Ransomware Watch · Jun 14, 2026
Data note: The RansomLook API / RSS and the ransomware.live API were blocked in the sandbox by egress/source policies (returned empty). This issue was reconstructed via WebSearch aggregation (Ransom-DB, Bitdefender, MOXFIVE, Check Point, and other tracking sources). Counts are a lower bound, not a complete leak-site snapshot.
Overview
- Reference window (most recent complete 24h tally, 6/11): total new posts 39
- Most active groups: Qilin (18)· DragonForce (7)· M3RXDLS (6)· DireWolf (4)
- Most-hit sectors: Manufacturing, Energy, Real Estate, Construction & Engineering
- Most-hit geographies: United States (US), United Arab Emirates (UAE)
- Watchlist hits: groups qilin, dragonforce; sectors manufacturing, energy
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Multiple (18 within 24h, concentrated in manufacturing/energy) | Manufacturing / Energy | US / UAE | group:qilin · sector:manufacturing · sector:energy | Ransom-DB |
| DragonForce | Multiple (7) | Manufacturing / Real estate, etc. | US | group:dragonforce · sector:manufacturing | UnderCode |
| ShinyHunters | 100+ organizations (PeopleSoft 0-day), 68% universities | Education | US / Global | kw:data leak · sector:education | The Hacker News |
Note: ShinyHunters is a data-theft/extortion operation (not traditional encryption-based ransomware), but its PeopleSoft 0-day campaign (CVE-2026-35273) is the biggest theme of this issue, so it is highlighted here; see the KEV section of the main brief for details.
All New Posts (aggregated, not an itemized snapshot)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | 18 victims (aggregated) | Manufacturing / Energy | US / UAE | 2026-06-11 | Ransom-DB |
| DragonForce | 7 victims (aggregated) | Real Estate / Manufacturing | US | 2026-06-11 | UnderCode |
| M3RXDLS | 6 victims (aggregated) | Mixed | — | 2026-06-11 | Bitdefender |
| DireWolf | 4 victims (aggregated) | Mixed | — | 2026-06-11 | Bitdefender |
Anomalies / Trend Notes
- Qilin keeps topping the chart: roughly 500 victims in 2026 and about 1,500 cumulative; a single day can account for nearly half of all new leaks — still the number-one operation.
- Duplicate-claim phenomenon: researchers have observed Qilin, The Gentlemen, DragonForce, Coinbase Cartel and others repeatedly claiming victims already published by other groups; leak-site counts are inflated by duplication and require cross-checking.
- ShinyHunters pivots to supply-chain-style 0-day data theft: the PeopleSoft campaign (CVE-2026-35273) hit 100+ organizations in one stroke, mostly in education; expect a subsequent "extort one by one / publish in batches" phase — a key tracking target for the coming days.
- Law enforcement: European authorities took down the AudiA6cryptocurrency money-laundering pipeline (which laundered hundreds of millions of dollars for ransomware gangs); this may affect affiliate payouts and cash-out speed in the short term.
Watchlist configuration: intel/ransomware/watchlist.yaml