Ransomware Watch · Jun 16, 2026
Data source: RansomLook recent-posts API (
https://www.ransomlook.io/api/posts?days=1, public endpoint). This batch's discovered timestamps span 2026-06-14T17:45 → 2026-06-15T15:44. The payload contains onlygroup_name+discovered, with no victim / sector / geo fields — so the victim/sector columns below are left empty, and named victims are supplemented from news sources.
Overview
- Total new posts: 29
- Groups involved: 5 (the gentlemen, nova, krybit, audit team, bavacai)
- Watchlist hits: 0 (no lockbit / akira / qilin / play / cl0p / medusa / ransomhub or other watched groups appeared in this batch)
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| — (no hits this batch) | — | — | — | — | — |
All New Posts (aggregated by group, discovered 2026-06-14→15)
| Group | Posts | Victim | Sector | Geo | Discovered |
|---|---|---|---|---|---|
| the gentlemen | 21 | — (not provided by API) | — | — | 2026-06-15 09:49–14:28 |
| nova | 4 | — | — | — | 2026-06-14 17:45 / 06-15 12:46·14:50 |
| krybit | 2 | — | — | — | 2026-06-14 22:53 / 06-15 13:44 |
| audit team | 1 | — | — | — | 2026-06-15 01:42 |
| bavacai | 1 | — | — | — | 2026-06-15 15:44 |
Anomalies / Trend Notes
- "the gentlemen" floods the board in a single day (21/29, 72%): posts appeared in bulk within a one-hour window on 06-15 09:49–10:49 (many just 1 second apart) — clearly automated/bulk listing. Recent intelligence indicates the group has worm-like propagation capability, runs double extortion, and has previously claimed large batches of victims — track closely to see whether it is migrating or dumping backlogged data. Reference: TechCrunch — the worst hacks and breaches of 2026 so far.
- Watched groups collectively quiet: lockbit / akira / qilin and other watchlist groups had 0 posts this batch, in contrast to yesterday (lockbit5's high frequency in the 06-15 batch) — possibly publishing-cadence fluctuation; check tomorrow for a rebound.
- Data limitations: this batch's RansomLook payload lacks victim/sector/geo, so sector-concentration and geographic analysis are not possible; for named victims, fall back to the RSS (
https://www.ransomlook.io/rss.xml) or cross-check with ransomware.live.
Watchlist configuration: intel/ransomware/watchlist.yaml