Extortion activity and victim disclosures across active groups.
34 new victim claims in 36 hours across 10 groups, krybit the most active (12); headline: Aurora leaked SAP integrator ERPIS/ShipERP's full source code and financial data.
Krybit and Qilin lead a 36-hour window of 64 distinct victim claims across roughly 20 groups, cross-validated between RansomLook and ransomware.live.
Roughly 40 genuine ransomware victim disclosures within 36 hours: the crew focused on multiple Myanmar institutions and Cyprus Airways; dark project and qilin logged 6 each; one dragonforce case involves credit and Social Security information for thousands of clients.
15 groups left 44 victim claims over the past 36 hours; qilin and the crew were the most active, ShinyHunters demanded a USD 13 million ransom from CyrusOne, and LockBit5 claimed security company ADT.
Eight groups added new victim claims over the past 36 hours: coinbase cartel led with 13 in a single day; shinyhunters claimed security firm ReliaQuest and regional bank BOK Financial; emperador claimed Vietnam's national power utility; lockbit5 claimed Brazilian defense shipbuilder ICN.
RansomLook recorded 124 claims over the past 36 hours, with the gentlemen, coinbase cartel, direwolf, and qilin the most active; a large number of anomalous entries resembling vulnerability probe / injection strings were found mixed into the gentlemen's data and have been excluded.
RansomLook logged 91 victim disclosures over the past 36 hours, spanning roughly 25 groups. the gentlemen was the most active (about 24 claims across many industries in Europe, the Americas, and Asia), followed by direwolf (about 13) and qilin (about 10). Notable: Kingston Technology (memory manufacturer) and Capgemini Engineering (global IT consultancy) claimed by everest; Interim HealthCare claimed by anubis.
RansomLook logged roughly 60 victim disclosures over the past 36 hours: qilin, titan, everest, inc ransom, and krybit were the most active; lockbit5 claims an attack on U.S. Bank, xpl0itrs claims Target, and the gentlemen set its sights on Taiwan's BioPharma and on Babcock. CISA/FBI report that Medusa has breached 500+ US critical infrastructure organizations; in China, the Sorry ransomware has broken out at multiple sites.
64 attack disclosures claimed by ransomware groups were monitored over the past 36 hours, spanning roughly 20 active groups; qilin and shinyhunters were the most active, with shinyhunters' targets clustering in healthcare and pharma, alongside individual cases such as the public release of 11TB of NYC Health + Hospitals data.
RansomLook logged 51 victim disclosures over the past 36 hours, spanning 20 different ransomware groups.
42 RansomLook victim claims read within a 36-hour window, from 11 groups; qilin was the most active, claiming 19 victims in a single day.
RansomLook logged 39 intrusion claims within a 36-hour window, spanning 12 ransomware groups.
RansomLook logged 44 ransomware group disclosures within a 36-hour window, spanning 16 groups. The following are selected by activity level and target significance.
RansomLook logged 50 victim disclosures over the past 36 hours from 15 groups. the gentlemen and qilin were the most active; coinbase cartel's disclosures of Hitachi High-Tech and Turner and Townsend carry the widest impact; Clop was active on two fronts the same day (the Shell incident plus a ZEBRA.COM disclosure).
112 disclosures monitored over the past 36-hour window, from 17 active groups (source: RansomLook).
RansomLook logged 113 victim claim disclosures within a 36-hour window, aggregated by group below.
Source material: RansomLook (global disclosure RSS), 54 victim disclosures within a 36-hour window.
RansomLook recorded 52 new victim claims in the past 36 hours; qilin and the gentlemen together account for more than half. The most notable targets include Hong Kong Baptist University, Université Libre de Bruxelles in Belgium, and Taiwanese biopharma company PharmaEssentia.
RansomLook logged 30 victim disclosures across 7 groups in the past 36 hours; qilin was the most active (8), while leakeddata disclosed a concentrated batch of 11 US law firm victims.
⚠️ Data-source note: the RansomLook Recent Posts API was unreachable this run (network/provenance restrictions). Data on this page comes from secondary tracking sources and news reporting, not a structured API pull. Figures are approximate.
⚠️ Data-source note: the RansomLook API / RSS was unreachable from the execution sandbox this round (restricted network egress). The following is a compilation of recent representative activity based on public intelligence reporting, not live per-post RansomLook data. Watchlist hits are marked with ⭐.
⚠️ Data note: this run could reach neither the RansomLook API (`/api/posts?days=1`) nor the RSS fallback from the execution environment (sandbox network restrictions + web_fetch provenance gate). The items below are compiled from public reporting, not a structured RansomLook pull; the victim list is incomplete and covers only representative victims named on or around the day.
Source: RansomLook `api/posts?days=1`. ⚠️ The latest post timestamps returned by the API this run fall on 2026-07-23~24, suggesting source-side lag; coverage is not strictly the past 24 hours — for reference only.
⚠️ Collection note: direct access to the RansomLook API (`/api/posts?days=1`) and its RSS feed was blocked by network policy inside the sandbox (empty responses), so this edition cross-checks recent disclosures via web search instead. The data is "representative of the week" rather than a strict 24h full set, and victim counts are omitted.
⚠️ Data source note: both the RansomLook API (`/api/posts?days=1`) and the RSS fallback were blocked by the sandbox's network egress controls (HTTP 000). This page is an **indicative snapshot compiled from web search**, not RansomLook's complete victim set for the day; victim counts and "discovered" times follow public reporting and may lag or be incomplete.
Data source: RansomLook `api/posts?days=1` (window approx. 2026-07-23 17:00 → 07-24 15:00 UTC)
Data source: RansomLook `/api/posts?days=1`. The API returns a limited field set (group_name / post_title / discovered) with no sector or geo, so those columns are left blank below.
The two entries were discovered less than a second apart (2026-07-19T15:58:56 / :57), the classic signature of a batch upload to a leak site.
Data source: RansomLook `api/posts?days=1` (the returned window covers the latest leak-site updates from 2026-07-18 to 07-19). This endpoint returns only group_name / post_title / discovered, so each victim's sector and geo are manual inferences.
⚠️ qilin hitting **City Ambulance Service** deserves attention: emergency medical services is an extremely availability-sensitive sector, and qilin has long been on the watchlist (~1,496 cumulative leak-site victims over the past 12 months, roughly 16% market share — see [Infosecurity](https://www.infosecurity-magazine.com/news/qilin-dominates-ransomware-market/)).