow control technology and valves, specializing in HVAC and irrigation applications</i><br />Target victim <b>website</b>: <i>griswoldcontrols.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>NADAP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30352</link>
<guid>650bbf5d3ffa2b7d9b8b36d62d667ced</guid>
<pubDate>Sat, 07 Mar 2026 11:45:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>NADAP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b204281c54872c7c81952f88ae14720d50cc990cecace1005cd1b46f4d4a4bb6</i><br /><br />Threat actor <b>description</b>: <i>A non-profit organization</i><br />Target victim <b>website</b>: <i>nadap.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Hart</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30351</link>
<guid>768b2f133c3ea3ca2db797f5aa593417</guid>
<pubDate>Sat, 07 Mar 2026 11:44:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>City-of-Hart</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f0ffec7004947b54921f1d6d01fe6977bf85e2baf7c331cfb2b7478e94552be</i><br /><br />Threat actor <b>description</b>: <i>A City of Hart local municipal organization</i><br />Target victim <b>website</b>: <i>cityofhart.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brighton-Eye</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30350</link>
<guid>133b5f08ade8b354bfd42b98c629ef05</guid>
<pubDate>Sat, 07 Mar 2026 11:43:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Brighton-Eye</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fef67758513edd0bb9e750935e730cf7eff625e93f0d0ba9050a23a228cfe824</i><br /><br />Threat actor <b>description</b>: <i>An eye care center in Brooklyn, NY</i><br />Target victim <b>website</b>: <i>brightoneye.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cornerstone-Financial-Advisors-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30349</link>
<guid>5646dfcf5046a6c1b4014ee53d9d614d</guid>
<pubDate>Sat, 07 Mar 2026 11:43:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Cornerstone-Financial-Advisors-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90f7c15e9d22070a17bc96029eb0ebcc8bfd96f0c617a2a5a6a6bdf66cb67c46</i><br /><br />Threat actor <b>description</b>: <i>A full service CPA firm</i><br />Target victim <b>website</b>: <i>cfa-oc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sanders-Legal-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30348</link>
<guid>423aa9774a2b7131b0061979ecb645e8</guid>
<pubDate>Sat, 07 Mar 2026 11:42:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Sanders-Legal-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f6c59f87126d75cabbcdff6de1ba4cefbe3a4bf7617215e2ebad249658b4f14</i><br /><br />Threat actor <b>description</b>: <i>A law firm based in Atlanta, Georgia</i><br />Target victim <b>website</b>: <i>sanderslegalgroup.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>OneSource-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30347</link>
<guid>311ce497f79478c471790cb0067b2863</guid>
<pubDate>Sat, 07 Mar 2026 11:41:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>OneSource-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26b27902cca99442f7dd0e4ee224682480d2e30cce1fc7b93451b8921d174068</i><br /><br />Threat actor <b>description</b>: <i>A provider of RCM and billing services</i><br />Target victim <b>website</b>: <i>onesourcemg.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sierra-Management-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30346</link>
<guid>a7f3d45a6782bc654321c0a9bc92ca66</guid>
<pubDate>Sat, 07 Mar 2026 11:41:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Sierra-Management-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de043da5d20f8ca85aed53f44535f9f8c1739f8be75430bb783b73fd458b1f60</i><br /><br />Threat actor <b>description</b>: <i>Provides comprehensive medical practice management</i><br />Target victim <b>website</b>: <i>sierramanagementgroup.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>AFDL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30340</link>
<guid>25a81df4364d32613794af6c800db478</guid>
<pubDate>Sat, 07 Mar 2026 08:42:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AFDL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49e9c2a8f3cdb8025ecaf58e86eb94e08662a5b91db03bab70e06965fafc4710</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Johnson-Vollmerhausen--Gates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30344</link>
<guid>c94ac72ea12ea1943136f2bc64719600</guid>
<pubDate>Sat, 07 Mar 2026 08:27:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Johnson-Vollmerhausen--Gates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6ebeb8b64454b7e1c5bfddb8f609c41dbd99aa771c72134175cdd9b308ecf9e</i><br /><br />Threat actor <b>description</b>: <i>Johnson Vollmerhausen & Gates provides professional accounting, tax, and advisory services tailored to the needs of both individuals and businesses.</i><br />Target victim <b>website</b>: <i>jvgasheville.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ladue-Family-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30341</link>
<guid>b1655d34c2c61209de20e71d9a2dc66f</guid>
<pubDate>Sat, 07 Mar 2026 07:01:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Ladue-Family-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f237af1df38aea841911ffb37f83bf1e49e27aff4f22624094d9019573d3a2da</i><br /><br />Threat actor <b>description</b>: <i>A major leak of smiles.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>CPG-Documentation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30339</link>
<guid>8135d1bf28501f18186f9152e28c1b3f</guid>
<pubDate>Sat, 07 Mar 2026 03:14:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>CPG-Documentation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5515d7700656941da9332852a9588dce3e51e3f74ce20a24268c6d694209bbaf</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>cpgcanhelp.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Family-Farms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30338</link>
<guid>3636844381b63509f2790081f79bf3c8</guid>
<pubDate>Sat, 07 Mar 2026 02:41:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Northern-Family-Farms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c11a3da220ba56306a3962d1e55ed6dd24fa6dfbd8e499a3ebcadcda59e5ccd5</i><br /><br />Threat actor <b>description</b>: <i>Northern Family Farms, located in Merrillan, WI, has been a trusted wholesale supplier of Christmas trees and nursery plants since 1955. They offer a variety of products including Fraser Fir, Balsam Fir, White Pine, and numerous types of nursery plants such as fruits, topiaries, and shrubs. The company serves distributors and businesses across the country, ensuring top-quality plants for retail and landscaping needs. With a commitment to customer satisfaction, they invite potential clients to tour their facilities in West Central Wisconsin.</i><br />Target victim <b>website</b>: <i>www.northernfamilyfarms.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>11th-Street-Veterinary-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30336</link>
<guid>cb389d202584d0ca7193967cf2bf06eb</guid>
<pubDate>Sat, 07 Mar 2026 01:47:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>11th-Street-Veterinary-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec60e5919e49d274b50090b9160385bb457c034b4610abce55f7f4dcf41dc83f</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.11thstvet.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Huntington</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30335</link>
<guid>7f88a31a9369d5c49af25c4e84ea29d8</guid>
<pubDate>Sat, 07 Mar 2026 00:25:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>City-of-Huntington</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1be3877f051dccb9ad05dbfb277c405bd16a73eb21e1a1e27afc42ef764e3466</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1871, the City of Huntington is located in western West Virginia. It is the county seat of Cabell County and also stretches into Wayne County.
</i><br />Target victim <b>website</b>: <i>www.cityofhuntington.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>T-a-Solberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30333</link>
<guid>a3c3404f520cf86e3fe5b0ac321d8df4</guid>
<pubDate>Fri, 06 Mar 2026 21:19:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>T-a-Solberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a19d4bef1c7676cac81e106694676e489c267fbd6d0ba8f151b5b8e83f53ee3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.tasolberg.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Don-E-Bower</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30332</link>
<guid>4f7edff394522f1aca11501d3f332477</guid>
<pubDate>Fri, 06 Mar 2026 21:18:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Don-E-Bower</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>748d9e3055213148a87fa136f5af083adf5d6c2610795d7ff2f031bd0d209660</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.donebowerinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Design-To-Print</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30331</link>
<guid>7757f31d887b1ef82d67308fc850bf5a</guid>
<pubDate>Fri, 06 Mar 2026 21:17:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Design-To-Print</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ef892c45a51a27abf6d37201d4531c89cda6049befcd541f0d23f45fbb97cc8</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.designtoprint.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>DFW-Aero-Mechanix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30329</link>
<guid>76cb2624c9d093d029a3a43ae55148f1</guid>
<pubDate>Fri, 06 Mar 2026 21:16:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>DFW-Aero-Mechanix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8480fb2b5ef435b115ccb38a03c7a5c551a7bcb86d0c7dcf2a0eb7d6c62308d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dfwaero.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garland-Williams--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30328</link>
<guid>3569ced5d21506feef9e1ce0cd9e0178</guid>
<pubDate>Fri, 06 Mar 2026 21:16:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Garland-Williams--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fada1813549ae6da9d3449e18803518f740a6521699de240455d60b6ff2ddc3a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.garlandwilliamscpa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>nelsonworldwide.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30326</link>
<guid>94e02ee38fd8f58b976ade80c5aeab54</guid>
<pubDate>Fri, 06 Mar 2026 20:34:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>nelsonworldwide.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8dad6ee2451298ff014d10c3e667499874d7670653ca9738477c9c9c3251e48</i><br /><br />Threat actor <b>description</b>: <i>NELSON Worldwide is an award-winning firm delivering architecture, interior design, graphic design, and brand strategy services that transform all dimensions of the human experience, providing our clients with strategic and creative solutions that positively impact their lives and the environments w…</i><br />Target victim <b>website</b>: <i>www.nelsonworldwide.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nephrology-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30325</link>
<guid>37db35cc291fceddcf807acffb973a7e</guid>
<pubDate>Fri, 06 Mar 2026 20:01:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Nephrology-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8056e13aab05bdc92809019097c7ce77a39f9fa1c0529e0b6f487565c983af01</i><br /><br />Threat actor <b>description</b>: <i>nephkc.com  zoominfo.com/c/nephrology-associates/469726875 Nephrology Associates prides itself on providing the highest quality of care for patients with kidney disorders in the Kansas City area</i><br />Target victim <b>website</b>: <i>nephkc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>H--L-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30320</link>
<guid>52cf16b573a97bddb9aea03cf5710746</guid>
<pubDate>Fri, 06 Mar 2026 19:41:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>H--L-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>964e9d1f1a860190485e6dc27dea1e9bc161b850326cf6c59bc62d060bc406d7</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Graham-County-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30316</link>
<guid>8fc30966df18b68dc8181947fa6400ea</guid>
<pubDate>Fri, 06 Mar 2026 18:41:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Graham-County-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8583c3e6865b9b2f73c8f71a2de37db94b9d3a3647e26bb044fbe4fd231ce62f</i><br /><br />Threat actor <b>description</b>: <i>Graham County Electric is committed to provide members with affordable cost effective energy solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Delventhal-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30306</link>
<guid>e3423656a3520cb9a9825048b5cb59aa</guid>
<pubDate>Fri, 06 Mar 2026 14:38:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Delventhal-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>495128bd8475a3300d1f622d636d30c0f1950ca7629ad1ed7d8b19b6ab48e181</i><br /><br />Threat actor <b>description</b>: <i>The Delventhal Company offers a wide range of construction and management services including general contracting, construction management, design-build, and rea...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Rehabilitation-Technology-ART</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30307</link>
<guid>1721075016476163d0405fdfe93667c1</guid>
<pubDate>Fri, 06 Mar 2026 14:38:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Advanced-Rehabilitation-Technology-ART</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f68ee16e4fd882ef853c049cf35407070334dc98445b206177729a3f1ba9e38</i><br /><br />Threat actor <b>description</b>: <i>Advanced Rehabilitation Technology (ART) specializes in state-of-the-art no-dig technology solutions aimed at protecting and extending the life of critical infr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>RC-Fence-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30310</link>
<guid>11b8d3b78031b222c720affbaf39f9e7</guid>
<pubDate>Fri, 06 Mar 2026 14:37:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>RC-Fence-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0ac944767c76bc256bb2be3f947b46786cad46d7dd654678ecd9f89ea4a238e</i><br /><br />Threat actor <b>description</b>: <i>R&C Fence, Inc. is a locally owned and operated company that has been providing custom-built fence installation services for both commercial and residential clients since 1970. With an in-house fabrication shop, they are equipped to handle complex fencing projects while ensuring high quality and service excellence. Their experienced staff offers guidance on various fencing materials and installation solutions tailored to client needs. They serve the Fort Wayne area and surrounding regions, including South Bend, Auburn, and Warsaw</i><br />Target victim <b>website</b>: <i>www.randcfence.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Verdugo-Tool--Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30308</link>
<guid>6ef43ab936ea0c3ff156b0e099c783ba</guid>
<pubDate>Fri, 06 Mar 2026 13:39:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Verdugo-Tool--Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8004773b545e15603e190ec73ff0deb3fa1f34714deb431c61315838ef6556fc</i><br /><br />Threat actor <b>description</b>: <i>Verdugo Tool and Engineering specializes in sheet metal stamping parts, serving industries including aerospace, defense, automotive, medical, and commercial for over 50 years. They offer a one-stop shop for all sheet metal needs, providing services such as tool and die design, laser cutting, metal stamping, and various value-added services.We will upload 10gb of corporate data soon. Employee personal documents, HR files, projects, contracts and agreements, confidentiality agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Central-HIDTA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30299</link>
<guid>58836fbe6a74d8fbef6dbce688905c71</guid>
<pubDate>Fri, 06 Mar 2026 12:39:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>North-Central-HIDTA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c33ac4cbc85c0b7dd3a5d959fa739c87522695d25b4247c1b1a0c45130b039dd</i><br /><br />Threat actor <b>description</b>: <i>North Central HIDTA is a federal program aimed at uniting federal, state, local, and tribal law enforcement agencies to combat drug trafficking activities in Mi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-C-Scott-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30303</link>
<guid>fe93fd567b9aafe3cc3372a19309fc6a</guid>
<pubDate>Fri, 06 Mar 2026 11:44:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>A-C-Scott-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f0267a69729f5837fd500fb996ec7e626245c89a94e65b8f83a1b87e4badc47</i><br /><br />Threat actor <b>description</b>: <i>A.C. Scott Electric Company was established in 1967 by Dexter C. Ricker and Frederik C. Nielsen as a partnership. On May 14, 1968 the company succeeded to incorporate. With the resignation of Dexter C. Ricker in 1984, Frederik C. Nielsen and his wife, Maiken Nielsen obtained 100% ownership of the corporation. From this point forward, A.C. Scott Electric Co., Inc. was operated as a "family-owned" small business enterprise in the State of New Jersey. Frederik and Maiken retired from the day to day operation of the corporation in 1999, relinquishing ownership and operational control to their son, Michael C. Nielsen.</i><br />Target victim <b>website</b>: <i>www.acscottelectric.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ICS-Electrical-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30302</link>
<guid>ab5a47d41c51bcd432f515088a070b8b</guid>
<pubDate>Fri, 06 Mar 2026 11:43:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>ICS-Electrical-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebaf617e6608b0ac9260ca050ceb2c77189a9d398868a12a9576526c5a8358c2</i><br /><br />Threat actor <b>description</b>: <i>ICS Electrical Services is a Cincinnati based electrical contracting company that has been specializing in complex industrial installations since 1997.  We provide a unique approach to the many facets of the industrial market that set us apart from the rest.  Our services include full service electrical installations, outage and startup support, PLC system upgrades, instrumentation installation & Calibration, electrical design-build, UL Listed control panel assembly, automation & programming, and maintenance & repairs.</i><br />Target victim <b>website</b>: <i>icselectricalservices.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>C.A.-LINDMAN-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30301</link>
<guid>bc8147ca69573b8a699c18e7ddbcfb48</guid>
<pubDate>Fri, 06 Mar 2026 11:42:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>C.A.-LINDMAN-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81211b36da09c4e8896715fd95b01ebbfe004e9e3c2162a59c78ac52c43b0727</i><br /><br />Threat actor <b>description</b>: <i>Numerous data items, including financial and project details, were leaked from servers located at the company's headquarters in Florida, Maryland, and North Carolina.

C.A. Lindman, Inc., founded in 1990, has grown from a small restoration company with less than 10 employees, into one of the top 20 national firms specializing in exterior concrete and masonry repairs over the last 30 years. The founders, Rob Pusheck and Jeff Procter, have kept Lindman focused on meeting all of their clients’ needs and expectations. The “Lindman Difference” is the company’s motto and delivering this superior service is the company-wide goal every day.</i><br />Target victim <b>website</b>: <i>www.calindman.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edgar-Agents</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30297</link>
<guid>bdb7179e2db5dca88a7117c1d344a553</guid>
<pubDate>Fri, 06 Mar 2026 09:41:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Edgar-Agents</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>887077b778e2dc37ae817bd1554742bfa1030d060d5d330a153fa23c46d0f049</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>pacepacific.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30296</link>
<guid>ed4e17d67f76e380e297298c8629c38d</guid>
<pubDate>Fri, 06 Mar 2026 07:35:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>pacepacific.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1027e1f76ed3ce3aedc6660658c99444f276629bf0b16e0e01cc15f279d7782</i><br /><br />Threat actor <b>description</b>: <i>PACE Pacific Corporation is a Native American woman-owned small business that specializes in general contracting services in Arizona and New Mexico. Established in 1991, the company provides ground-up construction services for a diverse range of clients, including state, local, federal, tribal entities, and private developers. PACE offers comprehensive capabilities such as Construction Management, Self-Performing Concrete Division, and Design-Build Services, while maintaining a commitment to quality and a trained professional team. With extensive experience in sectors like education, healthcare, and military facilities, PACE aims to exceed client expectations as both a prime and subcontractor Employees: 200  Revenue: $13.2 Million Industry: Construction Management  Phone Number: (602) 437-8729</i><br />Target victim <b>website</b>: <i>pacepacific.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CFGI-Management-LLC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30294</link>
<guid>708f29ec20d162afd5d0f6e9506c3933</guid>
<pubDate>Fri, 06 Mar 2026 03:47:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>CFGI-Management-LLC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d17186ce2266b2a94d097440f01650bbbc0744bff44d440f0340f4b20eb75c73</i><br /><br />Threat actor <b>description</b>: <i>Over 800k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 09 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 06 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>MedicalGPT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30291</link>
<guid>c9bbba509b7304e3aec72ce594a0bec1</guid>
<pubDate>Fri, 06 Mar 2026 03:10:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>MedicalGPT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>175972a53ea7177cb1fb10e64258bf700aa19edd2a8947cb154adb65e455b777</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>medicalgpt.info</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>yurdriversnetwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30290</link>
<guid>e0f4d7c0453ad5d27b69eba851357a31</guid>
<pubDate>Fri, 06 Mar 2026 03:09:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>yurdriversnetwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca3d8cf2e5dcfe44558fa9ec411ebdba3529d1e3e710cb9449304c42330a0986</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>yurdriversnetwork.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>northstaria.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30289</link>
<guid>216cbd05fb1918ba700506718cd8d915</guid>
<pubDate>Thu, 05 Mar 2026 22:28:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>northstaria.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2b8ac69b1c69dcfdedd632784f1d0721ba8c78cacbb677388df2ffb51c56e68</i><br /><br />Threat actor <b>description</b>: <i>North Star Insurance Advisors is the leading final expense telesales company in America, dedicated to serving the senior market, agents, and partners. The company offers innovative training, a competitive compensation structure, and limitless growth opportunities for agents and partners. With over 40 years of combined experience, North Star utilizes proprietary technology to assist families with their final expense needs. As a purpose-driven organization, they prioritize people and aim to provide valuable resources to navigate life's challenges. Employees: 200 Revenue: $44.9 Million Industry: Insurance Phone Number: (636) 205-5005</i><br />Target victim <b>website</b>: <i>northstaria.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>parkerlipman.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30288</link>
<guid>bc5e6eabfbafdca716f42c5e69644480</guid>
<pubDate>Thu, 05 Mar 2026 18:59:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>parkerlipman.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1416c2e3f75500213697c3d71f8a982e761183fd815d74ea08166dce84153c1</i><br /><br />Threat actor <b>description</b>: <i>Parker Lipman LLP is a premiere Denver personal injury law firm working for years, protecting the rights of the injured. Call our experienced attorneys for representation in personal injury and accidents.</i><br />Target victim <b>website</b>: <i>parkerlipman.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tennessee-Valley-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30282</link>
<guid>81dd12121d041b1cff1d0792266b2ce6</guid>
<pubDate>Thu, 05 Mar 2026 18:38:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tennessee-Valley-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3cdb7006478d1d3cb06a28838702264108cdd4e51329eda3007c7f6364747cfa</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ELC-Security-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30286</link>
<guid>654146dbdcd94564df622bab7dfaba8b</guid>
<pubDate>Thu, 05 Mar 2026 18:36:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ELC-Security-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f22e92379845c909d1f9bfcfe60e3355d7a575c5ee2c77de98f2179104674928</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.elcsecurity.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Applied-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30278</link>
<guid>1d7c91037101cce725efa1fe469232a5</guid>
<pubDate>Thu, 05 Mar 2026 16:38:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Applied-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>292ca00e6f6573cca893d545fa6207ed427a6873fc75e8c8114e4efc6a05158d</i><br /><br />Threat actor <b>description</b>: <i>Applied Products, Inc. is a leading supplier of high-performance,pressure-sensitive adhesives for various OEM industries such as HVAC, construction, automotive, and appliance manufacturing.We will upload corporate data soon. Employee passports, DLs, projects, confidential agreements, clients docs, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>K--S-Company-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30273</link>
<guid>5ceda82de78ea91d4c01e536a0673341</guid>
<pubDate>Thu, 05 Mar 2026 14:39:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>K--S-Company-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ff484eac5eeb89d5125cc24051a2f873809455c763e926c7a49bd7239d63cf6</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>DesignSourceCT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30275</link>
<guid>5131f6caead4314643b671b624714d94</guid>
<pubDate>Thu, 05 Mar 2026 14:39:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DesignSourceCT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c36f06707030a3ad8682529f2dfd18ae15f87a507146b8d880960e47b573d547</i><br /><br />Threat actor <b>description</b>: <i>DesignSourceCT is Connecticut's largest and most comprehensive designer showroom, established in 2005, catering to trade professionals and their clients. The showroom offers a thoughtfully curated selection of high-quality home furnishings, including fabric, furniture, flooring, and more from trusted brand names.We will upload corporate data soon. Projects, contracts, clients docs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>CTI--Coordinators</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30272</link>
<guid>a0318d32cb96f76323313e33d189b3ce</guid>
<pubDate>Thu, 05 Mar 2026 12:41:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>CTI--Coordinators</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f81586f1a944e23ae01a31425e61f8746bf7aafe3e53f34df25c2b870317c08</i><br /><br />Threat actor <b>description</b>: <i>Freight transportation services throughout the United States and province of Ontario Canada</i><br />Target victim <b>website</b>: <i>cticoordinators.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jameson-Pepple-Cantu-PLLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30269</link>
<guid>03de7a07ac1437954fb6ed41b144e18d</guid>
<pubDate>Thu, 05 Mar 2026 08:23:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>Jameson-Pepple-Cantu-PLLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c175283ee2618e3c0bcfdc5246540fe1f5ffac2595ba4864f516b82114cd2b3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Jameson Pepple Cantu PLLC is a boutique law firm located in Houston, Texas. This firm provides a broad range of legal services but specializes in areas related to business such as Corporate Law, Real Estate, Mergers and Acquisitions, and Securities. The team, made up of experienced professionals, prides themselves in their dedicated and personalized approach to each client's legal needs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>piglerautomation.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30266</link>
<guid>7bc8c88bb24cbfee9378e0af71e171a1</guid>
<pubDate>Thu, 05 Mar 2026 02:13:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>piglerautomation.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>402db62b703fb3bfd0b972d5669e95fab545afd14d087c4bf63083c40c9410f6</i><br /><br />Threat actor <b>description</b>: <i>Pigler Automation specializes in Industrial Automation System Integration, helping clients streamline and modernize their operations to enhance efficiency and productivity. Their services include control system consultation, project planning, and support for various industries such as biopharma, oil and gas, and energy. With over 20 years of experience, their team of certified engineers offers expertise in SCADA design, PLC programming, and system integration. Pigler Automation aims to bridge the gap between legacy systems and cutting-edge automation, ensuring clients can optimize performance and stay ahead of industry challenges. Employees: 50  Revenue: $5 Million Industry: Industrial Machinery & Equipment Phone Number: (866) 871-1456 </i><br />Target victim <b>website</b>: <i>piglerautomation.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>DOCTUS-USA-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32984</link>
<guid>ff3c93fc42532372383929e6d8f7de0e</guid>
<pubDate>Wed, 04 Mar 2026 23:08:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>deadlock</b> claims attack for <b>DOCTUS-USA-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da6fa83a970b3604ffcc31b7558d0a96c2425ebf8f3f8dde4c8c10db06074513</i><br /><br />Threat actor <b>description</b>: <i>Doctus offers top-tier medical records services in the USA, specializing in the management and organization of medical documentation.</i><br />Target victim <b>website</b>: <i>doctususa.com</i>]]></description>
<category>deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Environmental-Air</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30264</link>
<guid>69654c562132cec527c1ac7bf54e2791</guid>
<pubDate>Wed, 04 Mar 2026 20:42:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Environmental-Air</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>27e9259446b8aa860de43efa4d5e93f5f324d1e1315870b1030de29eeb059150</i><br /><br />Threat actor <b>description</b>: <i>Environmental Air, Inc. has been a trusted provider of Sheet Metal Fabrication, Custom Ductwork Fittings, Welding, and HVAC Installation services for over 40 ye...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>saturnmachine.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30263</link>
<guid>2a58c8ee009158220b7b2c03e333db41</guid>
<pubDate>Wed, 04 Mar 2026 18:40:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>saturnmachine.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f68360b79a952a5ce4e7dd15f05403b400dbd841042b3c6d0ccf48a8cd764f5</i><br /><br />Threat actor <b>description</b>: <i>Saturn Machine is a leading designer and manufacturer of equipment for major steel companies in North America, specializing in steel fabrication, machining, laser processing, and sandblasting. The company prides itself on delivering high-quality products and problem-solving solutions, supported by a team of skilled professionals and advanced machinery. With capabilities in mechanical and electrical engineering, hydraulic system design, and welding fabrication, Saturn Machine aims to expand its services to a broader client base. Their commitment to customer satisfaction and excellence in design sets them apart in the steel products manufacturing industry. Employees: 50 Revenue: $6 Million Industry: Industrial Machinery & Equipment Phone Number: (270) 333-2104</i><br />Target victim <b>website</b>: <i>saturnmachine.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CJL-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30256</link>
<guid>76a77077b53444d655fff2a6c350d5ca</guid>
<pubDate>Wed, 04 Mar 2026 18:40:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CJL-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>724dc7dbb2e0ce551959742198a59e0577201934914bd3e4e79e899881fba9c2</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MarketGraphics-Research-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30249</link>
<guid>c86027cb65669a6bec290bd22c969f2d</guid>
<pubDate>Wed, 04 Mar 2026 16:40:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MarketGraphics-Research-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddb5dca84a69e3403775f20a179d9fb7b7bc454bddd51f043aaa8d4919918798</i><br /><br />Threat actor <b>description</b>: <i>MG Research Markets specializes in providing comprehensive housing market research and analysis services. The company serves a diverse range of clients by delivering accurate and forward-thinkingdata through various interactive tools and GIS services.We will upload 60gb of corporate data soon. Personal files of employees (passport and DL numbers, SSNs and so on), detailed financials, projects, contracts, NDAs, partners and clients contacts and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>lawofficesoferichershler.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30254</link>
<guid>58e36f59f7e532acacf9cb6ef1ab91b9</guid>
<pubDate>Wed, 04 Mar 2026 15:47:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>lawofficesoferichershler.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c08d380bd578b5e7432ebb796bb70e2abc468c999def21608e9be3eeabd5852</i><br /><br />Threat actor <b>description</b>: <i>The Law Offices of Eric Hershler, APC, in Los Angeles, focuses exclusively on personal injury cases.</i><br />Target victim <b>website</b>: <i>lawofficesoferichershler.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>hopkins-law.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30253</link>
<guid>7e909d0e18cec1ad8ad9076be0b669c2</guid>
<pubDate>Wed, 04 Mar 2026 15:46:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>hopkins-law.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de970a4a486a62410c80455448327d92ed2e5ee2699af0c2db08c6c4f23ef1f2</i><br /><br />Threat actor <b>description</b>: <i>Hopkins Barvié & Hopkins, P.L.L.C. is your trusted Gulf Coast firm for personal injury, business litigation, and family law—fiercely protecting your rights while guiding you with honesty, respect, and genuine care.</i><br />Target victim <b>website</b>: <i>hopkins-law.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>bclawoffices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30251</link>
<guid>6b1d7eadb42d159909af05a7a6d88989</guid>
<pubDate>Wed, 04 Mar 2026 15:45:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>bclawoffices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad0c1057e2dbb4700fe11fc35d68512307efc1c46940889046a335d92aa8382f</i><br /><br />Threat actor <b>description</b>: <i>At the Law Offices of Brent W. Caldwell, we help people who have been injured in accidents get the legal support they need during a difficult time. While there are many personal injury firms in California and Nevada, we take pride in being more than just a law office with strong results. We are focused on building real relationships with our clients and treating every case with the attention it deserves.</i><br />Target victim <b>website</b>: <i>bclawoffices.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reynolds-DeMarco--Boland</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30250</link>
<guid>1951440c60517e1646b22e78584305b1</guid>
<pubDate>Wed, 04 Mar 2026 15:40:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Reynolds-DeMarco--Boland</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8cadc167c7fb333b6be84b3405de4e1e13d2fcf64869d7b2c064cf8dbf5a8bc</i><br /><br />Threat actor <b>description</b>: <i>Reynolds, DeMarco Boland, Ltd. is a general litigation law firm based in Rhode Island, specializing in insurance law, personal injury, civil rights, and numerous other practice areas. The firm primarily represents insurers and their insureds in civil litigation, as well as providing legal advice for first party claims and coverage issues.We will upload over 100gb of corporate data soon. Clients' personal files (w9, i9 forms, passports, DLs, SSNs, medical records), police reports, court files, and other confidential files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huffman-Insurance-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30248</link>
<guid>35405f014bb0dbc14cea7766ccd0256e</guid>
<pubDate>Wed, 04 Mar 2026 14:08:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Huffman-Insurance-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2d81b0e4b9910e1fcc723ac132ca942a5debc4f3070f5917736666dc2c19e21</i><br /><br />Threat actor <b>description</b>: <i>Huffman Insurance Agency was founded in 1975 and operates in the Richlands, Virginia area with an office in Ashland, Kentucky. Huffman represents a strong network of Independent Agents offering home, car, and business insurance</i><br />Target victim <b>website</b>: <i>www.huffmaninsurancegroup.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Business-Automation-Specialists-of-Minnesota</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30247</link>
<guid>b8321cc2ef02a2823b92d06f2ea3e298</guid>
<pubDate>Wed, 04 Mar 2026 14:00:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Business-Automation-Specialists-of-Minnesota</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca467dbb6c0b4ae28ece483b14397851f35889aa861647afc56acd56a9ef2e42</i><br /><br />Threat actor <b>description</b>: <i>Business Automation Specialists (BASM) is a Microsoft Partner tha
t focuses on providing implementation, consultation, customizatio
n, and support for Microsoft Dynamics 365 Business Central and NA
V.

We will upload 10 gb of corporate data soon. Employee personal fi
les (passports, DLs, medical files), NDAs, contracts and agreemen
ts, financials, projects, clients' files, internal confidential f
iles, and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>HTH-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30246</link>
<guid>a3e2acf65a87adb6db5976ca4f149665</guid>
<pubDate>Wed, 04 Mar 2026 14:00:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>HTH-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06cbaffee268471437935bace6e6a33aedc0a9692b94b5243261fc1f7a9ee2c5</i><br /><br />Threat actor <b>description</b>: <i>HTH Companies Inc. is a leading professional industrial service p
rovider, specializing in scaffold erection, mechanical insulation
, industrial cleaning, industrial maintenance, mechanical work, a
nd painting and coatings.

We will upload over 60gb of corporate data soon. Employee persona
l files (i9, w9, passports, DLs, medical information), NDAs, cont
racts and agreements, projects, financials, confidential files, a
nd so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nicholas--Tangeman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30245</link>
<guid>936a0bd1ac3c96d08aa66bfbc3ed9758</guid>
<pubDate>Wed, 04 Mar 2026 14:00:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nicholas--Tangeman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d6650e0eb9e548d2a419ede1cc98e1b9e3ea452ca1153207615c4a0af338143</i><br /><br />Threat actor <b>description</b>: <i>Nicholas & Tangeman, LLC is a general practice law firm based in 
Laramie, Wyoming, serving clients in Wyoming and Colorado. The fi
rm offers a wide range of legal services including civil litigati
on, criminal law, personal injury, estate planning, and corporate
business planning.

We will upload over 100gb of corporate data soon. Lots of clients
' personal files (passports, DLs, medical record), NDA, police re
ports, court files, and other confidential files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-City-of-Hesperia-CA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30241</link>
<guid>a0ac90988690d6ab675e7758a92d5828</guid>
<pubDate>Wed, 04 Mar 2026 12:40:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>The-City-of-Hesperia-CA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e46adefb58c90f66634c525d9f8ff84706f31aa43a31876da701c65f1fa367d</i><br /><br />Threat actor <b>description</b>: <i>Access was gained to files containing state secrets, non-disclosure agreements, contracts with private and public companies, as well as personal data of employees and government officials. Transactions, payment, and tax documents were also obtained.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>ATS-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30239</link>
<guid>12f9ed7d561f5536e2316645dba28c66</guid>
<pubDate>Wed, 04 Mar 2026 11:48:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ATS-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c96dfcabbb5c8365bbdb6faef41ddce409ddb03a37d6f9a14e933eee319d7e1</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.theatsgroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vision-Aero</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30238</link>
<guid>b276f01d37dac0090b04042539a2aaab</guid>
<pubDate>Wed, 04 Mar 2026 11:47:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Vision-Aero</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29e893b2009f4af84b2883ed7ff91198a7bd59cd8700844e43df364c789b31c1</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.vision.aero</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>cwpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30237</link>
<guid>965052c6a03942b536a3ff2d134d61c1</guid>
<pubDate>Wed, 04 Mar 2026 11:13:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cwpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37698c04516e92b4cd8fce14ed6e2a3cde13575f299426a6c32d5c10256383e7</i><br /><br />Threat actor <b>description</b>: <i>Office Products Retail & Distribution PO Box 11309, Spring, Texas, 77391, United States Phone Number (281) 251-9814 Website www.cwpa.com Revenue <$5 Million  CWPA is a provider of office equipment and furniture, specializing in customized solutions to improve office efficiency for businesses in Spring, TX. They offer a single-source approach for office supplies, managed print services, promotional products, and office ergonomics. Their intended clients include office managers and businesses seeking reliable, efficient ordering processes. CWPA emphasizes personalized customer service and prompt delivery, making them a preferred partner for various office supply needs.</i><br />Target victim <b>website</b>: <i>cwpa.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bravo-Electro-Components</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30232</link>
<guid>9b01ea73aa4de36440a527d52e63870a</guid>
<pubDate>Wed, 04 Mar 2026 09:36:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Bravo-Electro-Components</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7cc224df154a567323632f088d9de5d3efa2ff5ac6a24519c4d229a9f166ad3</i><br /><br />Threat actor <b>description</b>: <i>Bravo Electro specializes in providing a wide range of power supplies, including AC/DC converters, medical power supplies, and modular power solutions. They also offer various fan products, including DC and AC fans, along with components for custom power solutions. Their target clients include engineers, purchasing agents, and technicians looking for reliable power solutions and expert design support. With a commitment to customer service and competitive pricing, Bravo Electro aims to empower designs with exceptional service and technical expertise</i><br />Target victim <b>website</b>: <i>bravoelectro.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ICAFe-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30231</link>
<guid>975643d32f495b3ef6409c11fa1dec18</guid>
<pubDate>Wed, 04 Mar 2026 09:28:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ICAFe-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ec388da426b01e54c1956c859713eac6073e8feff0eda06dcf3ba9421cc51fd</i><br /><br />Threat actor <b>description</b>: <i>Southwest Air Equipment is a single-source equipment supplier ded
icated to the spray foam industry, offering comprehensive service
s including replacement parts, repairs, and complete spray rig se
tups.

We will upload corporate data soon. Lots of clients files, NDAs, 
contracts and agreements, financials, confidential files, a bit o
f personal information and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Klevorn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30229</link>
<guid>c105ca8b5f446bfd69de73e75defe1ac</guid>
<pubDate>Wed, 04 Mar 2026 06:41:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Klevorn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22030a1fefb3e5029a43e61194b9279ca9a34fd3c8776a446a9d51bc96684e07</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Napolin-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30225</link>
<guid>a45045acdffeec7b92ea019675da48fc</guid>
<pubDate>Wed, 04 Mar 2026 00:42:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Napolin-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f1d27ef5bf0f0f3fa00c26b34151271184c1de5ad7be9d6dc305171adbfd460</i><br /><br />Threat actor <b>description</b>: <i>Alexander D. Napolin is a top-rated, 100% plaintiff-side California personal injury attorney, exclusively advocating for injured individuals – never defending insurance companies or corporations.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-of-Mark-E.-Lewis--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30224</link>
<guid>f9d6b4b6c27bc520071ac934b5845e50</guid>
<pubDate>Wed, 04 Mar 2026 00:41:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Law-Offices-of-Mark-E.-Lewis--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49fdba302c117ff9d5069cfe27eb1ff3e798416ea0537fc347b75b765d437914</i><br /><br />Threat actor <b>description</b>: <i>At the Law Offices of Brent W. Caldwell, we help people who have been injured in accidents get the legal support they need during a difficult time. While there are many personal injury firms in California and Nevada, we take pride in being more than just a law office with strong results. We are focused on building real relationships with our clients and treating every case with the attention it deserves.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brockman-Injury-Lawyer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30222</link>
<guid>467fc60274ae2cefade0487f255c3f5d</guid>
<pubDate>Tue, 03 Mar 2026 22:41:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Brockman-Injury-Lawyer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a594631a45cce285a5201712a66ad76fbc42213e2c39fee5cb67e2fb8bf4bce9</i><br /><br />Threat actor <b>description</b>: <i>The attorneys at Jonathan R. Brockman, P.C. are dedicated to helping victims who have been injured or killed due to the negligence of others. Between them, our attorneys have more than 70 years of experience pursuing personal injury claims on behalf of clients and representing clients in a court of law. They have successfully tried cases in federal court and argued cases in the Georgia Court of Appeals and the Georgia Supreme Court.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hersher-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30221</link>
<guid>6d658d7273dabf3a616e9193db0446d8</guid>
<pubDate>Tue, 03 Mar 2026 22:41:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Hersher-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3fc86c8908ad3f9dc8b49077a3c4cd753b365fad388f4f4d99624d775f7aa86</i><br /><br />Threat actor <b>description</b>: <i>The Law Offices of Eric Hershler, APC, in Los Angeles, focuses exclusively on personal injury cases.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hopkins-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30220</link>
<guid>8e958e9a4d44b87aeb02e489dc7c48ec</guid>
<pubDate>Tue, 03 Mar 2026 22:41:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Hopkins-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a2b9c5090b198746282c14668f1f783bc87bd4d217980cccf033f158a93064a</i><br /><br />Threat actor <b>description</b>: <i>Hopkins Barvié & Hopkins, P.L.L.C. is your trusted Gulf Coast firm for personal injury, business litigation, and family law—fiercely protecting your rights while guiding you with honesty, respect, and genuine care.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawrence-Journal---World</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30219</link>
<guid>981d50d64a8d5a7d90aa7eb49927e1b9</guid>
<pubDate>Tue, 03 Mar 2026 22:37:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Lawrence-Journal---World</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3aa505c3479fbf745d482028f760e14a4b4ba38208b2b0419fe7dbe81299294</i><br /><br />Threat actor <b>description</b>: <i>Lawrence Journal-World is a news organization based in Lawrence, Kansas, providing coverage on diverse topics including news, sports, opinion, and community events. The publication offers a platform for local announcements, classified ads, and job listings, catering primarily to residents and the surrounding community. It also features educational insights and updates relevant to local schools and government activities. Target clients include local residents, businesses, and those interested in Lawrence's happenings.</i><br />Target victim <b>website</b>: <i>ljworld.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Minogue-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30218</link>
<guid>051b614de48247432c8a44200229791d</guid>
<pubDate>Tue, 03 Mar 2026 22:36:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Minogue-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a82507057cd982a7c5ed6368afc2ef1b6b3ecd3fdf99691ef5ea57ab0f3fd17d</i><br /><br />Threat actor <b>description</b>: <i>Minogue Associates, Inc. specializes in comprehensive construction valuation reports and estimates for both commercial and residential properties, as well as consulting services for construction litigation. Established in 1973, the company has extensive experience in damage assessment and estimating services for a wide range of structures, including high-rise buildings, hotels, and schools. Their clients include property owners and insurance companies seeking expert appraisal and dispute resolution services. With a reputation for professionalism and integrity, Minogue Associates handles high-profile assignments involving significant financial exposures.</i><br />Target victim <b>website</b>: <i>minogueassociates.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>GapVax</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30212</link>
<guid>75ef1021ee69eb5414f2103193d4c8dc</guid>
<pubDate>Tue, 03 Mar 2026 20:10:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GapVax</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0fba206417252cdf94be576f1cafca2c1f96115873d5b4272ad717c0ba44f777</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gapvax.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Katz-Kantor-Stonestreet--Buckner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30211</link>
<guid>0fb14adee231d12b0f1465448626e6f7</guid>
<pubDate>Tue, 03 Mar 2026 19:42:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Katz-Kantor-Stonestreet--Buckner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f675bbcff209c6c94202a3fb000726508a07a737e05b6809c7466768b4b60f02</i><br /><br />Threat actor <b>description</b>: <i>Katz, Kantor, Stonestreet & Buckner serves all of West Virginia with compassionate and zealous legal representation built on decades of experience. Established in 1931, our firm has been representing clients from Bluefield, Princeton, Beckley, Welch, Lewisburg, Charleston, Morgantown, and all areas in between in West Virginia for over 88 years.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conklin-Office-Furniture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30208</link>
<guid>2947f6c206cc56866a88cc47130625d7</guid>
<pubDate>Tue, 03 Mar 2026 19:40:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Conklin-Office-Furniture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>544fd82ea7b22dcb3b1e4fcb61d439fa08bbcc4bfe1f2b0ea80a89b07a6513ba</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>JBC-Computers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30209</link>
<guid>0f47d8af9d0abe580c26d8551f4071f1</guid>
<pubDate>Tue, 03 Mar 2026 19:40:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>JBC-Computers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce0ed46dde81cabba623f883d0046c0cc668a37784be8f755589cf37a628ce0e</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.chrishudsonlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30210</link>
<guid>c01afd54a92fec65ed6d29f568cebd48</guid>
<pubDate>Tue, 03 Mar 2026 19:39:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.chrishudsonlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>556b9c0379abd7ce9f5bbda13086919f16bc9dfe5197bda7a46d73bacbf01c17</i><br /><br />Threat actor <b>description</b>: <i>At Chris Hudson Law Group, we value the attorney-client relationship and understand that being an injured party in an accident is a stressful and overwhelming experience — things are even worse if there is a permanent disability or if a death occurs. We're here to help you recover and move past this difficult time.</i><br />Target victim <b>website</b>: <i>www.chrishudsonlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Encompass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30199</link>
<guid>f164ba76f5fba1522bfbb098c4597aa6</guid>
<pubDate>Tue, 03 Mar 2026 16:41:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Encompass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39e129e1178c0a067564b6310cc4182ea921e39cd200df854647b7a108630955</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2001 and headquartered in Clarksville, Virginia, Encompass Solutions is a preferred Epicor partner and Value-Added Re-seller (VAR), that delivers mis...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Belmont-Plastic-Surgery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30201</link>
<guid>5e5c6be7a4b64ead7fe95a284e013e18</guid>
<pubDate>Tue, 03 Mar 2026 15:14:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Belmont-Plastic-Surgery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbe1b5a850f9601d5e2023bb97e08afeca4070673a248a16b1b2214617531f2c</i><br /><br />Threat actor <b>description</b>: <i>Belmont Plastic Surgery, led by award-winning surgeon Dr. Jules Feledy, offers comprehensive cosmetic and reconstructive procedures. The practice specializes in breast augmentation, body contouring, and facial rejuvenation, delivering natural-looking.</i><br />Target victim <b>website</b>: <i>www.belmontplasticsurgeryva.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>maisonlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30200</link>
<guid>b453b5a7a737a3fc489fa11aaac1618b</guid>
<pubDate>Tue, 03 Mar 2026 15:11:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>maisonlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7ced33d267930c245f4dec0b5e1134f2d4d02fbf473ccae5a22eb9a95db07559</i><br /><br />Threat actor <b>description</b>: <i>Maison Law provides skilled, experienced, and personalized legal guidance to the voiceless and the injured in the Central Valley.</i><br />Target victim <b>website</b>: <i>maisonlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aaronson-Rappaport-Feinstein--Deutsch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30195</link>
<guid>f14e3a6ee7be3b52ad152791d821faa5</guid>
<pubDate>Tue, 03 Mar 2026 09:46:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Aaronson-Rappaport-Feinstein--Deutsch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9896d0efbd69becf09fa9e3a2e35b62f3bcd9875e60e21a04bcd04bf8e14d9f4</i><br /><br />Threat actor <b>description</b>: <i>Aaronson Rappaport Feinstein and Deutsch, LLP is a New York-based law firm that specializes in providing legal services across various practice areas, including medical malpractice, construction litigation, and product liability.</i><br />Target victim <b>website</b>: <i>arfdlaw.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dallas-Regional-Chamber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30194</link>
<guid>3a9aa4b8be741e21ba9f80b3c3684ce5</guid>
<pubDate>Tue, 03 Mar 2026 09:46:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Dallas-Regional-Chamber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abff07c72c0ad297a7ff49e7a27259e1ac2142237c7a93632be1851e048074e3</i><br /><br />Threat actor <b>description</b>: <i>The Dallas Regional Chamber is a prominent business organization known for its role as the economic growth champion and business voice of the Dallas region.It focuses on priorities such as economic development, education, public policy, and quality of life.</i><br />Target victim <b>website</b>: <i>dallaschamber.org</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>ShopBot-Tools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30193</link>
<guid>de81daf004a31370f811e649f9a6252a</guid>
<pubDate>Tue, 03 Mar 2026 09:45:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>ShopBot-Tools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>926e98e931f1f46e7bf60c03259c30a150ea9a88ef35e50560e1e04d90323c93</i><br /><br />Threat actor <b>description</b>: <i>ShopBot Tools is a leading manufacturer of high-quality CNC routers, designed for machining various materials including wood, plastic, and aluminum.</i><br />Target victim <b>website</b>: <i>shopbottools.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Navicore-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30192</link>
<guid>a154ffbcec538a4161a406abf62f5b76</guid>
<pubDate>Tue, 03 Mar 2026 09:45:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Navicore-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49ab8758e44fe1f3fcf9c25ccf53d6b125773fe2a3d8fac9af323dcd8adec2be</i><br /><br />Threat actor <b>description</b>: <i>Navicore Solutions strengthens the well-being of individuals and families through education, guidance, advocacy and support.</i><br />Target victim <b>website</b>: <i>navicoresolutions.org</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Professional-Retail-Outlet-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30191</link>
<guid>453129ee88ee891d1b7581e77eafac40</guid>
<pubDate>Tue, 03 Mar 2026 09:44:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Professional-Retail-Outlet-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2d8c2a00442d5c277a39d11d0b45ba772ed1f5fec1987fe0cbd3bdff021495f</i><br /><br />Threat actor <b>description</b>: <i>PROS specializes in facilities management and maintenance services for specialty retail chains, boasting 20 years of experience.</i><br />Target victim <b>website</b>: <i>proservicecall.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>SR-Compression-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30190</link>
<guid>fe4edcd654c99506f068af26a2c525c5</guid>
<pubDate>Tue, 03 Mar 2026 09:44:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>SR-Compression-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4b0598f930ebd0277027e4898fe0f79c6fd2e236493c6503bdb961c7bd116c1</i><br /><br />Threat actor <b>description</b>: <i>S&R Compression is an oil & energy company offering compression and vapor recovery services.</i><br />Target victim <b>website</b>: <i>sandrcompression.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Emanuelson-Podas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30189</link>
<guid>0623815a789c473725fe584c43c777e9</guid>
<pubDate>Tue, 03 Mar 2026 09:44:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Emanuelson-Podas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>289783c81f364caa0c7acf0375c95dcaf88fd59221f3fa9f83fe286d14a516c9</i><br /><br />Threat actor <b>description</b>: <i>Emanuelson-Podas, Inc. is a mechanical, electrical, and plumbing engineering firm that specializes in creating innovative building system solutions.</i><br />Target victim <b>website</b>: <i>epinc.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Promotion-Management-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30187</link>
<guid>929a74e4471269c813c699a00168c37e</guid>
<pubDate>Tue, 03 Mar 2026 09:43:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Promotion-Management-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a479b3d720ab0291c8c96c4dbc69b26728643e1de8f25e7e3644c95589d02069</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1983, Promotion Management Center, Inc. (PMC) provides fulfillment services.The company specializes in customer incentives, loyalty rewards, employee recognition awards, rebates and third party logistics (3PL) orders your programs generate.</i><br />Target victim <b>website</b>: <i>pmci.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sterling-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30186</link>
<guid>ac67dfce0ec1c3d113cfe8f34fffb366</guid>
<pubDate>Tue, 03 Mar 2026 09:42:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Sterling-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2867232486718b2b5cc5df52731022ed31d8af14f4bebc433b7d2c9125816f6d</i><br /><br />Threat actor <b>description</b>: <i>Sterling Industries is a North American-based contract manufacturer and assembler of medical devices and sub-components.</i><br />Target victim <b>website</b>: <i>sterlingindustries.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Raw-Seafoods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30185</link>
<guid>9022449a6088c336116c9b5fe457c700</guid>
<pubDate>Tue, 03 Mar 2026 09:42:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Raw-Seafoods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4169cac4708c8bd1e396a50c7b926d074a2742d5561d59a9ced9f5b04012e3a9</i><br /><br />Threat actor <b>description</b>: <i>Raw Seafoods, Inc. is a family owned and operated company in Fall River, Massachusetts dedicated to providing our customers with exceptional products, and service.We specialize in fresh and frozen scallops, fish and value-added food solutions.</i><br />Target victim <b>website</b>: <i>rawseafoods.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lewis-Drug</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30183</link>
<guid>50a0eaaf3cd93fa86551c7112c259a3a</guid>
<pubDate>Tue, 03 Mar 2026 09:41:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Lewis-Drug</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b0e0df385e8b4efe16141da1d64508c7c60d26abfc90dbb3c73c87d480c36ed</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1942, Lewis Drug owns and operates a chain of drug and pharmacy stores.It provides prescription and non-prescription drugs.</i><br />Target victim <b>website</b>: <i>lewisdrug.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>HomeSite-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30182</link>
<guid>c42af68f28d516c05caf4ef35a6c4b0c</guid>
<pubDate>Tue, 03 Mar 2026 09:41:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>HomeSite-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>244a77058058d0bad501f0c68116c55d6334f7c94a2bcc2265dd239d71a5033d</i><br /><br />Threat actor <b>description</b>: <i>HomeSite Services Inc., a residential, commercial and retail services company, was founded in 2005 with three goals in mind:to perform superior work, offer quality products, and provide our clients with unbeatable service.</i><br />Target victim <b>website</b>: <i>homesiteservices.net</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Revival-Animal-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30181</link>
<guid>e02476ced92efdc385c3fca2c0de05fd</guid>
<pubDate>Tue, 03 Mar 2026 09:41:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Revival-Animal-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>746cebe04e33f8f71076aaa17359c20e0d6971d0e54589087ce69dd9a0857136</i><br /><br />Threat actor <b>description</b>: <i>Revival Animal Health was founded in 1989 by Dr. Roy Nielsen, Jr., affectionately known as "Doc Roy."Quickly the company expanded from pet vaccines to an extensive line of pet healthcare products.</i><br />Target victim <b>website</b>: <i>revivalanimal.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integral-Analytics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30179</link>
<guid>77161bf6b433fd5a7d8f2b6da38384d9</guid>
<pubDate>Tue, 03 Mar 2026 09:40:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>AiLock</b> claims attack for <b>Integral-Analytics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb1b413bd7b34a6dad443ed87656be2fb5c0e668d756bb403cdd68afa36f9b1a</i><br /><br />Threat actor <b>description</b>: <i>Integral Analytics specializes in data intelligence solutions for the energy sector, focusing on improving planning and forecasting for utilities, producers, manufacturers, and regulators.Their flagship products include LoadSEER, DSMore, and IDROP, which assist in energy efficiency, demand response, and distributed energy resource management.</i><br />Target victim <b>website</b>: <i>integralanalytics.com</i>]]></description>
<category>AiLock</category>
</item>
<item xmlns:dc='ns:1'>
<title>IOTA-HOTEL-TBILISI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30178</link>
<guid>135781112da49675bbf837615b1ac977</guid>
<pubDate>Tue, 03 Mar 2026 08:46:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>IOTA-HOTEL-TBILISI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e472eda711cee4b578ab495028c7ee03b22901f3cbf3e35e81390bead2294c47</i><br /><br />Threat actor <b>description</b>: <i>- VIP Lists- Invoices, Passport...- Financial Documents</i><br />Target victim <b>website</b>: <i>iotahotels.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Andal-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30177</link>
<guid>fdacbbcc2ed7e3b738dd9b305a9f0515</guid>
<pubDate>Tue, 03 Mar 2026 05:09:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Andal-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a02be1b8e01f4fa18f3235862e6a23d48dfb1339b2557eb598028b7311752f4a</i><br /><br />Threat actor <b>description</b>: <i>Injury accident law firm data breach: driver IDs and other personal data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woflow-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30176</link>
<guid>bc6c8ec976e7e344ee61d0d2bd54838b</guid>
<pubDate>Tue, 03 Mar 2026 04:46:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Woflow-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ad4292843df06c25ddfac687f452a97579f058e29f0d8196b8243b36660f4d5</i><br /><br />Threat actor <b>description</b>: <i>Several hundreds of millions of records containing PII, transaction/order data, other internal corporate data, and a lot more (you don't want us to say publicly) have been compromised. This is a final warning to reach out by 05 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 03 Mar 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bartram-Trail-Surveying</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30174</link>
<guid>3384c1784cc82c0416e1d66d0f38baaf</guid>
<pubDate>Tue, 03 Mar 2026 02:21:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Bartram-Trail-Surveying</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac5674e37134cba16e457fc4fb1c0627c380c00f66fea6a2662894545c6d225d</i><br /><br />Threat actor <b>description</b>: <i>Bartram Trail Surveying, Inc. is a Florida licensed land surveying company that specializes in providing accurate and precise land surveying services across the state. Utilizing state-of-the-art technology, including drone surveying, LiDAR, and GIS, they cater to builders, engineers, and clients involved in land development projects. 
</i><br />Target victim <b>website</b>: <i>www.bartramtrail.net</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lundeen-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30171</link>
<guid>c625cd198573c817ebd635325e37cad0</guid>
<pubDate>Mon, 02 Mar 2026 23:37:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lundeen-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04d181aacd59925b79f0f9e5eaaa24366809c69bb06a2ff4140d9b3bcc84b6bb</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bayshore-Ford-Truck-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30173</link>
<guid>9181303866f74e72f4b4b39ffbd6a330</guid>
<pubDate>Mon, 02 Mar 2026 23:37:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bayshore-Ford-Truck-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0332e2673f24633428610153449149b915e6525246003d00dcd4e8bb5e4cbb7</i><br /><br />Threat actor <b>description</b>: <i>Automotive Parts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>GordonClifford-Realty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30170</link>
<guid>376557cb7cd4da934b134a58709022a3</guid>
<pubDate>Mon, 02 Mar 2026 21:50:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GordonClifford-Realty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad48abe0790676dc332f53e22b603bbbd509843c3a6318b4278eaa9313243eba</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gordoncliffordmanagement.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Kuker-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30168</link>
<guid>9f365ac1b27ce95a3f99bdcc68420756</guid>
<pubDate>Mon, 02 Mar 2026 21:49:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Kuker-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>484e324deee276875728a983653d3c54f8e438cad3d4fa1b5db79f1d1afea0c1</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ohklegal.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>LRA-Constructors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30167</link>
<guid>865476c5e0cd0523e326757deceaae4a</guid>
<pubDate>Mon, 02 Mar 2026 21:49:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>LRA-Constructors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>614bccf2a88e5393418467575b6b4f057b8bfd629cccccad6e09a6657925cbfe</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.lraconstructors.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cobblestone-Creek-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30166</link>
<guid>fa7d9e789db0b0f053e0229ebc2aed0e</guid>
<pubDate>Mon, 02 Mar 2026 21:48:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cobblestone-Creek-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>faddbd7f6b89e5db58d8a9ee66266e8d9ecf866ad2a83763ce4509375f68b7b2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cobblestonecreekcc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Project-Consulting-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30165</link>
<guid>4b794d8229db8f33a386b3cbba9eeeee</guid>
<pubDate>Mon, 02 Mar 2026 21:47:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Project-Consulting-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e80dd05a4e0f5509f9dd90c552422fad4f4d938fa08e719a819e546be7f924fa</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.projectconsulting.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Go-Professional-Cases</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30164</link>
<guid>a26508d81dd3592b9b8dd27bf8c82e80</guid>
<pubDate>Mon, 02 Mar 2026 21:47:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Go-Professional-Cases</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95d532de1bfb94123c881284ecb4d29df51541741cfc5160c29786aadbe6f696</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.goprofessionalcases.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>WCC-Technologies-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30163</link>
<guid>e85ca00d008a532279b798033d59a4c7</guid>
<pubDate>Mon, 02 Mar 2026 21:46:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>WCC-Technologies-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e78328988a70f05d056b62fedaf2d96bb8969a8cad02123329ffabc012a49ad</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wcctechgroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Favaro-Lavezzo-Gill-Caretti</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30162</link>
<guid>4727afc79cd3e723f90b611df73a8b8d</guid>
<pubDate>Mon, 02 Mar 2026 21:46:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Favaro-Lavezzo-Gill-Caretti</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff5cd8792a03deae0eb0324cf0b31452d2ae6ed109c9138956c9aafc5bf21a13</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.flgch.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>IDH-Entertainment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30158</link>
<guid>53d57871ab3fc4405f05229e639f166c</guid>
<pubDate>Mon, 02 Mar 2026 20:38:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>IDH-Entertainment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74a89f4cbcd146174f5de47e1228c4b49624298d0d3614688ac5aa1c7346e69d</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.precisioncoating.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30156</link>
<guid>da36dbd22af21eca8661ff099dfb95b3</guid>
<pubDate>Mon, 02 Mar 2026 18:36:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpswww.precisioncoating.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e464bda23b82a3e32422b8b6e31c663cfcfe2baef59a601a7c1d65c2ffeae2b</i><br /><br />Threat actor <b>description</b>: <i>All their developments, technologies, patents, data from other companies, please pay attention to the company that bought these technologies for 150 million, everything important was stolen - photo and video components   Founded in 1969, Precision Coating provides high-tolerance coating and specialized metal-finishing services to the medtech industry for applications including vascular, endosurgical, and orthopedic instruments and devices. The GlideLine family of medical device coating finishes is the broadest offering of applied fluoropolymer (PTFE) coatings in the industry, customized to optimize the design, quality, and performance characteristics of high-quality medical products. InfiNiTiCoat is Precision Coating's proprietary low-temp cure process, optimized for coating performance on nitinol devices; specifically optimized to preserve the desired characteristics of nitinol in wire, strip, and tube forms. PCCI has unique process control over challenging nitinol handling, coating, and curing. The MICRALOX® portfolio of chemistries offers superior patented aluminum oxide coatings with a microcrystalline barrier that revolutionizes aluminum anodizing with exceptional barrier properties and corrosion</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bain-Oil-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30155</link>
<guid>ae8970f7d83581427155bc725c003594</guid>
<pubDate>Mon, 02 Mar 2026 18:06:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Bain-Oil-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de53f10b894ce3f328fca35aea61cbc55e8b188bbaf401962dba4d2af71b084c</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.bainonline.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>SIMETRI-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30154</link>
<guid>1daf6cfb21ba43954310a6dd338d0416</guid>
<pubDate>Mon, 02 Mar 2026 18:06:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>SIMETRI-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>825256763670bab515869adbca87afdc796abd4aafd23d5d40b7f44c902d7c4a</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>simetri.us</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Martin-Cukjati--Tom-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30153</link>
<guid>42cae009aa36f970c223de2959268e5a</guid>
<pubDate>Mon, 02 Mar 2026 16:31:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Martin-Cukjati--Tom-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e30597b924df26a2e57d7a6925cc6de4466a13f8d747ecd875462b33d2b3280</i><br /><br />Threat actor <b>description</b>: <i>Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southold-Town-Senior-ServicesSouthold-Police-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30150</link>
<guid>983379e5eacf56a55f44720792d81bc2</guid>
<pubDate>Mon, 02 Mar 2026 09:42:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Southold-Town-Senior-ServicesSouthold-Police-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>990752be420967ef65f20a3c6228f0c00fb867a7a84e7471c2a937a2c12b0894</i><br /><br />Threat actor <b>description</b>: <i>Southold Town Senior ServicesSouthold Police Department The Town of Southold, New York provides various government services including forms and permits, online payments, and notifications for residents. Southold Police Department is a company that operates in the Local industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Seal-Beach-and-Seal-Beach-Police-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30144</link>
<guid>a70f6138de778744f7b767b618b5d52d</guid>
<pubDate>Sun, 01 Mar 2026 20:44:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Seal-Beach-and-Seal-Beach-Police-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd9703d69d9ee25aeb633f76f1340bdfd1e188860b487384b2b39980082e2c83</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.sealbeachca.gov</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Enterprise-Network-Group-of-Indiana</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30135</link>
<guid>a00ba776735f6e27e0619d46a07be9d3</guid>
<pubDate>Sun, 01 Mar 2026 20:42:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Enterprise-Network-Group-of-Indiana</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab7194b869104adb078749ec80230574d93654963ad33beae9831013c58667a5</i><br /><br />Threat actor <b>description</b>: <i>Electronics</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>denmark.k12.wi.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30143</link>
<guid>f9ae0edbbb69c65b4ba6a4df582eb206</guid>
<pubDate>Sun, 01 Mar 2026 20:11:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>denmark.k12.wi.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e34654e0089413ea17c5e5132ab3e8475aa4cd3ed4840d9fb2d349ba197b4da1</i><br /><br />Threat actor <b>description</b>: <i>Denmark High School is a company that employs 100to249 people and has 10Mto25M of revenue. The company is headquartered in Denmark, Wisconsin. Employees: 200  Revenue: $18.2 Million Industry: Education  Phone Number: (920) 863-4200</i><br />Target victim <b>website</b>: <i>denmark.k12.wi.us</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>abramssales.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30142</link>
<guid>b056f5d60446a5d5ca7fba949cae3cfa</guid>
<pubDate>Sun, 01 Mar 2026 20:10:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>abramssales.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8265fdcf5d2bb388897c9959cae5e7a6f4184784dbbd3156124a0adc69582a73</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2001, Abrams Architectural Products, Inc. is a leading distributor, fabricator, and installer of architectural metals, particularly aluminum composite material cladding systems. They collaborate with architects and general contractors to ensure their visions are realized through quality products, expert solutions, and tailored services. Their product offerings include a variety of architectural metal systems for both exterior and interior cladding, catering to projects of various sizes and complexities. With a strong reputation for excellence, they serve a diverse range of clients across the United States, providing top-tier general contracting services in fields such as airports, museums, and medical centers. Employees: 50  Revenue: $5.3 Million Industry: Architecture, Engineering & Design  Phone Number: (770)745-8728</i><br />Target victim <b>website</b>: <i>abramssales.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Special-Shapes-Refractory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30136</link>
<guid>cb804af641d900ffe033193d2b7c4a84</guid>
<pubDate>Sun, 01 Mar 2026 19:21:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Special-Shapes-Refractory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3adb95409148c3b968edc239765afdc16c291b5213bbcdd8a8d0474c1e20d08</i><br /><br />Threat actor <b>description</b>: <i>ssrco.com zoominfo.com/c/special-shapes-refractory-company-inc/1132759207 Special Shapes Refractory Company (SSRC) is a leader in providing high-quality precast shapes and monolithic materials primarily for the glass, steel, and other industrial manufacturers. They focus on minimizing downtime and enhancing equipment reliability through innovative solutions, efficient manufacturing processes, and a commitment to customer service. SSRC caters to a wide range of industrial clients, offering customized refractory solutions and quick lead times. With decades of experience, they emphasize the importance of using pure raw materials to ensure the best product quality and performance</i><br />Target victim <b>website</b>: <i>ssrco.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Riach-Gese-Jacobs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30127</link>
<guid>1157b03c64072655b2490a18963fae1a</guid>
<pubDate>Sun, 01 Mar 2026 11:42:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Riach-Gese-Jacobs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ed0ad916c69c60ba3050bd932f474ba74db301ab61e8ca5d2551e6dfca34728</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schmuck-Welt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30110</link>
<guid>2cc0b255c4894762e17aad3059ce2dcb</guid>
<pubDate>Sat, 28 Feb 2026 20:39:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Schmuck-Welt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2cca09fe3625cda8db695975e2bae18c27fc5213f05031dbe1720a310424c3a0</i><br /><br />Threat actor <b>description</b>: <i>Retail · Pennsylvania</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pro-Plastics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30112</link>
<guid>330bb1faa22252b4be21c91c92a697e9</guid>
<pubDate>Sat, 28 Feb 2026 20:39:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pro-Plastics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d68d7c2df6c4e4e753bbfaf077aa7e8b4f3d526cc445ff876ab169b1d6c4070e</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Andover-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30113</link>
<guid>14b9130e6dbe8185cb68fa211921a335</guid>
<pubDate>Sat, 28 Feb 2026 20:39:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>North-Andover-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf76db0870e4cc0851a840e06a2588da02f9096f52d0734b2c2463a06432807d</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>PriceTable</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30107</link>
<guid>d8591042aaf8c8d8b53b7e43085a0587</guid>
<pubDate>Sat, 28 Feb 2026 14:30:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>PriceTable</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>139acebf6b95bc2803428bf8be3d3b46b542bc9659513053a94e94160cd09514</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>pricetable.io</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>hicare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30106</link>
<guid>737344cccb5f89b59a89a5f20cc3f303</guid>
<pubDate>Sat, 28 Feb 2026 14:30:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>hicare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>005d5f544e2a60e24225772e4f3ed71acf498df47b3e9a06b2307162b0092ff7</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.hicare.net</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>GoHighLevel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30105</link>
<guid>25ba6ebb3e470993540ebc62e98a51e2</guid>
<pubDate>Sat, 28 Feb 2026 14:30:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>GoHighLevel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aaaf1b003389b775e6e5144c7f666afe028bda3c3b631b51d6fdf0a67c899cfb</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.gohighlevel.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Whipflip</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30104</link>
<guid>7ca595cd7955654b36629c1470763487</guid>
<pubDate>Sat, 28 Feb 2026 12:59:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Whipflip</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74c9459b6e8218371275ccf83a027e2bb7a8793753891fbdc712442f7ea13257</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.whipflip.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aegis-Project-Controls</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30103</link>
<guid>3e95b38ce315f12892dee0121e6fad4a</guid>
<pubDate>Sat, 28 Feb 2026 12:29:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Aegis-Project-Controls</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29d07f12a35ce644bf02796d1052a71812f99e5c22f060781e00df434575e1a0</i><br /><br />Threat actor <b>description</b>: <i>Aegis Project Controls is a construction company providing 4d scheduling, training, and construction scheduling services. 
214GB of files, projects, and documents that threaten US national security. These include projects on military-critical facilities (Space Fence, Nitrocellulose Facility, etc.), biosecurity laboratories (USAMRIID), critical infrastructure facilities, and others. We know you didn't contact the FBI after the attack on your infrastructure, but now the FBI will come to you. We advise you to contact us immediately; your IT department knows how. You have 15 days before this data is made public. 
Dear David J. Hatwell (+1 269-673-8962, +1 360-918-3187, +1 240-331-0437), we promise you public shame and the destruction of your company if you don't pay. Time has begun.</i><br />Target victim <b>website</b>: <i>www.consultaegis.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Skibiel-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30102</link>
<guid>92945505a99aea57f8d9a7fc2f739595</guid>
<pubDate>Sat, 28 Feb 2026 10:05:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Skibiel-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb61ef502dbd9e1ed44ccf2b5870d8027db7ef910303d25f9b9db8267f9f403b</i><br /><br />Threat actor <b>description</b>: <i>Georgia Work Injury And Personal Injury Lawyers</i><br />Target victim <b>website</b>: <i>skibiellaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rockwood-Retirement-Communities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30094</link>
<guid>69908a3ae9144cf4918985a785114a46</guid>
<pubDate>Fri, 27 Feb 2026 23:16:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>Rockwood-Retirement-Communities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>675f41d186501c59a01795dd71f6e5e58e2bbe01578f3b58bfff1b880767f727</i><br /><br />Threat actor <b>description</b>: <i>With more than 65 years of mission-driven nonprofit service and two thriving Life Plan communities in Spokane, Washington, Rockwood Retirement is the recognized leader in senior living in the Inland Northwest. Our vision is simple: to create caring retirement communities that enrich the lives of seniors, every day.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plaza-Home-Mortgage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30093</link>
<guid>9f5f53f37396a3c5c13d76d62b5edaab</guid>
<pubDate>Fri, 27 Feb 2026 21:18:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Plaza-Home-Mortgage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61df6bc02dfbed748b0bdba2b8386f8cfe490f32ca115ef7be12b2822cafffd5</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2000, Plaza Home Mortgage offers conventional fixed-rate, conventional ARM, FHA, and VA loa…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>US.MAD-DOG-CONSTRUCTION</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30092</link>
<guid>4daf3131a3b73237edccfc5c6acbd7ad</guid>
<pubDate>Fri, 27 Feb 2026 17:39:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>US.MAD-DOG-CONSTRUCTION</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1c10fe91fc57bcd94a6265e6fba96792a12349bf2e4a195033003b709647b34</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Two-River-Group-Holdings-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30091</link>
<guid>37654b793d96ed06d8c2bfa60658a502</guid>
<pubDate>Fri, 27 Feb 2026 16:47:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Two-River-Group-Holdings-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c778b6f5bbb078c5e8849da817c5c7aa2e0552c11ae54f32ce3308cb64fd3f8a</i><br /><br />Threat actor <b>description</b>: <i>Two River specializes in founding, building, and incubating companies in the life sciences sector that…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nations-Financial-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30090</link>
<guid>1dc907539dc8fc57e6b3cbf1a276ccce</guid>
<pubDate>Fri, 27 Feb 2026 16:47:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Nations-Financial-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0aed07c208c7126eb3b00a4abd518868c22170a453742f4b4bb814182acd591</i><br /><br />Threat actor <b>description</b>: <i>Above all else, Nations is committed to providing the highest level of support and assistance to its f…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>HEMIC---Hawaii-Employers-Mutual-Insurance-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30089</link>
<guid>0fff885ae427e3adae25dbb31251470c</guid>
<pubDate>Fri, 27 Feb 2026 16:47:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>HEMIC---Hawaii-Employers-Mutual-Insurance-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c20d926d8f568a7eb03c4895cb31518ca93fb128b8102201174f77a410c1f6db</i><br /><br />Threat actor <b>description</b>: <i>HEMIC, founded in 1996 and located in Honolulu, Hawaii, is a company that specializes in worker's comp…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hrp-Hitesh-Cpa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30087</link>
<guid>e31003304da364867f1dce3be564fb7a</guid>
<pubDate>Fri, 27 Feb 2026 16:40:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hrp-Hitesh-Cpa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7dd35710ba325328af65f865a964de9925d25d4c491ac96ae35811a115cd59e</i><br /><br />Threat actor <b>description</b>: <i>HRP HITESH CPA PC specializes in providing cloud-based payroll and accounting services to business clients. The firm leverages advanced technology to automate payroll processes, compliance filing, and payroll taxes, ensuring a user-friendly experience.We will upload corporate data soon. Lots of clients data, financials, forms, a bit of personal information and more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ace-Ethanol</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30076</link>
<guid>6b18d371703cf5221bc39c1a03a3be64</guid>
<pubDate>Fri, 27 Feb 2026 14:42:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ace-Ethanol</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01b00523a0704c4e7883a31df56c237a5d6e8dd33dfc71353b6197861003a046</i><br /><br />Threat actor <b>description</b>: <i>Ace Ethanol LLC serves as a marketing resource for corn producersin northwestern Wisconsin, focusing on the production of ethanol, dried distillers grains, and corn oil. The company aims to contribute to national energy freedom while ensuring improved efficiencies and environmental safety.We will upload 15gb of corporate data soon. Employee files (SSNs,w9 forms and so on), specifications and projects, chemical recipes, financials, lots of HR files, partner's files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Land-and-Lakes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30082</link>
<guid>28d89ee0086b8d5e875b59d3338f3d3a</guid>
<pubDate>Fri, 27 Feb 2026 14:34:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Land-and-Lakes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f97deb293650ea1d0ef011effa797653b90c56f2f11694533213cef32475438</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.land-and-lakes.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Unisoft-Communications</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30079</link>
<guid>68c20262d2657796f56d2101e46b3e73</guid>
<pubDate>Fri, 27 Feb 2026 13:48:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Unisoft-Communications</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96d7366d9b1fd4d8b45b35949392907cdedbe735ddaa7f5de96faddd58a7a91e</i><br /><br />Threat actor <b>description</b>: <i>Unisoft Communications, Inc. specializes in developing advanced c
ommunication software solutions for the non-standard Property and
Casualty Insurance industry. With over 40 years of experience th
rough its sister company, Unicorp Data Processing, Inc., the comp
any addresses the communication challenges faced by insurance com
panies, premium finance companies, and their agents.

We will upload 31gb of corporate data soon. Employee data, client
s' data, financials, lots of contracts and agreements and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accelerated-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30077</link>
<guid>a1b2e04c65e8fa74ba1e50a429b828ca</guid>
<pubDate>Fri, 27 Feb 2026 13:08:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Accelerated-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efcb439a2515dc2e1f20fdf860d90cf5738d27c5039aa2c983fc0130c404b952</i><br /><br />Threat actor <b>description</b>: <i>Allied H.V.A.C. Inc. (Accelerated Services, Inc.) is a full-service HVAC provider specializing in commercial and residential installation, maintenance, and repair. The company delivers year-round comfort and indoor air quality solutions to clients throughout Suffolk and Nassau Counties, Long Island, NY, supported by 24/7 emergency service.</i><br />Target victim <b>website</b>: <i>www.acceleratedhvac.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Com-Tec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30073</link>
<guid>319b2600b8defbf79afcb125d55ff9c7</guid>
<pubDate>Fri, 27 Feb 2026 12:22:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Com-Tec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1b2ecc02202d96580b2acda2cdffbc6d482541f2a020bf31863019109d7c69a</i><br /><br />Threat actor <b>description</b>: <i>Com-Tec Communications specializes in structured network cabling 
and offers tailored technology solutions for businesses in Orange
County and Lake Forest, California. Their services include telec
om VOIP, surveillance systems, Wi-Fi improvements, network infras
tructure, and audio-visual enhancements to boost productivity and
security.

We will upload 70gb of corporate data soon. Employee files (passp
ort and DL scans, i-9 forms and so on), specifications and projec
ts, financials, confidential files, HR files, client and partner 
files, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Beauty-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30072</link>
<guid>08eac1d7ee7ce0f8c4a4d22ba0c72f03</guid>
<pubDate>Fri, 27 Feb 2026 12:22:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>American-Beauty-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae4a752eefa44eef41145c9a28a1186ec26bb12865949eec77079584a7004a52</i><br /><br />Threat actor <b>description</b>: <i>American Beauty School, established over 50 years ago, offers div
erse and innovative educational opportunities in cosmetology, nai
l specialty, and esthetics. Located in the Bronx, NYC, the school
has built strong relationships with local salon and spa owners, 
providing hands-on experience and career support for its students
. 

We will upload corporate data soon. Employee files (passport and 
DL scans and so on), financials and other internal files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lymphedema-Therapy-Specialists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30071</link>
<guid>5c72c99424191cfd8ec2227b923c03d9</guid>
<pubDate>Fri, 27 Feb 2026 10:58:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Lymphedema-Therapy-Specialists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6e45e8d875ff0a34f813348bfb17d57274702c3d752ffffcfdc0570d97f5183</i><br /><br />Threat actor <b>description</b>: <i>Lymphedema Therapy Specialists is a private outpatient clinic in Houston, Texas, specializing in the treatment of lymphedema through various therapies including manual lymph drainage, pneumatic compression therapy, and wound care. The clinic aims to assist patients in managing their symptoms by providing educational resources and tailored treatment plans. With experienced professionals on staff, they serve individuals suffering from lymphedema and associated conditions in the Houston area. Their mission is to alleviate suffering and support patients in their healing journey.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-Taenzer--Ettenson-P.C.-tesalaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30070</link>
<guid>48b508b64892bdf1d3a44e6de12e146a</guid>
<pubDate>Fri, 27 Feb 2026 09:31:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Law-Offices-Taenzer--Ettenson-P.C.-tesalaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5281a57928d41d56f41ba331f1668893f35f9dca02543f6e945c4c3c70b1b8a</i><br /><br />Threat actor <b>description</b>: <i>TAENZER & ETTENSON, P.C. is well-prepared to effectively serve your personal and business legal needs with years of experience in the practice of law. Our accomplished, professional staff will: Provide you with expert legal advice Identify key issues in your case Maintain your confidentiality at all times Extend to you the personal service and attention you deserve We are dedicated to providing you with exceptional legal services.  Laek: 30GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>tesalaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pathstone-Family-Office-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30066</link>
<guid>69fe9173086cb3761312feb26edacf6e</guid>
<pubDate>Fri, 27 Feb 2026 02:34:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Pathstone-Family-Office-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>908b0a3e62252782c3376f8fe9191a5a334dff748f435e117d6841802d362e34</i><br /><br />Threat actor <b>description</b>: <i>Over 641k records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 2 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 Feb 2026 | Warning: FINAL WARNING</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ripple-Neuro</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30064</link>
<guid>dde4952e3874b24df8091b3e4b62e501</guid>
<pubDate>Thu, 26 Feb 2026 21:33:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Ripple-Neuro</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>426152c50cd7a2b6a44cc06db9283e11d60b2e47ac984afde9998a3979e80cbc</i><br /><br />Threat actor <b>description</b>: <i>Ripple Neuro builds neuroscience research tools and medical devices for electrophysiology, offering portable wireless processors, implantable tech, and accessories for various models. They serve researchers in BCI, closed-loop stimulation, and wireless signal acquisition.</i><br />Target victim <b>website</b>: <i>www.rippleneuro.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Landmark-Rehab-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30062</link>
<guid>2c9aabda8931c46b74753eb6dd9136dd</guid>
<pubDate>Thu, 26 Feb 2026 20:35:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Landmark-Rehab-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3d55510b57634024e9bd9aeda74bea4c20c8c00c8d8fbfb28c500a2e87d75be</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.landmarkrehabgroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>BT-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30061</link>
<guid>d26cf5a5aa1c2999c8339d77fc3eed44</guid>
<pubDate>Thu, 26 Feb 2026 20:34:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>BT-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25f5a9a6bde7906d8fe4224eb03fa958d227fdf4f526a25a47f3c1877bc37eb4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.btrefservices.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrity-Building</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30060</link>
<guid>3821223063bdae6ed4fc1703402ea917</guid>
<pubDate>Thu, 26 Feb 2026 20:33:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Integrity-Building</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53ef31b6029a877a8d566de6ccad1d9094e7d25ec9ec2c190d08a0f928a18e02</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ibcaz.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>ntic.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30053</link>
<guid>245149b06f14727ef0eb8c159cc246d6</guid>
<pubDate>Thu, 26 Feb 2026 17:24:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>ntic.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c5d5a4d38c163c223fca0929c37eb88bb1293fcf2038bc94419e03072b971b9</i><br /><br />Threat actor <b>description</b>: <i>Northern Technologies International Corporation (NTIC) is a specialty chemical company that develops and markets proprietary environmentally beneficial products and services focused on corrosion prevention and protection solutions. The company specializes in innovative rust and corrosion prevention…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/northern-technologies-international-corp/28033941</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Physicians-Clinic-of-Iowa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30052</link>
<guid>d0ab3eaa2d0af7efe82a485a26fb2705</guid>
<pubDate>Thu, 26 Feb 2026 17:23:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Physicians-Clinic-of-Iowa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3cbe05750a435f4fce89aaa9f7171665775779b08e91492f6d7779578dee0f17</i><br /><br />Threat actor <b>description</b>: <i>Clinic data breach: another example of negligence in a medical institution.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thrash-Commercial-Contractors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30046</link>
<guid>e797b9be4cf8c1f1de10c2fba822e99a</guid>
<pubDate>Thu, 26 Feb 2026 16:04:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Thrash-Commercial-Contractors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f187ddfe60727decb4568f8410c6a711d8b974339d30807d1007bd4ff4dcf47</i><br /><br />Threat actor <b>description</b>: <i>Thrash is a Southeast commercial builder offering general contracting, construction management, preconstruction, and design-build. Known for detailed execution, clear communication, and strong client relationships across institutions and states.</i><br />Target victim <b>website</b>: <i>www.thrashco.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carlo-J.-Martina-P.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30042</link>
<guid>ee812d04b09fc5eab089f59baa8a6b2c</guid>
<pubDate>Thu, 26 Feb 2026 13:51:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Carlo-J.-Martina-P.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>809e128a7353c35f36dfdd4445fa93bdb5789bd2cb820c2bec10e9fb1a67d981</i><br /><br />Threat actor <b>description</b>: <i>Plymouth MI Divorce & Family Law Attorneys</i><br />Target victim <b>website</b>: <i>martinalaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Odom-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30041</link>
<guid>a83d567f09e542dbe66a7e1a9430504a</guid>
<pubDate>Thu, 26 Feb 2026 13:51:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>The-Odom-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>795f20d82c3e916ba871390685fc4c1ffa44a51e442d660ff99cc9236ce04158</i><br /><br />Threat actor <b>description</b>: <i>Representing individuals and businesses in matters related to easements, agreements, and zoning, including variances and appeals</i><br />Target victim <b>website</b>: <i>mecklaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>thinlinetech.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30039</link>
<guid>eb8957cfa91a0992d3570d7fac93cb8e</guid>
<pubDate>Thu, 26 Feb 2026 13:07:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>thinlinetech.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b298565e916b42636843c6ee25440561c1109dd721a6c6a6ad8d496a990554c2</i><br /><br />Threat actor <b>description</b>: <i>Thinline Technologies offers reliable IT consulting and expert computer and network support services to businesses in the Baltimore metro area.</i><br />Target victim <b>website</b>: <i>thinlinetech.com</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>milespartnership.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30038</link>
<guid>17a5521f02c96ba003e028f278e3ab15</guid>
<pubDate>Thu, 26 Feb 2026 08:32:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>milespartnership.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9336627b5a05b6fba748d8c91cbee7e34d1a2ddd3e3979f6a1a126d90851710a</i><br /><br />Threat actor <b>description</b>: <i>The company was founded in 2005 and is based in Sarasota, Florida. Miles Partnership offers destination marketing, digital marketing, print publishing, data management, mobile marketing, email marketing, and hospitality marketing.</i><br />Target victim <b>website</b>: <i>milespartnership.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Envirogen-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30037</link>
<guid>148d442971558088c915121f85c797b3</guid>
<pubDate>Thu, 26 Feb 2026 03:24:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Envirogen-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9337f26e66c87518178ca0b57c199d34e64de3665c8302962197bbee0868e1a</i><br /><br />Threat actor <b>description</b>: <i>Major data breach of Engineering firm with high-profile clients.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zaner-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30032</link>
<guid>2f96a08bf9fecb843023a3f94a8ddf9d</guid>
<pubDate>Wed, 25 Feb 2026 15:09:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Zaner-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45d9bc02cade5ddeec410207c8c61b95ed8290f28409a9b7e134161bb0535218</i><br /><br />Threat actor <b>description</b>: <i>Zaner, a family-owned brokerage since 1980, provides global commodities risk-management, advisory, research, and trading tech. Serving futures, metals, currencies, energies and agriculture, they offer hedging, precious metals solutions, competitive pricing.</i><br />Target victim <b>website</b>: <i>www.zaner.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jones-Haber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30030</link>
<guid>e05baf3e0c3214593c5ee81af5917770</guid>
<pubDate>Wed, 25 Feb 2026 14:30:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Jones-Haber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01dff60c16d96808af5cfa396c82529cf6a8bbbf1f55091e8846fff1aed00f8b</i><br /><br />Threat actor <b>description</b>: <i>Jones, Haber &amp; Rollings is a multi-service law firm based in Cape Coral, Florida, with over 75 years of combined legal expertise. Established in 1988, the firm provides comprehensive legal counsel across various practice areas throughout the state of Florida. 
</i><br />Target victim <b>website</b>: <i>www.joneshaberlaw.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Siskiyou-Telephone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30029</link>
<guid>51e706f8b33d4020dbe481ae37603842</guid>
<pubDate>Wed, 25 Feb 2026 14:29:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>The-Siskiyou-Telephone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>962013b7c19df0cb208bb154b740e4e3e3b9cee1340df7cc0b3f5cdaa4a9f2b8</i><br /><br />Threat actor <b>description</b>: <i>Siskiyou Telephone is a rural independent service provider serving Western Siskiyou County, California, since 1896. The company offers high-speed internet packages with speeds up to 1000 Mbps and telephone services, catering to both residential and business clients.</i><br />Target victim <b>website</b>: <i>www.siskiyoutelephone.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tricolor-Holdings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30017</link>
<guid>53e5fee4b79f57668bd8e85742d9f9cd</guid>
<pubDate>Wed, 25 Feb 2026 05:44:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kittykatkrew</b> claims attack for <b>Tricolor-Holdings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff4cf92e84c78136481c5243b4b2441d5e55650d71cc3d720bc9b90c9f929591</i><br /><br />Threat actor <b>description</b>: <i>Mission-driven auto lender expanding access to affordable vehicle ownership nationwide. Deadline: 2026-03-03T00:00:00+00:00 Status: Awaiting Contact</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kittykatkrew</category>
</item>
<item xmlns:dc='ns:1'>
<title>Birmingham-Museum-of-Art</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30016</link>
<guid>ad7030d0d43a7f5903f38cc76af762a5</guid>
<pubDate>Wed, 25 Feb 2026 00:53:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Birmingham-Museum-of-Art</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90af04dcf23310d758100bfd534229a1c3f98a49f738ed388aab8a8e9f5a30ae</i><br /><br />Threat actor <b>description</b>: <i>The Birmingham Museum of Art in Alabama features a vast collection of over 27,000 artworks and offers free admission to visitors. The museum is open from Tuesday to Sunday and hosts various exhibitions and events throughout the year. It serves a diverse audience, including families, students, and art enthusiasts, providing educational resources and opportunities for engagement.
</i><br />Target victim <b>website</b>: <i>www.artsbma.org</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Triumph-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30013</link>
<guid>987abbb401850a3f9d10dc85a625c0c9</guid>
<pubDate>Tue, 24 Feb 2026 23:14:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Triumph-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4a51f7abd8f899725de97d9139b1af01a54506396aab5f702316dad25871653</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Triumph Group is an international company specializing in manufacturing and repairing aerospace structures, systems, and components. Their work encompasses commercial, regional, business and military aircraft, as well as their components. Triumph Group has a robust supply chain providing services globally, significantly enhancing the performance of the aerospace industry.</i><br />Target victim <b>website</b>: <i>triumphgroup.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Insight-Hospital-amp-Medical-Center-Chicago</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=30012</link>
<guid>7c365ebfc34003c40033cc47f6116dd1</guid>
<pubDate>Tue, 24 Feb 2026 23:08:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Insight-Hospital-amp-Medical-Center-Chicago</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a05995a4c60f7b5defe6fe13001c3c5fd4adb949aa37ca04081cf36bf47b9746</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1852 Mercy Hospital &amp;amp; Medical Center is a member of Trinity Health. They are a teaching hospital headquartered out of Chicago, Illinois
</i><br />Target victim <b>website</b>: <i>insightchicago.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hudson-Awning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29981</link>
<guid>45b531e01616fe0a6b2d8d51583b36a7</guid>
<pubDate>Tue, 24 Feb 2026 18:42:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Hudson-Awning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed615926845c56a294978345b646ade825613588b46022db1a9aca3822261768</i><br /><br />Threat actor <b>description</b>: <i>Hudson Awning has been providing exceptional products and services since 1881, specializing in a wide variety of awnings, including fabric awnings, metal canopi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Middlesex-Transporters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29982</link>
<guid>a1e4a9d047858b87c17707c0c4e91657</guid>
<pubDate>Tue, 24 Feb 2026 18:42:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Middlesex-Transporters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>628ea9fea4bb87cd0af29b4d27eb8242cd0d2716c9fd13a636b0da5d826e851a</i><br /><br />Threat actor <b>description</b>: <i>Middlesex Transporters LLC specializes in non-emergency medical transportation services aimed at providing cost-effective solutions for patients with healthcare...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>CognitiveTPG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29973</link>
<guid>2b98e671fcbb48f8a586538960c8cff2</guid>
<pubDate>Tue, 24 Feb 2026 14:43:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CognitiveTPG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aba7c6ba2fa03c30156b0debee450cf53115b10cde19328116fd486da01a17a1</i><br /><br />Threat actor <b>description</b>: <i>CognitiveTPG specializes in innovative printing solutions, offering a range of products including label printers, POS printers, and security print solutions. Their intended clients span various industries such as retail, healthcare, banking, hospitality, and manufacturing.We will upload corporate data soon. Passports numbers, DLs, SSNs,addresses, phones and other personal information of employees, partners files, specifications, projects info, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aptean</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29978</link>
<guid>bc475ee878093039d641e94e5345fe25</guid>
<pubDate>Tue, 24 Feb 2026 14:00:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Aptean</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c68722b15233591df66ec87a1286a574e81b7354206a1c6ad688b44ba04bfb66</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Aptean is a leading global provider of industry-specific software solutions. The company targets specific industries such as manufacturing, distribution, and retail to offer ERP, supply chain, and compliance solutions. The company helps businesses to stay at the forefront of their industries by using technology and industry-specific expertise to address unique business challenges.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nebraska-Hearing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29976</link>
<guid>0f8dbc56f1117ef240cbb653bb721a42</guid>
<pubDate>Tue, 24 Feb 2026 13:16:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Nebraska-Hearing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47e6d5f1b36f289f158abd93c8d93b058cc5690961bf6e1820debce2303fe756</i><br /><br />Threat actor <b>description</b>: <i>Nebraska Hearing Instruments LLC is a Hearing Aid Equipment Supplier in Omaha, Nebraska</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Employer-Solutions-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29972</link>
<guid>1acd4d26929098c6af011ed1a5d93e9d</guid>
<pubDate>Tue, 24 Feb 2026 12:36:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Employer-Solutions-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2049e56522c0c5bbac277a870e163a0473432a8171882071cdc25a330fcd958</i><br /><br />Threat actor <b>description</b>: <i>ESSG provides HR, payroll, and compliance solutions designed to s
treamline administrative tasks for businesses. Their services tar
get employers of record seekers, staffing companies, and small to
medium-sized businesses, offering tailored assistance in payroll
management, employee benefits, and compliance regulations.

We will upload almost 80gb of corporate data soon. Passports, Dls
, SSNs and other information of more than 100 ppl, financials, HR
files, client, partners information, NDAs and other confidential
files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-of-Pennsylvania</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29971</link>
<guid>9ac2fc991d780c349fe1e5863e731108</guid>
<pubDate>Tue, 24 Feb 2026 12:13:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>University-of-Pennsylvania</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>712b4b0f1dec73723a74fe1daab681e732ce0c184bbe987c3c6a3bd26745a84d</i><br /><br />Threat actor <b>description</b>: <i>Records: 1.2M Records | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harvard-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29970</link>
<guid>46c4e6a9d4e1392f1f86747329e15ab0</guid>
<pubDate>Tue, 24 Feb 2026 12:13:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Harvard-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a7be3fa95697b869d161d2b9c149fab36f61d81e89816fed659013d45291fc61</i><br /><br />Threat actor <b>description</b>: <i>Size: 1.1GB (compressed) | Updated: 04 Feb 2026 | Note: Make the right decision, don't be the next headline. | This is the direct result of advisors advising you against paying a ransom. It has the opposite effect. Do NOT provoke us again and pay the ransom when we contact you.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Figure-Technology-Solutions-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29969</link>
<guid>07f7b1153c6e600da9abeddc1b03f2c8</guid>
<pubDate>Tue, 24 Feb 2026 12:13:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Figure-Technology-Solutions-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f75737228925db8f0b805615b2b9281f9057be2da740b9fd96b539ef670cf023</i><br /><br />Threat actor <b>description</b>: <i>Size: 2.5GB (compressed) | Updated: 13 Feb 2026 | Note: Pay or be humiliated. | They were given multiple chances to pay the ransom, but they decided to waste time and hide instead.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>CarGurus-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29967</link>
<guid>31716bdf834f7838689285ce155e7a64</guid>
<pubDate>Tue, 24 Feb 2026 12:13:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>CarGurus-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6475873b2bd37c77367db5e959a7b38d620a4289803e36c2edbf3a818cd5a66</i><br /><br />Threat actor <b>description</b>: <i>Size: 6.1GB (compressed) | Updated: 21 Feb 2026</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mercer-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29966</link>
<guid>798ec5bb849d8c08c6cc22e0ff196b1d</guid>
<pubDate>Tue, 24 Feb 2026 12:13:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Mercer-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e61318615445b371e35fde0d075d73d7707a7087ccc6edc57a38fd0ebcfd329</i><br /><br />Threat actor <b>description</b>: <i>Updated: 21 Feb 2026</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beacon-Pointe-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29965</link>
<guid>e483cc701d962f6b22bfea4b09635652</guid>
<pubDate>Tue, 24 Feb 2026 12:13:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Beacon-Pointe-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f540ca84728888b7b7c40c1a02aa5711bf8da3eb274bf91907ad0b395eb42f70</i><br /><br />Threat actor <b>description</b>: <i>Size: 60GB (compressed) | Updated: 22 Feb 2026</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>suffolkva.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29962</link>
<guid>2d00ce98adf1abcedcf3cecb0859343a</guid>
<pubDate>Tue, 24 Feb 2026 11:58:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cloak</b> claims attack for <b>suffolkva.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9817386adb6fde0c7c82c563f0d1d0806a691a846da603a7baed6131b38c457</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cloak</category>
</item>
<item xmlns:dc='ns:1'>
<title>PoindexterHill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29958</link>
<guid>8b7496b0d4f85eb60f8c70fc494c9983</guid>
<pubDate>Tue, 24 Feb 2026 08:40:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PoindexterHill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f280261558a31aa7401bb8215636d718982967526e8cc426bdd5ddac4980aba</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jac-Vandenberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29960</link>
<guid>7b0e861aacb92e74f2ea443d7c626b53</guid>
<pubDate>Tue, 24 Feb 2026 08:35:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Jac-Vandenberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c693655cc3f91c817180bfd14d66d583d2c1c1b8369bee2f2bce9144039efac</i><br /><br />Threat actor <b>description</b>: <i>Jac Vandenberg is a company dedicated to providing fresh produce, including citrus, grapes, pome fruits, and stone fruits, sourced responsibly from farm to store. They emphasize food safety, sustainability, and innovation in their operations. The company targets grocery stores across America, aiming to deliver high-quality fruits that cater to consumer preferences.</i><br />Target victim <b>website</b>: <i>jacvandenberg.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Silver-Lake-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29956</link>
<guid>57e289de16e78690c58902a1eb00c835</guid>
<pubDate>Tue, 24 Feb 2026 05:40:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Silver-Lake-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af5a0908668a4bfc7ff2286dcc794f03808cff8e909fcf047013cc6a621bbbd7</i><br /><br />Threat actor <b>description</b>: <i>www.silverlakemc.com https://www.zoominfo.com/c/silver-lake-medical-center/8258341 Now known as L.A. Downtown Medical Center (LADMC), Silver Lake Medical Center is an accredited healthcare facility in Los Angeles operating two campuses. The facility provides a range of services, including 24-hour urgent care at its downtown location and specialized behavioral health services at its Rosemead campus.</i><br />Target victim <b>website</b>: <i>www.silverlakemc.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Orrick-Herrington--Sutcliffe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29954</link>
<guid>68d42d85d6ef70aa12305106ba6abc20</guid>
<pubDate>Mon, 23 Feb 2026 22:46:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Orrick-Herrington--Sutcliffe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>291cf95e4c77ba6ab4b616acf1a8c559767293ce48b89e447ebcf1c786266da6</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1963 and headquartered in San Francisco, California, Orrick, Herrington & Sutcliffe is a co…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rocky-Mountain-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29952</link>
<guid>0601b74059931609ce1fd8410db6fb14</guid>
<pubDate>Mon, 23 Feb 2026 21:42:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rocky-Mountain-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1c7b25a5ae7c2527dfd0f24b0296a2a0a6f2ac28932192d08d9bdb6abd15b1a</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zelenkofske-Axelrod</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29948</link>
<guid>61b4258564db32b0b663450f8cfa54cc</guid>
<pubDate>Mon, 23 Feb 2026 20:42:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Zelenkofske-Axelrod</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5bba750a2a7c93abf5354bbbc62aedb6b09c90183f918887816f2cd42da2c56</i><br /><br />Threat actor <b>description</b>: <i>Zelenkofske Axelrod, LLC (ZA) is a regional CPA firm based in Pennsylvania, with multiple offices providing auditing, accounting consulting, and tax services pr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spire-Payments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29949</link>
<guid>55b9d07f95df2d8a391673726bf4ef3d</guid>
<pubDate>Mon, 23 Feb 2026 19:40:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spire-Payments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c466ada02c9216fca0c2683b7ad3ab42ace13a04676c80186272640f4fd42c96</i><br /><br />Threat actor <b>description</b>: <i>Credit Cards & Transaction Processing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>GENERON</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29950</link>
<guid>84846ca9435252790f0e076d7d5d29df</guid>
<pubDate>Mon, 23 Feb 2026 19:40:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>GENERON</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4ef9770e55b073cd60da91b551290b941b0242b373630b0d265faa0d4d102fe</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accuick</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29951</link>
<guid>2b21de16a5c3b0913227003411b15196</guid>
<pubDate>Mon, 23 Feb 2026 19:01:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cipherforce</b> claims attack for <b>Accuick</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>618339a6ace2efc74abdd1a72b49b7a78fe13e2c1b15ddba47b772faa27b134d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cipherforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>TWU-Local-100</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29944</link>
<guid>bf811576819a427614cbc193920b16df</guid>
<pubDate>Mon, 23 Feb 2026 16:42:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TWU-Local-100</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4b793188306d836a8330a517f726e543629c4cd2cb8a6acc37c778906d9a666</i><br /><br />Threat actor <b>description</b>: <i>Membership Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>FAMILY-EYECARE-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29945</link>
<guid>003fd8188c1a5913a61bba3db2c670e8</guid>
<pubDate>Mon, 23 Feb 2026 15:44:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>FAMILY-EYECARE-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24e9ab3c6ca8cc7d0df5b104663d9fa86ab5f60bc8809ff930e96aab3c1ca723</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-City-of-Cocoa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29943</link>
<guid>5030f1c110959586c7cf489e4a6713b6</guid>
<pubDate>Mon, 23 Feb 2026 14:37:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>The-City-of-Cocoa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4953040c4de27df65f9e0eac21b93e8614418c50491b44fd782ff0e12eb79ca6</i><br /><br />Threat actor <b>description</b>: <i>The City of Cocoa offers diverse public services aimed at enhancing the quality of life for its community. Their services include water management, economic development programs, and various community engagement initiatives. Intended clients encompass local residents, businesses, and visitors who seek information and support from city departments. The city is also focused on maintaining public safety, health, and environmental stewardship.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>primepak.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29942</link>
<guid>c323092e3dc96ec44049c28c7dd27089</guid>
<pubDate>Mon, 23 Feb 2026 14:37:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>primepak.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e545d14f42bb5c5ba4ffe378d368938ee78d48eab761b623603c9f7e5f41ffe8</i><br /><br />Threat actor <b>description</b>: <i>Primepak is your worldwide specialist in packaging. As a leading manufacturer, importer and distributor since 1972, we provide a wide range of solutions for every application in packaging, plastic bags, poly sheets, tubing and films. Employees: 200  Revenue: $54.3 Million Industry: Manufacturing  Phone Number: (201) 836-5060 </i><br />Target victim <b>website</b>: <i>primepak.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>tektreeinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29939</link>
<guid>c3a05fe072d3d4f009eccce97c41ca71</guid>
<pubDate>Mon, 23 Feb 2026 13:25:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cipherforce</b> claims attack for <b>tektreeinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93cc2eb3172aed6bc2345b582bee4eaa0eed4a08e9967294505e02477c6061cb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TektTree Inc. is a global technology consulting and IT service provider that offers services in software development, IT consulting, and project management. The company is dedicated to helping customers build effective, efficient and collaborative systems. They have a team of experienced professionals who specialize in different sectors such as banking, healthcare, retail, and telecommunications.</i><br />Target victim <b>website</b>: <i>tektreeinc.com</i>]]></description>
<category>cipherforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>hiringsteps.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29938</link>
<guid>87e942236933558e0ea7cd7dee76e9db</guid>
<pubDate>Mon, 23 Feb 2026 13:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cipherforce</b> claims attack for <b>hiringsteps.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7b25e207c72c34fbac6dc1b85e7ef0d33e5b763e04e0a125fa3ecd02752ca89</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "HiringSteps.com" is a robust online cloud-based platform designed to streamline the recruitment processes for businesses of different sizes. The platform allows recruiters to post job openings, source candidates, conduct interviews, check references, and send job offers all in one place. It aims to simplify recruitment by reducing paperwork and improving coordination among employers, recruiters, and candidates.</i><br />Target victim <b>website</b>: <i>hiringsteps.com</i>]]></description>
<category>cipherforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rainier-Clinical-Research-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29935</link>
<guid>7da66e82dc1f8024527341be2df86b9f</guid>
<pubDate>Mon, 23 Feb 2026 01:40:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Rainier-Clinical-Research-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>260c0778b8a6808e603bea9fc09547d016bb344044cea9b75c70f6f578d9214d</i><br /><br />Threat actor <b>description</b>: <i>Rainier Clinical Research Center is a leading research facility specializing in clinical trials for diabetes, medical devices, and high-volume studies, with over 700 studies completed in 30 years.  The center provides a purpose-built 15,000 square-foot research space   We will publish all the information next week.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlantic-Design-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29934</link>
<guid>7998b659c5fdea8653a0ed11b4a89dd2</guid>
<pubDate>Sun, 22 Feb 2026 18:48:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Atlantic-Design-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34a6a84dacc803a717fc0cab011e2f7bf1dadb4ee35ca0b72bae5df6c1e616d3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.atlanticcompanies.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>FaulknerLocke</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29933</link>
<guid>adb1341c69f3803a176b96c5584520f4</guid>
<pubDate>Sun, 22 Feb 2026 18:47:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>FaulknerLocke</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f943beae29a0c51f60cfaad8dfac34b224de4dbbb3b1796cec572dbc62339b81</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.faulknerlocke.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hendrick-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29932</link>
<guid>449ddfa2100f691195ad1b10e5bcd846</guid>
<pubDate>Sun, 22 Feb 2026 18:47:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Hendrick-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce71df3b560f698dc913d2b746ce85a5a120ddf727e591b4f595591c22a5003f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hendrickconstruction.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Young--Associates-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29931</link>
<guid>4cfbfb28ee66aceab7be17065ebdb6e5</guid>
<pubDate>Sun, 22 Feb 2026 18:46:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Young--Associates-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35f4321d9f0bea83948a1e4f948819713d68b20a0d933e6f506650f55b843289</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wjyaengineers.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>PenLink</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29930</link>
<guid>db92254e80a05b411642bc6885748637</guid>
<pubDate>Sun, 22 Feb 2026 18:45:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>PenLink</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6078cfa93a1a3ad722766ca620f645ada8072d82537ab524cac2f95442e5229</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.penlink.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gulfstream-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29929</link>
<guid>9cc03ce5c1ea026ca10e9f83572a0200</guid>
<pubDate>Sun, 22 Feb 2026 18:45:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Gulfstream-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20dc28814a0fc6e5622691ef006b3744a4a20e74f1b4cec9aa8fe59c18fb5436</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gulfstreamservices.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cumberland-International-Trucks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29927</link>
<guid>694eabca410cc15c81fab9dc514a629e</guid>
<pubDate>Sun, 22 Feb 2026 13:44:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cumberland-International-Trucks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dac559aa2f81b2dc1f0de0086ed19afd808977845ff79c2b5499c3887b3c6496</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Okanogan-County-Vets</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29919</link>
<guid>a6e541f4abdd89b30649ca4e7f47ec24</guid>
<pubDate>Sun, 22 Feb 2026 07:42:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Okanogan-County-Vets</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5fca5d70ed0fec7967136f3bd57b1262cbb4c1b89931ec099d663b6bf932e5d</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Complete-Thermal-Svc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29922</link>
<guid>cef73ce6eae212e5db48e62f609243e9</guid>
<pubDate>Sun, 22 Feb 2026 07:42:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Complete-Thermal-Svc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fec54ef7ccbf0b138b17786b7d891f7475a7c09e0fc23c28100065893a24fdc4</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>US-Trading</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29924</link>
<guid>8284f7dbed939c962b771ff17d41aeb7</guid>
<pubDate>Sun, 22 Feb 2026 07:42:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>US-Trading</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc44f3480b973477d576cebbda9c2dfe9f0bc0b2d46597a4ce278e2c99821959</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>HUGS-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29909</link>
<guid>228205019b79a1a8101b261c10df7ecd</guid>
<pubDate>Sat, 21 Feb 2026 19:17:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>HUGS-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1be7b9dc557f38c07800a8a8c10df63793d154ce352599047740ceb584f0e5fc</i><br /><br />Threat actor <b>description</b>: <i>hugsinsurance.com zoominfo.com/c/hugs-insurance/1319728881 HUGS INSURANCE BROKER is an online insurance consultant that specializes in helping clients purchase, consult, and compare insurance products. The company prides itself on being a friendly and knowledgeable partner in navigating insurance options for various lifestyles. They offer personalized assistance to ensure clients find the right insurance for their needs. HUGS aims to simplify the insurance process, making it accessible and understandable for all customers</i><br />Target victim <b>website</b>: <i>hugsinsurance.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bluefish-Dental--Orthodontics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29907</link>
<guid>f0f42953e6ac78566f36c5824c795c7f</guid>
<pubDate>Sat, 21 Feb 2026 16:40:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bluefish-Dental--Orthodontics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b04c31462670e4191ab9dc8ef661eb143533b1d534bbadf0c51e053b6f1c29b1</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.bluefishdental.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WTSmedia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29904</link>
<guid>e07c7d69b5b26f6ed17e514e404d77ea</guid>
<pubDate>Sat, 21 Feb 2026 14:41:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WTSmedia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5376f8a520e4b14487dba9e6c0263e738a6f946e3b28dacf55b005f88c8cd2aa</i><br /><br />Threat actor <b>description</b>: <i>Electronics</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>onlinedivorcetexas.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29902</link>
<guid>ecc19ff8dfa0fba0aac51c409d06e653</guid>
<pubDate>Sat, 21 Feb 2026 07:12:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>onlinedivorcetexas.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca026c6e609d1a8bff426edbdc0373d841e6ad1e492789655a2c6d89e75791db</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>example.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>fcc-inc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29882</link>
<guid>cd6c652e6f498d4363bff3c4b63bd685</guid>
<pubDate>Fri, 20 Feb 2026 21:53:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>fcc-inc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c977b23e03a5eaf032a2f6802f26f55060ef2ec7a7db9e7021ceebdfad65b3c8</i><br /><br />Threat actor <b>description</b>: <i>Fremont Contract Carriers, Inc. - FCC - strives to be a low cost carrier, while still providing qual...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>maxusacorp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29886</link>
<guid>0ac18d27cc2284445bc249e8a83462fe</guid>
<pubDate>Fri, 20 Feb 2026 21:53:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>maxusacorp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e999729c0ee24ac96f2c62e96161406d022e1e551db6b6a6454f55c89264fc83</i><br /><br />Threat actor <b>description</b>: <i>The company specializes in developing innovative and durable tools such as rebar tiers, nail guns, a...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>dmxm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29888</link>
<guid>68da88f6136bd6e456811e4a1f941ac0</guid>
<pubDate>Fri, 20 Feb 2026 21:53:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>dmxm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0721e2c6661c857829489234083ea6a85653af774ec78589af0f828e57844205</i><br /><br />Threat actor <b>description</b>: <i>Description: Dynamic Machining & Manufacturing (DM²) is a Swiss-style machining company that special...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>crystalcoastpm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29892</link>
<guid>96a0d70498272acfee21d3dbae846113</guid>
<pubDate>Fri, 20 Feb 2026 21:53:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>crystalcoastpm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2ccda9576d9688732f53c54ac076afa71a6bf01b3479f2ff56d245c9e1763fb</i><br /><br />Threat actor <b>description</b>: <i>Crystal Coast Pain Management Center specializes in providing a comprehensive range of services for...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>xpressnebs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29893</link>
<guid>36d3be4cf501c5ad9e07d3e2507b181a</guid>
<pubDate>Fri, 20 Feb 2026 21:53:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>xpressnebs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2e4184c71ec994093eeb98a0c3360fb689fe74379c9eb188a670b8b5f50da76</i><br /><br />Threat actor <b>description</b>: <i>Xpress Nebs is a JCAHO certified Durable Medical Equipment company that specializes in providing hig...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>wjnklaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29894</link>
<guid>308794a90ec43d779df31a2e865a6f36</guid>
<pubDate>Fri, 20 Feb 2026 21:53:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>wjnklaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d746adcc12132fd8466ed5b5c00bfc1fa3c7ebbd84c232e302bfcd40549df22</i><br /><br />Threat actor <b>description</b>: <i>Westervelt, Johnson, Nicoll & Keller, LLC is a historic law firm based in Peoria, Illinois, with ove...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>smilescare.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29895</link>
<guid>f226f6cf9fdfe5a00262793195a3d228</guid>
<pubDate>Fri, 20 Feb 2026 21:53:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>smilescare.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b61cdfaf0d0fdd2da3310f207d411c6953d8402fda3338cd2376986b623bedf</i><br /><br />Threat actor <b>description</b>: <i>At SmilesCare.com, we are committed to being your trusted source for reliable and easy-to-understand...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>associated.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29897</link>
<guid>31beb41824b307d9f0deb076f8f9ee3b</guid>
<pubDate>Fri, 20 Feb 2026 21:53:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>associated.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96c95de4161151f56d4276a3496b556b81903e3b0ec839b2d21a675f0742950c</i><br /><br />Threat actor <b>description</b>: <i>The Associated: Jewish Federation of Baltimore is dedicated to supporting and nurturing Jewish life...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colonial-Van-Lines</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29877</link>
<guid>fecd1185063ed3d28b657ef4816b63f6</guid>
<pubDate>Fri, 20 Feb 2026 18:21:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Colonial-Van-Lines</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>496787191088af831e2a556b531c37b04e8bed2cf28c4feab8a60ad29437981a</i><br /><br />Threat actor <b>description</b>: <i>Colonial Van Lines is a U.S.-based long-distance moving and relocation company headquartered in Pompano Beach, Florida. Founded in 2003, the family-owned company specializes in interstate and cross-country residential, corporate, and military moves. It provides full-service packing, loading, transportation, storage, and unpacking solutions across the 48 continental states. The company operates a nationwide network of agents and a fleet of moving trucks, handling thousands of moves annually. Colonial Van Lines trains its staff through its own training facility and focuses on customer care and customized relocation services. With decades of industry experience, it aims to make moving easier, safer, and more organized for customers. The company headquarters is located in 1441 SW 29th Ave, Pompano Beach, Florida 33069, United States. 51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>RTC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29878</link>
<guid>db884574bea7de391188651592585c7e</guid>
<pubDate>Fri, 20 Feb 2026 18:20:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>RTC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1c2688c6282c3a110b3bed55aab5f42121007fcdb288eebcbef5f85f2d6f559</i><br /><br />Threat actor <b>description</b>: <i>RTC (rtc.com) is a global retail solutions and merchandising company that helps brands and retailers improve in-store shopping experiences and operational efficiency. The company designs and manufactures retail fixtures, shelf management systems, beverage merchandising displays, and theft-deterrence solutions, while also providing planning, development, rollout, and project management services. RTC works with major international brands to create customized retail environments that increase sales and productivity. With more than 75 years of industry experience, hundreds of employees, and offices and production facilities in multiple countries, RTC focuses on innovation, detail-driven retail design, and long-term client partnerships to support modern retail businesses worldwide. The company headquarters is located in 2800 Golf Road, Rolling Meadows, Illinois 60008, United States. 501-1,000 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aramsco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29879</link>
<guid>4927e1395ab1d386386a762cad17d7a7</guid>
<pubDate>Fri, 20 Feb 2026 18:20:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Aramsco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79835bc9e28d3bf49007ed2f12fe1a6dc9fee0067d6e04149e734779bc6ce113</i><br /><br />Threat actor <b>description</b>: <i>Aramsco is a U.S.-based distributor of professional cleaning, restoration, surface preparation, and safety products. The company supplies contractors and facility maintenance professionals with equipment, chemicals, tools, and personal protective equipment used in carpet cleaning, water and fire damage restoration, abatement, and construction preparation. In addition to product distribution, Aramsco provides training programs, technical education, disaster support, and equipment services to help businesses operate efficiently. It operates multiple branch locations and an online store serving customers nationwide. By combining industry expertise, support services, and a wide product catalog, Aramsco positions itself as a one-stop source for professional restoration and cleaning industry needs. The company headquarters is located in Five Radnor Corporate Center, 100 Matsonford Road, Suite 510, Radnor, Pennsylvania 19087, United States. 1K - 5K Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Madison-Services-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29880</link>
<guid>974e22cdbdb3734482fd0bcc2dc9bb79</guid>
<pubDate>Fri, 20 Feb 2026 17:39:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Madison-Services-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf84f733d5b422c687b73161d23e374f095e2822e6381576dae01b91ad4bc2e1</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Cherokee-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29874</link>
<guid>55ae21ea938d436617a8bddffede5e3d</guid>
<pubDate>Fri, 20 Feb 2026 16:39:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Cherokee-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d78c651dda102e4b54832708a835aabfb46204e59183f88e55e4198a75624f58</i><br /><br />Threat actor <b>description</b>: <i>Fabcon manufactures and erects precast concrete wall panels for every type of structure. Projects range from a 10,000 square-foot machine shop to a one-million square foot distribution center, and from a single-story bakery to a 16-story housing facility.We will upload corporate data soon. Employee personal documents (passports, DLs and so on), financials, projects, drawings and specification, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fabcon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29876</link>
<guid>cf4f35ee546a6d8fe9461b8db8a8200a</guid>
<pubDate>Fri, 20 Feb 2026 15:39:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fabcon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a2248974c0c78139874915cb952144ebd4a19818ae1c0db1d263543e9f18ce5</i><br /><br />Threat actor <b>description</b>: <i>Fabcon manufactures and erects precast concrete wall panels for every type of structure. Projects range from a 10,000 square-foot machine shop to a one-million square foot distribution center, and from a single-story bakery to a 16-story housing facility.We will upload almost 190gb of corporate data soon. Client information, employee personal documents (passports, SSNs, DLs and so on), detailed financials, projects (confidential files), NDAs, etc. Kerkstra Precast company data will be disclosed as well.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pearl-Institute-for-Clinical-Research-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29870</link>
<guid>4d612ec00583838471ceff508d9f67c7</guid>
<pubDate>Fri, 20 Feb 2026 11:09:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Pearl-Institute-for-Clinical-Research-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>997cf6c1a894ae25e664ffc5f5c0a7b1cefb5a324227e2cafb0fe8d50610f098</i><br /><br />Threat actor <b>description</b>: <i>Data is not available for now.</i><br />Target victim <b>website</b>: <i>pi-cr.net</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gentegra</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29867</link>
<guid>abdb9f5517daf77fe4714ad0669c9e19</guid>
<pubDate>Fri, 20 Feb 2026 01:16:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Gentegra</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1c011fd7e5ec4ec85f4bdbd41b2607166b215bf120be0c54d93b17468238bf7</i><br /><br />Threat actor <b>description</b>: <i>GenTegra specializes in innovative solutions for the stabilization and shipping of DNA and RNA, focusing on products that ensure sample integrity during transportation. Their offerings include a suite of RNA protection products and forensic DNA storage solutions, catering to clients in life sciences, forensic labs, and biobanking. With technology validated for maintaining the quality of samples at room temperature, GenTegra is recognized for revolutionizing hassle-free sample management and offering superior protection for RNA and DNA. Their products are designed to seamlessly integrate into existing protocols, showcasing compatibility with standard purification kits.</i><br />Target victim <b>website</b>: <i>www.gentegra.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Iblesoft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29865</link>
<guid>f72e0b9fc085734d1bb6932d3f5b48fd</guid>
<pubDate>Thu, 19 Feb 2026 20:46:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Iblesoft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a642e9a485882cd90de6e7997cdd08f889a38481c23b89c1b85ee0446e02b93f</i><br /><br />Threat actor <b>description</b>: <i>Iblesoft Inc. is a full service software development, global resource placement and business consulting firm based in Doral, FL. Iblesoft provides state of the art business consulting services and cutting edge technology solutions to companies of all sizes, offering them improved efficiency and profitability.</i><br />Target victim <b>website</b>: <i>www.iblesoft.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Corradino-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29851</link>
<guid>5eac0347e226308d6c55e79d4d4e6eb0</guid>
<pubDate>Thu, 19 Feb 2026 20:41:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Corradino-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>778d3700505a274e8bc9fcac3558b3c7c1fa570dfa4efcbadcf873514322a39f</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saltech-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29864</link>
<guid>8a1f74ea8d333ac37a9fe795aa4183e2</guid>
<pubDate>Thu, 19 Feb 2026 19:22:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Saltech-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c5578fcb63cab60bc7a1f7d3d6af1f76ece89e8b7d09dd5a71e2817a29943a6</i><br /><br />Threat actor <b>description</b>: <i>Saltech Systems is a technology company specializing in application development, web design, IT services, and digital marketing, with offices located in Iowa and Texas. They offer a wide range of services including custom website and mobile app development, IT support, cybersecurity, and cloud hosting solutions. Their intended clients include businesses seeking to enhance their online presence and streamline operations through tailored technology strategies. With a commitment to exceptional customer service, Saltech Systems aims to empower clients to thrive in a rapidly evolving digital landscape.</i><br />Target victim <b>website</b>: <i>www.saltechsystems.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Electriduct</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29863</link>
<guid>9c68bf8965e0692b91ef2f048cea8378</guid>
<pubDate>Thu, 19 Feb 2026 19:21:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Electriduct</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a7cc0c52250956533ed7f3d9ba6addb72ec1500f86995212a1dd7b0ff82a3ec1</i><br /><br />Threat actor <b>description</b>: <i>Electriduct specializes in cable management solutions, offering a wide range of products including cable protectors, wire management tools, and power distribution equipment. Their extensive catalog features items such as braided sleeving, cable carriers, and traffic safety products, catering to both indoor and outdoor applications. The company targets professionals in various industries who require reliable and efficient cable management solutions. Electriduct is committed to providing high-quality products at competitive prices, with a focus on customer satisfaction and expert support.</i><br />Target victim <b>website</b>: <i>www.electriduct.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marwood</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29861</link>
<guid>822e5a4c9294866332d5cc0a328596d5</guid>
<pubDate>Thu, 19 Feb 2026 19:17:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Marwood</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28b1cd6ec7d6081268078819ee45c273e63610b0f14088c222d0461ac1b5c053</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.marwoodltd.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kirbor-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29858</link>
<guid>f6533e79009ff4a7c9f4ad85ed45709e</guid>
<pubDate>Thu, 19 Feb 2026 19:15:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kirbor-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>114d64e57c2b43e1f968626f3c9329aca67a0878a9dc84875583645297ef3eb5</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kirbor.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tropic-Tool--Mold</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29857</link>
<guid>fbb52ce1dc9851b47da22ee229dbbda8</guid>
<pubDate>Thu, 19 Feb 2026 19:15:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Tropic-Tool--Mold</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3c36c161a61b3c0bc5ef4d07cc6ca24970fc978ad97cdfacd637933e69bb1eb</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.tropictoolandmold.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arizona-Lighting-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29856</link>
<guid>e1dbbe5fa0cc885cabb5d674c14ca7a9</guid>
<pubDate>Thu, 19 Feb 2026 19:14:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Arizona-Lighting-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1bd01989534e053a6463cab2c292f76654d344e6dd080746cfe6efb4509b2ba</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.arizonalightingsales.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indianapolis-Car-Exchange</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29855</link>
<guid>6abfefaf79dff3c6a5bcfde47a85749f</guid>
<pubDate>Thu, 19 Feb 2026 19:13:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Indianapolis-Car-Exchange</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61554d51f7976fd2fdfc30231cb4c1f7ac93be43a2345861ad29e650b28c615c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.icefriday.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oklahoma-Auto-Exchange</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29854</link>
<guid>3dc2c2f6a6a75cba6bc726b4545e788c</guid>
<pubDate>Thu, 19 Feb 2026 19:13:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Oklahoma-Auto-Exchange</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d43dc697ea138f3a5e965f15e9f99d4a71faa9ee4ed6860cd09da65289cebe8</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.okaex.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Auto-Auction-of-New-England</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29853</link>
<guid>5d213468da8857324393c707fb3f6f67</guid>
<pubDate>Thu, 19 Feb 2026 19:12:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Auto-Auction-of-New-England</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c4c8bb9e552bd71681d550e3647b1d99717838afca78fa2ee6988cae9625a16</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.aane.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spring-Brook-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29852</link>
<guid>97a111b32fdafbaa0de29a40b2df1ffd</guid>
<pubDate>Thu, 19 Feb 2026 19:11:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Spring-Brook-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af78116588294363ae09c4ff1ebf1baef66c20ade2b41372c3cc64142d2a301f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.springbrookcc.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>fivestates.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29850</link>
<guid>f1af9918adf75d2cfe2e87861a72f1f6</guid>
<pubDate>Thu, 19 Feb 2026 18:39:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>fivestates.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6b1c76a4614f6717503eed4b5cf8a0553feb65514e214ef74e51c6144016f43</i><br /><br />Threat actor <b>description</b>: <i>Five States Energy is a private investment firm based in Dallas, Texas, with over 30 years of experience in the energy sector. The company specializes in acquiring producing oil and natural gas properties, primarily focusing on independent, onshore operators and working interest owners across various regions in the U.S. Recently</i><br />Target victim <b>website</b>: <i>fivestates.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kroll-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29848</link>
<guid>6ab2ef9e3a9f4ed96fb1b77191e612d0</guid>
<pubDate>Thu, 19 Feb 2026 17:44:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kroll-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29c310983e7d2bd0dee0249e7dfbe08b164840fdbdd90d8c281cb37bd4ebdd7d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.krollcorp.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Telecare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29843</link>
<guid>de556ca8eba0fc417ac22b46cd3d0c84</guid>
<pubDate>Thu, 19 Feb 2026 17:42:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Telecare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42508e60c94a3179b81cdbf1b214d802e83c3dcf8404174cce2f8c6b27c01811</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TCPN-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29847</link>
<guid>48c166e714c21cbdb72f2e85d87fb118</guid>
<pubDate>Thu, 19 Feb 2026 17:41:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>TCPN-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>526a8f38be88055fbeb34f606dc9ef64205a7c0b6ba58c907fdbc3fab23b4adf</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>tcpninc.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>RS-Development-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29845</link>
<guid>f3d283dc9dbbcf9377d91798ac47cf2f</guid>
<pubDate>Thu, 19 Feb 2026 17:40:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>RS-Development-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5baf04820cfe19fec25e7b0a5fdfff64e4a56b247e2157ba1706752713a17e52</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.rsdev.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kensington-HPP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29841</link>
<guid>8a95e369d9ff66dd5f5dea5fa7b5ab9a</guid>
<pubDate>Thu, 19 Feb 2026 14:43:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kensington-HPP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>950c78aa446474e565c91ad8ee5b0fcb3e67b21714736fcedfb1b6b05ad4ae86</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MD-Charts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29842</link>
<guid>18b30c4ac2b116fdb322b3a7f749979e</guid>
<pubDate>Thu, 19 Feb 2026 14:29:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>MD-Charts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a19726d44a20670af047b8742d9b167ee7ba5a82d72cd9d03d8b6ff4b3e76f1f</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>mdchartsehr.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>O.Berk</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29828</link>
<guid>1968e73cfcb43ede6c35cf8ef0f7d1d3</guid>
<pubDate>Wed, 18 Feb 2026 18:40:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>O.Berk</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>258d882caa406d9fe188b34b2da31fd4e2185b2d6b4e6d88c9cfc4faa9eaedd9</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Piping--Boiler-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29831</link>
<guid>c1092c40dfa01c731017bd0dd7cf63ef</guid>
<pubDate>Wed, 18 Feb 2026 18:34:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>American-Piping--Boiler-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c760b793a819bb0adc7edf8778af81a97c93ceceb2f59ebce08672295b69269</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>www.apbconstructiongroup.org</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>AA-Global-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29823</link>
<guid>3ffedfdaa29dbf097fb6724d2e890b00</guid>
<pubDate>Wed, 18 Feb 2026 16:38:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>AA-Global-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4dfe8dee4d53ba17c971d8c0bff8f254c72ac97df9a232e4726628fead0d6f4c</i><br /><br />Threat actor <b>description</b>: <i>A&A Global is a trusted partner operators, retailers, and business owners turn to for toys, candy, and creative product solutions that build loyalty, increase foot traffic, and drive real business results.We will upload corporate data soon. Detailed personal files of employees (SSNs, passports, DLs, medical information and other personal files), HR files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cargo-Largo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29824</link>
<guid>7e8bc77312d6dfdd73cd283ad31a3444</guid>
<pubDate>Wed, 18 Feb 2026 16:38:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cargo-Largo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b4173ef5db2682f8fdd17986eab69db4bdc132643facb830a4f11c9edc997c3f</i><br /><br />Threat actor <b>description</b>: <i>Cargo Largo is a discount store located in Independence, MO, offering a wide range of name-brand products including electronics, clothing, furniture, shoes, and hardware at competitive prices.We will upload corporate data soon. Customer information, financials and other internal files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Application-Solution-Providers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29825</link>
<guid>f0e37e9e9b28f94f89e67d28df74c2b4</guid>
<pubDate>Wed, 18 Feb 2026 15:14:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Application-Solution-Providers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58a44e49d77739205541e30ca7c3cd728a9045cd2055f3a8f63516f2a65b3a2c</i><br /><br />Threat actor <b>description</b>: <i>Application Solution Providers, Inc. delivers cloud-based DaaS and software, plus consulting, development, marketing, support, and training—enabling flexible, remote operations with tailored, customer-focused solutions to boost efficiency.</i><br />Target victim <b>website</b>: <i>www.aspdd.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>DeWalch-Technologies-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29822</link>
<guid>8b42d3eeb4da1f29ee08dedd7855a0ed</guid>
<pubDate>Wed, 18 Feb 2026 14:38:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>DeWalch-Technologies-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8ed70a1e9c74340af4f42fd5fcd5e5267ab37f64564de92ce287a43e006ffff</i><br /><br />Threat actor <b>description</b>: <i>DeWalch Technologies, Inc. is a vertically integrated engineering and manufacturing company with operations in four key verticals: security, energy, manufacturing, and digital.</i><br />Target victim <b>website</b>: <i>www.dewalch.com</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cedar-Grove-Warehouse</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29821</link>
<guid>4744015f38ee03ef7f62f60a5017907c</guid>
<pubDate>Wed, 18 Feb 2026 13:58:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cedar-Grove-Warehouse</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a796f6f14aed3cedf1813a9e6e54a0cb8c6113d670f7478bf0555db301f9d5d2</i><br /><br />Threat actor <b>description</b>: <i>Cedar Grove Warehouse is a family-owned logistics and warehousing
company that offers a range of services including dock-to-dock l
ogistics solutions, rail car cross docking, and various storage o
ptions such as refrigerated, freezer, and dry storage. 

We will upload almost 27gb of corporate data soon. Personal files
of employees (SSNs, passports, national IDs and DLs of more than
100 ppl and other personal information), financials, HR files, p
rojects, client files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-4-Recruitment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29818</link>
<guid>f5fd4686872b63a5840cc1113450801e</guid>
<pubDate>Wed, 18 Feb 2026 12:34:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>First-4-Recruitment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f201f8eeb69dc979e5f82705209b42034e95073e2aceb89221faf0c01f63b5b</i><br /><br />Threat actor <b>description</b>: <i>First 4 Recruitment is a prominent recruitment agency based in the North West, specializing in the Industrial, Logistics, Construction, and Commercial sectors.</i><br />Target victim <b>website</b>: <i>www.first4-recruitment.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Daniel-L-Kaler-DDS-PC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29817</link>
<guid>e2ae9d605614017e3ae77dcbc1aaee23</guid>
<pubDate>Wed, 18 Feb 2026 12:34:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Daniel-L-Kaler-DDS-PC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0bdc891244be0a10229e457fca861674318f4c75cea7f5c99c5e944c365f3a8a</i><br /><br />Threat actor <b>description</b>: <i>Daniel L. Kaler, DDS, PC offers unparalleled orthodontic services to children, teens, and adults in Sioux City, Le Mars, IA, and Wayne, NE. The practice is dedicated to creating beautiful, healthy smiles through gentle and effective treatments in a comfortable environment.</i><br />Target victim <b>website</b>: <i>www.drkaler.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Diversified-Supply-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29816</link>
<guid>fc64004dee3fa6dec3cf0a018f64f1cd</guid>
<pubDate>Wed, 18 Feb 2026 11:40:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Diversified-Supply-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b18fa0401b91f4b6162e5b08ee4ab48b0f4b7c405502e1c32d9408bd96449594</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>IFL-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29814</link>
<guid>32364276cb2f62e1e492f15ca557159c</guid>
<pubDate>Wed, 18 Feb 2026 05:42:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>IFL-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a6fcc7db8d20e731027fa64167b4f595402a8a8ef7c27a94f2dae1da7ddac32</i><br /><br />Threat actor <b>description</b>: <i>Data breach at an Air Transportation Company.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cheyenne--Arapaho-Tribes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29813</link>
<guid>1fd1df658a0a3d7f385185db7c9c5029</guid>
<pubDate>Tue, 17 Feb 2026 21:24:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Cheyenne--Arapaho-Tribes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee86344ea4ad33b18d6e3ba31d825e67e8419baa1fadb28e0387522daa4eb65b</i><br /><br />Threat actor <b>description</b>: <i>Cheyenne & Arapaho Tribes The Cheyenne and Arapaho Tribes are a federally recognized united nation of two distinct peoples-the Tsistsistas (Cheyenne) and Hinono'ei (Arapaho)-with a historic alliance formed in the early 19th century.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wilson-Workflow-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29812</link>
<guid>73fb305c6b3819a3e01c5d351e699abc</guid>
<pubDate>Tue, 17 Feb 2026 21:19:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Wilson-Workflow-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a8657425cdb15ed732fe9f839d6b5b7415c48a09749571aeb575eb0733d70c8</i><br /><br />Threat actor <b>description</b>: <i>Data is not available now.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Midwest-Wheel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29800</link>
<guid>a69017f8746c392b173dc70700fda957</guid>
<pubDate>Tue, 17 Feb 2026 20:43:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Midwest-Wheel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f5389fd9b7d2e61977a7a000ede7c351cfb5b0fc2055d012f98642a5de8662d</i><br /><br />Threat actor <b>description</b>: <i>Automotive Parts</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saiful-Bouquet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29801</link>
<guid>73d0e1095870b725152f48157d253034</guid>
<pubDate>Tue, 17 Feb 2026 20:43:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Saiful-Bouquet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f74ef1424609bc1a6e6f1e1a40b2c4669534221e61133031f9736f86bf63fdb</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stockton-Cardiology-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29808</link>
<guid>874b2add857bd9bcc60635a51eb2b697</guid>
<pubDate>Tue, 17 Feb 2026 19:10:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Stockton-Cardiology-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25dfacfb6b0a53cd4a361584e3e1fc25894349b3a3b1bb11e5e597f380e659aa</i><br /><br />Threat actor <b>description</b>: <i>A provider of cardiology services.</i><br />Target victim <b>website</b>: <i>stocktoncardiology.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Management-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29807</link>
<guid>8c4b0479f20772cb9b68cf5f161d1e6f</guid>
<pubDate>Tue, 17 Feb 2026 19:10:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Community-Management-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39faa6bb694abedf27eed48d7fdd8bf3be9ea08b8adc0dd0a92bc1a6f0a80d39</i><br /><br />Threat actor <b>description</b>: <i>Serves residential and master-planned communities, town homes, mixed use and commercial/retail properties.</i><br />Target victim <b>website</b>: <i>cmamanagement.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Robeck-Fluid-Power</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29806</link>
<guid>98a733901e53052474f2320d0a3a9473</guid>
<pubDate>Tue, 17 Feb 2026 19:09:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Robeck-Fluid-Power</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>616e9f329673384e22e3b1eab48d18981c214d8c7049c392557c9a70aec5ae2d</i><br /><br />Threat actor <b>description</b>: <i>A supplier of machinery solutions</i><br />Target victim <b>website</b>: <i>robeckfluidpower.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fong-Ilagan-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29805</link>
<guid>b4525c940c2ee20606f7a6a59f32ab8b</guid>
<pubDate>Tue, 17 Feb 2026 19:08:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Fong-Ilagan-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1cb191a03518fc8ac94adb0b4829b0ec3be4e834a00f9cea21dd3d5f0eb5d9e</i><br /><br />Threat actor <b>description</b>: <i>An immigration law firm from Texas, USA.</i><br />Target victim <b>website</b>: <i>fonglegal.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>OfficeWorks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29804</link>
<guid>8a6b756f8eb9b358f11ece6ddca066f7</guid>
<pubDate>Tue, 17 Feb 2026 19:08:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>OfficeWorks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a5e0ea14f96681bd9cccd92e8f62f8a0c99880c5ac4912470ac25349bbe5bdb</i><br /><br />Threat actor <b>description</b>: <i>An office space consulting firm.</i><br />Target victim <b>website</b>: <i>officeworks.net</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miller-Johnson-Jones-Antonisse--White</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29803</link>
<guid>7851934f3332c6b7ff9a3e4ed82e532d</guid>
<pubDate>Tue, 17 Feb 2026 19:07:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Miller-Johnson-Jones-Antonisse--White</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee516cb67e84942794f3192ddb108fa9b871c47e37a9e82e5b74b193fdacb4d5</i><br /><br />Threat actor <b>description</b>: <i>A law firm based in Oklahoma City.</i><br />Target victim <b>website</b>: <i>mjjaw.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>gbaco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29794</link>
<guid>457c753860099e09373e202e39292de9</guid>
<pubDate>Tue, 17 Feb 2026 14:40:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>gbaco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>435d19523b4c7e7b76fdee75936c47fda9b74f6a69cf93b94a081f910e7cf6cb</i><br /><br />Threat actor <b>description</b>: <i>GOFF BACKA ALFERA & COMPANY, LLC is a full-service public accounting and consult...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>powersmiller.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29795</link>
<guid>aa713fa341f6786c39b587498449a999</guid>
<pubDate>Tue, 17 Feb 2026 14:40:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>powersmiller.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1630864f9b49348ab8f6ea437ab6b509e1728cb212c99ed66817f21b6926f232</i><br /><br />Threat actor <b>description</b>: <i>Powers Miller Attorneys At Law is a civil litigation firm based in Northern Cali...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29796</link>
<guid>81c83933ca039e756f2b0d69ebaa38ba</guid>
<pubDate>Tue, 17 Feb 2026 13:39:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Brm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1469a9b995e098436c5efa127442a982e4452c41d934a0a527ae0e816fd45210</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Castle-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29792</link>
<guid>cb99590f7cf124e88bdd3a40b3b1c8bb</guid>
<pubDate>Tue, 17 Feb 2026 12:39:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Castle-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1798a569ad42c6df7f5471536e9c22fe8b391559c030bf405819f2f85ca1ee19</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>structuredassetservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29793</link>
<guid>dc0e16a46c7bb604bc7fd87037f32787</guid>
<pubDate>Tue, 17 Feb 2026 12:20:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>structuredassetservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68ca4a80161c336f498525ac7e685d1139e3b579cd64f05ecfa74429183e7244</i><br /><br />Threat actor <b>description</b>: <i>About Structured Asset Funding and 123LUMPSUM -- Located in Hallandale Beach, Florida, Structured Asset Funding, LLC and 123LUMPSUM are the leading purchasers of structured settlement payments and annuities. These specialty finance companies apply institutional financing, underwriting and legal expertise to purchase future cash flows from individuals whose life circumstances have changed suddenly and need immediate cash from their structured settlements and insurance annuities</i><br />Target victim <b>website</b>: <i>structuredassetservices.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hiwassee-Builder-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29788</link>
<guid>c6fc35734a1a498915984159907854e9</guid>
<pubDate>Tue, 17 Feb 2026 03:18:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Hiwassee-Builder-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fcfb7001fe7e776e92ac0be2cd917d7ee97c1a00da19c53622893d1828f6556c</i><br /><br />Threat actor <b>description</b>: <i>HIWASSEE BUILDERS SUPPLY is dedicated to delivering a wide range of building products and services with exceptional value and service across East Tennessee and beyond. They offer in-house expertise for project design, estimation, and timely product delivery, catering to both home remodeling and commercial construction needs. With four locations in East Tennessee, they ensure efficient service and support throughout various projects.  Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>farbank.com-flywatertravel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29787</link>
<guid>2661d3ecfd1458a72d642c635f4972ce</guid>
<pubDate>Tue, 17 Feb 2026 03:18:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>farbank.com-flywatertravel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1bf43eb7e0d089c72a969c55f707f232b56f6642c306426238b73040775a3430</i><br /><br />Threat actor <b>description</b>: <i>Far Bank Enterprises is an integrated manufacturer and distributor of fly fishing products and services, including fly fishing rods, reels, waders, lines, leaders, tippet, performance outdoor apparel, and travel to the world's finest fly fishing experiences. Far Bank subsidiaries operate under the brand names Sage, Redington, RIO Products, and Fly Water Travel. Fly Water Travel is a leading provider of guided fly fishing trips and vacations, dedicated to delivering exceptional experiences for passionate anglers.  Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nebraska-Health-Imaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29786</link>
<guid>12b2fce48d921b502cb67aaf23df662f</guid>
<pubDate>Tue, 17 Feb 2026 02:48:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Nebraska-Health-Imaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6fd1dfa38ba95f4f13dc54a5faa9586846e60540f00ea340d94f8fcec988bd28</i><br /><br />Threat actor <b>description</b>: <i>Nebraska Health Imaging is an accredited outpatient diagnostic center in Omaha, NE, offering a comprehensive range of affordable diagnostic and screening radiology services, including MRI, CT, X-rays, and Ultrasound.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Modoc-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29774</link>
<guid>ec6019ea251a4e03b08d4135153be64e</guid>
<pubDate>Mon, 16 Feb 2026 17:37:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Modoc-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eaa68f7709483b61de99844fe4f96c6f555a6893f9ea0712b4abba6dd45f6229</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Williams-Brothers-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29776</link>
<guid>82553a1ebce1e1df751e69b697bd097b</guid>
<pubDate>Mon, 16 Feb 2026 17:37:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Williams-Brothers-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7c55ae32ba1b403b56f5f45341b1a85734cd19676edf5a44b0eab5828dbb8c8</i><br /><br />Threat actor <b>description</b>: <i>Williams Brothers Construction Company, based in Houston, is a leading highway contractor in the United States with over 70 years of experience. They specialize in bridge construction, roadway paving, and handling complex special projects, emphasizing engineering excellence and innovation.We will upload almost 90gb of corporate data soon. Lots of personal files of employees, confidential financials and other files, projects, client files, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abbott-Media-Productions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29779</link>
<guid>28869ca36d89935b7de5d54a513e63e3</guid>
<pubDate>Mon, 16 Feb 2026 17:25:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Abbott-Media-Productions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62bc95f0f6c8fe120fccb7b8a208c3a6061b8b2eb80d9063169f9e9037236cb0</i><br /><br />Threat actor <b>description</b>: <i>Abbott Media Productions, based in Tucson, Arizona, specializes in 3D animation, technical animation, and a full range of video production services. They provide animation services and interactive applications, incident reenactments, product animation, and motion graphics. Their primary clients include government agencies, defense contractors, and commercial organizations.</i><br />Target victim <b>website</b>: <i>https:abbottanimation.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marshall--Stevens</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29777</link>
<guid>b5932e1bc9bc30711f71a60a3d5c965c</guid>
<pubDate>Mon, 16 Feb 2026 17:12:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Marshall--Stevens</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7c27cb4f3e79c64c1951a81be1e5f0ac0b45e12e27387e58481f7bb7d51cdfc</i><br /><br />Threat actor <b>description</b>: <i>Marshall & Stevens was established in 1932. The firm has pioneered new concepts to provide realistic c…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>hh2home.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29772</link>
<guid>b9e4d53a5bd0882b7715b90c7c29aea2</guid>
<pubDate>Mon, 16 Feb 2026 14:43:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>hh2home.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b50df51255854a78f3652bfd0a93ea7ebe6cecc0d59712b516f8df117cc90672</i><br /><br />Threat actor <b>description</b>: <i>For 30 years, we have been the preferred wholesale partner for many of your favorite retailers. During this time, we have continued to develop our passion for innovation and creating quality furniture designed to inspire. We believe that real life is beautiful, and nowhere is this more evident than in our homes.</i><br />Target victim <b>website</b>: <i>hh2home.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>faswealthpartners.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29771</link>
<guid>28ec410e2ac9d191d1d1558806bace8c</guid>
<pubDate>Mon, 16 Feb 2026 14:42:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>faswealthpartners.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6c717562599367d5ed784e7a6f2cdcbde15d190cf8c1a20387defe22d14c127</i><br /><br />Threat actor <b>description</b>: <i>FAS Wealth Partners, Inc. is a fee-based financial advisory firm located in Kansas City. The company offers a wide range of services, including asset management, retirement planning, and estate planning. The firm primarily serves high-net-worth individuals, families, retirees, executives, professionals, and business owners, providing customized financial planning and investment management solutions. With a personalized approach, the company helps clients achieve their financial goals and optimize their wealth. 
Founded in 1979, FAS Wealth Partners focuses on building strong relationships with clients through its team of certified financial planners.</i><br />Target victim <b>website</b>: <i>faswealthpartners.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hagen-Rosskopf</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29765</link>
<guid>185982320d79cd9d4bdfa9164f801930</guid>
<pubDate>Mon, 16 Feb 2026 14:38:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hagen-Rosskopf</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fce353f0ef96e171ebb4c2fbaa3f0de107f95dbf873484e28ebcad7c741063b</i><br /><br />Threat actor <b>description</b>: <i>A fast paced, boutique law firm that specializes in personal injury with a niche in representing injured cyclists.We will upload corporate data soon. Clients' personal information(passports, DLs, health information and so on), confidential legal files, court docs, police reports, employee files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>traceenv.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29769</link>
<guid>1b31785397bc74c6ff59451d4f410b71</guid>
<pubDate>Mon, 16 Feb 2026 13:59:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>traceenv.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb1e2316c8be54355bfcaa0ce6493b44de99a5f2923a4506848d9aff44d11908</i><br /><br />Threat actor <b>description</b>: <i>Trace Environmental Systems Inc. is an innovative organization specializing in providing continuous stack emission monitoring systems and data collection solutions that ensure regulatory compliance.The company serves a variety of industries, including ethanol production, power generation, chemical manufacturing, waste-to-energy, wastewater incineration, cogeneration/recovery/university facilities, and refineries.</i><br />Target victim <b>website</b>: <i>traceenv.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>mapsweb.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29768</link>
<guid>56497e4ee7adaa68126174b985b7081c</guid>
<pubDate>Mon, 16 Feb 2026 13:58:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>mapsweb.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9e5801d9345123ac382ff7465e9a0f529b317f621cfdc47a4e265d25e65948d</i><br /><br />Threat actor <b>description</b>: <i>Modern Advanced Print Solutions (MAPS, Inc.) is a leading independent corporation located in Leavenworth, Kansas, specializing in a wide range of products for 
document management and office systems. The company offers innovative print management, asset lifecycle management, and other professional services designed to improve business efficiency.</i><br />Target victim <b>website</b>: <i>mapsweb.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Branagh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29757</link>
<guid>a49ab7f57366ac88e823ae316a39e6fb</guid>
<pubDate>Sun, 15 Feb 2026 19:38:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Branagh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>735450b65efc7514a9c58932f79f9d6f153dd5f1ecc0e675d1805ccd2af23a89</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.branaghinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Schlenker-and-Cantwell-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32980</link>
<guid>617b19230f317bed77a9e7f63cab277c</guid>
<pubDate>Sat, 14 Feb 2026 23:04:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>deadlock</b> claims attack for <b>Schlenker-and-Cantwell-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9eecb852e2733da317166b89d9a87197992362a4809af1c61a73850fdd8b7b41</i><br /><br />Threat actor <b>description</b>: <i>Schlenker & Cantwell, P.A. is a certified public accounting firm based in the USA, offering services such as tax preparation and planning, auditing and assurance, bookkeeping, payroll, financial reporting, consulting, and estate-trust management.</i><br />Target victim <b>website</b>: <i>cpasch.com</i>]]></description>
<category>deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Morton-Grove-Park-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=32978</link>
<guid>bceb3255d9e971801589ea08667466f0</guid>
<pubDate>Sat, 14 Feb 2026 23:03:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>deadlock</b> claims attack for <b>The-Morton-Grove-Park-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53ce0845f81aa8dc3a50ba89a29b8bd7d82efc67ee0917ac4545b1cc8cc87f52</i><br /><br />Threat actor <b>description</b>: <i>The Morton Grove Park District (MGPD) is a separate municipal agency established in 1951, governed by five elected commissioners and subject to Illinois state laws.\r\n\r\nhttps://mortongroveparks.com/\r\n\r\n\r\nTheir motto is:\r\nEveryone who lives in, works in, or visits Morton Grove has constitutional rights, no matter their citizenship or immigration status. The Village is committed to making sure every person feels safe, supported, and respected.\r\n\r\nMore than 50 GB of data containing personal and sensitive information belonging to both internal employees and the organization\'s clients and suppliers.\r\nDocuments on financial plans and internal policies are protected by a non-disclosure policy. (Including racist and sexist insights)\r\nWe invite all journalists, lawyers, and law enforcement agencies to review this information.</i><br />Target victim <b>website</b>: <i>mortongroveparks.com</i>]]></description>
<category>deadlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adirondack-Networks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29743</link>
<guid>f076abd96d6f1a9ae1b32bde776e9e82</guid>
<pubDate>Sat, 14 Feb 2026 15:09:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Adirondack-Networks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5aefd486db3ffc4f765c675fce214ee5ee552fac8d950dd81ef251b074060c4e</i><br /><br />Threat actor <b>description</b>: <i>Internal Documents.</i><br />Target victim <b>website</b>: <i>adirondacknetworks.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeast-Pharmacy-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29717</link>
<guid>021b8947656eb84e4c641506215777c8</guid>
<pubDate>Sat, 14 Feb 2026 12:37:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northeast-Pharmacy-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3749cedfdc7c341361bbcaa7e26c74fa0889d02815ccfcef8c866a77e08b6c41</i><br /><br />Threat actor <b>description</b>: <i>Northeast Pharmacy Service Corporation (NPSC) is dedicated to supporting independent community pharmacies by providing business development services, individualized support, and strategic advocacy. They offer a range of concierge-level services, including access to dedicated pharmacy consultants, educational resources, and industry insights to help pharmacies thrive.We are going to upload company data soon. You will find financialdata (audit, invoices,financial reports), personal files and customers data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MESA-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29727</link>
<guid>f7fb43719fb4947a5d0faa61de9fb232</guid>
<pubDate>Sat, 14 Feb 2026 11:26:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>MESA-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12309ac39e4d85b572c51c6dd4b8b97e24d27b64a68ea8ac0252a4f7a917f7d5</i><br /><br />Threat actor <b>description</b>: <i>MESA Products is a U.S.-based industrial company that supplies cathodic protection materials and corrosion control solutions. The company focuses on preventing rust and structural damage in critical infrastructure such as pipelines and underground metal systems. Its product range includes test stations, connection kits, and monitoring equipment used to measure and maintain corrosion-protection systems. MESA emphasizes safety, reliable manufacturing, and high on-time delivery performance while supporting engineers, utilities, and construction sectors. The company’s mission is to protect people, property, and the environment by extending the life and reliability of essential infrastructure through quality protective technologies and technical support services. 
The company headquarters is located in 4445 S 74th East Ave, Tulsa, Oklahoma 74145, United States.
201-500 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>hanover-ma.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29725</link>
<guid>c21721f351b4c39bf61f7d9a987615e5</guid>
<pubDate>Sat, 14 Feb 2026 11:14:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>hanover-ma.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adacd68e11e85ca5c511323697f8940bb0c0d3c9295dea33e337f822a18a5327</i><br /><br />Threat actor <b>description</b>: <i>The mission of the Hanover Police Department is to prevent crime, but instead of doing their job, th...</i><br />Target victim <b>website</b>: <i>hanover-ma.gov</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>cmcconstruct.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29723</link>
<guid>943b303113e117eac269699cdb061768</guid>
<pubDate>Sat, 14 Feb 2026 11:11:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>cmcconstruct.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>471eaf87d6757950fa4a6e78bc5e2494ec63071cc48eb5f816068f4b2d4c7525</i><br /><br />Threat actor <b>description</b>: <i>Chamberlain & McCreery is a general contractor specializing in the construction of custom, energy-ef...</i><br />Target victim <b>website</b>: <i>cmcconstruct.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>JC-Resorts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29716</link>
<guid>2963dbc550404970787514aa177006e8</guid>
<pubDate>Sat, 14 Feb 2026 10:38:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>JC-Resorts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7df006b491ececfb401133f3b38c95e25218d9a40a98841b0a41008c84f94aaf</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buff-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29715</link>
<guid>bf9d0c59964a37b03173d7c683153962</guid>
<pubDate>Sat, 14 Feb 2026 06:55:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Buff-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c36ddd6ccc8fa5a9a458f903b6c14114ea660ce4d13d12c0f054735bf2ed9bd</i><br /><br />Threat actor <b>description</b>: <i>Rosenthal, Kooshoian & Lennon, LLP is a long-established Buffalo, New York law firm with over 70 years of experience representing clients in personal injury, criminal defense, and related matters.  They handle a wide range of cases including construction and vehicle accidents, wrongful death, product liability, and DUI/DWI defense.  The firm is known for personalized legal advocacy, trial experience, and free consultations for many types of cases.  Their attorneys combine courtroom skill with community recognition and professional involvement.- Clients' personal data- Court decisions- Evidence- Police reports, etc. https://bufflaw.com/</i><br />Target victim <b>website</b>: <i>bufflaw.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Copier-Careers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29712</link>
<guid>ea90e42eb981294a7fb36b39326d9617</guid>
<pubDate>Fri, 13 Feb 2026 23:08:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Copier-Careers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb2789bedbc54a7714f485fda04aebeeba9658499c69e7b4ba317073a4399772</i><br /><br />Threat actor <b>description</b>: <i>Copier Careers is a recruiting firm connecting Copier Channel employers with skilled professionals. It focuses on strategic placements—Sales Reps, Managers, and other office equipment roles—to help businesses grow, and provides job seekers a job board.</i><br />Target victim <b>website</b>: <i>www.copiercareers.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Syverson-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29711</link>
<guid>253637b08749bde403df7fcd0b66f731</guid>
<pubDate>Fri, 13 Feb 2026 23:07:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>The-Syverson-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c82dcd705ced14209eec892ae53e0be72211dc863c0e77beb59ba2af4bc51a0a</i><br /><br />Threat actor <b>description</b>: <i>TSG is a retained executive search firm specializing in medical device and life sciences recruiting. They deliver rapid, client and candidate-focused talent acquisition—including diagnostics, clinical research and leadership placement.</i><br />Target victim <b>website</b>: <i>www.thesyversongroup.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Archaeological-Institute-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29706</link>
<guid>bb4ea12f999f3e1c0df45ab2983be5df</guid>
<pubDate>Fri, 13 Feb 2026 21:38:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Archaeological-Institute-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>497301b394582bd5a5b0f1908e8436a65f6cce17d16f06f994d92a6f6c5fdd3a</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1879, the Archaeological Institute of America (AIA) is the oldest and largest archaeological organization in North America. Today, the AIA has over 200,000 members and 110 local societies in the United States, Canada, and abroad.</i><br />Target victim <b>website</b>: <i>archaeological.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>CHASI-A-part-of-Sun-River-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29705</link>
<guid>20a8571b66205bd36a898172ae082c53</guid>
<pubDate>Fri, 13 Feb 2026 21:34:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>CHASI-A-part-of-Sun-River-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b7378470f07b29b671e2f07be4e4a4a5b5f9ecebd5af5f0a473c0ac1ceb33c8</i><br /><br />Threat actor <b>description</b>: <i>An interesting non-profit organization</i><br />Target victim <b>website</b>: <i>chasiny.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heartland-Title-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29704</link>
<guid>c5e04ccb6be7fab8ccb9df005a075cc2</guid>
<pubDate>Fri, 13 Feb 2026 19:10:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Heartland-Title-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2035781520c820b3cba4a3dd4a2113e497e323104b45e8a3ba89b06332d48df</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.heartlandtitleco.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>UCG-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29703</link>
<guid>1dcad8cc5b82a7ef72f72716b220cf13</guid>
<pubDate>Fri, 13 Feb 2026 19:09:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>UCG-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e8dcf0d3dc9c4c2785661ba43e0fa9a821b63c21ca5cf36ff51f152b626d700</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ucgassociates.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>HMA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29701</link>
<guid>49de010bfd34f149fc319dd839707a36</guid>
<pubDate>Fri, 13 Feb 2026 19:08:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>HMA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>85d9aa7b505b4e2c4decf9648e85aeac5fe273f18572a107cc587ec78d2fdd9e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hmapr.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lusamerica-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29700</link>
<guid>04907a4c18ddcbc3155a2e65598a5c7b</guid>
<pubDate>Fri, 13 Feb 2026 19:07:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Lusamerica-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c9dcc50c65c8c3ba740027918a2ab004fea992e59bee008f1581b766f517176</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.lusamerica.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carrera-Casting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29693</link>
<guid>d7facbd2b01e0596ed7115dbdc49df43</guid>
<pubDate>Fri, 13 Feb 2026 17:38:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Carrera-Casting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a299a6d2c1b296a89ba91f1460ea2bae15c7dd0ae66cb14e714fa272233b324</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Michael-L-Larson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29695</link>
<guid>766c626b2cb1532f235d3bd44279f2f9</guid>
<pubDate>Fri, 13 Feb 2026 17:38:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Michael-L-Larson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6dd10603c91d03d518875886f8aaa3956bad4d2e66b54bc1c3bdcf775ffcb7f</i><br /><br />Threat actor <b>description</b>: <i>Michael Larson & Co., P.C. (MLL Co) specializes in providing tax and client advisory services to businesses operating globally, nationally, and within the greater Portland area. We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), employees and customers information (passports, medical information, driver's license ) A bit of personal files and customers data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-New-Castle</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29691</link>
<guid>97fad65319f26ae8c99e0a47a7ca7d57</guid>
<pubDate>Fri, 13 Feb 2026 16:17:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>City-of-New-Castle</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d7946c6c7788a6a146c93e2aa973bad2bac0c0d4e0783d096265eebf9265ee2</i><br /><br />Threat actor <b>description</b>: <i>newcastlecity.delaware.gov zoominfo.com/c/city-of-new-castle/1205094711 The City of New Castle offers a vibrant, historic community situated along the Delaware River, known for its colonial charm and outdoor recreational spaces. It caters to residents, visitors, and businesses with services such as expedited permitting and reliable utilities. The city promotes a variety of recreational activities, including parks, trails, and community events. With a rich history and preservation efforts</i><br />Target victim <b>website</b>: <i>newcastlecity.delaware.gov</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smart-Glass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29689</link>
<guid>3a7666b08689f8259f0f1671eaac81cd</guid>
<pubDate>Fri, 13 Feb 2026 16:15:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Smart-Glass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5feaa309a20d176d2b329a7d154b7edb8abb8d6b96d901929614a6c42b2d6cc4</i><br /><br />Threat actor <b>description</b>: <i>smartglassco.com zoominfo.com/c/smart-glass/348631137 Smart Glass specializes in innovative glass processing technology and operates a state-of-the-art factory located in El Fayoum, Egypt. Their facility spans 40,000 square meters and is equipped with the latest advanced equipment from leading manufacturers. The company is dedicated to revolutionizing glass processing with their cutting-edge solutions. Smart Glass aims to serve clients in various industries seeking high-quality glass products</i><br />Target victim <b>website</b>: <i>smartglassco.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Marena-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29688</link>
<guid>967d1576e70c8f8649702b974e035744</guid>
<pubDate>Fri, 13 Feb 2026 15:37:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>The-Marena-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97abc40b8c7507c74f448e2e3050ad2f624fa05b2e5651e0a0d7763c72708ecd</i><br /><br />Threat actor <b>description</b>: <i>Contains a set of SQL databases

For the past 30 years, Marena has been dedicated to advancing the effective use of medical-grade compression through research, innovation, design, and manufacturing of garments for long-term wellness benefits. Our mission is to help patients around the world heal in comfort, recover with confidence, and live better.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elite-Screens-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29687</link>
<guid>79538b5ba48344b080bb6dc46622657f</guid>
<pubDate>Fri, 13 Feb 2026 12:26:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Elite-Screens-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc8771df6abb27740501d333f0689036f6dc343af3c9f4e22cc21e862123e8c2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2004, Elite Screens Inc. is a US-based projection screen manufacturing company with its world headquarters in California and satellite offices in Australia, China, France, Germany, India, Latvia, Mexico, Japan, and Taiwan. Elite is a certified professional manufacturer of projection screens that specializes in producing retail, commercial and custom integrator sales channels. Elite Screens products are available through authorized distributors, re sellers, retailers and system integrator worldwide.</i><br />Target victim <b>website</b>: <i>elitescreens.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Empire-Express</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29683</link>
<guid>ca1e7c16062816dd5c888af7ea5afa0b</guid>
<pubDate>Fri, 13 Feb 2026 01:38:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Empire-Express</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df29424e475c27eea1a902fe4dc1a00d527745b88de1c2929e2a1f63d9607726</i><br /><br />Threat actor <b>description</b>: <i>Empire Express, Inc. provides trucking transportation services. The company offers transports clothing and apparel, air cargo, home and office products, packagi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yelete-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29680</link>
<guid>0caa694ffbe5d4bc7a4f359989388fdb</guid>
<pubDate>Thu, 12 Feb 2026 22:38:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Yelete-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>712fd76a37b3e56ac07ccc2727338d4a5a7fc4de886f0c20521cbcc2f112bc5d</i><br /><br />Threat actor <b>description</b>: <i>Yelete Group, Inc. specializes in wholesale activewear, apparel, and lingerie, offering a wide range of products including leggings, tights, and various clothin...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Halcyon-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29681</link>
<guid>3eec1ed838fd558428398779631b66a5</guid>
<pubDate>Thu, 12 Feb 2026 21:30:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Halcyon-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0faf2c6f864ae09b4758e0e60587549aa2584bfd740dd50125f6d719fa0360a5</i><br /><br />Threat actor <b>description</b>: <i>Halcyon is the industrys first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware. Halcyon is built by offensive security experts to stop attackers.</i><br />Target victim <b>website</b>: <i>www.halcyontechnologies.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pathway-Reads-and-Data-Analysis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29676</link>
<guid>dba595edc1e3c2214ed62c128944c932</guid>
<pubDate>Thu, 12 Feb 2026 18:19:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pathway-Reads-and-Data-Analysis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>50e96578881feb47519c6d57ab543dc84f0e0f7675e688aba250c40a589d7a9b</i><br /><br />Threat actor <b>description</b>: <i>Pathway Reads and Data Analysis is a company that operates in the
Energy, Utilities & Waste industry. The company is headquartered
in Raymore, Missouri.

