Ransomware Watch · Jun 5, 2026
Time window: past 24 hours (2026-06-04 → 2026-06-05)
Data sources: The RansomLook API/RSS was blocked by the sandbox egress allowlist (host not on the network allow list, same as yesterday); this edition is a WebSearch aggregation (ransomware.live / Ransom-DB / RedPacket Security / vendor tracking). Per-victim accuracy cannot be fully guaranteed; the victims below are either multi-source confirmed or single-source DLS posts, and the 6/3 victims are cross-source carryover that surfaced later.
Overview
- Estimated total new posts: ~30–40(public aggregate-source basis)
- Active leak sites involved: ~90
- Most active groups: Qilin, Akira, DragonForce, INC Ransom(The Gentlemen and Nova/RALord also posted)
- Watchlist hits: ≥5(Qilin × healthcare/multi-sector, Akira × financial/manufacturing, INC × manufacturing)
Watchlist hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| DragonForce | SETS Solutions | IT / services | — | group:dragonforce | redpacketsecurity.com |
| Qilin | (multi-sector, continuing the 6/3 cluster) | healthcare / multi | US | group:qilin + sector:healthcare | ransomware.live |
| Akira | (financial / manufacturing) | financial / manufacturing | US | group:akira + sector:financial | ransomware.live |
| INC_RANSOM | (manufacturing) | manufacturing | — | group:inc + sector:manufacturing | ransomware.live |
ℹ️ Because direct RansomLook access is unavailable, the per-victim list for 6/4 is incomplete this cycle; DragonForce × SETS Solutions is a new DLS post confirmed by a single source (RedPacket). The remaining rows are sector/geography profiles summarized for the most active groups.
All new posts (multi-source confirmed + 6/3 carryover)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| DragonForce | SETS Solutions | IT / services | — | 2026-06-03/04 | link |
| Qilin | Singing River Health System | healthcare / hospital | US | 2026-06-03 | link |
| Qilin | MarketJoy | sales / marketing | US | 2026-06-03 | link |
| Qilin | JNP ENG | engineering | — | 2026-06-03 | link |
| Qilin | Eat Salad | food / retail | — | 2026-06-03 | link |
| Akira | Hal Otey Financial | financial | US | 2026-06-03 | link |
| INC_RANSOM | Öztuğ Otomotiv | manufacturing / automotive | TR | 2026-06-03 | link |
| DragonForce | Copamex | manufacturing / paper | MX | 2026-06-03 | link |
⚠️ Because RansomLook is unreachable, the table above lists victims confirmed across multiple sources (ransomware.live / Ransom-DB / RedPacket) and may be incomplete; a full DLS census requires direct RansomLook access to state precisely.
Anomalies / trend notes
- Qilin remains the highest-output group per day: continuing its structural multi-quarter lead at #1 (>1,700 tracked victims), with healthcare (Singing River Health System) still a high-value target.
- DragonForce stays active: SETS Solutions is new, and combined with Copamex (Mexican paper) on 6/3, the post-"cartel" geographic expansion (toward Latin America and services) continues.
- Akira hit financial/manufacturing: consistent with its profile of over $150M in 2025 proceeds and targeting high-value entities.
- INC hit manufacturing: the Europe/Middle East supply-chain axis continues (Öztuğ Otomotiv, Turkish automotive manufacturing).
- The quarterly picture is unchanged: Qilin has held #1 for several quarters, Akira is second, and the ransom payment rate is near its all-time low of ~28%.
This cycle's ransomware data is in degraded mode (WebSearch aggregation plus multi-source confirmation). Per-victim precision returns once direct RansomLook access is restored.
Watchlist configuration is in intel/ransomware/watchlist.yaml