Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-07
Ransomware·2026-06-07

Ransomware Watch · Jun 7, 2026

Window: past 24 hours (2026-06-06 → 2026-06-07, a weekend, when new DLS posts are typically fewer)
⚠️ Data basis: the RansomLook API / RSS is blocked under the current sandbox egress allowlist (host not on the allow list; curl returns empty). This edition instead cross-checks aggregated second-hand sources via WebSearch (breachsense / ransomware.live / cybersecurity-insiders / hendryadrian and others); per-victim accuracy and exact discovery times cannot be guaranteed at 100%.

Overview

  • Total new posts (aggregate estimate): ~20–30, across ~85 active leak sites (weekend slowdown)
  • Most active groups: Qilin, Akira, Play, INC Ransom, The Gentlemen; LockBit / Genesis / DragonForce / Worldleaks also posted new entries
  • Watchlist hits: roughly 10+ (see the table below) — still heavily concentrated in US healthcare and manufacturing
  • Quarterly picture unchanged: Qilin still #1(>1,800 publicly tracked victims, 101 victims in May alone, topping the chart for a fifth consecutive month), Akira #2; May saw ~646 victims across 61 groups industry-wide (breachsense basis)

Watchlist hits (read first)

GroupVictimSectorGeoHitLink
The GentlemenDownriver Medical AssociateshealthcareUSgroup (family) · sector:healthcare/medical · geo:usbreachsense
The GentlemenEdgewood Surgicalhealthcare / surgicalUSsector:healthcare/medical · geo:usbreachsense
The GentlemenMichigan Surgical Centerhealthcare / surgicalUSsector:healthcare/medical · geo:usbreachsense
LockBitSierra Vista HospitalhospitalUSgroup:lockbit · sector:hospital · geo:usbreachsense
GenesisFamily Medical Associates of RaleighhealthcareUSsector:healthcare/medical · geo:usbreachsense
PlayCorley ManufacturingmanufacturingUSgroup:play · sector:manufacturing · geo:usbreachsense
INC RansomStuga MachinerymanufacturingUKgroup:inc · sector:manufacturingbreachsense
INC RansomNational Standard PartsmanufacturingUSgroup:inc · sector:manufacturing · geo:usbreachsense
AkiraKennon WorldwidemanufacturingUSgroup:akira · sector:manufacturing · geo:usbreachsense
Qilin(energy / oilfield services continuing)energy / oil—group:qilin · sector:energy/oilransomware.live
BavaqaiDolphin ManufacturingmanufacturingUSsector:manufacturing · geo:usbreachsense

All new posts (24h aggregate, selection)

GroupVictimSectorGeoDiscoveredLink
The GentlemenDownriver Medical AssociateshealthcareUS2026-06-04/06link
The GentlemenEdgewood SurgicalsurgicalUS2026-06-04/06link
The GentlemenMichigan Surgical CentersurgicalUS2026-06-04/06link
LockBitSierra Vista HospitalhospitalUS2026-06-05link
GenesisFamily Medical Associates of RaleighhealthcareUS2026-06-05/06link
PlayCorley ManufacturingmanufacturingUS2026-06-05link
INC RansomStuga MachinerymanufacturingUK2026-06-05/06link
INC RansomNational Standard PartsmanufacturingUS2026-06-05/06link
AkiraKennon WorldwidemanufacturingUS2026-06-05link
BavaqaiDolphin ManufacturingmanufacturingUS2026-06-04link

Anomalies / trend notes

  • The Gentlemen family posted three US healthcare/surgical organizations in one day(Downriver Medical, Edgewood Surgical, Michigan Surgical Center), continuing the concentrated output this family's affiliates have directed at the US medical-surgical space since May. Combined with the previously documented DFIR Report analysis of "malicious GPO plus SYSVOL scheduled tasks for domain-wide deployment," healthcare IR teams should prioritize verifying GPO integrity.
  • Manufacturing remains the second most affected sector(Corley, Stuga, National Standard Parts, Kennon, Dolphin); Play / INC Ransom / Akira maintain their steady cadence against mid-sized industrial firms, and manufacturing returned to first place among sectors in May with 58 victims.
  • The healthcare-plus-manufacturing pattern matches yesterday (6/6), with watchlist hits heavily concentrated and almost entirely on US targets.
  • The ransom payment rate remains at a historic low(~28% in recent statistics), sustaining the "more attacks, fewer payments" pattern; Qilin has topped the chart as a single group for a fifth consecutive month, and its volume alone now exceeds the sum of the bottom 50 groups.
  • Weekend effect: new DLS posts fall below weekday levels, and some 6/4–6/5 posts were backfilled by aggregate sources within the 6/6–6/7 window, leaving discovery times with a ±1–2 day margin of error.
← Prev
Ransomware Watch · Jun 6, 2026
Next →
Ransomware Watch · Jun 8, 2026
Qilin(multi-sector posts continuing)mixedmultiple2026-06-06link