
Weekly CISO Digest — Week of 2026-07-27: Ransomware Hits Critical Infrastructure
Headline Incident: Deadlock Ransomware Targets Kenya National Highways Authority
The Kenya National Highways Authority (KeNHA), responsible for managing the country's national highways, was hit by the Deadlock ransomware group, causing significant disruption to construction and maintenance operations. The attack, which occurred in Africa, targeted critical infrastructure, highlighting the growing trend of ransomware actors focusing on public sector and essential services. The incident included a published onion link for potential data exposure but has not been independently confirmed by KeNHA. Ransomware groups are increasingly leveraging operational disruption to pressure payment, with attackers now targeting government agencies in addition to private enterprises. CISOs in the infrastructure and public sector should review segmentation and incident response plans for operational technology (OT) environments. Immediate review of backup integrity and network segmentation is advised.
This Week's Incidents
Doommageddon ransomware targets iw steelTEC Makine San. ve Tic. A.,Ş.
What: Turkish manufacturer iw steelTEC Makine San. ve Tic. A.,Ş. was targeted by Doommageddon ransomware, with 100 GB of data claimed leaked.
Who's at risk: Manufacturing and industrial firms in EMEA.
Action: Audit access controls and monitor for data exfiltration.
Deadlock ransomware targets KEMEK manufacturing company
What: KEMEK, a leading Baltic automation manufacturer, was attacked by Deadlock ransomware, causing operational impacts.
Who's at risk: Automation and manufacturing in the Baltics.
Action: Validate endpoint protection and review incident response playbooks.
Hydraulic-components.net targeted by m3rx ransomware with 215 GB data theft
What: German supplier hydraulic-components.net suffered a 215 GB data theft by m3rx ransomware, affecting over 226,000 files.
Who's at risk: Industrial suppliers and logistics in Europe.
Action: Enforce multi-factor authentication and review third-party access.
Section9 ransomware targets travel and tourism company in Macau
What: Section9 ransomware encrypted systems at ****.com.mc, disrupting travel and tourism operations in Macau.
Who's at risk: Hospitality and travel sectors in APAC.
Action: Patch exposed RDP and VPN endpoints immediately.
Ransomware attack claimed on servicebypremier.com by m3rx
What: m3rx ransomware group claimed an attack on US-based HVAC and refrigeration firm servicebypremier.com, engaging in extortion.
Who's at risk: Commercial service providers in North America.
Action: Review backup procedures and test restoration capability.
Ransomware Incident by Section9 Targets Technology Sector
What: Section9 ransomware encrypted systems at an unnamed tech organization, causing confirmed service disruption.
Who's at risk: Technology sector globally.
Action: Harden remote access and monitor for lateral movement.
Deadlock Ransomware Targets Carrier AB
What: Swedish logistics company Carrier AB was disrupted by Deadlock ransomware, impacting operations across Sweden.
Who's at risk: Transport and logistics in EMEA.
Action: Conduct tabletop exercises for ransomware scenarios.
Ransomware Incident at Park Manufacturing Corp.
What: Park Manufacturing Corp. in the US lost access to 195 GB of data in a ransomware attack by Global Secret Group.
Who's at risk: US manufacturing and electronics companies.
Action: Update EDR signatures and verify offsite backups.
Australian Energy Provider Origin Energy Discloses Data Breach
What: Origin Energy, a major Australian provider, disclosed a breach impacting sensitive customer data.
Who's at risk: Energy and utilities in Asia-Pacific.
Action: Notify affected customers and enhance monitoring for identity misuse.
Ransomware Attack on Pro-Tuff | Decals Disrupts Business Operations
What: Pro-Tuff | Decals, a US retail/e-commerce firm, was hit by Global Secret Group, losing access to 412 GB of data.
Who's at risk: Retail and e-commerce in North America.
Action: Review DDoS protection and incident communication plans.
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
What: Attackers compromised hotel/conference Wi-Fi gateways to redirect users to fake Microsoft 365 login pages, stealing credentials globally.
Who's at risk: Hospitality, corporate travelers, and any orgs with remote employees.
Action: Instruct users to avoid public Wi-Fi for authentication and enable conditional access policies.
Deadlock ransomware steals 880GB from Hidromek
What: Turkish heavy machinery manufacturer Hidromek lost over 880 GB of internal data to Deadlock ransomware.
Who's at risk: Industrial and construction equipment manufacturers.
Action: Monitor for large outbound data transfers and review DLP policies.
Section9 ransomware attack on *****.ind.br disrupts agriculture operations in Brazil
What: Section9 ransomware encrypted files at *****.ind.br, disrupting Brazilian agriculture operations.
Who's at risk: Agriculture and food supply chain in Latin America.
Action: Segment OT/IT networks and restrict privileged access.
ExfilSquad ransomware targets Wesco International
What: US-based Wesco International was targeted by ExfilSquad, exfiltrating 2.6 million records of sensitive PII and authentication data.
Who's at risk: Distribution and supply chain firms with large customer/employee datasets.
Action: Rotate credentials and notify affected individuals.
This Week's Pattern
- Ransomware actors are aggressively targeting critical infrastructure and manufacturing, with Deadlock, Section9, and m3rx responsible for the majority of attacks (10 of 15 incidents).
- Data exfiltration and extortion are now standard, with several incidents involving hundreds of gigabytes or millions of records stolen before encryption.
- Public-facing services (Wi-Fi, RDP, VPN) remain high-risk entry points; CISOs should prioritize patching, segmentation, and user education to reduce exposure.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

