Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-21
Ransomware·2026-05-21

Ransomware Watch · May 21, 2026

Data from RansomLook public data cross-checked against industry news. The API was not reachable directly in WebSearch mode; this issue aggregates public leak-post signals from the past 24h.

Overview

  • New post signals (past 24h, cross-source sample): estimated 30–45 (industry aggregation)
  • Most active groups in 24h (by cadence): LockBit · INC_Ransom · Akira · Qilin
  • Watchlist hits: see table below

Watchlist Hits (Priority)

GroupVictimSectorGeoHitLink
AkiraBarclay Damonlegal / professional servicesUSgroup:akiraRansomLook Akira
AkiraActon Electricalmanufacturing / utilities—group:akira, sector:utilities, sector:manufacturingSame as above
AkiraTSG Enterprises——group:akiraSame as above
QilinHamer Childs——group:qilinRedPacket mirror
LockBit(5+ new posts, 24h)mixedmixedgroup:lockbitRansomLook recent
INC_Ransom(multiple)mixedmixed—Same as above
The Gentlemen(continuing expansion)mixedmixed—DFIR Report flash

All New Posts

Since WebSearch mode cannot connect directly to the RansomLook API, see the full 24h list at:

  • RansomLook recent
  • Ransomware.live recentcyberattacks

Additional victims cross-verified across sources (5/19–5/20):

  • Novanew post: RADWAG (instrument / weighing-equipment manufacturing, Poland)
  • Lamashtunew post: ROTH-TECHNIK AUSTRIA (mechanical industry, Austria)

Anomalies / Trend Notes

  • The Gentlemen RaaS accelerating its expansion: on 5/11 the DFIR Report published the EtherRAT → TukTuk → GoTo Resolve → GPO deployment attack chain; the group claims 320 victims, most occurring in 2026. Its locker modules cover Windows / Linux / NAS / BSD / ESXi. Worth long-term tracking.
  • Qilin and LockBit reconsolidated their leading positions in Q1 2026(Industrial Cyber Q1 2026 report). Qilin continued posting new victims at a daily cadence this week.
  • DBIR 2026 corroboration: ransomware featured in 48% of cases (44% the year before), but the median ransom fell below $140k — the footprint is still expanding while the average ransom declines, possibly tied to a "mass-produced small targets" strategy.
  • Common thread across new attack chains: EtherRAT/TukTuk + legitimate RMM (GoTo Resolve) + GPO scheduled-task domain-wide delivery — the archetypal intra-enterprise attack pattern observed this month; worth building detection coverage along the RMM/GPO dimension.

Sources

  • RansomLook recent posts
  • The Hacker News — Akira leaks unprecedented one-day volume
  • Industrial Cyber Q1 2026 Ransomware Report
  • Check Point Q1 2026 Ransomware Report
  • DFIR Report — The Gentlemen via TukTuk / EtherRAT
  • Verizon 2026 DBIR
Next →
Ransomware Watch · May 22, 2026