Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-19
Ransomware·2026-06-19

Ransomware Watch · Jun 19, 2026

Data window: RansomLook /api/posts?days=1, actually covering 2026-06-17T20:46 → 2026-06-18T14:45 UTC (real-time clock lags the report date; roughly an 18-hour window). The API returns only group_name / post_title / discovered, with no sector/geo fields — sector/geography is inferred manually from victim names.

Overview

  • Total new posts: 67
  • Groups involved: 11
  • Watchlist hits: ~42(driven up mainly by lockbit5's massive bulk dump)
  • Top 3 most active groups: lockbit5 (34) · the gentlemen (12) · safepay (5)

Watchlist Hits (read first)

GroupVictimSector (inferred)GeoHit
inc ransomHorizon Family Medical GroupHealthcareUSgroup:inc · sector:medical
shinyhuntersAmazon-owned OneMedical.comHealthcareUSsector:medical
shinyhuntersNAIC.org (National Association of Insurance Commissioners)Finance/regulatoryUSsector:financial (editorial judgment)
inc ransomneuwoges.de (housing)Real estateDEgroup:inc
lockbit5delano.k12.mn.usEducation, K-12USgroup:lockbit · geo:us
lockbit5saude.mt.gov.brHealthcare/governmentBRgroup:lockbit
lockbit5eternal.hk—HKgroup:lockbit · geo:hk
lockbit5comta.com.tw—TWgroup:lockbit · geo:tw
lockbit5parkviewtaipei.comHospitalityTW (Taipei)group:lockbit
akiraApptricity (logistics/supply-chain software)LogisticsUSgroup:akira
akiraBerg LillyLegalUSgroup:akira
playeurOptimum / Integrated Technologies / Greg CrosslinMixedEU/USgroup:play
ransomhousePrince George CountyGovernmentUSsector:government (editorial judgment)

Note: lockbit5 dumped 34 victims in a single batch, including multiple Asia-Pacific (.tw/.hk/.th/.jp) and Latin American (.br/.co/.mx/.hn) targets; the table above lists representative hits only.

All New Posts (aggregated by group)

GroupCountRepresentative victims
lockbit534majorcineplex.com, daikyonishikawa.co.jp, saude.mt.gov.br, delano.k12.mn.us, eternal.hk, comta.com.tw, elematic.com …
the gentlemen12SGS Malaysia, Al Khaja Holding, Cofaq, Sertrans, Yudu Technology, TERRIO Therapy Fitness …
safepay5harcourts.net, gut-heckenhof.de, zaunsysteme.de, brscappuccio.it, seinordovest.it
play3eurOptimum, Integrated Technologies, Greg Crosslin
lynx3wolfconstruction.net, eastersealsia.org, someco.com
inc ransom2Horizon Family Medical Group, neuwoges.de
shinyhunters2NAIC.org, Amazon-owned OneMedical.com
genesis2ABC of Indiana/Kentucky, United Personnel (Masis Staffing)
akira2Apptricity, Berg Lilly
lamashtu1Great Foods
ransomhouse1Prince George County

Anomalies / Trend Notes

  • lockbit5 massive bulk dump: 34 victims published at once within a single time slot (06-18 12:40–12:41 UTC), with highly dispersed geography (Asia-Pacific, Latin America, Europe, North America) — consistent with LockBit's usual "bulk-list old inventory" playbook after resurfacing; be wary of the data's authenticity and potential reuse.
  • "the gentlemen" remains highly prolific(12 posts), extending yesterday's assessment of it as the second-most-active group by victim count; this batch includes SGS Malaysia and other well-known multinational testing/certification organizations.
  • shinyhunters targets high-value victims: simultaneously claims NAIC.org(National Association of Insurance Commissioners) and Amazon-owned One Medical(healthcare), continuing its large-scale data-extortion trajectory.
  • Healthcare in the crosshairs again: inc ransom (Horizon Family Medical) + shinyhunters (One Medical) + lockbit5 (saude.mt.gov.br) — multiple groups hit healthcare/health targets on the same day.
  • New/rare group names: lamashtu, genesis, and lynx appear at low frequency; keep observing to determine whether any are rebrands.
← Prev
Ransomware Watch · Jun 18, 2026
Next →
Ransomware Watch · Jun 20, 2026