Ransomware Hits Mexico and US in LATAM
KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM added victims in Mexico and the United States, with signs of regional expansion.
KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM posted new victims over 24 to 72 hours, with cases in Mexico and the United States. Security Arsenal flagged signs of expansion into LATAM, while other trackers confirmed Mexican victims and one U.S. case not yet validated by the affected company.
KRYBIT, EMPERADOR, THEGENTLEMEN and INCRANSOM posted new victims over 24 to 72 hours, with confirmed cases in Mexico and the United States and signs of expansion into Latin America. Security Arsenal linked KRYBIT to 14 victims in a single day, including two in Mexico, and THEGENTLEMEN to 16 victims in 24 hours, with about 31% of them in LATAM.
What do KRYBIT's recent posts show?
KRYBIT showed concentrated, multi-country activity, with 14 victims posted in one day and two of them in Mexico, according to Security Arsenal. The same monitoring also said the group listed the tum.com.mx domain and uicc.org on its leak site on September 1, 2026, reinforcing the picture of a simultaneous campaign against multiple organizations.
External research on tum.com.mx identified the victim as Transportistas Unidos Mexicanos División Norte, S.A. de C.V., one of Mexico's largest road transport operators. Other leak-tracking sources, however, classified the domain as education. That sector mismatch does not change the central point, a Mexican victim attributed to KRYBIT.
What is known about EMPERADOR and its technical chain?
EMPERADOR posted four new victims in 72 hours, and its initial access pattern involved exploitation of edge devices, with exposed RDP and phishing as secondary vectors, according to Security Arsenal. In its analysis, the firm also placed confirmed victims in the United States, including one in transportation.
The TTP chain attributed to the group included edge device exploitation, preparation of remote access tools, lateral movement with PsExec and WMI, data staging, shadow copy deletion, and encryption. The report does not mention victims in Latin America for this batch, but it does show a consistent technical pattern and a clear focus on exposed infrastructure.
Where did THEGENTLEMEN strike?
THEGENTLEMEN posted 16 victims in 24 hours, and about 31% of those posts were tied to Latin America, with cases in Mexico, Brazil, Puerto Rico, and Argentina, according to Security Arsenal. The same analysis placed victims in transportation, healthcare, energy and utilities, agriculture and food production, and retail and e-commerce.
Among the listed cases is Northwest Trophy, a retail victim in the United States that was also recorded by incident aggregators and breach trackers as a case still unconfirmed by the company or regulators. Specialized portals noted technical discovery and estimated attack dates, but kept the incident in claim status without corporate validation.
What does INCRANSOM add to this picture?
INCRANSOM added five new victims in 72 hours, and the set included cases in Mexico, the United States, and South Africa, with U.S. victims in energy and utilities, professional services, and technology, according to Security Arsenal. In LATAM, victim tracking attributed to INCRANSOM the attack on the Mexican company Wittmann, classified as manufacturing.
That overlap across sources broadens the regional picture of the actor, which appears active in manufacturing and energy, with documented presence in Mexico. At the same time, its latest batch of posts reinforces that the group operated across more than one geography at once, within a short public exposure window on leak sites.
Sources
- Krybit Ransomware Impacts TUM Transportistas Unidos Mexicanosdexpose.io· Dexpose
- EMPERADOR Ransomware Gang: 4 New Victims Posted — Energy Sector Targeting, Edge Device Exploitation and Detection Rulessecurityarsenal.com· Security Arsenal
- INCRANSOM Ransomware Gang: 5 New Victims Posted — Manufacturing and Energy Targeting Analysis with Detection Rulessecurityarsenal.com· Security Arsenal
- Ransom! Northwest Trophy (AUG-2026)hendryadrian.com· Hendry Adrian
- Northwest Trophy Listed by The Gentlemen Ransomware ...galaxywarden.com· Galaxy Warden
- tum.com.mx data breach — Krybit ransomware leak (2026)darkfield.orizon.one· Darkfield (Orizon)
- Ransomware Group krybit Hits: tum.com.mxhookphish.com· HookPhish
- uicc.org data breach — Krybit ransomware leak (2026)darkfield.orizon.one· Darkfield (Orizon)
- wittmann — INCRANSOM Ransomware Attack | Breach Housebreach.house· Breach House
- Victim: Northwest Trophy – thegentlemenransomware.live· ransomware.live
- KRYBIT Ransomware Gang: 14 Victims Posted in Single Day Surge — Cross-Sector Campaign Analysis and Detection Engineeringsecurityarsenal.com· Security Arsenal
- Northwest Trophy: Unconfirmed Breach Claims & DoxxScan™ Ratingrecentbreaches.com· RecentBreaches
- THEGENTLEMEN Ransomware Gang: 16 Victims Posted in 48 Hours — Sector Targeting Analysis and Detection Rulessecurityarsenal.com· Security Arsenal



