Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware

Ransomware

Victim disclosures

Extortion activity and victim disclosures across active groups.

83 Issues · Page 1 / 3

2026-08-28
Ransomware Watch · Aug 28, 2026

34 new victim claims in 36 hours across 10 groups, krybit the most active (12); headline: Aurora leaked SAP integrator ERPIS/ShipERP's full source code and financial data.

34 Items
2026-08-27
Ransomware Watch · Aug 27, 2026

Krybit and Qilin lead a 36-hour window of 64 distinct victim claims across roughly 20 groups, cross-validated between RansomLook and ransomware.live.

64 Items
2026-08-26
Ransomware Watch · Aug 26, 2026

Roughly 40 genuine ransomware victim disclosures within 36 hours: the crew focused on multiple Myanmar institutions and Cyprus Airways; dark project and qilin logged 6 each; one dragonforce case involves credit and Social Security information for thousands of clients.

29 Items
2026-08-25
Ransomware Watch · Aug 25, 2026

15 groups left 44 victim claims over the past 36 hours; qilin and the crew were the most active, ShinyHunters demanded a USD 13 million ransom from CyrusOne, and LockBit5 claimed security company ADT.

7 Items
2026-08-24
Ransomware Watch · Aug 24, 2026

Eight groups added new victim claims over the past 36 hours: coinbase cartel led with 13 in a single day; shinyhunters claimed security firm ReliaQuest and regional bank BOK Financial; emperador claimed Vietnam's national power utility; lockbit5 claimed Brazilian defense shipbuilder ICN.

8 Items
2026-08-23
Ransomware Watch · Aug 23, 2026

RansomLook recorded 124 claims over the past 36 hours, with the gentlemen, coinbase cartel, direwolf, and qilin the most active; a large number of anomalous entries resembling vulnerability probe / injection strings were found mixed into the gentlemen's data and have been excluded.

10 Items
2026-08-22
Ransomware Watch · Aug 22, 2026

RansomLook logged 91 victim disclosures over the past 36 hours, spanning roughly 25 groups. the gentlemen was the most active (about 24 claims across many industries in Europe, the Americas, and Asia), followed by direwolf (about 13) and qilin (about 10). Notable: Kingston Technology (memory manufacturer) and Capgemini Engineering (global IT consultancy) claimed by everest; Interim HealthCare claimed by anubis.

91 Items
2026-08-21
Ransomware Watch · Aug 21, 2026

RansomLook logged roughly 60 victim disclosures over the past 36 hours: qilin, titan, everest, inc ransom, and krybit were the most active; lockbit5 claims an attack on U.S. Bank, xpl0itrs claims Target, and the gentlemen set its sights on Taiwan's BioPharma and on Babcock. CISA/FBI report that Medusa has breached 500+ US critical infrastructure organizations; in China, the Sorry ransomware has broken out at multiple sites.

12 Items
2026-08-20
Ransomware Watch · Aug 20, 2026

64 attack disclosures claimed by ransomware groups were monitored over the past 36 hours, spanning roughly 20 active groups; qilin and shinyhunters were the most active, with shinyhunters' targets clustering in healthcare and pharma, alongside individual cases such as the public release of 11TB of NYC Health + Hospitals data.

64 Items
2026-08-18
Ransomware Watch · Aug 18, 2026

RansomLook logged 51 victim disclosures over the past 36 hours, spanning 20 different ransomware groups.

51 Items
2026-08-17
Ransomware Watch · Aug 17, 2026

42 RansomLook victim claims read within a 36-hour window, from 11 groups; qilin was the most active, claiming 19 victims in a single day.

5 Items
2026-08-16
Ransomware Watch · Aug 16, 2026

RansomLook logged 39 intrusion claims within a 36-hour window, spanning 12 ransomware groups.

39 Items
2026-08-15
Ransomware Watch · Aug 15, 2026

RansomLook logged 44 ransomware group disclosures within a 36-hour window, spanning 16 groups. The following are selected by activity level and target significance.

12 Items
2026-08-14
Ransomware Watch · Aug 14, 2026

RansomLook logged 50 victim disclosures over the past 36 hours from 15 groups. the gentlemen and qilin were the most active; coinbase cartel's disclosures of Hitachi High-Tech and Turner and Townsend carry the widest impact; Clop was active on two fronts the same day (the Shell incident plus a ZEBRA.COM disclosure).

