Redpacketsecurity Multiple Ransomware Attacks Target Various Sectors on September 18, 2026
Article Content
- •Multiple organizations, including MPA Pharma and AstraZeneca Türkiye, were targeted on the same day.
- •The attacks involved significant data theft, with millions of records compromised across various sectors.
- •No ransom demands were disclosed, but publication deadlines suggest ongoing threats from the attackers.
On September 18, 2026, the ransomware groups Rhysida and N0N claimed responsibility for multiple data-leak incidents affecting various organizations, including MPA Pharma, a Vietnamese betting operator, STOKR, PayPal support operations, BeLi Teacher, Argentem Creek Partners, and AstraZeneca Türkiye. The attacks primarily involved data theft rather than system encryption, with significant volumes of sensitive information reported stolen. MPA Pharma was listed with 2.9 million files and 5.8 TB of data, while the Vietnamese betting operator had over 2 million registered bettors' data compromised. STOKR's leak involved sensitive investor information, and PayPal's support operations faced exposure of 86.7 million connection records. The attackers set deadlines for further data publication, indicating ongoing threats. No ransom amounts were specified in the claims, and the extent of the operational impact remains uncertain.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Emperador and Argentem Creek Partners in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…