Redpacketsecurity Multiple Ransomware Attacks Target Various Industries in September 2026
Article Content
- •Multiple ransomware groups are actively targeting various industries, including pharmaceuticals and technology.
- •Data leaks involve millions of records, with significant operational impacts reported.
- •No ransom amounts have been disclosed, but deadlines for data publication are set by attackers.
In September 2026, several ransomware groups, including Rhysida and N0N, claimed responsibility for multiple data-leak incidents affecting diverse organizations. Victims include MPA Pharma, Nexbex Solutions, and AstraZeneca Türkiye, with data theft incidents reported involving millions of records across various sectors, including pharmaceuticals, technology, and education. The Rhysida group listed MPA Pharma, claiming access to 5.8 TB of sensitive data, while N0N targeted entities like PayPal support operations and a Vietnamese betting operator, with claims of extensive personal and operational data theft. No ransom amounts were specified in the claims, and the incidents are characterized as data-leak operations rather than encryption events. The attacks have led to operational disruptions and network blackouts for some organizations, with deadlines set for data publication by the threat actors. As of September 19, 2026, the situation remains fluid, with ongoing threats of data exposure and operational impacts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (21)
Following this threat?
Track Emperador and Argentem Creek Partners in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…