50 Items
2026-08-13
Ransomware Watch · Aug 13, 2026

112 disclosures monitored over the past 36-hour window, from 17 active groups (source: RansomLook).

2026-08-12
Ransomware Watch · Aug 12, 2026

RansomLook logged 113 victim claim disclosures within a 36-hour window, aggregated by group below.

2026-08-11
Ransomware Watch · Aug 11, 2026

Source material: RansomLook (global disclosure RSS), 54 victim disclosures within a 36-hour window.

15 Items
2026-08-10
Ransomware Watch · Aug 10, 2026

RansomLook recorded 52 new victim claims in the past 36 hours; qilin and the gentlemen together account for more than half. The most notable targets include Hong Kong Baptist University, Université Libre de Bruxelles in Belgium, and Taiwanese biopharma company PharmaEssentia.

6 Items
2026-08-09
Ransomware Watch · Aug 9, 2026

RansomLook logged 30 victim disclosures across 7 groups in the past 36 hours; qilin was the most active (8), while leakeddata disclosed a concentrated batch of 11 US law firm victims.

2026-07-31
Ransomware Watch · Jul 31, 2026

⚠️ Data-source note: the RansomLook Recent Posts API was unreachable this run (network/provenance restrictions). Data on this page comes from secondary tracking sources and news reporting, not a structured API pull. Figures are approximate.

2026-07-30
Ransomware Watch · Jul 30, 2026

⚠️ Data-source note: the RansomLook API / RSS was unreachable from the execution sandbox this round (restricted network egress). The following is a compilation of recent representative activity based on public intelligence reporting, not live per-post RansomLook data. Watchlist hits are marked with ⭐.

2026-07-29
Ransomware Watch · Jul 29, 2026

⚠️ Data note: this run could reach neither the RansomLook API (`/api/posts?days=1`) nor the RSS fallback from the execution environment (sandbox network restrictions + web_fetch provenance gate). The items below are compiled from public reporting, not a structured RansomLook pull; the victim list is incomplete and covers only representative victims named on or around the day.

2026-07-28
Ransomware Watch · Jul 28, 2026

Source: RansomLook `api/posts?days=1`. ⚠️ The latest post timestamps returned by the API this run fall on 2026-07-23~24, suggesting source-side lag; coverage is not strictly the past 24 hours — for reference only.

2026-07-27
Ransomware Watch · Jul 27, 2026

⚠️ Collection note: direct access to the RansomLook API (`/api/posts?days=1`) and its RSS feed was blocked by network policy inside the sandbox (empty responses), so this edition cross-checks recent disclosures via web search instead. The data is "representative of the week" rather than a strict 24h full set, and victim counts are omitted.

2026-07-26
Ransomware Watch · Jul 26, 2026

⚠️ Data source note: both the RansomLook API (`/api/posts?days=1`) and the RSS fallback were blocked by the sandbox's network egress controls (HTTP 000). This page is an **indicative snapshot compiled from web search**, not RansomLook's complete victim set for the day; victim counts and "discovered" times follow public reporting and may lag or be incomplete.

2026-07-25
Ransomware Watch · Jul 25, 2026

Data source: RansomLook `api/posts?days=1` (window approx. 2026-07-23 17:00 → 07-24 15:00 UTC)

2026-07-23
Ransomware Watch · Jul 23, 2026

Data source: RansomLook `/api/posts?days=1`. The API returns a limited field set (group_name / post_title / discovered) with no sector or geo, so those columns are left blank below.

2026-07-22
Ransomware Watch · Jul 22, 2026

The two entries were discovered less than a second apart (2026-07-19T15:58:56 / :57), the classic signature of a batch upload to a leak site.

2026-07-21
Ransomware Watch · Jul 21, 2026

Data source: RansomLook `api/posts?days=1` (the returned window covers the latest leak-site updates from 2026-07-18 to 07-19). This endpoint returns only group_name / post_title / discovered, so each victim's sector and geo are manual inferences.

2026-07-20
Ransomware Watch · Jul 20, 2026

⚠️ qilin hitting **City Ambulance Service** deserves attention: emergency medical services is an extremely availability-sensitive sector, and qilin has long been on the watchlist (~1,496 cumulative leak-site victims over the past 12 months, roughly 16% market share — see [Infosecurity](https://www.infosecurity-magazine.com/news/qilin-dominates-ransomware-market/)).

Next →