Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-12
Ransomware·2026-06-12

Ransomware Watch · Jun 12, 2026

Window: past 24–48 hours. Degraded data-source notice: RansomLook /api/posts returned 403 Forbidden from the sandbox egress today, and RSS was likewise unreachable. The victim data below was reconstructed via WebSearch from ransomware.live and leak-tracking sites; it is not a complete leak-site snapshot, covers only the named victims that could be retrieved, and the counts are lower bounds.

Overview

  • New posts (visible sample): 5+(the actual leak-site total for the day is higher; API restrictions prevented a full pull)
  • Groups involved: 3(LockBit5, Akira, Fulcrumsec)
  • Watchlist hits: 5(multiple hits across group, sector, and geography)
  • Most active: LockBit5(still leading, continuing the concentrated dump from 6/11)

Watchlist hits (read first)

GroupVictimSectorGeoHitLink
LockBit5Central Romana Corporationagriculture / sugar productionDominican Republic (DO)group:lockbitransomware.live
LockBit5Shougang Peru (shougang.com.pe)steel / mining (critical infrastructure)Peru (PE) · Chinese-owned parentgroup:lockbit · sector:manufacturing · geo:china-linkedransomware.live
FulcrumsecGlobal Schools Foundation (GSG)education (K-12 / international schools)Singapore (SG)sector:education · geo:singaporeransomware.live
AkiraCentre Ellipsehealthcare—group:akira · sector:healthcareransomware.live
LockBitDelano Public Schoolseducation (K-12)United States (US)group:lockbit · sector:educationransomware.live

All new posts (visible sample)

GroupVictimSectorGeoDiscoveredLink
LockBit5Central Romana Corporationagriculture / sugarDO2026-06-11ransomware.live
LockBit5Shougang Perusteel / miningPE2026-06-11ransomware.live
FulcrumsecGlobal Schools FoundationeducationSG2026-06-10ransomware.live
AkiraCentre Ellipsehealthcare—2026-06-10ransomware.live
LockBitDelano Public SchoolseducationUS2026-06-10ransomware.live

Anomalies / trend notes

  • LockBit5 remains highly productive: after the concentrated dump on 6/11 it still leads the leak sites, and its comeback posture looks firmly established; watch its naming cadence and the geographic distribution of its victims.
  • Critical infrastructure / Chinese-linked ownership: LockBit5 named Shougang Peru (Shougang Hierro Peru)— steel and mining critical infrastructure with a Chinese parent company. The intrusion is estimated to trace back to 5/20, so the leak lagged the compromise significantly.
  • Education and healthcare both under pressure: a single window produced GSG (Singapore international schools), the Delano school district, and Centre Ellipse (healthcare) — continuing education and healthcare as high-frequency ransomware targets (healthcare led May with 28 incidents).
  • Data gap: because of the RansomLook API restriction, full sector/geography statistics are not possible today; the table above is a lower-bound sample of what could be retrieved, so do not read it as a decline in the day's total leak-site volume.

Watchlist configuration is in intel/ransomware/watchlist.yaml. Data source: ransomware.live (reconstructed via WebSearch).

← Prev
Ransomware Watch · Jun 11, 2026
Next →
Ransomware Watch · Jun 13, 2026