We are going to upload company data soon. You will find financial
data (audit, payment details,financial reports), employees and c
ustomers information (emails, phones) NDAs and other documents wi
th personal information. 
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stanley-Autenrieth-Auction-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29672</link>
<guid>5fde161290a4ebf1163b976f2fa03cdd</guid>
<pubDate>Thu, 12 Feb 2026 16:38:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Stanley-Autenrieth-Auction-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41ca0d0c96015a5cbdaf322398745c9ae383383a97896ff3852676fad5db57f3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phoenix-Art-Museum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29673</link>
<guid>0c945a8e12dd7ff713c275c1ad6de9e1</guid>
<pubDate>Thu, 12 Feb 2026 15:08:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Phoenix-Art-Museum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba5954a0dfd9726b28d5fb35a59303b93bae5fe5a013cfc0d98d3db78cf32832</i><br /><br />Threat actor <b>description</b>: <i>Phoenix Art Museum Phoenix Art Museum is an art museum that showcases art from around the U.S. in Phoenix, Arizona.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Campbell-Rappold--Yurasits</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29668</link>
<guid>4db3b4270aca22aa23c78c4acf712915</guid>
<pubDate>Thu, 12 Feb 2026 09:38:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Campbell-Rappold--Yurasits</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>feddd56a6e6bd805a93d55b7a3d30ed5c83c06280233e02a13401342ba80bd00</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sakata-Seed-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29670</link>
<guid>c5f03386978cf62ddb7f2f46e9bd5790</guid>
<pubDate>Thu, 12 Feb 2026 09:38:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sakata-Seed-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96fe0cc79ba2db596ce7d44d5bde21ccfbc68f6b008f12d061bff761c6284cba</i><br /><br />Threat actor <b>description</b>: <i>Home Improvement & Hardware Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Segue-Manufacturing-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29665</link>
<guid>e54eb3dcfb82757f17eafe999d14f97f</guid>
<pubDate>Thu, 12 Feb 2026 07:41:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Segue-Manufacturing-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e474402b7b0abc6279a54e26a0fde2ad02b69f120fbf6e31f917cd9c50097b15</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.segue-mfg.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>auxhomeservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29663</link>
<guid>f06d9b059d9be032816e17a6d8a3d430</guid>
<pubDate>Thu, 12 Feb 2026 05:39:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>auxhomeservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e060be89329f507e2beb100d2b021ae99049c6a0625299c6a26eaea09bce26c1</i><br /><br />Threat actor <b>description</b>: <i>Aux Home Services is a trusted provider of plumbing, electrical, heating, and air conditioning services in Birmingham, Alabama, along with Jefferson and Shelby counties. They pride themselves on delivering prompt and reliable service, available 24/7, with skilled technicians who respect and clean up after their work. The company emphasizes upfront pricing and quality craftsmanship, ensuring customer satisfaction. Their diverse range of services includes AC and heating installations, plumbing repairs, and electrical systems management. Employees: 50 Revenue: $6.9 Million Industry: Construction Management  Phone Number: (205) 979-0946</i><br />Target victim <b>website</b>: <i>auxhomeservices.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>atchadwick.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29662</link>
<guid>4394baa58b824ad2b3f83ba695cecd6a</guid>
<pubDate>Thu, 12 Feb 2026 05:38:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>atchadwick.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>805dec827771b7bbc095f25aa9fe8c555d4898ad778283f4a77f6ef97ef85e4c</i><br /><br />Threat actor <b>description</b>: <i>A.T. Chadwick is a mechanical contracting firm that offers services in plumbing, heating, air-conditioning, refrigeration, process piping, and field management. The company was founded in 1966 and is headquartered in Bensalem, Pennsylvania. Employees: 500 Revenue: $159.1 Million Industry: Construction Management Phone Number: (215) 245-5800</i><br />Target victim <b>website</b>: <i>atchadwick.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlantic-Refinishing--Restoration</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29653</link>
<guid>c7567e4dd48114e82ef45702ccbc06c5</guid>
<pubDate>Wed, 11 Feb 2026 22:41:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Atlantic-Refinishing--Restoration</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f8b2f6987239d8aa443d2377dd785dac0594aa51984f9da62769118df17fcc4</i><br /><br />Threat actor <b>description</b>: <i>The data leaked from the company's servers includes all project work(Exp. PENTAGON), employee information,  confidential company agreements and etc. In particul...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Office-of-COX--SANCHEZ</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29660</link>
<guid>3fcee1ea342699e1bf18973b242f9b65</guid>
<pubDate>Wed, 11 Feb 2026 21:57:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Law-Office-of-COX--SANCHEZ</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32b7319b87f61ccae73e9676aece5b524ae348160dc3b23f8cdf7f79ae3fd6c5</i><br /><br />Threat actor <b>description</b>: <i>The Law Firm of Cox & Sanchez has been committed to serving the residents of the State of Florida with clear, concise, and actionable answers to their legal issue for nearing 40 years. We are budget-conscious, and results driven and treat each client with dignity and respect. We know that listening and understanding your exact and distinct legal problems will lead to most efficient solutions.</i><br />Target victim <b>website</b>: <i>www.coxsanchez.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Andringa-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29659</link>
<guid>4a204e824b80ebb74ac7895ab81fcabf</guid>
<pubDate>Wed, 11 Feb 2026 21:56:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Andringa-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebfbf79db7fc09d6750250d7df2d2fa06c10d374cdb9792ffb7331a2f0e79f1c</i><br /><br />Threat actor <b>description</b>: <i>Bob Andringa has been involved in commercial and real estate litigation for the past twenty years. Bob is experienced in the foreclosure and partition areas of law for both Plaintiffs and Defendants. In addition, his office is knowledgeable and proficient in litigating contractual and landlord/tenant disputes</i><br />Target victim <b>website</b>: <i>www.andringalaw.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clark-Foam-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29654</link>
<guid>282b71a86a960e117b12b24d88aff20e</guid>
<pubDate>Wed, 11 Feb 2026 21:15:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Clark-Foam-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de5e28fac934dafa4e0d4ef3635783d870bbe2dfd21af6b3a5f95d2ac4c172c8</i><br /><br />Threat actor <b>description</b>: <i>clarkfoam.net zoominfo.com/c/clark-foam-products-corp/25809475 Clark Foam Products is a specialized foam fabricator with over five decades of experience serving various industries, including aerospace, automotive, medical, and packaging. They offer a diverse range of high-quality foam products such as crosslink foam, polyurethane foam, and filter foam, along with custom fabrication and design services tailored to meet specific client needs. The company is recognized for its innovative cutting</i><br />Target victim <b>website</b>: <i>clarkfoam.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.hfplanners.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29652</link>
<guid>a9e1944b39bf72d5222e1e9585e6c08a</guid>
<pubDate>Wed, 11 Feb 2026 20:36:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.hfplanners.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22728f3448a94d90610e681f322566142fc5132e4f11e570029c337c4f26b805</i><br /><br />Threat actor <b>description</b>: <i>full data corp</i><br />Target victim <b>website</b>: <i>www.hfplanners.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>R.J.-Zavoral--Sons-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29651</link>
<guid>6daab15a4f57549b7f236d7f0cfca3c8</guid>
<pubDate>Wed, 11 Feb 2026 20:34:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>R.J.-Zavoral--Sons-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0733dd959faf30c054c09366385da65de1413cd009657529e48f5dbb82d92e1d</i><br /><br />Threat actor <b>description</b>: <i>Established in 1951, R.J. Zavoral and Sons, Inc. is a leading earth moving and construction services contractor based in East Grand Forks, MN, specializing in asphalt paving, road and rail construction, site work, and underground utilities. The company serves clients across the Red River Valley, including municipalities, private businesses, and industries, providing solutions for flood mitigation and environmental site management. With a commitment to quality and family values, R.J. Zavoral and Sons employs innovative technologies to ensure efficient project execution and customer satisfaction. Their extensive experience in construction has allowed them to build strong relationships with various clients, further solidifying their reputation in the industry</i><br />Target victim <b>website</b>: <i>www.rjzavoral.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Altak</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29650</link>
<guid>fc363ff03fd6ee72e038e54e555c6153</guid>
<pubDate>Wed, 11 Feb 2026 19:40:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Altak</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5237793437b91ffbc1b2009f14509e7cdb5d8d0924f6b7b5b6658efb41b8bb2c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.altakinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Catalanatto--Barnes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29649</link>
<guid>150c1a63c456776f622da0602c807f2a</guid>
<pubDate>Wed, 11 Feb 2026 19:39:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Catalanatto--Barnes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d22a00bd94c0cdb28d46cccfd171867c93609974c90480e29a31acd81a57064e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bscatcpa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>On-Point-Defense-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29644</link>
<guid>49f1166a6220873fb19f1905f439850c</guid>
<pubDate>Wed, 11 Feb 2026 18:29:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>On-Point-Defense-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9cd303bdea9398a17f025c405e9177ac2cdd4844881f7fbee4ed239d145295a1</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>COIT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29645</link>
<guid>7bff87c59e3fbc5e1ded2fe3ce1d9865</guid>
<pubDate>Wed, 11 Feb 2026 18:29:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>COIT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0169f0e2638ad871b68b48f1a610c135d87678919417a12cf617b0abf56a283d</i><br /><br />Threat actor <b>description</b>: <i>COIT is a full-service specialty Cleaning & Restoration company that can handle all maintenance cleaning needs and unforeseen mishaps requiring professional remediation. We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports), personal files and customers data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northbridge</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29647</link>
<guid>f9c1a456675346ff7d0f2b8b1e7b1899</guid>
<pubDate>Wed, 11 Feb 2026 18:11:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Northbridge</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e61edc3c5bf5f648465f51d2eceeed8897ebdd13fce7114f6844839f1b9f67d7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.northbridgecre.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tsunami-Tsolutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29646</link>
<guid>356cdab4ed0406224c0880771445819a</guid>
<pubDate>Wed, 11 Feb 2026 17:34:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Tsunami-Tsolutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8191abf5bf043876287bd9f3d5190b72b28d66f66fe2cf6efd1e3c9387235a4</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Tsunami Tsolutions is a tech company offering IT services and software solutions to key domains, mainly aviation and manufacturing. Their offerings include data procurement and analysis, MRO, supply chain management, and reliability prediction software. It undertakes and manages its customers' technological tasks, aiding them in strategizing and enhancing their business performance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aviam-Corporate-Housing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29643</link>
<guid>d8e0a5cf600594ec60296c205af805e7</guid>
<pubDate>Wed, 11 Feb 2026 16:06:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Aviam-Corporate-Housing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84b3932cc5be4b8013107684c3c02b58f5d08d7f0391cbe6f27f68efdd4d2741</i><br /><br />Threat actor <b>description</b>: <i>Aviam is the nation's premier corporate housing provider, offering furnished, fully equipped accommodations with maid service, 24/7 emergency support, and customizable packages for executives, teams, or interns — more comfort and savings than hotels.</i><br />Target victim <b>website</b>: <i>www.aviam.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Topkin--Partlow</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29642</link>
<guid>d286a917bfa85c1f2c139e704417d295</guid>
<pubDate>Wed, 11 Feb 2026 15:41:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Topkin--Partlow</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0054c7ff1ce6d17c52cd56e97943645ddfd530f7a100995be7678f948c2c30ff</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tower-Insurance-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29641</link>
<guid>e07c2c81c883f095372f10815aaa25ba</guid>
<pubDate>Wed, 11 Feb 2026 14:43:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tower-Insurance-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4108206446ac305bcc37e45129aac222010bf7325ee881038d09201811db5897</i><br /><br />Threat actor <b>description</b>: <i>Insurance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Andringa-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29631</link>
<guid>4e18967c55baab1033250c9f8b0016b1</guid>
<pubDate>Wed, 11 Feb 2026 08:41:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Andringa-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19199a89ae80851f53e34997b2b59bd29cbb995c20e18a0a2eac2169f4a48b7b</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cox--Sanchez</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29632</link>
<guid>e5fea2100557ed4a239fa49305613d6b</guid>
<pubDate>Wed, 11 Feb 2026 08:41:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cox--Sanchez</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>407ab4a3ddbd07b69b1b1c7c50e76dada2119e0db77c86b3c22662c4bec7a192</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>falconmgt.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29639</link>
<guid>3e59bff2aa24cd053805ecbe01cbdf7d</guid>
<pubDate>Wed, 11 Feb 2026 08:29:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>reynolds</b> claims attack for <b>falconmgt.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afa4f87797f6280445952029c054343ad86cb8d669232df0413f67b420b694d0</i><br /><br />Threat actor <b>description</b>: <i>Falcon Management Corp. was founded in 1991. The company's line of business includes providing financial planning and investment advisory services.</i><br />Target victim <b>website</b>: <i>falconmgt.com</i>]]></description>
<category>reynolds</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hood-River-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29638</link>
<guid>758dd0edb588eb2606f15ffb43391bf1</guid>
<pubDate>Wed, 11 Feb 2026 08:22:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>Hood-River-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9acf97eaa82c61eef1c5da9aa8919a9cf4e5bec93baf55faadd917ccf03b9ab0</i><br /><br />Threat actor <b>description</b>: <i>A dental clinic offering its clients a wide range of services.</i><br />Target victim <b>website</b>: <i>www.hoodriverdentist.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>WVPCA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29637</link>
<guid>656a03108e4217b836ccd9f58fa18900</guid>
<pubDate>Wed, 11 Feb 2026 08:21:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>WVPCA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f64826a260e3d2a277245172cbc29fb0d9aff0e17bed894deac41e9ff0e70076</i><br /><br />Threat actor <b>description</b>: <i>An organization that supports and develops a network of community health centers throughout West Virginia.</i><br />Target victim <b>website</b>: <i>www.wvpca.org</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>SPEC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29636</link>
<guid>8d6a9e37e8c314a0b3fc23a54e5ec105</guid>
<pubDate>Wed, 11 Feb 2026 08:21:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>SPEC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97883e77a9854949ac833cc48cf47d1befcdd83b354af293de1dabe9490108fe</i><br /><br />Threat actor <b>description</b>: <i>A company operating in the field of radiography.</i><br />Target victim <b>website</b>: <i>spec150.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>FUSION-HILL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29635</link>
<guid>0919fe8239ba5be746ae7a1d44f50a7f</guid>
<pubDate>Wed, 11 Feb 2026 08:20:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>bravox</b> claims attack for <b>FUSION-HILL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65bad56e85a39054485da58c7bc510ff1d6a96af79cef2ead7cdb04296324394</i><br /><br />Threat actor <b>description</b>: <i>A company operating in the broad field of marketing and advertising.</i><br />Target victim <b>website</b>: <i>www.fusionhill.com</i>]]></description>
<category>bravox</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lindenhurst-Fire-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29625</link>
<guid>b03d078b859d32d6b12b3e491acaf978</guid>
<pubDate>Wed, 11 Feb 2026 06:41:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lindenhurst-Fire-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e4f6f8e2f08700947db4e3b5e9edb625a5fd8a6f1509fca5c05b4c74113012d</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mississippi-Market</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29626</link>
<guid>9572d7558e2231f00f8c9a0005101b01</guid>
<pubDate>Wed, 11 Feb 2026 06:41:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mississippi-Market</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dea24c2fa198ef90659dd30f8e3ce30890fd4dd9fe99fff73789219c8fe8bb4c</i><br /><br />Threat actor <b>description</b>: <i>Consumer Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>BCS-ProSoft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29623</link>
<guid>c40d81efdade5f24d4d1181392064079</guid>
<pubDate>Wed, 11 Feb 2026 00:26:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>BCS-ProSoft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9988ed8f5bc0d3be320cc4141e6fb9058e870650d2a9a577aeff7cc1562809c</i><br /><br />Threat actor <b>description</b>: <i>BCS ProSoft is a technology consulting firm that specializes in business management software, particularly offering solutions from Sage, Deltek, and ARM. They provide ERP consulting services, project management, implementation, and support tailored to a range of industries including manufacturing, healthcare, and professional services. With a commitment to understanding their clients' unique needs, they aim to enhance operational efficiency and ensure smooth technology transitions. A notable provider with over 1,500 clients, BCS ProSoft's services are designed to mitigate risks and enhance the value of technology investments</i><br />Target victim <b>website</b>: <i>www.bcsprosoft.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>FISHWINDOWCLEANING.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29605</link>
<guid>b18f646fb284fc597d309242de321023</guid>
<pubDate>Tue, 10 Feb 2026 21:12:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FISHWINDOWCLEANING.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04deb516187d09a16afc30ba17126146433c2399be89b08f2d31e1041444a89d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SOLUTIONSINSAFETY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29606</link>
<guid>bda9f65e28426fc1f93c4f5f223cd1bc</guid>
<pubDate>Tue, 10 Feb 2026 21:12:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SOLUTIONSINSAFETY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87d3ba26c1d6f1dc4b0f391497d3fe29f1bca415e213ef81e03efab28a3a5db5</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BOYDEN.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29607</link>
<guid>56915424977fb94b0ec40a3f31af89ed</guid>
<pubDate>Tue, 10 Feb 2026 21:12:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BOYDEN.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d997d7ee55a596507165859df9ac22d04ad21192103edec384687698b6c683b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SPOHNASSOCIATES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29609</link>
<guid>8ef3abcafea125f2518236e28761c9da</guid>
<pubDate>Tue, 10 Feb 2026 21:12:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SPOHNASSOCIATES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e835e4d46476ee176c653f557bc74a6abecfb4ba9727a30fd4ba6deed0573f2</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GARNERGROUP.NET</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29610</link>
<guid>1a0b9d091283b31708a6e8dec004bd6e</guid>
<pubDate>Tue, 10 Feb 2026 21:12:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GARNERGROUP.NET</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcc2f3211376b084b72231424595b302342583774c2af477f18153c294a9dc69</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>THEPERPETUAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29611</link>
<guid>ab6ef074b86ed41809fa9ad6f22bf862</guid>
<pubDate>Tue, 10 Feb 2026 21:12:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>THEPERPETUAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c348e52935d4c34c7c3721cc97e75506a7e95d57842c88849219e99b6a8f0894</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HYDEPARKUMC.ORG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29613</link>
<guid>e4af65db2a5a17afca8bf5cc475fed0b</guid>
<pubDate>Tue, 10 Feb 2026 21:12:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HYDEPARKUMC.ORG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5e3009ad38a498e03a8ba264166caa6af4626c9d4543ed63c14789b9a3ac186</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GIACARE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29614</link>
<guid>845ae5f86e478f372a410a0fc2db1d82</guid>
<pubDate>Tue, 10 Feb 2026 21:12:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GIACARE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5fc12f75f1b7e866b891d9f2af2cad60dbd59294cac0a28d7127652aaa71feaa</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GIASPACE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29615</link>
<guid>1700002d4c70cbf14d54658d280cb88e</guid>
<pubDate>Tue, 10 Feb 2026 21:12:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GIASPACE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60a44fb663072ecbb5b47a3be23af1273ceb46d00591ce0ee8405cbba245e44f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ONESUPPORT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29616</link>
<guid>75d52237743d661f8f60a988e9ba5989</guid>
<pubDate>Tue, 10 Feb 2026 21:12:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ONESUPPORT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fed785ef1f2b125b789d3c6e608f4affd0cc21a6cc6184cf84f45c87cea2565</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HUDSONSUSTAINABLE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29617</link>
<guid>d454766e392ac21320cccd0b55ecba00</guid>
<pubDate>Tue, 10 Feb 2026 21:12:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HUDSONSUSTAINABLE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7484491829c125ce73910a61462b7df86bbdba1f74136dfb43729cd362dfe43</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GOKALLIT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29618</link>
<guid>8357ebc8e1db498622c8933ea5319243</guid>
<pubDate>Tue, 10 Feb 2026 21:12:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GOKALLIT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c35a5470f5e7a170a8dcbb6ae4d76dff9dfa7ef8db3745ce2f9e1a9f2b03b0bb</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>CHEHARDY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29619</link>
<guid>65f0989f1bb0020cedc498afe707a197</guid>
<pubDate>Tue, 10 Feb 2026 21:12:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CHEHARDY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8079d1484856c557db2faef001338828a414ee6164f310277b54728ff50bd81</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>RBDCONSTRUCTION.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29620</link>
<guid>54e634f071ec5bc3571636aa671d7ca2</guid>
<pubDate>Tue, 10 Feb 2026 21:12:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>RBDCONSTRUCTION.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a812b28c22364aa0108f48f2d8bf5f481b18e9ea5eedfa37fcd367bec8d8a56</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BROADREACHRETAIL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29621</link>
<guid>e0413443ad67ce88208e6159c63b742f</guid>
<pubDate>Tue, 10 Feb 2026 21:12:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BROADREACHRETAIL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47aba7cf52e8c59bf513be1445af1066cbeda0a8bd8a36a8a17b21bf9216578c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Venesco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29601</link>
<guid>493c4b304be1e32548b7ad5d5c22ef6b</guid>
<pubDate>Tue, 10 Feb 2026 19:03:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Venesco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f741dc8b0045d0f0623b364495c14458db1439db16ddeb77b560daeac2d25fe4</i><br /><br />Threat actor <b>description</b>: <i>Venesco specializes in providing premium administrative, healthcare, and professional services primarily for military and civilian clients. Their offerings include management consulting, logistics support, psychological services, and comprehensive training programs tailored to meet the unique needs of various agencies. With a strong focus on delivering quality and innovative solutions, Venesco supports a range of programs including research and development as well as health service initiatives. The company is dedicated to equipping clients with essential knowledge and skills to address critical challenges and achieve mission success.</i><br />Target victim <b>website</b>: <i>www.venesco.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Snyder-Diamonds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29600</link>
<guid>b09d978ea462060c446ed6833f58735c</guid>
<pubDate>Tue, 10 Feb 2026 19:02:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Snyder-Diamonds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd197a34b10b45b11b610bcc19e03f2129a2bfac92e3786a57a47bad04167b46</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1949 with locations in Santa Monica, Pasadena and North Hollywood, Snyder Diamond is a progressive, design-forward kitchen and bath showroom steeped in tradition. Our knowledge, service and selection sets us high above the competition. Snyder Diamond is an authorized dealer of such brands as Hansgrohe, Sub Zero Wolf, Miele, Rohl, Fantini, Dornbracht, Kalamazoo Outdoor Gourmet, Victoria + Albert, TopBrewer, Viking and more.</i><br />Target victim <b>website</b>: <i>www.snyderdiamonds.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Halcyontek</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29599</link>
<guid>8d4af5c8b9b40206046d4f2c889eceed</guid>
<pubDate>Tue, 10 Feb 2026 19:02:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Halcyontek</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0763619427e60c953af978aea7a476f63911dd0e9d82b5822406c8c7e89cc3a3</i><br /><br />Threat actor <b>description</b>: <i>Halcyon is the industrys first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware. Halcyon is built by offensive security experts to stop attackers.</i><br />Target victim <b>website</b>: <i>www.halcyontek.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Milwaukee-Forge</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29598</link>
<guid>e92ae67e4af9da61bbb3690018fa4f1e</guid>
<pubDate>Tue, 10 Feb 2026 18:57:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Milwaukee-Forge</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e75b18733bf8ac0ac37691c0b91b68ac70077522d26f1a6e29144b21d9b6f73</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.milwaukeeforge.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beasley--Gilkison</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29594</link>
<guid>772c1c73d4ffe88046a3cdb8772e53eb</guid>
<pubDate>Tue, 10 Feb 2026 16:44:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Beasley--Gilkison</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a435824a0e9dbc6d1506cdd1ae598668935432af8c5a3a11587aa55686bd3f40</i><br /><br />Threat actor <b>description</b>: <i>Beasley & Gilkison LLP has provided expert legal services to indi
viduals, businesses, and institutions in East Central Indiana sin
ce the 1890s. With over 120 years of experience, the firm is know
n for its high standards and commitment to the community. 

We are ready to upload more than 32GB data. There are lots of ess
ential corporate documents such as: financial data (audit, paymen
t details, invoices), detailed employees and customers informatio
n (driver's license , medical information, emails, phones) confid
ential information, NDAs and other documents with detailed person
al information.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PrintForm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29585</link>
<guid>8cc8cb74f22a588e728b78d11696d2fb</guid>
<pubDate>Tue, 10 Feb 2026 16:00:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>PrintForm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69557105733a33a691764fc20f0117e46e6ca4f3d63e53c952fab6234d0bcb58</i><br /><br />Threat actor <b>description</b>: <i>Our mission is to make it easy for customers to buy custom-designed parts that meet their needs. PrintForm specializes in build-to-order custom-manufactured plastic and metal parts for various markets, including medical, aerospace & defense, automotive, appliances, energy, oil & gas, and consumer products. From a single prototype up to thousands of production parts, virtually any company designing new or improved products with plastic or metal components will benefit from the on-demand solutions PrintForm provides. As a single source for multiple manufacturing processes, PrintForm provides an expert-level service in transitioning customers through the design to manufacturing cycle.  Services include advanced 3D Printing/additive manufacturing processes and more traditional methods like Silicone molding, CNC Machining, Sheet metal, and Injection Molding.- Drawings- Working Projects- Confidential Client Documents https://printform.com/</i><br />Target victim <b>website</b>: <i>printform.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grandview-Family-Medicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29576</link>
<guid>43e8ab73ce9890e4e041d2db5fd36999</guid>
<pubDate>Tue, 10 Feb 2026 14:24:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Grandview-Family-Medicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>856eb2ce0367d9aa6aad74c108f2b5c43f8e6e1f805dd5e36ebcb3e059e11357</i><br /><br />Threat actor <b>description</b>: <i>Grandview Family Medicine is a healthcare provider offering a range of services including family medicine, obstetrics, women's health, men's health, and pediatrics. They operate clinics in Provo and Cedar Hills and provide both in-person and telehealth appointments for their patients. The clinic emphasizes comprehensive care, addressing chronic disease management, mental health, urgent visits, and minor procedures. Their intended clients include families and individuals seeking quality healthcare across various age groups. 
The company headquarters is located in 1900 North State Street Provo, Utah 84604 United States.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMITHIPSERVICES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29577</link>
<guid>6027b8cfb50835b0349ee47aaac993d5</guid>
<pubDate>Tue, 10 Feb 2026 14:23:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SMITHIPSERVICES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e22cb56f4c275c4e70c06b7c1554e88b808c6934513138a2c6d61bc8501328b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>PROACTIVEMEDICAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29578</link>
<guid>cf4352a7d775ba25bc66ac22006a13cb</guid>
<pubDate>Tue, 10 Feb 2026 14:23:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>PROACTIVEMEDICAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4894fca8b22d396016f66b97c888dc8ab9cb6fc536601e616bdb1452d761550c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ITARCHITECHS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29579</link>
<guid>37c77fc83549b5204e788fb979887c92</guid>
<pubDate>Tue, 10 Feb 2026 14:22:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ITARCHITECHS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3726da5851c37b1aebafd19a1e75df67118722b4d0f8abfd8d08f5179e714591</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HUDSONEXECUTIVE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29580</link>
<guid>060381704cad174497ca51d13c40b98a</guid>
<pubDate>Tue, 10 Feb 2026 14:22:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HUDSONEXECUTIVE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96afc9a7546f9bcb7dbfbe3756dba6b59a653db859151f5e1526a9dd8bfebb57</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ANSTECHINC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29581</link>
<guid>109e3ceb0fb7112c1e9e4a3b45e68212</guid>
<pubDate>Tue, 10 Feb 2026 14:22:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ANSTECHINC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1319886913f214e38302e55fcb71eb8edb9df13301fe005c0fca12907e6e8cf6</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>C4-Carroll-County-Cannabis-Co.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29582</link>
<guid>1ad12e2680e7833bf77feaa9bb1f02e6</guid>
<pubDate>Tue, 10 Feb 2026 13:41:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>C4-Carroll-County-Cannabis-Co.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10e8f338e5ed708197983e0dc728c63a0a7bddd4db72f68a5bddbc818d8e9a73</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>moultriesheriff.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29575</link>
<guid>1fae41f41823dafacc197c3f5121128e</guid>
<pubDate>Tue, 10 Feb 2026 12:24:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>moultriesheriff.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f2ef50223c2bb68b3364ee61567b4dcd232f53c35dde881df2e89d3659caf03</i><br /><br />Threat actor <b>description</b>: <i>Sheriff's Office. 187-GB sensitive data </i><br />Target victim <b>website</b>: <i>moultriesheriff.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pavlus-Travel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29571</link>
<guid>de8a3ed278e460fbf67355f99a6a865f</guid>
<pubDate>Tue, 10 Feb 2026 06:02:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Pavlus-Travel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df1f24fbedb9ce894ef35ad27cd436ffcf8c1b84603b87181d042b858c3558a9</i><br /><br />Threat actor <b>description</b>: <i>Specializes in luxury sea cruises, river cruises, and guided tours</i><br />Target victim <b>website</b>: <i>pavlus.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Core-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29570</link>
<guid>e0cba95d2999ca566c986fb793e7ecc7</guid>
<pubDate>Tue, 10 Feb 2026 00:48:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Core-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ced466824c16fa02c477435ad2850ea9df15d1ca911d2845254ad2df6d4d7bde</i><br /><br />Threat actor <b>description</b>: <i>Core Supply has been taking business from the competition since 2010. We believe in our aggressive approach and our active partnerships with our customers and suppliers. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>tuftco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29568</link>
<guid>bdbb7b82339a6700741e6dd665b8a993</guid>
<pubDate>Mon, 09 Feb 2026 20:28:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>tuftco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>033a599cc85c29b40ffbdd0b21f49ff2af55728432db4076dee7ec7a920e818b</i><br /><br />Threat actor <b>description</b>: <i>Tuftco is a world-leading manufacturer of tufting machines and equipment, providing comprehensive solutions for carpet mills from tufting to finished carpet Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barrett-Financial-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29567</link>
<guid>cb25605bb7380864f4af64b7d4b493f0</guid>
<pubDate>Mon, 09 Feb 2026 20:18:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Barrett-Financial-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e047d35b76dbd76ee117b154ce9843b1880e848c02d9ad88d4efa3466c33c6b</i><br /><br />Threat actor <b>description</b>: <i>Barrett Financial Group, LLC offers top Local Mortgage Services for Conventional, FHA, VA, Jumbo, and …</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tech-Environmental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29565</link>
<guid>391c5f953a77f6ddf639b5e62bb75c3e</guid>
<pubDate>Mon, 09 Feb 2026 19:40:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tech-Environmental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7741be5462aa76c40d9a30a7930c0e1ba1f4b43a08096f2f008f7eeb76d6d554</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>iQ-NetSolutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29563</link>
<guid>b13c4b2504158972122bb5cbeda135b2</guid>
<pubDate>Mon, 09 Feb 2026 17:39:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>iQ-NetSolutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eea1f6b989d64386d8978332f23c97e0a94d1cccfaf741a91b97e28fe8cc9c79</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>horizonmedia.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29564</link>
<guid>23a741fa2f45791cd3462521042150b2</guid>
<pubDate>Mon, 09 Feb 2026 17:21:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>horizonmedia.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9387608e5ba4e4258f47b6d8360bcfa0faa3d602a6e069692007453c5ae0fb2</i><br /><br />Threat actor <b>description</b>: <i>Official Announcement: Horizon Media Data Breach

ULTIMATUM: Horizon Media has 48 hours to reach an agreement. If our terms are not met, a full leak consisting of 3.2 TB of sensitive corporate data will be made public and distributed to global media outlets and regulatory bodies.

The leaked dataset…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/horizon-media-inc/351810076</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Body-By-Fisher</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29558</link>
<guid>08a7a2e472df1185eec3b0c1c0b1ba14</guid>
<pubDate>Mon, 09 Feb 2026 16:41:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Body-By-Fisher</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd9e4501a660e306df530a563c4b53969f01e7ba9753f1daa54d0262247f5f0c</i><br /><br />Threat actor <b>description</b>: <i>Consumer Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Augusta-Housing-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29560</link>
<guid>e4971735e71b7c924d2f5aef6f5a7334</guid>
<pubDate>Mon, 09 Feb 2026 16:40:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Augusta-Housing-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24d2549dea821d92fe674037d250010d51296845f7d05fda8a8e27a7b6c404eb</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Putnam-Precision-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29557</link>
<guid>0b071c1de69040ddc45603a7fbceac82</guid>
<pubDate>Mon, 09 Feb 2026 13:22:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>crypto24</b> claims attack for <b>Putnam-Precision-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23b0b1b3ce692111fe7460d3f291d7cb4fa824bb1331c5ce385514c5e5d80fde</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Putnam Precision, Inc. is a prominent manufacturing firm based in the USA, specializing in high-grade custom, precision components. The company primarily services the medical, semi-conductor and aerospace industries. Putnam uses state-of-the-art technology to ensure accuracy & quality in their products, with services including CNC machining, milling, turning, and assembly operations.</i><br />Target victim <b>website</b>: <i>www.putnamprecision.com</i>]]></description>
<category>crypto24</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rutherford-Investment-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29555</link>
<guid>a9bd54659f4a895624ba4a669a7ca977</guid>
<pubDate>Mon, 09 Feb 2026 01:18:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Rutherford-Investment-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac84855c097b6f0619867b3186f9cde79d29b5cecfef6c5713a951afa0184c49</i><br /><br />Threat actor <b>description</b>: <i>Data breach of real estate investment firm: financial and Personalp identification data exposed.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>KlearNow.AI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29554</link>
<guid>bd3e776678a01701f968d3cd4b787d39</guid>
<pubDate>Sun, 08 Feb 2026 20:05:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>KlearNow.AI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e70b3cc163933540127e1cf34a0ac7c2a67369eba831466888b764eb5ae7ef7c</i><br /><br />Threat actor <b>description</b>: <i>www.klearnow.ai https://www.zoominfo.com/c/klearnowai/566144278 3 TB of data: all correspondence for the last two years, a database dump, all source code. We filed CBP declarations for giants such as BASF, Safran, Sumitomo, etc. KlearNow.AI is on a mission to simplify global trade with AI and ML driven products that make logistics clear, cost-effective, and transparent by transforming B2B supply chains with its smart Logistics as a Service (LaaS) platform. The platform eliminates manual data ent</i><br />Target victim <b>website</b>: <i>www.klearnow.ai</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>San-Diego-Eye-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29553</link>
<guid>38a44c258ac6985bb71726a37252d313</guid>
<pubDate>Sun, 08 Feb 2026 08:36:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>San-Diego-Eye-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>caef40fb411c5c33fb31f74b3d2cfb689956c9bd70620a53eeac1561e927b4bb</i><br /><br />Threat actor <b>description</b>: <i>San Diego Eye Tissue Bank</i><br />Target victim <b>website</b>: <i>sdeb.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abel-Schillinger</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29549</link>
<guid>af20aa8cc361a5498fb417683dfd8488</guid>
<pubDate>Sun, 08 Feb 2026 02:14:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Abel-Schillinger</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac28e72c196d17bb6ce151674c32accedd1619fa5172d40e38415a627f626532</i><br /><br />Threat actor <b>description</b>: <i>Patent lawyers' data breach; Drafts and intellectual property.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>granmanor.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29522</link>
<guid>dd823d6e1e3a88daf0873b36aa204369</guid>
<pubDate>Sat, 07 Feb 2026 22:41:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>granmanor.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78aafd7a34122333fbfdaabe8fa03b3ffd5ee85ffd4051d752a3a42b08354a66</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>zeroenergy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29523</link>
<guid>b3ca9f305782d831cfe65fdf7b980b51</guid>
<pubDate>Sat, 07 Feb 2026 22:41:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>zeroenergy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>daac433816cc969f425fd05239c7424e0434dce7393c546b036a2a137f1926db</i><br /><br />Threat actor <b>description</b>: <i>Architecture, Engineering & Design</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>poweron.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29524</link>
<guid>18dc2aa306574480d292c7b0210f7545</guid>
<pubDate>Sat, 07 Feb 2026 22:41:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>poweron.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5333cd6607911e8c6a3ad9c536b2f2d281ed9623b39510638abc69fc85986397</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>abdata.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29526</link>
<guid>3eb4c11722507eae902e13a8f202e947</guid>
<pubDate>Sat, 07 Feb 2026 22:40:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>abdata.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1a317843e90bde6abcbf45a64c87c29fe659f28ebee2fe36c2af4d57924cf49</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrated-Fresh-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29544</link>
<guid>d44ea21d9f3f0734cb163b5fe8168cac</guid>
<pubDate>Sat, 07 Feb 2026 21:33:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Integrated-Fresh-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>760705db8c1a25a62800b39c952a1eda27847eea2c3736db4f3f5e31eb29ae0f</i><br /><br />Threat actor <b>description</b>: <i>IFS supplies fresh produce, perishable logistics, warehousing, and custom support to foodservice, retail, and wholesale. With subsidiaries Fresh-Link Produce, Kool Logistics, and Synergy Worldwide, IFS streamlines farm-to-table operations.</i><br />Target victim <b>website</b>: <i>www.integratedfresh.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gruel-Mills-Nims-Pylman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29543</link>
<guid>4fa1b2338942dacb0f7c2a1fbfae628a</guid>
<pubDate>Sat, 07 Feb 2026 21:32:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Gruel-Mills-Nims-Pylman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab6800d428bf9a45f271bc22e2208978b22517e1605ba3a10c4653cd76a14e29</i><br /><br />Threat actor <b>description</b>: <i>Gruel Mills Nims Pylman PLLC is a Grand Rapids personal injury firm with national reach. With 35 years experience, they represent victims of vehicle-construction accidents, sexual abuse, and medical malpractice, focusing on trust, access, and full compensation.</i><br />Target victim <b>website</b>: <i>www.gmnp.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carlyle-Senior-Care-of-Florence</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29542</link>
<guid>0496c088275cca21054077df4d52bdcd</guid>
<pubDate>Sat, 07 Feb 2026 21:31:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Carlyle-Senior-Care-of-Florence</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7bb1d104d2443ccd807e8ee9f27d7a1a628bde0cea6dfc6b1e84cdaf5077f69d</i><br /><br />Threat actor <b>description</b>: <i>CSC, a respected private nursing home, delivers high-quality skilled nursing, memory care, rehabilitation, medication management, assistance with ADLs, nutritious meals, social programs, and end-of-life care in a supportive, community-driven environment.</i><br />Target victim <b>website</b>: <i>www.carlyleflorence.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Internal-Medicine-of-Milford</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29541</link>
<guid>dd14fcb4232caeda4d922db41d6174df</guid>
<pubDate>Sat, 07 Feb 2026 21:31:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Internal-Medicine-of-Milford</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11a23fcd98361bb63752fa5e5706929f09d084b8eca31ad7ad6bd9ee3818a0c3</i><br /><br />Threat actor <b>description</b>: <i>Internal Medicine of Milford — a patient-focused practice in Milford, CT offering internal and family medicine: acute care, preventive services, chronic disease management, and in-office testing for individuals and families seeking trusted, high-quality local care.</i><br />Target victim <b>website</b>: <i>www.immct.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rella-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29540</link>
<guid>b851cb30a3604f1a03c679a79b0a443d</guid>
<pubDate>Sat, 07 Feb 2026 21:30:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Rella-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c883ee35fbd5411b22140c87b4d601b7c671b5b62429e841e0f563d8a96faf9</i><br /><br />Threat actor <b>description</b>: <i>Rella Associates, P.C. provides legal help in Workers Compensation, Social Security Disability, and NYCERS for job injuries and illnesses. Led by Gerarda Rella and Michael Catallo, the Sleepy Hollow firm delivers personalized, aggressive representation and timely client communication.</i><br />Target victim <b>website</b>: <i>www.rella-associates.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Flint-Hills-Dialysis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29539</link>
<guid>badc93fe6e7962936c7f7d5ad32f69e4</guid>
<pubDate>Sat, 07 Feb 2026 21:29:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Flint-Hills-Dialysis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a9afa4377c1f0d47d33d0728a6e538daa7f480eb419cf1c0e03252dcb1bb629</i><br /><br />Threat actor <b>description</b>: <i>Flint Hills Dialysis focuses on dialysis and chronic kidney disease management, creating personalized treatment plans to improve patients' lives. With clinics in Manhattan and Marysville, Kansas, their team emphasizes patient education and compassionate care.</i><br />Target victim <b>website</b>: <i>www.fhdks.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Illinois-Dermatology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29538</link>
<guid>8ce629476d3d9bb6519cd146973a27ec</guid>
<pubDate>Sat, 07 Feb 2026 21:28:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Southern-Illinois-Dermatology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1059928fb8b389fd9b40b1b38e4cafc254a2aee619f110a3cd6ea4f50fd589ee</i><br /><br />Threat actor <b>description</b>: <i>Southern Illinois Dermatology, founded in 1996 by Board-Certified Dr. Ted G. Van Acker, has grown from one office to 15 locations. We offer general, surgical, cosmetic dermatology and advanced laser treatments with attentive, professional care.</i><br />Target victim <b>website</b>: <i>www.siderm.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Parts-Life-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29537</link>
<guid>b43a306ca1e27299a57727ff5c0d4998</guid>
<pubDate>Sat, 07 Feb 2026 21:28:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Parts-Life-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a14c3547e29240437169614a98357cda5f1c1a2709300827eb7a1ae784e907ff</i><br /><br />Threat actor <b>description</b>: <i>Parts Life, Inc., is an certified supplier of engineering, manufacturing, and alternate-source DMSMS solutions for military systems. Our reverse engineering and R.O.P.E. services produce source-approved manufacturable data; prototypes tested for form, fit, function.</i><br />Target victim <b>website</b>: <i>www.partslifeinc.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>DeVal-LCS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29536</link>
<guid>246fd89796299b9af42e8093e81cc124</guid>
<pubDate>Sat, 07 Feb 2026 21:27:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>DeVal-LCS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14ec16d33e02e89707b683dc42c4a65a68ff049e51976a555ba666dfd7b0b296</i><br /><br />Threat actor <b>description</b>: <i>DeVal LCS is a U.S. mechanical and electro-mechanical manufacturer specializing in armament and ground‑support equipment for the DoD. An AS9100D-certified business, DeVal provides build-to-print turnkey manufacturing, precision machining, and assembly.</i><br />Target victim <b>website</b>: <i>www.devallcs.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>SchureMed</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29535</link>
<guid>bde1d613c4e7839d1baac6aea8357e7d</guid>
<pubDate>Sat, 07 Feb 2026 21:26:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>SchureMed</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40683cfe646ae0ebbb3d70217136d76d56d5acd2f5d9ec1921f6dabdb4e2fe82</i><br /><br />Threat actor <b>description</b>: <i>SchureMed makes surgical patient-positioning equipment that improves safety, comfort, and outcomes. Their range covers orthopedic, laparoscopic, and custom OR solutions, backed by in-house R&D, manufacturing, competitive pricing, and tailored customer service.</i><br />Target victim <b>website</b>: <i>www.schuremed.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Optimum-Health-Institute</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29534</link>
<guid>41c0fb7d37adb58e9cc4b4a82e8a0f46</guid>
<pubDate>Sat, 07 Feb 2026 21:26:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Optimum-Health-Institute</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c542b928d739d0948700820bcfaa89cf70aff9680f9aeb5fdc2dc935aa63f110</i><br /><br />Threat actor <b>description</b>: <i>Optimum Health Institute (OHI) runs faith-based, holistic 3-week wellness retreats in San Diego and Austin. Combining classes, activities, and nutrient-rich meals, OHI supports body, mind, and spirit for stress reduction, fitness, and spiritual growth.</i><br />Target victim <b>website</b>: <i>www.optimumhealth.org</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anatomic-Clinical-Laboratory-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29533</link>
<guid>8396e81a648b3b78745e1f08579e0bb0</guid>
<pubDate>Sat, 07 Feb 2026 21:25:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Anatomic-Clinical-Laboratory-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81384e6e5587d21618eb9c8b3a8591890d6194f5a55290a0d5dc2821a89d4df0</i><br /><br />Threat actor <b>description</b>: <i>Nashville-based physician-owned pathology group serving Middle Tennessee with high-quality diagnostics care with timely reporting and accessibility for clinicians, subspecialty expertise, timely reports, and community care for uninsured patients</i><br />Target victim <b>website</b>: <i>www.aclapath.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dunn-and-Dunn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29532</link>
<guid>13bfa3b0c77bec4598bc7fe923d12972</guid>
<pubDate>Sat, 07 Feb 2026 21:24:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Dunn-and-Dunn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f5c4ace150fb49f30f190e39ac362b7163b33a8f6e244bff784dd729d6d9c28</i><br /><br />Threat actor <b>description</b>: <i>Dunn and Dunn is a Boston - based law firm established in 1928. They specialize in providing legal counsel and representation to healthcare professionals. Core practice areas include: Medical malpractice defense, Long-term care defense, General liability defense</i><br />Target victim <b>website</b>: <i>www.dunnanddunn.com</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tri-Cities-Gastroenterology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29531</link>
<guid>256c6f5b61473aaaf1fe73f571b4b28b</guid>
<pubDate>Sat, 07 Feb 2026 21:24:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>insomnia</b> claims attack for <b>Tri-Cities-Gastroenterology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fe2ef317a6eeafffec7bc541f78149f63c0de0f4afa946ab87afb0905c843fd</i><br /><br />Threat actor <b>description</b>: <i>Tri-Cities Gastroenterology provides comprehensive digestive care focused on whole-person wellness, using human and technological resources to ensure patient comfort and timely, reliable information and reports for referring physicians.</i><br />Target victim <b>website</b>: <i>www.digestivewellness.net</i>]]></description>
<category>insomnia</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carlton-Scale</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29514</link>
<guid>1e9857752ba7f46d8d36021825e60441</guid>
<pubDate>Sat, 07 Feb 2026 20:04:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Carlton-Scale</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>905089e65b0cea888506b2267ac3c4c3a827af9747576edffb222009dafc7f7e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.carltonscale.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>De-Gruyter-Brill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29513</link>
<guid>53fa2bb31e7b9c5afebcd5bc6212c09d</guid>
<pubDate>Sat, 07 Feb 2026 20:04:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>De-Gruyter-Brill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b9cbab877342b174b0a88ed79b1342aabc6a977c6c8fffc123e3f60ae4bae79</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.degruyterbrill.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>ESS-Metron</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29512</link>
<guid>424ab970cad62b90ca3eee3e832920ba</guid>
<pubDate>Sat, 07 Feb 2026 20:03:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ESS-Metron</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40d62b26a726f8c7eade3c4246383507f6b4077c6de1f13ed506958874f3bdd1</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.essmetron.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ilderton-Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29511</link>
<guid>9a46841c7df6435e8df5644f4867a987</guid>
<pubDate>Sat, 07 Feb 2026 20:02:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Ilderton-Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc69f96f08e24fc37eebb1dba74081a3104455f63994f52a0fd6a6cd85133969</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ildertoncontracting.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blooms-Bus-Lines</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29510</link>
<guid>41d934b57541fa144f6b6b585312a7e3</guid>
<pubDate>Sat, 07 Feb 2026 20:02:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Blooms-Bus-Lines</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d3fa4867353ca6406e6aa6ac6a8126373af59a6d5e6249309e729eb60464c16</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bloombus.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>RAL-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29509</link>
<guid>e195c8d9639740a0e9118526e45d4389</guid>
<pubDate>Sat, 07 Feb 2026 20:01:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>RAL-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bedd2d460d92a8bd74f1ec6b5c1c41bd46073bf7c9fe478688a52c619677987</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ralcompanies.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>KaiserAir</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29508</link>
<guid>556db02d592d6762904be04584decfa4</guid>
<pubDate>Sat, 07 Feb 2026 20:00:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>KaiserAir</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b921db138b63d332f6926868c8177bdd66b1558d08ee01829c5403e8b45a03a3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kaiserair.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>AMR-PEMCO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29505</link>
<guid>1a79e60cce2641f20b34acb72cd287d7</guid>
<pubDate>Sat, 07 Feb 2026 14:41:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>AMR-PEMCO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd6798f30feb2591920f0e5afe70c448bfeb327cb0939d51ec9fbba33c73a7da</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>VIPPLLC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29496</link>
<guid>5cd338743288fdb62b74ee279d51bf93</guid>
<pubDate>Sat, 07 Feb 2026 10:01:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>VIPPLLC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5dff64811066093a33e9412b7fb7861dd67ca1f6bc980968be10164bea997b06</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>CROWDEDISLAND.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29500</link>
<guid>3cdb497dee6acf5f571d685740fc6327</guid>
<pubDate>Sat, 07 Feb 2026 10:01:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CROWDEDISLAND.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2805dfcc103e6535357b364ea33311a8ba5cf77a62c717e4f3a6bda2cba704c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>NGATTORNEYS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29503</link>
<guid>d9fa461a6fb17006b5dd1a4e3741d829</guid>
<pubDate>Sat, 07 Feb 2026 10:01:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NGATTORNEYS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adbe40419d56d705617fe8b9afdc239cc9cdfdec773d3fded19a76d4f36b7d66</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlas-Air</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29494</link>
<guid>539c294351032d5473dbcfcc619ff021</guid>
<pubDate>Fri, 06 Feb 2026 22:48:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Atlas-Air</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8eaf9605e3dc4f70735d0c8ad7f2f97c43cddd51634911833ca90bbd5773f4d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Atlas Air Worldwide Holdings Inc. is a cargo and passenger charter airline based in Purchase, NY. Founded in 1992, Atlas Air operates globally with a large and efficient fleet of Boeing 747 aircraft. The company offers a variety of services like outsourced aircraft, crew maintenance, and insurance (ACMI), charter businesses, and dry leasing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>A</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29493</link>
<guid>47e3711856579ea4c53625d15fcc306d</guid>
<pubDate>Fri, 06 Feb 2026 21:49:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>A</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93a317b7c9392a47ed4cd349a65cb218ce15316442cac86c534668c53e955ccb</i><br /><br />Threat actor <b>description</b>: <i>A healthcare organization from USA.</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accountnet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29487</link>
<guid>371f5bb6b80541e62f0ecf7341293e2d</guid>
<pubDate>Fri, 06 Feb 2026 20:05:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Accountnet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f1f75108d108eaf8175e3572dae90be81ce0591b5188ea4b79d5253fd08df684</i><br /><br />Threat actor <b>description</b>: <i>Accountnet Inc provides educational webinars, newsletters, quarterly sales events and strong post-sales support</i><br />Target victim <b>website</b>: <i>www.accountnet.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Associated-Endocrinologists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29486</link>
<guid>74093e762e3747d3965126f98cbe4e57</guid>
<pubDate>Fri, 06 Feb 2026 20:03:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Associated-Endocrinologists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba9d9df312c7b80a27cda971a5e0217f79892518c8f043707133aa35fc1607f8</i><br /><br />Threat actor <b>description</b>: <i>Associated Endocrinologists is a leading specialized endocrinology center in Michigan, specializing in diseases of the thyroid, parathyroid, pituitary, and adrenal glands, as well as diabetes. With over 40 years of experience, they are one of the largest endocrinology clinics in the Midwest, providing services such as thyroid radiofrequency ablation, ultrasound-guided biopsy, and diabetes patient education. Their team includes board-certified physicians trained at prestigious institutions, ensuring high-quality medical care for patients and the security of their personal data.</i><br />Target victim <b>website</b>: <i>www.endocrinemds.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinite-Tiers-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29484</link>
<guid>c6c07dc0686f5f5bca5c9794e8c44ffc</guid>
<pubDate>Fri, 06 Feb 2026 18:46:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Infinite-Tiers-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9718c61134edfdd6f2343d571449b6e5a9d9d8044f913a8819a85bdbfee84896</i><br /><br />Threat actor <b>description</b>: <i>itgsoftware.com ITG Software, Inc. is a provider of mission critical integrated business software solutions. Using a rigorous design approach, we build integrated software systems that will have a marked positive effect on the bottom line. Infinite Tiers Group, Inc. has a unique approach to building software systems. This stems from our understanding of the usability and applicability of current technology as well as our vision of what's next. We are committed to providing the highest quality</i><br />Target victim <b>website</b>: <i>itgsoftware.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Logility</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29470</link>
<guid>14515b66c19dfb745f5a2fccc8f1393f</guid>
<pubDate>Fri, 06 Feb 2026 15:26:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Logility</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7609e3cd5bfd435ef0b03d45c03911b1bf9314d12ed74c0567d39fb087fdb8a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Logility is a global provider of supply chain planning and retail planning solutions. The company's services drive efficiencies, performance, and profitability by providing organizations with the tools to streamline operations. Established in 1972, Logility provides strategic, merchandise, assortment, demand, inventory, replenishment, and supply chain management solutions.</i><br />Target victim <b>website</b>: <i>logility.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peerson-Audio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29468</link>
<guid>8606adb6620707257e0d5cb386f095b7</guid>
<pubDate>Fri, 06 Feb 2026 14:42:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Peerson-Audio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7d8667c3d3274c3ce67ed5321411d6d31c0a2664a174d59e0e1f730b524a3e4</i><br /><br />Threat actor <b>description</b>: <i>Advantage Product Enterprise specializes in innovative rigging solutions for audio installations, offering products such as the APE Hanger, CHAIN Monkey, U Tube, and Bumper BoostPeerson Audio Incorporated specializes in designing and installing professional audio, video, and lighting systems tailored for a variety of clientele including houses of worship, sporting venues, performing arts venues, government buildings, and businesses.We will upload corporate data of the companies soon. Employee information, HR files, financials, customers info and a bit more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advent-Aircraft-Systems-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29466</link>
<guid>57ce0427b9e3b1b777b3efcf5684452e</guid>
<pubDate>Fri, 06 Feb 2026 02:49:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Advent-Aircraft-Systems-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b33ec5673da678f1bffc410c0078962c9d322ce10b89d1337fef17ec9ccba6f7</i><br /><br />Threat actor <b>description</b>: <i>Data breach on aerospace developments.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Penn-Fencing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29464</link>
<guid>eacbec704544fb3e45efadf8eedbf9c8</guid>
<pubDate>Fri, 06 Feb 2026 00:12:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Penn-Fencing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5147abf5ad35e93e6fcca94cfe8cb1015d50805b92d98b0d5af62e995fbd60d7</i><br /><br />Threat actor <b>description</b>: <i>Penn Fencing, Inc. specializes in the fabrication and sales of fencing, decking, and railing products, offering a wide variety of options both online and in-store. They provide professional installation services within 150 miles of Pittsburgh, PA, and ship vinyl products across the United States with a lifetime warranty. Their intended clients include residential homeowners looking to enhance their outdoor spaces as well as commercial clients needing security solutions. With a commitment to quality, they focus on vinyl and aluminum materials, ensuring durability and low maintenance for their products.</i><br />Target victim <b>website</b>: <i>www.pennfencing.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.platinumdrywall.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29459</link>
<guid>3f78614f061c508c892c4dfe0abdf27e</guid>
<pubDate>Thu, 05 Feb 2026 22:24:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>httpswww.platinumdrywall.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>262bc8b613def6a5669a5d0c7acc8f23db43f3d4ef20c4d77279a907cdf88115</i><br /><br />Threat actor <b>description</b>: <i>Platinum Drywall has been providing drywall and framing services to commercial construction companies since 2001.  They specialize in metal framing and truss systems and acoustic applications for commercial projects. Their services include: Drywall Installation Acoustic Ceilings Insulation Wall Systems Fire and Soundproofing Joint Compound Finishing Tenant Improvements Metal Stud Framing Metal Roof Trusses Load-Bearing Metal Stud Systems Hollow Metal Door Frames Metal Support Drywall</i><br />Target victim <b>website</b>: <i>www.platinumdrywall.net</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wayco-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29458</link>
<guid>ea30a83f57dabc455488ad906feaf213</guid>
<pubDate>Thu, 05 Feb 2026 21:32:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Wayco-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f85a020269fd14228afa98a9d81a611cb0a18adda9cbb957a6d772a301eaab8</i><br /><br />Threat actor <b>description</b>: <i>Wayco, Inc. is a family-owned company with over 50 years of experience providing full-service paving solutions in northeastern Pennsylvania. Their extensive offerings include asphalt paving, oil chipping, aggregate sales, concrete services, excavating, and utility site work. The company prides itself on its knowledgeable staff, including licensed engineers for project consultation, and is a PA State Certified Contractor with products approved by PennDOT. Wayco, Inc. caters to clients in need of paving and construction services, ensuring high-quality results through a dedicated team.</i><br />Target victim <b>website</b>: <i>www.waycoinc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Exco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29457</link>
<guid>5f8d8411ff393c9cb54249e010b017b4</guid>
<pubDate>Thu, 05 Feb 2026 21:13:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Exco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d5c80cc8767ebebcb39f02a56c38db967708b0899c26fb45f602d71f829dde3</i><br /><br />Threat actor <b>description</b>: <i>Exco is a network of accounting, consulting, and audit firms that simplifies entrepreneurship across France and internationally. They offer services in accounting, audit, tax, social management, human resources, and legal advice, ensuring tailored support for businesses in various sectors. With a commitment to responsible growth and expertise in complex financial situations, Exco provides guidance in corporate management, financial transactions, and sustainability. Their multidisciplinary teams work closely with clients to foster business development throughout every stage of a company's lifecycle.</i><br />Target victim <b>website</b>: <i>www.exco.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Western-Slope-Iron--Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29455</link>
<guid>8301f99aa26536037481546bf5543536</guid>
<pubDate>Thu, 05 Feb 2026 20:17:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Western-Slope-Iron--Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1d126a85b51b7d7c2d5716f87280c2cf7b76c1bedd579cdf50bbf4eca18fa04</i><br /><br />Threat actor <b>description</b>: <i>Western Slope Iron & Supply, Inc. is a certified steel fabricator operating since 1974, based in Grand Junction, Colorado. The company specializes in the fabrication of structural and miscellaneous steel for high-end commercial, industrial, residential, and governmental projects throughout the Western United States. Additionally, they serve as a Hilti distributor, offering a variety of steel parts and supplies for diverse applications. Their commitment to customer service and proactive project management has garnered positive feedback from clients across various sectors.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reilly-Foam-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29454</link>
<guid>29579d096935b2f86a4d4f1be47cb69c</guid>
<pubDate>Thu, 05 Feb 2026 19:41:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Reilly-Foam-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de3458e7aaeb1abb9914f74243bd23d184a37777c9f2889c8f38a2cd4ec02ff2</i><br /><br />Threat actor <b>description</b>: <i>Reilly Foam Corporation manufactures fabricated foam components for several industries & applications</i><br />Target victim <b>website</b>: <i>www.reillyfoam.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Hospital-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29450</link>
<guid>0f450f46df1e06c6737e4ac25603c02a</guid>
<pubDate>Thu, 05 Feb 2026 14:48:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>United-Hospital-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53b35118dc21c72df0f0ba3aca6b26ac59987211e589984b03c934c5a37cadb7</i><br /><br />Threat actor <b>description</b>: <i>Fenco Solutions is a leading American manufacturer specializing i
n laboratory-related products, including lab casework, tables, sa
fety cabinets, fume hoods, and biosafety cabinets. The company of
fers a wide range of services such as lab design, consulting, ins
tallations, renovations, project management, and expedited supply
services.

We will upload 39gb of corporate data soon. Employee information,
w-9 forms, projects, financials, contracts and agreements, custo
mers info, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LumioDental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29448</link>
<guid>3c2140d1a64d146fbd15082b3a34130c</guid>
<pubDate>Thu, 05 Feb 2026 14:43:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>LumioDental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8fdaaf3bb3096f1eb51d85eeb9c457cb349918e1471f02f18ce91053d3a5c58e</i><br /><br />Threat actor <b>description</b>: <i>A company that manages a network of dental clinics.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>brooklyn-group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29444</link>
<guid>1d3b870a10ac880f27c0b5b69756e749</guid>
<pubDate>Wed, 04 Feb 2026 23:10:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>brooklyn-group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>574f3dd676339049e13110d862d9b0cafe334e120af5119b3cc94dde89fba208</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>brooklyngroup.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>ISTS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29442</link>
<guid>91a8884b0dc5d0c47cf772bd1942a5af</guid>
<pubDate>Wed, 04 Feb 2026 20:25:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ISTS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d81eedb46f1372e3eab96f6d12ca40493a681ce69f450f773f5f78432496ce63</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.applyists.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CBH-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29441</link>
<guid>29ac0835a14c551405ff79715374bd05</guid>
<pubDate>Wed, 04 Feb 2026 20:25:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>CBH-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8aa7a8aae0782528e8e7463d9e14e6ca552b1795bed3cebea5db6bec780b491</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cbhhomes.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodfield</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29440</link>
<guid>84c87f842d01e3bf469827b469dcacec</guid>
<pubDate>Wed, 04 Feb 2026 20:24:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Woodfield</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e33eac5bc6ca0a8123d7d8f0f9263d6c64064f98b36e4c0ea9cab34ec8c6849</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.woodfieldinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Richey-Tax-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29436</link>
<guid>12bf6e4ef656f8d8a5b2ee769c747c77</guid>
<pubDate>Wed, 04 Feb 2026 16:40:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Richey-Tax-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df0ad3d68f82c9988423467ac0f7ee017fcd7a9d9cffd7c9222cae7022e69ad4</i><br /><br />Threat actor <b>description</b>: <i>Richey Tax Solutions LLC, based in Tucson, AZ, specializes in small business consulting, income tax preparation, and retirement and tax planning. The firm is known for its professional, experienced, and affordable services tailored for retirees, business owners, executives, and independent professionals.We will upload 25gb of corporate data soon. They refused to save client's data. SSNs, passports, DLs, death/birth certs, financials information, correspondence and other confidential files, legalfiles, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Royal-Wine-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29338</link>
<guid>7dcb383d6623119ecdde0537f3a7f974</guid>
<pubDate>Wed, 04 Feb 2026 14:39:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Royal-Wine-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5826053e864d01d92617e03444654c7b40f08ab6292efdc3db3cd2d71b16935d</i><br /><br />Threat actor <b>description</b>: <i>Royal Wine Corp is a family-owned company specializing in the production and distribution of high-quality kosher wines, liqueurs, and spirits. The company offers a diverse portfolio, including various brands of wines and spirits, with an emphasis on its Israeli selections. Their target clients include wine and spirit enthusiasts looking for unique and authentic kosher beverages.We will upload 25gb of corporate data soon. Detailed employee personal information (SSNs, passports, DLs, health information, credit cards and so on), clients information (projects, contracts, contacts), financials, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>efulfillment-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29340</link>
<guid>49129551dac6241eb7d1f601f058679b</guid>
<pubDate>Wed, 04 Feb 2026 14:39:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>efulfillment-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af831da3e6d91b1aab066816f72b0bb6f08a9ca0b01a9228f11d419098616151</i><br /><br />Threat actor <b>description</b>: <i>eFulfillment Service (eFS) is a third-party logistics provider (3PL) and provides ecommerce businesses with inventory storage, order processing, shipping, Fulfillment by Merchant (FBM), Fulfillment by Amazon (FBA) Prep and returns service.We will upload corporate data soon. Accounting files, clients' accounting files, detailed financials and other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>DOnofrio-General-Contractors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29435</link>
<guid>08afe31e80612e5ea99ac4daea3b666b</guid>
<pubDate>Wed, 04 Feb 2026 14:08:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DOnofrio-General-Contractors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d75cc6dd43bc673255967dc959f7760b511e47c7e75513ba3afe548bc5573d23</i><br /><br />Threat actor <b>description</b>: <i>D'Onofrio General Contractors Corp., based in Brooklyn, N.Y., spe
cializes in heavy infrastructure and marine construction projects
, leveraging decades of industry experience since its founding in
1991. The company serves clients in New York, New Jersey, Pennsy
lvania, and Connecticut, focusing on projects for local utilities
, including the modernization of generation plants and power subs
tations.

We will upload corporate data soon. Employee files (SSNs and othe
rs), projects, financials and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lakeside-Union-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29328</link>
<guid>f40ed67587440c64e5b3881297d5c827</guid>
<pubDate>Wed, 04 Feb 2026 08:01:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Lakeside-Union-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2dbfbda5ad9e4cdd3dbdc68adbb1ea94170e6cb4adb7b6bdadcf1f84d2fb218</i><br /><br />Threat actor <b>description</b>: <i>Lakeside Union School District</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crystal-Coast-Pain-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29325</link>
<guid>fee801ecfba08d39cd8ebed9fdcbe7e9</guid>
<pubDate>Wed, 04 Feb 2026 01:24:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>Crystal-Coast-Pain-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>840f4b5dd29861be164f42b6f5f6d343c5a9d85ab4ae878dbdcb506a6a33a9ab</i><br /><br />Threat actor <b>description</b>: <i>SSN, medical data, medical cards</i><br />Target victim <b>website</b>: <i>crystalcoastpm.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Western-New-York-Energy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29322</link>
<guid>27523bf027aea782710f6055e2958b7b</guid>
<pubDate>Tue, 03 Feb 2026 19:27:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Western-New-York-Energy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7e3efd8df024b14304ed83fa1f616d55bd6fdef084f597465763c7cf177b4e8</i><br /><br />Threat actor <b>description</b>: <i>Western New York Energy LLC – Major Data Breach Announcement Western New York Energy LLC (wnyenergy.com), a leading regional ethanol producer and renewable energy company based in Medina, New York, has suffered a significant data compromise. Total volume of obtained data: ≈100 GB The leaked archive contains highly sensitive and business-critical materials, including:  Confidential internal documents Client and counterparty data Non-Disclosure Agreements (NDAs) Financial records and reports Operational documentation and procedures Investor-related materials and presentations Corporate governance documents Commercial contracts and business agreements Technical drawings, schematics, and engineering files  …and a substantial amount of other proprietary and strategically important information that is vital to the company’s operations, partnerships, and competitive position. This dataset provides deep insight into the internal workings, financial structure, client relationships, and strategic planning of one of the Northeast’s key ethanol producers. The information is authentic, recent, and untouched.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Forella-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29321</link>
<guid>7d44eb268a656ba8bf731a62eb9156af</guid>
<pubDate>Tue, 03 Feb 2026 16:41:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Forella-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08012a19b1b974d7b854b331678dbcbf39bd553e1daadc017bd774349a0224d5</i><br /><br />Threat actor <b>description</b>: <i>Forella is a Minority Business Enterprise (MBE) that offers a range of services including cost estimating analyses, CPM P6 schedule management, constructability reviews, and project management. They specialize in expert investigations and dispute resolution, providing construction economics services to their clients.We will upload 457gb of corporate data soon. Detailed employee personal information (SSNs, passports, DLs, health information, credit cards and so on), financials, NDAs, contracts and agreements,confidential projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PTI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29319</link>
<guid>70bbf5f950fcde758686c2635893ca0a</guid>
<pubDate>Tue, 03 Feb 2026 14:48:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>PTI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a0cab9329719523d522d7241dc3876356cc64afd2ba8045b7db1e86a040ee52</i><br /><br />Threat actor <b>description</b>: <i>PTI offers inspection systems for package leak testing, seal inte
grity, and container closure integrity testing (CCIT). Their tech
nologies exclude subjectivity from package testing and use test m
ethods that conform to ASTM standards. The company is based in Ha
wthorne, New York.

We will upload corporate data soon. Financials, personal docs of 
upper management, a bit of projects information and other interna
l files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Drake-Precision-Dental-Laboratory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29318</link>
<guid>dedd9d7c6b5c98236fcc72f4b462f277</guid>
<pubDate>Tue, 03 Feb 2026 14:48:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Drake-Precision-Dental-Laboratory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc35b3775b0cb79f505adbb87b1de2b717795ea28c80d8dc6f23f20a488e2e7d</i><br /><br />Threat actor <b>description</b>: <i>Drake Dental Lab specializes in creating esthetic dental solution
s, offering a range of products including crowns, bridges, dentur
es, implants, clear aligners, and sleep appliances. Since 1956, t
he company has been dedicated to precision and innovation in digi
tal dentistry.

We will upload 39gb of corporate data soon. Employee personal inf
ormation (SSNs and other information of more than 120 employees),
financials, NDAs, contracts and agreements, customers' informati
on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-of-Thomas-J-Skinner-IV</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29317</link>
<guid>8afc0327c6d499ed20c99d2a2502c7b9</guid>
<pubDate>Tue, 03 Feb 2026 13:54:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Law-Offices-of-Thomas-J-Skinner-IV</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>537edf4f75e7c43ba73c4e41d6183f6487b9a6af4325c07345fb665379873c8c</i><br /><br />Threat actor <b>description</b>: <i>What problems does this law firm have besides its shitty logo? Find out in the article.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rosenblum-Schwartz-Fry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29316</link>
<guid>7500bbe7e791e2d3a19f61cf43b87b99</guid>
<pubDate>Tue, 03 Feb 2026 13:53:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rosenblum-Schwartz-Fry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aaa599ac1025f582936ce3c7072fe1109670d117abba79901a0fbaa7e4ddd17e</i><br /><br />Threat actor <b>description</b>: <i>Rosenblum Schwartz & Fry, P.C., provides strong legal representat
ion against misdemeanor and felony criminal charges.

We will upload 1.3tb of corporate data soon. Detailed information
about clients (passports, DLs, SSNs, medical information, financ
ials and so on), employee information, lots of legal files, confi
dential ones, court files, police reports and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Balloons-Everywhere</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29310</link>
<guid>95cb29c65c9f39aee2714e7734c344cc</guid>
<pubDate>Tue, 03 Feb 2026 12:30:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Balloons-Everywhere</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46f2f7bd3e641abeff8b18d30921b5b4bba337e0d5b76211733ade7bd6bb8007</i><br /><br />Threat actor <b>description</b>: <i>Balloons.com is a wholesale distributor specializing in a wide range of balloon products including foil film, latex balloons, and balloon decoration kits. They cater to various themes, occasions, and licensed characters, offering items for both everyday events and special celebrations. Their services target individuals and businesses looking for party supplies, with a focus on DIY balloon decor and promotional products. Additionally, they provide customers with resources and learning tools related to balloon usage and care. 
The company headquarters is located in 16474 Greeno Road, Fairhope, AL 36532-5528, United States.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Hays-Fire-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29311</link>
<guid>4cd32d6e6c24dad2afe99e445b936b66</guid>
<pubDate>Tue, 03 Feb 2026 12:30:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>South-Hays-Fire-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87fa1dca64c93f44b85ad7851a83bddc89c3b925e5d54b4907b1fce3accd4dba</i><br /><br />Threat actor <b>description</b>: <i>Hays County Emergency Services District 3 provides essential fire prevention and emergency services to the South Hays County area. The district focuses on recruiting full-time firefighters and is dedicated to community safety and preparedness. In addition to emergency response, the district promotes public knowledge on fire safety and outdoor burning regulations. Their commitment to accessibility ensures that all community members can engage with their services effectively. 
The company headquarters is located in 3528 Hunter Road, San Marcos, Texas 78666.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blystone--Bailey</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29309</link>
<guid>6fb2011334a2bf8dca4e120157fab408</guid>
<pubDate>Tue, 03 Feb 2026 04:08:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Blystone--Bailey</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19ae53d604048a8aeee69d9a25a482459050b93a50d1310c4268a5256b98f6e2</i><br /><br />Threat actor <b>description</b>: <i>Blystone & Bailey, CPAs, PC is a Michigan-based CPA firm offering a range of services including audit, tax preparation and planning, payroll, financial planning, bookkeeping, and IT services management.  The firm caters to various industries such as real estate, hospitality, oil, gas and energy, professional services, construction, manufacturing, retail, agriculture, franchising, and government and non-profit sectors.  We have the entire Blystone & Bailey customer base at our disposal. Mail, financial documents, audits and more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENCOMPASS-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29307</link>
<guid>cbe674ba9bc1702bf55e91103db4a022</guid>
<pubDate>Mon, 02 Feb 2026 23:34:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>ENCOMPASS-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a0aa9233a5bbe1f84a1f9ac088085de501378e4c8dba9544ba170e2669d29f6</i><br /><br />Threat actor <b>description</b>: <i>Finance documents, clients PII</i><br />Target victim <b>website</b>: <i>encompass-inc.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Family-Health-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29306</link>
<guid>e5f1d4219be6d4dafe14bc929d5c2808</guid>
<pubDate>Mon, 02 Feb 2026 22:44:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>Family-Health-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec992f0f033fbfac56445beca74f866db8f896270bc774d215bc60c40d840219</i><br /><br />Threat actor <b>description</b>: <i>Family Health Centers of Southern Indiana offers quality healthcare services to low-income, underinsured, and uninsured residents in Jeffersonville, New Albany, Corydon, and Clarksville. Their dedicated team of board-certified physicians and nurse practitioners provides a wide range of primary health care services, including a mobile dental unit. The organization emphasizes care for </i><br />Target victim <b>website</b>: <i>www.fhcenters.org</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>Erickson-Thorpe--Swainston</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29303</link>
<guid>26e12e8ce3cf76d35b5ab714143378cd</guid>
<pubDate>Mon, 02 Feb 2026 18:40:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Erickson-Thorpe--Swainston</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>469d52b821cd8111d08a4f13b9fbac1b3adc87580aa08c7d01b9b7befa80188e</i><br /><br />Threat actor <b>description</b>: <i>The law firm of Erickson, Thorpe & Swainston was founded in 1969. Since then, the firm has effectively and successfully represented its clients in state and fed...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medinah-School-District-11</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29304</link>
<guid>b1ab8aea23da706493a95512b29c7dd7</guid>
<pubDate>Mon, 02 Feb 2026 17:40:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Medinah-School-District-11</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e902df98479009abae8262940ee3410bcd7a5665855d56aaa926d3e61e143ec</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>JST-Power-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29298</link>
<guid>dda8019dec3926428ce2f4b0c9496fad</guid>
<pubDate>Mon, 02 Feb 2026 16:39:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>JST-Power-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88e57d8765fdd45fa0229c5c86a8d23efaf3dce8c8207609319b654c5cbbef14</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1993, J.S.T. provides product development of any electric connection systems in products like amusement equipment, audio and visual equipment, household appliances, office equipment, industrial equipment, automobiles, and traffic systems.We will upload 70gb of corporate data soon. Employee information,financials, confidential clients information, large amount of projects files, contracts and agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Exterior-Worlds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29288</link>
<guid>e87b5193d3e60a52a8e3df82af428e27</guid>
<pubDate>Mon, 02 Feb 2026 14:40:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Exterior-Worlds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>871fa617ac0476caf73c3ea10eefbbb170959dd1f2a74db7620ef6549964c26c</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Range-Cooperatives</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29290</link>
<guid>7a1eae3489145133fdd9dbd917810547</guid>
<pubDate>Mon, 02 Feb 2026 14:40:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Range-Cooperatives</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c43fabc07eb534ceedc0b852143aa68cc2512e777a31a62725d7a54a8e33720</i><br /><br />Threat actor <b>description</b>: <i>Energy, Utilities & Waste</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Hechtman-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29291</link>
<guid>29e055ad65e83cc5d56f5481d543b67d</guid>
<pubDate>Mon, 02 Feb 2026 14:40:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Hechtman-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3c5999b0a9d9bd5a68fa9cb1b4867dc497470f00f17ff4837d42e0a324fda2d</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kilograph</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29292</link>
<guid>dbc6904b9ae5239ad74f90306daae0ad</guid>
<pubDate>Mon, 02 Feb 2026 14:40:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kilograph</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf13250d3ba3820d2a68361e45b1fe0678b619d49630e85e8a54587dc5d4f72c</i><br /><br />Threat actor <b>description</b>: <i>Kilograph is an award-winning creative agency that specializes inshaping brands, places, and experiences. They utilize strategic storytelling and engaging visuals, combined with innovative technologies, to fulfill their clients' needs.We will upload corporate data soon. Passports, w9 forms and otheremployee documents, clients' personal information (docs, health information), financials, confidentiality agreements, contracts and agreements, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sprokkit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29286</link>
<guid>3c383a7279bf9f3e124ee4b34fe7bca3</guid>
<pubDate>Mon, 02 Feb 2026 07:46:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sprokkit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fecb0bb878fae5a72a4615af1086f2de97568ccadc41e575cba1cd338a415715</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stephenson-Ziegenhorn--Bernard</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29287</link>
<guid>ee82b11edbd4f34a1081986fb2ecf895</guid>
<pubDate>Mon, 02 Feb 2026 07:45:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Stephenson-Ziegenhorn--Bernard</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e09d24f87012866afc06eafcae7f8a5bddd9ae101d1310413a6bd64478c0b3c</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Best-Attorneys</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29283</link>
<guid>eb39b5b5c9f53442cdfb5dc8229dfe39</guid>
<pubDate>Mon, 02 Feb 2026 04:54:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Best-Attorneys</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c5c5e69981d1fe28f1b607b514c777f3855a1613d5e40604ccb75cc892a7a1b</i><br /><br />Threat actor <b>description</b>: <i>Eisenberg Lowrance Lundell Lofgren is dedicated to your success. We are contingency fee lawyers specializing in personal injury, immigration, and criminal defense located in South Jordan Utah.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Polycom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29282</link>
<guid>8194758636bb0e5bab1a445835138b98</guid>
<pubDate>Mon, 02 Feb 2026 02:37:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Polycom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38eacda85c63b7a6151d026ea9452a73478209683c7a1ac55fed2d812e0f8e90</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Polycom is an American multinational company specializing in creating technology that fosters easy and efficient collaboration for businesses. Polycom's products include communication devices, video conferencing systems, and other related applications and services. The company has a globally spread presence, with its headquarters located in San Jose, California. It was acquired by Plantronics in July 2018.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Iron-Mountain</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29281</link>
<guid>e417e85606b3fc0cdab5f65d721f2ee0</guid>
<pubDate>Mon, 02 Feb 2026 02:37:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Iron-Mountain</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67b6554811d089a7cf39e71ab7d2d96d0d973d4124f11158808145824fdb8d57</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Iron Mountain Incorporated is a global business specializing in storage and information management services. Founded in 1951, based in Boston, Massachusetts, it helps organizations to store, manage, protect, retrieve information and data. Its offerings include records and information management, data backup and recovery, secure shredding, and data centers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>T--M-Electric-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29277</link>
<guid>67245236ce5a981076ce7feffc35c893</guid>
<pubDate>Sun, 01 Feb 2026 20:32:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>T--M-Electric-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>808225a3fa5d04fbb2ac464d8d78bf000be00facdec63e0495be30a547306c62</i><br /><br />Threat actor <b>description</b>: <i>T&M Electric LLC is a state certified full-service electrical contractor based in northeast Florida, specializing in residential and commercial electrical installations and services. They offer a range of services including new construction, electrical troubleshooting, panel upgrades, generator installations, and LED lighting upgrades. Their commitment to quality service, professionalism, and customer satisfaction distinguishes them in the electrical contracting industry. The company targets homeowners and businesses in northeast Florida, providing reliable and efficient solutions for all electrical needs</i><br />Target victim <b>website</b>: <i>tmelectricinc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deatak</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29276</link>
<guid>d0adfd0849265d3738d28df149746e21</guid>
<pubDate>Sun, 01 Feb 2026 19:54:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Deatak</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56f89d084fed8b523bd884a4a5250d525d4eec6cd38fa4d25a86ce5027c89acd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.deatak.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stellium</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29275</link>
<guid>afb10ddfce75e4a231f083365f04e08f</guid>
<pubDate>Sun, 01 Feb 2026 17:33:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Stellium</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>940f5b766c2cb1740ca576943fb96bbd69aa67f90f903b7a417871d3bd3efba9</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Stellium is a consulting firm focused on services for supply chain management optimization, such as data analytics, lean manufacturing strategies, and innovative technology implementation. They cater to multiple industries, including energy, manufacturing, technology, and healthcare, among others. Their methods revolve around the utilization of advanced data to optimize operations and produce successful business outcomes.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acu-Trans-Solutions-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29274</link>
<guid>0a9c1911c5cb76cd01bd5fc2870892bd</guid>
<pubDate>Sun, 01 Feb 2026 17:33:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Acu-Trans-Solutions-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c52cd52b3683a7e6e8ca5bb54943fb56b8f76948e2693719fc958f86e8cf2359</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Acu Trans Solutions LLC is a company providing professional translation services across multiple languages. It specializes in sectors such as legal, healthcare, business and government. Their team is made up of certified linguists and translators who deliver accurate and high-quality translations. Besides translation, services also include transcription and interpretation, aiding businesses in their international communication.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>SIGMA-Processing-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29273</link>
<guid>2a912ac127cc3ac74d5255fa9097f3a9</guid>
<pubDate>Sun, 01 Feb 2026 17:32:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>SIGMA-Processing-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e40506ab2c9e6938aa1767dde3380907082423956e3131b1e2fc85105ec9f11c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Foamtec-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29272</link>
<guid>16fe58fde1b4617fa7148321b3c0c3c9</guid>
<pubDate>Sun, 01 Feb 2026 16:22:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Foamtec-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>128c2a1beb864073744b93748f2cc514afd56c9ac50002e2ae6f256edbc153e5</i><br /><br />Threat actor <b>description</b>: <i>Foamtec International is a global PU foam Manufacturing partner. We deliver quality, specialty foam products for contamination control, medical and specialty markets</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Odyssey-Academy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29271</link>
<guid>1f239457a5b2fb11ddafc392ffd18e1f</guid>
<pubDate>Sun, 01 Feb 2026 15:29:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Odyssey-Academy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>221187a0439d9b734077277dde369e895a55eaf428ea76acb127bb5114e6f50b</i><br /><br />Threat actor <b>description</b>: <i>Odyssey Academy is a free public charter school. This school educates and prepares children for adulthood, but a large amount of data has become publicly available due to the disrespectful and negligent attitude of its staff and administration. As a result, student and staff data and the school's records, including full financial reports and other confidential documentation, have been compromised.</i><br />Target victim <b>website</b>: <i>odyssey-academy.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mullinax-Ford</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29270</link>
<guid>89242c1e4610507f79f8a7b192880778</guid>
<pubDate>Sun, 01 Feb 2026 04:02:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Mullinax-Ford</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c1150ef18b354ee4686ad236293490b050003a4cade8b99ab568fa31169eeaa</i><br /><br />Threat actor <b>description</b>: <i>Located in Apopka, FL, Mullinax Ford is proud to be one of the premier dealerships in the area. From the moment you walk into our showroom, you'll know our commitment to Customer Service is second to none. We strive to make your experience with Mullinax Ford a good one - for the life of your vehicle. Whether you need to Purchase, Finance, or Service a New or Pre-Owned Ford, you've come to the right place</i><br />Target victim <b>website</b>: <i>mullinaxford.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>SoCal-ROC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29268</link>
<guid>f843074d5076212128800b4857d189aa</guid>
<pubDate>Sun, 01 Feb 2026 00:42:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SoCal-ROC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72dc7e1054947e27a66b9f4a664d8d26b5994c69997b979f297c2ce668bc8c45</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hawk-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29269</link>
<guid>d77f939ce26039cc0a0226aeb635d6dd</guid>
<pubDate>Sun, 01 Feb 2026 00:25:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Hawk-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c5cea73857ea1f25cd7747dcade71ea8ceeeee6a71c410b4ed542fe41372418</i><br /><br />Threat actor <b>description</b>: <i>At Hawk Law Group, our trial attorneys were born and/or raised in the Augusta area. Collectively, our lawyers have more than 71 years of experience and are widely recognized throughout the Central Savannah River Area (CSRA) due to their tremendous successes in and out of the courtroom.  Our lawyers understand the complexities of civil and criminal litigation and realize the importance of our justice system for their clients and families.  </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bar-S-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29245</link>
<guid>53d7f154d6c0738fa10f9402b2e93e96</guid>
<pubDate>Sat, 31 Jan 2026 17:28:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Bar-S-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc2346f61d93b9720c4775a4699cc4ada5c50c3a24efc5ff88eee5fe492da36e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.barsinc.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>NAI-Plotkin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29244</link>
<guid>af1870edf5b2de354c2b90d442a299d3</guid>
<pubDate>Sat, 31 Jan 2026 17:27:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>NAI-Plotkin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6710eb268cc6bb28c2d2aabf3ca3da6940d05783c78e7ef397378fb2dd418fd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sdplotkin.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Transaction-Packing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29243</link>
<guid>bf6055077ad393192cb34e27b607e4f2</guid>
<pubDate>Sat, 31 Jan 2026 15:59:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Transaction-Packing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d869ef994323c493974c8d1ce5411fa8c5501ce64a26035d5d55358068b03966</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.transactionpacking.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hallauer-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29242</link>
<guid>5262d5a886484791a7c4c9bd5351a2cf</guid>
<pubDate>Sat, 31 Jan 2026 09:19:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Hallauer-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd87bed42607a7f9421d4d59b42a4bd078f5c723d3b301b87ad5e9fcf4762bd8</i><br /><br />Threat actor <b>description</b>: <i>The go-to firm throughout the Hampton Roads region for Criminal Defense, Family Law, Military Law, and Personal Injury matters</i><br />Target victim <b>website</b>: <i>hallauerlaw.net</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dolby-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29238</link>
<guid>b628a477ffe52c257f35814beca57353</guid>
<pubDate>Sat, 31 Jan 2026 05:38:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Dolby-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a543b8f59a49412a0e99d837bba7df1d441baf0d459b1d582f235b9e1e95f26a</i><br /><br />Threat actor <b>description</b>: <i>Dolby Laboratories, Inc. creates audio and imaging technologies that transform entertainment and communications at the cinema, at home, at work, and on mobile devices. The company develops and lice...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wieson-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29237</link>
<guid>311864ecae3eaccf77475c575b178460</guid>
<pubDate>Sat, 31 Jan 2026 02:05:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Wieson-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b7d5be4b0caf0c7c472cd2128bedbc96e68d03553cf5419d257309db4e015bb</i><br /><br />Threat actor <b>description</b>: <i>www.wieson.com https://www.zoominfo.com/c/wieson-technologies-co-ltd/128565406 Wieson Technologies specializes in the design and manufacturing of connectors and cable assemblies, with a focus on super high-speed technology and wireless communications. Their product range includes interconnect components, wireless components, medical electronics, and automotive electronics. The company serves various industries such as cloud computing, data communication, and medical electronics. Established in 1990, Wieson Technologies aims to provide innovative solutions to clients in need of advanced electronic connectivity</i><br />Target victim <b>website</b>: <i>www.wieson.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beacon-Mutual-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29235</link>
<guid>8424248303304cda787d00ef2732f8f0</guid>
<pubDate>Sat, 31 Jan 2026 00:31:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Beacon-Mutual-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f7a70a63717bb61b76903848b70a7b9a50ea403b4571aacb6e910f45e25a5f8</i><br /><br />Threat actor <b>description</b>: <i>MAJOR DATA LEAK – Beacon Mutual Insurance Company EXPOSED: 275 GB (296,228,795,086 bytes) of highly sensitive internal data Beacon Mutual Insurance Company (Warwick, RI) – the primary workers' compensation insurer for Rhode Island businesses (also operating in MA & CT) – has suffered a massive data compromise. The leaked archive contains approximately 275 GB of uncompressed/internal files and includes the following categories of highly confidential information:  Internal corporate documents and correspondence Complete financial statements and reports (2018–2025) Full employee list with personal details Confidential agreements, NDAs, vendor contracts, and partnership documents Detailed claims data: workers' compensation payouts, injury reports, medical records tied to claims Client / policyholder database: business information, insurance policies, payment history Personally identifiable information (PII) of individuals (employees, claimants, insured workers) – names, SSNs, addresses, dates of birth, contact details, etc. Training materials, internal manuals, compliance & safety documentation Multiple system backups and database dumps …and much more internal operational content</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawsoft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29234</link>
<guid>54c6997a78e69329bbf97a9256104e4f</guid>
<pubDate>Sat, 31 Jan 2026 00:14:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Lawsoft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e76334bfe74bbe2a9306ba27364d6fc370046d4f7c9adcc8752dc8c6c847b5ed</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/lawsoft-inc/354268207 lawsoftweb.com www.lawsoft-inc.com LawSoft, Inc. specializes in providing scalable and customizable software solutions for law enforcement agencies, including Computer-Aided Dispatch (CAD), Records Management Systems (RMS), and Fire EMS systems. Their products aim to streamline reporting and data integration, boasting a user-friendly design and incorporating legacy system data for a cohesive experience. The company emphasizes strong customer service with 24/7, US-based support and partners closely with clients to cater to their specific needs. LawSoft targets law enforcement agencies seeking efficient, effective technology to enhance their operational capabilities</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hydrometrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29233</link>
<guid>3713d66bff68568a81cc5bfd409a3703</guid>
<pubDate>Sat, 31 Jan 2026 00:14:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hydrometrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2920b416490ccb2f38f4eb80754a3714ec1edf708d1145d4cee08c381a8e63a</i><br /><br />Threat actor <b>description</b>: <i>www.hydrometrics.com https://www.zoominfo.com/c/hydrometrics-inc/18513967 Hydrometrics, Inc. is a Montana-based company that offers professional scientific and engineering services to industrial, commercial, municipal, and private sectors throughout the United States. With over 40 years of experience, they specialize in civil and environmental engineering, water resources and hydrogeology, mine permitting and compliance, and hazardous waste management. Their interdisciplinary approach ensures client satisfaction through reliable and effective solutions tailored to specific project needs. Hydrometrics is committed to empowering environmental responsibility and delivering dependable results.</i><br />Target victim <b>website</b>: <i>www.hydrometrics.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abatix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29231</link>
<guid>d17b9f24d0283dea76343dd18297f806</guid>
<pubDate>Fri, 30 Jan 2026 23:05:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Abatix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>695dd7901b314def44e1c665529cb5bceb63d43649466d6d5add443247c4a42e</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/abatix-corp/99255 www.abatix.com Foundeded in 1983, Abatix is a supplier of products for the general construction, industrial safety, petrochemical, energy, environmental, hospital, fire and water restoration, and disaster response industries supporting customers across the nation and is headquartered in Mesquite, Texas. Established in 1983 and with branch offices in the Atlanta, Baton Rouge, Chicago, Dallas, Houston, Jacksonville, Las Vegas, Los Angeles, Phoenix, San Antonio, San Diego, San Francisco, Sacramento and Seattle areas, Abatix has grown into a nationally recognized supplier of products for the General Construction, Industrial Safety, Petrochemical, Energy, Environmental, Hospital, Fire and Water Restoration, and Disaster Response industries supporting customers across the nation.</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>woodwardoralsurgery.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29230</link>
<guid>4dcc45e9d02ac1b27fe544687d823bac</guid>
<pubDate>Fri, 30 Jan 2026 20:33:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>woodwardoralsurgery.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90587405cbdd83de1e0cfcf0930f1fdd9b70e4fc7fa8bfd6776441edf2691d10</i><br /><br />Threat actor <b>description</b>: <i>Patient data, med cards</i><br />Target victim <b>website</b>: <i>woodwardoralsurgery.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>wjnklaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29228</link>
<guid>de52c3533a78c94f7b3dbc7160f551f6</guid>
<pubDate>Fri, 30 Jan 2026 17:34:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>wjnklaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a3b23ee560f7037c090f415b8dc9328f989430df6932dea16edf1f201abb2a0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>wjnklaw.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>LONGHORNORGANICS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29217</link>
<guid>f6c744ece7e1a36892eba3a5d2938110</guid>
<pubDate>Fri, 30 Jan 2026 16:35:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LONGHORNORGANICS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03e1eaf01919e33c1511d7643dc310697cb6433ca8598bdbfded98df1c9492c3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SHACKELFORD.LAW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29219</link>
<guid>a2667dd894062c9ca2a4602cb4718f52</guid>
<pubDate>Fri, 30 Jan 2026 16:35:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SHACKELFORD.LAW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5983fbe111308ff2358ecf579ba26adfa4530583a013969ed4d872edb1c67877</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SERVE-CLOUD.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29220</link>
<guid>127eeffce3105803c5cbd2aa9428ef5c</guid>
<pubDate>Fri, 30 Jan 2026 16:35:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SERVE-CLOUD.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b0b688e044f48e8dc62fc7ca13d4a833bb05ab5101802f0a59d82220ec2a7be</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Littlefield-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29205</link>
<guid>9b0bb812b40cb63d352715c0040dbfba</guid>
<pubDate>Fri, 30 Jan 2026 14:39:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Littlefield-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d8a9b1e676a025de89986797f78dbd3a56723f5ed17c47ab66541dc25ba0cbd</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bryant-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29211</link>
<guid>508cb643c0ea0e2f6451bba7aa5cfb64</guid>
<pubDate>Fri, 30 Jan 2026 14:39:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bryant-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80f6c706352e30a23ee59cf7c88ccb9863d5209a9d9d18983392b98c7e1cc3f6</i><br /><br />Threat actor <b>description</b>: <i>Bryant Home specializes in providing comprehensive engineering solutions for the built world, focusing on geotechnical engineering, building envelope consulting, and hydrological analysis.We will upload 10gb of corporate data soon. Detailed employee personal information (health information,scans of personal documents), detailed financials, credit cards, payments details, contractsand agreements, confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northeast-IndustrialManufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29213</link>
<guid>dc14e10c0ecf8029a86d27e74d140539</guid>
<pubDate>Fri, 30 Jan 2026 14:29:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northeast-IndustrialManufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb34539788616c38b582c3ad2f15addfab56190cfe2cbd5666b1445a85d8ab65</i><br /><br />Threat actor <b>description</b>: <i>Northeast Industrial Manufacturing (NEIM), founded in 1993, speci
alizes in high-quality goods and services tailored to the waste, 
recycling, scrap, oil, and gas industries. Their team boasts exte
nsive expertise, committed to delivering optimal services at comp
etitive prices.

We will upload 10gb of corporate data soon. Detailed employee per
sonal information, detailed financials, credit cards, payments de
tails, confidentiality agreements, NDA, contracts and agreements,
etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rocky-Mountain-Associated-Physicians</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29203</link>
<guid>4ce43eeff8805bee6936a5bcb383edc6</guid>
<pubDate>Fri, 30 Jan 2026 12:11:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Rocky-Mountain-Associated-Physicians</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>129def216fd5504b66c1371017327648c973d2196a4f91829ddc868cb99d1cef</i><br /><br />Threat actor <b>description</b>: <i>Utah’s Leading Bariatric Specialists, surgical & Medical Weight Loss Solutions in Salt Lake City</i><br />Target victim <b>website</b>: <i>utahbariatrics.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlantic-National-Trust</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29202</link>
<guid>d023867f3674a2d8514221428c6760ef</guid>
<pubDate>Fri, 30 Jan 2026 12:11:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Atlantic-National-Trust</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e095ebcd75b52daa0b74a08ab92e6c07b7c609e578fdddaaf5eecc793588994d</i><br /><br />Threat actor <b>description</b>: <i>Deals in commercial asset-backed loans, commercial real estate acquisition, secured lending, development and management</i><br />Target victim <b>website</b>: <i>atlanticnationaltrust.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>shorelinenyc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29200</link>
<guid>4dc78ee9d84aeec573c4179447b5f17c</guid>
<pubDate>Fri, 30 Jan 2026 10:41:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>shorelinenyc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9bb5fb05a1733d777c1b576414482c5a1f0244d56c5f13a83f34eabf73767ee</i><br /><br />Threat actor <b>description</b>: <i>Shoreline builders continuously raises the bar in excellence, quality and safety...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.roschvisionary.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29201</link>
<guid>6774b4304eb6167c263fa777644370aa</guid>
<pubDate>Fri, 30 Jan 2026 10:41:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.roschvisionary.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>519c56b462a2affe30812ee3110f34ab25ce84756d7a5537c38fe78d2219924c</i><br /><br />Threat actor <b>description</b>: <i>Rosch Visionary Systems specializes in software solutions designed specifically ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tulsa-International-Airport</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29199</link>
<guid>517cd23ae4375b47d04ef6363a229b13</guid>
<pubDate>Fri, 30 Jan 2026 08:12:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tulsa-International-Airport</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>965eec8aaaf8000a3a0fb7db6340925f55773b204e269726c364dbfa4130df42</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>flytulsa.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>NGC-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29135</link>
<guid>6e2559b077897e54a426cbdbd0bb05cc</guid>
<pubDate>Thu, 29 Jan 2026 19:33:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>NGC-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71a44300fa1f3d3c88cb1d3b235a1e29c9706cccdab2731dcba22412bbc7b7cd</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] NGC Software is a leading provider of Product Lifecycle Management (PLM), Supply Chain Management (SCM), Enterprise Resource Planning (ERP) and Shop Floor Control software and services for brands, retailers and consumer products companies. Founded in 1982, the company delivers solutions to help businesses improve their speed, productivity and profitability. Located in Miami, Florida, it serves clients globally.</i><br />Target victim <b>website</b>: <i>ngcsoftware.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crosslists-Data</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29131</link>
<guid>b21da80e55c4e85ed1270e4fafb702c2</guid>
<pubDate>Thu, 29 Jan 2026 16:45:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Crosslists-Data</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>85965ec8fb1c581bf7b1eb17892661a6c6a3ca37b298bb54946771e10709c4f1</i><br /><br />Threat actor <b>description</b>: <i>Crosslists Data specializes in providing high-quality new business data for marketers across the country. Their services include custom segmentation and data acquisition, catering to a diverse clientele that includes publishers and non-profits.We will upload 21gb of corporate data soon. Employee personal information (passports, DLs, address and so on), customers' financial and accounting files, contracts and agreements, confidential files, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>anomatic.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29134</link>
<guid>5831e536b6f7828e911b47c0f2525161</guid>
<pubDate>Thu, 29 Jan 2026 16:31:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>anomatic.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33f0902b7a9f53013e74ff38bd6c429aa2311048eaf261f4bbe173981cf93567</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1965 and headquartered in New Albany, Ohio, Anomatic is a full-service manufacturer of anodized aluminum and metalized packaging for the automotive, beauty, personal care, consumer electronics, pharmaceutical, medical devices, and spirits industries worldwide</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/anomatic-corp/6852027</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Easypak</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29129</link>
<guid>55f16320eb523947f12d2e94d9630c6e</guid>
<pubDate>Thu, 29 Jan 2026 14:16:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Easypak</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aea5beadcf9c29c2308a0c22eed4d0c9954f5a87394b9a827fb37713bd0c89fb</i><br /><br />Threat actor <b>description</b>: <i>EasyPak is a leading provider of thermoformed packaging solutions
for a wide range of industries and applications globally. We off
er dependable, high-performing plastic packaging for food, consum
er goods, medical, and industrial applications.

We will upload 70gb of corporate data soon. Very detailed employe
es (SSNs of 30  employees and other personal information), custom
ers' SSNs, lot of contracts and agreements, financials, confident
ial files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>BrandingBusiness</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29128</link>
<guid>24f1f625bd45de40d754ee728086e4dc</guid>
<pubDate>Thu, 29 Jan 2026 14:09:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>BrandingBusiness</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f591fa6cdaeded4f1c21a6ed4960564ecf484a49d4169b6aab1bb108303e5b72</i><br /><br />Threat actor <b>description</b>: <i>BrandingBusiness</i><br />Target victim <b>website</b>: <i>brandingbusiness.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Melton-Machine--Control</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29126</link>
<guid>a120cbe81a9c5d6c1f699e15a2691de8</guid>
<pubDate>Thu, 29 Jan 2026 13:32:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Melton-Machine--Control</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ded15b417c7135a0c7ea930f48af026077589cfc4c5f585bba8c67c3a5adec18</i><br /><br />Threat actor <b>description</b>: <i>Melton Machine & Control specializes in factory automation soluti
ons, offering a variety of products including robotic welding sys
tems, automated inspection systems, and collaborative robots. The
company provides tailored automation solutions across diverse in
dustries such as agriculture, manufacturing, and construction.

We will upload corporate data soon. Employees data (DLs, passport
s, SSNs and so on), contracts and agreements, financials, payment
details, clients' passports and other information, HR files, NDA
s and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MG-Oil</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29125</link>
<guid>00649cd10c9934e5bb72fe5beaf0f283</guid>
<pubDate>Thu, 29 Jan 2026 13:32:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MG-Oil</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5220ae8c5460db6d9cc7b47b510153e31605eba0b1f8175f4d10c57cd6228f1b</i><br /><br />Threat actor <b>description</b>: <i>M.G. Oil Company offers a diverse range of services including fue
l supply, convenience stores, lube services, and entertainment so
lutions through casinos and automatic vending. They are the large
st provider of video lottery and amusement machines in South Dako
ta and operate 20 convenience store locations focused on excellen
t customer service.

We will upload 35gb of corporate data soon. Detailed personal inf
ormation of almost all employees, financial information about lot
teries, a bit of customer files, confidentiality agreements and o
ther interesting internal data.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hillmann-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29122</link>
<guid>837e868ffbb3a67451e480e1864e071d</guid>
<pubDate>Thu, 29 Jan 2026 12:53:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hillmann-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0677c5106e88cd0c460456b4e90dfeb9bf2e684525a3535572b8d74d7efbfca4</i><br /><br />Threat actor <b>description</b>: <i>Hillmann Consulting is a nationwide construction consulting and d
ue diligence company that specializes in planning, managing, and 
executing construction projects. They offer a wide range of servi
ces including environmental health and safety, due diligence and 
remediation management, energy consulting, and construction servi
ces.

We will upload 116gb of corporate data soon. Employees' data (250
 DLs, passports, SSNs and so on), contracts and agreements, fina
ncials, HR files, confidential files, NDAs and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MACT-Health-Board</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29121</link>
<guid>394201ad68984c677be221f6d9f263fc</guid>
<pubDate>Thu, 29 Jan 2026 12:46:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>MACT-Health-Board</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb4378b227fc141a4e10b35a19515ffadf218fd1a2273eaa365dc611888732de</i><br /><br />Threat actor <b>description</b>: <i>MACT Health Board</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Property-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29119</link>
<guid>dc74d495021d5eb62f2a0dc42a47442b</guid>
<pubDate>Thu, 29 Jan 2026 12:03:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Community-Property-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d662f7c597ae02ae9a759dd4fac5d4418bc6913a1aeca03f3970902cc309867</i><br /><br />Threat actor <b>description</b>: <i>CPM rapidly evolved into one of the premier association managemen
t firms in the industry and is on the forefront of innovative and
specialized services. CPM has developed expertise in all areas o
f association management and keeps Board Members updated on law c
hanges. The firm specializing in the management of common interes
t developments including condominiums and planned unit developmen
ts. 

We will upload 67gb of corporate data soon. Large amount of detai
led clients' data, employee personal information (DLs, w-9 forms 
and so on), contracts and agreements, detailed financials (credit
cards, payment details and so on), confidential files and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>consultaegis.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29118</link>
<guid>857cd81e6a7d216eeaf1946a803a7d5e</guid>
<pubDate>Thu, 29 Jan 2026 11:31:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>consultaegis.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9aefe3bd4faadb3ea24b13c2b623ab882e2cca56f879e1e8d2ea57ac583f5183</i><br /><br />Threat actor <b>description</b>: <i>The data contains materials of national security including BIO laboratory facilities blue prints, and infromation regardless US army nitroglycerin supply chain.</i><br />Target victim <b>website</b>: <i>consultaegis.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>zallc.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29117</link>
<guid>a92df7cbfdddcc938abc806992026a19</guid>
<pubDate>Thu, 29 Jan 2026 11:29:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>zallc.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da1916b721409e8f39a7a258ef62fa1e5bf3a30e88b3806ae8c2ec96d9c98236</i><br /><br />Threat actor <b>description</b>: <i>PII data, SSN´s financial and audit reports.</i><br />Target victim <b>website</b>: <i>z*l*c.o*g</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weapons-License-Warren-County-Sheriffs-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29113</link>
<guid>a4db53c680ab731e9aa1eba01398bcac</guid>
<pubDate>Thu, 29 Jan 2026 09:41:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Weapons-License-Warren-County-Sheriffs-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e288e3d7cd60c933d2f32bb11adf142f7165ae3f701e2ad2cee945a7f07dc9ac</i><br /><br />Threat actor <b>description</b>: <i>The Warren County Sheriff's Office (Kentucky, USA), led by Sheriff Brett Hightower, is a professional law enforcement agency dedicated to protecting residents and visitors, upholding Kentucky state laws and the U.S. Constitution, and delivering comprehensive public safety services across the county. The office provides a wide range of functions, including proactive crime prevention, rapid incident response, equitable enforcement of ordinances and statutes, civil process execution, tax collection and administration, concealed carry permit issuance, and various community-oriented programs and educational initiatives. Headquartered in Bowling Green, the agency maintains a 24/7 operational commitment to emergency preparedness, integrity-driven community policing, and continuous improvement through citizen engagement and feedback to enhance overall safety and quality of life.</i><br />Target victim <b>website</b>: <i>warrencountykysheriff.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>NVHG.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29101</link>
<guid>0c61127c49ea5107f5088e2c93ed743e</guid>
<pubDate>Thu, 29 Jan 2026 08:50:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NVHG.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9346a25a94a55c2df83e5dba14ee5620440a834f6430b263d1b05d2d06d8acc5</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>WHEELOCKST.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29102</link>
<guid>d1f6b0f22fb84f1e2ee58c9481de0e5e</guid>
<pubDate>Thu, 29 Jan 2026 08:50:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WHEELOCKST.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f196b5b9e6bba711f1e563b27566ddaf6c4a43b874ed67f30980b47da0dbfd3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>DESKTOPG.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29103</link>
<guid>d6181e24bc01e4a832249fa9a2de8470</guid>
<pubDate>Thu, 29 Jan 2026 08:50:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>DESKTOPG.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d41ac22069eaee23f5732f2586970a94ba52f9a0590af4a229b327ee7fcec15</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LeMatic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29099</link>
<guid>3540a005ce1b9c61b8c40338a7fa3b56</guid>
<pubDate>Thu, 29 Jan 2026 00:43:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>LeMatic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e0c27272b1112a579f0ffdbde1f8b9de5b1a23812005ad1048caa2a470e37f9</i><br /><br />Threat actor <b>description</b>: <i>LeMatic is a leader in automated baking technology, offering innovations such as the AutoOp® and AutoEye® equipment lines to meet the evolving demands of the baking industry. Their product range includes solutions for slicing, packaging, basket handling, specialty systems, dough imprinting, pan cleaning, and robotics. LeMatic also provides aftermarket services, parts, and upgrades, ensuring customers receive the support they need for high-volume production and cutting-edge technology. Their intended clients include bakeries and industrial food producers looking for reliable and advanced baking solutions.</i><br />Target victim <b>website</b>: <i>www.lematic.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bumble-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29097</link>
<guid>0a9e30ce0e92f1f994081bd5a4ab7817</guid>
<pubDate>Wed, 28 Jan 2026 20:46:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Bumble-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79ab1944ce6aa18fafc6950ef5c81699af57c19e017daa4c48d771c5d61a447f</i><br /><br />Threat actor <b>description</b>: <i>Updated: 29 Jan 2026</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chu--Yang-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29093</link>
<guid>afb385227f5ff1dcd5c746974baf1060</guid>
<pubDate>Wed, 28 Jan 2026 19:41:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chu--Yang-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db96bac98b8ce6e57abc6c8e0ed884d2df7e545fdd0a60d30d720fbf524dc823</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Service-Broadcasting-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29095</link>
<guid>e6bbe250889b758c4007c91144c3fb6a</guid>
<pubDate>Wed, 28 Jan 2026 19:41:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Service-Broadcasting-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b792399894f3334e785963b5d0ca8c4d6dd1451fb3dbb6bf8e4b0a44b7496a6a</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>NessCampbell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29096</link>
<guid>19317b848dbb3dcbfb5684c662fd25ff</guid>
<pubDate>Wed, 28 Jan 2026 19:41:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>NessCampbell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f3fb0384f151bb64f8693883799c998ffac395ff75ea97b93a1456e16d5bfc5</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CMA-Flooring--Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29089</link>
<guid>d2cc6063bce8482e2cdf59d6a1885d73</guid>
<pubDate>Wed, 28 Jan 2026 16:47:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>CMA-Flooring--Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c255af0cbc5ff9f61813f61d6b2af6198a4a023c0d447ac7ceb281c7ed0854cf</i><br /><br />Threat actor <b>description</b>: <i>CMA Flooring & Design</i><br />Target victim <b>website</b>: <i>cmaflooring.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Family-Partnerships-of-Central-Florida</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29086</link>
<guid>b2a4e73b05f071e8167cb2ff945a2ffa</guid>
<pubDate>Wed, 28 Jan 2026 14:35:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>moneymessage</b> claims attack for <b>Family-Partnerships-of-Central-Florida</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04a4e404f65431c229f4867283e2dffe6d786aa41f6de1180b4985b84d260cb0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Family Partnerships of Central Florida is a non-profit organization that offers care for children with special needs. The services are aimed at enhancing the quality of life for children and their families by providing medical, emotional, educational, and social support services. They focus on early intervention and work directly with families to customize care plans for each child’s unique needs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>moneymessage</category>
</item>
<item xmlns:dc='ns:1'>
<title>tiw-group.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29083</link>
<guid>80f5c854f86f7ecdd80a84b2973a9b08</guid>
<pubDate>Wed, 28 Jan 2026 11:05:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>tiw-group.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>493e1163656c246a5ed510aabdbd9f4ee09437a1ad112da23b2a26c2f73f5333</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TIW Group is a specialist software firm with over 30 years of experience in developing solutions for the insurance industry. Their flagship product, ALIS, provides end-to-end solutions for life insurance and annuity processing. Additionally, they provide business process automation, legacy modernization, and risk compliance management services. Their digital solutions help businesses to streamline operations and improve business efficiency.</i><br />Target victim <b>website</b>: <i>tiw-group.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>KLMEQUITIES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29063</link>
<guid>13287c195ee2950c927824118a3a42b3</guid>
<pubDate>Wed, 28 Jan 2026 09:13:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KLMEQUITIES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa2b549939eb7da1428aa82389c72868e601a3fe505aacc35e3afc201e1e0f1e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>NYASPHALT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29064</link>
<guid>3a3fbf606d98da42ecaf1ed523ee083c</guid>
<pubDate>Wed, 28 Jan 2026 09:13:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NYASPHALT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>848ebb57c6e112843ca5a7be39250ef51d12250303e877d0e568aa22d7340487</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>KRIEGMANANDSMITH.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29065</link>
<guid>2562e666dd1a56d065589ec818bda84c</guid>
<pubDate>Wed, 28 Jan 2026 09:13:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KRIEGMANANDSMITH.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d631d796f34a745decbe846b29c657b6697f205226ebf6b1c5e56b432710c0d9</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GALEINTL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29067</link>
<guid>86d4303e4f27966fade0cf152d9ae234</guid>
<pubDate>Wed, 28 Jan 2026 09:13:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GALEINTL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30d8ea0c0e94d83279e3f1982d85c4d2ca1e187b202e4fa665fb9c99e6b81a49</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MCKEEGROUP.NET</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29069</link>
<guid>ec4ecf2f2dc2d3314c1d4cbd433b632b</guid>
<pubDate>Wed, 28 Jan 2026 09:13:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MCKEEGROUP.NET</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1f8a219efcf0c2ea4f518de780f012e35a5771a7ddb27c4b8124180d79f52ff</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ESCALI.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29070</link>
<guid>b76f4e72625e1782dd4758a45cbc1cd6</guid>
<pubDate>Wed, 28 Jan 2026 09:13:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ESCALI.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9744d65642f5bd5d2488d10c9c838c86eb2d9e27d48e82e687a53736010522a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>COBU-ARCH.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29071</link>
<guid>ba9353718aa3b1793b8a23d51e19ef15</guid>
<pubDate>Wed, 28 Jan 2026 09:13:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>COBU-ARCH.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc23bfb0ae85f18650abb405dfa7aee95066af248082709df55f3f9d3628711f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ARKTLA.ORG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29072</link>
<guid>ed5b4ad21f1090dc8bde85374a049f63</guid>
<pubDate>Wed, 28 Jan 2026 09:13:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ARKTLA.ORG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecee906145d058bc39ea8d8da3ee7d5f10c7f949000954627ac140916566c9bb</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>M-B.LAW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29073</link>
<guid>c8443b6213aa517f2d701ebf845fdae4</guid>
<pubDate>Wed, 28 Jan 2026 09:13:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>M-B.LAW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b70024906ea462ed764d84d989e65d10874a1560f19526d6e0d9eb2418e0c8dc</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>JLK-Rosenberger</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29050</link>
<guid>a30499ad9ae847c32510caccd5d2af71</guid>
<pubDate>Wed, 28 Jan 2026 01:05:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>JLK-Rosenberger</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2fb0a779e37515f0f626b1b03101603af2d06cb5f4f6db0e0dc115c827ce2657</i><br /><br />Threat actor <b>description</b>: <i>JLK Rosenberger LLP, Certified Public Accountants: A full service accounting and business advisory firm with offices in Irvine and Glendale, California and Dallas, Texas.  The firm is recognized as a Top 400 Firm by Inside Public Accounting and one of the largest auditors of insurance entities in the United States as ranked by Aon and AM Best  We have 300GB of data. Internal mail, accounting, company customer information and we will publish all the information next week. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>LGBTQ-Center-Orange-county</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29049</link>
<guid>58be01aa723db6569480940d2c1fde3d</guid>
<pubDate>Wed, 28 Jan 2026 01:05:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>LGBTQ-Center-Orange-county</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e95a78ec35c5e8353dc7afe9828284b7951515fbd58ab41ce71d0d04fb7347a1</i><br /><br />Threat actor <b>description</b>: <i>The LGBTQ Center OC was established as a volunteer organization in 1971 and incorporated in 1975 as a 501(c)(3) non-profit community-based organization. The Center provides services to more than 20,000 individuals annually across a broad spectrum of culture, ethnicity, age, and economic background.  We will publish all the information next week.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>DeRenzis--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29048</link>
<guid>8eeaabfc288f5918418dab1c7d300e4c</guid>
<pubDate>Wed, 28 Jan 2026 01:04:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>DeRenzis--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9760ebc600f2b70a6f04f4d3871ae16a3eff3aba18cdf11ecc1f3d510693890</i><br /><br />Threat actor <b>description</b>: <i>DeRenzis & Associates, LLP is a specialized accounting firm focusing on agriculture accounting for both dairy and farming sectors.  They offer services including financial statement compilation, income tax preparation, estate planning, and breakeven analysis.   We will publish all the information next week.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Affordable-Housing-Management-Overview-Metrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29046</link>
<guid>9c2847534128a1e12e08ba1fa9e2c29b</guid>
<pubDate>Wed, 28 Jan 2026 00:07:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Affordable-Housing-Management-Overview-Metrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46844a3e8223976f470636502c6805d476978354b0da35081f109e52a6f206a5</i><br /><br />Threat actor <b>description</b>: <i>Affordable Housing Management, Inc. (AHM, Inc.) is a nonprofit organization established in 1970 to address the housing needs of individuals in the community who may struggle to access quality housing. The organization is dedicated to developing and managing quality, affordable rental housing that enhances the quality of life and supports economic stability. AHM, Inc. operates multiple communities, providing essential housing options for its citizens. Through its initiatives, the organization aims to contribute significantly to local business growth and overall community welfare.</i><br />Target victim <b>website</b>: <i>affordablehousingmanagementmetrics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>JP-Research</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29044</link>
<guid>d6cb41a908909feead800375f0e96b04</guid>
<pubDate>Wed, 28 Jan 2026 00:06:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>JP-Research</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c952bfb8f8cabfbce4103b1c50d1ab078b620ff7ca30541e671dfe34d4177ba</i><br /><br />Threat actor <b>description</b>: <i>JP Research, Inc. is a leading US statistical and engineering research firm providing research and a broad range of litigation support services in the fields of automotive and consumer product safety. The company integrates advanced statistics, data analytics and engineering (mechanical, automotive, design, and bioengineering) disciplines to address global safety research problems. In bringing together highly specialized technical fields of expertise, JP Research’s approaches to problem solving frequently set the bar for future research. JP Research founded an international consortium to support a Road Accident Sampling System for India (RASSI), and has established a fully incorporated company, JP Research India, Pvt., Ltd., to pursue automotive safety research, accident data collection and crash investigation in India. Specialties Statistical Modeling,  Probability & Risk Analysis,  Class Action , Comparative Risk Assessment,  Claims, Consumer Complaints Analyses,  Statistical Significance , Failure & Reliability Analysis,  Regression Analysis,  Quality Control Procedures,  Review & Analysis of Police Accident Reports , Forecasting & Time Series Biomechanics and Automotive Engineering Statistical/Economic Evaluation</i><br />Target victim <b>website</b>: <i>www.jpresearch.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>FIAMPACK</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29043</link>
<guid>bfe671b7d65b8143e5a5e13d2415ec2c</guid>
<pubDate>Wed, 28 Jan 2026 00:06:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>FIAMPACK</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>15070ee0a46135ef7e452a096d508366654f399e1ca15c34724c49ced520630f</i><br /><br />Threat actor <b>description</b>: <i>FIAMPACK is a custom contract packager specializing in packaging solutions for the fragrance and cosmetic industries. They excel in combining metal, plastic, and glass materials to create innovative packaging designs. With locations in the USA and Asia, they leverage US engineering expertise alongside Asian manufacturing capabilities. Their experienced team focuses on delivering fast turnaround times for packaging projects.</i><br />Target victim <b>website</b>: <i>www.fiampack.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>anagnosdoor.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29042</link>
<guid>9b2946207cfe91ad1c5c5f4888f39cbb</guid>
<pubDate>Tue, 27 Jan 2026 23:41:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>anagnosdoor.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e114f5b1894a9bfec38ead774bf2eb49602ba71a00a30a196719a03320fc0ba2</i><br /><br />Threat actor <b>description</b>: <i>Anagnos Door Co. specializes in the sale, installation, maintenance, and servicing of commercial overhead doors and related products. Established in 1989, the company is well qualified to serve clients in the competitive construction market of the Chicago area. With a team of IDEA-certified fire door technicians, Anagnos Door Co. ensures high-quality service and expertise. Their primary clients include businesses in need of commercial and industrial door solutions. Employees: 50 Revenue: $8.6 Million Industry: Home Improvement & Hardware Retail Phone Number: (708) 728-9000</i><br />Target victim <b>website</b>: <i>anagnosdoor.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>nbccministries.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29041</link>
<guid>6aaf618580961e7d7d50f1a6aa246fa1</guid>
<pubDate>Tue, 27 Jan 2026 23:40:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>nbccministries.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8fcd86e482cb73af4420898fc56d0e1961924b2320344159bf236bf46732f79</i><br /><br />Threat actor <b>description</b>: <i>New Beginnings Church is a company that operates in the Religious Organizations industry. It employs 5to9 people and has under500K of revenue. The company is headquartered in Matthews, North Carolina. Employees: 25 Revenue: $5 Million Industry: Organizations  Phone Number: (704) 567-2900</i><br />Target victim <b>website</b>: <i>nbccministries.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Callagy-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29040</link>
<guid>8bd6aa50162ebeffc7294b652bc3ea4f</guid>
<pubDate>Tue, 27 Jan 2026 23:40:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Callagy-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>32cf16f402b4c68c2a2c5d4ca3ab7cc4c30073eecb68fa78256a25c191877e8a</i><br /><br />Threat actor <b>description</b>: <i>CALLAGY LAW, P.C. 650 From Road, Suite 240 Paramus, NJ 07652 callagylaw.com  This law firm specializes in various legal areas, including business litigation, personal injury, family law, and healthcare law. The firm is known for its commitment to providing comprehensive legal representation and has been operational since 1997.  Total data in the leak: 355 GB (480,169 Files, 38,388 Folders)  Leaked data: - Clients: companies and individuals - Data Classification: confidential, Private/Proprietary - Special data: Corporate email correspondence, external business correspondence, corporate documents,company policies and regulations,customer contracts and NDAs (Non-Disclosure Agreements),  court hearing materials and litigation case files (litigation documents),customers' personal data and their medical confidentiality (PII,PHI) and other related information.  - Financial data: financial metrics / financial performance data, invoices, payments, and other financial transactions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Match-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29037</link>
<guid>c30eae095af40e4bdefe6e0f1636eea2</guid>
<pubDate>Tue, 27 Jan 2026 22:44:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Match-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be0f14547c4ea10c718922ecaa83611ba01e248b380d2f214f5861b41a28565c</i><br /><br />Threat actor <b>description</b>: <i>Records: 10M Records | Updated: 28 Jan 2026 | Note: Your greed is killing you. | Don't be an idiot like this company. Make the right decision; don't be the next headline. Get off your moral high horse and make the right decision for your stakeholders. PAY OR LEAK otherwise you'll be made an example of.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>newkirklaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29035</link>
<guid>3156231783935e97c9ac263991fe57cc</guid>
<pubDate>Tue, 27 Jan 2026 20:40:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>newkirklaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01d2d100e319ef20e2413c0f78e02020e2df63c56ff6fb90daa23859a41dd511</i><br /><br />Threat actor <b>description</b>: <i>Newkirk Zwagerman, P.L.C. is a law firm based in Des Moines, specializing in employment law and advocating for employees' rights. They provide legal services to individuals facing discrimination, harassment, and retaliation in the workplace, as well as those involved in executive employment disputes and Title IX actions. The firm serves clients in Iowa and Minnesota, offering personalized legal representation to help employees navigate complex employment issues. With a commitment to fairness and accountability, Newkirk Zwagerman, P.L.C. empowers clients to stand up against larger corporate entities and seek justice</i><br />Target victim <b>website</b>: <i>newkirklaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gallagher-Transport-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29031</link>
<guid>3aa5bcc51a5e92cb51f514cc51391d4e</guid>
<pubDate>Tue, 27 Jan 2026 18:16:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Gallagher-Transport-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9769efbacbf75b0bff8c59077a08d0e7b5d554ecf39fede8f0f3ed6147d898c7</i><br /><br />Threat actor <b>description</b>: <i>Gallagher Transport International is a leading customs broker specializing in personalized and compliant freight solutions for importers and exporters. With over 25 years of experience, the company offers a full suite of services, including customs clearance, cargo insurance, and freight forwarding, while ensuring compliance with U.S. regulations. Their dedicated team focuses on proactive communication and personalized service to streamline the shipping process for clients across various industries, including FDA-regulated items, medical equipment, and specialty equipment. Gallagher Transport serves clients nationwide through multiple offices, aiming to make the transportation of goods as efficient and cost-effective as possible.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ashcraft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29030</link>
<guid>a0674936bd251655ff8e14e18c74b879</guid>
<pubDate>Tue, 27 Jan 2026 18:16:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Ashcraft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02e1824cc9ba87bed2baf8febb423cae5a2dfb31cc93936dca5c2bf17369a45e</i><br /><br />Threat actor <b>description</b>: <i>The Ashcraft Company is a HVAC manufacturers' representative based in the Dallas/Fort Worth Metroplex. We specialize in selling custom Heating, Ventilation and Air Conditioning (HVAC) systems and engineered solutions in North Texas.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>QualiChem-Metalworking</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29026</link>
<guid>bdf4880433deb05d33cd59e756e3ae6c</guid>
<pubDate>Tue, 27 Jan 2026 16:37:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>QualiChem-Metalworking</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1973de7233f1073ca4b86eff723badf16be11ae6ee110f97b26b3950b14b7fe1</i><br /><br />Threat actor <b>description</b>: <i>QualiChem, Inc. manufactures some of the most advanced metalworking fluids available in the world.</i><br />Target victim <b>website</b>: <i>qualichem.com</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Connor-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29021</link>
<guid>4a850ecfb32efa4f6e894ed5b631d445</guid>
<pubDate>Tue, 27 Jan 2026 14:43:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Connor-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6798453dfa8e52d16f2c10fa6622f91d5b08bda0e99b257bd611cf94b2f63d9c</i><br /><br />Threat actor <b>description</b>: <i>TThe company operates in the wholesale trade of engineering materials and equipment..</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goodmanagement</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29024</link>
<guid>614b785e10cceb93fb854958a5f93d1f</guid>
<pubDate>Tue, 27 Jan 2026 13:07:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Goodmanagement</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0ddf60b2638e1e33d4a0e678eab7f984c0420050f3e80e51348efba077c0585</i><br /><br />Threat actor <b>description</b>: <i>A professional hospitality management company</i><br />Target victim <b>website</b>: <i>goodmanagement.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Parts--Maintenance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29023</link>
<guid>1fee5d8b6b5230e47fc933334d03ff5b</guid>
<pubDate>Tue, 27 Jan 2026 13:06:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Global-Parts--Maintenance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>802e24d89e5c57232944358b6f8b779e0c5709ba903dd50e526e5d92cae3ec26</i><br /><br />Threat actor <b>description</b>: <i>Tailored procurement solutions and supply chain management</i><br />Target victim <b>website</b>: <i>globalpartsllc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>IMA-Diligence-Services-A-Division-of-IMA-Financial-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29022</link>
<guid>35f4421c476ab29bd7492717ccb0642c</guid>
<pubDate>Tue, 27 Jan 2026 13:05:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>IMA-Diligence-Services-A-Division-of-IMA-Financial-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>959b3a736d89d46e3e18e4055cac4ccb3a6d310b74f0cf9afde424419db0258e</i><br /><br />Threat actor <b>description</b>: <i>A provider of financial services</i><br />Target victim <b>website</b>: <i>.</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>MMD-Insurance-Law-Advocates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29019</link>
<guid>b9b5c1aceaf0491b0c041bca34418f07</guid>
<pubDate>Tue, 27 Jan 2026 10:39:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>MMD-Insurance-Law-Advocates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6519aa0a11d5bb4c006ec2cb56284491d42dd311c5f60d7230379c65597a37c6</i><br /><br />Threat actor <b>description</b>: <i>Dedicated to representing homeowners, business owners and condominium associations in insurance disputes</i><br />Target victim <b>website</b>: <i>mmdinsurancelawadvocate.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Trevino-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29018</link>
<guid>25557eaf26d046e1e08f4f8dfe82d1c4</guid>
<pubDate>Tue, 27 Jan 2026 08:35:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>The-Trevino-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26738709910915054a869e2b79988690990d8a8d0fafdf817128f6c9ced2e895</i><br /><br />Threat actor <b>description</b>: <i>WE HAS COLLECTED SUCH DATA AS:   - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Drawings  And a lot of other VERY IMPORTANT information! </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>OEC-Medical-Systems-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29017</link>
<guid>db649c1d69f2a2d2af63f4c5567e7244</guid>
<pubDate>Tue, 27 Jan 2026 03:11:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>OEC-Medical-Systems-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>086504fc315ebd3cd0a2940e8aa6743f3c85d8410651c2ba80198ff0fca72a6e</i><br /><br />Threat actor <b>description</b>: <i>OEC Medical Systems, Inc</i><br />Target victim <b>website</b>: <i>oremeyeclinic.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Panera-Bread</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29016</link>
<guid>85c8395916ffc2198dd670da1b20d108</guid>
<pubDate>Tue, 27 Jan 2026 00:19:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Panera-Bread</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c2d73a38063a58b2855c7ec0d0c0dae7313b416bbbb04444e6a713512dbd53e</i><br /><br />Threat actor <b>description</b>: <i>Records: 14M Records | Updated: 27 Jan 2026 | Note: Don't be the next headline. | Don't be an idiot like this company. Make the right decision, don't be the next headline.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>freidarothman.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29015</link>
<guid>5ff4fb7b73fa956e5a0382824f85c96a</guid>
<pubDate>Mon, 26 Jan 2026 23:19:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>freidarothman.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>633a8c8bec8bf143e24a1c87ad1e66ba24148e7e1098ca9e5b251fd36859a587</i><br /><br />Threat actor <b>description</b>: <i>Based jewelry and accessories brand founded and led by designer Freida Rothman, who grew up in Brooklyn and comes from …</i><br />Target victim <b>website</b>: <i>freidarothman.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tele-Plus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29010</link>
<guid>636e0538092a048a7d49aa0b20e2bff1</guid>
<pubDate>Mon, 26 Jan 2026 19:42:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Tele-Plus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47960c683c4163154abc6fb587b5c952c5ec4c2f6f9a4bebd4c3efd567ba8e8</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.telepluscorp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>FB-Mfg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29009</link>
<guid>6e4c10382ea6d02e196ebcab34cfbffb</guid>
<pubDate>Mon, 26 Jan 2026 19:41:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>FB-Mfg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8cfb78e701b3e811d33be6098dda4433e262a4a643b2c84e34af3320bacf153f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.fbmfg.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Sourcing-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29008</link>
<guid>ae7a1abc672c5913a8338992ec6b7e72</guid>
<pubDate>Mon, 26 Jan 2026 19:41:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Sourcing-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22e2e1213ab649261d7a4fa540ea51c4b7e3f1b3e746ca35eebe4c3b7078610a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.thesourcinggroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quantum-Fuel-Systems-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29006</link>
<guid>11a5b5ef81cff76a0a1f3d042f635df3</guid>
<pubDate>Mon, 26 Jan 2026 19:40:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Quantum-Fuel-Systems-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33d13ac46c5b8dc07ae6b8404514715b96f309a8aa54b5707cbbf447b849737f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.qtww.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aquatic-Control</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29005</link>
<guid>3484e1bac36fc0d1f0e86ae3b5aed870</guid>
<pubDate>Mon, 26 Jan 2026 19:39:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Aquatic-Control</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a64ef84dde6f508d29a471b30c20b31040a38aacd0e1acba38bea45f3cfc9c1e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.aquaticcontrol.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Christine-London</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29004</link>
<guid>a5526b5c1e15754a534e9ff97728a32f</guid>
<pubDate>Mon, 26 Jan 2026 19:38:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Christine-London</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b852ed7c12dbcd8c905b79d4acb9be9bc2945578ba6d0041725d5bd3b0d8aa20</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.christinelondonltd.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Routten--Laster-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29003</link>
<guid>7a1e01c1f482effc90f8e7d0e2581aff</guid>
<pubDate>Mon, 26 Jan 2026 19:38:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Routten--Laster-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4884feab9a4f0d27b6e423d676e66cb21dcbb26c021e8ca93b9096a0f6677c5</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.routtenlasterlaw.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Joyva</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29002</link>
<guid>8d0e8d50eb0bad1727b38382d4fa42ef</guid>
<pubDate>Mon, 26 Jan 2026 19:37:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Joyva</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6d6f4b9288e51d8d95fba6e06a0eb29e73da144dc32ac96aa2205aec788674b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.joyva.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.shrimphouse.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=29001</link>
<guid>1c76fb9381aac8712c2d06e31a05702b</guid>
<pubDate>Mon, 26 Jan 2026 19:05:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.shrimphouse.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25ec0cd837d63199627adc3d02beb2a21aba6f5e5131e4c3dbd7c45d35b6babe</i><br /><br />Threat actor <b>description</b>: <i>1tb data </i><br />Target victim <b>website</b>: <i>www.shrimphouse.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prince--Schmidt-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28998</link>
<guid>a75a8ecb7cea780ca37daff6501c60a2</guid>
<pubDate>Mon, 26 Jan 2026 14:51:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Prince--Schmidt-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3a7f5cd5e528d7058dabd825258de196e96d21baf593bd956a60af968e3c1d0</i><br /><br />Threat actor <b>description</b>: <i>Prince & Schmidt LLP</i><br />Target victim <b>website</b>: <i>LawForPersonalInjury.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mills-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28972</link>
<guid>80577d9cb5c479e8e8b85252f1bfe005</guid>
<pubDate>Mon, 26 Jan 2026 04:54:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mills-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54d3b6e0eff03968a7321b414f582b9b8d407f9429f81b18a3938539c0f2b961</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WRENLAWFIRM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28947</link>
<guid>7b905b5bd19b35cf3f9d762aa6acaa45</guid>
<pubDate>Sun, 25 Jan 2026 16:56:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WRENLAWFIRM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ddc86437d01ad8d85ea87fba09c6969738e2428c9461e87e004d21c47379651</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LDHRLAW.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28948</link>
<guid>ef9ffa986fa98b2485fe6b57ac0c6b1b</guid>
<pubDate>Sun, 25 Jan 2026 16:56:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LDHRLAW.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d11424513ab444c1be9b39a3f2df86a94a66a20834654d0673e28ac1810e96ee</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GENESYSSPINE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28949</link>
<guid>d8eab7a13d4255428253eef1b2e64b0d</guid>
<pubDate>Sun, 25 Jan 2026 16:56:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GENESYSSPINE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eaecfabff4933e01cde3c1f813a3ab28a399e5d184e0401895be1f33f169f7c0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HILTON.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28950</link>
<guid>713a6858eec9a67eeff4b55c6184656a</guid>
<pubDate>Sun, 25 Jan 2026 16:56:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HILTON.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9133cc851594f68819a59b0ad430c879235508ebd4bc080377a92ffe41266e53</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>WEATHER.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28951</link>
<guid>110eed2c630aab0f3fa87d6473926732</guid>
<pubDate>Sun, 25 Jan 2026 16:56:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WEATHER.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8250c2f05b6e93bdfca173f3ac1403e9092356c7f83ffb3f2d07e4b2d32e2b3f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>RTCCOMPUTERS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28954</link>
<guid>ae0da2b96cb66af397177a53a709860e</guid>
<pubDate>Sun, 25 Jan 2026 16:56:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>RTCCOMPUTERS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9159a67d92f91b818909dcd0c0fbd4b8fb0265c44ff20f5cb5152de6b5450549</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>4DITSOLUTIONS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28961</link>
<guid>091de388b6057d21b628726885c2b0db</guid>
<pubDate>Sun, 25 Jan 2026 16:56:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>4DITSOLUTIONS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf8350a6fea92073056d5fbd9e92fe7b873e7e2fc5c2ba1f8778b1ec357cee92</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>VISTA-TRAINING.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28962</link>
<guid>5103ae07e6b7cd584364696695b075de</guid>
<pubDate>Sun, 25 Jan 2026 16:56:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>VISTA-TRAINING.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf4d9beaeee6245d698dc80fc56c3e90a3a6a6bbb9a9278bb6e463338f41526a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>WILDRIDGELANDSCAPE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28964</link>
<guid>f9aa778d602c7ba036e50f85deeb7250</guid>
<pubDate>Sun, 25 Jan 2026 16:56:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WILDRIDGELANDSCAPE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0048fa1a9ef007cfa6fad5418383ea620e8128d408f47fc82fdf4e46aaad9a61</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INSPYRSOLUTIONS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28966</link>
<guid>0421c02f0fc9cebfa39a613c3c59c3e2</guid>
<pubDate>Sun, 25 Jan 2026 16:56:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INSPYRSOLUTIONS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb4c3a9bad8306e40112ef022ea13b9f89bc63e6cb05565ea8a490c1777b8eb6</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>EXCELAS1.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28968</link>
<guid>1b3c1623c5c98ad8549b8f62670d1f52</guid>
<pubDate>Sun, 25 Jan 2026 16:56:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>EXCELAS1.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5cd04d2f6ec5d04acdbeffb9759bc550a45b1709fab83c1e2c173a65571ce1bc</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cytek-Biosciences</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28989</link>
<guid>1fcf9224f1f09a97ad293c680a215696</guid>
<pubDate>Sun, 25 Jan 2026 12:48:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Cytek-Biosciences</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74b9a99420087f3d4e2cb8519261bbc578e5408dc6d8421f54fa192819fd65e9</i><br /><br />Threat actor <b>description</b>: <i>Cytek Biosciences Cytek Biosciences is a leading cell analysis solutions company founded in 1992 and headquartered in Fremont, California with global offices across North America, Europe, and Asia.   Sold   0%   																					All data was sold, stay with us, we will upload new Companies later 																			  More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Successful-Match</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28987</link>
<guid>6acf2725b339ee1695ebf86253f75221</guid>
<pubDate>Sun, 25 Jan 2026 05:19:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>The-Successful-Match</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca47767a67184d0381b8e2e75654f106776610d45da0c71fb996c26168d59021</i><br /><br />Threat actor <b>description</b>: <i>The Successful Match (MD2B)</i><br />Target victim <b>website</b>: <i>thesuccessfulmatch.com/publishing</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shiffler-Equipment-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28940</link>
<guid>ad1dc188240785dd12c21e40524dbbcd</guid>
<pubDate>Sat, 24 Jan 2026 20:43:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shiffler-Equipment-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>977466ee5ac81ae339bd605d76497086cd52d21d329e01a33ec031464c5f321c</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>D--D-Building</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28942</link>
<guid>938abaff15ddc97965b156b23136c1c9</guid>
<pubDate>Sat, 24 Jan 2026 20:43:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>D--D-Building</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>150e7a8cbc9147392cfc39a340d55c8684458d38b87507a82211d64fdc508e27</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>gsglobalresources.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28980</link>
<guid>4bd5096853abc791756085adf90dfe7f</guid>
<pubDate>Sat, 24 Jan 2026 20:21:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>gsglobalresources.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ebcf7722de5feea78a2d49f8f01f2b208bba78ee4473890e1352ac5a56592cc</i><br /><br />Threat actor <b>description</b>: <i>GS Global Resources (often abbreviated GSGR) is an American industrial engineering and machine-performance solutions company headquartered in Mukwonago, Wisconsin. Founded …</i><br />Target victim <b>website</b>: <i>gsglobalresources.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>trulinemfg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28977</link>
<guid>2c09b237b3fe0a29b7ae5b63cd8632aa</guid>
<pubDate>Sat, 24 Jan 2026 20:19:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>trulinemfg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9c1b0a2b62e78646be190226d2ba422ab58e4b48c2d27b201c6fb6446ed72b1</i><br /><br />Threat actor <b>description</b>: <i>Tru-Line Manufacturing Company is an American industrial fabrication firm headquartered in Decatur, Alabama that specialises in the metal fabrication of …</i><br />Target victim <b>website</b>: <i>trulinemfg.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>superiordrywall.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28976</link>
<guid>cd65710fc56d8163dfaed043e4129690</guid>
<pubDate>Sat, 24 Jan 2026 20:19:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>superiordrywall.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f03c5034877d5543c330fdab39655132f7c6c73f79e1f52cead570906c081f8b</i><br /><br />Threat actor <b>description</b>: <i>Superior Drywall is an established American commercial drywall contracting company based in Oxnard, California, specialising in a range of interior …</i><br />Target victim <b>website</b>: <i>superiordrywall.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Herzing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28943</link>
<guid>d37b9e2b497aa9312965a132d98279b0</guid>
<pubDate>Sat, 24 Jan 2026 19:43:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Herzing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4bd807f444129e62525c949e38762fcea3fe14b474b3550794082fb54f721f84</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.advancedcoolingtech.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28938</link>
<guid>dd0e5d3313b032ce56c959d25e1beee1</guid>
<pubDate>Sat, 24 Jan 2026 08:41:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>www.advancedcoolingtech.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>592dcb9db769c5b063a4fe20e4741765367abe6cf3b63a51bd50a503cf333ed2</i><br /><br />Threat actor <b>description</b>: <i>Advanced Cooling Technologies, Inc is a leading provider of medical cooling solutions, specializing in the distribution of Airsys Medical Chillers in the USA. T...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>IGI-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28934</link>
<guid>437bce6c54114f437f169de31d370f1b</guid>
<pubDate>Fri, 23 Jan 2026 15:42:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>IGI-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45696fef424c5425fc5392876adaa22cdf7d72a4d53f15dc84085320209fcec8</i><br /><br />Threat actor <b>description</b>: <i>IGI Global is an international academic publisher committed to producing the highest quality research and ensuring the timely dissemination of innovative research findings through an expeditious and technologically advanced publishing process.We will upload 220gb of corporate data soon. Employee personal information (passports, DLs, credit card details, health information), financials, contracts and agreements, NDA, confidentiality agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Uinta-Bank</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28930</link>
<guid>b4feeda018954b3a901f25f66e7f911e</guid>
<pubDate>Fri, 23 Jan 2026 00:44:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Uinta-Bank</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3afb0787548fb3e08c7a1c275e10309f9721a996d4219a0907bfee37eea0b3c</i><br /><br />Threat actor <b>description</b>: <i>Established in 1919, Uinta Bank is a community bank headquartered in Mountain View, Wyoming. Uinta Bank is proud to provide community banking to the individuals...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ECA-USA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28919</link>
<guid>aabcec3c1485362f5f588135883d37b6</guid>
<pubDate>Thu, 22 Jan 2026 20:08:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ECA-USA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd0292fc6d14281c73b6af0031c1f7f15dd11d9e301bc1e56702a80a891f3e35</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ITROBOTICS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28923</link>
<guid>ad0e9e545bd1d949dcf019ce06a2ae95</guid>
<pubDate>Thu, 22 Jan 2026 20:06:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ITROBOTICS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de37994127bc54dba924219f05adb5215dace7b23c65e8a055188bfd32d3dc61</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MONTALBAARCHITECTS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28924</link>
<guid>71d54f4b09795d02cbc6959c1145e886</guid>
<pubDate>Thu, 22 Jan 2026 20:05:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MONTALBAARCHITECTS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f14ac53fbf7d75cea9ff27138d578570cc194e7aa4bf1a0db71f237145aef61</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>-AERIFY.IO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28926</link>
<guid>e9abec5e32203998211653b45023be1c</guid>
<pubDate>Thu, 22 Jan 2026 20:04:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>-AERIFY.IO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>760ab3518105213ee29dc8185733997c09ae2506ca6ad2e2405e4bd756f11466</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SMITHDALIA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28928</link>
<guid>6e92962008491b24a803ff3b7d61734b</guid>
<pubDate>Thu, 22 Jan 2026 20:03:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SMITHDALIA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d870ff39c0de75d5cbaeb26d2db2199ae0bbe9244da6d486e0738d839b8ab59</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ELKAIR.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28929</link>
<guid>fbcefc201bbac612e5ff6b96c64e2465</guid>
<pubDate>Thu, 22 Jan 2026 20:02:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ELKAIR.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c701b5cefbd620c0b2e91d871ddf6fc727e1402fc9f3fc1cf9e77abaa725020</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nike-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28913</link>
<guid>9a985e5d14e44dc2c97d12877dd7cd8c</guid>
<pubDate>Thu, 22 Jan 2026 18:43:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Nike-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42dd1ceed496f7070766615ba77fdbdf93c21ceb705b72fe0de0a65c4c0436a6</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>EDF-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28915</link>
<guid>5f69e19efaba426d62faeab93c308f5c</guid>
<pubDate>Thu, 22 Jan 2026 17:44:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>EDF-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6530b80e5274cf6769c36a5b269dc4a98261a7fbce205e1817de3f698584a09</i><br /><br />Threat actor <b>description</b>: <i>Electronics</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Universal-Builders-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28910</link>
<guid>d2a83dc418ee9d6209d8356fca703f13</guid>
<pubDate>Thu, 22 Jan 2026 16:44:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Universal-Builders-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9bd9cc1c45133052b37a37117e3728c4521f5f9cf8f56491c6f40e5fe2143c5</i><br /><br />Threat actor <b>description</b>: <i>Universal Builder Supply (UBS) specializes in innovative scaffolding, hoisting, protection, and access solutions tailored for major construction projects. Since 1931, they have focused on delivering custom-engineered scaffolding and hoisting systems used in prestigious projects worldwide, including the Statue of Liberty andGrand Central Station.We will upload 22gb of corporate data soon. Detailed employee personal information (addresses, SSNs, passport and DL scans, bank account information, credit cards and so on), HR files, financials, project files, projects, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spiros-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28912</link>
<guid>32c12acc9a2efc3fa896bb3ebcd47ee7</guid>
<pubDate>Thu, 22 Jan 2026 15:43:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Spiros-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30ebe963ab2632217f060a90dc8ac9757694c0e203460f701fc1f1688798b685</i><br /><br />Threat actor <b>description</b>: <i>Spiros Industries is a custom manufacturing company specializing in precision springs and wire forms, known for its commitment to quality and expertise. They serve various industries, particularly medical, firearms, and packaging, and offer services including prototyping and specialty packaging.We will upload over 20gb of corporate data soon. Detailed employee personal information (w4 forms, passports, DLs medical information, credit cards and so on), customer files, financial and accounting information, contracts and agreements, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Service-Lane-eAdvisor</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28907</link>
<guid>2d95d0882174e6abcf9ebe52b57a61a1</guid>
<pubDate>Thu, 22 Jan 2026 10:24:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Service-Lane-eAdvisor</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4150e845b78e051d709df9dc05c809cfda62f28bf649351a45a267136088902</i><br /><br />Threat actor <b>description</b>: <i>Service Lane eAdvisor</i><br />Target victim <b>website</b>: <i>sleadvisor.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>OnSight</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28906</link>
<guid>71f7e51efde5fe99cc2d6dbd64e1319c</guid>
<pubDate>Thu, 22 Jan 2026 00:29:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>OnSight</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>530a21e0ce4401c05f988438ec808c11ac745fabeaca7bda3438dc63c788b4ef</i><br /><br />Threat actor <b>description</b>: <i>ONSIGHT is a leading production facilities company, specializing in services to the film and broadcast industries. The suite of services range from equipment rental through to post production and DI finishing. Conveniently based at Shepperton Studios, the camera department supplies high-end digital cameras and 2D or 3D production equipment. The award-winning post production team is located in Soho, London and offers editing systems with 24/7 technical support, a digital lab, and a full 2D or stereoscopic 3D post service. Renowned for innovative technology and groundbreaking 3D, ONSIGHT works closely with key manufacturers and is an official service provider to the premier 3D broadcaster, BSkyB. Recent 3D credits include the BAFTA-winning Flying Monsters 3D With David Attenborough (Atlantic/Sky 3D), Madam Butterfly 3D (a co-productionfrom RealD and the Royal Opera House, produced by Principal Large Format), Flight of the Butterflies in 3D (SK Films), Kingdom of Plants 3D WithDavid Atten</i><br />Target victim <b>website</b>: <i>onsight.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>CE-Electronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28905</link>
<guid>e2e57ded5b59a2058dd5855564c6b5ea</guid>
<pubDate>Wed, 21 Jan 2026 21:58:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>CE-Electronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d375f6b5273b45ca049e7d869d7c977a12f234e5b0c106e1487bb16445223d85</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ceelectronics.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cemtech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28904</link>
<guid>0ebd0b8b51eb0d0062065a7657486c8e</guid>
<pubDate>Wed, 21 Jan 2026 21:57:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cemtech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>071e70add9ec0c2ede9cd468e8c196d854ad02b1230d3254587c8d8cfda67b16</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cemtech-corp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Midway-Windows-and-Doors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28903</link>
<guid>a007685ecc0ccf820b8ac1d6e77f69fd</guid>
<pubDate>Wed, 21 Jan 2026 21:00:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Midway-Windows-and-Doors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7d14553eb31d3d9563e7d4593a1ee35ada81aebfe4122949af767162755dc67</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.midwaywindows.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bayside-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28899</link>
<guid>bdddf7327677bbfc879f505df7122e2e</guid>
<pubDate>Wed, 21 Jan 2026 19:50:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bayside-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6a760930da7d32376796b66542456e2256242a0caee7ba474556ef9ce6224be</i><br /><br />Threat actor <b>description</b>: <i>Are you looking for a dentist in Rowlett, TX, 75088 near Mesquite? Bayside Dental offers general, restorative & cosmetic dentistry services.</i><br />Target victim <b>website</b>: <i>www.baysidedental.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ShuBee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28898</link>
<guid>95b428e98d2b66a8ab324313cfc45300</guid>
<pubDate>Wed, 21 Jan 2026 19:03:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>ShuBee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a2c221a01277c27e3cd8063233d1b1379ff70f2e75e18839c8f7982ef7a7230</i><br /><br />Threat actor <b>description</b>: <i>ShuBee is a company providing care wear to service companies. It offers products such as shoe covers, disposable coveralls, service mats, gloves, and cleanup essentials. The company was established in 2000 and is headquartered in Macon, Georgia.</i><br />Target victim <b>website</b>: <i>www.shubee.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clipper-Petroleum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28886</link>
<guid>cbc39d6ea03f171f1349ce64dc0529c9</guid>
<pubDate>Wed, 21 Jan 2026 17:44:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Clipper-Petroleum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8da438b5835d97824cc0a8ddf00968c2de5080c5b33dbc79b5d1d98ce89ed514</i><br /><br />Threat actor <b>description</b>: <i>Clipper Petroleum is a petroleum marketer based in Flowery Branch, Georgia, with over 90 years of experience. The company operatesas a convenience store and fast food retailer while also servingas a wholesale fuel distributor.We will upload over 60gb of corporate data soon. Customer and employee personal documents, internal confidential files, detailed financial and accounting information, contracts and agreements, credit card details, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Serometrix-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28896</link>
<guid>10164f723a34e25cd518da38b02af653</guid>
<pubDate>Wed, 21 Jan 2026 15:53:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Serometrix-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>400eeb3dd833239b31c677679218aa56210b20a5660d3d45d29c579821b8286c</i><br /><br />Threat actor <b>description</b>: <i>Serometrix LLC</i><br />Target victim <b>website</b>: <i>serometrix.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Orthopaedic-Specialists-of-Massachusetts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28887</link>
<guid>f0ab8e556d0cbb5c0e4201791cfaeae0</guid>
<pubDate>Wed, 21 Jan 2026 14:18:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Orthopaedic-Specialists-of-Massachusetts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4dde1b9a66089957808ceebd60369ccba1ae961069b5cab2f0f285f320b9f8b</i><br /><br />Threat actor <b>description</b>: <i>Orthopaedic Specialists of Massachusetts provides superior orthopaedic and sports medicine care through a team of expert surgeons and physicians. Their services include surgical and non-surgical treatments for a variety of orthopaedic issues, such as arthroscopic surgery, joint replacements, and sports medicine. With locations in Norwood, Milton, and Sandwich, MA, they cater to patients of all ages and offer expedited appointments. The practice is dedicated to delivering compassionate care and improving patients' health and quality of life.</i><br />Target victim <b>website</b>: <i>www.orthomass.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>KOROLFINANCIAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28869</link>
<guid>1164caada87d881437173e9a15f78aa5</guid>
<pubDate>Wed, 21 Jan 2026 14:07:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KOROLFINANCIAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45de2b27096603758dfa0b51e01cf79040624b3f2f2aa987699998b60331eef2</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MCMATHLAW.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28872</link>
<guid>1a21d8c9bbb99bca627434dbf4b98d01</guid>
<pubDate>Wed, 21 Jan 2026 14:05:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MCMATHLAW.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>287dedd9ad63df45c906e47e22ea22f64c71b410d9d8ec6091d5b1bd19c27fad</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>WORKFORCESOFTWARE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28873</link>
<guid>ccfed80e87ba3e3a64b55176df02a9d5</guid>
<pubDate>Wed, 21 Jan 2026 14:04:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WORKFORCESOFTWARE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a729b3af0606b8f1a2a559995a1cec395418879dbde5bc0a57094e25d6b70f3f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>KCDWORLDWIDE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28874</link>
<guid>192188b239173a6a0c88762b38d97f65</guid>
<pubDate>Wed, 21 Jan 2026 14:04:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KCDWORLDWIDE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0123aafbe67314a43b9ac85f7527c9d25cafdf51006cc6993b0e760f8ea76701</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ONYXEQUITIES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28875</link>
<guid>bd74971af53184c9911331d4f7bdb4a0</guid>
<pubDate>Wed, 21 Jan 2026 14:03:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ONYXEQUITIES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd9e9e243cb411bbe1ad4ecfd205332242e5cded933676d979173db940811fd0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jet-care-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28895</link>
<guid>de7e76952411d036ca4b58ffcf37bfe7</guid>
<pubDate>Wed, 21 Jan 2026 13:54:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Jet-care-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ede2f6886f7a852a567ee0469db2794e411cf72deae593d7ece5a7ccffa08f39</i><br /><br />Threat actor <b>description</b>: <i>Jet-care International</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>us-duct.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28877</link>
<guid>4ce2dc45f5dcc0b44e0162f8dc4ea237</guid>
<pubDate>Wed, 21 Jan 2026 13:44:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>us-duct.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b5c19fda958169c8b926bea7f22aad1c61f2c81f1c4056ad907716a0e2e466f</i><br /><br />Threat actor <b>description</b>: <i>US Duct Inc. is an American private company engaged in the design and manufacture of industrial duct...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>INTEGRITEK.NET</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28881</link>
<guid>27b5429c1dcf4774c3ee26cd87e3f0df</guid>
<pubDate>Wed, 21 Jan 2026 13:32:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INTEGRITEK.NET</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8569ba6c2044fab41d4e0070837e1c4f41f5ce2998094f79c2626f1127b209e4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>automax.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28888</link>
<guid>6cd4d4f7768fc86ca5642be0f600b518</guid>
<pubDate>Wed, 21 Jan 2026 13:26:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>automax.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4fbfa78bc8710dc06826a717060b543c4d37c13262c8b85ed2dca716121a3c0c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] AutoMax.com is a leading used car dealership group in the US. Known for its wide range of high-quality pre-owned vehicles, AutoMax.com provides affordable options with comprehensive auto inspection and warranty. They offer financing options for all credit situations. The company is committed to delivering excellent customer service through its knowledgeable and friendly staff.</i><br />Target victim <b>website</b>: <i>automax.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.saundersandsaunders.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28894</link>
<guid>1ed021a05ef5089233379be996f7bbdd</guid>
<pubDate>Wed, 21 Jan 2026 13:16:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>www.saundersandsaunders.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a527828de7bc935df51897c8045ca35ccd1d7db60a61075b223a7d4de2430932</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>www.saundersandsaunders.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>WRP-Asia-Pacific-Sdn-Bhd</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28852</link>
<guid>e1b036022a6aaa7d187caae163216533</guid>
<pubDate>Tue, 20 Jan 2026 19:08:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>WRP-Asia-Pacific-Sdn-Bhd</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b61365a8620402fefe942f64ababf308797bc710f4f8c2d14782d1ad3ef61c68</i><br /><br />Threat actor <b>description</b>: <i>www.wrpworld.com https://www.zoominfo.com/c/wrp-asia-pacific-sdn-bhd/346914589 WRP is one of the world's leading manufacturing and distributing groups producing premium quality gloves for the medical, dental, food and critical environment market. Headquartered in Malaysia, WRP's manufacturing facilities are located in Malaysia and Indonesia. We implement a quality assurance program which is consistent with US FDA's latest Quality System Regulation (QSR) guidelines, and our manufacturing and quality systems are certified to EN ISO 9001 standard. Our products are in full compliance with ASTM standards as well as the European Medical Device Directive 93/42/EEC and, where such is the case, with the national standard transposing harmonized standards EN455 Parts 1, 2 & 3. In order to serve our customers better, we have established a marketing office located in Uniontown, Ohio.</i><br />Target victim <b>website</b>: <i>www.wrpworld.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Release-Marine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28843</link>
<guid>4e17f2a258effb8ae350f8a8062d9a4c</guid>
<pubDate>Tue, 20 Jan 2026 15:58:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Release-Marine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9958cff5c0af92d71fa0031a917e61bd5a64806307922567eb3b8b0c2ae5a77</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.releasemarine.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Raymundos-Food-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28842</link>
<guid>abd146bcead71b89b0d035473288f07a</guid>
<pubDate>Tue, 20 Jan 2026 15:57:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Raymundos-Food-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>770e2b14e93a0e38f0493b107c6ca460ce3436a33c9dc40d7a2b9d8a5f4f4d3f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.raymundos.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Riverwood-Golf-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28841</link>
<guid>92b5e9dae4200367fc5d494d3af0690e</guid>
<pubDate>Tue, 20 Jan 2026 15:56:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Riverwood-Golf-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48c26d3deb5e94e2e763fc7f6bcd1aba52575d26aec5ab99b75a0a4bdfff49c0</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.riverwoodgc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eastern-Ice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28840</link>
<guid>fe5e746f078fb13928d9558651397be2</guid>
<pubDate>Tue, 20 Jan 2026 15:56:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Eastern-Ice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16f24571befba140e54e079439d38d287d25217f773daf2f8ae3c13a089831c9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.easternice.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ciena</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28839</link>
<guid>b946c734affd9d4de72dd92957bfc9f8</guid>
<pubDate>Tue, 20 Jan 2026 15:23:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Ciena</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6bedfa4e98fee2afbfd920af1bec96e9daf95df65a321469a617c2b0909815e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Ciena Corporation is a US-based global supplier of telecommunications networking equipment, software, and services. The company's solutions support the delivery of voice, video, and data traffic for many of the world's largest telecom service providers. Its product portfolio includes solutions for optical transport, broadband access, data center connectivity, and software automation. It was founded in 1992 and headquartered in Hanover, Maryland.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>ETC-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28834</link>
<guid>46116d4f0bc6e57e0d8d0ea4274c38f0</guid>
<pubDate>Tue, 20 Jan 2026 14:39:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>ETC-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b711bac9157aa459a53630ff6bb546889b261b02a47d63226fe85b944edaff6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "ETC Companies" is an American consulting company that specializes in providing solutions for employee benefits, HR technology, payroll, and risk management. The company aims to deliver customized programs, strategic planning, and relevant insights to help businesses in different fields efficiently manage their staff and employee services. It offers services like compliance reporting, compensation analysis, among others.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>TriApex-US-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28823</link>
<guid>263903fbcdfed99b3332d4f0ee123e66</guid>
<pubDate>Tue, 20 Jan 2026 01:23:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>TriApex-US-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f2d473a15398a69527f376961aa3fdd135548802ae0a2fdc268b84c7e2d099d</i><br /><br />Threat actor <b>description</b>: <i>TriApex US Laboratories</i><br />Target victim <b>website</b>: <i>tri-apex.com/info/news/headlines/596.html</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Talleyville-Fire</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28818</link>
<guid>efa41f347fb5bfa798ab738ead1d2045</guid>
<pubDate>Tue, 20 Jan 2026 00:28:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Talleyville-Fire</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9c73a95dd9a42cefce72d42a9d635be9b2c404d0a78f003c1b15161fe655cd0</i><br /><br />Threat actor <b>description</b>: <i>Talleyville Fire Company is dedicated to providing essential fire, ambulance, and rescue services to approximately 50,000 residents in New Castle County, Delaware. They rely on community support and donations to maintain their equipment and operations to effectively safeguard lives and property. The organization also promotes fire safety through educational programs and actively seeks volunteers to assist in their mission. Notable community events, such as fundraisers and public service activities, further highlight their commitment to the local community.</i><br />Target victim <b>website</b>: <i>www.talleyvillefire.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pivotal-Healthcare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28819</link>
<guid>6452782166334798a0364267bcc94422</guid>
<pubDate>Tue, 20 Jan 2026 00:27:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pivotal-Healthcare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1421c0668055ed3ef5d939371d6ef0acb93b838a16095cc609492d1eb0283ea2</i><br /><br />Threat actor <b>description</b>: <i>Pivotal Healthcare is a company that operates in the Hospitals & Physicians Clinics industry. It employs 10to19 people and has 500Kto1M of revenue. The company is headquartered in the United States.</i><br />Target victim <b>website</b>: <i>www.pivotalhealthcare.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>abcseamless.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28815</link>
<guid>a89b9b817d1c710e6ef5000032e1c514</guid>
<pubDate>Mon, 19 Jan 2026 19:36:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>abcseamless.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afbc7882cdf4e197bd1c3d745d415acd47b1c23f8cde69ff14124479ce4d1830</i><br /><br />Threat actor <b>description</b>: <i>ABC Seamless is a U.S.-based home improvement and exterior construction company that specialises in custom on-site manufactured seamless steel siding, …</i><br />Target victim <b>website</b>: <i>abcseamless.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reeves-Information-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28809</link>
<guid>a60e1e1f6684d5cb9efcb8a6131f8b74</guid>
<pubDate>Mon, 19 Jan 2026 17:54:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Reeves-Information-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c3cc257033ea8669c61cc09963855bf87c77d763148bffcfe9a31093938ae7c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>ASRock-Rack</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28808</link>
<guid>2a5f614fbd6b69fd6695ae213d63eef0</guid>
<pubDate>Mon, 19 Jan 2026 17:54:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>ASRock-Rack</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>537be278889a63fe393205a53ecffe7f273ecd9d2592c7b19d5e7610a5fd76ea</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] ASRock Rack is a professional server and workstation manufacturer, dealing primarily with cutting-edge technology for data centers and cloud services. Established in 2013, this industry leader provides equipment specifically tailored for HPC, data center, enterprise IT, education, and small-medium businesses. Product range includes server motherboards, server and workstation systems, network appliances, and storage devices.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Durashiloh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28804</link>
<guid>942e78606ae2c894bc420163d6d27aa3</guid>
<pubDate>Mon, 19 Jan 2026 16:43:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Durashiloh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9ba1f95d12025d1d3dbf4cfda6ffef338865c223f255dd52f90b1ca51e6631d</i><br /><br />Threat actor <b>description</b>: <i>The company specializes in the development, engineering, and manufacturing of various components and systems for the automotive industry and other sectors.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bray-Whaler</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28798</link>
<guid>f5bdd987e82cfcad049b164a59d1fe2f</guid>
<pubDate>Mon, 19 Jan 2026 00:34:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bray-Whaler</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55fe6fa95736ac9ce631bc4fb6ce69fcde4d7b007344d72a2ef20640b62a1ec6</i><br /><br />Threat actor <b>description</b>: <i>Bray Whaler Inc operates as a comprehensive construction management firm specializing in complex hospitality and commercial development projects. The company brings together expertise in project oversight, budget management, and quality control to deliver results across diverse property types and scales. Their work spans the full spectrum of hospitality construction, from boutique establishments to large-scale entertainment venues, as well as residential and mixed-use developments that require sophisticated coordination and execution. The firm's approach centers on understanding the unique demands of each project type. Hotel construction demands particular attention to guest experience elements, operational workflows, and timeline precision. Restaurant and club projects require specialized knowledge of kitchen systems, dining layouts, and compliance with health and safety regulations. Casino and entertainment venues present additional complexity through their specialized infrastructure</i><br />Target victim <b>website</b>: <i>www.braywhaler.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Channel-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28799</link>
<guid>96874a5ae20067403f7daa6b787019c4</guid>
<pubDate>Mon, 19 Jan 2026 00:34:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Channel-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>85b43ccf48242f6260dbf947e73540ea029d82a5edda4bfb2839dce63857973b</i><br /><br />Threat actor <b>description</b>: <i>Channel Products specializes in inventing and manufacturing component systems and technologies aimed at enhancing safety, reliability, and efficiency for manufacturers. With over 40 years of experience, the company offers advanced ignition technology, custom engineering solutions, and expert support to a diverse range of manufacturing clients. The organization places a strong emphasis on integrity, reliability, and customer service, making it a trusted partner for those seeking a competitive edge in the market. Channel Products is recognized for its commitment to quality and innovation in the engineering and manufacturing sectors.</i><br />Target victim <b>website</b>: <i>www.channelproducts.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Avalon-Hills</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28800</link>
<guid>cc83ee3e84c79e7fbf27cb415c68bbcf</guid>
<pubDate>Mon, 19 Jan 2026 00:33:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Avalon-Hills</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f615431622a5d7af9ae5bf1abf9b5fa19e252d8c73413ac3235505acae0794ca</i><br /><br />Threat actor <b>description</b>: <i>The Avalon Hills business staff work behind the scenes to help manage all aspects of the program. They route calls, assist with travel plans for clients and families, track all things financial, keep all of the technical machines purring and whatever else it takes to keep a busy program in business! The financial office and utilization review team partners with families to help them access and maximize their insurance benefits. This requires the dedication of families to expand the financial resources available to them for treatment. We help those struggling with an eating disorder recover through a combination of the best, tried-and-true traditional psychotherapies and applied neuroscience, including the latest discoveries about human brain plasticity. Prior to arriving at Avalon Hills, our 21 year-old daughter struggled with a life-threatening eating disorder for over 4 years.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Waste-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28801</link>
<guid>fd675b153ecc803a1bac6aad641085c5</guid>
<pubDate>Mon, 19 Jan 2026 00:33:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>National-Waste-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa51ddc109c941743aec7ae6a54b54738ddd9d347ca1206fc6c9c48780a32a5e</i><br /><br />Threat actor <b>description</b>: <i>National Waste Associates (NWA) is a family-owned waste management consultant that specializes in providing tailored commercial and industrial recycling solutions. They serve various industries including construction, healthcare, retail, and hospitality, by optimizing waste management plans and significantly reducing costs for organizations with multiple locations across the U.S. and Canada. With a focus on sustainability, NWA has been recognized for diverting over 90% of waste from landfills and provides ongoing gap analyses and customized reporting for their clients. Their extensive database of hauler relationships allows them to pair clients with the best vendors for their specific waste management needs.</i><br />Target victim <b>website</b>: <i>www.nationalwasteassociates.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thunder-Mountain-Harley-Davidson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28795</link>
<guid>e02721e864b2649003bcf15ba4da931a</guid>
<pubDate>Sun, 18 Jan 2026 23:54:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Thunder-Mountain-Harley-Davidson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3c5742ebd7f0fe2c0b8fcd8c428d889fc16a42c8ddb627447e57491fccc83cb</i><br /><br />Threat actor <b>description</b>: <i>A Harley-Davidson dealership</i><br />Target victim <b>website</b>: <i>thundermountainharley.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mid-park-Ink</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28796</link>
<guid>e082709f3e06a243b4722c670f8edcdf</guid>
<pubDate>Sun, 18 Jan 2026 23:53:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Mid-park-Ink</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>851ed9056b2f5df16edbaa25a467cb754b42c6deee6cb17412a3acfaba120b59</i><br /><br />Threat actor <b>description</b>: <i>A construction holding from Kentucky.</i><br />Target victim <b>website</b>: <i>mid-park.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>QFloors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28797</link>
<guid>f93f4793c2783325b8b6e96c21f3ce5e</guid>
<pubDate>Sun, 18 Jan 2026 23:52:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>QFloors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa079187a7ce82cc622fb27a3f33c8d6e190460b389cbe12cd4c5adce7350a31</i><br /><br />Threat actor <b>description</b>: <i>A flooring software provider.</i><br />Target victim <b>website</b>: <i>qfloors.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bikkal--Associates-sblawyers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28788</link>
<guid>33a7dc86f60ef6b8228c9df8a7e68d30</guid>
<pubDate>Sun, 18 Jan 2026 21:07:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bikkal--Associates-sblawyers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a03a988974807484c63fd070d372b0d6f58129952cfa01b7473ea536730b9209</i><br /><br />Threat actor <b>description</b>: <i>Bikkal & Associates, P.C. is a full-service immigration law firm based in New York, specializing in immigration and nationality law for individuals, families, and employers. With over 40 years of experience, the firm provides comprehensive assistance with various immigration matters, including employment-based immigration, naturalization, and family-based immigration. They are dedicated to protecting the rights of immigrants and offer personalized legal guidance to navigate complex immigration processes. The firm serves clients in New York, the tri-state area, and nationwide.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Title-Guaranty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28790</link>
<guid>8381d2a3fb8e75c7e5f659371d2cc656</guid>
<pubDate>Sun, 18 Jan 2026 21:06:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Title-Guaranty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f69690d0742c854fb011781e75283f32ce08df2dce8916435f92f943453c8129</i><br /><br />Threat actor <b>description</b>: <i>Title Guaranty Company of Lewis County is a locally owned title escrow provider located in Chehalis, Washington, servicing clients across the entire state. They offer comprehensive title and real estate settlement services tailored for realtors, consumers, lenders, builders, and commercial clients. The company emphasizes integrity and local knowledge, ensuring personal attention and outstanding service for each transaction. Their mission is to simplify the closing process, making significant transactions easier for their clients.</i><br />Target victim <b>website</b>: <i>www.titleguaranty.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-Volkswagen-Mazda</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28786</link>
<guid>a1dd9267e737ca837e80cb0f1bb7118d</guid>
<pubDate>Sun, 18 Jan 2026 19:45:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>University-Volkswagen-Mazda</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a147369b1a023b097f02b7055c5c7b83ed06bce2c9c641234daaeaa76102337</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dreher-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28782</link>
<guid>77b6d3de326a27f5240f743e228e6d60</guid>
<pubDate>Sun, 18 Jan 2026 18:44:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dreher-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35b166d5d82ab3fbf942e0cb45663c3167a71344921e126668911671600696cb</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MKC-Customs-Brokers-International-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28785</link>
<guid>091b26e964b0e771fbcc107aad43186e</guid>
<pubDate>Sun, 18 Jan 2026 13:24:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>MKC-Customs-Brokers-International-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e7adb46eca6a12bcf0c582c9cfaa98ab1e093b792979b93d3e656548769c574</i><br /><br />Threat actor <b>description</b>: <i>International trading has never been as complicated and demanding as it is today. Every shipment, large or small, requires a customs broker who is an absolutely dependable working partner. That's MKC Customs Brokers!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Orthopaedic-Specialists-of-Massachusetts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28775</link>
<guid>b387056cb9e8740f37727d8ca2d0db1c</guid>
<pubDate>Sat, 17 Jan 2026 18:44:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Orthopaedic-Specialists-of-Massachusetts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7f710e47a8af6b04575b75081b289c4f3f96787532fadc58a825359210c9f9b</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cary-Pediatric-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28774</link>
<guid>77eecef58086c6f635d85f283792aed4</guid>
<pubDate>Sat, 17 Jan 2026 15:43:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cary-Pediatric-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d0a46a12932de8f2316cada041396c28bf5f63bcba47fd8e58aaa871d3e0ebb</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ilumno</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28768</link>
<guid>45204519c15e0b1ce35f9d4b63749226</guid>
<pubDate>Sat, 17 Jan 2026 08:42:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ilumno</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1610a885ffe5db4abfdc76eaeb2f185c2378241d8cecfd09551eb07a056fb78c</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ecsc.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28763</link>
<guid>52e56b822322cbc9dc33606cfc3edd1c</guid>
<pubDate>Fri, 16 Jan 2026 17:35:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>ecsc.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>174f078ea5095a586691342c2636e62bc6fa8c8a56b41e5fce9a7edc8e0fc5d8</i><br /><br />Threat actor <b>description</b>: <i>Website www.ecsc.org Revenue $11.2 million Industry Electricity, oil and gas Energy, utilities and waste Organizational structure Similar companies Company analytics About South Carolina Electric Cooperatives  Electric Cooperatives of South Carolina, Inc. is a statewide service and trade association representing electric cooperatives throughout the state. It serves 18 consumer-owned electric cooperatives, one wholesale electric cooperative, one transmission cooperative, and one materials cooperative. The association's mission is focused on providing electricity to nearly 2 million South Carolinians through an extensive network of power lines, as well as providing energy efficiency programs and clean energy initiatives. The association advocates for the electrification of rural  areas and provides various resources, including educational programs and assistance in purchasing electric vehicles.</i><br />Target victim <b>website</b>: <i>ecsc.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>La-Macchia-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28761</link>
<guid>d8769c1fdeb8834c6a4808a11fb2716a</guid>
<pubDate>Fri, 16 Jan 2026 15:44:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>La-Macchia-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b4b45edc9d85e74c271009e5caa64bb5d228b37141736ed10599ff6ab6bd32d</i><br /><br />Threat actor <b>description</b>: <i>La Macchia Group is a comprehensive consulting and design-build firm based in Milwaukee, Wisconsin.We will upload 12gb of corporate data soon. Employee passports, driver licenses and other files, HR files, drawings and specifications, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Commenco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28756</link>
<guid>048517851c55e77cf9daf170c6fdd7ab</guid>
<pubDate>Fri, 16 Jan 2026 14:44:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Commenco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30ccf45942d48f678ec3c45bd8387b200b93f55992ef88d6fc9ca4a17d344f3a</i><br /><br />Threat actor <b>description</b>: <i>Commenco specializes in Wireless network infrastructure, Private LTE, wireless devices, equipment installations, system deployments, tower maintenance, and technology support services for commercial, industrial, and government operations.We will upload corporate data soon. Client data, payment details,a bit of personal files, financials, NDAs, numerous contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>DigiCOURSE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28758</link>
<guid>c841b23266e204fc9271733469516275</guid>
<pubDate>Fri, 16 Jan 2026 13:43:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DigiCOURSE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02873e78eb12c22e0124c6ea4db3782db3fc4091853cb2647e2fb34f8361488f</i><br /><br />Threat actor <b>description</b>: <i>DigiCOURSE is a worldwide industry leader specializing in commandand control positioning systems for offshore marine oil and gas exploration. The company offers a range of services including engineering, customized manufacturing, and non-magnetic calibration among others.We will upload corporate data soon. Employee personal information(passport, IDs and so on), client information, detailed financials, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Industrial-Rivet--Fastener-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28759</link>
<guid>355e1a7b56e95137d9649e56cdf4025b</guid>
<pubDate>Fri, 16 Jan 2026 13:43:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Industrial-Rivet--Fastener-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f61294eb6e150cd8adc2c6b828e538050dc2671657e609711f2c0630053a0fa4</i><br /><br />Threat actor <b>description</b>: <i>Industrial Rivet & Fastener Company specializes in a vast range of high-quality rivets and riveting tools, serving distributors and end users in various industries, including automotive.We will upload 36gb of corporate data soon. Employee personal information (SSNs, passports, IDs and so on), HR files, client information, detailed financials, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>JR-Advertising-Specialties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28752</link>
<guid>57b9c682ed39822cdebb3c80d823794b</guid>
<pubDate>Fri, 16 Jan 2026 09:42:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>JR-Advertising-Specialties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc9b3345b44b68784c248a9f4b8d710a6503f7c8824842a4b47ab79622d0a7f9</i><br /><br />Threat actor <b>description</b>: <i>JR Advertising Specialties Inc specializes in promotional products and business gifts, offering a vast selection to meet various needs. Their product range incl...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Upper-Township</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28755</link>
<guid>86c26c7eb678214b9749fe1c5364cff2</guid>
<pubDate>Fri, 16 Jan 2026 08:26:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Upper-Township</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96f64169a7b8e15de6379792f9aac0aae0aa0a01d1b090f01b4f9629dcb11555</i><br /><br />Threat actor <b>description</b>: <i>A New Jersey local municipal level organization</i><br />Target victim <b>website</b>: <i>uppertownship.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>cirrusaviation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28751</link>
<guid>7b061988b655fa9f9d4ffc41d1d68160</guid>
<pubDate>Fri, 16 Jan 2026 03:48:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cirrusaviation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ed8481ee72727ab501ad9226b202c43a6796212af06d17ff09c5fea9ef8cc9b</i><br /><br />Threat actor <b>description</b>: <i>Cirrus Aviation Services is the largest luxury private jet charter service in Las Vegas. Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Financial databases, all transactions, all clients And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Krez--Flores</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28741</link>
<guid>671ee9fb86338a4643eb6d3f2d00496c</guid>
<pubDate>Thu, 15 Jan 2026 19:42:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Krez--Flores</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc55e997a70cb1be13731a102593491ea2e03cd963be5ce63bcedc5789aabab0</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Texas-State-Utilities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28742</link>
<guid>9828cb4d004ea22ddad5fb03c84a2379</guid>
<pubDate>Thu, 15 Jan 2026 19:42:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Texas-State-Utilities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>751fc1cb6c8dbab6423b3bc8e5201c8d92b76fde53e7dc76665535d462dcacd7</i><br /><br />Threat actor <b>description</b>: <i>Electricity, Oil & Gas</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28744</link>
<guid>7b75a9a9404959d96c63d1f61ec75550</guid>
<pubDate>Thu, 15 Jan 2026 19:42:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Moen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c934cdb98c52c98aa4fc19fe1c17ed2d1d7a21bc7fac0053a7a2535a364fc73</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gorlick-Kravitz--Listhaus-CogneSense-Netberry-Solutions-Hein-Electric-Supply-Jet-Wast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28738</link>
<guid>f9c1e83924ec2b3b79247ac16c7c966b</guid>
<pubDate>Thu, 15 Jan 2026 16:42:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gorlick-Kravitz--Listhaus-CogneSense-Netberry-Solutions-Hein-Electric-Supply-Jet-Wast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60e29f23e357c35d57916e75b15511d8bf0963d0d42592dbf6ef0134eae37cff</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 22gb of data of the following companies:Gorlick Kravitz & Listhaus PC operates as a specialized labor andERISA law firm serving multiemployer unions, their benefit funds, and union-affiliated organizations. Cognesense provides advanced measurement, monitoring, and controlsolutions for industries with strict regulations. Netberry Solutions offers services of two areas: INTERNET AND NEWTECHNOLOGIES.Hein Electric Supply Company is an independent electrical distributor based in West Allis, Wisconsin, specializing in a wide rangeof electrical products and services. Jet Wastewater Treatment Solutions offers a comprehensive range of chemical supplies to enhance the efficiency of its systems.You will find personal employee personal data, client information, numerous project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Paylogix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28739</link>
<guid>ecc1d44b677d62d29e0f646131316ca6</guid>
<pubDate>Thu, 15 Jan 2026 15:42:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Paylogix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ecf4de2917f8c60097d05d8133124c6eb23ac1cee4642b8423a0fa8c7e3af21</i><br /><br />Threat actor <b>description</b>: <i>Paylogix is an insuretech pioneer offering premium technology solutions that streamline the administration of voluntary benefits. Their robust suite of services includes enrollment, premium billing, alternative funding, and a software-as-a-service platform tailored for groups of all sizes.We will upload 185gb of corporate data soon. Employee personal information (complete information about 130 employees including SSNs, passports, DLs and so on), client information, detailed financials, internal confidential files, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gorlick-Kravitz--Listhaus-CogneSense-Netberry-Solutions-Hein-Electric-Supply-Jet-Wast...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28740</link>
<guid>59a57dd9c157d6b95b56dfaebb6a45e3</guid>
<pubDate>Thu, 15 Jan 2026 15:39:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gorlick-Kravitz--Listhaus-CogneSense-Netberry-Solutions-Hein-Electric-Supply-Jet-Wast...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>791f2f0916e0ff2e288390c0a18ac69299a1aaa48a883cd83ad0120c9a1ba0f4</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 22gb of data of the following companies:

Gorlick Kravitz & Listhaus PC operates as a specialized labor and
ERISA law firm serving multiemployer unions, their benefit funds
, and union-affiliated organizations. 

Cognesense provides advanced measurement, monitoring, and control
solutions for industries with strict regulations. 

Netberry Solutions offers services of two areas: INTERNET AND NEW
TECHNOLOGIES.

Hein Electric Supply Company is an independent electrical distrib
utor based in West Allis, Wisconsin, specializing in a wide range
of electrical products and services. 

Jet Wastewater Treatment Solutions offers a comprehensive range o
f chemical supplies to enhance the efficiency of its systems.

