Redpacketsecurity Krapf Group and Others Targeted by Ransomware Claims
Article Content
- •Krapf Group listed as a ransomware victim with claims of compromised driver data.
- •Namtheun2.com reported a data exposure of approximately 1.2 TB without encryption details.
- •Moscone.com was also listed, but specifics about the data compromise remain unclear.
On September 22, 2026, Krapf Group, a U.S.-based transportation company, was listed on a ransomware leak site attributed to the KAIROS group. The post claims that personal information related to thousands of bus drivers was compromised, but lacks details on whether data was encrypted or stolen. Additionally, two other organizations, namtheun2.com and moscone.com, were also listed on a ransomware leak site on September 11, 2026, with claims of 1.2 TB of data exposure for namtheun2.com and unspecified data for moscone.com. No ransom demands or specific details about the compromised data were provided in any of the listings. The claims remain unverified and should be treated as unconfirmed until corroborated by independent evidence. The articles emphasize that no files or stolen information were disclosed by RedPacket Security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Kairos Group and Krapf Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…