Threat Watch · Sep 4, 2026
Law and accounting firms are unusually dense in this window's victim list: Katten Muchin Rosenman, Hagelgans & Veronis, Blanco & Etcheverry, SGLA and Maglin Miskiv belong to five different groups but all landed within the same 36 hours. These firms are not large themselves, but the files they hold for clients cover litigation, tax and M&A — the leverage is not on the victim.
Everything below is a claim posted by a group on its own leak site, not a confirmed intrusion. Two trackers independently mirror those sites; where both recorded the same claim, this issue says so — that is the only cross-check available here.
Group activity
Settra — 9 new claims
The highest count in this window, spanning Spanish industrial manufacturing (Industrias Alegre), Italian diagnostics (DiaSorin), Canadian distribution and cell tower construction (Hansler Smith, Teletek Structures), US medical billing (MedEvolve), Dutch engineering consultancy (Buro Boot) and a US law firm (Hagelgans & Veronis). Several posts carry specific descriptions of data volume; the Buro Boot entry lists 79,344 PDF files along with the directory structure they sat in.
Sources: ransomware.live · ransomware.live · ransomware.live
Storm — 7 new claims
Concentrated on US small and mid-sized businesses, spread across sectors with no obvious common entry point: construction (Petrocare), aircraft engine wire harness repair (Star Aviation), subprime auto lending (GSAC Auto Financing), an agricultural cooperative (Superior Ag), wealth management (Chicago Partners Wealth Advisors, over $850 million in assets under advice), diesel engine management (Macquarrie) and orthopedic implant R&D (SITES Medical).
Sources: ransomware.live · ransomware.live · ransomware.live
SilentRansomGroup — 3 new claims
One is the law firm Katten Muchin Rosenman; the other two are posted as initials with a "FULL DATA TIMER" counting down and the full names withheld. RansomLook records the same victims under the name leakeddata — the two trackers using different group names for one set of claims, the same situation as the Holland & Knight entry on Sep 2.
Sources: ransomware.live · RansomLook
Spacebears — 2 new claims
Studio Oculistico Ciraci, an ophthalmology clinic in Bari, Italy that opened in 1989 and is accredited with the Italian national health service, and SGLA, an accountancy firm in Stockton, California. Both claims were recorded independently by both trackers.
Sources: ransomware.live · ransomware.live
Gunra — 2 new claims
The law firm Blanco & Etcheverry (around $5 million in revenue) and the insurer Occidental (around $157 million). This group's posts carry revenue figures, which says what it is screening targets on.
Sources: ransomware.live · ransomware.live
Panzer — 2 new claims
The Bildungscampus of Heilbronn University in Germany, and the Central Java provincial communications and informatics agency in Indonesia (Dinas Komunikasi dan Informatika). A university and a provincial government body — both public sector.
Sources: ransomware.live · RansomLook
Qilin — 2 new claims
Complete Packaging Solutions (business services) and Tanner (finance). Down from three on Sep 2.
Sources: ransomware.live · ransomware.live
Vexy — 2 new claims
The McDonald's franchise operation in Ecuador and the Brazilian adhesive tape manufacturer Engefitas — both Latin American targets.
Sources: ransomware.live · ransomware.live
Auditteam — 2 new claims
One is mansurovogroup, an integrated agricultural enterprise in Kursk Oblast, Russia, operating across grain and seed production, beef and dairy cattle and two further segments. The other is posted only as an internal domain name, PIT.local. Claims against Russian entities are not common on these leak sites.
Sources: ransomware.live · ransomware.live
Notable targets
Katten Muchin Rosenman — claimed by SilentRansomGroup
A large full-service US law firm with offices in major American cities and internationally, practising across corporate law, real estate and other areas. It is the third large US law firm posted within a week, after Holland & Knight on Sep 2 and Greenberg Traurig on Sep 3.
Sources: ransomware.live · RansomLook
DiaSorin — claimed by Settra
A listed Italian in-vitro diagnostics company operating globally. The post states that it covers only a portion of the data the group has chosen to publish.
Sources: ransomware.live
NeoGen Corporation — claimed by ShinyHunters
The post claims over 5 million Salesforce records containing some personally identifiable information, plus more than 541GB of internal SharePoint corporate data, and says no agreement was reached. It follows the group's Aug 30 claim over McKesson patient records — another large SaaS data claim from the same group.
Sources: RansomLook
INCAN (Instituto de Cancerología y Hospital Dr. Bernardo del Valle) — claimed by Krybit
Guatemala's leading private cancer treatment institution. It is not the only healthcare entry this window: Settra's MedEvolve (US medical billing) and Spacebears' Studio Oculistico Ciraci (Italian ophthalmology clinic) fall in the same category.
Sources: ransomware.live
America's Food Basket — claimed by Wallstreet
A US cooperative grocery-store network offering store locations, weekly ads, online shopping and delivery. Both trackers recorded this claim.
Sources: ransomware.live · RansomLook
EDIF S.p.A. — claimed by Aurora
An Italian wholesale distributor of electrical equipment, plumbing and lighting systems. The post claims the exposed files include passwords for company systems and customer file transfers.
Sources: ransomware.live