Ransomware Watch · Jun 26, 2026
Data source: RansomLook
/api/posts?days=1. ⚠️ This run returned the same window as 2026-06-25 (latest post timestamp 2026-06-25T00:22, no newer posts). The tables below overlap with yesterday's and are retained only for a complete archive.
Overview
- Total new posts: 28
- Groups involved: 7 (the gentlemen, nova, stormous, akira, qilin, inc ransom, anubis)
- Watchlist hits: 6 (akira ×2, qilin, inc ransom; anubis=healthcare and CHIFENG=China are contextual judgements)
Watchlist Hits (read these first)
| Group | Victim | Sector | Geo | Hit | Discovered |
|---|---|---|---|---|---|
| akira | Miami Machine | manufacturing | US | group:akira | 06-24T14:51 |
| akira | Jit Ex | logistics? | — | group:akira | 06-24T15:53 |
| qilin | Cash Canada | financial | CA | group:qilin | 06-24T13:51 |
| inc ransom | horizoneye.com | — | — | group:inc | 06-24T15:53 |
| anubis | Quest Health Solutions | healthcare | US | sector:healthcare (contextual) | 06-25T00:22 |
| the gentlemen | CHIFENG GOLD SEPON | mining | CN | geo:china (contextual) | 06-24T13:48 |
All New Posts
| Group | Victim | Discovered |
|---|---|---|
| nova | lpgroup.pt | 06-24T11:50 |
| the gentlemen | Meccanica Gn | 06-24T13:28 |
| the gentlemen | Gegenbauer Elektrotechnik | 06-24T13:38 |
| the gentlemen | Stadttheater Giessen | 06-24T13:38 |
| the gentlemen | BDS CZ | 06-24T13:38 |
| the gentlemen | Beran Concrete | 06-24T13:38 |
| the gentlemen | Al Dhow Group | 06-24T13:38 |
| the gentlemen | Natren | 06-24T13:48 |
| the gentlemen | CHIFENG GOLD SEPON | 06-24T13:48 |
| the gentlemen | Bell Hardware | 06-24T13:48 |
| the gentlemen | Plateau Excavation | 06-24T13:48 |
| nova | alejandria.biz | 06-24T13:51 |
| qilin | Cash Canada | 06-24T13:51 |
| the gentlemen | Au Vieux Campeur | 06-24T14:30 |
| akira | Miami Machine | 06-24T14:51 |
| nova | transvill.com.pe | 06-24T14:51 |
| akira | Jit Ex | 06-24T15:53 |
| inc ransom | horizoneye.com | 06-24T15:53 |
| nova | transvill | 06-24T17:54 |
| nova | alejandria | 06-24T17:54 |
| nova | lpgroup | 06-24T17:54 |
| stormous | impulso-store.com | 06-24T20:52 |
| stormous | montechiaro-store.com | 06-24T20:52 |
| stormous | lorenzoni-store.com | 06-24T20:52 |
| stormous | maglificioliliana.com | 06-24T20:52 |
| stormous | jaggroup.com (UPDATE — full data dump) | 06-24T20:52 |
| stormous | mlit.com.my (UPDATE — full data dump 10GB) | 06-24T20:52 |
| anubis | Quest Health Solutions | 06-25T00:22 |
Anomalies / Trend Notes
- Data did not refresh: the window RansomLook
?days=1returned this run is identical to 2026-06-25, with no post later than 06-25T00:22 — the API-side window has likely not rolled over yet. Tomorrow's run should pick up fresh data. - the gentlemenstill leads with 11 posts in a day, concentrated in manufacturing / construction / retail (mostly EU, plus Kuwait's Al Dhow and China's Chifeng Gold SEPON).
- novashows duplicate postings (transvill / alejandria / lpgroup each posted twice, with and without the domain suffix); the real unique victim count is about 3.
- stormousposted 6 entries, mostly e-commerce sites, 2 of which are "full data dump" updates (jaggroup, mlit.com.my at 10GB).
- anubis → Quest Health Solutionsis a healthcare victim and worth watching (healthcare remains a high-value target).
Watchlist configuration: see intel/ransomware/watchlist.yaml