Ransomware victim disclosure
← All victimsERSA (Enrique Remmele S.A.C.I.)
listed as ersa.com.py · Claimed by Krybit · listed 10 hours ago
Status timeline
- ListedJun 17, 2026
- Data leakeddate unknown
At a glance
- Group
- Krybit
- Status
- Data leaked
- Country
- Paraguay
- Sector
- Manufacturing
- Listed on leak site
- Jun 17, 2026
About the victim
AI dossier — public-source company profileERSA (Enrique Remmele S.A.C.I.) is a 100% Paraguayan industrial company founded in 1928. Limited public information is available, but the company operates in the manufacturing sector.
- Industry
- Industrial Manufacturing
- Founded
- 1928
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed status: data_published), indicating confirmed exfiltration, but the post excerpt provides no details about data type, volume, or sensitivity. Industrial manufacturing data may include operational information, but without specifics on regulated/sensitive content, severity is assessed as medium.Krybit group claims to have compromised ERSA and published data. The specific nature of the breach (encryption, exfiltration, or both) and the scope of data accessed are not detailed in the available leak post excerpt.
What the group claims
ERSA (Enrique Remmele S.A.C.I.) is a 100% Paraguayan industrial company founded in 1928, originally established for the ...
Sources
Source
Indexed 10 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

