Redpacketsecurity [METAENCRYPTOR] Ransomware Attacks Target AECOM, Beckman Coulter, and Promantra
Article Content
- •Three U.S. companies listed as ransomware victims on the same day.
- •No specific details on data encryption or ransom demands provided.
- •Claims remain unverified and should be treated with caution.
On September 17, 2026, three U.S.-based companies—AECOM, Beckman Coulter, Inc., and Promantra, Inc.—were listed as victims on the METAENCRYPTOR ransomware group's leak site. AECOM is involved in infrastructure consulting and engineering, while Beckman Coulter specializes in medical diagnostics, and Promantra provides healthcare technology services. The listings do not specify the nature of the attacks, whether data was encrypted or stolen, or any ransom demands. No details regarding the volume of compromised data or specific categories of information were disclosed. The lack of corroborating evidence means these claims should be treated as unverified until confirmed by independent sources. The incident highlights ongoing threats to organizations in critical sectors, particularly healthcare and engineering.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track MetaEncryptor and Aecom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Ransomware Attacks Target Various Companies on September 7, 2026 On September 7, 2026, multiple companies fell victim to ransomware attacks from various groups, including AURORA, THEGENTLEMEN, and DARK PROJECT. Notable victims include Jinny Beauty Supply, Zanini, and NFM Lending, with claims of extensive data breaches involving sensitive customer and corporate information. The…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…