You will find personal employee personal data, client information
, numerous project files, accounting and financials and other int
ernal operational files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>McAloon--Friedman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28737</link>
<guid>b34cff5ba1f72525e525dd444eceaa99</guid>
<pubDate>Thu, 15 Jan 2026 14:42:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>McAloon--Friedman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb1209a9bc0b404728484c4047225d5b7cf99b0de5e0400b80fa08a1f73d1d7c</i><br /><br />Threat actor <b>description</b>: <i>McAloon & Friedman, headquartered in New York City, New York, is a full-service law firm. They provide legal representation in a variety of healthcare practice areas, including medical malpractice, general liability, personal injury, and product liability.We will upload 627gb of corporate data soon. Enormous number of legal files (hearings, investigation reports, police reports), client files (SSNs, passports, DLs, death\birth certs and so on), employee files, financials and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpstrustarholdingsllc.com-httpsvistlabs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28736</link>
<guid>7446e64c368d215c1786214f5118b5bc</guid>
<pubDate>Thu, 15 Jan 2026 05:24:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpstrustarholdingsllc.com-httpsvistlabs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f546ef0954c8fa091b1b092a5165ae513ef8dce825d4e076ae83bfc8a7fee9a</i><br /><br />Threat actor <b>description</b>: <i>All company data, development drawings, confidential files, investor company files, all financial transactions, equipment, violations, 1.4 TB</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nordstrom-Rack</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28735</link>
<guid>f9dd94e7acd400658ac4fd2817ea4fef</guid>
<pubDate>Thu, 15 Jan 2026 02:49:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tengu</b> claims attack for <b>Nordstrom-Rack</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea14e20235a1203f00862fce38757da2a6e341193940f773a47bdb67ecaefb7d</i><br /><br />Threat actor <b>description</b>: <i>Nordstrom Rack is a company that operates in the Apparel & Accessories Retail industry. It employs 1to4 people and has 500Kto1M of revenue. The company is headquartered in San Jose, California</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tengu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Samson-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28732</link>
<guid>4b84a4fbb709d5887d092b74ee5d6724</guid>
<pubDate>Wed, 14 Jan 2026 23:29:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tengu</b> claims attack for <b>Samson-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>15ddb337766c3a1065b7e04fcae2a22d756eb064784b937925b03b08dadf6745</i><br /><br />Threat actor <b>description</b>: <i>Samson Equipment specializes in designing and manufacturing custom weight rooms tailored for schools, colleges, and tactical training professionals. Their product lineup includes a range of durable strength training equipment like power racks, barbells, and accessories, all made to withstand high usage. The company offers personalized services including 3D render consultations to envision the final layout of weight rooms before purchase. With a commitment to exceptional quality, customer service, and a lifetime warranty, Samson Equipment aims to empower athletes and training facilities alike.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tengu</category>
</item>
<item xmlns:dc='ns:1'>
<title>JJ-White</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28717</link>
<guid>21e04c4536ac1ee11ab991e1dea13c47</guid>
<pubDate>Wed, 14 Jan 2026 21:40:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>JJ-White</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95e91c6a10bb768bffbcb825f08365def6183bcafbaf3df469e4e51625a4b869</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] JJ White is a multi-divisional construction company based in Philadelphia, Pennsylvania. It specializes in general, mechanical and industrial construction with additional services in HVAC maintenance and service, fire protection, and rigging projects. The company operates across the United States working with industries such as healthcare, pharmaceutical, petrochemical, and manufacturing.</i><br />Target victim <b>website</b>: <i>jjwhiteinc.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Visionwheel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28719</link>
<guid>19f560c0fc2e02c530e64152bb9ec137</guid>
<pubDate>Wed, 14 Jan 2026 21:39:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Visionwheel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3037ca604286d7dcb71d3951338c201081d196e4f2fac132e424f4889c872c6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Visionwheel is a prominent manufacturing company that produces high-quality, aesthetically-designed alloy wheels for various vehicles such as cars, light trucks, and SUVs. The company offers a wide range of styles, finishes, and sizes, catering to diverse customer requirements. Visionwheel ensures a rigorous testing process to maintain robust safety standards. It also continually innovates in design to stay abreast in the competitive auto industry.</i><br />Target victim <b>website</b>: <i>visionwheel.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ernest-Maier</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28702</link>
<guid>a188366540b081052eb44432bc73c6a3</guid>
<pubDate>Wed, 14 Jan 2026 18:43:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ernest-Maier</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2c41775ab7694c35ca62a7c152a2926d51f06787d795e15e03778532a7accb4</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Designers-Mirror-and-Glass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28703</link>
<guid>45a042358c47c0059ee86d8508dfcbec</guid>
<pubDate>Wed, 14 Jan 2026 18:43:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Designers-Mirror-and-Glass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f01ed80b5749c0cdd43a6490c2d9db5286d464e68ebdb6a15cd9aaaa2428ff8a</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pathology-Associates-Of-Saint-Thomas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28704</link>
<guid>89bdedf8c38bda669ba5aba697d7703b</guid>
<pubDate>Wed, 14 Jan 2026 18:43:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pathology-Associates-Of-Saint-Thomas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c787ec96536cee2c5e8b2cfe6bf747c4503da5589d554a5c1256454f53e39d1</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lunsford-Capital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28705</link>
<guid>82bdd6d74c304d5130239833c88d2f18</guid>
<pubDate>Wed, 14 Jan 2026 18:43:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lunsford-Capital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca39abf115ccda52abefd469ea2c4d9e6b2be42125a1c684338a02ad531ac0a3</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pre-Con-Builders</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28706</link>
<guid>382c43c484ddee6d1c699d2fd5980d32</guid>
<pubDate>Wed, 14 Jan 2026 17:43:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pre-Con-Builders</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5b726fac4bf6df6bd88bc7e72f1f96dd9e21efd469f658d44e8b2f9043253c3</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Radiant-Remodeling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28707</link>
<guid>a401bed218424c069af5121745e2c46f</guid>
<pubDate>Wed, 14 Jan 2026 17:43:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Radiant-Remodeling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77689828fa5a26216b286c9e4ced7bc41d64d4f69825e51a93feabd8a1f89d1d</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-National-Auto-Loan-Network</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28712</link>
<guid>023974618d255e24c14b5b47c5282260</guid>
<pubDate>Wed, 14 Jan 2026 17:13:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>The-National-Auto-Loan-Network</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b780af24871f44c1ae39fe0133f7315b0a2a4611f25358cf98ad753728cd47f</i><br /><br />Threat actor <b>description</b>: <i>National Auto Loan Network specializes in auto loan refinancing, having successfully refinanced over 2 billion dollars in auto loans for more than 100,000 customers since its inception in 2010. The company is founded by finance professionals with over 40 years of experience and aims to simplify the refinancing process for clients. They pride themselves on excellent customer service and educating clients about their loans. NALN serves individuals looking to save money on their monthly car payments through effective loan refinancing solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rebars--Mesh</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28698</link>
<guid>6e958d69ccac1ad04342b584042c3db5</guid>
<pubDate>Wed, 14 Jan 2026 16:43:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rebars--Mesh</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f912c7d6c37f72ded3402588b3e3e366d247c50e526921e9497c7511792a86eb</i><br /><br />Threat actor <b>description</b>: <i>Rebars & mesh is an independent WBE-certified reinforcing steel fabricator serving New England and Eastern New York. The company specializes in rebar fabrication, pre-assembly services, and offers a wide range of complementary products such as welded wire meshand bar supports. We will upload 15gb of corporate data soon. Employee personal information (DLs, addresses, emails and so on), client information, financials, agreements, drawings and specifications etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ImageWorks-Display</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28699</link>
<guid>0d7c463832b871c20405a6c9296b5517</guid>
<pubDate>Wed, 14 Jan 2026 16:43:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ImageWorks-Display</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1d799e3ed47f69418cc7dd67fa2c6e1ae49a909b926b6318619f18bc2b81474</i><br /><br />Threat actor <b>description</b>: <i>ImageWorks Display & Marketing is a full-service Point-of-Purchase display company. The company specializes in the development andproduction of custom displays, signage, and in-store tobacco displays.We will upload 15gb of corporate data soon. Employee personal information (w9 forms and so on), client information, numerous financials files, agreements and contracts, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TruGolf</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28700</link>
<guid>851e8eaf4988ed55c3d335ea8d5ed61b</guid>
<pubDate>Wed, 14 Jan 2026 15:42:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TruGolf</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a4297fd3dfa87f51ae25f93a3ee13054a941be2f3c5b3bc2c3833838c078364</i><br /><br />Threat actor <b>description</b>: <i>TruGolf develops and manufactures golf simulation hardware and software for both business and consumer markets. The company specializes in creating immersive virtual golf experiences that accurately replicate course designs and gameplay nuances.We will upload 37gb of corporate data soon. Employee personal information (SSNs, DLs, addresses, emails and so on), client information, financials, contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fechner-Pump--Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28695</link>
<guid>7c2174131255d8e906a502237185a436</guid>
<pubDate>Wed, 14 Jan 2026 14:43:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fechner-Pump--Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>490786a533378f276b74eeda7fd4c34bba411dd21e65aea0def0ff5e6c5fdb73</i><br /><br />Threat actor <b>description</b>: <i>Fechner Pump Supply has been serving the oil and gas industry in Oklahoma and southern Kansas for over 33 years, offering a wide range of products and services tailored to both independent producers and large corporations.We will upload 157gb of corporate data soon. Employee personal information (SSN, addresses, phones, emails, scans of personal documents and so on), projects, client information, financials, contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>H2-Builders</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28696</link>
<guid>ac3d7f8fd40bd1debfff97fc0667e95a</guid>
<pubDate>Wed, 14 Jan 2026 14:43:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>H2-Builders</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82b6e425e50fcf4ccecafd7897aaaff33f712c1444577ecf26d6f63bf3f96609</i><br /><br />Threat actor <b>description</b>: <i>H2 Builders is a custom home builder located in Bluffton, SC, specializing in luxury home construction in the Lowcountry. With over 25 years of experience, the company has successfully completed more than 500 custom homes, ensuring high-quality craftsmanship and customer satisfaction.We will upload more than 20gb of corporate data soon. Client information, financials, contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpsacswinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28708</link>
<guid>94397fe878869449f866b64722a0b7c9</guid>
<pubDate>Wed, 14 Jan 2026 13:42:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpsacswinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c397711018087ca51ab4e798954c7cbf43fadba9ed13f199b7c1341624c2bfd</i><br /><br />Threat actor <b>description</b>: <i>1.5tb </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hyatt-Place-New-York--Chelsea-Hotel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28697</link>
<guid>46a62c34c7b8b0c0d02f0833df49ec20</guid>
<pubDate>Wed, 14 Jan 2026 11:11:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Hyatt-Place-New-York--Chelsea-Hotel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb987b09cca4efb9bb30505403aaea2092f6befec0cbff5d171d699d0c17495f</i><br /><br />Threat actor <b>description</b>: <i>Hyatt Place New York / Chelsea Hotel</i><br />Target victim <b>website</b>: <i>hyatt.com/hyatt-place/en-US/lgazc-hyatt-place-new-york-chelsea</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpsbellowsmfg.comcompany</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28689</link>
<guid>2a8efa289025a74ce50cae9e92e0edb2</guid>
<pubDate>Tue, 13 Jan 2026 22:46:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpsbellowsmfg.comcompany</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3d39ab65f5c84cc72b26710c031bfc80fba427a918d35b1f8d7f8df728abf6d</i><br /><br />Threat actor <b>description</b>: <i>1.3tb  </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bulk-Handling-Systems-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28679</link>
<guid>f87ce61286012c89c54a93e61a88e761</guid>
<pubDate>Tue, 13 Jan 2026 16:43:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bulk-Handling-Systems-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>607894c7d89fc3510645bcff809eaff31a154d55e26b0838c26bdbf5d5902ced</i><br /><br />Threat actor <b>description</b>: <i>BHS serves a diverse clientele, including waste management companies, recyclers, and municipalities, helping them navigate changing material streams and energy recovery challenges.NRT is a leader in plastic bottle and flake sorting technology, boasting the largest installed capacity in PET plastic reclamationplants worldwide.We will upload 24gb of corporate data soon. Detailed employee personal information (addresses, phones, emails, scans of personal documents and so on), projects, client information, lots of internal confidential files, financials, credit cards, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Itasca-Consulting-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28680</link>
<guid>80154d0cf42299d38de5046efc2429a3</guid>
<pubDate>Tue, 13 Jan 2026 15:42:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Itasca-Consulting-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1941af9510f9c3995dda9523484d4dfec0961c24212a244ee92bc0a0e5f4683</i><br /><br />Threat actor <b>description</b>: <i>Itasca is a global engineering consulting and software firm, working primarily with the geomechanics, hydrogeological and microseismics communities.We will upload 20gb of corporate data soon. Detailed employee personal information (addresses, phones, emails, scans of personal documents and so on), projects, client information, internal confidential files, financials, credit cards, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rodneys-Sign-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28676</link>
<guid>39acb542878b92997468cd17aa72399e</guid>
<pubDate>Tue, 13 Jan 2026 03:51:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Rodneys-Sign-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>550f56eb8ca24c2e0eee02fe706282065621bc47676bc7591a222da02d3e5342</i><br /><br />Threat actor <b>description</b>: <i>ASI Raleigh offers a full-service team to support the planning, engineering and implementation of precise execution and superior quality signage projects for North Carolina’s leading brands. Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fit-Line-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28672</link>
<guid>6964e9d5cd1aab8c7c72b12b77f2fd20</guid>
<pubDate>Tue, 13 Jan 2026 00:52:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Fit-Line-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17931b96b4f97e983dcb847c85d3a22a44eb5c19526291adc9f89542288a53fa</i><br /><br />Threat actor <b>description</b>: <i>Fit-Line Global® is a trusted supplier, designer, research and development resource for SEMI-F57-0301 compliant PFA and PVDF components. They employ efficient manufacturing processes to create products that meet the most demanding applications. Fit-Line Global has been a trusted supplier to the semiconductor industry for more than 25 years. Headquartered in California, Fit-Line Global dedicates itself to providing quality products, with the fastest lead time in the industry, at a fair price. The company exclusively produces ultra-high purity PFA and PVDF components to eliminate the possibility of cross-contamination.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cape-Fear-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28673</link>
<guid>5b32eb1adf7d661dfc01777ed24cc7ad</guid>
<pubDate>Tue, 13 Jan 2026 00:52:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Cape-Fear-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc6aeb752a67061dceacbfd08cbb21e3f5621d2a5647fa124075ebe276015e57</i><br /><br />Threat actor <b>description</b>: <i>Cape Fear Country Club is a private members-only country club in North Carolina, founded in 1896. It offers an 18-hole golf course designed by Donald Ross, along with tennis, swimming, fitness amenities, dining services, and a wide range of social and family-oriented activities. The club is known for its long-standing traditions, high service standards, and close-knit community environment.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pilot-automotive</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28670</link>
<guid>e74843b99da8b29775c6aa9080436844</guid>
<pubDate>Tue, 13 Jan 2026 00:20:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pilot-automotive</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef225539b6a23ff1346db14da760440de063ebcf318262273554ba86e2c1d780</i><br /><br />Threat actor <b>description</b>: <i>Pilot specializes in a wide range of automotive accessories, including truck, interior, and exterior accessories as well as lighting and replacement parts. They offer products such as step bars, grille covers, and various car care items aimed at enhancing vehicle functionality and aesthetics. Targeting both personal vehicle owners and automotive enthusiasts, their products cater to any driver looking to customize and improve their car or truck. With a commitment to quality, Pilot features well-known brands like Bully Truck Accessories and Voodoo Ride.</i><br />Target victim <b>website</b>: <i>www.pilotautomotive.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>MyVete</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28671</link>
<guid>ececf8310d5c47ae7dbdf1cda6163c72</guid>
<pubDate>Mon, 12 Jan 2026 22:53:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kazu</b> claims attack for <b>MyVete</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce71a7053a22b253655b4c99c8dc57b214714009d91389de750d84093cea3b06</i><br /><br />Threat actor <b>description</b>: <i>MyVete is a veterinary software designed to help animal clinics and veterinary practices manage their operations more efficiently. The platform includes features for managing patient records, appointments, billing, and inventory, all in one system. MyVete allows veterinarians to track medical histories, schedule appointments, and send reminders for vaccinations or follow-up care. The software also includes tools for managing invoicing and payments, allowing clinics to accept payments through multiple methods, including credit cards and insurance claims. With its easy-to-use interface, MyVete streamlines administrative tasks, reducing time spent on paperwork and improving patient care. By providing real-time access to patient data and operational insights, MyVete helps veterinary practices improve efficiency and deliver better care to animals.</i><br />Target victim <b>website</b>: <i>myvete.com</i>]]></description>
<category>kazu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harrison-Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28669</link>
<guid>2210bc8c8682f678d552ff7add41b418</guid>
<pubDate>Mon, 12 Jan 2026 20:43:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Harrison-Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3af20ca5e6e4a73545f94e7dba6507ff19ae7327d1334fbfb7ba285acb850d62</i><br /><br />Threat actor <b>description</b>: <i>Harrison Design is an award-winning design firm specializing in architecture, interior design, and landscape architecture. Their services cater to various sectors including residential, multifamily, sacred, and hospitality projects. Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development  - Drawings  And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Resource-Corporation-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28656</link>
<guid>d5eeeb68551631bceacdeeb4e2a9d3c1</guid>
<pubDate>Mon, 12 Jan 2026 20:43:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Resource-Corporation-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b596f3837a4f249b5ece53bc329e599828ff242a75414cc0f581714a6bd2745</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Young-Wealth-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28657</link>
<guid>e4b6786bef5f306479ebdcc6fec136b3</guid>
<pubDate>Mon, 12 Jan 2026 20:43:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Young-Wealth-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ab3c62d0d0f7a7b46713a82a2dd496a0f519e5619fe258d2e620df0dd89bd5d</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>klhindustries.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28665</link>
<guid>f2c41f31655fe4735c50168fce9b688f</guid>
<pubDate>Mon, 12 Jan 2026 19:48:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>klhindustries.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f770863730fee4d5e68963aee925246fbfe7925821ac9d3540cdee2aef89f155</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>klhindustries.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>G-WAY-Microwave</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28658</link>
<guid>1084a91264d0a5d47eeb3659f9c36935</guid>
<pubDate>Mon, 12 Jan 2026 19:42:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>G-WAY-Microwave</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c161e1a006d9e6a0bea7fb23eb0224eefcbe21c10157451ac16997a87ffed8a</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Superior-Water-Conditioning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28659</link>
<guid>149f6a58b66493adaa38bc178da51e75</guid>
<pubDate>Mon, 12 Jan 2026 19:42:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Superior-Water-Conditioning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>065916da6a9eed068f1c4a139095574dd15e859c012c6b5b3afba679fee3b463</i><br /><br />Threat actor <b>description</b>: <i>Consumer Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>sealbeachca.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28661</link>
<guid>c79bb048121bbc1d20d79c6b83ef17b5</guid>
<pubDate>Mon, 12 Jan 2026 18:57:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>sealbeachca.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b1638449105ad8bcf35bb9c690f6b7937331f05e6cbd422682d2c10cdecd1bf</i><br /><br />Threat actor <b>description</b>: <i>Datatheft 300gb of data stollen includes gov documents, deeds and much more</i><br />Target victim <b>website</b>: <i>sealbeachca.gov</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>sealbeachpd.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28662</link>
<guid>fdccddea8522e14b9d8a41551d9256fa</guid>
<pubDate>Mon, 12 Jan 2026 18:56:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>sealbeachpd.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c6e79f6495b493edc7fb2b6f5f9ddab18e59d4363b980bc04ed9d7a9198da9d</i><br /><br />Threat actor <b>description</b>: <i>data theft, evidence, officers personal information police reports, DEA open cases information</i><br />Target victim <b>website</b>: <i>sealbeachpd.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Best-Insurance-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28650</link>
<guid>52d3882d85ec8a840371c62855241ceb</guid>
<pubDate>Mon, 12 Jan 2026 18:41:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Best-Insurance-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06aa9efeea725ff6562ffedb842399f4419b12ae65ebd0ac5c6f3b3418135200</i><br /><br />Threat actor <b>description</b>: <i>Insurance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hayden-Safe--Lock</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28651</link>
<guid>14253cc3324fa4766ffbe5f12a7dba10</guid>
<pubDate>Mon, 12 Jan 2026 18:41:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hayden-Safe--Lock</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dac0b76817adda52ee2bf92ec25f4d37107e207b82020cd59bf2aa7b2508dda0</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Outdoor-Recreation-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28646</link>
<guid>789334de6daa80d83ab4acb6a4bf5ac7</guid>
<pubDate>Mon, 12 Jan 2026 16:42:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Outdoor-Recreation-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72c6acc8cfd09738e914a8120ac7a6958b50cb21d84174e49cbdeeca04958444</i><br /><br />Threat actor <b>description</b>: <i>The Outdoor Recreation Group (TORG) is a solutions-driven company, relentless in our drive to meet the needs and exceed the expectations of each and every customer within multiple product categories and industries. We primarily focus on the Camping, Hunting and Fishing markets, with specific specialty in the sewn goods and accessory categories.We will upload corporate data soon. Lots of internal data, partners information, a bit of financial docs, projects, contracts and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rod-Danielson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28655</link>
<guid>974e2945a18e0bfb8e3aa8becac3e65c</guid>
<pubDate>Mon, 12 Jan 2026 15:51:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Rod-Danielson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dabb5cfda15a3be743b669d240a75752346d1956487f2406c0319aa6b6e80ede</i><br /><br />Threat actor <b>description</b>: <i>Rod Danielson serves as a Chapter 13 Trustee in the Central District of California, Riverside Division. The organization provides public services related to Chapter 13 bankruptcy for debtors, creditors, attorneys, and other interested parties. It offers information on various procedures including appearances at hearings and guidance on case management. The intended clients encompass individuals and entities involved in Chapter 13 bankruptcy proceedings in Riverside.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Syrstone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28648</link>
<guid>b5f73d2f8c5e4aa26041effe5fbdf930</guid>
<pubDate>Mon, 12 Jan 2026 15:42:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Syrstone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e9fc4d82f21abc5b629943cb13a36214c284a704bf50834d1693d46e641600e8</i><br /><br />Threat actor <b>description</b>: <i>Syrstone, originally known as the Syracuse Stone Company, is a specialized subcontracting firm with over 50 years of experience inthe site and highway construction industry. The company providestop quality and cost-effective subcontract work including granite curbing, grooving grinding, unit paving, and rumble strips.We will upload 58gb of corporate data soon. Detailed employee personal information (SSN, passports, drivers licenses, credit cards, addresses, phones, emails and so on), financials, client information, NDAs, internal confidential docs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>CSS-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28649</link>
<guid>ae490cce121bcb4989be859bcbda433a</guid>
<pubDate>Mon, 12 Jan 2026 15:42:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CSS-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df35da9c10ba7f846fd5a73946ba9ab0f831aaea523d7a67ac089252131a655b</i><br /><br />Threat actor <b>description</b>: <i>CsS Services provides end to end eviction management through our service infused technology platform to portfolios throughout the United States.We will upload 45gb of corporate data soon. Employee personal information, customer information, financials, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epport-Richman--Robbins-Kalamazoo-Valley-Community-College-BJ-Transportation-FR-Law-G</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28644</link>
<guid>1130d3f4bee922658eb1347e27ff55f3</guid>
<pubDate>Mon, 12 Jan 2026 14:44:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Epport-Richman--Robbins-Kalamazoo-Valley-Community-College-BJ-Transportation-FR-Law-G</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5fe25b0163aabedbff5022260e41b16895973e08018255df1d6f641cb6444b0</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 10gb of data of the following companies:Epport, Richman & Robbins, LLP is a Los Angeles-based law firm that specializes in complex commercial and banking litigation across California, as well as sophisticated real estate transactions nationwide.TKH Group, PC is an accounting firm based in Otsego, MI, offeringa wide range of services including tax preparation, financial planning, and business consulting.B&J Transportation specializes in airport transfers, business transfers, and event transportation, ensuring clients remain on schedule and together throughout their journey.FR Law Group PLLC is a law firm based in Phoenix, AZ, that specializes in providing legal services from a business perspective.Red River Glazing is a commercial and residential glass company with offices in Fargo and Bismarck, North Dakota.You will find personal employee personal data, client information, numerous project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epport-Richman--Robbins-Kalamazoo-Valley-Community-College-BJ-Transportation-FR-Law-G...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28653</link>
<guid>638c1a4f003b46aad4aa5cf3f424d215</guid>
<pubDate>Mon, 12 Jan 2026 13:44:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Epport-Richman--Robbins-Kalamazoo-Valley-Community-College-BJ-Transportation-FR-Law-G...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de0b6292e43341a28ffd02c7092845e0113fc62ca2db9f9080661e76ab5e15d8</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 10gb of data of the following companies:

Epport, Richman & Robbins, LLP is a Los Angeles-based law firm th
at specializes in complex commercial and banking litigation acros
s California, as well as sophisticated real estate transactions n
ationwide.

TKH Group, PC is an accounting firm based in Otsego, MI, offering
a wide range of services including tax preparation, financial pl
anning, and business consulting.

B&J Transportation specializes in airport transfers, business tra
nsfers, and event transportation, ensuring clients remain on sche
dule and together throughout their journey.

FR Law Group PLLC is a law firm based in Phoenix, AZ, that specia
lizes in providing legal services from a business perspective.

Red River Glazing is a commercial and residential glass company w
ith offices in Fargo and Bismarck, North Dakota.

You will find personal employee personal data, client information
, numerous project files, accounting and financials and other int
ernal operational files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>FOX-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28641</link>
<guid>1e5afae270de728fd14f20133233d33a</guid>
<pubDate>Sun, 11 Jan 2026 20:59:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>FOX-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47a69d6fc8ad6038914a9d03d6db2ef2529b36f14946ffc4c67df844eb3fd32</i><br /><br />Threat actor <b>description</b>: <i>FOX Architects LLC is an architecture and interior design firm that specializes in transforming workplace environments through strategic design and comprehensive planning. The firm brings together expertise in spatial strategy, building systems, and user-centered design to create functional, innovative work spaces that enhance organizational performance and employee experience. The company's service offerings span the full spectrum of workplace transformation, from detailed zoning research and regulatory compliance analysis to large-scale master planning initiatives. FOX Architects conducts thorough site planning and analysis to evaluate property potential, then executes building renovations that modernize infrastructure while preserving architectural integrity. This integrated approach allows the firm to address both immediate renovation needs and long-term strategic facility goals within a cohesive framework.</i><br />Target victim <b>website</b>: <i>www.fox-architects.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cardiovascular-Medical-Group-of-Southern-California-CVMG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28640</link>
<guid>a12848aeac58ac57e95977f93fec17fd</guid>
<pubDate>Sun, 11 Jan 2026 19:52:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Cardiovascular-Medical-Group-of-Southern-California-CVMG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8d41434bcfb05e71b0b5e10ea3657bf06c4a013cfcf73b90c474f8d69b4fd67</i><br /><br />Threat actor <b>description</b>: <i>Cardiovascular Medical Group of Southern California provides a comprehensive range of cardiovascular services, including diagnostic testing, disease management, and advanced treatments for patients of all ages. Their board-certified physicians specialize in cardiology and internal medicine, ensuring expert care and a focus on preventing heart disease. The clinic leverages the latest medical technologies to support patient health and offers accessible virtual services such as electronic appointment requests and test results. Their commitment to personalized care is evident in their strong physician-patient relationships and partnerships with renowned medical institutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ingomar-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28637</link>
<guid>be4b74cc626578c5fbed9a26c481d8cb</guid>
<pubDate>Sun, 11 Jan 2026 19:51:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Ingomar-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>910e7ff5fc969c1221053bedafbe562da7bc082877124356e6d8890926536ee9</i><br /><br />Threat actor <b>description</b>: <i>Ingomar Church offers a variety of worship services and community activities aimed at enhancing spiritual growth. Their programs include traditional and contemporary worship, youth and children's ministries, small group connections, and outreach services. The church invites individuals and families to engage with faith-based teachings and serve the community. Located in Pittsburgh, PA, they provide a nurturing environment for spiritual and personal development.</i><br />Target victim <b>website</b>: <i>www.ingomarchurch.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ITG-Electronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28638</link>
<guid>41eed75111d927aa8cce63e2757c100d</guid>
<pubDate>Sun, 11 Jan 2026 19:51:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>ITG-Electronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3c05b79676aa0d5109dd6685a3660ef2fbb3c9de288ebfb8cd18847be07bde4</i><br /><br />Threat actor <b>description</b>: <i>ITG Electronics, Inc. specializes in a vast range of electronic components including power inductors, EMI filters, common mode chokes, and transformers, catering to high-performance applications in various industries. Their products are designed for automotive, industrial, consumer, and medical sectors, offering both standard and custom solutions. With a strong commitment to energy efficiency and compliance with industry standards, ITG provides tailored solutions for power supplies and electronic systems. Their expert sales team is accessible for inquiries and customized product requirements, ensuring specific needs are met efficiently.</i><br />Target victim <b>website</b>: <i>www.itgelectronics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Granville-Inn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28639</link>
<guid>54d2d10822ea47f64edaa52fa184dfb0</guid>
<pubDate>Sun, 11 Jan 2026 19:51:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Granville-Inn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31e2637247501327fb808f5d83d7eb6505a4f49cbbc506338e27c544ed4d41f4</i><br /><br />Threat actor <b>description</b>: <i>Granville Inn offers elegant accommodations with luxury amenities, a fine dining experience, and versatile meeting spaces. This historic inn, located just outside Columbus, Ohio, features 39 guest rooms and suites that combine old-world charm with modern conveniences. It is highly regarded as a wedding venue, providing picturesque settings and luxurious services for couples. Additionally, Granville Inn caters to business clients with full-service meeting facilities equipped with the latest audio-visual technology.</i><br />Target victim <b>website</b>: <i>www.granvilleinn.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pecan-Tree-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28634</link>
<guid>5c6839e11219ac4b4021d194b43665f7</guid>
<pubDate>Sun, 11 Jan 2026 18:55:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pecan-Tree-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9d9e5163479d75237e7e69101932759733be9099fda8763a06fd9ee1c4602fc</i><br /><br />Threat actor <b>description</b>: <i>Pecan Tree Dental is a dental practice located in Grand Prairie, TX, dedicated to providing comfortable and personalized dental care for families. They offer a comprehensive range of services including preventive, cosmetic, restorative, and emergency dentistry. The practice is accessible to residents of Grand Prairie and its surrounding communities, accommodating various patient needs with amenities and flexible scheduling. Their mission emphasizes community care, involvement in charitable work, and an insurance-friendly approach to dental health.</i><br />Target victim <b>website</b>: <i>www.pecantreedental.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Youngstown-Pipe--Steel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28635</link>
<guid>5afa3c562f5bf2eff62de390e531c25d</guid>
<pubDate>Sun, 11 Jan 2026 18:55:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Youngstown-Pipe--Steel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e701df2d9645ab99d0defc66345906846db2a797b16448d68bbc1a7cf9fa90fb</i><br /><br />Threat actor <b>description</b>: <i>Youngstown Pipe & Steel, LLC (YPS), located in Campbell, OH, is a steel service center specializing in the value-added processing and distribution of carbon and alloy steel products in an expanding array of shapes and sizes. Our company is comprised of experienced, community-minded associates. We are committed to achieving profitable growth and creating superior value for our customers by safely providing high quality products and services while delivering them on time. YPS was founded in 1979 and acquired by DNV Management Corporation in 2004. Since its acquisition, DNV has expanded product lines, installed a high definition plasma burning table, oxy-fuel burning tables, multiple saws and other equipment for value added processing. We deliver our products utilizing a dedicated fleet of trucks and in 2011, relocated to a 300,000 sq. ft. warehouse. In 2012 DNV Management created DNV Energy to concentrate on the growing product and service demands of the shale oil and gas industry.</i><br />Target victim <b>website</b>: <i>www.youngstownpipeandsteel.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vernon-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28636</link>
<guid>251fbd782fec91a50eb1b6050f8d7f2b</guid>
<pubDate>Sun, 11 Jan 2026 18:55:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Vernon-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad347004b673eda46c8d24fc64f6e0909d32924198a149e6e18fbf1095b41d11</i><br /><br />Threat actor <b>description</b>: <i>Vernon Sales is a leading dollar store supplier in the United States. Here you can find everything you need for your dollar store, discount store, 99 cent store, convenience store.</i><br />Target victim <b>website</b>: <i>www.vernonsales.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hog-Slat</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28627</link>
<guid>b67d084d74c3f7c0145f96a0ac4c82a8</guid>
<pubDate>Sun, 11 Jan 2026 17:59:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Hog-Slat</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8df389b77d4f7e7ac4b61fae999056cb2ef211ad3c537f60bd6f359d3e326852</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/hog-slat-inc/48483868 https://www.zoominfo.com/c/hog-slat-inc/406568064 Hog Slat, Inc. is the largest contractor and producer of equipment for hog farmers in the United States, employing approximately 1,000 direct employees and an additional 1,400 subcontractors for construction projects. The company specializes in building turnkey facilities for both family farms and large agricultural units across the U.S. and internationally. Hog Slat also sells equipment packages to clients who prefer to construct their own facilities. Their services cater to a wide range of agricultural clients focused on livestock production. Hog Slat was founded in 1969. This company provides the manufacturing and installation of fans for confinement type hog units. Their headquarters are located in Newton Grove, North Carolina.</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pensam-Residential</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28625</link>
<guid>37563f059c2d815bf5fc637cb88e1df3</guid>
<pubDate>Sun, 11 Jan 2026 13:48:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pensam-Residential</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>788a99c449ec57e92ec1e065d916145ddfc5bf1841b1e28900519de94226d4ff</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.pensamcapital.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Family-Surgery-Center-Covenant-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28619</link>
<guid>81e2631c91b78268005021e704312097</guid>
<pubDate>Sun, 11 Jan 2026 12:23:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Advanced-Family-Surgery-Center-Covenant-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d173f7f026e32ee84035e96e7b5517bb79d872da935542a7b543dac238cd4f8</i><br /><br />Threat actor <b>description</b>: <i>A provider of surgical services</i><br />Target victim <b>website</b>: <i>covenanthealth.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cisneros-group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28622</link>
<guid>ac83d3f400e95a5d31e7c59d2743bf73</guid>
<pubDate>Sun, 11 Jan 2026 11:54:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Cisneros-group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f09e03907fe19db7fad5f2336a03a2cc80fc4cdb42bd56b74aad62af40e13376</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1929, Cisneros is a global media and entertainment enterprise headquartered in Miami, Florida. The company specializes in broadcasting, digital advertising, and real estate development with operations across North and South America, including Mexico. Cisneros offers mobile applications and technology solutions while maintaining a diverse portfolio of media properties and entertainment content. The company combines traditional broadcasting with digital innovation to deliver content and services to both business and consumer markets worldwide - corp you have 7 days to contact and get in touch, sample provided.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Launie--Marino</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28614</link>
<guid>4f6cb5f6a3723a126aa3cae19027a2f8</guid>
<pubDate>Sat, 10 Jan 2026 20:56:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Launie--Marino</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81e0ae7bc187105e5a232378c418ae84d80956266d0a78ecc5fd47e3350566f9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.launiemarino.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dennys-5th-Avenue-Bakery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28613</link>
<guid>3a95790514f43839f9aef7a3e9d00d5c</guid>
<pubDate>Sat, 10 Jan 2026 20:55:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Dennys-5th-Avenue-Bakery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9eb4b995c335c9d2e2e6cafe668745c52ef2895455e9368db47f0036133f224</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dennysbakery.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>WiZiX-Technology-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28612</link>
<guid>6760b957686819cb6636c2319fb4f872</guid>
<pubDate>Sat, 10 Jan 2026 20:54:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>WiZiX-Technology-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aec048f49ea4cf4c51701975cb5d38a96618f9819fcb9cd4b3f1c05deb3bcdba</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wizixtech.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Foshee-Architecture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28608</link>
<guid>430b55d1924ca394c90192228f7995df</guid>
<pubDate>Sat, 10 Jan 2026 12:18:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Foshee-Architecture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57f10227ebe6f07838575c05eb23f3c24e78f85dc5f8cea017a856e23c25f187</i><br /><br />Threat actor <b>description</b>: <i>Foshee Architecture is a Montgomery, Alabama-based architecture firm specializing in comprehensive design services for a variety of sectors including multi-family housing, healthcare facilities, office spaces, retail, and restaurants. Founded by John H. Foshee, the firm utilizes a personalized design process informed by a rich family history in the construction industry. By collaborating with experts in engineering and other disciplines, they provide tailored architectural solutions that prioritize client objectives and budgets. Their extensive experience positions them to effectively manage complex projects while ensuring high standards of functionality and aesthetic appeal.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>publicsafety.ohio.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28607</link>
<guid>bb24c3e3687e57b7db6ec47711b21770</guid>
<pubDate>Sat, 10 Jan 2026 04:04:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>publicsafety.ohio.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dad58c1420c52365189b8c59f359721193ba900382361549f58eec56ec1c8dc</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>example.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>CompactInd</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28606</link>
<guid>a54ff7dbb86659426466904cf2b77aa1</guid>
<pubDate>Sat, 10 Jan 2026 03:59:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>CompactInd</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7eaf780c277acde0302235c59623f6b66c3b28006a1b71909540512875ccc550</i><br /><br />Threat actor <b>description</b>: <i>Compact Industries, Inc. is a leading contract manufacturer specializing in dry food products, particularly powdered food items and sugar-based drink mixes. Established in 1963, the company offers custom blending and contract packaging services, catering to a diverse range of clients.  Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:  - Confidential documents  - Clients Data  - NDA  - Financial data  - Operations  - Corporate data  - Business Agreements  - Development   And a lot of other VERY IMPORTANT information</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Vanguard</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28605</link>
<guid>9346d72c6cc9656611d6bb3bb61a0804</guid>
<pubDate>Fri, 09 Jan 2026 23:59:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>osiris</b> claims attack for <b>American-Vanguard</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7273fafebdbb78c0f872c9c2c20d0311d60d172a937a85ed76ed2c673e0ec6ed</i><br /><br />Threat actor <b>description</b>: <i>American Vanguard Corporation is a U.S.-based company specializing in agricultural chemicals, primarily focused on crop protection products like herbicides, insecticides, fungicides, and fumigants. Founded in 1969 and headquartered in Newport Beach, California, the company markets products under its AMVAC brand and other specialized labels, serving global agricultural markets. Through a combination of research and development, strategic acquisitions, and a focus on sustainable practices, American Vanguard aims to enhance crop yields while minimizing environmental impact. It invests in greener alternatives to traditional chemicals and emphasizes innovation in pest control solutions. As a publicly traded company (NYSE: AVD), its financial performance is closely tied to agricultural trends and regulatory changes within the industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>osiris</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swavelle-Group-Wearbest-Sil-Tex-Mills</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28599</link>
<guid>164ecd36bc9fc1781df239d00b004d3b</guid>
<pubDate>Fri, 09 Jan 2026 16:43:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Swavelle-Group-Wearbest-Sil-Tex-Mills</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3258114adb7baf1942c8229b539bc08d84eabb30d58f5e06f0255587d5f88158</i><br /><br />Threat actor <b>description</b>: <i>Swavelle Group Fabric Solutions is a diverse textile supplier that offers a wide array of fabrics suitable for various decorating needs.Wearbest Siltex Mills is a family-run textile manufacturer located in Garfield, New Jersey. The firm serves residential clients and furniture manufacturers.We will upload 165gb of corporate data soon. Detailed personal information of every employee (SSN, passport numbers and scans, DL,birth certificates, addresses, phones, emails and so on), clientdocumentation, projects, NDA, so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>McCraw-Oil</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28601</link>
<guid>b0ada4f4c8f1d05eeb1ce32e241a7c55</guid>
<pubDate>Fri, 09 Jan 2026 15:43:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>McCraw-Oil</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37a3e8b51a91aa325e206df21e4b2e787283c61fbb95747836d461930b70251b</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1948, McCraw Oil provides gas, diesel, propane, agricultural chemicals and other products to service stations and customers in Texas and Oklahoma. Bonham, Texas.We will upload 40gb of corporate data soon. We will upload employee documents, lots of projects, specifications and drawings, NDA,client information, contracts and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Carlson-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28602</link>
<guid>1b11b526a5870e9a37b9aec669d68131</guid>
<pubDate>Fri, 09 Jan 2026 15:17:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>The-Carlson-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1128210813b2e0ce4302abf92c73c16e16cdbecdb7012a2bb5e253b302a6d9b7</i><br /><br />Threat actor <b>description</b>: <i>Established in 1976, The Carlson Law Firm has built a reputation not only for our formidable presence in courtrooms but for our deep-rooted desire to serve the community. Our foundation rests on the shoulders of our Managing Partner, Craig Carlson. A proud veteran, Craig's values are the compass that has guided our firm's journey, helping us grow from a modest establishment in Killeen, Texas, to a renowned legal powerhouse with 17 locations in Texas, an office in California, and another in Florida.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>stignatiusijamsville.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28598</link>
<guid>48699cb3676ece50d68d3e1ebe2e03d7</guid>
<pubDate>Fri, 09 Jan 2026 12:22:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>stignatiusijamsville.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e4777d06500f149d6374ff17aacef3da9c893b518686db68657ac1b5bf378803</i><br /><br />Threat actor <b>description</b>: <i>St Ignatius of Loyola Catholic Community is a company that operates in the Religious Organizations industry. It employs 10to19 people and has under500K of revenue. The company is headquartered in Ijamsville, Maryland Employees: 20 Revenue: $5 Million Industry: Church Management Phone Number: (301) 695-8845 </i><br />Target victim <b>website</b>: <i>stignatiusijamsville.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>About-Women-Ob-Gyn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28596</link>
<guid>df236b5b4ec12e88f2cb714b641b8cc4</guid>
<pubDate>Thu, 08 Jan 2026 21:37:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>About-Women-Ob-Gyn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ccb642acf5512a72821ad833835b16c4a28819a86e2b5f4f0e0f38162684ab11</i><br /><br />Threat actor <b>description</b>: <i>Data Breach at Gynecology Clinic.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spring-Grove-Area-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28585</link>
<guid>c223c9e3210c1fccaae202a1d1d9abaa</guid>
<pubDate>Thu, 08 Jan 2026 18:44:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spring-Grove-Area-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2dffd9e5d9fe1596b3887e059f5a21b235868e29216beea19a6278d070dc968</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Retrofit-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28586</link>
<guid>da56d057fe13171851e819d9be266cf5</guid>
<pubDate>Thu, 08 Jan 2026 18:44:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Retrofit-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>632960225783520fbdc02e91dae25f2fe504089c9ee61a420d438876f6c19f24</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CPJ.ORG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28593</link>
<guid>c57d4c50a6b5969e1244e60155863090</guid>
<pubDate>Thu, 08 Jan 2026 17:47:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CPJ.ORG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe9b6608c49c163468b21a6a63da0a0ac4c9de3c289566093fd2008778b09135</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] CPJ.ORG, or the Committee to Protect Journalists, is a non-profit organization based in New York. Its mission is to promote press freedom worldwide and defend the rights of journalists to report the news without fear of reprisal. It does this by monitoring and documenting violations against press freedom and providing safety guides and other resources for journalists.</i><br />Target victim <b>website</b>: <i>CPJ.ORG</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BORING.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28592</link>
<guid>d6df8e50c3cc76ab487e51448cc1c57f</guid>
<pubDate>Thu, 08 Jan 2026 17:46:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BORING.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd7709ffe79cceea5c99957d923a4c6647fffb78539100d56e6018f08cb1d4d1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>BORING.COM</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TriVector-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28587</link>
<guid>ce651728d53387a4dc56052bc6d035dd</guid>
<pubDate>Thu, 08 Jan 2026 17:44:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TriVector-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cba450f5d7e12546fc6e651ff2bd47f2883c078fdf62813d810506b9347c85c7</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpslpollockpr.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28590</link>
<guid>f1543ed948fae345d291eea0a5968985</guid>
<pubDate>Thu, 08 Jan 2026 16:57:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpslpollockpr.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6a3dba49f4a2adc850561612a55b23ed05dfd45ec16a279fe20fc79fb7c6b55</i><br /><br />Threat actor <b>description</b>: <i>all data  corp / all client data  </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morton-Buildings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28578</link>
<guid>040cea6d24ed05b83f0db871f6794b61</guid>
<pubDate>Thu, 08 Jan 2026 16:43:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Morton-Buildings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dad8c8fac34cee0920bed85c0190b45583ce430bae92ad796443f29ac5c31941</i><br /><br />Threat actor <b>description</b>: <i>Morton Buildings, headquartered in Morton, Illinois, is a companythat specializes in the designs, builds, and constructs of post-frame buildings, including residential, farm and agriculture, equestrian, commercial, office, and community.We will upload more than 100gb of corporate data soon. Employee documents, projects, specifications and drawings, NDA, partner information, contacts and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fedcap</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28588</link>
<guid>9f3fedf17034316a32b96e87686c44d9</guid>
<pubDate>Thu, 08 Jan 2026 15:57:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Fedcap</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47f824b777d46dc73bbeab1ba8ed913e45ec2541d435d7c3c30b2bcc6169e5b0</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1935, Fedcap is a nonprofit organization that creates opportunities for people with barriers to economic well-being. Fedcap's headquarters is in New York City, New York.</i><br />Target victim <b>website</b>: <i>www.fedcap.org</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anteriad</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28579</link>
<guid>0e495e80390ae6477a619c5067c8b16f</guid>
<pubDate>Thu, 08 Jan 2026 15:43:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Anteriad</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4667eac15fb70e56a36c79ac2601223097f8dc26ba06a6dc544fa26a5447bcb2</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>These-companies-havebeen-hacked.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28580</link>
<guid>b24e8379f02a337976cc22e17ade2786</guid>
<pubDate>Thu, 08 Jan 2026 15:43:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>These-companies-havebeen-hacked.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e4e972046a6376d9e7419a74267163613c46e0cd1409e387ed6ae4ea7d611453</i><br /><br />Threat actor <b>description</b>: <i>We didn't take their data but you can try on your own. If you want details, leave your contacts.Gateway FiberShout! FactoryFilmRiseHuebsch ServicesCrawford Software Consulting</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Udall-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28581</link>
<guid>62c27b26606d99ec99bc79d5de20f9d4</guid>
<pubDate>Thu, 08 Jan 2026 15:43:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Udall-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77e49a6bb6a593d7cef588e8769f1eceb73d809a0054f4428ec3274a9188ff4a</i><br /><br />Threat actor <b>description</b>: <i>Udall Law Firm is a reputable legal practice serving clients throughout Arizona since 1952, with offices located in Tucson and Phoenix. The firm offers a wide range of legal services, including business law, personal injury, estate planning, and real estate law, among others. It is dedicated to providing customized legal solutions and responsive communication to meet the needs of its clients.We will upload 78gb of corporate data soon. Large amount of clients' personal information (passport numbers, SSNs, drivers licenses, death/birth certs, financials and so on), NDA, police incidents, confidentiality agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gordon-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28576</link>
<guid>729d1221683eaf66616b5a8b301522d1</guid>
<pubDate>Thu, 08 Jan 2026 14:44:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gordon-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a42613b3905fbc47550af9867473469e9f7bb34f6c697c4949313c5414d391e1</i><br /><br />Threat actor <b>description</b>: <i>Gordon Companies Inc. is a family operated & owned business, Gordon Companies include Pool Central, Christmas Central, Daves and Northlight retail stores.We will upload corporate data soon. Employee personal information(passport numbers, SSNs and other scanned documents), client data, financials, NDA and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Applied-LNG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28577</link>
<guid>2def82558a0b5b01ac62b2bc46cfdb76</guid>
<pubDate>Thu, 08 Jan 2026 12:47:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Applied-LNG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b246de70e5544265e1dc89f91e8a814c720e036158b9ae95e35d478c478ebca4</i><br /><br />Threat actor <b>description</b>: <i>file listing https://gofile.io/d/wsV8hlApplied LNG specializes in providing liquefied natural gas (LNG) solutions for various energy needs, including equipment financing, maintenance, and logistics. The company emphasizes the environmental benefits of natural gas, highlighting its clean-burning properties that contribute to reducing greenhouse gas emissions. Founded in 1995, Applied LNG has over 20 years of experience and expertise in the LNG sector, particularly in the motor fuel market and power generation.</i><br />Target victim <b>website</b>: <i>www.appliedlng.com</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Structures-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28570</link>
<guid>3b5baa4288a1ba4f0ce32ab6f6350603</guid>
<pubDate>Thu, 08 Jan 2026 01:07:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-Structures-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cdff931ffd10443d31515a1bb4b4b7c3b41ab12c2898cebc15e77a137c32ffc2</i><br /><br />Threat actor <b>description</b>: <i>The Structures Group, Inc is a consulting engineering firm specializing in structural engineering, special inspections, and forensic analysis. They offer services including independent review plans and due diligence/risk analysis, catering to a diverse clientele that includes commercial, residential, and institutional projects. Their expertise spans various sectors such as healthcare, education, and justice facilities. The company is committed to delivering high-quality engineering solutions to enhance structural integrity and safety.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evergreen-Printing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28565</link>
<guid>5f221f5f69bcd62696d967a8e84e450f</guid>
<pubDate>Wed, 07 Jan 2026 17:45:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Evergreen-Printing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a635eeacf407b23321b3eb17130838259af8e3128f070bf8569563bf61e21c7e</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Commercial-Paving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28562</link>
<guid>cdd7da5c0696e931cef4d22f7b0cb58c</guid>
<pubDate>Wed, 07 Jan 2026 15:43:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Commercial-Paving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d073fe092f0d6e1877f21889e9107dbed6c5363ea6ba97990dd17198e35656e5</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wilson-Smith-CochranDickerson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28563</link>
<guid>bf96708cdf085ba206fc100ee802b4bb</guid>
<pubDate>Wed, 07 Jan 2026 15:43:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wilson-Smith-CochranDickerson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>669363e99c5b75069b5dfef8cdf2e2de8998119dfe017d743b842a6a5957610e</i><br /><br />Threat actor <b>description</b>: <i>Wilson Smith Cochran Dickerson is a law firm specializing in trial and appellate litigation, providing advocacy and advice for clients dealing with business and casualty disputes.We will upload 120gb of corporate data soon. We will upload numerous files with personal information of clients, lots of court files, police reports, court hearings and other confidential legal files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>RJS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28564</link>
<guid>de6fa2e6abc1e244d7dc3534d3c81e2a</guid>
<pubDate>Wed, 07 Jan 2026 15:43:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RJS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5235523aa46b9b6b0d34ce29e960ca534c97e6cf2a9b706e9643fa2725d9da40</i><br /><br />Threat actor <b>description</b>: <i>RJS Corporation is a global supplier of equipment for the tire manufacturing industry, specializing in products such as tension controllers, creel systems, and specialty tire equipment.We will upload corporate data soon. You will find detailed employee information (SSNs, passport numbers, DLs, addresses and so on), financials, agreements with Goddyear, Bridgestone, Nokia, Yokohama, Michelin, Pirelli and so on, NDAs and other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westlake-Christian-Academy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28569</link>
<guid>7bb09a9a59920da2c778f2ad47a9b1f0</guid>
<pubDate>Wed, 07 Jan 2026 14:22:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Westlake-Christian-Academy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c1878cb3480bb28b1114fbdc90ae8dfe8d110348e62180aea08709f4f0bf7e8</i><br /><br />Threat actor <b>description</b>: <i>Westlake Christian Academy is a private Christian school located in Grayslake. Due to security issues, its database, including its entire student list and staff information, was made publicly available. The staff at this institution exhibits extreme indifference and inappropriate behavior toward its students and staff.</i><br />Target victim <b>website</b>: <i>westlakechristianacademy.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>RGD-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28568</link>
<guid>5a0ff4520c5b59aae5315322f3927d39</guid>
<pubDate>Wed, 07 Jan 2026 14:21:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>RGD-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0aec9aa2ed724a4bd4ee5b226a5158905a35e2f1cd40d6a66c3891c8fb23ee28</i><br /><br />Threat actor <b>description</b>: <i>RGD Consulting Engineers is a full-service engineering firm specializing in mechanical, electrical, plumbing, and structural design, based in Florida. RGD is focused on providing engineering solutions, exceptional customer service, and cost-effective systems. Serving a variety of markets throughout Florida, the United States, and the Caribbean, RGD collaborates closely with its clients.</i><br />Target victim <b>website</b>: <i>rgdengineers.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>strategic-ts.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28567</link>
<guid>b634a18d05447cdccf5f9012450904f2</guid>
<pubDate>Wed, 07 Jan 2026 14:00:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tengu</b> claims attack for <b>strategic-ts.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbd97d37b70e2484faa2ddd7ec872c140ad4b22b9203e8dd1fa9a484626edf36</i><br /><br />Threat actor <b>description</b>: <i>The website https://strategic-ts.com/ belongs to a small US-based IT and technology services company—and serves as the official website for a company called Strategic Technology, which operates in IT services and technical support. This information is based on company data available from professional databases.</i><br />Target victim <b>website</b>: <i>strategic-ts.com</i>]]></description>
<category>tengu</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morgan-Records-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28555</link>
<guid>7a43fa89fbc04c64cd1f481b59db4b45</guid>
<pubDate>Tue, 06 Jan 2026 23:23:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Morgan-Records-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c67252c3f19469f1c701216f6e66e0f90172b8699f77e7bdac732b16840f68e8</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Morgan Records Management is a company specializing in secure document storage, data protection, and document destruction services. They offer solutions for digital transitions, including scanning services, and electronic content management systems. Their focus is on protecting client information, helping businesses save space, reduce risk, and manage data more efficiently. They operate both domestically and internationally.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apex-Spine-and-Neurosurgery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28552</link>
<guid>d741ff8c24fe26717eb3101e2d8d30c1</guid>
<pubDate>Tue, 06 Jan 2026 21:11:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Apex-Spine-and-Neurosurgery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca6c74e8d88a2926101980e85a8d3f55e3d49c9176d8f0706bad285722742e19</i><br /><br />Threat actor <b>description</b>: <i>Apex Spine and Neurosurgery specializes in the comprehensive neurosurgical treatment of spinal and cranial disorders. The team consists of neurosurgeons who offer treatment options, including minimally invasive spine surgery, tailored to the needs of their patients. They serve patients from across Georgia, particularly Atlanta, and emphasize a patient-centered approach. Their services cover a wide range of conditions, including back pain, brain tumors, and trauma.</i><br />Target victim <b>website</b>: <i>apexspineandneuro.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>USArt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28547</link>
<guid>6abdec2606bd68762a72dc1a4038d1ff</guid>
<pubDate>Tue, 06 Jan 2026 19:44:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>USArt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b862d8d3b88d62f702bbc1e9435773a021ca0f70b898aaae87be3c65f70a65a7</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charles-Leonard-Steel-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28551</link>
<guid>254a0aea9ce1d3b9a864f786f4e1f827</guid>
<pubDate>Tue, 06 Jan 2026 19:00:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Charles-Leonard-Steel-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5b875a5aba3352bdc84d105b818604bf56f53759bd8840ae444d37176bf6641</i><br /><br />Threat actor <b>description</b>: <i>Charles Leonard Steel Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Secorp-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28540</link>
<guid>29c5509d98ea56c71fcf591468c48f4f</guid>
<pubDate>Tue, 06 Jan 2026 14:46:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Secorp-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ffa287701f5c0588d311f4720011201757799ad16e5bf11f32c1a08706fe91e9</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medical-Asset-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28541</link>
<guid>9670c7ffe205da4e538326c9691fa4f2</guid>
<pubDate>Tue, 06 Jan 2026 14:46:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Medical-Asset-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bf25be313cacd795b28c624f68b8f6101dfcd2d86488fd308b0b9f9f91ddd3e</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Health-Bridge-Chiropractic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28542</link>
<guid>09bd2862fe3035ad3223816b439045e3</guid>
<pubDate>Tue, 06 Jan 2026 14:46:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Health-Bridge-Chiropractic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>540c4e962faea1a95e9769a8dad6396d51a87cf31fdef322785861ab6c6c2e60</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Due-Doyle-Fanning</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28544</link>
<guid>d4c46cea171bad8d235542b789c591f0</guid>
<pubDate>Tue, 06 Jan 2026 11:56:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Due-Doyle-Fanning</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc95c45f345e7ddebfcf51ff53ce8409afd9535b36c2b7d35dafab5a0e3d830d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.duedoyle.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mill-Brothers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28543</link>
<guid>11b53f23ad385f735495083c7327faf9</guid>
<pubDate>Tue, 06 Jan 2026 11:56:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Mill-Brothers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>375d5bdb0c9637e8f2fab3de1f9a9a99f23a6d213e4508092ea03cc2cb4b4204</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.millbrothers.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CEIVA-Logic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28536</link>
<guid>4c86f3bbcab249f879058d1825887571</guid>
<pubDate>Mon, 05 Jan 2026 17:41:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>CEIVA-Logic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa1af02fc496099679b807fe93ccee2c04c35521bed04c9fa261c151ad5361a1</i><br /><br />Threat actor <b>description</b>: <i>CEIVA is the inventor of the world's first connected digital photo frame, offering a full line of digital frames that automatically receive and display new digital photos every day. Their products allow users to instantly share and showcase digital photos with ease. CEIVA targets customers looking f…</i><br />Target victim <b>website</b>: <i>www.ceiva.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.blackdogsalvage.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28521</link>
<guid>08a1fbda444d0ed569626fdb23520d02</guid>
<pubDate>Mon, 05 Jan 2026 16:48:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.blackdogsalvage.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a280978334e1d15b99ccd60eb5aa5cff726d42ba3768eef4d6a4efe35cc2022d</i><br /><br />Threat actor <b>description</b>: <i>Black Dog Salvage specializes in the reclamation, repurposing and resale of arch...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>crawfordorthodontics.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28522</link>
<guid>d70e32743f8e7a78de2f837c5b4d3833</guid>
<pubDate>Mon, 05 Jan 2026 16:48:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>crawfordorthodontics.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb78969bae98cb73353308eb2ef8588ec0d6956ac5f0cae5c50487766b52bdbb</i><br /><br />Threat actor <b>description</b>: <i>Crawford Orthodontics</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.stcharlesprep.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28523</link>
<guid>16cba01e083801067db052ea5cfd254c</guid>
<pubDate>Mon, 05 Jan 2026 16:48:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.stcharlesprep.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8bcff3bb0260e4b63601725f09bec810f94c53aa5883ae6945a01bb707a6a129</i><br /><br />Threat actor <b>description</b>: <i>St Charles Preparatory School is a company that operates in the Education indust...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.mscorp.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28525</link>
<guid>75a1f82bf4376a1bcfdc5a0bd08ac34f</guid>
<pubDate>Mon, 05 Jan 2026 16:48:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.mscorp.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71d836c6c7716612fbb939e92d92ecf0ce54bca9c92ed9f18140ba435e30bbe2</i><br /><br />Threat actor <b>description</b>: <i>Marine Systems Corporation (MSCorp) specializes in marine engineering, design, p...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.burdettedental.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28526</link>
<guid>0d620a440d7259218ff725f59419a5a1</guid>
<pubDate>Mon, 05 Jan 2026 16:48:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.burdettedental.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3bb2a9cb776dfb0e7c1b2ae5ef12ff58387eb9630aef6fd1b7fe685bcdf593b1</i><br /><br />Threat actor <b>description</b>: <i>Burdette Dental Laboratory, located in Birmingham, Alabama, has over 50 years of...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Posillico</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28531</link>
<guid>34e127b2acf56a344457e1537dce906d</guid>
<pubDate>Mon, 05 Jan 2026 15:44:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Posillico</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6eff8bca43dd0613a5c2c80372a9a9bc746d1c4e3eeb7fdf4048aec419622fcb</i><br /><br />Threat actor <b>description</b>: <i>Posillico is dedicated to setting the standard for excellence in the construction industry relative to: infrastructure, quality oflife, and making a difference by using innovation and solid relationships at all levels.We will upload almost 1TB of corporate data and SQLs soon. We took everything: personal information of employees, projects, contracts and agreements, detailed financials, insurance files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Lewis-Bear</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28532</link>
<guid>07feb1e17b2da92bd4e1f870eaaa6add</guid>
<pubDate>Mon, 05 Jan 2026 15:44:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Lewis-Bear</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06dbd226bc7b8fac7cbbc90c5f8a03372bc4345f581f0542748a839c08c4a85b</i><br /><br />Threat actor <b>description</b>: <i>The Lewis Bear Company Established in 1876, as a grocery company,The Lewis Bear Company is the oldest privately held corporation in Florida. In 1995, the grocery division was sold, leaving a focused beer distribution company.We will upload corporate data soon. Employee scanned documents (DLs, passports and other files), HR files, projects, agreements, detailed financials, customer information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>kiddsservices.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28508</link>
<guid>48033f895a8eb822024e647cc943596d</guid>
<pubDate>Mon, 05 Jan 2026 10:45:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>kiddsservices.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0dd5d3213eea0ac7a07bad0b8328d6b34e7df444f7dd1c08154e8cbc2871db9</i><br /><br />Threat actor <b>description</b>: <i>Kidds Restoration Services is a family-owned restoration company based in Lynchb...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>miltonfl.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28511</link>
<guid>e73902cc3bc6c3bb0534870f6b8272e4</guid>
<pubDate>Mon, 05 Jan 2026 09:44:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>miltonfl.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39db208931c0e9d8be3f616f48ecef7ac8300b59695aa007db9646d6c7b73356</i><br /><br />Threat actor <b>description</b>: <i>MILTON-FL.RESTAURANTS800.COM serves up a guide for restaurants in the city of Mi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Triad-Packaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28520</link>
<guid>dafd2bc3a016e34da1c696cb44993a56</guid>
<pubDate>Mon, 05 Jan 2026 09:38:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sicarii</b> claims attack for <b>Triad-Packaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38eeb5fb15f6a1a5f8d4d81ed6d48e7dd05c680f8fe7c63a63ca21fabb6c6031</i><br /><br />Threat actor <b>description</b>: <i>חברת Triad Packaging סבלה מהדלפת נתונים גדולה. 102 גיגה-בייט של נתונים רגישים נגנבו כולל מסמכים פנימיים, רישומים פיננסיים, ומידע לקוחות. הנתונים יפורסמו בעוד: קבצים אלה ישמשו כהוכחה לנתונים שהתקבלו. כל הנתונים יפורסמו אם התשלום לא יתקבל בתוך 24 שעות. | Countdown: 18h 15m 02s</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sicarii</category>
</item>
<item xmlns:dc='ns:1'>
<title>madisonareaymca.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28496</link>
<guid>206bde0d66915a51fe13c59741767e9c</guid>
<pubDate>Mon, 05 Jan 2026 08:45:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>madisonareaymca.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d90151ee36f43590a61afb60e4f4259c20059cad229daa4e6879b4b2c1ced1e3</i><br /><br />Threat actor <b>description</b>: <i>The Madison Area YMCA offers a variety of programs and services focusing on yout...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>MM-Auto-Parts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28519</link>
<guid>8595663aca75cac5588e45a0b8602baa</guid>
<pubDate>Mon, 05 Jan 2026 07:37:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>MM-Auto-Parts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd9584d7f643ec85f78fb3c540693f2d977ba9f72fd62587a4df71b60080a8d3</i><br /><br />Threat actor <b>description</b>: <i>M&M Auto Parts, Inc. specializes in providing high-quality auto parts, including over 150,000 parts in stock and ready for delivery. They cater to customers looking for affordable replacement parts, offering savings of up to 70% over new parts. The company also features a wide range of aftermarket and remanufactured products, ensuring a comprehensive selection for various automotive needs. Their intended clients include both individual consumers and businesses seeking reliable and cost-effective auto parts solutions.</i><br />Target victim <b>website</b>: <i>www.mmautoparts.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harris-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28513</link>
<guid>f379a3ed36544a264646efdfe79a9212</guid>
<pubDate>Mon, 05 Jan 2026 07:36:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Harris-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9bbc5de65e7501a3a3c96c530f7a8938518daf82c70b602499d559eecf4fd01a</i><br /><br />Threat actor <b>description</b>: <i>Harris Consulting Engineers has been perfecting the built environment since 1983, specializing in mechanical, plumbing, electrical, and data technology services. The firm's dedicated team aims to meet the goals and budgets of their clients. They focus on providing high-quality engineering solutions tailored to the construction and renovation industries. Kent Bell, the President and Owner, leads the company in fostering client relationships and delivering on projects.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Krenzer-Marine-Overview-Metrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28514</link>
<guid>2d15e029e5ab6f925e5cc6447350ad62</guid>
<pubDate>Mon, 05 Jan 2026 07:36:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Krenzer-Marine-Overview-Metrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>407e19a0f62655254fcc892da756f80d3f60d04edc4513f9a6c2661caac1e061</i><br /><br />Threat actor <b>description</b>: <i>Krenzer Marine is a full-service boat dealer located in Sodus Point and Ithaca, New York, specializing in the sale of new and used boats, boat rentals, and expert service. They offer a wide range of boats including fishing boats, pontoons, and cruisers from top brands like Chaparral, Robalo, and Starcraft. The company caters to clients in the Rochester, Syracuse, Finger Lakes, and Lake Ontario areas, providing comprehensive marina support and parts. Krenzer Marine is committed to meeting customer needs with convenient locations and a focus on quality service.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lares</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28515</link>
<guid>8a8aee6f4d29fa77828d4f011a237ea5</guid>
<pubDate>Mon, 05 Jan 2026 07:36:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lares</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c49081268067d11a83086e64900a7566db32d1404aecc44ada72ee64a37dc108</i><br /><br />Threat actor <b>description</b>: <i>Lares Corporation specializes in performance equipment and aftermarket parts for vehicles, aimed at automotive enthusiasts and everyday drivers. They offer a wide range of universal fit components including pumps, pulleys, U-joints, and filters. The company provides various resources such as tech tips, articles, and a catalog for customers to enhance their automotive experience. Lares Corporation aims to empower clients in both performance tuning and regular vehicle maintenance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Boathouse-on-the-Bay</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28516</link>
<guid>9cb7b5ea641f6919eec4a49c7957c6e0</guid>
<pubDate>Mon, 05 Jan 2026 07:35:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-Boathouse-on-the-Bay</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46c6971a74d15009cb7108018f56f1ea94158b54c5c0b107d69917db8c5177c3</i><br /><br />Threat actor <b>description</b>: <i>Boathouse on the Bay is an upscale waterfront restaurant located in Long Beach, offering stunning views and a fine dining experience with a focus on premium steak, seafood, sushi, and cocktails. The establishment features live music and hosts various events, including private parties and corporate gatherings, accommodating up to 200 guests. Guests can enjoy a variety of dining options, including weekend brunch and special holiday events. The restaurant is known for its commitment to exceptional service and creating memorable experiences for its clientele.</i><br />Target victim <b>website</b>: <i>www.boathouseonthebay.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Windward-Life-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28517</link>
<guid>ed45799a50e5fe02ff62fc8aacf2e4d5</guid>
<pubDate>Mon, 05 Jan 2026 07:35:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Windward-Life-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1da44dd575a884da9ba437dd469ff9681711dd520f20cef08f4d1cdfb7248f8f</i><br /><br />Threat actor <b>description</b>: <i>Windward Life Care offers premier home care, aging life care management, and home health care services specifically designed for older and disabled adults in San Diego, CA. Their services include personalized Aging Life Care Management, companionship, transportation, personal care, and skilled nursing services. With over 20 years of experience, they focus on enhancing the quality of life for their clients by providing exceptional support and navigating the complexities of health care. Windward Life Care aims to foster independence and safety for their clients within the comfort of their own homes.</i><br />Target victim <b>website</b>: <i>windwardlifecare.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wesley-Heating--Cooling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28518</link>
<guid>dd04b0cb9dc44609df0f78c4960e9589</guid>
<pubDate>Mon, 05 Jan 2026 07:35:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Wesley-Heating--Cooling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d163fcba5d15d947c803383695480fb485151efbe80c1f79b7c578f8298a28a6</i><br /><br />Threat actor <b>description</b>: <i>Wesley Heating & Cooling is an HVAC company based in Green Bay, Wisconsin, specializing in heating, cooling, and air conditioning services since 1951. They offer repair, replacement, and maintenance services for various heating and cooling systems, including geothermal heat pumps and ductless mini-splits. Their intended clients include homeowners in Green Bay, Oshkosh, Fond du Lac, and surrounding areas, looking for reliable and efficient HVAC solutions. Wesley Heating & Cooling is committed to customer satisfaction, providing community service, maintenance plans, and financing options for new installations.</i><br />Target victim <b>website</b>: <i>www.wesleyheatingandcooling.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28503</link>
<guid>3bb7e223dd6fe07da16874517cf3fa54</guid>
<pubDate>Mon, 05 Jan 2026 06:28:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>American-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c57b8ad9c032e3819b433fa7ed61eb0504b8314c88883a9a751c79c8a8f41f76</i><br /><br />Threat actor <b>description</b>: <i>American Health provides a comprehensive array of healthcare services including hospital operations, emergency medical services, and smart clinics. The organization is focused on delivering world-class education and training for healthcare professionals such as physicians, nurses, and EMTs through their AH Academy and specialized programs. Their intended clients encompass a wide range of healthcare needs, including home healthcare and support for special needs individuals. With a commitment to quality and patient experience, American Health aims to improve healthcare delivery across various sectors.</i><br />Target victim <b>website</b>: <i>americanhealth.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>GreenValley-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28497</link>
<guid>0704b08c67807572593dba22b536d449</guid>
<pubDate>Mon, 05 Jan 2026 06:27:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>GreenValley-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba04bdd8211019a25515bceea8824814c2d1f314d2421bf61881e33a335c958a</i><br /><br />Threat actor <b>description</b>: <i>GreenValley International Inc (GVI), based in Berkeley, California, is a leading innovator in 3D mapping technologies, offering a diverse range of aerial, terrestrial, and mobile LiDAR survey and mapping hardware systems along with advanced software solutions. Their product lineup includes various laser scanning platforms and the LiDAR360 data processing platform, catering to industries such as forestry, power line inspection, mining, and utilities. GVI specializes in LiDAR and image fusion technology, focusing on achieving precise digital representations of three-dimensional spaces. Committed to innovation, GVI continues to expand its technological capabilities in the LiDAR sector.</i><br />Target victim <b>website</b>: <i>www.greenvalleyinternational.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>NLFX-Professional</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28498</link>
<guid>7425da72a486e6097524b74f9f242765</guid>
<pubDate>Mon, 05 Jan 2026 06:27:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>NLFX-Professional</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ca2b4526d94a741bae63d94a124a4375da6f4a9f0ab9bb8b4dbc5e27c92359f</i><br /><br />Threat actor <b>description</b>: <i>NLFX Professional is an award-winning leader in the audio, video, and lighting industry, specializing in selling equipment and providing product integration solutions. They offer a wide range of products, including pro audio, lighting systems, video streaming gear, and musical instruments, catering to clients in various sectors such as entertainment and worship. With a focus on customer satisfaction, NLFX provides exceptional technical support, financing options, and expert installation services. They are certified dealers for over 300 top-rated professional manufacturers, ensuring high-quality offerings for their clients.</i><br />Target victim <b>website</b>: <i>www.nlfxpro.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lampire-Biological-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28501</link>
<guid>65378614c4adbc65cc1643a8bd221e59</guid>
<pubDate>Mon, 05 Jan 2026 06:26:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lampire-Biological-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f4253c0b68227f31394ed2b3327b6402f6381152d87f37feb66609e936ac7d2</i><br /><br />Threat actor <b>description</b>: <i>LAMPIRE Biological Laboratories, a pioneering biotech life science firm specializing in the creation and supply of vital biological reagents for the diagnostic and pharmaceutical industries. Our extensive offerings encompass tailor-made polyclonal and monoclonal antibody development, secondary antibodies, IgGs, BSA, animal blood, tissues, and organs. We also provide both normal and disease-state human serums and plasmas, along with cutting-edge cell media, OMNI C3 cell culture bags, contract manufacturing solutions, and an array of technical support services.</i><br />Target victim <b>website</b>: <i>www.lampire.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pools-by-Bradley</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28502</link>
<guid>a472370cd24972948ca543bcb05a29b2</guid>
<pubDate>Mon, 05 Jan 2026 06:26:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pools-by-Bradley</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>faaac73142407dc1bf82698ae532199c540f41e2463d6a68160af4729df23b98</i><br /><br />Threat actor <b>description</b>: <i>Pools By Bradley specializes in designing and building custom outdoor pools and spas tailored to individual client needs in Central Florida, particularly in Orlando. Their services include a variety of enhancements such as water features, lighting effects, and entertainment elements to create a unique pool experience. The company caters to a diverse clientele, ranging from families to exercise enthusiasts, ensuring that each pool reflects the client's vision and ambient style. With a focus on quality craftsmanship and exceptional customer service, Pools By Bradley has established a strong reputation in the industry.</i><br />Target victim <b>website</b>: <i>www.poolsbybradley.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>IDeaS.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28493</link>
<guid>3126ed973cbecde2bbffe419f139f456</guid>
<pubDate>Mon, 05 Jan 2026 03:59:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>IDeaS.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5854cecc20e22b5ab89b4ef2c98e7ef0a15cb7ab7b4542d1969565138e7e301b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] IDeaS is a global technology company specializing in revenue management solutions. They provide innovative software and services for profit optimization, forecasting and pricing to businesses like hotels, parking facilities, and rental agencies. Using advanced analytics, they help clients make data-driven decisions to increase revenue, control costs, and optimize business operations.</i><br />Target victim <b>website</b>: <i>IDeaS.com</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Resource-Corporation-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28492</link>
<guid>297e6e1f21723046a8c1115ec1a8b8a7</guid>
<pubDate>Sun, 04 Jan 2026 19:22:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Resource-Corporation-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3ad65844ce901f0d115ca95eac5013b0146975722271554942dc9d61d6730653</i><br /><br />Threat actor <b>description</b>: <i>Resource Corporation of America specializes in converting hospitals' at-risk dollars into revenue, focusing on third-party eligibility solutions. With over 30 years of experience, they have achieved a 93% certification success rate and have managed more than two billion dollars in patient account charges. Their services are aimed at hospitals navigating complex healthcare policies and regulatory changes. The company stands as a trusted partner for healthcare leaders seeking to optimize revenue amid evolving Medicaid reforms. 
The company headquarters is located in 1120 Marina Bay Dr, Kemah, TX 77565, United States.
201-500 Employees
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cal-Spas-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28490</link>
<guid>9e020ebb181dfd3fb1229c6ceb076a60</guid>
<pubDate>Sun, 04 Jan 2026 13:43:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cal-Spas-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff71f74ade6f73e6c44d0f46e69c72dce0f1a7f8efca987955574811236ca349</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>KwikLedgers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28482</link>
<guid>67da624214ee8e89992ce70459e669a3</guid>
<pubDate>Sun, 04 Jan 2026 05:53:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>KwikLedgers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d60896743fbfeb225232ef911c8b37e1edd2b0c8bf5e7db30aceaa8212c239db</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>kwikledgers.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>Youngblood-Tyler--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28480</link>
<guid>3ec7b0f8bc5bf7eb2a73ea78a115d94a</guid>
<pubDate>Sat, 03 Jan 2026 19:18:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Youngblood-Tyler--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e83dd19602fc9a230b30b780cd866be50eca7239e5ef960f093673085ec92307</i><br /><br />Threat actor <b>description</b>: <i>Youngblood, Tyler & Associates, P.C. is a leading firm specializing in civil engineering, land surveying, site development, and land planning, serving clients in Virginia, North Carolina, and West Virginia for over 50 years. Their comprehensive services include environmental assessments, drainage system design, surveying for residential and commercial projects, and detailed site development planning. The company fosters strong client partnerships throughout all phases of development, addressing needs from land purchasing to zoning and government approvals. With a dedicated team of professionals, they emphasize quality service and tailored solutions for each project.</i><br />Target victim <b>website</b>: <i>www.youngbloodtylerassociates.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Borough-of-Moonachie</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28474</link>
<guid>f50ebce922538b3c57a3e6b7bbb6d628</guid>
<pubDate>Sat, 03 Jan 2026 17:17:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Borough-of-Moonachie</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be0a8872a6e25d2f70112b7b2729e79761fb68ebb8ee312b3969648b2fcaa8c7</i><br /><br />Threat actor <b>description</b>: <i>On April 11, 1910, Moonachie was finally incorporated as a borough. That same year, the Board of Education and the Moonachie Fire Company were organized. Town life in Moonachie, during these days, was centered around family, farms and the church.  Robert L. Craig became the first Mayor. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>mtspokanepediatrics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28475</link>
<guid>4b8fd3f079e7f86de2eb88ff847effee</guid>
<pubDate>Sat, 03 Jan 2026 15:34:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>mtspokanepediatrics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95aa5125ac2ce10bdad1efc99d74cd1d3a7a4c004304c282aa53ee90216459ef</i><br /><br />Threat actor <b>description</b>: <i>Mt. Spokane Pediatrics offers comprehensive healthcare services for patients from birth through youn...</i><br />Target victim <b>website</b>: <i>mtspokanepediatrics.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>UBS-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28470</link>
<guid>5af7c96251ec5ea316631afea1456741</guid>
<pubDate>Fri, 02 Jan 2026 21:44:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>UBS-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfd801ad4f54579bb2be1555d836d3d2f5c7f96a73510169ae3ed35a489a77de</i><br /><br />Threat actor <b>description</b>: <i>United Business Systems specializes in simplifying the management of hardcopy and digital documents for various industries, with a strong focus on education. Th...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ellison-Educational-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28462</link>
<guid>001d908c7637618bb0a8af0c8be5cd41</guid>
<pubDate>Fri, 02 Jan 2026 19:44:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ellison-Educational-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7ac189f53b3b88565c98adb76d5e30a5daed95496181f928f937ca91bfb8fe7</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sai-Oral-SurgeryOral</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28456</link>
<guid>d1f8643fbc2b43ef133eec4e483b3565</guid>
<pubDate>Fri, 02 Jan 2026 18:45:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sai-Oral-SurgeryOral</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14e93fa1bd6a1b341a0fa406b8dd232ac9faef201a11ba293e3bd98b1f72201d</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>McKenzie-SewOn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28458</link>
<guid>1d0d4779bbefa4ccc9dfb920a110f05a</guid>
<pubDate>Fri, 02 Jan 2026 18:45:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>McKenzie-SewOn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>133b32e68717940df1154377caaca9ac7f4cc6ffaa8200c9fd4bd4c4f027e030</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>j-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28461</link>
<guid>2f9fe1e3d5d2749628ccbd9e7d3f377b</guid>
<pubDate>Fri, 02 Jan 2026 17:44:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>j-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a04020bef39be0346aa9a360f2a2d03792ad588aee0e602d510a073f3b01a5f</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lakeside-Title-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28469</link>
<guid>6d8470222cb0e9ca1519ab84406ef2b2</guid>
<pubDate>Fri, 02 Jan 2026 13:06:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Lakeside-Title-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3a04b4b2c4747bba4323515e9394b7f3beb4b8e27d1d06cd19027c8184e8603</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.lakesidetitle.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wardell-Builders</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28468</link>
<guid>1b975b9f0481510eafbbfb055280e433</guid>
<pubDate>Fri, 02 Jan 2026 13:06:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Wardell-Builders</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>996bfca57b77da4522d1a4db31ef9f079d0049b822f5ddde47c8ee6d8033fd3f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wardellbuilders.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garner-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28467</link>
<guid>7363e32af3e3a10f22af512c70068958</guid>
<pubDate>Fri, 02 Jan 2026 13:05:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Garner-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7261da066970d9b4980713bb5354f227722324680e28fac03ece129abfa63303</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.garnerfoods.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Benise-Dowling--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28465</link>
<guid>3e59327f1a6ccf540d9878cf8c991278</guid>
<pubDate>Fri, 02 Jan 2026 13:04:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Benise-Dowling--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e7dfe7f56165fa86f24885cc5db257433edbbde65377500753ee7b92d506efd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.benise-dowling.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rockport-Technology-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28455</link>
<guid>1fd6b8f9b13318adc358fca5d1ea1b5b</guid>
<pubDate>Fri, 02 Jan 2026 12:06:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Rockport-Technology-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ebc9f66bcac7c3170a0d18c9bbd43e7e31da2548fd132dd3d4e1cb9755dc34d2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rockporttech.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stoughton-Steel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28454</link>
<guid>0334bbbe24552d27a5c4c2dcc41570c3</guid>
<pubDate>Fri, 02 Jan 2026 12:05:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Stoughton-Steel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2eeb6adc76040e04df2015ad2d6f3cfb25ea64e87112a1430d3147d5b4e4c757</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.stoughtonsteel.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barnes--Jones</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28450</link>
<guid>7fa37b4aadce3de52314aa3ff5c6673d</guid>
<pubDate>Thu, 01 Jan 2026 17:44:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Barnes--Jones</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a65499d4ec33684e9155408e25e9c66a468ea0edd671ad1c56764b5f3ae14a61</i><br /><br />Threat actor <b>description</b>: <i>Barnes & Jones was founded before the turn of the century by two engineers: Walter Barnes, a graduate of The Massachusetts Institute of Technology, and Bill Jon...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Infinite-Computing-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28449</link>
<guid>7faf67c63084cf8345243e912885f1a5</guid>
<pubDate>Wed, 31 Dec 2025 17:01:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Infinite-Computing-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3c4fea5230f835a196510bcadd05de0b35de2bf9733d8b7346d9976d5072293</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.infinite-usa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>BNZ-Materials</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28445</link>
<guid>4eedf3f92629bc3b1a208cfaacc4b2d2</guid>
<pubDate>Wed, 31 Dec 2025 16:54:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>BNZ-Materials</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>938cbfd77abc3820b4af185bacdcc2d70cbe7cad9fac1344de40c4cd837bb452</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hunneman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28448</link>
<guid>8e14f4de91da22108a5247cc18253a0a</guid>
<pubDate>Wed, 31 Dec 2025 14:57:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Hunneman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0aee2d61874662c282eb8469774b2d662572e5081fa27804ec41de50f419aff5</i><br /><br />Threat actor <b>description</b>: <i>Hunneman, founded in Boston in 1929, is a real estate firm that offers a full range of real estate brokerage, leasing investment sales, and management services.</i><br />Target victim <b>website</b>: <i>htpps:www.hunnemanre.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Z-Tronix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28444</link>
<guid>ab1513164c86afa5d30f46b482c3030a</guid>
<pubDate>Wed, 31 Dec 2025 11:43:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Z-Tronix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd7eab6b1ed4d7ef9d85b5ef2f67d1889919f21ee43f85a4097c41478d95d0cc</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.z-tronix.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quasar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28443</link>
<guid>c2db5ca3f8789c124affa4023764635d</guid>
<pubDate>Wed, 31 Dec 2025 11:43:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Quasar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2012f849e5e6980bdcb3e72355e988e37071ca0c84ad8c606244655956d178d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.quasardata.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burnham-Brown</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28440</link>
<guid>d79af587a459b1a0ae549a11190e0853</guid>
<pubDate>Wed, 31 Dec 2025 10:26:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Burnham-Brown</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bd525e096979c7a433d61246d16757d5a332e22f94710b138e550541c10cde7</i><br /><br />Threat actor <b>description</b>: <i>Burnham Brown is a law firm based in Oakland, California that provides legal services in various practice areas including retail and hospitality, real estate, business and commercial, as well as employment law. The firm caters to clients across industries such as transportation, logistics, and manufacturing, helping them navigate legal risks and compliance issues. They offer updates and resources on changes in law and industry-related news to inform their clients. Additionally, Burnham Brown conducts events and discussions to engage with the community and provide insights on evolving legal matters.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sedgwick-Government-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28438</link>
<guid>4f3e1a55bdd71769da5e20b374f20f43</guid>
<pubDate>Tue, 30 Dec 2025 22:40:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>Sedgwick-Government-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f827a76a698b5c3fdaa04521fbab29666565414991b76c0f693912f238231ff</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Sedgwick Government Solutions is part of Sedgwick, a leading global company specializing in risk and benefits solutions. The company offers expertise in different sectors including, health, property, casualty, disability and productivity. It is recognized for its technology and innovation-driven approach to provide comprehensive risk and benefits solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>OSI-Systems-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28439</link>
<guid>20a79e1ab3a172d48f5f78498616ec4d</guid>
<pubDate>Tue, 30 Dec 2025 22:23:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>OSI-Systems-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c87e834c7b9fa7fed05d47b898edfad8615e9d06ae4da8aeeae6e1ce93be1a8f</i><br /><br />Threat actor <b>description</b>: <i>OSI Systems, Inc.  Total data in the leak: 250GB  Leaked data: - Clients: US Government, US Secret Service, IDSS, GLOBAL AEROSPACE INC, Governments of many countries, Casco Automotive Singapore Pte Ltd, Medtronic, Opengear Inc,  Sick Sdn Bhd, ST JOSEPH HOSPITAL, SSM HEALTH CARE CORPORATION, UPMC HEALTH SYSTEM and many other large clients all over the world! - Data Classification: Secret - Projects: Raven, Canopy, SPARK, Lighthouse and many other projects. All project information: development, laboratory testing, drawings, subcontractors, suppliers. - Financial data: Company structure. Company income and expenses, shareholders information, such as BlackRock, Inc. and many other investors. Nasdaq data. Contracts with customers and suppliers, NDA contracts. And a lot of other VERY IMPORTANT information! </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Midkiff-Muncie--Ross-P.C</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28435</link>
<guid>dec8b1ac1258d33ac95d675366558a27</guid>
<pubDate>Tue, 30 Dec 2025 16:37:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Midkiff-Muncie--Ross-P.C</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f0e509732a9c4f1fd8c836ce0945b57e43fc62b3cff4d34d863d619d45af88a</i><br /><br />Threat actor <b>description</b>: <i>Midkiff, Muncie & Ross, P.C</i><br />Target victim <b>website</b>: <i>midkifflaw.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Falk-Waas-Hernandez-Cortina-Solomon--Bonner-Overview-Metrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28436</link>
<guid>dd473ece077230d91b9340e3b4e57c11</guid>
<pubDate>Tue, 30 Dec 2025 15:07:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Falk-Waas-Hernandez-Cortina-Solomon--Bonner-Overview-Metrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc194b0180896c327ec5b29d2b6cb64062f59fbcb28a9a79cebe567f52462a01</i><br /><br />Threat actor <b>description</b>: <i>Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fitzpatrickhotels.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28427</link>
<guid>07614251f62899912b42cf137c9b7a3e</guid>
<pubDate>Tue, 30 Dec 2025 11:55:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cloak</b> claims attack for <b>Fitzpatrickhotels.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f46763fd316dfc27a1d3635e5c6aa1cc8862dd4812ac209a30f17e35e51d90db</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cloak</category>
</item>
<item xmlns:dc='ns:1'>
<title>collinscomputing.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28428</link>
<guid>fdf7a157d555f8ac35f2a820488c342c</guid>
<pubDate>Tue, 30 Dec 2025 11:54:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>collinscomputing.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8b6a2b9923814c039e78d660b16f060d340d96c07d62bf42e61b8513709701b</i><br /><br />Threat actor <b>description</b>: <i>Collins Computing specializes in providing accounting software solutions, focusing on 
Acumatica Cl...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>davidrosenbakerysupply.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28425</link>
<guid>91983ccf17b3200975d9e3d8a09236a8</guid>
<pubDate>Mon, 29 Dec 2025 20:13:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>davidrosenbakerysupply.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b9e3cde421ddecc04cd0c5c1cfe96617297f38b67ea786feaa1df57be39db2f</i><br /><br />Threat actor <b>description</b>: <i>David Rosen Bakery Supply is a long-established wholesale bakery supply and distribution company headquartered in Maspeth, New York, serving commercial …</i><br />Target victim <b>website</b>: <i>davidrosenbakerysupply.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>moorelumber.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28423</link>
<guid>0014fcb3db4c8459d26309b177005b10</guid>
<pubDate>Mon, 29 Dec 2025 20:12:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>moorelumber.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5409eaaa90f45f3502d115469b98cf0d853d0616c649ac294e842d43a1548de2</i><br /><br />Threat actor <b>description</b>: <i>Moore Lumber & Hardware Co. is a U.S. building-materials retailer and hardware supplier based in Ayer, Massachusetts. Founded in the …</i><br />Target victim <b>website</b>: <i>moorelumber.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>sproutnet.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28420</link>
<guid>ebe048f25228d088e0216147377171b2</guid>
<pubDate>Mon, 29 Dec 2025 20:10:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>sproutnet.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8853a3cde2d02c8f181e737cef3600dab647f3a40e2519bdc44eb5238a9f8a60</i><br /><br />Threat actor <b>description</b>: <i>SproutNet — operating under International Specialty Supply — is a U.S. producer and supplier of sprouting seeds, sprouts, natural ingredients …</i><br />Target victim <b>website</b>: <i>sproutnet.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Genoa-Lakes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28417</link>
<guid>7854c8701c5da6d80d602a20133d2bf8</guid>
<pubDate>Mon, 29 Dec 2025 20:05:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Genoa-Lakes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7970da5a7aeedc0f54b549e0f49401be4c0ae8541bebc322392af2eb6c83b778</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.genoalakes.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Esquire-Brands</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28407</link>
<guid>e2701537f72184bb152aa9d26a93ecca</guid>
<pubDate>Mon, 29 Dec 2025 20:04:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Esquire-Brands</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3e84fc20b172b0f5d5b30b08dfccbe8ed711998031bf6e142ee188e4dacd56c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.esquirebrands.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>JZ-Russell-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28416</link>
<guid>f9989a9443ac061cf808a80bb8edb46c</guid>
<pubDate>Mon, 29 Dec 2025 20:04:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>JZ-Russell-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e55310f9a01b84653f2401562eed088b3c95db336eebabd027ede13aa75cc1e4</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jzrussellind.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cr-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28414</link>
<guid>98c9832865e4ab224a1649e8e6e9a2a0</guid>
<pubDate>Mon, 29 Dec 2025 20:03:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cr-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a47b843022411f385189a69b63485331c5ec985c4cafe5cbfd0984da0c6ae23f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.candrelec.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burnex</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28403</link>
<guid>a90ab441fabcbbac21aaf1360076bd8d</guid>
<pubDate>Mon, 29 Dec 2025 18:43:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Burnex</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d21ff9cb2f3e4d77212a3e7096fd0c3e0f4b840f7a43536382dc8f653b22ac6</i><br /><br />Threat actor <b>description</b>: <i>Burnex Corporation is a leading manufacturer of precision metal stampings and wire forms, offering both custom and standard metal parts for various industries s...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>NK-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28404</link>
<guid>9744c8cf184ceb07cf5c2bbce1489eb3</guid>
<pubDate>Mon, 29 Dec 2025 18:43:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>NK-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17b252256fd9cd58762801818ab64e5bf142c77ee180ef2f9ce39a70c49d545f</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1982, NK Technologies is a current sensing technology manufacturer and distributor headquartered in San Jose, California. Products include sensing sw...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Willowdale-Steeplechase</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28395</link>
<guid>78b9508436357acbab1aabb76e12739f</guid>
<pubDate>Mon, 29 Dec 2025 10:43:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Willowdale-Steeplechase</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c43ffffe65514333cef24ca388cc55b0949c5279259d3abfeb268809d8faca1</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>APC-Home-Health-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28394</link>
<guid>7c3a966d88a80726a95c2e16e56c3997</guid>
<pubDate>Mon, 29 Dec 2025 06:17:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>APC-Home-Health-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6509208384b14b609906d5eb37feca75ab452968fd58a5756333b6fc514742d9</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1982, APC Home Health Services is a home care provider, servicing Harlingen, Texas. Their services allows the elderly to stay in their home and receive medical care for health conditions, receiving assistance with daily tasks or homecare during day or night depending on their need.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goodwin-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28385</link>
<guid>900e9a6cea0b0ddfecbfba02cc20b13f</guid>
<pubDate>Sun, 28 Dec 2025 20:52:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Goodwin-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1189e7664e0329fc3c0133c937f4d66ed38b3332dd8ba5fbd3885be53c48abc9</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neurological-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28384</link>
<guid>d7260db1e48d63995af17ebc0390a5a3</guid>
<pubDate>Sun, 28 Dec 2025 16:56:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Neurological-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6e24f510276a0c1110714a4783ab27c1ca5e13346cced3559b97e25a61e9e22</i><br /><br />Threat actor <b>description</b>: <i>Neuro Associates, located in Kirkland, Washington, is a neurology clinic established in 1974 with a team of four highly experienced neurologists. The clinic off...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Intonu.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28388</link>
<guid>b59978537754917c2df87b96ac795ef2</guid>
<pubDate>Sun, 28 Dec 2025 15:48:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>Intonu.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a9d8e9a62907869a47fa584bfdd9e32a97dc31026c35e929fee8bc3a2642025</i><br /><br />Threat actor <b>description</b>: <i>Financial, Hr documents, claims</i><br />Target victim <b>website</b>: <i>Intonu.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jennings-SD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28390</link>
<guid>1792c408f2a894f77fbbeb5f57c210a1</guid>
<pubDate>Sun, 28 Dec 2025 15:45:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>Jennings-SD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c53c2fda7da9171c9894a6831cab00331f52c62f34b61c3bf62a30aa5d29f1fb</i><br /><br />Threat actor <b>description</b>: <i>Financial data, HR data</i><br />Target victim <b>website</b>: <i>Jennings SD</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>sharinc.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28391</link>
<guid>2abbb2e05e3945e87fcae7d3186a03be</guid>
<pubDate>Sun, 28 Dec 2025 15:44:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>sharinc.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ec57d49e4522cab94e82ea176fdc281b616c0c05030b38291f0cca9f32f8944</i><br /><br />Threat actor <b>description</b>: <i>Financial, Custommer data</i><br />Target victim <b>website</b>: <i>sharinc.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>JBS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28382</link>
<guid>3010a3b06b878fde04e1e207df23bb53</guid>
<pubDate>Sun, 28 Dec 2025 08:00:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>JBS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45b5063529dd284397a1bc81a66a17bf4eb698a72029370b676e14a44a97e775</i><br /><br />Threat actor <b>description</b>: <i>JBS is a regional, public, nonprofit corporation established under Act 310 of the 1967 Alabama Legislature. The region served by the Authority is designated in the State Mental Health Plan as Region M-5, and comprises Jefferson, Blount and St. Clair counties, with a total of more than 800,000 residents. There are three mental health centers which serve the region. It is the responsibility of the Authority to plan, coordinate and develop the system of mental health services for the entire region. The Authority provides consultation regarding program development and funding; coordination of regional programs; delivery of region-wide services; and a consolidated budgeting process to simplify the funding of programs at the local and state level.
company is headquartered in 940 Montclair Rd., Birmingham, AL 35213, USA.
201-500 Employees, The total amount of data leakage is 168.6 GB.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>ryc.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28377</link>
<guid>36677a1d815d4528bebf89833d168f56</guid>
<pubDate>Sat, 27 Dec 2025 20:43:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>ryc.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b67c9138e86fb4626529ec3334351f8641d7b0c31b201253503051f522cd25c3</i><br /><br />Threat actor <b>description</b>: <i>Raritan Yacht Club (RYC) is a private, member-owned recreational club located in Perth Amboy, New Jersey, with a history dating …</i><br />Target victim <b>website</b>: <i>ryc.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>debralmorrison.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28375</link>
<guid>61204932bccb948357e1a0281de24080</guid>
<pubDate>Sat, 27 Dec 2025 20:42:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>debralmorrison.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b1418646c6b02ca94ae34bc9eb2ebd94ad7696402daa3c14395edea2c8893cdf</i><br /><br />Threat actor <b>description</b>: <i>Debra L. Morrison operates a professional coaching, speaking, and financial education practice associated with the domain DebraLMorrison.com, which serves as …</i><br />Target victim <b>website</b>: <i>debralmorrison.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>hmpccpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28374</link>
<guid>abf57562806a737f3f8456b63b50f5ff</guid>
<pubDate>Sat, 27 Dec 2025 20:41:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>hmpccpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05bf3b319ce8cc0654cfb755b2131e852f62b4395a32d5034fa433365b0b248d</i><br /><br />Threat actor <b>description</b>: <i>Harvey & Martin, PLLC is a professional accounting firm based in Massachusetts, United States, with additional offices in Gloucester, MA …</i><br />Target victim <b>website</b>: <i>hmpccpa.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>larosadelmonte.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28370</link>
<guid>414c073ee1379bd7bc7b332159cab1e6</guid>
<pubDate>Sat, 27 Dec 2025 20:39:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>larosadelmonte.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>139b637a055438b666e922beac95b5c910d7bc76aa3d5910808fce1fbaab05b7</i><br /><br />Threat actor <b>description</b>: <i>La Rosa Del Monte is a long-standing family-owned moving and logistics company based in Bronx, New York, with operations extending …</i><br />Target victim <b>website</b>: <i>larosadelmonte.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Georgia-Dermatology--Skin-Cancer-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28307</link>
<guid>22533fb038725070faa56e0d03825120</guid>
<pubDate>Fri, 26 Dec 2025 18:15:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Georgia-Dermatology--Skin-Cancer-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4c4a829375c75d146adc82a8b9fc21e24a2ccf0c56cad3efb67f0068609eda4a</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ortho-Mattress</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28308</link>
<guid>55dd9b82d52ce59b5faeabc5667d5c01</guid>
<pubDate>Fri, 26 Dec 2025 18:15:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ortho-Mattress</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>544fd58b09994b3aff65c2560ca79fb6014f4a6d2a6a9fc5cff2f0db3f3a85d2</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>mc2engineers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28331</link>
<guid>cfb32325857e9b4e076699ee4c6afaee</guid>
<pubDate>Fri, 26 Dec 2025 15:37:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>mc2engineers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9474d45b8e7f24d01759b6866005b7e23317532f9fe3133127bbb3ad5091e29</i><br /><br />Threat actor <b>description</b>: <i>MC Squared is a regional engineering consulting firm specializing in geotechnical, environmental, ma...</i><br />Target victim <b>website</b>: <i>mc2engineers.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>npiav.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28310</link>
<guid>0237aedd1eafebe97db4611a4328b141</guid>
<pubDate>Fri, 26 Dec 2025 15:21:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>npiav.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57eec1f10e3600b736e7b963a8b688c1e1225cc7c191496b7963ad17fd270a3e</i><br /><br />Threat actor <b>description</b>: <i>NPi Audio Visual Solutions specializes in providing top-notch audio visual rental and staging servic...</i><br />Target victim <b>website</b>: <i>npiav.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>itgsolutions.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28313</link>
<guid>83be9a147d7cebfb58df77f586ad919a</guid>
<pubDate>Fri, 26 Dec 2025 15:20:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>itgsolutions.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2793dd3e07d9502f44f6ca3a30da37b4f62f954572fc80f9311afb47e8744ca2</i><br /><br />Threat actor <b>description</b>: <i>Integrated Technology Group (ITG) specializes in providing technology solutions tailored for the edu...</i><br />Target victim <b>website</b>: <i>itgsolutions.com</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Progressive-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28304</link>
<guid>a0845f6123cde73d218c375817c81083</guid>
<pubDate>Fri, 26 Dec 2025 15:12:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Progressive-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54f1e8088db83f4f0f164b06c09bb5e10d3e09abb495b913145f2eb4d2ba00bd</i><br /><br />Threat actor <b>description</b>: <i>Progressive Laboratories, Inc. specializes in producing targeted nutritional supplements specifically for healthcare professionals.We will upload corporate data soon. Financials, employees files, projects, contracts and agreements, NDAs and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ruhrpumpen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28305</link>
<guid>8d57c03206c460f9e9637e46b8337713</guid>
<pubDate>Fri, 26 Dec 2025 15:12:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ruhrpumpen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0932ab45e8a1eab16ee00e12a06219aeedf6d06ef6805e141a0c143ebc397b2c</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2000 and headquartered in Tulsa, Oklahoma, Ruhrpumpen Group designs manufactures, and supplies pump and pumping equipment. The Company produces overhung pumps, vertical pumps, hydraulic decoking systems, fire pumps, and other products.We will upload 142gb corporate data soon. SSNs of almost 600 employees and other personal information, detailed financials, projects, contracts and agreements, NDA, numerous project files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>CSA-Tax--Advisory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28302</link>
<guid>b806521ac395b5b8474a8e3e81ab50f9</guid>
<pubDate>Fri, 26 Dec 2025 14:48:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>CSA-Tax--Advisory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1632cfc7f92df56914eabc98c3d7267c09c119959bc1f908f89a1a8f24491b50</i><br /><br />Threat actor <b>description</b>: <i>CSA Tax & Advisory is a licensed accounting firm based in Haverhill, MA, special...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Madera-County-Superintendent-of-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28294</link>
<guid>caeb849de01d6c60e5eefb19f3719471</guid>
<pubDate>Thu, 25 Dec 2025 18:55:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Madera-County-Superintendent-of-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c303744c661d29fd63f97ae5f850043886b08249b13b6deef0fe7b0709446248</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>io.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28296</link>
<guid>863077711ff23e3a4cc4ddb915cc02f5</guid>
<pubDate>Thu, 25 Dec 2025 18:50:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>io.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c847ef199ac36f5a4b320053efb92dc00c9492ca0a477836bc060ed08b5fe88</i><br /><br />Threat actor <b>description</b>: <i>Financial, Hr documents, claims</i><br />Target victim <b>website</b>: <i>i**o**.us</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chrysler</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28298</link>
<guid>2e668e3f91f3ea4db52a8d56c556a0d5</guid>
<pubDate>Thu, 25 Dec 2025 17:53:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Chrysler</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1cb2b24b554c8e4da341ad7eba89917db90d03d221ad65386c6392693981d570</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Chrysler is an American automobile manufacturer that was first established in 1925. Known for their range of reliable family cars, luxury sedans, and sporty convertibles, the company has a significant role in the global automotive industry. It was founded by Walter Chrysler, and is currently a subsidiary of Stellantis, resulting from the merger of Fiat Chrysler and Groupe PSA.</i><br />Target victim <b>website</b>: <i>Chrysler.com</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>CYMA-SYSTEMS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28295</link>
<guid>f08f86e95c9d083c89f058285f9ff636</guid>
<pubDate>Thu, 25 Dec 2025 15:24:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>CYMA-SYSTEMS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e827ad23b8779608badaa712ecfb81ef57ef5c2eef6d85e5c6c9210f8ecfde80</i><br /><br />Threat actor <b>description</b>: <i>CYMA Payroll and Accounting Software is designed for volume payroll processing and unique markets that process complex payroll. Through Employee Self-Service, the CYMA payroll software extends to the web allowing maximum flexibility. At its core, CYMA has been producing Accounting Software solutions since 1980 - ready to decrypt and return data + stop leak operation, reach us</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>grade-results</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28290</link>
<guid>6ab025df5539049ffad9e5f29eab084b</guid>
<pubDate>Wed, 24 Dec 2025 23:55:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>grade-results</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3cf40f869236446049606cfe1890ef5473a28fcefe4bffdf48a9673c7675ca2</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>graderesults.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>eiconnect.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28284</link>
<guid>57ec01697e39d6f606e37cfc93234991</guid>
<pubDate>Wed, 24 Dec 2025 21:20:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>eiconnect.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>391c060e4e4e7afe1816617105c435c1fb6bc14b3354452568d21f278c44005e</i><br /><br />Threat actor <b>description</b>: <i>Electronic Interconnect, often referred to as EI, is a U.S.-based manufacturer and supplier of printed circuit boards (PCBs) headquartered in …</i><br />Target victim <b>website</b>: <i>eiconnect.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>massfd.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28283</link>
<guid>c08876cb72b043bfbd2009cb2f0ecbf5</guid>
<pubDate>Wed, 24 Dec 2025 21:20:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>massfd.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db4fb337840eed6c55aec041ef38ea880b2a3508934d33e458590f52db750383</i><br /><br />Threat actor <b>description</b>: <i>MassFD — as reflected by the domain massfd.org — appears to be the official website of the Massapequa Fire District, …</i><br />Target victim <b>website</b>: <i>massfd.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>cmac-llc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28282</link>
<guid>4af91b65e743af91ae454a32f7717a36</guid>
<pubDate>Wed, 24 Dec 2025 19:26:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>cmac-llc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efc17ffbe11a3f39ee1b8f757e81beca24129c23ce96ef48caf390f774185be2</i><br /><br />Threat actor <b>description</b>: <i>cMAC LLC is a small, privately-held construction and general contracting firm based in Renton, Washington, serving residential and commercial clients …</i><br />Target victim <b>website</b>: <i>cmac-llc.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Agralite-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28273</link>
<guid>373590403f80d686f78b18a45ddd22ef</guid>
<pubDate>Wed, 24 Dec 2025 16:36:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Agralite-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8630be7bd25fd0e1261876cc74bff73e92d553d93e4cf4163c98690f618724e2</i><br /><br />Threat actor <b>description</b>: <i>Alex Rubbish & Recycling provides residential and commercial garbage, recycling, yard waste, and roll-off container services in Alexandria, MN. The company also manages leftover ash/fines, leachate, and organics recycling for the Pope/Douglas Waste to Energy facility. We will upload 136gb of corporate data soon. Detailed personal employee information (name, dob, and other information), client information, NDA and tons of other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trubee-Wealth-Advisors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28274</link>
<guid>388a513a9cf7a2873844b2d60d57eb8d</guid>
<pubDate>Wed, 24 Dec 2025 16:36:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Trubee-Wealth-Advisors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fccce555a6c417a16536ac3868a21933c1197ca27d9d0f867c0d91da2cdc3e06</i><br /><br />Threat actor <b>description</b>: <i>Trubee Wealth Advisors offers a diverse range of investment services tailored for individuals, small businesses, corporations, andphilanthropic organizations. We will upload 165gb of corporate data soon. Clients and employees information (passports, driver licenses, birth and death certs,w9 forms), accounting, financial statements, benefits, financialanalysis, capital and profit, clearing contract analysis, verification of funds letter, compliance, licensing, HR information, outside brokerage, client DB, confidential client information, NDA and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Watertech-of-America-WorldPoint-ECC-Mastermedia-Garrett-Leather-Guttenberg-Industries.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28275</link>
<guid>f079191821316f4c47d54f841995ae2c</guid>
<pubDate>Wed, 24 Dec 2025 16:36:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Watertech-of-America-WorldPoint-ECC-Mastermedia-Garrett-Leather-Guttenberg-Industries.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe7db00e0c050b1d901232538bc9231d290c496ea9aa7b57c894ebaa55d02f35</i><br /><br />Threat actor <b>description</b>: <i>We obtained more than 12gb of data of the following companies:Watertech of America, Inc. specializes in industrial water treatment services across the Midwest, focusing on boiler water, cooling water, and wastewater treatment. At WorldPoint provides healthcare training services. From curriculum & course materials for American Heart Association (AHA), NAEMT®, AAP, AAOS, and more, to training supplies for CPR & AED training, skill training & simulation, and live rescue. Mastermedia International serves as a trusted voice of faith in the media and entertainment industry, providing pastoral support to the leaders of studios, networks, and production companies. Garrett Leather specializes in high-quality leather products and services, catering to various sectors including automotive, aviation, hospitality, furniture manufacturing, and more.Guttenberg Industries is a full-service custom plastic injection molder, providing high-precision molding and related services globally for almost 50 years. The company specializes in a wide range of capabilities such as in-mold labeling, over-molding, and producing parts of various sizes from small to large.You will find personal employee personal data, client information, numerous project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rafael-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28276</link>
<guid>711dccfb52e41f338d36458ca11cc876</guid>
<pubDate>Wed, 24 Dec 2025 15:57:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rafael-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee115c0700824c6e99bb891e373e9ce29f11be155a07e3641bfd38d483b00c2d</i><br /><br />Threat actor <b>description</b>: <i>Rafael Construction is a full-service commercial general contractor based in Las Vegas, Nevada, specializing in commercial development with services including ground-up construction, design-build, construction management, and public works projects.We will upload more than 20gb of corporate data soon. Personal employee files (passports, DL, social security numbers ~100), financials, confidential internal files, client information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Building-Trades</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28277</link>
<guid>46235a3abdd04841af13c4d768f13c21</guid>
<pubDate>Wed, 24 Dec 2025 15:57:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Building-Trades</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7fa4af3e3d7c9f2e439d7c10d2f4b6bf0ed3186609cff8866cbff351b787bc7</i><br /><br />Threat actor <b>description</b>: <i>The Los Angeles/Orange Counties Building and Construction Trades Council represents 48 local unions and district councils, servinga membership of 160,000 skilled workers. They provide rigorous apprenticeship programs, ensuring that members are well-trained for both private and public-sector projects.We will upload 14gb of corporate data soon. Detailed personal information about employees, clients and their families (scans of passports, DLs, complete forms with full personal information, photos and so on), detailed financials, client information, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ARO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28258</link>
<guid>61deee96aa0901e6edeb0a4a077ad082</guid>
<pubDate>Wed, 24 Dec 2025 13:54:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ARO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4160a61cfe1a112e515231e9aa3596ea67bcde0c5cba445b878d6aae65399aea</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Felix-Gonzalez-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28260</link>
<guid>5596542fbe4b92a84e5ff41a01641eee</guid>
<pubDate>Wed, 24 Dec 2025 13:54:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Felix-Gonzalez-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca20694becc88f4ea5c13a37b283255906de7a25f626fe7bf0e6cf721a4e4f88</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Steel-Dynamics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28264</link>
<guid>bc42a91889ffc14111c4eae0557c5259</guid>
<pubDate>Wed, 24 Dec 2025 13:54:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Steel-Dynamics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce316760e7e319d92e19113e44856f40611beb26cd7376da2a8d9515bb09ff8a</i><br /><br />Threat actor <b>description</b>: <i>Steel Dynamics is a leading manufacturer of steel products and provider of metals recycling services operating in the United States and internationally since 1993. The company produces a comprehensive range of steel products including sheet steel, structural beams, rail products, engineered bars, and specialty steel sections. Steel Dynamics also offers metals recycling services, processing both ferrous and nonferrous scrap metals into reusable forms.We are going to upload their corporate data soon. You will find tons of Accounting files, documents, and audits. Upon obtaining this data, you could gain invaluable insights into their company's financial health and strategic direction making.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tri-State-Metal-Roofing-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28255</link>
<guid>7d9b272d3486358dce2f0195fc91c884</guid>
<pubDate>Wed, 24 Dec 2025 12:53:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Tri-State-Metal-Roofing-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ea1fee9b95e0d756f2417deda5034ed14bdda9411ab6ca29e0ea84c300876d3</i><br /><br />Threat actor <b>description</b>: <i>Tri-State Metal Roofing Supply is Utah's top metal roof supplier offering a variety of roofing and siding materials factory-direct, including standing seam and ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ellison-Educational-Equipment-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28256</link>
<guid>4b1d35d72137cace2f9546ca80eee53f</guid>
<pubDate>Wed, 24 Dec 2025 11:03:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Ellison-Educational-Equipment-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e4a220088167fd6f9beb08fd00acb179ec2f682b2f66fb1313273a2bb0f57a8</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>amsino.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28265</link>
<guid>1a7da998ded68c09b6fb68853539e59a</guid>
<pubDate>Wed, 24 Dec 2025 10:17:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>amsino.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6a41c256297a36c04d6a0aee1f8a03b2df4c448ae6db664010f93ef449f8aca</i><br /><br />Threat actor <b>description</b>: <i>Amsinos superior quality and technological advancements have gained the trust of healthcare professionals worldwide. With over 25 years of experience, we are fully aware of what it takes to meet and exceed industry expectations. Our commitment to improving patient care is not only reflected in our p…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/amsino-international-inc/2129982</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>International-Door-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28267</link>
<guid>81aa5aa1989ff76f8f8e5f467814c499</guid>
<pubDate>Wed, 24 Dec 2025 09:51:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>International-Door-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c9f4087f479b1f79029dbd36c37b9b04c9926082a5383a0129f687db577f5d6</i><br /><br />Threat actor <b>description</b>: <i>International Door, Inc</i><br />Target victim <b>website</b>: <i>international-door.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>pellcityschools.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28251</link>
<guid>1dfbac99bfb6d351efe1814d7339e9d9</guid>
<pubDate>Tue, 23 Dec 2025 21:50:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>pellcityschools.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4906cfce26359d37f44dd81e72c31e9d887286e0aaed9542babd35b8041e16e5</i><br /><br />Threat actor <b>description</b>: <i>Pell City Schools is a public K-12 school district based in Pell City, Alabama, serving students from pre-kindergarten through 12th …</i><br />Target victim <b>website</b>: <i>pellcityschools.net</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>SWWC-Service-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28239</link>
<guid>7eb9e62d8ab75192146e99c863a08119</guid>
<pubDate>Tue, 23 Dec 2025 20:01:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SWWC-Service-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b720a3e58cf18b06a304a409a9f3050ca419f27bacee9ba4e54afda5fc661f8</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CoreHQ</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28240</link>
<guid>0a7428310ebcbb3b8d6760fe98b7158e</guid>
<pubDate>Tue, 23 Dec 2025 20:01:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CoreHQ</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25a075df84e72e65970d6eac39e888efc234900cd736788635abc79dd30505de</i><br /><br />Threat actor <b>description</b>: <i>Software</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shore-Gardens-Rehabilitation--Nursing-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28241</link>
<guid>c82d64a97a01ac0869fcb90cd22b96c0</guid>
<pubDate>Tue, 23 Dec 2025 20:01:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shore-Gardens-Rehabilitation--Nursing-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81477fd7df641b5327acb70dfc55ee18d386ee735f6bad82ce72fd8d12aed553</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Sonnenschein-Groupe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28242</link>
<guid>3cc4f07c92a240dd56dcdebf58161f58</guid>
<pubDate>Tue, 23 Dec 2025 20:01:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Sonnenschein-Groupe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59f874d2ae0ee42a279e4c4ae19a56531c4dc748c53baae6489bc12e1240adc5</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jaf-Gifts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28243</link>
<guid>e45f01aa9fb6ae18a5b306a057d7c886</guid>
<pubDate>Tue, 23 Dec 2025 20:01:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jaf-Gifts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a46e07b6d57458402a3b471dad607143936ce565d66684aba9f8870f758a0c2</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accela</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28249</link>
<guid>b229ed523ffbcc8c48d47eb8bcd760c6</guid>
<pubDate>Tue, 23 Dec 2025 17:45:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Accela</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e9b8957606c975758d7a153e52a8a6af1fcae7cefde4e8784fb61e17b528a7e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Accela is a leading provider of cloud-based productivity and civic engagement applications for government agencies. Their solutions, including permitting, licensing, code enforcement, and public health solutions, are designed to streamline workflow, automate processes, and provide citizen access to various government services. Accela's software platform powers over 2000 governments worldwide.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chatham-Asset-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28230</link>
<guid>b3f7e349cd770760805077c584b137b7</guid>
<pubDate>Tue, 23 Dec 2025 15:53:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Chatham-Asset-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4aa730f42b6d6d3f5d46e44dbc8cfdd6178a66255efd2b3ef10ad518f9d0b4a9</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>ruskcountywi.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28232</link>
<guid>476c386f6e35d7cbcf9085354dd035dc</guid>
<pubDate>Tue, 23 Dec 2025 15:53:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>ruskcountywi.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bdf6d07f9d003e50613d3416d48d5e3bbdb589f6cf82f4282665f16068e90337</i><br /><br />Threat actor <b>description</b>: <i>Rusk County, Wisconsin is a community that provides services such as an Airport,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>ccedarvalleyservices.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28234</link>
<guid>b110ae3636fc62aee44893300d695f99</guid>
<pubDate>Tue, 23 Dec 2025 15:53:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>ccedarvalleyservices.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37f4e37dad1081f2298ea1ad2dadfad2be20bea1bf590060d25f893af8f6aa04</i><br /><br />Threat actor <b>description</b>: <i>Cedar Valley Services Inc is an employment agency based in Southern Minnesota, o...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.fecrwy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28235</link>
<guid>408e9a2230d37f5dc50fe7c5a03322c1</guid>
<pubDate>Tue, 23 Dec 2025 15:53:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.fecrwy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4554316e24935d9cf33b04596beb743290310e3183e7a08edcd5752602ebdec</i><br /><br />Threat actor <b>description</b>: <i>The Florida East Coast Railway freight rail system located along the east coast ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Unified-Assessment-Platform-ExamRoom.AI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28245</link>
<guid>c6bb5b7c76d884e6ee984f5f2132f42f</guid>
<pubDate>Tue, 23 Dec 2025 14:42:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>crypto24</b> claims attack for <b>Unified-Assessment-Platform-ExamRoom.AI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e7f7b5291cb162b84ca7cf43fd1e139762b0f299ef69bde23162793c86b4a60</i><br /><br />Threat actor <b>description</b>: <i>***</i><br />Target victim <b>website</b>: <i>examroom.ai</i>]]></description>
<category>crypto24</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodglen-Medical-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28228</link>
<guid>90f0b00fd44ae507b39ff6d87e26f2b2</guid>
<pubDate>Tue, 23 Dec 2025 00:17:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Woodglen-Medical-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>272a0ace56c0be92a5cd85ce24303b7510e491ccee1893181d43a7f81a3c1fdc</i><br /><br />Threat actor <b>description</b>: <i>The biggest leak of boobies!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Center-for-Life-Resources-ECI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28225</link>
<guid>66c2f73dac3dd6c9f20921b76563bafe</guid>
<pubDate>Mon, 22 Dec 2025 23:10:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Center-for-Life-Resources-ECI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0bf6dbfb13e0eb1cb4081017beb0bbbdf599d87cce7959e3bd677463178aef4f</i><br /><br />Threat actor <b>description</b>: <i>Center for Life Resources is dedicated to enhancing the quality of life for individuals in Central Texas by providing a range of services including adult and children's mental health support, substance use services, and assistance for individuals with Intellectual and Developmental Disabilities. The organization operates a 24-hour crisis intervention hotline and collaborates with local law enforcement and hospitals to ensure comprehensive care. Their intended clients include individuals facing mental health challenges, families in need of support, and those requiring crisis intervention. With multiple locations across several counties, they aim to serve the diverse needs of their community.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Geometrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28226</link>
<guid>68ab14b322fecf44196cc1186f167857</guid>
<pubDate>Mon, 22 Dec 2025 23:10:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Geometrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ae0a305f67d0a6e4da820db5b30e2529f0e406b6b3923fc511c5b800293a689</i><br /><br />Threat actor <b>description</b>: <i>Geometrics is a division of OYO Corporation and headquartered in San Jose, CA. The company is a designer and manufacturer of land, marine and airborne geophysical hardware, sensors and software, covering seismic, magnetic, and electromagnetic technologies. Founded in 1969, Geometrics began operations developing magnetometers.</i><br />Target victim <b>website</b>: <i>www.geometrics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Total-Air-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28227</link>
<guid>2cfdbddf1acf5da263a3c43ab7b9f371</guid>
<pubDate>Mon, 22 Dec 2025 23:09:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Total-Air-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0b6ef0b876d37c80342d0593bd012fad2ed97da9a5c4d5e683d370bdee8e2da</i><br /><br />Threat actor <b>description</b>: <i>Total Air Solutions has been keeping customers cool, comfortable, and happy since 2003. We provide a full range of residential and commercial HVAC services in the Gulf Coast communities from Longboat Key to Punta Gorda Isles, including new installation, seasonal maintenance, repair, and air filtration. Contact us at 1-888-426-1770 for convenient scheduling, free estimates on new systems, and our "No Lemon Warranty. At Total Air Solutions, we are dedicated to serving your best interests.</i><br />Target victim <b>website</b>: <i>www.totalairsolutions.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hanlon-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28224</link>
<guid>d917e680c14c6fcd74d08c935436f1b5</guid>
<pubDate>Mon, 22 Dec 2025 22:09:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Hanlon-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>006508ac53b86a6bf4392027d59ac711ce1ed2558f848ede6a1d8c2d9795eb73</i><br /><br />Threat actor <b>description</b>: <i>Hanlon Electric Company is a full-service electrical contractor based in Pittsburgh, specializing in minimizing downtime and maximizing electrical efficiencies. They offer a wide range of services including electrical construction, building maintenance, telecommunications, and eco-friendly energy solutions. The company serves various sectors, including commercial, industrial, educational, and medical facilities, and is committed to safety and quality. Established in 1930, Hanlon Electric is dedicated to providing cost-effective solutions tailored to the needs of its clients.</i><br />Target victim <b>website</b>: <i>www.hanlonelectric.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acme-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28221</link>
<guid>2752a6fc31927efaf4ff9f54b1c769cb</guid>
<pubDate>Mon, 22 Dec 2025 17:58:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Acme-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55b557241f4d21c9ee7f93f73705aebb66bddcfb7767540ef32effad8866a114</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.acmeelectriccompany.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scenic-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28220</link>
<guid>1deac92dd0c21ea46585fe693b4330ec</guid>
<pubDate>Mon, 22 Dec 2025 17:57:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Scenic-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab65a5e3b8a6f0e8b8577ec2bdfabd0aa98bd39976b538b25ef63e4a8eb9e119</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.scenicsolutions.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Besco-Electrical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28219</link>
<guid>941510c72491f8137e7f4a306aefe69b</guid>
<pubDate>Mon, 22 Dec 2025 17:55:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Besco-Electrical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bba03fede95b8310bec09ea0405cfb84bd2fb7a691edf361b01f65b93d6dbd3d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.bescoelectrical.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swartz-Campbell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28215</link>
<guid>738c045d6205c050d3d6c57e5e6f2d76</guid>
<pubDate>Mon, 22 Dec 2025 15:53:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Swartz-Campbell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11703c750b007a4a777d0dfeae0878a6850360f32d067b5f093dea3919c8d071</i><br /><br />Threat actor <b>description</b>: <i>Swartz Campbell LLC is a law firm with multiple locations across the East Coast specializing in areas including class action, employment, medical malpractice, and divorce. The law firm was founded in 1921 and is headquartered in Philadelphia, Pennsylvania.</i><br />Target victim <b>website</b>: <i>https;www.swartzcampbell.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lugiano-Medical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28213</link>
<guid>e601ac8ec15075e6c6d0831dbd5a9c81</guid>
<pubDate>Mon, 22 Dec 2025 15:10:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lugiano-Medical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>606fca746ca37ee8d6d41bb0775e29c01f211328650b5d4d60dde4ff751399f5</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.lugianomedical.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>GOOD-Foundation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28196</link>
<guid>8b9845fa0b5ce34fb2de2050a0bb1353</guid>
<pubDate>Mon, 22 Dec 2025 13:26:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>GOOD-Foundation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fee7bfdda05b817df18f1eec7e603d710f85b11e0f1ae6447589e49a8d32a5ec</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hongfa-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28197</link>
<guid>408567fb466fdcc5171cd962e3c83862</guid>
<pubDate>Mon, 22 Dec 2025 13:26:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Hongfa-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8384b97169755881b02e5bbed7f992159dd67aeb4051a87617f4933231a5848</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eanes-ISD-schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28198</link>
<guid>13efec348e66852991bc20ed97caa574</guid>
<pubDate>Mon, 22 Dec 2025 13:26:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Eanes-ISD-schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b28158c1dd80c21ebcc20ead2b379454b4e12d54ee4e8d31c541a74b52bdeace</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cedar-Valley-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28191</link>
<guid>06efc3b2376e4b23e284094112b8ce94</guid>
<pubDate>Mon, 22 Dec 2025 01:27:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cedar-Valley-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d576f97128fe147e8f4bf3344292b2b4262e6f81891b5082f284078d093851a</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Empire-Screen-Printing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28192</link>
<guid>95ca43b0dd15e6c2017380002b8b3851</guid>
<pubDate>Mon, 22 Dec 2025 00:26:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Empire-Screen-Printing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b560c3f26629d018f811c9ad18e36ab11c34d155a662033b88372ebd969c0fd</i><br /><br />Threat actor <b>description</b>: <i>Empire Screen Printing, Inc. provides screen printing. The Company flexography, digital printing, and doming. Empire Screen Printing services customers in the United States.</i><br />Target victim <b>website</b>: <i>www.empirescreenprinting.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>svlawus.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28187</link>
<guid>f52a97aeb3db83504088d414ae36a7b9</guid>
<pubDate>Sun, 21 Dec 2025 12:10:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>svlawus.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea1db79d57e2b5e9d9cd63d0045fffb5962cd94b326a2d0fcd0454154e0d1a8f</i><br /><br />Threat actor <b>description</b>: <i>COMPOSITION OF FIRMS:  >svlawus.com Sanchez Vadillo LLP is a full-service boutique law firm established in 1999, dedicated to providing strategic and efficient legal counsel to individuals, businesses, and financial institutions. The firm specializes in various practice areas including business closings, civil litigation, corporate counsel, family law, immigration, and real estate transactions. With a team of 10 attorneys and 30 staff members, they prioritize professionalism and exceptional client solutions. Their commitment to excellence is reflected in numerous awards, including multiple Top Producer recognitions from Old Republic Title Insurance. Employees: 50 Revenue: $6.3 Million Industry: Law Firms & Legal Services   Phone Number: (305) 436-1410  >eagrealtyinternational.com  EAG Realty International specializes in assisting clients with buying, selling, and leasing real estate properties, including residential and commercial options in the South Florida area and internationally. The company is committed to providing a high degree of service and professionalism, ensuring a smooth and pleasurable experience for its clients. With a team of licensed real estate agents, EAG Realty offers expert guidance in property valuation and market insights. Their clientele includes individual buyers and sellers, as well as international investors seeking property opportunities. Employees: 200 Revenue: $17.7 Million Industry: Real Estate Phone Number: (305) 477-4413  >torresvadillollp.com  Employees: 50 Revenue: $5 Million Industry: Law Firms & Legal Services   Phone Number: (214) 295-8473  >mytitlelogic.com Employees: 50 Revenue: $5 Million Industry: Consumer Services Phone Number: (727) 823-7778</i><br />Target victim <b>website</b>: <i>svlawus.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kucera-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28184</link>
<guid>b137eb4183c4e03586f8ae9257bbf3bc</guid>
<pubDate>Sat, 20 Dec 2025 19:07:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kucera-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2125f94e6327079d5237b6c80f4e28ef82ef8caae6d87a99a5f0bddb8c95bbfa</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kucerainternational.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Titan-Motor-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28182</link>
<guid>abffbd61825be76adbbe7bf96233f42b</guid>
<pubDate>Sat, 20 Dec 2025 16:56:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Titan-Motor-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>666892b007739cfc41e5705f0830300604037eac03f4ab1c6cf4404c2d168f3c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.titanmotorgroup.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dolan-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28181</link>
<guid>f9e6aa5c93154c16fc5fa8382d8b8de6</guid>
<pubDate>Sat, 20 Dec 2025 16:55:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Dolan-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b9a0e0fdd673066fef5e9058032d3bce85f888795fbda4994e9bcf60103212bc</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.dolanconstructioninc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>IAPMO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28178</link>
<guid>479eaa8e93a42b42d12992f086cfa14f</guid>
<pubDate>Sat, 20 Dec 2025 15:26:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>IAPMO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8fc5d6796ae237983fb8c47e1571df57daf99ac7f40df690926421f6045f4370</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.iapmo.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Homestead-Electrical-Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28173</link>
<guid>d80f8d2f11bbd1a8ab728b02fa3cd66a</guid>
<pubDate>Sat, 20 Dec 2025 12:54:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Homestead-Electrical-Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3a6ff9e5f9d534f210ba42bd7f64b6f14bcfdef13e2d886ae52b45ffd60f40c</i><br /><br />Threat actor <b>description</b>: <i>Homestead Electrical Contracting, LLC has been providing a range of electrical services since 1981, focusing on core values such as honesty, integrity, and teamwork. Their offerings include electrical design and build, high voltage wiring, fire alarm system installation, and maintenance agreements available 24/7. The company caters to a diverse client base, including notable names like Walgreens Corporation and Lake County Water Reclamation District. They strive to maintain strong relationships with their clients while ensuring high-quality service and client satisfaction.</i><br />Target victim <b>website</b>: <i>www.homesteadelectricalcontracting.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Insight</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28175</link>
<guid>e1e266b5bbdb6da994c4f9cb09635d10</guid>
<pubDate>Sat, 20 Dec 2025 12:21:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Insight</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfd346331b01985fe4eb1100b2213d6063f03457dd783b2a0cc1a4022c236f81</i><br /><br />Threat actor <b>description</b>: <i>Insight is a leading solutions and systems integrator — providing computer hardware, software, cloud solutions and IT services to business, gover...</i><br />Target victim <b>website</b>: <i>insight.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rio-supermarket</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28171</link>
<guid>bf74cbe3722200f6fad86af0b239d900</guid>
<pubDate>Sat, 20 Dec 2025 09:26:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rio-supermarket</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a21dcf7a84eb8dc2a188f50090fb97b482cd4954937072f8a2516c87ace205d</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deibel-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28170</link>
<guid>9390f4d0da32633807f299e76c568ace</guid>
<pubDate>Fri, 19 Dec 2025 23:19:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Deibel-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e81322c9a0beaed1aab8ad125c7e95d96d11c29b5653a11a1e3e4b69f8522ceb</i><br /><br />Threat actor <b>description</b>: <i>Data breach at a U.S. food safety and quality testing laboratory.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Turnamics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28169</link>
<guid>c12bc20ecfdf52bc1f65d6dbebdbee94</guid>
<pubDate>Fri, 19 Dec 2025 22:26:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Turnamics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e77a3b11291edfef7ffc1a66624491de9f22051858f4790d7b199c5c29231b3</i><br /><br />Threat actor <b>description</b>: <i>Turnamics, Inc. is a contract manufacturer based in Asheville, NC, specializing in short to medium production runs of machined parts since 1969. The company has evolved from a small turning shop into a world-class manufacturing operation, employing nearly 75 skilled individuals. Turnamics is committed to quality and utilizes advanced machining techniques to meet diverse manufacturing needs. Their services cater to clients seeking reliable and precise machining solutions.</i><br />Target victim <b>website</b>: <i>www.turnamics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Star-Asset-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28167</link>
<guid>bbdbf47737d418bdc77c73ef28c50a49</guid>
<pubDate>Fri, 19 Dec 2025 21:46:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>North-Star-Asset-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6b6162863a9432b0d148019cf1379cf012f7f4b372e5647648b7441613e12de</i><br /><br />Threat actor <b>description</b>: <i>North Star Asset Management, Inc. is a prominent independent SEC Registered Investment Advisory firm based in Wisconsin, managing nearly $3 billion in assets. They offer tailored investment management and retirement planning services for families, corporations, and endowments, always prioritizing client interests as fiduciaries. Their team consists of 11 investment professionals, including 9 CFA Charterholders and 2 CFP professionals, boasting over 200 years of combined investment experience. North Star is recognized for its personalized and independent financial advice, charging a fee of 0.6% of managed assets.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>eagrealtyinternational.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28163</link>
<guid>69812e3f04486f27c1b6f6d2820e5c90</guid>
<pubDate>Fri, 19 Dec 2025 19:54:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>eagrealtyinternational.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cea08e5dba09570600660968a23e6e711dbce2d65c0472bf2787833d5a2c2247</i><br /><br />Threat actor <b>description</b>: <i>COMPOSITION OF FIRMS:  >svlawus.com Sanchez Vadillo LLP is a full-service boutique law firm established in 1999, dedicated to providing strategic and efficient legal counsel to individuals, businesses, and financial institutions. The firm specializes in various practice areas including business closings, civil litigation, corporate counsel, family law, immigration, and real estate transactions. With a team of 10 attorneys and 30 staff members, they prioritize professionalism and exceptional client solutions. Their commitment to excellence is reflected in numerous awards, including multiple Top Producer recognitions from Old Republic Title Insurance. Employees: 50 Revenue: $6.3 Million Industry: Law Firms & Legal Services   Phone Number: (305) 436-1410  >eagrealtyinternational.com  EAG Realty International specializes in assisting clients with buying, selling, and leasing real estate properties, including residential and commercial options in the South Florida area and internationally. The company is committed to providing a high degree of service and professionalism, ensuring a smooth and pleasurable experience for its clients. With a team of licensed real estate agents, EAG Realty offers expert guidance in property valuation and market insights. Their clientele includes individual buyers and sellers, as well as international investors seeking property opportunities. Employees: 200 Revenue: $17.7 Million Industry: Real Estate Phone Number: (305) 477-4413  >torresvadillollp.com  Employees: 50 Revenue: $5 Million Industry: Law Firms & Legal Services   Phone Number: (214) 295-8473  >mytitlelogic.com Employees: 50 Revenue: $5 Million Industry: Consumer Services Phone Number: (727) 823-7778</i><br />Target victim <b>website</b>: <i>eagrealtyinternational.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>rogitz.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28162</link>
<guid>89fb52e6ca126344d7c493e22ad1e1f7</guid>
<pubDate>Fri, 19 Dec 2025 18:48:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>rogitz.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>942d00e3868762b6436e7bc6fd8e3810a4fd6c68e8f31ed27d9c41142ff4575b</i><br /><br />Threat actor <b>description</b>: <i>Rogitz & Associates was a small intellectual property law firm based in San Diego, California, specialising in patent prosecution, patent …</i><br />Target victim <b>website</b>: <i>rogitz.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>springersjewelers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28160</link>
<guid>4e8e25b6b415f4026f6fd44b5ddd7c76</guid>
<pubDate>Fri, 19 Dec 2025 18:47:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>springersjewelers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff07d40b2958d0b9648999629ed21529199fcb5d1e2d8cad41301649fd69e1cd</i><br /><br />Threat actor <b>description</b>: <i>Springer’s Jewelers is a historic family-owned jewelry retailer based in Portland, Maine, with additional store locations in Bath, Maine and …</i><br />Target victim <b>website</b>: <i>springersjewelers.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>coloradopowerline.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28156</link>
<guid>03bb3e5b97d32f9dd98b94845d9b2650</guid>
<pubDate>Fri, 19 Dec 2025 18:45:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>coloradopowerline.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02d1b06f6a592ffe659155241521640d9a124f924a6a6abb73239c8862a804ff</i><br /><br />Threat actor <b>description</b>: <i>Colorado Powerline, Inc. (often abbreviated CPI) is a U.S. electrical infrastructure construction company headquartered in Sedalia, Colorado. Founded in 2006, …</i><br />Target victim <b>website</b>: <i>coloradopowerline.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>keystoliteracy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28133</link>
<guid>25ca7e9577b39f7730394bc4db6b58ab</guid>
<pubDate>Fri, 19 Dec 2025 16:13:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>keystoliteracy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19886bb0ab2e6b0b85fb6a22f3a652e63d03731ff6ac19232b4d716750045aa8</i><br /><br />Threat actor <b>description</b>: <i>Keys to Literacy is a premier provider of literacy teacher training, curriculum, and ongoing coachin...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>pdcm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28134</link>
<guid>04a1d468059361fc702a1b8574f7c27f</guid>
<pubDate>Fri, 19 Dec 2025 16:13:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>pdcm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2f492e3a73e1a529f6c067196f49e746328c7344aa1f24de31b568ddc8f4d13</i><br /><br />Threat actor <b>description</b>: <i>We offer a range of insurance types from business and group insurance to individual life and health....</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>tuscon-physicans.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28135</link>
<guid>3f12cc3464d7a80a7706f970dc254bb7</guid>
<pubDate>Fri, 19 Dec 2025 16:13:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>tuscon-physicans.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bdc196df0dcb896dd382aab70db2c235927ec3a50ac063c3be823c4c9b3b3499</i><br /><br />Threat actor <b>description</b>: <i>A community of highly skilled, board certified doctors, specializing in General, Orthopedic, Plastic...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>clarindahealth.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28136</link>
<guid>62e0f0199800c074f93589f48fa8d509</guid>
<pubDate>Fri, 19 Dec 2025 16:13:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>clarindahealth.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7405fc9f012c9f55519aa9963c2789721f8731153462addb5d4f7a4d4db1acea</i><br /><br />Threat actor <b>description</b>: <i>CRHC offers an array of medical and rehabilitative services, including respiratory therapy, physical...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>firstrateak.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28139</link>
<guid>b589775cf387584a460c9a316b24ad74</guid>
<pubDate>Fri, 19 Dec 2025 16:13:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>firstrateak.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a5b3d110db412a2312737aa80eb32ff869574864d3dc3c60dec0cc05267d15d</i><br /><br />Threat actor <b>description</b>: <i>First Rate Financial is a mortgage brokerage focused on industry leading communication, technology,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>jvdbassoc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28140</link>
<guid>6e6d5361da6fb4a2d24b4ef90f224f46</guid>
<pubDate>Fri, 19 Dec 2025 16:13:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>jvdbassoc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9bc050c14b1c3d904c86ad310ab35f6019ba509783c22adda75948754af5fd58</i><br /><br />Threat actor <b>description</b>: <i>JVDB &amp; Associates Inc is located in Elgin, Illinois, and was founded in 1999. At this location,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Miami-JV</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28142</link>
<guid>99a57cbf9929486ac2e6f630447cc6f2</guid>
<pubDate>Fri, 19 Dec 2025 16:11:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Global-Miami-JV</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37bd072f19ac9f90cc45304d8ed2f84b5893db4ac25d46ce0f56844378febf32</i><br /><br />Threat actor <b>description</b>: <i>Global Miami Joint Venture operates as a franchise organization under the larger Manchu WOK brand. The company operates franchise locations in Miami, Florida, and conducts its business within thenan sector.We will upload corporate data soon. Employees personal documents (passports, DLs and so on), detailed financials, numerous projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Susquehanna-Glass</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28143</link>
<guid>80cb2002656131b6ee8c02ab8fe076e0</guid>
<pubDate>Fri, 19 Dec 2025 16:11:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Susquehanna-Glass</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0936b57f215d5f896a1265db3ae171f0938a39e8a427f99e64ad485ae2e6967</i><br /><br />Threat actor <b>description</b>: <i>Susquehanna Glass is a family-owned and operated business. Today,it flourishes under the leadership of third-generation owner Walt Rowen, the grandson of original partner, Walter Roye.We will upload 35gb of corporate data soon. Detailed personal information of almost 800 people (i-9 forms, scans of passports, DLs, SSNs, drug test ans so on), detailed financials, customer information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shamrock-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28122</link>
<guid>3948730d3bfbcc822e6cebe4361364ba</guid>
<pubDate>Fri, 19 Dec 2025 14:52:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Shamrock-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c227043ec850401a01d0b56d3d0d929f65b81c2b3d2891e40f37eacdc7827f9e</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1941, Shamrock Technologies is a global provider of micronized polytetrafluoroethylene products. They also offer a line of specialty micronized powders, dispersions, emulsions, and compounds including PTFE, polyethylene, polypropylene, fluoropolymers, custom wax alloys, natural waxes, and other specialty additives. Their products are found in inks and coatings, thermoplastics, greases, elastomers, personal care products, and other specialty applications. 
The company headquarters is located in Newark, New Jersey. 51-200 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>l.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28125</link>
<guid>f6a0809b7f72d3310dc58ff04b5fadd8</guid>
<pubDate>Fri, 19 Dec 2025 14:52:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cloak</b> claims attack for <b>l.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7c65cdf2899f956530edc15df48a199592e7a60092d403a373d815d504aff80</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cloak</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colonial-Metals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28147</link>
<guid>70ba980356d834b5d3ca215040c64e2f</guid>
<pubDate>Fri, 19 Dec 2025 14:15:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Colonial-Metals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c6320dbbb085dba42d88ab8da5b1d5a3972f6a604661cdfdef491de5d6854b69</i><br /><br />Threat actor <b>description</b>: <i>Colonial Metals, Inc. is a full-service global supplier specializing in over 600 precious metal-based chemicals and services. The company is dedicated to providing personal and reliable customer service, fostering trust and comfort among its clients. Committed to sustainability, Colonial Metals aims to reduce greenhouse gas emissions by 25% by 2030 through various environmental initiatives. Their product offerings include refining services, analytical capabilities, and custom synthesis for various industrial markets</i><br />Target victim <b>website</b>: <i>colonialmetals.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Flavor-Producers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28144</link>
<guid>945628f89a79f5c21148e6c85b241947</guid>
<pubDate>Fri, 19 Dec 2025 14:05:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Flavor-Producers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84e01ba3a57fedadd389b3a1a62f26a0cd270d848279c102076f607d212d9902</i><br /><br />Threat actor <b>description</b>: <i>https://flavorproducers.com/ https://www.zoominfo.com/c/flavor-producers-inc/23530808 Flavor Producers is a leading manufacturer specializing in organic, natural, and plant-based flavors and extracts. The company focuses on creating new taste experiences tailored for food, nutrition, and beverage applications, addressing the growing consumer demand for transparency and quality. Through innovative technologies and a versatile portfolio, Flavor Producers offers a variety of flavor profiles to inspire culinary creativity. Their services cater to manufacturers seeking to enhance their products with superior taste solutions. Full customer database and a lot of additional info.</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Genesis-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28132</link>
<guid>2ccc3ed7fd2601e8f77299ddbf89cbcb</guid>
<pubDate>Fri, 19 Dec 2025 12:38:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Genesis-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>795255c9e559c0762933c55fa601247792609d010e3d95cc74a5d71599119aac</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.genesisworld.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maison-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28131</link>
<guid>a8d6452ad4feb2545d93de0400874b63</guid>
<pubDate>Fri, 19 Dec 2025 12:37:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Maison-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b80fdbd3e275e8b4a42fe14337e13eb164a169392f50fa55ffd0b14262c1fd4</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.maisonlaw.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Larry-Pitt--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28130</link>
<guid>f65ee09b9fc46b70d8a901dac2977363</guid>
<pubDate>Fri, 19 Dec 2025 11:31:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Larry-Pitt--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>475c7b40801c6d9b59db310dbd0ec4c59c5accf512890cdbfc4ebcb62f244be2</i><br /><br />Threat actor <b>description</b>: <i>Larry Pitt & Associates</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Josh-Steel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28114</link>
<guid>2791cbf7a6b8b8c08804168ddcf1c172</guid>
<pubDate>Fri, 19 Dec 2025 11:26:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Josh-Steel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a035071c26522db3f1cf6f2217bd197bf192753b48a2cce795ea8caba1b1d68</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawsoft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28126</link>
<guid>d010cdb000ad9085cc4b563736ba8607</guid>
<pubDate>Fri, 19 Dec 2025 10:27:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Lawsoft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0b47c936731c94677e738ad6ead68874673dcc447a2088224cb7309cb572bb7</i><br /><br />Threat actor <b>description</b>: <i>LawSoft, Inc. specializes in providing scalable and customizable software solutions for law enforcement agencies, including Computer-Aided Dispatch (CAD), Records Management Systems (RMS), and Fire EMS systems. Their products aim to streamline reporting and data integration, boasting a user-friendly design and incorporating legacy system data for a cohesive experience.</i><br />Target victim <b>website</b>: <i>www.lawsoft-inc.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>allenprinting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28127</link>
<guid>4da9e81f4bb667b11e3b1064b10fb2c3</guid>
<pubDate>Fri, 19 Dec 2025 09:40:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>allenprinting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f8fb4a50f3cd2fee54d6d7c9defecd929d7c37d7e2ef93deaa55797581999d0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Allen Printing is a Nashville-based company that offers commercial printing and direct mail services. They have been in business for over 80 years, providing a variety of services including digital printing, offset printing, bindery, and graphic design. Their clientele ranges from local businesses to renowned corporations. They pride themselves on their quality, service, and timely delivery.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clarksville-ISD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28112</link>
<guid>a311dd84030f32ea6e0550b09f5869eb</guid>
<pubDate>Thu, 18 Dec 2025 22:27:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Clarksville-ISD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8c27d6cc54e82c42df4527095034a674dbe83e826cfe3af678cffceafb7b0a0</i><br /><br />Threat actor <b>description</b>: <i>Once again, we see how a certain school organization, Clarksville ISD, was attacked and compromised due to the negligence and irresponsibility of employees with other people's data, that is, other people, as a result of which a large amount of confidential data was compromised, including the SNN of all students for the entire year, as well as all employee data, including SNN, banking transactions, and financial components.</i><br />Target victim <b>website</b>: <i>clarksvilleisd.net</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pacific-Rim-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28100</link>
<guid>aa6753f1f7962a29a43ffa397473774f</guid>
<pubDate>Thu, 18 Dec 2025 22:24:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Pacific-Rim-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>021134b6389fdcea78132e862631d81ce88d4cbba01f1f712b556ef12791b1a6</i><br /><br />Threat actor <b>description</b>: <i>Pacific Rim Mechanical (PRM) is a Southern California-based mechanical contractor (HVAC, Plumbing, Energy Solutions) serving commercial, industrial, healthcare, and biotech sectors since 1987,  known for high-quality construction, maintenance, and repair services, focusing on integrity,  safety, and long-term client partnerships through expertise and innovation like BIM modeling.  Clients: Sony, SpaceX, THERMA LCC, ASML LCC... Laek: 100GB  WE HAS COLLECTED SUCH DATA AS:   - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development  - Drawings  And a lot of other VERY IMPORTANT information!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heritage-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28110</link>
<guid>43102e91c7b170ead9cc2f6f0a37f1af</guid>
<pubDate>Thu, 18 Dec 2025 21:31:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Heritage-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>980723c9446c776701c9278b8240ae1dd3694d9a8b8d809aa0d31631efb41de4</i><br /><br />Threat actor <b>description</b>: <i>Heritage Engineering prides ourselves on repeat business by ensuring high customer satisfaction on each and every project. Our team is ready to assist you in any size project. We work closely with each of our clients to ensure that we deliver outstanding service and high quality designs that are completed on time and within budget. If you would like to discuss a project please contact us. We look forward to working with you.</i><br />Target victim <b>website</b>: <i>www.heritageengineering.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>RK-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28111</link>
<guid>eff273b8ff65204546e793d51f41ab68</guid>
<pubDate>Thu, 18 Dec 2025 21:31:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>RK-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0419b3765b065e544e27f8cdcff75793796d0eb542b272f3ae7035f02129fe8</i><br /><br />Threat actor <b>description</b>: <i>RK Centers is a family-owned real estate development company specializing in the acquisition, development, and operation of prime open-air regional and community shopping centers in New England and South Florida. The company currently manages over 10,000,000 square feet of retail and office space, catering to a diverse clientele. With a focus on grocery-anchored and convenience retail centers, RK Centers aims to enhance community shopping experiences. Their extensive portfolio includes properties across multiple states, including Massachusetts, Florida, and Rhode Island.</i><br />Target victim <b>website</b>: <i>www.rkcenters.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ragland--Jones-LLP.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28101</link>
<guid>9dd3ecb6819c19341cce4399afa2c7dd</guid>
<pubDate>Thu, 18 Dec 2025 21:30:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Ragland--Jones-LLP.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6460db36e499fc4050c03fca1c877386a4b462ca865a54e2f845bc989221f96</i><br /><br />Threat actor <b>description</b>: <i>Providing estate planning, real estate law, business formation, and other legal services in the Harrison area, Ragland Law Firm is ready to provide you with the services you need. Call (870) 741-4490 for more info.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>L-S-GRIM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28102</link>
<guid>f6a81a05f0dc6797d195dfb9aad909bb</guid>
<pubDate>Thu, 18 Dec 2025 21:30:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>L-S-GRIM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e1c7c8eee19084badff1c5293694fd68bf5ba73d436846775ba20e0709c60a8</i><br /><br />Threat actor <b>description</b>: <i>L.S. Grim Consulting Engineers is a Mid-Atlantic-based engineering services corporation specializing in mechanical, electrical, and plumbing engineering design and consulting. They offer a variety of services including electrical systems, fire protection, and project management, all designed to meet code requirements and support LEED certification. With over 30 years of experience, their team focuses on quality control and effective project management to ensure client satisfaction. Their intended clients include organizations needing comprehensive engineering solutions and facilities management.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Shore-Tool--Die</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28103</link>
<guid>cc0d9865e5284b52347fc0417b99b0c8</guid>
<pubDate>Thu, 18 Dec 2025 21:30:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>South-Shore-Tool--Die</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>119eabda0820914020ddc9a22c1dd6778dd06fbcd87e3b3568716ce1f91c0d5b</i><br /><br />Threat actor <b>description</b>: <i>South Shore Tool and Die specializes in precision machining services across various industries, including food processing machinery, machine tools, and plastic and blow molding machine builders. They also cater to sectors such as printing press manufacturing, pump manufacturing, off-road construction, railroad, and robotics. Their diverse client base reflects their capability to meet the needs of multiple markets. The company is located in Benton Harbor, Michigan.</i><br />Target victim <b>website</b>: <i>www.southshoretoolanddie.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lawrence-Family-Jewish-Community-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28104</link>
<guid>8702581b10fc44c8ee9021a967744624</guid>
<pubDate>Thu, 18 Dec 2025 21:29:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lawrence-Family-Jewish-Community-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ec36a393c42362bae572f855f7495ea150ac5722f14c30ea9fc5250d90aefe4</i><br /><br />Threat actor <b>description</b>: <i>The Lawrence Family Jewish Community Center (LFJCC) offers a diverse range of programs and services aimed at fostering community among San Diego's Jewish population as well as the general public. Their offerings include sports, fitness, aquatics, early childhood education, and various cultural events that cater to all age groups. The center emphasizes inclusivity and welcomes individuals from any background or faith to participate in their programs. Key initiatives include youth camps, educational classes, and cultural events that celebrate Jewish heritage and community engagement.</i><br />Target victim <b>website</b>: <i>www.lfjcc.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Optimum-Window-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28105</link>
<guid>4231962b766e3f90f64fa07e4fc2d5cf</guid>
<pubDate>Thu, 18 Dec 2025 21:29:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Optimum-Window-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2098e61d586a5aaa305894a0a4dca341ce2d12e5ee391c640391d8b4ee7e8923</i><br /><br />Threat actor <b>description</b>: <i>Optimum Window Mfg is the largest and most diversified manufacturer of steel windows and doors in the United States, offering custom high-tech metal systems for commercial and high-end residential applications since 1985. The company specializes in a wide range of products including fire-rated and non-rated steel windows and doors, aluminum windows and doors, as well as bronze and stainless steel options. Optimum collaborates closely with architects to create custom designs that merge performance, structural integrity, and aesthetic appeal. Their mission emphasizes the importance of precision craftsmanship and technology to deliver unique, high-quality products tailored to their clients' specifications.</i><br />Target victim <b>website</b>: <i>www.optimumwindowmanufacturing.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Behr-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28109</link>
<guid>9dfcbc9897ad8f393da9c34d4883524f</guid>
<pubDate>Thu, 18 Dec 2025 21:28:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Behr-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfc7e4ca535b602a1349e5a0a01bd295fe1a042fe79a5534bfae60404262c8fc</i><br /><br />Threat actor <b>description</b>: <i>Behr Enterprises is a Wisconsin-based metal fabrication company specializing in a wide range of services including laser cutting, welding, machining, and assembly. They cater to industrial, commercial, and residential clients, offering both high volume manufacturing capabilities and custom specialty designs. The company prides itself on providing 'drop everything' service, ensuring projects are completed on time with the highest quality craftsmanship. With a team of skilled fabricators and state-of-the-art machinery, Behr Enterprises is committed to delivering precision and reliability in metal fabrication.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Associated-Thermoforming</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28097</link>
<guid>3090f54f8d8eecd6469c3a9eb3ddb48a</guid>
<pubDate>Thu, 18 Dec 2025 20:26:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Associated-Thermoforming</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>827784a5ebcf6f1ae4c1ca88dc0261356799f330b8b6c443ff780923d9e27de3</i><br /><br />Threat actor <b>description</b>: <i>Associated Thermoforming offers a full range of services. ATI specializes in technically challenging custom thermoforming solutions, including vacuum forming, pressure forming, and twin sheet forming.We will upload 582gb of corporate data soon. Employees personal documents (passports, DLs and so on), financial information, client information, numerous projects, NDAs, confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>L.O.-Trading</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28095</link>
<guid>c4caf9e04a0d4f83565449f2cce9d5d5</guid>
<pubDate>Thu, 18 Dec 2025 18:26:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>L.O.-Trading</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>635bedb76423b6da9d968b0f45de42fa10e9d3157e1c9d77d48012867f4fd441</i><br /><br />Threat actor <b>description</b>: <i>L.O. Trading is a leading Technical Trading and Logistics Company that specializ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Farwest-Fabrication</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28088</link>
<guid>2c3f3db53ca4d872f79d87ec33c8c5fd</guid>
<pubDate>Thu, 18 Dec 2025 16:27:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Farwest-Fabrication</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>379fdee1fe221bcc92b954e797625d183a7a3bd9328a7ee32127316ba2db6645</i><br /><br />Threat actor <b>description</b>: <i>Farwest Fabrication specializes in steel fabrication, offering products such as pipe piling, structural and architectural steel.We will upload 45gb of corporate data soon. Employees information, financials, payment details, client files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phillips-Scales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28089</link>
<guid>2ed82a7e645e45584d3aabab834eef35</guid>
<pubDate>Thu, 18 Dec 2025 16:27:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Phillips-Scales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99246acbebe36efef79fffd32a11917d3f686c0eb50fc689d7a30765fd28042b</i><br /><br />Threat actor <b>description</b>: <i>Phillips Scales Alaska is the largest distributor of commercial and industrial scales in the state, offering a wide range of products including airport, bench, crane, floor, retail, and truck scales.We will upload 10gb of corporate data soon. Employees personal documents (passports, DLs, SSNs and other information), detailed financial information, client information, projects, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morningstar-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28093</link>
<guid>5e5bd82a90466d9434c270b85ddf187c</guid>
<pubDate>Thu, 18 Dec 2025 15:26:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Morningstar-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6186aa9b1280740c47954c21e18e498a82398f02fd7cc10338355f8a553500fc</i><br /><br />Threat actor <b>description</b>: <i>Morningstar Properties is a vertically integrated real estate developer, owner, and operator specializing in self-storage and marinas. We will upload 44gb of corporate data soon. Employees personal documents (passports, DLs and other information), financials, client information, projects, confidential files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Household--Commercial-Products-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28094</link>
<guid>d348d11f7f80d82e49a05e3c2269d373</guid>
<pubDate>Thu, 18 Dec 2025 15:26:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Household--Commercial-Products-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>187e678f4c9adc86dc262ca6525db49758b5c7205f964d3ffdbf43e82285ac2c</i><br /><br />Threat actor <b>description</b>: <i>HCPA, or the Household and Commercial Products Association, represents companies that manufacture and sell household and commercial products, advocating for a sound business environment that promotes safety and innovation.We will upload 23gb of corporate data soon. Employees, clients, partners personal documents, financial information, a lot of projects files (many of them are confidential), production information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>deerfield.com-singulargenomics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28085</link>
<guid>bf95b1669852932f77dc04f5ee405b7b</guid>
<pubDate>Thu, 18 Dec 2025 07:54:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>deerfield.com-singulargenomics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7e67b4f1ec2fc14a9c649aad2962b86360de808960778e42aad3fa5950dfc75</i><br /><br />Threat actor <b>description</b>: <i>Singular Genomics https://www.singulargenomics.com/   The company, known for its next-generation sequencing technologies such as the G4® Sequencing Platform and the upcoming G4X™ Spatial Sequencer, is now focused on further innovation in genomic and spatial multiomics research.  Singular Genomics Systems, Inc. is a life science technology company founded in 2016 that develops next-generation sequencing (NGS) and multiomics technologies to empower researchers and clinicians in advancing science and medicine. The company's mission centers on leveraging its proprietary Sequencing Engine platform, which underpins its core product tenets of accuracy, speed, flexibility, and scale. Its commercially available G4 Sequencing Platform is a benchtop genomic sequencer designed for fast and accurate results, while the G4X Spatial Sequencer, an upgrade to the G4 platform, enables high-throughput in situ direct sequencing of RNA, targeted transcriptomics, and proteomics profiling from formalin-fixed, paraffin-embedded (FFPE) tissues. The company is also developing the PX Integrated Solution, a multiomics platform that combines single-cell analysis, spatial analysis, genomics, and proteomics in one instrument. As of February 21, 2025, Singular Genomics was taken private following the closing of an acquisition by Deerfield Management. The company is headquartered in San Diego, California, with additional operations in La Jolla.  Target CEO:  Drew Spaventa https://www.linkedin.com/in/drew-spaventa-98087213/  Josh Stahl https://www.linkedin.com/in/joshua-stahl-77238627/  Target Owner:  James E. Flynn https://www.linkedin.com/in/james-flynn-99304a72/ Deerfield Management Company, L.P.  Singular Genomics is currently owned by Deerfield Management Company, L.P., following the completion of its acquisition on February 21, 2025. The transaction involved an affiliate of Deerfield acquiring all outstanding shares of Singular Genomics common stock not already owned by Deerfield for $20.00 per share in cash. As a result, Singular Genomics transitioned from a publicly traded company to a private entity, with the goal of providing greater strategic flexibility. The company's new leadership includes Josh Stahl as Chief Executive Officer and Drew Spaventa, the co-founder, continuing on the board as a special advisor to the CEO.   The data affected by this breach includes:  Source Codes Biological Data Experemental Data Client Data Personal Data (PII) Staff Data Financial Data Proposal Contracts NDA's Internal Documents Service Agreements  Breach size:  20TB  Breach review:  Singular Genomics Systems, Inc., a U.S.-based life-science technology company developing high-throughput spatial multiomics and next-generation sequencing platforms, experienced a data breach discovered on September 11, 2025. The threat actor involved was identified as INC_RANSOM. The breach is currently under investigation, and the leak size remains unknown. The incident highlights growing concerns about cybersecurity in the genomics sector, where biological data is increasingly processed through digital pipelines vulnerable to cyber threats. https://www.breachsense.com/breaches/singular-genomics-systems-data-breach/   Research Genomes:  Bacillus_cereus bcereus clost danio_rerio ecoli epr grch38 metaphlan4_databases mm10 Mycobacterium_tuberculosis phep phix phixil plasmodium_falciparum pse rhodo Rhodobacter_sphaeroides roche ruber sal spc staph synthetic_allen synthetic_allen_hp1 synthetic_allen_hp2 tb      This company does not show any interest in solving its problem. She doesn't care about the security of her data and the research of her customers. </i><br />Target victim <b>website</b>: <i>singulargenomics.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>MedHelp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28081</link>
<guid>be7c20a83fb93c62352414aa58e525c2</guid>
<pubDate>Wed, 17 Dec 2025 22:20:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>MedHelp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>240bb5c120f4804e041f5e015acb8c4c90fdb7500168f21d2cfce8a4478b2455</i><br /><br />Threat actor <b>description</b>: <i>MedHelp Birmingham provides urgent and primary care services in the Birmingham area, welcoming walk-in patients. Their offerings include a Long COVID clinic, wellness therapies, and specialized services such as Lyme Disease treatment and gynecology care.
</i><br />Target victim <b>website</b>: <i>medhelpclinics.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>smilecenterutah.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28079</link>
<guid>7cf67a2def04352826be6914e1bb5405</guid>
<pubDate>Wed, 17 Dec 2025 20:26:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>smilecenterutah.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c96a7655fbffd12f3546b7b6da72597a65f3f22318ebda84fa720523b97644d</i><br /><br />Threat actor <b>description</b>: <i>Smile Center Utah is a private dental practice located in Provo, Utah, providing comprehensive oral healthcare services to patients of …</i><br />Target victim <b>website</b>: <i>smilecenterutah.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>artcitydental.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28076</link>
<guid>163e836b057fa98808f41048cba1195f</guid>
<pubDate>Wed, 17 Dec 2025 20:24:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>artcitydental.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12e544783453164a6496348e153f5fdc2fbd31fde3e607b87a8d3a78a3e29bfc</i><br /><br />Threat actor <b>description</b>: <i>Art City Dental is a family-oriented dental clinic located in Springville, Utah, within the United States. The practice provides a …</i><br />Target victim <b>website</b>: <i>artcitydental.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>gandlmechanical.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28075</link>
<guid>a621f7ab8fd0eae3805566885dda4a25</guid>
<pubDate>Wed, 17 Dec 2025 20:24:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>gandlmechanical.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6722fe3d79835ff3e826611297f976b1eacb5a2e801a048ac0210642109fd7ae</i><br /><br />Threat actor <b>description</b>: <i>G & L Mechanical Contractor, L.P. is a regional mechanical contracting firm based in Grapevine, Texas, and has been operating …</i><br />Target victim <b>website</b>: <i>gandlmechanical.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adelman--Gettleman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28064</link>
<guid>b9c317d06906da03e3d4798fe5824e31</guid>
<pubDate>Wed, 17 Dec 2025 18:26:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Adelman--Gettleman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7689e799518db8c125010d68d02b5433f2c91b4553476753775113123b810867</i><br /><br />Threat actor <b>description</b>: <i>Adelman & Gettleman is a boutique law firm based in Chicago that specializes in commercial insolvency, bankruptcy, and related litigation. With over 40 years of experience, the firm is known for efficiently resolving financial difficulties for its clients through creative and consensus-driven approaches.We will upload 31gb of corporate data soon. Clients and employeesinformation (passports, DLs, SSNs), financials, court files, police reports and other confidential files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ACME-Industrial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28065</link>
<guid>ad01564d8f0f4da5627726cc96f717d6</guid>
<pubDate>Wed, 17 Dec 2025 18:26:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ACME-Industrial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb3bc1a6debb04624e3d9736146bb5f9e8e7f179cc861f7f20792b975af15898</i><br /><br />Threat actor <b>description</b>: <i>ACME Industrial, Inc. offers a wide range of industrial, commercial, and marine repair and mechanical services from their 10,000 square foot facility in Staten Island, New York.We will upload 256gb of corporate data soon. Employees information (passports, DLs, SSNs, birth and death certs, medical information), financials, payment details, client files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Latitude-33-Planning-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28066</link>
<guid>e5f69a36d50c3cb60dc35e49a62f4f24</guid>
<pubDate>Wed, 17 Dec 2025 18:26:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Latitude-33-Planning-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>990b11a0bf8b76c8c2f4beba60045bcc2218e16a9a85bc22393077e60dfe1afa</i><br /><br />Threat actor <b>description</b>: <i>Latitude 33 is a certified Small Business Enterprise that provides planning, engineering, and surveying services across various locations, including San Diego, Los Angeles, Sacramento, and Salt Lake City.We will upload 53gb of corporate data soon. Employees information(passports, DLs, and numerous forms with personal information), detailed financials, payment details, client files, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Amla-Commerce</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28062</link>
<guid>0a6ad41f086b7d5700c2cc9e937bd348</guid>
<pubDate>Wed, 17 Dec 2025 08:52:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Amla-Commerce</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b3aadc87eb9ffbe0726a9e29d62e5bcc70dea169a580cc11dfceea7476160a2</i><br /><br />Threat actor <b>description</b>: <i>Amla Commerce develops ecommerce software platforms. Architected with a focus on long-term sustainability, the platforms offer unmatched flexibility and scalability, as well as premium feature sets and deep functionality proven to enable growth and support even the most complex operational needs for mid-market and enterprise-level companies. Amla Commerce is the parent company of Artifi Labs, an enterprise product customization platform, and Znode, a .NET ecommerce platform with headless architecture and multi-store capabilities. Artifi and Znode power the ecommerce experiences of hundreds of companies across dozens of industries including apparel and soft goods, promotional products, uniforms, CPG and retail. Amla Commerce is a privately-held company, headquartered in Milwaukee, WI.</i><br />Target victim <b>website</b>: <i>www.amla.io</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pueblo-West-Colorado</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28055</link>
<guid>c9a4268367a43297ba960eb5bd78155c</guid>
<pubDate>Wed, 17 Dec 2025 07:26:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pueblo-West-Colorado</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>183a47f047060d4cc827ad8d3cb6923baf08cf37ede9e49a6c6a7f77a811e56c</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roose-Ressler--Green-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28053</link>
<guid>4df6cbc5729a0eda1d4aecbb08fbe9f9</guid>
<pubDate>Wed, 17 Dec 2025 05:26:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Roose-Ressler--Green-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f116f55576aababe679fa6f585464772672179b969adbd1e1838d7e823afd50</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smith-Hawks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28054</link>
<guid>761067fbba1d6ef159173bfb8109abc2</guid>
<pubDate>Wed, 17 Dec 2025 05:26:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Smith-Hawks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49380f156f9d692fb53ae6ee212832b08a7861ba75aa68d95b86500eee469454</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Holiday-Tours</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28049</link>
<guid>ddf20ca99b0ddd9a0e505ed7830ea299</guid>
<pubDate>Tue, 16 Dec 2025 22:22:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Holiday-Tours</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91adb33deeadbad061e0736943a9bcf353c8be9a9525808289dab4b22ff3e402</i><br /><br />Threat actor <b>description</b>: <i>Holiday Companies, established in 1978, is a family-owned business based in North Carolina that specializes in providing motorcoach services, group travel, and a range of travel packages including cruises and air travel. They offer charter bus rentals and preplanned tours throughout North America and beyond, ensuring a safe and enjoyable travel experience for their clients. Their commitment to safety and high DOT ratings underscores their focus on providing top-notch services. With a diverse fleet of coaches, they cater to various organizations in need of group transportation solutions.</i><br />Target victim <b>website</b>: <i>www.holidaytours.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lanmark-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28048</link>
<guid>e9527aec68523b8ceb74e12b8685b96a</guid>
<pubDate>Tue, 16 Dec 2025 21:32:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lanmark-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45cfb68a3ccf3ef0349cf1a58afa157cc8cab40b7ae6bcc76433e4fab07b8e74</i><br /><br />Threat actor <b>description</b>: <i>Lanmark Group, Inc. is a full-service general contracting firm based in Brooklyn, NY, founded in 2005. The company specializes in handling complex construction projects for both public and private sector clients, demonstrating a commitment to quality, safety, and client satisfaction. With a focus on meticulous planning and execution, Lanmark has established a strong reputation through their extensive portfolio of successful projects. Their expertise is showcased in multi-million dollar constructions, making them a trusted partner for state and municipal agencies.</i><br />Target victim <b>website</b>: <i>www.lanmarkgroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Milhench-Supply-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28047</link>
<guid>6ba927e95e97f5564105147a9d188931</guid>
<pubDate>Tue, 16 Dec 2025 21:31:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Milhench-Supply-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ebc4d4b6fab3b17dc4754c97cb77f38d8a8e97d5248d792faa4abe702051004</i><br /><br />Threat actor <b>description</b>: <i>Milhench is a family-run business that has been providing everyday necessities to keep various industries running cleanly and efficiently for over three generations. Their mission focuses on delivering dependability and quick delivery services across New England. They offer Vendor Managed Inventory programs to help clients maintain lean inventory and improve cash flow. Milhench serves a diverse range of clients, including agriculture, healthcare, hospitality, and government sectors.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peaker-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28030</link>
<guid>fca02d37f2e8afc58148dfdd93d0faf3</guid>
<pubDate>Tue, 16 Dec 2025 21:31:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Peaker-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6bbec03973c734193cf4ab0b953ba65c5d6624023eba8eeb56a1f6f002f2ac36</i><br /><br />Threat actor <b>description</b>: <i>Peaker Services, Inc. engages in rebuilding, repairing, and maintaining diesel engines and related equipment for railroad, power generation, and marine companies. The company also designs, assembles, and installs systems used in generator, compressor, propulsion, and mechanical drive systems; designs and installs custom control systems; and provides emergency and custom repair, case and pan repair, component and assembly rebuilding, contract maintenance, inspection, and surveying services. In addition, it engages in the distribution of power generation and control equipment. The company was founded in 1971 and is based in Brighton, Michigan with facilities in Brighton, Michigan; and New Castle, Delaware. Peaker Services, Inc. operates as a subsidiary of PSI Holding Company.</i><br />Target victim <b>website</b>: <i>www.peakerservices.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shlansky-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28031</link>
<guid>151d71ff5173c3e5ade51b51b1429c7c</guid>
<pubDate>Tue, 16 Dec 2025 21:31:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Shlansky-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>228b2caacadc46f0173d3da5274753d4dc61f97a7b6f363468f92f81ddb19514</i><br /><br />Threat actor <b>description</b>: <i>Shlansky Law Group (SLG) is a business law firm based in Wilmington, Delaware, specializing in providing creative legal solutions for clients in various industries including aerospace, defense, IT, and biopharmaceuticals. Established in 1995, SLG's civil lawyers are skilled in handling complex business matters such as corporate governance, fiduciary duties, and contracts, focusing on achieving favorable outcomes for their clients. The firm's dedication to client service is characterized by a nimble and consistent approach that prioritizes the specific goals of each client. SLG offers extensive experience in civil litigation, helping clients navigate disputes effectively while ensuring robust legal representation.</i><br />Target victim <b>website</b>: <i>www.shlanskylawgroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bowman-Trailer-Leasing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28032</link>
<guid>e41605316903fe4426fb0c9eee0c5b19</guid>
<pubDate>Tue, 16 Dec 2025 21:30:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bowman-Trailer-Leasing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>253500335e23ea9ca5be795e5598b4bd2cbaf4fe90f0ae12d12310e26b1e91bc</i><br /><br />Threat actor <b>description</b>: <i>Bowman Trailer Leasing specializes in nationwide trailer leasing, offering a range of products including flatbeds, dry vans, and storage containers. They serve the transportation, construction, manufacturing, and retail industries with over 30 locations across the eastern United States. Established in 1972, the company provides reliable services and real-time asset tracking for their clients. With a strong focus on customer service, Bowman Trailer Leasing aims to meet diverse transportation and storage needs.</i><br />Target victim <b>website</b>: <i>www.bowmantrailerleasing.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Centurion-Security--Investigations</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28033</link>
<guid>590894963d4a3cc360d47e890416c00a</guid>
<pubDate>Tue, 16 Dec 2025 21:30:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Centurion-Security--Investigations</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63beb5aacdd2e3b0e5d2c9294164cc4567649831a63fbc2e673ee0fb12baf448</i><br /><br />Threat actor <b>description</b>: <i>Centurion Security is a premier, locally-owned security company in Utah, offering a range of services including home security, corporate building security, and private investigations. The company prides itself on its local expertise and commitment to understanding the unique needs of Utah businesses. With a focus on delivering exceptional service, Centurion Security aims to provide reliable security solutions without losing the personal touch that larger national vendors often overlook. Their historical knowledge and deep appreciation for the local market make them a trusted partner in security management.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keycodes-Inspection-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28034</link>
<guid>1e5afce26f816c212a6b27dc47923658</guid>
<pubDate>Tue, 16 Dec 2025 21:30:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Keycodes-Inspection-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b60670a1fd1dd01585dfd4800ad082a9968e28c54d02bb846648cecea233865</i><br /><br />Threat actor <b>description</b>: <i>Keycodes Inspection Agency is a Pennsylvania State certified third-party inspection agency specializing in residential and commercial building inspections, including plumbing, mechanical, electrical, energy, and accessibility inspections. The agency is dedicated to public safety and customer service, ensuring timely and professional building code inspections. Their inspectors maintain current knowledge of building codes through required continuing education courses. Keycodes Inspection Agency is recognized as Lehigh Valley's premier inspection agency.</i><br />Target victim <b>website</b>: <i>www.keycodesinspectionagency.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-Uzzo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28035</link>
<guid>2b7768fbcdb86bdb2c9288a0e5982d2b</guid>
<pubDate>Tue, 16 Dec 2025 21:29:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>A-Uzzo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7dd1c364aa38408c87f42069f3f20993012f2a5b1687e62696e0e67ea1a8e4b7</i><br /><br />Threat actor <b>description</b>: <i>A. Uzzo & Company is a certified public accounting firm based in Purchase, NY, specializing in personalized accounting, tax planning, and advisory services. They cater to a diverse clientele, including small business owners, individuals seeking financial planning, and corporations requiring complex accounting solutions. With decades of experience, the firm emphasizes tailored strategies, innovative solutions, and long-term client relationships. Their comprehensive services include tax planning and preparation, estate and wealth advisory, and accounting consulting.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>TACK-Electronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28036</link>
<guid>3e12d6d201020d2c809f63b8d02161b3</guid>
<pubDate>Tue, 16 Dec 2025 21:29:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>TACK-Electronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7eefc6fb4d6e0c63b0e6fce869944f0187dac6a8913bf34a4e2b0fc937537015</i><br /><br />Threat actor <b>description</b>: <i>TACK Electronics specializes in producing high-quality custom wire harnesses and cable assemblies tailored for a variety of electronic applications across multiple industries. With over 25 years of experience, the company offers services including kitting, inventory management, and strategic sourcing to enhance efficiency for its clients. They are committed to quality production, ensuring that all products are 100% tested and meet customer expectations. Their clientele includes leading companies in sectors such as entertainment, transportation, aerospace, and medical.</i><br />Target victim <b>website</b>: <i>www.tackelectronics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mercury-Wire-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28037</link>
<guid>af698f2b39b1f19d13e7259e6b560a85</guid>
<pubDate>Tue, 16 Dec 2025 21:29:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Mercury-Wire-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34b267d48f3f7e4c9088ecdabdff27685956fb3e6e2d8799c139f00a302e848e</i><br /><br />Threat actor <b>description</b>: <i>Mercury Wire is a manufacturer specializing in innovative custom wire, cable, and engineered assemblies since 1967. They provide tailored solutions by understanding client needs and employing lean processes, focusing on collaboration and high-value outputs. Their products serve a wide range of industries, including industrial, medical, military, and defense, as well as specific applications like underwater cable. The company is committed to building lasting relationships with clients through dedicated problem-solving and extensive material resources.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cinema-Concepts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28039</link>
<guid>0b890a8ca95e146ae3686e4bd3b8c9d2</guid>
<pubDate>Tue, 16 Dec 2025 21:29:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Cinema-Concepts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8aecf0b82769dab9f863a1263f89a44ea0f45f85001b2133c0d14ebe0c507928</i><br /><br />Threat actor <b>description</b>: <i>Cinema Concepts is a creative studio and production company specializing in content creation, digital mastering, and duplication/distribution for cinematic exhibition. With extensive experience and cutting-edge technology, they produce quality cinema-ready files for theatrical projection and optimize media for various platforms. Since 1977, they have collaborated with agencies, corporations, broadcasters, studios, independent filmmakers, and film festivals, redefining the media production experience. Their scalable and flexible studio enables them to effectively create, edit, and prepare content that resonates with audiences.</i><br />Target victim <b>website</b>: <i>www.cinemaconcepts.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>aspenviewacademy.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28046</link>
<guid>1a24d0708b32892bc735d64fa20d9dfb</guid>
<pubDate>Tue, 16 Dec 2025 21:27:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>aspenviewacademy.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8453c61167cdcb100ab7a2a02b0d22a9b25b4a95533abc9c267de8007821d462</i><br /><br />Threat actor <b>description</b>: <i>Aspen View Academy is a charter school located in Castle Rock, Colorado, serving students from pre-kindergarten through 8th grade. Founded …</i><br />Target victim <b>website</b>: <i>aspenviewacademy.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>feldmanandlopez.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28045</link>
<guid>f37432dbde02ae7536cab364df00ccae</guid>
<pubDate>Tue, 16 Dec 2025 21:27:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>feldmanandlopez.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f6515788f473a9d033d58b0d0dcbed3501e465159d6762a00137cea0662d2df</i><br /><br />Threat actor <b>description</b>: <i>Feldman & Lopez, P.A. is a law firm based in Miami, Florida, that specialises in property insurance law and related …</i><br />Target victim <b>website</b>: <i>feldmanandlopez.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>hoodriverdentist.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28043</link>
<guid>08b41ec0a7a71415ee6b932e222d8af3</guid>
<pubDate>Tue, 16 Dec 2025 21:26:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>hoodriverdentist.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd1a7297e5b4c2bf19a1b2397e75c33601df4ed9675ffebe5dcddb5bd40d8b06</i><br /><br />Threat actor <b>description</b>: <i>Hood River Dental is a private dental practice located in Hood River, Oregon, providing comprehensive oral healthcare services to individuals …</i><br />Target victim <b>website</b>: <i>hoodriverdentist.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Leger--Shaw</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28025</link>
<guid>119e3b320ed9a4694e5173c3b64591f1</guid>
<pubDate>Tue, 16 Dec 2025 21:26:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Leger--Shaw</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>368fef97cebf1f92a1c052b4174aee75704fecd9abbfceb80009025a4313bdab</i><br /><br />Threat actor <b>description</b>: <i>Leger & Shaw is a New Orleans-based law firm established in 1979, specializing in maritime and admiralty law, class actions, complex litigation, commercial liti...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edward-J-Kone</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28026</link>
<guid>21353d3d417eb49d01e341ef047696ae</guid>
<pubDate>Tue, 16 Dec 2025 21:26:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Edward-J-Kone</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>922d77a9d24d3330469ad362c933728d886e68361695a5a85eefbec11d638c09</i><br /><br />Threat actor <b>description</b>: <i>Edward J. Kone, P.A. is a law firm focused on providing legal services in criminal defense, traffic violations, and personal injury cases. The firm, led by expe...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trine-Access-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28027</link>
<guid>487cbe45b70fc4e83a1dd07546649e34</guid>
<pubDate>Tue, 16 Dec 2025 20:26:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Trine-Access-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80bdaaa9eeec3443b59f1ea9659eaf4ba11acbb3fcdcf83088de2065aedc85a9</i><br /><br />Threat actor <b>description</b>: <i>In 1999, a new company, Trine Access Technology was formed under new ownership. Our principle remains the same while our goals are greater than ever. Trine offers the largest selection of electric strikes in the industry, including the 3000 Series SMALLEST ELECTRIC STRIKES IN THE WORLD and the EN series ONLY UL® outdoor rated strike.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Power-Curbers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28028</link>
<guid>604ee6361f8a853c947ede4e3c9da372</guid>
<pubDate>Tue, 16 Dec 2025 20:25:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Power-Curbers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>636474229eec1e84fc9c46229ba2af73ac320d5c68c007ef53a371b4676f60a7</i><br /><br />Threat actor <b>description</b>: <i>Established in 1953 in Salisbury, NC, Power Curbers manufactured the worlds first automatic curb machine. The original machines, extruders used in forming small curbs, are still manufactured as the Power Curber 150 extruder.</i><br />Target victim <b>website</b>: <i>www.powercurbers.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-Orthopaedic-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28029</link>
<guid>e8d6b4ac3e525d79c01f47bed8e1f93c</guid>
<pubDate>Tue, 16 Dec 2025 20:25:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Florida-Orthopaedic-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e41621d8b205873fc33cb0653aaeb051d1ee083c141920440ca39afba4543e10</i><br /><br />Threat actor <b>description</b>: <i>Florida Orthopaedic Associates & Walk-In Clinic is a leading provider of orthopedic care in Central Florida, offering services such as joint replacement, spine treatments, sports medicine, and general orthopedics. With a team of fellowship-trained physicians, they provide both surgical and non-surgical treatment options to address a variety of musculoskeletal conditions. The clinic operates multiple locations and features a walk-in service for immediate injury care, ensuring that patients receive timely attention for urgent orthopedic needs. Established in 1969, they have delivered over 50 years of specialized care to the community.</i><br />Target victim <b>website</b>: <i>www.floridaorthopaedicassociates.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.advancedentdenver.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28018</link>
<guid>3e159a2c6c50b5f1da0b308352b8c616</guid>
<pubDate>Tue, 16 Dec 2025 18:27:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.advancedentdenver.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a13dd92ce98084380d5f8554d6af70bdae5c9733251b60c9e64c973541ee3d64</i><br /><br />Threat actor <b>description</b>: <i>Advanced ENT & Allergy Center is a leading provider in Denver specializing in al...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allure-Home-Creation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28024</link>
<guid>13712c22586d46361e911d81469a1a3e</guid>
<pubDate>Tue, 16 Dec 2025 18:24:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Allure-Home-Creation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df82b79947fa33dfeda02f0d2b47f049a29ff857b6fc7014fe5f5b6d85ed0264</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.allurehome.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fairgrove-Oil</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28023</link>
<guid>3c03e7f05b5cbd91dffba3da4986bc1a</guid>
<pubDate>Tue, 16 Dec 2025 18:23:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Fairgrove-Oil</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c214db68e3227cbc1abedc5beb8342365e803d143c9dbc7f9246ccaa23ad217</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.fairgroveoil.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maypay-Farms-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28022</link>
<guid>1c7501e5cf59a9b7b371f9d76a67c03b</guid>
<pubDate>Tue, 16 Dec 2025 18:23:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Maypay-Farms-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3cb04b0bdeabb94916c60810fcb8335f26197dd7453d81e4bb99de5efb2656d3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.maypayfarms.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Specialty--Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28020</link>
<guid>64bb3c7589214974e7fd34f975ced5be</guid>
<pubDate>Tue, 16 Dec 2025 18:22:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Southern-Specialty--Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a72d60aabbf4bc7c30d7684b3c5e09dd370f07d5a76bd07f89e51d60be2f1e03</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.southernspecialtysupply.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Walters-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28016</link>
<guid>a485f44b58ac44713d61366e5648f187</guid>
<pubDate>Tue, 16 Dec 2025 15:26:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Walters-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa535a5cac6e3910e72d0e1e2520cdfd2a21efa6914f84449b1b7f3163714137</i><br /><br />Threat actor <b>description</b>: <i>Specializing in the production of structural steel and construction.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>LiftPRO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28010</link>
<guid>d4535535b455dd9b910ba56286a4d8f5</guid>
<pubDate>Tue, 16 Dec 2025 14:26:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>LiftPRO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad313604b8ddeb82d1d2845f67f2e751b6a43baffeb2f324d3a5b271250a12b8</i><br /><br />Threat actor <b>description</b>: <i>LiftPRO has over 40 years of experience providing lifting, rigging, and weighing solutions for various industries, including transportation and military applica...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precise-Benefits-Group-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28015</link>
<guid>9ef76737dc71b2cf44533b32fb344419</guid>
<pubDate>Tue, 16 Dec 2025 11:58:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Precise-Benefits-Group-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6b49757caa506c8241a4a08e28c39a9034c13e5639708e1e04f4967eb3ede6f</i><br /><br />Threat actor <b>description</b>: <i>Precise Benefits Group LLC operates as an employee benefits consulting and HR solutions provider. The company offers strategic employee benefits programs and services designed to help businesses manage healthcare costs, ensure regulatory compliance, and improve administrative efficiency. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beyer-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28004</link>
<guid>68af3564fb6024e891d093f8c3b8bc42</guid>
<pubDate>Tue, 16 Dec 2025 00:13:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Beyer-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae0100e364334e6e3fde59df3ffcacea59d5e054d03b96704502df86db55919b</i><br /><br />Threat actor <b>description</b>: <i>Data breach from Silicon Valley lawyers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Denk--Roche-Builders</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27991</link>
<guid>4cd9b9a23d1c08707a723b56062a502f</guid>
<pubDate>Mon, 15 Dec 2025 18:25:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Denk--Roche-Builders</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ceee1c080bb6691237220f814ffd7e9d8d47970a8b413950e32f67a6e4719555</i><br /><br />Threat actor <b>description</b>: <i>Denk & Roche Builders specializes in the construction of wood-framed and metal structures, providing services from early design concepts to final finishes, including solar applications and mass timber. We will upload 54gb of corporate data soon. Employee information,detailed financials, projects, contracts and agreements, client files, confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>International-Standard-Valve</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27992</link>
<guid>35fe071cd4426fe8a90666101fff1bf0</guid>
<pubDate>Mon, 15 Dec 2025 18:25:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>International-Standard-Valve</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8644bb5c0a515c73ac2dccaaebf49215fe0c4f6081058bfd8905b0a54887acdb</i><br /><br />Threat actor <b>description</b>: <i>International Standard Valve, Inc. specializes in providing a range of ball valves, gate, globe, and check valves tailored for theoil and gas, oil refining, natural gas, power generation, chemical, petrochemical, pulp and paper, and mining industries.We will upload corporate data soon. Employee information (name, DOB and other information), detailed financials, customer information, contracts and agreements, projects, specifications and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>uro.com-USA-Virginia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=28007</link>
<guid>79a23b3b9ac3c3c789b319b86d784613</guid>
<pubDate>Mon, 15 Dec 2025 15:26:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ms13089</b> claims attack for <b>uro.com-USA-Virginia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb5a84a74381962738bfbdf618fbfc1fcf8d2617b94c844c98d6fd735b1e2d93</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>ms13089</category>
</item>
<item xmlns:dc='ns:1'>
<title>Print-O-Tape</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27993</link>
<guid>acbcd0c9b20213125418321ef002f24d</guid>
<pubDate>Mon, 15 Dec 2025 15:18:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Print-O-Tape</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73871a80df8909aee395b3597bbf89e481ac6c3fd3b9ff9f7aadea5b9934de1b</i><br /><br />Threat actor <b>description</b>: <i>Print-O-Tape, Inc. is a manufacturer specializing in self-adhesive labels, offering a wide range of products including custom labels, stock labels, RFID labels, and roll materials. The company has established strong relationships with well-known end users, resellers, and OEMs, providing labeling solutions. Their commitment to innovation and technology allows them to remain an industry leader, serving markets such as transportation, warehousing, food and beverage, and consumer goods. Print-O-Tape, Inc. manufactures and supplies self-adhesive labels to customers worldwides.</i><br />Target victim <b>website</b>: <i>printotape.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gordon-Clifford-Properties-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27988</link>
<guid>731d1ffc634f4e5ac44b01592b12a0ad</guid>
<pubDate>Mon, 15 Dec 2025 11:44:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Gordon-Clifford-Properties-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>075dcdb66da30e020531568aac3050ebc4900d10d7c03d9289e7af3a2ec2f201</i><br /><br />Threat actor <b>description</b>: <i>Property management and serving san francisco property owners</i><br />Target victim <b>website</b>: <i>gordoncliffordmanagement.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Angstrom-Automotive-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27987</link>
<guid>e3bff3cd294df3b24f6fe9e700d86a91</guid>
<pubDate>Mon, 15 Dec 2025 11:43:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Angstrom-Automotive-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c9bf734df1456caaf994e542e4076adfff675ab83dd48700a709ca4c5f222b0</i><br /><br />Threat actor <b>description</b>: <i>Leading tier 1 full-service supplier for Automotive and Industrial OEMs</i><br />Target victim <b>website</b>: <i>angstrom-usa.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>cityofsignalhill.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27981</link>
<guid>086c98cd8fcd5da4d44864f9b3c7c2fa</guid>
<pubDate>Mon, 15 Dec 2025 02:14:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cityofsignalhill.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>724860f60bb39a287267481ad7c9b9b80e1891b880c41b76bafb094072d80374</i><br /><br />Threat actor <b>description</b>: <i>Signal Hill, CA offers a range of services and resources to its residents, including city hall renovation updates, a shop local campaign called Open Rewards, and information on upcoming city events. The city also provides resources for job seekers, safe clean water initiatives, and community assistance programs. Residents can access the city's cable channel online, nominate pets for Pet of the Month, and download the Signal Hill Now mobile app for convenient access to city information. Employees: 50 Revenue: $7.1 Million Industry: Government  Phone Number: (562) 989-7300</i><br />Target victim <b>website</b>: <i>cityofsignalhill.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kier--Wright</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27970</link>
<guid>43d5b8fc1b0674e7cfd04c36d6bb6442</guid>
<pubDate>Sun, 14 Dec 2025 23:26:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kier--Wright</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a2b20253a8a020f1f7824c93f69f00b79f84781da4a521f60cbb0317cc79a7e</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>lampus.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27974</link>
<guid>0ba166bf271f1eb979cda386d2b74265</guid>
<pubDate>Sun, 14 Dec 2025 20:39:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>lampus.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b27dc0ec73104d2f0668516dc663f49274393390e4cb24e6bc5f1bc8879a923</i><br /><br />Threat actor <b>description</b>: <i>R.I. Lampus Company, operating the domain Lampus.com, is a long-established American manufacturer and distributor in the building materials industry. Founded …</i><br />Target victim <b>website</b>: <i>lampus.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smith-Roberts-Baldischwiler-LLC--OKC-Engineering-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27968</link>
<guid>e6eb4c2fedeb246841d5b95592cb1218</guid>
<pubDate>Sun, 14 Dec 2025 14:25:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Smith-Roberts-Baldischwiler-LLC--OKC-Engineering-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>697f1795aaaeaedc272af237380aaf6f00aa8c4be193f34a37a19eac6ebf9045</i><br /><br />Threat actor <b>description</b>: <i>Many projects of large companies are now available to public. Customer information, confidential data, and much more. 
Successful engineering projects begin wit...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>dabafinance.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27967</link>
<guid>3db0c81b0a25ab06af83bde59115dd4b</guid>
<pubDate>Sun, 14 Dec 2025 01:53:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>dabafinance.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ce3160f9e1c594a356b2582dea18050d9b6d573804cd140025b2c6bf78ada96</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>example.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vishnick-McGovern-Milizio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27962</link>
<guid>b7720952eb73703ed33b3f05ddd2690a</guid>
<pubDate>Sat, 13 Dec 2025 18:22:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Vishnick-McGovern-Milizio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b23c41fd7161a5311889071cc5430c5ec1c9bb3eb1795e70af95ed074af79dd0</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.vmmlegal.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jabezco-Industrial-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27960</link>
<guid>7428f98008346bb6aa6fc92d257505ab</guid>
<pubDate>Sat, 13 Dec 2025 16:59:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Jabezco-Industrial-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4a8849d877a7bd1dcf8f5b4dfc52fab1de963b2516f39eed07d4b94bff2ad37</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jabezco.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Choates-HVAC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27959</link>
<guid>57c2380d5c0be43f6c952835e58f7a55</guid>
<pubDate>Sat, 13 Dec 2025 16:59:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Choates-HVAC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cad7fdf1da7557dd6394db14fcd1037fcd208a547a6543c94104d7f4c4542030</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.choateshvac.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Viga-Eatery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27958</link>
<guid>352decc1e8f3d97fcdb53af60cbe1f53</guid>
<pubDate>Sat, 13 Dec 2025 16:58:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Viga-Eatery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>daeeb26b44040929aba915ed82394d0fe8acb8ed1d832945ed50e597bda80933</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.vigaeatery.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eastman-Cooke</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27957</link>
<guid>1fe37085233f04789c85afa0a8b3f7b3</guid>
<pubDate>Sat, 13 Dec 2025 16:57:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Eastman-Cooke</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d2daae05585283b8a85cee6b71bdb482ddf7e7fb00ca8aa4932879693769d10</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.eastmancooke.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Temple-Shalom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27951</link>
<guid>1899267a7cab6c98197ea43751df1c07</guid>
<pubDate>Sat, 13 Dec 2025 13:26:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Temple-Shalom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1c9037ba2729a2b77b18445d0de6849a4a1921beb987594178870adff0008d9</i><br /><br />Threat actor <b>description</b>: <i>Temple Shalom is a Reform Jewish community of approximately 400 families who celebrate the diversity of modern Judaism in the Washington, D.C. area by welcoming...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Inter-American-Tropical-Tuna-Commission-IATTC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27947</link>
<guid>f335bf480fd91007c3c81a67a1dd4294</guid>
<pubDate>Fri, 12 Dec 2025 22:48:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>minteye</b> claims attack for <b>Inter-American-Tropical-Tuna-Commission-IATTC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0cda02e90ecc5fa802d77e583de8ea6be84a76f37682eeead13ee2672c35288</i><br /><br />Threat actor <b>description</b>: <i>Size: 2.3 TB</i><br />Target victim <b>website</b>: <i>www.iattc.org</i>]]></description>
<category>minteye</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sponseller-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27946</link>
<guid>e52265108325dab81ab318b51c5c83a1</guid>
<pubDate>Fri, 12 Dec 2025 22:48:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>minteye</b> claims attack for <b>Sponseller-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05c6ad46a8ede468b8349b8904b5ada787156f48bf4902df1a284cf6feb82a6c</i><br /><br />Threat actor <b>description</b>: <i>Size: 300 GB</i><br />Target victim <b>website</b>: <i>www.sponsellergroup.com</i>]]></description>
<category>minteye</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cranford-Buckley-Schultze-Tomchin-Allen--Buie-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27945</link>
<guid>0c9aecd2692cfe28067bb0eba9ae409a</guid>
<pubDate>Fri, 12 Dec 2025 22:47:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>minteye</b> claims attack for <b>Cranford-Buckley-Schultze-Tomchin-Allen--Buie-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f5a428cad13b4a5844fdf534dfe01dd60b59eb7b30f8cb8093bc408d801eacda</i><br /><br />Threat actor <b>description</b>: <i>Size: 350 GB</i><br />Target victim <b>website</b>: <i>www.southcharlottelawfirm.com</i>]]></description>
<category>minteye</category>
</item>
<item xmlns:dc='ns:1'>
<title>David-M.-Schwarz-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27943</link>
<guid>f428ed8209a04774dd294d6dc12ae201</guid>
<pubDate>Fri, 12 Dec 2025 22:47:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>minteye</b> claims attack for <b>David-M.-Schwarz-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa8ec77fc21ce2d724d0f2941260228aea9ceb112cc70ea3f8666d85e01058dd</i><br /><br />Threat actor <b>description</b>: <i>Size: 1.9 TB</i><br />Target victim <b>website</b>: <i>www.dmsas.com</i>]]></description>
<category>minteye</category>
</item>
<item xmlns:dc='ns:1'>
<title>ACE-Forwarding</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27940</link>
<guid>e7269f62ac39734ee9cfb1d0bd72cb06</guid>
<pubDate>Fri, 12 Dec 2025 22:11:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>obscura</b> claims attack for <b>ACE-Forwarding</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af7497b324bb297aedebf5d2d09eaaabbd482532f77e7f6e14d14f71b7e7f2ba</i><br /><br />Threat actor <b>description</b>: <i>Ace Forwarding offers several methods of protecting your freight. Full-service crating and repackaging are available in a variety of materials. Our full time staff of carpenters will custom-tailor crating and packaging to fit your specific needs.</i><br />Target victim <b>website</b>: <i>aceforwarding.com</i>]]></description>
<category>obscura</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Keetoowah-Band-of-Cherokee-Indians-in-Oklahoma</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27938</link>
<guid>8ee15923664a1ff58e5f7fddfdb91679</guid>
<pubDate>Fri, 12 Dec 2025 16:56:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>United-Keetoowah-Band-of-Cherokee-Indians-in-Oklahoma</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e4b67b3f47bffe7740b15a4619d756ad3ca0af1f4b7c15409885c6c4dd7794dd</i><br /><br />Threat actor <b>description</b>: <i>United Keetoowah Band of Cherokee Indians in Oklahoma</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>RJS-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27928</link>
<guid>0d2b7cc9dbcaf0935fd159ccfe19345d</guid>
<pubDate>Fri, 12 Dec 2025 16:27:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RJS-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41330fba16ff899a9c908e57e5cb9da01e37f7b997e7acd9d36b302e0701863f</i><br /><br />Threat actor <b>description</b>: <i>RJS Logistics is a freight and logistics company specializing in transporting produce and refrigerated freight. RJS Logistics alsoprovides van freight and flatbed freight services.We will upload corporate data soon. Employee information (DLs, w-9, phones, address and so on), detailed financials, a lot of customers files, contracts, NDAs, confidentiality agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Warrior-Crane-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27926</link>
<guid>1a7f33274089feff1baef7286b95fe0e</guid>
<pubDate>Fri, 12 Dec 2025 14:25:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Warrior-Crane-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6efe750f2507b2b74fb3a5cd782cfa834ddade2efabfaa18b2d918271b2762e</i><br /><br />Threat actor <b>description</b>: <i>Warrior Crane is a leading provider of specialized crane lifting services, delivering customized solutions to diverse industries. We will upload 22gb of corporate data soon. Employee information (DLs, passports, phones, address and so on), financials, client information, contracts and agreements, confidentiality agreements,etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maven-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27934</link>
<guid>3a4f2a43162106f67b1d40af656e4f5c</guid>
<pubDate>Fri, 12 Dec 2025 14:17:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Maven-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>331e641bc7fa6307d23c6c2a787aa4f407318f6261c1a2c150b1ac8afbf0cc7a</i><br /><br />Threat actor <b>description</b>: <i>We offer one of the best solutions in the market. We have solutions to target every vertical segment of the market be it a small shop, a small busi...</i><br />Target victim <b>website</b>: <i>mavensolutions.net</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arcom-Digital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27933</link>
<guid>dccf189cbe63472d0f4f5b00facfd2e1</guid>
<pubDate>Fri, 12 Dec 2025 14:16:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Arcom-Digital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a73792937e7eb6207ad56cbf5462170b02168af1686c02fb910809388fa61b0</i><br /><br />Threat actor <b>description</b>: <i>Arcom Digital specializes in advanced digital technologies aimed at enhancing network performance through products like PNM+, Hunter, and QAM Snare...</i><br />Target victim <b>website</b>: <i>arcomdigital.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anderson-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27929</link>
<guid>79a1ceaa787c9e27d921fa324d93e9dd</guid>
<pubDate>Fri, 12 Dec 2025 14:02:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Anderson-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29976b81a21aed194ff32c93b7b7586cf68c550ca71e531c6ad4116fb30c2c26</i><br /><br />Threat actor <b>description</b>: <i>We specialize in navigating complex regulatory requirements, engineering precise designs, and ensuring seamless permitting to get you building faster. With over 35 years of experience, we solve your most demanding engineering, permitting, and compliance challenges, letting you move to construction with precision and expertise.Personal information of employees and clientsFinancial documentsProjects, drawings https://www.andersoneng.com/</i><br />Target victim <b>website</b>: <i>www.andersoneng.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Personal-Injury</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27916</link>
<guid>11e7a6a3701b0a2593faef99048a2c86</guid>
<pubDate>Fri, 12 Dec 2025 08:25:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Personal-Injury</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c04f68f9766d14ed34c812473e4b5ac2b70364350bdcc50bb5af07754c55972</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jeff-DAmbrosio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27917</link>
<guid>c96a3c8c43f8a4316ba293e5257bceb4</guid>
<pubDate>Fri, 12 Dec 2025 08:25:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Jeff-DAmbrosio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d569d2f50d25944b7fd0e313b9d014c78d342397a6a9ecc9c4193ef9e55889e0</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spitzer-Auto-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27918</link>
<guid>cb04f3f921fe1d7e1be45b44f8bba68e</guid>
<pubDate>Fri, 12 Dec 2025 08:25:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spitzer-Auto-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60bf5576960719d5bdfb377d33bd5f6ebd1af7c682bcf7ccb74bbc0a75131088</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Oxford-Rehabilitation-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27919</link>
<guid>5e6c70cda1988d563aba2fa39bc65169</guid>
<pubDate>Fri, 12 Dec 2025 08:25:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Oxford-Rehabilitation-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ecf15ef57ec32f7971e68d43ed7a12dd7cdb09d5f791680ec2b1678eae70a9b</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Parkes-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27920</link>
<guid>9d12e02aa8d4f4aa04006cdc0eca2517</guid>
<pubDate>Fri, 12 Dec 2025 08:25:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Parkes-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>50004b56c379f6fcf286293cb85912671fbedf5e5b0eada5cd9260dec506e716</i><br /><br />Threat actor <b>description</b>: <i>Commercial & Residential Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greene-Metal-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27921</link>
<guid>dd12bd299fda26a6e4bb066bb2d30d39</guid>
<pubDate>Fri, 12 Dec 2025 08:25:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Greene-Metal-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7c348c0588407d0ae31dac1a7b0d59d07e32f94d63d044d51fa5e4b97f41669</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Iroquois-Memorial-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27915</link>
<guid>50e8d294d7bce40086885257076ede3f</guid>
<pubDate>Thu, 11 Dec 2025 21:44:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Iroquois-Memorial-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43df48f5aa47cdba40a7a6fc801ac3f80bd0053204ddd9d9496701d5081695b5</i><br /><br />Threat actor <b>description</b>: <i>Cost-efficient, high quality, consumer-responsive health care services</i><br />Target victim <b>website</b>: <i>iroquoismemorial.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Air-Systems2</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27910</link>
<guid>20bd92d00294780ca1aa5dcbb4474e36</guid>
<pubDate>Thu, 11 Dec 2025 18:25:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northern-Air-Systems2</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>169700c6058e0978a889f86ea9a2decb47f94d1ab28964e643029e2e2557cf5a</i><br /><br />Threat actor <b>description</b>: <i>Northern Air Systems has been a leading manufacturer of high-quality HVAC systems for commercial and industrial applications for nearly three decades.As you could have noticed, we've made it 2nd time to penetrate totheir systems and locked almost 90 vms. At this time we've takenfive times more data (150gb) and we will upload the files soon. Detailed employee information (i-9 forms, passports, DLs, medicalinformation, pictures and so on), client data (DLs, addresses, emails), detailed financials, lots of projects information, contracts and agreements, numerous NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodard-Emhardt-Henry-Reeves--Wagner-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27914</link>
<guid>85fc1189e46c7278b2aeb7008506a6f2</guid>
<pubDate>Thu, 11 Dec 2025 14:49:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Woodard-Emhardt-Henry-Reeves--Wagner-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e55e2e91a32e53776d590a7b1fda244959e7defca40247f017b8eab2cbe97a2</i><br /><br />Threat actor <b>description</b>: <i>Woodard, Emhardt, Henry, Reeves & Wagner, LLP</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>A.S.A.P.-Restoration</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27903</link>
<guid>388e1fde50eb5883ad7b020fdb42b250</guid>
<pubDate>Thu, 11 Dec 2025 13:26:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>A.S.A.P.-Restoration</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ca91cf756d125d9ed3683b18bf740d26d08e77cf0383423ffee4b27d7a14a5f</i><br /><br />Threat actor <b>description</b>: <i>ASAP Restoration FL is a Florida-based company specializing in emergency restoration services for water, fire, and mold damage, operating 24/7 across South Flor...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ada-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27905</link>
<guid>9cc1efe753654fa0220a77e5c3c14478</guid>
<pubDate>Thu, 11 Dec 2025 12:13:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ada-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6dcceab95f9da79ec52b03615f95a15802340dc059d2975a7916ddb31d758024</i><br /><br />Threat actor <b>description</b>: <i>ADA Technologies, Inc. is a Colorado-based manufacturing company 
with a focus on advanced energy storage and innovative products f
or advanced markets. The company utilizes third-party funding for
continuous research and development to create manufacturable pro
ducts tailored to the needs of its customers.

