logo

Mespinoza Ransomware Leaks Sensitive Data

ID: 5a08203b-b6ec-5fee-84f4-c95f3c001519

STIX ID: report--5a08203b-b6ec-5fee-84f4-c95f3c001519

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-07-17

...
...

Cyble researchers identified and verified multiple data leaks posted by the PYSA/Mespinoza ransomware group affecting organizations including Diamond Box, Allard‑Europe, Matthews, Fincamex, St Andrew’s College and Liberty Linehaul; published material reportedly includes payroll records, policy documents and credit card details. The post contains screenshots of leaked content and high-level remediation advice (use MFA, strong passwords, monitor financial transactions, enable updates and use reputable antivirus) but does not provide technical indicators or deep malware analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.