Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-15
Ransomware·2026-06-15

Ransomware Watch · Jun 15, 2026

Data source: RansomLook recent-posts API (?days=1, public endpoint). The latest batch returned has discovered timestamps of 2026-06-08 → 2026-06-09 (no 06-14/15 posts appeared). The payload contains only group_name + discovered, with no victim / sector / geo fields — so the victim/sector columns below are left empty, and named victims are supplemented from news sources.

Overview

  • Total new posts: ~32
  • Groups involved: 7 (lockbit5, qilin, akira, ransomhouse, termite, stormous, nova)
  • Watchlist hits: ~24 (lockbit5×16, qilin×6, akira×2)

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
lockbit5— (not provided by API)——group:lockbitRansomLook
qilin— (not provided by API)——group:qilinRansomLook
akira— (not provided by API)——group:akiraRansomLook

⭐ A single batch of ~16 lockbit5 posts appeared within roughly 17 seconds around 2026-06-09 14:50 — likely bulk/automated publishing or a one-off data migration.

All New Posts (aggregated by group, discovered 2026-06-08→09)

GroupPostsVictimSectorGeoDiscovered
lockbit5~16———2026-06-09
qilin6———2026-06-08/09
akira2———2026-06-08/09
ransomhouse2———2026-06-08
termite2———2026-06-09
stormous2———2026-06-09
nova1———2026-06-09

Named Victims Supplemented from News Sources (not RansomLook fields)

GroupVictimSectorGeoNoteLink
The GentlemenMultiple (claims 478)Multiple sectorsGlobalWorm-like propagation capability, double extortionTechCrunch
Brain CipherThe Adviser (regional newspaper)mediaAUClaims 350+ GB stolen, ransom deadline 6/2PrivacyGuides
KairosGregory JewellersretailAUClaims ~574 GB stolenPrivacyGuides

Anomalies / Trend Notes

  • lockbit5 high-frequency burst: a single batch of ~16 posts appeared within ~17 seconds. Given lockbit's history of repeatedly rebranding after takedowns, watch whether this is a new round of listing inflation or a re-publication of old data.
  • Law enforcement: on 6/12 Europol took down the "AudiA6" crypto money-laundering service used by ransomware gangs — this may briefly disrupt some groups' cash-out chains.
  • Data limitations: this RansomLook payload lacks victim/sector/geo, so sector-concentration analysis is not possible; next run, fall back to the RSS (https://www.ransomlook.io/rss.xml) or cross-check with ransomware.live.

Watchlist configuration: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 14, 2026
Next →
Ransomware Watch · Jun 16, 2026