Skip to main content

Company intelligence

Btxglobal cybersecurity incidents and threat signals

btxglobal.com

Btxglobal logo

This company page brings together public reporting currently associated with Btxglobal. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Btxglobal. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Btxglobal

Btxglobal logoRansomware
Medium

BTX Global Logistics Targeted by Qilin Ransomware

March 2026 saw a massive influx of cybersecurity news, with a significant wave of ransomware and other malware attacks carried out by threat actors tied to North Korea, Russia and the Islamic Republic of Iran, potentially in concert with the conflict occurring between the latter and the U.S. While there has been action by different law enforcement agencies to counter some of these, the fallout from the attacks  is still ongoing and your business should remain wary of the increased cyber risk going into April and the rest of 2026 . SWK Technologies has put together this month’s Cybersecurity News Recap to help your business keep track of the biggest threats and what they mean for your security posture : Medusa Gang Attacks NJ Passaic County and Mississippi Hospital The Medusa ransomware gang claimed credit for two high-profile attacks in March 2026, targeting the University of Mississippi Medical Center (UMMC) and Passaic County of New Jersey’s local government systems . The UMMC breach began February 19 and forced the closure of 35 clinics across the state, suspended elective surgeries and imaging appointments, and cut off access to the hospital’s Epic electronic health record system for nine days. Staff reportedly reverted to handwritten charts and some patients were diverted to other facilities. Medusa added UMMC to its dark web leak site on March 12, claiming to have exfiltrated more than 1 TB of data including patient health information and employee records, and demanding $800,000 in ransom. Medusa also claimed a separate attack on Passaic County on March 17, demanding the same amount and disrupting phone lines and IT systems serving nearly 600,000 residents. Operating a ransomware-as-a-service (RaaS) model, the group has been active and has a history of targeting critical infrastructure organizations from healthcare to the public sector. Medusa has already claimed various other victims in 2026 , including Frauenshuh Commercial Real Estate, Acme Truck Line, Bell Ambulance , Grandview Family Medicine and many more. The gang seemingly became more active last year in the wake of international law enforcement actions that took down several of the leading ransomware groups . Medtech Vendor Stryker Hit by Pro-Iran Hackers The Iran-linked hacktivist group Handala claimed responsibility for a destructive cyber attack against medical technology manufacturer Stryker on March 11 , framing the attack as retaliation for a U.S. airstrike on a school in Iran. The attackers, suspected to be linked to Iran’s Ministry of Intelligence and Security (MOIS), appear to have gained access to a Microsoft Intune device management console using compromised administrator credentials – potentially obtained through infostealer malware – then issued a remote wipe command that affected more than 200,000 devices across 79 countries. Stryker claimed to have confirmed that the disruption was confined to its Microsoft environment and found no evidence of ransomware or malware deployed on its systems, and stated that Internet-connected medical products remained safe to use. As of March 15, 2026, the company was actively restoring impacted systems , with priority given to those supporting orders and shipping. The FBI and CISA actively engaged with Stryker during the investigation, and the former announced on March 19 that they had seized Handala’s data leak website , among several other domains tied to group (more on this below). Named after a cartoon character drawn by a Palestinian artist, the Handala group emerged in 2023 , claiming to be a pro-Palestinian hacktivist collective retaliating against Israel for its operations in Gaza at the time. Though they have claimed credit for multiple attacks against targets within the Israeli government and private sectors , the March 11 incident appears to be their first major attack against an American target. Qilin Hits Texas Construction Firm and Puerto Rico Food Processor The Qilin ransomware gang claimed responsibility for multiple new attacks on March 18, 2026, including: L.H. Lacy , a large Texas-based contractor serving the construction industry Productos La Aguadillana , a food and beverage processor in Puerto Rico Jacob & Sons , a retailer based in Pennsylvania BTX Global Logistics , a logistics service provider headquartered in Connecticut All of the victims were hit with double extortion – wherein data is first stolen and then threatened to be leaked if a ransom payment is not received – which is typical of Qilin’s M.O. The group had already claimed more than 400 victims in 2026 at the time of this writing, continuing a surge that saw it list over 1000 victims in 2025 and emerge as the most active ransomware gang of the year . Other high-profile attacks they have claimed includes breaches against the LISI Group of France, Nissan , Tulsa International Airport , the Tennessee Valley Electric Cooperative and the Church of Scientology , all within a six-month period. First observed in 2022, Qilin operates a RaaS model , is suspected to be linked to Russia, and consistently targets industries where data sensitivity and operational disruption increase pressure on victims to pay.

Btxglobal

FAQ

Questions about Btxglobal cybersecurity reporting

What does the Btxglobal page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Btxglobal.

Does every mention of Btxglobal appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.