Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-04
Ransomware·2026-06-04

Ransomware Watch · Jun 4, 2026

Time window: past 24 hours (2026-06-03 → 2026-06-04)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (host not on the network allow list, same as yesterday); this edition is a WebSearch aggregation (ransomware.live / BreachSense / vendor tracking) cross-checked against confirmed 6/3 victim disclosures. Per-victim accuracy cannot be fully guaranteed, but the single-day victims below are multi-source confirmed.

Overview

  • Estimated total new posts: ~30–40(public aggregate-source basis)
  • Active leak sites involved: ~90
  • Confirmed single-day victims: 8(multi-source confirmed)
  • Watchlist hits: 6(Qilin × 4, Akira × financial, INC × manufacturing; hits across healthcare/manufacturing/financial)

Watchlist hits (read first)

GroupVictimSectorGeoHitLink
QilinSinging River Health Systemhealthcare / hospitalUSgroup:qilin + sector:healthcareransomware.live
QilinMarketJoysales / marketingUSgroup:qilin + geo:usransomware.live
QilinJNP ENGengineering—group:qilinransomware.live
QilinEat Saladfood / retail—group:qilinransomware.live
AkiraHal Otey FinancialfinancialUSgroup:akira + sector:financialransomware.live
INC (incransom)Öztuğ Otomotivmanufacturing / automotiveTRgroup:inc + sector:manufacturingransomware.live

ℹ️ Note: in the table above, Singing River Health System is attributed to both Qilin and Anubis across different aggregate sources (possibly multiple claims or a repeat leak). It is tagged on the healthcare/hospital hit; attribution needs confirmation via direct leak-site access.

All new posts (confirmed single-day victims)

GroupVictimSectorGeoDiscoveredLink
QilinSinging River Health Systemhealthcare / hospitalUS2026-06-03link
QilinMarketJoysales / marketingUS2026-06-03link
QilinJNP ENGengineering—2026-06-03link
QilinEat Saladfood / retail—2026-06-03link
AkiraHal Otey FinancialfinancialUS2026-06-03link
INC_RANSOMÖztuğ Otomotivmanufacturing / automotiveTR2026-06-03link
GenesisFamily Medical Associates of RaleighhealthcareUS2026-06-03link
DragonForceCopamexmanufacturing / paperMX2026-06-03link
Apt73 (Bashe)smarty.arpinet.amtelecom / ISPAM2026-06-03link

⚠️ Because RansomLook is unreachable, the table above lists single-day victims confirmed across multiple sources (ransomware.live / BreachSense) and may be incomplete; a full DLS census requires direct RansomLook access to state precisely.

Anomalies / trend notes

  • Qilin posted ~4 victims in one day across sectors (healthcare + marketing + engineering + food retail): continuing its structural multi-quarter lead at #1; healthcare (Singing River Health System, a well-known US hospital system) remains a high-value target for the group.
  • Healthcare remains high-frequency: Qilin (Singing River) and Genesis (Family Medical Associates of Raleigh) both registered healthcare hits the same day; the healthcare/hospital direction needs continued attention.
  • Akira hit financial: Hal Otey Financial registers on the financial-sector watchlist, consistent with Akira's profile of over $150M in 2025 proceeds and targeting high-value entities.
  • DragonForce hit Mexican manufacturing (Copamex, paper): manufacturing is a priority watchlist sector, and the post-"cartel" geographic expansion (toward Latin America) continues.
  • INC hit Turkish automotive manufacturing (Öztuğ Otomotiv): a manufacturing hit on the Europe/Middle East supply-chain axis.
  • The quarterly picture is unchanged: Qilin has held #1 for several quarters (>1,700 tracked victims), Akira is second, and the ransom payment rate is near its all-time low of ~28%.

This cycle's ransomware data is in degraded mode (WebSearch aggregation plus single-day confirmation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 3, 2026
Next →
Ransomware Watch · Jun 5, 2026