Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-02
Ransomware·2026-06-02

Ransomware Watch · Jun 2, 2026

Time window: past 24 hours (2026-06-01 → 2026-06-02)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (cowork-egress-blocked); this edition is a second-hand WebSearch aggregation cross-checked against quarterly reports. Per-victim accuracy cannot be guaranteed — treat as trend reference only.

Overview

  • Estimated total new posts: ~30–40(public aggregate-source basis)
  • Active leak sites involved: ~90
  • Watchlist hits: estimated 6–10(mainly Qilin × healthcare, Akira × manufacturing)

Watchlist hits (read first)

GroupSectorHitDescription
Qilinhealthcare / legalgroup:qilin + sector:healthcareFirmly #1 for several consecutive quarters; healthcare/legal remains high-frequency
Akiramanufacturinggroup:akira + sector:manufacturingManufacturing-focused targeting, about 34% of IR cases
The Gentlemen affiliatesmixedsector:manufacturingThe GPO-as-deployment playbook continues

⚠️ Because RansomLook is unreachable, no per-victim domain-level detail can be given this cycle. What follows are aggregate trends, not a precise single-day victim list.

All new posts (aggregate trend, not a precise list)

GroupStatusNotes
QilinMost activeMultiple new entries in healthcare/legal; 697 cumulative victims in H2 2025, 5x year over year
AkiraHighly activeMostly manufacturing; roughly $244M in cumulative proceeds
DragonForce / DevmanActiveAnnounced a "cartel" restructuring, giving affiliates an 80% profit share
The GentlemenActiveAffiliate cohort keeps producing across mixed sectors
Sinobi / NightSpire / Inc / PlayModerateRoutine cadence

Anomalies / trend notes

  • Payment rate at an all-time low of 28%(Coveware basis, declining for several quarters) — even as claimed attack volume rises, the share of victims willing to pay keeps falling.
  • DragonForce "cartel" restructuring: an 80% affiliate share plus customizable encryptors and provided infrastructure, aimed at expanding the affiliate base; victim volume may rise as a result.
  • Qilin's dominance is unchanged: 338 victims in Q1 2026 alone, holding #1 for a third quarter.
  • Quarterly picture: Qilin / Akira / The Gentlemen and the other leading groupscontinue to account for the bulk of 2026 victims.

This cycle's ransomware data is in degraded mode (WebSearch aggregation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 1, 2026
Next →
Ransomware Watch · Jun 3, 2026