We will upload about 235gb of corporate data soon. Detailed emplo
yee information (passports, DLs, SSNs, phones, address, birth cer
ts, medical information and so on), detailed financials, client a
nd customer information, lots of project files, contracts and agr
eements, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>NSE-Insurance-Agencies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27898</link>
<guid>7577c54ea4b4258f50a4477dbd1bca3a</guid>
<pubDate>Thu, 11 Dec 2025 02:09:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>NSE-Insurance-Agencies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d397a71fc41ce3f1891b95932279aa790e42ccfd291abed58462cd645d6b2ef6</i><br /><br />Threat actor <b>description</b>: <i>NSE Insurance Agencies, Inc. is an independent insurance agency established in 1912, providing a comprehensive range of insurance services to individuals and business owners in Tulare, Kings, and Kern counties.</i><br />Target victim <b>website</b>: <i>www.nseinsurance.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Erie-Molded-Plastics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27897</link>
<guid>91a8651859745d25095a46fdda893cfa</guid>
<pubDate>Thu, 11 Dec 2025 00:30:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Erie-Molded-Plastics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e4d6f7baaad72f52154f1e68f655010fe3cf52339d2d192c60edc4c2ee387960</i><br /><br />Threat actor <b>description</b>: <i>Quality You Can Count On... Integral to our Rapid Response program is an extremely competitive pricing structure designed to save you money. We offer flexible order quantities and stocking programs to help integrate our closures into your production schedule. In addition, our products are manufactured within the highest quality standards. Our GMP facility is temperature controlled and has earned an ISO 9001:2008 certification. EMP Closures is the proprietary stock cap and closure business for Erie Molded Plastics. For more than 35 years, Erie Molded Plastics has been providing OEM and distribution customers custom injection molded parts and integrated packaging solutions. All of our custom and stock products are manufactured in our state-of-the-art molding facility conveniently located in Erie, PA. This temperature and humidity controlled plant features more than 20 molding presses, ranging from 85 to 725 tons. </i><br />Target victim <b>website</b>: <i>www.eriemoldedplastics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lonich-Patton-Ehrlich-Policastri</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27891</link>
<guid>d4b928f113a81d37a37bdfe5a1fecfba</guid>
<pubDate>Wed, 10 Dec 2025 18:25:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lonich-Patton-Ehrlich-Policastri</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6954dee89e76d1ca908f0230e8550c037ee50142cc0e9001067dae2623c7c272</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kirby-Agri</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27892</link>
<guid>3b9b987df093605d39c7aa0e30771742</guid>
<pubDate>Wed, 10 Dec 2025 17:25:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kirby-Agri</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6158ac31e1bd255a1a1ca025927ab03bfedd4ae854727fb3246fe591c4f5bec</i><br /><br />Threat actor <b>description</b>: <i>Kirby Agri Inc. serves agricultural, landscape, and turf wholesalers with a complete line of fertilizer and plant nutrients.We will upload 15gb of corporate data soon. Employee information (name, DOB, address, email and so on), financials, customer information, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LINEMASTER-Switch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27893</link>
<guid>990ecc138c1cbd618aca7cfd08cd1aa8</guid>
<pubDate>Wed, 10 Dec 2025 17:25:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>LINEMASTER-Switch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7be37ebe2024244bead8c75ff53566532df1055eaa36f8dfbf78b73e2669ca46</i><br /><br />Threat actor <b>description</b>: <i>Linemaster Switch Corporation is a trusted manufacturer of medical and industrial footswitches, offering both custom and stock solutions with over 70 years of experience and ISO 13485 certification.We will upload about 25gb of corporate data soon. Employee information (passports, DLs and so on), detailed financials, customer information, projects, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Urban-Remedy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27883</link>
<guid>6b36917c087c21e48531ea1309ac0147</guid>
<pubDate>Wed, 10 Dec 2025 11:25:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Urban-Remedy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5fcfdcf3ee24a5ffb351dd61d42fd16d0f7ba5333aa08851c35f84a28732d30</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vestil-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27885</link>
<guid>87208431a38b263a8212d32da9222f2d</guid>
<pubDate>Wed, 10 Dec 2025 11:25:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Vestil-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0ba1eeb8d30d6a7e9b188a379b271e9b76f362ab639470e5550bd2c8d6908ff</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>dillonyarn.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27889</link>
<guid>5ebb9c2331e5ad574f452f293607041f</guid>
<pubDate>Wed, 10 Dec 2025 10:17:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>dillonyarn.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45f2be0805b21b7784b5592d0802c10aa39670b0d3a9e3a3973751abfc512709</i><br /><br />Threat actor <b>description</b>: <i>Dillon Yarn is a distributor of spun, flat and industrial yarn, as well as other incidental textile items for use in textile and related industries.</i><br />Target victim <b>website</b>: <i>dillonyarn.com</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cisneros</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27880</link>
<guid>30817601adbc53cc3d07ee109c602083</guid>
<pubDate>Wed, 10 Dec 2025 02:45:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cisneros</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29bbbfac6e1c69c31f005d460d2e79b860bbfea79061a5004522755f058f5450</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cisneros.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>rainbowtel.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27879</link>
<guid>8553bf408bb98c10bf0fdd4220b50329</guid>
<pubDate>Wed, 10 Dec 2025 01:27:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>rainbowtel.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7209aef1424bb3a28991f8c5652ce5621c7442fa7b10879eb0b71ac03e204f44</i><br /><br />Threat actor <b>description</b>: <i>Rainbow Communications offers reliable high-speed internet and phone services primarily in Northeast Kansas.  They cater to both residential and business clients, providing essential connectivity solutions.  We downloaded 200GB of selected information (accounting, HR, customer data, as well as confidential information).</i><br />Target victim <b>website</b>: <i>rainbowtel.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Teruya-Brothers-Ltd</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27878</link>
<guid>4a2d84630e650155dd3f0d107c9794a9</guid>
<pubDate>Tue, 09 Dec 2025 23:50:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Teruya-Brothers-Ltd</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ffaebef7c597fec3295868e7fab76d75570d4e5ecc86ce0ad4795eda1454a9a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>teruyabrothersltd.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CPS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27877</link>
<guid>4e69622f5a820f3d466927b558ba83ac</guid>
<pubDate>Tue, 09 Dec 2025 21:49:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>CPS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb172703fe2cfa93d7bdbd19d5ca67447f77c54a0a608769e0915fd6d9c7c623</i><br /><br />Threat actor <b>description</b>: <i>CPS, Ltd. is a full-service engineering firm based in Grand Forks, ND, specializing in municipal engineering, transportation, water resources, solid waste management, and construction engineering. Established in 1979, the company aims to provide innovative, technically sound designs tailored to meet the unique needs of clients in communities, companies, and governmental agencies across North Dakota and northwest Minnesota. Their services also include land planning and surveying, ensuring accurate data and documentation for a variety of projects. CPS, Ltd. is committed to leveraging its experience and expertise to support clients in achieving successful project outcomes.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>James-Free-Jewelers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27875</link>
<guid>b2904d830c10d441213b8a7f67e9aafd</guid>
<pubDate>Tue, 09 Dec 2025 19:56:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>James-Free-Jewelers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75e8b0bde0273a08ba42145fe253d7a3c24e77c0230e34eb4d12c36a82dad9bb</i><br /><br />Threat actor <b>description</b>: <i>James Free Jewelers specializes in fine jewelry and diamonds, offering a selection of engagement rings, Swiss timepieces, and luxury jewelry from renowned designers such as Mikimoto and Roberto Coin. Their extensive collection includes rings, bracelets, necklaces, and watches from prestigious brands like Rolex and Tudor. The company also provides custom jewelry design, repair services, and financing options tailored for clients seeking high-quality pieces. With locations in Dayton and Cincinnati, they cater to both local and online customers looking for exquisite jewelry and timepieces.</i><br />Target victim <b>website</b>: <i>www.jamesfreejewelers.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clean-Air</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27876</link>
<guid>25fadf1aed8557bf7c5355568201d8ee</guid>
<pubDate>Tue, 09 Dec 2025 19:56:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Clean-Air</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eeec364bb49b8e8ebd1549947040eebb4f84b5161a2c8e5d758cc064114dc414</i><br /><br />Threat actor <b>description</b>: <i>Baker Co. specializes in the engineering, testing, and manufacturing of made-to-order laboratory safety equipment, boasting over 100 years of industry experience. Their product offerings include biological safety cabinets, clean benches, pharmaceutical isolators, and fume hoods, among others. The company serves various sectors including biotechnology, pharmaceuticals, microbiology, and life sciences. With a commitment to biosafety and contamination control, Baker Co. collaborates with scientific partners to provide tailored solutions for laboratory automation and precision cell culture.</i><br />Target victim <b>website</b>: <i>www.cleanair.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dill-Dill-Carr-Stonbraker--Hutchings.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27862</link>
<guid>0ba41b0d638ce6603ba3187af10ea9ca</guid>
<pubDate>Tue, 09 Dec 2025 18:19:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Dill-Dill-Carr-Stonbraker--Hutchings.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a340ac3667a47825de7fa9ee31067cc1e9bda19e77ec274fee4ff68e3eef824</i><br /><br />Threat actor <b>description</b>: <i>A lawyer firm from Denver, USA.</i><br />Target victim <b>website</b>: <i>dillanddill.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sunair-Electronics-and-Circuitronix.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27863</link>
<guid>0ca43fa93984fe2501a08c50e7b72d36</guid>
<pubDate>Tue, 09 Dec 2025 18:19:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Sunair-Electronics-and-Circuitronix.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa1f8ae4d31f783d4eaa182a2bc46e4cfe7d7b1dc6162f99ce9969facaf97ff2</i><br /><br />Threat actor <b>description</b>: <i>Companies specialize in the manufacture of high-frequency communication products and printed circuit boards.</i><br />Target victim <b>website</b>: <i>sunairelectronics.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Inter-care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27869</link>
<guid>d697311aad4f58ad2c5d4286fc22980d</guid>
<pubDate>Tue, 09 Dec 2025 18:15:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>Inter-care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66057397687cb66c90e254146a2dce211e5ddff6c20711004257b71782600b6f</i><br /><br />Threat actor <b>description</b>: <i>Full quickbooks dump, patients data, and financial data</i><br />Target victim <b>website</b>: <i>theintracare.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Center-of-Association-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27865</link>
<guid>d13d62b286a371638640a3f4638f1629</guid>
<pubDate>Tue, 09 Dec 2025 17:40:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>The-Center-of-Association-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59bb6461087f1f6bc1313bebee675a840128a4b1acd7713be53078d29df3cfcb</i><br /><br />Threat actor <b>description</b>: <i>The Center of Association Management</i><br />Target victim <b>website</b>: <i>camihq.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hardesty--Hanover</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27856</link>
<guid>2ad6254f399210225fd55b419d4c855e</guid>
<pubDate>Tue, 09 Dec 2025 17:25:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hardesty--Hanover</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d1f6abb5ff2d470be23378927a21199cd22880eef443442fe5c0fb5a7f92ccd</i><br /><br />Threat actor <b>description</b>: <i>H&H is an expert firm specializing in infrastructure engineering and kinetic systems structures, providing a broad range of services including architectural design, construction engineering, and geotechnical engineering.We are ready to upload 323gb of corporate data. Detailed personalinformation of employees (passports, DLs, headshots, visas, and a lot of forms containing personal information), detailed financials, confidential docs, agreements and contracts, project, drawings, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chastain--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27857</link>
<guid>42261fcdb3fa72a280e5adbb43bda240</guid>
<pubDate>Tue, 09 Dec 2025 17:25:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Chastain--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b2d1b82bdc00b9584b970515583cdbf5e55333528a31b6b07a308e3412a30b4</i><br /><br />Threat actor <b>description</b>: <i>Chastain is a professional consulting firm providing land surveying, land planning and development, civil, water/wastewater, construction, structural engineering, and urban planning services.We are ready to upload more than 90gb of corporate data. HR files, detailed financials, confidential files, agreements and contracts, project, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rodenburg-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27858</link>
<guid>5df66942fc13bbf265e17d1a3cb14b91</guid>
<pubDate>Tue, 09 Dec 2025 17:25:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rodenburg-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8015f7cca72dd33035aefe7d42b8c319a90293c405b43f845817bd2b68dd9763</i><br /><br />Threat actor <b>description</b>: <i>The Rodenburg Law Firm represents collection agencies, commercialforwarders, lending institutions, auto and consumer finance companies, debt buyers, state colleges, health care organizations, and other creditors in credit matters including consumer and commercial collections.We are ready to upload more than 144gb of corporate data. Detailed employee information (passports, driver licenses and other docs), confidential legal files, court hearings, client information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>GearGrid</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27859</link>
<guid>6f2c88b9135a5473b22386fd9f0632b1</guid>
<pubDate>Tue, 09 Dec 2025 17:25:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>GearGrid</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8d620e052456e2dbad6384525435b5eaf315743fb39b786e487b40fc6f70e2c</i><br /><br />Threat actor <b>description</b>: <i>GearGrid is a U.S.-based storage system and equipment manufacturer specializing in solutions for the fire and EMS, tactical, athletic, and public works industries.We will upload 16gb of corporate data soon. HR files, client files, financials, numerous project files, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Wardlaw-Hartridge-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27853</link>
<guid>61e6cb26845d59928f3e93a2d4f8b2ef</guid>
<pubDate>Tue, 09 Dec 2025 15:26:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>The-Wardlaw-Hartridge-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcc707efcbcdfdfd768a6ee38820d4fcfa00fd6a4597d694be8a888b43d0f984</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tele-Fonika-Cable-Americas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27860</link>
<guid>9c0a8e12265d2305a56af86e552e47d5</guid>
<pubDate>Tue, 09 Dec 2025 13:54:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Tele-Fonika-Cable-Americas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd57b2151444d9f7055ad34d0d5740955367fdf1788d92cbfa37b8dc4c5dd446</i><br /><br />Threat actor <b>description</b>: <i>TFKable Group is a global leader in the production of high and extra-high voltage cables, primarily serving the energy sector. The company specializes in supplying land cables and accessories for offshore wind farms in the Baltic Sea, contributing to renewable energy projects. With a strong focus on quality and innovation, TFKable conducts advanced research and testing to ensure the reliability of its products. The company is actively expanding its operations and investing in modern technologies to strengthen the domestic supply chain for the energy sector - 10GB exf sales data , finance, partners, costumers infos + workers, IDs, invoices etc, sample provided</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>chemstress.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27851</link>
<guid>141facdacb30c9b2e86172c3cfdbecc1</guid>
<pubDate>Tue, 09 Dec 2025 08:49:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>chemstress.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b09402083b7d09a2684a31fef909e6648be47a0b7f210e8f6e52a12cb0bbdc4c</i><br /><br />Threat actor <b>description</b>: <i>Since its founding in 1965, the company has combined in-house disciplines — process, mechanical, piping, structural, instrumentation, electrical, and architectural …</i><br />Target victim <b>website</b>: <i>chemstress.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Serratelli-Hat</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27837</link>
<guid>af1a4ea496c2d7d01d9d1ebd8d5c82f4</guid>
<pubDate>Tue, 09 Dec 2025 08:25:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Serratelli-Hat</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39e2250ca0f8406abe00ee3b0405c2a9112ad107571746a1b3ebaefffdcc6c58</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acu-Trans-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27849</link>
<guid>1c1c4d29dbbb2712f31f1b688ee8aaa8</guid>
<pubDate>Tue, 09 Dec 2025 05:18:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Acu-Trans-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>24789604e6a14b3ac9ee11e7bfe02b21c1d3eb871d5e3c745e4af0277029dfe9</i><br /><br />Threat actor <b>description</b>: <i>300 GB Medical files</i><br />Target victim <b>website</b>: <i>www.acutranssolutions.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>b2be.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27830</link>
<guid>56713b5bbd4991e7a6cd723c2ec6063e</guid>
<pubDate>Mon, 08 Dec 2025 21:10:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>b2be.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22e2a9108ec0bdd896ddd293073a639015a4a9aa305fbbb9c93dc1a1806953bf</i><br /><br />Threat actor <b>description</b>: <i>B2BE provides a comprehensive suite of supply chain management solutions designed to enhance visibility, control, and efficiency for businesses globally. Their offerings include document management, e-invoicing, EDI, and automation tools tailored for both customer and supplier engagement. Targeting…</i><br />Target victim <b>website</b>: <i>www.b2be.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Redi-Carpet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27805</link>
<guid>a057378e3fd83af33775777b5183603b</guid>
<pubDate>Mon, 08 Dec 2025 20:25:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Redi-Carpet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>391f21b3646675c3b7c90c3421434171414642926f8b44ca32f0252802fb3c41</i><br /><br />Threat actor <b>description</b>: <i>Commercial & Residential Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Canno-Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27806</link>
<guid>800c987b1dabf9b106575da9bb5f15a6</guid>
<pubDate>Mon, 08 Dec 2025 20:25:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Canno-Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3adeb428d39633631c88cf6fd97cdbb3f9d46498580d19448558c7ba7e23639</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>sandiegowarroom.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27827</link>
<guid>30c395dcc0e469d351859f1e0499bd16</guid>
<pubDate>Mon, 08 Dec 2025 19:25:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>sandiegowarroom.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f31cc5ca0dc70478e530c26d88a1b8d3332abd68149464afc70db1e39e5eb525</i><br /><br />Threat actor <b>description</b>: <i>The Westin San Diego is a hospitality establishment that offers specialized meeting spaces known as War Rooms. These facilities feature executive-style conference seating, advanced technology, and secure environments designed for legal professionals and businesses. The venue provides state-of-the-art amenities to support strategic planning, operational performance, and collaborative events. With dedicated meeting spaces and personalized service, The Westin San Diego creates an optimal environment for professional gatherings, strategy sessions, and business collaborations in the hospitality sector. Employees: 50 Revenue: $5 Million Industry: Hospitality  Phone Number: (619) 338-3611</i><br />Target victim <b>website</b>: <i>sandiegowarroom.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.goodmanmfg.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27817</link>
<guid>67ba8120f499c6706644ce234fc5ee1c</guid>
<pubDate>Mon, 08 Dec 2025 18:50:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>stormous</b> claims attack for <b>www.goodmanmfg.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3280da5c5d707ee8a73d56c0394f13187dba42bf520867b66c4bfc70e6f1a1b9</i><br /><br />Threat actor <b>description</b>: <i>Administrative/System Files/ADMIN, DOAS,General operational, administrative records, and potential system configuration files /Proprietary Engineering Drawings/IP/Highly specific technical documents, schematics, and design files (Intellectual Property). The (MklUp) indicates marked-up or working drafts.Product Line/System Data /RoofTop Systems Folder, Goodman Models, Goodman 12.5 /Confidential information related to specific product lines,Systematically numbered Bitmap image files (BMP), which function as internal references for parts, components, or quality checks/Goodman LC</i><br />Target victim <b>website</b>: <i>www.goodmanmfg.com</i>]]></description>
<category>stormous</category>
</item>
<item xmlns:dc='ns:1'>
<title>hohmartin.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27811</link>
<guid>37c771d1bc9e621efc6c6c03c864f981</guid>
<pubDate>Mon, 08 Dec 2025 18:16:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>hohmartin.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a61d1c3fac94f3fb995134ffec650776b84882df25940fc0a1b462b8a774229</i><br /><br />Threat actor <b>description</b>: <i>House of Hope of Martin County provides a range of services aimed at supporting individuals and families in need, including food assistance, financial aid, housing support, and educational programs. Their initiatives, such as the Client Choice Pantry and various community resources, serve over 30,000 individuals each month. The organization also offers volunteer opportunities and encourages community involvement through events like charity tournaments. Their mission is to ensure a dignified process for those seeking help while effectively managing donations to support their programs. Employees: 50 Revenue: $5 Million Industry: Non-Profit & Charitable Organizations Phone Number: (772) 286-4673</i><br />Target victim <b>website</b>: <i>hohmartin.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Landreau-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27810</link>
<guid>eac53e141058c06737f091776b2e5462</guid>
<pubDate>Mon, 08 Dec 2025 17:46:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-Landreau-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ccbd0bb0e9266fa46d1e225861ba60faeee28cd585affa41f85bfeca2760dc0</i><br /><br />Threat actor <b>description</b>: <i>The Landreau Group is an independent insurance agency dedicated to serving the Minneapolis/St. Paul community and the greater metro area. They specialize in providing tailored insurance solutions for clients with complex needs, ensuring customers have the appropriate coverage to protect their businesses and homes. Founded in 2003 by Carlos Landreau, the company emphasizes a values-driven approach, prioritizing client relationships and offering integrity-driven service. With over 25 years of industry experience, they are committed to unraveling complexity and delivering knowledge to their clients.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.eliteflower.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27794</link>
<guid>4c524a05dcf524174f747e4006689e8f</guid>
<pubDate>Mon, 08 Dec 2025 16:26:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.eliteflower.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93693c23aeda3c43a19db4d51c7673ed4a24376d93bc2431b4af6e796b1818da</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1991 and headquartered in Miami, Florida, Elite Flower specializes in...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>AGI-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27796</link>
<guid>74a4cc144b5ab22075db0cf92761830e</guid>
<pubDate>Mon, 08 Dec 2025 16:26:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>AGI-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47942ada3e2654798775c1a3083f003b5b4bfd331f96961a1ce5bbbabd39118f</i><br /><br />Threat actor <b>description</b>: <i>AGDisplays is an advanced display solutions specialist offering USA assembled, custom LCD application design and solutions across all industries.We are ready to upload 30gb of corporate data. Detailed personal information of employees (passports and DL scans, emails, phones,medical information), agreements and contracts, financials, credit card information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nadel-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27797</link>
<guid>d36c8aa0e34a51ec87204ddc1329e2eb</guid>
<pubDate>Mon, 08 Dec 2025 16:26:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nadel-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c3718ea53ba57a2f49288aa8ba591a5ce0dbd4edb17244a55d3608c489d87b8</i><br /><br />Threat actor <b>description</b>: <i>Nadel Architects has been a leader in comprehensive architecture design and planning services for over 50 years, known for their creativity, integrity, and cost-effective solutions.We are ready to upload 472gb of corporate data. Personal information of employees (passports and other information), agreements and contracts, confidential project files, financials, NDAs, and soon.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TCG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27808</link>
<guid>60ca0083f9f3c57b8a91c3022d460c55</guid>
<pubDate>Mon, 08 Dec 2025 16:09:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>TCG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87a866e2a78dbfcb5ff7a0dde2e25d3747e35914768176ee8ac4353d570d1d2c</i><br /><br />Threat actor <b>description</b>: <i>TCG Inc delivers specialized information technology and management advisory services to federal government agencies, combining technical expertise with deep understanding of public sector operations. The company focuses on four core competencies: Agile development methodologies, federal shared services optimization, budget formulation and execution support, and health science analytics. This multifaceted approach enables TCG to address complex challenges across diverse government missions. The company's service offerings reflect extensive experience navigating federal procurement, compliance requirements, and mission-critical operations. TCG's Agile development capabilities help agencies modernize legacy systems and accelerate software delivery cycles. In budget management, the firm provides advisory support for formulation processes and execution strategies, helping agencies optimize resource allocation and financial planning. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nickman-DHK-Architects-Profondia-Talbot--Associates-Fishbowl-Solutions.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27800</link>
<guid>381c66445baad0ecd29fcf55354d77a2</guid>
<pubDate>Mon, 08 Dec 2025 15:25:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nickman-DHK-Architects-Profondia-Talbot--Associates-Fishbowl-Solutions.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c18de02a9247f8a49fa544c5b7af9c6c5ac56ab43e2323d98e47642fa0b8af1</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 24gb of data of the following companies:Nickman's Drug is a chain of five locally-owned community pharmacies located in Lemont and surrounding areas, dedicated to providing personalized, affordable pharmaceutical care.DHK Architects is an architecture and planning firm based in Boston, with offices in New York City and San Juan, PR.Profondia provides up-to-date data on the use of ICT in the Swissmarket.Talbot & Associates CPA is a bilingual accounting firm based in Manitoba, recognized as one of the top three accounting firms in Winnipeg.Fishbowl Solutions specializes in digital experience platforms, document management, and employee engagement services designed fororganizations seeking to streamline processes.You will find personal employee personal data, client information, numerous project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-La-Vergne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27801</link>
<guid>c2022b24f0b91de47194bcc16e578f02</guid>
<pubDate>Mon, 08 Dec 2025 15:25:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>City-of-La-Vergne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06c4375826eafb993d84e30fe833d2723ad60be15c61935337ea2df377c8f30f</i><br /><br />Threat actor <b>description</b>: <i>The City of La Vergne provides essential services including police and fire departments, public library, and community events aimed at engaging and educating lo...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capo-Brothers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27792</link>
<guid>777f838b6d6f456d4cd42e0c89e99c83</guid>
<pubDate>Mon, 08 Dec 2025 12:25:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Capo-Brothers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f69bb8714f42489e05606e2248dff911803ca7e388b7780db3ae965e6e21d21</i><br /><br />Threat actor <b>description</b>: <i>Capo Brothers is a premier commercial truck dealer located in Ronkonkoma and West Babylon, specializing in the sales, service, and parts of Isuzu and Mitsubishi...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Comcast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27793</link>
<guid>817e911ebe6fbdaf957341830a65cc87</guid>
<pubDate>Mon, 08 Dec 2025 08:17:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Comcast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58c973d42d27df2cca7baaded4b11037896f1e4710c2634d4b4ac79a91990d52</i><br /><br />Threat actor <b>description</b>: <i>As a global media and tech company, Comcast reaches hundreds of millions of customers, viewers, and guests with world-class connectivity and platforms and beloved content and experiences.The leak was made possible by Quasar Inc., a company that prepares technical documentation for Comсast and its Genesis project. The files contain design documentation for numerous cities, as well as detailed utility plans. https://corporate.comcast.com/</i><br />Target victim <b>website</b>: <i>corporate.comcast.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Caldwell--Company-Accounting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27790</link>
<guid>01efe0c4fb62ade937afa0bdf2ea0844</guid>
<pubDate>Mon, 08 Dec 2025 00:28:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Caldwell--Company-Accounting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae3c689d8680349dab824728449d551a7f87d0ac094525d768a43c74756bea9b</i><br /><br />Threat actor <b>description</b>: <i>Caldwell Company Accounting is a well-respected CPA firm located in Plantation, FL, specializing in comprehensive accounting, tax, and financial services for both individuals and businesses in Broward County. With over a decade of experience, they offer services including IRS problem resolution, tax planning, QuickBooks support, and personalized financial consulting. Their commitment to delivering timely answers and professional advice ensures clients can navigate their financial journeys with confidence. The firm aims to provide permanent solutions to tax issues and help clients save on taxes and avoid costly mistakes.</i><br />Target victim <b>website</b>: <i>www.caldwellandcompanyaccounting.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jeffrey-W-Krol--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27786</link>
<guid>0c22d45f31acf0f4192c8c12b7a55dee</guid>
<pubDate>Sun, 07 Dec 2025 18:48:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Jeffrey-W-Krol--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fbe275d213eed5cd0780dd8ab79e4ea9a41277004b20e9008b11f2fd94540e2f</i><br /><br />Threat actor <b>description</b>: <i>Jeffrey W. Krol & Associates, Ltd. is a full-service certified public accounting firm based in Chicago, Illinois, serving a diverse clientele across the United States. The firm offers a wide range of services including personal financial planning, business accounting, tax preparation, and QuickBooks services. Their dedicated team provides professional and personalized guidance to both individuals and businesses, addressing various financial and business needs. With years of experience, Krol & Associates is committed to assisting clients in navigating their accounting challenges.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>David-M.-Schwarz-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27760</link>
<guid>87b428922a688f8a0e4ace11a473f29a</guid>
<pubDate>Sun, 07 Dec 2025 17:26:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>David-M.-Schwarz-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0c1d4bc9a437fb9129d804801ed6252d45cc3b24ec5f7decc9eeac652ad2888</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gopher-Industrial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27779</link>
<guid>b77670e4a9c8e282811958dcea1493a1</guid>
<pubDate>Sun, 07 Dec 2025 15:46:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Gopher-Industrial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>13d90222add2c6c92458a69cf093fcfd134bd165e1c538163e51c52f6b18d05d</i><br /><br />Threat actor <b>description</b>: <i>Gopher Industrial is a premier industrial distributor specializing in hoses, welding products, safety solutions, and supply chain integration. They offer custom hose assemblies, inventory management through their GOcrib system, and a wide range of industrial supplies including safety products and welding equipment. The company focuses on delivering high-quality products and exceptional customer service to a diverse clientele. Their mission is to leverage technology to provide comprehensive solutions to customers around the globe.</i><br />Target victim <b>website</b>: <i>www.gopherindustrial.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>elematec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27766</link>
<guid>dc4a1c1e778909c03a41d2c672c2b962</guid>
<pubDate>Sun, 07 Dec 2025 15:38:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>elematec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>971e2e4256826a469ed689bb76e4feb047cdac491f09d2c0da74a25cdcb61faf</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Elematec Corporation is a Japan-based company engaged in procurement and supply of electronic components, semiconductors, displays, and other industrial materials. It also offers logistic, strategic inventory management, and technical support services. Furthermore, Elematec develops various products like emission components and touchscreen panels, contributing to the manufacturing industry worldwide.</i><br />Target victim <b>website</b>: <i>elematec</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Galesi-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27780</link>
<guid>a9d671a92095bb4bbd7ff64507e8f1e8</guid>
<pubDate>Sun, 07 Dec 2025 14:42:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Galesi-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f8b200228f9120cca6f8a242072bf2813d94f9dd46c1ca829051aeec76cfa1f</i><br /><br />Threat actor <b>description</b>: <i>Galesi Group is a national real estate developer focused on creating dynamic buildings that enhance communities and drive progress. Established in 1969, the company manages a diverse portfolio of over 11 million square feet of industrial, commercial, retail, and residential properties, primarily in New York's Capital Region. Their services include construction management, property management, real estate development, and third-party logistics. Galesi Group aims to meet the needs of various clients by providing tailored spaces and fostering economic growth in the communities they serve.</i><br />Target victim <b>website</b>: <i>www.galesigroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quality-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27781</link>
<guid>2f5c144531b316a819f61e78392e3d6d</guid>
<pubDate>Sun, 07 Dec 2025 14:42:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Quality-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46cc28d7659e6074c7f793deefc225f06e73240653604830480953b6d1498e63</i><br /><br />Threat actor <b>description</b>: <i>Quality Companies, headquartered in Youngsville, Louisiana, is a company that offers energy-related products and services and provides onshore and offshore construction, fabrication, maintenance, and other oil and gas-related services.</i><br />Target victim <b>website</b>: <i>qualitycompanies.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>La-Costa-Dental-Excellence</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27753</link>
<guid>0ff0a77035f9569943049ed3e980bb0d</guid>
<pubDate>Sun, 07 Dec 2025 13:25:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>La-Costa-Dental-Excellence</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abfe5ace043fad4282d6f5e2db23a8f29e5578ff1beefb5afa8fe2e552cc46d4</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Acoustical-Control</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27754</link>
<guid>0eb7a39fc22086b7e6249d1b5253dc2b</guid>
<pubDate>Sun, 07 Dec 2025 13:25:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Acoustical-Control</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51fcda881b5fd5af3547393bf992fb300e35965eacdd4e74349aa12d57d28dfe</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kanes-Furniture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27759</link>
<guid>b54daf1b0028f1c892d8e3a56261d078</guid>
<pubDate>Sun, 07 Dec 2025 12:30:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Kanes-Furniture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6aadbf1bf72e52af689cafa01f987e24d04ce0ba4db1ea2daabf25c3f882afb8</i><br /><br />Threat actor <b>description</b>: <i>Kane's Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>four-points.marriott.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27739</link>
<guid>259618323d3becf5697603b5a58254dd</guid>
<pubDate>Sun, 07 Dec 2025 10:39:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>four-points.marriott.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3b184f72c13855789b28b25487e4a40ddb90fd416fa4b694353c9cc01275a34</i><br /><br />Threat actor <b>description</b>: <i>Marriott Bonvoy™, an award-winning travel program, offers a brand for every type of journey. Earn an...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>physiciansmedicalbilling.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27747</link>
<guid>fdb72cbd0be58617706a18144e4edd05</guid>
<pubDate>Sun, 07 Dec 2025 10:39:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>physiciansmedicalbilling.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8bddcbbff8d7900f16065c3aaf81a22aed0c428e367b54781f7dd7f3dfb85d36</i><br /><br />Threat actor <b>description</b>: <i>Company Description: Physicians Medical Billing (PMB) is a full-service medical billing and accounts...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fish--Richardson-Overview-Metrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27756</link>
<guid>b3511c39b8e9c8fedc482b0f518c36eb</guid>
<pubDate>Sun, 07 Dec 2025 08:47:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Fish--Richardson-Overview-Metrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd58d25bac2e758c4732dd3520bfe6aa2763aafc618df45f18f44c295a5896b1</i><br /><br />Threat actor <b>description</b>: <i>Fish & Richardson, founded in 1878 and headquartered in Boston, Massachusetts, is a law firm specializ…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Benchmark-Electronics-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27734</link>
<guid>e0034a76c1f340348a2ac9abf6fc7a85</guid>
<pubDate>Sat, 06 Dec 2025 20:15:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Benchmark-Electronics-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c7f95affbe464cd93762d6d5a62feabb12f5e99944fd5d56046395799a3f266</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Benchmark Electronics Inc. is a global provider of integrated technology solutions and manufacturing services. Located in Arizona, USA, the company offers its services in various sectors including medical, industrial, aerospace, and defense. They specialize in electronic manufacturing services (EMS) and product design, engineering, technology solutions, advanced manufacturing, and after-market services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jack-Levine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27703</link>
<guid>8c5b85b2e2efb5bc2756a63747c720e9</guid>
<pubDate>Sat, 06 Dec 2025 18:25:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Jack-Levine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbdf3b20d06ae61fa47b03eed578a2fdda441f89a2b112448f9f40251f1c933a</i><br /><br />Threat actor <b>description</b>: <i>Jack Levine PA CPAs is a boutique CPA firm based in the Midtown/Wynwood area of Miami, specializing in corporate tax and accounting services for businesses, ind...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.mylawcompany.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27707</link>
<guid>5dc8b954ec4e47baffc64f98d496282c</guid>
<pubDate>Sat, 06 Dec 2025 18:18:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.mylawcompany.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64bd7983ca3af9c43996f526ef5b9e92ae92e55caa39aa256170b876bb85196e</i><br /><br />Threat actor <b>description</b>: <i>700gb 4,500 cases, personal data, passports, driver's licenses, medical data, medical card</i><br />Target victim <b>website</b>: <i>www.mylawcompany.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>lso.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27708</link>
<guid>80dcdb9cf644bba63464a2795f93a562</guid>
<pubDate>Sat, 06 Dec 2025 18:16:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>lso.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21b1e292850ab93d287511185767e5e1a9f05abcfbfee9c03d451e2afffff71d</i><br /><br />Threat actor <b>description</b>: <i>Lone Star Overnight (LSO) is headquartered in Austin, Texas, and, over the last 30 years, has become a leading regional parcel delivery company. LSO has a netwo... - LSO does not understand encryption so we demonstrated for them how encryption works. We have ~500 GB data total includin...</i><br />Target victim <b>website</b>: <i>lso.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Compounding</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27704</link>
<guid>355622b7e39186c76b1c8d7c90d8d67b</guid>
<pubDate>Sat, 06 Dec 2025 18:15:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Precision-Compounding</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c4682779508c9f66633f347f8009671000516e0a084382cac3f5f0aacc82a65</i><br /><br />Threat actor <b>description</b>: <i>Precision Compounding Pharmacy, located in Omaha, NE, specializes in creating customized medications that fit the unique needs of each patient. They collaborate with healthcare providers and patients to develop unique formulations, ensuring that all compounded medications are safe, effective, and accurately made. Their services include general compounding, men's and women's health, dermatology, low dose naltrexone, veterinary care, and nutritionals. With a commitment to quality and personalized care, they aim to achieve the best therapeutic outcomes for their clients.</i><br />Target victim <b>website</b>: <i>pcrxomaha.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Towerstream</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27682</link>
<guid>34b9df8d0ab73f851c2950554db628f7</guid>
<pubDate>Sat, 06 Dec 2025 05:26:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Towerstream</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4810a1d13f9eebe7edbb293e6b748cdfe1b5df01c53f02e345996640c76d9cee</i><br /><br />Threat actor <b>description</b>: <i>Broadcasting</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Khazzan-Logistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27683</link>
<guid>8699bde6741dbac805e5e1f4e1f9651a</guid>
<pubDate>Sat, 06 Dec 2025 05:26:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Khazzan-Logistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e36ede0f1e5bf102941cf2f0c4eba485454bf46c256a4006ce6f4e157dc17e6</i><br /><br />Threat actor <b>description</b>: <i>Freight & Logistics Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Canvas-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27697</link>
<guid>e71a19dede1686a40e8fddb2e0aa24ae</guid>
<pubDate>Sat, 06 Dec 2025 04:57:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Canvas-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3da8bf8fc066555ff02c0022a72504abebc2e3e9c20b90a14da608b2c3cf7bd3</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>canvas.church</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trumbull-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27694</link>
<guid>569d09d580e772e2acaf522ba342ac0e</guid>
<pubDate>Sat, 06 Dec 2025 03:15:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Trumbull-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1cc51f427477be108c9675c30c3a78952cb1e908d38c3824de6527a092d9d97</i><br /><br />Threat actor <b>description</b>: <i>The Internal Story of a County in the State of Ohio.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>bennett.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27693</link>
<guid>46ee2a36b86b9de6d43d6e7a6774889a</guid>
<pubDate>Sat, 06 Dec 2025 00:17:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>bennett.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c92cfa44d8d8e3e7ff4c05308d3a69c69f473e0c956ef1d56236362000e6281</i><br /><br />Threat actor <b>description</b>: <i>Bennett College is a liberal arts college located in North Carolina, dedicated to empowering women through education. The institution offers a unique microcollege model that emphasizes personal attention and support for students, including high school, veterans, and first-generation college students. With a focus on equity in various fields such as health, education, and the environment, Bennett College prepares its students for successful careers and global citizenship. The college is recognized for its strong retention rates and innovative academic programs, including a Minimester model that enhances learning accessibility. Employees: 200 Revenue: $20.9 Million Industry: Colleges & Universities Phone Number: (336) 517-2100</i><br />Target victim <b>website</b>: <i>bennett.edu</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beecher-Walker-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27676</link>
<guid>5ffd53ae71eb2693352a7c03c3cfd93c</guid>
<pubDate>Fri, 05 Dec 2025 19:25:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Beecher-Walker-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eec493d8a66b694a81419ff69023a686851ac95eee03056225eabb60667ccaf9</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>King-City-Lumber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27677</link>
<guid>8742739033fea88b95401b78a630f110</guid>
<pubDate>Fri, 05 Dec 2025 19:25:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>King-City-Lumber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ce89de7003e5418cffbf78ad0676d71282d1015cbaff70d6513fffe233953de</i><br /><br />Threat actor <b>description</b>: <i>King City Lumber is a well-established provider of quality lumber and building materials, specializing in custom metal structures for over 50 years in the Midwe...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shumate-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27674</link>
<guid>18f16de5c7012d9ab4e5de2a0dcb829b</guid>
<pubDate>Fri, 05 Dec 2025 18:25:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shumate-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20fbb6601667a2e7a47812f02bf1575943a78c076de7425752817aa8914fc7d7</i><br /><br />Threat actor <b>description</b>: <i>Commercial & Residential Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>AvtechTyee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27669</link>
<guid>ab8867645b0ef41d278102c85b55f782</guid>
<pubDate>Fri, 05 Dec 2025 16:25:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>AvtechTyee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab148e60f62777b4c72d12b9fa2cd6373f304ff52aa6949f9657e11427a7c4ec</i><br /><br />Threat actor <b>description</b>: <i>AvtechTyee is a company operating in the aerospace and defense industries.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Foster--Eldridge</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27670</link>
<guid>ee00009ae546957c0eb323df484a7d8c</guid>
<pubDate>Fri, 05 Dec 2025 16:25:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Foster--Eldridge</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7ab2feb7c8a38594b2844fbdf40f2333769460a61214ebe6abaade8425dee0c</i><br /><br />Threat actor <b>description</b>: <i>Foster & Eldridge, LLP is a Boston area boutique law firm recognized for its excellence in medical malpractice defense. The firm specializes in representing health care providers in professional liability matters and offers consulting and litigation services in risk management and regulatory compliance.We are ready to upload 60gb of corporate data. Detailed client personal information (passports, DLs, phones, addresses, medical information and so on), financials, hearings, police records, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rosland-Capital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27672</link>
<guid>27a34f041b383b2b229aea2a38b36c16</guid>
<pubDate>Fri, 05 Dec 2025 16:25:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rosland-Capital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a399b8a375660758d1c7f07c66f08262d4609ce03bb53dce8ae9807fec13c6f</i><br /><br />Threat actor <b>description</b>: <i>Rosland Capital is a precious metals asset management firm that sells gold and other precious metals in physical form.We are ready to upload corporate data. Projects, clients data, a bit of confidential files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Consolidated-Sterilizer-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27668</link>
<guid>dc274708bba5df6e8b2d99932a71b1ff</guid>
<pubDate>Fri, 05 Dec 2025 14:25:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Consolidated-Sterilizer-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb14ce2f2ea0dc77e9f7060360afd2b89ea804f054017a86c1985a8d657b9973</i><br /><br />Threat actor <b>description</b>: <i>Consolidated Sterilizer Systems has been manufacturing steam sterilizers and autoclaves in Boston, Massachusetts since 1946, setting the industry standard for over 60 years. Their product range includes customizable laboratory autoclaves for various applications such as animal research, life sciences, food safety, and healthcare environments.We are ready to upload about 10gb of corporate data. Employee personal information (passports, DLs, phones, addresses, medical reports and so on), financials, contracts and agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fargo-Park-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27678</link>
<guid>2d09a47c442ccf7b6b18c11b6930d3a7</guid>
<pubDate>Fri, 05 Dec 2025 14:19:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Fargo-Park-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47d75410e342b3abe61dc4e4c50f512add3dbc456d52d3081eb5f73c1936d478</i><br /><br />Threat actor <b>description</b>: <i>https://www.fargoparks.comFargo Park District, with over 2,100 acres of land, is divided into Finance, Enterprise, Events, Operations, Programming and Facilities, Human Resources, Valley Senior Services and Courts, and Community Physical Activity. The Fargo Park District boasts over 150 parks, amenities, and over 170 kilometers of trails and paths.</i><br />Target victim <b>website</b>: <i>fargoparks.com </i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>insightchicago.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27711</link>
<guid>447f2fe245facad3a6a6966ebb3add3b</guid>
<pubDate>Fri, 05 Dec 2025 11:56:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>insightchicago.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4fb0c48445a6d3da6ef3fcb14671cddac80d821678ae65f8ccfd861f4534fb4f</i><br /><br />Threat actor <b>description</b>: <i>Welcome to Insight Hospital and Medical Center in Chicago. Our state-of-the-art facility offers comp...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>jobberswarehouse.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27712</link>
<guid>c30729adc645e1b908c3a1ac09527804</guid>
<pubDate>Fri, 05 Dec 2025 11:56:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>jobberswarehouse.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e699cca25a4a0113a314c6c864c1e442c9cc013cdcb88263d79bd449a942de97</i><br /><br />Threat actor <b>description</b>: <i>You cant help but make the right move with Jobbers Moving Storage and Allied Van Lines. Because we k...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>rjwalker.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27713</link>
<guid>e78baa1ce9b86173c8d5f876a00e64e5</guid>
<pubDate>Fri, 05 Dec 2025 11:56:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>rjwalker.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ada7e80d56ba183d0be2d4aa3641691bf7689d3a35629bf4f0194e184109646</i><br /><br />Threat actor <b>description</b>: <i>R J Walker Plumbing , Heating, Electrical and Cooling.Our family owned and operated business, with s...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>terracaribbean.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27717</link>
<guid>5a2abde8196f74354e8a23ba9551d0cc</guid>
<pubDate>Fri, 05 Dec 2025 11:56:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>terracaribbean.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a5bb4c1163bc9d5414cf19b8a9072546ecaa4d7289fbcc6cf429e2a7c95ccc7</i><br /><br />Threat actor <b>description</b>: <i>Terra Caribbean is your expert in Caribbean real estate, we&#039;re well equipped to help find you y...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>brumfieldconstructioninc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27718</link>
<guid>e619f7a17016c62600bafacfb8e15a6f</guid>
<pubDate>Fri, 05 Dec 2025 11:56:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>brumfieldconstructioninc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bc9da89540b4436137475424fed1a44263897a82139defef2d3bafb5ca50515</i><br /><br />Threat actor <b>description</b>: <i>Brumfield Construction, Inc. is a professional commercial and residential construction company locat...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>intellioan.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27727</link>
<guid>214846ab5ca61bd83f438070a4ef7e34</guid>
<pubDate>Fri, 05 Dec 2025 11:56:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lockbit5</b> claims attack for <b>intellioan.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adfd2714ed93302ce63c75a34ef2c913458789ac32e1e33369f2797d3cc247ea</i><br /><br />Threat actor <b>description</b>: <i>Experience the Intelliloan difference! Get expert guidance on home loans, refinancing, and mortgage...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lockbit5</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smith-Fire-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27664</link>
<guid>8af7aa91dea57ef40a8a11afea500470</guid>
<pubDate>Thu, 04 Dec 2025 23:48:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Smith-Fire-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8645cb69cad4fb266dcc7e806916b8c0e90ce354fbf10159d3bdbf42faabd45</i><br /><br />Threat actor <b>description</b>: <i>A company that provides comprehensive fire protection services for buildings.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kana-Pipeline-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27663</link>
<guid>83c15a5063efa34c1e31fc0a00ff04f6</guid>
<pubDate>Thu, 04 Dec 2025 22:25:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kana-Pipeline-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc28847d991f5673459e5cb87ef8fc4ec7af2231695e7d45c31c12ba17450478</i><br /><br />Threat actor <b>description</b>: <i>Civil Engineering Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ABC-Home--Commercial-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27662</link>
<guid>f17e28704bf2b4702992842989431d24</guid>
<pubDate>Thu, 04 Dec 2025 19:26:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ABC-Home--Commercial-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ba2a15a4223587477d8f755cc4d58322a04bdc769467f6f5cbc42131975a1352</i><br /><br />Threat actor <b>description</b>: <i>ABC Home & Commercial Services is a provider of home and commercial pest control, air conditioning, heating, lawn care and more.We are ready to upload 24gb of corporate data. Employee personal information (passports, DLs, phones, addresses, medical information and so on), financials, contracts and agreements, confidentialfiles and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medisend</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27661</link>
<guid>e7c3645a3ea1024d6704a3133c7930a8</guid>
<pubDate>Thu, 04 Dec 2025 18:26:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Medisend</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3264857dd7e4905dd3c731e628e6212ef1db97d4953d9382273e6c20cf4b3b9f</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Minor-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27654</link>
<guid>c00e300d85cc5e5f0d11a782da9bf045</guid>
<pubDate>Thu, 04 Dec 2025 16:26:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Minor-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4342c83720466f6cf098595523af0e5aaa351edb8c7bcb0c8c15c747768369c</i><br /><br />Threat actor <b>description</b>: <i>The Minor Firm is a premier law firm located in Northwest Georgia, established for over 40 years. They specialize in complex legalmatters, providing superior representation to individual and business clients in areas such as Health Care Law, Human Resources Law, Municipal & Utility Law, Real Estate Transactions, and EstatePlanning.We are ready to upload 63gb of corporate data. Client and employee personal information (Passports, DLs, phones, addresses and so on), court confidential documents, police reports with photos andother legal files, financials and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scientology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27655</link>
<guid>36e7410e19523e17b648b49ad9230d75</guid>
<pubDate>Thu, 04 Dec 2025 15:27:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Scientology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea513e9d441d7465430fec8a2bdd241e447d5e952417dc64e327bba4cc49dc27</i><br /><br />Threat actor <b>description</b>: <i>Non-Profit & Charitable Organizations</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>McManes-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27656</link>
<guid>682793af8891c399ad9dee25d69700fb</guid>
<pubDate>Thu, 04 Dec 2025 15:27:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>McManes-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69039b74c7b6802229e18730d802b23ff8d62e9ed0fe435794e5346c412ead54</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Institutional--Supermarket-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27657</link>
<guid>9b203b041a90f85433f0acde61ae1cc7</guid>
<pubDate>Thu, 04 Dec 2025 15:27:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Institutional--Supermarket-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>254b86992add6a07070e90a2b0c91c95cfb7c36aa1db38edf821ba59ab198c42</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peter-Meijer-Architect</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27658</link>
<guid>b95466b8b139e9e1fa1400d527798b7c</guid>
<pubDate>Thu, 04 Dec 2025 15:27:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Peter-Meijer-Architect</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddba90303607d56f2412652e5da59f3fa1993d8cf56026cd48661b32969cd031</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>sspinnovations.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27653</link>
<guid>3af72c083ddb534a6fe310bc744b5809</guid>
<pubDate>Thu, 04 Dec 2025 13:25:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>sspinnovations.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfcbfc5bbcffaa25818124e24258aa7068d1220b2babb0811af5f158f3e719c3</i><br /><br />Threat actor <b>description</b>: <i>At SSP Innovations, we help utility, pipeline, and telecommunications organizati...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Yellow-Cab-of-Columbus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27651</link>
<guid>7b9291a4431d2198fe9a16bb135f3736</guid>
<pubDate>Thu, 04 Dec 2025 09:25:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Yellow-Cab-of-Columbus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>571062a1049db04daecdb0345a6f2dd888ad510250e5d735a057da6fb830713a</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quasar-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27650</link>
<guid>28c9325a8cf6c9b1ee059630afc5a838</guid>
<pubDate>Thu, 04 Dec 2025 04:58:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Quasar-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd91a9c8b777e1f599e5ab66a9a8ea4ffa09f643c13731fe6be4e16548619d37</i><br /><br />Threat actor <b>description</b>: <i>Quasar, Inc. specializes in high-quality design, implementation support, and related services tailored for the telecommunications industry. Since 1997, the company has set a benchmark with efficient and cost-effective network designs implemented across five continents and over 100 cities. Their offerings include plant network system designs, field services for strand work, and consulting to enhance operators' competitiveness. Additionally, Quasar provides complimentary services such as training and troubleshooting support to adapt to the evolving needs of the industry.Network projects, drawingsDetailed drawings of many cities with communications designsVarious information https://www.quasar.us</i><br />Target victim <b>website</b>: <i>www.quasar.us</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>CCJM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27648</link>
<guid>09a04b5f6189f34a3a8bb148c87cce78</guid>
<pubDate>Wed, 03 Dec 2025 21:29:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>CCJM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f844195b0f58f84119be7abf504215c74b931d95361720f61b6163505ee83afa</i><br /><br />Threat actor <b>description</b>: <i>CCJM is a multi-disciplined engineering firm that has been providing client-focused engineering solutions since 1979. Their services include buildings and facilities, civil/site work, construction management and inspection, energy solutions, smart technology, surveying, transportation, and water/wastewater management. The company emphasizes a collaborative approach to exceed client expectations through high-quality service and value. CCJM serves a diverse range of clients, including public and private sector projects, with a commitment to delivering innovative engineering solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clayco-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27639</link>
<guid>6bea0403f89e400ccd9b50f6f5875d27</guid>
<pubDate>Wed, 03 Dec 2025 20:15:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Clayco-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bad898ad2d17e3a1bfc90285bf6a73b8eb4cfdf93070336a7dc6ef95341404be</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.claycoelectric.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Eye-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27640</link>
<guid>42ada6a116005062613a49add8ab908b</guid>
<pubDate>Wed, 03 Dec 2025 20:13:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Valley-Eye-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e80d86b890b21a8225aed264ee853fb64d5f6558fa61646313fc4134e3e7e7a6</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.valleyeye.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>COTTAGE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27642</link>
<guid>c7710caff9842968fac74321fd95b77c</guid>
<pubDate>Wed, 03 Dec 2025 20:13:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>COTTAGE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc2444e6898dcdec7724c7a4ac86f8714af165c65193697aa24c4e151839b81e</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cottagehospital.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Providence-Academy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27647</link>
<guid>df17389413b21cab96900be63f2c7ec4</guid>
<pubDate>Wed, 03 Dec 2025 19:30:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Providence-Academy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39fb6b1f742e53a841229f15f6dc007f82366a9b20c1add6236b1d20312d88fd</i><br /><br />Threat actor <b>description</b>: <i>Providence Academy was established as a private Christian school. The institution's staff demonstrated a disregard for their own security and that of all their students. As a result, all student databases were accessed, revealing all personal information, including SSNs. The most unsafe and unsafe job was the Chief IT Director! This is simply nonsense! Numerous financial documents and confidential employee data were also leaked.</i><br />Target victim <b>website</b>: <i>providenceacademy.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Golden-Artist-Colors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27637</link>
<guid>ae8fec2f6956a0922e374a7c9d096d28</guid>
<pubDate>Wed, 03 Dec 2025 19:25:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Golden-Artist-Colors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2596370a614b4b7b3287a19030a4713837c0a5691b311dc10a394bdb7e1bffce</i><br /><br />Threat actor <b>description</b>: <i>A major manufacturer of art materials for professional artists and designers: acrylic paints, oils, watercolors, pastels and other media/materials.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pan-O-Gold-Baking-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27636</link>
<guid>e2692f5522a9bf6fe212e70758d0701b</guid>
<pubDate>Wed, 03 Dec 2025 18:24:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pan-O-Gold-Baking-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>788133cd1e1e431af2719f29aca9bae17e89bf52379c918b8709d7299a4937cd</i><br /><br />Threat actor <b>description</b>: <i>With a rich history dating back to 1906, Pan-O-Gold Baking Company has grown to include three state-of-the-art bakeries, making usone of the top wholesale bakers in the Midwest.We are ready to upload 21gb of corporate data. Employee information (DOB, phones, addresses and so on), agreements and contracts, detailed financials, client information, large amount of internaldocuments.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>cpasch.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27646</link>
<guid>614702957b7f03d0e9e4bcd2370c3a6d</guid>
<pubDate>Wed, 03 Dec 2025 18:18:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>cpasch.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1293c9459899c217de112b3673e248f75cdc7b0c049e4bc82d678fbbde9ebe86</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 200gb
150k</i><br />Target victim <b>website</b>: <i>cpasch.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Davis-Kitchens-United-States</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27643</link>
<guid>110be03bce924f1eb65caf8491effba0</guid>
<pubDate>Wed, 03 Dec 2025 16:51:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nightspire</b> claims attack for <b>Davis-Kitchens-United-States</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adb46e45821cad693bfa926dd5e8a3c1cebd9a78f7ca0e351f7872565f561b28</i><br /><br />Threat actor <b>description</b>: <i>Davis Kitchens, United States</i><br />Target victim <b>website</b>: <i>daviskitchens.com</i>]]></description>
<category>nightspire</category>
</item>
<item xmlns:dc='ns:1'>
<title>Custom-Engineered-Wheels</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27630</link>
<guid>4e111a3fe1958d7f4c0215bba108df0e</guid>
<pubDate>Wed, 03 Dec 2025 16:25:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Custom-Engineered-Wheels</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38e648517dfae2fa7eb482e4e0b6ac2ba82f5f9e307996b209b8c331678fd137</i><br /><br />Threat actor <b>description</b>: <i>CEW Inc. specializes in custom injection molding solutions, utilizing advanced technology to produce polyurethane foam products. They offer a diverse range of products, including industrial wheels, medical mobility solutions, and components for bicycles and recreational vehicles.We are ready to upload 65gb of corporate data. Detailed employee information (DOB, phones, addresses, documents scans and so on), agreements and contracts, numerous, confidential files, financials, client information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Building-Controls-and-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27631</link>
<guid>e3354d31c6019a82e5f8d20088c5afdb</guid>
<pubDate>Wed, 03 Dec 2025 16:25:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Building-Controls-and-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3467903103656580167b1c6ad62fddc308d07e0d255ce3ef16512d6646938998</i><br /><br />Threat actor <b>description</b>: <i>Building Controls and Services, Inc. (BCS) provides innovative building automation, mechanical equipment, and energy management solutions aimed at creating efficient and comfortable environments for facility owners and managers.We are ready to upload 12gb of corporate data. Detailed employee information (DOB, DLs, SSNs, phones, addresses, documents scans and other docs of at least 212 employees), agreements and contracts, confidential files, detailed financials, client information, disclosure agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eggelhof</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27632</link>
<guid>0753a43a5366ab9a63697fd9f3abfb9d</guid>
<pubDate>Wed, 03 Dec 2025 15:25:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Eggelhof</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>133594fd10eae2a46eec1d8ddeff6252bbaab6c9fc32e9592c75f2d4f58a662c</i><br /><br />Threat actor <b>description</b>: <i>Eggelhof Inc is a Houston-based company established in 1926, specializing in engineering products such as filtration and water treatment, piping and plant equipment, and steam specialties.We are ready to upload 67gb of corporate data. Projects, employeeinformation (DOB, phones, addresses and so on), agreements and contracts, financials, client information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LA-Injury-Attorneys</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27621</link>
<guid>e62e4e249110f293347233352a4edf81</guid>
<pubDate>Wed, 03 Dec 2025 14:25:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LA-Injury-Attorneys</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>892320df3756e7959943b139ccdc713283295d02d5a6a7e970d3348f9488273e</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Urbana</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27623</link>
<guid>5abad9111ffcd62ba77847ae11e1ae65</guid>
<pubDate>Wed, 03 Dec 2025 14:25:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Urbana</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b670cad8a7c0300ec9601d253b5bcdd758050586d35a5b1f8108f38ad848731</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rouse-Frets-White-Goss-Gentile-Rhodes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27625</link>
<guid>4bc8e183d66e91b1282955588fe864eb</guid>
<pubDate>Wed, 03 Dec 2025 14:25:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rouse-Frets-White-Goss-Gentile-Rhodes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b999301db938e2799b526614a9a735775f9e333e605aa8a75ebf2140d5ab8a58</i><br /><br />Threat actor <b>description</b>: <i>On September 30, 2018, the law firms of Rouse Frets Gentile Rhodes, LLC and White Goss, P.C. merged and became Rouse Frets White Goss Gentile Rhodes, P.C.We are ready to upload 87gb of corporate documents such as: detailed personal information clients and employees (SSNs, passports, driver licenses, addresses, phones, emails and so on), lots of confidential legal documents, court hearings, police reports, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wynn--Wynn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27626</link>
<guid>ffb430ebdabce62d4d56f4e13cb50fa4</guid>
<pubDate>Wed, 03 Dec 2025 14:25:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wynn--Wynn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71ff45cf85096a63efa9b668a73b284036a7cb51570ae5a126dbafda73e8f73d</i><br /><br />Threat actor <b>description</b>: <i>Wynn Wynn, P.C. is a general practice law firm based in Southeastern Massachusetts, offering a wide array of legal services including personal injury, family law, business litigation, criminal law, and real estate among others.We are ready to upload 12gb of corporate data. Another one law firm that doesn't case of their clients' personal information. You can find detailed clients' personal information (SSNs, passports,driver licenses, addresses, phones, emails and so on), court cases files, court hearings, police reports, incident reports, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bo-Beuckman-Ford</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27644</link>
<guid>0fa66dc7ac7cc66a4c72f28e7742f27f</guid>
<pubDate>Wed, 03 Dec 2025 13:53:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Bo-Beuckman-Ford</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>256d9bcdb1843a9ec41ccd4e855e0ab0c1f8e60eb0e2b81e628b913eda6fde96</i><br /><br />Threat actor <b>description</b>: <i>Bo Beuckman Ford</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-Generation-Logistics...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27629</link>
<guid>76cb696d89f827c907d66d9388d96553</guid>
<pubDate>Wed, 03 Dec 2025 11:09:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-Generation-Logistics...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4355f490a80c234399a459300ddf2d6885552c9c28c065ad517d1696c4797e2a</i><br /><br />Threat actor <b>description</b>: <i>Here is the access to 17gb of the following companies:

Wisconsin Knife Works is a leader in tooling and precis
ion manufacturing of woodworking cutting tools, backed 
by over 90 years of experience.

Smith Companies, Ltd. is a Boston-based firm specializi
ng in unbiased and sophisticated advanced planning solu
tions that effectively incorporate life insurance into 
clients' overall financial strategies.

EnviroTech Services, Inc. specializes in developing sup
erior road and surface solutions to manage all environm
ents; both natural and man-made.

Next Generation Logistics, Inc. specializes in advanced
transportation management solutions and services, leve
raging over 35 years of expertise in the logistics indu
stry.

Security First Bank is dedicated to providing comprehen
sive banking services that prioritize customer satisfac
tion.

You will find personal employee personal data, client i
nformation, numerous project files, accounting and fina
ncials and other internal operational files.
Open uTorrent, or any another torrent client.
Add torrent file or paste the magnet URL to upload the 
data safely.
Archives have no password.

MAGNET URL:
magnet:?xt=urn:btih:F470CF902BF67478830753A753DB48D6081
B9ACF&dn=Data 4&tr=udp://tracker.openbittorrent.com:80/
announce&tr=udp://tracker.opentrackr.org:1337/announce
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>lesker.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27616</link>
<guid>2b5102c218cb2e3df76c2a0d94244c73</guid>
<pubDate>Tue, 02 Dec 2025 20:51:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>lesker.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c601c599cce338c56022b93ca8dbe85cc8562f889b007ee920f6b22c802f4c5</i><br /><br />Threat actor <b>description</b>: <i>Since it's foundation in 1954, Kurt J. Lesker Company has manufactured and sold vacuum equipment and parts to the electronic and communications related industries</i><br />Target victim <b>website</b>: <i>www.lesker.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pathmaker-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27611</link>
<guid>9890b5738941827eb39657583b4249fc</guid>
<pubDate>Tue, 02 Dec 2025 20:19:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pathmaker-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff8df2e3b3c6b95791fe181e39adb5b1c0f2f3a4ea298b0ca69acdb6664f53a4</i><br /><br />Threat actor <b>description</b>: <i>PathMaker Group is a specialized consulting firm focused on Identity and Access Management solutions for businesses. They provide a full range of services, including planning, implementation, and management of identity management systems, access management, and privileged account management. The company serves a diverse clientele, emphasizing customer satisfaction and effective problem-solving. Established in 2003, PathMaker Group aims to build long-lasting partnerships with clients by combining technical expertise with consultative support.</i><br />Target victim <b>website</b>: <i>www.pathmakergroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mr-Christmas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27606</link>
<guid>f76adfc16cac13526a0d9d97e1401257</guid>
<pubDate>Tue, 02 Dec 2025 19:27:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mr-Christmas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc3fcf0b76e3d78148a94a38323ef0fb2f3537d591b4dcfd64a8c64260dfe18f</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moyes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27607</link>
<guid>13d429db192fbc7b5cabf9b936cf78e1</guid>
<pubDate>Tue, 02 Dec 2025 19:27:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Moyes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac461abd0c7327612e2f197d828ec346de7497829bea5f93d2760e7ee540ded1</i><br /><br />Threat actor <b>description</b>: <i>Finance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petra</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27614</link>
<guid>8b02ed5a86a1a326b7862bbba5eb74a7</guid>
<pubDate>Tue, 02 Dec 2025 19:23:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Petra</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69063915ad8d232a6f3e2ced97e146a441d790599573f9b212e656e72cfc44f4</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Petra is a multinational corporation that specializes in the manufacturing and distribution of consumer electronics and small appliances. They are based in Edmond, Oklahoma. This company works as a bridge between the manufacturers and retailers, providing thousands of high-quality products to retail stores nationwide. Petra Industries offers a variety of services from warehousing and distribution to logistics and supply chain solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reading-Elevator-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27613</link>
<guid>fdbeb638e95f0bb8868a6e7c1969a713</guid>
<pubDate>Tue, 02 Dec 2025 19:14:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Reading-Elevator-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c709a9faf3425b599d12379d6231584962b92ecace0b4907b7140826fe99dcf5</i><br /><br />Threat actor <b>description</b>: <i>Reading Elevator Service (RES) is a reputable elevator company established in 1969, specializing in the installation, maintenance, and modernization of non-proprietary elevator systems. The company is dedicated to delivering excellent customer service, ensuring safety and efficient traffic flow in both residential and commercial properties across Eastern Pennsylvania. RES is fully bonded and insured, with affiliations including IUEC, NAEC, NFIB, and the Chamber of Commerce. They provide a range of services aimed at meeting the unique needs of their clients while allowing flexibility in choosing service providers.</i><br />Target victim <b>website</b>: <i>www.readingelevatorservice.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>noment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27608</link>
<guid>414cb71ec2809a5fda79a2463125ddee</guid>
<pubDate>Tue, 02 Dec 2025 18:28:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>noment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f96f5a45b0b5f4135f30516b43db02385888311781afede019ef597f37428b16</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garrett-Taylor-Dds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27610</link>
<guid>8235568e92bbf73e71db3234723c8b51</guid>
<pubDate>Tue, 02 Dec 2025 18:24:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Garrett-Taylor-Dds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb58e462de80390f4223a30e605e289b1d18d8e5891513aeb886150d50f81c19</i><br /><br />Threat actor <b>description</b>: <i>Taylor & Carter Family Dentistry, located in Pine Bluff, AR, provides personalized dental care to patients of all ages. The practice, led by Dr. Garrett Taylor, Dr. Hannah Carter, and Dr. Rontae Graham, offers a range of services including general, cosmetic, and restorative dentistry. They emphasize advanced techniques and patient-centered care, ensuring a comfortable dental experience. Committed to community outreach, the team participates in various service projects both locally and internationally.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Toledo-Transducers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27596</link>
<guid>04d81fced5c98dd0927231751561d1fe</guid>
<pubDate>Tue, 02 Dec 2025 17:27:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Toledo-Transducers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48d2d655e05b5c109586c4c782c7dbd5d012523f316db4e5ccfb35c5feb31ac0</i><br /><br />Threat actor <b>description</b>: <i>Toledo Integrated Systems specializes in designing and manufacturing press control solutions, tonnage monitors, and load cells. Their product offerings include press controls, material handling control solutions, tonnage monitors, and various calibration services.We are ready to upload corporate documents such as: personal information of all employees (passports, driver licenses, medical tests, and other confidential personal files), detailed customer information (including personal documents), numerous confidential files, contracts and agreements, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prismier</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27597</link>
<guid>34ac42f166aab43ce18d720c21903cda</guid>
<pubDate>Tue, 02 Dec 2025 17:27:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Prismier</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fbe4e8040b86ad279193841bd9470e482df324ec4ba470c0cf61e4d03c79d3a3</i><br /><br />Threat actor <b>description</b>: <i>Prismier is a leading vertically-integrated Mechanical Contract Manufacturer (MCM). Service offerings include Design & Engineering, Rapid Prototype thru Production of Sheet Metal Fabrication & Stamping, Plastic Injection Molding, CNC Machining, Die Casting, and Assembly.We are ready to upload 42gb of corporate documents such as: detailed personal information of employees (passports, driver licenses, addresses, phones, emails and so on), customer information, projects, contracts and agreements, numerous NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>dakkota.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27609</link>
<guid>0dbcc22a131326b8056b0c26d845dda3</guid>
<pubDate>Tue, 02 Dec 2025 17:09:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>dakkota.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>653f294557e6d071a9097114f106e6f0a76863adc28150d5ec139f6eeca35379</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2001, Dakkota Integrated Systems is a manufacturing company that provides a variety of build-to-order manufacturing processes including cockpit, overhead, and fascia systems and more.</i><br />Target victim <b>website</b>: <i>dakkota.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Exegy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27603</link>
<guid>c657bb88929c8410c8b3dfb3d7a568e0</guid>
<pubDate>Tue, 02 Dec 2025 16:23:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Exegy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>494acb23f9ccc43ef3d59a8ae916030464109ebeb6ae5ae15b4c7175627886e1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Exegy, Inc. is a technology firm providing managed services and real-time market data solutions. The company delivers hardware-accelerated appliances, cloud-based services, and historical market data for applications in trading, risk management, and market surveillance. Exegy serves firms globally in the financial services sector, including traders, market makers, and brokers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ziglin-Signs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27590</link>
<guid>67ec9e8decb48e53b1dd1f6514ff7a5b</guid>
<pubDate>Tue, 02 Dec 2025 15:26:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ziglin-Signs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d948f8f56778d642947aaa519b1f7d133d8f72d25e0fd19427fca763a50c0db9</i><br /><br />Threat actor <b>description</b>: <i>Ziglin Signs Inc operates as a full-service custom signage provider delivering comprehensive visual communication solutions to businesses throughout the Midwest. The company specializes in designing and fabricating signage that establishes strong brand presence and professional identity for organizations ranging from independent local enterprises to multi-location franchise operations.We are ready to upload corporate documents such as: detailed employee information (passports, driver licenses, SSNs, addresses, phones, emails, medical information, credit cards details and os on), a bit of client information, contracts and agreements, confidentiality agreements, projects and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.precipiodx.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27600</link>
<guid>680a372679da6b97e589c2cf672d5aea</guid>
<pubDate>Tue, 02 Dec 2025 13:53:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.precipiodx.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b4855ce78b466e5c3cff098b903503abafb7b0a142a398627b8f9f1aace25e4c</i><br /><br />Threat actor <b>description</b>: <i>150gb</i><br />Target victim <b>website</b>: <i>www.precipiodx.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tlusty--Kennedy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27588</link>
<guid>a250c65c14391dd15c000484a2f49801</guid>
<pubDate>Tue, 02 Dec 2025 13:26:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tlusty--Kennedy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f234471e9575fa14328262cacf80b1ba747bf27a6f7360d1c9ca158126b4f56b</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mobilelink-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27585</link>
<guid>1833ac47b85928f3b36d2676ca9df03a</guid>
<pubDate>Tue, 02 Dec 2025 12:27:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Mobilelink-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a8d7fb699d8f16a7ae06cd5918cf50af946bc3444cc4e9d0f0e4415756d35ef</i><br /><br />Threat actor <b>description</b>: <i>Mobilelink USA is a private Cricket Wireless company that deals in providing unlimited 5G LTE services and state of the art devices with an understanding of wh...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capital-Star-Oil--Gas-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27586</link>
<guid>597626eebeefc042afb36a69a049696d</guid>
<pubDate>Tue, 02 Dec 2025 12:27:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Capital-Star-Oil--Gas-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c093051554071571fc9f60aeb9c3d9ea60c9a8db76205987eee3f5d94d70e27b</i><br /><br />Threat actor <b>description</b>: <i>Capital Star Oil & Gas, Inc. is a small independent oil & gas company based in Houston, Texas. Most of drilling activities are financed through private placemen...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Pools--Spas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27589</link>
<guid>ddccf393356f010bc68c23d9bc76e917</guid>
<pubDate>Tue, 02 Dec 2025 11:20:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>American-Pools--Spas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1bef02c8b7bf9166b0764f76a490426d7932af7371f64d3e8050a4114ed44903</i><br /><br />Threat actor <b>description</b>: <i>American Pools Spas is a premier pool builder based in Orlando, FL, offering a wide range of services including pool construction, renovation, and repair.  We have 500GB of data at our disposal (fiscal data, internal mail,budgets and many other things)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cleveland-County-Sheriffs-Office</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27587</link>
<guid>2c7dcef4ea90b05c642db06b3c128dfc</guid>
<pubDate>Tue, 02 Dec 2025 09:02:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Cleveland-County-Sheriffs-Office</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b4bb285ee19360a75617398b9b3d80452cbad157716f49e6b008d06265150aa</i><br /><br />Threat actor <b>description</b>: <i>Cleveland County Sheriff's Office</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>University-Loft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27582</link>
<guid>3a0cc05957ec30e262540e57b8a413ae</guid>
<pubDate>Mon, 01 Dec 2025 20:08:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>University-Loft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd2deeb45c98247c2aa00a683edca333f0cc7594235ac57468b2e6208941d149</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.uloft.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Island-Public-Service-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27580</link>
<guid>09963a393c5a37a7fda7a40e4ab52972</guid>
<pubDate>Mon, 01 Dec 2025 20:07:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>South-Island-Public-Service-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c26fae3849b35172e655532592042abac04da2d81ce8708a1cdede14a0261ce7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sipsd.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Virtualware-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27552</link>
<guid>2af9b1a840b4ecd522fe1cda88c8385e</guid>
<pubDate>Mon, 01 Dec 2025 18:26:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Virtualware-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2abb8685e200a575cd2b6d22aebfc0d56cf9438bc773c6a9525ec8a0515b3fb</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-GenerationLogistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27553</link>
<guid>2ff4529fe221eba7d79ce74b59d91e60</guid>
<pubDate>Mon, 01 Dec 2025 18:26:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-GenerationLogistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a30e8fe6a2ed63c73595d46249865d02ab8864b565440470d2cfcb87d761326</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 17gb of the following companies:Wisconsin Knife Works is a leader in tooling and precision manufacturing of woodworking cutting tools, backed by over 90 years of experience. Smith Companies, Ltd. is a Boston-based firm specializing in unbiased and sophisticated advanced planning solutions that effectively incorporate life insurance into clients' overall financial strategies.EnviroTech Services, Inc. specializes in developing superior roadand surface solutions to manage all environments; both natural and man-made.Next Generation Logistics, Inc. specializes in advanced transportation management solutions and services, leveraging over 35 yearsof expertise in the logistics industry. Security First Bank is dedicated to providing comprehensive banking services that prioritize customer satisfaction.You will find personal employee personal data, client information, numerous project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Industrial-Steam</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27561</link>
<guid>d35a992032a0224adc8231a4ff1c8330</guid>
<pubDate>Mon, 01 Dec 2025 18:15:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Industrial-Steam</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c7427cb61d125831a709530ca9c2a11528f02ec698d0d5400389e6be4c1c64a</i><br /><br />Threat actor <b>description</b>: <i>Industrial Steam is a leading manufacturer specializing in pressurized and atmospheric deaerators, providing innovative solutions for the boiler industry since 1952. Their product line includes various types of deaerators, blowdown systems, condensate recovery units, and advanced feedwater systems. With a commitment to unmatched performance and customer satisfaction, they offer unique designs such as dual compartment systems along with established technologies.</i><br />Target victim <b>website</b>: <i>www.industrialsteam.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clark--Sullivan-Constructors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27579</link>
<guid>1ceeb04b184ee1c9424f81c8a96fd686</guid>
<pubDate>Mon, 01 Dec 2025 18:12:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Clark--Sullivan-Constructors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9aed73447e0678118aedae045e41c041416dc2dfcac492ee338551373c01ba11</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.clarksullivan.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hall-Aluminum-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27578</link>
<guid>66ad4c25533779bfe270868c28b48b8d</guid>
<pubDate>Mon, 01 Dec 2025 18:11:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Hall-Aluminum-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e31e5b655c286adb5c076633c76cade65bd92ede11435044f0fd7af5c96f123</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hallaluminum.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>millerwoodtradepub.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27558</link>
<guid>fcec608f0259e123aa4c88a4a51abc50</guid>
<pubDate>Mon, 01 Dec 2025 16:55:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>millerwoodtradepub.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c37a9d86feff7c84b53a97acf2f7655d7859b9424de1342ca23d7641dd93cabf</i><br /><br />Threat actor <b>description</b>: <i>Established in 1927, Miller Wood Trade Publications is a leading source of information for the forest products industry, publishing 10 specialized magazines and resources. Their offerings include various marketing directories and handbooks tailored to the lumber market. The company's publications serve both domestic and international clients, connecting suppliers with buyers across the globe. With a focus on the lumber trade, they cater to all segments of this billion-dollar industry</i><br />Target victim <b>website</b>: <i>millerwoodtradepub.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-GenerationLogistics...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27562</link>
<guid>5ffdc65e9d413e3acd7b8ba5d03477a1</guid>
<pubDate>Mon, 01 Dec 2025 16:48:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wisconsin-Knife-Works-The-Smith-Companies-Envirotech-Services-Next-GenerationLogistics...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e44278b3bdc036bc5f3b64f157da39ea988405fa865445ccab1e06be00f3ffa</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 17gb of the following companies:

Wisconsin Knife Works is a leader in tooling and precision manufa
cturing of woodworking cutting tools, backed by over 90 years of 
experience. 

Smith Companies, Ltd. is a Boston-based firm specializing in unbi
ased and sophisticated advanced planning solutions that effective
ly incorporate life insurance into clients' overall financial str
ategies.

EnviroTech Services, Inc. specializes in developing superior road
and surface solutions to manage all environments; both natural a
nd man-made.

Next Generation Logistics, Inc. specializes in advanced transport
ation management solutions and services, leveraging over 35 years
of expertise in the logistics industry. 

Security First Bank is dedicated to providing comprehensive banki
ng services that prioritize customer satisfaction.

You will find personal employee personal data, client information
, numerous project files, accounting and financials and other int
ernal operational files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cleveland-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27549</link>
<guid>8d5ef74b92de0025e0a30d21d4714152</guid>
<pubDate>Mon, 01 Dec 2025 16:26:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cleveland-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff4420c7f91e733d6bf44b6a51c20cd5612fb849106727f913294864439a38fc</i><br /><br />Threat actor <b>description</b>: <i>Cleveland Construction is a family-owned commercial contractor specializing in construction management and self-performing interior trades.We are ready to upload 12GB of corporate documents such as: very detailed employee information (about 1500 SSNs, passports, addresses, phones, emails, driver licenses and so on), contracts and agreements, projects and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Martin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27550</link>
<guid>b61726a0869331a6dec8049de8f10fc9</guid>
<pubDate>Mon, 01 Dec 2025 16:26:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Martin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>095cee9ea7164de76754a79b33bbd72299f6800c6c6e91ea5396d01fdc167bb3</i><br /><br />Threat actor <b>description</b>: <i>Martin & Company is a leader in tech-enabled insurance solutions,providing a comprehensive suite of services designed for insurance carriers and managing general agents (MGAs).We are ready to upload 46GB of corporate documents such as: employee information (passport, driver licenses and os on), client information, contracts and agreements, confidential files, projects and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abhe--Svoboda</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27545</link>
<guid>fe103355d7f731a557951558ba906d39</guid>
<pubDate>Mon, 01 Dec 2025 14:26:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Abhe--Svoboda</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>593a4cbf7f279df4726d84af41ec21aa519b16bf4a7a438323454f95919d069f</i><br /><br />Threat actor <b>description</b>: <i>Abhe & Svoboda, Inc. is a full-service restoration contractor. Inaddition to offering a full range of industrial coatings services, our core competencies also include a variety of related construction services, such as concrete repair, and steel repair and replacement.We are ready to upload 82GB of corporate documents such as: Detailed personal employee information (passports, DLs, SSNs, addresses, emails, phones, medical information, credit cards), client information, projects, agreements and contracts, other internal documents.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Goldenrod</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27546</link>
<guid>ea0efe8ecbc569d1e8349f2625cb6af8</guid>
<pubDate>Mon, 01 Dec 2025 14:26:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Goldenrod</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>344b6fdd243ea695781c42364ed816cb399136eae87cc07a2fd8fc4acc1eed04</i><br /><br />Threat actor <b>description</b>: <i>Goldenrod has been designing and manufacturing industry-leading differential winding shafts, multiple bladder air shafts, lightweight aluminum and carbon fiber shafts, reel spools, chucks, and safety chucks for processors in the North American paper, film, foil, and non-woven converting industries.We are ready to upload 12GB of corporate documents such as: financial files, payment details, invoices and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Innomotive-SolutionsGroup</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27547</link>
<guid>b91f9ae1efafed4d85107226536195f3</guid>
<pubDate>Mon, 01 Dec 2025 13:26:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Innomotive-SolutionsGroup</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b2aaeffb3894be6c2f8c618c5d9ae8864d20ed7c4cb0b033d284b30be87b860</i><br /><br />Threat actor <b>description</b>: <i>Innomotive Solutions Group is a North American leader specializing in high-quality roll-up doors, LED lighting, and power lifting systems for trucks and specialty vehicles.We are ready to upload 10GB of corporate documents such as: Personal employee information (passport, phones, emails and so on), financials, client data, projects, agreements and contracts, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MD-Manouel-InsuranceAgency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27548</link>
<guid>1f0676fd3f275d08290dec8157496a08</guid>
<pubDate>Mon, 01 Dec 2025 13:26:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MD-Manouel-InsuranceAgency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>34bb09e02eb701b2124484eba200bab3859fdd4655b333c99d2c720a372eb87e</i><br /><br />Threat actor <b>description</b>: <i>S&R Insurance Services Inc. is a reputable insurance agency located in Rancho Cucamonga, California, specializing in a wide range of insurance products such as auto, home, commercial, life, umbrella, and health insurance.We are ready to upload more than 30GB of corporate documents suchas: Personal employee information, client data, projects, agreements and contracts, other internal documents.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rose-Displays</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27564</link>
<guid>c422e39e579b0c8896e9d9fc9a2ca8ac</guid>
<pubDate>Mon, 01 Dec 2025 08:53:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Rose-Displays</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74befd388e558c664f6c986f53cf9755dea34b6059713ddc2b245eabc59fad0a</i><br /><br />Threat actor <b>description</b>: <i>A division of Visual Creations Ink</i><br />Target victim <b>website</b>: <i>rosedisplays.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petro-Environmental.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27565</link>
<guid>c73b2ece3c47d44d3579a75ece205595</guid>
<pubDate>Mon, 01 Dec 2025 08:52:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Petro-Environmental.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c54ca8ed851b2d4c0c49173bf22185df557b15e03b758eb25a75ca8bb2dbf2e</i><br /><br />Threat actor <b>description</b>: <i>A company that offers a range of environmental services</i><br />Target victim <b>website</b>: <i>petroenviro.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Data-Enterprises-of-the-Northwest.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27566</link>
<guid>234d9cdb375d458cf93fb427a55da75f</guid>
<pubDate>Mon, 01 Dec 2025 08:51:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Data-Enterprises-of-the-Northwest.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa73f8eb3a4dbd3a98ecae31a1d4330e66ca99fa73f87a753231f6dda37edf59</i><br /><br />Threat actor <b>description</b>: <i>A company that offers the Automated Tool Inventory Control and Tracking System (ATICTS)</i><br />Target victim <b>website</b>: <i>aticts.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Curtis-Investment-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27568</link>
<guid>d24110aad582c07b5b3c8a978dd167c6</guid>
<pubDate>Mon, 01 Dec 2025 08:49:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Curtis-Investment-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f6bc0196c4823590bc194f945dc76fe4e2db54be387e765516c3924e3d8070a</i><br /><br />Threat actor <b>description</b>: <i>A full service real estate concern</i><br />Target victim <b>website</b>: <i>curtisinvestments.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>newhorizonsmedical.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27557</link>
<guid>a8c10ea52e3b84e7a2948f25a13f2768</guid>
<pubDate>Mon, 01 Dec 2025 08:45:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>newhorizonsmedical.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>402bc816060a5e21c2c7196c037559addeef242ff61eee014025093f4249f489</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 90k
236gb</i><br />Target victim <b>website</b>: <i>newhorizonsmedical.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.eastersealsnei.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27573</link>
<guid>e624d754286d0aac962f185f1a21809e</guid>
<pubDate>Mon, 01 Dec 2025 08:45:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>www.eastersealsnei.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19ab1bd2c0f0f3557296f5a8f5f872d2daa1ba7f50af2865e99a7378e252352f</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 550k
280gb</i><br />Target victim <b>website</b>: <i>www.eastersealsnei.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Soderstrom-Architects-LTD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27559</link>
<guid>00b546d495d29ea025af220831ceee42</guid>
<pubDate>Mon, 01 Dec 2025 07:37:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Soderstrom-Architects-LTD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c115bc0287de85345d5cfe3d4e03ff8a3312d6e363529e0cbbf38e68d12d645</i><br /><br />Threat actor <b>description</b>: <i>Soderstrom Architects is a Pacific Northwest architecture firm that offers creative yet practical solutions for spaces that inspire individuals and communities. They were founded in 1984 and operate out of Portland, Oregon</i><br />Target victim <b>website</b>: <i>www.sdra.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fun-For-Less-Tours</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27544</link>
<guid>dd159c05a369b53f45e46d799740331f</guid>
<pubDate>Mon, 01 Dec 2025 00:45:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Fun-For-Less-Tours</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b40e07eeeb56075c29a35cf24f02a8947ecf006ad911a72f3945e84524e4ff6</i><br /><br />Threat actor <b>description</b>: <i>Customer passports and personal data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Concord-Academy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27543</link>
<guid>50e9ea9c1bc5e6067ab7c0d8fbdd5f21</guid>
<pubDate>Sun, 30 Nov 2025 17:57:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Concord-Academy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b4389f91ff2d79f1084a48190104b74227061068258655292b9f9590e486058</i><br /><br />Threat actor <b>description</b>: <i>Concord Academy is a specialized educational institution that serves students with Autism, learning and intellectual disabilities, language processing disorders, ADD/ADHD, and other neurodiverse learning needs. The academy provides a unique learning community focused on respect and acceptance, operating within a small, structured, and secure environment. Their mission is to prepare these students for lifelong success, offering tailored educational programs and support. A significant percentage of graduates advance to post-secondary placements, reflecting the effectiveness of their individualized approach.
company is headquartered in 4942 Walnut Grove Road, Memphis, TN 38117, USA.
11-50 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Veton-Ai</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27541</link>
<guid>fbfe2df616b6864090539113663415f3</guid>
<pubDate>Sun, 30 Nov 2025 16:25:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Veton-Ai</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>591a35a1f24f35db998ebf2ea64506e8b8fc623c18e8136138445f1e14c1557e</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Division-10</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27540</link>
<guid>f10424d2b1cbf840765291e98f4ea293</guid>
<pubDate>Sun, 30 Nov 2025 06:44:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Division-10</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77f9327fb1434cd21e04d1374914283f4e26510d54dd2d9349c9c436cf060e98</i><br /><br />Threat actor <b>description</b>: <i>Division 10 Inc is a company based in Memphis, Tennessee, specializing in supplying specialty products to the construction industry since 1989. They offer services including product sales, estimating services, and installation quotes. Their clients range from contractors to automotive companies, evidenced by testimonials highlighting their successful project contributions. The company prides itself on its commitment to quality and customer satisfaction</i><br />Target victim <b>website</b>: <i>division10inc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>TBC-Consoles</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27524</link>
<guid>c101eebb637fa965d366c92c41a3751a</guid>
<pubDate>Sat, 29 Nov 2025 20:25:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TBC-Consoles</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2979cc2b38c16a07fea10fa9989e607d07fb828696632c95ad4636669b4706a</i><br /><br />Threat actor <b>description</b>: <i>Furniture</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CJW</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27525</link>
<guid>1a0f53650db79adca6f29470587a3d39</guid>
<pubDate>Sat, 29 Nov 2025 20:25:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CJW</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c6765cb1b5bbd274f1b7585d0323c8eee0040b23728816e19481730c82636a4</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chenango-Valley-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27526</link>
<guid>93b5129e24b9c92e5b8e7115056b46bd</guid>
<pubDate>Sat, 29 Nov 2025 20:25:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Chenango-Valley-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aaef7f9557fe3e42a5ed2f52950700726f16173c3b28bca812d33e0680d71bd9</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Asia-Condominium-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27527</link>
<guid>20ba096f2d3da322ed843f6a4bee9a91</guid>
<pubDate>Sat, 29 Nov 2025 19:25:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Asia-Condominium-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67d7abcf4d267e9cbece529a5f199206476d004bb59c93cd0af71e61df9e518f</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advantage-360</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27536</link>
<guid>84f3ad98554f4c77f309c271fb93e1e7</guid>
<pubDate>Sat, 29 Nov 2025 15:41:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>Advantage-360</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5caf2800c1dac7bf2521f866021c3e354aa7e0bb628628c4968840cd07ba5fd</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Advantage 360 is a software company that provides integrated customer relationship management, billing, and automation solutions. Their services are focused primarily towards telecommunications, digital service providers, and broadband providers worldwide. They offer scalable solutions which incorporate billing, customer care, fraud management, and revenue assurance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>iqs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27533</link>
<guid>51a4481447f563d89973aadd7e6cb95b</guid>
<pubDate>Sat, 29 Nov 2025 15:41:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>iqs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8018bda44e2caef137e50760ca9536fc4b0db6a4f6216fb1d0da989dfda7f8f4</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>LMG-Holdings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27534</link>
<guid>779146e5712cfe402503e06a5184bd69</guid>
<pubDate>Sat, 29 Nov 2025 15:41:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>tridentlocker</b> claims attack for <b>LMG-Holdings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a53185b8f440f439353ba41bddb8bba2a23d8715d1389a869ac849fa29120769</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] LMG Holdings, Inc. is a leading provider of ignition interlock devices. Based in Raleigh, North Carolina, the company’s main mission is to provide products that continuously monitor breath alcohol and prevent operation of the vehicle when the driver’s levels are above specified limits. They aim to make the roads safer by preventing drunk driving.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>tridentlocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>vviewisd.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27520</link>
<guid>06cfd38cb4f1b2227cc7f5b8aada2c96</guid>
<pubDate>Fri, 28 Nov 2025 22:56:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>vviewisd.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9a17161e652c41cea99318d391776a498620781d4df4992a2d22d75b2996ec2</i><br /><br />Threat actor <b>description</b>: <i>Valley View ISD was one of only fifteen districts in the entire state of Texas to receive this rating. We are extremely proud of our students and staff for this great accomplishment. This would not be possible without the collaboration of all our stakeholders. It is no secret that when schools, families, and communities support each other and come together, students achieve at the highest levels. On behalf of our Board of Trustees and staff, thank you for your continued support and commitment to our students. Employees: 800 Revenue: $27.8 Million Industry: Education   Phone Number: (416) 783-6181</i><br />Target victim <b>website</b>: <i>vviewisd.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Williamson-County-TX</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27519</link>
<guid>914504d6a7f15be15048fdb72ddd71a7</guid>
<pubDate>Fri, 28 Nov 2025 21:24:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Williamson-County-TX</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>265facd3ea683e7ceb450fadaa9527ebc4569225db9546663402fe4dc066f4bf</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zoya</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27516</link>
<guid>af5a968312f8d1e3246a966fac1606da</guid>
<pubDate>Fri, 28 Nov 2025 19:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Zoya</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0b0972d31a1ad069b524f210a85534682ba2f81989ef4b02727f25f4ff3be25</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weiss</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27517</link>
<guid>a256147c9ed7998d36a10038d1eaa7ea</guid>
<pubDate>Fri, 28 Nov 2025 19:24:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Weiss</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5a6c583f8bb86b6fec9cf7df2a54027bc3e314edfbeed3bf3e8f47ed050f1c7</i><br /><br />Threat actor <b>description</b>: <i>Accounting Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kleber-and-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27518</link>
<guid>f7e3b9df4fd0b3183fc4f380480c7788</guid>
<pubDate>Fri, 28 Nov 2025 19:24:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kleber-and-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0859a8187b52428290c2438ff596ab4e70f2395f08c3ae4706b8882e5371fdf</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lone-Rock-Timber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27507</link>
<guid>666108a9094a0ec0f62ca61a2eb74538</guid>
<pubDate>Fri, 28 Nov 2025 17:24:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Lone-Rock-Timber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf8746238b9f54776e96472384b5232ddf6bcd867dbacc421b2ea59f3c0f57f6</i><br /><br />Threat actor <b>description</b>: <i>Lone Rock is a timber company.We are ready to upload 25GB files of corporate documents such as:personal employee data, financials, agreements and contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morton-LTC-Reed-Pope-Law-American-Public-Television-Benchmark-Connector-Radtke-Contrac</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27508</link>
<guid>839e35ed92c4f5619e8579159f70c437</guid>
<pubDate>Fri, 28 Nov 2025 17:24:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Morton-LTC-Reed-Pope-Law-American-Public-Television-Benchmark-Connector-Radtke-Contrac</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd68b7f1485610f7391cc83fec2d4239e3d0abf09b82c2f0b08cf0340adbbda2</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 22gb of the following companies: Morton LTC Home specializes in providing pharmacy solutions tailored for long term care providers.Reed Pope is a leading business law firm based in Victoria, British Columbia, specializing in business law, land development, and real estate law.American Public Television (APT) is a distributor of public television programming that has introduced iconic shows and personalities such as Julia Child and Fred Rogers.LBenchmark Connector Corporation specializes in providing high-quality connectors for various industries, including military and aerospace applications.Radtke Contractors specializes in pile driving, marine and excavating contracting, their varied experience in snow removal, bridge, and railroad construction allows us to complete a wide range ofprojects in commercial, municipal and residential construction markets.You will find personal employees and customer information, lots of projects, agreements and contracts and other sensitive files. Some cases contain legal confidential files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Casting-House</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27509</link>
<guid>d61f11e5bda1c631302b96f8e65a6c3b</guid>
<pubDate>Fri, 28 Nov 2025 17:24:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Casting-House</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a7d9713f28964bc53834cb80b8d16d8eca0886ec6c9012e90b40a042ce614d9</i><br /><br />Threat actor <b>description</b>: <i>Casting House is a full-service custom jewelry manufacturing company that provides jewelers and designers with access to manufacturing solutions that will help grow their inventory.We are ready to upload 10GB files of corporate documents such as:personal employee data, financials, agreements and contracts, confidential files, credit card details, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Parrish-Tire</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27510</link>
<guid>4ecbb790f241666326d31f799eb85d1e</guid>
<pubDate>Fri, 28 Nov 2025 17:24:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Parrish-Tire</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b1b545324d3a8e7af6493b2d4ea177ba7e9c458546079134f59b328a1663246</i><br /><br />Threat actor <b>description</b>: <i>Parrish Tire Company is one of the largest tire dealers in the Southeast, operating wholesale, retail, and commercial truck tire centers in NC, SC, VA, GA, and OH.We are ready to upload 10GB files of corporate documents such as:personal employee data, client data (~150 credit cards details, and other information), financials, agreements and contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Panini-Kabob-Grill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27511</link>
<guid>b5daaa1a65fab780763c6dc7df93d38b</guid>
<pubDate>Fri, 28 Nov 2025 17:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Panini-Kabob-Grill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fc0e4d152ebe1ff4e951b08a9a1ecaabed1a13051388434ea2e25d531d7cfc4</i><br /><br />Threat actor <b>description</b>: <i>Panini Kabob Grill specializes in preparing fresh and healthier Mediterranean food using high-quality ingredients in a scratch kitchen.We are ready to upload 60GB files of corporate documents such as:detailed personal employee information (SSN, DLs, passport, photo, phone, emails and so on), credit cards, detailed financials, agreements and contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Family-Farm-and-Home</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27503</link>
<guid>63c94b74065fc62f96c334f08c534843</guid>
<pubDate>Fri, 28 Nov 2025 14:25:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Family-Farm-and-Home</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5cd3f365ea20993aa9a7be3b8a30ed8c021c6130b307658e94453f26d3eda04c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gershow-Recycling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27504</link>
<guid>76819f255a4d6d1d4d956492094489ea</guid>
<pubDate>Fri, 28 Nov 2025 14:25:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gershow-Recycling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dcd4bbfa21b6a9fedcfb473c024ee23991ac07993f007967add1f7d204bf23b</i><br /><br />Threat actor <b>description</b>: <i>Gershow Recycling is a prominent scrap metal buying and selling facility located in various regions including Suffolk County, Nassau County, and Brooklyn.We are ready to upload 31GB files of essential corporate documents such as: Employee information (DLs and other scanned documents), internal confidential files, detailed financials, clients information, interesting agreements details with organizations, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Design-Team-Sign-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27505</link>
<guid>d2d26584b4ffbf0de1af4a7e9ecf3b68</guid>
<pubDate>Fri, 28 Nov 2025 14:25:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Design-Team-Sign-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c2ce665907d449befb0d1bfcdd34bc1570079f224b10202b33ee60e8f8f2747</i><br /><br />Threat actor <b>description</b>: <i>Design Team Sign Company is a manufacturer of custom graphic signmedia.We are ready to upload 108GB files of essential corporate documents such as: HR files, personal data, detailed financials, databases, projects, agreements, customer information, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>K2d</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27506</link>
<guid>68090119a695209306eefe7f69ebf574</guid>
<pubDate>Fri, 28 Nov 2025 14:24:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>K2d</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>72a4205e156d5e2b22dc0f31343941e5583efd71b6be491f5d1652d7b96e97f4</i><br /><br />Threat actor <b>description</b>: <i>K2D Consulting Engineers is a professional Mechanical, Electrical, and Plumbing (MEP) consulting firm based in Los Angeles, recognized for its innovative and collaborative design approaches.We are ready to upload 121GB files of essential corporate documents such as: personal employee data, detailed financials, agreements, client information, confidentiality agreements, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Devereux-Advanced-Behavioral-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27515</link>
<guid>ab38039d7c1a6862cc692cd15e20d757</guid>
<pubDate>Fri, 28 Nov 2025 13:56:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Devereux-Advanced-Behavioral-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>601445dbbc3386fe722b2342784ef44252f91dc85c575700cfe8e6e97ee23273</i><br /><br />Threat actor <b>description</b>: <i>www.devereux.org https://www.zoominfo.com/c/the-devereux-foundation/60082215 Devereux Advanced Behavioral Health, headquartered in Villanova, Pennsylvania, is a behavioral healthcare organization that operates a network of clinical, therapeutic, educational, and employment programs.</i><br />Target victim <b>website</b>: <i>www.devereux.org</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mid-South-Pulmonary--Sleep-Specialists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27513</link>
<guid>b257ab6a4d4452e181b7998b5c6e38bc</guid>
<pubDate>Fri, 28 Nov 2025 12:19:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Mid-South-Pulmonary--Sleep-Specialists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78c3fbf7969fe4aa384d795cf9dd58f228ec89b0bc538341806b7daea4187ed1</i><br /><br />Threat actor <b>description</b>: <i>Patient data breach.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bcfpers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27494</link>
<guid>a2ad4a29fc99de79997f9a616c345a7b</guid>
<pubDate>Thu, 27 Nov 2025 18:29:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bcfpers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58545e1c05b7e95ce1e2ab7882ea9b936d10f9ce3fc6c12b94a060c564cca50c</i><br /><br />Threat actor <b>description</b>: <i>Insurance</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Volleyball-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27495</link>
<guid>8b867815185dd36ff091a2702449feb9</guid>
<pubDate>Thu, 27 Nov 2025 18:29:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>United-Volleyball-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51e939251616b3ae5bcd71402440387c8a54e502b94ac6f11b2ba488367d579f</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mechanical-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27497</link>
<guid>ce4e66f7f29c8b37eff635378a9b9c0f</guid>
<pubDate>Thu, 27 Nov 2025 16:48:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mechanical-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6093bf4fe59bb9e781ef8b026267be9f35dd7a3851410f2e01ac18a49ce21ca</i><br /><br />Threat actor <b>description</b>: <i>Mechanical Systems Company offers building automation controls an
d services. 

We are ready to upload more than 30GB files of essential corporat
e documents such as: Employee personal information (SSNs, DLs, pa
ssports and so on), confidentiality agreements, financials, clien
ts information, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crucible-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27489</link>
<guid>44fa07418c5653af898002db3298a9b7</guid>
<pubDate>Thu, 27 Nov 2025 14:29:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Crucible-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>404dc3bc6274518367f29b0f417c1aee6c5ac59463ea3fd0cc0c9d0e95456aa9</i><br /><br />Threat actor <b>description</b>: <i>Crucible Industries was founded in 1870. This company provides the manufacturing of steel long products, and other metal building materials.We will upload 10gb of corporate documents soon. Internal operational files, a bit of customer information, scans and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Country-Club-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27491</link>
<guid>d0683d8499a7dbd42ee1abbb938e090b</guid>
<pubDate>Thu, 27 Nov 2025 14:29:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Country-Club-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d105c79962f84b88e1904574f6f7fef24d5effc32a62a0fb97e478557afcfaba</i><br /><br />Threat actor <b>description</b>: <i>Country Club Enterprises (CCE) sells and services Club Car golf cars and other low speed vehicles to Country Clubs, municipalities, and homeowners throughout New England.We are ready to upload more than 14GB files of essential corporate documents such as: employees and their relatives personal information (DLs, passports and so on), detailed financials, contractsand agreements, NDA, interesting project files and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kelly-Wearstler-Gallery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27492</link>
<guid>285fb42cb5e295f9249b7819417b3b77</guid>
<pubDate>Thu, 27 Nov 2025 14:29:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Kelly-Wearstler-Gallery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7a40491c3f0ecc966ff641f20abc2f2df72064633646018af62141876535107</i><br /><br />Threat actor <b>description</b>: <i>Kelly Wearstlers global luxury brand is influenced by spans of residential and commercial interior design. Kelly Wearstlers holds product collections of furniture, lighting, rugs, fabrics and trims, wall coverings, luxe bedding, fine china, and decorative homeaccessories.We are ready to upload more than 14GB files of essential corporate documents such as: HR files (employee personal information, complete forms and so on), financials, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Asl-Consulting-DTG-Consulting-Solutions-Snyder-Cohn-SBLM-Architects-Dealer-Information...</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27498</link>
<guid>273e78ede0ff68fcf04aa41a3dd8d36b</guid>
<pubDate>Thu, 27 Nov 2025 13:09:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Asl-Consulting-DTG-Consulting-Solutions-Snyder-Cohn-SBLM-Architects-Dealer-Information...</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26b62c984221aedf0dc01bd8985ee92add874c374008455afc1d924b2867e3ab</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 14gb of the following companies:

ASL provides Human Resources Software, Professional Services and 
Managed Outsourced Solutions for large and medium-sized organizat
ions requiring a level of complexity and sophistication in HR bey
ond what is available from payroll providers with an HR offering.

DTG Consulting Solutions provides recruiting and staff augmentati
on for Information Technology and Finance professionals.

SBLM Architects specializes in blending design intelligence with 
technical excellence across various sectors, including healthcare
, education, retail, commercial, mixed-use, and civic projects.

Snyder Cohn is a renowned CPA and business advisory firm establis
hed in 1927, providing expert services to businesses, executives,
and nonprofits primarily in the Washington DC area. They offer a
comprehensive range of accounting services including compliance,
tax, audit, and specialized client accounting advisory services.

Dealer Information Systems (DIS) is a leading business management
software provider to ag, construction, truck refrigeration and l
ift truck dealers.

You will find personal employees and customer information, lots o
f projects, agreements and contracts and other sensitive files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Santa-Paula</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27487</link>
<guid>978f39314267adc0e1c50db2615b467c</guid>
<pubDate>Thu, 27 Nov 2025 12:28:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Santa-Paula</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d395c8155be7427069ae8093f3929bd96d02ffb505430f0aca60e7f8b3e09d8</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>St.-Johns-River-Water-Management-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27459</link>
<guid>00a88476f623e4b554a2277fa4de42a0</guid>
<pubDate>Wed, 26 Nov 2025 18:28:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>St.-Johns-River-Water-Management-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a36217d5f7255548795a3dd21421906ab18be7e48b404e2336f4b0d2f7831bc0</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zoetis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27460</link>
<guid>ec67ec14e2f01a4baeb2464a044aaec1</guid>
<pubDate>Wed, 26 Nov 2025 18:28:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Zoetis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c34ce3f0c00f4e01e29b27f9890066805af13fa991490dd3b3275bcc791d203</i><br /><br />Threat actor <b>description</b>: <i>Zoetis discovers, develops, manufactures, and commercializes animal health medicines, vaccines, and diagnostic products in the United States and internationally.We will upload 25gb of corporate documents soon. Lots of internaldocuments, clients' data, numerous test and other information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fineline-Architectural-Millwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27461</link>
<guid>b928c4fa4fc95fd7e83a96fa48c76418</guid>
<pubDate>Wed, 26 Nov 2025 18:28:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fineline-Architectural-Millwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f8bea189c4eca39b58358db035d0913eb72a03cbde906820de4266fdd7a0cb1</i><br /><br />Threat actor <b>description</b>: <i>Fineline Woodworks Inc. is full service custom carpentry located in Orange County in beautiful southern California.We will upload 100gb of corporate documents soon. Employee personal information, detailed financials, NDAs, projects, clientsinformation, agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Healthcare-Retroactive-Audits</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27462</link>
<guid>b6b505ff2025d4dec937e9dfba52e4c2</guid>
<pubDate>Wed, 26 Nov 2025 18:28:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Healthcare-Retroactive-Audits</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6367b7d930b4292db2913e3f48121a6ed8855119abe9b65f8c8f103ef033aac7</i><br /><br />Threat actor <b>description</b>: <i>22 171 128 medical record files, neatly packaged into 11 archives by hospital. The firm Healthcare Retroactive Audits, which was auditing the data for insurers,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ADC-Aerospace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27480</link>
<guid>3cfec6ddc9e6325247431a9ee7ee45ef</guid>
<pubDate>Wed, 26 Nov 2025 17:58:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ADC-Aerospace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2475e99a5c87f4dd2fc9c5d6f2534d3acfc59b622333a81a216f031521bfc992</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.adc-aerospace.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>AGS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27466</link>
<guid>67317d6dcc4cb778aeb9219565f5456b</guid>
<pubDate>Wed, 26 Nov 2025 16:36:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>AGS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>58169c71e62bdfceaf66dd7d2354bcb80654e74dda30c4eb40c24f962b2c505a</i><br /><br />Threat actor <b>description</b>: <i>AGS</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stacey-L-Tokunaga</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27458</link>
<guid>3570256111bfde271851c5e1f41325b5</guid>
<pubDate>Wed, 26 Nov 2025 15:28:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Stacey-L-Tokunaga</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8b153f3658d88a34e09485c55cc3458aeb545b967a7978542b15c023dbca215</i><br /><br />Threat actor <b>description</b>: <i>The Law Offices of Stacey L. Tokunaga specializes in Workers Compensation Defense law, offering committed and high-quality legal services to self-insured employers, third party administrators, and insured clients.We will upload 200gb of corporate documents soon. Detailed personal employee information (DLs, SSNs, passports, addresses, phones and so on), detailed financials, clients' credit cards, police reports, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bergeson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27451</link>
<guid>5679e914eb9b1e93d8924b8fc2e75a28</guid>
<pubDate>Wed, 26 Nov 2025 14:08:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bergeson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ee06f3deab8d74da2e14abdd1bc8b19b70f50052cd2bf9ef533db6e56154fd6</i><br /><br />Threat actor <b>description</b>: <i>Bergeson, LLP is a leading litigation law firm based in Silicon Valley, established in 1990. The firm specializes in representing individuals and companies in high-profile and high-stakes litigation across the country, offering innovative strategies tailored to complex business disputes.We are ready to upload more than 33GB data. There are lots of essential corporate documents such as: financial data (audit, payment details, invoices), detailed employees and customers information (passports, driver's license , Social Security Numbers,death/birth certificate) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dobco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27452</link>
<guid>1fdd72b9fc6717195f76ea7c0783fa25</guid>
<pubDate>Wed, 26 Nov 2025 14:08:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Dobco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd26d7c93830e5e09cb93228b4035c760b7ec49f03c159d172a586546838f544</i><br /><br />Threat actor <b>description</b>: <i>Dobco founded in 1989 and headquartered in Wayne, New Jersey, is an established multi-faceted general construction firm.We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pacific-Railway-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27453</link>
<guid>cefc67efdb268e350862ad876b826a6e</guid>
<pubDate>Wed, 26 Nov 2025 14:08:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pacific-Railway-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9039a13359bd91de58178264d128bf789372386446612899b02eb3c0b08a60ab</i><br /><br />Threat actor <b>description</b>: <i>Pacific Railway Enterprises, Inc. is a woman-owned corporation specializing in Railroad System Design and Consulting.We will upload more than 20gb of corporate documents soon. Employee lists containing personal information, NDAs, contacts and agreements, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>FloorHeat</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27454</link>
<guid>2161c3fb9c53f90509028a2179494696</guid>
<pubDate>Wed, 26 Nov 2025 14:08:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>FloorHeat</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>18860ad35e49c8bfa4f8b5544843b479b1efe8b8a54a418fe2637c427b4c33eb</i><br /><br />Threat actor <b>description</b>: <i>FloorHeat Company specializes in manufacturing and distributing radiant heat components and complete underfloor heating systems, including electric film, cable heating mats, and their patented EasyFloor hydronic heating system.We will upload 25gb of corporate documents soon. Detailed employee personal information, financial and accounting data, contacts and agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Williams--Sparages</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27456</link>
<guid>3b7dc46bb8c1cd27c5e259d59aec73f3</guid>
<pubDate>Wed, 26 Nov 2025 14:08:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Williams--Sparages</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a6360700a642068cb19baeef35559afd4306c58b2fcd519f0ef19b32c6beeb3</i><br /><br />Threat actor <b>description</b>: <i>Williams & Sparages is a full-service engineering firm specializing in civil engineering, planning and development, surveying and mapping, and construction services.We will upload about 127gb of corporate documents soon. Clients information, employee personal information, financials, credit card details, projects, contacts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burnham-Brown</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27446</link>
<guid>acc85fcea72cd0e4032763ed0c565dbc</guid>
<pubDate>Wed, 26 Nov 2025 11:28:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Burnham-Brown</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a8f20cdad716c963a16c71b60f7e632c98d0400e9a3911753b1439d0f8b0dd6</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eastek-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27447</link>
<guid>19813ce72de2e59f836d858196dabe6f</guid>
<pubDate>Wed, 26 Nov 2025 11:28:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Eastek-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f96d1cd9630621896b46fe86ff663e0a66a5cc0544abcd52c7f11bc18aaf8896</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Workflow-Concepts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27448</link>
<guid>bc354cf7b5f838d2b1e8a51a0282acdd</guid>
<pubDate>Wed, 26 Nov 2025 11:28:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Workflow-Concepts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e11ce6068934fe261f2f37030325003eed209721e9e50af0a790ef6200abd78f</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Disston</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27450</link>
<guid>84fc80be70d6ffd85f3f172f1f8ea150</guid>
<pubDate>Wed, 26 Nov 2025 11:28:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Disston</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>565ae4893c0828b665929affe32d96f52f94737a6fe74eded6b463c9a5325df6</i><br /><br />Threat actor <b>description</b>: <i>Building Materials</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carlton-Fields</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27464</link>
<guid>c859dc7fb3f221f8598a9d851cb6199d</guid>
<pubDate>Wed, 26 Nov 2025 11:13:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Carlton-Fields</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0cac905d86c16ddc1b42f38cea320792daf4adf8e6fcbf5293c43b211178f5b</i><br /><br />Threat actor <b>description</b>: <i>Carlton Fields is a nationally recognized law firm delivering strategic legal counsel to corporations,…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>AllerVie-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27443</link>
<guid>27a1e0e31bf1a18797d26f7796f1ae4e</guid>
<pubDate>Wed, 26 Nov 2025 01:12:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>AllerVie-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>165fc4a7f61fbeaef1a54fa4bec26102578e047a8695ef0d710892831407fb2f</i><br /><br />Threat actor <b>description</b>: <i>Major customer database leak.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Inspire-Communities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27437</link>
<guid>d95a2fa315683f22cfa4713558f64dfe</guid>
<pubDate>Tue, 25 Nov 2025 20:28:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Inspire-Communities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>074929478f658071a1c87638186f51eddc0cb41c905e47806aee3069dc71b703</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>New-England-Tractor-Trailer-Training-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27438</link>
<guid>1cbb2344a50511f9ea581e66c5cc54f7</guid>
<pubDate>Tue, 25 Nov 2025 20:28:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>New-England-Tractor-Trailer-Training-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>771dfc480ab9f471be80614cc70aaf6386d456ea1ed27202443035c2ac9a9d73</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Columbia-Medical-Practice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27429</link>
<guid>c6626118332e60bac18d07987a74c738</guid>
<pubDate>Tue, 25 Nov 2025 18:28:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Columbia-Medical-Practice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c98e756e03e5657455f8a5bfa3368e2fa30ba3ab6f6e4f3ef5600b5a7cd11b84</i><br /><br />Threat actor <b>description</b>: <i>0</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lake-Superior-State-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27430</link>
<guid>4bd6a2a0403d0b5c3157bae3ac4fc601</guid>
<pubDate>Tue, 25 Nov 2025 18:28:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lake-Superior-State-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2c5c0d3eb8d07df1a77b78c10b8914c86081b94487431077f88e0df12e6175f</i><br /><br />Threat actor <b>description</b>: <i>Education</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rochester-Philharmonic-Orchestra</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27431</link>
<guid>31c9f58aa5c02d63abfa65bf94dd602e</guid>
<pubDate>Tue, 25 Nov 2025 18:28:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rochester-Philharmonic-Orchestra</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bccc75128b13c4a6342aeb01fcc2c7567949b035b3f521506f517f4292124060</i><br /><br />Threat actor <b>description</b>: <i>The Rochester Philharmonic Orchestra (RPO) is a distinguished institution with a 100-year legacy of artistic excellence, offering a diverse range of concerts and educational programs. We will upload corporate documents soon. Musicians' personal information (SSNs, DLs, phones and so on), budget, internal confidential docs, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accord-Carton</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27432</link>
<guid>0eea9b5a14fff04fe8c0ebf78bc90d63</guid>
<pubDate>Tue, 25 Nov 2025 16:45:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Accord-Carton</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd2b5da0d1af2372fdc621d35785cfbdd0d7ae4cf5952ca28640ee714103b92c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Accord Carton is a family-owned company that specializes in designing and manufacturing high-quality folding cartons. Founded in 1940, the company is based in Alsip, Illinois. Accord Carton utilizes advanced printing and finishing technologies to produce innovative packaging design solutions. Their services are widely used across industries, including food and beverage, healthcare, and beauty products.</i><br />Target victim <b>website</b>: <i>accordcarton.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Standing-Chapter-13-Trustee</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27415</link>
<guid>624f9da624e85b501a40c03730f6ba83</guid>
<pubDate>Tue, 25 Nov 2025 12:28:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Standing-Chapter-13-Trustee</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49ea2a0edee8e8b6dc0639097ac3bde00814aabbd6cadca9618ac844b7df53f7</i><br /><br />Threat actor <b>description</b>: <i>The Standing Chapter 13 Trustee District of Minnesota provides services related to bankruptcy cases under Chapter 13, assisting debtors with payment information and case-related resources.We will upload 44gb of corporate documents soon. Employee and client personal documents (SSNs, passports, DLs and so on), detailedfinancials, internal confidential docs, contracts and agreements, court documents, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rempe-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27422</link>
<guid>36b5cde3df91a145d823508f9b5c9c91</guid>
<pubDate>Tue, 25 Nov 2025 10:47:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Rempe-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9a7101bac577e79c58d931b098f631a67a322fb5e6db1270a2e6e287230cb73</i><br /><br />Threat actor <b>description</b>: <i>Rempe Construction specializes in construction services, offering expertise to various clients in need of reliable building solutions. With a focus on quality and customer satisfaction, they deliver tailored construction projects. Located in Novato, California, they serve the local community and surrounding areas. Their commitment to excellence positions them as a trusted partner in the construction industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>MSK</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27425</link>
<guid>da5470b9e6792dbdc7ee450891b2945f</guid>
<pubDate>Tue, 25 Nov 2025 10:09:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>MSK</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52bde9a2a667a2a5fb0705f62624741364f91b547fa5a50cfa9892121397a985</i><br /><br />Threat actor <b>description</b>: <i>Established in 1908, Mitchell Silberberg & Knupp (MSK), is a firm that provides services such as Ventu…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>StatMedPlus-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27421</link>
<guid>aca1de509b1d10131783122f42ee4c75</guid>
<pubDate>Tue, 25 Nov 2025 08:47:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>StatMedPlus-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89f5edf97ecca6ffbbee7524a498c27148b8db7ff1850d64682ed9404548403b</i><br /><br />Threat actor <b>description</b>: <i>StatMedPlus LLC is located at 22 Jericho Turnpike in Mineola, New York 11501.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>HYTORC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27403</link>
<guid>90f5c2fca26cdc32f97373bba4c0c337</guid>
<pubDate>Mon, 24 Nov 2025 20:28:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>HYTORC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b4bedd911ecad4401b8b872a24f7074f7e12aef9513bded7b7efed56eb7cffb9</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Issaqueena-Pediatric-Dentistry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27407</link>
<guid>ffec51567543679f01ce65724adca743</guid>
<pubDate>Mon, 24 Nov 2025 17:48:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Issaqueena-Pediatric-Dentistry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f344e673472a5010d29d547570bee5067d16d3d452d2b858894161b4d11bfbe0</i><br /><br />Threat actor <b>description</b>: <i>Isaquenna is a medical center where people get dental treatment and leave their confidential data. Due to its low security, Isaquenna suffered a data breach involving its patients' phone numbers, addresses, SSNs, and personal information such as images, medical histories, and the entire history of the clinic.</i><br />Target victim <b>website</b>: <i>issaqueenadental.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lithographix</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27386</link>
<guid>e61d2ed0329c7be9a1cc46faed9b9a27</guid>
<pubDate>Mon, 24 Nov 2025 16:38:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Lithographix</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c3fec137ca06b3848f7f69c7bbd3ce0d01e884aa21a1ee0d4925e91d8e8e21e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Lithographix is a printing company based in Hawthorne, California, specializing in offering high-quality printing solutions. They provide services including large format printing, direct mail, digital printing, commercial printing, and binding services. They cater to a range of industries such as advertising, publishing, retail, and more. Established in 1975, Lithographix is known for delivering comprehensive, innovative, and eco-friendly printing solutions.</i><br />Target victim <b>website</b>: <i>lithographix.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Westrian-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27402</link>
<guid>e71f0aa2ed94afb5e84cabf28aea9dfb</guid>
<pubDate>Mon, 24 Nov 2025 16:17:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Westrian-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16a134a324192f3c5177b26a94ae3144f9cd1d50136eb11878ccd2928abf3642</i><br /><br />Threat actor <b>description</b>: <i>JR Engineering provides services in land management, surveying, land transportation, water resources, and structural design! This company was compromised due to extremely poor security and a weak IT department. Client databases were lost, including confidential contracts with clients and more! All of the company's current sketches and models are now publicly available, which could ruin its reputation and financial position!</i><br />Target victim <b>website</b>: <i>jrengineering.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chairmans-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27383</link>
<guid>ecec4e43c7aec3dac3535280cd06a37a</guid>
<pubDate>Mon, 24 Nov 2025 15:28:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Chairmans-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b44163c5df4be0c5937463b008916a72937af5f2f1dd50c9d19d8bf0e469f82d</i><br /><br />Threat actor <b>description</b>: <i>Chairmans Foods is a gold-star rated, USDA manufacturing plant and producer of fresh, frozen and refrigerated food products for more than 40 years. They serve delicious home cooked foods to various delis, grocers and chain restaurants.We are going to upload company data soon. You will find financialdata (audit, payment details, financial reports, invoices), personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Akehurst-Landscape-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27384</link>
<guid>7fcbff32ba6970c5a98efe594b17c6a8</guid>
<pubDate>Mon, 24 Nov 2025 15:28:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Akehurst-Landscape-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99e6c817e5c9df7149fe639355e73fb598baa4b77927677890330a8b42b8199a</i><br /><br />Threat actor <b>description</b>: <i>Akehurst Landscape Service, Inc., based in Joppa, MD, offers a wide range of landscaping, snow removal, and grounds maintenance services tailored to meet the needs of commercial, industrial, and residential clients. We are going to upload company data soon. You will find financialdata (audit, payment details, financial reports, invoices), personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>dynamichomerepair.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27400</link>
<guid>bcbbe077e03672f38b53fc30865f577a</guid>
<pubDate>Mon, 24 Nov 2025 15:09:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>dynamichomerepair.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b77cdd06ff435141bed6b2fefad818124295bd92fb8bcff75dc330b21a78e43</i><br /><br />Threat actor <b>description</b>: <i>Dynamic Home Repair is a U.S.-based company specializing in repair services for manufactured homes. It offers a “lifetime warranty” on …</i><br />Target victim <b>website</b>: <i>dynamichomerepair.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27388</link>
<guid>294aaff60deaa8b454a370d5952ed8ef</guid>
<pubDate>Mon, 24 Nov 2025 10:03:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Advanced-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>623c44112b7bb32dca7f4049aadfc1347a2defcf609b595e9d007141cfbb6c3e</i><br /><br />Threat actor <b>description</b>: <i>Advanced Dental, located in Aliso Viejo, CA, offers cutting-edge laser dentistry and a wide range of comprehensive dental services tailored for families. Their experienced team, led by Dr. Chitra Tiruveedula and Dr. Joseph C. Yang, provides personalized care for patients of all ages, from toddlers to seniors. The practice emphasizes advanced technology and techniques, including dental implants, Invisalign, and emergency dentistry, ensuring a comfortable and efficient experience. With flexible payment options and a commitment to patient well-being, Advanced Dental aims to create healthy smiles that last a lifetime.</i><br />Target victim <b>website</b>: <i>www.advanceddental.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Access-Search</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27389</link>
<guid>3d2b08aa7cfa68fd54e3f4a4e7ffcf7d</guid>
<pubDate>Mon, 24 Nov 2025 10:03:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Access-Search</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a951e26d43920f226d11a924e4009bd530b5105676cd7777a42650c1edac55b2</i><br /><br />Threat actor <b>description</b>: <i>Access Search, Inc. was founded with one simple mission: to be an honest, diligent, and knowledgeable search firm. With that goal in mind, we assembled the organization that exists today. We take great pride in our team. Each recruiter at ASI has several years of recruiting experience coupled with years of valuable experience in Big 4 public accounting and/or Fortune 500 finance. We come from some of Chicago's finest employers including Andersen Consulting, Deloitte & Touche, Ernst & Young, KPMG, Baxter International, Platinum Technology International, R.R. Donnelley & Sons, Unilever, Cardinal Heath, and Sears Roebuck & Company. Our recruiters draw upon their collective knowledge to present our clients with carefully screened and informed business professionals.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Liberty-Gold-Fruit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27387</link>
<guid>45ab092a5990dcce61e606f64873a98f</guid>
<pubDate>Mon, 24 Nov 2025 08:36:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Liberty-Gold-Fruit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8315de59d32e1f0cf0175cbd7e432cc8a5b009f2795ade80dfcd9e964734781</i><br /><br />Threat actor <b>description</b>: <i>Liberty Gold Fruit Company, Inc. is a family-owned business renowned for its premium quality food products and exceptional service since 1932. The company’s LIGO Brand boasts a presence on grocery shelves in 40 countries, primarily in Asia, Central America, and Europe, often ranking as a leading brand. With a commitment to excellence, Liberty Gold is one of the few remaining privately-owned companies in the industry. Its extensive distribution network ensures that their products reach a diverse clientele worldwide.</i><br />Target victim <b>website</b>: <i>www.libertygoldfruit.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Homestead-Museum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27391</link>
<guid>8074ea1e919ed5dc154c7fe6f1a2e212</guid>
<pubDate>Mon, 24 Nov 2025 00:20:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Homestead-Museum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04184029f2a21ddfac97de4e1127d269dd4f75579140d6b029ab3d9f5f281bc4</i><br /><br />Threat actor <b>description</b>: <i>The Homestead Museum is a Historic-Cultural Landmark located in the City of Industry, California, showcasing the history of Los Angeles from the 1840s to the 1920s. It offers a range of programs, including workshops and tours, aimed at educating visitors about local history and fostering advocacy for historical preservation. Ideal for families, students, and history enthusiasts, the museum provides engaging experiences such as storytelling sessions, crafts, and genealogy workshops. As a unique cultural resource, it invites visitors to explore its gardens, houses, and historical narratives.</i><br />Target victim <b>website</b>: <i>www.homesteadmuseum.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cayuga-Milk-Ingredients</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27372</link>
<guid>14d8905820297f70d9a211f964f16257</guid>
<pubDate>Sun, 23 Nov 2025 17:28:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cayuga-Milk-Ingredients</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c513b933098b398346b191aa5dbd29044edadf8f25967705097acf87693fc69</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Hunnicutt-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27373</link>
<guid>a627f2f69e1caf8063d3fa385f8c4149</guid>
<pubDate>Sun, 23 Nov 2025 17:28:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Hunnicutt-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e734f8fffe54cca8b8888caaad3a99808c37cd4eeccd6631cca357ec4211f53</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Summit-Construction-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27366</link>
<guid>69cf37d6e6e7462c6bef71561f143071</guid>
<pubDate>Sat, 22 Nov 2025 22:28:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Summit-Construction-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>385f458f017e775fa090833298b9359067995181d2e9c432dc0a8160fad40aff</i><br /><br />Threat actor <b>description</b>: <i>Summit Construction Supply is a leading commercial construction product supplier based in Loveland, Colorado, specializing in providing a wide range of construc...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nugent-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27367</link>
<guid>c2d523e62edb799b473d282f848e2076</guid>
<pubDate>Sat, 22 Nov 2025 22:28:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Nugent-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30ce370b2333a0f1945961f3cd1834c4f35f7730dc78698f61aed66b1d6e8d59</i><br /><br />Threat actor <b>description</b>: <i>Nugent Supply Company is a Women Business Enterprise (WBE) and a member of the Specialty Tools and Fasteners Distributors Association (STAFDA) based in Loveland...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fueling-Solutions-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27368</link>
<guid>af83dfe0b00bdce9c850ae8d3c8a1b99</guid>
<pubDate>Sat, 22 Nov 2025 22:28:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Fueling-Solutions-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>381b97d55c1e12b1e19c94e6ca3a0b70bdae66909272ca3a00b3d18662a9063a</i><br /><br />Threat actor <b>description</b>: <i>Fueling Solutions, Inc. specializes in providing commercial, industrial, and mission-critical fueling systems across over 30 countries on four continents. The c...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Healthcare--More</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27369</link>
<guid>07c0dec6e97ec77c01aa90902a3fc6b5</guid>
<pubDate>Sat, 22 Nov 2025 22:28:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Healthcare--More</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68bf3e32f7290821e721af6719506da7e61cdf58c78db5779d879eee0662d169</i><br /><br />Threat actor <b>description</b>: <i>Healthcare & Moore, led by independent insurance broker Myra 'Lynn' Moore, specializes in a comprehensive range of insurance products including Medicare plans, ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barr-Trucking-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27362</link>
<guid>119bd52062c0246257fcd0ec0b8f1902</guid>
<pubDate>Sat, 22 Nov 2025 18:52:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Barr-Trucking-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6394b730a2a5fabf29b093c4a60ea0746d57b6d3b50f1a219ea60e18f9021602</i><br /><br />Threat actor <b>description</b>: <i>Barr Trucking was formed in 1981 by William Mark Barr and his Father William DeWitt Barr in Pinckneyville, IL. At the time, Barr Trucking consisted of two water delivery trucks and one dump truck utilized to deliver residential rock. In 1983 Mark acquired his father’s share of the company with visions of expanding into new markets. The next year Mark purchased the company’s first semi, a 1975 R Model Mack. With an expanding fleet and company growth, a new facility was in order. In 1989, Barr Trucking purchased a large work shop and storage yard west of Pinckneyville, IL where the company operates today.</i><br />Target victim <b>website</b>: <i>barrcos.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>F-W-S-Countertops</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27363</link>
<guid>88595b57c894d9b4a978cdad11062292</guid>
<pubDate>Sat, 22 Nov 2025 18:51:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>F-W-S-Countertops</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c639c3ca1fba8795622dd9b87bcf6f5ff95b594936a4e2835a258fd138735427</i><br /><br />Threat actor <b>description</b>: <i>F-W-S COUNTERTOPS specializes in the design, fabrication, and installation of premium countertops, including Quartzite, Granite, Sintered Stone, Man-Made Quartz, and Wood Butcher Block. The company serves residential, commercial, and institutional clients in Southern Illinois and the tri-state area. With a focus on quality craftsmanship and a wide range of customizable products, they offer unique solutions for various projects such as kitchen and vanity countertops, wall backsplashes, and outdoor kitchens. Their showroom features full slabs and samples along with kitchen and vanity sinks in multiple styles and materials</i><br />Target victim <b>website</b>: <i>f-w-s.net</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mmlk</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27357</link>
<guid>b9de76f2825e2107822a5c68b172a144</guid>
<pubDate>Sat, 22 Nov 2025 18:28:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mmlk</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1dca0b59b7d1340d7380151e56507331c4bcbe98850df140cdcb7cf26f4643a8</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keystone-Fabricating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27360</link>
<guid>e5a872704d45c7fa661a94abd9f9d92d</guid>
<pubDate>Sat, 22 Nov 2025 17:13:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Keystone-Fabricating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2e45df6530f1cedad634b28c1267179536977d0e83bb86a5fec4b434f8fdd2f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.keystonefabricating.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CM-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27354</link>
<guid>4c1f53116d73ff13367ffbfd35d8a105</guid>
<pubDate>Sat, 22 Nov 2025 12:50:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>CM-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee11c4e42448054a65698c167e5bbadf2d4c0b72d168cb80d03517cbc3c20c83</i><br /><br />Threat actor <b>description</b>: <i>C&M Software is a leading technology company specializing in solutions for the financial market. Their offerings include automated processes, secure payment integrations, and payment solutions tailored for both immediate and installment transactions. The intended clients range from financial institutions to retail and corporate sectors, aiming to enhance efficiency and risk management within their financial operations. With a commitment to innovation, C&M Software is recognized for providing robust and flexible technology services that streamline payment processes and improve business intelligence.</i><br />Target victim <b>website</b>: <i>www.cmsw.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>onsolve.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27351</link>
<guid>7331da3b0e6d2887993eaee520f03a5a</guid>
<pubDate>Sat, 22 Nov 2025 11:43:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>onsolve.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1df3be6002f8ac66db055a16c4c520f999b8fd66a53045904500b7ffd17af5ae</i><br /><br />Threat actor <b>description</b>: <i>OnSolve is a leading critical event management provider that proactively mitigates physical threats, allowing organizations to remain agile when a crisis strikes. Using the most trusted expertise and reliable AI-powered risk intelligence, critical communications and incident management technology, the OnSolve Platform enables enterprises, SMB organizations and all levels of government to detect, anticipate and mitigate physical threats that impact their people, places and property.</i><br />Target victim <b>website</b>: <i>onsolve.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medical-Center-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27350</link>
<guid>4469eee129fe5da0d3edce5404418f59</guid>
<pubDate>Sat, 22 Nov 2025 08:16:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Medical-Center-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a06e08009f2ef5bf56234549d2122ecfeb1a833b5bed5a14035a2ece9e9b1aef</i><br /><br />Threat actor <b>description</b>: <i>Family Medicine and Primary Care Practice in Dublin, GA</i><br />Target victim <b>website</b>: <i>dublinmedicalcenter.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Interlink-Trade-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27352</link>
<guid>a1ff59c9fcd256be3695bb06465e1011</guid>
<pubDate>Sat, 22 Nov 2025 07:23:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Interlink-Trade-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22cc1cd5faa834fd3ae8ea9ad1a4db4a568fc24e9743192313d48585e68f2bfd</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.interlinktrade.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>gsccca.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27348</link>
<guid>df4684fd22721f7396ace865dbf2bf3f</guid>
<pubDate>Fri, 21 Nov 2025 21:53:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>gsccca.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>703567365b23ba3736df5d1cfb843dc63fcdf561dbd174f5261d00c8ddef7b93</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 500gb
400k</i><br />Target victim <b>website</b>: <i>gsccca.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>procure.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27346</link>
<guid>b9bd86411ab7be06a57612b91c7ef221</guid>
<pubDate>Fri, 21 Nov 2025 18:53:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>procure.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a33c96c695f4f931f3e59ac2e916ae51be9f44eda251b8a91607e19a62e42560</i><br /><br />Threat actor <b>description</b>: <i>Ransom: data theft 
40gb
120K</i><br />Target victim <b>website</b>: <i>procure.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alma-Realty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27334</link>
<guid>58a2819da7144df30bfb364e9bd53453</guid>
<pubDate>Fri, 21 Nov 2025 17:28:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Alma-Realty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>171d95524b573582d515e8bf241666a51109560cd6a08198793184c41afd7bb7</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Electro-Mechanical-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27336</link>
<guid>70933ed510f3c50e1ebf98ef8c6625c2</guid>
<pubDate>Fri, 21 Nov 2025 17:28:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Electro-Mechanical-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9065445cf7258eeb0d8fa7d5be6754d03c641558124aa43afd4bfee343fbf1b</i><br /><br />Threat actor <b>description</b>: <i>Electro-Mechanical Industries, Inc. (EMI) is a manufacturer of standard and custom electrical distribution equipment serving the needs of the electrical industry in the national and internationalmarketplaces.We will upload 50gb of corporate documents soon. Lots of forms with personal employee data (SSNs, addresses, phones, emails), financials, client data, contracts and agreements, projects, drawingsand specifications, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PM-Plastics-Reliable-Van--Storage-Landis-Whitinger-Strategic-Services-Kimber-Manufact</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27337</link>
<guid>0dd4332bc8f0e9692eaa585b1b20c712</guid>
<pubDate>Fri, 21 Nov 2025 17:28:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>PM-Plastics-Reliable-Van--Storage-Landis-Whitinger-Strategic-Services-Kimber-Manufact</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>686e942884ace39f43df86bd232eb05b924ad81ac2f85460efed9b0546fb3b27</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 29gb of the following companies:PM Plastics manufacturing of miniatures, small parts, large parts, and multiple component assemblies, with most polymers, acrylics, and thermoplastics.Reliable Van & Storage is a full-service moving company based in New Jersey, offering local, long-distance, and international relocation services for both residential and commercial clients.Landis is a real estate services company that that uses technology and data science to help renters reach home ownership.Whitinger Strategic Services is a business development firm that offers a variety of consulting services to help organizations grow in effectiveness, both internally and in the marketplace.Kimber provides a singular purpose of building fine sporting firearms, better even than classics from the golden age of American gunmaking.You will find personal employee personal data, client information, project files, accounting and financials and other internal operational files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>First-Fruits-Farms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27338</link>
<guid>2f4ab360cf3af4da6fde2edadc989788</guid>
<pubDate>Fri, 21 Nov 2025 17:28:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>First-Fruits-Farms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2014fa10604058fb37308447b91b7df5a7a13c33dc4f8c9b9ccd8f411ebb8e0</i><br /><br />Threat actor <b>description</b>: <i>First Fruits Farms, located in Prescott, Washington, is an agricultural company that specializes in apple and cherry orchards.We will upload 26gb of corporate documents soon. Employee personal documents (SSNs, passports, w-9 forms), detailed financials, customer data, contracts and agreements, projects, drawings and specifications, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>HCMSPARTNERS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27339</link>
<guid>c4561a0e19159df04bbefd195d1530a3</guid>
<pubDate>Fri, 21 Nov 2025 17:02:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HCMSPARTNERS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f46bc3fb10851898f419101d71b2fd58457f277f8b777bdf7eab03653eabbe3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MSG.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27307</link>
<guid>2bd17730427116dbfd936f57fbca0237</guid>
<pubDate>Fri, 21 Nov 2025 16:59:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MSG.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd186ce07c1abeeea7214680b9967010a5c45106a81e58986774898e007e1d02</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INTELLINUM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27308</link>
<guid>df1587ed91223bcb29b80f5bdcb9f3fa</guid>
<pubDate>Fri, 21 Nov 2025 16:56:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INTELLINUM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e94134cde3d5b2bf7a0a74e5b28883f571c49398cc3f7672f59ccf1f50b71449</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>KNEXTECH.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27309</link>
<guid>5e00e01a9eda901400af2385124a46f4</guid>
<pubDate>Fri, 21 Nov 2025 16:53:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KNEXTECH.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47044215e999cde5593cd9c7bd4c5a92f70e9560b8275b87b28d92fb06b57968</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ANYWHERE.RE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27310</link>
<guid>36784239eafd68f930b48af7ba423a3a</guid>
<pubDate>Fri, 21 Nov 2025 16:51:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ANYWHERE.RE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2290a34970994ac6dfc37af2097d7324241154a313da6cafcd0461fc40490cff</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GOLDSTARPENS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27311</link>
<guid>be9e47ef1ac42972d5bee9836c8c7b73</guid>
<pubDate>Fri, 21 Nov 2025 16:51:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GOLDSTARPENS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbb241ae1f2ad288c352e1467a307c3d9099274a9592989f53085238924b207e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>NORTHEASTERNCORP.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27314</link>
<guid>80ddea7f4c358d2a47c0292bd58a635f</guid>
<pubDate>Fri, 21 Nov 2025 16:36:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NORTHEASTERNCORP.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35b99a0f2167abd90c2d9c6bc3f982222d3ae2f25181fa9cb14e310bc8b99e65</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MACYS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27316</link>
<guid>e7a180ba295bede84074fba08a8feea4</guid>
<pubDate>Fri, 21 Nov 2025 16:33:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MACYS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2eaf6dd4c6160695fb184dfd57acafd778ca0fbf918b67be7f371a45fc36452</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HYPERTHERM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27317</link>
<guid>51ca813b865fb6a3be61edd9fdf0b157</guid>
<pubDate>Fri, 21 Nov 2025 16:22:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HYPERTHERM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7dbd4d541c2f1e338e84d232bf95d4410e0ed347ebe2e5f6a6d5f48d00b8c857</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INVENTIVE-IT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27319</link>
<guid>96998fec57d81a588cb70dfd7a56bab8</guid>
<pubDate>Fri, 21 Nov 2025 16:18:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INVENTIVE-IT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ff2f8b6032dccb032f4cb5939cab3e2c1499e769eb3b408d2e1826f3516f669</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>IBIZSOFTINC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27326</link>
<guid>50f5a0b224ddb1270e0f523c7efae216</guid>
<pubDate>Fri, 21 Nov 2025 16:12:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>IBIZSOFTINC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8291aa8db31d4b6feb21474fa63cdd4c2581d2301c78fe9229b1c2c2231c10a2</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LEGACYCLASSIC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27327</link>
<guid>d6979f4b1fc40f9d720e42d4ce13bb10</guid>
<pubDate>Fri, 21 Nov 2025 16:12:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LEGACYCLASSIC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c40db54a6f4ff782299952e861fc06ca63ea93ebaa48fca8267571af7499dcf</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>AOSOM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27328</link>
<guid>aad65b962da06a412ef0d9e499960b1a</guid>
<pubDate>Fri, 21 Nov 2025 16:12:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>AOSOM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9285fa377f7366041fcdb8beb76dfa98c762306d08dd2ddc66b8d8f5a5cc12f7</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INCENTIVECONCEPTS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27329</link>
<guid>80975550806eb4c9abaf7bb3d6cd4868</guid>
<pubDate>Fri, 21 Nov 2025 16:12:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INCENTIVECONCEPTS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f65dec9316508eea5c2ef8aac1e9d53b1be92a6703e2ed45274f22b3b58ee968</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wachusett-School-District-MA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27342</link>
<guid>a438a122ad7b41a2d652eccda5a6711b</guid>
<pubDate>Fri, 21 Nov 2025 15:46:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Wachusett-School-District-MA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>191eb46a333c376161129f58a507b028b6fc93387cda3bd1ea203e187b02badd</i><br /><br />Threat actor <b>description</b>: <i>Wachusett School District MA Wachusett School District MA is a public school district.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>UAM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27341</link>
<guid>58473c0cf0d3a91a67640caff09c74f3</guid>
<pubDate>Fri, 21 Nov 2025 14:22:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>datacarry</b> claims attack for <b>UAM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6e08303e239aef26f68b008b3e46490148dd91d6a536c22d069972f49bee09c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] UAM, officially known as Universal Asset Management, is a global leader in the aviation services industry. They specialize in whole asset management, from leasing, trading to dismantling end-of-life commercial aircraft. Established in 1992 and headquartered in Tennessee, USA, UAM utilizes advanced technology to serve a wide range of clients around the world. They are dedicated to environmental sustainability through recycling aircraft materials.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>datacarry</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gruenberg-Kelly-Della</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27301</link>
<guid>fe18b4fe37333a388473988576c744ee</guid>
<pubDate>Fri, 21 Nov 2025 12:16:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Gruenberg-Kelly-Della</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfe8e554334dbe9a193ee0e3ddd3a413ed1483b521293d0fcb251e03e6a654b9</i><br /><br />Threat actor <b>description</b>: <i>One more law firm, which posts glossy Instagram updates about its victories, has now shut down its phones after confronting client‑data leaks and other problems, leaving customers in the lurch. We’re prepared to take down that post immediately once the firm’s representatives contact us and begin negotiations to prevent the release of the data for which they are responsible. If you’re a client, reach out to the firm and tell them you do not want your medical or financial information made public.
Gruenberg Kelly Della is a Long Island-based law firm specializing in personal injury cases, dedicated to achieving justice for the wrongfully injured. Their experienced legal team handles a wide range of cases, including car accidents, medical malpractice, and wrongful death, with a strong commitment to client advocacy. The firm operates on a contingency fee basis, ensuring that clients pay no legal fees unless they win their case. With a proven track record of recovering hundreds of millions for their clients, they are passionate about helping individuals navigate the complexities of personal injury law.</i><br />Target victim <b>website</b>: <i>newyorklawgroup.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>PATLITE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27296</link>
<guid>066d798d72836b03af5a4a692960a6e0</guid>
<pubDate>Fri, 21 Nov 2025 00:10:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>PATLITE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48e3e738dd1f238c54a00b40223b275fdfcfaebee0c2bb302e5f1a693aad6b80</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1947, PATLITE Corporation is a technology engineering and manufacturing company. PATLITE provides LED status indicating lights, sound alarms, and visual and audible communication network systems. The company is based in Torrance, California.</i><br />Target victim <b>website</b>: <i>www.patlite.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>SAExploration</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27294</link>
<guid>2326eb84b13c47afd79b98dda65b4fd9</guid>
<pubDate>Thu, 20 Nov 2025 22:44:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>SAExploration</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c788d32f6a2a61b7eeb75e2283eb0b23186c4b0df21aac8594055d6c077d454</i><br /><br />Threat actor <b>description</b>: <i>SAExploration Holdings, Inc., an oilfield services company, provides seismic data acquisition and logistical support services to the oil and natura...</i><br />Target victim <b>website</b>: <i>saexploration.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kewaunee-Scientific</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27293</link>
<guid>81b669febd10363a78964e2ea652a9e6</guid>
<pubDate>Thu, 20 Nov 2025 22:43:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Kewaunee-Scientific</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cdb804cf93ccc5f2825298b558a59754bed40e7d2d2f427569f8d0fa43850a38</i><br /><br />Threat actor <b>description</b>: <i>Kewaunee Scientific Corporation designs, manufactures, and installs laboratory, healthcare, and technical furniture products. The company operates ...</i><br />Target victim <b>website</b>: <i>kewaunee.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>classiccenter.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27292</link>
<guid>57b01adc7eb0a085a9eed546e5b0f617</guid>
<pubDate>Thu, 20 Nov 2025 21:28:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>classiccenter.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c463b0acd4eb9a88d3c1214a55ceb74b86ccb8cd0caaf55bf8ebac40756c519</i><br /><br />Threat actor <b>description</b>: <i>Akins Ford Arena is a state-of-the-art entertainment venue located in downtown A...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fayette-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27285</link>
<guid>fff574293a6252f4029a9413f364b2e6</guid>
<pubDate>Thu, 20 Nov 2025 19:28:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Fayette-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0267152ba1daa8757f1e3ebddb8e6be68b5d27d9d90e047c1e74d2fc0bcb90f0</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Radio-Sound</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27291</link>
<guid>ec811d0d775adc62776ba80fadd4ed19</guid>
<pubDate>Thu, 20 Nov 2025 18:12:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Radio-Sound</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>df748b565a52f19e4ee7b9bcdc45e053d77e1289e8916ce35a4fec9c3a2c6374</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.radiosound.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Applied-Energy-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27290</link>
<guid>2b962f0b627cf45414b498eb963dde7d</guid>
<pubDate>Thu, 20 Nov 2025 18:11:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Applied-Energy-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39e8dffb880244d30315728e58230f839d2816129030f0f98a5b65dee0f16137</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.appliedenergysystems.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>One-Source-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27288</link>
<guid>97fb74bbdd02677adc1a871fdd16ac7a</guid>
<pubDate>Thu, 20 Nov 2025 18:10:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>One-Source-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89c53d52618a84987b4c7c8953f4450741052359fce6b7ad3e53cb7e85501a71</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.onesa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>N-C-Machinery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27287</link>
<guid>2dac573d6ff24bd9a16140531e156cdc</guid>
<pubDate>Thu, 20 Nov 2025 18:09:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>N-C-Machinery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb6ad94e6a667e8d155ff569a2ccd01d056c8954ff04b4c9d65f80cfda366758</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ncmachinery.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Highmark-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27286</link>
<guid>d0a0890b4ed35d097396473c7c84da92</guid>
<pubDate>Thu, 20 Nov 2025 18:08:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Highmark-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68e893130da99000e5e241525d51c2bd5393f6150c8f36133fdea3592e96b7a3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.highmarkcos.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>GREENBALL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27271</link>
<guid>ca172848cbc21794bac4f7ba9333fa5f</guid>
<pubDate>Thu, 20 Nov 2025 17:16:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GREENBALL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8d1ca128471be2ee6e74b8ebca634a2186d1d374d4053e8d548c3cb9f30fde7b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>-WELLBIZBRANDS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27274</link>
<guid>c712cafa19f7f3dfbd8a72abeac78ec8</guid>
<pubDate>Thu, 20 Nov 2025 17:13:22 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>-WELLBIZBRANDS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2afdd6abc476327644bb2beee8ccfc8925ab817ebd775ae2d1ca6118c229cb41</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>DOONEY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27275</link>
<guid>3279e1d4c83720ed7e4b99f98b26feb1</guid>
<pubDate>Thu, 20 Nov 2025 17:12:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>DOONEY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62404a89e98216e04b4a9e3f05ea6652ea3e063d5a9b2f08a9e22b17ef06d49f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>SIU.EDU-EBS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27276</link>
<guid>c4a5846ea90782929bf365eeec1eaa6d</guid>
<pubDate>Thu, 20 Nov 2025 17:12:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>SIU.EDU-EBS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07b9a47d6fe5e466bdbfe5543dcef10de5dfa2be36648b4e26270a46d887f0e8</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FRUIT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27247</link>
<guid>6a45c2b39692eedbfd0b378c47a5a693</guid>
<pubDate>Thu, 20 Nov 2025 16:47:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FRUIT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>778e287ebe5d091756906554097a8bea68777f2e86124b8abd5b2821f69c863d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FRONTROL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27248</link>
<guid>299024cfe2cd92197e0ab02d2421285c</guid>
<pubDate>Thu, 20 Nov 2025 16:47:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FRONTROL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>466c8b5e4cefffb3dff31780461e6fdc53b8cdc9d1b1017bb86b5a5f0b5e8080</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HUMANA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27249</link>
<guid>ff99dc2d99ab4c337ff158793b47bee6</guid>
<pubDate>Thu, 20 Nov 2025 16:46:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HUMANA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3b8cf912a8335123bb1d5715ffffb9722dcb3b2fa86768ae9daf86cc8dcd253</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ORACLE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27250</link>
<guid>374cad868cb62202053d308252bc4040</guid>
<pubDate>Thu, 20 Nov 2025 16:46:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ORACLE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9bcdedbc60dfd1f99ad46873d8b077f3f7d8d27acea9ccad916329c0a74e9776</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ABBOTT.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27251</link>
<guid>e5beda486259643c262e6fd24aa3ca88</guid>
<pubDate>Thu, 20 Nov 2025 16:45:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ABBOTT.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33ea3b88e1bf829bd9b9a82b4aa4ee02360c6c1ae958cc21875b51c791d9c3e0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BECHTEL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27257</link>
<guid>f590ad7f681d5cf0b57f2a38f4874883</guid>
<pubDate>Thu, 20 Nov 2025 16:42:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BECHTEL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>951a78340b507548882d9b85ffaab897595535906d8c38d7a10a112aa952d59b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ELCOMPANIES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27258</link>
<guid>aaea30db7c8b270df7a0f70f92db0ab3</guid>
<pubDate>Thu, 20 Nov 2025 16:42:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ELCOMPANIES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7799b5893e01eb0275306eb2bc65cba7acd6838c8a230b008a7d5931781eb01</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>RIDERTA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27259</link>
<guid>60fbbc1c544a895285294af287c36db8</guid>
<pubDate>Thu, 20 Nov 2025 16:41:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>RIDERTA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3187b4074be0b24dd2902bedd46b0f3287692c436fd1e773e03494cd3e99dcab</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BROADCOM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27260</link>
<guid>241f5934168d13edc6d3990fe5ddde40</guid>
<pubDate>Thu, 20 Nov 2025 16:41:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BROADCOM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4059ff5adaadc68b465673c5d0be239590cee185d8c6d69140665512be082625</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wright-ArchitecturalMillwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27279</link>
<guid>8f1132db5edd938b22f6167b7f67d82b</guid>
<pubDate>Thu, 20 Nov 2025 16:41:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wright-ArchitecturalMillwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fdf0012087e9407111d49874146b978b010efab91c20f66ec8aae20f8a131a2</i><br /><br />Threat actor <b>description</b>: <i>Wright Architectural Millwork specializes in high-quality archite
ctural woodwork and has been in the industry for 50 years. 

