Ransomware Watch · Jun 3, 2026
Time window: past 24 hours (2026-06-02 → 2026-06-03)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (HTTP 000, host not on the network allow list); this edition is a WebSearch aggregation (BreachSense / ransomware.live / vendor tracking) cross-checked against confirmed 6/2 victim disclosures. Per-victim accuracy cannot be fully guaranteed, but the single-day victims below are multi-source confirmed.
Overview
- Estimated total new posts: ~30–40(public aggregate-source basis)
- Active leak sites involved: ~90
- Confirmed single-day victims: 7(multi-source confirmed)
- Watchlist hits: 4(Qilin × healthcare, INC × health/government, Play group, SafePay × logistics)
Watchlist hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Clínica Maitenes | healthcare / medical | CL | group:qilin + sector:healthcare | ransomware.live |
| INC (INC_RANSOM) | Champaign-Urbana Public Health District | public health / government | US | group:inc + sector:healthcare/government | BreachSense |
| Play | Digitall Graphics | media / design | — | group:play | BreachSense |
| Play | Hightower Communications | telecom | — | group:play | BreachSense |
| SafePay | LCNet | logistics / transport | DE | sector:logistics | BreachSense |
ℹ️ On the watchlist,
qilin / play / incare priority groups,healthcare / government / logisticsare priority sectors, andusis a priority geography — all of them registered hits today.
All new posts (confirmed single-day victims)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | Clínica Maitenes | healthcare | CL | 2026-06-02 | link |
| INC_RANSOM | Champaign-Urbana Public Health District | public health / gov | US | 2026-06-02 | link |
| Play | Digitall Graphics | media / design | — | 2026-06-02 | link |
| Play | Hightower Communications | telecom | — | 2026-06-02 | link |
| SafePay | LCNet | logistics / transport | DE | 2026-06-02 | link |
| DragonForce | Synex Group | engineering / construction | LK | 2026-06-02 | link |
| DragonForce | Taos Mountain Casino | hospitality / gaming | US | 2026-06-02 | link |
⚠️ Because RansomLook is unreachable, the table above lists single-day victims confirmed across multiple sources (BreachSense / ransomware.live) and may be incomplete; a full DLS census requires direct RansomLook access to state precisely.
Anomalies / trend notes
- DragonForce posted 2 victims in one day across geographies (Sri Lanka + United States): consistent with the expectation that its "cartel" restructuring would expand the affiliate base and lift victim volume. Worth continued observation.
- Healthcare/public health remains high-frequency: Qilin (Clínica Maitenes) and INC (Champaign-Urbana Public Health District) both registered healthcare/public-health hits on the same day, continuing the structural trend of Qilin's multi-quarter healthcare targeting.
- Play posted 2 victims in one day: routine cadence but still active (media/design + telecom).
- SafePay hit German logistics (LCNet): logistics/transport is a priority watchlist sector, so the European supply-chain direction warrants attention.
- The quarterly picture is unchanged: Qilin has held #1 for several quarters, Akira is second (2025 proceeds over $150M), and the ransom payment rate is near its all-time low of ~28%— even as claimed volume rises, the share of victims willing to pay keeps falling.
This cycle's ransomware data is in degraded mode (WebSearch aggregation plus single-day confirmation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml