Dr Damiel Pugliese Ransomware Claim by lamashtu (Sep 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around September 30, 2026, the ransomware group tracked as “lamashtu” allegedly listed an entity identified as “Dr Damiel Pugliese” on its dark web leak site. The listing names the healthcare sector as the affected industry and references the domain “pugliese.loс”. The group claims to hold data belonging to an Argentine accountant, describing an individual certified by the University of Buenos Aires (U.B.A.) and registered with the Professional Council of Economic Sciences of Buenos Aires (C.P.C.E.C.A.B.A.).
Notably, the victim name in the leak site data (“Dr Damiel Pugliese”) does not match the name in the claimed data description (“Dr. Daniel P. Pugliese”). This inconsistency is common in low-quality or automated leak site postings and should be treated as a red flag regarding the claim’s reliability. No data volume was disclosed, and no samples, screenshots, or proof-of-life artifacts have been independently reviewed by Yazoul Security.
Threat Actor Profile
lamashtu is a low-profile ransomware operation with no publicly documented track record at the time of writing. Our intelligence team has identified no known victim count, no confirmed tooling, and no published research from established threat intelligence vendors. This absence of visibility is itself meaningful: it may indicate a newly emerged group, a rebrand of an existing operation, or an actor that simply has not attracted analyst attention.
Because no known tools or tactics have been attributed to lamashtu, we cannot assess whether the group favors double extortion, data-only extortion, or purely disruptive attacks. No YARA rules or detection signatures specific to this group are currently available. Defenders should rely on generic ransomware detection guidance - monitoring for mass file encryption behavior, unusual outbound data transfers, and unauthorized access to backup infrastructure - rather than group-specific indicators.
Alleged Data Exposure
The leak site text purportedly describes professional and credential information relating to an accountant. The claim references academic and professional registration details rather than a large corporate dataset. No file listings, record counts, or data samples have been provided in the information available to us.
Given the mismatch between the victim name and the described individual, it is possible the listing is inaccurate, recycled, or generated with limited verification by the actor. We have not confirmed that any data was actually exfiltrated, nor that the referenced domain or individual is connected to the posting.
Potential Impact
If the claim is accurate, the exposure could involve personal and professional identifying information, which carries risks of identity fraud, credential misuse, and targeted phishing against the affected individual and their clients. Healthcare-adjacent professional services are frequently targeted because of the sensitivity of client financial and personal records.
However, the small apparent scope and the internal inconsistencies in the listing suggest the practical impact may be limited. Ransomware groups routinely exaggerate victim significance to increase pressure and reputational damage.
What to Watch For
- Any official statement from the affected individual or their professional body.
- Publication of data samples by the group, which would raise confidence in the claim.
- Reuse of the lamashtu branding by other actors, which could indicate a rebrand.
- Additional victims appearing under the same group name, which would help establish a pattern.
Disclaimer
This report is based solely on an unverified claim published on a ransomware group’s leak site. Yazoul Security has NOT independently confirmed the attack, the data theft, or the accuracy of any details. Ransomware operators frequently make false or inflated claims. Nothing in this article should be treated as established fact, and no data, credentials, or access information is provided. For related coverage, see our /news/ section.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.