We will upload 87gb of corporate documents soon. Employee persona
l information (passport numbers, driver licenses, phones, emails)
, financials, a bit of client data, contracts and agreements, NDA
, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Swift-Filters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27280</link>
<guid>7144e2ba113bacdd760b73ae7478c74e</guid>
<pubDate>Thu, 20 Nov 2025 16:40:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Swift-Filters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89b9a170e918f6bc372ceca1a628c452e80a1dc7607e5fef2eb3040e3b9e1bbb</i><br /><br />Threat actor <b>description</b>: <i>Swift Filters is a leading US manufacturer of high-quality hydrau
lic filter elements, offering a wide range of replacement filters
for various brands including Parker Hannifin, Pall, and Donaldso
n.

We will upload 140gb of corporate documents soon. Employee person
al files, financials, client data, contracts, NDA, projects, draw
ings and specification, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>A10NETWORKS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27261</link>
<guid>d9a63503ec814c2c1f9a594b15679eb4</guid>
<pubDate>Thu, 20 Nov 2025 16:40:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>A10NETWORKS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d01c9030ec72da07ab0544c8cd6a6df4a1bce2d718d372fb239297fd5dea978d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENVOY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27262</link>
<guid>f7abe7d1372d2d2d0c15f1410e699b25</guid>
<pubDate>Thu, 20 Nov 2025 16:40:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ENVOY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d32fd937198261f3023bcd84d4668d1266cdca2f66131851d36d547497ab017f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MAZDAUSA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27265</link>
<guid>bbd4e463fe0ad675dcb2493d8abd6b0b</guid>
<pubDate>Thu, 20 Nov 2025 16:38:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MAZDAUSA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7716bba076a78214068851d70ff30293657824da84854dcd26ed4e041a1300a5</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LLPRODUCTS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27267</link>
<guid>1602c2b2b3692f45f9c6f00e435bdde5</guid>
<pubDate>Thu, 20 Nov 2025 16:31:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LLPRODUCTS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1c906d224d65cff6ec1ca3516b536a411a123fb0d42613e77d24c8d45f8799c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>PHOENIX.EDU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27269</link>
<guid>0139266877771d61f301725cd29cdb86</guid>
<pubDate>Thu, 20 Nov 2025 16:30:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>PHOENIX.EDU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c4f04707d90f7c9fc4b1730fcf13eccd2834ed92314190791146e09ae76a84f0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Teamglobal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27278</link>
<guid>f6be712d932810d3b2dd67e494cb78df</guid>
<pubDate>Thu, 20 Nov 2025 16:18:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>morpheus</b> claims attack for <b>Teamglobal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>572a979ec20ff25ea1c786ef64b0bdd88c091f41109914a15367c96a3e94c185</i><br /><br />Threat actor <b>description</b>: <i>Website:  teamglobal.com

Revenue: $6.3 Million

Premier contract and direct hire staffing services. 30 years of industry experience in aerospace and light industrial and an extensive client list.

**</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>morpheus</category>
</item>
<item xmlns:dc='ns:1'>
<title>AJ-Jersey</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27242</link>
<guid>e0b8da96bad1458e5d78007b9e2d38c4</guid>
<pubDate>Thu, 20 Nov 2025 14:28:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>AJ-Jersey</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f39de731474c62743974dcc343f131918d9c4ed7828e60c45a3460ca7a1b27a</i><br /><br />Threat actor <b>description</b>: <i>AJ Jersey Inc. is an industry leader in Forklift Sales, Forklift Rentals, Forklift Service and all of your Material Handling needs.We will upload almost 22gb of corporate documents soon. Employee personal data (driver licenses of 73 employees, detailed health reports with DOB, phones, emails and so on), financials and accounting, client files, contracts, specifications, projects, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Croft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27236</link>
<guid>5a18b2b3a647804eec32e380a70ba66f</guid>
<pubDate>Wed, 19 Nov 2025 20:14:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Croft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>574cda67c41fd3cb879d0a55931cee2da491827316a3f44d7e490f6710759cbf</i><br /><br />Threat actor <b>description</b>: <i>Croft is a leading window and door company specializing in energy-efficient vinyl and aluminum products, including a variety of windows and patio doors. With a commitment to quality and innovation, the company has built a reputation as one of the largest and most reliable suppliers in the industry since its establishment in 1920. Croft's offerings are designed to enhance comfort and energy savings for homeowners, making them an ideal choice for those seeking high-performance solutions. The company caters to both individual customers and certified dealers in the market.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Trust-Administrators</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27227</link>
<guid>0ea841a00684473af118beb024287ce3</guid>
<pubDate>Wed, 19 Nov 2025 16:39:21 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>American-Trust-Administrators</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3eee6dd824363aa68bbb386ddad1715e397818c3dc5118ecc272c4b2458ccbba</i><br /><br />Threat actor <b>description</b>: <i>American Trust Administrators, Inc. (ATA) is a national leader in
the administration and management of employee benefit plans.

We will upload almost 143gb of corporate documents soon. As you c
an understand there are a lot of HR files, confidentiality agreem
ents, detailed financials and accounting, lots of client files, p
rojects, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Orchid-Island-Golf-and-Beach-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27228</link>
<guid>ec341a16d2ebfd5bd5954296bd261ffc</guid>
<pubDate>Wed, 19 Nov 2025 15:50:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Orchid-Island-Golf-and-Beach-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82bfd49529a0d4cd535309f9d51a8e143333fb30acda94ecf6a11843cff64a9f</i><br /><br />Threat actor <b>description</b>: <i>Orchid Island Golf and Beach Club is a member-owned golf communit
y located in Vero Beach, Florida, nestled between the Atlantic Oc
ean and the Indian River.

We will upload almost 20gb of corporate documents soon. Employee 
data (driver licenses, phones, addresses), confidential files, fi
nancials and accounting, contracts and agreements, clients' infor
mation, NDA, projects, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Modern-Display</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27229</link>
<guid>7200be166920d491d01df95989e20999</guid>
<pubDate>Wed, 19 Nov 2025 15:50:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Modern-Display</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2134e68c55f377cdb249ee8fda8ffbda3e0459bdd4da549365384f48cf1c5e55</i><br /><br />Threat actor <b>description</b>: <i>Modern Display specializes in providing exquisite seasonal decor,
collectibles, and thoughtful gifts suitable for every occasion.

We will upload almost 20gb of corporate documents soon. Employee 
data, confidentiality agreements, detailed financials and account
ing, contracts with Disney and other widely known companies, clie
nt data, lots of projects, drawings and specification, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-InterTech-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27226</link>
<guid>29d750e5ac458ca572dfe267436a847f</guid>
<pubDate>Wed, 19 Nov 2025 15:23:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-InterTech-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ecfa3dae2eb29b7ff907d9cd48dd383570b03bfacd2c8780337515ff422817f</i><br /><br />Threat actor <b>description</b>: <i>The InterTech Group is a holding company based in North Charleston, South Carolina, focused on investments, diversification, and opportunity creation.We will upload 17gb of corporate documents soon. Detailed personal employee data (SSNs, passports, driver licenses, Mexican ID's, personal phones, addresses, addresses emails), employee relativesdata will be available as well, confidentiality agreements, financials and accounting, contracts and agreements, clients' information, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>CYTIVALIFESCIENCES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27212</link>
<guid>b841314f665bb44d5aeea2d40a193c17</guid>
<pubDate>Wed, 19 Nov 2025 14:44:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CYTIVALIFESCIENCES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca71bdd2b71bd1bcad1f538f9e28b59fa8c5f17e0572b16fdcc576fe1a981653</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pearl-River-Valley-Electric-Power-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27230</link>
<guid>fa980e7b000b6545a4c0c5373eb1b7f3</guid>
<pubDate>Wed, 19 Nov 2025 14:44:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pearl-River-Valley-Electric-Power-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08b7ce07640eff38c9b33c7705b105af73cb4091f42e7c9c7fa861154d704948</i><br /><br />Threat actor <b>description</b>: <i>PRVEPA is an electric cooperative dedicated to providing safe, de
pendable, and affordable power to the residents of South-Central 
Mississippi since 1938.

We will upload 62gb of corporate documents soon. Employee data (d
river licenses, phones, addresses, emails), confidential technolo
gies, financials and accounting, contracts and agreements, client
s' information, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>NCH.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27213</link>
<guid>5ec67ad4f910b37110d81f2b3a72720a</guid>
<pubDate>Wed, 19 Nov 2025 14:43:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>NCH.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f51f05e8128bcba5967fb1b148a1f438dde4a76062dacc26d42c355e9ab008dc</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENOVIS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27214</link>
<guid>08e546f8f607177ace79a17856033516</guid>
<pubDate>Wed, 19 Nov 2025 14:43:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ENOVIS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f52689058f83b16d4dc5ef6a75348c46d92a52204a04c6ea651704059ec70f4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ELKAY.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27215</link>
<guid>b51ecba56e03d4181e0006ff1e8a5355</guid>
<pubDate>Wed, 19 Nov 2025 14:42:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ELKAY.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>206eed4aa8ba9b1cc171133f91bda35c9e9b42a6fea131136cc6c66e54554c2f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LIFEFITNESS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27216</link>
<guid>617eed14b937d3e2c5cec24f79eb134d</guid>
<pubDate>Wed, 19 Nov 2025 14:42:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LIFEFITNESS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f53af038735b2f2ca945289d93f9507357cde66d6354578b2b500184997581b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TULANE.EDU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27217</link>
<guid>ea2c6871f6c0a711fe98331e411daa42</guid>
<pubDate>Wed, 19 Nov 2025 14:41:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>TULANE.EDU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f61723ac8af88f88790c77604b4c4cce607e5c6d07f4ffa75ae8e88cf2821763</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>RFSUNY.ORG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27218</link>
<guid>214a793090ffcaee487d7c0e1d5d23b0</guid>
<pubDate>Wed, 19 Nov 2025 14:40:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>RFSUNY.ORG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c91bb89a09627ad0ba186364a8884cf5e72b09195b10df4a0b7e34bc530489d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>BELFUSE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27219</link>
<guid>42a33d4150a53ec0160e9cad6f13b923</guid>
<pubDate>Wed, 19 Nov 2025 14:40:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>BELFUSE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef979603111a61210c5d4525b1a7d6ef566d8c7092bd37e255acbbf2943496da</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GARLANDISDSCHOOLS.NET</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27220</link>
<guid>6b3575c997eb8e46e71f91752bdfe41e</guid>
<pubDate>Wed, 19 Nov 2025 14:39:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GARLANDISDSCHOOLS.NET</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb81cd9d6550a8c02964506790469ce0d2abe3b24307e7fb66d92e7f9b8ced7c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>AVAILINFRA.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27221</link>
<guid>b08fd3752ae338af086a4369611fa83f</guid>
<pubDate>Wed, 19 Nov 2025 14:38:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>AVAILINFRA.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76f21c322886edc068cb7dc63683b9fe5d6e248e5305fc9e151e2f435c136fe7</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Perry-Brothers-Oil</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27222</link>
<guid>2bdc37abe64e30f5670fc891a5c83308</guid>
<pubDate>Wed, 19 Nov 2025 14:24:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Perry-Brothers-Oil</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af91a58747ae577a857e7be82608f53fa8161ab7e02d6c9862ecbcea4bbcda5a</i><br /><br />Threat actor <b>description</b>: <i>Perry Brothers Oil Company is an automotive shop specializing in tires, motor oil, and wheel alignments. We will upload 20gb of corporate documents soon. Personal employee and customers data (passports, driver licenses, personal phones, addresses, addresses emails, credit card records), confidentiality agreements, detailed financials and accounting, contracts andagreements, clients' information, incident reports, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>reidhurstnagy.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27231</link>
<guid>7a3989037ec79ff52a7c83c330874a5c</guid>
<pubDate>Wed, 19 Nov 2025 13:46:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>reidhurstnagy.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5bdd908fef8b300f39645db16cbd564fb8990bcd8e7b089b1efc455eea4ca22</i><br /><br />Threat actor <b>description</b>: <i>RHN CPA is a full-service accounting firm that provides diverse accounting services to various clients including businesses, First Nations, not-for-profit organizations, and individuals across the Lower Mainland and Okanagan. The firm is committed to delivering superior accounting and related services that enhance clients' quality of life, while fostering a supportive and flexible environment for its employees. With a focus on accessibility and personalized service, RHN CPA builds strong relationships with clients to support their growth and success. Their offerings include bookkeeping, tax preparation, and financial advisory services tailored to meet the unique needs of their community.</i><br />Target victim <b>website</b>: <i>reidhurstnagy.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>mcchemical.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27233</link>
<guid>f599aac605e05f944669afe5c1b79375</guid>
<pubDate>Wed, 19 Nov 2025 13:43:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>mcchemical.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b60ffa7e64c6b3614929dfa117c55a83757a5ece657d45fc5c34c0b4e9a089b</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 200k
80gb</i><br />Target victim <b>website</b>: <i>mcchemical.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cardinal-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27225</link>
<guid>204febcbbc5ee18b88a7c4680f293c19</guid>
<pubDate>Wed, 19 Nov 2025 13:25:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cardinal-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71113fcace63f9c7239f0a487c2a0638be2312a54e01be450ffed3e7b3f94dfb</i><br /><br />Threat actor <b>description</b>: <i>Cardinal Services, based in New Iberia, LA, is a leading oilfieldservice company specializing in land and offshore services.We will upload 90gb of corporate documents soon. Personal employee files (driver licenses, phones, addresses, emails, credit card details), financials and accounting, contracts and agreements, clients' information, incident reports, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stoss-Landscape-Urbanism</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27211</link>
<guid>27e2633066b399616dbb49c89802ecbb</guid>
<pubDate>Wed, 19 Nov 2025 10:47:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Stoss-Landscape-Urbanism</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dad551d17dcf416a303501ad5f0bd281c19ca9dfd2b4e4b5163cef29f818bf4e</i><br /><br />Threat actor <b>description</b>: <i>Stoss Landscape Urbanism specializes in designing landscapes and 
social spaces that promote resilience, vitality, and equity. Thei
r projects encompass a variety of sectors including downtown plaz
as, parks, waterfronts, campus institutions, and mixed-use reside
ntial areas.

We are ready to upload more than 76GB data. You will find employe
es and customers information (passports, Social Security Numbers,
emails, phones) confidential information, NDAs and other documen
ts with detailed personal information. 
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marine-Foods-Express-LTD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27210</link>
<guid>817bc5291463f8c993dd1d46eca2bd0d</guid>
<pubDate>Wed, 19 Nov 2025 10:24:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Marine-Foods-Express-LTD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf3cb022bd2a691872ce055640c4c46965ac19c636816796f9688b2c90a50a9e</i><br /><br />Threat actor <b>description</b>: <i>Food & Beverage</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Genrose-Stone--Tile</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27207</link>
<guid>f51cfc97dcd19892b6000e77f976bbf1</guid>
<pubDate>Wed, 19 Nov 2025 00:38:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Genrose-Stone--Tile</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97fb83cab4cf86d813e76e79d4cb12f6bc9c9567df962ba732a50e147eccfdf1</i><br /><br />Threat actor <b>description</b>: <i>Since 1988, we have been working together with homeowners, architects, and designers to bring ideas to life. Our core purpose is to inspire excitement through innovative products and support. At GENROSE Stone + Tile, we not only provide premium stone and tile for your project, we also look for ways to serve your best interests. Service and support are the foundations of the GENROSE brand, and your needs, creative vision, and long-term satisfaction are always our first priority. That's the difference we make every day. We search the world for the most beautiful natural stone and stay in step with fashion trends and technical innovations in interior design. With a very careful eye on style, quality and durability we source, import, and stock over 300 varieties of stone slabs and literally thousands of tile options. With our handcrafted tiles we can make any shape and any color tile in our manufacturing plant right in Connecticut to fulfill your vision. </i><br />Target victim <b>website</b>: <i>www.genrose.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>heywood.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27206</link>
<guid>faab108793e96f5c822ff32c527f66ca</guid>
<pubDate>Wed, 19 Nov 2025 00:38:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>heywood.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c83a0ce415ee4e931fc26f0bf3d85b64a68ac29afa592d46f9ed85a4d146efcc</i><br /><br />Threat actor <b>description</b>: <i>A member of the Heywood Healthcare system, Heywood Hospital is an acute care hospital in Gardner, MA, providing a broad range of high quality medical, surgical, obstetrical, pediatric and behavioral health services on an inpatient and outpatient basis.</i><br />Target victim <b>website</b>: <i>heywood.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>grandeprairie.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27191</link>
<guid>9d02d64b8e1ef4389b2ca1f4c19b2497</guid>
<pubDate>Tue, 18 Nov 2025 18:45:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>grandeprairie.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d6c8c549b57daa9e99dc58148166079ab4b1c9de29eaef731ab9ae4583bb8b8e</i><br /><br />Threat actor <b>description</b>: <i>Grande Prairie Public Library offers a variety of services including room reservations, notary public services, exam proctoring, and technology assistance. The library provides resources for all ages, including youth, teens, and adults, with access to eBooks, audiobooks, and educational databases. They also partner with Tutor.com to offer live virtual tutoring services. The intended clients are community members seeking educational resources, technology support, and recreational activities Employees: 50 Revenue: $5 Million Industry: Hospitality   Phone Number: (708) 798-5563</i><br />Target victim <b>website</b>: <i>grandeprairie.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bleyl-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27190</link>
<guid>3125b62f0e477cfdfbc779a31de3beb6</guid>
<pubDate>Tue, 18 Nov 2025 18:24:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bleyl-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cac5275e91e558679cf9de4feb3a6e3a0e8576b6f57bc0cefc7f908b33e768b0</i><br /><br />Threat actor <b>description</b>: <i>Bleyl Engineering is a Consulting Civil Engineering firm based inConroe, Texas and with offices in Bryan - College Station, Austin, and Houston.We will upload 25gb of corporate documents soon. Lots of employeepersonal files (passports, driver licenses, SSNs, phones, addresses, email addresses, credit card details), detailed financials, contracts and agreements, clients' information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>zadroinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27196</link>
<guid>7dea0e3bf353aa76b7af76ad8b70b186</guid>
<pubDate>Tue, 18 Nov 2025 18:23:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>zadroinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc3a098c8718fd333452aff89f393bd938315b7ddc04ad4b5551f6b54d88bcd7</i><br /><br />Threat actor <b>description</b>: <i>Zadro Inc. is a California-based beauty, health, and wellness brand with over 37 years of experience in creating innovative products. Specializing in advanced technology and holding more than 40 patents, the company offers a range of items including makeup mirrors, towel warmers, massagers, and aromatherapy products. Its intended clients include individuals seeking to enhance their daily routines and achieve spa-like comfort at home. With a commitment to quality and customer satisfaction, Zadro Inc. has established itself as a trusted brand in the wellness and beauty industry. Employees: 200 Revenue: $11.9 Million Industry: Retail Phone Number: (714) 892-9200</i><br />Target victim <b>website</b>: <i>zadroinc.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>General-Distributing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27185</link>
<guid>cc7895156592259f3ca4d789cb629260</guid>
<pubDate>Tue, 18 Nov 2025 15:20:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>General-Distributing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80911d123ac29e8ebfdafd6eb673be55a8e3c3a9fea0869c21903afe1f1dad6b</i><br /><br />Threat actor <b>description</b>: <i>General Distributing Co is a company that operates in the Convenience Stores, Gas Stations & Liquor Stores industry. It employs 100to249 people and has 25Mto50M of revenue. The company is headquartered in Salt Lake City, Utah.
company is headquartered in 5350 W Amelia Earhart Drive, Salt Lake City, UT 84116, USA.
168 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nationwide-Legal-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27188</link>
<guid>82cc164ceb375988c7ccc91b0b98c08c</guid>
<pubDate>Tue, 18 Nov 2025 15:20:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Nationwide-Legal-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>952620b84c06eefbf809aeacfa5afed772776c6db575627b7e3ee48f8abaa2e9</i><br /><br />Threat actor <b>description</b>: <i>Nationwide Legal LLC is a leading litigation support and legal services company based in Los Angeles, California, serving clients across the United States. The company provides a wide range of professional services, including process serving, e-filing, court reporting, document duplication, investigations, and subpoena preparation. With the motto “where technology meets experience,” Nationwide Legal focuses on combining advanced digital solutions with decades of industry expertise to ensure accuracy, speed, and reliability in every task. The company supports law firms, corporations, and government agencies by streamlining legal processes and improving overall efficiency in complex litigation workflows.
company is headquartered in The headquarters address of Nationwide Legal LLC is 1609 James M Wood Blvd, Los Angeles, CA 90015, United States.
501-1,000 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>QuaLex-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27181</link>
<guid>71dc407af5ad9f5e2a8513886d398f8b</guid>
<pubDate>Tue, 18 Nov 2025 13:23:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>QuaLex-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d9477a7f0dc64c1826a068050782628af7bcdb477d3a988adca44ce7ef64153</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smoll--Banning-CPAs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27180</link>
<guid>50f09698c0bb749bdebded62c26516ac</guid>
<pubDate>Tue, 18 Nov 2025 02:48:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Smoll--Banning-CPAs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93765cdc23c0d275df9b0afba9a792297e579a1cac7bc0bf6a2e78736f8e25e5</i><br /><br />Threat actor <b>description</b>: <i>Smoll & Banning, CPAs Smoll & Banning, CPA's, LLC is an independent accounting firm located in Dodge City, Kansas.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kdr-Real-Estate-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27174</link>
<guid>c19fa3728a347ac2a373dbb5c44ba1c2</guid>
<pubDate>Mon, 17 Nov 2025 21:24:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kdr-Real-Estate-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e52fcceb00056319f343c4d95ffb1523062d34d2f8234d357ddc00ded3cefff2</i><br /><br />Threat actor <b>description</b>: <i>Real Estate</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Air-Design-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27176</link>
<guid>312e53ccba0b2ddfefd4a1f05b55bcdd</guid>
<pubDate>Mon, 17 Nov 2025 20:25:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Air-Design-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe4e15f12acaacad32ea4bf4815d7655777b63c4c581f3ac2fde3e50a4452d3d</i><br /><br />Threat actor <b>description</b>: <i>Air Design Systems, Inc. is a woman-owned business based in the Chicago area, specializing in complete ventilation solutions since 1977. They offer services such as Building Information Modeling, fabrication, and design assistance, catering to markets including healthcare, education, and commercial projects. The company is recognized for its commitment to innovation, quality, and safety, having received multiple awards for its exemplary safety programs and subcontractor excellence. With a focus on advanced technology and 3D coordination, Air Design Systems aims to provide high-quality infrastructure for successful project outcomes.</i><br />Target victim <b>website</b>: <i>www.airdesignsystems.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lincoln-IT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27177</link>
<guid>2e34e565526802985f40f7c11146406d</guid>
<pubDate>Mon, 17 Nov 2025 20:25:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lincoln-IT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8692fc69b3e9cecc1dbc16ed06e531c39fe44ffb4a981fcfa31afe6fa160e7cc</i><br /><br />Threat actor <b>description</b>: <i>Gregory N. Mirsky is an AWS certified solutions architect and security specialist with extensive experience in optimizing cloud infrastructure and applications. He specializes in cloud migration, cybersecurity compliance, and implementing modern application architectures, such as serverless and containerized solutions. His targeted clients include companies seeking to enhance their IT security and operational efficiency, as well as those in need of infrastructure modernization. With a strong background in collaboration between technology teams, Mirsky offers holistic and strategic approaches to systems design.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>H-G-Reynolds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27178</link>
<guid>de9d696001c1d17877d1dde0d35ffa41</guid>
<pubDate>Mon, 17 Nov 2025 20:25:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>H-G-Reynolds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1c7a999549cde788ac467d1d78a6e3ec4affbff837a4765cd3793f2544b9d93</i><br /><br />Threat actor <b>description</b>: <i>H.G. Reynolds is a full-service construction management company specializing in the development of K-12 school facilities in the southeastern United States. With over 70 years of experience, the firm emphasizes maintaining long-term relationships with clients and positively impacting local communities through state-of-the-art educational spaces. Their range of services includes management planning, preconstruction services, quality control, and safety. H.G. Reynolds aims to enhance educational infrastructure while contributing to local economic growth.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charles-Rutenberg-Realty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27163</link>
<guid>5236d2d466e7a1d9785a33e298a58c3c</guid>
<pubDate>Mon, 17 Nov 2025 18:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Charles-Rutenberg-Realty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38a130c853a696e9b1480b410e1b0e5917fb1d4010748504014a7832b4b9ff95</i><br /><br />Threat actor <b>description</b>: <i>Charles Rutenberg Realty, Inc., servicing Pinellas, Pasco, Hillsborough, & Hernando County real estate.We will upload 91gb of corporate documents soon. Their downloads folder contains so many personal docs (more than 1,5gb of just scanned docs), (passports, driver licenses, SSNs, phones, addresses, email addresses, credit card details, employee headshots), financials, contracts and agreements, NDA, clients' information, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Poes-Accounting-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27172</link>
<guid>5387241957e449ab627283e8fb027d76</guid>
<pubDate>Mon, 17 Nov 2025 17:37:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Poes-Accounting-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1928d2a3fc26552f2a30ecd208df5d37deba434090cfcb714aab9333b666670</i><br /><br />Threat actor <b>description</b>: <i>Accounting services and tax return preparation</i><br />Target victim <b>website</b>: <i>poecpas.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quinn-Jay-Patent</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27173</link>
<guid>f7f62619bfc41df6707311b79ab5e3e6</guid>
<pubDate>Mon, 17 Nov 2025 17:37:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Quinn-Jay-Patent</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0c59ccad63e455b7996d7e4dd2715311287d52b7d644b51bd87225d30877379</i><br /><br />Threat actor <b>description</b>: <i>Drawing services for the intellectual property community</i><br />Target victim <b>website</b>: <i>quinnjaypatent.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Office-of-Ronald-W.-Hillberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27171</link>
<guid>e3fe004c8a465494fcb14db3bb9f0ee1</guid>
<pubDate>Mon, 17 Nov 2025 17:36:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Law-Office-of-Ronald-W.-Hillberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a4fa1640d225e61604c3bc46186d3770396b93a008503208cf9e2f8aa350574</i><br /><br />Threat actor <b>description</b>: <i>Estate planning and wills</i><br />Target victim <b>website</b>: <i>hillberglaw.biz</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eagle-Oil--Gas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27161</link>
<guid>0524bbc7d57d3edbd146cb19bbd4d1f2</guid>
<pubDate>Mon, 17 Nov 2025 16:24:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Eagle-Oil--Gas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce169a72e728ff9a18a5cdd10c7cdfc01b6aa66b042590619d0a8cee7187fc08</i><br /><br />Threat actor <b>description</b>: <i>Eagle Oil & Gas operates and manages its own properties and the assets of other companies, focusing on drilling new wells and optimizing legacy assets.We will upload 70gb of corporate documents soon. Employee personal documents (scanned passports, driver licenses, SSNs, phones, addresses, email addresses, credit card payment details and so on),confidential contracts and agreements, NDA, and other client's files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ARH-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27162</link>
<guid>818a7cd413218993d9f871449f4e3321</guid>
<pubDate>Mon, 17 Nov 2025 16:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ARH-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c56cada0d0c2f46a5acd07d5dfc5d184b3624a0be1689c23cf3ef6e69986bcaf</i><br /><br />Threat actor <b>description</b>: <i>ARH is an award-winning design engineering firm specializing in surveying, professional planning, environmental sciences, and GIS technologies.We will upload more than 12gb of corporate documents soon. Employee personal documents (scanned passports, driver licenses, SSNs, phones, addresses, email addresses, credit card details and so on), financials, contracts and agreements, NDA, client personal information, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>UNDER-ARMOUR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27169</link>
<guid>157d9f8e3592c76c244fa8f0327a04c0</guid>
<pubDate>Mon, 17 Nov 2025 16:13:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>UNDER-ARMOUR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9c74f69649ffa449435dfff954ca18336d5d0627c920608b5b41cd9e378e8cb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Under Armour, Inc. is an American multinational corporation founded in 1996 by Kevin Plank. The company specializes in manufacturing and selling branded performance apparel, footwear, and accessories. Its products are engineered with innovative technologies to mitigate the impact of environmental conditions on physical activities. Headquartered in Baltimore, Maryland, it caters extensively to the sports industry globally.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>BOLD-Furniture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27154</link>
<guid>7b3b85acc94d2df9ba27b7188e30d667</guid>
<pubDate>Mon, 17 Nov 2025 12:24:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>BOLD-Furniture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5649e1f1bdf723ad873a6893939f7d5033c49e7ec62747a37189427aca6a4a84</i><br /><br />Threat actor <b>description</b>: <i>BOLD Furniture manufactures distinctive, highly functional and adaptable standard and custom furniture and fixtures for all kinds of work environments.We are going to upload company data soon. You will find financialdata (audit, invoices), project details, personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MOBI-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27155</link>
<guid>08bf786cb3b22d313ee37f93586a24f4</guid>
<pubDate>Mon, 17 Nov 2025 12:24:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MOBI-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdb8cee32be4a83f43a348303fb679d9f313406c943a479610c90d642cd4e84e</i><br /><br />Threat actor <b>description</b>: <i>MOBI Technologies Inc. is a consumer health and home electronics brand committed to elevating the consumer experience around digital living and wellness monitoring for all ages. We are going to upload company data soon. You will find financialdata (audit, payment details, invoices), personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Enterprise-Fund</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27151</link>
<guid>fc83b39f9ff554b393188dbc36e3f835</guid>
<pubDate>Sun, 16 Nov 2025 16:13:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>United-Enterprise-Fund</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f27030a6b17f32d5f4967e244a299383e509b5b5726b0e72a1733080f84e87ae</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/united-enterprise-fund-lp/104726614 www.unitedenterprisefund.com United Enterprise Fund is a New Yorkbased financial services firm that delivers personalized investment management and advisory solutions. The company specializes in helping clients pursue long-term financial objectives through strategic investment planning and risk management. Operating from the heart of the financial district, United Enterprise Fund combines tailored planning with market insight to support sustainable financial outcomes.</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Horst-Realty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27146</link>
<guid>4064e4d885e4be966c600e071394c636</guid>
<pubDate>Sat, 15 Nov 2025 15:51:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>brotherhood</b> claims attack for <b>Horst-Realty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8f4c2797aafe72cada7373d68b0501f87ce3a8f1ad55380e6355a416b7e0c7e</i><br /><br />Threat actor <b>description</b>: <i>Contains: 27 Gb compressed Files, Emails</i><br />Target victim <b>website</b>: <i>www.horstrealty.com</i>]]></description>
<category>brotherhood</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spoleta-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27145</link>
<guid>b5628fed964d280aab18f11d1afcd3fe</guid>
<pubDate>Sat, 15 Nov 2025 15:51:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>brotherhood</b> claims attack for <b>Spoleta-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0360092167c9917c44555c99f2be7c7d5a60625c78476129e2e3a6339a2bb3c3</i><br /><br />Threat actor <b>description</b>: <i>Contains: 4 Gb compressed Free Files + 33 Gb compressed Paid Files, Database</i><br />Target victim <b>website</b>: <i>spoleta.com</i>]]></description>
<category>brotherhood</category>
</item>
<item xmlns:dc='ns:1'>
<title>Force-Brokerage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27133</link>
<guid>a7c2fa485508eb3890858493a5c7ed8b</guid>
<pubDate>Sat, 15 Nov 2025 12:02:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Force-Brokerage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28121e4a129507e83f3469d81d3c9e7bc98e8fc9d852f37ba75b0b0e5d357157</i><br /><br />Threat actor <b>description</b>: <i>Price ??? Disclosures 0/1</i><br />Target victim <b>website</b>: <i>forcebrokerage.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sol-Trading</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27129</link>
<guid>a7282c84a4c2109c3697b6aca8b86aba</guid>
<pubDate>Fri, 14 Nov 2025 23:24:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sol-Trading</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>481f686d4238a4a0130376afa0583419256ac3f45c14457d835af35b4e3eb4a9</i><br /><br />Threat actor <b>description</b>: <i>Grocery Retail</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>killinglyschools.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27131</link>
<guid>6a7c8b3c6b0ecb1b72233e98c09793f4</guid>
<pubDate>Fri, 14 Nov 2025 22:18:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>killinglyschools.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e218709dc47cae971d25e949dbba08ac867a1b2d56a5170fb67e3c206f2e398</i><br /><br />Threat actor <b>description</b>: <i>Killingly Public Schools is a K-12 public school district based in Danielson, Connecticut, serving students in the town of Killingly. …</i><br />Target victim <b>website</b>: <i>killinglyschools.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>eakas.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27130</link>
<guid>64998e5967db4db4bf25df2128c87c10</guid>
<pubDate>Fri, 14 Nov 2025 21:46:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>eakas.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a469edaab6b86b4ed72ba09a18b141895d7fbf5506dc106cc412e38fd98aae05</i><br /><br />Threat actor <b>description</b>: <i>Eakas Corp. specializes in producing both functional and decorative products for the automotive industry, serving as a Tier 1 supplier to manufacturers in the United States. They offer comprehensive services including engineering, injection molding, painting, chrome plating, assembly, and quality testing to ensure consistent product quality. Their product range includes various automotive components such as door handles, bumper fascias, and mirror assemblies. Eakas is committed to customer satisfaction by delivering quality services on time and at competitive prices. Employees: 416 Revenue: $81.3 Million Industry: Manufacturing  Phone Number: (815) 223-8811 phone site x236 (cell:870-208-5643) 248-536-2211 815-488-1879 x208 / 815-713-0753 (815) 223-8811 248-536-2211 248-536-2211 x224 (cell:815-830-6497) x218 (cell:815-875-7241) 248-536-2211 815-719-2814 815-713-0753 homePhone: 815-497-2023 5135921045 </i><br />Target victim <b>website</b>: <i>eakas.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jefferson-Enterprises-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27116</link>
<guid>41b7a4257befb2e8999eb01cb3b376b0</guid>
<pubDate>Fri, 14 Nov 2025 18:24:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Jefferson-Enterprises-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c07b8dc33c77035e6df8e28d7189c96469642d74f230444ce616825c46b80bac</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Platinum-Healthcare-Staffing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27117</link>
<guid>9aea3c940f8665926c97b3d3c64ace44</guid>
<pubDate>Fri, 14 Nov 2025 18:24:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Platinum-Healthcare-Staffing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55a9760ae3aba8acc34914ab0966e8e4005e67a1e0563cb0ad4c16e611c44c9a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Herman--Chamow</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27119</link>
<guid>ececd3cff01bb6137f0578be5337a5f2</guid>
<pubDate>Fri, 14 Nov 2025 18:24:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Herman--Chamow</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d77c3f671bee8a3268369f859f52a3b23d5149c5db8df832c0ca098695b80fa4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aero-Precision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27120</link>
<guid>0121fc02bb750488e774fff937545734</guid>
<pubDate>Fri, 14 Nov 2025 18:24:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Aero-Precision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b448c7266c7672f210ddff8b7735f6b26da3c848a09f02e59e9954b192aa8d0</i><br /><br />Threat actor <b>description</b>: <i>Aero Precision is a firearm and components manufacturer.We will upload 24gb corporate documents soon. Employee information, project details, contracts and agreements, NDAs, specifications, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Banks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27121</link>
<guid>79ab793439aeaf01b4e2c8d4ceab0b70</guid>
<pubDate>Fri, 14 Nov 2025 18:24:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Valley-Banks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6d3861892962ef78e651bf823a1bfe84852dc85568c0ed95b14e281e3880b70</i><br /><br />Threat actor <b>description</b>: <i>Valley Bank is a state chartered community bank, with branches inRonan, Arlee, Hot Springs, Thompson Falls, Pablo, Polson and Saint Ignatius.We will upload 294gb corporate documents soon. Employee information (scanned passports, driver licenses, hr docs with DOB, phones,addresses, credit card details and so on), contracts and agreements, NDAs, and other client's files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trigg-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27122</link>
<guid>a4111706bdc4b0445173f69f8418889b</guid>
<pubDate>Fri, 14 Nov 2025 17:25:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Trigg-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0089f037efa3fd92aeb01de395df138a3deb307cfd0b4d4fd5c6354b4a4dc20b</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valley-Plains-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27128</link>
<guid>c34ae2b80c30c0a74b1c8e980e4dbe5d</guid>
<pubDate>Fri, 14 Nov 2025 16:17:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Valley-Plains-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0fb40fe2b37674b4dad111a5b38617f65cf90c711a2e3b28ab64e93af26a9cb9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.valleyplainsequipment.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sellers-Publishing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27127</link>
<guid>99687949804f7bd0a24a825122001657</guid>
<pubDate>Fri, 14 Nov 2025 16:16:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sellers-Publishing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>606f18653469a5b1a72e3662a85dc83db932cab91d1229786d7a05dcddca32a7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rsvp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>BK-Precision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27126</link>
<guid>20ef1c5bb97b3a464dc4d8bb4da18bac</guid>
<pubDate>Fri, 14 Nov 2025 16:16:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>BK-Precision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a845ed9f054221d73ccd7095d9fde3395015f2066e8e56afd8b73c90ce9119a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bkprecision.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barbizon-Lighting-Company-Roseburrough-Tool-Mqd-McKay-Empire-Victor-Insulators.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27123</link>
<guid>77a81025ac3a31baaa0bd6dd3b5773d9</guid>
<pubDate>Fri, 14 Nov 2025 15:39:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Barbizon-Lighting-Company-Roseburrough-Tool-Mqd-McKay-Empire-Victor-Insulators.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcb2ff4180805eceaf1a9ab9c4bfb1212e451978ce297bf76565bb90e9a2e48a</i><br /><br />Threat actor <b>description</b>: <i>We obtained about 15gb of the following companies:
The Barbizon Lighting Company specializes in sales, integration a
nd services of lighting and rigging equipment for houses of worsh
ip, live productions, performing arts, themed environments, film,
and television. 
Roseburrough Tool Company, Inc. is a manufacturer and provider of
high-quality tools and construction supplies.
MQD conducts independent, private, and accredited product testing
s and perform veterinary diagnostics and provide consulting servi
ces on hygiene,
technology, and other quality-related issues.
Ralph McKay Industries, Inc. specializes in manufacturing high-qu
ality agricultural parts including discs, coulters, openers, swee
ps, chisels, specialty items, and crop lifters.
Victor Insulators is a leading manufacturer and seller of insulat
ors, specializing in products made from standard strength silica 
porcelain and alumina.

You will find personal employee, client, partner information, pro
ject files, accounting and financials and other internal operatio
nal files.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>A-B-Communications</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27124</link>
<guid>90667252a0a036041ddc3553799772ef</guid>
<pubDate>Fri, 14 Nov 2025 14:41:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>A-B-Communications</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ee662aba269c1aad48167afc9df2d02788d2fe4eb98bf49d1f358c99617977a</i><br /><br />Threat actor <b>description</b>: <i>A-B Communications has been serving businesses since 1960, offeri
ng a range of services including professional answering, call cen
ter solutions, voicemail/IVR services, and secure messaging. 

We will upload almost corporate documents soon. Detailed personal
employee information (about 100 persons or more), lots of scanne
d passports, DLs, SSNs, birth/death certs and so on. Contracts an
d agreements, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Waukegan-Steel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27111</link>
<guid>bac6ab6f28645db5cbbbbf00ed123f36</guid>
<pubDate>Fri, 14 Nov 2025 12:25:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Waukegan-Steel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a7ec782c2a30d7efce4073e2c0f728d11003dbd91f641e5af6b6252d3487c8c</i><br /><br />Threat actor <b>description</b>: <i>Waukegan Steel is a structural steel fabricator serving the Midwest, specializing in high-quality steel fabrication since 1929. The company has worked on notable projects in the Chicago area, such as Soldier Field and Willis Tower, offering a complete range ofservices including structural, miscellaneous, and ornamental steel fabrication.We will upload almost 15gb of corporate documents soon. Scanned personal documents (passports, social security numbers, driver licenses, w-9 forms and so on), project information, NDAs, contractsand agreements, financials, client's information, lots of drawings of ongoing projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Basin-Harbor</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27112</link>
<guid>8eef9b6c2c8397ee32bf3da4c752bc3c</guid>
<pubDate>Fri, 14 Nov 2025 12:25:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Basin-Harbor</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52db54c2dea92d7c205253e20a1bc81e44566ca5fa2e6f4f34f61f51f0f1cb9d</i><br /><br />Threat actor <b>description</b>: <i>Basin Harbor is a unique Vermont resort situated on the shores ofLake Champlain, offering a blend of timeless traditions and lakeside charm. The resort spans 700 acres and features historic cottages, making it an ideal destination for outdoor adventures, waterfront relaxation, and family gatherings. We are going to upload company data soon. There are lots of essential corporate documents such as: financial data (audit, payment details, invoices), detailed employees and customers information (passports, driver's license , Social Security Numbers, emails, phones) confidential information and other documents with detailedpersonal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barnhart</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27113</link>
<guid>218a6beba67ce30416235c45f0357c20</guid>
<pubDate>Fri, 14 Nov 2025 12:25:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Barnhart</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3791622f78055600716a211ef4f400e6de664338313768a1d1cbf2abeb259ab</i><br /><br />Threat actor <b>description</b>: <i>Barnhart is a third-party global logistics provider dedicated to delivering customized transportation solutions with a focus on safety and service. We are going to upload company data soon. There are lots of essential corporate documents such as: financial data (audit, payment details, invoices), detailed employees and customers information (Passports, driver's license ,Social Security Numbers, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Foot-Doctors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27114</link>
<guid>8783118abe1d12ceacf48e74fe8f9550</guid>
<pubDate>Fri, 14 Nov 2025 07:20:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>The-Foot-Doctors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6c50a59e8553224217517ad13a877e133f8962de2206fe05a5f77d4078be090</i><br /><br />Threat actor <b>description</b>: <i>The Foot Doctor's patients are people just like you - people who need pain relief and expert, effective foot care. When you choose our Casper, Wyoming podiatrists, you're choosing knowledgeable Podiatric surgeons who will take your pain seriously.Dr. Michael P. Wilkinson is board-certified with the American Board of Foot and Ankle Surgery and a fellow of the American Academy of Podiatric Sports Medicine. Dr. Wilkinson received his podiatric education from The California College of Podiatric Medicine in San Francisco, CA in 1995.Dr. Wilkinson competed at the highest level of collegiate athletics earning a scholarship to play defensive line on the Stanford football team. He is an avid football alum reuniting with teammates often to root on the Cardinal.While he founded The Foot Doctor, P.C. in 1997 in Casper, he performs some foot surgery. However, he loves the challenge and rewards of solving a multitude of foot conditions with creative custom orthotics for runners and other athletes and preventing diabetic amputations through educating patients, diabetic foot care, and therapeutic shoes and insoles. Dr. Wilkinson and his wife Alexandra enjoy spending time with their three children and one grandson and keeping active with golf and skiing.We look forward to working with you and your family!Personal information of employees and clientsOther documents https://wyofootdoctor.com/</i><br />Target victim <b>website</b>: <i>wyofootdoctor.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>wafergrind.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27101</link>
<guid>6484bc7860f609cf2e18ab5eebe01ba0</guid>
<pubDate>Thu, 13 Nov 2025 23:47:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>wafergrind.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f46711cc7c61976fdb4833e8da2a3bacba3a08c52b784feed0f45c271203dee2</i><br /><br />Threat actor <b>description</b>: <i>Grinding & Dicing Services Inc (GDSI) provides wafer thinning and dicing services to the IC industry for critical post-fabrication process requirements. GDSI is headquartered in San Jose, California. Employees: 50 Revenue: $5 Million Industry: Manufacturing-Electronics  Phone Number: (408) 451-2000 </i><br />Target victim <b>website</b>: <i>wafergrind.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>duboiswood.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27107</link>
<guid>cc56f342b0dc3f74024688bf135beab4</guid>
<pubDate>Thu, 13 Nov 2025 23:47:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>duboiswood.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44ecfd44461338aab562377ddbcfee98c92d8913baa11ce9865e69983c947f8a</i><br /><br />Threat actor <b>description</b>: <i>Dubois Wood, located in southern Indiana, has been a domestic producer of high-quality, American-made furniture since 1979. The company caters to several markets by offering superior products at competitive prices, distinguishing itself in the furniture-making industry. Employees: 200 Revenue: $21.6 Million Industry: Retail-Furniture  Phone Number: (812) 683-3613</i><br />Target victim <b>website</b>: <i>duboiswood.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>GLOBALLOGIC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27090</link>
<guid>fd6c128733fc1d31f48a431ee6dfe1bc</guid>
<pubDate>Thu, 13 Nov 2025 22:49:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GLOBALLOGIC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe90bcb4fd5f95c4cf87c8825c10668b37581afa55ee6063ff73faa5cc744eeb</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>rosemontexpo.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27105</link>
<guid>1745680a5a547dc1fb4b69f85054c299</guid>
<pubDate>Thu, 13 Nov 2025 22:48:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>rosemontexpo.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cbcf1e537d6b1978fa19b08d6bda3a866ab07c6830c3cf9c25b2f8b758d28a94</i><br /><br />Threat actor <b>description</b>: <i>Rosemont Exposition Services, Inc. is an Illinois-based company that offers exhibitor show services. These include exhibit rentals, utilities, decorating services, catering, and area information. Formerly known as O'Hare Exposition Services, they primarily function as the full-service general contractor for all trade shows and events held at the Donald E. Stephens Convention Center located in Rosemont, IL. Employees: 500 Revenue: $48.6 Million Industry: Business Services Phone Number: (847) 696-2208 </i><br />Target victim <b>website</b>: <i>rosemontexpo.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metropolitan-Adjustment-Bureau</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27108</link>
<guid>318d38a7aa1b5fca9ff53fdefef3ee88</guid>
<pubDate>Thu, 13 Nov 2025 22:43:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>Metropolitan-Adjustment-Bureau</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2b76445fd6492957518ef28c6cd6a2f025314d4ac467d1e5162f18d20c6b49b</i><br /><br />Threat actor <b>description</b>: <i>Metropolitan Adjustment Bureau is a public insurance adjusting firm with over 50 years of experience assisting homeowners and businesses with insurance claims related to fire, water, earthquake, and disaster damage.</i><br />Target victim <b>website</b>: <i>www.metroadjusters.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>-AFLGLOBAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27091</link>
<guid>45e7f7967d7fb661fabbb61db524a286</guid>
<pubDate>Thu, 13 Nov 2025 21:58:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>-AFLGLOBAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1cb0492d391759319e2aa8ad33d088f814be4e3b710ff4106f0bd557e462b4a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>INTEGRALIFE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27092</link>
<guid>426281d73409354c214025722c6160a8</guid>
<pubDate>Thu, 13 Nov 2025 21:57:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INTEGRALIFE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c93565ffd5c09a198ff27e3dba252adf02cc4cfeede6b08963479107f088cab</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MARITZ.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27093</link>
<guid>56e3fb541605e047f551bffc5a3dc209</guid>
<pubDate>Thu, 13 Nov 2025 21:57:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MARITZ.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>214dd6aaa9dd6f7673a1638cebd1b608db2a2a9139c6ad3f06ec34f3dd3bf211</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HELIXESG.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27094</link>
<guid>da960bb5bdcdc36aa9f836df530a9e3c</guid>
<pubDate>Thu, 13 Nov 2025 21:56:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HELIXESG.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7976c214b49be510b814ce486dfc8cd0edc6fb82b7aadae90c126b6e0456728</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TPICOMPOSITES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27095</link>
<guid>021de1d3005e39b3eab3f7591231696b</guid>
<pubDate>Thu, 13 Nov 2025 21:56:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>TPICOMPOSITES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09f0196de0115f67facaa5e7bf2586cd00354f79c4775c2bcca965f7c7ad7c29</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FLUKE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27096</link>
<guid>0722ba570f1e381a4cf86360ad7d2000</guid>
<pubDate>Thu, 13 Nov 2025 21:56:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>FLUKE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bae02aadc36a653faccf6378c652a4cfe7d5652be2643d30fa52f9192fd42bf3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>PENS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27099</link>
<guid>da5e8bfed9bdb84595be92afeb3fd378</guid>
<pubDate>Thu, 13 Nov 2025 21:54:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>PENS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec9ca4bae5ff83ee896acef523bca20a3d297e4cfb77a2244f8a926887d726d0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENTRUST.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27100</link>
<guid>d73bdb1ac56ee271cda563e7949255b2</guid>
<pubDate>Thu, 13 Nov 2025 21:53:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ENTRUST.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c375db3bfb11f8312b02f26a481fc55d7a42a17d87906e386cb751d20f2598c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>FullBeauty-Brands</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27089</link>
<guid>c5d84b491de9533ab5043b62c3d41057</guid>
<pubDate>Thu, 13 Nov 2025 17:20:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>FullBeauty-Brands</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9626f6e6d7d387ce89b9bc8559dfe466b7ebbe3abfd761478127778bed7d09c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] FullBeauty Brands is a US-based plus-size women's and men's apparel and home goods company. The company operates multiple brands such as Woman Within, Roaman's, Jessica London, Ellos, Swimsuits For All, KingSize, and BrylaneHome. It is committed to providing stylish, high-quality products in sizes that are traditionally hard to find.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lung-Rose-Voss-Wagnild</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27087</link>
<guid>2716856dce285289a8cf7463eee2eb45</guid>
<pubDate>Thu, 13 Nov 2025 17:15:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Lung-Rose-Voss-Wagnild</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b28ee6e9aff19998625432204b28c6c038c8489ea5135da8678e4d7b0a3e727</i><br /><br />Threat actor <b>description</b>: <i>Hawaii’s leading law firm data breach.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smith-Gardner</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27078</link>
<guid>dcc1041b85c1bcd477a8f90cad93775e</guid>
<pubDate>Thu, 13 Nov 2025 16:10:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Smith-Gardner</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8cac0730c7e46f123d01d863037d5666a60e7593043d16c195c6e7562c9ccd67</i><br /><br />Threat actor <b>description</b>: <i>Smith Gardner is an industry-leading solid waste consulting engin
eering firm committed to delivering sound, innovative solid waste
solutions.

We will upload almost 101gb of corporate documents soon. Employee
personal documents (passports, w-9 forms and so on), confidentia
l projects, NDAs, contracts and agreements, financials, client's 
information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PACCAR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27082</link>
<guid>f719801846ff4eb77a7e393cbf607d00</guid>
<pubDate>Thu, 13 Nov 2025 14:20:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>PACCAR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ccad9c7c179fc45caad368163807da232fa7bfa100248cd626c1e99a7530166a</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1905, PACCAR is a global technology company in the design, manufacture and customer support of high-quality light, medium and heavy-duty...</i><br />Target victim <b>website</b>: <i>paccar.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Avery-Dennison</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27081</link>
<guid>0bec370d93e454d9a0cd7dee3e0ef456</guid>
<pubDate>Thu, 13 Nov 2025 14:19:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Avery-Dennison</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88e49cfd0310545f1dadeb29670710f73224076663314df4cf47d832915140d4</i><br /><br />Threat actor <b>description</b>: <i>Avery Dennison Corporation produces and sells pressure-sensitive materials worldwide. The companys Label and Graphic Materials segment offers press...</i><br />Target victim <b>website</b>: <i>averydennison.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>SGK-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27079</link>
<guid>13941bddb1399810f387f38dc7c775f0</guid>
<pubDate>Thu, 13 Nov 2025 14:18:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>SGK-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b7e4ed05b7b497fe77d3aa8fc4e2697be0af7b0a4adaf6c761d023c9be5c5daa</i><br /><br />Threat actor <b>description</b>: <i>Based in Des Plaines, Illinois, SKG is a marketing company that specializes in global brand development, activation, and deployment. The company is...</i><br />Target victim <b>website</b>: <i>sgkinc.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vikor-Scientific-LLC--Korgene</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27072</link>
<guid>0e6930d35e9a52977d5bd93c414ce3b2</guid>
<pubDate>Thu, 13 Nov 2025 11:18:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Vikor-Scientific-LLC--Korgene</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9d12274b1a728d7b6136aae0fd6b4e674765820beac7ee375faafae6993f358</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Vikor Scientific, LLC / Korgene is a specialized molecular diagnostics company dedicated to advancing the healthcare sector through innovation. They offer comprehensive, customized diagnostic tests to clinicians for better patient outcomes. Vikor aims to combat the rise of antibiotic resistance by providing targeted treatments. Korgene, on the other hand, develops efficient diagnostic platforms to detect diseases like cancer.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>KorPath</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27073</link>
<guid>841b9457fd9014ede0e8ba949e5be76d</guid>
<pubDate>Thu, 13 Nov 2025 11:18:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>KorPath</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9deda1acb9e9b6ebd0f145d37051267ec6b39fa26b961f0b027afb95bb277a59</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] KorPath is a biotechnology company that specializes in early-stage technologies. Their main focus is on identifying unique compounds and molecules that can be used in various medical interventions. The company conducts extensive research on pathological conditions including cancer and neurodegenerative disorders. They also offer preclinical services such as ex vivo efficacy studies.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cornerstone-Staffing-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27071</link>
<guid>6151ca1f26822034f6b12f142bdfc9db</guid>
<pubDate>Thu, 13 Nov 2025 10:45:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Cornerstone-Staffing-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54116a069b65bd2f0fb322ca03bdfd1f09396d3dc69daba9d8f21dd2c85d155f</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.cornerstone-staffing.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.pointcag.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27070</link>
<guid>521255db815eb7f2e44d31ce130352c9</guid>
<pubDate>Thu, 13 Nov 2025 09:22:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kraken</b> claims attack for <b>www.pointcag.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8347ceda9fa4c9c293524292dfa73f04c1d5167f5258a99ba6b650b09c659c27</i><br /><br />Threat actor <b>description</b>: <i>POINT provides expert Construction Management Consulting and Litigation Services with objectivity and reliability. 

http://o5...</i><br />Target victim <b>website</b>: <i>www.pointcag.com</i>]]></description>
<category>kraken</category>
</item>
<item xmlns:dc='ns:1'>
<title>MultistateTax-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27067</link>
<guid>b53b3c9fb0fe5c6cbdbb5fedace0745b</guid>
<pubDate>Thu, 13 Nov 2025 01:45:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>MultistateTax-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5fe4b8b514776fbcd91798ffded4c830e117b86b1953a2a1778b09da7fbd22b1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>iconinternational.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27062</link>
<guid>861fc05a34bf88b3c689a89ef8f34384</guid>
<pubDate>Wed, 12 Nov 2025 19:42:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>iconinternational.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ea3474d5098617149d38599d017ec8082ddb080b20244cd0dc7a3fb8610ecd6</i><br /><br />Threat actor <b>description</b>: <i>ICON International, Inc. is a corporate barter firm that offers innovative solutions and strategic thinking to help brands grow and create economic value.</i><br />Target victim <b>website</b>: <i>www.iconinternational.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>doversd.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27061</link>
<guid>3dc91c9313038ce8c97966f7f4194aac</guid>
<pubDate>Wed, 12 Nov 2025 19:25:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>doversd.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>856af66d78cf5760d4b1e44671b3f857492f6a196847d367ddc4dc6889c58533</i><br /><br />Threat actor <b>description</b>: <i>Dover City Schools is a public K-12 school district located in Dover, Ohio, serving approximately 2,650 students across multiple schools. …</i><br />Target victim <b>website</b>: <i>doversd.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>KohaFoods-Hawaii</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27057</link>
<guid>228b495ddf77bcfc7f5a57c1648599f9</guid>
<pubDate>Wed, 12 Nov 2025 13:19:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>KohaFoods-Hawaii</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e4efb4829912db5445b0833456bd0af88e85819f3935218ebe568a8d632724a</i><br /><br />Threat actor <b>description</b>: <i>Koha Foods is a Honolulu-based distributor and wholesaler specializing in Asian food products. The company boasts a diverse selection of over 2,500 items including seafood, condiments, and Korean dishes, catering primarily to local Oahu businesses such as restaurants and supermarkets. Having served Hawaii since 1970, Koha Foods emphasizes quality and connection with the community through its offerings. In addition to distribution, they manufacture their own signature Korean food items using authentic recipes and high-quality ingredients.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>bridge-housing-corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27053</link>
<guid>288a8d4e8014cf089c28ac2eba7c7d0b</guid>
<pubDate>Wed, 12 Nov 2025 12:49:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>bridge-housing-corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71028cf132ead1362299d9a4ce6f29510ae3c0e66db7390996ba13379a5e6e41</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1983 BRIDGE Housing is a non-profit that works towards securing affordable housing. The organization is headquartered in San Francisco, California.  We have over 150 GB of confidential information, and the management of this organization has completely ignored us. Remember, the publication of your data is entirely their fault.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>forensicmed.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27055</link>
<guid>647eb89e04e05801979246bd0d2ec15b</guid>
<pubDate>Wed, 12 Nov 2025 11:48:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>forensicmed.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>942567d933f62e70f7959269c8a9538a89f172ce5b9d62bc4937d098219c0de6</i><br /><br />Threat actor <b>description</b>: <i>Forensic Medical is a comprehensive forensic pathology company headquartered in Nashville, Tennessee, which provides medical examiner, death investigation, medical autopsy services, expert forensic testimony and forensic management services to government agencies and private individuals.</i><br />Target victim <b>website</b>: <i>forensicmed.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Treetop-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27049</link>
<guid>8e7035e068f7046d16a509453862e0da</guid>
<pubDate>Wed, 12 Nov 2025 10:24:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Treetop-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4565b7bc0ef53d11508b6034301e94afdd34d2f3d5c0d981957fafe50d825bb</i><br /><br />Threat actor <b>description</b>: <i>Treetop Companies is a real estate investment firm founded in 2005 by Azi Mandel and Adam Mermelstein.We will upload almost 100gb of corporate documents soon. Lots of confidential files, clients personal documents (passports, drivers licenses, financials), other internal client information, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Irwin-Car</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27039</link>
<guid>faaae1866a54fdb13aa89b7da8101bdc</guid>
<pubDate>Tue, 11 Nov 2025 21:23:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Irwin-Car</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f9694a08b6eb70ad765034dfb1958da6d3e557fab0677c8ca95aa83f024ffe1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Irwin Car and Equipment is a manufacturing company specialized in the production of heavy-duty material handling equipment. They create custom mining cars, conveyor cars, tunneling cars and more. It aids various industries, including mining and tunneling, in improving their efficiency and safety. The company is based in the USA and is recognized for its innovative and durable equipment.</i><br />Target victim <b>website</b>: <i>irwincar.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brenda-Richardson-Memorial-Care-Home-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27046</link>
<guid>4fc147e998bc303d0f94b6239b7b1449</guid>
<pubDate>Tue, 11 Nov 2025 20:50:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Brenda-Richardson-Memorial-Care-Home-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>620a167f8b78bfc86510159ef2d9a0d23a2b17664132e479a2e8daba1f3f750e</i><br /><br />Threat actor <b>description</b>: <i>Negligence of mental health care agency employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Olive-Branch-Family-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27045</link>
<guid>32cf59fa14aee4619887264860712707</guid>
<pubDate>Tue, 11 Nov 2025 20:48:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Olive-Branch-Family-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ecd6aa220f7bc81bcbc88226eccc82dc863aac20483597e33d833413be5b3431</i><br /><br />Threat actor <b>description</b>: <i>Data Breach at U.S. Medical Center Puts Thousands of Patients at Risk</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>DARTMOUTH.EDU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27037</link>
<guid>5f7733de9c8bddeb31b24d3434640003</guid>
<pubDate>Tue, 11 Nov 2025 19:24:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>DARTMOUTH.EDU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53abfee837a6862612213de40d281f531e6f3baf91ec151191dc75f90f16a3fd</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>glendaleobgyn.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27044</link>
<guid>bae4f11996f82f08ae1800943df99925</guid>
<pubDate>Tue, 11 Nov 2025 19:18:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>glendaleobgyn.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fdcf78abaf263ef8ceacfc4cfa4d720d81e002cdea398ba3ff85d933010c7e4</i><br /><br />Threat actor <b>description</b>: <i>Glendale OBGYN (an obstetrics and gynecology practice) would likely operate as a mid-sized women’s health clinic in Glendale, California, offering …</i><br />Target victim <b>website</b>: <i>glendaleobgyn.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>S.B.-Conrad-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27040</link>
<guid>788292a2cdb9fa425ff5fb269688befd</guid>
<pubDate>Tue, 11 Nov 2025 18:22:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>S.B.-Conrad-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d30b11a21f6f3d61aa902417f05b91dbfb26f7086fc84bacabf2514c068d907f</i><br /><br />Threat actor <b>description</b>: <i>A general contracting construction company</i><br />Target victim <b>website</b>: <i>sbconrad.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Continental-Global-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27041</link>
<guid>4423df30c2370b6c952d07397078b3ae</guid>
<pubDate>Tue, 11 Nov 2025 18:22:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Continental-Global-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>555ee6c10b86503bbf6325bbd0e82fd81cb97ee2f7568290389add3368a6ab69</i><br /><br />Threat actor <b>description</b>: <i>A subsidiary of PPI Global</i><br />Target victim <b>website</b>: <i>cgmh.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Manusos-General-Contracting-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27043</link>
<guid>64ad8f3af92ef8d9a1c7dfd7265e577d</guid>
<pubDate>Tue, 11 Nov 2025 18:20:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Manusos-General-Contracting-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8c6c26320710a0e8055a4d2a88c77b6c060bc336d47a7ff6ad1fc18d334266c6</i><br /><br />Threat actor <b>description</b>: <i>A general contracting construction company</i><br />Target victim <b>website</b>: <i>manusosinc.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barry-Sallinger-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27031</link>
<guid>2ecc65c44282f1ad4bfa9ca7bf4d0a37</guid>
<pubDate>Tue, 11 Nov 2025 17:24:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Barry-Sallinger-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b9e539221e67b8e826692b1a7b7ef4efb39a6013e5b12d9fd414f9c1d2c3d9c2</i><br /><br />Threat actor <b>description</b>: <i>Sallinger / Melancon Defense Attorneys are top-rated criminal defense lawyers based in Lafayette, specializing in alcohol, drug offenses, and complex litigation. We will upload corporate documents soon. Clients personal documents (scanned passports, drivers licenses, SSNs, medical information), court files, financials, confidentiality agreements, confidential files, police reports and other legal files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miromar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27029</link>
<guid>5cacb64862789cc1a6c5d2e646e8177f</guid>
<pubDate>Tue, 11 Nov 2025 16:24:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Miromar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>140d2aa60ccc6abde375b51dbc6bd222d3f7b9dc5a15a2446bad2139d018a2df</i><br /><br />Threat actor <b>description</b>: <i>Miromar Development Corporation is a multi-faceted real estate development company which holds a portfolio of internationally recognized residential and commercial properties in the United States.We will upload corporate documents soon. Clients information, HR files, financials, agreements and contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rhodes-Young-Black-Duncan-RYBD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27030</link>
<guid>ee2ce2b68e8909ca92ffea6598099cbe</guid>
<pubDate>Tue, 11 Nov 2025 16:24:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rhodes-Young-Black-Duncan-RYBD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a1b9f99b48bc5a84d519f6dde4958aadae1ad91f66c04f61e88604733b718e2</i><br /><br />Threat actor <b>description</b>: <i>Rhodes, Young, Black & Duncan is a CPA consulting firm based in Duluth, offering comprehensive tax, accounting, and business consulting services.We will upload corporate documents soon. Lots of clients personaldocuments (scanned passports, drivers licenses, SSNs, medical information), HR files, financials, agreements and contracts, projects, a few military related files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brian-Kyles-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27026</link>
<guid>76652668cad0e5ab9abedb7d7357d6fd</guid>
<pubDate>Tue, 11 Nov 2025 14:24:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Brian-Kyles-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4bfb9b8d86d6e2f01eb95cc1489f9042edf24f340a1f77fd335e07603fe73324</i><br /><br />Threat actor <b>description</b>: <i>Commercial & Residential Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Doctor-Alliance--Streamlined-Document-and-Billing-Management-for-Healthcare-Providers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27034</link>
<guid>2fecdeaa123ef60a82894a45c5a7ae26</guid>
<pubDate>Tue, 11 Nov 2025 13:19:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kazu</b> claims attack for <b>Doctor-Alliance--Streamlined-Document-and-Billing-Management-for-Healthcare-Providers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91f94070375426d9495a1808281585f906cfca8824b6ef0495763e6816ce2ede</i><br /><br />Threat actor <b>description</b>: <i>Doctor Alliance (doctoralliance.com) is a U.S.-based healthcare technology platform that helps physicians and medical agencies manage documents, referrals, and billing in one secure online system. Headquartered in Dallas, Texas, it offers services such as electronic document signing, coordination with agencies, and billing support for programs like CPO, CCM, and TCM. The platform integrates with systems like Axxess Home Health to streamline workflow and reduce paperwork, promoting faster document turnaround and improved billing efficiency -- contact me to protect your files !!</i><br />Target victim <b>website</b>: <i>doctoralliance.com</i>]]></description>
<category>kazu</category>
</item>
<item xmlns:dc='ns:1'>
<title>omniumint.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27028</link>
<guid>baef4802848fb2c2e3026a7f26a53315</guid>
<pubDate>Tue, 11 Nov 2025 12:21:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>omniumint.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>15ab401b185b42d3153d45f00b285ec2b6c2c025e67aeba2c6a3849ddc1a1ee8</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 1.2million
1.2 tb
and one very interesting email</i><br />Target victim <b>website</b>: <i>omniumint.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>himmelstein.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27025</link>
<guid>33a88364c4e7651c59a0116c74de1f9b</guid>
<pubDate>Tue, 11 Nov 2025 07:50:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>himmelstein.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0e226af75f90683a5dd28198f7aa3f5f2d737d6c8891ebdf240f428213418ef</i><br /><br />Threat actor <b>description</b>: <i>S. Himmelstein & Company is a U.S.-based specialist manufacturer founded in 1960, headquartered in Hoffman Estates, Illinois. The company focuses …</i><br />Target victim <b>website</b>: <i>himmelstein.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>GAEAGLOBAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27011</link>
<guid>3804d8a77337b4ed9c5f388c98822525</guid>
<pubDate>Tue, 11 Nov 2025 01:09:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GAEAGLOBAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4618d936787f4278fb892d9de890eb9fa4b24c0030988acef0e2a4228b029e3b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>P2ENERGYSERVICES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27012</link>
<guid>bb78a710e7d0494db915c83459de0c42</guid>
<pubDate>Tue, 11 Nov 2025 01:09:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>P2ENERGYSERVICES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08172726934ca9bbea3d93a4aca47ec0ce95b390eae10e62a73c95195de8c5dc</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GLOBUSANDCOSMOS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27013</link>
<guid>d48fff99ca7aafcfe2e7a5c530eef864</guid>
<pubDate>Tue, 11 Nov 2025 01:08:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GLOBUSANDCOSMOS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26445596bdfa48509bc5324c53516e204699f335dc0f681d4f080f1b743c2718</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>ENNVEE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27014</link>
<guid>5c17761f7220777710a535e7dea512d3</guid>
<pubDate>Tue, 11 Nov 2025 01:08:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ENNVEE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c40cbd7668fc6e15b5d8acba8382be087db2fa81042a201162a4cbed7420cadd</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>VITAMIX.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27016</link>
<guid>eb94d25085ab649f81d89e90cbe12fee</guid>
<pubDate>Tue, 11 Nov 2025 01:05:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>VITAMIX.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f96f56d95ea30885f469045efe75208d8f56564da2cff765f059ca31c1c6a37</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>GARDENOFLIFE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27017</link>
<guid>b9df039a53bee7e42906016fbf7cd441</guid>
<pubDate>Tue, 11 Nov 2025 01:04:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>GARDENOFLIFE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>094a56923e1277346b6ed8cca3c7d68253c1bfd87012c1821e597f4e8a4028c4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Middlesex-Endodontics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27022</link>
<guid>f7b6da9dedde15499538bf7e5e23f0ee</guid>
<pubDate>Tue, 11 Nov 2025 00:58:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Middlesex-Endodontics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23ec3a50c12da9ceecaa5b66d9a13becffe4931c44a779eacc44bb71778a4070</i><br /><br />Threat actor <b>description</b>: <i>Middlesex Endodontics is conveniently located in Burlington and Winchester, MA. Our experienced team of endodontists and staff is dedicated to providing the highest level of professional care for our patients. Besides routine endodontics (root canals), our services also include: Pediatric endodontics, Post removal and retreatment, Endodontic surgery, and Implants. EXPERIENCE For over 40 years our practice has worked together with area dentists to provide the best overall dental care. Supporting our 5 endodontists is an experienced staff --many members of which have been with us for over 15 years, with several over or approaching the 25 year mark. We do not believe any patient should have to wait with pain and discomfort. We offer same day emergency appointments and we also like to accommodate busy schedules with expanded hours for scheduled appointments including evenings and Saturdays.</i><br />Target victim <b>website</b>: <i>www.middlesexendodontics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.modcomedia.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27020</link>
<guid>b9dfbed6c12d438d6c550fa1a2032135</guid>
<pubDate>Tue, 11 Nov 2025 00:27:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>www.modcomedia.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be54d433e13a21ac80cea7a7fd4af3646e0f4f2161f8e8e989b63ae810d38bc4</i><br /><br />Threat actor <b>description</b>: <i>5GB of confidential data, 400GB of total data, contracts with Rockstar, Siemens, and other popular brands.</i><br />Target victim <b>website</b>: <i>www.modcomedia.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Easterseals-Arc-of-Northeast-Indiana</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27003</link>
<guid>0c8c5b55e8a3c4c0856a1fc3d0a46f61</guid>
<pubDate>Mon, 10 Nov 2025 21:22:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Easterseals-Arc-of-Northeast-Indiana</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c07a4d579177a4b056c426b5314e57fcd4114d7cfd907dfbf8737bc765a7e96</i><br /><br />Threat actor <b>description</b>: <i>Easterseals Northeast Indiana provides life-changing services and programs for individuals with disabilities, their families, and the wider community. Their offerings include youth and adult services, employment readiness programs, wellness coordination, and recreational activities designed to empower participants. The organization operates across multiple locations in northeast Indiana, including Fort Wayne, Columbia City, and Angola, and is committed to meeting the unique needs of each individual. Through compassionate staff and various service initiatives, they aim to create inclusive environments and enhance the quality of life for their clients.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Unit-School-District-201</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27004</link>
<guid>1eb4505084d87118b8c710ac96b97cb2</guid>
<pubDate>Mon, 10 Nov 2025 21:22:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Community-Unit-School-District-201</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>336cadf0b05ec365afa92ad24db86133efc800c2ad4cccd0733f75e4d7cca9c9</i><br /><br />Threat actor <b>description</b>: <i>Community Unit School District 200 is dedicated to inspiring, educating, challenging, and supporting all students to achieve their highest potential in learning and personal development. The district offers various educational programs and services aimed at fostering student growth and excellence. Their intended clients include students, parents, and the community, with a focus on providing a supportive environment for all. The district is committed to innovation and technology in education, as well as special education services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>ielplumbing.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27006</link>
<guid>a3f559a66f188c89e4289caa9765aaef</guid>
<pubDate>Mon, 10 Nov 2025 20:46:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>ielplumbing.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5819596a0ba64e1eb5afc6ae6e246bbf39b1eec237c6da64dde67c692c27ed62</i><br /><br />Threat actor <b>description</b>: <i>I.E. Plumbing Services is a privately-held plumbing contractor based in Southern California, operating from two locations in the Riverside / …</i><br />Target victim <b>website</b>: <i>ielplumbing.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heart-South-Cardiovascular-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27005</link>
<guid>5aafc3f70332f6e42228be384d3c4f01</guid>
<pubDate>Mon, 10 Nov 2025 20:45:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Heart-South-Cardiovascular-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>92a3088875af854447477c1984edaf3126d71399a76588dedf75cd7140e365c9</i><br /><br />Threat actor <b>description</b>: <i>Heart South Cardiovascular Group Heart South is a leading provider of comprehensive cardiac and vascular care in Central Alabama.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garvin-Promotion-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27002</link>
<guid>7580584dbb499d1e2a45411a0cc7fa23</guid>
<pubDate>Mon, 10 Nov 2025 18:55:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Garvin-Promotion-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56538b2000fe50d11eec99026387e8d254a98d36d41cd5797d5968ec3c8bc21b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.garvinpromo.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jean-Georges</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=27001</link>
<guid>ffa486a4029dee1a46c0ed19bdc4b6b7</guid>
<pubDate>Mon, 10 Nov 2025 18:54:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Jean-Georges</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>105f39fa75ba4211c6375f8635ebc04d671f0753e2a8c0ab95a8e1cbb56cef29</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jean-georges.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ioxo--Stream-Computers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26999</link>
<guid>36bf0c2be198fce4b4ce1bdc6c9dbd56</guid>
<pubDate>Mon, 10 Nov 2025 18:53:17 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Ioxo--Stream-Computers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e16eb9d63ec3b6d7c018ad2c1ea8ce98e7fa01cfdd925691811bdb050f32e52</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ioxo.cloud www.streampc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Darvin-Furniture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26998</link>
<guid>d3b0b66668aabbb1887660ef1ba740ff</guid>
<pubDate>Mon, 10 Nov 2025 18:52:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Darvin-Furniture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97579866fd18aca017b8626e71a6e773c4479a190e949edc36fd3ba6f7e3cc57</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.darvin.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Land-Title-Guaranty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26997</link>
<guid>d1c1a2daad72f9d116f600c1c542b573</guid>
<pubDate>Mon, 10 Nov 2025 18:51:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Land-Title-Guaranty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dbc17da847cf976307a081d3ceeebad789066ae5ba9d917e131c681e419f552</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.landtitleweb.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mciver-Engineering--Controls</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26993</link>
<guid>1d14f7a40b5c0e95f6b5529810582f23</guid>
<pubDate>Mon, 10 Nov 2025 18:25:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mciver-Engineering--Controls</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c865c65e1ff538e978d56bc67e5ad96f97aba4d0babd774ecc5c5e702b6ad4f6</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ami-Bearings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26994</link>
<guid>c5c57642a4f73eae7413ce5ad2782158</guid>
<pubDate>Mon, 10 Nov 2025 17:24:29 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ami-Bearings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f0da0ddb45e52a271e5360a3ebbcd83abb75fe8345568951cc2ae976d1022b8</i><br /><br />Threat actor <b>description</b>: <i>AMI Bearings, Inc. is a premier manufacturer of mounted ball bearings that caters to the North American market.We will upload 15gb of corporate documents soon. Employee information, clients information, lots of projects information, agreements and contracts, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MARCK-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26995</link>
<guid>005cbfa3ec6690c005d1de9182683241</guid>
<pubDate>Mon, 10 Nov 2025 15:49:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>MARCK-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>113da3288d3bf96bd499b521da00017ada2e8588d3b80530c565c633d92166a0</i><br /><br />Threat actor <b>description</b>: <i>GMARCK Industries believe that the services we provide make a difference: In Your Company - From your first 360 Waste Audit to implementing and maintaining your customized recycling program, we help you reach your sustainability goals while helping you increase efficiencies and reduce costs. In Our Community - Recycling keeps reusable products out of the landfill, while boosting the local economy with sustainable jobs.</i><br />Target victim <b>website</b>: <i>www.marck.net</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weintraub-Traub-Tracy--Virk-Cras-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26991</link>
<guid>d9e6b46563c1a62a6d0979d929fe2e6b</guid>
<pubDate>Mon, 10 Nov 2025 12:21:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Weintraub-Traub-Tracy--Virk-Cras-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd9d5c5a43c5b138c2560940880690b1be5becce2aa7b76a63b880e8b2b9b611</i><br /><br />Threat actor <b>description</b>: <i>We have data from Piaty Müller-Mezin Schoeller Rechtsanwälte GmbH, payment and tax records, employee and client documents, as well as projects and developments, and personal correspondence with clients. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>LMHT-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26990</link>
<guid>72417e4a6ce410ee495dc2978c405084</guid>
<pubDate>Mon, 10 Nov 2025 07:47:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>LMHT-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>401bd4dd0733c32a9aabda21d2d6cab5b762a34e8a2125b24ee5493695de87f8</i><br /><br />Threat actor <b>description</b>: <i>LMHT Associates</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seward-County-KS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26986</link>
<guid>5564890753e533c5fb71cf81125fccfb</guid>
<pubDate>Mon, 10 Nov 2025 00:53:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Seward-County-KS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8c579abcabf62744183fc0c189a21ec3c8b6c1af61a0c963d8cd0b97303cb9d</i><br /><br />Threat actor <b>description</b>: <i>Seward County is a county located in Kansas. This county was formed on March 20, 1873 and the county seat is Liberal.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>CapitalPlus-Exchange</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26987</link>
<guid>552f5e345c9d523300ea73c6a65b0a6e</guid>
<pubDate>Mon, 10 Nov 2025 00:52:48 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>CapitalPlus-Exchange</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1a968bec680f09933d40e3fe70a107591b7948134afe789cda3aca07a7b8ea6</i><br /><br />Threat actor <b>description</b>: <i>CapitalPlus Exchange (CapPlus) supports financial institutions in emerging economies by enhancing their strategic and operational capacities, offering training and innovative financing solutions for small and medium enterprises (SMEs). Through initiatives like the Education Markets Impact Initiative (EMII) and FIRST+, CapPlus helps to unlock education finance markets and catalyze job creation in sectors such as agriculture by improving access to finance. CapPlus partners with local institutions to tailor financial services, focusing on underserved demographics such as women and youth. With nearly two decades of experience, CapPlus aims to reduce poverty by expanding financial services for small businesses.</i><br />Target victim <b>website</b>: <i>www.capitalplusexchange.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atrium-Living-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26979</link>
<guid>b2ebf93cb2667a995c12787e51e6ec0b</guid>
<pubDate>Sun, 09 Nov 2025 18:42:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Atrium-Living-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c712f3f0bbeb77b0aa34005279e556a0f932dffda7e01daab5b182e10bf6773</i><br /><br />Threat actor <b>description</b>: <i>Atrium Living Centers is a 100% employee-owned company providing skilled nursing, rehabilitation, and long-term care services. The organization is dedicated to delivering compassionate, high-quality healthcare to residents while promoting dignity, respect, and community involvement. With a strong focus on personalized treatment, Atrium Living Centers offers both short-term post-acute rehabilitation and long-term nursing care. Their mission is to “be a light in the lives of our residents and families,” ensuring comfort and well-being in a supportive environment. The company operates multiple care centers across several U.S. states, including Ohio, Michigan, Kentucky, and Wisconsin.
company is headquartered in Atrium Living Centers headquarters is located at 2550 Corporate Exchange Drive, Suite 200, Columbus, Ohio 43231, United States.
2,000 Employees
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ringmor</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26976</link>
<guid>fc33073cb57bd68d6df31b8c97c91e93</guid>
<pubDate>Sun, 09 Nov 2025 13:10:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Ringmor</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bceb307eb379e3b863417e75cae0dc861d48d52125dd9d96fd64ba74327598f2</i><br /><br />Threat actor <b>description</b>: <i>CallMor offers virtual phone system services aimed at businesses looking for unlimited communication options with no hidden fees. Their plans are designed to simplify connectivity for teams and clients alike and include 24/7 customer support. With offices in Orange County, San Diego, and Los Angeles, they prioritize customer satisfaction and provide competitive pricing in the telecommunications market. CallMor is known for its professional service and effectiveness in improving communication and sales results for its clients</i><br />Target victim <b>website</b>: <i>www.ringmor.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>JC-Auto-Accident-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26971</link>
<guid>fc60881482701eecdb18102735fc2308</guid>
<pubDate>Sat, 08 Nov 2025 18:24:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>JC-Auto-Accident-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7043a8c8037746bf3354961665ed4266971b8d009954172f9be15df189a5d064</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gadge-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26972</link>
<guid>07fc49d464acdc489fc1a262fecf8023</guid>
<pubDate>Sat, 08 Nov 2025 18:24:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Gadge-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>820467a11407b973d63c9a3f064000efa0bcb8c7e85499a73125a41812665081</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Delivery-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26968</link>
<guid>1ff74a7bfef596dee39077acae425bcd</guid>
<pubDate>Sat, 08 Nov 2025 12:25:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Advanced-Delivery-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a578859a46eeea186228770ae2bb62407e9a98ee914122f96f36925869c746ea</i><br /><br />Threat actor <b>description</b>: <i>Freight & Logistics Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SHRM-New-Mexico</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26967</link>
<guid>407db1f4e4ad1fc027d01a09ed569d7d</guid>
<pubDate>Sat, 08 Nov 2025 05:51:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SHRM-New-Mexico</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59a17d6f5efff9e9e48644094ceaf128d486b90810f58a0c95f372603f127392</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.shrmnm.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mold-In-Graphic-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26964</link>
<guid>0e53dc3b8871ecd8207df9da83f683b6</guid>
<pubDate>Sat, 08 Nov 2025 00:44:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mold-In-Graphic-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f79dd1c228ede029786d0fac43de4dbcda67706a3d3f3e1425428be211e2e7d</i><br /><br />Threat actor <b>description</b>: <i>Mold In Graphic Systems specializes in providing permanent labeli
ng solutions for plastic durable goods using their unique Polymer
Fusion Labels.

We will upload 15gb of corporate documents soon. Employee informa
tion (Driver licenses, credit cards scans, medical information an
d so on), projects information, internal confidential files, agre
ements and contracts, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shollenberger-Januzzi--Wolfe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26957</link>
<guid>468e5112d68b2cb7c9df93692fe5730f</guid>
<pubDate>Fri, 07 Nov 2025 20:24:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Shollenberger-Januzzi--Wolfe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be87ff3afc8995e6a2edab3f1c600b079770a887477608267a4bb1d3ef2498a6</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marine-Turbine-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26958</link>
<guid>3afa23ac1b717491cdb68424e043a45f</guid>
<pubDate>Fri, 07 Nov 2025 20:24:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Marine-Turbine-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c4d35499b885ddfe63ad7e13623c8060b59214c0816f155ddcae1b0bc97ab4b</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clackamas-Community-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26959</link>
<guid>8e09ecaeb8fc3c2f8f0b52fff9eec3ec</guid>
<pubDate>Fri, 07 Nov 2025 18:30:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Clackamas-Community-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4576b1c5f49f4979287a2112b824d60e2f707b1d9232d641b6be1592f59ab519</i><br /><br />Threat actor <b>description</b>: <i>Clackamas Community College offers a variety of academic programs including associate degrees, certificates, and customized training for various career pathways. The college is committed to supporting a diverse student population, including veterans, English learners, and adult learners seeking education and skill development. With over 100 programs and a focus on community engagement, CCC provides resources such as financial aid, counseling, and student clubs. Their mission is to empower individuals to achieve their educational and career goals while celebrating equity and inclusion.
company is headquartered in 19600 Molalla Avenue, Oregon City, Oregon 97045, United States.
936 Employees. The total amount of data leakage is 1.21 TB
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Village-of-New-Lenox</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26951</link>
<guid>0943a2b85be5f182bcd97cee9beebd5f</guid>
<pubDate>Fri, 07 Nov 2025 18:24:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Village-of-New-Lenox</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fb1a6ba956b61871ad8095a81adf8cd8769b4b9dfda63d0442496284557d6fd</i><br /><br />Threat actor <b>description</b>: <i>Government</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Klae-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26952</link>
<guid>e2fc74dd6dde6ff116ccc7a4086adc0c</guid>
<pubDate>Fri, 07 Nov 2025 18:24:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Klae-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94f76de36a71875f214d558175d76db21ca9f4c00aa4a4c096f8ce3fa242a36f</i><br /><br />Threat actor <b>description</b>: <i>Commercial & Residential Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Soapy-Joes-Car-Wash</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26953</link>
<guid>440bcbe45a6a4e361b606228f0c86365</guid>
<pubDate>Fri, 07 Nov 2025 18:24:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Soapy-Joes-Car-Wash</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>561d2be536acc39c8acfc8e38548b8960d8a1021812e2ad9ff550d5d4ec12dfe</i><br /><br />Threat actor <b>description</b>: <i>Voted Best Car Wash in San Diego. Guinness World Record holder.We will upload more than 40gb of corporate documents soon. We obtained personal information of all employees of this company. Phones, addresses, DLs, passports, almost 2000 SSN numbers, medical information. Detailed financials, lots of confidential files, contracts and agreements, partners information and so on, NDAs etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shands-Elbert</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26954</link>
<guid>7aedaa9271fdee6dc5b0d3e9858e1cf1</guid>
<pubDate>Fri, 07 Nov 2025 18:24:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Shands-Elbert</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>412d662693530a0e13d420194e6c85b2c084b90b156158754750e0c5d4c07786</i><br /><br />Threat actor <b>description</b>: <i>Shands, Elbert, Gianoulakis & Giljum, LLP is a law firm based in St. Louis with over 50 years of experience offering a wide range of legal services. They provide expertise in areas such as business law, education law, labor and employment, litigation, and estate planning, serving clients including corporations, governmentalentities, educational institutions, individuals, and small businesses.We will upload more than 31gb of corporate documents soon. Another ones lawyers that don't care of their clients (and family members) personal information. Name, DOB, phones, addresses, DLs, passports, SSN numbers, numerous medical files. Detailed financials, lots of confidential files, court hearings, police reports and soon.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PLP-SoCal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26955</link>
<guid>793fde23ec4fb2972bfe2ee461f63645</guid>
<pubDate>Fri, 07 Nov 2025 18:24:54 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>PLP-SoCal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c775d2141a6f2de99be49786193563a8e2dd2336bbd0cb3a7e38c986d0650da6</i><br /><br />Threat actor <b>description</b>: <i>PLP SoCal is Southern California's premier representative of performance Architectural Lighting, Decorative Lighting, Lighting Controls, Acoustic, EV Charging Stations, Illuminated Handrails & Site Furnishing.We will upload 26gb of corporate documents soon. You will find full personal information of almost every employee. (Name, DOB, phone, SSN, address, DL, passport, medical information, family members personal information and so on), financials, internal confidential files, client information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Koch--Co-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26956</link>
<guid>4854417254fa352c8deea7c55ed11dd2</guid>
<pubDate>Fri, 07 Nov 2025 18:24:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Koch--Co-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d433ac53898e1a5af0187fbee7180a894eec0cfaec9bc44d7c729de84bda54b7</i><br /><br />Threat actor <b>description</b>: <i>Koch & Co, Inc., is a wood door and cabinet manufacturing company.We will upload 54gb of corporate documents soon. Detailed financials and accounting, projects information, contracts, agreements, lots of HR files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aptura-Group--Central-Indiana-Hardware</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26961</link>
<guid>e41576c2d63eab99e7d7209204739ce8</guid>
<pubDate>Fri, 07 Nov 2025 15:33:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Aptura-Group--Central-Indiana-Hardware</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0162127668856aa0e4aa73067e4381368f4a211923f5de7680f7ec19360a9f04</i><br /><br />Threat actor <b>description</b>: <i>Central Indiana Hardware - Produces custom access systems, space management solutions, and high-performance hardware to optimize the security and functionality of commercial spaces.
APTURA GROUP is a wholly employee-owned company specializing in innovative solutions and services in the door hardware and security systems industry. Working with several leading brands, including Central Indiana Hardware (CIH), APTEK, Security Builders Supply, and HG/Schultz Door, we have built our reputation on precision, efficiency, and exceptional customer service that consistently exceeds expectations.
CIH helps the company work more productively.</i><br />Target victim <b>website</b>: <i>apturagroup.com & cih-inc.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rex-Hide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26950</link>
<guid>ec78e9f1c48cec8f5a6de60b921e4e46</guid>
<pubDate>Fri, 07 Nov 2025 08:25:35 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rex-Hide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ab14248bf6282e43815ed451c915d613257a764331a7c7136467edaab27732e</i><br /><br />Threat actor <b>description</b>: <i>Manufacturing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Health-Dimensions-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26939</link>
<guid>802cb8aeda781c153c4358d9e6cd32ad</guid>
<pubDate>Thu, 06 Nov 2025 22:25:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Health-Dimensions-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8487bd31645f7dcd739fd6c73679c9170519e047475172893cab1de5fc3f7b7e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>WASHINGTONPOST.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26936</link>
<guid>91ab07539b36f85ba8180d74ad2bb3ee</guid>
<pubDate>Thu, 06 Nov 2025 20:35:56 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>WASHINGTONPOST.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>28c995f0a22f32b4949451eba6007d5149d48ec8d29c567e8ec2ee796915f2d3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>UScraft</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26937</link>
<guid>0c48ec1f07958ea1b58ac7721dc6058b</guid>
<pubDate>Thu, 06 Nov 2025 19:25:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>UScraft</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a11226a56d5cbd0447a3e9fe6bfa693f9ffd7992ababe8347f71ad3a997c410</i><br /><br />Threat actor <b>description</b>: <i>Advertising & Marketing</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>RHEEM.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26924</link>
<guid>f5e083092550d2f93898e9829e677e39</guid>
<pubDate>Thu, 06 Nov 2025 18:22:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>RHEEM.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f52075113937b8d068c88078ec1d696cb223f904d5af4549908de2a07f28842d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Systems-Integrated</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26930</link>
<guid>695494b434b3711f396bc5f0d3c0a54e</guid>
<pubDate>Thu, 06 Nov 2025 17:24:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Systems-Integrated</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91c91772cca957f9aa6035ea933a053865cb742ba55033784ec8fac76e06b612</i><br /><br />Threat actor <b>description</b>: <i>Industrial Machinery & Equipment</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Black-Hills-Bentonite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26920</link>
<guid>53e232bcc4a6386499454667194addd1</guid>
<pubDate>Thu, 06 Nov 2025 16:24:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Black-Hills-Bentonite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d34db57d115fe756109897aa4d3c5886d4107922e94329874ac2713be1e58a46</i><br /><br />Threat actor <b>description</b>: <i>An American company founded in 1947. It mines and processes sodium bentonite, a natural clay used in well drilling, metal casting, and pond and landfill sealing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>E-First-Aid-Supplies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26914</link>
<guid>1df58e63816ec9ab895d8f14640a5f47</guid>
<pubDate>Thu, 06 Nov 2025 14:25:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>E-First-Aid-Supplies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ef3785e64e0b43276b020d916c81fdf5d551867a466486bafa54c7d2e38011a9</i><br /><br />Threat actor <b>description</b>: <i>Fieldtex is a manufacturer known as Fieldtex Cases that produces soft sided carrying cases for portable electronic equipment for medical and military markets. Their second division is a medical supplies distributor known as Fieldtex Medical.We will upload more than 14gb of corporate documents soon. Employee and customer, financials, confidential files, lots etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>INTERNATIONAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26915</link>
<guid>1533e368c21be061fac64ad083b5f8c1</guid>
<pubDate>Thu, 06 Nov 2025 14:22:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>INTERNATIONAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b48df1253689c91eed7f8889e9c9feb43256efccf336034f09fa1450fa54680</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>KIRBYCORP.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26916</link>
<guid>2d16ef569bb8d2fddf2e9b279f73e7f8</guid>
<pubDate>Thu, 06 Nov 2025 14:21:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>KIRBYCORP.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd5a7f5c084197b0ceb95016d8625dbfda49f7476edd9157655539c0e8412f17</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRIMBLE.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26917</link>
<guid>93e0873f2cce60514c26bd8bbdc3ccc8</guid>
<pubDate>Thu, 06 Nov 2025 14:21:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>TRIMBLE.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b34e2a6d0965bd476042610443223d1f7af321a845e2f54ae591e67490ea1d52</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MKS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26918</link>
<guid>b3385637859c7e1bf875c127272934a6</guid>
<pubDate>Thu, 06 Nov 2025 14:20:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MKS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ef5bf035a719f5c701cf1c1662eb6e896613f3d74fbe39af1fc0b525125ed02</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dermatology-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26933</link>
<guid>f88c38d9ce16d575ff23353bde81df3b</guid>
<pubDate>Thu, 06 Nov 2025 14:19:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Dermatology-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b27d27017b4b026d4be3a77c92287302d48f3644c2224e3c4b6f6ba045308cd</i><br /><br />Threat actor <b>description</b>: <i>Leak of clinic customer data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Union-League-of-Philadelphia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26892</link>
<guid>daa845e72247bceebbf545aed4737521</guid>
<pubDate>Thu, 06 Nov 2025 00:14:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>The-Union-League-of-Philadelphia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e429f02349b66cb0d6c360db9d2d43fb75d90bddb141339d99cca565dacb87d2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1862 as a patriotic society to support the Union and the policies of President Abraham Lincoln, The Union League of Philadelphia laid the philosophical foundation of other Union Leagues across a nation torn by civil war. The League has hosted U.S. presidents, heads of state, industrialists, entertainers and dignitaries from around the globe and has proudly supported the American military in each conflict since the Civil War. The Union League continues to be driven by its founding motto, Amor Patriae Ducit or Love of Country Leads.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>LaRosas-Pizzeria-</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26888</link>
<guid>5ca641f66bd082a37a9b11fe9236c7fd</guid>
<pubDate>Wed, 05 Nov 2025 20:52:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>LaRosas-Pizzeria-</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ad0e76ad72a73a26270f7047734f5822b884daa877213972469ea5ab3efa535</i><br /><br />Threat actor <b>description</b>: <i>LaRosa’s Pizzeria is a family-owned pizza restaurant chain founded in 1954 by Donald “Buddy” LaRosa in Cincinnati, Ohio. Known for its signature thin-crust pizzas made with Aunt Dena’s original sauce recipe, the company has become a regional favorite across Ohio, Kentucky, and Indiana. LaRosa’s offers a wide variety of Italian-inspired dishes including pasta, hoagies, and salads. The brand emphasizes family traditions, community values, and quality ingredients. Still operated by the LaRosa family, it continues to represent the spirit of local hospitality and authentic Italian-American cuisine after more than 70 years in business. company is headquartered in 2334 Boudinot Avenue, Cincinnati, OH 45238, United States. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maine-Course-Hospitality-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26883</link>
<guid>cc658daf205377fb870d72f7c9f2b59f</guid>
<pubDate>Wed, 05 Nov 2025 17:25:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Maine-Course-Hospitality-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c4520a9f07805b51014f9eb53d63f0fc8b32cfb1c0bb5cd4113de88a1cbf4c1</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shelbyville-Police-Department</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26886</link>
<guid>f6f20ada728b7a41ea4c0eb996c817b6</guid>
<pubDate>Wed, 05 Nov 2025 15:57:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Shelbyville-Police-Department</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b360c4ac63d3104677c40fc03a6356647563551f61960df16b2f3521000afdd0</i><br /><br />Threat actor <b>description</b>: <i>The Shelbyville Police Department is committed to protecting lives and preventing crime. But the opposite has happened! Officers are failing to protect themselves and are endangering other residents due to their indifference to safety! A vast amount of confidential data has been exposed! As a result, access was gained to the department's cameras, all data and databases containing archived videos and crime footage, as well as all available cameras and devices recording audio or video!</i><br />Target victim <b>website</b>: <i>shelbyvillepolice.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>sensationalteeth.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26885</link>
<guid>ede08f3ae4d17d223051ed8282a67caf</guid>
<pubDate>Wed, 05 Nov 2025 15:54:15 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>sensationalteeth.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>019ec4664a8cec31c95d921e204a4cdc3c7463a713751cccf6e1626997a2cb11</i><br /><br />Threat actor <b>description</b>: <i>Oelbaum Kagan Dentistry provides comprehensive dental services in the Bronx and New York City, with offerings including routine care, cosmetic dentistry, restorative procedures, and orthodontics. Led by experienced dentists Dr. Victor Oelbaum and Dr. Victor Kagan, the practice prioritizes patient comfort and satisfaction, employing advanced technology for optimal treatment. They aim to create a welcoming environment for both new and returning patients, promoting extensive dental health care. The team is dedicated to delivering high-quality treatment tailored to the needs of individuals, families, and seniors. Employees: 25 Revenue: $5 Million Industry: Dental Offices  Phone Number: (718) 882-7202 </i><br />Target victim <b>website</b>: <i>sensationalteeth.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pine-Pharmaceuticals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26879</link>
<guid>3ea1a7505194e632a33246e1c7a1a0ee</guid>
<pubDate>Wed, 05 Nov 2025 15:25:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pine-Pharmaceuticals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab0861c509f8050dcc720bb83139b8291962a5747995aff7f51de19f37c90a6a</i><br /><br />Threat actor <b>description</b>: <i>Pine Pharmaceuticals is one of the industry's largest and most trusted 503B outsourcing facilities specializing in the preparationof high-quality, ready-to-administer compounds and repackaged products.We will upload more than 18gb of corporate documents soon. Detailed employee information (complete I-9 forms, SSN, DL, passports, birth/death certs and so on), customer information, projects details, financials, confidential files, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Christina-Development</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26880</link>
<guid>4028aad989b92a2aaf6fc94295aaf8ab</guid>
<pubDate>Wed, 05 Nov 2025 15:25:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Christina-Development</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>438eb4d9febc41204737e61ec2ee2ce3af05c527605fe2360ba9ebb609ed2b8a</i><br /><br />Threat actor <b>description</b>: <i>Christina is a Los Angeles-based real estate investment firm with45 years of experience, focusing on providing investors the opportunity to invest in prime real estate in locations such as Beverly Hills, Malibu, and Santa Monica.We will upload more than 18gb of corporate documents soon. Employee personal documents (passports, driver licenses, birth/death certificates), customer projects and other information, client information, financials, confidential files, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>mcintoshlabs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26884</link>
<guid>bca7d174d4387a5394a9c3d899091b2d</guid>
<pubDate>Wed, 05 Nov 2025 13:24:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>mcintoshlabs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e2e340240d7d6eb8e2585c513be38fa6ba8981fc02d878c635e6f4a9534d2fd6</i><br /><br />Threat actor <b>description</b>: <i>McIntosh Laboratory is an iconic American company, founded in 1949 and headquartered in Binghamton, New York. It specializes in high-end, …</i><br />Target victim <b>website</b>: <i>mcintoshlabs.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Coilplus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26877</link>
<guid>e6ce7db38187cc8f163c21f26b62879b</guid>
<pubDate>Wed, 05 Nov 2025 12:48:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Coilplus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a16be965cd033c32d6e4206da0e6a0e94476d3a4300c37adfa996f18108bdfd</i><br /><br />Threat actor <b>description</b>: <i>Coilplus is part of the MetalOne Group, MetalOne is the largest i
ntegrated steel company in the world.

We will upload 14gb of corporate documents soon. Detailed employe
e information (complete I-9 forms, SSN, DL, passports, birth/deat
h certs and so on), financials, internal confidentiality agreemen
ts, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Durvet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26872</link>
<guid>36609c3d6cf0d6ca0887852c9d84e57d</guid>
<pubDate>Wed, 05 Nov 2025 06:25:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Durvet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55954ab35b3f7416a9b705f82d6218cbe5eed04629e3d66d129ef7e2ace4d153</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ConvExx</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26871</link>
<guid>e055a992677dc62362dc6ceda3245224</guid>
<pubDate>Tue, 04 Nov 2025 20:54:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ConvExx</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5deaf7bff237acf6a617739ef742953a8b48420e4df50e97ab1ca07525ef1b46</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.convexx.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sellars-Absorbent-Materials</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26870</link>
<guid>a25a6cb241dbe44d927ea9eac5a61172</guid>
<pubDate>Tue, 04 Nov 2025 20:53:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sellars-Absorbent-Materials</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7a9f7d1c8be0bef4678c8d9838d8424894f480b70b685d124a454e9d6405d62</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sellarscompany.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-PowerNet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26869</link>
<guid>743c11a9f3cb65cda4994bbdfb66c398</guid>
<pubDate>Tue, 04 Nov 2025 20:52:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>American-PowerNet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>571ddf29e1d86ad269eddd76fa363d996cf718709f7eee637b8633504a14962d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.americanpowernet.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mangos-Tropical-Cafe</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26861</link>
<guid>542a659782a0b10f3b9bf402455d3169</guid>
<pubDate>Tue, 04 Nov 2025 18:25:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mangos-Tropical-Cafe</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>585e5b29e89d1cf92fe188071d8108d87ab2c80133ab7f346eb0a4faf6902e7e</i><br /><br />Threat actor <b>description</b>: <i>Hospitality</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MS-Metal-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26863</link>
<guid>5af545e99254638ce9829ea2329f72d4</guid>
<pubDate>Tue, 04 Nov 2025 17:25:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MS-Metal-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d9e9f79d88b151737048b2b6f3e68db1636456ac3c644ebd2c360fd81f59d546</i><br /><br />Threat actor <b>description</b>: <i>MS Metal Solutions offers a wide range of manufacturing capabilities including cutting, welding, and powder coating to cater to diverse industries such as automotive, agriculture, and office furniture. We will upload corporate documents soon. Complete information about employees (w-9 forms containing DOB, SSN, DL, passport, address, email, phone   personal docs scans, credit card details), HR files, financials, internal confidential files, NDA, confidentiality agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Palacios-Marine--Industrial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26858</link>
<guid>680a8d55cea7984805c47e807c854f84</guid>
<pubDate>Tue, 04 Nov 2025 16:25:05 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Palacios-Marine--Industrial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb69fe90966a4029b6ca7f7724441ffb9d3d201c33342510460a69ed5c9cff89</i><br /><br />Threat actor <b>description</b>: <i>Palacios Marine Industrial (PMI)  offers quality contracting and service solutions while prioritizing environmental health and safety. We will upload corporate documents soon. Detailed employee information (passports, driver licenses, medical information, social security number and other scans with personal information), NDA, contracts and agreements, client data, drawings, and other operational data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Benda-Grace-Stulz</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26859</link>
<guid>8b9f221c0a8ce23d96068fafae80c7ec</guid>
<pubDate>Tue, 04 Nov 2025 16:25:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Benda-Grace-Stulz</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>14c530f28774a6df9f78ed4ad3ebf42d622b9a28f035a3fda389103b8e778ab3</i><br /><br />Threat actor <b>description</b>: <i>You Are Number One at Benda, Grace, Stulz & Co. operates in the Certified Public Accountant business/industry within the Engineering, Accounting, Research, and Management Services sector. Their most valuable assets - our clients. And this company is ready to share 90gb of their data containing the data of their clients. We will upload corporate documents soon. Detailed client financials,a bit of employee personal information, NDA, credit card details, payment information, confidentiality agreements and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elliott-Tax-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26860</link>
<guid>737b0dc5f7113a4a045cd290bc2ae2d9</guid>
<pubDate>Tue, 04 Nov 2025 16:25:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Elliott-Tax-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33052daad499edec55aa1e98a94aabc54840c988cf1786122e909e87f9edb63d</i><br /><br />Threat actor <b>description</b>: <i>Elliott Tax Service is a local firm in San Mateo specializing in income tax preparation and advice, boasting 27 years of experience. We will upload 82gb corporate documents soon. Client personal documents scans, employee personal information and other HR information. Clients financials and other files, NDA, credit card details, payment details, confidentiality agreements, legal and court documents, police reports, and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Automated-Logistics-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26865</link>
<guid>9bfa4291fb5844d8d79e81724c9d853c</guid>
<pubDate>Tue, 04 Nov 2025 14:51:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Automated-Logistics-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ee8c6483d994914172d16492c5b2af0c68c2b603bf8855dbf8f3f4e24123538</i><br /><br />Threat actor <b>description</b>: <i>Automated Logistics Systems</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>General-Micro-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26857</link>
<guid>ea9be6ea49c5c752abb11953955c90e4</guid>
<pubDate>Tue, 04 Nov 2025 13:24:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>General-Micro-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3325f3591e952f152a5773e386ffffc47b47840a16e9823ab2d1d2a7a0d2de9</i><br /><br />Threat actor <b>description</b>: <i>General Micro Systems (GMS) is the rugged server company. The company is known as the industry expert in highest-density, modular,compute-intensive, and rugged small form-factor embedded computing systems, servers, and switches.We will upload corporate documents soon. Detailed project information, a bit of client information, financials, confidential military information, NDA, the most interesting thing here is confidential files of Intel corporation concerning Thunderbolt. And they don't care about such data leaked. We'll upload the files soon.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Invacare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26856</link>
<guid>aa45ea35cbdcb42012f2bf55012a0624</guid>
<pubDate>Tue, 04 Nov 2025 08:43:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Invacare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f194dc3717c6e41d667df8489dc4b90609cbe33745d3dc80c7785025e9c40b8</i><br /><br />Threat actor <b>description</b>: <i>Invacare Invacare, founded in 1885 and headquartered out of Elyria, Ohio, is a manufacturer and distributor of home and long term care medical products.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crown-Automotive-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26852</link>
<guid>4a79a7ede1f5c12290122e93a1331a7e</guid>
<pubDate>Tue, 04 Nov 2025 00:48:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Crown-Automotive-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a1b028c0989187e9d1a914c84109536e3f1fb9372112600825620b20559af3c</i><br /><br />Threat actor <b>description</b>: <i>Crown Automotive Sales Co specializes in providing high-quality replacement parts for Jeep, Chrysler, and Dodge vehicles. With over 8,000 part numbers and a diverse range of applications, the company supplies authorized dealers with essential components for both maintenance and upgrades. Additionally, their RT Off-Road line features performance accessories specifically tailored for Jeep models. The company has been a key player in the automotive parts industry since 1963, serving retailers and dealers exclusively.</i><br />Target victim <b>website</b>: <i>www.crownautomotivesales.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.myriversidedentaloffice.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26850</link>
<guid>7d9a49f74cd1c1740ce05485e41258b8</guid>
<pubDate>Mon, 03 Nov 2025 21:25:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>mydata</b> claims attack for <b>www.myriversidedentaloffice.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48fd3c6560604bf02cd964fa971d40237fa82e7e1eb6d4fe0dbe923ca0876760</i><br /><br />Threat actor <b>description</b>: <i>It is dental practice devoted to restoring and enhancing the natural beauty of your smile using conservative, state-of-the-art procedures that will result in beautiful, long lasting smiles!</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>mydata</category>
</item>
<item xmlns:dc='ns:1'>
<title>Irwin-Car</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26851</link>
<guid>50ab6aa42d206917721ed0e79778ab9f</guid>
<pubDate>Mon, 03 Nov 2025 19:22:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Irwin-Car</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>810a813835565e8e26a97ad0e4dceb97029245d0df3ceb91c38c610abe1cc4bc</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.irwincar.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morris-Communications-Company-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26837</link>
<guid>65f76dcdbd789fbe2623a33ab6b35da0</guid>
<pubDate>Mon, 03 Nov 2025 17:24:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Morris-Communications-Company-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17bc507f1a4fbf9531a42c1e21a952f0d9610abfc14a879c76764a1a76b0237f</i><br /><br />Threat actor <b>description</b>: <i>Morris Communications Company, founded in 2001 and headquartered in Augusta, Georgia, is part of a privately held company with diversified holdings in media, Real Estate and property development and agriculture.We are ready to upload more than 84GB data. There are lots of essential corporate documents such as: financial data (audit, payment details, invoices), detailed employees and customers information (passports, driver's license , Social Security Numbers, medicalinformation, death/birth certificate, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moonlight-Basin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26838</link>
<guid>af3de23c3548eaaf65ba6278bacbf607</guid>
<pubDate>Mon, 03 Nov 2025 17:24:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Moonlight-Basin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4ed098d3f54ed99e3918e56425f00ff0e17cad33575e5de756707beeb074396</i><br /><br />Threat actor <b>description</b>: <i>Moonlight Basin offers the best snow conditions in Montana, firstclass rental lodging and vacation homes, fine dining, spa services, and easy access to attractions such as Yellowstone National Park and seasonal activities such as fishing, horseback riding, hiking, and rafting, Moonlight Basin is also known for providing anextraordinary level of guest service.We will upload 17gb of corporate documents soon. A bit of client and employee data, lots of internal reports, contracts and agreements, accounting and financial documents, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Designs-for-Vision</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26839</link>
<guid>085dfc68338d1ed37766086a1aee1934</guid>
<pubDate>Mon, 03 Nov 2025 17:24:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Designs-for-Vision</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf62adcc218575c18dc8ef291eda7bff7cbf8fd680a908617c6199869499d8d0</i><br /><br />Threat actor <b>description</b>: <i>Designs for Vision, Inc. specializes in high-quality magnification and LED headlights for dental, medical, and low vision applications.We will upload about 50gb of corporate documents soon. Lots of project information, a bit of personal information, credit cards details and other financial and accounting information, contracts and agreements, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mecanex-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26840</link>
<guid>1a371879ae7ae905850d5dee733f303e</guid>
<pubDate>Mon, 03 Nov 2025 17:24:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mecanex-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74faeb3ff4cc625799e0a5ed637464a3b025c6a4db21799ee073fc9ad2353323</i><br /><br />Threat actor <b>description</b>: <i>Mecanex USA is a U.S. subsidiary of RUAG Aviation. RUAG Aviation is a leading supplier, support provider and integrator of systemsand components for civil and military aviation worldwide. We will upload 24gb of corporate documents soon. Detailed employee information (Social security number, passports, driver licenses, phones, addresses and so on), confidential military information, lots of contracts and agreements (including military), information on how to work with explosive and so on, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bishop-Ireton-High-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26842</link>
<guid>63f6019ca436ea42e23a670f0bca5a8f</guid>
<pubDate>Mon, 03 Nov 2025 15:56:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Bishop-Ireton-High-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d816681e73110c271f43b2ceae1ca5b9c33465ad650588e8913704e0abbc529e</i><br /><br />Threat actor <b>description</b>: <i>Bishop Ayrton High School is a Catholic college preparatory school that focuses on spiritual, intellectual, creative, social, and physical development. The school offers an academic program that includes honors courses and dual enrollment programs, as well as a variety of extracurricular activities, such as sports and arts programs. The school helps students and their families receive an education based on Christian principles that prepares them for future challenges. The school supports the Salesian community, which combines learning and service, encouraging students to participate in community service and personal growth.</i><br />Target victim <b>website</b>: <i>bishopireton.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pinto-Coates-Kyre--Bowers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26849</link>
<guid>ba8e2e450af203ab114d338707251486</guid>
<pubDate>Mon, 03 Nov 2025 15:56:30 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Pinto-Coates-Kyre--Bowers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76ec1726fe77cd7a819e799296fd2a68eeb3095efb33d86f5d18fc28e892ad72</i><br /><br />Threat actor <b>description</b>: <i>Pinto Coates Kyre & Bowers is a civil litigation law firm based in Greensboro, NC, specializing in defending individuals and corporations as well as representing claimants in diverse legal matters. Due to its easily accessible security, the company was compromised and published publicly! The company and its clients lost a significant amount of confidential information and data!</i><br />Target victim <b>website</b>: <i>pckb-law.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Montage-Marketing-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26834</link>
<guid>980e5ef572c190392a6fe0dd63b3d917</guid>
<pubDate>Mon, 03 Nov 2025 15:24:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Montage-Marketing-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c97971320ea5f18cc008967eba9e21cd3015053fb644616183819d7fe8a81d78</i><br /><br />Threat actor <b>description</b>: <i>Montage Marketing Services is an outsourced contact center specializing in handling peak activity periods and supporting back-office needs through their Customer Contact Center, Custom Fulfillment Center, and Administrative Services.We will upload 26gb of corporate documents soon. Employee and customer information, contracts and agreements, accounting and financial documents, HR files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Seasons-Federal-Credit-Union</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26835</link>
<guid>8c78bd132fff9eb9d47d4759fb8eda13</guid>
<pubDate>Mon, 03 Nov 2025 15:24:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Seasons-Federal-Credit-Union</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>29fbde3042108f19b97a5d4aff123ea04f4256c9982d6c865c4394a710009d37</i><br /><br />Threat actor <b>description</b>: <i>Montage Marketing Services is an outsourced contact center specializing in handling peak activity periods and supporting back-office needs through their Customer Contact Center, Custom Fulfillment Center, and Administrative Services.We will upload 17gb of corporate documents soon. Employee and customer information, w-9 forms, contracts and agreements, confidential files, accounting and financial documents, HR files, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>UnitedLayer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26843</link>
<guid>719653e675f24537d4cb647537a2a04f</guid>
<pubDate>Mon, 03 Nov 2025 14:10:00 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>UnitedLayer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91c1e67d58939067007e4fa3730003863162bdd90c62f607a5c6a53d3fd9a640</i><br /><br />Threat actor <b>description</b>: <i>UnitedLayer® provides the Colocation services from one of the largest data centers in San Francisco, USA, at 200 Paul Ave. Their long list of managed services enables enterprises to modernize their infrastructure and improve their responsiveness, resource utilization, scalability, and agility resulting in better customer experience and faster time to market</i><br />Target victim <b>website</b>: <i>www.unitedlayer.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gerson--Schwartz-Accident--Injury-Lawyers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26833</link>
<guid>487cf32249fbaaa5a79258e26d54fe19</guid>
<pubDate>Mon, 03 Nov 2025 12:22:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Gerson--Schwartz-Accident--Injury-Lawyers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63b9b896de062239fbc4bffa882967ef6e4ca35974df8b0de6407405efa1429d</i><br /><br />Threat actor <b>description</b>: <i>A Miami law firm representing victims in all types of legal proceedings related to accidents, injuries, and wrongful death</i><br />Target victim <b>website</b>: <i>injuryattorneyfla.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>REPECHAGE</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26830</link>
<guid>0f9d99f598cb439e8e733a3c7bb9892c</guid>
<pubDate>Mon, 03 Nov 2025 10:52:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>REPECHAGE</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>00c96b02474b2156769c0ec38830847e9e5d9c28327f74756d8f970b4b5d7aff</i><br /><br />Threat actor <b>description</b>: <i>We have over 1 TB of personal data belonging to this organization, and all attempts at peaceful resolution have been completely ignored. Aware that the addresses, phone numbers, and job titles of individual employees, medical records, and complete data on clients and partners have been lost (and will undoubtedly be used for selfish purposes by a huge number of people), they have shown complete indifference—REPECHAGE we want you to know about this before it is too late.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mayco-International-www.maycointernational.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26825</link>
<guid>20ab3465d85c1a8a408d7d0897f12cc8</guid>
<pubDate>Sun, 02 Nov 2025 23:45:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Mayco-International-www.maycointernational.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73d486c5b80bf41864fef3dd644fcd95d273efee3dde1be06b8da85ec189763f</i><br /><br />Threat actor <b>description</b>: <i>Data breach at automotive industry leader.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Deco-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26823</link>
<guid>2f96e47253a9f882207e621f642aa2f1</guid>
<pubDate>Sun, 02 Nov 2025 13:16:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Deco-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2a3916129b540dec9903784d310d81caac31123c30cccf0c2d379c7b08d8d90</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.decodental.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Professionals-Choice-Sports</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26820</link>
<guid>1d9aa373bc6d83a320559b9b7261db73</guid>
<pubDate>Sat, 01 Nov 2025 15:23:13 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Professionals-Choice-Sports</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7bceafd7e2b5e3b6dc00e72055df65654d46b46c3bad367d9c561a68c6bc838a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.profchoice.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Encore-Repair-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26819</link>
<guid>3980c69a4aef759ee74a882fe274dc84</guid>
<pubDate>Sat, 01 Nov 2025 15:22:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Encore-Repair-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db5f0f8aebe7ab5a7d670306d0c89ec6d8e4ad67f4ef925908fe2bb4eb776556</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.encorerepair.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tavo-Packaging-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26818</link>
<guid>53e2a437534e65b9403677a567069f20</guid>
<pubDate>Sat, 01 Nov 2025 15:21:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Tavo-Packaging-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>05392d425070bed34e7dc5e353723c9d6bce3b9225a58594f16a4027edd00aaf</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.tavopackaging.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wright-Tool</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26817</link>
<guid>95932ec3ba94ee1951d83524c88d8c49</guid>
<pubDate>Sat, 01 Nov 2025 15:21:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Wright-Tool</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>945de4af6d2499fd719a3a31392ca9c598a929e77be2cfbdfec59ce8bb6b79fb</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.wrighttool.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Red-Phoenix-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26811</link>
<guid>dce311e9986a54e3925ea37479f55e10</guid>
<pubDate>Sat, 01 Nov 2025 11:24:37 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Red-Phoenix-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc3168d3e1d58a93f8499f76c979c5ccbb6f8761914ebbc2a7e1ebe100730bc3</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>aa-llp.com-aa.law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26807</link>
<guid>4b2e0217a0ed46be7207c0acfe2fee53</guid>
<pubDate>Fri, 31 Oct 2025 19:51:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>aa-llp.com-aa.law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbcf52a026e765c68187a08439d9b7f8da30c68443ae4765e707111d0c188439</i><br /><br />Threat actor <b>description</b>: <i>All criminal cases, clients' personal documents, medical records, and all confidential files were stolen.</i><br />Target victim <b>website</b>: <i>aa.law</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hometown-Credit-Union</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26804</link>
<guid>22f266a9987440c2fcba09a845b638b1</guid>
<pubDate>Fri, 31 Oct 2025 13:25:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hometown-Credit-Union</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd2501aa7aa54ccf8d50a48259b53e6d2a1296547665569d2554e64e79b1c380</i><br /><br />Threat actor <b>description</b>: <i>Hometown Credit Union offers a range of financial services including savings accounts, checking accounts, consumer loans, and homeequity lines of credit.We will upload corporate documents soon. HR documents with employee personal information (social security number, addresses, phones, emails, driver licenses), lots of financial documents, accounting documents and other internal documents.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gun-Accessory-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26802</link>
<guid>75ab8ec90f11a4f0a172aee44bc801bc</guid>
<pubDate>Fri, 31 Oct 2025 10:25:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Gun-Accessory-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc5a8e5a0e1656bf9b070e3bf43d39b32329565a0e45935f54be9b0a3c9d258f</i><br /><br />Threat actor <b>description</b>: <i>Business Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CCI-Tax-Pros-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26803</link>
<guid>1b3ecca102b57d735ac385a9c03fd15b</guid>
<pubDate>Fri, 31 Oct 2025 08:15:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>CCI-Tax-Pros-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9621a3d4d1fdf62f1dd7d5af46fdb5d3acfb0a869a092fc8c837da2a71745bcf</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] CCI Tax Pros, Inc., based in Virginia, USA, is a consulting company that specializes in providing comprehensive tax and financial services to both businesses and individual clients. Their services range from personal tax planning, professional tax return preparation, and representation before tax authorities, to business tax management and strategic planning. Their team comprises of experienced accountants and financial advisors who strive to maximize their clients' savings and returns.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.verdugohillsdental.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26797</link>
<guid>1c3ef503ecadc5b8674be1540c609009</guid>
<pubDate>Fri, 31 Oct 2025 02:25:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>mydata</b> claims attack for <b>www.verdugohillsdental.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8384c00c302513f8677dcd13cde931b132e9aefa02e815deffcb1e0352bedfa9</i><br /><br />Threat actor <b>description</b>: <i>At Verdugo Hills Dental in Glendale, CA, our experienced team is committed to more than just dentistry—we’re here to ensure your comfort and overall well-being every step of the way. From routine check-ups to advanced restorative treatments, we deliver comprehensive care with a gentle touch, alw...Read more ⇒</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>mydata</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Matlusky-Firm-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26800</link>
<guid>9092e7bee2d622e7c6c5ef8476928917</guid>
<pubDate>Fri, 31 Oct 2025 02:15:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>The-Matlusky-Firm-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b556deff1ca958ffd07de7b4b7cc0ba11d23dbdfc7c5b25be39f95bb87e158a</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>TENAX-Law-Group-PC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26798</link>
<guid>ceb689455a88ec958a3c9e3983f3f5b4</guid>
<pubDate>Fri, 31 Oct 2025 01:21:18 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>TENAX-Law-Group-PC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb19df379a1c1fc8e27b2374d4fc48d0c8b991ad67e292a4825a733b5e9fafc7</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TENAX Law Group, P.C. is a U.S.-based law firm that specializes in numerous sectors. Areas of practice include business law, estate planning & trusts, real estate law, civil litigation, among others. It is committed to providing high-quality legal services & personalized solutions to both individuals and businesses. Located in Point Richmond, California, they're renowned for maintaining professional and cost-effective legal solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>Center-for-Neuropsychology-Learning-and-Development</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26791</link>
<guid>5571df479aa024d28e17f555babd1fcb</guid>
<pubDate>Thu, 30 Oct 2025 19:24:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Center-for-Neuropsychology-Learning-and-Development</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc27a374e14f2cedc82082aad3ce3d7764c4edb04cd35a342b0be53da34a34e4</i><br /><br />Threat actor <b>description</b>: <i>Healthcare Services</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Post-Ranch-Inn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26795</link>
<guid>3cbddfc0631041f3bebf720bf2d72e7f</guid>
<pubDate>Thu, 30 Oct 2025 18:50:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Post-Ranch-Inn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5966d06d69343e186273429fa515ed0bfbbb971715993e1e843245d55b2f0e2</i><br /><br />Threat actor <b>description</b>: <i>Post Ranch Inn is a luxury hotel situated on the cliffs of Big Sur, offering stunning views and serene accommodations designed for restorative experiences. The hotel features a variety of luxurious packages, exceptional dining options at its acclaimed restaurant Sierra Mar, and engaging wellness activities like yoga and guided nature walks. Catering primarily to couples and those seeking a tranquil getaway, Post Ranch Inn emphasizes sustainability and community investment. Recognized with numerous awards, including a Three-Key MICHELIN distinction, it provides an unforgettable escape for discerning travelers.</i><br />Target victim <b>website</b>: <i>www.postranchinn.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Architectural-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26783</link>
<guid>3855053032ebfd54d04e184091bcbe34</guid>
<pubDate>Thu, 30 Oct 2025 18:24:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Architectural-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>854fc463a073979fd95913fb4c97281b01dadcc62b9e353c6cb1cc7be5768bc3</i><br /><br />Threat actor <b>description</b>: <i>Architectural Systems, Inc. is a full-service partner in the commercial construction industry, dedicated to providing high-qualityproducts and timely delivery.We will upload 355gb of corporate documents soon. Numerous confidential files of clients (drawings of building, security systems),customer information, accounting information, contracts and agreements, client information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anderson-Moore-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26785</link>
<guid>8eef6ff991f69d436ef38262bb3eef52</guid>
<pubDate>Thu, 30 Oct 2025 17:25:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Anderson-Moore-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ad46f262fdc0dfdb87fbe6f9f1649bb0b03b1e94e70da0a19c9f5063104dc84</i><br /><br />Threat actor <b>description</b>: <i>Construction</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huber--Erickson--Bowman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26779</link>
<guid>9c9a06df136e82ebb47c92b32ef7a61b</guid>
<pubDate>Thu, 30 Oct 2025 15:24:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Huber--Erickson--Bowman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06cabf17361b3fc1718df996b418bb60073e02fa0936c9c78d294f4b262541f0</i><br /><br />Threat actor <b>description</b>: <i>HEB Advisors is Salt Lake City's premier full-service tax and accounting firm with over 45 years of experience, serving individuals, small and mid-sized businesses, government entities, and non-profit organizations.We will upload 66gb of corporate documents soon. We've taken incredibly large amount of personal information of clients and employees (addresses, phones, DOB, driver licenses, social security cards, credit cards and so on and so forth), detailed accounting information, internal confidential files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Boilersource</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26780</link>
<guid>3b74ab8eb83faf0992aad7a123d02707</guid>
<pubDate>Thu, 30 Oct 2025 15:24:40 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Boilersource</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb12f57eedbe4795fe6e0d97406c5f46f20357f6cdf7a0755d12b3bc3c03ef1a</i><br /><br />Threat actor <b>description</b>: <i>Meilner Mechanical Sales, doing business as Boilersource, is a third-generation, family-owned and proud WBENC certified business.We will upload corporate documents soon. Employees personal information (addresses, phones, DOB, driver licenses, social security cards, credit cards insurance forms with personal information), accounting information, contracts and agreements, NDA etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sullivan-Interests</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26781</link>
<guid>9c32c3ceb9d37c517bf8ff4b2c517e6d</guid>
<pubDate>Thu, 30 Oct 2025 15:24:39 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sullivan-Interests</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7b15e246656107d2c7f7fe7cca91141d503ae27af250c1686b13fb84ad8c5d7</i><br /><br />Threat actor <b>description</b>: <i>The Sullivan Brothers Family of Companies (SBFC) offers a diverserange of services in environmental remediation, disaster recovery, health, construction, infrastructure, and industrial sectors across North America and beyond.We will upload 40gb of corporate documents soon. Employees personal information (passports, addresses, phones, DOB, driver licenses, social security cards, w-9 forms), accounting information, contracts and agreements, incidents and police reports and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Buffalo-Games-Edaron-Ceaco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26782</link>
<guid>ec4a427258aa615cc0b56df3b79683ac</guid>
<pubDate>Thu, 30 Oct 2025 15:24:38 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Buffalo-Games-Edaron-Ceaco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a85a1b22918dc595cab2b493930c64e29e7b952c855de9de18d89a2016044998</i><br /><br />Threat actor <b>description</b>: <i>Buffalo Games is an American company that specializes in board games and puzzles, headquartered in Buffalo, New York. We also tooksome data from Edaron, Inc. and Ceaco.We will upload 34gb of corporate documents soon. Numerous employee docs (passports, driver licenses, social security cards, w-9 forms), accounting information, contracts and agreements, client information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ANSELL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26773</link>
<guid>dd939412d661b27a92e611a89e977f0a</guid>
<pubDate>Thu, 30 Oct 2025 14:17:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>ANSELL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d982295a530be16fd622d20f6481e46da5fd05c7d62dacad0291bcfcfe27b5e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Gerson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26774</link>
<guid>f54b03e4f11c8bd9920741657069c6b6</guid>
<pubDate>Thu, 30 Oct 2025 13:25:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Gerson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6bbdf7c0995b5b2198bf21ff3ca8fb7d74af740424a40aa80dd8505e47e3e258</i><br /><br />Threat actor <b>description</b>: <i>Gerson is a company specializing in high-quality respiratory protection products, including NIOSH and FDA approved respirators, masks, and filter systems. Their product range includes various styles such as molded masks, half masks, and full face masks, catering to diverse industrial and health needs. We are going to upload company data soon. You will find financialdata (audit, payment details, financial reports, invoices), detailed employees and customers information  (medical information, emails, phones)  and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>RPI-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26775</link>
<guid>2948bc9a490e9251ad1c9be2bc2796cb</guid>
<pubDate>Thu, 30 Oct 2025 13:25:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RPI-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09536188f99ae28bcc2326c842c2b69ce299c37099ef2304880c69fcb31e74b7</i><br /><br />Threat actor <b>description</b>: <i>RPI Roofing specializes in providing professional commercial roofing services for businesses in the southeastern United States.We will upload 90gb of corporate documents soon. Detailed employee information (addresses, phones, DOB, driver licenses, social security cards and so on), financial information, internal confidential files, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Econo-Pak</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26776</link>
<guid>1ef97cba05f5ab8401445bec0d6d523f</guid>
<pubDate>Thu, 30 Oct 2025 13:25:08 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Econo-Pak</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12b30a8d748149bd4854797dce5af24ee7389ed539938493123cc5a6316336ea</i><br /><br />Threat actor <b>description</b>: <i>Econo-Pak is a food packaging expert. They help growing companiesand Fortune 500 clients package food products at a fixed price.We are going to upload company data soon. You will find financialdata (audit, payment details, invoices), detailed employees and customers information  (emails, phones)  and other documents withdetailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apache-OpenOffice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26777</link>
<guid>aa48055d254b34d08c1a88a7c92c58cd</guid>
<pubDate>Thu, 30 Oct 2025 13:25:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Apache-OpenOffice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fbcdcb2a4836a094a97641502f6734cd524822a0c625c029233f951ed329e93</i><br /><br />Threat actor <b>description</b>: <i>Apache OpenOffice is an open-source office productivity software suite developed by the Apache Software Foundation. It was createdas a successor project of OpenOffice.org, itself a successor to StarOffice.We will upload 23gb of corporate documents soon. Employee information (addresses, phones, DOB, driver licenses, social security cards, credit cards information and so on), financial information, internal confidential files, lots of reports about their problemswith the application and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>halifax.k12.va.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26787</link>
<guid>56c12a4512e84416de450db11ab040c3</guid>
<pubDate>Thu, 30 Oct 2025 13:09:27 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>halifax.k12.va.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>130cff506a529880c778ab7b7b659691214db8d6536372780818c68d0da484f2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>halifax.k12.va.us</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spindletop-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26772</link>
<guid>2e28dda26c212b9fddfcfa1e44ab97b1</guid>
<pubDate>Thu, 30 Oct 2025 09:53:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Spindletop-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2ae7622d9d3e87720eed2f7bf72a4de7fb8109971d53d6e6b7c3bfdc17809aa</i><br /><br />Threat actor <b>description</b>: <i>Spindletop Center Spindletop Center is a non-profit healthcare organization focused on providing behavioral healthcare, as well as programs for individuals with intellectual and developmental disabilities and substance use recovery services. Over 100,000 patient records (address, phone number, passport number, social security number, diagnosis, medical history, etc.)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evolve-Mortgage-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26770</link>
<guid>c5ba6c2c3073e705c04fab652e3482f3</guid>
<pubDate>Thu, 30 Oct 2025 03:22:46 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Evolve-Mortgage-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7054d4dc61ab4aa43886913a4058373a1e449789af3e1909d3082e77decbf736</i><br /><br />Threat actor <b>description</b>: <i>Introducing Evolve Mortgage Services, the old company name mrn3.com. We stole more than 20 TB of company data. Including 2TB of databases. This company refused to resolve the issue with us with the security of its customers' data. This company does not care about the safety of its customers. They don't care about leaks and disclosure of your data. We have all the data on all clients of both companies since 2016. SSN numbers, scans of client IDs, home and work addresses, personal, home and work phone numbers, FULL credit history about each client. Personal and confidential PII form information for thousands of citizens of the United States of America.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>nationalcoatingsinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26769</link>
<guid>1adfb4bd48c63abb9cd5e5cb2311b319</guid>
<pubDate>Thu, 30 Oct 2025 01:24:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>nationalcoatingsinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edcbfb1d60f365f82219873282118dbcf882e2a2f9e954e991efd2cb66ba3421</i><br /><br />Threat actor <b>description</b>: <i>National Coatings is a trusted commercial and industrial painting company servin...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Time-Equities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26764</link>
<guid>aa40d567c94a14b2e9c126c1b043457d</guid>
<pubDate>Wed, 29 Oct 2025 19:15:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Time-Equities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c27358f1b200c30ed7d3f50f93afec5eaacdc8e435f65051a5eb8a14363ee641</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Time Equities is a globally diversified real estate firm, founded in 1966, based in New York City. The company focuses on 3 main aspects: acquisition, development, and management of properties. It handles a variety of types, ranging from office and retail to industrial and residential. They have properties in 30 states in the US, as well as in Europe and Canada.</i><br />Target victim <b>website</b>: <i>timeequities.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>OpenEyes-Technologies-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26761</link>
<guid>9978e9e9fb93fb29863fa07903d01010</guid>
<pubDate>Wed, 29 Oct 2025 18:25:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>OpenEyes-Technologies-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6675c342b7707cf28fa7a9dbc553fa8d2ede8416e1cc79ebbb360cf5463548c4</i><br /><br />Threat actor <b>description</b>: <i>Confidential data from two companies OpenEyes Technologies Inc. and OpenEyes Software Solutions Pvt. Ltd (OPC) Corporate office, Suite #405, 4th Floor, Iscon Atria 1, Gotri Road, Vadodara – 390021, Gujarat – India . OpenEyes Technologies Inc. Headquarter · 1629 K Street, NW Suite 300. Washington, DC 20006 · +1.202.349.5858. Email address. dc@theOpenEyes.com ; ODC (India)</i><br />Target victim <b>website</b>: <i>theopeneyes.com</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phillips-Printing-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26744</link>
<guid>6713524ea458bee4d73485010e9c682f</guid>
<pubDate>Wed, 29 Oct 2025 18:24:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Phillips-Printing-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c4068eca2d0de05f2a97281ff80545047ae4c56718086f1c9b8a86b1c5c18ee</i><br /><br />Threat actor <b>description</b>: <i>This is a commercial printing house that deals with design, offset and digital printing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bell-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26745</link>
<guid>75ad20f9c546aef9e9fcc21e08a8a3dd</guid>
<pubDate>Wed, 29 Oct 2025 17:25:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bell-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d402d6a6f14d080917c8ed5c8dab4d0b8f5cfaa43e759dcec32bc2e8de813475</i><br /><br />Threat actor <b>description</b>: <i>Founded in Lexington, Kentucky in 1914 by Howard K. Bell, Bell Engineering has earned a solid reputation as a provider of solutions-based, innovative engineering applications that fulfill the needs of communities and industries around the country.We will upload corporate documents soon. Clients information, employee information, detailed financial information, projects, contracts and agreements, lots of specifications and drawings, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ritz-Clark--Ben-Asher</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26746</link>
<guid>a3171cc0f610fdfdf460831fb25a3dc7</guid>
<pubDate>Wed, 29 Oct 2025 17:25:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ritz-Clark--Ben-Asher</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93b6cb22ffb6df0154f063540916586d8560b2b63d637f201a21930bacc532df</i><br /><br />Threat actor <b>description</b>: <i>Ritz Clark & Ben-Asher LLP is a nationally recognized law firm focused on representing individuals facing employment-related legalissues.We will upload 109gb of corporate documents soon. Lots of clientsdocuments (passports, driver licenses, social security numbers, I-9 forms, and so on), same information of employees, detailed financial information, lots of legal documents, court cases, hearings, police reports, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Price--Ramey-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26760</link>
<guid>73bf740ed941e13e76e67049a5165b91</guid>
<pubDate>Wed, 29 Oct 2025 16:54:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Price--Ramey-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>725a2faf2f1c3ca4fcfb0fa1b8301cc5704970e4f4e1888fb80ab63fabee2f11</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.priceramey.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wright-Gardner-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26742</link>
<guid>497e5e9501f2ffbc07b4db02c8c5421e</guid>
<pubDate>Wed, 29 Oct 2025 16:25:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wright-Gardner-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9fdbc09853263fd905cc8d1dacacf3c0f05e433e9dbce3efd5310cd7e86e1978</i><br /><br />Threat actor <b>description</b>: <i>Wright-Gardner Agency offers customized insurance solutions for individuals and businesses, including home, auto, life, and commercial insurance options.We will upload more than 12gb of corporate documents soon. Clients and customers information (financials, contacts, contracts), detailed employee information (DOB, driver licenses, phones, addresses, emails, emergency contacts and so on), lots of confidential files, contracts and agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clarion-Safety-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26750</link>
<guid>10ce671d55af2d7a7be6fbc8d028cdf1</guid>
<pubDate>Wed, 29 Oct 2025 16:19:31 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Clarion-Safety-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82ba9b39728c704522a3647af2004e940ead0b497d0f6c3e0745a68f486d3882</i><br /><br />Threat actor <b>description</b>: <i>Clarion Safety is at the forefront of product and workplace safet
y communication, leading the best practice ANSI and ISO standards
in these areas for over three decades. 

We will upload more than 40gb of corporate documents soon. Client
and customers information (addresses, phones, DOB, numerous form
s with personal information), employees information (DOB, phones,
emails and other HR information), detailed financial information
, confidential files, NDA, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>reesegroupinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26758</link>
<guid>acd58adfb79073f8cbe2bdc0a3201968</guid>
<pubDate>Wed, 29 Oct 2025 15:24:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>reesegroupinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43f8c6e6165c68d4f52c57c021a91318178f23f56cde24b7b18dd7708ef1faba</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>reesegroupinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>southernspecialtysupply.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26747</link>
<guid>d8e04b16451f7f67a5da5005d4e032ee</guid>
<pubDate>Wed, 29 Oct 2025 15:23:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>southernspecialtysupply.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1127203fd0de25a1b3c3527bbb1c15180d902e11b0b70119c0f0cec2772c96c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.southernspecialtysupply.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>tanyacreations.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26748</link>
<guid>8e6386593ca0e8602ff05a069fa23777</guid>
<pubDate>Wed, 29 Oct 2025 15:23:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>tanyacreations.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>daa9281d79cd88d1708fc076e709203ba8c749d5932377dd72867dc549026007</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.tanyacreations.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Simon-Property-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26743</link>
<guid>e150c862ec07920e8c0a6809302fb2a2</guid>
<pubDate>Wed, 29 Oct 2025 15:17:41 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Simon-Property-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b06296fa3bad1d27287c3226d4515b461ac48c3b9ef9312d16ca77e5d8f96aa</i><br /><br />Threat actor <b>description</b>: <i>Simon Property Group is a leading real estate investment trust (REIT) based in Indianapolis, Indiana. Founded in 1993, it owns, develops, and manages premier shopping malls, outlets, and lifestyle centers across the United States and internationally. The company’s well-known properties include Premium Outlets and The Mills centers. Led by CEO David E. Simon, it focuses on creating high-quality retail and entertainment destinations that attract millions of visitors each year. Despite challenges from online retail, Simon Property Group continues to innovate by combining shopping, dining, and mixed-use spaces, maintaining its position as a global leader in retail real estate. company is headquartered in 225 West Washington Street, Indianapolis, Indiana 46204, USA. 3,000 employees </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>renrns.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26755</link>
<guid>b105ac0f79d9e167dbc3ea6d69e6145a</guid>
<pubDate>Wed, 29 Oct 2025 13:55:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>renrns.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7473d7f444329231656c5e630b3ceb3002759cc173426963539170cf5600ba0</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>renrns.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>upea.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26754</link>
<guid>ead3f24f650fcf6d8936af5c23ecafc4</guid>
<pubDate>Wed, 29 Oct 2025 13:54:24 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>upea.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>934097135500afa3e91cc8de65a61162e7d9a7e451481682ba62d06dd6046b71</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.upea.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>chirhochiropractic.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26753</link>
<guid>8ad259d840bf6a763d6c1805d5c714c8</guid>
<pubDate>Wed, 29 Oct 2025 13:53:47 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>chirhochiropractic.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>caeafc77174d7d1a9ea3c09e71a8459f27f563bafcf1c97f828806fda885cd50</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.chirhochiropractic.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>echolakefoods.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26751</link>
<guid>3fa14ed7b5855de1e9a3cf48677fa60c</guid>
<pubDate>Wed, 29 Oct 2025 13:52:32 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>echolakefoods.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af905c9c561c93267fe61ad93287084c02124cb75216ef058a9d51f5c88d2460</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>echolakefoods.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sadler-Gibb--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26738</link>
<guid>423e44c6ee3fc6678aefa0f854160482</guid>
<pubDate>Wed, 29 Oct 2025 13:24:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sadler-Gibb--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>542101c5d3525fe982e3930821cb4092324c08993693da0acaca5bd5dbc7b29a</i><br /><br />Threat actor <b>description</b>: <i>Sadler Gibb is a certified public accounting firm dedicated to providing professional financial services to businesses and individuals. They specialize in tax planning and preparation, financial statement audits, business advisory, bookkeeping, and payroll processing. We are ready to upload more than 65GB data. There are lots of essential corporate documents such as: financial data (audit, payment details, invoices), detailed employees and customers information (passports, driver's license , Social Security Numbers, death/birth certificate, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>G--H-Distributing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26734</link>
<guid>88186ae4f3d59234d5b515b1ca86660f</guid>
<pubDate>Wed, 29 Oct 2025 11:25:04 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>G--H-Distributing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25e002ae07560acf2692c30eefa6b1c2e306881467eea593222f260a82a9139f</i><br /><br />Threat actor <b>description</b>: <i>GH Distributing Inc. is a prominent agricultural and industrial supply distributor in South Dakota, known for its retail and wholesale operations.This company will soon be known as another one that doesn't care of employee information. We will upload corporate documents soon.You will find lots of 2-9 forms with addresses, phones, emails and other information of employees. Also there are accounting files, projects, client information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bridgehead-I.T</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26735</link>
<guid>83d8be72f731a9977c2ac9e41807ac0d</guid>
<pubDate>Wed, 29 Oct 2025 11:25:01 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bridgehead-I.T</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b3c06e6cb60518bf7e10547a04be9975f37c12bce60df77b6e99a02f9e4897e</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1999, Bridgehead I.T. Inc. provides customized Information Technology (IT) solutions for businesses across all industries. Bridgehead I.T. services are specifically engineered for eachclient needs. Bridgehead I.T. is headquartered in San Antonio, TX.We are going to upload company data soon. You will find financialdata (audit, payment details, invoices), personal financial details of employees, accounting files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pritchard-Brown--Chillicothe-Metal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26733</link>
<guid>4ec227f2c9f8dd31ccb23834f1022721</guid>
<pubDate>Wed, 29 Oct 2025 06:24:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Pritchard-Brown--Chillicothe-Metal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1da4c8fc99a5ec8f940f00ee3f1a37a3a81670fb254b69b0c3a0f9b4e75d581</i><br /><br />Threat actor <b>description</b>: <i>Pritchard Brown and Chillicothe Metal Company (CMCO) are two manufacturers that collaborate to develop comprehensive solutions in the field of protective enclosures and microclimate control systems. Founded in 1947, Pritchard Brown specializes in custom-designed protective enclosures, offering a range of weatherproof, weather-resistant, and noise-absorbing models specifically designed for harsh operating environments. With over 50 years of experience, Chillicothe Metal Company complements Pritchard Brown's offerings by specializing in protective enclosures and complete generator sets. Operating in a wide range of industries, including energy, utilities, petrochemical, mining, and defense, CMCO has completed more than 40,000 projects at facilities around the world. Its expertise in design, engineering, and manufacturing is evidenced by its work on high-profile projects such as the Statue of Liberty and NASA.</i><br />Target victim <b>website</b>: <i>pritchardbrown.com & cmcousa.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-Spectrum-Environmental-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26729</link>
<guid>35b47299c1130953d286c976e9c608dc</guid>
<pubDate>Tue, 28 Oct 2025 22:53:57 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Florida-Spectrum-Environmental-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a1686f90eb09135d17c44d4896916410c0aed24feab2c0cafd2adfc4954c9d8</i><br /><br />Threat actor <b>description</b>: <i>Florida-Spectrum Environmental Services, Inc. is a premier full-service environmental testing and analytical chemistry laboratory specializing in the assessment of contamination in various mediums, including water, soil, and hazardous wastes. With over 40 years of experience and multiple locations in Florida and Georgia, the company serves the Engineering, Consulting, Chemical, Petroleum, and Waste Management industries. They offer a range of analytical and sampling services, supported by a commitment to superior service and client satisfaction through dedicated Client Service Managers. Their philosophy emphasizes building partnerships with clients, ensuring that the data quality objectives of environmental projects are met efficiently.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>WarmBlue</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26728</link>
<guid>6c0924840f28f96026147e2cde8420af</guid>
<pubDate>Tue, 28 Oct 2025 21:49:16 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>WarmBlue</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f8fba7754e7cf8fa97391bd7f2d59db3832b7654372f9c567d312216a040a2db</i><br /><br />Threat actor <b>description</b>: <i>Small company</i><br />Target victim <b>website</b>: <i>www.warmblue.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heimbrock</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26725</link>
<guid>9a65d8f681eb161006ac959a570600f5</guid>
<pubDate>Tue, 28 Oct 2025 21:18:26 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Heimbrock</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8def9888c0b2e137d35ce4915a15c9aa5e0f7169c4be64263e611769afd00f59</i><br /><br />Threat actor <b>description</b>: <i>Heimbrock Inc. is a national refractory contractor.</i><br />Target victim <b>website</b>: <i>heimbrock.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eligibility-Tracking-Calculators</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26727</link>
<guid>a4376b1e16378bd96b9ca18a1efb03a8</guid>
<pubDate>Tue, 28 Oct 2025 21:14:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>Eligibility-Tracking-Calculators</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>98b00bff53b61e9461e557dbf943bd4aad9d19da1af756275ec58095b6022f67</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "Eligibility Tracking Calculators" (ETC) is a company that offers technological solutions for employee benefits management. It provides software applications that help employers, insurance brokers, and CPA firms to track and calculate their employee benefits eligibility efficiently. This assists organizations in adhering to various legal compliance requirements related to employee benefits.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>MASTEC.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26705</link>
<guid>066dac329055466b3d5094adc421744f</guid>
<pubDate>Tue, 28 Oct 2025 19:24:06 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MASTEC.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>199a5002b9020dd6b6437baf7d31454109623a96111192bbb4fa8b763614be4d</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lorber-Greenfield--Polito-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26722</link>
<guid>610126195c0f6e4df38f399c3325aecb</guid>
<pubDate>Tue, 28 Oct 2025 18:20:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Lorber-Greenfield--Polito-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97050bfa8c87b289a8d34fb510b24617dff0c8f98b641693d70eb5f5032e56ee</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.lorberlaw.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gemini-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26721</link>
<guid>a16b5a3c25b73ce4e3445e369749dd43</guid>
<pubDate>Tue, 28 Oct 2025 17:43:07 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Gemini-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>295e4f44cf24180e6678982afe9da61403ad7b709fc7c283599ff23c76366540</i><br /><br />Threat actor <b>description</b>: <i>Gemini Group</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henry-Raymond--Thompson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26720</link>
<guid>24ed200dcfcc1b04fad9d6e361e41ac9</guid>
<pubDate>Tue, 28 Oct 2025 17:41:28 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Henry-Raymond--Thompson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c9591050c71f74b85e39b95478efc909c7a993ec44dbf71a40bed43d874111e3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hrmtcpas.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Evogence</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26719</link>
<guid>58977814981a9bab5e4495ab61d13efa</guid>
<pubDate>Tue, 28 Oct 2025 17:40:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Evogence</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>efa478c89e1afacdd1936862fe2b51cbee0aeb972274b25d79c02efe650bb40e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.evogence.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Super-Quik</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26718</link>
<guid>e704bb84211a84111e4c138a17e68edb</guid>
<pubDate>Tue, 28 Oct 2025 17:40:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Super-Quik</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7e6223e95a57c799497b83521f4b325fae838baffb21ad28690a1f5ff9b4c93</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.superquik.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aphase-II</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26716</link>
<guid>4815717d5a93704f7d9f0e23dd3d78fc</guid>
<pubDate>Tue, 28 Oct 2025 17:38:52 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Aphase-II</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93ee9fe49ed38a3149dc7d316f5fc851796a63dcbdad6d68ca8834d83f7ec8ce</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.aphaseii.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kitchen-Design-Concepts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26715</link>
<guid>36bf351df23d91002df48e5c8c78e635</guid>
<pubDate>Tue, 28 Oct 2025 17:38:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Kitchen-Design-Concepts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a7f434ab4ba43482969a13db78f634713a53a1d4fc2434eabc64495cbac0910</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.kitchendesignconcepts.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sylvester-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26712</link>
<guid>621937d0e97e2559f2170a66a2218089</guid>
<pubDate>Tue, 28 Oct 2025 17:36:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Sylvester-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6b4e026888f0af47a992d05fb0085a1aecc6973d44b70632f9ddc446d452ac2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.sylvesterroofing.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>BK-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26698</link>
<guid>45b60dbddc4b267a67ced2c509beb4f2</guid>
<pubDate>Tue, 28 Oct 2025 17:24:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>BK-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af2f4616eb9bb7090ee3e8a5a297cc21f389fac8bf8e57de0776de9c7a39f743</i><br /><br />Threat actor <b>description</b>: <i>BK Technologies mission is to remain deeply rooted in the critical communications industry for all military, first responders, andpublic safety heroes.We will upload 25gb of corporate documents soon. Employees information (phones, emails, addresses, medical cards and so on), accounting and financials, lots of confidential agreements, military contracts, contracts with BOSCH and other companies, NDA, credit card information, payment details, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Boyer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26699</link>
<guid>1124ba177f7d0f77f243297b70d5b005</guid>
<pubDate>Tue, 28 Oct 2025 17:24:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Boyer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e494613f2b2be43bed3a988df371710fa24fceb942548feae6b62e8ad350351</i><br /><br />Threat actor <b>description</b>: <i>Boyer Company is a leading commercial real estate development andconstruction management firm based in the Western United States.We will upload more than 13gb of corporate documents soon. Clientinformation, detailed accounting and financials, w-9 forms with personal information, lots of agreements and other internal docs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>fhw.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26711</link>
<guid>45fe7c4d0a9c4104b3157fea2f233ad5</guid>
<pubDate>Tue, 28 Oct 2025 17:14:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>fhw.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c782cc052c45ffd358875c53992264d6790b9405ae2b82213a18652908e273b9</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 700k
120gb</i><br />Target victim <b>website</b>: <i>fhw.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bergman-Dacey-Goldsmith</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26693</link>
<guid>14d9f3a29e7fb45297564da4fe44473e</guid>
<pubDate>Tue, 28 Oct 2025 14:24:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bergman-Dacey-Goldsmith</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9676464a3b93639773e61cf4147308dcec3e0d8aef5b5c12cff7243abe9064f0</i><br /><br />Threat actor <b>description</b>: <i>BDG Law Group is a full-service law firm based in Los Angeles, specializing in business litigation, construction law, real estate,and various other legal services. We will upload 110 GB of corporate documents soon. Complete personal information of employees and clients (phones, emails, addresses, driver licenses, passports, social security numbers, confidential legal files, court hearings, police reports, medical information and is on), accounting and financials, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>CESO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26696</link>
<guid>a03175e68893309a3c69d0b9e018bcca</guid>
<pubDate>Tue, 28 Oct 2025 14:08:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CESO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a8a8a0d50d723dccf8eba89d488822855c1dbc5a81b3bb33dba73e31d4e7839</i><br /><br />Threat actor <b>description</b>: <i>CESO is a comprehensive firm offering multi-disciplinary capabili
ties through our ability to provide surveying, landscape architec
ture, civil engineering, environmental, architecture, and interio
r services to our clients.

