HackerFeeds
All ransomware incidents
brinks-co.nz

Ransomware group clop hits BRINKS-CO.NZ

CRITICAL
·Transportation·NZ·2026-09-23

BRINKS-CO.NZ — a transportation target operating in NZ has been listed by the clop ransomware group on 2026-09-23. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationBRINKS-CO.NZ
Threat Group
clop
Summary[AI generated] N/A I don't have verified information about a company operating under the domain "BRINKS-CO.NZ." I want to flag that this domain name is worth treating with caution from a threat intelligence perspective: it closely mimics "Brinks," the well-known US-based security and cash logistics company, while using a New Zealand country-code domain, a pattern sometimes associated with typosquatting or brand impersonation for phishing purposes. I cannot confirm whether this is a legitimate New Zealand subsidiary, an unrelated business, or a malicious lookalike domain without further verification through domain registration records, WHOIS data, or corporate registries. I'd recommend checking NZ Companies Office records and domain registration history before treating this as a legitimate entity.
Date of Breach2026-09-23
Discovery Date2026-09-23
RegionNZ
Target DomainBRINKS-CO.NZ
Business SectorTransportation
Severity
CRITICAL

Claim by clop

[AI generated] N/A I don't have verified information about a company operating under the domain "BRINKS-CO.NZ." I want to flag that this domain name is worth treating with caution from a threat intelligence perspective: it closely mimics "Brinks," the well-known US-based security and cash logistics company, while using a New Zealand country-code domain, a pattern sometimes associated with typosquatting or brand impersonation for phishing purposes. I cannot confirm whether this is a legitimate New Zealand subsidiary, an unrelated business, or a malicious lookalike domain without further verification through domain registration records, WHOIS data, or corporate registries. I'd recommend checking NZ Companies Office records and domain registration history before treating this as a legitimate entity.

Posted by the clop threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

BRINKS-CO.NZ

Leak post (onion / Tor)

tor

http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion/archive12/brinks-co-nz

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.