Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-23
Ransomware·2026-05-23

Ransomware Watch · May 23, 2026

Window: 2026-05-21 → 2026-05-23 (early) · Sources: WebSearch + Ransomware.live + RansomLook public reporting
Note: the RansomLook API and website are blocked at the workspace egress, so JSON could not be pulled directly; this issue is a public-reporting cross-checked edition.

Overview

  • Total new posts (covering 5/21 + early 5/22): ~12 newly published victims
  • Groups involved: 4(Qilin, PEAR, TheGentlemen, LockBit) + 5+ peripherally active groups (Akira, Inc Ransom, Clop, Play, Nightspire, DragonForce, Sinobi)
  • Watchlist hits: 3
    • LockBit × Shottermill Junior School (group:lockbit+ sector:education)
    • PEAR × Exchange Group (sector:financial)
    • Qilin (group:qilin, multiple victims)

Watchlist Hits (Priority)

GroupVictimSectorGeoHitLink
LockBitShottermill Junior SchoolEducation (K-12)UKgroup:lockbit + sector:educationRansomware.live
PEARExchange GroupFinancial ServicesCanadasector:financial + sector:bankingRansomware.live
QilinCJ ArchitectsArchitectureUSgroup:qilinRansomware.live
QilinCZ CollectionsFashion / ApparelNew York, USgroup:qilinRansomware.live

All New Posts

GroupVictimSectorGeoDiscoveredLink
QilinCJ ArchitectsArchitectureUS2026-05-21Ransomware.live
QilinCZ CollectionsFashion / ApparelNew York, US2026-05-21Ransomware.live
PEARExchange GroupFinancial ServicesCanada2026-05-21Ransomware.live
PEARFana JewelryLuxury / JewelryNew York, US2026-05-21Ransomware.live
PEARProFarm GroupAgriculture / Agri-techCalifornia, US2026-05-21Ransomware.live
TheGentlemenGrupo PasquelConstruction / Hardware RetailMexico2026-05-21Ransomware.live
LockBit (5.0)Shottermill Junior SchoolEducation (K-12)UK2026-05-21Ransomware.live
Akira(multiple)mixedglobal2026-05-21 → 5/22RansomLook
Inc Ransom(multiple)mixedglobal2026-05-21 → 5/22RansomLook
Clop(multiple)mixedglobal2026-05-21 → 5/22RansomLook
Play(multiple)mixedglobal

Anomalies / Trend Notes

  • PEAR: unusually high posting density today (three independent victims across industries). Watch whether a one-off "bulk leak" is being staged for publicity.
  • TheGentlemen: firmly in RansomLook's top-3 most active this week.
  • LockBit 5.0 variant resurgence: despite repeated law-enforcement takedowns, the family remains active through its 5.0 variant, hitting "soft targets" including a junior school; watchlist hit on sector:education— UK primary-education IT should liaise with the NCSC.
  • Qilin / TheGentlemen / Akiracontinue to dominate the weekly DLS posting charts — consistent with the ReliaQuest Q1 2026 report trend (DLS posts +22% YoY).
  • PROMPTFLUX / PROMPTSTEALand other "runtime LLM-calling" malware have not yet been directly linked to known ransomware families, but cross-pollination of TTPs is an inevitable trend— next quarter, watch for LLM-rewritten ransomware loaders.

Reference Links

  • Ransomware.live — daily map
  • Ransomware.live — Summary page
  • RansomLook main site
  • RansomLook — Recent posts
  • Check Point — Q1 2026 ransomware state
  • Securelist — 2026 ransomware trends
  • SecurityBrief — leak sites +22%
← Prev
Ransomware Watch · May 22, 2026
Next →
Ransomware Watch · May 24, 2026
2026-05-21 → 5/22
RansomLook
DragonForce(multiple)mixedglobal2026-05-21 → 5/22RansomLook