Ransomware Watch · May 22, 2026
Window: 2026-05-21 → 2026-05-22 (24h)
Data sources: RansomLook public pages (the sandbox cannot reach the API directly; using mirrors + ransomware.live + PurpleOps aggregation)
Overview
- Total new posts: ~13 (24h window)
- Groups involved: 6+ (Qilin, PEAR, TheGentlemen, LockBit 5.0, Leak Bazaar, Lynx)
- Watchlist hits: 5
- Most active groups: Leak Bazaar (9), Lynx (8)(together >70% of volume, but mostly re-releases of old dumps)
- Top groups to watch (by Q1 ranking): Qilin (Q1 338 posts), LockBit 5.0 revival
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Porter Yett | Legal services | US | group:qilin | ransomware.live |
| Qilin | CJ Architects | Architecture / consulting | UK | group:qilin | ransomware.live |
| Qilin | CZ Collections | Retail | EU | group:qilin | ransomware.live |
| LockBit (5.0) | Shottermill Junior School | Education (K-12) ⚠️ | UK | group:lockbit + sector:education | ransomware.live |
| TheGentlemen | Grupo Pasquel | Logistics / commerce | LATAM | group:thegentlemen-adjacent + sector:logistics | ransomware.live |
⚠️ LockBit 5.0 publicly attacked a primary school —
- LockBit 5.0 has turned more aggressive since its rebrand at the start of the year
- The education sector (especially K-12) is a high-frequency target in the UK
- This "small school + large ransom" combination signals an extortion wave ahead of the summer break
All New Posts (24h)
| Group | Victim | Sector | Geo | Discovered |
|---|---|---|---|---|
| Qilin | Porter Yett | Legal | US | 2026-05-21 |
| Qilin | CJ Architects | Architecture | UK | 2026-05-21 |
| Qilin | CZ Collections | Retail | EU | 2026-05-21 |
| TheGentlemen | Grupo Pasquel | Logistics | LATAM | 2026-05-21 |
| PEAR | ProFarm Group | Agri-tech | EU | 2026-05-21 |
| PEAR | Exchange Group | Services | UNK | 2026-05-21 |
| PEAR | Fana Jewelry | Retail / jewelry | UNK | 2026-05-21 |
| LockBit 5.0 | Shottermill Junior School | Education (K-12) | UK | 2026-05-21 |
| Leak Bazaar | (multiple, re-dump) | Mixed | Multiple | 2026-05-21 |
| Lynx | (multiple) | Mixed | Multiple | 2026-05-21 |
Anomalies / Trend Notes
Emerging developments
- PEAR posted 3 victims in a single day— PEAR was not previously a top-tier active group; 3 in one day warrants watching for rebrand / consolidation signs
- Qilin maintains its Q1-leading cadence— 3 victims on 5/21 alone, consistent with its Q1 activity of 338 posts (~3.7/day)
- LockBit 5.0 + education— the 5.0 variant is testing a new range of target industries
Linkage with upstream incidents
- SonicWall Gen6 SSL-VPN brute-forcing activity(see the main brief) — the TTPs correspond exactly to Akira. Akira posted no new victims on 5/21, but a wave is expected 5/22–5/24. Watch for a concentrated burst of Akira postings within the next 24–72h.
- The Gentlemen RaaSkeeps expanding (claims 320 victims, most in 2026); this week's addition, Grupo Pasquel, is LATAM logistics, widening its geographic coverage.
Re-dump noise
- Leak Bazaar (9) + Lynx (8)account for >70% of volume, but most posts are re-releases of old dumps, not new compromises. The true 24h new-victim count should be read as ~11once re-dumps are removed.
Q1 2026 Ransomware Sector Overview (Background)
- Qilin held the top spot for a third consecutive quarter, with 338 victimsin Q1
- LockBit: 163 victimsin Q1 (a strong comeback after the 5.0 variant relaunch)
- Qilin + Akira + The Gentlemen + LockBit together account for 41% of total share— the sector is re-concentrating
- The Gentlemen claims 320 victims (Q1+)