We will upload corporate documents soon. Very detailed personal e
mployees information (passport scans, SSN lists, driver licenses,
phones, emails, addresses, medical cards and so on), accounting 
and financials, confidential clients projects and other files, lo
ts of NDA, credit card information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Productive-Tool-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26697</link>
<guid>2e7f535455049bda7e8c9df49e3d293c</guid>
<pubDate>Tue, 28 Oct 2025 13:48:09 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Productive-Tool-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d35020c3db25fa397ec52a5789977252f7c7f2f0ac2417f8c7412459132a7df2</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.ptpsystems.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bellflower-Unified-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26695</link>
<guid>ff0a431a29c728e766168d412be85567</guid>
<pubDate>Tue, 28 Oct 2025 12:55:12 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Bellflower-Unified-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc73d24e9a17697a89a88ec0f429ceafeef2155e1069082cb4f4f2c2251a9342</i><br /><br />Threat actor <b>description</b>: <i>Bellflower Unified School District Headquartered Bellflower, California, Bellflower Unified School District is a general education district that offers K-12 classes.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Axelson-WilliamowskyBender--Fishman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26692</link>
<guid>2d564b42a715a624dbc939d5434e6262</guid>
<pubDate>Tue, 28 Oct 2025 12:24:58 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Axelson-WilliamowskyBender--Fishman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41194a9e3a1a2d55ca548463f2041968b25dc8bcf8dfd516c21f66452223c5b5</i><br /><br />Threat actor <b>description</b>: <i>Axelson, Williamowsky, Bender & Fishman, P.C. is a full-service law firm serving the Washington Metropolitan Area with over 100 years of combined experience. They offer a wide range of legal services including personal injury, family law, estate planning, realestate, and business law. We are ready to upload more than 100GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), detailed employees and customers information (passports, driver's license , Social Security Numbers, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Riddell-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26694</link>
<guid>9577390e8eeb4fae6241266d2f2ab279</guid>
<pubDate>Tue, 28 Oct 2025 11:11:14 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Riddell-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fe97dbce8463a709fd014c7a06f7738a55b812fee6ca253701edaae3e19736c</i><br /><br />Threat actor <b>description</b>: <i>Real Estate Law, Title Insurance, Probate Estate Planning, Bankruptcy, Foreclosures/Short Sales</i><br />Target victim <b>website</b>: <i>rlglawfirm.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jimfor-S.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26691</link>
<guid>408c43f7f18fd6b4f50bf3857aecbd3f</guid>
<pubDate>Tue, 28 Oct 2025 05:11:55 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ciphbit</b> claims attack for <b>Jimfor-S.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe7657620d0a90efbb07dcc7c5eb8ec6f1f2d6991433ccef236dd5a3d2edbcf0</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>jimfor.com</i>]]></description>
<category>ciphbit</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advantage-CDC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26687</link>
<guid>ffc7ad29e9362b828655bba4a3fe60dc</guid>
<pubDate>Tue, 28 Oct 2025 02:13:42 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Advantage-CDC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1336d7009aa7dbd41de4d9ffe1c36dcf9db839cf10f8b08b286359ca3eee723c</i><br /><br />Threat actor <b>description</b>: <i>A company that provides long-term loans</i><br />Target victim <b>website</b>: <i>advantagecdc.org</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kipp--Christian</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26688</link>
<guid>4cb9b6afe97b8c5fffb19af9227f8a36</guid>
<pubDate>Tue, 28 Oct 2025 02:13:23 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Kipp--Christian</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a615e20ad94294f54c59e7d043ee22e7c7c1dac2320da2c7f0f57c5e838afe6e</i><br /><br />Threat actor <b>description</b>: <i>A law firm located in Salt Lake City</i><br />Target victim <b>website</b>: <i>kippandchristian.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cohens-Fashion-Optical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26689</link>
<guid>2c1b748dffe74069de48429ee20cfc96</guid>
<pubDate>Tue, 28 Oct 2025 00:26:53 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Cohens-Fashion-Optical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a49f70c13d9d476c9eceb2b10e7235046fd0ba8240d4640bc29eec496b1ed5e7</i><br /><br />Threat actor <b>description</b>: <i>Cohen's Fashion Optical (formerly known as Cohen's Optical) is an optical retailer headquartered in New York City featuring fashion products such as eyeglasses, frames and sunglasses, lenses, contact lenses, and accessories. Professional eye exams are usually available with on-site Doctors of Optometry</i><br />Target victim <b>website</b>: <i>cohensfashionoptical.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>usbmemorydirect.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26686</link>
<guid>cf1974d028f1a6ad6378cdc9539853b3</guid>
<pubDate>Mon, 27 Oct 2025 20:47:59 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>stormous</b> claims attack for <b>usbmemorydirect.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>26dd35e0074f20229b5f7f285756a02f305b60c538229a59d156603724996848</i><br /><br />Threat actor <b>description</b>: <i>Personal data (individual names, photos, etc.), company/business data (company names, services, tools, equipment), backup copies, system archive compressed files, internal documents and project files, and more.</i><br />Target victim <b>website</b>: <i>usbmemorydirect.com</i>]]></description>
<category>stormous</category>
</item>
<item xmlns:dc='ns:1'>
<title>MedImpact-Healthcare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26681</link>
<guid>53cdd4182f8d7e4b71e9b598f46f814b</guid>
<pubDate>Mon, 27 Oct 2025 20:18:33 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>MedImpact-Healthcare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7f15d1ff7572369ad384ff43aee76ad6da340d4a60fbeb4f1d203d09af207694</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.medimpact.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Navigator-Business-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26680</link>
<guid>5b6f477594a1fa41586e0ee57d76daba</guid>
<pubDate>Mon, 27 Oct 2025 20:15:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>Navigator-Business-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c70bbc6950aa84015d500af7619e2407c4592367d1abe5ec746a61985b71d47</i><br /><br />Threat actor <b>description</b>: <i>Life Sciences/Biotechnology, Distribution, and Consumer Products Organizations come to Navigator Business Solutions when they find their ability to grow and or adapt is being limited by their current business processes and systems.</i><br />Target victim <b>website</b>: <i>www.navigatorbusinesssolutions.com</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>SanDiego-Automotive-Museum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26674</link>
<guid>37db198a94d1b7770f36244f1fda20ca</guid>
<pubDate>Mon, 27 Oct 2025 18:25:03 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>SanDiego-Automotive-Museum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1f34aec300db53bce97d0511375ad08014e2b551bd3c52388294a43be20cf16</i><br /><br />Threat actor <b>description</b>: <i>The San Diego Automotive Museum is a premier transportation museum located in Balboa Park, dedicated to showcasing the history and evolution of motorized vehicles through its collections and exhibitions. It offers educational programs and community events aimed at both automobile enthusiasts and casual visitors. The museum services local residents and tourists, providing a rich experience for anyone interested in the social and technological impact of vehicles. With various membership options and ongoing events, the museum also focuses on career exploration and hands-on learning through its IGNITE Academy.</i><br />Target victim <b>website</b>: <i>www.sandiegoautomotivemuseum.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Double-Oak-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26676</link>
<guid>efdbf45bfc950fc5a2ac0e1511a354b8</guid>
<pubDate>Mon, 27 Oct 2025 18:21:44 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Double-Oak-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6144c374eede664fa3418a735eb6ed2f295fd0f780c2d98dbe53cd1b9ce17cf7</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.doubleoakinc.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Engineered-Profiles</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26660</link>
<guid>faa346cce8568de3e8822f5857d6b918</guid>
<pubDate>Mon, 27 Oct 2025 17:24:25 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Engineered-Profiles</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56d074eccfe0451cfd1f057f4c8a02f4b94f40e1d12547d03976a4e72746d719</i><br /><br />Threat actor <b>description</b>: <i>Engineered Profiles specializes in high-quality plastic extrusion, design, and advanced manufacturing technologies.We are ready to upload more than 56gb of corporate documents. Employee information (social security cards, driver licenses, medical information, addresses, phones and so on), projects, customer information, accounting, confidentiality agreements, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Henrietta-Ezeoke-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26669</link>
<guid>69a2835d20b8290bc7984b8aa6538f89</guid>
<pubDate>Mon, 27 Oct 2025 17:11:20 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Henrietta-Ezeoke-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07f5e7c38df1e6c4f4ad788e2d91e8c1e60a2c40157a38f1c4995003f1ac8f8f</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>houstonwrongfuldeathlawyers.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Izaki-Group-Investments</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26668</link>
<guid>b68e8a73610d9aeeef7b5a2bfffbcb7f</guid>
<pubDate>Mon, 27 Oct 2025 17:10:36 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Izaki-Group-Investments</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4c613d7bb5872a85aec973cf0f08e4c05aa402c408d6f58c2132fdf5dee252a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>www.izaki-group.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maki-Building-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26666</link>
<guid>b34caaa41c545122c9b31631174b7015</guid>
<pubDate>Mon, 27 Oct 2025 15:48:11 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Maki-Building-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56e689e86b0a8188aded5cbb08a369bfdc60280bdec1a55a7a18c0133af33c67</i><br /><br />Threat actor <b>description</b>: <i>Maki Building Centers is a company engaged in commerce and manufacturing with three branches in central Massachusetts. The company has warehouses, manufacturing facilities, large volumes, and financial resources! Security was very low, and the entire system was successfully compromised and taken over. Company, employee, and customer data ended up in our hands and, accordingly, in the public!</i><br />Target victim <b>website</b>: <i>makicorp.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Abilene-Family-Medical-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26662</link>
<guid>858ec5a3b980fd513684df12b8683db9</guid>
<pubDate>Mon, 27 Oct 2025 13:12:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Abilene-Family-Medical-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>660062de0f910e168720ba3ab89d971a073505591b786943cfdf67af03f90b3c</i><br /><br />Threat actor <b>description</b>: <i>Abilene Family Medical Associates</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Flegenheimer-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26656</link>
<guid>0a979f021ded11b1db1a9468d6a65826</guid>
<pubDate>Mon, 27 Oct 2025 11:24:43 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Flegenheimer-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f8c394f0927cb49a4b417664022ed0586f8020859bec3592168459202731732</i><br /><br />Threat actor <b>description</b>: <i>Flegenheimer International is Licensed Customs Broker company based out of 227 W Grand Ave, El Segundo, CA, United States.We are ready to upload more than 16gb of corporate documents. Employee information (address, phones and so on), customer information, accounting and other business files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miami-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26657</link>
<guid>389c96d539ed67bd670f0a32d9765469</guid>
<pubDate>Mon, 27 Oct 2025 10:49:45 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Miami-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77b07040eea1e6d64ad61442e97521923d95e06388b5876b410a66884935c2a4</i><br /><br />Threat actor <b>description</b>: <i>A licensed and insured company providing a full range of property management services</i><br />Target victim <b>website</b>: <i>miamimanagement.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>LaBonne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26649</link>
<guid>bc27eb4af89384b95ab89cc980814502</guid>
<pubDate>Sun, 26 Oct 2025 19:49:02 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>LaBonne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c0af67fdd8c336c78e8d2c8ccfb5bd973e1d9ad41ec185d14050fabaee6b503</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.labonnes.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metal-Pros</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26648</link>
<guid>e74f0b8cc8a53963231216f649076da0</guid>
<pubDate>Sun, 26 Oct 2025 19:48:19 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Metal-Pros</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3912e621fa7cfb1adede18c24ca4fcf962de6753ad60b28c356bbbb5d33f99b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.metalprosllc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Alabama-Regional-Planning-Commission</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26644</link>
<guid>612b1105e9636bffe0afd71b33a854a8</guid>
<pubDate>Sun, 26 Oct 2025 16:24:34 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>South-Alabama-Regional-Planning-Commission</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ffc659c694c9f45e1f84c4fb7fb1f96520ae7b219d736c19969f06c4382afc9</i><br /><br />Threat actor <b>description</b>: <i>SARPC is a locally controlled and organized instrument of local government in Southwestern Alabama, serving Mobile, Baldwin, and Escambia counties, along with twenty-nine municipalities. The organization provides programs and services focused            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>auge.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26643</link>
<guid>de06ce4800bd5a95f4dc7312700c3e3e</guid>
<pubDate>Sun, 26 Oct 2025 11:55:10 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>auge.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47be95383943acdd506a169bfffef5e89215be332e3fabeb62c36408e7f0def</i><br /><br />Threat actor <b>description</b>: <i>Industrias Auge S.A de C.V is a company that specializes in manufacturing and distribution of commercial and specialty alloy fasteners, including machined components. It offers alloy fasteners, machined components, anchoring systems, line pipe, boiler and heat exchanger tubing, casing tubing, platings & coatings, fittings, flanges, and structural material. The company was founded in 1965 and is based in Houston, Texas  We have contracts, data of all employees of the company internal mail, drawings and more at our disposal. We will share all this.</i><br />Target victim <b>website</b>: <i>auge.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Latona-Trucking</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26640</link>
<guid>5b85f7b702c448f83eb60d77551e20f3</guid>
<pubDate>Sun, 26 Oct 2025 08:24:51 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Latona-Trucking</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>786e636c686271dc334c43a8ee44cb8c57bdec936fea594f4b1f588e82a71868</i><br /><br />Threat actor <b>description</b>: <i>latonatrucking.com is a company that operates in the Transportation industry. It employs 100to249 people and has 1Mto5M of revenue.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saturn-Machine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26641</link>
<guid>6c9c4ca27e9848025ab5cc56702e797b</guid>
<pubDate>Sun, 26 Oct 2025 08:24:50 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Saturn-Machine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c2a5da1c834d1851d592a65a204cf9df9d013f08f607b5d6b4241aa70a03296</i><br /><br />Threat actor <b>description</b>: <i>Saturn Machine is a leading designer and manufacturer of equipment for major steel companies in North America, specializing in steel fabrication, machining, las...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>West-Welch-Reed-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26642</link>
<guid>08c7bab8988c8f289a3e47c2700dac52</guid>
<pubDate>Sun, 26 Oct 2025 08:24:49 CET</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>West-Welch-Reed-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02357442925628be59bdee76321e4e99299c17cb4d47b4680c92177a3267a39d</i><br /><br />Threat actor <b>description</b>: <i>West, Welch, Reed Engineers, Inc. offers engineering services focused on transforming ideas into tangible projects. They cater to a diverse range of clients, pr...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Precision-Machined-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26638</link>
<guid>79a00b87195cb584d0b3b5358e19f795</guid>
<pubDate>Sat, 25 Oct 2025 22:25:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Precision-Machined-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62129e0a67f21dbaf8469402536ea90ceac18555b707dddacc929aa313def1bf</i><br /><br />Threat actor <b>description</b>: <i>Precision Machined Products is a tier one supplier of downhole equipment for the Oil and Gas Industry.We are ready to upload more than 12gb of corporate documents. Employee information and other HR files, projects, internal confidential files, clients confidential files, lots of specifications and drawings, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Essential-Cabinetry-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26636</link>
<guid>47ff2df82c7ee1eee6a617829de46b22</guid>
<pubDate>Sat, 25 Oct 2025 21:24:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Essential-Cabinetry-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b65e082bdc37fd34795a93f2120f9424a3c838e493fab236dd99ff418486539</i><br /><br />Threat actor <b>description</b>: <i>Simpsonville, SC-based Essential Cabinetry is a manufacturer of custom, semi-custom and stock-plus kitchen and bathroom cabinetry that is sold primarily through the dealer channel. Through its three market-leading brands (Tedd Wood Fine Cabin            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Adore-Children-and-Family-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26631</link>
<guid>5636cbbbf9d5624b172862ee276bec73</guid>
<pubDate>Sat, 25 Oct 2025 18:21:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Adore-Children-and-Family-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be77c40ac8d662dbf7cff4bf33b8f16324210b1176e72108fe367302caee9edb</i><br /><br />Threat actor <b>description</b>: <i>Adore Children and Family Services is a foster care agency dedicated to providing substitute care for children in need. The organization offers a comprehensive range of services, including individual case management, behavioral assessments, and training for foster families.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Sugar-Land</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26627</link>
<guid>659d6880990e3894803d8b8c131c8789</guid>
<pubDate>Sat, 25 Oct 2025 17:24:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Sugar-Land</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b8c75ebe5cba95fba6bf6324857afa95956b5be8cddaffd27380c43ef0361e3d</i><br /><br />Threat actor <b>description</b>: <i>Founded as a sugar plantation in the early mid-20th century and incorporated in 1959, Sugar Land is a city in the state of Texas, in the United States. The city is within the Houston, The Woodlands and Sugar Land metropolitan area and Fort Be            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kaufman--Stigger</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26629</link>
<guid>0d4caa61a340cc953d6d0ec97ecd6180</guid>
<pubDate>Sat, 25 Oct 2025 17:24:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kaufman--Stigger</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1351a62825bb44469189701847f778317156dae64e8a308d52dedc33928e0e72</i><br /><br />Threat actor <b>description</b>: <i>When you call Kaufman & Stigger, PLLC Injury Lawyers, you will talk to a team with decades of experience helping people injured after an accident. Our Louisville-based law firm is focused exclusively on providing counsel to injured clients th            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>DAVIDYURMAN.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26621</link>
<guid>fe8cc9477d746cb4c6d1a0d09ea685cd</guid>
<pubDate>Sat, 25 Oct 2025 15:15:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>DAVIDYURMAN.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>239b1810f4e96af73bcacd4f2ba6ad80ff8528a721bf166f2e10afa43164530e</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>COXENTERPRISES.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26623</link>
<guid>43e9fffa93004c327ce88972bc528eca</guid>
<pubDate>Sat, 25 Oct 2025 15:14:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>COXENTERPRISES.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab09b4086878d336e4bf426e05be24ea1d0ec3f7cb5ed831464999cb9bea1230</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>HRSD.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26624</link>
<guid>b8028b0003882ecaf9ff4f5a92a0cc23</guid>
<pubDate>Sat, 25 Oct 2025 15:13:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HRSD.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7481d3f13852ff18e30df897cbea3839c864e35e6b70f70ebb7185d7cdaa1133</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>MetroWest-Community-FCU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26625</link>
<guid>5d1d848d2a48beb57a1aa5c86fdf2881</guid>
<pubDate>Sat, 25 Oct 2025 14:24:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MetroWest-Community-FCU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b64f6c5538cc51a6ecfd2d63e034f68c29a380e8e6f3071c7d79fce6954dbb5</i><br /><br />Threat actor <b>description</b>: <i>MetroWest Community Federal Credit Union offers a range of personal banking services including checking and savings accounts, mobile banking, and various lending products such as vehicle, home, and personal loans.We are ready to upload corporate and client documents. Lots of clients documents (DLs, birth and death certs and numerous forms with personal information), financial and accounting information, court cases information, employee personal files, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>greenhouseapt.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26616</link>
<guid>e0354c78e2ed7d09be80f3781f7f1c8e</guid>
<pubDate>Fri, 24 Oct 2025 21:22:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>greenhouseapt.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b3e68dc97e4152f4d14356788d1d7f88b5d0a42cb3214a12d21c2078ab29311</i><br /><br />Threat actor <b>description</b>: <i>The Greenhouse is an apartment building and management/letting operation in Boston’s Back Bay / South End that offers 1–3 bedroom …</i><br />Target victim <b>website</b>: <i>greenhouseapt.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>hanson-inc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26613</link>
<guid>7caf3e67c79b93b52339407142ee7198</guid>
<pubDate>Fri, 24 Oct 2025 20:47:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>hanson-inc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53d47c352dd9f82a360c69ec329f65abdbcf98b3e7803b1837136c9109cd67e5</i><br /><br />Threat actor <b>description</b>: <i>Hanson Professional Services Inc. is a national consulting firm that specializes in engineering, planning, and allied services. They provide a wide range of services including aviation, asset management, construction support, and sustainability solutions, catering to various sectors such as healthca…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/hanson-professional-services-inc/1114749567</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hall-Estill</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26615</link>
<guid>6506f30b358ef57db84f257ad7540011</guid>
<pubDate>Fri, 24 Oct 2025 19:43:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Hall-Estill</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6b12f2d5e49e17bd11d9210b253f5e659f5f4f96d14cf61343ee37b1a56db8e</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1966 in Tulsa, Oklahoma, Hall Estill is a full-service law firm with clients ranging from F…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Summit-Hotel-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26609</link>
<guid>8550c8318d98aa713e0ef7c500981dbc</guid>
<pubDate>Fri, 24 Oct 2025 17:24:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Summit-Hotel-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a21377ae39bd01141e0c97ec83659806354664164323c000b545742922f02106</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Essilor-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26610</link>
<guid>df320a984cfb79b17d721a870665cdba</guid>
<pubDate>Fri, 24 Oct 2025 17:24:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Essilor-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af3698f8261cf6c9f4031c3ecebec7f2d08bb275abab94c9f3ab8ef6f1f1ca81</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peruvian-Connection</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26611</link>
<guid>64a9c037f9a4d1f4ad271611c784a92b</guid>
<pubDate>Fri, 24 Oct 2025 17:24:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Peruvian-Connection</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d47eb2a3d41067b06b939e7fefb0528c075dc8d9591aaa4a421d2da286989c7c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>simmerscrane.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26606</link>
<guid>dd4378fa6376a85a4cafc940fbc289f0</guid>
<pubDate>Fri, 24 Oct 2025 10:24:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>simmerscrane.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2682abbb3e9aa6bf8c2352f5d735ec017221ab23f6539c556d38ae8b109a23a2</i><br /><br />Threat actor <b>description</b>: <i>Simmers Crane Design & Services Company was founded in 1958 by Charles Simmers, ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>IREM-companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26600</link>
<guid>958bb6bd458626ce4add509077f3c5df</guid>
<pubDate>Thu, 23 Oct 2025 23:25:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>IREM-companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>637bcc783a448d37d732891d47b46db64345605b25d7d346c8efd9c8c6646193</i><br /><br />Threat actor <b>description</b>: <i>IREM companies, USA - is an international institute for real estate and asset managers, promoting management through education and information exchange. IREM conducts real estate management training courses, organizes national meetings of rea            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>iCare-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26591</link>
<guid>38abae704fb4cdba00a26baa58cb4443</guid>
<pubDate>Thu, 23 Oct 2025 16:18:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>iCare-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff6628620d34ccbd9426ac6427a512bb943715d0513d14f1ab25780890521086</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1997, iCare Software, based in the United States, delivers innovative management solutions for childcare and afterschool programs. Serving childcare centers, preschools, afterschool programs, and multi-site operations, iCare automates critical tasks like attendance tracking, staff scheduling, tuition collection, and compliance reporting. Its unique offerings include AI-driven analytics, business intelligence dashboards, and CRM tools to boost enrollment and staff retention. With seamless data migration and robust back-end technology, iCare empowers providers to focus on quality care while streamlining operations and driving growth.</i><br />Target victim <b>website</b>: <i>icaresoftware.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vanan-Online-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26590</link>
<guid>6df811b75fbf2f0dc32a60ece213f1a3</guid>
<pubDate>Thu, 23 Oct 2025 16:17:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Vanan-Online-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db1156d026f1b2a0fcfda3cb17fdaf15dc638bcb06e45c57ea65e03445f4988f</i><br /><br />Threat actor <b>description</b>: <i>Vanan Online Services offers a comprehensive range of language services, including transcription, translation, captioning, subtitling, voice-over, and typing. They cater to individuals and businesses across various industries, providing solutions in over 100 languages with a focus on quality and affordability. With a commitment to seamless project management and customer support, they ensure timely deliveries and customer satisfaction. The company has built a strong reputation over a decade of service, making them a trusted partner in the language services field.</i><br />Target victim <b>website</b>: <i>vananservices.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>CSCGLOBAL.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26579</link>
<guid>b3caae6857cf5662d007d49b4ace0e05</guid>
<pubDate>Thu, 23 Oct 2025 11:15:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>CSCGLOBAL.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d1df8eb83ec9ed75392094b2164d7daf2b419219d704dffbfba6084e35293d2</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>LKQCORP.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26581</link>
<guid>a79f393b36fd04bbbdd6d344caba8e11</guid>
<pubDate>Thu, 23 Oct 2025 11:12:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>LKQCORP.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d9b74bd2bff1259629325c28e8f2ba979ef3e0e3b6e2d51b538ed6363911ba4</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Real-Estate-Specialists</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26568</link>
<guid>cbf66d053fa53ff5ad8a9e83e2f864be</guid>
<pubDate>Thu, 23 Oct 2025 00:25:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Real-Estate-Specialists</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c9425bd673c07996e91f875a53c709f9e28e80c2b33314c57c3c2c7e7986257</i><br /><br />Threat actor <b>description</b>: <i>Real Estate Specialists is dedicated to managing and maintaining rental properties in southeast Wisconsin, focusing on enhancing their performance since 1982. They offer a comprehensive range of property management services, catering to prope            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Samera-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26569</link>
<guid>3d3f53e1702fe7d002b4dd7d166d1996</guid>
<pubDate>Thu, 23 Oct 2025 00:25:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Samera-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca523123bbc47421d495fdaf0be57fbb522c90cbe6a1b3a84eb94cbce084e811</i><br /><br />Threat actor <b>description</b>: <i>Samera Health is a Third Party Administrator (TPA) that provides Health, Dental, and Vision benefits for employer groups. The company focuses on delivering innovative and cost-saving solutions while ensuring a positive customer experience thr            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CHDFS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26570</link>
<guid>d9c9af41dda3bd35df1fddd4ff2b9b2b</guid>
<pubDate>Thu, 23 Oct 2025 00:25:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>CHDFS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5e567248551e07850bbb7f14ebbdd9a4034b7aeb3bc8439d18373895ff97198</i><br /><br />Threat actor <b>description</b>: <i>CHDFS Inc is dedicated to providing social services and support for individuals, families, and communities in need. They offer a range of programs including OPWDD, OMH, Early Intervention, and Health Home Care Management. Their mission focuse            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>NurseSpring</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26571</link>
<guid>8feddc18ebc59ad43f459ab72b07f93f</guid>
<pubDate>Thu, 23 Oct 2025 00:25:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>NurseSpring</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60d366952f0cb15d052ff09fbf7c056d91054b311d297af2e935eb9cc1b1375d</i><br /><br />Threat actor <b>description</b>: <i>NurseSpring specializes in home health care, health care staffing, and nurse recruitment services. They prioritize compassion, dignity, and respect while delivering care, ensuring clients receive the right care at the right time. Their intend            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integral-Networks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26572</link>
<guid>efb926bfce4f58539b1c2b45a5676b09</guid>
<pubDate>Thu, 23 Oct 2025 00:25:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Integral-Networks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0e4b1cdc54ee70616e7eda6745cdfcb2137d677f7c73ab32204a051c657c404c</i><br /><br />Threat actor <b>description</b>: <i>Integral Networks, Inc. is a leading IT services provider in Sacramento, specializing in responsive IT support tailored to the needs of legal firms and various other industries including construction, manufacturing, and finance. They offer a             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Signet-Armorlite-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26573</link>
<guid>178656689427a1c3b74f44d9f4fc0754</guid>
<pubDate>Thu, 23 Oct 2025 00:25:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Signet-Armorlite-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b39c8d49e26a35dfec20e2e4bf583f3e2856751fe6477e1e73678c4ac7d96c2</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1947, Signet Armorlite, Inc., an optical company, designs and manufactures glass ophthalmic lenses and molds. It also distributes lenses worldwide and adhesive optical supply products in the United States. Signet Armorlite is headq            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Magna-Hospitality-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26565</link>
<guid>98c2473648afc991669f9b9334c11072</guid>
<pubDate>Wed, 22 Oct 2025 19:24:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Magna-Hospitality-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5c1e45e9cff089c8061057a04ef83b7c432b5b7ede237cd0343d502789541a1</i><br /><br />Threat actor <b>description</b>: <i>Magna Hospitality Group, USA -  a private equity firm dedicated to the investment, development and management of hotel properties. Magna employs more than 100 professionals specializing in all areas including investment, finance, legal, hotel            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>More-Than-Gourmet</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26566</link>
<guid>c82864f384d7a8f675b311a9d9560aba</guid>
<pubDate>Wed, 22 Oct 2025 19:24:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>More-Than-Gourmet</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3db7a3c985432abdc482b07bfbc7e1721071648125dcc7fb23f51466ab06c82d</i><br /><br />Threat actor <b>description</b>: <i>More Than Gourmet, USA - is a food company based on classic French culinary traditions. MTG products are used in gourmet restaurants, resorts and sold in specialty gourmet food stores.  Privately held since 1993, MTG has been financially soun            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ATT-Careers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26564</link>
<guid>d690d0cd274a05efe2a0a58dac0d9461</guid>
<pubDate>Wed, 22 Oct 2025 14:15:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>ATT-Careers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0aaa5d8f1e071bf9c81bc01ce736dc35ce0062c4ef4c08f6ff0f7ec1a52fa03c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] AT&T Careers is the employment division of AT&T, an American multinational conglomeric communications company. It offers opportunities in various fields including technology, sales, marketing, customer service, cybersecurity. The company seeks individuals interested in the tech industry with drive for innovation. Roles include internships, entry-level, management, and more experienced positions. It provides competitive benefits and a diverse, inclusive workplace.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Applied-Technology-Resources</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26557</link>
<guid>06f867ad5a8dd38502b33ec03d5abc47</guid>
<pubDate>Wed, 22 Oct 2025 09:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Applied-Technology-Resources</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61769acd59bdb675d5749799b8005a1445b6f9277182c96df86da3e0f8643fc7</i><br /><br />Threat actor <b>description</b>: <i>Applied Technology Resources, Inc. is an international leader in Title Search Exams throughout the United States, offering unmatched accuracy and turnaround times through their proprietary information system. The company specializes in custom            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MILGARD.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26559</link>
<guid>db18ad102e99e047876c7c51ff482d5a</guid>
<pubDate>Wed, 22 Oct 2025 09:11:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>MILGARD.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63658dca9e86fb95448aaffcdf74bba8d6c5679def0ae47fb3fc2f579da19e54</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>COPELAND.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26560</link>
<guid>db922619896fd0e04b6e58c897c61841</guid>
<pubDate>Wed, 22 Oct 2025 09:10:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>COPELAND.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2e0d0a0f4941e0549cde7da8737df41a8e2858fb698cda2c613545374ec5046</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tri-City-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26549</link>
<guid>a6071a20f0095f50c0bc7329d45184be</guid>
<pubDate>Wed, 22 Oct 2025 00:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Tri-City-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>890dd08f44163253c5427419ddf9d838776749b37c6260e856596a66a8be0f0b</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2003 and headquartered in Downers Grove, Illinois, Tri City Foods is a franchisee of the Burger King restaurant chain. The company owns and operates locations in and around Chicago, Illinois.
A group of companies was attacked: lmc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SANHUA-INTERNATIONAL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26550</link>
<guid>56c9807aabbf7dc7279c1ec2b314bc47</guid>
<pubDate>Tue, 21 Oct 2025 20:11:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>SANHUA-INTERNATIONAL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5fbb9b53e8bb86f370b54abf881bf116e787971ab916b2b202b9566590de8db</i><br /><br />Threat actor <b>description</b>: <i>Sanhua International is delivering on its commitment to offer eco-friendly products with the North America introduction at the 2017 AHR Expo in Las Vegas of the Green Tech Line of refrigeration and air conditioning components, designed for use with natural refrigerants R290 (propane), R600a (isobutane) and R744 (CO2). Recent mandates from the U.S. Environmental Protection Agency (U.S. EPA) are leading commercial refrigeration and air conditioning manufacturers to redesign product offerings for a greener future. Sanhua works closely with these world-class manufacturers by providing high quality, hydrocarbon and CO2 ready system components including valves, controllers, transducers, filter driers and micro-channel heat exchangers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nelligan-White-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26552</link>
<guid>9b665b2accf17da9077cea4c5dad8e94</guid>
<pubDate>Tue, 21 Oct 2025 19:18:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Nelligan-White-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea7f2257f5e3a6cfe7d26310328e8468107cc15eb17f0a44a7e399dae87376da</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.nelliganwhite.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>National-Coatings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26551</link>
<guid>bbd2f7ac63dcd6415a821f8b0168b88e</guid>
<pubDate>Tue, 21 Oct 2025 19:17:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>National-Coatings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>081e03f9211b2fce81f54f1edb4bce76b021099e665061e7ef017187ec5446bf</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.nationalcoatingsinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prime-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26546</link>
<guid>327f7a07efe1dae93cc6313e8cdfbbdc</guid>
<pubDate>Tue, 21 Oct 2025 18:38:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Prime-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52b4356c5c762d8f2485c9270225e0c918c733ea17cc22453a622d278689ff3b</i><br /><br />Threat actor <b>description</b>: <i>Our practice specializes in procedures ranging from cosmetic dentistry, preventive dentistry, orthodontics, and early intervention orthodontics for young children and teenagers. Providing high-quality dental care is what we strive for daily and this is reflected in our detail-oriented work ethic. We work with patients closely to achieve the best results clinically possible, placing emphasis on educating our patients along the way. At Prime Dental we take extra care to explain the specifics of each procedure provided as well as to inform patients on what they can personally do to achieve better results. Because we see dentistry as a partnership, educating our patients is a top priority in our goal to improve patients overall dental health. We also place a strong emphasis on keeping current with modern technological advances so youll find our clean and contemporary facility equipped with quality, state-of-the-art technology</i><br />Target victim <b>website</b>: <i>www.primedental.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crave-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26547</link>
<guid>707ab73422e213d6c39597e2078c565e</guid>
<pubDate>Tue, 21 Oct 2025 18:38:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Crave-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e82b1248eda9b8f1c77b3356f278967f553e4ec650cf80191231b8c3c0f6392</i><br /><br />Threat actor <b>description</b>: <i>Crave Management Group is a fast-food franchisee operator based in Montana, known for its diverse brands and commitment to operational excellence. With a growing presence in Utah, the company is expanding its portfolio to include Bobbys Burgers by Bobby Flay alongside its existing Taco Bell locations. They prioritize exceptional customer experiences and offer unique benefits to employees, including early parental leave and paid volunteer opportunities. Crave Management Group is excited about creating numerous new career opportunities while maintaining a focus on community engagement and employee growth.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peraso</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26548</link>
<guid>6d0ca152a941f960431082ec429f6f11</guid>
<pubDate>Tue, 21 Oct 2025 18:37:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Peraso</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>935408f97eaa902d6dda15b651d26118f720e84294c463507252f1ded9e29c39</i><br /><br />Threat actor <b>description</b>: <i>Peraso</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>marquscompanies.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26529</link>
<guid>a03e5aa252e564c23062c4af8b7adf1e</guid>
<pubDate>Tue, 21 Oct 2025 15:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>marquscompanies.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>103d76361c3ffbb2247dd8d04a9a0ca1468629d236633f517ceff4965ae341c8</i><br /><br />Threat actor <b>description</b>: <i>Marquis Companies offers healthcare services. The Company offers assisted living...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Southern-Specialty-and-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26536</link>
<guid>834806a11a5b9335f5947a842a4a00df</guid>
<pubDate>Tue, 21 Oct 2025 15:17:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Southern-Specialty-and-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8e1a8d3a62cc3361b6060762f8b9eae93ce286cdfd6909a4d7170c851da64ce</i><br /><br />Threat actor <b>description</b>: <i>Provide support for offshore, onshore, and drilling operations.</i><br />Target victim <b>website</b>: <i>southernspecialtysupply.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roth--Scholl</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26537</link>
<guid>fd37c8fab2b7e539b0131c6572ee7d1c</guid>
<pubDate>Tue, 21 Oct 2025 15:17:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Roth--Scholl</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a071302049eec39fb349a95ef69a145bcca63d70f1afd1f0644f15456ce5538</i><br /><br />Threat actor <b>description</b>: <i>Providing legal service in Commercial Litigation, Real Estate, Business Law.</i><br />Target victim <b>website</b>: <i>rothandscholl.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>River-City-Eye</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26538</link>
<guid>b4c544e383856764707838df2ebaff46</guid>
<pubDate>Tue, 21 Oct 2025 15:16:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>River-City-Eye</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ea4620eacad1b00bf40fc340a25c8f7741ab925d86b97c9495d8f1c168aa812</i><br /><br />Threat actor <b>description</b>: <i>Optometry clinic located in the Hollywood District and Happy Valley.</i><br />Target victim <b>website</b>: <i>rivercityeye.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Austin-Capital-Trust</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26539</link>
<guid>b8ba4466c47209f470ae8902069192a6</guid>
<pubDate>Tue, 21 Oct 2025 15:16:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Austin-Capital-Trust</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e6f422c48a4bccae3cec805ed86c37741b62c2bbc672c1332fb5a6cc8023a00</i><br /><br />Threat actor <b>description</b>: <i>The Trust company that offers a range of financial services.</i><br />Target victim <b>website</b>: <i>austincapitaltrust.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Healthy-Living-Market-and-Caf</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26540</link>
<guid>793d2101fe21893b3d463a6600eead38</guid>
<pubDate>Tue, 21 Oct 2025 15:15:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Healthy-Living-Market-and-Caf</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>076c4baa7d9cfe55870f046fcbacf00ae97368a8ea6721cbdbb8ab5f2034603b</i><br /><br />Threat actor <b>description</b>: <i>Healthy Living Market & Cafe is a marketplace organic and products</i><br />Target victim <b>website</b>: <i>healthylivingmarket.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Claimlinx</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26542</link>
<guid>cf577c93108e7dcf27f7905e65933d18</guid>
<pubDate>Tue, 21 Oct 2025 15:15:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Claimlinx</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6df1f763ecbcbb9ecff7139cdfa0a19917314b66d2d3b430664763debd806e16</i><br /><br />Threat actor <b>description</b>: <i>A provider of health insurance benefits for the businesses</i><br />Target victim <b>website</b>: <i>claimlinx.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ronemus--Vilensky</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26545</link>
<guid>fdfef5e702d13ee41d102090422bc7b5</guid>
<pubDate>Tue, 21 Oct 2025 15:14:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Ronemus--Vilensky</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02a025493205279bd5df33437453dc1be4ecdd480fcab7d83113603d2ca07285</i><br /><br />Threat actor <b>description</b>: <i>A New York-based law firm</i><br />Target victim <b>website</b>: <i>ronvil.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dependable-Plastic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26543</link>
<guid>ae5b201527b188809873d2f108db3a79</guid>
<pubDate>Tue, 21 Oct 2025 15:13:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>Dependable-Plastic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9e43524392a52a17fab139628c1c9870a65a33c3cbd0acbec0064d0dbe477034</i><br /><br />Threat actor <b>description</b>: <i>A janitorial supplies company based in Brooklyn, New York</i><br />Target victim <b>website</b>: <i>dependableplastic.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>I-Tek-Medical-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26544</link>
<guid>8238291cb43f4eb400feef91b4ddc225</guid>
<pubDate>Tue, 21 Oct 2025 15:13:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>genesis</b> claims attack for <b>I-Tek-Medical-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fe39ab18ae1772af98d618761a5c07351980f80a2c40af310542074ec467a459</i><br /><br />Threat actor <b>description</b>: <i>A provider of contract design, development, and manufacturing</i><br />Target victim <b>website</b>: <i>i-tekmedical.com</i>]]></description>
<category>genesis</category>
</item>
<item xmlns:dc='ns:1'>
<title>U.S.-Vanadium-Holding-Company-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26531</link>
<guid>e4aded2e2c92b168bfaf4b509a62be56</guid>
<pubDate>Tue, 21 Oct 2025 12:53:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>crypto24</b> claims attack for <b>U.S.-Vanadium-Holding-Company-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62aa25155317b9b506cdf007bc740a4275fd7d773f6a1de2f464de34727789b5</i><br /><br />Threat actor <b>description</b>: <i>We have successfully extracted over 300GB of documents from your internal network, including internal company documents, customer and project information, and other data stored within your internal systems.</i><br />Target victim <b>website</b>: <i>usvanadium.com</i>]]></description>
<category>crypto24</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mailing.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26532</link>
<guid>83870fb92477054676ffda84e1e22f9f</guid>
<pubDate>Tue, 21 Oct 2025 12:51:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mailing.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc88fc7dc95eabc00c93a5aa83138b83aca1ebf45db27c0ca3c98341533ba69a</i><br /><br />Threat actor <b>description</b>: <i>Mailing.com is a printing and mailing company that offers service
s in Lithographic Printing, Digital Printing, Mailing Services, A
rt and Design and more.

We are ready to upload 40gb of corporate documents. Employee pers
onal information (Full name, DOB, address and so no), same inform
ation of their VIP clients, drawing and specifications, etc.
</i><br />Target victim <b>website</b>: <i>Mailing.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nvno</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26533</link>
<guid>ec151b6ecbb40275f4ac68bc99635554</guid>
<pubDate>Tue, 21 Oct 2025 12:50:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Nvno</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55351b726b052542aab19c688f99380926e7c7ef92645bfc1f303e866632cf4e</i><br /><br />Threat actor <b>description</b>: <i>Napierski, VanDenburgh, Napierski & O'Connor, L.L.P. is a leading
civil litigation firm based in Albany, NY, specializing in vario
us legal areas including medical malpractice defense, personal in
jury, and employment law.

We are ready to upload about 6gb of corporate documents. There ar
e SO MUCH personal documents. Full information of at least 150 of
their clients (Full name, DOB, address, passport numbers, SSNs, 
DLs and so no). Employee personal information (DOB, addresses, ph
ones, salaries and other information), a lot of court cases inclu
ding ransomware and others, corporate information of dozens of co
mpanies will be uploaded. Stay tuned.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>trailridgeenergy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26527</link>
<guid>6488517bf6015b4964f5576aae4206e9</guid>
<pubDate>Tue, 21 Oct 2025 11:24:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>trailridgeenergy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4ad9f44f51001e076fae96a16e01fee515f7b91098e21b6efebbdc8e0f4342d</i><br /><br />Threat actor <b>description</b>: <i>Trail Ridge Energy Partners II LLC is a privately held oil and gas exploration a...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.dekalbcountyga.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26528</link>
<guid>2b12a84466d35eee6f84649d1c0ac8a5</guid>
<pubDate>Tue, 21 Oct 2025 11:24:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.dekalbcountyga.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d516e6d2c376f372308756822bfbe369174fb38a3b405745675472a56a87a8e7</i><br /><br />Threat actor <b>description</b>: <i>DeKalb County is the third most populated county in the state of Georgia and is ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.ccls.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26526</link>
<guid>393db82ebb6d0148176e924e40f9d2e6</guid>
<pubDate>Tue, 21 Oct 2025 08:24:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.ccls.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>575e7f286067a52aba19309e6490dca63bb879607cbb078f74559a9de4e4964e</i><br /><br />Threat actor <b>description</b>: <i>The Chester County Library & District Center was established in 1962 and moved t...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>McDonald-Building</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26530</link>
<guid>cf4d516ca85abafb7b26406d82bf9f0b</guid>
<pubDate>Tue, 21 Oct 2025 07:52:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>McDonald-Building</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1edcbc7253a03df68303da10a0f12bd8ae476548f9af2b9a1c25af1b92871682</i><br /><br />Threat actor <b>description</b>: <i>McDonald Building Co. is a growing construction firm that embarks on innovative projects within the Architecture, Engineering, and Construction (AEC) industry. They utilize advanced technologies such as Virtual Design Construction to ensure quality and efficient project delivery while maintaining strong relationships based on trust and dependability. The company employs a unique drone, nicknamed Batman, to monitor and provide updates on construction progress and safety. Their commitment to excellence has garnered positive feedback from clients, highlighting their adaptability and competency.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greater-Mental-Health-of-New-York</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26525</link>
<guid>9a3bd37a71b632e7726f149bbd771052</guid>
<pubDate>Mon, 20 Oct 2025 20:46:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Greater-Mental-Health-of-New-York</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8dc38da5323f86bf1d679b7f89b7e2527a6e17f457d7a0125262efe84f62b350</i><br /><br />Threat actor <b>description</b>: <i>Greater Mental Health of New York is the new name of the merged entity of The Mental Health Association of Westchester and The Mental Health Association of Rockland, two agencies who have a long history of collaboration and a shared mission and ethos for promoting mental health throughout the Hudson Valley region.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tryon-Distributing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26522</link>
<guid>9486af7e0d767abe3859480dd307e1b7</guid>
<pubDate>Mon, 20 Oct 2025 20:45:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Tryon-Distributing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d5548504ed74810e402735b4ff9a677623f5256c20a3651501af7c7a7aa199f</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1985, Tyron Distributing is a craft beer and fine wines distributor headquartered in Charlotte, North Carolina.</i><br />Target victim <b>website</b>: <i>tryondistributing.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>MSC-Wireless</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26524</link>
<guid>03f27843d915554916cc80323ce5f787</guid>
<pubDate>Mon, 20 Oct 2025 20:44:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>MSC-Wireless</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd2cb4023acb52210dcf6d777d0e37530627b7c6c70e3acefbecaadc8bbbd737</i><br /><br />Threat actor <b>description</b>: <i>Wireless in the mountains</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>South-Atlanta-Medical-Clinic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26520</link>
<guid>6c0aa5ae1b6aadd1cfe5f1151b1a6c60</guid>
<pubDate>Mon, 20 Oct 2025 19:50:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>South-Atlanta-Medical-Clinic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6413c5564a2ca578654ad9c4f44499510e259581c7be6263e218fde9b8d11a6</i><br /><br />Threat actor <b>description</b>: <i>South Atlanta Ambulatory Surgery Center is a specialized outpatient surgical facility in Stockbridge, Georgia, dedicated exclusively to ear, nose, and throat procedures. The center is staffed by experienced board-certified otolaryngologists and anesthesiologists, providing high-quality, personalized surgical services for both pediatric and adult patients. With a focus on excellence and comfort, South Atlanta ASC is equipped with advanced technology for various ENT surgeries, including computer image-guided sinus surgery and balloon sinuplasty. Their mission is to ensure cost-efficient, compassionate care tailored to the needs of each patient.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harmony-Brands</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26521</link>
<guid>17d23e54aab31807fc9060d0d191161b</guid>
<pubDate>Mon, 20 Oct 2025 19:50:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Harmony-Brands</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0566dee6ca0de1d53be372af0e87d45758afdc373665344e9e263e09fa47d4e</i><br /><br />Threat actor <b>description</b>: <i>Harmony Brands was founded in 2014, from a desire to create a premium sod grass that matched the needs of the varied geography of the United States, and also measured up to the industrys highest standards. Harmony, based in Sarasota, Florida, was created by Bethel Farms, one of the nations leading sod growers, with over 50 years of agricultural expertise.Harmony sod was first available to homeowners in Florida and within a few months, Georgia, Alabama, Mississippi and Texas. Currently its available throughout the continental United States. Soon after, a Harmony sod installation program was launched. Harmony Brands aims to offer homeowners everything to create a unique outdoor living experience, from quality sod to premium care and maintenance.</i><br />Target victim <b>website</b>: <i>www.harmonybrands.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phoenix-Village-Dental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26519</link>
<guid>49cea6b66a1c9d9fcbba8946453c057b</guid>
<pubDate>Mon, 20 Oct 2025 18:41:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Phoenix-Village-Dental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7903bb04476b9ec75c7782686319633e4907e798b2bfa83f64e03bcad0c07d80</i><br /><br />Threat actor <b>description</b>: <i>Phoenix Village Dental is a family dentistry practice designed with you in mind! We know how busy you are-and how difficult it is to fit dental visits for your family into your hectic schedule.</i><br />Target victim <b>website</b>: <i>www.phoenixvillagedental.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ocbar.orgUSA114GB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26518</link>
<guid>f5e298925daba7141e05ef336ae52e30</guid>
<pubDate>Mon, 20 Oct 2025 18:16:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>ocbar.orgUSA114GB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da75e69bb7b8c8e8cbe18114605145b434cd4a96220ca1c4e4afdf2872b23720</i><br /><br />Threat actor <b>description</b>: <i>Unknown - Orange County Bar Association</i><br />Target victim <b>website</b>: <i>ocbar.org/USA/114GB</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>cdom.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26516</link>
<guid>db16fe601371c8ef1105fa442e445b07</guid>
<pubDate>Mon, 20 Oct 2025 18:05:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>cdom.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5857535690b1e825af8d8b3d42522ecfab1716c14084fe2e3554c25a691db4f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>cdom.org</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Selig-Enterprises-AAA-Parking</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26508</link>
<guid>9a8d909d7652448b2dc301613a123aab</guid>
<pubDate>Mon, 20 Oct 2025 16:17:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Selig-Enterprises-AAA-Parking</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbc62bcef1eeed646fe240567d5fdb9c12327be6d6b4355f9d5d8f292877afa8</i><br /><br />Threat actor <b>description</b>: <i>There are two companies in the upcoming leak. Selig Enterprises i
s a real estate company that has a portfolio of more than 15 mill
ion square feet of retail, industrial, residential, hotel, office
, and mixed-use properties throughout the Southeast. And AAA Park
ing, headquartered in Atlanta, Georgia, and established in 1956, 
is a parking management company.

We are ready to upload 81gb of corporate documents of these two c
ompanies. Employee personal documents (passports, DLs), clients p
ersonal information (Full name, DOB, SSN, phone and so on), detai
led accounting and financials, credit cards details, projects (co
nfidential ones), drawing and specifications, NDAs, police report
s and other interesting information.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cabinets-2000-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26512</link>
<guid>fc6c370893059e7241288dc04db24ee7</guid>
<pubDate>Mon, 20 Oct 2025 14:50:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>Cabinets-2000-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7ab2a775cb6d4b551c16a7ada7b65a15316fa6f437a46d1d28b4114b394ca371</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "Cabinets 2000, LLC" is a business that manufactures and sells a diverse variety of cabinetry products. Based in Norwalk, California, it serves a range of customers primarily in the residential market. The company is committed to offering high quality, affordable cabinets. Products range from kitchen and bathroom cabinets, to office and storage solutions. Key attributes include design flexibility, on-time delivery and excellent customer service.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>Linxx-Global-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26501</link>
<guid>a4f87e21ec472bbff8435588d5b08a8f</guid>
<pubDate>Mon, 20 Oct 2025 07:14:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Linxx-Global-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>abf9be2120ef66adce3a326a3fc8c3b4743afc6e137469034bdfc774bb3d92ff</i><br /><br />Threat actor <b>description</b>: <i>Linxx Global Solutions is a leading provider of mission-critical support services specializing in Training, Security, and Cyber Security solutions. Their primary goal is to enhance the safety, security, resiliency, and productivity of their clients through innovative problem-solving and a commitment to excellence. The company has established a strong reputation by successfully supporting various contracts, including those with the U.S. Navy and the U.S. Army. With their focus on delivering high-quality services, they serve a diverse range of clients in government and military sectors.
company is headquartered in 2901 S Lynnhaven Rd Ste 450, Virginia Beach, VA 23452, United States.
724 Employees
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accord-Carton</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26499</link>
<guid>de96180969ef18d44b7c93571803bb16</guid>
<pubDate>Sun, 19 Oct 2025 20:40:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Accord-Carton</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65f001de26bc48e020a053d139bf6496d88ab5511bb31f33038da43860cc0857</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.accordcarton.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Khatami-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26491</link>
<guid>5eb97552583ad9440a45927fb0263bd8</guid>
<pubDate>Sun, 19 Oct 2025 19:24:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Khatami-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55603c3439327dfae546d3830b816a4e53c6bb2bc334631b137d0af536fc8653</i><br /><br />Threat actor <b>description</b>: <i>Hoss Law is a law firm specializing in personal injury and family law services, dedicated to helping clients in Sacramento and surrounding areas. They focus on maximizing compensation for accident victims and offer a no-win, no-fee guarantee,            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kudela--Weinheimer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26493</link>
<guid>f3db95bfda8bf707858c4c50a41e811a</guid>
<pubDate>Sun, 19 Oct 2025 19:24:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Kudela--Weinheimer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9ef86aced2910ad1e9c38d258a29aaf7dd17075b41d786211383b99b9dbfc02</i><br /><br />Threat actor <b>description</b>: <i>KW Landscape Architects is a landscape architecture firm that specializes in creating exceptional built environments by balancing innovation with functionality. With over 30 years of experience, they offer services across various markets incl            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>healthandvitalitycenter.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26497</link>
<guid>a66dbabd793deed367030aadfcfc59b9</guid>
<pubDate>Sun, 19 Oct 2025 17:41:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>healthandvitalitycenter.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63bfa383ee3b17cbd01f09b4636104ba708a729463183dd7a9ead1f8edaac240</i><br /><br />Threat actor <b>description</b>: <i>The Health & Vitality Center is a holistic medical practice located at 11600 Wilshire Blvd, Suite 120, Los Angeles, CA. …</i><br />Target victim <b>website</b>: <i>healthandvitalitycenter.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>BARCO-Rent-A-Truck</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26471</link>
<guid>a432f60bb9550adf0c2e00bf906d8939</guid>
<pubDate>Sun, 19 Oct 2025 17:25:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>BARCO-Rent-A-Truck</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1cd845de73b5ece56b8897dddb33b7892934a7ead6b4c672c512af4976f11023</i><br /><br />Threat actor <b>description</b>: <i>Barco Rent-A-Truck is a leading provider of corporate 4x4 pickup truck rentals in the United States, offering a comprehensive fleet of brand new trucks, including 1/2, 3/4, and 1-ton models. Their services cater to a wide range of clients, fr            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gas-Generator-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26473</link>
<guid>26324d8e2cc1957b8e581568a089a51c</guid>
<pubDate>Sun, 19 Oct 2025 17:25:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Gas-Generator-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae5f4f29749755d5f8551f5a99e87e9fa674bcd5c9b3b96a4f597ca0f276a4f5</i><br /><br />Threat actor <b>description</b>: <i>Gas Generator Solutions (GGS) is a privately owned, independent organization established to provide Lab Managers with single point of contact for the Servicing and Repair of ANY Laboratory Gas Generator within their facility, independent of b            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stowaway-Storage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26475</link>
<guid>471f23c944fc170279354fb74ece7ce4</guid>
<pubDate>Sun, 19 Oct 2025 17:25:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Stowaway-Storage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e7db9b46f90e275434665059c1aa01509bfbe41181f71467fd78edc3853328b</i><br /><br />Threat actor <b>description</b>: <i>Opened in the fall of 1998, Stowaway Storage has long been part of the North Haven community. The business has always been family owned and operated since it's beginning. Owner Raymond V Iannucci started the company on land previously utilize            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>JA-Jennings</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26476</link>
<guid>ba16fd41fab7b93931b2e628c6e62441</guid>
<pubDate>Sun, 19 Oct 2025 17:25:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>JA-Jennings</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11852fe9cb0bb718ec67a5e31b065b4f34e27ba2b7ce742959c15ece9ed7754e</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1917, J.A. Jennings is a mid-size full-service construction company which constructs private sector commercial interiors projects as well as full-scale building renovations and infrastructure programs throughout the New York City m            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Scales-Sales--Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26480</link>
<guid>90d048af68ca32e1bfb1d645e35ab644</guid>
<pubDate>Sun, 19 Oct 2025 17:25:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Scales-Sales--Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>511b2eade85c20aa52ac44b46460a6375943576ea6f4830f0ac08447cb27c72d</i><br /><br />Threat actor <b>description</b>: <i>Scales Sales & Service LLC was originally founded in 2004 in Omaha, Nebraska. A full-service scale company with locations in Greeley, CO, Colorado Springs, CO, Denver, CO, Omaha, NE, Kearney, NE, Scottsbluff, NE and Atlantic, IA, in addition             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Laloma</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26481</link>
<guid>77bd8919603ba3c00e26d92710171b8c</guid>
<pubDate>Sun, 19 Oct 2025 17:25:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Laloma</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfb98b1f89209f0105c0557e6bc9f6a78b4e6737b4ec0a29e89a604da4adae54</i><br /><br />Threat actor <b>description</b>: <i>La Loma Tamales is a Mexican restaurant chain in the Minneapolis-St. Paul area known for its traditional, handmade tamales made from fresh ingredients, including a unique process of cooking and grinding their own corn. They offer both savory             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>My-Florida-Case-Management-Services-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26496</link>
<guid>1697fe5eb0141dca1379090a4d766cc7</guid>
<pubDate>Sun, 19 Oct 2025 16:44:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>My-Florida-Case-Management-Services-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d60eafb59a01cad88052bf112d1df892c7fedba0c9b8cc4e5698ea4446becc93</i><br /><br />Threat actor <b>description</b>: <i>My Florida Case Management Services, LLC, a professional case management company located in Doral, FL. It could also be a general reference to the state of Florida's case management services, such as the Medicaid Mental Health Targeted Case Management program provided through the Florida Agency for Health Care Administration (AHCA) for individuals with serious mental illnesses or emotional disturbances. Additionally, it may refer to court-based case management, such as the Family Court Case Management process.</i><br />Target victim <b>website</b>: <i>www.mapquest.com</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Blood-and-Marrow-Transplant-Group-of-Georgia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26482</link>
<guid>3b0d3acaf5e61ac97738f559aa43fb1d</guid>
<pubDate>Sun, 19 Oct 2025 16:25:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>The-Blood-and-Marrow-Transplant-Group-of-Georgia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e68f8bcad3b89ca10d3984babc7a3c529e22e67b96e18fba728eae3a23534ae</i><br /><br />Threat actor <b>description</b>: <i>The Blood and Marrow Transplant Group of Georgia (BMTGA) specializes in providing advanced care for patients undergoing blood and marrow stem cell transplantation, acute leukemia treatment, and CAR T-cell immunotherapy. They are recognized fo            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sports-Medicine-and-Orthopaedics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26484</link>
<guid>8b71c85ef2c0088afedaf83ebb8ed0b2</guid>
<pubDate>Sun, 19 Oct 2025 16:25:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sports-Medicine-and-Orthopaedics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a26a822305033edc63b7a962df6091e27db67b4c0fba9a12e257944f52ce018</i><br /><br />Threat actor <b>description</b>: <i>Sports Medicine and Orthopedics is committed to providing excellent patient care and education to orthopedic patients across Rhode Island, Massachusetts, and Connecticut. Led by Dr. Jack Goldstein, a Fellowship Trained Orthopaedic specialist,            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Winholt-Equipment-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26485</link>
<guid>729016c738c95503023f9c7bba4cb332</guid>
<pubDate>Sun, 19 Oct 2025 16:25:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Winholt-Equipment-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>707e5b82cf493a2732bcfea3f78d579de84b742494c3ab63fdc81a209119fef4</i><br /><br />Threat actor <b>description</b>: <i>Winholt Equipment Group, founded in 1946 and headquartered in Woodbury, New York, is a manufacturer of food service, food handling, and material handling equipment.
As a multiple-facilities manufacturer, we have the resources to quickly reac            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>All-Weather-Architectural-Aluminum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26486</link>
<guid>c2e2be234ac059e1be0c0201da680753</guid>
<pubDate>Sun, 19 Oct 2025 16:25:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>All-Weather-Architectural-Aluminum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a595380d4f40005be4346e575b7fbc9e5a11ee08652901a739fcea4770c5ea7</i><br /><br />Threat actor <b>description</b>: <i>All Weather Architectural Aluminum specializes in custom windows and doors, providing innovative solutions for both residential and commercial projects. Their extensive range includes sliding, folding, and pivot designs, catering to the uniqu            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SIGN-Fracture-Care-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26488</link>
<guid>3dcfdd8da0bc9ad027d2e7184439ad44</guid>
<pubDate>Sun, 19 Oct 2025 16:25:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SIGN-Fracture-Care-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0169e3dcba1324fd4bd29cd9a1b8970b22da1fca7553d275ff16062179a8c9ae</i><br /><br />Threat actor <b>description</b>: <i>SIGN Fracture Care International is a humanitarian organization dedicated to creating equality in fracture care globally by building sustainable orthopedic capacity in developing countries. They provide education to surgeons and donate the ne            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indian-Spring-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26489</link>
<guid>9de812f86fcb6f1cd0f661d684978665</guid>
<pubDate>Sun, 19 Oct 2025 16:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Indian-Spring-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>611eeec4dd2f6121a3112e563e0e111035bedbfe5b0d57ac0c25bbd6dde6b81d</i><br /><br />Threat actor <b>description</b>: <i>Located in beautiful Boynton Beach, Florida, Indian Spring Country Club is a gated, private country club that has the total package ...championship golf, tennis, fitness, casual and formal dining. The Indian Spring Country Club experience is             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grande-Prairie-Public-Library</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26490</link>
<guid>8d9a224f87de1920fca2833749d18df3</guid>
<pubDate>Sun, 19 Oct 2025 16:25:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Grande-Prairie-Public-Library</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b8e4ce2a75b9fff8b4b2719caa77ee869dc4ff0cd48b2b685607f708a421bea</i><br /><br />Threat actor <b>description</b>: <i>The Grande Prairie Public Library District is located at 3479 West 183rd Street, in Hazel Crest, Illinois. We serve the communities of Hazel Crest and Country Club Hills. We provide service to all residents living within our district boundari            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Long-Island-Weight-Loss-Institute</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26469</link>
<guid>22b8064b56f29c9bdf64e9b09bbdc56e</guid>
<pubDate>Sun, 19 Oct 2025 05:25:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Long-Island-Weight-Loss-Institute</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7f476b849d803c9aa2b14c3b597561eaceb63310a0dade8a6702d23bcb03fe3</i><br /><br />Threat actor <b>description</b>: <i>Long Island Weight Loss Institute is a medical weight loss clinic that offers physician-supervised weight loss programs designed to treat the whole person. The clinic provides individualized support tailored to each patient's unique needs wit            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>summitgolfbrands.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26468</link>
<guid>2ca586bb2adf43e68fb77b916b0fc7db</guid>
<pubDate>Sun, 19 Oct 2025 00:47:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>summitgolfbrands.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2e103a8eedccac14e464f93f0b5bddb40f596cc9aefd3ec42d045591081962f2</i><br /><br />Threat actor <b>description</b>: <i>SUMMIT GOLF BRANDS specializes in high-end golf apparel and sportswear, selling products online and through leading country clubs and resorts worldwide. Their portfolio includes brands such as Fairway Greene, Zero Restriction, B. Draddy, and EP New York, with a presence in over 3,000 accounts across more than 25 countries. The company emphasizes quality through vertical integration for decoration and fulfillment, ensuring exceptional service. They cater to various clients including pro shops, corporations, and retailers, focused on delivering innovative and stylish apparel for golf enthusiasts. Employees: 125 Revenue: $27.9 Million Industry: Holding Companies & Conglomerates  Phone Number:(212) 302-7255 760-607-7574 501-940-5393 203-722-2472 207-317-1954 203-984-1657 516-776-3298 203-402-9704 917-975-9357 585-967-0609 917-587-2409 540-270-5566 800-926-8010</i><br />Target victim <b>website</b>: <i>summitgolfbrands.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>EMERSON.COM---EBS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26461</link>
<guid>90c5b57809d8cb1703f89023c6d17060</guid>
<pubDate>Sat, 18 Oct 2025 14:34:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>EMERSON.COM---EBS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>071738338786bcd7d76827cc2fc9f1c238be44fbbefb3e7291ef28f1dc316dbb</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>AA.COM---EBS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26462</link>
<guid>58b311abb1f038c7371016670f355608</guid>
<pubDate>Sat, 18 Oct 2025 14:33:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>AA.COM---EBS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1f71bcb93ca304c9d5a3260c4402c57198f4169eb12a58464591dcc2a51bc744</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Collins-Aerospace--RTX.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26460</link>
<guid>f829d0a47d2f435f6c452ebe867f6056</guid>
<pubDate>Fri, 17 Oct 2025 23:24:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Collins-Aerospace--RTX.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53ed75d22648575a35fe881cc9685c33d4bc7acb013241eb35653f7825dcdaf6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Collins Aerospace, a unit of Raytheon Technologies Corporation, is a leader in technologically advanced, intelligent solutions for the global aerospace and defense industry. Created in 2018 by bringing together UTC Aerospace Systems and Rockwell Collins</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>D-Magazine-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26457</link>
<guid>4466f2c1e7eed04c491b8620b142ff72</guid>
<pubDate>Fri, 17 Oct 2025 21:52:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>D-Magazine-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>218477a6abf2e09cecc0f67194df1f1ff5e6c0fecb093318d226346935e10d30</i><br /><br />Threat actor <b>description</b>: <i>ounded in 1974, D Magazine is a monthly magazine covering Dallas-Fort Worth. Topics include Food, Arts, Home, Living, Business, and Weddings. The company is headquartered in Dallas, Texas.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hematology-Oncology-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26456</link>
<guid>dfba6121d0dbcf806a79e74a7ba58a7b</guid>
<pubDate>Fri, 17 Oct 2025 20:47:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Hematology-Oncology-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>107e1ff5de331dcfaec11ce2d304d1a2ffe35c16dd50806ca623924219045068</i><br /><br />Threat actor <b>description</b>: <i>Hematology Oncology Consultants Michigan Hematology Oncology is a private practice dedicated to providing the highest level of quality care in a healing environment for the mind, body and spirit of patients dealing with cancer and blood disorders.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cottage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26451</link>
<guid>783900b1dad49f8e7665ebea90ccdfcc</guid>
<pubDate>Fri, 17 Oct 2025 20:45:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cottage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c49c71ffba5852127426dac45920669ef6dec7a38fe1392a1ff8a75798c66475</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cottagecorp.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shadrix--Parmer-P.C.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26452</link>
<guid>5b8b532425202aabea874712edabd2ac</guid>
<pubDate>Fri, 17 Oct 2025 19:26:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Shadrix--Parmer-P.C.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6927468fb042a89a46888051036ac87dda80537467253b02b15ee5faddf9a244</i><br /><br />Threat actor <b>description</b>: <i>Documents, correspondence, payments, clients</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Manko-Window-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26441</link>
<guid>fca1843a88d84796402f2cb5cf8fead4</guid>
<pubDate>Fri, 17 Oct 2025 19:25:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Manko-Window-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b4bacbcf6ea4261d34c7e0d5e88bd8def1abac901ad63116dc31541b2abdb4fd</i><br /><br />Threat actor <b>description</b>: <i>Manko Window Systems is a manufacturer of commercial windows, aluminum systems, and glass products.We are ready to upload 20gb of corporate documents. Client personal information (SSNs, DOB, phones and other docs), employee information, accounting and financials, projects, drawing and specifications, detailed information on their products, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tenryu-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26442</link>
<guid>c8d128c127cc299c41e73a24f1158b7c</guid>
<pubDate>Fri, 17 Oct 2025 19:25:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Tenryu-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97cb22a8b6dda350c398f71a0d47207a95beee7786f58045052e592ed1487d15</i><br /><br />Threat actor <b>description</b>: <i>Tenryu America, Inc. is a leading manufacturer of high-quality saw blades, offering over 3,000 types of carbide blades suitable for woodworking, metalworking, plastic cutting, and machining composite materials.We are ready to upload corporate documents. Employee information (DOB, addresses, phones and so on), a bit of client data, financials, contracts, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>GFFF---Galine-Frye-Fitting--Frangos-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26449</link>
<guid>4139cb778ebae8996577f0a5533e4bb0</guid>
<pubDate>Fri, 17 Oct 2025 17:39:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>GFFF---Galine-Frye-Fitting--Frangos-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3c1828904d91a7f2951443475906ed520006d39642086be78bd4eb463ad28fe</i><br /><br />Threat actor <b>description</b>: <i>Highest-rated San Mateo personal injury attornes</i><br />Target victim <b>website</b>: <i>dongaline.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Consolidated-Restaurant-Operations-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26437</link>
<guid>cf8e18367059d20cbb1650809d53e825</guid>
<pubDate>Fri, 17 Oct 2025 14:25:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Consolidated-Restaurant-Operations-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e310f85d1b3ec0f957e561aa5b7f9dd648281fbc8a7fd49759661f15e1b90b86</i><br /><br />Threat actor <b>description</b>: <i>Consolidated Restaurant Operations, Inc. (CRO) operates more full-service and franchise restaurants internationally in addition tocatering events.We are ready to upload 38gb of corporate documents. Scans of employee documents (Passports, driver licenses, medical information, SSNs and other docs), lots of confidentiality agreements, detailed financials, NDAs, police reports, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plastics-Extrusion-Machinery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26438</link>
<guid>9cdef155fb46f275b78d8c9eb523d7a0</guid>
<pubDate>Fri, 17 Oct 2025 14:25:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Plastics-Extrusion-Machinery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f6378e59b8ed3bc0fffa227188fb36046d7ce5667f0e938d5d99d50d9698b27c</i><br /><br />Threat actor <b>description</b>: <i>Plastics Extrusion Machinery LLC, known as PEM, is a leading provider of innovative downstream equipment tailored for the PVC pipeand custom profile industries. We We are ready to upload more than 350GB data. There are lots ofessential corporate documents such as: financial data (audit, payment details,financial reports, invoices), detailed employees and customers information ( Dl numbers, Social Security Numbers, medical information, emails, phones) confidential information, NDAsand other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Curtis-Steel-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26439</link>
<guid>c5d2c718008d3490546d029cab134fb7</guid>
<pubDate>Fri, 17 Oct 2025 12:39:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Curtis-Steel-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a4350929192633f9fa3304a38cc8ca142a8445182123d244248f0fbdfbe6ed66</i><br /><br />Threat actor <b>description</b>: <i>Curtis Steel Aluminum Co. is a leading tubing supplier based in L
as Vegas, providing high-quality metal and steel products, includ
ing aluminum, carbon steel, stainless steel, and welding supplies
. The company offers various precision services such as steel cut
ting, laser cutting, metal drilling, and hole punching, catering 
to both commercial and individual clients since 1970. 

We We are ready to upload more than 20GB data. There are lots of 
essential corporate documents such as: financial data (audit, pay
ment details,financial reports, invoices), detailed employees and
customers information ( Dl numbers, Social Security Numbers, med
ical information, emails, phones) confidential information, NDAs 
and other documents with detailed personal information. 
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>BMP-Worldwide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26429</link>
<guid>6ac9ae1743524cdf9197f1ea50412d72</guid>
<pubDate>Thu, 16 Oct 2025 18:46:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>BMP-Worldwide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>309e3b7e9e2e4270cf47981c3242390906c342d6151b4b3dc18fe266033ddfc0</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bmpworldwide.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Coilplus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26426</link>
<guid>22b880633e6c3b3c7bccc56c59ff11b9</guid>
<pubDate>Thu, 16 Oct 2025 16:25:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Coilplus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7deaa35ab6c2285a9fbcb67575bc63fb755a9b40e2a67be5a0f3772a0ce4ac6b</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>gslong.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26413</link>
<guid>da92ce36d3c841c78a1dc24ea5abcb72</guid>
<pubDate>Thu, 16 Oct 2025 13:24:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>gslong.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f06e663ab87a31e5ad791bac67292a164197d048fd9e98ddbe90ec8541fd310</i><br /><br />Threat actor <b>description</b>: <i>GS Long provides specialized services in plant nutrition, plant protection, and field consulting for the agricultural industry. 
The company specializes in developing customized solutions to increase crop yields and safety. Committed to buil            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>coppage.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26414</link>
<guid>86779aa5332ae2efcb7252165bc633e5</guid>
<pubDate>Thu, 16 Oct 2025 13:24:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>coppage.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>898654e52d95be25642097d430210c3c04803078f6251a929dac9914a8f1511a</i><br /><br />Threat actor <b>description</b>: <i>At Coppage Construction, we design and build homes.
1.The document is a statement of income for Coppage Construction Company, Inc. for the period ending April 30, 2025.
2.The document is a report entitled “Work in Process” by Coppage Co            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>arizonafireplaces.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26415</link>
<guid>3aef625160d85a9fc3b52f3be4474ed5</guid>
<pubDate>Thu, 16 Oct 2025 13:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>arizonafireplaces.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>98ab7fd1b82b85b4392c582471492cf48f360b319e7c6da25c464ddb006f898c</i><br /><br />Threat actor <b>description</b>: <i>Arizona Fireplaces offers its customers top-notch quality and service for fireplaces and accessories from leading global brands.
1.Arizona Department of Revenue — Contractor’s Certificate (Form 5005) “Contractor's Certificate for Prime            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>pcdpackaging.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26417</link>
<guid>691f1c02ba340056657d9fd9f5bf017c</guid>
<pubDate>Thu, 16 Oct 2025 13:24:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>pcdpackaging.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d6a3fc636f804368e34368e0f0358951df3be9cbffe7715ea4e8560a2bcae30</i><br /><br />Threat actor <b>description</b>: <i>Development of customized industrial packaging. Single-use racks, export packaging, packaging for power units, specialized packaging, packaging for sea containers.
1.The document is an official bank statement from PCD Packaging de México S.            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.ronvil.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26421</link>
<guid>3ca43d27fa81f452a4d0b6ae09f809aa</guid>
<pubDate>Thu, 16 Oct 2025 09:24:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kraken</b> claims attack for <b>www.ronvil.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0426dc24ea730bde13046627e62203868d37136c914140c63109b3247c6b3ae1</i><br /><br />Threat actor <b>description</b>: <i>Ronemus & Vilensky LLP is a New York-based law firm specializing in personal injury, civil rights, medical malpractice, and acci...</i><br />Target victim <b>website</b>: <i>www.ronvil.com</i>]]></description>
<category>kraken</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beta-Dyne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26408</link>
<guid>5e29cd6e10b0c9d7af2be2668f0f152a</guid>
<pubDate>Thu, 16 Oct 2025 07:25:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Beta-Dyne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0943e0ace77bc4e643b8ba51065ff957f43100bff81219da3886e74e569d0d6b</i><br /><br />Threat actor <b>description</b>: <i>Beta Dyne, USA - develops and manufactures electrical equipment for the industrial plants, communications и medical. With over 20 years in the power industry, Beta Dyne, Inc. has developed a wide range of unique and high performance power pr            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Middlesex-Appraisal-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26406</link>
<guid>165cbe7ba268f8d7901f5edbc896084e</guid>
<pubDate>Thu, 16 Oct 2025 02:25:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Middlesex-Appraisal-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f71fe0470ffdaf05f4adb4c951709c26114fa6e9d9e1c507d565a8ac06275bbc</i><br /><br />Threat actor <b>description</b>: <i>Middlesex Appraisal Associates, USA - provides appraisal services in Eastern Massachusetts in Middlesex, Essex, Suffolk, Norfolk, Worcester, and Plymouth counties. Founded in 1992, the company provides appraisal and consulting services utiliz            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sprague--Jackson</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26407</link>
<guid>261afa2a7f87c853bb38ebe6149a0ac0</guid>
<pubDate>Thu, 16 Oct 2025 02:25:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Sprague--Jackson</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f2c3647beb6b2721ba9847558f770d76e065dc2504eede31514439d55d878a7</i><br /><br />Threat actor <b>description</b>: <i>Sprague & Jackson, USA - Sprague & Jackson is a tax services firm that offers a range of client services including secure document submission and payment options. They provide personalized assistance through scheduled meetings to help clients            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bengal-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26405</link>
<guid>96f4303c756ba84f75fdbcc92d0f0414</guid>
<pubDate>Thu, 16 Oct 2025 01:25:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bengal-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>141853b28f11257db4c22a966c27369c9d52be2e8bc662c533a94f3ed8faaa28</i><br /><br />Threat actor <b>description</b>: <i>Bengal Industries, USA - founded in 1995, is a specialty carrier serving the continental United States and Canada.  The company is experienced in turnkey projects involving heavy lifting and transportation services. If the load is large, heav            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rasi-Laboratories</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26404</link>
<guid>e7ba959de901f17d3f72929c945df002</guid>
<pubDate>Wed, 15 Oct 2025 22:25:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rasi-Laboratories</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f10df03c3aca5bfbb378efcd48441a34fd19d042b360270f1b63f11b0a85f85e</i><br /><br />Threat actor <b>description</b>: <i>Rasi Laboratories, USA -  a manufacturer and developer of nutraceuticals, specializing in dietary supplements like capsules, tablets, probiotics, and functional foods.  Their facility in Cranbury, New Jersey, spans 198,500 square feet and is             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tex-Tube</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26403</link>
<guid>81fd0241fd6df61d5201d65fd47bb698</guid>
<pubDate>Wed, 15 Oct 2025 18:45:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Tex-Tube</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35a1d4b9ae3c02d3d515b59e35e62e785a2421e78e711aa0e2f3f8831e5ef41b</i><br /><br />Threat actor <b>description</b>: <i>Tex-Tube Tex Tube has over 75 years of experience in manufacturing steel products, specifically electric resistance welded (ERW) steel pipes, adhering to API and ASTM specifications. Serving the North American continent, the company produces tubular steel products that meet both API and ASTM standards.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Richmond-Behavioral-Health-Authority</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26395</link>
<guid>58a3c88f8354d4464ad552a6ab7ce400</guid>
<pubDate>Wed, 15 Oct 2025 18:43:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Richmond-Behavioral-Health-Authority</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fdf091858976a00c607f6bf26548886f15692f49c4f3fcc315f528950fc6886</i><br /><br />Threat actor <b>description</b>: <i>Richmond Behavioral Health Authority (RBHA) is a statewide organization dedicated to providing comprehensive mental health, mental retardation, substance abuse and prevention services to the residents of the City of Richmond. The organization            ...</i><br />Target victim <b>website</b>: <i>www.rbha.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cellucap-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26402</link>
<guid>0dc5fdbc98f80f9aaf2b43b8bc795ea8</guid>
<pubDate>Wed, 15 Oct 2025 18:42:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cellucap-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3b1da83d708a62ac761b177009f7e1f2ddc0aae022aa62476a3ebd0ae7427d81</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cellucap.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Global-Shop-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26401</link>
<guid>26bdec29ad7cc9553a512959d3896f97</guid>
<pubDate>Wed, 15 Oct 2025 18:41:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Global-Shop-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cac2a0dea7f074dd41279b720ff054c67459db4e9f841af087c4b6148e1cd0b2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.globalshopsolutions.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Legacy-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26400</link>
<guid>19bf54221c2a7acc39e53408da0b4612</guid>
<pubDate>Wed, 15 Oct 2025 18:40:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Legacy-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2dd6c7c5e7d98128bfa7ea73f1f973d70440f0d9896905a77a04d4b96eec46f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.legacymfg.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Koch--White-Heating--Cooling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26399</link>
<guid>b22c8dd80eaa4578ca19fc1c6e983da7</guid>
<pubDate>Wed, 15 Oct 2025 18:40:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Koch--White-Heating--Cooling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9bd294d42b36ad08e7b996f3e41f66d4b5cadac42fd506aa737783f5000d3f66</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.koch-white.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Royal-Thai</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26398</link>
<guid>5f6780632f5d27dd0cded5fc9361169e</guid>
<pubDate>Wed, 15 Oct 2025 18:39:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Royal-Thai</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b935b7d80a211217d619122d7819a884969234974a65b9f73f8e51c8093a333</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.royalthai.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>EMBASY-OF-BOLIVIA-DC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26397</link>
<guid>125afb06ef365c0991aa632cd76104e1</guid>
<pubDate>Wed, 15 Oct 2025 18:21:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>EMBASY-OF-BOLIVIA-DC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9635603e9217e37e4a990d6f1bff35d6f528d118f2d0e2c44c336636972fc5fd</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 200k
400gb</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>regionalurology.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26396</link>
<guid>a47cab1df307c338b6843eb72d9ee91e</guid>
<pubDate>Wed, 15 Oct 2025 18:20:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>regionalurology.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f979ab93f5e9da8ea84604c2fe50f38a3dd6833715b9c2df665df7924f75020f</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 200k
300gb</i><br />Target victim <b>website</b>: <i>regionalurology.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>Core-Resources-Inc-CRI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26390</link>
<guid>82555ac1fb22a5c18698fda8c4220169</guid>
<pubDate>Wed, 15 Oct 2025 16:46:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Core-Resources-Inc-CRI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e51ef829d25d161db82377a9a1e3b734dd419ac219e17f7e9a3095191f8003f6</i><br /><br />Threat actor <b>description</b>: <i>Core Resources specializes in real estate development, general contracting, and owner representation, aiming to establish lasting partnerships in the construction industry. Their services encompass a holistic approach, covering everything from blueprints to financial consulting, to cater to clients’ essential assets. The company emphasizes integrity and strong values, which guide their operations and relationships. They serve a diverse clientele, including notable projects like Washington Park and Coldstream Country Club.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Newmark-Healthcare-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26391</link>
<guid>4d04ff8c215cf3678bb0b3aaf7ee4939</guid>
<pubDate>Wed, 15 Oct 2025 16:46:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Newmark-Healthcare-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d49997f510e3334ec0f82c83b4cf0963cff83bb8916610979a72530d6ebd226</i><br /><br />Threat actor <b>description</b>: <i>Newmark Healthcare Services specializes in healthcare recruiting, staffing, and medical career placement, including locum tenens physician placement. The company provides customized solutions tailored to meet the unique needs of healthcare organizations, enhancing recruitment strategies with the latest techniques and digital marketing. Their services extend to healthcare consulting, focused on optimizing organizational efficiency and addressing specific challenges faced by clients. With a commitment to honest engagement and personalized service, Newmark aims to build genuine partnerships with both clients and candidates.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>East-Jefferson-General-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26392</link>
<guid>ce182c417ca31f93b03690507fa78f83</guid>
<pubDate>Wed, 15 Oct 2025 16:45:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>East-Jefferson-General-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09432bd9773fc5cae657f9441ae25e09a52b56146fb900f1ee1ef07ed16edb4d</i><br /><br />Threat actor <b>description</b>: <i>Established in 1971, East Jefferson General Hospital is a non-profit community hospital providing care to patients throughout the area. The campus is located in Metairie, Louisiana.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Zierick-Manufacturing-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26393</link>
<guid>7cb74407125873315ea8225aacd97e6d</guid>
<pubDate>Wed, 15 Oct 2025 16:45:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Zierick-Manufacturing-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b615d14e75a19e5183903c4e3ed946b5cbc2000e90d616ac910623f39f9c51ec</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1919 and headquartered in Mount Kisco, New York, Zierick Manufacturing engages in designing, engineering, prototyping, and manufacturing connectors and other stamped metal components for the electronics industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Centurion-Family-Office-Services-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26387</link>
<guid>4b0c6b58fb9b42eaace2cb27c73343db</guid>
<pubDate>Wed, 15 Oct 2025 16:24:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Centurion-Family-Office-Services-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0bc807057bda7e956898c73e4a1b3aa31c1e2ace89a0959e4f7c9aaba59e520</i><br /><br />Threat actor <b>description</b>: <i>Centurion originated as an idea to bring the high-value, high-impact services, traditionally reserved for only the wealthiest of individuals, to a broader network of families and entrepreneurs. Our Family Office Services address the needs of             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Superior-Linen-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26374</link>
<guid>a0dabc6f2a8ea64b7fb210eec0175a02</guid>
<pubDate>Wed, 15 Oct 2025 15:25:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Superior-Linen-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60f44940a8c783269dfa7887b213e2005cb7305a96f8fc6e3d483b5ce0d3fd16</i><br /><br />Threat actor <b>description</b>: <i>The Superior Linen Supply Company is designed to serve as an extension of our customers' business. By providing timely delivery of quality merchandise, outstanding service and affordable prices for over a century, customers have come to know             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Victory-Christian-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26377</link>
<guid>fbd4c23e175c533d7887cf4c717fac7e</guid>
<pubDate>Wed, 15 Oct 2025 15:25:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Victory-Christian-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09560c53b2584c6dc99d4f77facfa80a6d20f1efbb66c490f6b163d1c16f37ac</i><br /><br />Threat actor <b>description</b>: <i>Victory Church is a community-focused church located in Tulsa, OK, dedicated to fostering a space where individuals can love God and love people. The church offers a variety of ministries, including programs for children, youth, and young adu            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bay-West</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26378</link>
<guid>af921d3f4ba622035a8eb3ec4cb87659</guid>
<pubDate>Wed, 15 Oct 2025 15:25:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bay-West</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7761275d04622f19b32c379ed9cc8da4cb7753fa201516076525533199ba1fac</i><br /><br />Threat actor <b>description</b>: <i>Bay West LLC provides environmental consulting and remediation services for government and commercial enterprises. The company offers services in the areas of industrial storm water permitting and consulting; brownfield site assessment, clean            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Florida-Marking-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26379</link>
<guid>eaef056473008c7fe947a09daeb8f592</guid>
<pubDate>Wed, 15 Oct 2025 15:25:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Florida-Marking-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7adf97366fe989af48b496e2e2d366f19b8c9930ef9e6e7f24b71a5def4625b</i><br /><br />Threat actor <b>description</b>: <i>The Kennedy Group, an Inovar company, specializes in providing innovative labeling and packaging solutions that enhance brand visibility. They offer a wide range of high-performance products, including pressure-sensitive labels, warehouse loc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wheale-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26381</link>
<guid>02d1941438bbd398f00e76203eeee9ea</guid>
<pubDate>Wed, 15 Oct 2025 15:25:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Wheale-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e279bcd709c53feacad5c3f2855cd3e36b76dc9fd935cc318c2156300fa5280</i><br /><br />Threat actor <b>description</b>: <i>It's Wheale Law Firm's vision that justice is achieved, tailored to each client's case.
Most injury lawyers define success in one way:  money.  Not surprisingly, these attorneys also treat each case and each client the same.  You deserve mor            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ChampionX</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26389</link>
<guid>724192f20f6974d1078ed37a52cf53e3</guid>
<pubDate>Wed, 15 Oct 2025 14:13:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>ChampionX</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad3d5650b0efd69cbc1e3636274bd33f4bdd15374ee598197bff55f36e482524</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in The Woodlands, Texas, ChampionX is a global leader in chemistry solutions and highly engineered equipment and technologies that he...</i><br />Target victim <b>website</b>: <i>championx.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kearney-Public-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26388</link>
<guid>6ca372d29d2e321e25d0a7a6458d7995</guid>
<pubDate>Wed, 15 Oct 2025 13:22:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Kearney-Public-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d0fce9c241dde8f19adb962ad8517385005b40473412684affc72c51c4874e2</i><br /><br />Threat actor <b>description</b>: <i>Kearney Public Schools is a school district comprised of 18 schools of various ages! This school has significant financial and other resources and the ability to protect itself and its students! However, it chose a poor path and is now paying for its irresponsibility! A large amount of confidential and classified information of various kinds was leaked into the public domain! This included personal security data, financial documents, and even information belonging to third parties, such as students' relatives and parents.</i><br />Target victim <b>website</b>: <i>kearneypublicschools.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Navigator-Business-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26370</link>
<guid>1ed013af9f67744751dc13861ebeea2f</guid>
<pubDate>Wed, 15 Oct 2025 09:45:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Navigator-Business-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aeca391f4555f803e8dd52efc0d4ea795ef8cf80fd7bb77c78414384e98d6f95</i><br /><br />Threat actor <b>description</b>: <i>Helps companies conquer their industry and business complexity by implementing and supporting the best fit systems and processes</i><br />Target victim <b>website</b>: <i>nbs-us.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Executive-Cabinetry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26337</link>
<guid>819ba59c63730c44639f973a71652916</guid>
<pubDate>Wed, 15 Oct 2025 02:24:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Executive-Cabinetry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6980e08107297e4510bada88d91b98764ba7cb639c8ffe56b7fb54ad3ea6e79e</i><br /><br />Threat actor <b>description</b>: <i>Located in Simpsonville, South Carolina, Executive Cabinetry is an industry leader in semi-custom and custom cabinetry. The Executive Cabinetry facility encompasses 226,000 square feet of vertically integrated manufacturing space. Simply stat            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>WebCut-Converting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26347</link>
<guid>0d0d9d004baee1e34b4dc96a0ba2e03d</guid>
<pubDate>Wed, 15 Oct 2025 02:24:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WebCut-Converting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edc42368c92c3d98625bd35933c6cd46fb938213c44647021f6e6c0c261a1c1b</i><br /><br />Threat actor <b>description</b>: <i>WebCut Converting, Inc. specializes in contract slitting, laminating, and sheeting services tailored for the printing, converting, medical, and industrial markets. They process a variety of substrates including films, foams, non-wovens, and p            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pro-Fab</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26350</link>
<guid>9a2645cb664378e50626065996e58791</guid>
<pubDate>Wed, 15 Oct 2025 02:24:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pro-Fab</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e485e08865c5cba9c3af9192a946b5b3a08d008310517f01f8a8a019131ee950</i><br /><br />Threat actor <b>description</b>: <i>Pro Fab, Inc. specializes in custom design and fabrication products and services primarily for cleanrooms and industries such as semiconductor manufacturing, medical pharmaceutical labs, and American defense. They offer a wide range of produc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>New-Jersey-Property-Liability-Insurance-Guaranty-Association</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26351</link>
<guid>a50d6d536bc495e21188adddad4e853a</guid>
<pubDate>Wed, 15 Oct 2025 02:24:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>New-Jersey-Property-Liability-Insurance-Guaranty-Association</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e3cfdf4b50b00d5230f83f191d2b64647dc2931f8759245841592e58aa5cfc3</i><br /><br />Threat actor <b>description</b>: <i>New Jersey Property-Liability Insurance Guaranty Association, USA - is committed to excellence in providing outstanding claims service to claimants and policyholders in accordance with the Association's statutory responsibilities on behalf of            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>All-Truck-Transportation-Co.-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26352</link>
<guid>659815cccf7b2a3c4bc88c198377a778</guid>
<pubDate>Wed, 15 Oct 2025 02:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>All-Truck-Transportation-Co.-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c1b0f66a0f1a9187ace8ede2ff93a52506067b25fe8eacd4fe5f306e82dea6d</i><br /><br />Threat actor <b>description</b>: <i>All Truck Transportation Co., Inc. is an asset-based carrier offering local and regional truckload transportation solutions. We are headquartered in Chicago, Illinois with a vast network of terminals throughout the Midwest. We operate within             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charles-River-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26353</link>
<guid>427d46205152382d9d20f64490c8cce0</guid>
<pubDate>Wed, 15 Oct 2025 02:24:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Charles-River-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a76e14b75c2d96c2521ffdf43d1c99317d824adc4d662dc3459404caf66a681</i><br /><br />Threat actor <b>description</b>: <i>Charles River Properties, USA -  a real estate brokerage based in Waltham, Massachusetts, that handles residential and commercial sales and rentals. The company works only with very large properties. In its portfolio you will not find real es            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ganther-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26335</link>
<guid>3ff55afdf16fea13cf00f29dddc53948</guid>
<pubDate>Tue, 14 Oct 2025 21:55:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Ganther-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3a2c00838bff12bac40eef57b692ad18316266ae50111073869ae793a682912</i><br /><br />Threat actor <b>description</b>: <i>Established in 1979, GCI is headquartered in Anchorage, Alaska. They are a telecommunications provider with services including internet, mobile, TV, and more. As Alaska's largest telecommunications provider, they're committed to bridging the digital divide in the most remote communities in the world by investing in connectivity solutions that empower all Alaskans to live more connected lives.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>UT-Health-Austin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26356</link>
<guid>4a381f06f401489920c2ed5650ac4915</guid>
<pubDate>Tue, 14 Oct 2025 20:25:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>UT-Health-Austin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96cccc3b46d9e54cb7f9b73ee9bba81a63494cff2186ad85f29b127c41244259</i><br /><br />Threat actor <b>description</b>: <i>UT Health Austin is the clinical practice of the Dell Medical School located in downtown Austin, offering personalized and comprehensive health care services. The organization provides a wide range of medical services including adult psychiat            ...</i><br />Target victim <b>website</b>: <i>www.uthealthaustin.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Repeated-Signal-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26323</link>
<guid>f35537cb63b3c6f0c82ff3d27e37814f</guid>
<pubDate>Tue, 14 Oct 2025 20:24:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Repeated-Signal-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69c9b0f4efec61d47299fce005a52d6c5d9ae99279255fb04de401b8739fdea9</i><br /><br />Threat actor <b>description</b>: <i>Repeated Signal Solutions (RSS) specializes in Cellular, Public Safety, and Wireless Coverage Solutions, offering a wide range of services including engineering, construction management, and managed services since 2004. Their expertise spans             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Catawba-County-Government</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26324</link>
<guid>deabeaf0bc00589d890fa81d23f56bf5</guid>
<pubDate>Tue, 14 Oct 2025 20:24:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Catawba-County-Government</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b0e89f5af3cf3db6efabb60e0a9059f87ba49f8ccf3fffff99b39a6ba890feec</i><br /><br />Threat actor <b>description</b>: <i>Catawba County, NC provides an online directory to services around the area including Human Resources, Libraries, Sheriff's Office and more. Created for Catawba County and located in North Carolina.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>HMP-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26325</link>
<guid>7b5bdfc3463973353c96415d45663cc4</guid>
<pubDate>Tue, 14 Oct 2025 20:24:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>HMP-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1c579c8acf0604b060ecdeb93f4a0f6cf9e746d5fbe945886a17a7134ee96ca</i><br /><br />Threat actor <b>description</b>: <i>For 40 years, the company has built trusted brands including Psych Congress, the premier source for mental health education, and the Symposium on Advanced Wound Care (SAWC), the largest wound care meeting in the world. HMP Global partners wit            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Morris-Sockle</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26326</link>
<guid>aae14bda33aa45a1d45d45011529b806</guid>
<pubDate>Tue, 14 Oct 2025 20:24:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Morris-Sockle</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d19e7b2f68fab8b9c3c5814906953c2e6d37cfcc6db2c7d1eb35fea3175f7d7</i><br /><br />Threat actor <b>description</b>: <i>Morris-Sockle, PLLC is a premier law firm specializing in Family Law and Divorce, with over 40 years of experience in protecting clients' rights during and after divorce. They offer a comprehensive range of services including divorce processe            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Capitol-Construction-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26327</link>
<guid>b2a223f097589a3682d3221d102fc52e</guid>
<pubDate>Tue, 14 Oct 2025 20:24:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Capitol-Construction-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8c0aa25b057ce88c36c466974d444cf7d7fc9d0fade194354d4557dca5c3637</i><br /><br />Threat actor <b>description</b>: <i>For over 25 years, Capitol Construction Services, Inc. has been one of the most professional general contractors in the Indianapolis market and has followed many clients all over the United States. CCSI has become experts in the areas of tena            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Journal-of-Managed-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26331</link>
<guid>ac596866c319dc8ac9d108a4f3da2fc3</guid>
<pubDate>Tue, 14 Oct 2025 20:24:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>American-Journal-of-Managed-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63bba3d180741f771c979a5b3c32e71986935761d14c0841e8469dfdbf2f24dc</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1995, The American Journal of Managed Care is a multimedia peer-reviewed, Medline-indexed journal that keeps industry leaders on the forefront of various different policies. This company is headquartered in Cranbury, New Jersey.
T            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>PQCNC-Hospitals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26333</link>
<guid>556af2550dcbee76da893225af4aaf44</guid>
<pubDate>Tue, 14 Oct 2025 20:24:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PQCNC-Hospitals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8432a1e804ea8c125ea783d66620c39e3be7605240c3d46371096ae29c83eeb</i><br /><br />Threat actor <b>description</b>: <i>The Perinatal Quality Collaborative of North Carolina is a community-focused organization dedicated to improving maternal and infant health outcomes in the state. They offer various initiatives and resources aimed at enhancing the quality of             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-Riviera-Beach-Florida</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26360</link>
<guid>83575ac3b1da0569ebbbea825b9346a3</guid>
<pubDate>Tue, 14 Oct 2025 20:22:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>City-of-Riviera-Beach-Florida</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>60f78a70385f49d0580214cbee0235bfc7e3ed9f4a6e9ba92e347901e22bd8ee</i><br /><br />Threat actor <b>description</b>: <i>The City of Riviera Beach is committed to making its' website/social media accessible and user-friendly for everyone. If you are having difficulty viewing or navigating the content on our website, or notice any content, feature, or functional            ...</i><br />Target victim <b>website</b>: <i>www.rivierabch.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trans-World-Shipping-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26362</link>
<guid>fec4a76ff20508cb6c36cf6b37fea805</guid>
<pubDate>Tue, 14 Oct 2025 20:21:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Trans-World-Shipping-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eed3f408b8cc333457cec69b369b7339db50fe8081ec67181821c745afede9ad</i><br /><br />Threat actor <b>description</b>: <i>Trans-World Shipping Service, Inc. and Toledo Air Cargo, Inc. are full-service companies offering a wide variety of import and export services including US customs brokerage, international freight forwarding, air freight services, warehousing            ...</i><br />Target victim <b>website</b>: <i>www.tws-tac.net</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Addis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26363</link>
<guid>e8349b4c48f9678248af8c5e8148a16e</guid>
<pubDate>Tue, 14 Oct 2025 20:21:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Addis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0dc31cde1e4e001a35d282e33e87b0dc5da5394d5c124604d44b21b9cb163709</i><br /><br />Threat actor <b>description</b>: <i>Addis, Louisiana, located in West Baton Rouge Parish, along the Mississippi River, situated on Louisiana Highway One, is located just minutes from Louisiana’s State Capitol City – Baton Rouge. The Town of Addis is a growing town, home to             ...</i><br />Target victim <b>website</b>: <i>www.addisla.org</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>LaRosas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26365</link>
<guid>105f777347c73908a23cbf0de0c33d3b</guid>
<pubDate>Tue, 14 Oct 2025 20:19:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LaRosas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80b7267531b73cad4e991fadb80c26375447c7750b1154773cb92a22dd838712</i><br /><br />Threat actor <b>description</b>: <i>LaRosa's, Inc. operates and franchises Italian restaurants and family pizzerias. The company offers pizzas and other Italian favorites for dine-in, delivery, and carrying out. It serves guests and neighborhoods throughout Greater Cincinnati,             ...</i><br />Target victim <b>website</b>: <i>www.larosas.com</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ostrolenk-Faber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26316</link>
<guid>7059c6d38ee3bd1197869687cbb10fc2</guid>
<pubDate>Tue, 14 Oct 2025 18:25:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ostrolenk-Faber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e58f6bb2042f5da24b20a03bfb60cad8cbbfc8ddb6c8143d26d938bb8f70681c</i><br /><br />Threat actor <b>description</b>: <i>Ostrolenk Faber LLP is a premier intellectual property boutique law firm that has been specializing in domestic and international intellectual property legal matters since 1929.We are ready to upload more than 43gb of corporate documents. Employees personal documents, scans of customer documents (SSNs, name, DOB, address and so on), project files, lots of client information, financials, confidential project files, contracts and agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Art-Guild</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26317</link>
<guid>771f705223826e116ce54153b8f1268a</guid>
<pubDate>Tue, 14 Oct 2025 18:25:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Art-Guild</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0f40dcf1bec8cf3b70c4f549ab41142764ce4bd25cb1a9feaa8a43bd3c4ac37</i><br /><br />Threat actor <b>description</b>: <i>Art Guild is a full-service provider of face-to-face marketing and educational programs.We are ready to upload 24gb of corporate documents. Lots of HR files with employee information (DOB, addresses, phones, medical test and so on), a bit of client data, financials, contracts, confidential project files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>baronespecialtysteel.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26334</link>
<guid>93f19dbc4426f203a274642a804f36e8</guid>
<pubDate>Tue, 14 Oct 2025 16:53:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>baronespecialtysteel.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c34fa677d8ae9359ed23d3fc2b93e44c3c364011d9254c3ffdf923fe351804e3</i><br /><br />Threat actor <b>description</b>: <i>Bar One Specialty Steel specializes in providing high-quality specialty steel products tailored for various industrial applications. Their product offerings include a wide range of steel grades and forms designed to meet specific client needs. The company primarily serves clients in the manufacturing, construction, and automotive sectors. With a focus on exceptional customer service and precision engineering, Bar One aims to be a trusted partner in the steel supply chain. Employees: 25 Revenue: $5 Million Industry: Industrial Machinery & Equipment Phone Number:(877) 541-6421</i><br />Target victim <b>website</b>: <i>baronespecialtysteel.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Law-Offices-of-Michael-C-George</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26315</link>
<guid>e75d64c2cffa2c2daa3809c44103d725</guid>
<pubDate>Tue, 14 Oct 2025 16:25:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Law-Offices-of-Michael-C-George</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>def33117dc204e7daa057cad1211b83074d10370fbf8fd92afbe773dd0a4c9c0</i><br /><br />Threat actor <b>description</b>: <i>The Law Office of Michael C. George, P.A. specializes in personal injury and criminal law, providing legal representation for clients throughout Florida who hav...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pratt-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26308</link>
<guid>476e44e8d1f95737990dcabe656081b4</guid>
<pubDate>Tue, 14 Oct 2025 15:25:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Pratt-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e20514cf8bebccd3d39b58780ca36ba63cc6329f3b88510ec6ab189d1f58b390</i><br /><br />Threat actor <b>description</b>: <i>Pratt Homes was founded in 1973 by Len and Lowell, who, along with their partner Uncle Doug, built their first official Pratt Home in Scandia. They faced student loans but were driven by a passion for quality craftsmanship. Their commitment t            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Force-Marketing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26309</link>
<guid>ba0745192120cbda87da3de261ec9f02</guid>
<pubDate>Tue, 14 Oct 2025 15:25:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Force-Marketing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc5a610931339e0c3e0e227b19c58614dd08ace26254aa250739f3023c508aff</i><br /><br />Threat actor <b>description</b>: <i>Force Marketing, USA - Founded in 2006, Force Marketing is a leading marketing technology provider to the automotive industry, whose Helix Technologies, WeDrive Automotive and DRIVE video technology brands deliver combined synergies to optimi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plast-O-Matic-Valves</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26310</link>
<guid>ea8f123bcd0751b651e0944774d790e0</guid>
<pubDate>Tue, 14 Oct 2025 15:25:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Plast-O-Matic-Valves</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d7c8023b08dcbec7994f3dd84d5e4d2a0277794ecc04c10aef9f143a1013f36</i><br /><br />Threat actor <b>description</b>: <i>Plast-O-Matic Valves, Inc. specializes in the development and manufacturing of high-quality thermoplastic valves and controls for various industries, including agriculture, chemical processing, wastewater treatment, and semiconductor applications.We are ready to upload 51gb of corporate documents. Employees personal documents (DLs and others), lots of HR forms, clients information, financial and accounting data, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blood-Bank-Computer-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26311</link>
<guid>48e3e457e80b2cf856688ab6280c0d56</guid>
<pubDate>Tue, 14 Oct 2025 15:25:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Blood-Bank-Computer-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c577b1e51f742ea1ea0134507a7a11a4e4fd6974e9e3e506dd11f9ce8b43db8</i><br /><br />Threat actor <b>description</b>: <i>BBCS Inc specializes in innovative blood banking software and biologics management solutions, designed to enhance operational workflows and decision-making for healthcare providers.We are ready to upload 20gb of corporate documents. Detailed employees personal documents scans (passports, DLs, SSNs, w-9 forms, credit card details and so on), confidential HR forms, clients information, medical information, financial and accounting data, contracts and agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ME-Global-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26313</link>
<guid>93c91c3712b38f071fe9804ced79c112</guid>
<pubDate>Tue, 14 Oct 2025 14:25:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ME-Global-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3099d2096edfd224f71781a130b68fdb719740ceece7335653d181a216da814f</i><br /><br />Threat actor <b>description</b>: <i>M&E Global Group, Inc. USA -  specializes in point of purchase display and store fixture manufacturing, offering comprehensive services from design to production and fulfillment. Another part of this business is the production of parts such a            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Karnes-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26292</link>
<guid>35b729b42782ce151f53d08c954284dd</guid>
<pubDate>Tue, 14 Oct 2025 02:25:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Karnes-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6d2972e601a8f30e319ec33b6694a9aadef0aa0ef174df5097fbf0dfd7f109e</i><br /><br />Threat actor <b>description</b>: <i>Karnes Electric Cooperative, USA is a not-for-profit electric distribution utility that serves 12 counties in South Texas and the Coastal Bend region. Headquartered in Karnes City, Texas, it offers competitive rates and innovative solutions t            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bank3</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26290</link>
<guid>72dee70a8d52e44dd4e2bd463b806ffe</guid>
<pubDate>Tue, 14 Oct 2025 00:25:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Bank3</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd317752d4b01743a46381ff9561c3bad47c06c4e66b2e85e2c18f067caf2094</i><br /><br />Threat actor <b>description</b>: <i>Bank3, USA - it's a disaster for the clients. Bank3 is a community-driven banking institution offering personal and business banking services, as well as mortgage lending. The bank serves clients in various locations including Memphis, Nashvi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>San-Bernard-Electric-Cooperative</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26288</link>
<guid>b769f92a201bb18dd58e514e7c2e8f05</guid>
<pubDate>Mon, 13 Oct 2025 23:26:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>San-Bernard-Electric-Cooperative</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>06f66335c3f402064e34c90329f0ab59e622cfa5ff82b9d94c88d35e30e62e7d</i><br /><br />Threat actor <b>description</b>: <i>San Bernard Electric Cooperative, USA - offers a range of services including outage reporting, generator installation, and energy efficiency programs. Its intended clients are members of the community who utilize electric services, as well as            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>SourceOne-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26282</link>
<guid>806107639381a3c77b34ee5128f7430f</guid>
<pubDate>Mon, 13 Oct 2025 21:01:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>SourceOne-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>215efb41c65358e9a58755afede401184df5477f4f68c35867c3ffbdfe2310ba</i><br /><br />Threat actor <b>description</b>: <i>SourceOne Corporation, USA - specializes in managing all phases of Outside Plant (OSP) and Inside Plant (ISP) projects, offering comprehensive solutions including fiber design, permitting, construction, and final inspection. The company provi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fountains-Condominium-Operations</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26283</link>
<guid>f0bc49a48370642aac2e13d6db960830</guid>
<pubDate>Mon, 13 Oct 2025 21:01:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Fountains-Condominium-Operations</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d469f05eebec246fd24b4b79ecbdbc4d2f6d824f7dfeee2cae0eb4c2d9092610</i><br /><br />Threat actor <b>description</b>: <i>Fountains Condominium Operations Inc. is an in-house management company dedicated to ensuring the beauty, safety, and stability of the area, promoting neighborl...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Design-To-Print</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26261</link>
<guid>2fd71648d0bfec3f35c7415c3901a72c</guid>
<pubDate>Mon, 13 Oct 2025 13:58:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Design-To-Print</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>336af02c5899276594fa4c63b9ff246d51c2e893c2207e1c485b8f3aa1309dea</i><br /><br />Threat actor <b>description</b>: <i>Printdaddy design printing is known for its excellence and expertise in indoor, outdoor advertising, custom vinyl banners that are personalized according to your business requirement. Advertise you business well and our designs will bring the best out of your services company is headquartered in 175 N 400 E, St. George, UT 84770, USA. 73 Employees. The total amount of data leakage is 3.3 TB. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cemtrex</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26263</link>
<guid>1d03841ea08e08c6e1c43cee7e07aaaa</guid>
<pubDate>Mon, 13 Oct 2025 13:52:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Cemtrex</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b666d7e5c53dbc88eb1bd2b3f61caba6ce2d0b0f15ca8d921fc241868c4f501c</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2004 and headquartered in Brooklyn, New York, Cemtrex is a global, diversified industrial and manufacturing company that provides a wide array of solutions to meet today's technology challenges. Cemtrex provides manufacturing services of advanced custom engineered electronics, industrial contracting services and monitoring instruments for industrial processes and environmental compliance. company is headquartered in 276 Greenpoint Avenue, Building 8, 2nd Floor, Brooklyn, NY 11222, USA. 264 Employees</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>North-Stonington-Elementary-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26285</link>
<guid>acc9a9c91909c59853d0f527e068c11c</guid>
<pubDate>Mon, 13 Oct 2025 13:17:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>North-Stonington-Elementary-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0671d8619dd27c5f9446d44e7495a0321367ab04787f49d3238ccf99f3e64bf4</i><br /><br />Threat actor <b>description</b>: <i>North Stonington Public Schools have two public schools and 736 students, strives to create a safe environment for themselves, their school, and their students. However, their "Safety First" slogan has recently changed! Despite having extensive resources and support, North Stonington Public Schools has a very poor IT security team that is doing a poor job! With our help, over 3 TB of confidential data was exposed, meaning all student data, including the entire history and documentation, is now in our hands!</i><br />Target victim <b>website</b>: <i>northstonington.k12.ct.us</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>michigancityin.gov</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26273</link>
<guid>90ee95b54c20d0991531360036611c37</guid>
<pubDate>Mon, 13 Oct 2025 11:52:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>obscura</b> claims attack for <b>michigancityin.gov</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83939e57e2100273ab29aeb3a6131071c4aacb08e3ca2caa32b9a97675e73753</i><br /><br />Threat actor <b>description</b>: <i>Revenue: ?? | Leak Size: 450 GB | Status: Published</i><br />Target victim <b>website</b>: <i>michigancityin.gov</i>]]></description>
<category>obscura</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carewell</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26264</link>
<guid>4f513f68a7732df8db6b106ba6565073</guid>
<pubDate>Mon, 13 Oct 2025 09:20:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Carewell</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d03ddf7af069a44c4eac4df66c57e2ef94571ddb48936fecb2810bbfd0d93b89</i><br /><br />Threat actor <b>description</b>: <i>No description available.</i><br />Target victim <b>website</b>: <i>Not provided</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>CMF</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26258</link>
<guid>902c747a0d415560ebd0cfb9f8e01794</guid>
<pubDate>Sun, 12 Oct 2025 20:43:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>CMF</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b8683d8f0312755d065b63da1106dd793711e7b3c803fc93f1ad59413ba4608</i><br /><br />Threat actor <b>description</b>: <i>CMF Inc specializes in expert design assistance, fabrication, and installation services for architectural sheet metal and related products. Since 1956, they have collaborated with leading architects and builders to deliver innovative metal solutions for a variety of projects, including commercial, educational, and public spaces. Their comprehensive services encompass design-build, design-assist, CAD/BIM drawing, and all aspects of metal roofing and siding. CMF is recognized for their craftsmanship, having received multiple awards for their work on notable projects like the Apple Park Headquarters and the LACMA Resnick Pavilion.</i><br />Target victim <b>website</b>: <i>www.cmf.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sunbelt-Design--Development</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26259</link>
<guid>b02e588aac5fb0396ed0293ebaba8326</guid>
<pubDate>Sun, 12 Oct 2025 20:42:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Sunbelt-Design--Development</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>762bf031d09187ed78b80de24b20e6ec8b0e027798a27a38f23265f4c66f3a47</i><br /><br />Threat actor <b>description</b>: <i>Sunbelt Design & Development, Inc. specializes in ground handling equipment, lifting equipment, inspection equipment, spare parts, and maintenance equipment. The company aims to provide high-quality solutions for clients in need of reliable lifting and handling equipment. Their comprehensive offerings include inspection and testing services, ensuring safety and compliance in operations. Based in San Antonio, Texas, Sunbelt caters to various industries that require robust handling and maintenance solutions.</i><br />Target victim <b>website</b>: <i>www.sunbeltdesignanddevelopment.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>HARVARD.EDU</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26252</link>
<guid>eadb38098fddecbe319d0d83c840134a</guid>
<pubDate>Sun, 12 Oct 2025 19:42:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>clop</b> claims attack for <b>HARVARD.EDU</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c8b43708820d952fb4cb284521fb4f966b5019fcc66298abdb92181c9370c6b</i><br /><br />Threat actor <b>description</b>: <i>Headquarters:
Massachusetts Hall, Cambridge, Massachusetts, 02138, United States
Phone:
(617) 495-1000
Website:
www.harvard.edu
Revenue:
$6.1 Billion
Industry:
Colleges & Universities, Education </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>clop</category>
</item>
<item xmlns:dc='ns:1'>
<title>Team-Schierl-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26239</link>
<guid>e81fbbc0f74685dfb845057e10587be2</guid>
<pubDate>Sun, 12 Oct 2025 03:26:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Team-Schierl-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>69b66ea032cb4115ecc44574c1254b2a4af53a41b81cae870a53d167be693ca2</i><br /><br />Threat actor <b>description</b>: <i>Team Schierl Companies is an organization of retail businesses and real estate development. TSC was founded in 1956 and is currently headquartered in Stevens Point, Wisconsin. Today, the family owned and operated Team Schierl Companies passed            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Balfour-Beatty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26246</link>
<guid>c91c68898d52729db7e6168dcd9b2845</guid>
<pubDate>Sun, 12 Oct 2025 00:49:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Balfour-Beatty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2cf751ea359a40efbace4e9042cb4868ed5078fd81230fe57ef4fa9ae7815fdf</i><br /><br />Threat actor <b>description</b>: <i>Balfour Beatty US, founded in 1933 and headquartered in Dallas, Texas, is a commercial construction company that offers services for construction management, general contracting, cost consulting, and design-building.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Minnesota-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26249</link>
<guid>e11c667b4ee37a4d0ff7a34695f07405</guid>
<pubDate>Sun, 12 Oct 2025 00:15:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radiant</b> claims attack for <b>Minnesota-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>adb9985c632a307583da3bfb3c47c7225101837df65d055a30194ff5e1b2573b</i><br /><br />Threat actor <b>description</b>: <i>Unknown. Contact us within 7 days or we will expose your hospitals name, add the view more button and start our pressure process.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>radiant</category>
</item>
<item xmlns:dc='ns:1'>
<title>Retail-Texas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26248</link>
<guid>861180853c3c32a9d29791a80a8f21ec</guid>
<pubDate>Sun, 12 Oct 2025 00:14:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radiant</b> claims attack for <b>Retail-Texas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>40094a2e9f420e1bebb130e657e8955adb679538f85bbef1bb36cb6c2ffc7f3c</i><br /><br />Threat actor <b>description</b>: <i>Unknown. Contact within 7 days or we will publish your name, add the view more button and begin our pressure process.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>radiant</category>
</item>
<item xmlns:dc='ns:1'>
<title>Streebo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26245</link>
<guid>9ca688b61d4c5f20cab24ef1287e2bad</guid>
<pubDate>Sat, 11 Oct 2025 23:19:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Streebo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7c7241b26d9a3925dd0ebb63eef7ef05983de6e076d63f4c72fb2f6276b5f287</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "Streebo" is an established global IT solutions company, specializing in AI-powered digitization services and products. With a focus on Automation, Mobile and AI technology, Streebo develops digital experiences for industries like banking, healthcare, eCommerce, & telecommunication. Renowned for its consultative approach, Streebo partners with businesses to reshape and renovate their digital landscape, aiding in their overall growth and efficiency.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Citizens-Committee-for-Children-of-New-York</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26242</link>
<guid>3afb012b9305852ff2d460b5aabd071d</guid>
<pubDate>Sat, 11 Oct 2025 20:32:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>brotherhood</b> claims attack for <b>Citizens-Committee-for-Children-of-New-York</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5eb35805d4bc0c7eff1aad19fc4b031531911085768b4c7cece9c4cb0dc7c739</i><br /><br />Threat actor <b>description</b>: <i>Contains: 45 Gb compressed Files</i><br />Target victim <b>website</b>: <i>www.cccnewyork.org</i>]]></description>
<category>brotherhood</category>
</item>
<item xmlns:dc='ns:1'>
<title>Maine-Oxy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26238</link>
<guid>df35ddf90fe44c0afd1a334f5d2aa398</guid>
<pubDate>Sat, 11 Oct 2025 16:07:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Maine-Oxy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>33d9096d823591e30d56b6a5fa6d24bd5bc0ab10df8782228dfc7e9553220735</i><br /><br />Threat actor <b>description</b>: <i>Financial data breach</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Complete-Milling-Lab</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26217</link>
<guid>794c58ac5bc1a201c0dd171621d565bd</guid>
<pubDate>Fri, 10 Oct 2025 21:15:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Complete-Milling-Lab</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>985830bf10a216150ee8ccef7a54e6cbadc183da91b64b56c8e095b7db47c10d</i><br /><br />Threat actor <b>description</b>: <i>Complete Dental Lab is a family-owned dental laboratory based in South Florida, specializing in a wide range of custom restorations. They focus on delivering high-quality oral products, including crown and bridge restorations, partial dentures, and night guards, while also offering 24-hour expedited services. Their commitment to customer service fosters strong relationships with dentists and their staff, enhancing dental practices through superior products. The lab leverages advanced dental techniques and materials to cater to diverse client needs, ensuring durability and aesthetic appeal.</i><br />Target victim <b>website</b>: <i>completemillinglab.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Paleontological-Research-Institution</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26218</link>
<guid>bac5c16e8ddd5aba46bf99b19c05fe93</guid>
<pubDate>Fri, 10 Oct 2025 21:15:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Paleontological-Research-Institution</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd2ac13c98748a346c36e599997a944e3c2b7610fdafeb7b19c39f93de731139</i><br /><br />Threat actor <b>description</b>: <i>The Paleontological Research Institution, or PRI, is a paleontological organization in Ithaca, New York with a mission including both research and education. The Paleontological Research Institution was founded in 1932.</i><br />Target victim <b>website</b>: <i>www.priweb.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>empirico-mr.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26226</link>
<guid>1e360e456bb346d5ec2e9d6b411a323f</guid>
<pubDate>Fri, 10 Oct 2025 21:14:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>empirico-mr.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f1cae867ab678807a5c065737e42fd69c13c0688fd9e8406c2cc0b27491286b</i><br /><br />Threat actor <b>description</b>: <i>Empirico Research is a boutique global market-research and data-collection firm founded around 2016. The company combines online panels, telephone interviewing …</i><br />Target victim <b>website</b>: <i>empirico-mr.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>bridgenetcommunicationsrgv.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26224</link>
<guid>851fd85e0c2baf63f6042123c2b4aac7</guid>
<pubDate>Fri, 10 Oct 2025 21:13:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>bridgenetcommunicationsrgv.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8f7633a470391cae9c3f2f595b1821520c8c16f9ceecb4bed0caa2db08b95737</i><br /><br />Threat actor <b>description</b>: <i>BridgeNet Communications is a regional low-voltage and structured-cabling specialist serving the Rio Grande Valley and parts of Central Texas. The …</i><br />Target victim <b>website</b>: <i>bridgenetcommunicationsrgv.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>krne.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26223</link>
<guid>cfe04034c4af619cfabd5f2c785131d2</guid>
<pubDate>Fri, 10 Oct 2025 21:12:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>krne.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bc8f3d7ae55548a48efce59a00766ffbf27b660e0e32098ee4df63047a04f2b</i><br /><br />Threat actor <b>description</b>: <i>Krne Law Firm a small to mid-size private legal practice, perhaps specializing in general civil law, real estate, business contracts, …</i><br />Target victim <b>website</b>: <i>krne.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>portofuneralhomes.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26221</link>
<guid>89c44761d7bafba48b64d0477dfb544e</guid>
<pubDate>Fri, 10 Oct 2025 21:11:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>portofuneralhomes.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ddb4d3753c58d7f6e08f9c8cc281ab4245415ea2b3b10a9c653e785213444ad</i><br /><br />Threat actor <b>description</b>: <i>Porto Funeral Homes (Porto / Porto Funeral Home) operates funeral and memorial services in New Haven County, Connecticut, with facilities …</i><br />Target victim <b>website</b>: <i>portofuneralhomes.net</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bellingham-Vet-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26216</link>
<guid>67c4b489cfd04c9a094ea2781cb69bee</guid>
<pubDate>Fri, 10 Oct 2025 20:23:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bellingham-Vet-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b34fbc004ffd469b193f51e85d9780f545c1d799d6e46fc8e8e2a597527bbe2b</i><br /><br />Threat actor <b>description</b>: <i>Bellingham Animal Hospital specializes in preventive care. We strongly recommend regular check-ups for your animal to ensure better health and a longer life. If your pet needs medical attention, Bellingham Animal Hospital's staff will take the time to explain treatment options. We'll help guide your decision process by answering any questions or concerns. Our practice utilizes the latest technology to help your pet overcome ailments and return to full health.</i><br />Target victim <b>website</b>: <i>www.bellinghamvetcenter.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Central-Jersey-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26213</link>
<guid>bb6023f7e8817eda36cae6b7405ee65d</guid>
<pubDate>Fri, 10 Oct 2025 20:22:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Central-Jersey-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0684e82d7a72b5ba5c0577ebfca14d203f0ccd97a37e7ebe919bab5416a3cacc</i><br /><br />Threat actor <b>description</b>: <i>Central Jersey Medical Center (CJMC) is a Federally Qualified Health Center (FQHC) that provides primary care, dental, and preventive health services for you and your family. We are a community-based center, guided in part by our patients, and focused on meeting the health needs of the people we serve.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brevard-Skin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26215</link>
<guid>57198de0fd9b28665ba93b8c07ccbae3</guid>
<pubDate>Fri, 10 Oct 2025 20:17:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Brevard-Skin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f684a256f98cb171ddd6ec2af375dadb104199a5cc2c12e385aff2429b02c88</i><br /><br />Threat actor <b>description</b>: <i>Dedicated to providing comprehensive dermatological care to address a wide range of skin, hair, and nail conditions</i><br />Target victim <b>website</b>: <i>brevardskin.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Confie</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26210</link>
<guid>79976930d5b363b51b6e7557ac2dafd2</guid>
<pubDate>Fri, 10 Oct 2025 15:37:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Confie</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4ce43f55695f1c63c8e622f775eabebb569aeb85cf65d4f5d9008ab15f9c5f9a</i><br /><br />Threat actor <b>description</b>: <i>Confie, founded in 2008 and headquartered in Huntington Beach, California, is an insurance distributio…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>americanhome</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26196</link>
<guid>d17f5f9a0f781be4885fbd8b25f4f51a</guid>
<pubDate>Fri, 10 Oct 2025 15:31:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>americanhome</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0d8b394e7480aca9fa8032a0a43ee735329704a39f9ce880b1a44e0e688758a2</i><br /><br />Threat actor <b>description</b>: <i>American Home Furniture and Mattress was founded by Mr. Emanuel "Mannie" Blaugru...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Five-Star-MechanicalInc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26197</link>
<guid>bafe5a19bbef4152f217efc037c1be59</guid>
<pubDate>Fri, 10 Oct 2025 14:34:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Five-Star-MechanicalInc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f32839c6efd89c6a251ea2239a58a1de8910b227f5e2fb9349d0e81866d3f80a</i><br /><br />Threat actor <b>description</b>: <i>Five Star Mechanical Inc. specializes in providing commercial andindustrial HVAC services, plumbing, piping, and sheet metal fabrication.We are ready to upload 30gb of corporate documents. Employee and owners personal information (passports, DLs, SSNs, address, emails and so on), customers files, projects, financials and other operating files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carlson-Building-Maintenance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26198</link>
<guid>0e8b25d538721f754c135daf02eb8a64</guid>
<pubDate>Fri, 10 Oct 2025 14:34:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Carlson-Building-Maintenance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5739c9ee8bc54964c75223f5b8ec7f62446532bb3bb16d89f02ec7df2fefb522</i><br /><br />Threat actor <b>description</b>: <i>Carlson Building Maintenance specializes in commercial cleaning services throughout the Midwest, offering a variety of solutions including general cleaning, hard floor care, carpet cleaning, and specialty services. They serve diverse industries such as retail,grocery, schools, and warehouses, tailoring their cleaning programs to meet the specific needs of each facility. We are ready to upload more than 20GB of there data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, driver's licenses, emails, phones), confidential information and other documents with personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Friendly-Gus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26209</link>
<guid>1135230be8c1d1853111db00c02d48bb</guid>
<pubDate>Fri, 10 Oct 2025 13:49:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Friendly-Gus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7135638fcb7bb74458bf1ad0aac97eeb1463d908bd4ba3889c92522b727dd304</i><br /><br />Threat actor <b>description</b>: <i>FRIENDLY GUS FOOD STORE is a retail wholesale distribution business that is supplying independent grocers throughout rural Georgia. They offer chicken,iced tea and spaghetti. It was founded in year 1915 and it is headquartered at Dublin, Georgia.</i><br />Target victim <b>website</b>: <i>www.friendlygus.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Woodmen-Valley-Chapel</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26199</link>
<guid>63a82e1bc44f8cf90a9189b4632951df</guid>
<pubDate>Fri, 10 Oct 2025 12:38:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>brotherhood</b> claims attack for <b>Woodmen-Valley-Chapel</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>36dfcb7918af149e975cf8397095cbb5de394ee368268765121e7aaaf8297ead</i><br /><br />Threat actor <b>description</b>: <i>Contains: 274 Gb compressed Files</i><br />Target victim <b>website</b>: <i>woodmenvalley.org</i>]]></description>
<category>brotherhood</category>
</item>
<item xmlns:dc='ns:1'>
<title>Motility-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26202</link>
<guid>5fa260f9aef5c32cc0ddf4934f058bdf</guid>
<pubDate>Fri, 10 Oct 2025 12:37:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>brotherhood</b> claims attack for <b>Motility-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>729b3e4025bbd46440cbd113541ff00fc24d171aad3271004ba0f9a34fa21e5f</i><br /><br />Threat actor <b>description</b>: <i>Contains: 3.3 Gb compressed Files, Databases</i><br />Target victim <b>website</b>: <i>www.motilitysoftware.com</i>]]></description>
<category>brotherhood</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.ucisd.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26187</link>
<guid>a215c3439968170d0649dc73b81b5fb4</guid>
<pubDate>Thu, 09 Oct 2025 23:59:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.ucisd.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e0a1d3047f6a41c238782c60fd64d14323cb055df249d978fe86352e8af89e4</i><br /><br />Threat actor <b>description</b>: <i>Uvalde Consolidated Independent School District, USA -  is a public school district based in Uvalde, Texas, US. Located in Uvalde County, the district extends into portions of Zavala and Real counties. It is a progressive, rural school distri            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>georgetown-brewing-co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26190</link>
<guid>b9a01aa77750279f4bc00c265a632095</guid>
<pubDate>Thu, 09 Oct 2025 23:52:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>georgetown-brewing-co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3272dba385da398f0e6dd609e95f9c56d822375c41eb23ff8f4adc859ab66c53</i><br /><br />Threat actor <b>description</b>: <i>Georgetown Brewing Company is an independently owned craft brewery located in Seattle, known for its flagship beer, Mannys Pale Ale. The brewery transitioned from draft-only production to canning select beers and offers pints in its tasting room alongside kegs, growlers, and cans for customers to take home. Their focus remains on brewing high-quality, flavorful beer, with a lively atmosphere that encourages visitors to enjoy their offerings on-site or at local bars. Intended clients include craft beer enthusiasts and patrons looking to experience unique local brews.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accelerated</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26189</link>
<guid>df4dc4a2a2e34014279a7fe7dd5fd47b</guid>
<pubDate>Thu, 09 Oct 2025 18:19:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Accelerated</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa3e480129684e08ad56a2904e04a3aa9d776555dbf102e0b51a9f51f17d9306</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.acceleratedusa.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elmer-W.-Davis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26188</link>
<guid>caa1f293d0555eec031b201f066d6278</guid>
<pubDate>Thu, 09 Oct 2025 18:18:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Elmer-W.-Davis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd88cf8f9ffd3a3e4293329972ae0ff433c6b5b9f3c28c4b14a2452327e35e7e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.elmerdavis.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Midsun-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26183</link>
<guid>15dd27d1e33bb4f584e33e7ab49608d1</guid>
<pubDate>Thu, 09 Oct 2025 17:31:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Midsun-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eaa2a2aa598c8808581661e0c22326a7ff69e5d38b7b16528d69a93b8e70d788</i><br /><br />Threat actor <b>description</b>: <i>Midsun Group, USA specializes in extending the life of power utility equipment through premium silicone covers and coatings. Their innovative products provide solutions for wildlife intrusion and environmental contamination, enhancing reliabi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northern-Air-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26184</link>
<guid>16d62f85a33e3e975a40c787b69d68dd</guid>
<pubDate>Thu, 09 Oct 2025 17:31:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Northern-Air-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>268f3111e29649ad3dbdf199ca2cbad52b02f2bd4573b7e390e315535bf6b23f</i><br /><br />Threat actor <b>description</b>: <i>Northern Air Systems has been a leading manufacturer of high-quality HVAC systems for commercial and industrial applications for nearly three decades.We are ready to upload 22gb of corporate documents. Client data (DLs, addresses, emails), employee information (DLs, emails, phones and so on), lots of projects information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sdii-Global</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26186</link>
<guid>1c0ec7275bfb7c37e7ed1f88750cce1d</guid>
<pubDate>Thu, 09 Oct 2025 16:15:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Sdii-Global</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8fc5b55da7488318ad77c175bd4c31f353f92e7f5d41ffd1e80509a34f7beae</i><br /><br />Threat actor <b>description</b>: <i>Sdii Global Since 1989, Sdii Global has set the standard in forensic engineering and consulting, renowned for our expertise and unwavering commitment to excellence.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.msssolutions.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26185</link>
<guid>cd7624e391b1552c6de504d71dadc520</guid>
<pubDate>Thu, 09 Oct 2025 15:41:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>www.msssolutions.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aba545b7cfd3eaefcca16f40b36f196d3cbaaa74e51f9a8641090c7c28f4c537</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1996, MSS Solutions is a full-service Mechanical Contractor offering Design-Build, Design-Assist, and complete implementation services. The company specializes in new construction, large-scale renovations, and retrofit/replacement projects for HVAC, Fire, Security and Controls systems. Th…</i><br />Target victim <b>website</b>: <i>www.zoominfo.com/c/mss-solutions-llc/74305122</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>MBS-Secure</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26180</link>
<guid>4cb2c784110fa31d56c0d67b36d19cab</guid>
<pubDate>Thu, 09 Oct 2025 15:32:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>MBS-Secure</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e1b068eed259e7efa4287ab4972458d9a604dc7a53d1d337db931d9f7d7714f</i><br /><br />Threat actor <b>description</b>: <i>MBS Secure, Ntiva - Ignore your teeth and they'll go away. The same goes for customers. If you leak their confidential data online, they'll leave. That's what happened to MBS Secure, a cybersecurity company. It has many customers, including i            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heritage-Communities</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26179</link>
<guid>5872043836c3d79e59d2ad6886918bfd</guid>
<pubDate>Thu, 09 Oct 2025 10:26:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Heritage-Communities</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6b7f009ca0c62b0369774156e23391d2ade56d3e6dbfaabf6cf7c4e6d0abd66</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>cameronhodges.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26150</link>
<guid>968402fb81659baface13dfca7f11890</guid>
<pubDate>Wed, 08 Oct 2025 19:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>cameronhodges.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67639bab111d659cb9d81e0b0e096ec58bba72308328c51cdf3ce3008deb6abb</i><br /><br />Threat actor <b>description</b>: <i>Cameron, Hodges, Coleman, LaPointe & Wright, USA - No matter where you are in Florida, we are here to leak your data. law firm specializing in insurance defense with over 35 years of experience. They provide legal services to clients across F            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Peter-Law-Offices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26151</link>
<guid>c7550aa992da57915ff925bf923825fa</guid>
<pubDate>Wed, 08 Oct 2025 19:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>St-Peter-Law-Offices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53a192418751a5c9996c61c3940ec00490fb0e88490055d5cab6a2725e543a80</i><br /><br />Threat actor <b>description</b>: <i>St. Peter O’Brien Law Offices, P.C. is a law firm that specializes in various areas of law, including adoption, business formationand compliance, estate planning, real estate, tax law, general litigation, and guardianships.We are ready to upload 188gb of corporate documents. Employee personal documents (DLs, financials and other docs), customer files (DLs, SSN numbers, credit card details, payment details, medical records and so on), project information, financial and accountinginformation, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hoyer-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26152</link>
<guid>938a56471d1a3fb0f01f1b04ad30f398</guid>
<pubDate>Wed, 08 Oct 2025 19:27:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hoyer-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>61d850de85159a08b48e7f3c2abea5b17e099b6b9330863905ceb4d914f2500f</i><br /><br />Threat actor <b>description</b>: <i>Hoyer Law Group, PLLC is a nationwide law firm specializing in employment legal services, advocacy for victims of employment discrimination, harassment, wrongful termination, and help whistleblowers navigate legal complexities while safeguarding against retaliation.We are ready to upload corporate documents. Customer personal documents (a bit of personal docs, correspondence and other docs), employee files (w4 complete forms, SSNs, phones, addresses and so on), project information, medical reports, police reports, and other confidential documents, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>VIM-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26153</link>
<guid>141bd48b3fcfa157981a2155709ad6a7</guid>
<pubDate>Wed, 08 Oct 2025 19:27:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>VIM-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74d63f5da441e81263733ccd4076ab4923045e261cb55e2b76518a14c1de18d4</i><br /><br />Threat actor <b>description</b>: <i>VIM Technologies, Inc. is a leading provider of compliance monitoring software solutions and support services tailored for the electric utility and industrial markets.We are ready to upload corporate documents. Customer information,partners files, projects, contracts and agreements, employee files (I-9 forms and other data), NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chek-Tan-and-Company-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26175</link>
<guid>f47a07182433c042d84cb754ddcac64f</guid>
<pubDate>Wed, 08 Oct 2025 19:10:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>Chek-Tan-and-Company-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc400c7a4e552df72cd3ef85ec75cf6bb30633a141238dcd3ccf50b3b056dc0a</i><br /><br />Threat actor <b>description</b>: <i>Chek Tan and Company offers accounting, audits, management consulting, IRS representation, and tax management services. San Francisco, California, United States.</i><br />Target victim <b>website</b>: <i>chektan.com</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>Shape-Corp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26176</link>
<guid>f702ad17879bf0f827cdd740da7fb1df</guid>
<pubDate>Wed, 08 Oct 2025 19:08:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>Shape-Corp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9da06d17ab44172525f4ede12ffb0381d42d697c735a896ed0833eb50a130827</i><br /><br />Threat actor <b>description</b>: <i>Shape Corp. is a global leader in automotive engineering and manufacturing, providing advanced crash management and body structure solutions utilizing ultra-high strength steel roll forming, tight tolerance aluminum extrusions and large tonnage injection molding. The company specializes in producing lightweight and innovative products that maximize performance while minimizing environmental impact.
[[ Data extracted include Engineering design files, Marketing and presentation assets, CAD, mechanical designs, CNC programs, project documentation, automation data, brand media, financial, production, and quality assurance records etc.. ]]</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Catered-Affair</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26169</link>
<guid>4b8cdf66647df5b1d9549039eca7819e</guid>
<pubDate>Wed, 08 Oct 2025 17:24:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-Catered-Affair</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c7e8ce1bb7b086d8a7b5c1655ed3d657f4bc2fc2d1d82f955acbc29e6dd81ec3</i><br /><br />Threat actor <b>description</b>: <i>The Catered Affair is a Boston and New England catering company with upscale venues and creative menus for weddings, corporate events, and private parties.</i><br />Target victim <b>website</b>: <i>www.thecateredaffair.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Public-Relations-Society-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26170</link>
<guid>019059823f48e01d3dc9e864a371605f</guid>
<pubDate>Wed, 08 Oct 2025 17:24:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Public-Relations-Society-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0305073c314447acce241ca3161576add6252c3cc7b3ce9ce5ebe33c83a592ea</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1947, the Public Relations Society of America (PRSA) is a nationwide non-profit trade association serving the communications community and public relations professionals. It is headquartered in New York City, New York.</i><br />Target victim <b>website</b>: <i>www.prsa.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sun-Fiber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26171</link>
<guid>dcb5060fba0123ff56d253331f28db6a</guid>
<pubDate>Wed, 08 Oct 2025 17:24:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Sun-Fiber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2232e7ba8641fb8c5f6697d907047ff71ad9d53f2748b9b42e744f30b3c3cfb4</i><br /><br />Threat actor <b>description</b>: <i>Sun Fiber LLC is a leading manufacturer and supplier of recycled polyester staple fiber (Re-PSF), catering primarily to the Home Textile and Furniture industries. The company is committed to providing customized filling solutions that meet a variety of customer needs with a focus on softness and comfort. Sun Fiber emphasizes a customer-centric approach, offering supply chain support, technical assistance, and personalized service. Established in 1999, Sun Fiber combines industry expertise with sustainable practices to ensure product quality and reliability.</i><br />Target victim <b>website</b>: <i>www.sunfiber.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>MTI-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26172</link>
<guid>8803f7fa56465a59d0c1a12ec666f533</guid>
<pubDate>Wed, 08 Oct 2025 17:23:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>MTI-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fc84ebc560ddb949fa2947138ba1f54a03abfb64d5dbcee229fd05649e02b632</i><br /><br />Threat actor <b>description</b>: <i>MTI America specializes in providing comprehensive workers' compensation ancillary healthcare solutions, including transportation, language services, physical medicine, and home care. Their services cater to insurance carriers, self-insured employers, third-party administrators, and case management companies, ensuring efficient and empathetic patient care. The company offers a range of programs such as tele-rehabilitation, diagnostic imaging, and durable medical equipment, all designed to enhance the recovery process for injured workers. With a focus on innovation and client satisfaction, MTI America aims to transform the claims process and improve outcomes for patients.</i><br />Target victim <b>website</b>: <i>www.mtiamerica.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>D.-Wilson-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26173</link>
<guid>0594763bf6171668f8bc4cd79ebcbd63</guid>
<pubDate>Wed, 08 Oct 2025 17:23:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>D.-Wilson-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2cca11f6b60339dfe91ac40c238e61cf2a69e6cf6ce2cea985b77ad62d0e1940</i><br /><br />Threat actor <b>description</b>: <i>D. Wilson Construction is a leading commercial and industrial construction company founded in 1957, serving South and Central Texas from its offices in the Rio Grande Valley and San Antonio. Known for its reliable and timely building solutions, the company specializes in both design-build and design-bid-build projects. Their notable clients include the Bert Ogden Auto Group and the City of New Braunfels, reflecting a diverse portfolio in the commercial sector. D. Wilson Construction has earned recognition as a top contractor in the region, showcasing their commitment to quality and client satisfaction.</i><br />Target victim <b>website</b>: <i>www.dwilsonconstruction.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>IFPC-Worldwide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26174</link>
<guid>dd5db93a1d7b73cc6b3e36f136f7d99f</guid>
<pubDate>Wed, 08 Oct 2025 16:57:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>IFPC-Worldwide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ccb4f8cf5b8e10c15237cd63c2a1627d55c21b3e22d8f2435161721247010ab</i><br /><br />Threat actor <b>description</b>: <i>Once again, a company "IFPC" that claims to ensure public safety during hiring, customer verification services, and a wealth of other personal and confidential information has been leaked due to poor security and employee performance.</i><br />Target victim <b>website</b>: <i>ifpcworldwide.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Right-at-Home-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26158</link>
<guid>f1461909ac11780acf665caf329c10b9</guid>
<pubDate>Wed, 08 Oct 2025 16:15:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Right-at-Home-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8a826130b87cba3f2611aaae6a75a12e1dfd6f026ee2bab65f2b50356d8a825</i><br /><br />Threat actor <b>description</b>: <i>Right At Home Care, LLC provides home care services designed to promote independence, healing, and comfort for clients. Their offerings include companionship care, assistance with daily living activities, and specialized care for conditions like Alzheimer's and dementia. The company focuses on tailoring care to meet the individual needs of each client, ensuring a personalized approach. Their intended clients are individuals seeking to maintain their quality of life and independence while receiving compassionate support in the comfort of their own homes.</i><br />Target victim <b>website</b>: <i>www.rightathomecare.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Industrial-Chemicals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26159</link>
<guid>09b8c249733de5c23897177cc1a25e51</guid>
<pubDate>Wed, 08 Oct 2025 16:14:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Industrial-Chemicals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8912dbd46219c2ace00a6f089254ca2589a64581529a038e1aaa24ba6fa01754</i><br /><br />Threat actor <b>description</b>: <i>Industrial Chemicals Corporation is a wholesale-commodity chemical distributor. We have proudly served the Colorado market for over 60 years and the New Mexico market for nearly 20 years. Our primary focus is to provide a variety of chemicals to the marketplace that is in packaging suitable to the customer's requirements. We will provide reliable service to our customers, with quality products, by anticipating and then meeting/exceeding their expectations. We are dedicated to the safety of our employees and our customers. We will operate our distribution facilities with the utmost concern for safety. We will represent our supplier partners in a cooperative and responsible manner that demonstrates a concern for the environment and our community. Our standard is to meet as minimum, and to exceed as a norm, all parameters in the "Responsible Distribution Process", as set forth by the National Association of Chemical Distributor (NACD).</i><br />Target victim <b>website</b>: <i>www.industrialchemicals.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tibbetts-Lumber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26163</link>
<guid>9d50bcc2d13c9160fcf2a3fd160252a6</guid>
<pubDate>Wed, 08 Oct 2025 16:14:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Tibbetts-Lumber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6dae245b7c47ab67cf70b40475b36d8473e31c07aa220d5cc03bdc10d07bdbae</i><br /><br />Threat actor <b>description</b>: <i>Tibbetts Lumber Co. is a leading provider of construction materials in Florida and the Caribbean, offering a wide range of residential building products including lumber, trusses, and millwork. Established in 1949, the company prides itself on delivering high-quality products at reasonable prices while fostering a family-centric work culture. Their services cater primarily to residential builders, providing manufactured trusses, installed trim, windows, and siding for new construction and remodeling projects. With a commitment to excellence and integrity, Tibbetts Lumber aims to serve its customers while honoring its legacy.</i><br />Target victim <b>website</b>: <i>www.tibbettslumber.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dakota-Boys-and-Girls-Ranch</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26164</link>
<guid>e91cc44798f02debded730aaf2453fe5</guid>
<pubDate>Wed, 08 Oct 2025 16:13:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Dakota-Boys-and-Girls-Ranch</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1c9448cc0764493c1853a97c1d7a61792137140c059167b20e5b17bcdf1efde</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1952, Dakota Boys and Girls Ranch is a Christian residential treatment and educational center for children and their families. The company is headquartered in Minot, North Dakota.</i><br />Target victim <b>website</b>: <i>www.dakotaranch.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lashbrook</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26165</link>
<guid>df934f579f2cfbd5eadc33af86b60a6c</guid>
<pubDate>Wed, 08 Oct 2025 16:13:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Lashbrook</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7481bcd29637a5306f245ac490036c512bee21f9bba1f46ee05f46954f3c6fd1</i><br /><br />Threat actor <b>description</b>: <i>Lashbrook started with just a handful of styles that were finished in our founder Eric’s garage. Eric named the company after his great, great grandfather, an immigrant who was among the first western settlers. We honor his pioneering spirit today as we innovate and have grown to offer nearly infinite options for personalization. Throughout our growth, we've remained dedicated to handcrafting our products in Utah.</i><br />Target victim <b>website</b>: <i>www.lashbrook.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bohlsen-Restaurant-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26166</link>
<guid>ebc33d3cfa0dc5d199f58077fbd1de28</guid>
<pubDate>Wed, 08 Oct 2025 16:13:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bohlsen-Restaurant-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3203ffc2671995454837e1771cbc88c890f15fa76ac314cd36ecd63eb856ed1b</i><br /><br />Threat actor <b>description</b>: <i>Bohlsen Restaurant Group is a family-based organization. Michael and Kurt Bohlsen, third generation restaurateurs, uphold the family tradition of mixing the essential ingredients to any successful restaurant enterprise - service, style and cuisine. By focusing on quality, we hope to inspire today's discerning diners and generations of future diners at a Bohlsen Restaurant. We believe that you should have a great dining experience and have fun along the way. We have a strong sense of community, and we aim to enrich the lives of both those who choose to dine with us as well as our valued and loyal staff. </i><br />Target victim <b>website</b>: <i>www.bohlsenrestaurantgroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Desert-Plastering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26167</link>
<guid>944ba20ccf432f83a48b0879149ea2d1</guid>
<pubDate>Wed, 08 Oct 2025 16:12:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Desert-Plastering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce12f3c66206a87d8ea5611cbbafc3e4e8ba59faaec79e789ba3a401ad04f517</i><br /><br />Threat actor <b>description</b>: <i>With over 35 years of working experience in Lath and Stucco, Desert Plastering was founded in 1998 by Manuel and Javier Rodriguez. In January, 1999 Desert Plastering, LLC was officially established. To date, both principals are actively involved with the day-to-day management of all projects to bring forth the utmost quality, durability and dependability of our products & services. Customer Service and Satisfaction is our primary goal and we take pride in all the jobs and projects that we do. Diligently taking care of issues before they escalate into major problems. With a wonderful group of team players and highly qualified personnel, Desert Plastering has grown at a steady pace and we look forward to future growth with all Builders at the same rate. </i><br />Target victim <b>website</b>: <i>www.desertplastering.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Osland-Financial-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26155</link>
<guid>6bea12680b6672c5427a4413d7fbbed0</guid>
<pubDate>Wed, 08 Oct 2025 15:21:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Osland-Financial-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>993621ec3039e95a4f3377cf39818ccffee85d8bfa8f07cd84cfbe38f1f96716</i><br /><br />Threat actor <b>description</b>: <i>Osland Financial Group specializes in simplifying financial planning to help clients navigate investment, risk management, retirement preparation, and wealth preservation. They offer a range of services including annuities, long-term care insurance, life insurance, and disability income insurance. The company aims to establish long-term, trusted relationships by providing essential information for achieving financial objectives. Their intended clientele includes individuals seeking financial security and proactive asset protection.</i><br />Target victim <b>website</b>: <i>www.oslandfinancialgroup.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Catherine-of-Siena</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26156</link>
<guid>ccd9cd148bbec8a9c3bfea662aef81ce</guid>
<pubDate>Wed, 08 Oct 2025 15:21:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>St-Catherine-of-Siena</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e074e34baf1432219cfcb36cc117b039c713cbfb1c8b2e1683d890fb6fcdd1f</i><br /><br />Threat actor <b>description</b>: <i>Catholic community of St. Catherine of Siena, commit ourselves to live out Christ's great commandments to love God and to love our neighbor as ourselves.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>JB-Brown--Sons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26160</link>
<guid>32d7f5dcce0010ba30b41ee9b36dbced</guid>
<pubDate>Wed, 08 Oct 2025 15:20:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>JB-Brown--Sons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be1d04fa4f68fcf31436262199f4c0443696dbd3e0e4c8036e56071a55762e16</i><br /><br />Threat actor <b>description</b>: <i>J.B. Brown Sons is a commercial property management and development company based in Portland, Maine, with over 200 years of experience in real estate. The company specializes in owning, leasing, and managing a variety of commercial properties, including office, warehouse, manufacturing, retail, and mixed-use buildings. Aimed at long-term stable growth, J.B. Brown Sons offers responsive services to assist tenants with their commercial space needs. Their portfolio of properties and development projects reflects their deep-rooted presence in the Greater Portland area.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>DataStream-Content-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26147</link>
<guid>b5839f3b37f86762f4e300e32db051ea</guid>
<pubDate>Wed, 08 Oct 2025 12:39:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DataStream-Content-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>23d173c95a0fa5a783d9a9baaa840ecc507a849b58135061a8749e28d8e97215</i><br /><br />Threat actor <b>description</b>: <i>As the premier content concierge, DataStream Content Solutions pr
ovides comprehensive information management solutions that allows
you harness the power of data. 

We are ready to upload corporate documents. Customer files, proje
ct information and other files. Be careful when working with them
because they allow everyone to access your data.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chapter-13-Texas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26149</link>
<guid>c8819aac10c0706b7466f78bd9854da0</guid>
<pubDate>Wed, 08 Oct 2025 11:49:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Chapter-13-Texas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c36bc18b0868f290ac38b14d7de11c32af225ade4501cd4b3f2f4892ba6e1ad7</i><br /><br />Threat actor <b>description</b>: <i>We have over 150GB of private data, ranging from employee data to customer and partner data. The management of planoch13.com has completely ignored us. You have 24 hours before we publish.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cerenade</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26148</link>
<guid>3b716043fd8fff8812df0a90a592958c</guid>
<pubDate>Wed, 08 Oct 2025 11:44:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cerenade</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a41040a30193ae20058bfb27563e8f0af08e80602947df3d87036a72689dd56d</i><br /><br />Threat actor <b>description</b>: <i>Cerenade Technology is a leader in providing cloud-based solution
s for immigration law firms, offering products such as eIMMIGRATI
ON, eCMS, and eForms Solutions. Their software aims to automate w
orkflows, manage cases and clients, and ensure compliance for leg
al and government organizations.

This is a very special case. We obtained almost 100gb of their cl
ients scanned documents (passports and visas). Thousands of adult
s and kids are going to suffer because of this leak. We got docum
ents of people from India, USA, Mexico, Middle East countries, Ja
pan and other countries around the globe. It appears that Cerenad
e's software automates personal fraud schemes.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Linxx-Global-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26146</link>
<guid>b9648e4dc6a5ad47bea0c9023e810dfd</guid>
<pubDate>Wed, 08 Oct 2025 11:17:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Linxx-Global-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afa8d81619ce63ccc374b7b09d4454f851d1e78ecfddf7e133adb0d18fc67b8d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Linxx Global Solutions is a U.S. based company that provides training and operational support services for the defense sector. Their offerings include security and defense training, protective services, intelligence, and maritime solutions. Linxx works in partnership with the federal government and military, and is particularly specialized in counter-terrorism and law enforcement training.</i><br />Target victim <b>website</b>: <i>linxxglobal.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charter-Industrial-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26142</link>
<guid>ae9950b87ffc3b372739ad468bb2a676</guid>
<pubDate>Wed, 08 Oct 2025 08:13:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sarcoma</b> claims attack for <b>Charter-Industrial-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54e8ecd2887a89d16fb74eb7b8a0163ca06e4496691ea34bd223eff1228b6e56</i><br /><br />Threat actor <b>description</b>: <i>Charter Industrial Supply
Charter Industrial Supply is a family-owned distributor specializing in industrial and hydraulic hose and fittings, serving diverse markets such as construction, military, and original equipment manufacturing (OEM). They offer a wide range of products including valves, fasteners, and pipe fittings, and are recognized for their reliable performance and extensive inventory management solutions. The company prides itself on maintaining a 100% fill rate and meeting the demanding needs of their clients, which include industry leaders and critical projects across various sectors. As a premier distributor, they have established partnerships with top manufacturers and provide quality-certified products in accordance with ISO and military specifications.Geo: USA - Leak size: 67 GB Archive - Contains: Files, SQL</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sarcoma</category>
</item>
<item xmlns:dc='ns:1'>
<title>ebaengineering.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26135</link>
<guid>fd7b8a148f3a229310f4170e8f4fa383</guid>
<pubDate>Tue, 07 Oct 2025 21:20:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>ebaengineering.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ad25928811707772c6b07d203b1b1d68067bc215ec3dbacb14540536009f1287</i><br /><br />Threat actor <b>description</b>: <i>EBA Engineering is a multidisciplinary engineering firm focused on providing exceptional, client-centered experiences with a commitment to delivering results. They offer a wide range of services including construction management, civil site engineering, geotechnical engineering, and asset management…</i><br />Target victim <b>website</b>: <i>www.ebaengineering.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.rocketstores.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26133</link>
<guid>a24904e5d3ed28eae9225fd787f64a71</guid>
<pubDate>Tue, 07 Oct 2025 19:51:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>www.rocketstores.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7a4dee87068c0d482d738b4aaa2a25028e3b4f20798d84abb4a6eff9e0685b3b</i><br /><br />Threat actor <b>description</b>: <i>$738.9 Million | Gas Stations, Convenience & Liquor Stores Retail</i><br />Target victim <b>website</b>: <i>www.rocketstores.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>indiesemi.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26134</link>
<guid>5b80dedf31c1b00d98e7f24c45cd3c1c</guid>
<pubDate>Tue, 07 Oct 2025 19:51:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>indiesemi.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>990994e66a4c57ca0379ef45668837f3fdee1102dfc29a6e9162c41b869e2f68</i><br /><br />Threat actor <b>description</b>: <i>indie offers highly innovative automotive semiconductors and software solutions for Advanced Driver Assistance Systems (ADAS), including LiDAR, connected car, user experience and electrification applications.</i><br />Target victim <b>website</b>: <i>www.indiesemi.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>California-Golf-Club-of-San-Francisco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26121</link>
<guid>f6556dfe948f58c57650fc8c13294030</guid>
<pubDate>Tue, 07 Oct 2025 17:27:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>California-Golf-Club-of-San-Francisco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a644d0c278a9474912c1027469c1d7099a0a35d7cb82c01978919763ae9a2007</i><br /><br />Threat actor <b>description</b>: <i>California Golf Club of San Francisco, commonly known as Cal Club, is a private golf club established in 1918, originally located in Ingleside before moving to its current 425-acre site in 1924. The club features a world-class golf course des            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Massachusetts-Bay-Community-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26123</link>
<guid>54b352116069f22a7b46fb2e2917732a</guid>
<pubDate>Tue, 07 Oct 2025 16:27:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Massachusetts-Bay-Community-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb8674180268fadd48b37697bb21a36d07c9cc4208349a26dcd940e9d05ed070</i><br /><br />Threat actor <b>description</b>: <i>Massachusetts Bay Community College is a comprehensive, open-access community college, offering associate degrees and certificate programs. 
We gave MassBay every opportunity to prevent this publication. We engaged their leadership. Their re            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>J-Lorber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26124</link>
<guid>cdaf0f49f125851ae975f4e3a063db52</guid>
<pubDate>Tue, 07 Oct 2025 16:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>J-Lorber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55b36d583813d7fb5500ebc5746570e5b0a5b208002b205f8965496b0e1c4c7c</i><br /><br />Threat actor <b>description</b>: <i>J. Lorber Company specializes in a wide range of plumbing, HVAC, and hydronics products, including water heaters, fixtures, and heating systems.We are going to upload 45gb of data soon. Personal documents of customers (DLs, addresses, credit card details and so on), employee information (names, DOB and other information), financial and accounting files, contracts, agreements, projects, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Harbor-Diesel--Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26125</link>
<guid>a21679f89da6d712ed6581b3cc5fc64d</guid>
<pubDate>Tue, 07 Oct 2025 16:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Harbor-Diesel--Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e87d9daa563c2a1de5503c48d13d27f1dd60d07cc069e44d535f92e8fba9a399</i><br /><br />Threat actor <b>description</b>: <i>Harbor Diesel and Equipment, Inc. primarily operates as the Southwestern Distributor of ZF Heavy Duty Off-Highway and On-Highway Driveline Products, the Southern California Dealer for Capacity ofTexas Trailer Jockeys and Factory Authorized Full-Service Dealerfor Cummins, Caterpillar (Truck and Marine), Detroit Diesel and John Deere Natural Gas On-Highway Engines. We are going to upload 7gb of data soon. Customers information, w9 forms, detailed employee information, detailed financial and accounting files, contracts, agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>archway.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26128</link>
<guid>d3416acbe6cd441c5fea6bf3a9816cd9</guid>
<pubDate>Tue, 07 Oct 2025 14:11:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>archway.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46d4eb19fddeaa4b2b91d99d73b5eecd150611726553c81a111f9ea23cdac3ca</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1952 and headquartered in Rogers, Minnesota, Archway is a provider of marketing logistics, fulfillment services, and supply chain management solutions.</i><br />Target victim <b>website</b>: <i>www.archway.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lautrec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26116</link>
<guid>356f7eed0a78a9c4802b42bed40c84d6</guid>
<pubDate>Tue, 07 Oct 2025 12:27:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Lautrec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1d7c71cc378ca7edc9dc69ca9c7be7c9b4cee7d711e7358a65a12d16dc7dbf2</i><br /><br />Threat actor <b>description</b>: <i>Lautrec is based out of the United States with an office operating in Alberta, Canada. Lautrec offers new and pre-owned manufactured homes, apartments, townhomes, and RV rental sites. Their communities offer swimming pools, sports facilities, and a community clubhouse.We are ready to upload more than 18GB of there data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports,driver's license, Social Security Numbers, birth certificates, emails, phones) confidential information and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clifford-Paper-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26110</link>
<guid>6100b117ea6245ad3383b299ad5f7ee1</guid>
<pubDate>Tue, 07 Oct 2025 00:27:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Clifford-Paper-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a67352404dabac81c09feb1c027d0bde030e6a0b1d22095236b65320b75bade</i><br /><br />Threat actor <b>description</b>: <i>Clifford Paper Inc, USA - is a family-owned business with a deep legacy in the forest products industry, operating since 1985. They specialize in providing paper products and value-added services. Clifford Paper maintains strong relationships            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Centers-Laboratory</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26108</link>
<guid>1b285431b6d97f0b3d25c629171a4448</guid>
<pubDate>Mon, 06 Oct 2025 22:27:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Centers-Laboratory</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ed7123e54f64f15e38b907dcffcfe3bd9bff8c94b564c7b1f5340be0c145b37</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>AES-Clean-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26115</link>
<guid>ada2552da65206d7f880ef928a65753e</guid>
<pubDate>Mon, 06 Oct 2025 21:20:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>AES-Clean-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0a65a80ba28d53401251acaffb79152646723952801bdc50132504f6ac75995</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.aesclean.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dataforth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26114</link>
<guid>f6370bef326f11083c0fc214d6d01d12</guid>
<pubDate>Mon, 06 Oct 2025 21:19:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Dataforth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>325bac87f8af8688ff269241e528d2543c89d290346c98717a92d2dde6e68617</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dataforth.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Development-Services-Group-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26105</link>
<guid>48d09449297662146572c38c68b7eb5e</guid>
<pubDate>Mon, 06 Oct 2025 20:27:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Development-Services-Group-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52eb5ffdf416c7878df41f00e16c037a6645a2c486946fdb3ed161c18ca96fea</i><br /><br />Threat actor <b>description</b>: <i>Development Services Group, Inc., USA -  The most high-profile terrorist attacks and crimes against the public that are being planned. All of this is contained in the reports of Development Services Group, Inc. You have to admit, it's interes            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.landmarkmgtinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26106</link>
<guid>f70576b9278d9a5c4814046749627269</guid>
<pubDate>Mon, 06 Oct 2025 20:27:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.landmarkmgtinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c0ada3c0d4837e4ae04434ae9d6c97e494a9df7a40b058682f33ebb9fce7b50d</i><br /><br />Threat actor <b>description</b>: <i>Landmark Management, Inc., manages 90 projects, consisting of 2,462 units across 5 states. Whether you are searching for an apartment to rent or a reliable company to manage your rural development property, let us put our thirty-six years of             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rogue-Valley-Door</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26111</link>
<guid>4ede9640e357f086a55ab84467f2bfe2</guid>
<pubDate>Mon, 06 Oct 2025 20:14:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Rogue-Valley-Door</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22a5d987cfe5191de5a145633fb8dd57822b0870320eb2bbaccfb39fdae34c44</i><br /><br />Threat actor <b>description</b>: <i>Rogue Valley Door specializes in manufacturing a wide range of high-quality doors, including decorative, urban, rustic, traditional, and specialty options. Their products cater to homeowners and professionals seeking to enhance entrance aesthetics and functionality. The company offers tools like a door builder and visualizer to help clients design their ideal doors. Additionally, they provide various resources and support for door installation, repair, and maintenance.</i><br />Target victim <b>website</b>: <i>www.roguevalleydoor.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Law-Offices-of-James-Scott-Farrin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26112</link>
<guid>6924d618d27cad63a1b3fca578c13e49</guid>
<pubDate>Mon, 06 Oct 2025 20:14:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Law-Offices-of-James-Scott-Farrin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1160bb6d0b4f3919a91a871a8a85ba41b3a020d7e96509c7b3a23dcc6c658d8e</i><br /><br />Threat actor <b>description</b>: <i>The James Scott Farrin Law Firm is a legal services firm that handles personal injury, medical malpractice, eminent domain cases, and more. The firm is based in Durham, North Carolina with additional offices based around North Carolina and South Carolina.</i><br />Target victim <b>website</b>: <i>www.farrin.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.nurturecare.comUSA192GB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26113</link>
<guid>e71dca519a9758e28dac9f1804b297cd</guid>
<pubDate>Mon, 06 Oct 2025 19:46:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>www.nurturecare.comUSA192GB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3c7674af7b6a205337aec325b2b24c33ed9a8430bd8a4db18315da4d52971f44</i><br /><br />Threat actor <b>description</b>: <i>Unknown - NurtureCare</i><br />Target victim <b>website</b>: <i>www.nurturecare.com/USA/192GB</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Milliman-Financial-Risk-Management-LLC-Milliman-Inc.-subsidiary</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26098</link>
<guid>1af1a2e1c891b3cb9fad0a57d927a492</guid>
<pubDate>Mon, 06 Oct 2025 19:27:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Milliman-Financial-Risk-Management-LLC-Milliman-Inc.-subsidiary</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b53543df19212252e4f2a36760c7b80e68efa7edcc6af2788f1b553c14e87433</i><br /><br />Threat actor <b>description</b>: <i>Milliman Financial Risk Management LLC is a global leader in financial risk management to the retirement savings industry. Established in 1998, the practice includes over 200 professionals operating from three trading platforms around the world (Chicago, London, and Sydney). Milliman FRM is a subsidiary of Milliman, Inc.We are going to upload 260gb of corporate data soon. Client information (clients' financial portfolios, account balances, transfers and so on), lots of internal operating files, financial and accounting files, contracts, agreements, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Daily-Printing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26099</link>
<guid>c6b674f5588228036011778df458d756</guid>
<pubDate>Mon, 06 Oct 2025 19:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Daily-Printing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6568c03edc0e79034b748ccb15fc28f0fd5e121f2ae3830ad5ba482a1d213c00</i><br /><br />Threat actor <b>description</b>: <i>Daily Printing provides commercial printing services, digital printing, variable data printing, web-to-print, and print on demand services.We are going to upload 32gb of data soon. Client information, a bit of employee files, lots of internal operating files, financialand accounting files, contracts, agreements, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Orion-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26100</link>
<guid>87ae9f68b3b1afa507a7bf4fd7e3144e</guid>
<pubDate>Mon, 06 Oct 2025 19:27:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Orion-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5744397637fdb2747ca37153bf012e3dc11ac0c69aec34069f7940d4699e865</i><br /><br />Threat actor <b>description</b>: <i>Daily Printing provides commercial printing services, digital printing, variable data printing, web-to-print, and print on demand services.We are going to upload 32gb of data soon. Internal confidential information containing client personal information (SSNs, address,email addresses and so on), employee information (w9 forms), financial and accounting files, contracts, agreements, clients' engineering specifications and drawings, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mecklenburg-County-Public-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26101</link>
<guid>ec69afac0d09f2914d811fa665d06e54</guid>
<pubDate>Mon, 06 Oct 2025 18:26:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mecklenburg-County-Public-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1174a98b09d9239fb4b7c656234f03522e01ffaa21e31312f6b017ec10a9c4b5</i><br /><br />Threat actor <b>description</b>: <i>Charlotte-Mecklenburg School District, USA - Do you keep your children's secrets? They are the most precious thing you have. They must not be betrayed. And that is exactly what the Charlotte-Mecklenburg School District (CMS) specializes in. T            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>mcgeorgeai.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26102</link>
<guid>4d951e4a84953a9cbd85cfcbede14509</guid>
<pubDate>Mon, 06 Oct 2025 18:26:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>mcgeorgeai.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>783aea3ba9c7e1b880b0f0698790916a7878ef48fc1a9de9cdad85bca42e35fd</i><br /><br />Threat actor <b>description</b>: <i>McGeorge Architecture Interiors (MAI), USA - свободный доступ в любой дом. MAI is a full service architecture and interior design firm specializing in corporate office, retail projects of all varying scopes and sizes,             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>kecymetals.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26097</link>
<guid>23c84f1d392d1453b7a1e380bd6acd0a</guid>
<pubDate>Mon, 06 Oct 2025 16:27:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>kecymetals.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>523b905b2fb1182e8b08c0c77bc7a5e33a58f8f4848ac487c4212019d01a9bd1</i><br /><br />Threat actor <b>description</b>: <i>Kecy Metal Technologies, USA - Terrible management, outdated equipment, uncompetitive salaries. This is how employees describe working conditions at Kecy Metal Technologies on condition of anonymity. The company was founded in 1988 in Michiga            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ludlow-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26095</link>
<guid>84648eaca6a7fc8394fbdb9cf07fd236</guid>
<pubDate>Mon, 06 Oct 2025 15:27:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ludlow-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7fc3b3b7ae483a012b03e846df7cc409992b410bf720ad715ee2da356516eba0</i><br /><br />Threat actor <b>description</b>: <i>Ludlow Construction Co. Inc. is a business specializing in underground infrastructure, roadway construction, and site development with over 25 years of experience. They offer services including road construction, sewer, water, storm utilities installation, site development, and curbing concrete.We are going to upload 205gb of corporate data soon. Detailed employee information (Names, DOB, DLs of almost all the employees, medical certificates, passports and other docs scans), financial and accounting files, correspondence with authorities, contracts, agreements, projects with specifications, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Natoli-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26093</link>
<guid>925cdef65f6a1d131fd8ca6c867c5c0a</guid>
<pubDate>Mon, 06 Oct 2025 13:27:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Natoli-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54b57de1e89094b5dda680a48e368db6b5f2d3981593025a9582ea53ce13602e</i><br /><br />Threat actor <b>description</b>: <i>Natoli Engineering is a renowned leader in tablet compression tooling with over fifty years of expertise in manufacturing high-quality punches and dies. They offer a range of products including tablet presses, encapsulation machines, and replacement parts, alldesigned to meet the needs of research and production in the pharmaceutical industry.We are ready to upload more than 936GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports,driver's license, Social Security Numbers,death/birth certificates, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpswww.libertydentaltown.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26089</link>
<guid>8c41eebf5a1f5867cbe38cf59b37c1bf</guid>
<pubDate>Mon, 06 Oct 2025 05:27:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>mydata</b> claims attack for <b>httpswww.libertydentaltown.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5faa91b71fe83091efaf7e67a63261c93b0bfec777f4d624add6b3b1732a7944</i><br /><br />Threat actor <b>description</b>: <i>Liberty Dental Care & Dentures provides general dentistry 7100 Sennet Pl, Suite E Liberty Township, Ohio 45069Around The Corner From Laser Web in Liberty Town Centerlibertydental007@gmail.com513-644-2086513-644-228958Gb data has been stolen</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>mydata</category>
</item>
<item xmlns:dc='ns:1'>
<title>WELLSLANDSCAPING.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26091</link>
<guid>91be0e18777ce6c751271fcc00d93d87</guid>
<pubDate>Mon, 06 Oct 2025 01:54:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>WELLSLANDSCAPING.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68a387dcbd3a6f1e0e858a5c2f6533894349bab580864cfe593d8d24fa89eb9a</i><br /><br />Threat actor <b>description</b>: <i>We provide a comprehensive array of services for both commerical and residential properties. In addition to traditional lawn and garden care we offer onsite consultation, landscape design, installation, and maintenance. Wells Landscaping is fully licensed and insured - just another way we show "You are important to us!" Employees: 25 Revenue: $$5 Million Industry: Architecture, Engineering & Design Phone Number:(781) 963-6017</i><br />Target victim <b>website</b>: <i>WELLSLANDSCAPING.COM</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Red-Hat-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26086</link>
<guid>faf73b21f308431fb3cf1c58d228eca2</guid>
<pubDate>Sun, 05 Oct 2025 19:21:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Red-Hat-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>858ea7b2f5ba65bf31fb300656ea164117170b6ac8cd3013778d2338ceff057e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Red Hat, Inc. is a leading American multinational software company that provides open-source software products to businesses. It became a subsidiary of IBM in 2019. The company is best known for Red Hat Enterprise Linux, a top-level operating system. Other notable offering includes its architecture service, cloud computing (virtualization), and storage solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>SP-Global-spglobal.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26083</link>
<guid>d2fb7247a8585505ca84d40afe37eea6</guid>
<pubDate>Sun, 05 Oct 2025 10:48:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>SP-Global-spglobal.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5440ad3a8968987b5c378a3513f726ef6c025bdf7faffb37630749e546f17dc</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] S&P Global is an American company that provides high-quality market intelligence in the form of credit ratings, analytics, data, and insights to help customers make informed decisions. It operates through four divisions: S&P Global Ratings, S&P Global Market Intelligence, S&P Dow Jones Indices, and S&P Global Platts, covering various sectors like energy, finance, commodities, and technology.</i><br />Target victim <b>website</b>: <i>spglobal.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>hillsidelibrary.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26080</link>
<guid>502bde293ec97ed8b6113eed820d2f62</guid>
<pubDate>Sun, 05 Oct 2025 07:19:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>hillsidelibrary.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5cb7b78a97ea128e61ee3861a572425484630682237ebbd240f9e454e517b007</i><br /><br />Threat actor <b>description</b>: <i>Hillside Public Library offers a number of options for patrons blind or visually impaired. Our Kurzweil software scans in any typewritten document and reads the document aloud to the patron. We also have 2 types of magnifiers. The first, the software-based Zoomtext, reads any computer-generated documents and files, including web/internet pages. Our other magnifier allows the user to increase the print size on documents and books. Employees: 25 Revenue: $5 Million Industry: Hospitality Phone Number:(973) 923-4413</i><br />Target victim <b>website</b>: <i>hillsidelibrary.org</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>stalkerradar.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26079</link>
<guid>97bed14a683cfd0065fd1a5613a1a205</guid>
<pubDate>Sun, 05 Oct 2025 05:21:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>stalkerradar.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7becc5bb512beefe8b230171beae461a8168da98088aea816c9ad629fa4ab94f</i><br /><br />Threat actor <b>description</b>: <i>Applied Concepts, Inc., d.b.a. Stalker Radar, was founded as a small contract engineering and manufacturing firm in 1975. Since that time, we have grown to be the United States premier manufacturer of police radar and Lidar in the United States. More state police agencies use our speed enforcement equipment than all other radar brands combined. Employees: 142 Revenue: $$25.3 Million Industry: Manufacturing Phone Number:(972) 398-3780</i><br />Target victim <b>website</b>: <i>stalkerradar.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>ocmaine.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26078</link>
<guid>e7aa803cb22f5aea99caa8c91fcf94e5</guid>
<pubDate>Sun, 05 Oct 2025 04:20:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>ocmaine.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a583122bf2cde3e45018d49c6aa1930e50ce79243c93565024a2bb3121f4579a</i><br /><br />Threat actor <b>description</b>: <i>Ouellet Construction is a family-led construction company specializing in commercial construction services in Southern Maine and the broader New England area. They are dedicated to delivering exceptional service through a collaborative and personalized approach that ensures projects remain on time and within budget. Their client base includes various sectors such as healthcare, manufacturing, non-profit, education, retail, and banking. With a focus on establishing enduring relationships, Ouellet Construction emphasizes integrity and consistency in all their projects. Employees: 25 Revenue: $5.3 Million Industry: Commercial & Residential Construction  Phone Number:(207) 725-0100</i><br />Target victim <b>website</b>: <i>ocmaine.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>uhlcompany.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26076</link>
<guid>1ee634c4211a128142ecef927787f0af</guid>
<pubDate>Sun, 05 Oct 2025 01:27:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>uhlcompany.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5da92b73e0998c9559b411169d281485d4833b962b8d6e72fa5450c41fffc4f2</i><br /><br />Threat actor <b>description</b>: <i>Imagine that the building where you live or work has gone haywire. You can't turn the lights on or off, the heating and air conditioning systems are out of order, and the video cameras have stopped focusing on the right areas. Do you think th            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Standard-Fiber</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26074</link>
<guid>762f942f9ebc76e485a774e4bea7f4de</guid>
<pubDate>Sat, 04 Oct 2025 16:39:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blackshrantac</b> claims attack for <b>Standard-Fiber</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>419800f22a8615f0c633789261846dc2b9502c038b70c29ad0dad7cd275c0083</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Standard Fiber is a global company specializing in designing and manufacturing bed and home textiles. They maintain key partnerships with manufacturers to provide products, such as bed sheets, comforters and pillows, to retail and hospitality industries. In addition to product development, it provides supply chain solutions and ensures quality control compliance. Established in 1998, Standard Fiber maintains offices in California, USA and Shanghai, China.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blackshrantac</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medstar-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26073</link>
<guid>0bdfa70fd4894b47e136ae023e2db7c2</guid>
<pubDate>Sat, 04 Oct 2025 16:18:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Medstar-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>432ab5d3a65a1a56f3aca49d4914c5c8bb1ddbd7866e164640e600ee138c4379</i><br /><br />Threat actor <b>description</b>: <i>Medstar Health</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Corban-OneSource</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26063</link>
<guid>002fdf1e30206e2b0289c5bdc7d5a369</guid>
<pubDate>Sat, 04 Oct 2025 02:26:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Corban-OneSource</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e06d44424ca9ae72e4c56f439e99ec3b24c7fd359ca5c7e76bf475e9f2d9b1f4</i><br /><br />Threat actor <b>description</b>: <i>Corban OneSource, USA - maximize risks to compliance. Company provides comprehensive HR outsourcing services, including payroll administration, employee benefits management, and HR support, aimed at reducing risks and improving organizational            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Western-Orthopaedics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26068</link>
<guid>5677daf23249cd3061fec263776483bb</guid>
<pubDate>Sat, 04 Oct 2025 01:49:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Western-Orthopaedics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f7f7bbdfa80835e83c3828d3e83c2757708c1af9dc6c95554f0b0d8cf9c27fe</i><br /><br />Threat actor <b>description</b>: <i>The orthopaedic surgery, musculoskeletal conditions, sports injuries and spinal conditions</i><br />Target victim <b>website</b>: <i>western-ortho.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Waterborne-Environmental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26067</link>
<guid>e1d55a1caf2d7b5c0c88fd76b8df2141</guid>
<pubDate>Fri, 03 Oct 2025 19:45:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Waterborne-Environmental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d42098c4e077ea9191fc636ce1f148b989278fbd053e1b769bf7ec5099a6e09f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.waterborne-env.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>DSA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26022</link>
<guid>e855c133ac38e1b4d136b6a4c12c4826</guid>
<pubDate>Fri, 03 Oct 2025 18:27:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>DSA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a9230b556f071d8518fa33e952c19132f3d560440f98c1f436ad1c051c35886</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1963, & based out of Pennsylvania, Data Systems Analysts is a company that provides information technology & consultingsolutions services with locations in Feasterville, PA, Aberdeen,MD, Tinton Falls, NJ, Fairfax, VA & McLean, VA.We are ready to upload more than 19GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, Social Security Numbers, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TransUnion</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26042</link>
<guid>6b8268b2aea8c743f066d9a8f5d056f6</guid>
<pubDate>Fri, 03 Oct 2025 15:53:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>TransUnion</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f505458845d102b6b0f752ec8618aaf8c896e09adf7234dc9463138c4d3fa4e</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TransUnion is a global credit reporting agency that provides credit information and analytics services to businesses and individual consumers. It collects and aggregates information on over a billion individual consumers in over thirty countries including "Big Three" credit-reporting agencies in the United States. The data they handle includes credit history, credit scoring, and personal information protection services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cisco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26053</link>
<guid>ec615d81761cddecefc011465ed6e3a2</guid>
<pubDate>Fri, 03 Oct 2025 15:52:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Cisco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71990ef4ea2f0d86d2fb0b232b5cd6172f14ff982551733176b2b78a24f25c65</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Cisco Systems, Inc. is a multinational company based in San Jose, California. It specializes in developing and selling networking hardware, high-technology services, and products. Founded in December 1984, it has been paving the way for digital innovation primarily in the IT industry. Much of the internet protocols and its infrastructure are driven by Cisco's technological advancements.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Google-Adsense</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26045</link>
<guid>c3236725cfb305098d9c19d3ed7b15b2</guid>
<pubDate>Fri, 03 Oct 2025 15:52:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Google-Adsense</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46d09b5718469c54991c20b0c36839cb16325c4293a4ee8460b41d3bfb93b3d2</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Google AdSense is a program run by Google through which website publishers in the Google Network of content sites serve text, image, video, or interactive media advertisements, that are targeted to site content and audience. These advertisements are administered, sorted, and maintained by Google, providing a revenue generating opportunity for publishers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>1-800Accountant</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26057</link>
<guid>df977c84b274de4bd67ed823cf61931e</guid>
<pubDate>Fri, 03 Oct 2025 15:51:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>1-800Accountant</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b71b51b358e3de5be1d86c1e19808162c34762b967379d46e78f5105c13a4269</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] 1-800Accountant is a nationwide virtual accounting firm merging the convenience of technology with proactive professional services to provide small businesses with tax, accounting and advisory services. They serve start-ups, small and medium-sized businesses across various industries. The services include tax preparation and planning, bookkeeping, payroll, entity formation, tax planning and audit defense. Their mission is to make accounting and taxes easy and affordable for individuals and small businesses.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saks-Fifth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26026</link>
<guid>b05b64b135c654deacc33cf7c4a8aeb5</guid>
<pubDate>Fri, 03 Oct 2025 15:51:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Saks-Fifth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>54087995fe77387c0d276070c618f558541da112a29a8b796f25544e307c6ffa</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Saks Fifth Avenue is a luxury retail store originating from the United States. It is renowned for its high-end offerings in clothing, shoes, handbags, jewelry, beauty products, and home goods. Founded in 1867, Saks has garnered global recognition with its flagship store located on Fifth Avenue, New York City. The company also operates numerous department and outlet stores across the United States and online platforms.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>CarMax</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26032</link>
<guid>bd4341b9f5d6bd9c55b3fde4b287bd50</guid>
<pubDate>Fri, 03 Oct 2025 15:50:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>CarMax</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cccb4a32f17c6a508901b580b852be59cb7d068d3117b38bfb2df9dbfe1e8e7f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] CarMax is a leading car dealership company in the United States that specializes in used cars. The company offers a unique car buying experience to its customers with its no-haggling and fair pricing model. In addition, CarMax also offers financing options and a wide range of car types, makes and models. They are renowned for their thorough inspections, warranties, and return policy.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>TripleA-aaa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26033</link>
<guid>a4b5a70ca8cf24d0eb4330748d1e72e5</guid>
<pubDate>Fri, 03 Oct 2025 15:50:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>TripleA-aaa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5bf17168307a6ca946ce5b1845787a79036260c54216e07873618d091bbd0c87</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] TripleA is a fintech company that aims to simplify cryptocurrency transactions. It provides a business-to-business platform for companies to accept Bitcoin and other cryptocurrency payments. Using blockchain technology, TripleA converts received cryptocurrencies into a local currency, mitigating exchange rate risks. It also supports cross-border transactions, enabling businesses globally to accept cryptocurrency payments from any country.</i><br />Target victim <b>website</b>: <i>aaa.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26024</link>
<guid>dc996ffddc4f1b64eda6c10cd08739fc</guid>
<pubDate>Fri, 03 Oct 2025 15:48:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Petco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83dc60dfd86def7661e907235b5df39bdd9e1fa3c09b213903e33d05fcc3083c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Petco is a leading pet specialty retailer in the US providing essential pet products and services. Founded in 1965, it offers a variety of pet food, supplies, and services such as grooming and dog training. Petco operates more than 1,500 locations across the US and Puerto Rico. Its goal is to improve the lives of pets, pet parents, and Petco employees.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Instacart</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26029</link>
<guid>16af635d9bcc11766919e03aebcb8cf8</guid>
<pubDate>Fri, 03 Oct 2025 15:47:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Instacart</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>053018325f3595e228a0349d1b383bdfe5823055d0173488771f0f456ea8497d</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Instacart is an American company that operates as a same-day grocery delivery and pick-up service in the U.S. and Canada. Customers shop for groceries through their mobile app or website from participating stores. The purchased items are delivered to customers' doorsteps by a personal shopper.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>HBO-Max</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26035</link>
<guid>d2669f6dd645e4881e07eb89a00afa98</guid>
<pubDate>Fri, 03 Oct 2025 15:47:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>HBO-Max</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c35c5f39506da0f9d76250d3c1daa174989ac30719d6e9cff78529b6698f6080</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] HBO Max is a premium streaming service offered by Home Box Office, Inc., a subsidiary of WarnerMedia Entertainment. Launched in 2020, it delivers a vast library of personalized content like original series, theatrical films, and specials directly to viewers. It combines HBO's content with shows, movies, and originals from Warner Bros., DC, CNN, TNT, TBS, and more.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Engie-Resources-Plymouth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26052</link>
<guid>c44bfdfa0357e84e7243173b7bdee5a9</guid>
<pubDate>Fri, 03 Oct 2025 15:46:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Engie-Resources-Plymouth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be85db09ddc1ba2813139165cee563e5520c227417a734f10e13c0b1d4cd83db</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Engie Resources (Plymouth) is one of the leading energy providers in the United States. The company operates from Plymouth, Massachusetts, and offers competitive electricity and gas plans for large and medium-sized businesses, local authorities, and institutions. As part of the global ENGIE group, it emphasizes renewable energy and sustainable business practices. From energy procurement to risk management and advising services, they provide comprehensive energy solutions.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Albertsons-Jewel-Osco-etc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26050</link>
<guid>115672407a04ac04cbe1a44c16ac4f26</guid>
<pubDate>Fri, 03 Oct 2025 15:46:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Albertsons-Jewel-Osco-etc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7ad4d7624528c7415b826e5dd6befc783c87aea968436320699303990823ad1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Albertsons Companies Inc. is one of the largest American grocery corporations, founded by Joe Albertson in 1939. It operates stores across 34 states under 20 well-known banners including Albertsons, Safeway, Vons, Jewel-Osco, Shaw’s, Acme, Tom Thumb, Randalls, United Supermarkets, Pavilions, Star Market, and Carrs. It remains a leader in the supermarket industry, offering grocery products, pharmacy services, and specialty food products.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Instructure.com---Canvas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26048</link>
<guid>28b666d0bbf15152aca966add171113d</guid>
<pubDate>Fri, 03 Oct 2025 15:46:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Instructure.com---Canvas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbfb00cac0faa59f9994ac310fd76c0e2e419d07b80801af084f3ae8b03bfd29</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Instructure Inc. is a technology company that developed the Canvas Learning Management System (LMS). Founded in 2008, Canvas is used by educators and students worldwide to connect and integrate digital learning resources into a school's curriculum. Upgraded features include assessment and reporting tools, plus customizable apps. They also offer Bridge, an employee development and engagement software for businesses.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>HMH-hmhco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26049</link>
<guid>60b4f063604e40c044bb1113825bc17a</guid>
<pubDate>Fri, 03 Oct 2025 15:45:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>HMH-hmhco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e7290171c4ff7b7959d226407739fd342c07e1ad296d06ff61efc5568f17d685</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] HMH, or Houghton Mifflin Harcourt, is a long-established publishing company specializing in educational content. They provide a variety of instructional technology, assessments, and other learning materials to schools in over 150 countries. The company also publishes a number of well-known trade and reference works, alongside children's books. Their goal is to foster a lifelong love of learning in every individual they serve.</i><br />Target victim <b>website</b>: <i>hmhco.com</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>GAP-INC.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26036</link>
<guid>93fb03efcd98ca5aa136ff9f761c9c2d</guid>
<pubDate>Fri, 03 Oct 2025 15:44:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>GAP-INC.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8983766420b48beaf337b9503cecbbfba58df6ff497f452842bf52c2da35f527</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] GAP, INC. is an American multinational clothing and accessories retailer. The company was founded in San Francisco, California by Donald Fisher and Doris F. Fisher in 1969. The company operates several well-known brands apart from Gap itself, including Banana Republic, Old Navy, Intermix, Hill City and Athleta. Known for its casual style, Gap is one of the largest apparel retailers in the world.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>KFC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26039</link>
<guid>3efe6c32370fb3b8bcba9451df36483a</guid>
<pubDate>Fri, 03 Oct 2025 15:43:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>KFC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>840f3c8a084cf9fc6ed4b91de2acfdbd870d4648ad98f0e76133d75bac7917e3</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] KFC (Kentucky Fried Chicken) is a world-renowned fast food restaurant chain known for its fried chicken. It was founded by Colonel Harland Sanders in 1952 in Kentucky, USA. The brand is now a subsidiary of Yum! Brands and operates over 23,000 outlets globally. KFC's secret recipe of "11 herbs and spices" is a distinctive feature of their products. The company also offers burgers, sides and drinks, among other items.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>McDonalds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26041</link>
<guid>2b74be52b8b68afdc9ba228f485c71bc</guid>
<pubDate>Fri, 03 Oct 2025 15:43:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>McDonalds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3f029cd2b31c7b091374ae8529fa0bd23231796648ab03d27c00a6011ac7252</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] McDonald's is a global fast-food chain, established in the USA in 1940 by Richard and Maurice McDonald. It is renowned for its hamburgers, french fries, breakfast items, soft drinks, and desserts. Primarily, the business model is based on franchising, operating over 38,700 restaurants in over 100 countries worldwide. The Golden Arches logo is globally recognized.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Walgreens</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26051</link>
<guid>56ac9c76e0abcb1c69c370705e45993f</guid>
<pubDate>Fri, 03 Oct 2025 15:42:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Walgreens</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0f14c0e60013f7e8e80d75cb4bdf887bc0e1c0ca68bf31a11461232acbd07ec6</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Walgreens is an American pharmaceutical retail company, established in 1901. It is one of the largest US drugstore chains, known for selling prescription and non-prescription drugs, health and wellness products, cosmetics, and groceries. It also offers health services like immunization and patient care clinics. Often, Walgreens operates 24/7 to allow customers access to their products and services at any hour.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Marriott</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26059</link>
<guid>41edce5cfc8f660a3c9a4c1d502d7bef</guid>
<pubDate>Fri, 03 Oct 2025 15:42:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Marriott</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9dcdf530f6f07271f6fa6fb6e2990f6f7bcc2630a3a69b7df0cf469405f2b581</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Marriott International is a renowned multinational hospitality company, headquartered in Maryland, USA. Founded in 1927, it operates a broad portfolio of hotels and related lodging facilities globally. Offerings include diverse properties from luxury to economy chain brands. As of today, Marriott has more than 7,000 properties in over 130 countries and territories, making it one of the world's largest hotel companies.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Home-Depot</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26062</link>
<guid>2f9fc227758c8375bfd10a1447c195cf</guid>
<pubDate>Fri, 03 Oct 2025 15:41:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Home-Depot</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e34232566e787b763c7d49b9e9c57aface03f581c32f7d26eda5c0989fcf1df</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Home Depot is the largest home improvement retailer in the United States. It is a one-stop-shop for tools, construction products, and various services. The company caters to do-it-yourself (DIY) customers, professional contractors, and the construction industry. It offers installation services and tool and equipment rental in addition to selling a litany of home improvement items.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>UPS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26061</link>
<guid>5c0321b6b78eecdfcf72e6a44222fef9</guid>
<pubDate>Fri, 03 Oct 2025 15:40:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>UPS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1cb8b825485f3e6d88de0cff10db07f59a3f3425d1de32fa07c85df91e5f2900</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] United Parcel Service (UPS) is an American multinational company that specializes in logistics, courier delivery services, and supply chain management solutions. Founded in 1907, it's headquartered in Atlanta, Georgia. With a global network, UPS delivers over 20 million packages daily to 220+ countries and territories worldwide. It also offers services like freight forwarding and supply chain designing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Republic-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26046</link>
<guid>d6623790e6c5ecbbd823c3bbd576cb3e</guid>
<pubDate>Fri, 03 Oct 2025 15:40:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>Republic-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ff008da9063d08a17c80d37079975dd74693b891768aa974939a854cd992cef</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Republic Services, Inc. is a leading firm in recycling and non-hazardous solid waste services in the United States. Founded in 1998 and based in Phoenix, Arizona, the company provides waste collection, transfer, evacuation, recycling, and landfill services. It serves commercial, industrial, municipal, and residential customers, catering to multiple sectors including housing, education, and healthcare.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>DisneyHulu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26030</link>
<guid>c6f32964ed71a81a16b0c3e047350c06</guid>
<pubDate>Fri, 03 Oct 2025 15:40:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>DisneyHulu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ade3d659f93863cfce0593aab7c6b3bacaeb2ec51abbcbc59d8bd65742b0b5fa</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Disney/Hulu refers to two separate entities, the Walt Disney Company and Hulu LLC. Walt Disney is a diversified multinational mass media and entertainment conglomerate, known for its film and TV production. Hulu, partially owned by Disney, is an American subscription video-on-demand service offering a variety of TV shows and movies.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>FedEx</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26060</link>
<guid>b7aee80335268a4c2bc6bc5ba337b4e1</guid>
<pubDate>Fri, 03 Oct 2025 15:39:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>shinyhunters</b> claims attack for <b>FedEx</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e0076234ae05504ce3c3b5dd3c5a27e5c474161a3d7112805305a0682a07827f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] FedEx Corporation is a multinational delivery services company headquartered in Memphis, Tennessee. Founded in 1971, it offers courier express, freight forwarding, logistics services globally. Along with these, FedEx provides e-commerce, packaging, shipping and business services. It pioneered a system for real-time tracking of packages which has now become an industry standard. With a fleet of cargo aircraft, FedEx is one of the world's largest airlines.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>shinyhunters</category>
</item>
<item xmlns:dc='ns:1'>
<title>Saint-Marys-Home</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26015</link>
<guid>0b606c5849811a2d8b92b8f4e6391fd7</guid>
<pubDate>Fri, 03 Oct 2025 13:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Saint-Marys-Home</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ce33786aa2b6dd4639b1d4983672d193f57de384c5e6f5460729208e744ddff</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sobotec</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26016</link>
<guid>6750b4fb30436bc1df7d0513eb0022e9</guid>
<pubDate>Fri, 03 Oct 2025 13:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sobotec</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e2288b5bffb6e14a2f145b28aafb79bf7834d7f80535b23e87a152d378e6b81</i><br /><br />Threat actor <b>description</b>: <i>Sobotec was founded in 1988 with a vision to produce the best modern wall panel systems available. That vision, coupled with a strong engineering background and a commitment to innovation, led Sobotec to become the first company worldwide to design and developa Rainscreen Wall Panel System (SL-2000) for the metal compositematerial (MCM) ALUCOBOND®. We are ready to upload more than 277GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, Social Security Numbers, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Milburn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26017</link>
<guid>7ea6925b773d2ab35403de093b290a17</guid>
<pubDate>Fri, 03 Oct 2025 13:27:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Milburn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>75e662a452da49d49823d14f1c7f0a37ed64f61c36ae5575f64a5d964e4436c0</i><br /><br />Threat actor <b>description</b>: <i>Milburn is a General Demolition contractor out of Chicago, Illinois. They deploy the latest in demolition technology and equipmentwith a fleet of Bobcat skid steers and Brokk remote demolition robots that can tackle everything from structural slab demolition to full interior strip-outs. We are ready to upload more than 16GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), (passports, driver's license, SSNs , emails, medical information, medical cards) Confidential information and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Field-and-Goldberg</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26018</link>
<guid>08648e60ac32d2c805ab6b0e0c174180</guid>
<pubDate>Fri, 03 Oct 2025 12:27:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Field-and-Goldberg</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db802ab0891bf6a5bbcffd23f63955ea779e07bc100c92c8bbd0e41286d1eef3</i><br /><br />Threat actor <b>description</b>: <i>Field and Goldberg, LLC is a  law firm located in Chicago specializing in real estate taxation, transactions, and litigation. The firm provides comprehensive legal services to a range of clients including condo associations, commercial properties, banks, and apartment buildings. We are ready to upload more than 232GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), project details, personal financial details of employees, accounting files. Confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TriMed-Inc.-Henry-Schein</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26008</link>
<guid>f4a6ed9b2695f62c1b2763fa0d56527d</guid>
<pubDate>Thu, 02 Oct 2025 21:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>TriMed-Inc.-Henry-Schein</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78ab5190fc70ffc5cc18d75d9e327f910054b987e838c543a8bb2f0e0956ae0c</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in Santa Clarita, California, TriMed is a leader in developing cre...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>sagchip.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26003</link>
<guid>804a372a28109de1050ce3c0738b1eb4</guid>
<pubDate>Thu, 02 Oct 2025 19:26:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>sagchip.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d4495d183d4e7b6c896ebb7abb4c29e205ee9f0a8dd50cacd0dc521a42e3be6a</i><br /><br />Threat actor <b>description</b>: <i>the Saginaw Chippewa Indian Tribe of Michigan, USA - It's impossible to keep a poker face now. This small community of about 3,000 people is located in Isabella County, near Mount Pleasant. The tribe owns gas stations, a water park, a hotel,             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mitchell-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26004</link>
<guid>12853ea82bcc01634317345a2175a51d</guid>
<pubDate>Thu, 02 Oct 2025 19:26:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mitchell-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19e4bd409819f01ad9063ad2e8d460603468162953fe7c2698eeddaeeb29e4c5</i><br /><br />Threat actor <b>description</b>: <i>Mitchell Industries, USA - like sand through one's fingers. The company manufactures Accu-Weld¢ wedge wire screens for applications in both the petroleum and refining industries. The family-owned company has been in business for many years a            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Xebec-Building</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26006</link>
<guid>c414093ef0e52a9437267acfcb481dbe</guid>
<pubDate>Thu, 02 Oct 2025 18:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Xebec-Building</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d34fa44288d33acac9355b3b5948ac2074553bb11853abc67604b0852215556f</i><br /><br />Threat actor <b>description</b>: <i>Xebec Building Company is a premier design build and general construction firm, providing services throughout the major Los Angeles and Southern California submarkets.We are going to upload corporate data soon. Detailed employee information (Name, DOB, DLs and other docs), financial and accounting files, clients and customers information, contracts and agreements, projects, lots of policies, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>wilsenergy.comUSA77.1GB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26010</link>
<guid>61cfeaeeca00302aed604bef641447a5</guid>
<pubDate>Thu, 02 Oct 2025 17:27:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>wilsenergy.comUSA77.1GB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>19bd50d3843a35207017d1ba3c00654a6daa5b25f33e5f010fff9d08cdd136f4</i><br /><br />Threat actor <b>description</b>: <i>Unknown - Wilsenergy</i><br />Target victim <b>website</b>: <i>wilsenergy.com/USA/77.1GB</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weber-Flavors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26007</link>
<guid>925a10591aef311718138363f040e391</guid>
<pubDate>Thu, 02 Oct 2025 16:41:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Weber-Flavors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8aee15f73eb75608637d843defab8e41f9ec5bce1030b31b5b8412bdffcfcb2d</i><br /><br />Threat actor <b>description</b>: <i>Weber Flavors is a family-owned company with over a century of experience in serving the food industry by providing thousands of flavors for various applications. They specialize in custom flavor creation, offering a diverse range of products including liquid flavors, powder flavors, vanilla, and organic flavors. Their intended clients are businesses within the food industry looking for tailored flavor solutions.</i><br />Target victim <b>website</b>: <i>www.weberflavors.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dual-Temp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25998</link>
<guid>2f3d5280b5160e984c5472b5110a74b1</guid>
<pubDate>Thu, 02 Oct 2025 15:27:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Dual-Temp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bf72ae1f38002e9f591e902db8ef0320050323fa02728a6d6ed014da59035e5c</i><br /><br />Threat actor <b>description</b>: <i>Dual Temp is a leader in mechanical engineering specializing in design, build and service of HVAC/R, Plumbing and Automated Building Control Systems in Eastern Pennsylvania.We are going to upload corporate data soon. Detailed employee information (DLs of more than 100 employees, photos and other employee files), detailed financials, information about customers, confidentiality agreements, projects, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Displayit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25999</link>
<guid>a17c8f64019807c6c53ea7fad557679b</guid>
<pubDate>Thu, 02 Oct 2025 14:27:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Displayit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d9fa0e7478e616e2fa2c84f8beab57fef233a25816c746cd799448e1808476d</i><br /><br />Threat actor <b>description</b>: <i>DisplayIt specializes in designing and fabricating custom displays, casework, and signage tailored for various industries including retail, healthcare, restaurants, and technology.We are going to upload 105gb of corporate data. Employee information, financials, clients confidential files, contracts and agreements, projects (lots of Starbucks project files), and of other data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apricorn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=26000</link>
<guid>63793ae8b9ddc409224f9ba13919d1b6</guid>
<pubDate>Thu, 02 Oct 2025 14:27:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Apricorn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d31b91eefbe2362c69fe5abd672c0e7d37f3225f68ade2b9851a7e030bad7921</i><br /><br />Threat actor <b>description</b>: <i>Apricorn provides secure storage innovations worldwide to companies and organizations seeking the ultimate protection for their data at rest.We are going to upload corporate data soon. Detailed employee information (lots of medical records, tests, EEGs, MRIs, CTs, SSN scans and other personal information), financials, information about clients, contracts and agreements, projects, NDA, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spectrum-Painting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25987</link>
<guid>cffb7924cc48c212e70437f8b32c5831</guid>
<pubDate>Thu, 02 Oct 2025 00:19:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Spectrum-Painting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0824d361c0adc142ac66ea956a91ed3521d7f21e38c2f3da9815c12ae2cdadb7</i><br /><br />Threat actor <b>description</b>: <i>Spectrum Painting NYC is a full-service painting company with over 100 years of combined experience, focusing on luxury high-rise buildings and commercial structures throughout the New York Tri-State area. They offer a variety of services including painting, wallcovering installation, plastering, and epoxy finishes. The company's management team ensures that all projects meet their high standards, leading to work with prestigious developers and builders across the nation. Spectrum Painting has built a reputation as a leader in commercial painting since its inception in 1996.</i><br />Target victim <b>website</b>: <i>www.spectrumpainting.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prince-William-Ice-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25988</link>
<guid>fecbb2b0283f5e5452813021a81585c3</guid>
<pubDate>Thu, 02 Oct 2025 00:19:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Prince-William-Ice-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0a4537d891bdeafacb40eb1f27f68c5a407693ff9fb773219aec36600bc9e727</i><br /><br />Threat actor <b>description</b>: <i>Prince William Ice Center provides Northern Virginia with a premier facility for all of your skating and hockey needs. We offer a full range of figure skating and ice hockey programs on our NHL and Olympic-sized rinks all year round. Our professional staff of ice hockey and figure skating instructors offer lessons for all ages and skill levels to assist our skaters and players to reach their optimum level of performance. Prince William Ice Center has a variety of public skating, Freestyle, and Stick & Shoot sessions scheduled through the week. Our full-service Pro Shop has professionally-trained skate sharpening technicians, and our Café offers snacks, meals, and catering for parties, business meetings, and team meetings.</i><br />Target victim <b>website</b>: <i>www.pwice.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>American-Association-on-Health-and-Disability</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25989</link>
<guid>834520f1cd753417e62225779928fe9e</guid>
<pubDate>Thu, 02 Oct 2025 00:18:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>American-Association-on-Health-and-Disability</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>326f9ecea920f1e9a021d4de20527b5fe8a13121c60aec16c67503970ce321a3</i><br /><br />Threat actor <b>description</b>: <i>The American Association on Health and Disability (AAHD) is focused on enhancing overall health for individuals with disabilities through health promotion and wellness initiatives. They engage in policy advocacy, research, and public health programs aimed at reducing health disparities and ensuring health equity for persons with disabilities. AAHD also disseminates information related to disability health and provides resources such as their peer-reviewed Disability Health Journal. Their intended clients include individuals with disabilities, healthcare professionals, researchers, and policy makers.</i><br />Target victim <b>website</b>: <i>www.aahd.us</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Judson-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25990</link>
<guid>5faade0d566fcec8b00f8d195be751aa</guid>
<pubDate>Thu, 02 Oct 2025 00:18:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Judson-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dd766d0382306ccd81102a07a863a43d8256a7abeef53f7b482b0159d9987330</i><br /><br />Threat actor <b>description</b>: <i>Judson Center, trusted by Michigan families for more than 97 years, is a non-profit human service agency that provides comprehensive services that strengthen children, adults and families impacted by abuse and neglect, autism, developmental, behavioral, and physical health challenges so they can achieve whole health, well-being, and maximum potential. Judson Center also offers integrated primary healthcare for all through Judson Center Family Health in Warren and is a Certified Community Behavioral Health Clinic (CCBHC). Since opening its doors in 1924, Judson Center has grown to change the lives of over 12,000 children, adults, and families each year. Judson Center has offices in Genesee, Macomb, Oakland, Washtenaw, and Wayne counties.</i><br />Target victim <b>website</b>: <i>www.judsoncenter.org</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Karat-by-Lollicup</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25991</link>
<guid>397fc000ce6f8e94df510c3ff5d86a61</guid>
<pubDate>Thu, 02 Oct 2025 00:18:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Karat-by-Lollicup</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d450d873515566e644ce566e43ac98663917ff1c2af9c336109356d41a2e721d</i><br /><br />Threat actor <b>description</b>: <i>Karat® by Lollicup is a rapidly-growing manufacturer and distributor of environmentally friendly, single-use disposable products, primarily used in restaurants and food service settings. The company supplies a wide range of products for national restaurant chains, as well as smaller, regional chains. Karats products include food packaging, containers, tableware, cups, lids, cutlery and straws. The company also provides additional environmentally friendly options to sustainably-conscious customers.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Immaculate-Heart-of-Mary</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25992</link>
<guid>1efc1b615012fad9d233b3f3ca069dd1</guid>
<pubDate>Thu, 02 Oct 2025 00:17:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Immaculate-Heart-of-Mary</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e84258a846d3bd10e09a83bd92290146d4e9cd8b1117d7723551981c4e75e0c9</i><br /><br />Threat actor <b>description</b>: <i>Immaculate Heart of Mary Home, associated with the Immaculate Heart of Mary Roman Catholic Church, has been serving the Brooklyn community since 1893 with a focus on faith and unity. The church offers various ministries including catechesis, consolation support, and food pantry services, aimed at meeting the spiritual and practical needs of its congregants. St. Joseph the Worker Catholic Academy is part of the community, providing education in a Catholic environment to students of all faiths. The organization prioritizes connecting with its members through live Mass services and updating them on important parish information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Johnson-Regional-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25993</link>
<guid>2a822afd087f6001d3a645686ff08389</guid>
<pubDate>Thu, 02 Oct 2025 00:17:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Johnson-Regional-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b48fcae293af9d79c12b0a54f343f06117aeb8159350092954b99ab9f8cf01a</i><br /><br />Threat actor <b>description</b>: <i>Johnson Regional Medical Center has been a healthcare provider in Johnson, Logan, Franklin, and Pope counties since 1922, evolving from humble beginnings into a licensed facility with 90 beds. The center offers a wide range of medical services including outpatient therapy, orthopedics, emergency care, and various specialty clinics. Their commitment to quality care aims to serve local patients and visitors effectively. They also engage in community events and support initiatives such as blood drives and health education classes.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Integrity-Wealth-Consulting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25996</link>
<guid>97ea23024b2ad96252af3583dce92d5f</guid>
<pubDate>Thu, 02 Oct 2025 00:14:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Integrity-Wealth-Consulting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a112712e37d4a61ee76157014164cdcc272326fc264b76f1fcf3312e82bf0e5</i><br /><br />Threat actor <b>description</b>: <i>IWC Schaffhausen, founded in 1868 and headquartered in New York, New York, is a luxury Swiss watch manufacturer. IWC has been a subsidiary of the Swiss Richemont Group since 2000.</i><br />Target victim <b>website</b>: <i>www.integritywealthconsulting.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>suntreeinternalmedicine.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25984</link>
<guid>a77520dcdffad519983fef3884d172e1</guid>
<pubDate>Wed, 01 Oct 2025 21:53:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>suntreeinternalmedicine.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57826fb0e0636889d96867c438bc2ca12070c869a27a0862188acaa447e71883</i><br /><br />Threat actor <b>description</b>: <i>Suntree Internal Medicine is a medical center located in the Suntree neighborhood of Melbourne, FL, offering a wide range of healthcare services including preventive care, diagnostic testing, and weight reduction programs. They emphasize personalized, compassionate care and aim to provide swift and efficient visits while maintaining a focus on patient comfort and wellbeing. The center is open seven days a week and provides same-day appointments for convenient access to healthcare. They also offer free in-house antibiotics to expedite recovery for their patients</i><br />Target victim <b>website</b>: <i>suntreeinternalmedicine.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Watsonville-Community-Hospital</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25980</link>
<guid>7af30e45ae2c3b194ef8e9a9162811d2</guid>
<pubDate>Wed, 01 Oct 2025 21:15:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Watsonville-Community-Hospital</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>545391b1f2bb48fa4220f41f614f6c89e3babe31fa6c4a3741dc46054be38b44</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1895, Watsonville Community Hospital is a 106-bed, acute care facility accredited by The Joint Commission. In addition to the emergency department that serves as an advanced life support base station for Santa Cruz County, the hospital offers a comprehensive portfolio of medical and surgical services, including a full service Wound Treatment Center. The physicians and staff at Watsonville Community Hospital strive to exceed patient expectations, while delivering compassionate, quality care.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mitrani-Rynor-Adamsky--Toland</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25973</link>
<guid>c66e591693fd6e7b26fc5a60efb68817</guid>
<pubDate>Wed, 01 Oct 2025 20:26:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mitrani-Rynor-Adamsky--Toland</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>39a32a124076d34e576874ac10044c3c11f179db867fad48473d3e31791bfb7f</i><br /><br />Threat actor <b>description</b>: <i>The company has failed to contact us.

