Ransomware Watch · Jun 9, 2026
Window: past 24 hours (2026-06-08 → 2026-06-09, Monday into Tuesday, weekday catch-up beginning)
⚠️ Data basis: this cycle neither the public RansomLook API (/api/posts?days=1) nor the RSS feed (rss.xml) could be reached directly from the sandbox (egress 403 / not in the web_fetch provenance set). The victim dimension instead uses a ransomware.live snapshot (updated 2026-06-07 15:20 UTC, covering 6/5–6/6 postings), cross-checked against WebSearch aggregation (Check Point / industrialcyber quarterly reports and others); exact per-victim discovery times cannot be guaranteed at 100%.
Overview
- Collection basis (ransomware.live snapshot, 6/5–6/6 postings): about 12new posts across roughly 10groups
- Most active groups (in window): Qilin, Akira, Play; Nova, Anubis, Krybit, INC Ransom (Incransom), Genesis, and Blackwater also posted
- Watchlist hits: about 6, concentrated in healthcare / education / manufacturing plus the US and CN geographies
- Quarterly picture: roughly 2,122 victim organizationsindustry-wide in Q1 2026; Qilin #1 for a third consecutive quarter (338 victims), LockBit recovered to #4 (163), and Qilin + Akira + The Gentlemen + LockBit together account for about 41%
Watchlist hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Play | Pearson Ford | transportation / logistics | US/GB | group:play · sector:logistics | ransomware.live |
| Nova | Aspire Hospital | healthcare | IN | sector:healthcare · sector:hospital · sector:medical | ransomware.live |
| Nova | Universitas Nasional (UNAS) | education | ID | sector:education | ransomware.live |
| INC Ransom | kelmreuter.com / obrieneng.com | business services / engineering | US | group:inc | ransomware.live |
| Krybit | huashan.com.cn (Shantou Huashan Electronics, semiconductors) | manufacturing | CN | sector:manufacturing · geo:cn · geo:china | ransomware.live |
| Akira | (mid-sized industrial firms, continuing) | manufacturing | US/EU | group:akira · sector:manufacturing | ransomware.live |
All new posts (24h, ransomware.live snapshot selection)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Blackwater | www.utourworld.com | hospitality / tourism | — | 2026-06-06 | ransomware.live |
| Play | Pearson Ford | transportation / logistics | US/GB | 2026-06-06 | ransomware.live |
| Incransom (INC) | kelmreuter.com | business services | US | 2026-06-06 | ransomware.live |
| Genesis | cavalierflooring.com | trade association | US | 2026-06-06 (attack estimated 6/5) | ransomware.live |
| Nova | Universitas Nasional (UNAS) | education | ID | 2026-06-06 | ransomware.live |
| Krybit | huashan.com.cn | manufacturing (semiconductors) | CN | 2026-06-06 | ransomware.live |
| Anubis | Jeffrey Burr | consumer services / legal | US | 2026-06-05 | ransomware.live |
| Nova | Aspire Hospital | healthcare | IN | 2026-06-05 | ransomware.live |
| Krybit | schultz.com.br | business services / travel | BR | 2026-06-05 | ransomware.live |
| Anubis | D&M Contractors | construction | GB | 2026-06-05 | ransomware.live |
Anomalies / trend notes
- Healthcare and education both named by Nova in one cluster: within the window, the single group Nova listed both India's Aspire Hospital (healthcare) and Indonesia's Universitas Nasional (education), both priority watchlist sectors, and claimed "servers already encrypted" in each case. Worth tracking whether Nova's sector preference persists.
- Chinese semiconductors enter the ransomware picture: Krybitlisted Shantou Huashan Electronics (huashan.com.cn, a semiconductor device manufacturer), a double hit on CN plus manufacturing. In the same window Krybit also named the Brazilian travel operator schultz.com.br, showing opportunistic strikes across geographies and sectors.
- New / low-frequency group names: Blackwater, Genesis, Nova, Krybit, and Anubiswere relatively active in this snapshot, several of them relatively low-frequency names; watch for whether they are post-takedown rebrands or newly established RaaS operations.
- Structure unchanged: on a quarterly basis Qilin holds #1(338 victims in Q1, top for three consecutive quarters), LockBit has recovered to #4 (163) after law-enforcement action, and its victim geography has shifted from mostly US toward a more even distribution (Europe / Latin America), possibly to evade law-enforcement jurisdiction.
- Cadence: 6/6–6/7 was a weekend with light posting; weekday catch-up begins 6/8 (Monday), post counts are expected to keep recovering in the 6/9 window, and this table reflects only what the snapshot shows, so it is conservative.
- Data-basis reminder: RansomLook was entirely unreachable this cycle and all victim detail comes from the ransomware.live snapshot plus aggregate sources. Reviewing with the RansomLook API tomorrow to backfill the structured fields is recommended.