Ransomware Watch · Jun 4, 2026
Time window: past 24 hours (2026-06-03 → 2026-06-04)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (host not on the network allow list, same as yesterday); this edition is a WebSearch aggregation (ransomware.live / BreachSense / vendor tracking) cross-checked against confirmed 6/3 victim disclosures. Per-victim accuracy cannot be fully guaranteed, but the single-day victims below are multi-source confirmed.
Overview
- Estimated total new posts: ~30–40(public aggregate-source basis)
- Active leak sites involved: ~90
- Confirmed single-day victims: 8(multi-source confirmed)
- Watchlist hits: 6(Qilin × 4, Akira × financial, INC × manufacturing; hits across healthcare/manufacturing/financial)
Watchlist hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Singing River Health System | healthcare / hospital | US | group:qilin + sector:healthcare | ransomware.live |
| Qilin | MarketJoy | sales / marketing | US | group:qilin + geo:us | ransomware.live |
| Qilin | JNP ENG | engineering | — | group:qilin | ransomware.live |
| Qilin | Eat Salad | food / retail | — | group:qilin | ransomware.live |
| Akira | Hal Otey Financial | financial | US | group:akira + sector:financial | ransomware.live |
| INC (incransom) | Öztuğ Otomotiv | manufacturing / automotive | TR | group:inc + sector:manufacturing | ransomware.live |
ℹ️ Note: in the table above, Singing River Health System is attributed to both Qilin and Anubis across different aggregate sources (possibly multiple claims or a repeat leak). It is tagged on the healthcare/hospital hit; attribution needs confirmation via direct leak-site access.
All new posts (confirmed single-day victims)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | Singing River Health System | healthcare / hospital | US | 2026-06-03 | link |
| Qilin | MarketJoy | sales / marketing | US | 2026-06-03 | link |
| Qilin | JNP ENG | engineering | — | 2026-06-03 | link |
| Qilin | Eat Salad | food / retail | — | 2026-06-03 | link |
| Akira | Hal Otey Financial | financial | US | 2026-06-03 | link |
| INC_RANSOM | Öztuğ Otomotiv | manufacturing / automotive | TR | 2026-06-03 | link |
| Genesis | Family Medical Associates of Raleigh | healthcare | US | 2026-06-03 | link |
| DragonForce | Copamex | manufacturing / paper | MX | 2026-06-03 | link |
| Apt73 (Bashe) | smarty.arpinet.am | telecom / ISP | AM | 2026-06-03 | link |
⚠️ Because RansomLook is unreachable, the table above lists single-day victims confirmed across multiple sources (ransomware.live / BreachSense) and may be incomplete; a full DLS census requires direct RansomLook access to state precisely.
Anomalies / trend notes
- Qilin posted ~4 victims in one day across sectors (healthcare + marketing + engineering + food retail): continuing its structural multi-quarter lead at #1; healthcare (Singing River Health System, a well-known US hospital system) remains a high-value target for the group.
- Healthcare remains high-frequency: Qilin (Singing River) and Genesis (Family Medical Associates of Raleigh) both registered healthcare hits the same day; the healthcare/hospital direction needs continued attention.
- Akira hit financial: Hal Otey Financial registers on the financial-sector watchlist, consistent with Akira's profile of over $150M in 2025 proceeds and targeting high-value entities.
- DragonForce hit Mexican manufacturing (Copamex, paper): manufacturing is a priority watchlist sector, and the post-"cartel" geographic expansion (toward Latin America) continues.
- INC hit Turkish automotive manufacturing (Öztuğ Otomotiv): a manufacturing hit on the Europe/Middle East supply-chain axis.
- The quarterly picture is unchanged: Qilin has held #1 for several quarters (>1,700 tracked victims), Akira is second, and the ransom payment rate is near its all-time low of ~28%.
This cycle's ransomware data is in degraded mode (WebSearch aggregation plus single-day confirmation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml