Ransomware Watch · Jun 10, 2026
Window: past 24 hours (RansomLook
/api/posts?days=1, covering 2026-06-08 16:49 → 2026-06-09 14:50 UTC, Monday-into-Tuesday weekday catch-up)
✅ Data basis: this cycle the public RansomLook API was directly reachable (/api/posts?days=1returned JSON). ⚠️ However, this payload contained only thegroup_nameanddiscoveredfields — nopost_title, victim, sector, or geo. Per-victim detail therefore cannot be provided this cycle; the tables below aggregate by group and time. The RSS feed (rss.xml) returned binary content that the fetch tool could not parse as text, and ransomware.live/v2/recentvictimswas not directly reachable due to provenance restrictions, so victim names could not be cross-filled.
Overview
- Total new posts: 32
- Groups involved: 7(lockbit5, qilin, akira, ransomhouse, termite, stormous, nova)
- Watchlist hits: 25(lockbit5 17 + qilin 6 + akira 2; all matching the
groupslist)
Watchlist hits (read first)
Only group-level data is available this cycle (no victim names), so hits are aggregated by group.
| Group | Posts | Hit | Window (UTC) | Link |
|---|---|---|---|---|
| lockbit5 | 17 | group:lockbit (rebrand → LockBit 5.0) | 2026-06-09 14:50:08 → 14:50:25 (posted in a burst of about 17 seconds) | ransomlook.io/group/lockbit5 |
| qilin | 6 | group:qilin | 2026-06-08 16:49 → 2026-06-09 01:48 | ransomlook.io/group/qilin |
| akira | 2 | group:akira | 2026-06-08 16:49 / 2026-06-09 14:46 | ransomlook.io/group/akira |
All new posts (24h, aggregated by group)
| Group | Posts | First seen (UTC) | Last seen (UTC) | Link |
|---|---|---|---|---|
| lockbit5 | 17 | 2026-06-09 14:50:08 | 2026-06-09 14:50:25 | ransomlook.io |
| qilin | 6 | 2026-06-08 16:49:59 | 2026-06-09 01:48:12 | ransomlook.io |
| akira | 2 | 2026-06-08 16:49:34 | 2026-06-09 14:46:55 | ransomlook.io |
| ransomhouse | 2 | 2026-06-08 20:48:06 | 2026-06-08 22:49:38 | ransomlook.io |
| termite | 2 | 2026-06-09 01:48:16 | 2026-06-09 01:48:17 | ransomlook.io |
| stormous | 2 | 2026-06-09 14:47:18 | 2026-06-09 14:47:19 | ransomlook.io |
| nova | 1 | 2026-06-09 13:45:21 | 2026-06-09 13:45:21 | ransomlook.io |
Anomalies / trend notes
- LockBit5 comeback burst: a single group posted 17 entries within roughly 17 secondsat 14:50 UTC on 6/9, accounting for 53% of all posts that day. This kind of bulk dump usually means a previously accumulated backlog of victims is being published at once, and it matches Check Point / Arete intelligence on the revival of LockBit 5.0(announced on RAMP in September 2025, internal codename "ChuongDong," risen to #4 in Q1 2026 with 163 victims, up 106% quarter over quarter). Worth close tracking: are these genuinely new victims, or repopulated old data to pad the site? LockBit has historically filled its leak site with old breaches.
- Qilin remains the steadiest group: 6 posts in the window, evenly distributed from throughout 6/8 into the early hours of 6/9, continuing the #1 position it has held for three consecutive quarters in Q1.
- Low-frequency / new group names: termite, stormous, ransomhouse, and novaeach contributed 1–2 posts in this window; the paired, tightly spaced postings from termite and stormous (within the same second) suggest automated bulk publishing.
- Data-basis reminder: the victim dimension is missing this cycle (sector and geography cannot be determined, so watchlist
sectors/geoshits cannot be evaluated) and only thegroupsdimension is assessable. Tomorrow, using the RansomLook/recentpage or the/api/group/<name>endpoint to backfill victim names is recommended, or cross-referencing ransomware.live where provenance allows.