Ransomware Watch · Jun 11, 2026
Data source: RansomLook
/api/posts?days=1(window ending 2026-06-09 14:50 UTC, the most recent data this API call returned). This call returned onlygroup_nameanddiscovered, with no victim / sector / geo fields, so the victim table is based mainly on group activity and sector / geography matching is unavailable today.
Overview
- Total new posts: 32
- Groups involved: 7
- Watchlist hits (by group): 3 groups(lockbit5 →
lockbit, qilin, akira) - Standout observation: LockBit5 dumped 16 posts in a single-day burst, half of the day's total — an apparent bulk upload or comeback surge.
Watchlist hits (read first)
| Group | Posts | Hit | Note |
|---|---|---|---|
| lockbit5 | 16 | group:lockbit | Repeatedly disrupted and repeatedly resurgent; watch the rebrand. Single-day bulk dump |
| qilin | 6 | group:qilin | Sustained high activity; linked to the Check Point VPN 0-day campaign (medium confidence) |
| akira | 2 | group:akira | Consistently active group |
All new posts (aggregated by group)
| Group | Posts | Discovered (window) | Watchlist |
|---|---|---|---|
| lockbit5 | 16 | 2026-06-09 14:50 UTC (bulk) | ⭐ lockbit |
| qilin | 6 | 2026-06-08 ~ 06-09 | ⭐ qilin |
| akira | 2 | 2026-06-08 / 06-09 | ⭐ akira |
| ransomhouse | 2 | 2026-06-08 | — |
| termite | 2 | 2026-06-09 | — |
| stormous | 2 | 2026-06-09 | — |
| nova | 1 | 2026-06-09 | — |
ℹ️ This API call returned no victim names. A victim named on the news side (not from the API): BCD Travel (ShinyHunters, roughly 396,000 customer records already dumped publicly).
Anomalies / trend notes
- LockBit5 burst: 16 posts in one day, half the daily total, matching a "bulk upload" or post-rebrand clearing-out pattern; cross-checking whether the victim list and timestamps on its leak site represent a one-off backfill is recommended.
- Qilin stays elevated: consistent with the in-the-wild Check Point VPN 0-day campaign (CVE-2026-50751) — the VPN initial-access → Qilin deployment chain is worth tracking.
- Data gap: the API returned no victim/sector fields, so sector concentration and geographic analysis are not possible. For a complete victim table, scraping the RansomLook
/recentpage or fixing RSS parsing is recommended.
Configuration is in the ransomware category of intel/sources.yaml · watchlist: intel/ransomware/watchlist.yaml