Ransomware Watch · Jun 1, 2026
Time window: 2026-05-31 → 2026-06-01
Data sources: WebSearch aggregation (ransomware.live / breachsense / SharkStriker / The Record / Coveware-cited and other public tracking sources)
⚠️ Note: RansomLook API + RSS again failed this cycle due to the egress allowlist (WebFetch domain filtering); this edition relies on aggregated second-hand data.
Overview
- New posts (24h aggregate): ~30-40
- Active DLS sites: ~90 (flat)
- Groups involved: 5+ (primarily Qilin / Akira / DragonForce(Devman) / The Gentlemen / Sinobi, plus second-tier Inc Ransom / Nova / NightSpire / Play)
- Watchlist hits: ≥ 3 by rough filtering on victims visible in the aggregate (healthcare / manufacturing)
- Macro signal: the ransom payment rate has fallen to 28%, an all-time low(Coveware basis), despite claims of rising attack volume
Watchlist hits (matched on known victims/sectors)
| Group | Victim/Target | Sector | Geo | Hit | Note |
|---|---|---|---|---|---|
| Qilin | (healthcare/legal targeting continues; per-victim list unavailable this cycle) | healthcare / legal | (likely US) | group:qilin, sector:healthcare | Qilin keeps the lead, focused on healthcare plus backup destruction |
| Akira | (manufacturing targeting) | manufacturing | global | group:akira, sector:manufacturing | Akira's manufacturing activity continues |
| The Gentlemen | (mixed sectors; GPO deployment TTP continues) | mixed / industrial | EU/US | group:thegentlemen | The DFIR Report 5/11 EtherRAT+TukTuk→GPO chain is public |
A complete per-victim table remains unavailable this cycle (egress restriction). It can be backfilled once RansomLook's two endpoints are restored.
All new posts (aggregate view, batch deltas observed at group level)
| Group | New count (24h estimate) | Note |
|---|---|---|
| Qilin | 4-6 | Still first on cumulative volume; heavy healthcare/legal share |
| Akira | 3-5 | Mostly manufacturing |
| DragonForce / Devman | 2-4 | Small and mid-sized European businesses continue |
| The Gentlemen affiliates | 2-3 | GPO deployment TTP is now standardized |
| Sinobi | 1-3 | Steady second-tier output |
| Inc Ransom / Nova / NightSpire / Play | 1-2 each | Second tier continues |
Anomalies / trend notes
New observations in the last 24 hours
- Payment rate at a record low (28%)— the most important macro signal this cycle. The share of victims who pay has now declined for multiple consecutive quarters, indicating that backup/recovery maturity and "do not pay" policies are landing at more organizations. Ransomware groups offset this with higher claimed attack volume and double-extortion pressure, so DLS posting volume has not fallen in step. For defenders this means groups will apply public pressure more aggressively and accelerate their leak cadence.
- Qilin keeps hitting healthcare/legal proportionally— combined with the M-Trends 2026 / Mandiant findings on Qilin (AGENDA) targeting backup infrastructure and identity systems, EDR/IR teams in these two sectors should prioritize checking reachability of the backup control plane.
- Akira's manufacturing focus continues— it overlaps with The Gentlemen affiliates on industrial/manufacturing targets, so OT-adjacent environments warrant attention.
Sector concentration (rough estimate)
- Healthcare / legal: ~30% (Qilin-dominated)
- Manufacturing / industrial: ~25% (Akira + The Gentlemen affiliates)
- Services / logistics / SMBs: ~20% (DragonForce's European targets)
- Other: ~25%
The quarterly picture is unchanged: Qilin / Akira / The Gentlemen / LockBit together account for roughly 40% of all 2026 victims; Qilin alone still exceeds the sum of the bottom 50 groups.
New / resurfaced groups
- Given data-source limits, no clearly new group was observed this cycle.
IR / hunt recommendations
- Qilin / Akira: audit backup infrastructure reachability — who can reach the backup control plane from an ordinary workstation?Recovery denial is now the norm. Against a record-low 28% payment rate, recovery capability is exactly what makes not paying possible.
- The Gentlemen family: pull the DFIR Report 5/11 IOCs plus the Check Point joint-report IOCs, focusing on anomalous GPO creation/modification, scheduled tasks under SYSVOL/NETLOGON, and unusual GoTo Resolve installations.
- DragonForce / Devman: do not let recent EDR alerts from small and mid-sized European businesses get buried in noise.
Data health
- RansomLook API + RSS: blocked by WebFetch domain filtering (egress allowlist not in the provenance set)
- ransomware.live / The Record / SharkStriker: readable indirectly via WebSearch
- Coveware-basis payment-rate data: readable via the Bleeping Computer reprint
Next step: work with the project maintainer to add RansomLook's two endpoints to the WebFetch allowed domains, which would restore per-victim data.