Ransomware Watch · May 23, 2026
Window: 2026-05-21 → 2026-05-23 (early) · Sources: WebSearch + Ransomware.live + RansomLook public reporting
Note: the RansomLook API and website are blocked at the workspace egress, so JSON could not be pulled directly; this issue is a public-reporting cross-checked edition.
Overview
- Total new posts (covering 5/21 + early 5/22): ~12 newly published victims
- Groups involved: 4(Qilin, PEAR, TheGentlemen, LockBit) + 5+ peripherally active groups (Akira, Inc Ransom, Clop, Play, Nightspire, DragonForce, Sinobi)
- Watchlist hits: 3
- LockBit × Shottermill Junior School (
group:lockbit+sector:education) - PEAR × Exchange Group (
sector:financial) - Qilin (
group:qilin, multiple victims)
- LockBit × Shottermill Junior School (
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| LockBit | Shottermill Junior School | Education (K-12) | UK | group:lockbit + sector:education | Ransomware.live |
| PEAR | Exchange Group | Financial Services | Canada | sector:financial + sector:banking | Ransomware.live |
| Qilin | CJ Architects | Architecture | US | group:qilin | Ransomware.live |
| Qilin | CZ Collections | Fashion / Apparel | New York, US | group:qilin | Ransomware.live |
All New Posts
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | CJ Architects | Architecture | US | 2026-05-21 | Ransomware.live |
| Qilin | CZ Collections | Fashion / Apparel | New York, US | 2026-05-21 | Ransomware.live |
| PEAR | Exchange Group | Financial Services | Canada | 2026-05-21 | Ransomware.live |
| PEAR | Fana Jewelry | Luxury / Jewelry | New York, US | 2026-05-21 | Ransomware.live |
| PEAR | ProFarm Group | Agriculture / Agri-tech | California, US | 2026-05-21 | Ransomware.live |
| TheGentlemen | Grupo Pasquel | Construction / Hardware Retail | Mexico | 2026-05-21 | Ransomware.live |
| LockBit (5.0) | Shottermill Junior School | Education (K-12) | UK | 2026-05-21 | Ransomware.live |
| Akira | (multiple) | mixed | global | 2026-05-21 → 5/22 | RansomLook |
| Inc Ransom | (multiple) | mixed | global | 2026-05-21 → 5/22 | RansomLook |
| Clop | (multiple) | mixed | global | 2026-05-21 → 5/22 | RansomLook |
| Play | (multiple) | mixed | global |
Anomalies / Trend Notes
- PEAR: unusually high posting density today (three independent victims across industries). Watch whether a one-off "bulk leak" is being staged for publicity.
- TheGentlemen: firmly in RansomLook's top-3 most active this week.
- LockBit 5.0 variant resurgence: despite repeated law-enforcement takedowns, the family remains active through its 5.0 variant, hitting "soft targets" including a junior school; watchlist hit on
sector:education— UK primary-education IT should liaise with the NCSC. - Qilin / TheGentlemen / Akiracontinue to dominate the weekly DLS posting charts — consistent with the ReliaQuest Q1 2026 report trend (DLS posts +22% YoY).
- PROMPTFLUX / PROMPTSTEALand other "runtime LLM-calling" malware have not yet been directly linked to known ransomware families, but cross-pollination of TTPs is an inevitable trend— next quarter, watch for LLM-rewritten ransomware loaders.