Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-14
Ransomware·2026-06-14

Ransomware Watch · Jun 14, 2026

Data note: The RansomLook API / RSS and the ransomware.live API were blocked in the sandbox by egress/source policies (returned empty). This issue was reconstructed via WebSearch aggregation (Ransom-DB, Bitdefender, MOXFIVE, Check Point, and other tracking sources). Counts are a lower bound, not a complete leak-site snapshot.

Overview

  • Reference window (most recent complete 24h tally, 6/11): total new posts 39
  • Most active groups: Qilin (18)· DragonForce (7)· M3RXDLS (6)· DireWolf (4)
  • Most-hit sectors: Manufacturing, Energy, Real Estate, Construction & Engineering
  • Most-hit geographies: United States (US), United Arab Emirates (UAE)
  • Watchlist hits: groups qilin, dragonforce; sectors manufacturing, energy

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
QilinMultiple (18 within 24h, concentrated in manufacturing/energy)Manufacturing / EnergyUS / UAEgroup:qilin · sector:manufacturing · sector:energyRansom-DB
DragonForceMultiple (7)Manufacturing / Real estate, etc.USgroup:dragonforce · sector:manufacturingUnderCode
ShinyHunters100+ organizations (PeopleSoft 0-day), 68% universitiesEducationUS / Globalkw:data leak · sector:educationThe Hacker News

Note: ShinyHunters is a data-theft/extortion operation (not traditional encryption-based ransomware), but its PeopleSoft 0-day campaign (CVE-2026-35273) is the biggest theme of this issue, so it is highlighted here; see the KEV section of the main brief for details.

All New Posts (aggregated, not an itemized snapshot)

GroupVictimSectorGeoDiscoveredLink
Qilin18 victims (aggregated)Manufacturing / EnergyUS / UAE2026-06-11Ransom-DB
DragonForce7 victims (aggregated)Real Estate / ManufacturingUS2026-06-11UnderCode
M3RXDLS6 victims (aggregated)Mixed—2026-06-11Bitdefender
DireWolf4 victims (aggregated)Mixed—2026-06-11Bitdefender

Anomalies / Trend Notes

  • Qilin keeps topping the chart: roughly 500 victims in 2026 and about 1,500 cumulative; a single day can account for nearly half of all new leaks — still the number-one operation.
  • Duplicate-claim phenomenon: researchers have observed Qilin, The Gentlemen, DragonForce, Coinbase Cartel and others repeatedly claiming victims already published by other groups; leak-site counts are inflated by duplication and require cross-checking.
  • ShinyHunters pivots to supply-chain-style 0-day data theft: the PeopleSoft campaign (CVE-2026-35273) hit 100+ organizations in one stroke, mostly in education; expect a subsequent "extort one by one / publish in batches" phase — a key tracking target for the coming days.
  • Law enforcement: European authorities took down the AudiA6cryptocurrency money-laundering pipeline (which laundered hundreds of millions of dollars for ransomware gangs); this may affect affiliate payouts and cash-out speed in the short term.

Watchlist configuration: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 13, 2026
Next →
Ransomware Watch · Jun 15, 2026