Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-09
Ransomware·2026-06-09

Ransomware Watch · Jun 9, 2026

Window: past 24 hours (2026-06-08 → 2026-06-09, Monday into Tuesday, weekday catch-up beginning)
⚠️ Data basis: this cycle neither the public RansomLook API (/api/posts?days=1) nor the RSS feed (rss.xml) could be reached directly from the sandbox (egress 403 / not in the web_fetch provenance set). The victim dimension instead uses a ransomware.live snapshot (updated 2026-06-07 15:20 UTC, covering 6/5–6/6 postings), cross-checked against WebSearch aggregation (Check Point / industrialcyber quarterly reports and others); exact per-victim discovery times cannot be guaranteed at 100%.

Overview

  • Collection basis (ransomware.live snapshot, 6/5–6/6 postings): about 12new posts across roughly 10groups
  • Most active groups (in window): Qilin, Akira, Play; Nova, Anubis, Krybit, INC Ransom (Incransom), Genesis, and Blackwater also posted
  • Watchlist hits: about 6, concentrated in healthcare / education / manufacturing plus the US and CN geographies
  • Quarterly picture: roughly 2,122 victim organizationsindustry-wide in Q1 2026; Qilin #1 for a third consecutive quarter (338 victims), LockBit recovered to #4 (163), and Qilin + Akira + The Gentlemen + LockBit together account for about 41%

Watchlist hits (read first)

GroupVictimSectorGeoHitLink
PlayPearson Fordtransportation / logisticsUS/GBgroup:play · sector:logisticsransomware.live
NovaAspire HospitalhealthcareINsector:healthcare · sector:hospital · sector:medicalransomware.live
NovaUniversitas Nasional (UNAS)educationIDsector:educationransomware.live
INC Ransomkelmreuter.com / obrieneng.combusiness services / engineeringUSgroup:incransomware.live
Krybithuashan.com.cn (Shantou Huashan Electronics, semiconductors)manufacturingCNsector:manufacturing · geo:cn · geo:chinaransomware.live
Akira(mid-sized industrial firms, continuing)manufacturingUS/EUgroup:akira · sector:manufacturingransomware.live

All new posts (24h, ransomware.live snapshot selection)

GroupVictimSectorGeoDiscoveredLink
Blackwaterwww.utourworld.comhospitality / tourism—2026-06-06ransomware.live
PlayPearson Fordtransportation / logisticsUS/GB2026-06-06ransomware.live
Incransom (INC)kelmreuter.combusiness servicesUS2026-06-06ransomware.live
Genesiscavalierflooring.comtrade associationUS2026-06-06 (attack estimated 6/5)ransomware.live
NovaUniversitas Nasional (UNAS)educationID2026-06-06ransomware.live
Krybithuashan.com.cnmanufacturing (semiconductors)CN2026-06-06ransomware.live
AnubisJeffrey Burrconsumer services / legalUS2026-06-05ransomware.live
NovaAspire HospitalhealthcareIN2026-06-05ransomware.live
Krybitschultz.com.brbusiness services / travelBR2026-06-05ransomware.live
AnubisD&M ContractorsconstructionGB2026-06-05ransomware.live

Anomalies / trend notes

  • Healthcare and education both named by Nova in one cluster: within the window, the single group Nova listed both India's Aspire Hospital (healthcare) and Indonesia's Universitas Nasional (education), both priority watchlist sectors, and claimed "servers already encrypted" in each case. Worth tracking whether Nova's sector preference persists.
  • Chinese semiconductors enter the ransomware picture: Krybitlisted Shantou Huashan Electronics (huashan.com.cn, a semiconductor device manufacturer), a double hit on CN plus manufacturing. In the same window Krybit also named the Brazilian travel operator schultz.com.br, showing opportunistic strikes across geographies and sectors.
  • New / low-frequency group names: Blackwater, Genesis, Nova, Krybit, and Anubiswere relatively active in this snapshot, several of them relatively low-frequency names; watch for whether they are post-takedown rebrands or newly established RaaS operations.
  • Structure unchanged: on a quarterly basis Qilin holds #1(338 victims in Q1, top for three consecutive quarters), LockBit has recovered to #4 (163) after law-enforcement action, and its victim geography has shifted from mostly US toward a more even distribution (Europe / Latin America), possibly to evade law-enforcement jurisdiction.
  • Cadence: 6/6–6/7 was a weekend with light posting; weekday catch-up begins 6/8 (Monday), post counts are expected to keep recovering in the 6/9 window, and this table reflects only what the snapshot shows, so it is conservative.
  • Data-basis reminder: RansomLook was entirely unreachable this cycle and all victim detail comes from the ransomware.live snapshot plus aggregate sources. Reviewing with the RansomLook API tomorrow to backfill the structured fields is recommended.
← Prev
Ransomware Watch · Jun 8, 2026
Next →
Ransomware Watch · Jun 10, 2026
Incransom (INC)obrieneng.comengineeringUS2026-06-05ransomware.live
Qilin / Akira(multi-sector posts continuing)mixedmultiple2026-06-05/06ransomware.live