Ransomware Watch · Jun 2, 2026
Time window: past 24 hours (2026-06-01 → 2026-06-02)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (cowork-egress-blocked); this edition is a second-hand WebSearch aggregation cross-checked against quarterly reports. Per-victim accuracy cannot be guaranteed — treat as trend reference only.
Overview
- Estimated total new posts: ~30–40(public aggregate-source basis)
- Active leak sites involved: ~90
- Watchlist hits: estimated 6–10(mainly Qilin × healthcare, Akira × manufacturing)
Watchlist hits (read first)
| Group | Sector | Hit | Description |
|---|---|---|---|
| Qilin | healthcare / legal | group:qilin + sector:healthcare | Firmly #1 for several consecutive quarters; healthcare/legal remains high-frequency |
| Akira | manufacturing | group:akira + sector:manufacturing | Manufacturing-focused targeting, about 34% of IR cases |
| The Gentlemen affiliates | mixed | sector:manufacturing | The GPO-as-deployment playbook continues |
⚠️ Because RansomLook is unreachable, no per-victim domain-level detail can be given this cycle. What follows are aggregate trends, not a precise single-day victim list.
All new posts (aggregate trend, not a precise list)
| Group | Status | Notes |
|---|---|---|
| Qilin | Most active | Multiple new entries in healthcare/legal; 697 cumulative victims in H2 2025, 5x year over year |
| Akira | Highly active | Mostly manufacturing; roughly $244M in cumulative proceeds |
| DragonForce / Devman | Active | Announced a "cartel" restructuring, giving affiliates an 80% profit share |
| The Gentlemen | Active | Affiliate cohort keeps producing across mixed sectors |
| Sinobi / NightSpire / Inc / Play | Moderate | Routine cadence |
Anomalies / trend notes
- Payment rate at an all-time low of 28%(Coveware basis, declining for several quarters) — even as claimed attack volume rises, the share of victims willing to pay keeps falling.
- DragonForce "cartel" restructuring: an 80% affiliate share plus customizable encryptors and provided infrastructure, aimed at expanding the affiliate base; victim volume may rise as a result.
- Qilin's dominance is unchanged: 338 victims in Q1 2026 alone, holding #1 for a third quarter.
- Quarterly picture: Qilin / Akira / The Gentlemen and the other leading groupscontinue to account for the bulk of 2026 victims.
This cycle's ransomware data is in degraded mode (WebSearch aggregation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml