Ransomware Watch · Jun 21, 2026
Data source: RansomLook
/api/posts?days=1(public endpoint). Window covers the past ~24h (discovered 2026-06-18 → 2026-06-19).
⚠️ Deduplication note: this API window fully overlaps the 2026-06-20 brief (server-side UTC was still 06-20), so there are no net-new posts relative to the previous issue. Below is the current snapshot, kept for archival continuity; every entry already appeared on 06-20, and the "Trend Notes" section only adds cross-day observations.
Overview
- Total new posts: 13 (net-new relative to the 06-20 brief: 0)
- Groups involved: 9 (qilin ×3, aurora ×2, nightspire ×2, all others ×1)
- Watchlist hits: 3 (all from the qilingroup; watchlist-group hits)
- Top 3 most active groups: qilin(3), aurora(2), nightspire(2)
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Discovered |
|---|---|---|---|---|---|
| qilin | Homes By J Anthony | Construction/home building | — | group:qilin | 2026-06-18 |
| qilin | ATCOM Outsourcing | IT/outsourcing | — | group:qilin | 2026-06-18 |
| qilin | THL Project Management Sdn. Bhd. | Engineering/project management | MY | group:qilin | 2026-06-18 |
qilin remains the only watchlist group on the board, continuing its high-activity streak of 2025–2026; opportunistic attacks with no clear sector preference.
All New Posts
| Group | Victim | Sector | Geo | Discovered |
|---|---|---|---|---|
| qilin | Homes By J Anthony | Construction/home building | — | 2026-06-18 |
| qilin | ATCOM Outsourcing | IT/outsourcing | — | 2026-06-18 |
| qilin | THL Project Management Sdn. Bhd. | Engineering/project management | MY | 2026-06-18 |
| cloak | ra-vogeler.de | General business | DE | 2026-06-18 |
| nightspire | dean cosmetic dentistry | Healthcare/dental 🩺 | — | 2026-06-18 |
| nightspire | legendsmn (Blue Ox / Paul Bunyan / Lumberjack Electric) | Electric power/utilities ⚡ | US | 2026-06-18 |
| shinyhunters | icsecurity.com | Security services | — | 2026-06-19 |
| aurora | ALS Global | Testing/certification | — | 2026-06-19 |
| icarus | Klue.com | SaaS/competitive intelligence | — | 2026-06-19 |
| anubis | KTR Real Estate Advisors | Real estate | — | 2026-06-19 |
| pear | Optimum First Mortgage | Finance/mortgage 💰 | US | 2026-06-19 |
| aurora | Hagerman & Company | IT services | — | 2026-06-19 |
| nova | Desert Micro | IT/electronics | US | 2026-06-19 |
🩺/⚡/💰 = sector-sensitive (healthcare / utilities / finance); not a literal watchlist keyword hit, but high-attention sectors, flagged manually.
Anomalies / Trend Notes
- No net-new posts this issue: the RansomLook days=1 window overlaps the previous issue; tomorrow, consider a wider window (
days=2) or fetching after the UTC day rolls over, to avoid two consecutive issues repeating the same victim batch. - icarus × Klue.com ties into threat intel: this batch's
icaruslisting of Klue.com is the same event as "Klue OAuth leak → Icarus extorting/leaking Salesforce CRM data" in this issue's main-brief threat-intelligence section — a SaaS supply-chain + double-extortion pattern worth tracking separately. - Sector-sensitive hits: a dental clinic (dean cosmetic dentistry), an electric utility (Lumberjack Electric), and a mortgage lender (Optimum First Mortgage), 1 each — healthcare, utilities, and finance were all named; isolated cases, not yet a cluster.
- Geography: identifiable geography is mostly US, plus DE and MY with 1 each; no CN/HK/TW/SG hits.