Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-23
Ransomware·2026-06-23

Ransomware Watch · Jun 23, 2026

Data source: RansomLook /api/posts?days=1 (public endpoint, direct connection succeeded).
⚠️ All 6 posts returned by the API this issue were discovered on 2026-06-20 / 06-21, fully overlapping yesterday's 2026-06-22 brief — there were no net-new posts within the past 24h (06-22 → 06-23) window. The RansomLook days=1 endpoint did not advance this round and is still replaying the previous batch. Following the "never pass off repeats as new" principle, these 6 entries are not counted as new disclosures this issue and are kept for continuity observation only.

Overview

  • Net-new posts in the past 24h (06-22 → 06-23): 0
  • Old posts replayed by the API: 6 (4 groups, all already covered in the 06-22 brief: nova ×2, inc ransom ×2, icarus ×1, nightspire ×1)
  • Watchlist hits: 0 new (the inc ransom ×2 in the old batch were recorded yesterday)

Recent Disclosures

GroupVictimSectorGeoHitDiscoveredStatus
——————No net-new posts in the past 24h

Continuity Watch (old batch, recorded on 06-22, outside the 24h window)

GroupVictimSectorGeoDiscovered
icarusDEADLINE MONDAY (countdown post)——2026-06-20
inc ransomNewspaper Media GroupMedia/publishing 📰—2026-06-20
novaNhà Thành PhốReal estate/constructionVN2026-06-21
nightspireArtistic SmilesHealthcare/dental 🩺—2026-06-21
novaLockers ITIT services—2026-06-21
inc ransomjktornelGeneral business—2026-06-21

Anomalies / Trend Notes

  • API stall signal: RansomLook days=1has returned the same 06-20/06-21 batch for two consecutive days without advancing. This may be upstream aggregation lag or simply no leak-site updates this cycle; tomorrow, watch for a one-time backfill of multiple days of backlog.
  • icarus still worth watching: the "DEADLINE MONDAY" countdown post recorded last issue is still up, and icarus has meanwhile been linked to the Klue.com OAuth token theft incident(see the threat-intelligence section of the main brief) — the group is expanding from leak-site listings into SaaS supply-chain extortion, with rising activity.
  • Watchlist groups (inc / nova, etc.) made no new moves in this 24h window.
← Prev
Ransomware Watch · Jun 22, 2026
Next →
Ransomware Watch · Jun 24, 2026