New extortion crew opens with a ministry and an ISP

Published

A leak site that did not exist a week ago is now advertising ten victims, and two of them are not the sort of names a new crew usually opens with: Argentina's Ministry of Education, and Inter, Venezuela's largest internet provider.

None of it is confirmed. A leak site entry is an accusation written by the people who profit from it, and that is where this story starts.

Ten listings, eight countries, one scrape

IntelFusions logged all ten claims on 18 September, but that single date is bookkeeping rather than a burst: every row carries the moment our importer first scraped the site, at 18:00 UTC that evening. WatchGuard's ransomware tracker, which picked the group up separately, dates the extortion posts across 12 to 14 September. The crew is the genuinely new part, and it fits the shape of this market in 2026, where more groups arrive with fewer victims apiece.

By our mapping the ten span eight countries: Argentina, Brazil, Luxembourg, Sweden, Turkiye, the United States (twice), Venezuela and Vietnam (twice). The sectors are just as scattered: a government ministry, a telecoms operator, a teachers' union, a pharmaceutical subsidiary, three finance and payments related firms, a legal services company, an education provider and a betting operator.

Records and access, not locked servers

Read the posts and one thing is conspicuously absent: encryption. WatchGuard's tracker entry classifies n0n as a data broker rather than a crypto ransomware operation, records it as first seen in September 2026, and notes both direct and double extortion. Its own description of the group is one line: emerging and active.

What the listings advertise is volume of access data. The entry against Inter claims more than 15.3 million subscriber connection records plus a full internal network map. The one naming Transcom WorldWide, an outsourced customer support provider, claims 86.7 million connection records from support agent sessions into a client's corporate remote access systems. The AstraZeneca Turkiye entry claims 1.35 million connection records and the security configuration of three sites; the US investment firm Argentem Creek Partners is credited with 2.5 million. Every one of those figures is the crew's own, unverified by us and unconfirmed by the organizations named.

A second motif repeats across the posts: the assertion that victims are holding a network blackout in place until a settlement is reached. That is the crew describing its own leverage, not an outage anyone else has observed.

When the famous brand is not the listed victim

The listing that names PayPal is the one to read slowly. The victim actually named is Transcom, the support outsourcer, and the claim concerns agent sessions into a client's systems rather than an intrusion into the payment company itself. A supplier compromise gets written up under the biggest brand in reach, because that is where the pressure sits. Establish that distinction before calling any of this a breach of the brand in the headline.

No patch here, but a short evidence list

There is no vulnerability to fix here. If your organization is on the list, or supplies one that is, the work is evidentiary: pull remote access and session logs for the dates the crew names, review what third-party support accounts can reach, and settle now what you will say when a customer asks. If you are not on it, the target profile still matters. Outsourced support desks, managed access and the identity plumbing between a supplier and its client are what this group says it walked off with.

The next few weeks will settle how much of it was real, and silence will be as informative as a statement. IntelFusions tracks the group as N0n, and the wider picture behind its most consequential claim sits on our Venezuela country profile.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions