MS13-089 surfaced on our tracker on a single date, 15 August 2026, with one claimed victim to date: a Chilean organization, servmarmg.cl, listed under an unspecified "Other" sector. The group's naming convention references a 2013 Microsoft security bulletin, though this appears to be branding rather than an indicator of technique. No MITRE ATT&CK techniques have been catalogued for this actor yet, and no pattern of sector or geographic concentration can be established from a single incident. The group is described in open-source reporting as operating a double-extortion model, but that claim, along with any prior victim history, comes from the actor's own messaging and remains unverified. At this stage MS13-089 should be treated as an unproven, low-volume entrant rather than an established threat with a defined operational signature.