Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-05
Ransomware·2026-06-05

Ransomware Watch · Jun 5, 2026

Time window: past 24 hours (2026-06-04 → 2026-06-05)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (host not on the network allow list, same as yesterday); this edition is a WebSearch aggregation (ransomware.live / Ransom-DB / RedPacket Security / vendor tracking). Per-victim accuracy cannot be fully guaranteed; the victims below are either multi-source confirmed or single-source DLS posts, and the 6/3 victims are cross-source carryover that surfaced later.

Overview

  • Estimated total new posts: ~30–40(public aggregate-source basis)
  • Active leak sites involved: ~90
  • Most active groups: Qilin, Akira, DragonForce, INC Ransom(The Gentlemen and Nova/RALord also posted)
  • Watchlist hits: ≥5(Qilin × healthcare/multi-sector, Akira × financial/manufacturing, INC × manufacturing)

Watchlist hits (read first)

GroupVictimSectorGeoHitLink
DragonForceSETS SolutionsIT / services—group:dragonforceredpacketsecurity.com
Qilin(multi-sector, continuing the 6/3 cluster)healthcare / multiUSgroup:qilin + sector:healthcareransomware.live
Akira(financial / manufacturing)financial / manufacturingUSgroup:akira + sector:financialransomware.live
INC_RANSOM(manufacturing)manufacturing—group:inc + sector:manufacturingransomware.live

ℹ️ Because direct RansomLook access is unavailable, the per-victim list for 6/4 is incomplete this cycle; DragonForce × SETS Solutions is a new DLS post confirmed by a single source (RedPacket). The remaining rows are sector/geography profiles summarized for the most active groups.

All new posts (multi-source confirmed + 6/3 carryover)

GroupVictimSectorGeoDiscoveredLink
DragonForceSETS SolutionsIT / services—2026-06-03/04link
QilinSinging River Health Systemhealthcare / hospitalUS2026-06-03link
QilinMarketJoysales / marketingUS2026-06-03link
QilinJNP ENGengineering—2026-06-03link
QilinEat Saladfood / retail—2026-06-03link
AkiraHal Otey FinancialfinancialUS2026-06-03link
INC_RANSOMÖztuğ Otomotivmanufacturing / automotiveTR2026-06-03link
DragonForceCopamexmanufacturing / paperMX2026-06-03link

⚠️ Because RansomLook is unreachable, the table above lists victims confirmed across multiple sources (ransomware.live / Ransom-DB / RedPacket) and may be incomplete; a full DLS census requires direct RansomLook access to state precisely.

Anomalies / trend notes

  • Qilin remains the highest-output group per day: continuing its structural multi-quarter lead at #1 (>1,700 tracked victims), with healthcare (Singing River Health System) still a high-value target.
  • DragonForce stays active: SETS Solutions is new, and combined with Copamex (Mexican paper) on 6/3, the post-"cartel" geographic expansion (toward Latin America and services) continues.
  • Akira hit financial/manufacturing: consistent with its profile of over $150M in 2025 proceeds and targeting high-value entities.
  • INC hit manufacturing: the Europe/Middle East supply-chain axis continues (Öztuğ Otomotiv, Turkish automotive manufacturing).
  • The quarterly picture is unchanged: Qilin has held #1 for several quarters, Akira is second, and the ransom payment rate is near its all-time low of ~28%.

This cycle's ransomware data is in degraded mode (WebSearch aggregation plus multi-source confirmation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 4, 2026
Next →
Ransomware Watch · Jun 6, 2026