Peru's Agrofruto SAC listed by Arcus Media
Arcus Media named Peru's Agrofruto SAC as a ransomware victim, with a data leak deadline set for Sept. 30, 2026.
Arcus Media named the Peruvian agroindustrial company Agrofruto SAC as a ransomware victim and set a data leak deadline for Sept. 30, 2026, pointing to data theft and active extortion. Ransomware.live also listed AGROFRUTO SAC as a victim attributed to the group, placing it in Peru’s agriculture and food production sector and estimating the attack date as Sept. 23, 2026.
Arcus Media listed the Peruvian agroindustrial company Agrofruto SAC as a ransomware victim and set a data leak deadline for Sept. 30, 2026, pointing to stolen corporate information and active extortion. Ransomware.live also recorded AGROFRUTO SAC as a victim attributed to the group, placing it in Peru’s agriculture and food production sector and estimating the attack date as Sept. 23, 2026.
What is known about the Agrofruto SAC case?
The available information indicates that the group claimed the incident and kept a data publication ultimatum in place, but there is no public validation of the affected company in the material provided. Dexpose published an independent entry on the claim and described the same Sept. 30, 2026 deadline, while noting that the information comes from the actor’s allegation and not from verification by Agrofruto SAC.
What does this show about Arcus Media activity?
Threat intelligence reports place Arcus Media in multiple markets across the Americas and beyond the region. A Kalir brief cited victims in Costa Rica, the United States, Canada and Brazil, while Scrutéx counted four publications attributed to the group during the week of Sept. 14 to 20, 2026. That monitoring did not provide victim names or public confirmation of the incidents.
What regional context do the other reports provide?
Infosecurity Magazine reported that South American organizations accounted for 6% of ransomware victims in the period analyzed, with the highest pressure on industrial, consumer goods and service, healthcare, IT and financial services. In the same report, among incidents attributed to known actors, 164 were assigned to Qilin and 116 to The Gentlemen.
What tactics does CYFIRMA attribute to the group?
CYFIRMA described ArcusMedia as focused on countries including Brazil, Spain, France, the United States and Canada, and linked it to an incident against an agricultural organization in Thailand. The report also said the group used phishing emails for initial access, customized ransomware binaries and obfuscation techniques.
What is confirmed for Latin America?
In the verified information, the confirmed case in the region is Agrofruto SAC in Peru. That is supplemented by mentions of the group’s activity in Brazil and Costa Rica in different weekly monitoring reports, although Scrutéx clarified that its publication count does not include public confirmation of the incidents.
Sources
- Ransomware arcusmedia publica a la agroindustrial peruana ...pulse.kalir.io· Kalir
- Weekly Intelligence Report - 25 Sep 2026cyfirma.com· CYFIRMA
- ArcusMedia Targets Agroindustrial Leader AGROFRUTO SACdexpose.io· Dexpose
- Victim: AGROFRUTO SACransomware.live· Ransomware.live
- Ransomware Attacks This Week: 221 Victims Across 47 Groups, September 14 to September 20scrutex.ai· Kalir
- Ransomware Attacks Reach Record High for 2026infosecurity-magazine.com· Infosecurity Magazine



