Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-16
Ransomware·2026-06-16

Ransomware Watch · Jun 16, 2026

Data source: RansomLook recent-posts API (https://www.ransomlook.io/api/posts?days=1, public endpoint). This batch's discovered timestamps span 2026-06-14T17:45 → 2026-06-15T15:44. The payload contains only group_name + discovered, with no victim / sector / geo fields — so the victim/sector columns below are left empty, and named victims are supplemented from news sources.

Overview

  • Total new posts: 29
  • Groups involved: 5 (the gentlemen, nova, krybit, audit team, bavacai)
  • Watchlist hits: 0 (no lockbit / akira / qilin / play / cl0p / medusa / ransomhub or other watched groups appeared in this batch)

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
— (no hits this batch)—————

All New Posts (aggregated by group, discovered 2026-06-14→15)

GroupPostsVictimSectorGeoDiscovered
the gentlemen21— (not provided by API)——2026-06-15 09:49–14:28
nova4———2026-06-14 17:45 / 06-15 12:46·14:50
krybit2———2026-06-14 22:53 / 06-15 13:44
audit team1———2026-06-15 01:42
bavacai1———2026-06-15 15:44

Anomalies / Trend Notes

  • "the gentlemen" floods the board in a single day (21/29, 72%): posts appeared in bulk within a one-hour window on 06-15 09:49–10:49 (many just 1 second apart) — clearly automated/bulk listing. Recent intelligence indicates the group has worm-like propagation capability, runs double extortion, and has previously claimed large batches of victims — track closely to see whether it is migrating or dumping backlogged data. Reference: TechCrunch — the worst hacks and breaches of 2026 so far.
  • Watched groups collectively quiet: lockbit / akira / qilin and other watchlist groups had 0 posts this batch, in contrast to yesterday (lockbit5's high frequency in the 06-15 batch) — possibly publishing-cadence fluctuation; check tomorrow for a rebound.
  • Data limitations: this batch's RansomLook payload lacks victim/sector/geo, so sector-concentration and geographic analysis are not possible; for named victims, fall back to the RSS (https://www.ransomlook.io/rss.xml) or cross-check with ransomware.live.

Watchlist configuration: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 15, 2026
Next →
Ransomware Watch · Jun 17, 2026