Full file directory: http://securo45z554mw7rgrt7wcgv5eenj2xmxyrsdj3fcjsvindu63s4bsid.onion/data/12/

-- Files of interest --

Trial list including discovery and perso            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Green-Labs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25983</link>
<guid>f20fc1528a7cf30c9d94068b6e65a20e</guid>
<pubDate>Wed, 01 Oct 2025 20:18:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-Green-Labs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e724558646f06854f169b5e8af91dadd4097fa83b75e503a523e2e5cbb2dc1d4</i><br /><br />Threat actor <b>description</b>: <i>The Green Labs LLC specializes in supplying bulk raw materials of organic functional foods and nutraceutical ingredients aimed at diverse industries including food, pharmaceuticals, and cosmeceuticals. They offer a wide range of innovative products such as superfoods, proteins, and extracts from reliable sources, focusing on quality and compliance. Their clientele consists of marketing companies, contract manufacturers, and private labelers, emphasizing long-term relationships and exceptional service. The company is committed to supporting consumers' transition to healthier lifestyles by providing high-quality organic certified raw materials.</i><br />Target victim <b>website</b>: <i>www.thegreenlabs.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Calsoft-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25982</link>
<guid>2d1cf69466793ffabe159495a3c28825</guid>
<pubDate>Wed, 01 Oct 2025 20:16:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Calsoft-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>10d74e508bbc5ecc2e868a50f93b2b4f81fdc8b87f0216561e6ab0ef037b9ba4</i><br /><br />Threat actor <b>description</b>: <i>For over two decades, Calsoft Systems has been a leading provider of business technology solutions, specializing in ERP systems implementation for Microsoft Dynamics GP, Microsoft Dynamics NAV, Microsoft Dynamics AX, and Microsoft Dynamics 365. As a Microsoft Gold Certified partner and award winner, Calsoft excels in multi-site ERP implementations, tailored customizations, comprehensive IT support services, and boutique customer service. Our expertise in the distribution, logistics, manufacturing and travel industries enable our clients to leverage an enterprise system to its fullest potential.</i><br />Target victim <b>website</b>: <i>www.calsoftsystems.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barr-and-Barr</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25969</link>
<guid>c89cef51792c2c4420221ba3964e5165</guid>
<pubDate>Wed, 01 Oct 2025 17:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Barr-and-Barr</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79cca66ea66b9b9ef80583ced5b080a4df0fb3f7527b94d8dedbe161e94dc8af</i><br /><br />Threat actor <b>description</b>: <i>Barr & Barr, Inc is a construction management company that provides building information modeling & construction management.We are going to upload 323gb of corporate data. Employee detailedinformation (name, address, DOB, phones, scanned passports, DLs,death reports and so on), financials, clients information, contracts and agreements, projects, and of other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Plainview-Volunteer-FD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25977</link>
<guid>eb95e630acb84f9cff9abfc310349381</guid>
<pubDate>Wed, 01 Oct 2025 17:16:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>The-Plainview-Volunteer-FD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66950a34b5319c0c6d76011ee8fabcf706a2677e7473e3d29d343eae9eb42c2e</i><br /><br />Threat actor <b>description</b>: <i>The Plainview Volunteer Fire Department provides fire protection and emergency services to the communities of Plainview, Old Bethpage, and parts of Woodbury, responding to approximately 2,200 emergencies annually. It operates three stations staffed by volunteer members and offers programs for Junior and Cadet Firefighters.</i><br />Target victim <b>website</b>: <i>plainviewfd.org</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dimensional-Control-Systems-3dcs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25974</link>
<guid>7a9caff9ca745d67b4115660429d3bf3</guid>
<pubDate>Wed, 01 Oct 2025 15:46:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>Dimensional-Control-Systems-3dcs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>766424259dfb972820275b0dd2c237a299f931982a096166e8cd12e5f2933ebf</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Dimensional Control Systems (DCS) is a company specializing in quality management and engineering services. They provide solutions to analyze and predict the impact of variation on product assembly and performance. Their software tools, like the 3DCS variation analyst, assist industries such as automotive, aerospace, medical devices, electronics, to enhance their product quality and manufacturing efficiency.</i><br />Target victim <b>website</b>: <i>3dcs.com</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>Keystone-Solutions-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25967</link>
<guid>56640a2494792805eaac82c499e97324</guid>
<pubDate>Wed, 01 Oct 2025 14:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Keystone-Solutions-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>deef91279a8b505af39eda5381f4243dca85eedbe527acb351ef986b25f114e7</i><br /><br />Threat actor <b>description</b>: <i>Keystone Solutions Group is a medical device contract manufacturer and product development company based in Kalamazoo, Michigan. They provide a range of services including assembly, kitting, packaging, sterilization management, and clean room environments. Keystone specializes in managing customer product transfers and offers comprehensive solutions from prototypes to full-scale production. We are ready to upload more than 65GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, driver's license, Social Security Numbers,emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>DRL-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25972</link>
<guid>f2bb74a2c8f3ec7d16e2982467277e55</guid>
<pubDate>Wed, 01 Oct 2025 12:47:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>DRL-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cfcaad13c563648cc2f4c5c98572199fe274605a2ce2ec71ac86dd2e66395380</i><br /><br />Threat actor <b>description</b>: <i>Customer data leak</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>callhci.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25971</link>
<guid>e8568f57572bc50daf688754f4717ccc</guid>
<pubDate>Wed, 01 Oct 2025 11:45:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>callhci.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0de755d4e08c06369ec9dee88c8a765ecce57da62151838f7b073536f5038539</i><br /><br />Threat actor <b>description</b>: <i>Heritage Communications is a B2B telecommunications provider based in Little Rock, Arkansas, specializing in high-quality Cloud and On-Prem VoIP services from NEC. They serve businesses throughout Arkansas and West Tennessee, offering scalable and customizable telecommunications solutions tailored to meet specific client needs. With over 30 years of industry experience, they prioritize customer experience and provide exceptional service and support. Their partnership with NEC enables them to deliver advanced technology and reliable communication solutions to their clients. Employees: 25 Revenue: $5.1 Million Industry: Cable & Satellite Phone Number:(501) 819-3100</i><br />Target victim <b>website</b>: <i>callhci.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>icc-nw.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25970</link>
<guid>9bfdc40ac4a69d961ab44de9268fd07d</guid>
<pubDate>Wed, 01 Oct 2025 11:44:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>icc-nw.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cefcaf59b2af9758d00728543457cc87b1511cb1ebd67010d447d5f692351529</i><br /><br />Threat actor <b>description</b>: <i>ICC NW specializes in manufacturing custom stainless steel tanks, mixers, and reactors tailored for the food processing, beverage, and pharmaceutical industries. Based in Canby, Oregon, the company boasts a state-of-the-art 50,000 square foot facility that is capable of producing tanks of substantial size and according to various industrial standards. Their product lineup includes various innovative vessels such as smart mix tanks and computerized processing controls, along with patented components like the Sanifoil impeller and Sanibearing steady bearing. ICC NW also provides engineering and automation services, including installation and retrofitting, making them a comprehensive partner for industries in need of efficient processing solutions. Employees: 74 Revenue: $8.2 Million Industry: Industrial Machinery Phone Number:(503) 912-2727</i><br />Target victim <b>website</b>: <i>icc-nw.net</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cholakyan-Chiropractic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25968</link>
<guid>2ece43ae64a6d8da7b88b71be40f7b13</guid>
<pubDate>Wed, 01 Oct 2025 10:49:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Cholakyan-Chiropractic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c46199dc91df4302f3b7f9e6c8ed26a5c40d3bf2fc364b70ddd98d1739a5c7c</i><br /><br />Threat actor <b>description</b>: <i>Here at Cholakyan Chiropractic we have built chiropractic offices, which are very well equipped with state of the art physiotherapy modalities, chiropractic tables, traction units, a high frequency Digital X-ray machine and rehab/therapeutic exercise equipment. In combination with a well trained staff of Chiropractors and Chiropractic Assistants we give each patient a personalized treatment plan and regimen to ensure that we get the best possible results for our patients.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>LAMMCO.NET</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25965</link>
<guid>51fe2fba6faea9b92809477e2fe80b4c</guid>
<pubDate>Wed, 01 Oct 2025 06:53:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>LAMMCO.NET</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3a8426290dc3521bb6568d503889071ef21954bf27778eace3a5515af5c89d6</i><br /><br />Threat actor <b>description</b>: <i>LAMMCO specializes in industrial furniture and construction specialties. The company focuses on providing high-quality products tailored for various industrial applications. Their intended clients include businesses in need of durable and functional furniture solutions. LAMMCO aims to meet the demands of the construction industry with innovative offerings. Employees: 25 Revenue: $5 Million Industry: Retail Phone Number:(765) 447-7400 CFO: Michael Smith</i><br />Target victim <b>website</b>: <i>LAMMCO.NET</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Smiles-By-Steedman</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25964</link>
<guid>8d6e401410acccfbd1e77b322cfb6e88</guid>
<pubDate>Wed, 01 Oct 2025 06:21:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Smiles-By-Steedman</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec56f036b2fa58a9aeb1d28a07e37706c6cde92b8db99b4ac9101b7944059c26</i><br /><br />Threat actor <b>description</b>: <i>Smiles By Steedman, a family and general dentistry practice in Lake Stevens, Washington! We are dedicated to providing you and your family with the personalized, affordable and comfortable care that you deserve. Through every step of the dental process, we will work and consult with you to ensure that you achieve a healthier oral state in your timeframe and on your budget.- Patients' personal information- documents and medical histories- Company network database- Financial documents- Other information etc.  https://www.smilesbysteedman.com/</i><br />Target victim <b>website</b>: <i>www.smilesbysteedman.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenville-Legal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25956</link>
<guid>14b1943788292919ae987f02167d2243</guid>
<pubDate>Tue, 30 Sep 2025 22:27:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Greenville-Legal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>569c32809fdb80baaa1e2c9e95cdaed9964791d0147ae2b6398d0819d529b744</i><br /><br />Threat actor <b>description</b>: <i>David R. Price, Jr., P.A. is a personal injury law firm based in Greenville, South Carolina, specializing in a wide range of legal matters including auto accide...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rectory-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25950</link>
<guid>ca8a2575f96034775c7dc00162fcc27f</guid>
<pubDate>Tue, 30 Sep 2025 19:59:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rectory-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a59ed77b30ed209202769c66de31ca628234aa45ad9f00182f7bdcdc6e82bbaa</i><br /><br />Threat actor <b>description</b>: <i>Rectory School, USA - What began as a charitable educational project has, turned into a money-making machine for children. The school, founded by Reverend Frank H. Bigelow in 1920, is now far removed from its philanthropic ideals. Sending you            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cascade-Pacific-Pulp</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25953</link>
<guid>c8632be6d99d932350491c9fa87159d7</guid>
<pubDate>Tue, 30 Sep 2025 18:28:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Cascade-Pacific-Pulp</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a95792a8619274eab60f9d694187ab191ebe56381c3ff035ef3851a768ee1d51</i><br /><br />Threat actor <b>description</b>: <i>Cascade Pacific PulpCascade Pacific Pulp LLC is a leading market pulp mill located inthe Pacific Northwest, known for its environmentally progressivepractices. The company produces 200,000 tons per year of high-grade pulp, including products like Oregon Gold and White Gold, which are used in various applications such as tissue and printing papers. We are ready to upload more than 146GB data. There are lots of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, driver's license, Social Security Numbers, death certificate, emails, phones) confidential information, NDAs and other documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Komar-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25957</link>
<guid>8039d1e6173bc70139d255a933d84a75</guid>
<pubDate>Tue, 30 Sep 2025 18:11:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Komar-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f99dfb6de436aaea7f59a7fda11d62d19beffc07a4a80db8b9c02bf4a54e92ca</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.komarindustries.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CCMC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25945</link>
<guid>10cf7332c3f7998555770c79032723c5</guid>
<pubDate>Tue, 30 Sep 2025 16:50:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>CCMC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b18f776e1bd5340963308010ca48aa50b491efa7790cafcc6f1cfd481498bff5</i><br /><br />Threat actor <b>description</b>: <i>CCMC, based in Scottsdale and founded in 1973, Arizona provides community association management services to residential communities, as well as association management for municipal districts, utility districts, commercial associations, and other entities. The company also provides pre-development consulting to developer clients across the country, including budget forecasting, community governance review, amenity planning, and lifestyle and communications development. company is headquartered in 8360 East Vía de Ventura #100, Scottsdale, AZ 85258, United States 738 Employees. The total amount of data leakage is 2.92 TB. </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Comcast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25946</link>
<guid>36a6cb7962364107dbd2aeee06d11814</guid>
<pubDate>Tue, 30 Sep 2025 16:50:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Comcast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>421d6d468551c473d4ffa9fc341f0e36df73acee360739b826987409d0a54c14</i><br /><br />Threat actor <b>description</b>: <i>Comcast Corporation operates as a media and technology company worldwide. It operates through Residential Connectivity & Platforms, Business Services Connectivity, Media, Studios, and Theme Parks segments. The Residential Connectivity & Platforms segment provides residential broadband and wireless connectivity services, residential and business video services, sky-branded entertainment television networks, and advertising. The Business Services Connectivity segment offers connectivity services for small business locations, which include broadband, wireline voice, and wireless services, as well as solutions for medium-sized customers and larger enterprises; and small business connectivity services in the United Kingdom. company is headquartered in Comcast Center 1701 John F. Kennedy Boulevard Philadelphia, PA 19103 United States. 182,000 Employees. The total amount of data leakage is 834.4 GB </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Organon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25947</link>
<guid>4a6aecb3942c1ab2641b83d0731a74b7</guid>
<pubDate>Tue, 30 Sep 2025 16:49:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Organon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>404747755311d70618ffa610b67f89ba59f5f30ea647ba1bed1311f6ead6d572</i><br /><br />Threat actor <b>description</b>: <i>Organon creates, manufactures and markets innovative prescription medicines that improve the health and quality of human life. Through a combination of innovation and business partnerships, Organon seeks to leverage each of its core therapeutic fields. company is headquartered in 30 Hudson Street, Jersey City, New Jersey 07302, USA. 10,000 Employees. The total amount of data leakage is 478.2 GB </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Insightin-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25948</link>
<guid>3824ab9a06b2d12d1221c7f79bd17da5</guid>
<pubDate>Tue, 30 Sep 2025 16:48:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Insightin-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ab636098436abd85551aec1465b703e3006f9d151743715180ade07e62815083</i><br /><br />Threat actor <b>description</b>: <i>Insightin Health helps healthcare payers eliminate data silos and deliver highly satisfying consumer-centric experiences. inGAGE our software as a service (Saas) platform is the industry leading solution for quickly creating a connected data ecosystem. Using artificial intelligence and machine learning techniques, inGAGE leverages the totality of the connected data, in real-time, to produce insights that drive Next Best Action (NBA) recommendations to solve pressing healthcare challenges. inGAGE allows healthcare payers to deliver lifetime member value, driving growth and increasing overall plan profitability. company is headquartered in 333 W Ostend St. Suite 100 Baltimore, MD 21230. 45 Employees. The total amount of data leakage is 378 GB
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>Priester-Aviation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25931</link>
<guid>e2625f6934c1cdc344a0f5b5ca3e1e37</guid>
<pubDate>Tue, 30 Sep 2025 13:51:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Priester-Aviation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>793fc76e3b7ec47831018772ace800c3881bcdcb3508af22496376e9a4eb36f7</i><br /><br />Threat actor <b>description</b>: <i>Priester Aviation is a leading provider of aircraft management and private jet charter services, based in Chicago, IL, and operating with nearly 200 years of combined experience in the industry.We are going to upload 124gb of corporate data. HUUUUUGE amount of employees (and their relatives) personal documents (passports, DLs and other docs with complete person information, medical testand other medical docs), crew personal documents, financials information, a bit of customer information, aircraft maintenance information, confidential contracts and agreements, numerous NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sinco</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25932</link>
<guid>d3cff5ee422bc11366792285cd0b6b93</guid>
<pubDate>Tue, 30 Sep 2025 13:51:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sinco</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>466749086ef88f57e5388f4688e9ad0599df786810a176a7e3576680cbe82a8f</i><br /><br />Threat actor <b>description</b>: <i>Sinco, Inc. is a certified company specializing in sheet metal fabrication, offering a range of services including profiling, forming, welding, machining, and powder coating.We are going to upload 13gb of corporate data. Employee and customers information, complaints, financials information, lots of agreements and contracts, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pawling</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25933</link>
<guid>610139afa33fd14569ca5713c1057fe1</guid>
<pubDate>Tue, 30 Sep 2025 13:51:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pawling</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>79f1b54270cc89287cda9e088b95261b559bc2a55cfc49eb9dee77ac5eea4ca0</i><br /><br />Threat actor <b>description</b>: <i>Pawling provides the following services: Architectural Products includes Impact Protection Systems Entrance Mats and Gratings Athletic Flooring Systems Heavy-Duty Impact Protection Systems Parking & Traffic Safety Products Presray includes Wateright Doors & Barriers Airtight Doors.We are going to upload 21gb corporate data. Detailed employee personal information (DOB, emails, titles, phones, addresses and so on), financials information, customer information, lots of agreements, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tom-Duffy-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25934</link>
<guid>89148408d209b6fc7dcc7ac44daf70aa</guid>
<pubDate>Tue, 30 Sep 2025 13:51:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Tom-Duffy-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4af65a6ec0d742c2448aa48f592fcf60d99a81ebbbddd593ddd575536ac7e69c</i><br /><br />Threat actor <b>description</b>: <i>Tom Duffy Company specializes in floor covering and supplies offering flooring installation, Ceramic Tile & Stone Setting, and floor heating systems.We are going to upload 7 gb of corporate data. Employee information (names, DOB, address, emails, phones), customers and partners information, financials, lots of agreements and contracts, NDAs etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Midwest-Industries-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25935</link>
<guid>3d7be5aea8e8c8c0224542aec2a732fa</guid>
<pubDate>Tue, 30 Sep 2025 13:51:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Midwest-Industries-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>febb2191a102b96fac547f8a7a8fa115d8f24eb1afe7959331e694910b4f90fe</i><br /><br />Threat actor <b>description</b>: <i>Midwest Industries, Inc. designs, manufactures, and markets boats. The Company offers small fishing boats, cruisers, specialty trailers, pontoons, deck boats, utility trailers, specialty water crafts, and on-water storage for boats.We are going to upload of corporate data. Full employee information (names, DOB, address, emails, phones, SSNs, passports, medicalinformation and so on), financials, agreements, internal confidential files and other HR files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sueba-USA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25938</link>
<guid>d2817e5b9188a8fac590cb6c263f2222</guid>
<pubDate>Tue, 30 Sep 2025 13:51:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sueba-USA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e6f54650878e1ec71c7b5708a3e4f0a992029e32bcfdd519ebeab461bf3290e3</i><br /><br />Threat actor <b>description</b>: <i>With over three decades of experience, a reputation for quality, and end-to-end expertise in developing luxury residential and commercial properties, SUEBA USA is an innovator in the real estate development market. We are going to upload 20gb of their corporate data. Lots of financial documents, detailed financials, clients documents, agreements, confidential files, projects, a bit of clients information, and of other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Von-Paris-Moving</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25939</link>
<guid>9f58ce25aeb1d1cf74703aeabda1b3a3</guid>
<pubDate>Tue, 30 Sep 2025 13:51:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Von-Paris-Moving</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3140da5ed5d7767fb53a6ca29622bb000eb1848e2e5dad31fe8a6d63d2d4ab78</i><br /><br />Threat actor <b>description</b>: <i>Von Paris Moving is a moving company that provides services in the moving and storage industry.We are going to upload corporate data. Employee detailed information (name, address, DOB, phones and so on), financials, clients documents, contracts and agreements, projects, and of other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Apex-CoVantage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25940</link>
<guid>170d889b454173db5ca041019ce726de</guid>
<pubDate>Tue, 30 Sep 2025 13:51:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Apex-CoVantage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fbd6b1e78c768be3ceec98a9afe7a622b278489ccf4951a19e0d4d9d4455a1d3</i><br /><br />Threat actor <b>description</b>: <i>Apex CoVantageThe company provides data conversion, prepress, content enhancement, and editorial services to publishers and both private and public libraries around the world.We are ready to upload more than 35GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, death certificate, emails, phones) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burke-Contracting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25941</link>
<guid>b2a3c1459a5e98694b1f8ce495a9906c</guid>
<pubDate>Tue, 30 Sep 2025 10:46:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Burke-Contracting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3e4374d0b0b9a76c9e778e1617388659888590e56ea5a2b59b80de11801a383</i><br /><br />Threat actor <b>description</b>: <i>Burke Contracting provides design-build, general construction, co
nstruction management and preconstruction consulting services.

We are going to upload 292gb of corporate data. Employees (includ
ing founders and upper management) personal information (w9 forms
with full names, DOB, address, emails, phones), financials and c
redit cards information, customers information, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MCBS-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25942</link>
<guid>68f24a4e5f0a836969e4d293fd2eec92</guid>
<pubDate>Tue, 30 Sep 2025 08:20:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>MCBS-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f8ddc695b340b7ee35d5f497ebefd05106c83d10ea4083e968640219f267cf9</i><br /><br />Threat actor <b>description</b>: <i>Provides a complete range of management services to healthcare providers</i><br />Target victim <b>website</b>: <i>mcbs.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>AZpro-Group-azprogroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25943</link>
<guid>be5dfeb671c12d7520445b9292e10d13</guid>
<pubDate>Tue, 30 Sep 2025 07:45:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>AZpro-Group-azprogroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0a974a76dda90663c1ad34f20cf2ecc10aadaf1bded32398cb7b23ce98ba69f</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] AZpro Group is a multi-faced company that specializes in graphic design, installation, and printing services. Based in Arizona, the company offers a diverse range of services such as vehicle graphics, custom interior graphics, exterior graphics, retail graphics, and large format printing. With its proven expertise, the company helps businesses enhance brand visibility through high-quality graphic solutions.</i><br />Target victim <b>website</b>: <i>azprogroup.com</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>Caresoft-Global-caresoftglobal.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25929</link>
<guid>0283ed0eee6998607137643223c4e475</guid>
<pubDate>Mon, 29 Sep 2025 20:42:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Caresoft-Global-caresoftglobal.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6089b971fe1fb5fc5895ab81c5b3c92a871503d4b85a385a5aaaf11630ebe94f</i><br /><br />Threat actor <b>description</b>: <i>Caresoft Global is a global engineering company specializing in solutions for the automotive, off-highway, agricultural, and construction equipment industries, as well as for Tier 1 suppliers.The company offers solutions in product development, cost optimization, manufacturing, and aftersales service.Caresoft Global is also a leader in automotive benchmarking, technology optimization, and cost reduction engineering strategies.Headquartered in the United States, the company has a strong global presence in Europe, Japan, China, India, and the UAE.Caresoft Global's clients include leading global automotive companies.All accounting records from 2021 to the present day and other documents are for sale.write to us for information:Qualitydatarecovery@mail.com</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>Petro-Diamond-petrodiamond.com---subsidiary-of-Mitsubishi-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25923</link>
<guid>656d366d457c77166c48c6b30a909702</guid>
<pubDate>Mon, 29 Sep 2025 15:43:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>Petro-Diamond-petrodiamond.com---subsidiary-of-Mitsubishi-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf1cde7e2c4c87130a03dc109da78db35cf44f9fc00a40d6a55dfe84cff9fb10</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Petro-Diamond is a commodity trading subsidiary of Mitsubishi Corporation. It's involved in the trade and marketing of petroleum and its derivatives, liquefied petroleum gas (LPG), and carbon-related materials. Also, they handle petrochemicals and participate in energy project developments.</i><br />Target victim <b>website</b>: <i>petrodiamond.com</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>Peavey-Electronics-Corporation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25924</link>
<guid>41d98b54063973ecbdcbe845ff38ff95</guid>
<pubDate>Mon, 29 Sep 2025 15:15:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Peavey-Electronics-Corporation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8dea6c4f634ccf76b886859d9ec02e953c571e724dace6720d62209001d381c6</i><br /><br />Threat actor <b>description</b>: <i>Peavey Electronics Corporation Founded by Hartley Peavey in 1965 as a one-man shop, today Peavey Electronics Corporation is one of the largest makers and suppliers of musical instruments, amplifiers and professional audio systems in the world-distributing more than 2,000 products to more than 130 countries.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>lakehaven.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25906</link>
<guid>3df9f63b70bff498764b4daa10ce8f6a</guid>
<pubDate>Mon, 29 Sep 2025 14:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>lakehaven.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b2d15ed2738adcfc66404556bc3dbe70924b4fac94320904987aeeddafe67a6</i><br /><br />Threat actor <b>description</b>: <i>Lakehaven Water District provides essential water and sewer services to residents of South King County, Washington.
1.The document dated January 3, 2025, is a report on GL Distribution for the pay period December 16–31, 2024 (payment on Ja            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>raimore.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25911</link>
<guid>24b482e0e7581adb4d2f9ec2a4abf347</guid>
<pubDate>Mon, 29 Sep 2025 13:45:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>raimore.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9525fe086116ddb32c82f56ed47f8beef5af2bc5114bf203287e8f3008eb8181</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>raimore.com</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>Virtual-Projects-virtualprojects.build</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25912</link>
<guid>88bccac4be340a681f5eff6d5cbde9d2</guid>
<pubDate>Mon, 29 Sep 2025 13:44:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>Virtual-Projects-virtualprojects.build</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>439eaab63979147d03e44c87c2fe68f0d1d10726c53898f0139e649d3f1932ce</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Virtual Projects is a construction-focused firm based in Northern California. They are dedicated to providing a comprehensive range of services including preconstruction, project estimating, and construction management. Their cutting-edge technology and experienced personnel allow them to offer virtual design and construction methodologies, assisting clients from concept through to completion.</i><br />Target victim <b>website</b>: <i>virtualprojects.build</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.braswellsvc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25919</link>
<guid>c5f5a733716c32cdc8da76f30827420d</guid>
<pubDate>Mon, 29 Sep 2025 13:36:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>www.braswellsvc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6121ab9c64d4ae3afef1cc1cba1695b37a7519f3b0f9e8ac0500491af7f8fe13</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 120000 USD | Note: 300gb exfiltrated</i><br />Target victim <b>website</b>: <i>www.braswellsvc.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.chicagobotanic.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25917</link>
<guid>5657a4a1f4bb5cc4b95d6e17b6ac6d62</guid>
<pubDate>Mon, 29 Sep 2025 13:34:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>www.chicagobotanic.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f4b24c282ef2641a7ac171ebf384ea44671161a39d5feeaabbfa10f0f8c003f</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 590000 USD</i><br />Target victim <b>website</b>: <i>www.chicagobotanic.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>r3consulting.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25916</link>
<guid>240771160420640663f944cc56c37018</guid>
<pubDate>Mon, 29 Sep 2025 13:33:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>r3consulting.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>591aa1ef35b66a7ae8531cbea285ea3f63a74e880327853c799d7aa18fab3994</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 350000 USD | Note: 400gb stollen</i><br />Target victim <b>website</b>: <i>r3consulting.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>ncgllc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25915</link>
<guid>629cfb1750e1aafd9fd8b37d5fa6e982</guid>
<pubDate>Mon, 29 Sep 2025 13:32:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>ncgllc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>092805d58d6b325423c70fed3581021aca29a6f026cde5db4264e1610e430b14</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 100000 USD</i><br />Target victim <b>website</b>: <i>ncgllc.com</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>sacada.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25913</link>
<guid>3276d012055292a66a29bc5aa5df12d7</guid>
<pubDate>Mon, 29 Sep 2025 13:31:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>sacada.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>12edece4c7f557f6f2598ec19b4fd099bdfcb4623b52f08f85fd8eb82e9bf58b</i><br /><br />Threat actor <b>description</b>: <i>Ransom: 100000 USD</i><br />Target victim <b>website</b>: <i>sacada.org</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>heparks.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25904</link>
<guid>b15780f320ec1c2819defb6d337eef1f</guid>
<pubDate>Mon, 29 Sep 2025 11:28:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>heparks.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d4db33c8a68f48208d2241cfca4aae5c9d7d69b55cf08e26feabed22e751c2b</i><br /><br />Threat actor <b>description</b>: <i>The Hoffman Estates Park District strives to provide the local community with exceptional recreational programs, well-maintained parks, and high-quality facilities. Their offerings include a variety of programs for youth, adults, and seniors,            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>MSB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25901</link>
<guid>2cf203516f33059cf320d8b7ec385328</guid>
<pubDate>Mon, 29 Sep 2025 07:27:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sarcoma</b> claims attack for <b>MSB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a6c8fc6b31f031ff3f32aec0fbab5a25f9ae5d5f26edcb84720cc0aa672aec72</i><br /><br />Threat actor <b>description</b>: <i>Site: msbuilders.com
														Industry: Commercial & Residential Construction
														GEO: USA</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sarcoma</category>
</item>
<item xmlns:dc='ns:1'>
<title>Naftali-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25902</link>
<guid>60a5a506e99d3b76a199c91aaf28c181</guid>
<pubDate>Mon, 29 Sep 2025 00:48:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Naftali-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8463d48e4d9862ee456966107c3dcfdf405cb4ac093ba7877c596c69bd895d64</i><br /><br />Threat actor <b>description</b>: <i>Naftali Group, a privately held global real estate development and investment firm based in New York City, has a prestigious track record, having led some of the most significant developments and landmark restorations. Founded and led by Miki Naftali, Naftali Group is highly specialized in identifying and acquiring undervalued properties in premier geographic areas with strong potential growth while maximizing the value of unique and irreplaceable assets. Naftali Group pursues strategic acquisitions and continuously grows its extensive portfolio of new development condominiums, income-producing, mixed-use properties and other assets. Through innovation and discipline, Naftali is recognized as a leading developer with a current and past portfolio comprised of more than 30 projects encompassing more than $9 billion in total value.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bignault--Carter</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25903</link>
<guid>06fcc10b4a95f17133ee992810735a01</guid>
<pubDate>Mon, 29 Sep 2025 00:48:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Bignault--Carter</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e88c400e3b47577e8e5f7b7f7cbb17d7613192e7bc934f544845cc2497b65f6c</i><br /><br />Threat actor <b>description</b>: <i>Bignault & Carters Savannah law practice is focused on the representation of Labor Unions and Pension, Vacation, and Health and Welfare Funds in and around Savannah Georgia</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-DM-Burr-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25898</link>
<guid>fc2ab5e9a8dd35473c8dc453a62962f7</guid>
<pubDate>Sun, 28 Sep 2025 22:48:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>The-DM-Burr-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3c6bb5c090159f3139402c53e3d7ad09db5779fddda6c7d2820b6c4ea54a047</i><br /><br />Threat actor <b>description</b>: <i>The DM Burr Group is a multifaceted company that has many divisions that are complementary to one another giving our customers the easiest way possible to bundle services together thus saving time and money at the same time. DM Burr was started in January of 1998 and has had extraordinary growth due to our ever present "the customer comes first" attitude. Cannot imagine a better group of managers and employees than the ones that work at DM Burr. DM Burr Mechanical- All phases of Heating, Cooling, Plumbing and Electrical installation, service and repair. Direct vendor of York and Lennox. DM Burr Disaster Restoration-Water.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Belleville-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25897</link>
<guid>dd1f345b360e81d1a63935eeae1ca462</guid>
<pubDate>Sun, 28 Sep 2025 21:57:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Belleville-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bbb9b36084130417ea7986df44fda2e429288ba715400edd30a12d456ee73c3e</i><br /><br />Threat actor <b>description</b>: <i>Belleville International specializes in precision load solutions, providing durable washers and disc springs designed for high-stress environments across various industries. Their product offerings include flange washers, valve components, and downhole drilling springs, all tailored to meet specific application needs. The company emphasizes customer-centric services, including 24/7 emergency support and quick turnaround on custom and stock products. With a commitment to quality and full traceability, Belleville International serves clients in sectors such as oil and gas drilling, valve manufacturing, aerospace, and automotive racing.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>WaltersMorgan-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25896</link>
<guid>af6e15cfa6c456895fd802a9d29ead74</guid>
<pubDate>Sun, 28 Sep 2025 21:56:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>WaltersMorgan-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c2246d1d93434ae45431c52c75d5b81adc8f038277ce9f45e8665682cb54bc00</i><br /><br />Threat actor <b>description</b>: <i>Walters-Morgan Construction, Inc. is a leading construction firm based in Manhattan, Kansas, specializing in the construction of water and wastewater treatment plants as well as other municipal utilities. Established in 1938, the company is dedicated to community success and environmental stewardship through quality engineering and construction services. They offer a wide range of career opportunities, promoting a positive work environment and benefits for employees of all skill levels. Their commitment to high-quality projects reflects their goal of ensuring community pride and satisfaction.</i><br />Target victim <b>website</b>: <i>www.waltersmorganconstruction.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Punctual-Abstract</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25892</link>
<guid>a06dfaedc1e4413666a940fb0e84fbd6</guid>
<pubDate>Sun, 28 Sep 2025 21:49:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Punctual-Abstract</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>236308192b1b421c8ff2b101ec0c5d444fcc20427d7f6cb3a74759577a65dc1d</i><br /><br />Threat actor <b>description</b>: <i>Punctual Abstract is a leading provider of abstracting services in the land title industry, boasting over 25 years of experience. The company utilizes advanced technology for national title production, delivering near-instant real estate property data returns across the United States. Their proprietary software integrates seamlessly with leading title and escrow platforms, allowing for efficient and accurate data management tailored to client needs. Punctual Abstract serves a variety of clients, including title agencies and underwriters, with extensive coverage and dedicated support.</i><br />Target victim <b>website</b>: <i>www.punctualabstract.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dorrell-Fabrics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25893</link>
<guid>303e5a77002b8f8acf84ef064760f23e</guid>
<pubDate>Sun, 28 Sep 2025 21:49:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Dorrell-Fabrics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1e641f7c67c1e9800ac731a38aa77c2ff1669e1b3af23fe44af10623a3109090</i><br /><br />Threat actor <b>description</b>: <i>Dorell Fabrics specializes in fabric sourcing and innovation, offering a wide array of products including residential, performance, contract, outdoor, and specialty fabrics. The company collaborates with designers, manufacturers, and suppliers to provide high-quality textiles tailored to meet specific needs. With nearly 88 years of experience, Dorell Fabrics is committed to operational excellence and trend forecasting in the textile industry. They aim to make the fabric sourcing process seamless for various clients across different sectors.</i><br />Target victim <b>website</b>: <i>www.dorrellfabrics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crane-Production-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25894</link>
<guid>f096d3da9f8797e053edd854335413ab</guid>
<pubDate>Sun, 28 Sep 2025 21:49:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Crane-Production-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0468a80f1013af01fbdef3208351fe8e4aeb3743c9d0241fd2b26ecaff00543</i><br /><br />Threat actor <b>description</b>: <i>Crane Production Systems is a full-service metal stamping and material handling company that specializes in the installation and servicing of industrial equipment. They provide a wide range of products including metal stamping machines, conveyors, and various retrofitting services for improved production efficiency. Their target clients include manufacturing industries looking for reliable machine solutions and technical support. With a commitment to excellence and customer service, Crane aims to enhance productivity and operational safety for their clients.</i><br />Target victim <b>website</b>: <i>www.craneproductionsystems.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Queens-Center-For-Change</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25895</link>
<guid>fd268d6fb813bbdb142908d7c23e4a88</guid>
<pubDate>Sun, 28 Sep 2025 21:48:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Queens-Center-For-Change</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d301890c0b9314c8e8729a1fba70f1e16a98c54db6bddd667f65b31ab642bd8f</i><br /><br />Threat actor <b>description</b>: <i>Queens Counseling for Change (QCC) provides behavioral counseling services. Services are provided by licensed counselors with many years of experience in the field. The agency is led by Larry Menzie, LCSW/R and Lillian Passoni, LCSW/R social workers with over 25yrs of experience providing services in a variety of settings.  QCC provides a myriad of services: problematic sexual behaviors, sexual offenses, batterers, anger management, bias crimes, animal cruelty education, and DWI (evaluations only).</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>BAM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25891</link>
<guid>f6ff1d6f23269b8af44ca23ab194e7e9</guid>
<pubDate>Sun, 28 Sep 2025 18:15:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>BAM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d5df6e9e41aa9412eeaccaf72d0a28ffc6447c6dc897460dc335f1b102f8f616</i><br /><br />Threat actor <b>description</b>: <i>You are fully aware of what we have, yet you’ve chosen not to uphold your end of the agreement. This is unacceptable. If you do not get in touch ...</i><br />Target victim <b>website</b>: <i>???</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Amelia-Overhead-Doors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25886</link>
<guid>a827c8955bcaf2cb9c7e451161ece13b</guid>
<pubDate>Sat, 27 Sep 2025 21:10:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Amelia-Overhead-Doors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8b2dc0cd369ee93ddf5ebbacb6b1e4663449d9dbe8a5b11020ea561c56c49de</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ameliadoor.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pangborn</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25885</link>
<guid>b079ec4c72b94420282bf9b0b544133d</guid>
<pubDate>Sat, 27 Sep 2025 21:10:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Pangborn</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a17e3c27fcc4717f518370b36fdd2de5787455ed5bd62df8c549596677cb756</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.pangborngroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>ComTec-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25881</link>
<guid>bddad3b16ee4fcc5f24b228a8f78a111</guid>
<pubDate>Sat, 27 Sep 2025 21:09:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ComTec-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>55001c88caa7f724ccb7df104e0b818141a9ec387439f694ab8b444bee4bc4e6</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.comtecsystems.net</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Earthadelic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25884</link>
<guid>9f423d8558ba8d9d96a987c9933ffd49</guid>
<pubDate>Sat, 27 Sep 2025 21:09:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Earthadelic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>980fd748168f5c8d7b3af6a4da6e351c31766f09a876cb748dd3a01375422c3d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.earthadelic.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Steve-Basso-Plumbing-Heating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25883</link>
<guid>60a77e068efeffff1391d72e4fbfec5c</guid>
<pubDate>Sat, 27 Sep 2025 21:08:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Steve-Basso-Plumbing-Heating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c390f614ea0ad71d34a5c5f5301d50db0601908faf325445a82596b29750ae8</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bassophac.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlas-Pressed-Metals</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25882</link>
<guid>f84aa65357bec670cbba3ae77711c233</guid>
<pubDate>Sat, 27 Sep 2025 19:35:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Atlas-Pressed-Metals</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c5ae29cda04d3f6936771aaae59153d9f80dd0b990017b59e1fca08f63f50e65</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.atlaspressedmetals.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Phillips-Feldman-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25878</link>
<guid>acc1fc2a7746c567f63c3c0490c35ddc</guid>
<pubDate>Sat, 27 Sep 2025 06:51:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Phillips-Feldman-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03eb0d71c3ebda2354f61c9322e1694b41e84591fc4ec5fa1e4778d742afd8bd</i><br /><br />Threat actor <b>description</b>: <i>Quality, personalized financial guidance to South Florida individuals and businesses</i><br />Target victim <b>website</b>: <i>cpfgcpa.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>thomasmhughes.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25869</link>
<guid>799d3f5de8680c081517920476881764</guid>
<pubDate>Fri, 26 Sep 2025 23:28:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>thomasmhughes.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>032992a1865bfe604fdd3b6ac38779eeac9cf0a93c4fb407fcbbeafa3063bddb</i><br /><br />Threat actor <b>description</b>: <i>Thomas M. Hughes, Ltd. USA - Calculation error. Company specializes in providing experienced legal counsel focused on employee benefits, ERISA, tax, and pension law. With over 30 years of expertise, they offer clear, practical solutions tailo            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Memphis-Millwork</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25867</link>
<guid>2fffa6dd1b50ced2b3d67b862bf2f61d</guid>
<pubDate>Fri, 26 Sep 2025 20:27:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Memphis-Millwork</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f179bb60aa49ae581737abf730fbbe4d69881af44d7667abfa417a2ee7d32744</i><br /><br />Threat actor <b>description</b>: <i>(Client data, accounting records, and internal documentation) Memphis Millwork specializes in commercial architectural millwork, catering to clients in Memphis ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cardinal-Machinery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25868</link>
<guid>bfd1269f6ca371debca250799daabb02</guid>
<pubDate>Fri, 26 Sep 2025 20:27:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Cardinal-Machinery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>644eb9c08031661cb42ec0badd036d894eee7dcae1770c0c1f20d44460eb8ee2</i><br /><br />Threat actor <b>description</b>: <i>(Full data) Cardinal Machinery is a family-owned business with over 50 years of experience in the Machine Tool Industry, serving clients across Tennessee, Alaba...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>ComTec-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25870</link>
<guid>c1b8c48c660ae44b22e250b32acae44f</guid>
<pubDate>Fri, 26 Sep 2025 15:47:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>ComTec-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b489fafece1ec17fc263aced2e2fedcd577e18bd398d2201b35f923a3296d980</i><br /><br />Threat actor <b>description</b>: <i>Specializing in business telecommunications and cost reduction consulting</i><br />Target victim <b>website</b>: <i>comtecsystems.net</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>WEST-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25858</link>
<guid>b276d5b499aa50a632efddf40bbdd75b</guid>
<pubDate>Thu, 25 Sep 2025 23:28:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>WEST-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04746bc2a22b8df763718e6185bb093cb0a178072878c917adb464830a2c7640</i><br /><br />Threat actor <b>description</b>: <i>West Water & Energy Systems Technology, USA - clean, but dangerous. Company specializes in sustainable water treatment solutions for various industries, particularly mining, boiler systems, and cooling towers. The company suffered a global da            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>XCAssociates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25859</link>
<guid>d64676745e6f99d0a8ab6c90160c438b</guid>
<pubDate>Thu, 25 Sep 2025 23:28:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>XCAssociates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77c783d921fa6480629f598aa409f262fb0c822912b33213f342db6de9205338</i><br /><br />Threat actor <b>description</b>: <i>XC Associates, USA specializes in the design and manufacturing of advanced carbon glass fiber composites tailored for various high-performance industries including medical, aerospace, energy, and consumer sectors. They offer a comprehensive r            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>oconnorcp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25848</link>
<guid>9c7eae0c470302045fc7e20c147b1929</guid>
<pubDate>Thu, 25 Sep 2025 17:27:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>oconnorcp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7d5d95feff4c40d14cac643eedf49a3da0b8e4903d2d961cab2e65586a2490a7</i><br /><br />Threat actor <b>description</b>: <i>O'Connor Capital Partners is a real estate investment company specializing in retail, office, industrial, residential, and multifamily properties in major cities across North America and Europe. The company was founded in 1983 and is headquar            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>waxhaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25849</link>
<guid>1abdec9e557dd71f742a5cfd35fb85f5</guid>
<pubDate>Thu, 25 Sep 2025 17:27:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>waxhaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>003e277ac25bf35ca6da91a496a87967892180a0cd094be34c990b1e4ae5c7bd</i><br /><br />Threat actor <b>description</b>: <i>The Town of Waxhaw in North Carolina.
1.All files relate to municipal procurement and contracts for the Town of Waxhaw (NC) for land rights acquisition services, map preparation, and related work for the Waxhaw-Marvin Road and Kensington Dri            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>regalmold.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25851</link>
<guid>5c10d595f3dfb3c6605a34f0c1a4c5b6</guid>
<pubDate>Thu, 25 Sep 2025 17:27:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>regalmold.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57c0ed0e44aff5df245aeaca0867cc26c938bb93cf18a8c1b49680cae549f78b</i><br /><br />Threat actor <b>description</b>: <i>We design and manufacture custom molds, components, and many other types of tools and assemblies for a wide range of customers.To manufacture custom products, we use precision machining on CNC machines, 5-axis machining, electrical discharge             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>halemakua.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25854</link>
<guid>b82e68e6366d4177332acdf3fa4d1e3a</guid>
<pubDate>Thu, 25 Sep 2025 17:27:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>halemakua.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0074f693c743eddc3eeaf16e38df9e2b323f02576d6030b1297d7511c4e82b6</i><br /><br />Threat actor <b>description</b>: <i>Hale Makua Health Services is a private, non-profit company located on the Hawaiian island of Maui. 
Our mission is to improve the well-being of our clients by providing personalized medical services at home, both at our facility and at your            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Study-Gate</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25860</link>
<guid>871c97e4e4732049f0e08079646b1f27</guid>
<pubDate>Thu, 25 Sep 2025 14:57:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Study-Gate</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f9bb28872e0c3e563c95675b2ce2a83ce53194cd6ec89778e3b327f9b8ffe7ac</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>studygate.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>pactchangeslives.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25839</link>
<guid>5b0f06cd304f174c316b40e5b384a164</guid>
<pubDate>Thu, 25 Sep 2025 00:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>pactchangeslives.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09e4ea9f43bb9d67257b8aa15644074eeea74441c1647eed51a0ab82fffd1380</i><br /><br />Threat actor <b>description</b>: <i>Porter County PACT is a company that operates in the Government industry. It emp...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>lwginc.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25840</link>
<guid>e9164c9ba1d2a0dc4e7a4a53a7613438</guid>
<pubDate>Thu, 25 Sep 2025 00:27:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>lwginc.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0768dcc809c1a029a6b169a894d8dbac14bc08ea12f2e056bf3840067fef5251</i><br /><br />Threat actor <b>description</b>: <i>LWG Construction offers end-to-end commercial construction services, focusing on...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>VIR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25838</link>
<guid>c3bd3d83ed8935f03a904ca943dd6f4d</guid>
<pubDate>Wed, 24 Sep 2025 23:28:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>VIR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b6e0d6122b3927074d3aec664cf29ebe031c723829269cd3892a1105647640a6</i><br /><br />Threat actor <b>description</b>: <i>Vir Biotechnology is a clinical-stage immunology company that focuses on combini...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>amsfulfillment.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25843</link>
<guid>0e9a570f97a6f2a4e1326a10228176a4</guid>
<pubDate>Wed, 24 Sep 2025 20:48:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>amsfulfillment.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4daf955d19543354ab0b3bba396556ea542b147573289cbe52023bd3f557fe1</i><br /><br />Threat actor <b>description</b>: <i>AMS Fulfillment is a leading full-service order fulfillment company operating as a third-party resource for order management, fulfillment center management and complex fulfillment services. AMS provides a full suite of fulfillment and distribution services to consumer products companies focused on serving the B2B retail (brick-and-mortar), online retail, and direct-to-consumer channels.</i><br />Target victim <b>website</b>: <i>www.amsfulfillment.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Valufinder-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25841</link>
<guid>9e667fbfbd97792f460f4c60557ab349</guid>
<pubDate>Wed, 24 Sep 2025 19:40:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Valufinder-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96ddb6a52c22229b370816d7f104a3c0de635c7013c84e63ca9e3f0d31726715</i><br /><br />Threat actor <b>description</b>: <i>Valufinder Group, Inc. is a boutique investment banking firm, recognized as a leader in providing comprehensive advisory services to mid-sized firms. Our seasoned professionals have mastered both the art and science of presenting businesses for financing or sale. We combine a highly personalized, service-oriented approach with a proven system for maximizing an owner's value, while minimizing risk, maintaining confidentiality, and anticipating and meeting the many challenges inherent in the process</i><br />Target victim <b>website</b>: <i>www.valufindergroup.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>TLD-Law.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25835</link>
<guid>8200e2e850224e4cea691cdc3ad0da2d</guid>
<pubDate>Wed, 24 Sep 2025 11:50:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>TLD-Law.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8747fdd55e24e3c30cf8fa11f3857eb344b75d7845a9ecd97e5f4de2f5f265a4</i><br /><br />Threat actor <b>description</b>: <i>TLD Law is a Southern California law firm specializing in estate planning, business transactions, employment law, real estate, and civil litigation.  They offer comprehensive legal services to both individuals and businesses, including corporate counsel, mergers and acquisitions, and trust administration.  ========================= In September, we downloaded corporate information from the company's server Tldlaw.com Their management decided not to contact us, so now we are publishing a small number of screenshots of internal corporate information. We own personal information of company employees, internal mail, financial information tldlaw.com</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Maryland-Department-of-Transportation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25836</link>
<guid>94f2bea7eb6186bb607e796153b2c343</guid>
<pubDate>Wed, 24 Sep 2025 11:08:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>The-Maryland-Department-of-Transportation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c67aa001427bb9ad8c733a8f8d108cb719e137e700c18fba5122c034289aa721</i><br /><br />Threat actor <b>description</b>: <i>The Maryland Department of Transportation</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.cr-installers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25829</link>
<guid>7fdcabbd898d3abe2690b023345adc9a</guid>
<pubDate>Wed, 24 Sep 2025 00:28:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.cr-installers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31aafcb5e49366a02d054d32102bd282cff15efa0706cdf38ffc70f981e1cdd7</i><br /><br />Threat actor <b>description</b>: <i>Chris Rodriguez Installers, USA - The company specializes in the installation, delivery, and warehousing of system furniture for federal, regional, and commercial organizations. CRI also operates a 50,000-square-foot warehouse conveniently lo            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Madison-Healthcare-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25818</link>
<guid>876af3a1db90d050582dc4b1c2201198</guid>
<pubDate>Tue, 23 Sep 2025 20:26:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Madison-Healthcare-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fdb760a7712284fa25df00bbfbc58fec2a9e1df44272e3eff8ff5503494a7f09</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pyramid-Global-Hospitality</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25819</link>
<guid>5361ef0c3c103c396bb6c7a24e638b5e</guid>
<pubDate>Tue, 23 Sep 2025 20:26:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Pyramid-Global-Hospitality</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fcbf563c950caa6ca1399c63b729195f5f0209b4e130561972a54b1f4502bdbe</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mavis-Tire-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25820</link>
<guid>d5c9087190e4d541da83e0739edeb60c</guid>
<pubDate>Tue, 23 Sep 2025 20:26:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Mavis-Tire-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6714d2384decc777e8ec63a350e8aed9bf351b0e378a351c8675bd41a0e0e6a7</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>KIPP-DC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25821</link>
<guid>9c75e36585c849bbac315c81661b0821</guid>
<pubDate>Tue, 23 Sep 2025 20:26:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>KIPP-DC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>737f7cb4db53cd1979715002588b517284df9a63b81e1f6e5b7eb5aaf285db40</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sapp-Bros</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25822</link>
<guid>a1b865daa05b1b1283171c4d28c02ec6</guid>
<pubDate>Tue, 23 Sep 2025 20:26:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Sapp-Bros</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f33e2f0c69394f3d3c9cd4ec53a465e395b531cd66f03ae294c1385d37a42aa3</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Washington-Prime-Group-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25823</link>
<guid>c49b360013e94c4d5e72d5e7cc3742ed</guid>
<pubDate>Tue, 23 Sep 2025 20:26:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Washington-Prime-Group-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f76d7bbbb5707167788525a999767c1eb404e1ce68994ea5b5699d9875cab14</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.margaritavilleatsea.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25824</link>
<guid>768d084123cb2ed6e871ad2019d3ae8a</guid>
<pubDate>Tue, 23 Sep 2025 20:26:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.margaritavilleatsea.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3b6f9a85ce65d9b153338d1467b303044302e2c38801a0de3b9a24eda40262d</i><br /><br />Threat actor <b>description</b>: <i>Margaritaville at Sea Cruises offers a unique offshore resort experience with fu...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Paul-Rossi-Law-Offices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25816</link>
<guid>cb1791d9672d69b321c67b55d0aa3db4</guid>
<pubDate>Tue, 23 Sep 2025 16:27:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Paul-Rossi-Law-Offices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fb5eed66d408e822c04f606da33ccc3bf0550851a924127ca6ea872e63b50cc6</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Speed-Art-Museum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25825</link>
<guid>de447028949b3471aa2617ad9db5a97f</guid>
<pubDate>Tue, 23 Sep 2025 15:47:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Speed-Art-Museum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>740d219cfaab80ed553714f496f66bd99ed6904fba24cc7eb016b16bdaeb0653</i><br /><br />Threat actor <b>description</b>: <i>The Speed Art Museum, originally known as the J.B. Speed Memorial Museum, now colloquially referred to as the Speed by locals, is the oldest and largest art museum in Kentucky. It was established in 1927 in Louisville, Kentucky, on Third Street next to the University of Louisville Belknap campus. It receives around 180,000 visits annually.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>PP-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25817</link>
<guid>0c9097d0139751fc728f1614cca51b43</guid>
<pubDate>Tue, 23 Sep 2025 12:53:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>PP-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1fbe8f05c8e620a7c1feb9606a0f93ee268378f23208d38367f8db8bcf804a6</i><br /><br />Threat actor <b>description</b>: <i>P & P Industries, Inc. | 2100 Enterprise Drive Sterling, IL 61081 | Phone: 815-632-3297  Internal documents, Finance, Development, Personal documents</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edro-Real-Estate</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25814</link>
<guid>f79995153b479a0830ca77943d5ed37f</guid>
<pubDate>Tue, 23 Sep 2025 04:20:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Edro-Real-Estate</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c71c4cdcdfb277258d08f8d1526d4767cb61a2663b23453beab45a0ad9559a31</i><br /><br />Threat actor <b>description</b>: <i>Real estate agency with extensive experience in construction, finance, and sales. Offers expertise in home construction and the financing process to guide buyers and sellers, available.- Database- Financial documents- Personal information of employees and clients https://edrorealestate.com/</i><br />Target victim <b>website</b>: <i>edrorealestate.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Takeuchi-US</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25812</link>
<guid>580606b7af236a5d0aec0dde1a7422fa</guid>
<pubDate>Mon, 22 Sep 2025 21:10:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Takeuchi-US</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>74d6dc1a748f39530c92529722aa0c715303d2f83b84cc3cd9cbbcc5124a9839</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.takeuchi-us.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>DHM-Properties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25811</link>
<guid>8f64c0a6975ce782d1adaf73ce892d51</guid>
<pubDate>Mon, 22 Sep 2025 21:09:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>DHM-Properties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a12c3fd735c1ff6e1bc9b1d5b16d879041698446616a915fa15a7121536faa2b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.dawnhomes.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vcinity</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25810</link>
<guid>1ac0c4b7634b3b88cea891e3aebe5860</guid>
<pubDate>Mon, 22 Sep 2025 20:22:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Vcinity</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c53ff735d88e817d9b480f7c8f26e3530487c87b118d506f3a94a81c92f3e8c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.vcinity.io</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>GrammaTech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25809</link>
<guid>23fd4faa302cb93d315147b1b7e713f1</guid>
<pubDate>Mon, 22 Sep 2025 20:21:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GrammaTech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>caf0eaa6d19358fdb3df6e5be09cca3a48153a1dd425b65b366bfd60acbefa93</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.grammatech.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>APG</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25808</link>
<guid>43675d9e95fa6fcff3217c6429c3e4cb</guid>
<pubDate>Mon, 22 Sep 2025 20:21:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>APG</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95e957154d18ed298ba183e65ab29d2fb9f162c33f871b550d55389bfa13584c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.apgsolutions.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Roth--Scholl</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25807</link>
<guid>0ecb6f61668018486c7ae0c73fef41f2</guid>
<pubDate>Mon, 22 Sep 2025 20:20:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Roth--Scholl</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b50cc10d05cba29ee1e28d4d762efd82915995c8530e3a6054fdef682dd7ae14</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rothandscholl.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>New-England-Waterproofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25806</link>
<guid>9bf9e4342000488a6910bbb1e8ceddf9</guid>
<pubDate>Mon, 22 Sep 2025 20:19:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>New-England-Waterproofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dcdb10c5d125cd19122c645c0c9fe930b00861e9b4df44ae36f13600d61acae7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.livedry.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Combined-Services-HVAC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25805</link>
<guid>370abbc7e1cbca7ae9e5d71dd316f28f</guid>
<pubDate>Mon, 22 Sep 2025 20:18:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Combined-Services-HVAC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48ca1eb33351d07f44d50b8f4b09cd732d5b811513db2e5c9be882a0c440851a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.combinedserviceshvac.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>PTR</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25804</link>
<guid>87755e2bb813ed0ad03d9801b4e0320d</guid>
<pubDate>Mon, 22 Sep 2025 20:18:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>PTR</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8d7bf5c4e7663c0f608eb35abc1c25ad66ec3ee13bde932b3947936b13ce29a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ptrco.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hilldun</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25802</link>
<guid>674d8d5f7f53691ee5ccf2d6095602da</guid>
<pubDate>Mon, 22 Sep 2025 19:37:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Hilldun</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5dc741a8ee2c81e5daf79ea06dfdb10f31551597bd7c655b763557067dce75a7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hilldun.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Markowitz-Ringel-Trusty--Hartog</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25799</link>
<guid>2f355056f055d7c1eabc82fdf1b71419</guid>
<pubDate>Mon, 22 Sep 2025 17:32:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Markowitz-Ringel-Trusty--Hartog</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47ac4384197040b5cdf1d98e5efbcf5f9d154fe2366a877a0326c488fa9a76fb</i><br /><br />Threat actor <b>description</b>: <i>Markowitz Ringel Trusty & Hartog provide setvices as Restructuring   Insolvency, Litigation   Dispute Resolution, Real Estate   Business, Probate   Guardianship, and Trust   Estates.We are going to upload 25gb corporate data. Huge amount of employees and clients information (full names, DOB, address, emails, phones, SSNs, DLs, death/birth certs and so on), legal files (police reports, hearings protocols and other court confidential files), financials, a bit of credit card information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>cegconstruction.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25785</link>
<guid>241f7e77a83327ca9f60c68f65960fc9</guid>
<pubDate>Mon, 22 Sep 2025 11:56:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>cegconstruction.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02e67180a7b10587c10089af7b830a8e86aad1a01427acabf8f8a1608234264c</i><br /><br />Threat actor <b>description</b>: <i>CEG Construction is on a path to self-destruction. This company is an industrial contractor based in Southern California that specializes in the construction of concrete warehouses and food processing facilities. They offer comprehensive desi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rainwalk-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25798</link>
<guid>779748b3baa7be62d16f8a23844951af</guid>
<pubDate>Mon, 22 Sep 2025 09:26:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Rainwalk-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>77d004b14b773cf42c447f1022f7d92954d397afe27a33ea5aacab1fe071a428</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>rainwalkpetinsurance.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>BEHCA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25796</link>
<guid>3f94dc570a5b16dc8e85fe4bdd0b8099</guid>
<pubDate>Mon, 22 Sep 2025 09:24:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>BEHCA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ddc4406332de5189c1086be4210f49d82936369fa29f2bc148ca61ecbc51d8d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>behca.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>MortDash</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25792</link>
<guid>f8e022748d5214eb5ce98d3f69a0036c</guid>
<pubDate>Mon, 22 Sep 2025 09:21:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>MortDash</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8643c7a77f1b3fabc89914714d64a5551ccce7b694822365fc892c0363be3921</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>mortdash.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>optimumdesign.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25787</link>
<guid>9dfdb3a175a991c93bb89b6585f09036</guid>
<pubDate>Mon, 22 Sep 2025 09:09:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>optimumdesign.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d2bed4ed1c2b26de2ea8f0d899595cb472a0e8a0a9021f1661e4d36d778c10d</i><br /><br />Threat actor <b>description</b>: <i>Optimum Design Associates specializes in PCB design services, leveraging elite experience and proven methodologies to deliver high-quality electronic engineering solutions.</i><br />Target victim <b>website</b>: <i>optimumdesign.com</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>Batesky-Law-Office-BLO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25786</link>
<guid>c61020b12cf805b7c3f39937118fffd3</guid>
<pubDate>Mon, 22 Sep 2025 08:18:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Batesky-Law-Office-BLO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e02f89d0d59e4fa27a2cfac51e5a4e93dd9dd068557d7ef08c76d0d2431adc24</i><br /><br />Threat actor <b>description</b>: <i>Attorney Richard Batesky has devoted nearly 30 years of his life to helping his clients receive compensation after a car accident, construction site accident, or personal injury due to another person’s negligence. At Batesky Law Office, we devote ourselves to discovering the best way to achieve a favorable outcome for all of our clients. Our knowledge and experience allows us to develop strategies that meet your individual needs. Indianapolis personal injury attorney Richard Batesky provides practical advice and solid counsel on all aspects of your case.Our philosophy is to remain in close contact and help you understand the strengths and weaknesses of your case from all perspectives. Personal injury and bankruptcy cases are not easy to litigate and can take years to achieve a result. There will be setbacks and obstacles along the way and an experienced attorney can build a solid case for you. The Indianapolis injury attorneys at Batesky Law Office will be devoted to your case and helping you receive the most favorable outcome.- Database- Financial documents- Personal information of employees and clients https://bateskylaw.com/</i><br />Target victim <b>website</b>: <i>bateskylaw.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Miami-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25784</link>
<guid>48d086c253bb8d866e7d5ba8414a5943</guid>
<pubDate>Mon, 22 Sep 2025 07:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sarcoma</b> claims attack for <b>Miami-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>71cf686dd495fd8da12afc3c207e8160478ad9d24136ff6ad1abd583a6a8c954</i><br /><br />Threat actor <b>description</b>: <i>Site: miamimanagement.com
														Industry: Business Services
														GEO: USA</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sarcoma</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pennsylvania-Office-of-Attorney-General</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25782</link>
<guid>e9ef4cc28cff2bbfaa9cca870ef88b58</guid>
<pubDate>Sun, 21 Sep 2025 00:46:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Pennsylvania-Office-of-Attorney-General</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8ad6498dc52f2efe0aaf5b67d74c3c024ffdbf2855b4a17b2527d1efc6eaaa4</i><br /><br />Threat actor <b>description</b>: <i>Pennsylvania Office of Attorney General is a law enforcement official that protects and serves the agencies of the Commonwealth and citizens of Harrisburg, Pennsylvania. 5.7TB data leak, access to internal network of FBI and more...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>goodcents.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25781</link>
<guid>11f9b53e8e2fafa24156bde7ba8b82d2</guid>
<pubDate>Sat, 20 Sep 2025 22:27:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>goodcents.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ff6fe895e5ce0e512e89055fcb4339383accd24da8d945067df8d7085da1ea25</i><br /><br />Threat actor <b>description</b>: <i>Goodcents, USA - Cheap food outlets are part of Custom Foods Inc., a company that produces frozen dough. The company manufactures a wide range of products, including dough for pizza, bread, cookies, and much more. The company supplies its pro            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>usadebusk.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25777</link>
<guid>6465f369dc088bc31009cf92a541b28b</guid>
<pubDate>Sat, 20 Sep 2025 05:46:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>usadebusk.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>70340d4e41bb484647a9518cf2fc12e44df3c0986325a55d3942317f564a1659</i><br /><br />Threat actor <b>description</b>: <i> USA DeBusk provides a comprehensive suite of industrial cleaning and infrastructure maintenance services to a diverse, blue-chip customer base across a broad r... - 2 TB including Contracts, Client Data, Employee Private Data, Incident Reports, and more</i><br />Target victim <b>website</b>: <i>usadebusk.com</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Machine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25775</link>
<guid>861e8bae74e22a572164fdb59b1caa8b</guid>
<pubDate>Fri, 19 Sep 2025 20:22:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>United-Machine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1fde4d64718a447b84f64a9c45953c76dc0319fe66508a430acd3c7224a8b751</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.unitedmachine.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Alan-Shintani-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25774</link>
<guid>5f6fc587ba2a036b38affbb8c0a42008</guid>
<pubDate>Fri, 19 Sep 2025 19:47:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Alan-Shintani-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a8988151b6bffd1a66d4dcb71f8ba87c9749877e6ccdfcfc63f140aa2eb973d4</i><br /><br />Threat actor <b>description</b>: <i>Photos and blueprints of government facilities.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jones-Soda-Stock-Symbol-JSDA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25770</link>
<guid>e86ebab434ff5a7172440f41518a7455</guid>
<pubDate>Fri, 19 Sep 2025 17:27:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Jones-Soda-Stock-Symbol-JSDA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e0c800244dc14546d5bbb68ad2c44ad5aa2399320ff337e40b79b2eb3438705</i><br /><br />Threat actor <b>description</b>: <i>Jones Soda Co.® (CSE: JSDA, OTCQB: JSDA) is a leading craft soda manufacturer with a growing line of cannabis products.We are going to upload 66gb corporate data. Employee information (complete name, DOB, address, emails, phones, SSNs and so on), financials, payment details, credit cards details, numerous contracts and agreements (with PepsiCo and others), NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>About-Ross-Brittain-Schonberg-Co.-Lpa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25771</link>
<guid>668e5773130d942b59a3ceea6ec85225</guid>
<pubDate>Fri, 19 Sep 2025 17:27:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>About-Ross-Brittain-Schonberg-Co.-Lpa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>742e416733eb59880c737d3c536f2ac9a6ee828575c91121b0f036704fe353ac</i><br /><br />Threat actor <b>description</b>: <i>Ross, Brittain & Schonberg specializes in Labor Law, Employment Law, Workers’ Compensation, and OSHA matters, representing management across various sectors.We are going to upload 66gb corporate data. Lots of legal files (police reports, hearings protocols and others), clients and employees documents and other personal information (Full names, DOB, address, emails, phones, SSNs, DLs and so on), financials, NDAs, etc. Very interesting data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>KCI-Telecommunications</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25769</link>
<guid>bbc57478f9bdc47a0126f9e93343346d</guid>
<pubDate>Fri, 19 Sep 2025 14:27:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>KCI-Telecommunications</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d909e077ff66faaeff17d34c1c744f90c78af046a62fb5815c5dfe602f41262d</i><br /><br />Threat actor <b>description</b>: <i>KCI provides support services and turn-key solutions focused on exceeding their client’s Network, Resources Management and legacy support needs.We are going to upload corporate data. A lot of personal information of employees (DOB, address, emails, DL numbers, phones and soon), confidential files, payment details, numerous contracts andagreements, financials, customer information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>cardiofocus.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25765</link>
<guid>489df1727ce07aae5f09ca2d90ff9f74</guid>
<pubDate>Thu, 18 Sep 2025 20:58:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cardiofocus.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8d55936a97fc7100a3c983f62c8146826a355f2bf153364080af568797bc75a</i><br /><br />Threat actor <b>description</b>: <i>CardioFocus specializes in offering innovative tools for electrophysiologists to treat atrial fibrillation. Their advanced technologies, including the HeartLight X3 and Centauri System, leverage laser and PFA technology for precise and effective treatment. The company focuses on enhancing procedural efficiency and patient outcomes through shorter procedure times and advanced customization. Their primary clients are electrophysiologists looking to improve care standards in managing complex cardiac arrhythmias. Employees: 87 Revenue: $29.1 Million Industry: Retail  Phone Number:(508) 658-7200</i><br />Target victim <b>website</b>: <i>cardiofocus.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gurneys-Resorts</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25755</link>
<guid>a5d16104be85fc85838ce2259c88f2cb</guid>
<pubDate>Thu, 18 Sep 2025 20:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Gurneys-Resorts</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>120b2d954cb7ff9416d8ed703f54d38d1505513476cda9f500166cb4af1b211a</i><br /><br />Threat actor <b>description</b>: <i>Gurneys Montauk Resort & Seawater Spa is a luxury beach hotel located in Montauk, NY, offering 158 rooms, suites, and beachfront cottages with stunning ocean views. We are going to upload 20GB of corporate data. Employees' personal information (passports, addresses, SSNs, phones, emails, medical information and so on), client information (DOB, full name, phone, emails, room numbers, addresses and so on), finance and accounting files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hood-Technology</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25756</link>
<guid>d1d2f825932ae8df3aa6db09325cf61e</guid>
<pubDate>Thu, 18 Sep 2025 20:27:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hood-Technology</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c77669a4b524efac21c3d3b4c59c3e2cdc0703baf94125c054b0e004813f543</i><br /><br />Threat actor <b>description</b>: <i>Hood Technology Corp is an engineering-oriented company based in Hood River, Oregon, specializing in the development of stabilizedgimbals for both manned and unmanned vehicles.  We are going to upload corporate data. Lots of project files withdrawings and specifications, contracts with sound names like Ferrari, Toshiba, MAN, Siemens, Apex and other companies. Customer information, lots of NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>MMI-Direct</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25759</link>
<guid>ba307c1fd60c35533dcf424e1befabff</guid>
<pubDate>Thu, 18 Sep 2025 20:27:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MMI-Direct</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>09208c730c94b3d88b91b7867c6a4fa8289588b0e531be0c961426235ff466f8</i><br /><br />Threat actor <b>description</b>: <i>MMI Direct is a leading data processor that specializes in providing services like NCOA, PCOA, analytics, list fulfillment, merge purge, and data append to nonprofits, businesses, and government clients.We are going to upload 116gb corporate data. Employee files (Passports, DLs, birth and death certificates, interviews and other personal documents), medical information, HR data, contracts and agreements, financial information, client information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wargo-French</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25761</link>
<guid>f838653dadc0732215222a1e0fd8190f</guid>
<pubDate>Thu, 18 Sep 2025 20:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wargo-French</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78fc03eaea19aa148e1d85db369956834f3f55fba4edc7e9f229e4b98f6b5a7c</i><br /><br />Threat actor <b>description</b>: <i>Wargo French Singer is a full-service law firm with offices in Atlanta, Los Angeles and Miami. We are going to upload 11gb corporate data. Lots of client information (DOB, address, emails, phone and so on), lots of confidential files, contracts and agreements with Coca-cola and other big names, financial information, projects and other files.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Legend-Senior-Living</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25752</link>
<guid>be03f76cc8e48304c888adcf6241e45b</guid>
<pubDate>Thu, 18 Sep 2025 19:27:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Legend-Senior-Living</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76bac9aa2378c66a5b10068bcf105fca1b2d939fed69078dd76e34d51e27efa0</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>ACRO-Automation-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25753</link>
<guid>d059f8fe3d5acacbe25424c27759f111</guid>
<pubDate>Thu, 18 Sep 2025 19:27:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>ACRO-Automation-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb4113ea8ac82f89249d46e0112b880521b9d34ad04b517115abdd02d8e86272</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-Wide</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25754</link>
<guid>2229f5e95ef45e343890f2e839c7f74c</guid>
<pubDate>Thu, 18 Sep 2025 19:27:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>City-Wide</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8bbd507bc18d560019da4d0ba9576cab8dc343832b8ebaed87fd996d63932a89</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dubroff-Easley--Lovell-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25764</link>
<guid>7bd89d300d39ced373d95ee7eb3c4b78</guid>
<pubDate>Thu, 18 Sep 2025 17:51:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Dubroff-Easley--Lovell-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>074b28e0d37e4ef4916d7a272234dd70771ae378a68075aba0cf4441aa190654</i><br /><br />Threat actor <b>description</b>: <i>Attorney service in family law</i><br />Target victim <b>website</b>: <i>dubrofflaw.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Tri-Century-Eye-Care</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25763</link>
<guid>e04a9a2d51029f73f5c3b7a085de91ee</guid>
<pubDate>Thu, 18 Sep 2025 17:51:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Tri-Century-Eye-Care</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>665e1fc4c2961ca32de45d47da578a10955d11db4c609f07da464ca9aae84dd2</i><br /><br />Threat actor <b>description</b>: <i>Ophthalmologists and optometrists provide comprehensive and sub-specialty eye care across patients of all ages</i><br />Target victim <b>website</b>: <i>tricenturyeye.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>United-Pharma</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25762</link>
<guid>2c0c63b0449c63fe70737d064f3c43bb</guid>
<pubDate>Thu, 18 Sep 2025 16:51:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>United-Pharma</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a2f09e201967c3bd19c7b05d580303fa390a4995f6231667be3fb18a57006a02</i><br /><br />Threat actor <b>description</b>: <i>United Pharma LLC is a softgel contract manufacturer based in Southern California, specializing in high-quality nutraceuticals and supplements. Founded in 2006, the company boasts a state-of-the-art 55,000 square foot facility and adheres to strict quality standards in its production processes. Their services include gelatin mixing, encapsulation, bottling, and custom labeling, catering to clients seeking innovative softgel solutions. With a highly experienced management team, United Pharma aims to be a progressive partner for both its customers and the community.</i><br />Target victim <b>website</b>: <i>www.unitedpharma.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.independentpaperboard.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25749</link>
<guid>9248a959405836566e6ba694aaa884a6</guid>
<pubDate>Thu, 18 Sep 2025 14:27:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.independentpaperboard.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>11295aaba623ad038cd8dfe2c323c1465298487bd7f752d5859935602f550218</i><br /><br />Threat actor <b>description</b>: <i>Independent Paperboard Marketing, LLC is a problem-solving paperboard brokerage ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>cardinal-services.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25742</link>
<guid>cf1f249ab7ce26315cf395fd2f794620</guid>
<pubDate>Thu, 18 Sep 2025 00:50:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cardinal-services.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16af2b1e1c64397428ad7662c26d1ba4d64a7f608e1ff3f1052a36a18ff3a947</i><br /><br />Threat actor <b>description</b>: <i>Cardinal Services is a full-service staffing company founded in 1984 and headquartered in Coos Bay, Oregon. Employees: 50 Revenue: $48.7 Million Industry: Business Services Phone Number:(541) 888-9799</i><br />Target victim <b>website</b>: <i>cardinal-services.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Thomas-Safran--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25740</link>
<guid>6158cdc6f0b5626d7f9b407adf4bb89b</guid>
<pubDate>Wed, 17 Sep 2025 22:18:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Thomas-Safran--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8bda54289e318ffca0b565fcb2b4ed2c99a36946e73307af87b3c1fd7070e25d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.tsahousing.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>lindenlaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25733</link>
<guid>fc08e88c689b903532df9465c4e21cab</guid>
<pubDate>Wed, 17 Sep 2025 21:52:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>lindenlaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f19ac0f9503bf4e6eb7975e399a51cb8586e5741da5190e56284f8066219427</i><br /><br />Threat actor <b>description</b>: <i>Howard T. Linden, P.C. is a Michigan-based law firm specializing exclusively in probate law, offering services such as wills, trusts, guardianships, and wrongful death settlements. With nearly 50 years of experience, the firm is known for its efficient and cost-effective probate services for attorneys, insurance companies, creditors, and families. The firm caters to both local and out-of-state clients needing assistance with probate matters in Michigan. Attorney Howard Linden's extensive knowledge and compassionate approach ensure that clients receive thorough and timely support throughout the probate process. Employees: 25 Revenue: $5 Million Industry: Law Firms Phone Number:(248) 358-4545</i><br />Target victim <b>website</b>: <i>lindenlaw.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>spartanburgcounty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25725</link>
<guid>30075533571c1a82bb8f1b810203cd57</guid>
<pubDate>Wed, 17 Sep 2025 20:29:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>spartanburgcounty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d88c697dd41ccb71afdfeca3ce0cd6355327ad518385ebd17d9495845fad981</i><br /><br />Threat actor <b>description</b>: <i>SPARTANBURG, USA - Failure before the election. 08/08/25 FOX Carolina issued an urgent announcement: “Spartanburg County officials have stated that a ‘cybersecurity incident’ has occurred on their network.” As always, local authoritie            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>alliancesteelco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25738</link>
<guid>3506709108e107543aa9fcf845daf0a6</guid>
<pubDate>Wed, 17 Sep 2025 20:13:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>alliancesteelco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4aea8560415bee4ade52757fd9ea637a4bbe2a1220e289898c195b71c13d4982</i><br /><br />Threat actor <b>description</b>: <i>“Alliance Steel” is a generic trade name used by multiple flat-rolled steel service centers in North America; relevant examples include …</i><br />Target victim <b>website</b>: <i>alliancesteelco.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>slusarski.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25737</link>
<guid>8ac65b1061ec1e8b4ebdebc5b98e5c9d</guid>
<pubDate>Wed, 17 Sep 2025 20:12:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>slusarski.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9a4a2366cce932fee7b731629e216e4b9ca02b0b3c403e9b03452b3a25955fe4</i><br /><br />Threat actor <b>description</b>: <i>Slusarski is a Michigan-based sitework, earthmoving and paving contractor founded in 1982 that provides excavation, asphalt paving, sealcoating, striping, materials …</i><br />Target victim <b>website</b>: <i>slusarski.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>drcloudemr.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25736</link>
<guid>1dc6d927cb8ec9838ad96a48af31ea4c</guid>
<pubDate>Wed, 17 Sep 2025 20:12:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>drcloudemr.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>de3dfe26e54454429ec4d8459810d454c38c8635fe00337547e1a9cf5d0d765f</i><br /><br />Threat actor <b>description</b>: <i>DrCloudEHR (often referenced as DrCloud/DrCloudEMR) provides cloud-hosted electronic health record (EHR) / practice management software targeted at ambulatory clinics and …</i><br />Target victim <b>website</b>: <i>drcloudemr.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>venetianassociates.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25735</link>
<guid>cfe1bae9441470f7d25f0ea2c29fce2d</guid>
<pubDate>Wed, 17 Sep 2025 20:11:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>venetianassociates.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5f66da5fe5c33bf7c1f6a5c72cb2ce492553892b24bfea8ed76aac33fa13084</i><br /><br />Threat actor <b>description</b>: <i>Venetian Associates is a private family-office style investment vehicle and lower-middle-market acquirer based in Michigan that focuses on buying consumer …</i><br />Target victim <b>website</b>: <i>venetianassociates.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>biosorthopedics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25731</link>
<guid>5fc4d0155cf2d4d93bdbdf4b8dc54da8</guid>
<pubDate>Wed, 17 Sep 2025 18:42:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>biosorthopedics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>84072aa6972113ef20eeb978ca60acc9e23559a17d6170772a3b1661657148a3</i><br /><br />Threat actor <b>description</b>: <i>Broward Institute of Orthopaedic Specialties (BIOS) is a multi-physician orthopaedic practice headquartered in Hollywood and Pembroke Pines, Florida. The practice …</i><br />Target victim <b>website</b>: <i>biosorthopedics.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prime-Asset-Fund</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25723</link>
<guid>c8c83f959021e1042efa4c5146754409</guid>
<pubDate>Wed, 17 Sep 2025 18:27:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Prime-Asset-Fund</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4883c965dd52c569c469f25d264f8b0c9fb802942776de64565f29aa1f1874ed</i><br /><br />Threat actor <b>description</b>: <i>Prime Asset Fund, USA is a highly questionable player in the US financial market. It is a company that operates in the investment banking industry. It employs 20 to 49 people and has revenues of $10 million to $25 million. Prime Asset also in            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.vdyne.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25722</link>
<guid>f25319e832341516c2a618ef2a314932</guid>
<pubDate>Wed, 17 Sep 2025 14:58:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.vdyne.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>935019b70d406359e980c9ac70166a43b9033963ccf66ff13208024ded6291d4</i><br /><br />Threat actor <b>description</b>: <i>VDyne, USA is a clinical-stage medical device company dedicated to developing transcatheter valve solutions for the treatment of debilitating and life-threatening Tricuspid Regurgitation (TR). They are developing medical micro-prostheses that            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>bmsi.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25706</link>
<guid>df90e07fdc98b84c3c41b4fbab8de98c</guid>
<pubDate>Tue, 16 Sep 2025 17:17:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>BrainCipher</b> claims attack for <b>bmsi.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42b1fed99e4607edb09bc205a4b7c76b6b69356aa28bb483cb311488ba79d9aa</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>bmsi.org</i>]]></description>
<category>BrainCipher</category>
</item>
<item xmlns:dc='ns:1'>
<title>Medpeds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25703</link>
<guid>3bc188adb791a56ccce03630b0d9f593</guid>
<pubDate>Tue, 16 Sep 2025 11:11:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Medpeds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2519be21265990595b9476eb9459482ed6180313af876d169a4b433eeaaf2058</i><br /><br />Threat actor <b>description</b>: <i>MedPeds Associates, located in Sarasota, Florida, specializes in Internal Medicine and Pediatrics with a strong emphasis on preventive care for adults, seniors, and children. The practice is recognized as a Level 3 Patient Centered Medical Home by the National Committee for Quality Assurance, showcasing its commitment to high-quality healthcare practices. They offer a full spectrum of medical services including same day lab services, chronic care management, and telehealth options. Their goal is to promote good health through proper nutrition, regular professional care, and the establishment of good habits.</i><br />Target victim <b>website</b>: <i>www.medpedsdocs.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>webville.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25695</link>
<guid>d61fc047656a08fd0cddc1a37e4dd729</guid>
<pubDate>Tue, 16 Sep 2025 05:28:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>webville.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25c8832aebdd7e5ea544de0077eb43cb3c00a9a942ec31487dbd6e10b3be2bf1</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>webville.net</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>elssurveying.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25694</link>
<guid>31073475fc4fe0f27c6b876472f0888e</guid>
<pubDate>Tue, 16 Sep 2025 05:27:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>elssurveying.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>279848cfefb3488d548d62556b37b6603f3f24218f373ed59fb5ab9bb4e788fb</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>elssurveying.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>News-Press--Gazette-Co.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25690</link>
<guid>507779fbc52283f223fb8cc6bb9e6d2e</guid>
<pubDate>Tue, 16 Sep 2025 00:47:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>termite</b> claims attack for <b>News-Press--Gazette-Co.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1e5e0e4b536bca17646023cc178ccfab966aaef9647a0f92a0e416fef61d0a4</i><br /><br />Threat actor <b>description</b>: <i>News-Press &amp; Gazette Company publishes daily newspapers and weekly publications. 
</i><br />Target victim <b>website</b>: <i>www.npgco.com</i>]]></description>
<category>termite</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.peuh.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25687</link>
<guid>0ab3906a724cfe5ba8b36e7c25d33491</guid>
<pubDate>Mon, 15 Sep 2025 21:51:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>devman</b> claims attack for <b>www.peuh.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1b129055c58e6bd3656d2260a4a63c5b77ece267277935f1514ef8bd6729bfe</i><br /><br />Threat actor <b>description</b>: <i>1700000 USD</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>devman</category>
</item>
<item xmlns:dc='ns:1'>
<title>VirMedice</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25668</link>
<guid>627f1c009880d8f375bf48ba6b8f4564</guid>
<pubDate>Mon, 15 Sep 2025 20:52:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>VirMedice</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d73c0851f9aa5405fb6f207cf018ccd00eb3d4f735601b17e380a4d52615c829</i><br /><br />Threat actor <b>description</b>: <i>VirMedice offers the NextGen Ambulatory EHR (Electronic Health Records) and NextGen Ambulatory PM software (Practice Management) in two Models</i><br />Target victim <b>website</b>: <i>virmedice.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>AdScale</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25684</link>
<guid>c80e2e3dfd073a58a7868ba33aed57a9</guid>
<pubDate>Mon, 15 Sep 2025 20:48:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>AdScale</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3643bb4ec1642b55383a6bab5e10bbc7670042b5f9963444dbd5d913c8fbc1f4</i><br /><br />Threat actor <b>description</b>: <i>AdScale is an AI-driven advertising platform tailored for e‑commerce and digital marketers, offering unified campaign management across Google Se...</i><br />Target victim <b>website</b>: <i>www.adscale.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dreyfuss-Williams--Associates-Co--LPA</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25665</link>
<guid>25d116dc9e29065600cd84782e385de2</guid>
<pubDate>Mon, 15 Sep 2025 20:48:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Dreyfuss-Williams--Associates-Co--LPA</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>52fcd94498b33fef697ead76fee4dc16c48e59b4fe067a88c4de6351b9bbbc10</i><br /><br />Threat actor <b>description</b>: <i>Dreyfuss Williams Attorneys & Counselors at Law is a law firm specializing in Health Care Law, offering legal representation to hospitals and medic...</i><br />Target victim <b>website</b>: <i>www.dreyfuss.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plug-Power</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25681</link>
<guid>cf1f4d5318c6b0a76eb889ba14443cbe</guid>
<pubDate>Mon, 15 Sep 2025 20:46:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Plug-Power</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa1480db2eb0c9e379264c1a8be4241621f3be155a1d481e2d5a91cfc29433ee</i><br /><br />Threat actor <b>description</b>: <i>Plug Power is a premier provider of innovative hydrogen fuel cell solutions, specializing in clean energy technologies that enable the transition t...</i><br />Target victim <b>website</b>: <i>www.plugpower.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Volt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25664</link>
<guid>9a1e6dff7dbc2da64a3577c8b9a24854</guid>
<pubDate>Mon, 15 Sep 2025 20:45:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Volt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc874944c1d0b78b8fa4e7cd12bbc3fcaee57531728dd86d8bda7646061e44ac</i><br /><br />Threat actor <b>description</b>: <i>Volt is a global talent solutions provider, specializing in workforce management, recruitment, and staffing across industries such as technology, e...</i><br />Target victim <b>website</b>: <i>www.volt.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wakefield--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25666</link>
<guid>b7e898084c1ec0616b4b2f0cf14a758b</guid>
<pubDate>Mon, 15 Sep 2025 20:45:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>coinbasecartel</b> claims attack for <b>Wakefield--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f6dd28f7e81fb6a8aca1618c68bd0b1ae4b7126c30172e99f09eeb243550e35</i><br /><br />Threat actor <b>description</b>: <i>Wakefield & Associates is a financial services company specializing in debt collection and billing services. Wakefield & Associates helps clients i...</i><br />Target victim <b>website</b>: <i>www.wakeassoc.com</i>]]></description>
<category>coinbasecartel</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lake-Book-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25667</link>
<guid>79525d41efbf16d3363c138f713d2417</guid>
<pubDate>Mon, 15 Sep 2025 19:47:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Lake-Book-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>16a28ec3d0d800c24ffd828c2aaca5bde5912b51fb33d9739cd0cd387ecd37bd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.lakebook.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eau-Palm-Beach-Resort--Spa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25678</link>
<guid>c6b2aa071387a2e68359d61f88ea16f6</guid>
<pubDate>Mon, 15 Sep 2025 19:47:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Eau-Palm-Beach-Resort--Spa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbef7bfbb7ca45003ecb0df5924efc0ea4f2798b243b183ce71601efe79feeb0</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.eaupalmbeach.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Energenecs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25677</link>
<guid>8c2a6cec60863b5ffd776ad9ff57495a</guid>
<pubDate>Mon, 15 Sep 2025 19:46:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Energenecs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc2b3c6614b9fd61c562cea440196c2bc357d2034b006d45f8e9cf40e9dd5353</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.energenecs.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garrison-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25676</link>
<guid>461254593ec0cc1839a590251176c99c</guid>
<pubDate>Mon, 15 Sep 2025 19:46:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Garrison-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>453e05497f27c953db38247f9a50b18acffdc4ecb8d7c385eaa482cd5e72c55f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.garrisonarch.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>McCarter-Electrical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25675</link>
<guid>eda9c67d6a20358927319cf3510402df</guid>
<pubDate>Mon, 15 Sep 2025 19:45:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>McCarter-Electrical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9eb95619ba76958e207e59cbad8f4f4287f1ec63d99c348875e8a665f8267c1a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mccarterelectric.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pathfinder</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25674</link>
<guid>62f6e7ceadd1f1eb64fe5d6936e7122b</guid>
<pubDate>Mon, 15 Sep 2025 19:44:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Pathfinder</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>240b79f7cada9235db667cc2c52c2ab4e9ff198e47a92534c06d1fc805122eea</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.pathfinderlld.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>General-Control-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25673</link>
<guid>03f68714dba796f8d6b268029d0e62c4</guid>
<pubDate>Mon, 15 Sep 2025 19:44:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>General-Control-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>22d4ef9d23bcb915662a4f0d8d848c0df09fa8d7fe0d1963823816849fe29b0c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.generalcontrolsystems.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>RFI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25672</link>
<guid>0555bb36e8cfb7af4aaad5472cab1c49</guid>
<pubDate>Mon, 15 Sep 2025 19:43:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>RFI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d15bac78506b422a15ac074743b90cdd534eb2edaaa68cb50a92b214a7498a38</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rfiingredients.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Crestone-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25671</link>
<guid>1bc3368ddb162d1f2846b60b810ce6c0</guid>
<pubDate>Mon, 15 Sep 2025 19:42:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Crestone-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f3dbdb53f27d973e06c345a2fd06ff33dc4a7562156c67fd45cdc7e99b681715</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.crestone-group.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>TerranearPMC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25670</link>
<guid>fffcc1a3964b4ad665fa2f07d7bfd086</guid>
<pubDate>Mon, 15 Sep 2025 19:42:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>TerranearPMC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>061335c1eefde2c54767c7b0b59f3b9476cea637245c9ca41efea04415751be3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rochesteroptical.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rochester-Optical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25669</link>
<guid>eaaec0f511fd0cbc445208525b36de96</guid>
<pubDate>Mon, 15 Sep 2025 19:41:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Rochester-Optical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3dc97eb889cef8c3e93d143d091fb1789d06c900d4b7ca843598fac9cc427f1</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rochesteroptical.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CyberData</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25656</link>
<guid>d3e0182476466a3c2fcc74778b89ea6b</guid>
<pubDate>Mon, 15 Sep 2025 17:27:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>CyberData</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a461c1eba7a6d1d65126de23bdf86221f2e4edf227ddefd6de4703c9209a6a05</i><br /><br />Threat actor <b>description</b>: <i>CyberData Corporation is a leading OEM design and manufacturing firm with more than 40 years of experience. They specialize in IP Endpoints for the VoIP marketplace, VoIP and POS (Point-of-Sale) connectivity solutions, and POS protocol conversion technologies.We are going to upload 9GB of corporate data. Employees' personalinformation, client data, partners data, a bit of finance and accounting files, lots of project files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Technology-Assurance-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25661</link>
<guid>54526e432dbfc94816c704c3e81710df</guid>
<pubDate>Mon, 15 Sep 2025 14:23:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Technology-Assurance-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c1461e299b9c94f8321210e75907134f91662c46b5c0e2d11750a1a52bd8ad8</i><br /><br />Threat actor <b>description</b>: <i>Technology Assurance Group is an organization of leading managed technology services providers (MTSPs) in the United States and Canada. TAG Members integrate all technology solutions including IT, cloud-based technologies, cybersecurity, telecommunications, AV, video surveillance, access control and managed print</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>jsgroup</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25662</link>
<guid>5de2a609f24dd206f3a9cfe3378fb4e0</guid>
<pubDate>Mon, 15 Sep 2025 14:22:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>jsgroup</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a18e8ec360c7a21cde9b305e6d18055b7c0ffaedb05ef8f12731bd101dcd7529</i><br /><br />Threat actor <b>description</b>: <i>JS Group International is a house of brands that encourages individual expression, authenticity, innovation and social responsibility. ‍ JS Group entered the North American fashion scene more than 50 years ago, having first made its mark in the evening wear market in 1971. Today, we have expanded into eight divisions, and are widely recognized as one of the leading suppliers of women's sportswear, dresses and evening wear, available in specialty stores, major chain stores and department stores worldwide, as well as on our brand websites.  Each of our brands, AMUR, Theia, JS Collections, Et Ochs, has a unique attitude that not only reflects the trends, but aims to instill confidence in all women, regardless of age or size. In addition, we hold licenses for BCBGMAXAZRIA, Halston and Kay Unger.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trucchis-Supermarkets-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25659</link>
<guid>013e7eede60069b472064b3e9a46455f</guid>
<pubDate>Mon, 15 Sep 2025 12:41:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>Trucchis-Supermarkets-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>78a6ebbc5e49dceb86264e29da0f8701a1d6d3eeac55541a62dbc047d005ee41</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Trucchi's Supermarkets, Inc. is a chain of family-owned supermarkets based in Taunton, Massachusetts, USA. It was established by William M. Trucchi Sr. in 1928. Currently, the company operates six full-service supermarkets in Massachusetts. Trucchi's places emphasis on providing value to customers by offering fresh quality products and personal customer service. They also offer custom cake designs through their bakery department.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>volinc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25651</link>
<guid>2abb73368bdec87c1ebcd83baae08823</guid>
<pubDate>Mon, 15 Sep 2025 10:27:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>volinc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>01a30b8cc8b770af06aa12ef4040c8cd94652edd4da4f0c95efe39234a8a8f2a</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1992 and headquartered in Conyers, Georgia, Volume Transportation, Inc. provides ground transportation, cargo loading, warehousing, storage, and material flow management services.
1.The document is a confidential mediation stateme            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>trchealthcare.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25652</link>
<guid>eb69ec3b34db9fc42da12bd9c3a8ad37</guid>
<pubDate>Mon, 15 Sep 2025 10:27:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>trchealthcare.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ed4d115709bd38d8a3b6dcaaf16de25f30daf4996c394a34ca68a22cc5fdf2d8</i><br /><br />Threat actor <b>description</b>: <i>The Therapeutic Research Center was founded in 1985 and is headquartered in Stockton, California. The Therapeutic Research Center specializes in studying and evaluating new drugs that are approved for use each year.
1.The document is a clini            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Baum-Precision-Machining</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25647</link>
<guid>92e2febe8d6183b8026d49448c382d0e</guid>
<pubDate>Mon, 15 Sep 2025 02:50:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Baum-Precision-Machining</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3360f2644d38894759c7f6a3862dc12b0fb5fca707f8d5ade4bac8ee51be8bfd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.baumprecision.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpwww.hiec.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25649</link>
<guid>c80bc2fbadab1c16dd058069491b4604</guid>
<pubDate>Mon, 15 Sep 2025 02:23:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpwww.hiec.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8466a8a2b1001adf4a6d8bf33c89922f7f4c699967ae293760ed977810f804e7</i><br /><br />Threat actor <b>description</b>: <i>H.I. Executive Consulting is a global executive search firm specializing in the recruitment of Board, CEO, and senior-level executives. The firm focuses on acquiring digital talent and transformational leaders to meet the needs of modern organizations. With a strong presence across the US, EMEA, and APAC, H.I.E.C operates through a united team in 14 international offices, providing tailored, expert advice for every assignment. Committed to promoting diversity, H.I.E.C helps clients attract a wide range of talent to foster innovative organizational cultures</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpsheritagegrowth.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25650</link>
<guid>9e1f10e4ad1f09457c81d8dbd9dd254f</guid>
<pubDate>Mon, 15 Sep 2025 02:22:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>httpsheritagegrowth.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b10a68c0f919f43ba12c791d301e89364205f917c391a7f0e0613d2f8b05b01</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2014, Heritage Growth Partners is a private, family investment office specializing in growth equity investments in collaboration with owner-managers. The firm emphasizes a patient and flexible capital approach, offering strategic, financial, and operational support to enhance long-term business growth. Heritage Growth Partners seeks to build true partnerships with management teams, understanding their goals and celebrating their entrepreneurial spirit. Their clients primarily include owner-managers looking for investment and collaborative resources to accelerate growth and increase value</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>usenergy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25642</link>
<guid>89a183c0c11d6d0ca7830f9d530a3097</guid>
<pubDate>Sun, 14 Sep 2025 22:41:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusalocker</b> claims attack for <b>usenergy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>81fb480ac54fe42fce7138377eca3a26c093a0821295c0d498317e726b42dcda</i><br /><br />Threat actor <b>description</b>: <i>Price-$120000 (sale in one hand there are options for making a profit from these files will be included in the deal)</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusalocker</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eagle-Excavation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25617</link>
<guid>694a6dc002be509353ef2c5dd874dfab</guid>
<pubDate>Sun, 14 Sep 2025 21:26:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Eagle-Excavation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a0a0510ef17c392a7d258b83a671e5feaa5b19e403566bd072112a46e9f9efe1</i><br /><br />Threat actor <b>description</b>: <i>Eagle Excavation, USA - They pride themselves on their digging skills, but they couldn't bury their dirty secrets deep enough. Eagle Excavation Atlantic performs site preparation work for projects throughout Georgia. They boast of multimillio            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>opso.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25608</link>
<guid>75e913d400755a0d2782fc65e2035e97</guid>
<pubDate>Sun, 14 Sep 2025 17:28:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>opso.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>645da31fccaf9a59b9a2dfb0f43360db04a36e780ebfa4ad6dab4fe277d800ae</i><br /><br />Threat actor <b>description</b>: <i>The Orleans Parish Sheriff's Office and Sheriff Marlin N. Guzman are responsible for the custody, care, and control of inmates in one of the largest urban correctional facilities in the United States.
1.The document is a summary report on in            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Conception-Reproductive-Associates-Colorado</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25616</link>
<guid>c764288af5c0147a988705c2e7826e28</guid>
<pubDate>Sun, 14 Sep 2025 13:48:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Conception-Reproductive-Associates-Colorado</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>45ebc3a0a5cc8cf56d46994f76529f43cbda55df54437f5ec0746308d164e7b1</i><br /><br />Threat actor <b>description</b>: <i>For over 20 years, Conceptions Reproductive Associates of Colorado has been a pillar of success and hope for patients across Colorado and around the world with clinical outcomes that meet or exceed US benchmarks.   We have a huge amount of data from this company in our hands. Medical records, patient images, customer personal data, medical records, email correspondence, photos, and more. In the event that we do not come to an agreement, all data will be published.</i><br />Target victim <b>website</b>: <i>conceptionsrepro.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Black-Butte-Coal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25613</link>
<guid>da38769133a761c1db1bf48db6e4a135</guid>
<pubDate>Sun, 14 Sep 2025 13:47:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Black-Butte-Coal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b138259b967abbd948485fee2b0d89c03ae4dc42d814f90fb74934745cf3f08</i><br /><br />Threat actor <b>description</b>: <i>Black Butte Coal Co is a company that operates in the Mining & Metals industry. It employs 101-250 people and has $25M-$50M of revenue. The company is headquartered in Point Of Rocks, Wyoming.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vicon</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25615</link>
<guid>9a469156f5e380345f69dba2862d44e0</guid>
<pubDate>Sun, 14 Sep 2025 13:47:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Vicon</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d50ca4fae50db3b4244ce64028d1c6c8705d8d471e5e036ecdab3a019460c528</i><br /><br />Threat actor <b>description</b>: <i>Vicon Industries, Inc. designs, assembles, and markets video management systems and system components for use in security, surveillance, safety, and communication applications worldwide. The companys product line comprises various video system elements, including cameras for image capture and stand-alone network video management system software, as well as various video recording, storage, management, and output devices and peripherals; analog, digital, and high definition megapixel cameras for fixed and robotic positioning applications; and other video system components, such as video encoders decoders and monitors, camera lenses, housings and mounts, matrix video switchers and controls, and various video transmission devices. Its products are used by commercial and industrial users comprising office buildings, manufacturing plants, warehouses, apartment complexes, shopping malls, and retail stores; federal, state, and local governments for national security purposes, agency facilities, prisons, and military installations; and financial institutions that include banks, clearing houses, brokerage firms, and depositories for security purposes. The companys products are also used by transportation departments for highway traffic control, and bridge and tunnel monitoring, as well as airport, subway, bus, and seaport security and surveillance; gaming casinos; health care facilities, which comprise hospitals; and institutions of education, such as schools and universities, as well as hotels and sports arenas. It sells its products primarily to independent dealers, system integrators, and security products distributors.</i><br />Target victim <b>website</b>: <i>vicon.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ramar--Paradiso</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25621</link>
<guid>f3bda8482463fdd4796e4f3880688643</guid>
<pubDate>Sun, 14 Sep 2025 13:27:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Ramar--Paradiso</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f5bbaa635bbf42b0e1244731be1772e4d0f3738d314881584766ce11b89ca5e</i><br /><br />Threat actor <b>description</b>: <i>The law firm of Ramar & Paradiso, are experts of medical malpractice defense, health care law, corporate law, contract dispute, and appeals</i><br />Target victim <b>website</b>: <i>ramarparadiso.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>West-Chester</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25622</link>
<guid>2b4bf71bc3df8c999ad2286bfe5a385f</guid>
<pubDate>Sun, 14 Sep 2025 13:26:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>West-Chester</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>823499b9eb4f2ac1e8e974eda6828e0cbac6c9f40cd7a60ede9a0edac997696c</i><br /><br />Threat actor <b>description</b>: <i>West Chester Township is the most populous township in Ohio, with a population of 65,242 according to the 2020 census</i><br />Target victim <b>website</b>: <i>westchesteroh.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Homsey-Law-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25620</link>
<guid>80088112c1b2f1ef9063e0f8ed2f9fe0</guid>
<pubDate>Sun, 14 Sep 2025 13:24:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Homsey-Law-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c8520de89ff5e94c33536cd7cca795a02d9ec48914bf2ffe77f00eec05144825</i><br /><br />Threat actor <b>description</b>: <i>Homsey Law Center are experts in personal injury law dedicated to serving Oklahoma City for the last 47 years</i><br />Target victim <b>website</b>: <i>homseylawcenter.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cheyney-University</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25623</link>
<guid>eac626340b6ff134e38fc5b7b1f14974</guid>
<pubDate>Sun, 14 Sep 2025 13:23:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Cheyney-University</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>817c50351037609b04af0b6107e9194af1a4b53f4f98fb2daddf48ffe5c9822d</i><br /><br />Threat actor <b>description</b>: <i>Cheyney University of Pennsylvania the nation’s first Historically Black College and University (HBCU)</i><br />Target victim <b>website</b>: <i>cheyney.edu</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rescue-Mission-Alliance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25626</link>
<guid>5e1fe0a89f56e5e59e057b49aae118bb</guid>
<pubDate>Sun, 14 Sep 2025 13:22:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Rescue-Mission-Alliance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce0862e613b6eb66c3bdc9867d71d2e29fe43ff03cc595db99a03c694ea2818c</i><br /><br />Threat actor <b>description</b>: <i>Pioneering Christian organization that helps people realize their potential to live beyond their limitations</i><br />Target victim <b>website</b>: <i>erescuemission.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cullen-Haskins-Nicholson--Menchetti</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25627</link>
<guid>8845ac2b3647d7e9dbad5e7dd7474281</guid>
<pubDate>Sun, 14 Sep 2025 13:21:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Cullen-Haskins-Nicholson--Menchetti</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f39ca6debff4ea014c22bcf6af9c43371c583bf8f3d79a213f455aa1d249004c</i><br /><br />Threat actor <b>description</b>: <i>The firm represente injured workers in Illinois state compensation cases</i><br />Target victim <b>website</b>: <i>chnm-law.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Beaumont-Bone--Joint-Institute</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25625</link>
<guid>0a8e9d1cf3ee0af0e6526059e1ac59d1</guid>
<pubDate>Sun, 14 Sep 2025 13:20:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Beaumont-Bone--Joint-Institute</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4469b941a2992f73937e8c245d332a32c25f10b14622a7bb7d5d3e6dfe70d2fd</i><br /><br />Threat actor <b>description</b>: <i>A trusted leader in orthopedic care with over 300 years of combined experience</i><br />Target victim <b>website</b>: <i>beaumontbone.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>US-Graphite</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25624</link>
<guid>69fc366f1a0ccb6967c128510f26854e</guid>
<pubDate>Sun, 14 Sep 2025 13:19:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>US-Graphite</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30658cc6168507ae1d453bd6567344f23b81eda2efb7f4cc5493a67c99835034</i><br /><br />Threat actor <b>description</b>: <i>Specialists in carbon and graphite engineering solutions</i><br />Target victim <b>website</b>: <i>us-graphite.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Expert-MRI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25628</link>
<guid>4421113f38b3ce3467c194394e8ca46c</guid>
<pubDate>Sun, 14 Sep 2025 13:18:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Expert-MRI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b830f49c20f9d7a645bdb4661088b6f31d9d7b087a97bcce82a5e563caeebc66</i><br /><br />Threat actor <b>description</b>: <i>Pioneers in Cutting-Edge Imaging for Brain, Neck, Spine Injuries, and Orthopedic Excellence</i><br />Target victim <b>website</b>: <i>expertmri.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Next-Level-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25630</link>
<guid>01b0d1b5a3812eded622df653d3cd482</guid>
<pubDate>Sun, 14 Sep 2025 13:17:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Next-Level-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9ef446c2a1eeb02fe1a673987dbee05a00b7f9a8451d9ec554345b981fe4998b</i><br /><br />Threat actor <b>description</b>: <i>Partners with companies to provide accounting, human resources and technology deployment services</i><br />Target victim <b>website</b>: <i>nextlevelsol.net</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reynolds--Reynolds</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25629</link>
<guid>59f09348ac59397302394ffcd5d9eb9a</guid>
<pubDate>Sun, 14 Sep 2025 13:16:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Reynolds--Reynolds</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc8975bbe5ab9e6acf4a325a4261d5e05e679bf0c7bb37ac42a4f4b3f4a96039</i><br /><br />Threat actor <b>description</b>: <i>Leading provider of automotive retailing solutions that help manage and improve dealership</i><br />Target victim <b>website</b>: <i>reyrey.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cleveland-City-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25602</link>
<guid>2cd39cf1b560c1eef41a7cebffc64b75</guid>
<pubDate>Sun, 14 Sep 2025 12:19:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Cleveland-City-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca32d286a81ca78b26d7a49eee14331b538782bcaf11cb47d97d094958e07ff7</i><br /><br />Threat actor <b>description</b>: <i>Cleveland City Schools offers educational and employment opportunities without regard to race, color, creed, national origin, religion, sex, age, or disability and adheres to the provisions of the Family Education Rights and Privacy Act (FERPA).</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>halbarstainless.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25596</link>
<guid>8cfedff86a61fa80c0836728161963ff</guid>
<pubDate>Fri, 12 Sep 2025 19:07:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>halbarstainless.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1017ebd5f0c89ad479effefadf8a0c608ef949f880373690e1e80cd9a745e71c</i><br /><br />Threat actor <b>description</b>: <i>Halbar Stainless Products Ltd., founded in 1974 by Cliff Baird, is a family-owned custom metal fabrication company specializing in stainless …</i><br />Target victim <b>website</b>: <i>halbarstainless.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>TimHaahs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25592</link>
<guid>0ef63386fdcb3dc2c2914b319668ff81</guid>
<pubDate>Fri, 12 Sep 2025 18:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TimHaahs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f34c3f0bb0679a8f2ab6792b7c91664bd086a42803640a2e4e48aa3bb30b894a</i><br /><br />Threat actor <b>description</b>: <i>THA Consulting is a DBE and W/MBE certified company that specializes in planning, design, and consultation services.We are going to upload 66GB of corporate data. Employees' personal documents (Passports, medical certificates, credit cards details), confidentiality agreements, payment details, finance and accounting files, clients information, projects, NDA etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>cityofmiddletown.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25594</link>
<guid>ad00ad125782c8dfc70a6c8e18b82792</guid>
<pubDate>Fri, 12 Sep 2025 17:36:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>cityofmiddletown.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90af66282db8bea5bb723e89d68201a02c08bc5155bb79408766748eb0cda810</i><br /><br />Threat actor <b>description</b>: <i>The City of Middletown, located in Ohio, United States, operates as a municipal government dedicated to providing essential services and …</i><br />Target victim <b>website</b>: <i>cityofmiddletown.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>osdcourtks.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25593</link>
<guid>0006dd05ea1e999ddaa041a7091b7b36</guid>
<pubDate>Fri, 12 Sep 2025 17:35:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>osdcourtks.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>04f88b2df5bd87c866381473a8e982eb9dd121d984fc045f5e72dfdd2cb1560d</i><br /><br />Threat actor <b>description</b>: <i>The domain osdcourtks.org appears to belong to the Osage County District Court in Kansas. As part of Kansas’s Fourth Judicial …</i><br />Target victim <b>website</b>: <i>osdcourtks.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>denali-industrial.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25591</link>
<guid>ab4981fb59db07f87db4b1a7a2e9efcf</guid>
<pubDate>Fri, 12 Sep 2025 16:26:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>denali-industrial.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38cd30bca044da8477d075f6536527510782ae2d0da33a541f74d6bf79761796</i><br /><br />Threat actor <b>description</b>: <i>Denali Industrial Supply - a knockout blow to its reputation. For 35 years, Denali Industrial Supply has been a supplier of high-quality industrial tools, fasteners, and accessories in Alaska. They work with many well-known manufacturers, inc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aluf-Plastics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25586</link>
<guid>872338a783596365d7fc8d44214be720</guid>
<pubDate>Fri, 12 Sep 2025 15:27:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Aluf-Plastics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a9fcd13583d0afaf7c05cc7f4dbbf20f473189e7ad22a1e8c15ecc826ddea599</i><br /><br />Threat actor <b>description</b>: <i>Aluf Plastics is a prominent manufacturer and distributor of high-quality plastic products, specializing in trash bags, can liners, sheeting, and poly bags.We are going to upload 40GB of corporate data. Employees' personal information (Full personal info: address, phone, passport information, medical information, credit cards), confidentiality agreements, finance and accounting files, clients and customers information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>PYATOK</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25587</link>
<guid>2b3aa41ec493d9908c56dcd665d08d22</guid>
<pubDate>Fri, 12 Sep 2025 15:27:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>PYATOK</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d6489d899829a6249bdeca7148166b8b73c2a0e1dc3719692f3491eaa978986</i><br /><br />Threat actor <b>description</b>: <i>PYATOK works to foster the development of vibrant, sustainable, inclusive communities through sensitive architecture and urban design, rigorous research and education, exemplary service and technical innovation, and thoughtful advocacy.We are going to upload 30GB of corporate data. Employees' personal information (USCIS forms with full info, medical information, credit cards), confidentiality agreements, payment details, finance and accounting files, clients information, projects, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brownstone-Agency</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25588</link>
<guid>f83d13844fb3dadd32223756dd132261</guid>
<pubDate>Fri, 12 Sep 2025 14:27:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Brownstone-Agency</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9b5c24d827fabd38b4a9f613e2a9821f37c53ef88e61e8076582f696f048fa71</i><br /><br />Threat actor <b>description</b>: <i>Brownstone Agency, Inc. offers a range of insurance products including property and general liability coverage, specifically tailored for brownstones, row houses, condominiums, and multi-family dwellings.We are going to upload 10GB of corporate data. Employee documents(Full name, DOB, addresses, zip and so on), lots of confidentialagreements, detailed finance and accounting files, lots of clients and customers information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mazza-Recycling-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25589</link>
<guid>3f4a917da8640f243cd5e5c2d66a99c6</guid>
<pubDate>Fri, 12 Sep 2025 14:27:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mazza-Recycling-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c05cbe495fe4279dadeab6e4925071972291605ed8394b605d9edf2775452293</i><br /><br />Threat actor <b>description</b>: <i>Mazza Recycling Services is a leading waste recycling company based in New Jersey, specializing in innovative waste recycling solutions for residential, commercial, and industrial clients.We are going to upload 27GB of corporate data. They didn't even try to protect their employees' personal information (Full name, DOB, addresses, zip, DLs of at least 69 employees, SSNs, medical insurance policies and so on), confidentiality agreements, financeand accounting files, clients and customers information, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Survival-Flight-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25584</link>
<guid>33cbad177e0a2ab6b93c92124826f407</guid>
<pubDate>Fri, 12 Sep 2025 11:26:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Survival-Flight-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>818600001bded5aea2a97e7159e17eb39e92439c9b9de95e3e82670cbcd971e1</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Meskan-Foundry</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25590</link>
<guid>f220707c3afe39d1779e0a34af72bb7f</guid>
<pubDate>Fri, 12 Sep 2025 10:49:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Meskan-Foundry</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6b388b0b754364448d866df2cf898ab933110bdfc83a360823b2946fed844a2f</i><br /><br />Threat actor <b>description</b>: <i>Meskan Foundry is a 5th generation, family owned, non-ferrous casting facility in Chicago since 1907. With over 200 combined years of foundry knowledge and experience passed down from generation to generation, you can be assured that the castings you receive from us are the best in the industry. We are a full service foundry, capable of handling all secondary operations to provide our customers with finished castings.</i><br />Target victim <b>website</b>: <i>www.meskan.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>TAKwest</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25583</link>
<guid>6e18b12a82c40871803b88fa42cc1a20</guid>
<pubDate>Fri, 12 Sep 2025 02:27:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>TAKwest</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d995237f1aae3e9e9dd11acb7b2e846ca3452c00ebefaa2aceccbb8e7b1c81af</i><br /><br />Threat actor <b>description</b>: <i>Broadband data leak. Those who provide access to new digital opportunities have failed to ensure their own cybersecurity. TAK West Shore is a subsidiary of TAK Broadband. They offer comprehensive service solutions in the field of fiber optic             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northwest-Medical-Specialties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25578</link>
<guid>c566177f38627e45e5a79dbf1dd187ca</guid>
<pubDate>Thu, 11 Sep 2025 19:28:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Northwest-Medical-Specialties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a88af93eb6ef332652647c7f2b2fd871b7ede3d303fa806728c53c5fc206cc8a</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>STANDARD-IRON--WIREWORKS-Helgesen-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25573</link>
<guid>15d4408a4d391c3fb8344af099a4a051</guid>
<pubDate>Thu, 11 Sep 2025 16:28:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>STANDARD-IRON--WIREWORKS-Helgesen-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41adf6395af6c98dfd6563abb6c95b4b672da188128abec35a57bc2f5ad4e44b</i><br /><br />Threat actor <b>description</b>: <i>STANDARD IRON & WIRE WORKS manufactures products in two distinct divisions. Contract Manufacturing fabricates, assembles and paints heavy-duty products for blue-chip original equipment manufacturers (OEMs) across numerous end markets including, agriculture, construction, power generation, industrial HVAC, among others.We are going to upload 40GB of corporate data. Employee data (SSNs, driver licenses, medical files and so on), finance and accounting files, payment details, customer information, contract and agreements, confidentiality agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fluxergy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25574</link>
<guid>da502cff136c2848905d8c0e169ba278</guid>
<pubDate>Thu, 11 Sep 2025 16:28:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Fluxergy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b23d1f6231b1bf16c45d2376b4c40881631c5d74399d09063059e1e96fb72609</i><br /><br />Threat actor <b>description</b>: <i>Fluxergy is developing a platform with multi-modal detection technologies which bring the variety of tests found in the central laboratory.We are going to upload 16GB of corporate data. Detailed employee data (lots of personal documents: SSNs, driver licenses, passports and so on), detailed finance and accounting files including confidential ones, lots of customer information, contract and agreements, confidentiality agreements, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Molod-Spitz--DeSantis</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25575</link>
<guid>e5299a3f17ebbcce23d7a8c90adf81cc</guid>
<pubDate>Thu, 11 Sep 2025 16:28:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Molod-Spitz--DeSantis</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0cb65db84519af3a9e60c718c994ed7bd2e207892d760ddef7f51e5ae9cd55ca</i><br /><br />Threat actor <b>description</b>: <i>Molod Spitz & DeSantis, P.C. specializes in defending clients in complex liability matters in New York and New Jersey courts. The firm prides itself on being trial-ready, with a long record of successful verdicts and a commitment to tracking metrics that reflect their results. We are going to upload 62GB of corporate data. Employee documents, medical information, confidential agreements, lots of customersinformation, detailed finance and accounting files, lots of clients information, contract and agreements with customers, police reports, investigations, court hearings, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TDK-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25576</link>
<guid>016dda407fff9ed48128da45058b0366</guid>
<pubDate>Thu, 11 Sep 2025 16:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TDK-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e927b34cc5254264418fd23bea7643b14b5ae2936e68387dc4a66b5f15c71e03</i><br /><br />Threat actor <b>description</b>: <i>TDK Technologies provides information technology consulting and custom software development for businesses through either staff augmentation or outsourced project solution delivery.We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), employees and customers information (passports, driver's license, SSN ) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Communicare-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25571</link>
<guid>87a57c9dce29e600b772912ff1c4c1c7</guid>
<pubDate>Thu, 11 Sep 2025 09:55:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>daixin</b> claims attack for <b>Communicare-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5d6978615b3fb4fa0d9c64c6da0796b60b88225e2c7cbeb3758d7b87918fb0f3</i><br /><br />Threat actor <b>description</b>: <i>Communicare, Inc. has been a premier provider of behavioral health services in Kentucky's heartland since 1967.</i><br />Target victim <b>website</b>: <i>communicare.org</i>]]></description>
<category>daixin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Insurance-Office-of-America</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25570</link>
<guid>70b546d3daac16b1d8a1fc46e6d63a72</guid>
<pubDate>Thu, 11 Sep 2025 09:54:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>daixin</b> claims attack for <b>Insurance-Office-of-America</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ad38c9d93149431603f9a25740ff4c7ce046c8c2ffe5500fb9cc4da21f2e4a7</i><br /><br />Threat actor <b>description</b>: <i>Insurance Office of America (IOA) is a premier, full-service insurance agency dedicated to delivering bespoke insurance solutions since 1988. We’re one of the USA’s fastest-growing agencies.</i><br />Target victim <b>website</b>: <i>ioausa.com</i>]]></description>
<category>daixin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gagosian</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25569</link>
<guid>ebe4361baf7318a92facaec817c6d0d9</guid>
<pubDate>Thu, 11 Sep 2025 09:54:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>daixin</b> claims attack for <b>Gagosian</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>326aeb8bd69176fc1249b386ee6ed21772c59248f67034cf60c0e076cf629a27</i><br /><br />Threat actor <b>description</b>: <i>Established by Larry Gagosian in Los Angeles in 1980, Gagosian is a global gallery specializing in modern and contemporary art that employs more than three hundred people at eighteen exhibition spaces across the United States, Europe, and Asia.</i><br />Target victim <b>website</b>: <i>gagosian.com</i>]]></description>
<category>daixin</category>
</item>
<item xmlns:dc='ns:1'>
<title>moinian.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25568</link>
<guid>07b6b142463f773e941206c21967edb1</guid>
<pubDate>Thu, 11 Sep 2025 09:48:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>abyss</b> claims attack for <b>moinian.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dd086e4cdd34b78f17fe5b95a79a688badde4638a713e37bff6c1610ae31880</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1982, The Moinian Group is a privately held real estate investment company focusing in New York City commercial, residential, and hospitality properties.</i><br />Target victim <b>website</b>: <i>moinian.com</i>]]></description>
<category>abyss</category>
</item>
<item xmlns:dc='ns:1'>
<title>deerfield.com--singulargenomics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25567</link>
<guid>bd38184ee56f9f286f9a4e649a740e42</guid>
<pubDate>Thu, 11 Sep 2025 05:22:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>deerfield.com--singulargenomics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4de7b0aa676e5fbb53061ae58db139806346647cf4bd5957339d41881b4bf77</i><br /><br />Threat actor <b>description</b>: <i>================================================================================================ deerfield.com  Deerfield Management ("Deerfield") is an American investment firm headquartered in New York City. It is focused on making public and private investments in the healthcare and biotechnology industries. Deerfield is considered to be one of the largest dedicated healthcare investment firms in the world. ================================================================================================ We hacked and compromised one of the many laboratories belonging to Deerfield: ================================================================================================ www.singulargenomics.com  A Singular Focus on Advancing Science and Medicine Our aim is to empower scientists to answer their most pressing questions, allowing them to forge a path of discovery without limits. Our commitment is to serve the scientific community through continuous and thoughful genomic innovation that's driven by real-world feedback and solution-oriented development. ================================================================================================  We downloaded about 20 TERABYTES of data from servers and Amazon storage. Including experiments, software sources, AI data, as well as research for the company's clients - fox chase, GeneDX, Juno, lexogen, HARVARD, siemens, and many others. Soon, anyone who wants and understands the issue will have the opportunity to study in detail the activities, research and experiments of this company. And to see who and why they are conducting their experiments in the field of gene engineering. Maybe it will become clearer why Deerfield is buying up pharmaceutical laboratories and what they want to achieve in the end. What do gene laboratories and government universities have in common? Everyone will soon be able to discover a lot of questions. ================================================================================================</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Encore-Leisure-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25562</link>
<guid>059def4514ca1bc7ff5781ac48428572</guid>
<pubDate>Thu, 11 Sep 2025 02:26:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>Encore-Leisure-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7117b48c714ad91656dfe1c73d0906188e303889fb2498d110d74a540f854f23</i><br /><br />Threat actor <b>description</b>: <i>Encore Leisure Group
 Founded by Dale Folmar and Jacques James, was formed to ma...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spectra-Logic</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25561</link>
<guid>bd652bf1e9b66171ef77f1e0db2e9c1e</guid>
<pubDate>Wed, 10 Sep 2025 23:27:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Spectra-Logic</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4bd8e9e7c15b5cbe2a4566ce8fa29f6fe6caa98c80e1f4ffa23f69973dfc6cf9</i><br /><br />Threat actor <b>description</b>: <i>Spectra Logic, USA - data protection and storage company LMAOOOAHHAHA I'm dead!!! Sorry, but this is really funny. PROTECTION! STORAGE! DATA!!!! On our blog, yes. So, Spectra Logic helps organizations manage, migrate, store and preserve busin            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>waverlychildcare.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25566</link>
<guid>54e86f8a9dd94e31f18fe3bc94f0ae75</guid>
<pubDate>Wed, 10 Sep 2025 19:09:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>waverlychildcare.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d7340adeb9ff955ce8e75f7c648a50f8eb568cdac683521b8a0e396e76cad80</i><br /><br />Threat actor <b>description</b>: <i>Waverly Child Care & Preschool is a nonprofit early childhood education provider based in Waverly, Iowa, established in 1970. It …</i><br />Target victim <b>website</b>: <i>waverlychildcare.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>RG-ELECTRIC-COMPANY-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25564</link>
<guid>d2f8a028891ab3c7e90238798117e99d</guid>
<pubDate>Wed, 10 Sep 2025 17:17:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>RG-ELECTRIC-COMPANY-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>59373cceb7e31eecc47d832e8ef77e5c5e067de25383ba0d71621d09f413f57d</i><br /><br />Threat actor <b>description</b>: <i>R. G. Electric Company, Incorporated, a Virginia-based electrical contractor founded in 1980. Around ~500GB of confidential data. The leak of internal company documents contains a huge variety of personal documents and information of clients, employees private data, private contacts, confidential contracts, confidential projects, orders, IDs, SSN, email conversations. Bank documents: statements, balances, Tax bills, signatures, checks. Video - https://streamable.com/4wn1jk , screenshots - https://imgur.com/a/Er9J1Kp, all contacts - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/RGELECTRIC_part2/dataRobert%20G%20Dashiel/contacts.csv</i><br />Target victim <b>website</b>: <i>rgelectric.com</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>ROBERT-G.-DASHIELL-JR.-P.E.-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25565</link>
<guid>05b755ace5b49029e32c3b90fb494edc</guid>
<pubDate>Wed, 10 Sep 2025 17:16:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>radar</b> claims attack for <b>ROBERT-G.-DASHIELL-JR.-P.E.-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>771991b73a58d178037cff524696945d800840549d8b9301efc777ec32567615</i><br /><br />Threat actor <b>description</b>: <i>Robert G Dashiell Jr PE Inc is a reputable engineering firm based in Norfolk, VA, specializing in providing professional engineering services. Around ~500GB of confidential data. The leak of internal company documents contains a huge variety of personal documents and information of clients, employees private data, private contacts, confidential contracts, confidential projects, orders, IDs, SSN, email conversations. Bank documents: statements, balances, Tax bills, signatures, checks. Video - https://streamable.com/4wn1jk , screenshots - https://imgur.com/a/Er9J1Kp, all contacts - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/RGELECTRIC_part2/dataRobert%20G%20Dashiel/contacts.csv</i><br />Target victim <b>website</b>: <i>rggroup.net</i>]]></description>
<category>radar</category>
</item>
<item xmlns:dc='ns:1'>
<title>1-ACT-Driving-Schools</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25558</link>
<guid>7d571ef48d7c44ec949687e28abcdf30</guid>
<pubDate>Wed, 10 Sep 2025 16:49:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>1-ACT-Driving-Schools</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99701a85cb91517ed1da3b3483205722b603f543f371ffe7633c186a5af2fa0a</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>1statlantaduischool.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>BFLI</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25557</link>
<guid>4b6f0a34fce7b7679d959111f4875948</guid>
<pubDate>Wed, 10 Sep 2025 15:43:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>BFLI</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47de0a9f1030975fd8add80330ddab6e37d318096be8ce3c03024388df4431aa</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>betterfamilylife.org</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Docklyne</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25556</link>
<guid>9fd54dd7e4d3bff4807c83c241e2751c</guid>
<pubDate>Wed, 10 Sep 2025 15:42:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Docklyne</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>379f7b2d70b4b79d5b2032e43006959abba1096817f84b90d3c05c2f3161832c</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>docklyne.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Northland-Auto-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25550</link>
<guid>24bb26bb300eefd5ecd1373e002d8df5</guid>
<pubDate>Wed, 10 Sep 2025 14:43:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>Northland-Auto-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ac6b34332a788d86279d70629ca76a65df50ad189c8b19e9725f3271202957d</i><br /><br />Threat actor <b>description</b>: <i>Our Company—Over 30 years of Success and LeadershipNorthland Auto Solutions is proud to be your preferred dealership solutions and insurance services provider. Founded in 1990 by Executive Director Allen Lentsch, we provide dealers with programs to support used car leasing, daily rentals, and all your dealership’s insurance needs. Northland is also known for ancillary products such as bonds, dealer supplies and GPS devices.The real surprise you’ll find in doing business with us is that we are approachable, knowledgeable, and share our experiences in ways that you can understand, learn from, and follow.- Database- Financial documents- Personal information of employees and clients https://northlandautosolutions.com/</i><br />Target victim <b>website</b>: <i>northlandautosolutions.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Accelerated-Academy</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25555</link>
<guid>aea9789988c08f28538422f1c3427388</guid>
<pubDate>Wed, 10 Sep 2025 14:16:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Accelerated-Academy</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cbaf4a0ba2539e25728bcab1bbc49f71158153ca9ab20c7057292a43411ef1aa</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>acceleratedacademy.us</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Commercial-Casework</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25551</link>
<guid>b4aa16d8d291bc9eef7d9eccc6567683</guid>
<pubDate>Wed, 10 Sep 2025 13:18:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Commercial-Casework</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8a3b1baf81d362ecc1bb0459ba2acb7bdcf96ecd6f5e084ace50dd1fe9c9ef0e</i><br /><br />Threat actor <b>description</b>: <i>Commercial Casework Inc. has been a leading provider of custom ar
chitectural woodwork and cabinetry in Northern California since 1
976, situated in the San Francisco Bay Area. The company speciali
zes in high-end tenant improvements for various commercial spaces
, including Board Rooms, Cafes, and Reception Areas. 

We are going to upload 12GB of corporate data. A lot of hr data, 
medical information, accounting files, payment details, client in
formation, project information, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Venezia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25552</link>
<guid>221d772de257c968c2c15b9155d436ab</guid>
<pubDate>Wed, 10 Sep 2025 13:17:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Venezia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f4fac5e4826e157e43e519d0efe466b24157591b7f2af6c471e5bb0e0544acd5</i><br /><br />Threat actor <b>description</b>: <i>Venezia, headquartered in Limerick, PA, provides high quality tra
nsport & trucking services for the Liquid, Dry Bulk & Specialty c
ommodities transportation industry to 48 states and Canada.

