Skip to content
Ransomware Attacks Target Nexbex Solutions and Axdia International

Ransomware Attacks Target Nexbex Solutions and Axdia International

First seen 12 Sep 2026, 15:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 18:55 UTC
  • Nexbex Solutions suffered a significant data breach with client information exposed.
  • Axdia International was listed by the Rhysida group, but details on the attack are scarce.
  • Both incidents lack independent verification and specific ransom demands.

On September 11 and 12, 2026, the Emperador and Rhysida ransomware groups claimed responsibility for attacks on Nexbex Solutions Private Limited and Axdia International, respectively. Nexbex Solutions, an India-based technology firm, reportedly had its databases compromised, exposing client information and source code. The Emperador group claimed to have accessed approximately 600 MB of database data and over 10 GB of source code. In contrast, Axdia International, a German electronics company, was listed on a ransomware leak site, but details regarding the attack's impact or data exfiltration were not provided. Both incidents lack independent verification and specific ransom demands. The current status of both attacks remains unclear, with no confirmed ransom payments or recovery efforts reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
Emperador claims attack on Nexbex Solutions
The Emperador ransomware group announced unauthorized access to Nexbex Solutions' databases and source code, claiming to have obtained sensitive client data.
Redpacketsecurity
2026-09-12
Rhysida lists Axdia International
Axdia International was listed on a ransomware leak site by the Rhysida group, but no details on the extent of the attack were provided.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Emperador and Axdia International in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed