Skip to content
Multiple Companies Targeted by Ransomware Groups MONEYMESSAGE and TERMITE

Multiple Companies Targeted by Ransomware Groups MONEYMESSAGE and TERMITE

First seen 22 Sep 2026, 04:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 05:43 UTC
  • MONEYMESSAGE and TERMITE claimed ransomware attacks on multiple U.S. companies.
  • No details on attack methods, data encryption, or ransom demands were provided.
  • All claims remain unverified and should be treated with skepticism.

On September 21 and 22, 2026, two ransomware groups, MONEYMESSAGE and TERMITE, claimed attacks on multiple companies. MONEYMESSAGE listed U.S. Electrical Services and Wiedenbach Brown, while TERMITE named Sealcon, TruAmerica Multifamily, and theLender as victims. The posts provided no details on the attack methods, whether data was encrypted or stolen, or any ransom demands. The claims are unverified and lack corroborating evidence. All companies mentioned are U.S.-based, with operations in energy, manufacturing, real estate, and financial services. The scope of the incidents remains unclear, and no specific impact or operational disruptions have been reported. As of now, these claims should be treated with skepticism until further evidence is available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
MONEYMESSAGE claims attack on U.S. Electrical Services and Wiedenbach Brown
The ransomware group named these companies as victims, but no details on the attack were provided.
Redpacketsecurity
2026-09-22
TERMITE claims attacks on multiple companies
Sealcon, TruAmerica Multifamily, and theLender were listed as victims, but details on the incidents remain unclear.
Redpacketsecurity
2026-09-22
Sealcon listed as a victim
Sealcon, a cable-management provider, was named in a ransomware leak post by TERMITE.
Redpacketsecurity
2026-09-22
TruAmerica Multifamily listed as a victim
The real estate investment firm was included in a post by TERMITE, but no details on the attack were shared.
Redpacketsecurity
2026-09-22
theLender listed as a victim
The wholesale mortgage company was named by TERMITE, with no specifics on the attack provided.
Redpacketsecurity

More articles in this cluster (4)

Following this threat?

Track Termite and Sealcon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed