Skip to content
Multiple Ransomware Attacks Target Various Industries in September 2026

Multiple Ransomware Attacks Target Various Industries in September 2026

First seen 18 Sep 2026, 18:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 18:44 UTC
  • Multiple ransomware groups are actively targeting various industries, including pharmaceuticals and technology.
  • Data leaks involve millions of records, with significant operational impacts reported.
  • No ransom amounts have been disclosed, but deadlines for data publication are set by attackers.

In September 2026, several ransomware groups, including Rhysida and N0N, claimed responsibility for multiple data-leak incidents affecting diverse organizations. Victims include MPA Pharma, Nexbex Solutions, and AstraZeneca Türkiye, with data theft incidents reported involving millions of records across various sectors, including pharmaceuticals, technology, and education. The Rhysida group listed MPA Pharma, claiming access to 5.8 TB of sensitive data, while N0N targeted entities like PayPal support operations and a Vietnamese betting operator, with claims of extensive personal and operational data theft. No ransom amounts were specified in the claims, and the incidents are characterized as data-leak operations rather than encryption events. The attacks have led to operational disruptions and network blackouts for some organizations, with deadlines set for data publication by the threat actors. As of September 19, 2026, the situation remains fluid, with ongoing threats of data exposure and operational impacts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-11
Nexbex Solutions attacked
Emperador ransomware group claimed a data leak involving client information and source code.
Redpacketsecurity
2026-09-12
Axdia International listed
Rhysida group claimed a data leak involving a German electronics company without encryption evidence.
Redpacketsecurity
2026-09-18
MPA Pharma attacked
Rhysida listed MPA Pharma with claims of 5.8 TB of sensitive data exposure.
Redpacketsecurity
2026-09-18
N0N targets multiple organizations
N0N claimed responsibility for attacks on PayPal support operations and AstraZeneca Türkiye, among others.
Redpacketsecurity
2026-09-19
Inter listed as victim
N0N identified Inter, Venezuela's largest internet provider, as a victim, indicating operational disruptions.
Redpacketsecurity

More articles in this cluster (21)

Following this threat?

Track Emperador and Argentem Creek Partners in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed