Ransomware group clop hits BRINKS-CO.NZ
BRINKS-CO.NZ — a transportation target operating in NZ has been listed by the clop ransomware group on 2026-09-23. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | BRINKS-CO.NZ |
|---|---|
| Threat Group | clop |
| Summary | [AI generated] N/A I don't have verified information about a company operating under the domain "BRINKS-CO.NZ." I want to flag that this domain name is worth treating with caution from a threat intelligence perspective: it closely mimics "Brinks," the well-known US-based security and cash logistics company, while using a New Zealand country-code domain, a pattern sometimes associated with typosquatting or brand impersonation for phishing purposes. I cannot confirm whether this is a legitimate New Zealand subsidiary, an unrelated business, or a malicious lookalike domain without further verification through domain registration records, WHOIS data, or corporate registries. I'd recommend checking NZ Companies Office records and domain registration history before treating this as a legitimate entity. |
| Date of Breach | 2026-09-23 |
| Discovery Date | 2026-09-23 |
| Region | NZ |
| Target Domain | BRINKS-CO.NZ |
| Business Sector | Transportation |
| Severity | CRITICAL |
Claim by clop
[AI generated] N/A I don't have verified information about a company operating under the domain "BRINKS-CO.NZ." I want to flag that this domain name is worth treating with caution from a threat intelligence perspective: it closely mimics "Brinks," the well-known US-based security and cash logistics company, while using a New Zealand country-code domain, a pattern sometimes associated with typosquatting or brand impersonation for phishing purposes. I cannot confirm whether this is a legitimate New Zealand subsidiary, an unrelated business, or a malicious lookalike domain without further verification through domain registration records, WHOIS data, or corporate registries. I'd recommend checking NZ Companies Office records and domain registration history before treating this as a legitimate entity.
Posted by the clop threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
BRINKS-CO.NZ
Leak post (onion / Tor)
http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion/archive12/brinks-co-nz
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

