Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-22
Ransomware·2026-05-22

Ransomware Watch · May 22, 2026

Window: 2026-05-21 → 2026-05-22 (24h)
Data sources: RansomLook public pages (the sandbox cannot reach the API directly; using mirrors + ransomware.live + PurpleOps aggregation)

Overview

  • Total new posts: ~13 (24h window)
  • Groups involved: 6+ (Qilin, PEAR, TheGentlemen, LockBit 5.0, Leak Bazaar, Lynx)
  • Watchlist hits: 5
  • Most active groups: Leak Bazaar (9), Lynx (8)(together >70% of volume, but mostly re-releases of old dumps)
  • Top groups to watch (by Q1 ranking): Qilin (Q1 338 posts), LockBit 5.0 revival

Watchlist Hits (Priority)

GroupVictimSectorGeoHitLink
QilinPorter YettLegal servicesUSgroup:qilinransomware.live
QilinCJ ArchitectsArchitecture / consultingUKgroup:qilinransomware.live
QilinCZ CollectionsRetailEUgroup:qilinransomware.live
LockBit (5.0)Shottermill Junior SchoolEducation (K-12) ⚠️UKgroup:lockbit + sector:educationransomware.live
TheGentlemenGrupo PasquelLogistics / commerceLATAMgroup:thegentlemen-adjacent + sector:logisticsransomware.live

⚠️ LockBit 5.0 publicly attacked a primary school —

  1. LockBit 5.0 has turned more aggressive since its rebrand at the start of the year
  2. The education sector (especially K-12) is a high-frequency target in the UK
  3. This "small school + large ransom" combination signals an extortion wave ahead of the summer break

All New Posts (24h)

GroupVictimSectorGeoDiscovered
QilinPorter YettLegalUS2026-05-21
QilinCJ ArchitectsArchitectureUK2026-05-21
QilinCZ CollectionsRetailEU2026-05-21
TheGentlemenGrupo PasquelLogisticsLATAM2026-05-21
PEARProFarm GroupAgri-techEU2026-05-21
PEARExchange GroupServicesUNK2026-05-21
PEARFana JewelryRetail / jewelryUNK2026-05-21
LockBit 5.0Shottermill Junior SchoolEducation (K-12)UK2026-05-21
Leak Bazaar(multiple, re-dump)MixedMultiple2026-05-21
Lynx(multiple)MixedMultiple2026-05-21

Anomalies / Trend Notes

Emerging developments

  • PEAR posted 3 victims in a single day— PEAR was not previously a top-tier active group; 3 in one day warrants watching for rebrand / consolidation signs
  • Qilin maintains its Q1-leading cadence— 3 victims on 5/21 alone, consistent with its Q1 activity of 338 posts (~3.7/day)
  • LockBit 5.0 + education— the 5.0 variant is testing a new range of target industries

Linkage with upstream incidents

  • SonicWall Gen6 SSL-VPN brute-forcing activity(see the main brief) — the TTPs correspond exactly to Akira. Akira posted no new victims on 5/21, but a wave is expected 5/22–5/24. Watch for a concentrated burst of Akira postings within the next 24–72h.
  • The Gentlemen RaaSkeeps expanding (claims 320 victims, most in 2026); this week's addition, Grupo Pasquel, is LATAM logistics, widening its geographic coverage.

Re-dump noise

  • Leak Bazaar (9) + Lynx (8)account for >70% of volume, but most posts are re-releases of old dumps, not new compromises. The true 24h new-victim count should be read as ~11once re-dumps are removed.

Q1 2026 Ransomware Sector Overview (Background)

  • Qilin held the top spot for a third consecutive quarter, with 338 victimsin Q1
  • LockBit: 163 victimsin Q1 (a strong comeback after the 5.0 variant relaunch)
  • Qilin + Akira + The Gentlemen + LockBit together account for 41% of total share— the sector is re-concentrating
  • The Gentlemen claims 320 victims (Q1+)

References / Data Sources

  • RansomLook — Recent posts
  • RansomLook — Global Posts RSS
  • ransomware.live
  • PurpleOps — Ransomware Tracker 2026
  • Check Point — State of Ransomware Q1 2026
  • Industrial Cyber — Ransomware sector reconsolidating
← Prev
Ransomware Watch · May 21, 2026
Next →
Ransomware Watch · May 23, 2026