Ransomware Watch · May 21, 2026
Data from RansomLook public data cross-checked against industry news. The API was not reachable directly in WebSearch mode; this issue aggregates public leak-post signals from the past 24h.
Overview
- New post signals (past 24h, cross-source sample): estimated 30–45 (industry aggregation)
- Most active groups in 24h (by cadence): LockBit · INC_Ransom · Akira · Qilin
- Watchlist hits: see table below
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Akira | Barclay Damon | legal / professional services | US | group:akira | RansomLook Akira |
| Akira | Acton Electrical | manufacturing / utilities | — | group:akira, sector:utilities, sector:manufacturing | Same as above |
| Akira | TSG Enterprises | — | — | group:akira | Same as above |
| Qilin | Hamer Childs | — | — | group:qilin | RedPacket mirror |
| LockBit | (5+ new posts, 24h) | mixed | mixed | group:lockbit | RansomLook recent |
| INC_Ransom | (multiple) | mixed | mixed | — | Same as above |
| The Gentlemen | (continuing expansion) | mixed | mixed | — | DFIR Report flash |
All New Posts
Since WebSearch mode cannot connect directly to the RansomLook API, see the full 24h list at:
Additional victims cross-verified across sources (5/19–5/20):
- Novanew post: RADWAG (instrument / weighing-equipment manufacturing, Poland)
- Lamashtunew post: ROTH-TECHNIK AUSTRIA (mechanical industry, Austria)
Anomalies / Trend Notes
- The Gentlemen RaaS accelerating its expansion: on 5/11 the DFIR Report published the EtherRAT → TukTuk → GoTo Resolve → GPO deployment attack chain; the group claims 320 victims, most occurring in 2026. Its locker modules cover Windows / Linux / NAS / BSD / ESXi. Worth long-term tracking.
- Qilin and LockBit reconsolidated their leading positions in Q1 2026(Industrial Cyber Q1 2026 report). Qilin continued posting new victims at a daily cadence this week.
- DBIR 2026 corroboration: ransomware featured in 48% of cases (44% the year before), but the median ransom fell below $140k — the footprint is still expanding while the average ransom declines, possibly tied to a "mass-produced small targets" strategy.
- Common thread across new attack chains: EtherRAT/TukTuk + legitimate RMM (GoTo Resolve) + GPO scheduled-task domain-wide delivery — the archetypal intra-enterprise attack pattern observed this month; worth building detection coverage along the RMM/GPO dimension.