Skip to content
Multiple Ransomware Attacks Target Various Sectors on September 18, 2026

Multiple Ransomware Attacks Target Various Sectors on September 18, 2026

First seen 18 Sep 2026, 18:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 21:53 UTC
  • Multiple organizations, including MPA Pharma and AstraZeneca Türkiye, were targeted on the same day.
  • The attacks involved significant data theft, with millions of records compromised across various sectors.
  • No ransom demands were disclosed, but publication deadlines suggest ongoing threats from the attackers.

On September 18, 2026, the ransomware groups Rhysida and N0N claimed responsibility for multiple data-leak incidents affecting various organizations, including MPA Pharma, a Vietnamese betting operator, STOKR, PayPal support operations, BeLi Teacher, Argentem Creek Partners, and AstraZeneca Türkiye. The attacks primarily involved data theft rather than system encryption, with significant volumes of sensitive information reported stolen. MPA Pharma was listed with 2.9 million files and 5.8 TB of data, while the Vietnamese betting operator had over 2 million registered bettors' data compromised. STOKR's leak involved sensitive investor information, and PayPal's support operations faced exposure of 86.7 million connection records. The attackers set deadlines for further data publication, indicating ongoing threats. No ransom amounts were specified in the claims, and the extent of the operational impact remains uncertain.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
MPA Pharma listed by Rhysida
Rhysida claimed to have stolen 2.9 million files from MPA Pharma, totaling 5.8 TB of data.
Redpacketsecurity
2026-09-18
Vietnamese betting operator targeted
N0N reported a data leak involving over 2 million registered bettors from a Vietnamese betting operator.
Redpacketsecurity
2026-09-18
STOKR listed by N0N
N0N claimed access to sensitive investor information from STOKR, a digital securities platform.
Redpacketsecurity
2026-09-18
PayPal support operations affected
N0N claimed to have accessed 86.7 million connection records from Transcom WorldWide, which supports PayPal.
Redpacketsecurity
2026-09-18
BeLi Teacher targeted
N0N reported a data leak from BeLi Teacher, including 152,044 customer records from an education center.
Redpacketsecurity
2026-09-18
Argentem Creek Partners listed
N0N claimed to have stolen over 2.5 million connection records from Argentem Creek Partners, an investment firm.
Redpacketsecurity
2026-09-18
AstraZeneca Türkiye targeted
N0N claimed access to AstraZeneca Türkiye's internal network-security configuration, affecting multiple sites.
Redpacketsecurity

More articles in this cluster (13)

Following this threat?

Track Emperador and Argentem Creek Partners in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed