Weekly Ransomware & Breach Intelligence Recap
Discover ransomware attacks and data breaches from Aug 31 – Sep 7, 2025, affecting healthcare, finance, manufacturing, and global supply chains, highlighting key risks and trends.
Weekly Ransomware & Breach Intelligence Recap
Over the past week (Aug 31 – Sep 7, 2025), our monitoring identified significant ransomware activity across multiple continents. The Top-5 most impactful cases were:
1. TEAM GROUP (Thailand) – Medusa:
Integrated engineering & infrastructure consultancy. Data leak of 2.25 TB, affecting critical sectors (water, transport, energy).
2. LPL Financial (USA) – Cephalus:
Major financial services provider. Breach highlights the continued targeting of the financial sector, with high systemic risk.
3. Colorado Health Network (USA) – Cephalus:
Healthcare provider with 900+ GB of data exposed. Threats to patient privacy (PHI/PII) and operational continuity.
4. Taiwan Flex Electronics (Taiwan) – Direwolf:
Electronics manufacturer in the automotive and consumer tech supply chain. Compromise could ripple into global production.
5. Samwha Capacitor Group (South Korea) – Gunra:
Global electronic component supplier. Risks include exposure of intellectual property and supply chain disruptions.

📊 Beyond ransomware, our source breach.house detected in the same timeframe:
• 145 new infostealer packages
• 143 fresh breaches
• 2 confirmed leads
Trend Insight: Healthcare, finance, and manufacturing remain top-targeted verticals, while critical infrastructure and supply chain exposures are on the rise.
Organizations must review vendor dependencies, update detection rulesets, and strengthen incident response readiness.
Discover all attacks and leaks and check if your data has been compromised at:
Darkeye Research Team
SamuelTracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.
Intel briefing
Get breach reports before they trend
Ransomware intel and breach disclosures in your inbox. Signal only, no noise.
Read next //
Weekly Ransomware & Breach Recap (Oct 27–02, 2025)
Discover ransomware attacks and breaches from Oct 27–02, 2025, targeting governments, energy, research, and enterprises, with escalating multi-TB data leaks.
Keep investigating //
Discussion (0)
Sign in to join the discussion
Share your take with the Darkeye community.
No comments yet. Be the first to weigh in.