Ransomware Watch · May 24, 2026
Time window: 2026-05-23 → 2026-05-24 (including the tail end of late 5/22)
Data sources: RansomLook recent posts + ransomware.live + public reporting
⚠️ Note: direct RansomLook API pulls failed due to egress restrictions; this issue is assembled from second-hand sources aggregated via WebSearch and full coverage is not guaranteed.
Overview
- New posts (known): ~20+ (limited to what is publicly searchable; actual DLS posting velocity is higher — see the Q1 ReliaQuest +22% YoY trend)
- Groups involved: 8+ (ShinyHunters / Titan / Qilin / Akira / Inc Ransom / Play / Clop / The Gentlemen, etc.)
- Watchlist hits: 4 (education, financial, shipping, healthcare-adjacent)
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Multi-group | University of Valencia | Education | ES | sector:education | ransomlook recent |
| Multi-group | Bank Negara Indonesia | Financial | ID | sector:financial, sector:banking | ransomware.live |
| Multi-group | G. Theodor Freese GmbH | Shipping / Maritime | DE | sector:shipping, sector:logistics | ransomware.live |
| Multi-group | Alkaloid AD Skopje | Pharmaceutical (healthcare-adjacent) | MK | sector:medical (loose match) | ransomware.live |
All New Posts (aggregated)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| ShinyHunters | Charter Communications, Inc. | Telecom | US | 2026-05-23 01:50 | ransomlook recent |
| ShinyHunters | Baker Distributing Company | HVAC distribution | US | 2026-05-23 01:50 | ransomlook recent |
| Titan | (9 posts, mid-sized) | Mixed | Mixed | 2026-05-23 | ransomlook recent |
| Multi-group | University of Valencia ⭐ | Education | ES | 2026-05-23 14:49 | ransomlook recent |
| Multi-group | Mopas Online Supermarket | Retail | — | 2026-05-23 11:48 | ransomlook recent |
| Multi-group | Mecanizados y Montajes Aeronáuticos | Aerospace manufacturing | ES | 2026-05-23 16:52 | ransomlook recent |
| Multi-group | A-Sonic Logistics | Logistics | — | 2026-05-22 | ransomware.live |
| Multi-group | Alkaloid AD Skopje ⭐ | Pharmaceutical | MK | 2026-05-22 | ransomware.live |
| Multi-group | Bank Negara Indonesia ⭐ | Banking | ID | 2026-05-22 | ransomware.live |
| Multi-group | ConsulTIC | IT consulting | — | 2026-05-22 | ransomware.live |
Anomalies / Trend Notes
This week's most active (by DLS post volume)
- ShinyHunters— Charter Communications is a highly conspicuous target (a major US telecom operator); ShinyHunters keeps posting on the Trinity of Chaos DLS
- Titan— 9 posts on 5/23 alone; consistently high-frequency over the past two weeks
- Akira / Qilin— the "duopoly" position held since Q1 continues (M-Trends 2026 tracks Akira as REDBIKE and Qilin as AGENDA)
- The Gentlemen— despite itself being leaked on 5/5, its affiliates keep posting— corroborating that its 90/10 split retains affiliates well
- Inc Ransom / Clop / Play / Nightspire / DragonForce / Sinobi— the second tier keeps up steady output
Newly appeared groups
- No entirely new actor observed coming online in the 5/23–5/24 window
Unusual concentration
- Spanish manufacturing: back-to-back Spanish victims on 5/23 (University of Valencia in education + Mecanizados y Montajes Aeronáuticos in aerospace manufacturing + Cablematic Dos Mil SLU in industrial equipment on 5/22) — worth watching; an affiliate may be working the Spanish manufacturing / education circles
- Shipping + logistics: G. Theodor Freese GmbH (German maritime) + A-Sonic Logistics both listed on 5/22 — consistent with M-Trends 2026 on RaaS normalizing "recovery denial" (deliberately hitting backups, identity, and virtualization management planes before encrypting)
Check Point 5/22 "Thus Spoke The Gentlemen" analysis (must-read)
See the "Threat Intelligence" section of the main brief. Key points:
- The Gentlemen's industrialized flow: victim VPN access → C2 push → EDR neutralization → encryption
- An aggressive 90/10 split to poach affiliates
- Roles:
zeta88/hastalamuerte(admin),Kunder,qbit,JeLLy,Protagor,Bl0ck,Wick,quant,donpakto,mAst3r
Data Collection Statement
- Direct RansomLook API pulls failed due to egress restrictions
- Data is assembled via WebSearch from multiple second-hand sources (RansomLook public recent-page summaries, ransomware.live, media reporting)
- Actual DLS posting velocity is higher; this table lists publicly indexable victims. Full structured data requires direct access to the RansomLook APIor the ransomware.live API
- Remediation suggestion: add
www.ransomlook.ioandapi.ransomware.liveto the egress allowlist