We are going to upload 35GB of corporate data. Employee data (DOB
, addresses, phones, emails, medical certificates, passports, dri
ver licenses and so on), finance and accounting files, payment de
tails, client information, project information, NDAs, etc.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>HD-Media-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25544</link>
<guid>96045cb4b220959781bbbff6f5367268</guid>
<pubDate>Tue, 09 Sep 2025 22:47:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>HD-Media-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7836e70c0992d921e0fd1c3f4d8182acccb3840a1e1855a946c3079dbfce67ba</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.hd-mediasystems.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mayors-Machine-Works</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25543</link>
<guid>7514b3e0aba63c1dc6d14618f0d1f386</guid>
<pubDate>Tue, 09 Sep 2025 22:46:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Mayors-Machine-Works</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dd197236722a8d881bfbb5558a1be1776d1bb5532cdd9182e991984040ce3e2</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mayorsmachine.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>JIT-Energy-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25542</link>
<guid>d7445d18d5c5ab0ce2bbd3bc67c8d9f3</guid>
<pubDate>Tue, 09 Sep 2025 22:45:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>JIT-Energy-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76666ea4d9a57f3058edf163d29b3f694c0ef0b1f98d55714b246b2a88b0a1be</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jitservicesinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anderson-Aluminum</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25541</link>
<guid>7377f47f95a1202ea8d330061b674dea</guid>
<pubDate>Tue, 09 Sep 2025 22:44:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Anderson-Aluminum</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bb2c792f399222e785cef2aeeb27f9eef03ee7ea90d514956de92a5a92564e94</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.andersoncompanies.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Royal-Machine--Tool</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25540</link>
<guid>6ae87b539605df13856d273cca0da569</guid>
<pubDate>Tue, 09 Sep 2025 22:44:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Royal-Machine--Tool</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f58c75e4241b29e474f3ac44e94cda12aa9f99061360053c1ee54daff5db6172</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.royalworkholding.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Reliable-Roofing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25539</link>
<guid>5683495c01530bccb72168dc75a983f1</guid>
<pubDate>Tue, 09 Sep 2025 22:43:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Reliable-Roofing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b728ac91d5cd21357be3c6ec1bf79985312e6b95bdac7a9733ded3b4bdbe896f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.reliableroofing.biz</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Celtic-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25538</link>
<guid>90a8d5aeed9822b634a21d1d5a2543c9</guid>
<pubDate>Tue, 09 Sep 2025 22:42:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Celtic-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>804f1c37dbea4a1c8744fdc5a7ac12215d605edffb57802a8a9b829fd93f4b35</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.celticengineering.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>GDZ-Computer-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25530</link>
<guid>e6258b956c06d8dbabbde10d4919e5ef</guid>
<pubDate>Tue, 09 Sep 2025 22:42:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GDZ-Computer-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d15db66b85e79842a462ff70ad6e2bb22845633cff48caf3ed9b3ecc12e3009d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gdz.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cool-Wind-Ventilation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25537</link>
<guid>688141bcde5012d86f76663a425ff07d</guid>
<pubDate>Tue, 09 Sep 2025 22:41:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Cool-Wind-Ventilation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0ea6a3f7c43a34cd954b9f35b04d4ffb734683ab43b37d716e253a3ee547cf07</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.coolwind.biz</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rising-Star-Hydraulics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25536</link>
<guid>3ae84dcbd2cfadb3fdd4d58dbaa386ef</guid>
<pubDate>Tue, 09 Sep 2025 22:40:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Rising-Star-Hydraulics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6c4f3cf92e440cd92278724b318ad2956424adb228fdb1dda94418b61693df5e</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.risingstarhyd.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edwards-Interiors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25535</link>
<guid>68f4f1c9069efc3169ccef543fc9b706</guid>
<pubDate>Tue, 09 Sep 2025 22:40:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Edwards-Interiors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07a418ce418e77f6bec868b644404d121191f48f9df763249a48a1209ebe03fa</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.eiiaerospace.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>GL-Veneer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25534</link>
<guid>f50118652ac9772880a8fe2822522f8f</guid>
<pubDate>Tue, 09 Sep 2025 22:39:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>GL-Veneer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fef9b694d2a835c12c68bda2bca7c78e7306c58b6e2dea3eb2d122ad05a2b19d</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.glveneer.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Allegis-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25533</link>
<guid>5b48cf6d948c70034f7a239f8e5c566d</guid>
<pubDate>Tue, 09 Sep 2025 22:13:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Allegis-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5ec66afce0f79b9f9849eab0022a597f38b70db840a33e9a86cf42079bebb123</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Allegis Group is a privately-held global talent solutions provider. The company offers a wide range of services, such as staffing and recruitment, workforce management, and talent advisory. Their expertise includes IT & communications, aerospace, biopharmaceuticals, energy, financial services, and more. Allegis was founded in 1983 and has its headquarters in Hanover, Maryland, USA.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aupaircare-and-Intraxinc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25532</link>
<guid>c56b7becfe4383d3ef77d68c78a5d2bd</guid>
<pubDate>Tue, 09 Sep 2025 22:13:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Aupaircare-and-Intraxinc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e434ecf60292b83e2ed3c294db9bea6f9dd91b28f129249098078c2f31946218</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] AuPairCare and Intrax Inc. are sister companies. AuPairCare is a leading au pair agency providing live-in childcare services to American families in over 40 states. It pairs host families with international young adults who provide up to 45 hours of childcare each week. Intrax Inc. on the other hand, is a globally-oriented company providing a variety of educational and cultural exchange programs, including work and internship, teaching, and language learning opportunities.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>ES-Food</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25506</link>
<guid>c913d53b4c55ee20acb97bad39c38458</guid>
<pubDate>Tue, 09 Sep 2025 20:26:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ES-Food</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>89b798624c26b20b2ddc447debce5650f583a4603f25a39cf4334138c3a6b5bf</i><br /><br />Threat actor <b>description</b>: <i>E&S Food, Inc., was started in 1980 by Settimo Guttilla, selling grated cheese from his car and his first warehouse was his garage. Now utilizing a warehouse over 50,000 square feet, E&S has over3,000 products, and the company employs over 50 employees.We are going to upload 190GB of corporate data. A lot of financial and accounting data, credit card details, personal information of employees, client information, a bit of client data, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kandeo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25525</link>
<guid>86a9d09856a0f9f7a762ddce0af753ce</guid>
<pubDate>Tue, 09 Sep 2025 16:03:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Kandeo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a4371e88c307d6f99c5208079a9e8d38571ea604af7c85be291339d15417e9e</i><br /><br />Threat actor <b>description</b>: <i>www.kandeofund.com , https://diaphanum.pe/ , https://www.zoominfo.com/c/kandeo/355444055 Kandeo is focused on providing innovative solutions to enhance growth for businesses. Their product offerings are designed to empower companies to achieve brilliance in their operations. The intended clients range from small startups to large corporations seeking to optimize their business strategies. By leveraging advanced technologies, Kandeo aims to drive success and foster sustainable development.</i><br />Target victim <b>website</b>: <i>www.kandeofund.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wharton-Independent</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25502</link>
<guid>bdbe575de5ecbc20be758c6f4e105da6</guid>
<pubDate>Tue, 09 Sep 2025 15:57:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>Wharton-Independent</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>029815c3454d4e864ae5dd9b34334752c91e126edd1a7aba72cdae10c2e2a6e7</i><br /><br />Threat actor <b>description</b>: <i>www.whartonisd.net , www.zoominfo.com/c/wharton-independent-school-district/213188688 Wharton Independent School District provides educational services to a diverse student population, aiming to prepare every student for success in a global society. The district offers a wide range of programs including athletics, special education, and vocational training. Targeting students from elementary through high school. Wharton ISD also emphasizes parental and community engagement in the educational process. Additionally, it provides resources and support for both students and staff across its various departments</i><br />Target victim <b>website</b>: <i>www.whartonisd.net</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>InjectSense</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25497</link>
<guid>bfaadb09eb2d1eb21b7b5f1eac3ea902</guid>
<pubDate>Tue, 09 Sep 2025 15:52:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>InjectSense</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>830eebc1912689100f9c499705b338c28e8212e438cfa2836dbc2e19b44ab7d1</i><br /><br />Threat actor <b>description</b>: <i>https://www.zoominfo.com/c/injectsense-inc/406591024 https://www.injectsense.com/ Injectsense specializes in ultra-miniature implantable sensors designed for digital health applications. Their self-anchoring platforms continuously measure health parameters such as absolute pressure and oxygenation, providing doctors with vital 24/7 health insights. The company combines expertise in semiconductor and medical systems, ensuring their devices are supply chain-ready and utilize advanced miniaturization technology. Their target clients include physicians seeking to improve patient care through autonomous sensing and actionable data.</i><br />Target victim <b>website</b>: <i>www.zoominfo.com</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>J.V.D.B.--Associates-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25515</link>
<guid>788719cc45ba3937014fad2961c6d27b</guid>
<pubDate>Tue, 09 Sep 2025 15:45:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>thegentlemen</b> claims attack for <b>J.V.D.B.--Associates-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bae2b4626a270b49ada162d5960182be08962ecdd3c77c6aba97efceb14e214</i><br /><br />Threat actor <b>description</b>: <i>[J. V. D. B. & Associates, Inc. is an Illinois collection agency. Illinois collection agencies can help businesses, medical practices and facilities that are creditors to collect their accounts receivable. Debt collection help might include; collection demand letters, debt collector phone calls, credit reporting to credit bureaus and legal proceedings including lawsuits.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>thegentlemen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Energy-Fishing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25489</link>
<guid>063b7d7ae9cd5ea74e1f879c52a91917</guid>
<pubDate>Mon, 08 Sep 2025 23:40:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Energy-Fishing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cbc1b0452a5f006175aa3cb14d0f53707caeb19ae457a7a935c2ebdcc358e269</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.energyfrs.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>BDE-Computer-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25488</link>
<guid>ea5b254610d3af85fb861cc7be787ad5</guid>
<pubDate>Mon, 08 Sep 2025 23:39:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>BDE-Computer-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>95c8e600b154fec3db5eb92a07e015a87b81010651d5bf39b2f632cbfc3c1ba3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bdecomputer.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Promark-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25487</link>
<guid>8648eaae8f6cd2dbd737201ba9708a34</guid>
<pubDate>Mon, 08 Sep 2025 23:39:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Promark-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b39a71456794894043844ded8fa25d741a41a928a6e7109237c3c2c0e3963cd</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.promarkpartners.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Melwood</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25486</link>
<guid>e61f7911ee778def6a5aade05bbe9ca1</guid>
<pubDate>Mon, 08 Sep 2025 20:44:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Melwood</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7e307aa20197bddca4393d410552e46500ef264db27f44f3e14c09f72e4bd497</i><br /><br />Threat actor <b>description</b>: <i>Melwood is a family of companies with a shared vision of a world where people with disabilities are fully included. Melwood comprises three primary companies—Melwood Enterprises, Melwood Community Services, and Melwood Inc.—together serving as one of the nation’s leading advocates, service providers, and employers of people with disabilities and their caregivers. They offer employment, job placement, job training, life skills for independence, support services, and youth and community recreational services to more than 3,000 people each year in D.C., Maryland, and Virginia.</i><br />Target victim <b>website</b>: <i>www.melwood.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bounds-Gillespie-Killebrew-Tushek-Architects</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25481</link>
<guid>f1ce94556e4edc2c15a463ca093a05bc</guid>
<pubDate>Mon, 08 Sep 2025 18:33:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>Bounds-Gillespie-Killebrew-Tushek-Architects</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>602013c87446e393a92a2c0b3db1e9b315c08b919034cf5bb633a37a93f12ac1</i><br /><br />Threat actor <b>description</b>: <i>BGKT Architects a new company has emerged out of a longstanding partnership betw...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>General-Converting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25475</link>
<guid>1c7640494d7b763e2f1521e08075cf61</guid>
<pubDate>Mon, 08 Sep 2025 17:30:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>General-Converting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae476122f266c6482d56ff5a01559f07a766386479ccfea5b76053e60a97cb65</i><br /><br />Threat actor <b>description</b>: <i>General Converting, Inc. was founded in 1982 and was comprised then of three people, a 1 color press, a small die cutter, and a gluer. Today, the thriving GCI remains an independent company and now employs a staff of 65 people, most of whom have been with the company for 10 years and longer. We are going to upload 138 GB of corporate data. Employee personal information (name, DOB and is on), detailed financial data, confidential agreements, lots of customer files, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>RBJ-Escrow-Software</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25476</link>
<guid>b8727981b7f3d46b51d5b6770632e453</guid>
<pubDate>Mon, 08 Sep 2025 17:30:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RBJ-Escrow-Software</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>67ee0bec843696fb3378f7e5db08d48f1102056c394af2c5879abb4e32b82508</i><br /><br />Threat actor <b>description</b>: <i>RBJ Escrow Software leverages 35 years of California escrow experience to provide advanced software solutions for escrow processing, title production, and trust accounting.We are going to upload 20GB of corporate data. A a lot of client data, HR files, detailed financial and accounting data, lots of files with personal data of employees, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>runaces.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25478</link>
<guid>020ea2e7e3f2cec1ca4af57682211297</guid>
<pubDate>Mon, 08 Sep 2025 16:30:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>runaces.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>66221c36ed85a7cd954438ecd1c4f243a3d8890bde8b63817670ec474087b145</i><br /><br />Threat actor <b>description</b>: <i>Finished the game. Running Aces -you're playing a losing hand.The Running Aces Casino and Racetrack opened in Columbus, Minnesota, in April 2008. Things did not go well from the start. In its first year of operation, the racetrack lost $4 mil            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>rose-acre-farms-inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25469</link>
<guid>b575e1f659c7d47f3fd50cc248891ecf</guid>
<pubDate>Sun, 07 Sep 2025 20:33:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>rose-acre-farms-inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3e62a813b7445ff83bf5aaeb1fd6d398f03c3631a4c0996c8bc24bf48ee2014f</i><br /><br />Threat actor <b>description</b>: <i>www.goodegg.com
 www.roseacre.com
 Established in 1939 and headquartered in Seym...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rad-Solutions-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25464</link>
<guid>f950866095596db1d471ffbc7694fb0a</guid>
<pubDate>Sun, 07 Sep 2025 09:10:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Rad-Solutions-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf97288fd057b8ee5d60ce179dadf0d7620e8b257c25da7be57fead4fd41ed4e</i><br /><br />Threat actor <b>description</b>: <i>Rad-Solutions, LLC is a North American company that specializes in energy curable raw materials, specialty coatings, and innovative products for various industries including graphic arts and cosmetics. Their product range encompasses Radsol brand acrylate diluents, oligomers, and unique items such as adhesion promoters and proprietary stabilizers. With a management team of experienced chemists and engineers, the company imports and markets a diverse array of raw materials, ensuring availability through strategic alliances with global manufacturers. Additionally, Rad-Solutions offers formulating assistance and contract manufacturing to meet the needs of their clients.
company is headquartered in 2221 Justin Road Suit 119-142 Flower Mound, TX</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>TuftsMedicine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25465</link>
<guid>f75de331bfe8b590187c79b46e70d24b</guid>
<pubDate>Sun, 07 Sep 2025 09:07:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cloak</b> claims attack for <b>TuftsMedicine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a50885b22cd00ce1a4da80f22a5ed95ff0535ec120a0a35d105099bf8f6422c</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cloak</category>
</item>
<item xmlns:dc='ns:1'>
<title>GPS-Trackit</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25468</link>
<guid>7b5f37cf6529d139d0735e31fa4baae4</guid>
<pubDate>Sun, 07 Sep 2025 06:13:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>GPS-Trackit</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a766233494ad200a648c026c328a8998f74be7717f441a9e07582c09535c609d</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>gpstrackit.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Archer-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25467</link>
<guid>4a50c47d4386ee44d38066ae1b474dd7</guid>
<pubDate>Sun, 07 Sep 2025 06:13:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>killsec</b> claims attack for <b>Archer-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2269d4ce6e103c246a92f22d667551d7a748607e3d67f8a5517d938afc2ee47b</i><br /><br />Threat actor <b>description</b>: <i>N/A</i><br />Target victim <b>website</b>: <i>archerhealthinc.com</i>]]></description>
<category>killsec</category>
</item>
<item xmlns:dc='ns:1'>
<title>Gordon-Rees-Scully-Mansukhani-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25466</link>
<guid>4d36e559787b682162ce19874702bf39</guid>
<pubDate>Sun, 07 Sep 2025 00:44:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Gordon-Rees-Scully-Mansukhani-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f50804c1e09f7e485b27ce41deeb3cc57ff5d957faded8104a5259d9c649fee</i><br /><br />Threat actor <b>description</b>: <i>Law Firms & Legal Services - California, United States - 2,500 Employees. Gordon & Rees was founded in…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mechatronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25456</link>
<guid>233e59fa6283938baff02608900e1bbf</guid>
<pubDate>Sat, 06 Sep 2025 20:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Mechatronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1d1ec5533f77ae08c09f9a4aaee9d07a5bf6c523f51a05a83ff88efc47003b70</i><br /><br />Threat actor <b>description</b>: <i>Mechatronics, Inc. USA specializes in providing a wide range of AC, DC, and EC fans and blowers, including accessories and custom assemblies, catering to industries such as telecom, medical, industrial, alternative energy, lighting displays,             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Indo-MIM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25451</link>
<guid>65df376cb19d1a208ea312d7f58c7579</guid>
<pubDate>Fri, 05 Sep 2025 14:28:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Indo-MIM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>56fac646913d532a08fd390a029d5f924a57ddc1de06bba2c0ee6579ddd9ecc2</i><br /><br />Threat actor <b>description</b>: <i>Indo-MIM s a manufacturer and supplier of precision-engineered products using Metal Injection Molding.We are going to upload 13 GB of corporate documents. A huge number of employee personal files (Full Name in Native Language, OtherNames Used, Telecode Name Used, Sex, Marital Status, Date of Birth, Place of Birth, Country/Region of Origin (Nationality), country/region of origin (nationality) above, National Identification Number, U.S. Social Security Number, U.S. Taxpayer ID Number, Home Address, City, State/Province, Postal Zone/ZIP Code), financialdata, project information, drawings and specifications, customerinformation and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Michigan-Sugar</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25452</link>
<guid>ededc7e1ce8f57bb859089b9360ed86f</guid>
<pubDate>Fri, 05 Sep 2025 14:28:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Michigan-Sugar</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>93fbada75f020bb8329358b451567c12f69280742066730090963faa4f9d13d5</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1906 and headquartered in Bay City Michigan. Michigan Sugar manufactures granulated, powdered, liquid, and brown sugars.We are ready to upload more than 40GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (driver's license, death certificate, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>HeavenlyDental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25446</link>
<guid>db6040c329c81f77c902cc63b2b74aca</guid>
<pubDate>Fri, 05 Sep 2025 06:41:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>obscura</b> claims attack for <b>HeavenlyDental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>25eaebe8092d06bae52b485cad6bd5b65477f3b2712ce9083c0d98f0eb3683c0</i><br /><br />Threat actor <b>description</b>: <i>Dental clinics in San Jose</i><br />Target victim <b>website</b>: <i>heavenly-dental.com</i>]]></description>
<category>obscura</category>
</item>
<item xmlns:dc='ns:1'>
<title>Plazadental</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25447</link>
<guid>9129fd2aed62d0d2a5093bd9d118f3ce</guid>
<pubDate>Fri, 05 Sep 2025 06:41:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>obscura</b> claims attack for <b>Plazadental</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bb04db2079ee3ce278df28ba5bbe7322780529d4cdd4364eba7478dd42e5bd9</i><br /><br />Threat actor <b>description</b>: <i>Dental clinics in San Jose</i><br />Target victim <b>website</b>: <i>plazadental.com</i>]]></description>
<category>obscura</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elite-Trailers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25450</link>
<guid>2ad63b2ee1c70baedfadbe817528fc17</guid>
<pubDate>Fri, 05 Sep 2025 06:19:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Elite-Trailers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7e16734cb8d707995d823978a8961bc4bb6c3908b1f4739e5b3c82d1cd5ef6a</i><br /><br />Threat actor <b>description</b>: <i>Elite Trailers Elite Trailer MFG, LLC. specializes in the custom manufacturing of high-quality trailers, including horse, livestock, and specialty models.</i><br />Target victim <b>website</b>: <i>elitetrailers.com</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ekmanian-Tax--Accounting</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25441</link>
<guid>16f0fd52ff1008af716ba556886e37d0</guid>
<pubDate>Thu, 04 Sep 2025 23:28:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ekmanian-Tax--Accounting</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6189631b6c039670accc296be1a30d956fd74661920b39f19848217f74bb9833</i><br /><br />Threat actor <b>description</b>: <i>Ekmanian Tax & Accounting, USA - scandal immediately after M&A. Company is a law firm that provides tax account services and bookkeeping for people and companies. Most recently, they announced a merger with another company, Brave Accounting.             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Monterey-Mushrooms-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25443</link>
<guid>961e4b86bf690651cf87d52d714bc7f1</guid>
<pubDate>Thu, 04 Sep 2025 23:17:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Monterey-Mushrooms-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ef92957ffa36b0fb74fb8e3395483873156182eabfc713d3a637d39838511a6</i><br /><br />Threat actor <b>description</b>: <i>Monterey Mushrooms, Inc. was initially established in 1971 as a single farm operation in Royal Oaks, California. Today, this multi-site business is headquartered in Watsonville, California, and has production, sales and administrative offices, internationally. Monterey is the country’s largest and only national marketer of fresh mushrooms, supplying products for sale to supermarkets, foodservice and ingredient manufacture operations, and for preparation of processed, canned, and frozen mushroom products. In 1999, the company furthered its expansion into the Midwestern and Southeastern regions via the acquisition of mushroom farms in Princeton, Illinois, and Orlando, Florida. Monterey also continued its expansion in the Pacific Northwest via contracted pounds from Canada - all pounds are packed and distributed under the Monterey Mushrooms label.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CI-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25439</link>
<guid>d2d6abcb8d26945763acf5d5b7872bce</guid>
<pubDate>Thu, 04 Sep 2025 19:28:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cicada3301</b> claims attack for <b>CI-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cb69e816fb3db23d848bc13c38eafdba419396fed29e0785d318ee981e2bed62</i><br /><br />Threat actor <b>description</b>: <i>9</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>cicada3301</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.sixgunsllc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25423</link>
<guid>6d287702e0f315118da3186374b4a191</guid>
<pubDate>Thu, 04 Sep 2025 17:27:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.sixgunsllc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f7445316bbf1f372af8af78103ca358b7772f7eafc1a4be108119a524060b4a4</i><br /><br />Threat actor <b>description</b>: <i>Six Guns LLC offers superior commercial framing, drywall, and acoustical service...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.simmonsboardman.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25424</link>
<guid>5534491fa36be80ffbade139ea1a48ac</guid>
<pubDate>Thu, 04 Sep 2025 17:27:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.simmonsboardman.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e5fbe6590a775bd15a267b90dbee9d728b1c2216d73b5776770c5e3fadee4288</i><br /><br />Threat actor <b>description</b>: <i>Simmons Boardman Publishing is one of the oldest and most well-respected private...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>firstlight.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25427</link>
<guid>17cc0dddda0de48483f7447086c73767</guid>
<pubDate>Thu, 04 Sep 2025 17:27:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>firstlight.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b4aaac6bda7e038d217ce7eea5c360cb7d916afdbea0fff92147c05041d913e</i><br /><br />Threat actor <b>description</b>: <i>Headquartered in Albany, New York, FirstLight provides fiber-optic data, Interne...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spokane-Produce</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25428</link>
<guid>74a3faa048e151b7a9b61267399d79e3</guid>
<pubDate>Thu, 04 Sep 2025 17:26:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Spokane-Produce</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0c875b30584c42dec87c0d48e36a96f04e368c116aefffa2ed452cd623f971b8</i><br /><br />Threat actor <b>description</b>: <i>Spokane Produce, Inc. is a family-owned business established in the 1940s, specializing in the distribution of high-quality fresh produce, cut fruits and vegetables, deli items, and floral arrangements. We are ready to upload more than 74GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (driver's license, birth certificate, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>cphcorp.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25440</link>
<guid>0f56e1045e205122bb0dd4233c0b944f</guid>
<pubDate>Thu, 04 Sep 2025 16:52:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>cphcorp.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2016da6f6d554d254bc4d954e53c80968bf5b585b4af820378dc0e5b8fafdac3</i><br /><br />Threat actor <b>description</b>: <i>CPH is a full service architectural and engineering firm providing design for public and private sector projects. The multi-disciplinary team includes architects, engineers (civil/structural/traffic/transportation/electrical/mechanical), planners, landscape architects, surveyors, environmental scientists and construction administrators. CPH works throughout the United States and the Caribbean, completing projects that include water and wastewater treatment, collection, and distribution systems, complete streets, roadways, parks and recreation, and commercial / industrial complexes. Employees: 257  Revenue: $44.1 Million Industry: Architecture Phone Number:(407) 322-6841</i><br />Target victim <b>website</b>: <i>cphcorp.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.medwayplastics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25430</link>
<guid>94a69f0a7d3171579ee7d8e089ad900b</guid>
<pubDate>Thu, 04 Sep 2025 16:27:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.medwayplastics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b98dbeb72c75fa2751fadc1fb81fa31c40d4d277a6daed3e766c79d8c60c1ef1</i><br /><br />Threat actor <b>description</b>: <i>Medway Plastics is a family-owned plastic injection molding company based in Cal...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>pesadoconstruction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25432</link>
<guid>4af455c264cf269a141d01d8ab29ad97</guid>
<pubDate>Thu, 04 Sep 2025 16:27:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>pesadoconstruction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b7a48483e44f51af3ebffe8483561efe721afb829b2a5f35bb4db521b41255b</i><br /><br />Threat actor <b>description</b>: <i>Pesado Construction is a premier General Contractor based in San Antonio, specia...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>volanno.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25436</link>
<guid>af075e90875e107a1963c799eb861a61</guid>
<pubDate>Thu, 04 Sep 2025 16:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>volanno.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>41274afb95041d3c4c5d0ec3d9004a838d2749bc45f3feb5c5b463e53c8e29a4</i><br /><br />Threat actor <b>description</b>: <i>Volanno is a software company providing software development, data analytics, an...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>city-of-batavia</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25437</link>
<guid>5988319f8fdeb1b2d254a9a38518f52e</guid>
<pubDate>Thu, 04 Sep 2025 16:27:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>city-of-batavia</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43d4d953569e35c579257c2ab73b7a4ba461f9c5eba997c1060f4c913261e376</i><br /><br />Threat actor <b>description</b>: <i>The City of Batavia is a business-friendly organization with a balanced budget, ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.metrotech.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25438</link>
<guid>3dc430c160636fb3d2b8ffb62d9f1f3c</guid>
<pubDate>Thu, 04 Sep 2025 16:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.metrotech.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fae373b6ae2a654d60933e1d45f0a2b0f16b7ad942e90c306226e5a5c1c64040</i><br /><br />Threat actor <b>description</b>: <i>Metro Technology Centers is a career and technology education institution that p...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carus</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25422</link>
<guid>976f3d77e359f934970e7287f2318116</guid>
<pubDate>Thu, 04 Sep 2025 14:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Carus</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd08f05a78a9111d9d528d73f3d236a8042e4ee28d37978446f083e76ec761e1</i><br /><br />Threat actor <b>description</b>: <i>Carus provides solutions to environmental concerns involving water, air and soil with specializations in the area of chemical oxidation and sequestration.We are ready to upload more than 161GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, credit cards, medical information, emails, phones) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>httpsipathpr.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25421</link>
<guid>29e3808cfcf435dea788d9da1c245d03</guid>
<pubDate>Thu, 04 Sep 2025 12:27:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>mydata</b> claims attack for <b>httpsipathpr.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>36a902650692184bf87855935c2baae89ea1d5b7fbf2d43706004d42d5d46a5a</i><br /><br />Threat actor <b>description</b>: <i>Integrated Pathology Services90 GB data</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>mydata</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rivertown-Surgey-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25416</link>
<guid>383a2a1e8e4bf855f4149671967161bb</guid>
<pubDate>Thu, 04 Sep 2025 05:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Rivertown-Surgey-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a11f34108ad4df904e56be3ad055864dc5a433ef86ff76a04b3253d20102414</i><br /><br />Threat actor <b>description</b>: <i>Rivertown Surgery Center is a Medicare-certified ambulatory surgical center specializing in outpatient procedures.
The facility offers general surgery, pain management, foot surgery, and radiology services, supported by modern equipment.
It            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>sandg.local</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25420</link>
<guid>87fff7865acbd081aa2570994204bbcc</guid>
<pubDate>Thu, 04 Sep 2025 01:26:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>sandg.local</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a525eb23b05ae8e9a54ff81666c64f29bf7443af2fbe925044940b4abb5eb879</i><br /><br />Threat actor <b>description</b>: <i>https://shaferpartners.com/    law 370gb data   </i><br />Target victim <b>website</b>: <i>sandg.local</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>omegabiotek.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25419</link>
<guid>89f53faf95dedd155d17d200c2f2df2e</guid>
<pubDate>Thu, 04 Sep 2025 00:25:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>omegabiotek.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dfc5125fc0b9f20cd58c13e068736fc4ea68b47838f8ac5c5d249c36cdc46573</i><br /><br />Threat actor <b>description</b>: <i>Omega Bio-tek is an ISO 9001:2015 certified company specializing in nucleic acid isolation products for clinical and basic research, biotechnology, and agricultural applications. Founded in 1998, the company offers superior nucleic acid extraction technologies, including magnetic beads, silica membranes, and salting-out. These three methods are available in a wide range of various kits and configurations for a total of over 900 products for manual and automated processing. Employees: 145 Revenue: $50.1 Million Industry: Manufacturing   Phone Number:(770) 931-8400 SANNIDHI  ABHINAV  6462589152 Brandy Dailey      +1 770 401 8694 Cynthia Chambers   9194957522 Icaza Ellen        770-596-0554</i><br />Target victim <b>website</b>: <i>omegabiotek.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>CANDhenterprises.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25417</link>
<guid>2243ee303bf3b1042e3d60895273eee0</guid>
<pubDate>Thu, 04 Sep 2025 00:25:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>CANDhenterprises.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>53a4e18c85d105ab44d6c28c8fff3b91e1914a4ff282d719a42953b74524607b</i><br /><br />Threat actor <b>description</b>: <i>C&H Enterprises is an ISO compliant custom fabrication Job shop, as well as an industry leader in precision machining. Our experienced and diversified management staff is available to assist you in the design and development of your project. As part of our valued engineering service, we will insure that your parts are manufactured as economically as possible. We are proud of our "Core Capabilities & Strengths" which enable us to provide precision parts to the semi-conductor, medical, defense, and other industries by utilizing the following diverse fabrication capabilities: State-of-the-art CNC Machining Department State-of the-art Inspection Department In-house Leak Testing using a Helium Mass Spectrometer Leak Detector In-house Welding Dept. employs welders that are certified in a variety of metals and weld types for structural and vacuum welding under such qualifications as AWS DI.1 and AWS DI.2.  Employees: 94  Revenue: $23.1 Million Industry: Industrial Machinery Phone Number:(510) 226-6083</i><br />Target victim <b>website</b>: <i>CANDhenterprises.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Moore--Van-Allen</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25418</link>
<guid>dddc6994d5d3cd2cce94b112443e8fc9</guid>
<pubDate>Wed, 03 Sep 2025 23:18:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>SilentRansomGroup</b> claims attack for <b>Moore--Van-Allen</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a63899e1c2406cb48e6f1c35dc437326ae267df5fc5787dc37b08686d011616d</i><br /><br />Threat actor <b>description</b>: <i>Jay Bilas, Of Counsel, appeared on a podcast called "The Dan Patrick Show" on 06/25/2025. Topics discu…</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>SilentRansomGroup</category>
</item>
<item xmlns:dc='ns:1'>
<title>Master-System-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25410</link>
<guid>f48db3cd91ebb288ff33e95493b6329b</guid>
<pubDate>Wed, 03 Sep 2025 22:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Master-System-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>577cd74ecdaca80cfcf2923fbf3b8f142d706be5d29e8599cc86165a54d0dc9d</i><br /><br />Threat actor <b>description</b>: <i>Master System develops and supports software and services that deliver enterprise management and collaborative supply chain solutions to thousands of small to midsize distributors in a number of industries.Master System is headquartered in Ar            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>UNIDEL-Ventures-Pvt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25414</link>
<guid>dedacf1615c66d5fcd7126df8cbefb46</guid>
<pubDate>Wed, 03 Sep 2025 18:38:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nova</b> claims attack for <b>UNIDEL-Ventures-Pvt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf4dea74698046a28b70ad45b28aebc3c416ffdf70a7cca935da3d72d289cca3</i><br /><br />Threat actor <b>description</b>: <i>The UniDEL Group has been providing technology solutions and products since 1973. SoftDEL Systems Ltd provides engineering software solutions for the US, European markets and Japanese markets...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nova</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jack-Resnick--Sons</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25405</link>
<guid>46c6a6c72edf42b1335217a9eb4b2325</guid>
<pubDate>Wed, 03 Sep 2025 18:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Jack-Resnick--Sons</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>182bb7a90036a913195a736dee7d928687085d60baef38b18a0b08e55469ef9d</i><br /><br />Threat actor <b>description</b>: <i>Jack Resnick & Sons provide a variety of real estate availabilities, including notable residential buildings like Symphony House and Gracie Mews.We are going to upload corporate data soon. You will find lots ofcontracts and form containing clients DOB, addresses, phones, emails, financial and accounting files, payment details, and other data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>stthom.edu</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25411</link>
<guid>6b71c628253026a0f563beb5dd759d41</guid>
<pubDate>Wed, 03 Sep 2025 17:40:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>stthom.edu</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44c25c7c48bc57270317df6141627bdd7f2c0ab475890d00b4aebe14ab6d1092</i><br /><br />Threat actor <b>description</b>: <i>The University of St. Thomas (UST) is Houston's Catholic University, committed to the religious, ethical and intellectual traditions of Catholic higher education. For more than 70 years, we've been graduating students like you into successful careers in medicine, education, business, public administration and more throughout Houston and across the globe. Our student body reflects the rich diversity of the city itself. We welcome undergraduate and graduate students of all faiths and of no faith. The campus is located in Houston's Museum District and Innovation Corridor, a diverse and vibrant urban environment with professional opportunities. We're just steps from downtown and the famed Texas Medical Center where many students perform prestigious internships. Read more about our mission and vision. Employees:300 Revenue:$64.9 Million Website:www.stthom.edu Phone Number:(713) 522-7911 Lambert, Anne -Vice President (713) 525-6999 Justin Puder -IT Manager (713) 525-3599 Alexander Thomas-Admins Operations Coordinator (713)942-5023</i><br />Target victim <b>website</b>: <i>stthom.edu</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>blytheco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25403</link>
<guid>d268221f68f96be176c05c7de5ad9501</guid>
<pubDate>Wed, 03 Sep 2025 17:27:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>blytheco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>819ebcdde8ab387ca9f72dd01f6f2c2a4f071478d4a6129222896d79ababbc1a</i><br /><br />Threat actor <b>description</b>: <i>Blytheco is a full-service consulting firm that has been working with small and medium-sized businesses since 1980. Blytheco offers a wide range of business management software (ERP, CRM, HCM, marketing automation), backed by exceptional prof            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>CESCONSULT</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25407</link>
<guid>75f4b15635b6362df162948b296aaef7</guid>
<pubDate>Wed, 03 Sep 2025 14:41:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>CESCONSULT</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>feacb8d760ae88331d3a3592a0f6e1f1e881aeb80f8b9ef1cb7348a6ac1a0f55</i><br /><br />Threat actor <b>description</b>: <i>CES Consultants, Inc. is a engineering firm that specializes in program management, construction management, and design-build solutions.firm founded in 2001 by Rudy M. Ortiz, PE, CGC.  This is a small part of what we downloaded. https://cesconsult.com/</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>TSI-Accessory-GroupStanley-Creations-Inc-iStar-Jewelry-Roman--Sunstone.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25402</link>
<guid>8afb5804f92f8d5f149bfc66d149aa92</guid>
<pubDate>Wed, 03 Sep 2025 14:27:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TSI-Accessory-GroupStanley-Creations-Inc-iStar-Jewelry-Roman--Sunstone.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd1eeb45203df7b0aa517d5aee6bcce641bd48565ff2b158b8c8e6d2b7d735c8</i><br /><br />Threat actor <b>description</b>: <i>We are going to upload about 35 gb of essential corporate documents of a bunch of companies. You will find in the archives: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, Social Security Numbers, medical information, emails, phones) confidential information and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>NPIAV</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25399</link>
<guid>b2cea2ce8a7b8ee1ad5a97f9170cf234</guid>
<pubDate>Wed, 03 Sep 2025 12:28:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>NPIAV</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b99ede78baca1c8bf51eb2bb6b95fe59d3f72c5a3692735b9c22e3061fdfa2ca</i><br /><br />Threat actor <b>description</b>: <i>NPi Audio Visual Solutions, USA - the company organizes and hosts business events and parties. What happens behind closed doors at private conventions? Now we can peek behind the curtain and find out what the rich and famous really discuss an            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Monterey-Mushrooms</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25396</link>
<guid>09097f6b55431417a44fb77260332781</guid>
<pubDate>Wed, 03 Sep 2025 00:38:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Monterey-Mushrooms</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4e926bcbffdfc23a7681c0382867dc29968688e54bab41a7d4a31cb2535fcc24</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Monterey Mushrooms, founded in 1971 and headquartered in Watsonville, California, is a multinational company that cultivates, packs, and distributes fresh market mushrooms for retail, foodservice, and ingredient markets. Its product portfolio includes various types of mushrooms, such as white, brown, specialty, and organic mushrooms.</i><br />Target victim <b>website</b>: <i>montereymushrooms.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.dimarcogroup.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25391</link>
<guid>a9a2c061a1c2743d489c6863eae6725a</guid>
<pubDate>Tue, 02 Sep 2025 22:26:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>www.dimarcogroup.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>806c48947c27fbdf7b8f6ecd0596d5b9f208b17db52e1a1359a71feb5cdf4698</i><br /><br />Threat actor <b>description</b>: <i>The DiMarco Group, LLC founded in 1910 and headquartered in Rochester, New York,...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Level-</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25388</link>
<guid>92759f3b989bd57b544abacd6cf92d32</guid>
<pubDate>Tue, 02 Sep 2025 16:56:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>medusa</b> claims attack for <b>Level-</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>94253093d06fe5a2bd206f6f4cc5ca62be6561f8382c33794617da275430b7a1</i><br /><br />Threat actor <b>description</b>: <i>Level is a B2B2C fintech company comprised of a diverse team from industry-leading companies like Square, Oscar, Google, Uber, and Airbnb. Together, were creating a new payments tech stack to help employers offer more accessible and personalized benefits for their teams. company is headquartered in PO Box 176, New York City, New York, 10013, United State. 167 Employees </i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>medusa</category>
</item>
<item xmlns:dc='ns:1'>
<title>ArtistsClients</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25394</link>
<guid>4703873a678a5cd835a7500d9a0948d1</guid>
<pubDate>Tue, 02 Sep 2025 15:12:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lunalock</b> claims attack for <b>ArtistsClients</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5b11ce3f275019b4588caf9d87de3d3f8fc4c3c94f4319f216030195ed7f8fbd</i><br /><br />Threat actor <b>description</b>: <i>We have breached the website Artists&Clients to steal and encrypt all its data. If you are a user of this website, you are urged to contact the owners and insist that they pay our ransom. If the ransom is not paid, we will release all data publicly on this Tor site, including source code and personal data of users. Additionally, we will submit all artwork to AI companies to be added to training datasets.</i><br />Target victim <b>website</b>: <i>artistsnclients.com</i>]]></description>
<category>lunalock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pooler-Enterprises</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25386</link>
<guid>e61b865c4e3287487f1b8feb13d6215c</guid>
<pubDate>Tue, 02 Sep 2025 14:27:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Pooler-Enterprises</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1ab8216ecb8d46c34af4b0454d76688737da67c772aface3a056999b2cc9c870</i><br /><br />Threat actor <b>description</b>: <i>Pooler Enterprises is a seasoned provider of commercial land development services based in Fishers, NY, with over three decades ofexperience. We are ready to upload more than 15Gb files of essential corporate documents such as: financial data (payment details, invoices), employees and customers information (emails, phones, addresses) confidential information and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Natare</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25387</link>
<guid>a262af3a94c718b89b81bd68713329e9</guid>
<pubDate>Tue, 02 Sep 2025 14:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Natare</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>51a7055e30208ef43d0bdaed8b5328d77254cc8ad061376b2c24d05759de2945</i><br /><br />Threat actor <b>description</b>: <i>Natare Pools specializes in designing, building, and installing custom stainless steel pools, spas, and related equipment for various applications including competition, commercial, and communityuse. We are ready to upload more than 10Gb files of essential corporate documents such as: financial data (audit, payment details, financial reports invoices), employees and customers information (emails, phones, addresses) confidential information and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>GCC-of-America-inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25395</link>
<guid>d5b2473a8cb10baff0ddae36ca49efa9</guid>
<pubDate>Tue, 02 Sep 2025 14:12:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>GCC-of-America-inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c989d44ea0b89fdeadc96d9a8cf9b7520c788aa51249fdf16388b55ad073e17b</i><br /><br />Threat actor <b>description</b>: <i>Data breach at one of the largest cement and concrete producers in North America.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pittsburgh-Gastroenterology-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25385</link>
<guid>ed043feaff3fc5794439b33118c12256</guid>
<pubDate>Mon, 01 Sep 2025 21:18:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Pittsburgh-Gastroenterology-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca467ca2c4ba21833c5ffa1869c3734d3a181c30d70fa39dabcd333ba9de9fe1</i><br /><br />Threat actor <b>description</b>: <i>Pittsburgh Gastroenterology Associates specializes in the diagnosis and treatment of digestive health issues, focusing on diseases of the esophagus, stomach, intestines, liver, gallbladder, and pancreas. The organization provides a comprehensive range of services, including state-of-the-art diagnostic and therapeutic options, particularly emphasizing screening colonoscopy starting at age 45 due to an increase in colorectal cancer among younger individuals. They aim to deliver high-quality medical care with a team of skilled providers dedicated to patient compassion and support. Their intended clientele includes individuals needing gastroenterology services and preventive screenings.</i><br />Target victim <b>website</b>: <i>pghgastro.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>bthcpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25384</link>
<guid>3ab2501f57ad3a624edf8599dc6237d5</guid>
<pubDate>Mon, 01 Sep 2025 19:10:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>bthcpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>995955223a8424a69eaedaf66db45489e124019d5ad6c06e23fa5f8222a7e45e</i><br /><br />Threat actor <b>description</b>: <i>BTH CPA is a professional accounting and advisory firm based in the United States, offering a full range of financial …</i><br />Target victim <b>website</b>: <i>bthcpa.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>usai.io</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25382</link>
<guid>0adde37468be10ecf593f1586c143494</guid>
<pubDate>Mon, 01 Sep 2025 19:08:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>usai.io</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd2ca5df0e6126d4b502ba30e40123ccffdfda7d6dd8ad7c6fa4b4a96f07b8df</i><br /><br />Threat actor <b>description</b>: <i>USAI is a U.S.-based artificial intelligence and technology solutions provider. The company develops AI-driven platforms and software designed to optimize …</i><br />Target victim <b>website</b>: <i>usai.io</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>wilsonatllaw.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25381</link>
<guid>caa0fe665af380b663e4cd90f4e976c8</guid>
<pubDate>Mon, 01 Sep 2025 19:07:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>wilsonatllaw.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d207c8b056ef6910abbff0eb76b723e8efe11b5d0f5d575f5623fd9a9a56b3f5</i><br /><br />Threat actor <b>description</b>: <i>Wilson AT Law is a U.S.-based legal practice specializing in areas such as personal injury, family law, estate planning, and …</i><br />Target victim <b>website</b>: <i>wilsonatllaw.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>scottschiff.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25380</link>
<guid>ced398e2e89ba5d2840497063e42b1ad</guid>
<pubDate>Mon, 01 Sep 2025 19:07:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>scottschiff.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>686b1f4133dff83d43ff6406503ab983b4eb7736f4931ce9e5a8395e3a573500</i><br /><br />Threat actor <b>description</b>: <i>Scott Schiff & Associates is a U.S.-based law firm located in Columbus, Ohio, with a specialization in personal injury and …</i><br />Target victim <b>website</b>: <i>scottschiff.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>mdneal.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25379</link>
<guid>402de63be8bc8040dd2878205deac386</guid>
<pubDate>Mon, 01 Sep 2025 19:06:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>mdneal.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20242f92833027ce9afa771f15cc308e8d0cab6596ff2f765062300edccc4c1f</i><br /><br />Threat actor <b>description</b>: <i>M.D. Neal Engineering is an American engineering consulting company specializing in structural engineering, design, and project management. The firm provides …</i><br />Target victim <b>website</b>: <i>mdneal.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>ellison-mills.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25378</link>
<guid>bdc9f6ada518791b8b76e8a07021e145</guid>
<pubDate>Mon, 01 Sep 2025 18:38:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>chaos</b> claims attack for <b>ellison-mills.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b755bb06810520d8e0e3732df4a9fe4d4cdf98d1356c8bd1e22eac8e1f250d5e</i><br /><br />Threat actor <b>description</b>: <i>Ellison-Mills Contracting is a family-oriented company specializing in wet utility and roadway infrastructure in Southern Arizona. They are committed to cultivating strong relationships with clients and team members while delivering quality construction management for various project types. With extensive experience in multimillion-dollar projects, the company prides itself on its ability to complete work on time and under budget across several contracting methods.</i><br />Target victim <b>website</b>: <i>ellison-mills.com</i>]]></description>
<category>chaos</category>
</item>
<item xmlns:dc='ns:1'>
<title>waterfordsurgicalcenter.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25376</link>
<guid>372680a47ac1b06023127cc5830f0441</guid>
<pubDate>Mon, 01 Sep 2025 17:41:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>waterfordsurgicalcenter.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3c464dd5d86b6f28f639f854f72f76da27841b85cbd32d8db727e2096964a85</i><br /><br />Threat actor <b>description</b>: <i>Waterford Surgical Center is a specialized healthcare facility in the United States dedicated to outpatient surgical care. The center provides …</i><br />Target victim <b>website</b>: <i>waterfordsurgicalcenter.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>oiwky.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25375</link>
<guid>262717604b93578b7309e4a57fe91447</guid>
<pubDate>Mon, 01 Sep 2025 17:41:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>oiwky.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c546e4f8f7809122acefe5556bb2e1baafd706752c1c0d9cfdbf63232ccd2af</i><br /><br />Threat actor <b>description</b>: <i>Oiwky is a U.S.-based technology and innovation company focused on providing IT solutions, digital platforms, and business support services. The …</i><br />Target victim <b>website</b>: <i>oiwky.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Genmark-Automation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25367</link>
<guid>c3c7377014553b7643f4f43a6f679360</guid>
<pubDate>Mon, 01 Sep 2025 17:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Genmark-Automation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa6a3702e06ed2ad02929f77139fa714091ea45f34264256423f5ab5a27acd54</i><br /><br />Threat actor <b>description</b>: <i>Founded in 1985 and headquartered in California. Genmark Automation is a worldwide developer and manufacturer of tool and fab automation equipment solutions for the semiconductor, flat panel, solar, LED, data storage, and associated industries.We are ready to upload more than 47Gb files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (green cards, passports, driver's license, Social Security Numbers, credit cards, death/birth certificate, medical information, emails, phones, addresses) confidential information, NDAs and other documents with detailed personal information so on. The company management refused to take the situation seriously. So their employees and customers will have to face all the consequences of their data being compromised.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Automated-Business-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25368</link>
<guid>b51e4564bcafee1b797c2ef510e0f989</guid>
<pubDate>Mon, 01 Sep 2025 17:27:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Automated-Business-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc0435fdd167fbc905725ab8b4c8ebc35a1e6787b70fe48552eb516c252f63dc</i><br /><br />Threat actor <b>description</b>: <i>Automated Business Solutions, Inc. is a designer and supplier of office equipments and comprehensive business solutions.We are ready to upload more than 93Gb files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (credit cards, death certificates, medical information, emails, phones, addresses) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TAK-Communications-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25373</link>
<guid>e51e26bd5855b6ea5fc7bcc2c4010124</guid>
<pubDate>Mon, 01 Sep 2025 17:13:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>TAK-Communications-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>49c54749f8afa6e5bfbd96148e996a35e86b9d136c417da6713ef4f60381e01b</i><br /><br />Threat actor <b>description</b>: <i>TAK Communications, Inc. is a nationally recognized Cable Installation Contract Firm for the Cable TV and Telecommunications industry. TAK provides a wide variety of services including Cable Installation, Fulfillment Services, Direct Sales, Underground Construction, Structured Cabling and more. TAK provides countless services for its Cable TV and Telecommunications business partners, with the overall customer experience at the forefront of our minds. Whether you are a TAK business partner, company employee, or consumer, expect nothing less than a positive and professional experience from everyone at TAK Communications, Inc. At TAK Communications, Inc. we understand any company is only as good as its employees and our employees are the most important part of our company. When becoming an employee at TAK Communications, Inc., you are part of a team that looks out for your best interests. We set our employees up for success and are happy to say we have countless veteran employees that are making their career with TAK Communications, Inc. Cable, Internet, Phone, Installation, Direct Sales</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>gmpc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25371</link>
<guid>fa5723a60fc448c4ee84819937dfdeb7</guid>
<pubDate>Mon, 01 Sep 2025 16:08:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>gmpc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0383df5283e1b0339b47aca3c417eb547bcb5b9f01f5ecf47a5ce7938d5bb0ca</i><br /><br />Threat actor <b>description</b>: <i>No description provided.</i><br />Target victim <b>website</b>: <i>gmpc.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>oakland-museum-of-california</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25361</link>
<guid>b34b82f8014b6e1c1f3274bb1d6fe0dd</guid>
<pubDate>Mon, 01 Sep 2025 14:27:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>oakland-museum-of-california</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>31bbe60b1e979a914a13c5af82d3bc235d840b7c7f0cbd86471bd926905e7342</i><br /><br />Threat actor <b>description</b>: <i>Established in 1969, Oakland Museum of California provides collections, exhibiti...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>PathoQuest-Biotechnology-Research</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25360</link>
<guid>10a55f345c206822c64a07d7728aef73</guid>
<pubDate>Mon, 01 Sep 2025 11:29:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>PathoQuest-Biotechnology-Research</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a1612e005bc9dfb42e9fccb99b208e5842d41e89881de69b31358eeaea992313</i><br /><br />Threat actor <b>description</b>: <i>PathoQuest-Biotechnology Research, USA-France The company conducts research on innovative biopharmaceuticals under complex testing conditions on two continents. PathoQuest offers a proven next-generation sequencing (NGS) approach to biosafety            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Arboris</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25366</link>
<guid>0d1e0d602ebcba3dec4cff58832c7181</guid>
<pubDate>Mon, 01 Sep 2025 10:46:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Arboris</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3630adee7ba348b28e85e0a90c1e80af2bee6086b9f343879b624c6eb0021d5</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.arboris-us.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Juggernaut</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25365</link>
<guid>2ee48d7685054b85f9e9d9b8b67c404f</guid>
<pubDate>Mon, 01 Sep 2025 10:46:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Juggernaut</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44cabffd154f37983b8ef42b619cc404adc33d012a6574a78987cd1e22747350</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.juggernautdesign.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Vanderpool-Construction</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25364</link>
<guid>f319ba8aa8a10c4d0df2b8acf127be64</guid>
<pubDate>Mon, 01 Sep 2025 10:45:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Vanderpool-Construction</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21ae66a3acc7b5e5bab35bbb1ec69777a22eafe5fd5e1662b1459d5fde3519f9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.vanderpoolinc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>All-States-Materials-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25363</link>
<guid>29f6bff5f05251565c618bbb35143c06</guid>
<pubDate>Mon, 01 Sep 2025 10:44:48 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>All-States-Materials-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b9ea4af9c27e68fc4b05f93a6c4831010d58db614fadc1fc1259aa26a887122</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.asmg.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>LEVEL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25362</link>
<guid>04678698d4bd6a8a5b775ec3ac878191</guid>
<pubDate>Mon, 01 Sep 2025 10:19:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>desolator</b> claims attack for <b>LEVEL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1151ee434e0fb3a31ac9ac617414051e380d2f57e32de65a27bfb4b001108118</i><br /><br />Threat actor <b>description</b>: <i>Status: waiting | Expiration: 2025-09-05T00:00</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>desolator</category>
</item>
<item xmlns:dc='ns:1'>
<title>LS-Proline</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25358</link>
<guid>51a9c5784bc9459856a826362c057737</guid>
<pubDate>Sun, 31 Aug 2025 01:53:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>LS-Proline</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e20c192a33f96301984e1ac69edbe01c3e02a18ef6c01f8d3323320f7bc3f8d6</i><br /><br />Threat actor <b>description</b>: <i>L&S Proline, USA - Drill, baby, drill! L&S Proline is a full-service company specializing in solutions for the oil and gas industry, offering a range of products and services, including measurement control equipment, structural fabrication, a            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ABM-Wireless-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25348</link>
<guid>27810d8aed732a494b7c10f1aaabcc8e</guid>
<pubDate>Sat, 30 Aug 2025 18:24:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>ABM-Wireless-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb87d4dac13ac3d574b1e1bf4bf7c48056a7cfb59ab194928bec71dd6be305da</i><br /><br />Threat actor <b>description</b>: <i>Inscope is a New York based Master Dealer in the wireless distribution space. Established in 2002, we have grown to become one of the largest Master Dealers for...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hilco-Metal-Building--Roofing-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25349</link>
<guid>c90a356873c27f2033848630133bbf22</guid>
<pubDate>Sat, 30 Aug 2025 18:24:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Hilco-Metal-Building--Roofing-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7613fbc87ee7d56ab368d1ecf77bf7fcf8e6cca1909bc6844a728396756a9480</i><br /><br />Threat actor <b>description</b>: <i>Hilco Metal Building & Metal Roofing Supply specializes in providing a comprehensive range of metal buildings, roofing materials, and custom-designed arenas spe...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Park-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25350</link>
<guid>c7d67339105519c3dae1c323022dbd04</guid>
<pubDate>Sat, 30 Aug 2025 18:24:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Park-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96691246c20b704f84fee900521a4f31c7ef5bfc6d2e706a11ace4633c1378b0</i><br /><br />Threat actor <b>description</b>: <i>(financial documentation and clients' data internally) Park Country Club is a premier traditional country club located in Western New York. The club offers a co...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Engineered-Components</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25353</link>
<guid>8f91e3c119da5993c7ff3bbdd6fb1f32</guid>
<pubDate>Sat, 30 Aug 2025 18:24:32 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Engineered-Components</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a7372005c5b005a4f432c70d679158823bf7ca0ff30e74e9e7212c5e7ba85684</i><br /><br />Threat actor <b>description</b>: <i>(Financial documents, counterparties, clients) We also distribute a multitude of other components that are utilized by original equipment manufacturers worldwid...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>sandersonmanagement.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25357</link>
<guid>d865f737d6777cdadaa957a87662d7ea</guid>
<pubDate>Sat, 30 Aug 2025 18:05:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>sandersonmanagement.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ddce09d56ab868cf6b37066150a025f6bb5fb1547811b933299da4cb01239a86</i><br /><br />Threat actor <b>description</b>: <i>Sanderson Management is a renowned property management company based in the United States, specializing in the efficient and effective management …</i><br />Target victim <b>website</b>: <i>sandersonmanagement.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>OB-GYN-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25347</link>
<guid>9a1a05c42c96b161ecd2884b758e114a</guid>
<pubDate>Sat, 30 Aug 2025 12:23:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>OB-GYN-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65e4d06fa3491e11eb351220d4faaa04197363052c076a41270c7bbfc8fe1b17</i><br /><br />Threat actor <b>description</b>: <i>OB/GYN Associates offers comprehensive women's healthcare from obstetrics and pregnancy to gynecological care in Reno, Nevada.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>atlanta-neighborhood-charter-school</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25337</link>
<guid>aac1ea0f73d4664c59969f5b9d6fd41e</guid>
<pubDate>Sat, 30 Aug 2025 00:28:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>atlanta-neighborhood-charter-school</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>98e593597ecc0f9aff610f8d66a9cd3f70c0d75b9e7d99c7158509ec6f311acc</i><br /><br />Threat actor <b>description</b>: <i>Atlanta Neighborhood Charter School (ANCS) is a K-8 public charter school in Atlanta, recognized for its academic excellence and innovative programs. However, they could not make a program to protect their own students. All information on the            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>companionsandhomemakers.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25345</link>
<guid>8d4965eaf92972d652fd44ece6f79533</guid>
<pubDate>Fri, 29 Aug 2025 21:37:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>companionsandhomemakers.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>00fd73d2adfa551bbef3e447fca0a4c0c8950965572ca1a3633449f85fe9a3f5</i><br /><br />Threat actor <b>description</b>: <i>Companions & Homemakers, based in Connecticut, is a nonprofit home-care service provider with more than 30 years of experience. It …</i><br />Target victim <b>website</b>: <i>companionsandhomemakers.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>hardwicktactical.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25340</link>
<guid>78ade5b560946211ce63652717b37aea</guid>
<pubDate>Fri, 29 Aug 2025 21:34:34 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>hardwicktactical.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b56a648d27a2f787bee4af89dd2ea98c386f533b4acf9a772eaa24202a6d057</i><br /><br />Threat actor <b>description</b>: <i>Hardwick Tactical Corporation, located in Cleveland, Tennessee, is a historic American manufacturer of military and professional uniforms. Founded in 1880, …</i><br />Target victim <b>website</b>: <i>hardwicktactical.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>templeemanu-el.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25339</link>
<guid>6dcb66034aed7493a93ef9b231ecaf14</guid>
<pubDate>Fri, 29 Aug 2025 21:33:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>templeemanu-el.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4a7660648889dbb2211abbec92fc7fe8b6a44e101f41ee03892213af6a052236</i><br /><br />Threat actor <b>description</b>: <i>Temple Emanu-El, located in Dallas, Texas, is one of the largest and most historically significant Reform Jewish congregations in the …</i><br />Target victim <b>website</b>: <i>templeemanu-el.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>thecelestehotel.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25338</link>
<guid>9b985eb1206505396c15126062c31bef</guid>
<pubDate>Fri, 29 Aug 2025 21:33:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>thecelestehotel.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f516211a9f9e46968baf990203ee09ed43c6d4bb0087b411b2010dc5e6797521</i><br /><br />Threat actor <b>description</b>: <i>The Celeste Hotel is a boutique hotel located in Orlando, Florida, within the University of Central Florida (UCF) campus area. …</i><br />Target victim <b>website</b>: <i>thecelestehotel.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>allphaselandscape.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25333</link>
<guid>8a005b6bbfa78c441688ee23f5756e04</guid>
<pubDate>Fri, 29 Aug 2025 18:27:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>allphaselandscape.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>96031a9d7798a30df3d10585da278c93651e11b238dafd9e530888b5e77051f0</i><br /><br />Threat actor <b>description</b>: <i>All Phase Landscape, USA is a company engaged in landscaping, design, and service of green areas in parks, around administrative, office, and residential buildings. Making the surrounding space more beautiful and environmentally friendly is o            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ibew1547.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25334</link>
<guid>9ec80d58ed3495c213848b3957cf8ea1</guid>
<pubDate>Fri, 29 Aug 2025 18:27:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ibew1547.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>20fe14644794d4570464ceec7336362920cc2264af493756a72a8e302801dd85</i><br /><br />Threat actor <b>description</b>: <i>IBEW Local 1547, USA - a union in Alaska that is supposed to provide safety and protect the rights of electric utility and communications workers, local officials, health care workers, and many other professionals. Safety - failed. Protection            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ogdenpubs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25335</link>
<guid>6aa899171430d12d1ed53cc8c02dc3d6</guid>
<pubDate>Fri, 29 Aug 2025 18:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ogdenpubs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35ee8cde388e36ed94e3572369ea257c84305c9ffc66d9812e88700430e97efc</i><br /><br />Threat actor <b>description</b>: <i>Ogden Publications Inc., USA - history repeats itself. One of the oldest publishing houses in the USA repeats its mistake time after time and has no experience. There is no other word than “idiocy” for their approach to problem solving. O            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>RMO</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25327</link>
<guid>ebfebc42d8f8dd67da25a2dcab4ac8ff</guid>
<pubDate>Fri, 29 Aug 2025 13:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RMO</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>093b9e911771433ad13b11ae12c364d7c86cfd72e35d2fb4aba2e49cf5b02d76</i><br /><br />Threat actor <b>description</b>: <i>RMO Orthodontics is a leading manufacturer and supplier of innovative and high-quality orthodontic instruments and supplies. They offer a comprehensive catalog of products including brackets, archwires, and accessories, catering primarily to orthodontic professionals. We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), employees and customers information (passports, emails, phones, SocialSecurity Cards, birth certificate) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Fredericks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25329</link>
<guid>6a639c52538fd7bb3e1186724afbe9b2</guid>
<pubDate>Fri, 29 Aug 2025 12:27:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Fredericks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5532f62b4f3d648bcc8ba4b8d8588b69c231734f702735dff45650fb9c372338</i><br /><br />Threat actor <b>description</b>: <i>The Fredericks Company is a leading manufacturer and innovator specializing in tilt and vacuum measurement sensors. We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), employees and customers information (emails, phones) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Delta-Information-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25323</link>
<guid>b8fd187b3f6b41d95bbc6c831075f367</guid>
<pubDate>Fri, 29 Aug 2025 03:20:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Delta-Information-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>be8e8ed284468c47c786481f924a56289e3aec553fc9e9a4b83e24d8b5878ba4</i><br /><br />Threat actor <b>description</b>: <i>We have got all the software and hardware code,and got 800G+ of internal data. The link will coming soon...
Of if anyone is intersted in purchasing the code,pls contact me</i><br />Target victim <b>website</b>: <i>acroamatics.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Town-of-Chatham-MASSACHUSETTS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25308</link>
<guid>6fe5f41ad53538d0b9c78ba3a5603d67</guid>
<pubDate>Fri, 29 Aug 2025 02:27:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Town-of-Chatham-MASSACHUSETTS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5583d5e26a1fca873b5b57c14118584a38181d485e10d6f890854993c7fde5eb</i><br /><br />Threat actor <b>description</b>: <i>Chatham, Massachusetts is located at the southeast tip of Cape Cod.

Chatham MA is a municipal government that provides essential services to its residents, including emergency services, utilities, and community resources. The town focuses             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>gmcontractinginc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25302</link>
<guid>7b763dcb78dd4c378a4170623a213821</guid>
<pubDate>Thu, 28 Aug 2025 21:26:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>gmcontractinginc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d6e8173a7730940edef7975de8c5238e3955e2946d0e3f1ec0b992c20adc623e</i><br /><br />Threat actor <b>description</b>: <i>GM Contracting offers a full range of residential utility construction services. GM Contracting has years of residential experience with water and sewer utilities. In addition to traditional construction methods, GM Contracting is a full serv            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Kafka-Conveyors--Equipment-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25316</link>
<guid>51f2e9ae8acea3cede0ab0b8fbcd973d</guid>
<pubDate>Thu, 28 Aug 2025 21:23:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Kafka-Conveyors--Equipment-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d72b41e23e8c9497e0ae7f737157d1a2f581e00a521528b12ca394353c259c08</i><br /><br />Threat actor <b>description</b>: <i>Kafka Conveyors & Equipment Inc., offers a variety of conveyor types and sizes, such as stacking conveyors, transfer conveyors, and stackable conveyors. We also offer to our customers recycling portable picking station and portable shingle feeders. All conveyors are custom designed and suited toward our customers' needs and different kinds of materials. Our conveyors are used in a variety of applications, transferring and stockpiling a wide range of materials, stone, sand & gravel quarries, asphalt, coal, salt, woodchips, topsoil, recycling, concrete recycling, and scrap yards. They are also used in the loading and unloading in rail yards, ship and barg docks.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Firelands-Scientific</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25304</link>
<guid>fdb0dfc7a10173835252be882819b650</guid>
<pubDate>Thu, 28 Aug 2025 18:02:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Firelands-Scientific</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b3982b24f09ff43000063a63af3b1e79b83781429fc8daebd77d2d7a3d19193</i><br /><br />Threat actor <b>description</b>: <i>Firelands Scientific</i><br />Target victim <b>website</b>: <i>firelandsscientific.com</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>summitcollege.eduUSA370GB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25303</link>
<guid>1f8107db1348b9e5ddcf83489018a5d2</guid>
<pubDate>Thu, 28 Aug 2025 15:22:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>summitcollege.eduUSA370GB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>86e30975a087781abd66e65269d1593d89b03aaeba0241a4e4be4b315411c743</i><br /><br />Threat actor <b>description</b>: <i>Unknown - Summit College</i><br />Target victim <b>website</b>: <i>summitcollege.edu/USA/370GB</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colorado-Health-Network-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25301</link>
<guid>030d985224c7b144b7d3f3e57e912ed8</guid>
<pubDate>Thu, 28 Aug 2025 07:09:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Colorado-Health-Network-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fbb02776acf6fe90861339942d21c4f9f8796a84460bdd9e88507f711dee6fc7</i><br /><br />Threat actor <b>description</b>: <i>900G+ data coming soon</i><br />Target victim <b>website</b>: <i>coloradohealthnetwork.org</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Texas-Pregnancy-Care-Network</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25300</link>
<guid>049251c63a428a409b576d20a86ec031</guid>
<pubDate>Thu, 28 Aug 2025 02:40:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Texas-Pregnancy-Care-Network</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>790650cb7caa995986ff2fd928c186d112f20524e476b364d12ef2e3c9ee848f</i><br /><br />Threat actor <b>description</b>: <i>coming soon</i><br />Target victim <b>website</b>: <i>texaspregnancy.org</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>wilderlawfirm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25299</link>
<guid>8631f219500638a09ee08a3033f25f43</guid>
<pubDate>Thu, 28 Aug 2025 02:39:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>wilderlawfirm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e1c50c95064d1cb2ecb57465f8cb96d669e81e71d10931b61d6cde3c95b3ae0f</i><br /><br />Threat actor <b>description</b>: <i>coming soon</i><br />Target victim <b>website</b>: <i>wilderlawfirm.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>climaxportable.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25296</link>
<guid>bb97e7d1b0e54df5e1ab088ecdfb4079</guid>
<pubDate>Wed, 27 Aug 2025 23:40:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>climaxportable.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d1e4d19e467fa00cd80336d2acb7bd1895d637a2d7dfff46db8fb4dcdb5b74d9</i><br /><br />Threat actor <b>description</b>: <i>CLIMAX, founded in 1966 and headquartered in Newberg, OR., is a provider of portable machining, welding, and testing systems to optimize performance, efficiency, and safety within the Oil & Gas, Mining & Heavy Construction, Power Generation, Shipbuilding & Repair, and Transportation industries. Employees: 136 Revenue: $40 Million Industry: Industrial Machinery    Phone Number:(503) 538-2185</i><br />Target victim <b>website</b>: <i>climaxportable.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Smile-Spa</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25291</link>
<guid>6b17d006a2ed6f12f07c7ea60b8002b5</guid>
<pubDate>Wed, 27 Aug 2025 17:27:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>The-Smile-Spa</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>966af84ff5585d17f7a000353ddf53ed1200f7e88eaeb4bc7fe21c7d7f01fdf3</i><br /><br />Threat actor <b>description</b>: <i>At the Smile Spa in Baton Rouge, LA, Dr. Aimee Russo-Mounger provides a variety of dental and spa services. Schedule a dentist appointment or fun spa day.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>allmaxnutrition.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25294</link>
<guid>5d8dc5dbd84f605017f1c835da6031d7</guid>
<pubDate>Wed, 27 Aug 2025 15:39:06 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>allmaxnutrition.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9487a2a701da07f66bd459d442c8f63e3beffb090dee6a04af8f6f9dda53af55</i><br /><br />Threat actor <b>description</b>: <i>ALLMAX Nutrition is a professional grade supplements provider for advanced bodybuilding and training. The company is headquartered in North York, Ontario, Canada. Employees: 83 Revenue: $5 Million Industry: Retail    Phone Number:(416) 223-4561</i><br />Target victim <b>website</b>: <i>allmaxnutrition.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Weathercraft-Companies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25286</link>
<guid>4b5fb5ef53ac99fb4961f6844ce0dd43</guid>
<pubDate>Wed, 27 Aug 2025 15:27:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Weathercraft-Companies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f73efeb2135cf3869c6dab3d5c38d3f793795e8aebc17801b1856b308ea1449b</i><br /><br />Threat actor <b>description</b>: <i>Contractor Specializing in Roofing, Siding, Gutters, Windows, and Overhead Door Installation
In 1976, Weathercraft of North Platte was founded by Alan Erickson and Bill Livengood, branching out from Weathercraft of Lincoln, NE.


Weatherc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dance-Brothers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25293</link>
<guid>77d40045c24c613463c3eef0732475f3</guid>
<pubDate>Wed, 27 Aug 2025 15:13:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Dance-Brothers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>edc327903b06315a3119a944239e704e838cb30bb0644da33d38128f2765e07b</i><br /><br />Threat actor <b>description</b>: <i>Dance Brothers, Inc. is a full service cast-in-place concrete contractor that specializes in commercial, industrial, and government projects. With over 40 years of experience, they have expertise in various structural concrete construction projects including heavy foundations, steel frame buildings, and high/mid-rise concrete frames. Their commitment to quality ensures that each project is completed to the satisfaction of owners, architects, and engineers. They offer a wide range of services, including concrete footings, walls, slabs, and precast structures.</i><br />Target victim <b>website</b>: <i>www.dancebrothers.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ZCORP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25295</link>
<guid>5d7bec8c05ebb017758028aa34da27b1</guid>
<pubDate>Wed, 27 Aug 2025 15:12:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>ZCORP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c59fdfde978adedf6b69a546015fe4c34bde9ac5d97dc664878a54911d444bfa</i><br /><br />Threat actor <b>description</b>: <i>ZCORP ZCORP is a technology enterprise based in Princeton, NJ, specializing in providing innovative products, services, and tools to help clients navigate the challenges of a rapidly evolving marketplace.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>Echo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25287</link>
<guid>793a0cce41071c3362bed8fddeaa2b15</guid>
<pubDate>Wed, 27 Aug 2025 14:30:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Echo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>87845cc975a2d37cb5ea593f8f54ca62ab656c4000013c1701f0749bbbbec57f</i><br /><br />Threat actor <b>description</b>: <i>Echo is an industry leader in the design, marketing and distribution of home and fashion accessories. Echo is as diverse in its color palette and patterns as it is rich in its family heritage andhistory. Since 1923, Echo has focused on the principles of creativity, service, innovation and quality established by its founders, Edgar and Theresa Hyman.We are ready to upload more than 331GB files of essential corporate documents such as: financial data (audit, payment details, invoices), employees and customers information (driver's license, Social Security Numbers, phones, emails, death/birth certificate, medical information) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bens-Asphalt</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25288</link>
<guid>b6f05a7baab2fe0eea07e59bd5b0b317</guid>
<pubDate>Wed, 27 Aug 2025 14:30:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bens-Asphalt</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9d15571a03eb937ea54c024bcb198f9bdbcdd92df24f73d8fff43725decec952</i><br /><br />Threat actor <b>description</b>: <i>Ben's Asphalt is an asphalt maintenance & parking lot management company in Southern California with a national presence. The company was founded in 1961 and is headquartered in Santa Ana.We are ready to upload more than 100GB files of essential corporate documents such as: financial data (audit, payment details, invoices), employees and customers information (phones, emails, medical information) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>brebeuf.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25285</link>
<guid>1ef039b8c360653698d917512eb41140</guid>
<pubDate>Wed, 27 Aug 2025 12:27:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>brebeuf.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4d0717bc49f08e7f084c66cc33a2bc11ce7e43e8877a33a82db47553ee812412</i><br /><br />Threat actor <b>description</b>: <i>Brebeuf Jesuit Preparatory School, USA - cut off and in trouble with the law. A small Jesuit school in Indianapolis got attention in 2019 when it refused to fire a teacher who was in a gay marriage. The school was then cut from the Archdioces            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>singersf.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25284</link>
<guid>f331db13ff819dd8efd8319b48f4a66c</guid>
<pubDate>Wed, 27 Aug 2025 10:27:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>singersf.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0ad46579348cd51c430a3f4b1e530d0df8d118b96a599c711548b31c5cf3a51</i><br /><br />Threat actor <b>description</b>: <i>Singer Associates, USA - Money has no odor. The company is cleaning up its reputation and washing other company's dirty laundry. It used to be done by laundresses and asenizers, now it's done by PR people. One of them, Sam Singer. He bought h            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Logan--Mencuccini</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25282</link>
<guid>6ee684091fe7cba88c97f114350cb2ea</guid>
<pubDate>Tue, 26 Aug 2025 18:47:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Logan--Mencuccini</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>62f816af9e90ae2013115b5ab7871f0e521b616f3228f9722ed81b6c6c621a7a</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.torringtonlaw.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Edward-J-McKarski</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25281</link>
<guid>2b7a26a14d10d78513786ac0a0e811ed</guid>
<pubDate>Tue, 26 Aug 2025 18:46:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Edward-J-McKarski</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d8e2281f23f28ea73f84b0abce34cb1ff0465cd8cb6b7123b5cb423f61f72f8c</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.mckarski-law.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Banville-Wine-Merchants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25280</link>
<guid>02c7b9e35b5abe16eff4721993beb0fd</guid>
<pubDate>Tue, 26 Aug 2025 18:45:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Banville-Wine-Merchants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>586b77112643d5a962436a4c491c85a00ae1279480350886c36de447a69a7280</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.banvillewine.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Premier-Realty-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25278</link>
<guid>28144c5d22c74864cee1b3eedbce3c85</guid>
<pubDate>Tue, 26 Aug 2025 18:44:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Premier-Realty-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7119630aa8a19ffe2dec38661600b22a036c24860313b3101bc0c803f78605d9</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.premierrealtygroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Motor-Controls-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25250</link>
<guid>a4589a60ea90b98f8f75780b4c829e9a</guid>
<pubDate>Tue, 26 Aug 2025 15:23:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Motor-Controls-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>02fefbfb7203de0002e50319d65ec585fa58bb10a7212a65df20b5391b659815</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>txpregnancy.org---Fake-Abortion-Clinics-Exposed</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25277</link>
<guid>c64c7085e3ecb77c60caf49560a1ea67</guid>
<pubDate>Tue, 26 Aug 2025 15:03:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>txpregnancy.org---Fake-Abortion-Clinics-Exposed</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0bab92aa20f2c96275d090ed0c59bc077ddfa2e84e1e63a8213890b958514da</i><br /><br />Threat actor <b>description</b>: <i>coming soon</i><br />Target victim <b>website</b>: <i>txpregnancy.org</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lewis-Baach-Kaufmann-Middlemiss-PLLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25275</link>
<guid>40547606fba6796b5cded9cf8f7b6062</guid>
<pubDate>Tue, 26 Aug 2025 14:59:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Lewis-Baach-Kaufmann-Middlemiss-PLLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b45300d51d4f204a2d57f882d3971856d34889b4d06f9b7b3ea21a05886941ef</i><br /><br />Threat actor <b>description</b>: <i>coming soon</i><br />Target victim <b>website</b>: <i>lbkmlaw.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lee--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25269</link>
<guid>a3e03b54faf412c2ac7250d6974c15cb</guid>
<pubDate>Tue, 26 Aug 2025 14:58:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Lee--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>17327630e0a4942da94f7f1758869f9b757c044fd324a0b86494370b03815ff7</i><br /><br />Threat actor <b>description</b>: <i>Lee & Associates DATA LEAK | (TB)</i><br />Target victim <b>website</b>: <i>lee-irvine.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sherman-Silverstein-Kohl-Rose--Podolsky-P.A.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25274</link>
<guid>ca4e13f25e6ea38d8d1a263b675331f6</guid>
<pubDate>Tue, 26 Aug 2025 14:58:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Sherman-Silverstein-Kohl-Rose--Podolsky-P.A.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>db6bedd51b298e57442e8102c98e24ac8471d8785aab4bb828bc253312a2a1a7</i><br /><br />Threat actor <b>description</b>: <i>SSKRPLAW DATA LEAK | (5GB+ ZIP)</i><br />Target victim <b>website</b>: <i>sskrplaw.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>Guerrero-Mears-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25273</link>
<guid>cda81c6cc858986f2be6ad43c64e5c99</guid>
<pubDate>Tue, 26 Aug 2025 14:57:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>Guerrero-Mears-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f0012f2d69fd0b94ac7216ae16fc1a6a1e8af492dcde89d59cec4e4961f58079</i><br /><br />Threat actor <b>description</b>: <i>Guerrero Mears LLP DATALEAK | (FORGOT THE SIZE)</i><br />Target victim <b>website</b>: <i>gmllp.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>LPL-Financial</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25268</link>
<guid>6b027466c3ca21b6d1a1d594d6820833</guid>
<pubDate>Tue, 26 Aug 2025 14:53:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>LPL-Financial</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e86e2d9a5acf284d46dc23171c1c5e35f2836994ef0b8941734c4385537821ee</i><br /><br />Threat actor <b>description</b>: <i>LPL Financial DATA LEAK | (I FORGOT THE SIZE,BUT ITS HUGE)</i><br />Target victim <b>website</b>: <i>balancedsolutions4me.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>K-Strategies-Marketing-and-Public-Relations</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25267</link>
<guid>37c429609aa5ffe35484714281ebcb23</guid>
<pubDate>Tue, 26 Aug 2025 14:53:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>K-Strategies-Marketing-and-Public-Relations</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76e3501a53b0abb1cba7b5b8b388d73a22877e7bedb75e1862b1df48476d8fa7</i><br /><br />Threat actor <b>description</b>: <i>K Strategies Marketing and Public Relations LEAK | 900+GB</i><br />Target victim <b>website</b>: <i>kstrategies.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>BAR-Architects--Interiors</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25266</link>
<guid>d54be4ff5a9dad8e016206a562bb7915</guid>
<pubDate>Tue, 26 Aug 2025 14:52:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>BAR-Architects--Interiors</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1d0f9874d701801423f37a3cd6e07dfca2d782ab6f1c011a0902ac29ff29ad0</i><br /><br />Threat actor <b>description</b>: <i>BAR Architects & Interiors DATA LEAK | 1.5T+</i><br />Target victim <b>website</b>: <i>bararch.com</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>CareSTL-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25264</link>
<guid>ac63ec3793010b4f6477df5e0006ca07</guid>
<pubDate>Tue, 26 Aug 2025 14:43:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>cephalus</b> claims attack for <b>CareSTL-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f47c5a43f565e508d58a29691ed060d5a7c561c452456704ee6e664126168d13</i><br /><br />Threat actor <b>description</b>: <i>CareSTL Health DATA Leak | 500+GB | KAWA4096 STEALED our data</i><br />Target victim <b>website</b>: <i>carestlhealth.org</i>]]></description>
<category>cephalus</category>
</item>
<item xmlns:dc='ns:1'>
<title>phillips66lubricants.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25259</link>
<guid>8d189ff5977605432446d89c584d2464</guid>
<pubDate>Tue, 26 Aug 2025 09:48:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>phillips66lubricants.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd98da646eff557c3ac4d9d825171b313f58fb0efb37891319af3fac1bf6d4ac</i><br /><br />Threat actor <b>description</b>: <i>hillips 66 Lubricants is a leading U.S.-based manufacturer and supplier of industrial and automotive lubricants. As part of the larger …</i><br />Target victim <b>website</b>: <i>phillips66lubricants.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>rivertoncabinets.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25256</link>
<guid>bbadca995530ba3c915c375b8a110b77</guid>
<pubDate>Tue, 26 Aug 2025 09:46:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>rivertoncabinets.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38e20be03cc46c84855115700464e8215f82965db1b94306b664b8a823afa9d9</i><br /><br />Threat actor <b>description</b>: <i>Riverton Cabinet Company is a U.S.-based custom cabinetry firm in New Lenox, Illinois, known for its craftsmanship and personalized design …</i><br />Target victim <b>website</b>: <i>rivertoncabinets.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>gibbswire.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25243</link>
<guid>99f437d56c43aa49b37af39678cd04e7</guid>
<pubDate>Tue, 26 Aug 2025 01:27:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>gibbswire.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30b7c1dcee51dbd3024d64c76bc5e2584d0a62a7a5cb2a0a2ef742d0602a49ea</i><br /><br />Threat actor <b>description</b>: <i>Gibbs Interwire, USA, is the nation's leading processor and distributor of Strip Coil and Wire Products in Stainless Steel, Carbon Steel, Nickel Alloys, and Red Metals. The company is continually growing and increasing production capacity thr            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>hydrometrics.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25244</link>
<guid>62747fb9b55ab4e37a8017a2f02e4440</guid>
<pubDate>Tue, 26 Aug 2025 01:27:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>hydrometrics.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57176a838635e4025c6aae8f335b4ae348cfd8a0e1c42ec546d1625eec87072f</i><br /><br />Threat actor <b>description</b>: <i>Hydrometrics, Inc., USA delivers professional scientific and engineering services to various sectors including industrial, commercial, municipal, and private clients across the United States. With over 40 years of experience, the company spec            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.nuggetent.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25245</link>
<guid>8e0f0412f7f84bfb507fed3304cfe0e0</guid>
<pubDate>Tue, 26 Aug 2025 01:27:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.nuggetent.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e088470a4b2ea14e586af3a3bb8951c760ae173c03bd84ef705d46fbb1848909</i><br /><br />Threat actor <b>description</b>: <i>Nugget Enterprises, Inc. USA - We can't protect Your Data. The company develops software and provides servers for dozens of companies across the country. Is Your Data Really Secure? - That's the question hanging on the home page of the compan            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Security-First-Credit-Union</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25246</link>
<guid>873111dfe6a0f5f2008f00687567e5d8</guid>
<pubDate>Mon, 25 Aug 2025 22:52:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Security-First-Credit-Union</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5ca40e218d9bd7b501d8f8081943746b68d36b68538f4d92ff95e32c306a654</i><br /><br />Threat actor <b>description</b>: <i>Security First Credit Union is the largest locally-based credit union in the Rio Grande Valley, focusing on providing financial services for the community. They offer a variety of products including savings and checking accounts, loans, mortgages, and mobile banking solutions. Their target clients are individuals and families in the Rio Grande Valley looking for accessible banking options and support. The credit union emphasizes community involvement and member benefits, aiming to enhance financial literacy through workshops and education programs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huntwood-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25247</link>
<guid>6ab5309c61d84b1386faaf1eb27aff0c</guid>
<pubDate>Mon, 25 Aug 2025 20:19:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Huntwood-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08f685b194dec5fe93c45c3fbdc5376eac11e96d94d1df6ab7b4ccd0ead649b0</i><br /><br />Threat actor <b>description</b>: <i>Huntwood Industries is a custom furniture manufacturer offering a selection of designs and finishes for residential spaces. Founded in 1988 in Liberty Lake, Washington, the company has grown to become the largest custom furniture manufacturer in the western United States.</i><br />Target victim <b>website</b>: <i>huntwood.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pocono-Farms-Country-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25242</link>
<guid>353b78669dd07c3d95ea4acbe7130488</guid>
<pubDate>Mon, 25 Aug 2025 18:50:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Pocono-Farms-Country-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bbc21b503be1a856c04c6c2c98917198c61187efb113c2ca5d36707edb60e88</i><br /><br />Threat actor <b>description</b>: <i>Pocono Farms Country Club - is a vibrant community offering a combination of family fun, recreational opportunities, golf, dining, clubbing and home ownership! Has shown themselves to be bad, as they treat information security very poorly and have paid the price! Ordinary people and members of Pocono Farms Country Club have been affected! The list of all transactions, purchases, visits, bank transactions and people's sensitive data has been compromised! Also Pocono Farms Country Club has chosen a position of silence, so all the hidden data will be here!</i><br />Target victim <b>website</b>: <i>https:poconofarms.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>nrlassoc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25231</link>
<guid>95729d35a507b967329beec22743ec26</guid>
<pubDate>Mon, 25 Aug 2025 17:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>nrlassoc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c33dfc4c8fd0cf984216132f77e47184036d7bebfd426dc44d00cbc005d7ac68</i><br /><br />Threat actor <b>description</b>: <i>NRL Associates, Inc. USA. The company manufactures machine tooled parts for a variety of customers. 10 years ago, the company significantly expanded and moved into a new 55,000 square foot state-of-the-art facility. They now have the most mod            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Van-Hook-Dental-Studio</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25234</link>
<guid>e56dbe0f3e1c9cecf699a16e06a98cae</guid>
<pubDate>Mon, 25 Aug 2025 16:38:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Van-Hook-Dental-Studio</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc67b65eaca066f46d03690dba6dbc0f9f553c04c7054361f1dfaad959d528ab</i><br /><br />Threat actor <b>description</b>: <i>Van Hook Dental Studio is a privately-owned dental laboratory that serves as an extension to dental practices. With 40 years of experience, they offer a range of products including fixed, removable, and implant restorations. Their services encompass custom shades, imaging, clinical advising, and on-site assistance. All products are FDA cleared and manufactured in the U.S.A.</i><br />Target victim <b>website</b>: <i>www.vhdental.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>trico176.orgUSA180GB</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25240</link>
<guid>b61db6a910e3b66ec8c44f77a713aa37</guid>
<pubDate>Mon, 25 Aug 2025 15:13:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>kairos</b> claims attack for <b>trico176.orgUSA180GB</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce9401912d6e8b62feb22edad0e529c859e53ce5e0179812a3ea29f00b81e5e6</i><br /><br />Threat actor <b>description</b>: <i>Unknown - Trico</i><br />Target victim <b>website</b>: <i>trico176.org</i>]]></description>
<category>kairos</category>
</item>
<item xmlns:dc='ns:1'>
<title>Dynacast</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25237</link>
<guid>0d6c3328aca8283a680588b4b4ea566e</guid>
<pubDate>Mon, 25 Aug 2025 13:41:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>direwolf</b> claims attack for <b>Dynacast</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0b60af2e171ee8f8d66aba4b44af43355b4d302e99bf34a56b8a2cfe18726956</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Dynacast is a global manufacturing company specializing in engineered metal components. It provides solutions using precision die casting, metal injection molding, and CNC machining. It caters to various sectors including automotive, healthcare, and consumer electronics. Established in 1936, Dynacast operates more than 20 manufacturing facilities in over a dozen countries.
</i><br />Target victim <b>website</b>: <i>dynacast.com</i>]]></description>
<category>direwolf</category>
</item>
<item xmlns:dc='ns:1'>
<title>diversifiedcpc.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25229</link>
<guid>e5b2ab6f40f18e0a3ddd836595ce4e2b</guid>
<pubDate>Mon, 25 Aug 2025 12:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>diversifiedcpc.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8ca724645ab23e7ea8f67a799911277b9467e682d873dc47ef794ac01a297212</i><br /><br />Threat actor <b>description</b>: <i>Diversified CPC International, USA manufactures products whose name is not known to the general public. The company is a world leader in the development, manufacture and distribution of aerosol propellants, hydrocarbon refrigerants, biomass s            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>medosweet.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25227</link>
<guid>e5eaa4d331b90223644163f09df29c70</guid>
<pubDate>Sun, 24 Aug 2025 21:27:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>medosweet.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca3d190033c7c2feb29735e188497d970a5548f20c9939fd994b406ef15b059f</i><br /><br />Threat actor <b>description</b>: <i>Medosweet Farms provides a full range of distribution services for fresh and frozen locally produced dairy products, 
made from environmentally friendly materials, to food service businesses throughout the Pacific Northwest.
1.Full company             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Graphite-Construction-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25226</link>
<guid>31dd7223d9103a8b518281cc099139b8</guid>
<pubDate>Sat, 23 Aug 2025 16:28:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Graphite-Construction-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cc4e5120cfff99cf4eedcf05fc245612089b55f3469fa4f086b90a4fa83c6843</i><br /><br />Threat actor <b>description</b>: <i>Graphite Construction Group is a commercial construction company that provides exceptional service and innovative design solutions that exceed expectations for quality construction.

It is Central Iowa's fastest-growing contractor.

In th            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>George-Haney--Son</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25223</link>
<guid>f34c1c12d462e8df1728610c4485db59</guid>
<pubDate>Sat, 23 Aug 2025 08:26:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>George-Haney--Son</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6d7e96dba887e1454efed4140503fcc0c00d66a5e2017e3627ac0e137caada71</i><br /><br />Threat actor <b>description</b>: <i>George Haney & Son Inc is a family-owned HVAC contractor based in Pasadena, CA, providing services to the San Fernando and San Gabriel Valleys. With a strong re...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>GEA-Consulting-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25221</link>
<guid>5fc4698a9539a70b368c5aa9736c49eb</guid>
<pubDate>Sat, 23 Aug 2025 07:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>GEA-Consulting-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ca8c52e2b8d9631632127602565289dd469e1a1eba854692ef6e81c37e083893</i><br /><br />Threat actor <b>description</b>: <i>(including financial documentation and client data) Founded in 1996, GEA Consulting Engineers is an engineering firm specializing in the design of mechanical, e...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wier-Boerner-Allin</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25220</link>
<guid>a97c37ca1941f04c8822733923adb673</guid>
<pubDate>Fri, 22 Aug 2025 19:12:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Wier-Boerner-Allin</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7b5c871c57ee36d207421ed313fd2af7ff42e6fddaf497fd41b6240d49ef4f9e</i><br /><br />Threat actor <b>description</b>: <i>WBA provides comprehensive architecture, interior design, and planning services that are both sensible and artful, tailored to a variety of design challenges. The company's portfolio includes such notable projects as the Brandon Amphitheater, Daddy Noble Field Stadium, and Mississippi Trade Mart, demonstrating its expertise in creating facilities. The company primarily serves clients in the public sector, including municipalities and educational institutions.</i><br />Target victim <b>website</b>: <i>wbaarchitecture.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mark-Edward-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25215</link>
<guid>4fe2f671070a7732be2a6781c96f665e</guid>
<pubDate>Fri, 22 Aug 2025 17:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Mark-Edward-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4868d7b167294110f0757b50bc62f223193bdfcf17a0347a96361205eb1c2fd5</i><br /><br />Threat actor <b>description</b>: <i>Mark Edward Partners is an independent full-service internationalbrokerage firm that offers comprehensive insurance solutions to a diverse clients.We are going to upload about 6gb of corporate files. You will find lots of client information, some documents contain personal information, numerous confidentiality agreements and contracts, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hill-Peterson-CarperBee--Deitzler</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25209</link>
<guid>4abd325e59c9705044764303dc5845b0</guid>
<pubDate>Fri, 22 Aug 2025 14:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hill-Peterson-CarperBee--Deitzler</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8a08e6e172769904cfd48dd56a5d1a346db1efe07987e2ee874b34151464911</i><br /><br />Threat actor <b>description</b>: <i>The Law Firm of Hill, Peterson, Carper, Bee & Deitzler, PLLC, began in 1980, when senior partner, R. Edison Hill, departed a largecorporate and insurance defense firm to begin a small personal injury practice. Today, our team of skilled attorneys engage exclusively in representing personal injury victims.We are going to upload company data soon. You will find financialdata (payment details, invoices),confidential information and other documents with personal information so on. A bit of personal files and customers data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Exotherm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25210</link>
<guid>0243242e59fbaabc4d27962c7bf26a1d</guid>
<pubDate>Fri, 22 Aug 2025 14:27:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Exotherm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8b53629f2925e011f9aad1ff0fa4d0f0dbe3e251e5baa7a9101346e29f48ccde</i><br /><br />Threat actor <b>description</b>: <i>Exotherm Corporation is a leader in the development and manufacture of custom-made heating devices. They produce Uniflux brand convection heaters.We are ready to upload more than 30GB files of essential corporate documents such as: financial data (audit, payment details, invoices), employees and customers information (Social Security Numbers, phones, medical information) confidential information, NDAs and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hogan-Construction-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25212</link>
<guid>e649b6eb958a777ca96ee70f22c6b27f</guid>
<pubDate>Fri, 22 Aug 2025 14:27:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hogan-Construction-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b2e0871419aa3f449f396128bb12ad5da004a817178692f9d2245d66bc465918</i><br /><br />Threat actor <b>description</b>: <i>Hogan Construction Group is a company that provides a comprehensive platform of value-based, client-focused construction management services. It offers interior renovations, design and bid-Build,historic restorations, and adaptive re-use.We are ready to upload more than 16GB files of essential corporate documents such as: financial data (audit, payment details, invoices), employees and customers information (Social Security Numbers, phones, emails, death/birth certificate ) confidential information and other documents with detailed personal information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mobal-Trucking</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25211</link>
<guid>1d28749e710c723a89ef42b371356b11</guid>
<pubDate>Fri, 22 Aug 2025 08:20:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Mobal-Trucking</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3e5441011349d0b5621488c315a4c0154f8563f3126dc91c8209f5ebb3613e3</i><br /><br />Threat actor <b>description</b>: <i>CONTACT INFORMATION OFFICE - 636-294-0770 MAL GREWAL MAIN NUMBER - 314-267-4288 {24 HOURS} FAX - 636-980-9719 EMAIL ADDRESS - MOBAL3855@YAHOO.COM</i><br />Target victim <b>website</b>: <i>-</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jacks-Lawn-Service-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25213</link>
<guid>25d6202ac9a813700f3660aafd2c59b8</guid>
<pubDate>Fri, 22 Aug 2025 08:19:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Jacks-Lawn-Service-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>265861dad6c460c344d99033d9554e80ad402f25cfe875d47164d6fc5e99818d</i><br /><br />Threat actor <b>description</b>: <i>Jack's Lawn Service, Inc., located in Monroe, Michigan, offers a comprehensive range of landscaping services for both residential and commercial clients. Their services include lawn maintenance, weed control, fertilization, insecticide applications, and small engine repairs among others. The company is dedicated to customer satisfaction and provides free estimates along with a 24/7 answering service for after-hour inquiries. Established in 1977, Jack's Lawn Service prides itself on earning the trust of its customers through high-quality service. https://www.zoominfo.com/c/jacks-lawn-service-inc/66176570</i><br />Target victim <b>website</b>: <i>www.jackslawnservice.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.greneker.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25206</link>
<guid>d976f9a7a2ee232ce4143426a181bd0a</guid>
<pubDate>Fri, 22 Aug 2025 01:27:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.greneker.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1529836fb656c5a94c7b77f0dfe85b7cf45b1a7bf70e8fd897ae6ec9bee82c48</i><br /><br />Threat actor <b>description</b>: <i>Greneker, USA - boobs and slaves. The company manufactures mannequins for clothing stores and entertainment centers. Its clients include major international brands such as Disney and Under Armour. The published date reveals the unpleasant sid            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.gillette-ac.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25195</link>
<guid>e8a31c08d0faff38f8bfa57c75d80828</guid>
<pubDate>Thu, 21 Aug 2025 21:27:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.gillette-ac.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d7ce758b570e5505cbb75120cc8c1384494a7992ceba8233892f0658e144ffd3</i><br /><br />Threat actor <b>description</b>: <i>Gillette Air Conditioning Company, USA specializes in air conditioning, heating, refrigeration, and boilers for commercial and industrial facilities. The company prides itself on safety, quality, and productivity, utilizing advanced technolog            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>TechSourceOne-IT-Solutions-Provider</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25197</link>
<guid>a70ef651f1086ff9a0a988e4ed93069a</guid>
<pubDate>Thu, 21 Aug 2025 21:27:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>TechSourceOne-IT-Solutions-Provider</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6e089e8825b1f88e6e15827d60c54b334705f9b95cb99b8f01de710f0b0d8a5b</i><br /><br />Threat actor <b>description</b>: <i>Email services & protection
Managed email services including SPAM filters, anti-virus, anti-malware protection.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sonitrol-Security-Solutions-SecureFL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25202</link>
<guid>dfb72f52212ce3e209fcaf3af7388a4d</guid>
<pubDate>Thu, 21 Aug 2025 21:27:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Sonitrol-Security-Solutions-SecureFL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>aa8d13d38fb558d57aacd0bc1487ec3190a57a3f22bb3b83a03af1911bb3f9fb</i><br /><br />Threat actor <b>description</b>: <i>Our mission is to provide the best in electronic security so that OUR community is a safer place to live and work.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Colmar-Industrial-Supplies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25204</link>
<guid>c98a3fedd72195a304fba80ebaa320fe</guid>
<pubDate>Thu, 21 Aug 2025 18:41:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Colmar-Industrial-Supplies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae300447c93f32edfbefa26add6a3de9546b519a40a164ae30c14a26322665b4</i><br /><br />Threat actor <b>description</b>: <i>Colmar Industrial Supplies Inc. is a leading distributor of cutting tools and industrial supplies located in Chicagoland. They offer a wide range of products, including cutting tools, maintenance and repair supplies, workholding solutions, precision measuring instruments, and abrasives for grinding and finishing. The company is committed to providing innovative and cost-effective solutions, ensuring timely responses and efficient inventory management for their clients. Their expert customer service team is dedicated to minimizing downtime for manufacturers and guaranteeing quick delivery of essential products.</i><br />Target victim <b>website</b>: <i>www.colmarindustrial.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Huron-Regional-Medical-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25205</link>
<guid>fb739f78a1b83ccad7886436e3146c77</guid>
<pubDate>Thu, 21 Aug 2025 17:09:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Huron-Regional-Medical-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5c51b93802b4c2668bd4da37bd637b95618481e9d4634fb1505057adf720aa5e</i><br /><br />Threat actor <b>description</b>: <i>HRMC is a private, not-for-profit organization. When the ownership of Huron's hospital passed from the Fransciscan Sisters to a locally-owned, private corporation (Huron Regional Medical Center, Inc.) in 1978, those involved in the purchase wanted to ensure Huron's community hospital would be governed by a board of directors reflecting a broad-base of the community. The volunteer board consists of three members recommended by the medical staff, one recommended by the City of Huron and one recommended by the Beadle County Commission. The other board members are elected at-large. Each board member is elected for a three-year term and can serve up to three consecutive terms. The property, funds, affairs and business of HRMC are managed by the board of directors, which is vested with the powers and authority conferred by the laws of South Dakota.</i><br />Target victim <b>website</b>: <i>www.huronregional.org</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sofo-Foods</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25194</link>
<guid>d877cfa2690d0b688ded2759209edea3</guid>
<pubDate>Thu, 21 Aug 2025 15:35:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>payoutsking</b> claims attack for <b>Sofo-Foods</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f583c254ba58d4cd300d722e6330660c58093fd59223ee5e00cb07906981b56c</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Sofo Foods is a family-owned food distribution company specializing in Italian and Mediterranean products. Founded in 1949, the company offers a wide range of products including deli items, produce, bakery items, meats, and cheeses. Sofo Foods mainly serves restaurants and retailers in the midwest and southeastern regions of the United States. It also provides catering services, food preparation tips, and recipes to its clients.</i><br />Target victim <b>website</b>: <i>sofofoods.com</i>]]></description>
<category>payoutsking</category>
</item>
<item xmlns:dc='ns:1'>
<title>Blazer-Building</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25190</link>
<guid>d31b97335d631727f3e7be457307c3a9</guid>
<pubDate>Thu, 21 Aug 2025 15:27:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Blazer-Building</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ac43d54bcda4f42dc0225148604d2669973049c87d3280debaf300b99788f27d</i><br /><br />Threat actor <b>description</b>: <i>Blazer Building is a general construction company that specializes in the expedited delivery of high-quality apartment homes.We are going to upload about 10gb of corporate files. You will find employees information (DOB, addresses, SSNs, phones, even petsnames and so on), HR files, detailed financial and accounting information (customers files), agreements and contracts, employee financial information, violation reports, police reports, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burt-Process-Equipment</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25191</link>
<guid>a66cefccf3f00265d7d3136e3008f5b9</guid>
<pubDate>Thu, 21 Aug 2025 15:27:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Burt-Process-Equipment</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e95aaa669689a90679d7f538289f9da3e07cd8ec1e14982397f576af271a5db2</i><br /><br />Threat actor <b>description</b>: <i>Burt Process Equipment is a leader in the worldwide community of people, businesses, and organizations striving to create a betterenvironment through the innovative and responsible use of water and natural resources. We are going to upload about 19gb of corporate files. You will find employees information (DOB, addresses, SSNs, phones, emails and so on), HR files, detailed financial and accounting information(customers files, employee financial information, payment details), lots of scanned docs with personal data, agreements and contracts, NDAs, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>All-Truck-Transportation-Co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25186</link>
<guid>b3a6feac837e75982c8b2bc0997cec29</guid>
<pubDate>Thu, 21 Aug 2025 04:14:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>spacebears</b> claims attack for <b>All-Truck-Transportation-Co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2f290a5e4cf6c0c8bdc9a898f3fc157d9acac1020e7f7ed1fdff0100274fcd0b</i><br /><br />Threat actor <b>description</b>: <i>All Truck Transportation Co, Inc. was founded in 1978 by CEO/Owner Mathew J. Alagna and is based in Chicago, IL. Over the years the company has grown steadily focusing on its commitment to provide qualified professional drivers and well maintained equipment with the latest technology. Each client’s needs are analyzed by their current transportation process. A customized solution is designed for each individual customer affording the companies maximum productivity to reduce their overall transportation costs.- Database- Financial documents- Personal information of employees and clients https://www.alltruck.com/</i><br />Target victim <b>website</b>: <i>www.alltruck.com</i>]]></description>
<category>spacebears</category>
</item>
<item xmlns:dc='ns:1'>
<title>Fullerton-Surgical-Center-FSC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25182</link>
<guid>57be811f4915eea52686805835b070b0</guid>
<pubDate>Thu, 21 Aug 2025 00:27:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Fullerton-Surgical-Center-FSC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2c03a459358b1d4ec0ae12f3acdfff8e34c4b90811e1ccdad4e162ac5e09460d</i><br /><br />Threat actor <b>description</b>: <i>Fullerton Surgical Center, USA, is a surgical clinic offering services in general surgery, orthopedics, otolaryngology, plastic surgery, pain management, urology, and gastroenterology. Of course, all these services cost a fortune, and the US             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ocean-Edge-Resort--Golf-Club</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25173</link>
<guid>2bfcb7da18b6e9b885e9aeedadad7e12</guid>
<pubDate>Wed, 20 Aug 2025 21:27:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>Ocean-Edge-Resort--Golf-Club</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fadf192ada021ae4fabeff4ac162a09bb3ff41aae5e3207f1cd8c77ba1149d31</i><br /><br />Threat actor <b>description</b>: <i>Ocean Edge Resort & Golf Club is a 429-acre resort in Brewster, Cape Cod (Massachusetts) featuring a historic mansion, luxury villas, golf, private beach access, and a wide range of dining, wellness, and recreational options.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>CBG-Surveying-Texas</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25184</link>
<guid>36a3c31c3e6d065c50b3d80fd9ba39bf</guid>
<pubDate>Wed, 20 Aug 2025 19:43:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>CBG-Surveying-Texas</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>08aadbd00d43fbb5d3d2ae0cfa42e1c8d1a3fdfb88921dc25458c6cd55823332</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cbgtxllc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Omega-Global-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25183</link>
<guid>71bfbe458113bbc3b27576494be78972</guid>
<pubDate>Wed, 20 Aug 2025 19:06:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Omega-Global-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec685422df51876d57dd461e63ddfc418270dfa3868f529f68faece8ec8e5268</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.omegagti.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greater-Pittsburgh-Orthopaedic-Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25180</link>
<guid>dbcec7736b4d543d9251de81b4a9917f</guid>
<pubDate>Wed, 20 Aug 2025 18:12:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>ransomhouse</b> claims attack for <b>Greater-Pittsburgh-Orthopaedic-Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dbfbe20ce46d52ccb21403268702783923bd554bde324846c03788e78c7180dd</i><br /><br />Threat actor <b>description</b>: <i>Pittsburgh Orthopaedic Associates (GPOA), Pittsburgh’s oldest continuously-operating orthopaedic surgical associates. Our goal is to provide compassionate orthopaedic care to patients of all ages for an extensive variety of conditions.</i><br />Target victim <b>website</b>: <i>www.gpoa.com</i>]]></description>
<category>ransomhouse</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bizcom-Electronics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25156</link>
<guid>a9dbfcad63c454a4e096bbe334b8e45d</guid>
<pubDate>Wed, 20 Aug 2025 16:27:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>Bizcom-Electronics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>993aa64c30ce11857e6fcf74560f16225419b5837aec5d272e2fd7cc5a7c4766</i><br /><br />Threat actor <b>description</b>: <i>izcom Electronics, Inc. is a service provider based in Milpitas, California, spe...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>lee-irvine.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25158</link>
<guid>856821bd2b5bc9082efb1f81f17ea132</guid>
<pubDate>Wed, 20 Aug 2025 16:27:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>lee-irvine.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>80ca79968e31088c9332bb82a913c93dacae422a220f43a0b580aec0c292cfa0</i><br /><br />Threat actor <b>description</b>: <i>Lee & Associates Irvine Inc. is a law firm specializing in representing clients in the acquisition, sale, and leasing of various commercial real estate properties, including industrial, office, retail, and medical properties.
1.The document             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>haaker.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25159</link>
<guid>73a28b73543c4fe7c22ef24532315015</guid>
<pubDate>Wed, 20 Aug 2025 16:27:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>haaker.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>13dced52ca729c5a3e51a21ff7901227d36fc03e88641735ac19f0bebf667763</i><br /><br />Threat actor <b>description</b>: <i>Haaker Equipment Company manufactures sweepers, sludge suction machines, and spare parts for them. The company was founded in 1972 and is headquartered in Los Angeles, California.
1.The document is invoice No. 3300290201 from Nilfisk Inc., i            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>netfusionconsulting.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25161</link>
<guid>a7a6b51b4da2a493f024aac42d94c7cd</guid>
<pubDate>Wed, 20 Aug 2025 16:27:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>netfusionconsulting.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa1d4a57f351bfcf386e779eafcc2ec6ab88d3e75c4ca87d886852a46be563a9</i><br /><br />Threat actor <b>description</b>: <i>NetFusion Consulting, Inc. is California's largest company specializing in IT integration in the medical and dental fields, specializing in IT consulting and integration specifically for dentists. The company offers a wide range of services,             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>garnertrucking.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25162</link>
<guid>53efc88b91116cc2a1c96cb17ddac5cf</guid>
<pubDate>Wed, 20 Aug 2025 16:27:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>garnertrucking.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>237aff47f38efa31defa9466905ef0fd25f4848a48a4eb4207897ea25e55cccb</i><br /><br />Threat actor <b>description</b>: <i>Garner is a company specializing in dry freight transportation, located in northwestern Ohio.
1.The document dated June 2, 2025, is the annual report on school tax withholdings in Ohio for 2021 for Garner Contract Maintenance.
2.The documen            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>RA-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25164</link>
<guid>7b4d37d410b3b267742787492c5cca46</guid>
<pubDate>Wed, 20 Aug 2025 16:27:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RA-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ece6308cdcce83a36c1bba2f483faea4dba5beb4874711c48288757149f6afdd</i><br /><br />Threat actor <b>description</b>: <i>RA Services offer a comprehensive line of medical business solutions to help your practice or healthcare facility achieve its financial and strategic goals.We are ready to upload more than 15GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information ( death certificate, passports,credit cards, medical information) A bit of personal files and customers data.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Steel-Encounters</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25165</link>
<guid>3773b6cf600f775304f7489130b3d7d1</guid>
<pubDate>Wed, 20 Aug 2025 16:27:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Steel-Encounters</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8df5a05801bab1b3e5d0ef540bce9b1a8ee157db4b05c38c736b279679a52ce5</i><br /><br />Threat actor <b>description</b>: <i>Steel Encounters is a commercial specialty subcontractor who provides steel joist and metal deck products and services, glazing, curtain wall, and architectural cladding systems to general contractors, architects, and building owners.We are ready to upload more than 21GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (passports, death/birth certificate, medical information, emails, phones) confidential information and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LandWorks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25166</link>
<guid>ceacaf9856f429dadabb36e45a45c7e2</guid>
<pubDate>Wed, 20 Aug 2025 16:27:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>LandWorks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5e1a11bb835f87d0738857fc8a11a222e93b26fad6c66929c6381f007b83c3ac</i><br /><br />Threat actor <b>description</b>: <i>Landworks landscape & lawn care company. Providing Residential & Commercial services since 1995 to Johnson County & greater KansasCity area.We are ready to upload more than 30GB files of essential corporate documents such as: financial data (audit, payment details, invoices), employees and customers information (Social Security Numbers, phones, medical information) confidential information and other documents with detailed personal information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>RAVEN-Mechanical</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25167</link>
<guid>25485df232e188a3f3e514ee1c9de020</guid>
<pubDate>Wed, 20 Aug 2025 16:27:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>RAVEN-Mechanical</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>99f353a378c8abfa7804031462c88f1074fcef5d76a2d7d5e78d76501a76c850</i><br /><br />Threat actor <b>description</b>: <i>Raven Mechanical is a family owned and operated commercial specialty construction company specializing in plumbing, HVAC, utility and specialty piping projects.We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), employees and customers information (passports, driver's licenses, SSCs, birth certificates ) and other confidential information, NDAs and documents with detailed personal information.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Blending-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25168</link>
<guid>2eed49993f93259b52fe9ad0f9d0c190</guid>
<pubDate>Wed, 20 Aug 2025 16:27:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Advanced-Blending-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90c52045a05a643ab8f0ab37974badf11bfcc7017eb9c6e931d8e732b0bceeba</i><br /><br />Threat actor <b>description</b>: <i>Advanced Blending Solutions is a leading designer, manufacturer, and supplier of blending and material convey equipment tailored for the plastics industry. We are going to upload about 352gb ( 10gb of SQL databases) of corporate files. You will find detailed employees information (DOB,DL numbers, addresses, SSNs, phones, and so on), HR files, detailed financial and accounting information, lost of agreements and contracts, credit card details, scans of documents with detailed personal information, customer financial and other information, etc.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Elkhart-Independent-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25179</link>
<guid>64bac3ef8a6e27b02dc9d6d972b03795</guid>
<pubDate>Wed, 20 Aug 2025 15:16:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Elkhart-Independent-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97b8fe89c452ab29549d2c066c95888daa61bd6c53e21b175f1f53a9038f1fba</i><br /><br />Threat actor <b>description</b>: <i>Elkhart Independent School District Elkhart Independent School District is a public school district based in Elkhart, Texas (USA). The district is located in southwest Anderson County and extends into northern Houston County.    More</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>southweststone.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25154</link>
<guid>d21555f006e86254e92c2b77463def4f</guid>
<pubDate>Wed, 20 Aug 2025 09:07:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>J</b> claims attack for <b>southweststone.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5aab22c4f92fa75e4d799b70309552199e2d86d3b1edbfeda9808602a65dfc17</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>southweststone.net</i>]]></description>
<category>J</category>
</item>
<item xmlns:dc='ns:1'>
<title>Burger--Brown-Engineering</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25146</link>
<guid>8c317a7c6c3e9bd6382554ce9f0811aa</guid>
<pubDate>Wed, 20 Aug 2025 00:18:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Burger--Brown-Engineering</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c1e4f1a98af21e2cd0cb1ef74697972fd60629145189ef8b36043ec42c9eedfb</i><br /><br />Threat actor <b>description</b>: <i>Burger & Brown Engineering, Inc. specializes in precision machining and injection molding services, serving clients in Kansas City and surrounding areas. The company's capabilities include precision CNC machining, high-speed micro milling, custom injection molding, and engineering design among others. Their clients span various industries, including the Department of Energy, medical, consumer products, and semi-conductor sectors. With a commitment to customer care and satisfaction, Burger & Brown aims to deliver manufacturing excellence and noteworthy quality in their services.</i><br />Target victim <b>website</b>: <i>www.burger-brown.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mutual-Screw--Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25147</link>
<guid>18318da7dae61a542729d9da994161be</guid>
<pubDate>Wed, 20 Aug 2025 00:18:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Mutual-Screw--Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>68b878e618f16c1f2780ad5cfbca62f721c75e8a2842e18f4bc6935dcf8788c6</i><br /><br />Threat actor <b>description</b>: <i>Mutual Screw & Supply is a leading distributor specializing in industrial fasteners and related accessories, offering a vast array of products including screws, nuts, bolts, washers, rivets, and safety equipment. Established in 1947, the company prides itself on providing high-quality products from reputable brands such as 3M, Starrett, and Irwin. Their services cater to a wide range of clients, enabling custom solutions, automated orders, and special pricing for bulk purchases. The company is dedicated to delivering exceptional customer service, ensuring that clients have easy access to the fasteners they need.</i><br />Target victim <b>website</b>: <i>www.mutualscrew.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Horizon-Hydraulics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25148</link>
<guid>861771f24543eab4b20bd2e057a44c39</guid>
<pubDate>Wed, 20 Aug 2025 00:17:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Horizon-Hydraulics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c054c9353c2af985939cbccd711d0eb19de85b9a70601248c6636c830ce33ba9</i><br /><br />Threat actor <b>description</b>: <i>Horizon Hydraulics is a full line hydraulic and pneumatic service center. They work across a wide array of industries and their services include both industrial and mobile hydraulics. Horizon Hydraulics is based in Oklahoma City, OK. Their experienced team of professionals is committed to providing the best fluid power solutions. We have a thorough process of diagnostic evaluation. Providing the right solutions for hydraulic maintenance and repair is not easy.  They have been providing our customers with the right solutions since 1983.</i><br />Target victim <b>website</b>: <i>www.horizonhydraulics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Stewart-Home-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25149</link>
<guid>2354ec2849bd2954df8dd2f2199d58a2</guid>
<pubDate>Wed, 20 Aug 2025 00:17:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Stewart-Home-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1c2d13e4edd67ed148267477c905f43190de97f4a9be3443f8238490bb9a4806</i><br /><br />Threat actor <b>description</b>: <i>Stewart Home & School is a residential school located in Franklin County, Kentucky, dedicated to serving individuals with intellectual or developmental disabilities. With over 130 years of experience, the institution offers a nurturing environment that prioritizes personal growth, social development, and lifelong learning through various programs including academics, vocational training, and recreational activities. Their community supports students in building friendships and participating in enriching activities such as sports and equestrian programs. Stewart Home & School invites prospective families to visit and witness the joyful atmosphere where students thrive.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>TD-Engineers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25150</link>
<guid>32600351773d885ac6fe1873947e7dfa</guid>
<pubDate>Wed, 20 Aug 2025 00:17:11 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>TD-Engineers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>313c3491c18d4f1e17e575bf883925288da1b2e31bbfefc055a00328d3d3fcf1</i><br /><br />Threat actor <b>description</b>: <i>T&D Engineers - Houston Texas. is a mechanical, electrical and plumbing (MEP) consulting engineering firm. They offer a diverse selection of engineering and design services for all phases of your building's lifecycle including initial planning and design, construction administration, ongoing upgrade and renovations and system troubleshooting.</i><br />Target victim <b>website</b>: <i>www.tdengineers.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRANTRONICS</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25151</link>
<guid>fd2c18a27361dd16124f2780015b05f3</guid>
<pubDate>Wed, 20 Aug 2025 00:16:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>TRANTRONICS</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cf02f6744f89a3c2f72ed11ffa0a2452b5088154eeb02cf5e44b21220a2ec646</i><br /><br />Threat actor <b>description</b>: <i>TRANTRONICS specializes in electronic assembly and quick turnaround of surface mount and thru-hole board assembly for prototype, pre-production and production orders. TRANTRONICS' mission is to be the recognized leader and highest quality provider of electronic contract manufacturing and services in the industry. Our goal is to provide superior quality work, on time delivery and competitive pricing. They understand and appreciate your sense of urgency and will provide the quickest turnaround available on quotations and assembly services.  They strive to exceed your expectations and to ensure the highest level of quality.  Trantronics is certified in ISO 9001:2008, ISO 13485.2003 and AS9100, which helps us in providing unparalleled quality, quick turn-around time and exceptional customer support. </i><br />Target victim <b>website</b>: <i>www.trantronics.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Mediate-Management</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25152</link>
<guid>dc61c1317e2c1637f0f8d2de7fd8da9b</guid>
<pubDate>Wed, 20 Aug 2025 00:16:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Mediate-Management</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e32eb6109eadf478d1cb49fe2f68eab511c1ea7c8802d328e3d0daa2e334309e</i><br /><br />Threat actor <b>description</b>: <i>Mediate Management is a property management company based in Boston, Massachusetts, specializing in rental and condo property management. They aim to provide effortless homeownership and maximize property value through comprehensive services, including maintenance, cleaning, and project management. Their commitment to exceptional customer service ensures each property is treated with individualized care and support available around the clock. Mediate Management caters to various types of properties, leveraging extensive experience to address unique challenges in community living.</i><br />Target victim <b>website</b>: <i>mediatemanagement.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>MPOWERHealth</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25144</link>
<guid>208c538e54592a60bde61d93e10cde94</guid>
<pubDate>Tue, 19 Aug 2025 21:28:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>MPOWERHealth</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8e51b2406e15da29a93e43be0e196df175ab11b2584531ec322c2a7ee489623f</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>childrenscouncil.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25145</link>
<guid>be419cdf098bae8c8530ea4f19af3837</guid>
<pubDate>Tue, 19 Aug 2025 20:39:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>childrenscouncil.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>114d473013a9e743cfcd3c5ad544ab2f230093560dfcc4b54e859ad91da7edb2</i><br /><br />Threat actor <b>description</b>: <i>Children’s Council of San Francisco is a nonprofit organization with over 50 years of experience advocating for and facilitating high-quality …</i><br />Target victim <b>website</b>: <i>childrenscouncil.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bobcat-Central</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25141</link>
<guid>0b7127c966fa2dc3e83d3c9651e9d9b6</guid>
<pubDate>Tue, 19 Aug 2025 17:27:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Bobcat-Central</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d2ac65079ad31f2a82cdda9d0d9d0623ea009bf4809ba64ff6013703862c3b9e</i><br /><br />Threat actor <b>description</b>: <i>Bobcat Central, Inc. began operations in Stockton in 1976. The company is an equipment dealer offering parts, service, rental, andsales of Bobcat equipment, attachments, Doosan heavy equipment, Tigercat, and Towmaster trailers.We are ready to upload more than 12GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers information (driver's license, Social Security Numbers, medical information) confidential information, NDAs and other documents with detailed personal information .</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Electro-Tech</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25142</link>
<guid>9940dc91e5d2185602912ef38945fcea</guid>
<pubDate>Tue, 19 Aug 2025 17:27:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Electro-Tech</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f6d6d69585394df46398e5132c20969360beed401af033a852e6fc26a3d69a3</i><br /><br />Threat actor <b>description</b>: <i>ElectroTech, Incorporated is a manufacturers representative for electrical products.We are going to upload company data soon. You will find financialdata (audit, payment details,financial reports, invoices), NDAs and other documents with detailed personal information and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rare-Editions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25143</link>
<guid>bfc58c81e954a4ee8722992437a86d9d</guid>
<pubDate>Tue, 19 Aug 2025 17:27:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rare-Editions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d3d58ac3397e7788005337dae6a85dc80005643fdfc5efdce57ee77783541c77</i><br /><br />Threat actor <b>description</b>: <i>Rare Editions has been making dresses for girls for over fifty years. Their line consists of dresses for special occasions, including birthday dresses, christening dresses, and flower girl dresses.We are going to upload company data soon. You will find financialdata , employees and customers information. Lots of projects information with samples of their products and other details.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>True-World-Group-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25130</link>
<guid>2c6da25c244f420a938f030b17e22d3e</guid>
<pubDate>Tue, 19 Aug 2025 15:26:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>True-World-Group-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>118f3561ef16f851b56ec253f58c0200c0242c405505962660a2dfa9065c15ef</i><br /><br />Threat actor <b>description</b>: <i>True World Group is one of the nation’s leading, diversified seafood-products co...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>Inotiv-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25129</link>
<guid>3393355454eebbeb6857ffa079e431ca</guid>
<pubDate>Tue, 19 Aug 2025 12:28:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Inotiv-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6eb87b9d3b42598fd7928f3b04b99529d9d95294a0429350c872ff9e922cac77</i><br /><br />Threat actor <b>description</b>: <i>Inotiv, Inc. is a publicly USA traded contract research organization (CRO) that provides nonclinical and analytical drug discovery and development services to the pharmaceutical and medical device industries.As a leading contract research org            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cain-Electric</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25138</link>
<guid>e8cc6d71668a336b1fae96066323a6ba</guid>
<pubDate>Tue, 19 Aug 2025 11:49:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Cain-Electric</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>97537f1877b4d7f5555d7b13d688db34ed7ec7ef5b48ea590ac2daa3bff47e1e</i><br /><br />Threat actor <b>description</b>: <i>At Cain Electric, we provide a full array of different services for our customers. From electrical service repair to solar installation of residential solar panels, we offer the advanced electrical solutions you need. We also offer new construction electrical services, industrial electrical installation, commercial electrical maintenance, security camera system installation, and more. Get the trusted electrical services you need for your residential, commercial, or industrial property today</i><br />Target victim <b>website</b>: <i>www.mikecainelectric.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>godbyhearth.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25132</link>
<guid>c24c1162580cb8b37ff4815dda98f4c3</guid>
<pubDate>Tue, 19 Aug 2025 10:11:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>godbyhearth.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b3478eab864c0ace4988a1cae4ecf61c5bd0431253171d4480b0876016dc6652</i><br /><br />Threat actor <b>description</b>: <i>Operating in Indianapolis and Carmel, Indiana, Godby Hearth & Home is a premium provider of home comfort solutions with origins …</i><br />Target victim <b>website</b>: <i>godbyhearth.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>apderm.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25126</link>
<guid>e3f2b325739bbe549d3875450b27a3a1</guid>
<pubDate>Mon, 18 Aug 2025 19:59:40 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>apderm.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b2d8907dc2ebdb99db0225f43e46603d975c45161596bf04386ddb58882693e</i><br /><br />Threat actor <b>description</b>: <i>APDerm is the largest physician-owned dermatology clinic in New England, with 25 locations in New Hampshire, Massachusetts, and Rhode Island. The company offers a full range of innovative medical, surgical, and cosmetic procedures to help pat            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-Security-Systems</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25124</link>
<guid>f03a550c53b59ef2cb9970d9672c78da</guid>
<pubDate>Mon, 18 Aug 2025 12:43:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Advanced-Security-Systems</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>632d0bbab2f6c33693fff3225a36d54f51c8cec9f3ead91628fc956237ed5aa0</i><br /><br />Threat actor <b>description</b>: <i>Advanced Security Systems has been a leader in the security industry for over 45 years. It customs design, install and service: burglar and fire alarms, video surveillance, access control and home automation, controlling lights, thermostat, door locks and more all from the smart phone. It transmits fire and security alarm signals to its monitoring station in Eureka. Advanced Security offers the only local monitoring station on the Northcoast. It invested in building and staffing its own local central station instead of contracting with a third party out-of-the-area provider. Advanced Security has remained a family owned and operated alarm company since 1971.</i><br />Target victim <b>website</b>: <i>www.advancedsecuritysystems.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>IQgistics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25120</link>
<guid>65b5fc46fc82087ba24609b14f2dc4ff</guid>
<pubDate>Mon, 18 Aug 2025 08:40:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>IQgistics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae0e784d0cb192e29bec5cb38b8d9e0a26cc6513a2a882cc70a3a726f3c281de</i><br /><br />Threat actor <b>description</b>: <i>IQgistics offers innovative GPS fleet tracking solutions designed to enhance logistics management for businesses of all sizes. Their comprehensive suite includes advanced tracking software and cellular products, providing tailored solutions that optimize fleet productivity and reduce operational costs. Utilizing cutting-edge technology, including AI-driven algorithms, IQgistics empowers clients to gain actionable insights and control over their logistics. With a dedicated support team, they ensure clients can focus on their core business while benefiting from scalable and flexible platform solutions.</i><br />Target victim <b>website</b>: <i>www.iqgistics.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rehabilitative-Health-Svc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25095</link>
<guid>875ffa7f896a4da039e296e2d1f54937</guid>
<pubDate>Sun, 17 Aug 2025 10:43:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Rehabilitative-Health-Svc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dc5c8eb8391cefb6cd4bab2abecde1561b70de0c08b4acec260beab86f790894</i><br /><br />Threat actor <b>description</b>: <i>Rehabilitative Health Services (RHS) is a comprehensive medical and mental health facility located in Ammon, ID, offering a diverse array of services including Addiction and Recovery, Family Medicine, Therapy, Counseling, and Psychological Testing. Established to provide quality therapy options, RHS aims to help clients overcome past trauma and navigate various mental health challenges through professional counseling and support services. With over 25 years in the community, RHS is dedicated to addressing both the physical and mental well-being of clients from childhood to adulthood. The facility also emphasizes community support and operates programs specifically designed for youth and individuals with severe mental illnesses</i><br />Target victim <b>website</b>: <i>www.rhscares.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>accsnet.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25101</link>
<guid>940222ade2401c27cf112992065c8877</guid>
<pubDate>Sun, 17 Aug 2025 09:24:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>accsnet.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9803e9552fa376252152a55e7c471e2f581ad5cf755df037820b954b7feda807</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>accsnet.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>advion.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25102</link>
<guid>934ae3fe682fd9b04e9a8b15dd789911</guid>
<pubDate>Sun, 17 Aug 2025 09:23:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>advion.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0634849eb8bea5b4917e683e2db8e12b0150729a69fa268178c120cb263ae9b8</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>advion.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>atcmanufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25103</link>
<guid>d82604de52c7a4c0d104443d90790b81</guid>
<pubDate>Sun, 17 Aug 2025 09:22:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>atcmanufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>07c661b08a4e1d2a7c7cf88ad66eeaf62fa92a29a339ef990b79c16a4f3cc935</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>brightwork.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25107</link>
<guid>b76226c0b9542b5fa7c4ff56ff755802</guid>
<pubDate>Sun, 17 Aug 2025 09:22:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>brightwork.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a977eaeeeeec358b2f880e94d46c750ca31a8c01fc03ca455109e6a3678b14b</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] BrightWork.com is a project management software company that provides solutions for teams and organizations to manage and track their projects. It offers templates, reports, role-based dashboards, risk management and work automation tools. BrightWork.com is designed to be integrated with Microsoft SharePoint, thereby bringing clarity, control, and simplicity to project portfolios.</i><br />Target victim <b>website</b>: <i>brightwork.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>starsalliance.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25096</link>
<guid>e72f04340ba52eeb59aac43d472d1d31</guid>
<pubDate>Sun, 17 Aug 2025 09:21:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>starsalliance.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>36d9eeac733ca4b37c702f6c4bdc3bf472b26a0fd801b447980f14f490492c4e</i><br /><br />Threat actor <b>description</b>: <i>The data has been purchased by other buyers</i><br />Target victim <b>website</b>: <i>starsalliance.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>wytechnology.local</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25098</link>
<guid>1fe165377d4907f0ea45a5397520b85c</guid>
<pubDate>Sun, 17 Aug 2025 09:20:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>wytechnology.local</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>21198fa722280e3d0d9fd9c89984d699e6ea064927ed41c74c406976db36e60e</i><br /><br />Threat actor <b>description</b>: <i>The data has been purchased by other buyers</i><br />Target victim <b>website</b>: <i>wytechnology.local</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>webcids.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25099</link>
<guid>bc4647bddd46ee572310781a51030572</guid>
<pubDate>Sun, 17 Aug 2025 09:20:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>webcids.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3d8f51576c864474402bd839ac89ae165c3a52fb4d7e464d076976e5e549e81e</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>webcids.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>magcpa.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25108</link>
<guid>97d59bbb0fa57e38380bf3415b38b044</guid>
<pubDate>Sun, 17 Aug 2025 09:19:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>magcpa.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>553015fdbe483a724e9f8eaff56a10f469ef96ddee51aa4ed7d124c4dde29e89</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>magcpa.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>primrose.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25112</link>
<guid>f02e21c27440aef2e5c495ce615279e3</guid>
<pubDate>Sun, 17 Aug 2025 09:18:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>primrose.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9c2bcd6fe5e6c77917208bf3b96a9041f10c917e6ebd066dd2832fa469f27335</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>primrose.com</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>clearybuilding.us</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25111</link>
<guid>821b7564a31a15c15f5670de9e5e127d</guid>
<pubDate>Sun, 17 Aug 2025 09:17:35 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>warlock</b> claims attack for <b>clearybuilding.us</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>83f5497c745b0c71804a395d11756e8389c1a771c37fb330723c297059eb759b</i><br /><br />Threat actor <b>description</b>: <i>all data</i><br />Target victim <b>website</b>: <i>clearybuilding.us</i>]]></description>
<category>warlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>mycpaconnection.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25083</link>
<guid>b0513535543a50eb3038a8e06541be1d</guid>
<pubDate>Sun, 17 Aug 2025 00:16:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>mycpaconnection.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44e5a8688689c2d30a6342efe9985ab8b1aaa08b31e4df33c94ea2eaedfd5c54</i><br /><br />Threat actor <b>description</b>: <i>Employees: 25 Revenue:$5 Million Industry:Accounting Services   Phone Number:(704) 878-9541 SENSITIVE DATA_$</i><br />Target victim <b>website</b>: <i>mycpaconnection.com</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hytrol</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25082</link>
<guid>97e61f42dca54837f80794d0ea3bbc4e</guid>
<pubDate>Sat, 16 Aug 2025 16:28:07 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Hytrol</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d17a77985cfcbb21326dee87ae67d60951b9b1dad6c49a589f9e8e3ef6109d7b</i><br /><br />Threat actor <b>description</b>: <i>Hytrol Conveyor Company, Inc. was founded in 1947. The Company's line of business includes manufacturing conveyors and conveying equipment. The company is headquartered in Jonesboro, ArkansasWe are ready to upload more than 20GB files of essential corporate documents such as: financial data (audit, payment details,financial reports, invoices), employees and customers (and even relatives) information (Social Security Card, death certificate, medical information) and other documents with detailed personal information so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>THE-MILLENNIUM-GROUP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25081</link>
<guid>766b9a83afd8feba96ec3dcd724fe4d9</guid>
<pubDate>Sat, 16 Aug 2025 08:20:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>d4rk4rmy</b> claims attack for <b>THE-MILLENNIUM-GROUP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>481fd6f1e7898e41cd2a661f57d0acc9422a8e06a7bd6cf3a5d4d7b9ab723183</i><br /><br />Threat actor <b>description</b>: <i>https://www.tmgofficeservices.com The Millennium Group (TMG) is a global provider of document management and workplace services with more than 40 years of operations. TMG is certified as a Minority Business Enterprise (MBE) and a Woman-Owned Business Enterprise (WBE). The company operates…</i><br />Target victim <b>website</b>: <i>tmgofficeservices.com</i>]]></description>
<category>d4rk4rmy</category>
</item>
<item xmlns:dc='ns:1'>
<title>VINSON--ELKINS-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25080</link>
<guid>b0bad21adb7b77a1503abfc43a27f934</guid>
<pubDate>Sat, 16 Aug 2025 08:19:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>d4rk4rmy</b> claims attack for <b>VINSON--ELKINS-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>129d2ce0b7dde7b33687c6a40b4913d004746550c678f00ba9b740fb1769aaac</i><br /><br />Threat actor <b>description</b>: <i>https://www.velaw.com Vinson & Elkins is a century-strong global law firm that partners with leading companies across key industries on wide‑ranging, complex matters. Blending deep experience with forward‑thinking counsel and close client collaboration, the firm helps organizations pursue goals and navigate…</i><br />Target victim <b>website</b>: <i>www.velaw.com</i>]]></description>
<category>d4rk4rmy</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pequannock-Township-School-District</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25076</link>
<guid>0d3132155b700d53e2684d499a3c30f3</guid>
<pubDate>Fri, 15 Aug 2025 21:52:02 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Pequannock-Township-School-District</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>90ce67cc200fc44244ae483223eda40f57b66ce63a7b8fe73416cf781fddaad8</i><br /><br />Threat actor <b>description</b>: <i>The Pequannock Township School District is a comprehensive community public school district that serves students in pre-kindergarten through twelfth grade from Pequannock Township, in  Morris County, in the U.S. state of New Jersey. As of the 201819 school year, the district, comprised of five schools, had an enrollment of 2,123 students and 167.5 classroom teachers, for a studentteacher ratio of 12.7:1. The district is classified by the New Jersey Department of Education as being in District Factor Group "GH", the third-highest of eight groupings.</i><br />Target victim <b>website</b>: <i>pequannock.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Grand-Rapids-Controls</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25073</link>
<guid>8141c60e393b72d67396df39cdda9c1e</guid>
<pubDate>Fri, 15 Aug 2025 18:47:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Grand-Rapids-Controls</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fd132bcc4e7793d5ea0d6c3529dcfed93b5ca491692a298520222b126db81d00</i><br /><br />Threat actor <b>description</b>: <i>The 150 GB leak involves confidential documents and NDA agreements with companies such as Ford, Bentley, Lear, and others.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>ZMM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25065</link>
<guid>d45e74902b530325e95724b12df237c4</guid>
<pubDate>Fri, 15 Aug 2025 16:09:36 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ZMM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7406a5fc2d5ced688134ee9857459b071b305d3c1605a139391e71e08fd71ef7</i><br /><br />Threat actor <b>description</b>: <i>ZMM Architects and Engineers is an award-winning design firm withoffices in West Virginia, Virginia, and Ohio, providing integrated professional services. They specialize in various sectors including education, healthcare, government, and commercial spaces, employing a holistic approach to building design that encompasses architecture, engineering, and sustainable design.We are ready to upload more than 50GB files of essential corporate documents such as: financial data (audit, payment details,financial reports), employees and customers information, confidential informationand other documents with detailed personal informationso on. You will also find such court hearings and other legal confidential docs.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Philadelphia-Investment-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25068</link>
<guid>f51f2cb97557b09a25b8ca407f1f3f29</guid>
<pubDate>Fri, 15 Aug 2025 15:09:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Philadelphia-Investment-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>37dd7aca113a41ac0ca1ddac1f9fab8b4d91ba7e74ba65c2f0ca5e6ea209a538</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Philadelphia Investment Partners is a private investment firm that focuses on global and international equities. Tracing its roots back to the 1980s, the company seeks to provide high net-worth investors, corporate pension funds, endowments, and foundations with superior investment performance and service.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>MYVISAJOBS.COM</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25071</link>
<guid>8acac47f63dc5da08a77ff8eca8d3986</guid>
<pubDate>Fri, 15 Aug 2025 15:08:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>MYVISAJOBS.COM</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3a8ebc58cc1f99d17363aa4e8a990b27bc59a803bac5cee20e657fcdec23f6fb</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] MYVISAJOBS.COM is a website that helps international students and professionals seeking work in the United States. The platform provides information about job sponsors, visa filings, employment, immigration attorneys, etc. Their data is collected from various U.S. federal agencies. The company aims to help immigrants secure suitable employment in the U.S. and navigate through the visa process efficiently.</i><br />Target victim <b>website</b>: <i>MYVISAJOBS.COM</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Karndean-International-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25066</link>
<guid>fa7fb9f1120429eafb496a431f96bc17</guid>
<pubDate>Fri, 15 Aug 2025 12:12:15 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>crypto24</b> claims attack for <b>Karndean-International-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee7b34e208c38596183d1b32fce0ba6bcc382c2d1443204c329f592a8fbe3816</i><br /><br />Threat actor <b>description</b>: <i>We have exfiltrated over 600GB of your most sensitive corporate data, including financial, technical, operational, and personal information covering customers, employees, and strategic business plans.</i><br />Target victim <b>website</b>: <i>karndean.com</i>]]></description>
<category>crypto24</category>
</item>
<item xmlns:dc='ns:1'>
<title>Norwest-Venture-Partners</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25057</link>
<guid>157c6fd13f6ad2911c5ec3a97dfd4438</guid>
<pubDate>Fri, 15 Aug 2025 00:34:49 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Norwest-Venture-Partners</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>382cfef732776e909c2ec123a2697734987a832aafa99bd95819fba1c4a45a75</i><br /><br />Threat actor <b>description</b>: <i>A top venture and growth equity investment firm, Norwest works side-by-side with the world’s most successful entrepreneurs, providing expert guidance and personalized resources every step of the way. Founded in 1961, Norwest Venture Partners is a global, multi-stage venture capital and growth equity investment firm. The company is headquartered in Palo Alto, California with offices in India and Israel.</i><br />Target victim <b>website</b>: <i>www.nvp.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>www.captrade.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25050</link>
<guid>914ceffcd6e7835cdc715e8ed99a6280</guid>
<pubDate>Thu, 14 Aug 2025 23:28:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>www.captrade.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ee48422ed8cf9feeeabf2b17a92c09694e7548fa7ff0fa39e42f66f44e0999e4</i><br /><br />Threat actor <b>description</b>: <i>Capital Trade, Incorporated, based in Washington, D.C., is the real force behind the crazy policy of raising US tariffs. The company provides legal services in the field of international trade and litigation support. They help the US governme            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ABcom</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25056</link>
<guid>6ece1478634d078f9483620b74fb05f9</guid>
<pubDate>Thu, 14 Aug 2025 21:36:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>ABcom</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2b022e96e3e5f61a6e6181f664b9448cb35feb44ed62e3a86fbcf52b7cc14681</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.abcomllc.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Greenscape-Pump-Services</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25055</link>
<guid>53b86c11c60dd11299ee3b0417d8f2ab</guid>
<pubDate>Thu, 14 Aug 2025 21:36:17 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Greenscape-Pump-Services</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2d7cabd325c273083acf46afaad9921bc5b68f7c33082ca7b559f8dac19bca04</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.gpsiwater.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>eShipGlobal</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25054</link>
<guid>51ac771526c1909f0763cae561568011</guid>
<pubDate>Thu, 14 Aug 2025 21:35:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>eShipGlobal</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>57383989ba9f3af1195ad81295e467afe400ec1cbb144b326cf05a3ce261212b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.eshipglobal.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>NextLabs</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25053</link>
<guid>cedb7f24376214d5fe503683cac8ab74</guid>
<pubDate>Thu, 14 Aug 2025 21:34:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>NextLabs</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1836020c97b1c79ba0b760550015b0734636136c24e0ee6a35dc7f7969f0d4bf</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.nextlabs.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ranshu-Meridian-Auto-Parts-VisionaireOmega-enviromenta-technologies-Ap-Air</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25052</link>
<guid>0d9f790e48d1c2850cc47db8af965495</guid>
<pubDate>Thu, 14 Aug 2025 17:17:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Ranshu-Meridian-Auto-Parts-VisionaireOmega-enviromenta-technologies-Ap-Air</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c3cdebf1cd4fa493f37317b3070b8d20555a977eb5a2b874ad415dbca25d55a9</i><br /><br />Threat actor <b>description</b>: <i>We are going to upload about 47 gb of a bunch of companies. All o
f them are auto parts related. You will find detailed employees i
nformation (DOB, DL numbers and so on), HR files, financial and a
ccounting information, lost of agreements and contracts, drawings
, specifications, corporate credit card details, scans of documen
ts with detailed personal information, customer data and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Erdy-McHenry-Architecture</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25048</link>
<guid>2ca6b57ab35e4f00b28b0ed884f6e84a</guid>
<pubDate>Thu, 14 Aug 2025 15:48:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Erdy-McHenry-Architecture</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>dab321a3a873d760769e64272273698e6d666b4ad4238792de393f011b6d2729</i><br /><br />Threat actor <b>description</b>: <i>Erdy McHenry Architecture specializes in a diverse range of archi
tectural services, including academic, cultural, agricultural inf
rastructure, commercial, housing, and health science projects.

We are ready to upload more than 26GB files of essential corporat
e documents such as: financial data (payment details, invoices), 
employees information. A bit of personal files and customers data
.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Lundberg-Design</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25044</link>
<guid>bcea8e33f6a05964bdf4ac26c1aa89cf</guid>
<pubDate>Thu, 14 Aug 2025 11:46:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Lundberg-Design</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ce1c2b04fdac5914d32147c5f31c3f59a6a56cac98f93eb33a636cf028ad2099</i><br /><br />Threat actor <b>description</b>: <i>Lundberg Design specializes in a diverse range of architectural p
rojects including residential, commercial, and public spaces. The
y offer services that encompass design for restaurants, hotels, r
etail spaces, and other urban and rural developments.

We are ready to upload more than 91GB files of essential corporat
e documents such as: financial data (audit, payment details,finan
cial reports, invoices), employees and customers information (pas
sports, driver's license) confidential information, NDAs and othe
r documents with detailed personal information so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rusin-Law</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25043</link>
<guid>e8f4d8f59f34ac30a908af58d123135a</guid>
<pubDate>Thu, 14 Aug 2025 10:46:50 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Rusin-Law</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c98541be52c698b531bbe478f94e3490ec391d51a79db42e3565bb3b0ccef6dd</i><br /><br />Threat actor <b>description</b>: <i>Rusin Law is a premier civil litigation defense firm specializing
in workers' compensation cases. Their services encompass a wide 
array of legal disciplines, including civil litigation, insurance
defense, employment law, and more.

We are ready to upload more than 134GB files of essential corpora
te documents such as: financial data (audit, payment details,fina
ncial reports, invoices), employees and customers information (bi
rth certificate,medical information) and other documents containi
ng confidential information. You will also find such documents as
police protocols, court hearings and other legal confidential do
cs.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Manhattan-Retirement-Foundation</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25039</link>
<guid>4197c77706a5d5610d83f009209b00fe</guid>
<pubDate>Thu, 14 Aug 2025 08:19:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Manhattan-Retirement-Foundation</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82597528750ebf72cda8121afc3b65c278d78e28b1f68b480a3e99567c21290b</i><br /><br />Threat actor <b>description</b>: <i>Continuing Care Retirement Community in Manhattan Kansas serving Manhattan and the surrounding communities providing Independent Living, Assisted LIving, Healthcare and Transitional Care services.</i><br />Target victim <b>website</b>: <i>www.meadowlark.org</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Barbas-Nunez-Sanders-Butler--Hovsepian</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25040</link>
<guid>c5c3478127f5e50e49b50a3846afe884</guid>
<pubDate>Thu, 14 Aug 2025 08:18:51 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>beast</b> claims attack for <b>Barbas-Nunez-Sanders-Butler--Hovsepian</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>cd6437b85fd9e375206bf7fea1dcb8defafea92d4a0bae31c8bcf64cbf0c0ab4</i><br /><br />Threat actor <b>description</b>: <i>Barbas, Nuez, Sanders, Butler & Hovsepian is a law firm based in Tampa, Florida, specializing in workers' compensation, personal injury, and social security disability claims. With over 150 years of combined legal experience, their team is committed to serving clients primarily in the Tampa Bay area, including Hillsborough, Pinellas, Pasco, and Polk Counties. They pride themselves on strong client relationships and personalized service, treating clients like family throughout the legal process. Established in 1989, the firm has a proven track record in helping clients obtain compensation for workplace injuries, personal injuries, and wrongful death cases</i><br />Target victim <b>website</b>: <i>www.barbaslaw.com</i>]]></description>
<category>beast</category>
</item>
<item xmlns:dc='ns:1'>
<title>Comprehensive-Pain-Centers</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25035</link>
<guid>099e842af821e68c6b90d20ddcfc0fc8</guid>
<pubDate>Thu, 14 Aug 2025 00:40:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Comprehensive-Pain-Centers</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>98f1959995e25533b2d3812345d6559ae96f3e5de2df0dfb76c63af180933625</i><br /><br />Threat actor <b>description</b>: <i>We operate on a wellness-based system. We offer you medical care services that are local to your community at your work site, educational institution, senior care facility, mall, etc. We offer subscription-based plans that can be used as a replacement for and as a supplement to existing medical care services. No travel to a clinic. No fuss, no hassle, just you and your doctor.</i><br />Target victim <b>website</b>: <i>www.comprehensivepaincenters.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>J-Derenzo</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25036</link>
<guid>da383b7f4fb8b92bb70373274bfa6879</guid>
<pubDate>Thu, 14 Aug 2025 00:40:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>J-Derenzo</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e8ac6fe727b7d86863a633716cb8e9c2c771a935d85b43509eb4013a70ba7a6e</i><br /><br />Threat actor <b>description</b>: <i>J. Derenzo Co. has been one of New England’s premier site work contractors for over 75 years. The team’s experience ranges from large scale rural site clearing to some of the most complex, tight-site, deep hole excavations in downtown Boston. Our diversity of expertise has been a key driver in amassing a portfolio of work that is second-to-none in the industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>One-Way-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25037</link>
<guid>4bbef9d1354586336831ab1b4e321f95</guid>
<pubDate>Thu, 14 Aug 2025 00:39:46 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>One-Way-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>778a1be09ee63584176a949a680ff5f4137926b18cf6030c807e09569d03a179</i><br /><br />Threat actor <b>description</b>: <i>Company is dedicated to taking the worry out of IT by providing outstanding computer support to Dental and Healthcare practices throughout Texas. While working closely with our clients we have resolved numerous distinct challenges with our hands-on technical approach. We are confident that our many years of offering our clients the best healthcare and dental information technology solutions available has resulted in increased efficiency and decreased overall costs for their practices.</i><br />Target victim <b>website</b>: <i>onewaysolutions.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>TELACU-College</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25033</link>
<guid>e12adf20632f7173b369b04f8e76a425</guid>
<pubDate>Thu, 14 Aug 2025 00:39:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>TELACU-College</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>646f30dda429c437460a82cc27d5ad5de1c2f044371278a8f05be3f328f847fb</i><br /><br />Threat actor <b>description</b>: <i>TELACU is a comprehensive organization focused on community development through various services such as construction management, real estate development, and financial services. They offer a wide range of housing solutions including family, mixed-use, and senior housing, alongside commercial and industrial development. TELACU also emphasizes education with foundations and programs aimed at college readiness and career success for diverse populations. Their intended clients include community members seeking housing, educational resources, and financial services.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ECM-Consultants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25034</link>
<guid>31bc5644ae198ad96dd9f2438bfdae3a</guid>
<pubDate>Thu, 14 Aug 2025 00:39:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>ECM-Consultants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>65c7bd9ad07a5f205b92551b2be313ea3034fb9b455a7eea25b82bb602a0d6ff</i><br /><br />Threat actor <b>description</b>: <i>ECM Consultants is an engineering, architectural, and construction management firm headquartered in Metairie, Louisiana serving the entire United States. ECM has offices in Baton Rouge and Lafayette, Louisiana and Houston, Texas.</i><br />Target victim <b>website</b>: <i>www.ecmconsultants.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Advanced-HPC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25038</link>
<guid>8a58beb9988f8b83e2f4ad93576c2f6a</guid>
<pubDate>Wed, 13 Aug 2025 23:19:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>anubis</b> claims attack for <b>Advanced-HPC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1b8670029991696f4fc596beacb1c56933478e86b80a95332f515dd1957b470c</i><br /><br />Threat actor <b>description</b>: <i>Leakage of internal documents at a company engaged in the development and implementation of HPC systems for science and defence.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>anubis</category>
</item>
<item xmlns:dc='ns:1'>
<title>Charak-Center-for-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25030</link>
<guid>bb83d7c0cd2928b6da5d26ceb1a98753</guid>
<pubDate>Wed, 13 Aug 2025 17:29:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Charak-Center-for-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>64261911f5ae366c68176f33ee909b571fb136c99d89a36001a417e0772377f0</i><br /><br />Threat actor <b>description</b>: <i>Charak Health and Wellness Center, USA: an organization providing mental health services and treatment for alcoholism and drug addiction. The widest range of psychiatric services in northeastern Ohio. The publication of internal company data             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>ffs.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25031</link>
<guid>52c2edca4131f0eeaff48a3f9a99bce0</guid>
<pubDate>Wed, 13 Aug 2025 17:29:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ffs.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88f3e4618e3f92e4433eddbf38dd2a0d126343bbfae37e52661b1e62553fb3b5</i><br /><br />Threat actor <b>description</b>: <i>Flavor & Fragrance Specialties is now a Lucta brand specializing in flavorings for coffee and other beverages. Our dedicated teams in the US will continue to provide unique market insights and customized flavor and fragrance solutions for our            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ahtna-Incorporated</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25026</link>
<guid>fe0437935a8eb2c42ac327ae401d8482</guid>
<pubDate>Wed, 13 Aug 2025 14:41:43 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Ahtna-Incorporated</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>afc54fd6cd10651f36c24ff3af28c5082c9d1ba62e0cfd97a627b7b24bf5e230</i><br /><br />Threat actor <b>description</b>: <i>Ahtna Inc., provides construction and integrated services. The company is headquartered in Glennallen, Alaska. Ahtna, Incorporated is Alaska Native Regional Corporations established by Congress under terms of the Alaska Native Claims Settleme            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Cos-County-Family-Health</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25028</link>
<guid>ca97f360a1f78cb7e0417131c8b3fc76</guid>
<pubDate>Wed, 13 Aug 2025 12:46:45 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>RunSomeWares</b> claims attack for <b>Cos-County-Family-Health</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bc5ad237ed5ab6261c5dd52dedb7885c84e8abd279e406b6d813d7a9d2efa204</i><br /><br />Threat actor <b>description</b>: <i>Coös County Family Health Services has provided comprehensive office-based primary care services for more than 10 years.</i><br />Target victim <b>website</b>: <i>coosfamilyhealth.org</i>]]></description>
<category>RunSomeWares</category>
</item>
<item xmlns:dc='ns:1'>
<title>Litchfield-Cavo-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25027</link>
<guid>0d346bf6310fdff1302c9d01fb713d51</guid>
<pubDate>Wed, 13 Aug 2025 10:39:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Litchfield-Cavo-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>42fe1f86964bfbd4c4e5c9e4c65b43e692bd7a094a5d11abdcc5cf1b8b120328</i><br /><br />Threat actor <b>description</b>: <i>Litchfield Cavo LLP is a premier coverage and litigation defense 
law firm founded in 1998 on one principal - client service comes 
first.

We are ready to upload more than 300GB  files of essential corpor
ate documents such as: financial data (audit, payment details,fin
ancial reports, invoices), employees and customers information (d
river's license, Social Security Numbers, death certificate, medi
cal information ) confidential information, NDA  and so on. A lot
of personal files and customer data,also you will find a lot of 
court documents such as police reports, hearings and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Box-Elder-County</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25025</link>
<guid>8b57c0bb0564fe650d8ad45b7d7c1017</guid>
<pubDate>Wed, 13 Aug 2025 05:21:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Box-Elder-County</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a88151bbe53784a51897ed5b6c89a71d8b0152758e0dd6c4fd87749efe18905f</i><br /><br />Threat actor <b>description</b>: <i>Box Elder County is a county in the northwestern part of the state of Utah, USA. Located in the northern part of the state, the county is a place for wildlife viewing and recreation of all kinds.</i><br />Target victim <b>website</b>: <i>boxeldercounty.org</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hygrade-Components</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25020</link>
<guid>39e947eb63c8bac0a911b23ac881c9bb</guid>
<pubDate>Wed, 13 Aug 2025 00:39:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Hygrade-Components</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a3925ca167b77448a39c90a8ddead9c756f5a64784bdada2883ceb90e2de3760</i><br /><br />Threat actor <b>description</b>: <i>Hygrade has provided custom roll formed products to a variety of industries since 1939. For precision roll formed shapes, frames and channels, come to Hygrade - the name that means High Quality. Whether it's angles, channels, special shapes, decorative trim, structural sections - whatever you need - Hygrade meets it with commitment to service and dedication to quality.</i><br />Target victim <b>website</b>: <i>www.hygradecomponents.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>Eagan-Insurance</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25021</link>
<guid>4a6691c609e4d04769c91b4b6f2d5358</guid>
<pubDate>Wed, 13 Aug 2025 00:39:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Eagan-Insurance</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e54cf3d22e5bdb246ddda7492c60ebc975874c99fe952bb3774235da4081b0ff</i><br /><br />Threat actor <b>description</b>: <i>Eagan Insurance Agency functions as an independent insurance agenciy in the New Orleans area that was established in 1954. Services provided by Eagan Insurance include Personal Insurance, Business Insurance, and Benefits. This agency offers a comprehensive commercial property and casualty department, a vital personal lines division with a unit specializing in the affluent client, and a rapidly growing employee benefits arena. </i><br />Target victim <b>website</b>: <i>www.eaganinsurance.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>bvasd.net</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25017</link>
<guid>db4af40394d17c2399d9b2becf0a961d</guid>
<pubDate>Tue, 12 Aug 2025 22:58:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>bvasd.net</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>eb9e0b0d785794b10e30865305f2a8f28e06f4f3d610fc8ff1bd57ba3606e371</i><br /><br />Threat actor <b>description</b>: <i>The Belle Vernon Area School District (BVASD) is a medium-sized public school district located approximately 40 minutes southeast of Pittsburgh in Westmoreland and Fayette counties, Pennsylvania.Formed in 1965 through the merger of the Belmar            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>northernconstruction.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25018</link>
<guid>3e70babf4bcfb88ff496d2f8326ba174</guid>
<pubDate>Tue, 12 Aug 2025 22:58:30 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>northernconstruction.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>35390a525c63ec3d032c593098cab4e540619a906b012a13074721b8aa151c73</i><br /><br />Threat actor <b>description</b>: <i>Northern Construction Service, LLC is a Massachusetts-based general contractor specializing in bridge construction, construction site work, port and harbor work, concrete work, and utility services.
1.The document consists of two invoices fr            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>syncadd.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25019</link>
<guid>112473807df45853e16204788ce21e2c</guid>
<pubDate>Tue, 12 Aug 2025 22:58:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>syncadd.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1498556029223fce838f8c05db9ac8dfb3581da97d03e2ec753bf9a03956d44f</i><br /><br />Threat actor <b>description</b>: <i>SYNCADD is a technology solutions provider that delivers effective data and business results to customers worldwide, including divisions of the US Armed Forces. The company's wide range of services includes audit preparation, corporate soluti            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Assisted-Living-Pharmacy-Service-LLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25012</link>
<guid>b71faf915b91184a5c4dc56c7d6262da</guid>
<pubDate>Tue, 12 Aug 2025 16:57:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>Assisted-Living-Pharmacy-Service-LLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8829c696492747a9483f18fe744227c35f0db50a19eafcca61b428133341ff20</i><br /><br />Threat actor <b>description</b>: <i>Assisted Living Pharmacy Service LLC operates in the field of providing medicines and assistance in selecting medications in WL, USA. The company states that “Our mission is to provide the best services in the industry at the highest level             ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Epperson-Law-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25016</link>
<guid>7b080bac7a1e553d6da63936a525c619</guid>
<pubDate>Tue, 12 Aug 2025 16:39:13 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>Epperson-Law-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>7095e67e3c477ae2672a17b88d8d771d71a562a2b00353c402c750e5769e1cf3</i><br /><br />Threat actor <b>description</b>: <i>The law firm called "Epperson Law Group" paid with their safety and the safety of their clients, because they were negligent and indifferent to their safety! Many people's data was compromised, and the work in the system was completely broken!</i><br />Target victim <b>website</b>: <i>epplaw.com</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>Nutis-Press</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25011</link>
<guid>68e3bf852693ad8a72f32fdfe50dc6d4</guid>
<pubDate>Tue, 12 Aug 2025 13:57:25 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Nutis-Press</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6a3b8d366b12b4c899a7c1ca91ad3618fe8b2ee9505b3c3e4c56904ea26db2b9</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>Trans-Tex</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25010</link>
<guid>8cae5112c2129ad4b825e8388c749b3d</guid>
<pubDate>Tue, 12 Aug 2025 05:42:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>rhysida</b> claims attack for <b>Trans-Tex</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>fa127ee2bb8e11b08daad728c97202c13ae1415a81d0dd94d6c401df3aa46f7e</i><br /><br />Threat actor <b>description</b>: <i>Trans-Tex Trans-Tex has been the leader in narrow web dye sublimation printing for over 25 years.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>rhysida</category>
</item>
<item xmlns:dc='ns:1'>
<title>City-of-St-Paul</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25007</link>
<guid>4e21a35107f3ebeb38da1a3ee0a6d47f</guid>
<pubDate>Mon, 11 Aug 2025 18:50:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>interlock</b> claims attack for <b>City-of-St-Paul</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b842818d34d38548cbb626843e1a30ac65e643645d92dffa9cf1af1d6929656b</i><br /><br />Threat actor <b>description</b>: <i>The government of the city of Saint Paul, Minnesota, including its representatives and employees, is extremely careless and irresponsible about the security of their city, because of this, a large part of the infrastructure was damaged, brought a lot of losses and damage! Including in the worst position were residents whose data was compromised in the internet! Saint Paul, Minnesota, population is about 310,992 people. The city is part of the Minneapolis - Saint Paul metropolitan area.</i><br />Target victim <b>website</b>: <i>stpaul.gov</i>]]></description>
<category>interlock</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Scharine-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25006</link>
<guid>1b4ee40ffb4c7cf07b1d29cb65862410</guid>
<pubDate>Mon, 11 Aug 2025 18:44:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Scharine-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>faa29fc30232d888ab1e523abd79ea4ba90c027488437bd5ca3945eca06aa02f</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.thescharinegroup.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bluewater-Yacht-Sales</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25005</link>
<guid>72a2c10a923eca15e8aee55da47a96f3</guid>
<pubDate>Mon, 11 Aug 2025 18:44:08 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Bluewater-Yacht-Sales</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>316594b08c3d951e70709223c973fadc6edf073e37a0b879cc67c207121908cb</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bluewateryachtsales.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Travancore-Analytics</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25004</link>
<guid>80b14a33b85fcee05b046edd635e27da</guid>
<pubDate>Mon, 11 Aug 2025 18:43:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Travancore-Analytics</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>480dbf0dd95fd9973a10db869773eb03c5cdf87476ef619c5dad5e7ca36035d3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ritetrack.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Rite-Track</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25003</link>
<guid>652a805887302f460fa9d0f968fdee9d</guid>
<pubDate>Mon, 11 Aug 2025 18:43:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Rite-Track</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>13cf67c6d1d3c1fb53e6a3ae483a6df7c490e5036ad9c36209637b1b4ad89d0b</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.ritetrack.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Wytech-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24984</link>
<guid>e103d1ed1d6c41b0f098ff377dde2966</guid>
<pubDate>Mon, 11 Aug 2025 15:39:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Wytech-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ec6cdb22f1d31e46172625e90396392314b55b0c67eb3bf46a4387bdfb7875d5</i><br /><br />Threat actor <b>description</b>: <i>For nearly 50 years, Wytech has been committed to earning its pos
ition as the preferred development and manufacturing partner for 
straight and cut medical wire, complex catheter mandrels, and cor
e wires for medical device OEMs and contract manufacturing organi
zations (CMOs) as the leading medical wire and precision grinding
partner. 

We are ready to upload more than 42Gb files of essential corporat
e documents such as: financial data (audit, payment details, fina
ncial reports, invoices), employees and customers information (em
ail's, medical information and other documents), confidential inf
ormation, NDA  and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>TRS-Industries</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24994</link>
<guid>10e36ff70e75deadae36b7648dacd8ad</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>TRS-Industries</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>853e53593e2d8d9b29ae930cfcaf1be11cd5db6e8cb84ca7a62dda6e3e841586</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sterling-Card-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24995</link>
<guid>f49a2479665b3bd13ec08d5d1a8bbe4c</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sterling-Card-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>30e50b402131ee1eef9c3cb8349a5b9441825f93a4851ae711a19f3166e9d762</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>sterlingcardsolutions.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Law-Offices-of-Hicks--Demps</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24999</link>
<guid>ad2d8a4d8e8654a34f898980254af33f</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Law-Offices-of-Hicks--Demps</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>487417c8b3189c6b6d381100e121538dc0bcf84afbf569425674af888090b980</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Safti-First</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25000</link>
<guid>70f44538106c52ad2a01ffba924792e2</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Safti-First</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>38316251bcffb451c259a2501843104f14548e04c54eafe2e55e5c1c41f9b92e</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>safti.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Aurora-Air-Products</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25001</link>
<guid>330add99531b6d578cc1c18e8444b10a</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Aurora-Air-Products</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3dfabee9091b356abcb306ab613c733eda5c3583c33b1a16d9845032fbb49ded</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>auroraair.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Sweetener-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=25002</link>
<guid>09d1d2fa86fbc25c85269b522d96b9a9</guid>
<pubDate>Mon, 11 Aug 2025 15:39:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Sweetener-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>73defcbd83afa099287ee9dcbd19ad73e0cc2ded055c10aa59979128c88b4817</i><br /><br />Threat actor <b>description</b>: <i>In summer 2025 our team managed to crack IT defenses of a large number of companies. Data of some of them hasn't been leaked, so we will just list company names.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>ESD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24981</link>
<guid>9adbaadf095c8de0d2d0b53fe92a5dbb</guid>
<pubDate>Mon, 11 Aug 2025 15:08:42 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>ESD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5f0253586b88f60c576309b6201ef5c8d2ffac9a7312de70d90701d63b4de4d8</i><br /><br />Threat actor <b>description</b>: <i>ESD Inc. specializes in engineering and manufacturing a diverse r
ange of mechanical and electronic payment systems tailored for th
e multi-housing and laundromat industries. 

We are going to upload company data soon. You will find financial
data (audit, payment details,financial reports, invoices), emplo
yees and customers information (medical information, passports, d
river's license ) A bit of personal files and customers data.
</i><br />Target victim <b>website</b>: <i>esdcard.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Architectural-DesignWest</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24985</link>
<guid>f3062c61fcdbab5937095c1629b71d05</guid>
<pubDate>Mon, 11 Aug 2025 15:08:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Architectural-DesignWest</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0906c1408e2af717a1af4d2879744c79fffe79822031497f1dc046eb07829ccb</i><br /><br />Threat actor <b>description</b>: <i>Design West Architects specializes in architectural design, focus
ing on various sectors including educational and residential proj
ects. 

We are ready to upload more than 27GB files of essential corporat
e documents such as: financial data ( audit, payment details, inv
oices), employees and customers information (telephone numbers, e
mail's, medical information,driver's license, DLs and other docum
ents), confidential information, NDA  and so on.
</i><br />Target victim <b>website</b>: <i>designwestarchitects.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Spring-Footwear</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24986</link>
<guid>77b1ae6be955316d7234f2bc5a409cdd</guid>
<pubDate>Mon, 11 Aug 2025 15:08:33 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Spring-Footwear</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3f9d9b36bb27502f701fcc80f42a332a53a9a0bb76936efe0d6e5b748fda783f</i><br /><br />Threat actor <b>description</b>: <i>Spring Footwear has dedicated itself to providing consumers with 
footwear. The company's brands are Spring Step, L'Artiste, Azura,
Flexus, Patrizia and Spring Step Professional.

We are ready to upload more than 23GB files of essential corporat
e documents such as: financial data (audit, payment details, invo
ices), employees and customers information (email's,driver's lice
nse,Social Security Numbers and other documents), confidential in
formation, NDA  and so on.
</i><br />Target victim <b>website</b>: <i>springfootwear.com</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Law-Company</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24987</link>
<guid>cc8c609563d2b30f18b01c0fa9e684b3</guid>
<pubDate>Mon, 11 Aug 2025 15:08:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>The-Law-Company</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4b13bd811cafa80e9730c612a6a561f1efc6fa0fbc3d880bd7c6f2c9c4e548aa</i><br /><br />Threat actor <b>description</b>: <i>The Law Company Inc provides commercial construction services for
vartious industries including retail, worship, industrial, educa
tion, corporate, healthcare, government, lodging, and cultural. 

We are ready to upload more than 14GB files of essential corporat
e documents such as: financial data (audit, payment details, fina
ncial reports, invoices), employees and customers information and
so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Anderson-Packaging</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24988</link>
<guid>228817faf36305ff344e4d7cbe4dc222</guid>
<pubDate>Mon, 11 Aug 2025 15:08:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Anderson-Packaging</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3fa08ee88636786d9fc8c75153149b99b019e1883d8a3ab18ec26a031838640b</i><br /><br />Threat actor <b>description</b>: <i>Anderson Packaging, LLC specializes in packaging and assembly ser
vices tailored for the aftermarket industry.

We are going to upload company data soon. You will find financial
data (audit, payment details,financial reports, invoices), emplo
yees and customers information, driver's license and a bit of per
sonal files and customers data.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Atlas-Transfer--Storage</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24990</link>
<guid>d2b6d861d66fa14bb7cf8c6112d13e0d</guid>
<pubDate>Mon, 11 Aug 2025 15:08:18 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Atlas-Transfer--Storage</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>88256a2bf8a510cfe940573ab51ffc80fe1117b33187c5de0f760acac35e0179</i><br /><br />Threat actor <b>description</b>: <i>Atlas Transfer & Storage not only handles residential and commerc
ial relocations, but we also provide premier storage solutions. 

We are going to upload company data soon. You will find financial
data (audit, payment details,financial reports, financial report
s, invoices), employees and customers information: driver's licen
se and a bit of personal files and customers data.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Insero--Co.-CPAs-LLP</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24991</link>
<guid>4b23f8dc9eb4ed500a662e396908d39b</guid>
<pubDate>Mon, 11 Aug 2025 15:08:12 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>Insero--Co.-CPAs-LLP</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>134a9e7343b8a323b23f83deb418293499af5223b002329d58eff92f5018cb99</i><br /><br />Threat actor <b>description</b>: <i>Insero & Co. CPAs founded in 1973 and headquartered in Rochester,
New York, is a premier public accounting firm.

We are ready to upload more than 40GB files of essential corporat
e documents such as: financial data (audit, payment details,finan
cial report, invoices), employees and customers information (pass
ports, emails, driver's license and other documents), confidentia
l information, NDA  and so on.
</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>Louis-Tieu-DDS-MD</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24976</link>
<guid>6f7ed2665430436edf77b2c6d75740c7</guid>
<pubDate>Mon, 11 Aug 2025 11:14:53 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Louis-Tieu-DDS-MD</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2bc87c00c2e63227f222a4ed7749f3dad4516e32ec6e11dade22395fbef0271c</i><br /><br />Threat actor <b>description</b>: <i>Dr. Louis Tiu was born in Taiwan and raised in Rowland Heights, California. After graduating from the University of California, San Francisco (UCSF) School of Dentistry, he continued his education in oral and maxillofacial surgery, earning two degrees: one from the UCSF School of Dentistry and the other from the University of California, Davis (UCD) School of Medicine. After receiving his medical degree from UCD, he completed his residency at UCSF.  He is responsible for the leak of more than 500 pieces of personal data belonging to his clients</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Community-Services-of-Missouri</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24974</link>
<guid>f138e593207a9b63ce9a539aa94337bc</guid>
<pubDate>Mon, 11 Aug 2025 00:31:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>weyhro</b> claims attack for <b>Community-Services-of-Missouri</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>a5a31ba3eaa858e6984a0f0067c8117f1aff115ad9cec1c8588b8180aa6bfb91</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Community Services of Missouri is an organization that provides a range of services to aid individuals and communities. These services include driver improvement programs, drug education and prevention programs, substance abuse traffic offender programs, and probation services. The organization focuses on fostering better understanding of safety, well-being, and responsible decision-making. Community Services of Missouri operates in various locations across the state of Missouri.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>weyhro</category>
</item>
<item xmlns:dc='ns:1'>
<title>Chemtron-RiverBend</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24975</link>
<guid>ff10bdb362b3ea4aa07fae2dcd78cf79</guid>
<pubDate>Mon, 11 Aug 2025 00:30:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>weyhro</b> claims attack for <b>Chemtron-RiverBend</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>948c37c587ee54494d2f649f064ca855ec54863f74b761424209cdf7cd315125</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Chemtron RiverBend is a leading hazardous waste and non-hazardous waste management service provider. They specialize in providing effective and safe disposal and recycling of waste for a wide range of industries. They deliver waste management solutions with safety procedures and regulations, ensuring environmental protection and compliance.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>weyhro</category>
</item>
<item xmlns:dc='ns:1'>
<title>L3Harris-Technologies</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24967</link>
<guid>b05f1c54b7595590394fdef928ede449</guid>
<pubDate>Sun, 10 Aug 2025 13:27:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>L3Harris-Technologies</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4f589eaf053c39962fe133edbdf44af6d296c0ecc06649fcba0f53559d718672</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>St-Thomas-More-Catholic-High-School</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24968</link>
<guid>081d5e994ab762a68f8c0546a8968b00</guid>
<pubDate>Sun, 10 Aug 2025 12:28:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>St-Thomas-More-Catholic-High-School</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>717d30edb9817a23d9549577030b1ff56304ba75aabc8644cf4992b0fbf0eee0</i><br /><br />Threat actor <b>description</b>: <i>St. Thomas More Catholic High School is one of the most famous and prestigious schools in Louisiana, USA. Every child in Lafayette wants to study here, and parents are willing to pay a lot to get their child into this elite environment. On th            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Howard-Financial--Associates</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24972</link>
<guid>2145031a345440c221d8992954a841db</guid>
<pubDate>Sun, 10 Aug 2025 12:10:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Howard-Financial--Associates</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>c59b2849ac58fc14f38f404ea62b3252ce78b1a0b67a019d9d9a27049f435693</i><br /><br />Threat actor <b>description</b>: <i>Welcome to Howard Financial Corp Audit and compliance (LIP AUDIT 2023–2025) Customer databases (ACTIVE/INACTIVE blue files, customer lists) Internal procedures and templates (HOWARD FINANCIAL PROCEDURES) Working with partners (AIG, Allianz, Americo, etc.) Personal work logs and diaries Customer letter archives Financial and product materials Contracts and legal documentation You may also meet with one of the directors, Gregory P. Howard, and perhaps share his enthusiasm for homosexuality with Asian men. You will soon see everything.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>RHI-Supply</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24964</link>
<guid>ab7c5cdb20164d2d25769bddd2fe1493</guid>
<pubDate>Sat, 09 Aug 2025 18:38:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>RHI-Supply</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>63ce80e1770bf2dd2f91836cf67fdaa7633fd5c9a0ffba5c087d7fcc1d72d5a7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.rhisupply.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>CFI-Tire-Service</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24963</link>
<guid>b4f6926d4794e9cdb293fa94a06b4577</guid>
<pubDate>Sat, 09 Aug 2025 18:37:37 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>CFI-Tire-Service</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>82dc4cc0e974849b302a6f15e3dd701b5db3e959395ad3276ebb83ec439946b3</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.cfitire.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Drive--Shine</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24954</link>
<guid>f915833c0979810086c2ea49db2993c6</guid>
<pubDate>Sat, 09 Aug 2025 02:54:04 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>lynx</b> claims attack for <b>Drive--Shine</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46881cca61b32e4209ecf41785e82643637aa46684436a093677a6aed38df248</i><br /><br />Threat actor <b>description</b>: <i>Drive & Shine is a premier car care service that offers express car washes, inte...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>lynx</category>
</item>
<item xmlns:dc='ns:1'>
<title>mauilodging.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24957</link>
<guid>e51e03b93afcc9032d56360fbfa2a47d</guid>
<pubDate>Fri, 08 Aug 2025 23:12:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>mauilodging.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>4329aac2edb738339c86f37f65ecfd7e9d06d45c14d7fae7113e0695c1a059c1</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] MauiLodging.com is a property rental service company based in Maui, Hawaii. This firm specializes in providing a wide range of accommodation options as per user requirements, from luxury villas to economical vacation rentals. Tailored to cater to the varying needs of tourists, the firm assures quality amenities, scenic locations, and personalized customer services, making the trip to the island unforgettable.</i><br />Target victim <b>website</b>: <i>mauilodging.com</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Pacific-HealthWorks</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24950</link>
<guid>ea16c8ad502b00dd6eb031b3fd35d738</guid>
<pubDate>Fri, 08 Aug 2025 10:22:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>Pacific-HealthWorks</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>91bcb4dbedd849773284b874b526e3015cdc2b723e60a2752fe7d310e225a328</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] Pacific HealthWorks is a management services organization based in Los Angeles, United States. The company primarily provides comprehensive management, administrative, and support services to healthcare practitioners and facilities, including doctors’ offices, healthcare clinics, and other related medical entities. They focus on business and operational aspects so the medical professionals can concentrate on patient care.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>La-Perouse</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24952</link>
<guid>c9ce98a38ebb27ccdb0e5083f2cfcde7</guid>
<pubDate>Fri, 08 Aug 2025 10:22:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>everest</b> claims attack for <b>La-Perouse</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e58e90006d5ff3231ff98c36e1555a4bbf6bfbaee9f7aae0f798dd504e58f610</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] N/A</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>everest</category>
</item>
<item xmlns:dc='ns:1'>
<title>Main-Electric-Supply-Co.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24948</link>
<guid>4579b0511a0e6319628ffc17cc6b3998</guid>
<pubDate>Fri, 08 Aug 2025 00:13:16 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sinobi</b> claims attack for <b>Main-Electric-Supply-Co.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bfc91a6f1cd23724295243eeda0cc440f35e472bf40a3e2442719eea80413a22</i><br /><br />Threat actor <b>description</b>: <i>Main Electric Supply Company was founded on October 14th, 1946 by Charles Vowels and Burt McCombs. From the very start, our company worked tirelessly to meet the growing demands of the electrical industry. Operating on a word of mouth basis and building a reputation for excellent service, it was not long before Main Electric Supply Company became a household name in the Los Angeles area.</i><br />Target victim <b>website</b>: <i>www.mainelectricsupply.com</i>]]></description>
<category>sinobi</category>
</item>
<item xmlns:dc='ns:1'>
<title>ryeco.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24936</link>
<guid>c0c29d6e2dd3f877b24a575d79081598</guid>
<pubDate>Thu, 07 Aug 2025 18:28:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>ryeco.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>46ee1ebf810ff0ae2a83f30be6138f11bd21aa838bdc0ec3bd8b91cf8895b635</i><br /><br />Threat actor <b>description</b>: <i>Ryeco is an international company that services and manufactures paper, hygiene products, and recycling materials such as paper, hygiene products, nonwoven materials, films, foil, labels, packaging, metals, plastics, printing, printing, glass            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>lpco.co</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24937</link>
<guid>3262c13088a37147f222c34b1a9029a4</guid>
<pubDate>Thu, 07 Aug 2025 18:28:28 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>lpco.co</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>44a65d7e5683a71dc6597641826d083c93f7d85b7d2b48badd6e48cae2cad73b</i><br /><br />Threat actor <b>description</b>: <i>Lawrence Paper specializes in the design and manufacture of corrugated boxes and packaging solutions. The company offers a wide range of services, including industrial boxes, retail-ready packaging, custom box manufacturing, as well as digita            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>eyeqmonitoring.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24938</link>
<guid>d830f71ff178b3698996fb6614751c91</guid>
<pubDate>Thu, 07 Aug 2025 18:28:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>eyeqmonitoring.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2ca35c0d46c65682e1ee8a2f4b6e145595696a23174ed062450f9664af362688</i><br /><br />Threat actor <b>description</b>: <i>Founded in 2007, EyeQ Monitoring is one of the largest providers of real-time video surveillance services in the United States. EyeQ installs and maintains state-of-the-art video surveillance systems throughout the United States and hires and            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>avosinamed.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24939</link>
<guid>f47dafa1b01fc67850d5576e5216df25</guid>
<pubDate>Thu, 07 Aug 2025 18:28:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>avosinamed.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bd073e0a31b18c3447091e73cca16f9cc0ba6f66570f0bed7ea4672a192bfea2</i><br /><br />Threat actor <b>description</b>: <i>Avosina Healthcare Solutions specializes in providing comprehensive medical billing and IT services, striving to optimize the work of doctors.
1.The document is an official payslip for March 2025 for an employee of Avosina Medical Technologi            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>lodipd.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24941</link>
<guid>d8c2a05e8270406dcdd260a088902cb5</guid>
<pubDate>Thu, 07 Aug 2025 18:28:24 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>lodipd.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1694a81b2dc3df889e9daa6579b2cdaf9046b8185b541ae3081a92bfde9fa043</i><br /><br />Threat actor <b>description</b>: <i>The primary duty of the Lodi Police Department is to serve humanity, protect life and property, defend the innocent from fraud, the weak from oppression or intimidation, and the peaceful from violence or disorder, and to respect the constitut            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>csrepair.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24942</link>
<guid>9f882c9b443017597c70b4edaa542a0c</guid>
<pubDate>Thu, 07 Aug 2025 18:28:23 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>csrepair.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6ef719e9f9c76c701dc4773046a39a325161b7ffb8f52335616a72857458d012</i><br /><br />Threat actor <b>description</b>: <i>CS Truck & Trailer is a comprehensive fleet service provider specializing in mobile repairs, preventive maintenance, and complex diagnostics for trucks and trailers.
1.The document is a notarized affidavit from Mason Jones confirming the acc            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>studebakersubmetering.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24943</link>
<guid>e6ec91cba600ca785d5e02beb0d0c8eb</guid>
<pubDate>Thu, 07 Aug 2025 18:28:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>studebakersubmetering.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1373e874921e7c5a3f9f0c0cc1ff4ef9d123687cbd8994ee33416de5928bc1fe</i><br /><br />Threat actor <b>description</b>: <i>The Belle Vernon Area School District (BVASD) is a medium-sized public school district located approximately 40 minutes southeast of Pittsburgh in Westmoreland and Fayette counties, Pennsylvania. Formed in 1965 through the merger of the Belma            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>sotaconstruction.com</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24944</link>
<guid>4ea59864816087bb60d6e5680c047a5e</guid>
<pubDate>Thu, 07 Aug 2025 18:28:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>qilin</b> claims attack for <b>sotaconstruction.com</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e773baaf665f034b208a54599756b0a246b199bf868c02e81ed72d70d41293e1</i><br /><br />Threat actor <b>description</b>: <i>Sota Construction Services is a leading provider of comprehensive and cost-effective construction services specializing in commercial and residential construction. The company emphasizes environmentally friendly construction methods and has b            ...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>qilin</category>
</item>
<item xmlns:dc='ns:1'>
<title>Prime-Beverage-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24928</link>
<guid>dd96eaef5612dd405d9d087ab539e38e</guid>
<pubDate>Thu, 07 Aug 2025 16:27:54 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>worldleaks</b> claims attack for <b>Prime-Beverage-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>76e6aabee409bb4091572e4b3cc9f4f253c1a73b5b05818578307d5d3049a467</i><br /><br />Threat actor <b>description</b>: <i>N/D</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>worldleaks</category>
</item>
<item xmlns:dc='ns:1'>
<title>BRIDGEWATER-ASSOCIATES</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24935</link>
<guid>546b5e6a6dfe42925b8a87ebcac1a9cb</guid>
<pubDate>Thu, 07 Aug 2025 11:49:44 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>d4rk4rmy</b> claims attack for <b>BRIDGEWATER-ASSOCIATES</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ea886636322e7c4dbc28d24714c1a3e894769bc004ce01309bf8dce3639bd83a</i><br /><br />Threat actor <b>description</b>: <i>https://www.bridgewater.com Bridgewater Associates is a premier asset management firm, focused on delivering unique insight and partnership for the most sophisticated global institutional investors. Our investment process is driven by a tireless pursuit to understand how the world’s markets and economies…</i><br />Target victim <b>website</b>: <i>www.bridgewater.com</i>]]></description>
<category>d4rk4rmy</category>
</item>
<item xmlns:dc='ns:1'>
<title>ONEX-CANADA-ASSET-MANAGEMENT-INC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24933</link>
<guid>942daac277daced487d09ddcbe753d73</guid>
<pubDate>Thu, 07 Aug 2025 11:48:52 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>d4rk4rmy</b> claims attack for <b>ONEX-CANADA-ASSET-MANAGEMENT-INC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>da2f35d83d92779ecf4c88b07a4fb375666aadddd96ff881a5b8ecdf60f609ed</i><br /><br />Threat actor <b>description</b>: <i>https://onex.com Onex Partners is a private equity platform focused on the upper-middle market in the United States, Canada, and Europe. Our successful track record is built on deep sector specialization and a disciplined, hands-on approach to private equity investing. they…</i><br />Target victim <b>website</b>: <i>onex.com</i>]]></description>
<category>d4rk4rmy</category>
</item>
<item xmlns:dc='ns:1'>
<title>TSAI-CAPITAL</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24932</link>
<guid>817fa9146e77f93396b5b4a108f58cfa</guid>
<pubDate>Thu, 07 Aug 2025 11:48:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>d4rk4rmy</b> claims attack for <b>TSAI-CAPITAL</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>1a1ddbaaf975805f7543b3cd38156be7c47466c256e4fc0aa2e701af289fbd33</i><br /><br />Threat actor <b>description</b>: <i>https://tsaicapital.com Tsai Capital™ is an investment management firm focused on the preservation and long-term growth of capital on behalf of select families and organizations. With more than two decades of experience, and as a third-generation investor whose financial roots date…</i><br />Target victim <b>website</b>: <i>tsaicapital.com</i>]]></description>
<category>d4rk4rmy</category>
</item>
<item xmlns:dc='ns:1'>
<title>Jamco-Aerospace</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24924</link>
<guid>4f9959469b99179f25fd5cf84f4cde62</guid>
<pubDate>Wed, 06 Aug 2025 19:30:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Jamco-Aerospace</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>af7d3fb09d8ab522a1ad65f5c9af6cc008d8eab0eb5212998e82b476939c7c83</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.jamco-aerospace.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Emprise</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24923</link>
<guid>8fb4529686c80d0a7f8442f94024eb9f</guid>
<pubDate>Wed, 06 Aug 2025 19:29:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Emprise</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0bd98e0d6e307300405552c92df087b8ae584bea7c1204e0a52e0117d97405c1</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.emprise-usa.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brads-Bedding-Plants</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24922</link>
<guid>4badf6fce1fb568ba4d71e1645e5da27</guid>
<pubDate>Wed, 06 Aug 2025 19:28:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>Brads-Bedding-Plants</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2dc9af2c001da01b59cfdff03f154b0292784f57a76f1414414089ee30d4ebc7</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.bradsbedding.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Magni-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24921</link>
<guid>8eb7be5a13cc39a3e56b78aba08b2039</guid>
<pubDate>Wed, 06 Aug 2025 19:28:09 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>play</b> claims attack for <b>The-Magni-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d0919a2a2df4ba01caf64588a3237021e1d40a8f3efdc5facc0025cfc1837568</i><br /><br />Threat actor <b>description</b>: <i>United States</i><br />Target victim <b>website</b>: <i>www.magnicoatings.com</i>]]></description>
<category>play</category>
</item>
<item xmlns:dc='ns:1'>
<title>MGM-Transformer</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24905</link>
<guid>2708fba0dc4216ab4ab4de1fc0c49862</guid>
<pubDate>Wed, 06 Aug 2025 19:28:03 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>akira</b> claims attack for <b>MGM-Transformer</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>518c17b8eadbbdf7bf05dc12e0ea3d66918e455d9c61a2704c9aa8ab18b70873</i><br /><br />Threat actor <b>description</b>: <i>MGM Transformers specializes in manufacturing a wide range of transformers, including medium voltage dry type, oil-filled, and custom-designed options, serving various sectors such as data centers, renewables, commercial industrial, and utilitiesWe are ready to upload more than 60GB files of essential corporate documents such as: financial data (audits, payment details, financial reports, invoices), employees and customers information (medical information, passports, driver's license, SSNs, DLs and other documents), confidential information, NDA and so on.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>akira</category>
</item>
<item xmlns:dc='ns:1'>
<title>LEARN-is-a-Regional-Educational-Service-Center</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24910</link>
<guid>1ca188ea50f3fc60a66b1aeec9622089</guid>
<pubDate>Wed, 06 Aug 2025 18:20:00 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>LEARN-is-a-Regional-Educational-Service-Center</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>bfd60204602bfba5e0cc861aee5dcdfe2d1650d8e2bcb303710b38e4d9e55887</i><br /><br />Threat actor <b>description</b>: <i>LEARN is a Regional Educational Service Center working with and for its member districts to improve the quality of public education for all learners</i><br />Target victim <b>website</b>: <i>www.learn.k12.ct.us</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>Quality-Data-Service-Inc.</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24911</link>
<guid>669c35c595fa7abcc0b82d0ba7d90f66</guid>
<pubDate>Wed, 06 Aug 2025 18:16:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>blacknevas</b> claims attack for <b>Quality-Data-Service-Inc.</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>03b8542e56d8f4cdc3f1e7ed131cc3741e3f6eced91d094474a1b7fde70a64e3</i><br /><br />Threat actor <b>description</b>: <i>Today, we’re opening the auction.Over the past several weeks, we’ve completed a full exfiltration from the infrastructure of Quality Data Service, Inc., Connecticut’s most “trusted” municipal software provider. The haul: approximately 300 GB of internal company data, including:SQL databases of client municipalities, tax departments, GIS records, and user credentialsGigabytes of PDFs, XLS files, DOC reports — many containing deeply sensitive financial, geographic, and personal data with contatsInternal emails, technical logs, software source code archives, vulnerability reports, and support ticketsMost importantly: comprehensive information on over 200 Connecticut municipalities, their operational structures, internal correspondences, and revaluation recordsThese aren’t just files. These are lives, towns, histories, and vulnerabilities — trusted to a company that no longer respects the responsibility it bears.Why Are We Doing This?We approached Quality Data Service, Inc. privately before publishing anything. Our intent was not destruction. But from the Founder &amp; President, to the CFO, Director of Assessor Support,ITs and others — we received silence, evasion, or worse: denial.They knew.They were warned.They did nothing.Their refusal to act wasn’t just negligence — it was an act of contempt for every municipality they serve.It’s not just about stolen data. It’s about a culture that prioritizes profit over protection, and PR over real recovery. And when cybersecurity “experts” are called in only to recommend burning what’s left — that’s not incident response. That’s malpractice.The AuctionWe are now offering:Full dataset: All stolen data, intact and complete (buyout option)Per-municipality packages: Tailored datasets for each town or districteQuality source code: Core application and modules available separatelyBuyers of individual municipality data will receive exclusive access — upon purchase, that data will be removed from general availability. (We believe in boundaries, even if others do not.)If You're a VictimIf your municipality is among the affected, you can contact us.We offer:Permanent removal of your data from our archives and auctionTechnical documentation proving the breachInternal evidence of the company’s failure to act, including logs and communications with their leadershipAssistance in legal proceedings to seek compensation from Quality Data Service, Inc.Names of involved individuals include:Vinny Crudele, Founder &amp; President VCRUDELE@QDS.BIZ 203-758-9446Leo Dinicola, Chief Financial Officer LDINICOLA@QDS.BIZ 860-417-3538	203-910-2316	leo_D@msn.comLinda Gordon, Director of Tax Support LGORDON@QDS.BIZIvana Crudele, Director of Assessor Support IVANA@QDS.BIZ 860-417-3617	203-518-1655David Crudele, Chief Operations Officer DCRUDELE@QDS.BIZ 203-758-9446	203-598-2692Bryan Reilly	 (IT) BMREILLY@QDS.BIZ 860-202-9557Tom Tanganelli	(IT)	860-456-2814	860-384-2449	tjtanganelli@gmail.comJeffery Johnson	(Sales) 860-643-8100	860-729-4551	jjohnson@qds.bizBruce Lavoie	(Programming)	860-620-0785	860-919-1343	bclhome@cox.netVicki Powell	(eQuality)		203-509-4255	powellcrudele@gmail.comWe take no joy in exposing them. But in the end, they chose convenience over courage.A Better WayYou may dislike what we’ve done — but it was never random.IT security is not a checkbox. It’s a culture. And we’ve seen firsthand how a failure to treat it seriously leads to the slow death of public trust. The worst thing about this breach is not the breach itself, but that it could have been prevented.We call on municipalities, CTOs, assessors, and public servants to work with real specialists who care more about solutions than headlines. The future belongs to those who build with integrity.listing https://gofile.io/d/5641ll</i><br />Target victim <b>website</b>: <i>www.qds.biz</i>]]></description>
<category>blacknevas</category>
</item>
<item xmlns:dc='ns:1'>
<title>FP-Georgia-Mfg-Inc</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24900</link>
<guid>1fbee9dc43156d20a7646ff826a8a219</guid>
<pubDate>Wed, 06 Aug 2025 17:28:39 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>nitrogen</b> claims attack for <b>FP-Georgia-Mfg-Inc</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>6f2e11a3b815df054ac4edfd4d9adfc69b6a9a677941f6f098b54b3901a4c065</i><br /><br />Threat actor <b>description</b>: <i>Tier-1 supplier of suspension components to the automotive industry.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>nitrogen</category>
</item>
<item xmlns:dc='ns:1'>
<title>Metro-Heating</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24897</link>
<guid>f2fe4479d8861f09946a28965a67d436</guid>
<pubDate>Wed, 06 Aug 2025 15:27:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>sarcoma</b> claims attack for <b>Metro-Heating</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>115272a4d57053ab6815e8bc3e7a6181a20374f6db037c3316170898c155f541</i><br /><br />Threat actor <b>description</b>: <i>Site: metroheatingandair.com
														Industry: Commercial & Residential Construction
														GEO: USA</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>sarcoma</category>
</item>
<item xmlns:dc='ns:1'>
<title>Consumer-Electronics--Computers-Retail-Retail</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24906</link>
<guid>b8da1ad63c85d7d91338134ee7c6671a</guid>
<pubDate>Wed, 06 Aug 2025 13:24:57 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Consumer-Electronics--Computers-Retail-Retail</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>9f5a1e3bfc2a1772ab41f9bd621fb0dbe312e44772febe32f97852137cee6683</i><br /><br />Threat actor <b>description</b>: <i>Michelli Weighing & Measurement is a trusted provider in the Weighing & Measurement Industry since 1947 with thirty-seven locations throughout the US, offering ISO 9001 certified services. They specialize in calibration for precision instruments used in weighing, force, torque, pressure, dimensional, electrical, temperature, and frequency measurement. Michelli provides comprehensive scale services, maintenance, calibration, and equipment repair, with heavy capacity test trucks for convenient on-site services. They welcome clients across various industries and ensure seamless transitions with a dedicated team of experts.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Heart-of-America-Medical-Centr-HAMC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24898</link>
<guid>03710901f9d12f609ce37724a57987fc</guid>
<pubDate>Wed, 06 Aug 2025 10:28:26 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>embargo</b> claims attack for <b>Heart-of-America-Medical-Centr-HAMC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>3472ae866b5f4c6ce45b4fb4fe3d423d44627a54c4c4ccb47905375545574a28</i><br /><br />Threat actor <b>description</b>: <i> About Heart of America Medical Center
A non-profit hospital offering comprehensive medical services, including emergency care, radiology/imaging, surgical cen... - I have your Data 800GB. I will post the data in three stages. You can view some of the files on the link from tor browse...</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>embargo</category>
</item>
<item xmlns:dc='ns:1'>
<title>Diversified-Project-Services-International</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24899</link>
<guid>5d147304859c2c8752cf5dedb4b50d49</guid>
<pubDate>Wed, 06 Aug 2025 09:14:55 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>dragonforce</b> claims attack for <b>Diversified-Project-Services-International</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>f2c05b64ac3f74623eaf6486c724c8eb462e0d3a7b09112ea1f9c0cba8e95868</i><br /><br />Threat actor <b>description</b>: <i>Diversified Project Services International, Inc. (DPSI) is a leader in engineering, geomatics (surveying), planning, permitting, inspection, energy management and construction management.</i><br />Target victim <b>website</b>: <i>dpsiinc.com</i>]]></description>
<category>dragonforce</category>
</item>
<item xmlns:dc='ns:1'>
<title>Neff-Specialties</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24875</link>
<guid>4e85fa3a7bb64fffde3307ca72f2aeb5</guid>
<pubDate>Tue, 05 Aug 2025 21:44:21 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Neff-Specialties</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>47cd8ed2e76ddd1d203e635c62f060fa0aafbaf9bbe5050feff6c5b33ceefd70</i><br /><br />Threat actor <b>description</b>: <i>Neff Specialties is a specialty sub-contractor that caters to the education, industrial, and commercial sectors across Pennsylvania, West Virginia, and Northern Maryland. The company designs, sells, installs, and services a variety of construction products, ensuring a hands-on and turnkey service to both public and private clients</i><br />Target victim <b>website</b>: <i>neffspecialties.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hamilton-Park</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24876</link>
<guid>e04f87e54ca47e7aac0fde5f55a2b928</guid>
<pubDate>Tue, 05 Aug 2025 21:43:27 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Hamilton-Park</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e3af77952417eb51524df09bee366f7b79f1bbbcd908c13c61d2f662e48f44b8</i><br /><br />Threat actor <b>description</b>: <i>Hamilton Park Interiors offers thoughtfully designed and quality home furnishings that reflect your style and your life</i><br />Target victim <b>website</b>: <i>hamiltonparkinteriors.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Brookside-Homes</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24877</link>
<guid>8f4131479defde8dc2f27d096c15d72f</guid>
<pubDate>Tue, 05 Aug 2025 21:42:56 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Brookside-Homes</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>0efc41b8f9e6bfd0a614d5acf529d7c52f1daad320055fa953e9ad4b9f8b866f</i><br /><br />Threat actor <b>description</b>: <i>Brookside Homes is a custom home builder renowned for delivering exceptional quality and service to discerning clients across Central Pennsylvania</i><br />Target victim <b>website</b>: <i>brooksidehomes.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Clarkston-First-Baptist-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24879</link>
<guid>52b8bc3917542528942a2d02a624d123</guid>
<pubDate>Tue, 05 Aug 2025 21:42:05 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Clarkston-First-Baptist-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>d278bb8aa97da18e46f983df6a44f48044c3584b088cecd7dfdafc49f25b306c</i><br /><br />Threat actor <b>description</b>: <i>From humble beginnings in 1881 and founded by former slaves on donated land, the Clarkston First Baptist Church stands today as a powerful, influential institution in the heart of Clarkston, Georgia</i><br />Target victim <b>website</b>: <i>clarkstonfbc.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Bromack-Manufacturing</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24880</link>
<guid>592f69eb8605faf19bb15d0b370cfac8</guid>
<pubDate>Tue, 05 Aug 2025 21:41:38 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Bromack-Manufacturing</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ced93eb5c8a3bc52b6649dd41a619d26fed8414bdad649bcbdd39ce22feff592</i><br /><br />Threat actor <b>description</b>: <i>The Bromack Company was founded in Los Angeles, California by Donald K Polgrean in 1963. Mr. Polgrean specialized in fixtures and furnishings to the Banking Industry</i><br />Target victim <b>website</b>: <i>bromack.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Ail-Hospitality-Group</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24881</link>
<guid>d0a194dc29ee00d2f22ef573f2d7097f</guid>
<pubDate>Tue, 05 Aug 2025 21:40:47 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Ail-Hospitality-Group</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>48b74b98aba2ae5e1128e399c342915e8b0a6e6acb0cc602a3095bbd4e7004da</i><br /><br />Threat actor <b>description</b>: <i>AIL Hospitality manage a diverse portfolio of hotels located in states like West Virginia, Maryland, Ohio, and Pennsylvania</i><br />Target victim <b>website</b>: <i>ailhospitality.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Twin-Oaks-Presbyterian-Church</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24882</link>
<guid>32e0740fc318fc059523a2f830a5b248</guid>
<pubDate>Tue, 05 Aug 2025 21:40:19 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Twin-Oaks-Presbyterian-Church</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2db2f7e131cf7f0589685c17a1cbeb6cb2ba6a86cf45b3d58006dd847b86dbe6</i><br /><br />Threat actor <b>description</b>: <i>Twin Oaks Presbyterian Church focuses on worship, discipleship, and outreach</i><br />Target victim <b>website</b>: <i>twinoakschurch.org</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>ThinkBig-Health-Care-Solutions</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24878</link>
<guid>519fab1c21e011cb83230c17046b5cf2</guid>
<pubDate>Tue, 05 Aug 2025 21:39:31 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>ThinkBig-Health-Care-Solutions</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e752178d5a2b556db837ee81892a31bc000519df947be569123cb34f7f3de619</i><br /><br />Threat actor <b>description</b>: <i>ThinkBig Health Care Solutions specializes in providing comprehensive services to medical practices, including contract acquisition, billing, collections, and practice management</i><br />Target victim <b>website</b>: <i>thinkbighcs.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Preferred-Homes-Realty</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24885</link>
<guid>e62649f9871ea7bcf0923df1bb269578</guid>
<pubDate>Tue, 05 Aug 2025 21:37:20 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Preferred-Homes-Realty</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>5a0684365c5e0ddf6f5a56434a969bff615f53a12327d95ddb21bb7742a7fda3</i><br /><br />Threat actor <b>description</b>: <i>To Preferred Homes Realty you will find a wide variety of useful information and resources designed to help you buy or sell a home more effectively in the Elgin, South Elgin, West Dundee, Bartlett, Huntley, Hampshire, Gilberts, St. Charles, Geneva and other towns in the Fox Valley Area</i><br />Target victim <b>website</b>: <i>preferredhomesrealty.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Job-Shop</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24886</link>
<guid>0df6dca4c9db6381e0c4e523a3e0f42b</guid>
<pubDate>Tue, 05 Aug 2025 21:36:29 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>The-Job-Shop</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>b5b1e3501fab0b865aee8ce276ec680e602081f9b2f518aa63c3c9070df8c2d3</i><br /><br />Threat actor <b>description</b>: <i>The Job Shop is where you come for the best talent and the best jobs. If you are looking for a job or looking for hiring or other staffing assistance in San Francisco or the rest of the Bay Area, contact us</i><br />Target victim <b>website</b>: <i>jobshopsf.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>The-Danvers-Law-Offices</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24888</link>
<guid>121f112758e4254fd9b922dfa871720d</guid>
<pubDate>Tue, 05 Aug 2025 21:35:41 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>The-Danvers-Law-Offices</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>570890e30d155bb27dacc9b688a929518fd013fe672ef18ec4cf64e856093e00</i><br /><br />Threat actor <b>description</b>: <i>The Danvers Law Offices, LLC is a boutique personal injury law firm based in Danvers, MA, serving residents throughout Massachusetts and New Hampshire since 2005</i><br />Target victim <b>website</b>: <i>danverslawyer.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>U.S.-Battery</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24890</link>
<guid>ec5df87779e995a54bde440633afb137</guid>
<pubDate>Tue, 05 Aug 2025 21:34:01 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>U.S.-Battery</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>e44a69cd8bb0ca116f5bddf55a76bbce57807738d700878a4bdfe6ceac710209</i><br /><br />Threat actor <b>description</b>: <i>Since 1926, U.S. Battery has been designing and manufacturing the world's highest quality deep cycle batteries</i><br />Target victim <b>website</b>: <i>usbattery.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>JWiz</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24891</link>
<guid>6547489ef6174ae02b6d87ee775b3950</guid>
<pubDate>Tue, 05 Aug 2025 21:33:14 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>JWiz</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>8543a3bf04f3eb184a8307223cf3a6497c4a2801bcf73bb2232b279c30b88aa1</i><br /><br />Threat actor <b>description</b>: <i>JWiz offers marketing solutions including online advertising and sales promotion, lead generation, social media, website design, development, hosting and search engine optimization for small and local businesses Samples Posted</i><br />Target victim <b>website</b>: <i>jwiz.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Hankin--Mazel-PLLC</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24892</link>
<guid>73715c097259c228af0648823d754407</guid>
<pubDate>Tue, 05 Aug 2025 21:32:22 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Hankin--Mazel-PLLC</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>ae118344b70256759c59987ce2b568cf3cd5af9df0d8f266658dd7e9a0ed35f8</i><br /><br />Threat actor <b>description</b>: <i>The staff at Hankin & Mazel has been representing cooperative and condominium boards for over 30 years Samples Posted</i><br />Target victim <b>website</b>: <i>hankinmazel.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>Garrison-Law-Firm</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24887</link>
<guid>083e81455b9ce29d158420b35214c4df</guid>
<pubDate>Tue, 05 Aug 2025 21:30:58 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>pear</b> claims attack for <b>Garrison-Law-Firm</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>117c6679959034637aaaf21d05ae9cce189cef1904a67f84108786118a8561d4</i><br /><br />Threat actor <b>description</b>: <i>Garrison Law Firm, LLC specializes in personal injury law, providing legal services to individuals who have suffered injuries due to accidents in Indiana, including car accidents, slip and fall incidents, and wrongful death cases</i><br />Target victim <b>website</b>: <i>garrisonlegal.com</i>]]></description>
<category>pear</category>
</item>
<item xmlns:dc='ns:1'>
<title>ridgefield.org</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24895</link>
<guid>be336fabd87358b66fd4f9c864eb81f3</guid>
<pubDate>Tue, 05 Aug 2025 20:50:10 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>safepay</b> claims attack for <b>ridgefield.org</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>43fb545086a2d1130fc12b0e8ec4fa7e9b92a2fcb4abd75d0a19e649cb287305</i><br /><br />Threat actor <b>description</b>: <i>[AI generated] "Ridgefield.org" represents Ridgefield public schools in Ridgefield, Connecticut. It is a holistic platform providing comprehensive information about the school district, including individual public schools within the district. The site offers resources, news, and updates to students, parents, teachers, and staff, covering academics, sports, arts, and other school-related activities.</i><br />Target victim <b>website</b>: <i>ridgefield.org</i>]]></description>
<category>safepay</category>
</item>
<item xmlns:dc='ns:1'>
<title>Carrollton-Ear-Nose-and-Throat</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24873</link>
<guid>df3abfaa6336c64811b77e86b9cb17b0</guid>
<pubDate>Tue, 05 Aug 2025 18:13:59 CEST</pubDate>
<dc:creator>RansomFeed</dc:creator>
<description><![CDATA[Ransomware group called <b>incransom</b> claims attack for <b>Carrollton-Ear-Nose-and-Throat</b>. The target comes from <b>USA</b>. <img referrerpolicy="no-referrer-when-downgrade" src="https://www.ransomfeed.it/matomo/matomo.php?idsite=1&amp;rec=1&amp;action_name=RSS-USA" style="border:0" alt="" /><br />We identify this attack with following <b>hash code</b>: <i>2a5dc374a71ea95331cf08b9ce2c950b3485d2a88866303cadf2950addd92f50</i><br /><br />Threat actor <b>description</b>: <i>Carrollton Ear, Nose and Throat, P.C. and the staff would like to welcome you to our website! We hope you find our website helpful when searching for information about our practice and your health needs. Our patients are very important to us and we want you to have the best possible experience while you are under our care. We are confident that you will find our staff dedicated to providing care of high quality and value. We look forward to serving you.</i><br />Target victim <b>website</b>: <i>N/D</i>]]></description>
<category>incransom</category>
</item>
<item xmlns:dc='ns:1'>
<title>Origene</title>
<link>https://ransomfeed.it/index.php?page=post_details&amp;id_post=24867</link>
<guid>