Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-26
Ransomware·2026-06-26

Ransomware Watch · Jun 26, 2026

Data source: RansomLook /api/posts?days=1. ⚠️ This run returned the same window as 2026-06-25 (latest post timestamp 2026-06-25T00:22, no newer posts). The tables below overlap with yesterday's and are retained only for a complete archive.

Overview

  • Total new posts: 28
  • Groups involved: 7 (the gentlemen, nova, stormous, akira, qilin, inc ransom, anubis)
  • Watchlist hits: 6 (akira ×2, qilin, inc ransom; anubis=healthcare and CHIFENG=China are contextual judgements)

Watchlist Hits (read these first)

GroupVictimSectorGeoHitDiscovered
akiraMiami MachinemanufacturingUSgroup:akira06-24T14:51
akiraJit Exlogistics?—group:akira06-24T15:53
qilinCash CanadafinancialCAgroup:qilin06-24T13:51
inc ransomhorizoneye.com——group:inc06-24T15:53
anubisQuest Health SolutionshealthcareUSsector:healthcare (contextual)06-25T00:22
the gentlemenCHIFENG GOLD SEPONminingCNgeo:china (contextual)06-24T13:48

All New Posts

GroupVictimDiscovered
novalpgroup.pt06-24T11:50
the gentlemenMeccanica Gn06-24T13:28
the gentlemenGegenbauer Elektrotechnik06-24T13:38
the gentlemenStadttheater Giessen06-24T13:38
the gentlemenBDS CZ06-24T13:38
the gentlemenBeran Concrete06-24T13:38
the gentlemenAl Dhow Group06-24T13:38
the gentlemenNatren06-24T13:48
the gentlemenCHIFENG GOLD SEPON06-24T13:48
the gentlemenBell Hardware06-24T13:48
the gentlemenPlateau Excavation06-24T13:48
novaalejandria.biz06-24T13:51
qilinCash Canada06-24T13:51
the gentlemenAu Vieux Campeur06-24T14:30
akiraMiami Machine06-24T14:51
novatransvill.com.pe06-24T14:51
akiraJit Ex06-24T15:53
inc ransomhorizoneye.com06-24T15:53
novatransvill06-24T17:54
novaalejandria06-24T17:54
novalpgroup06-24T17:54
stormousimpulso-store.com06-24T20:52
stormousmontechiaro-store.com06-24T20:52
stormouslorenzoni-store.com06-24T20:52
stormousmaglificioliliana.com06-24T20:52
stormousjaggroup.com (UPDATE — full data dump)06-24T20:52
stormousmlit.com.my (UPDATE — full data dump 10GB)06-24T20:52
anubisQuest Health Solutions06-25T00:22

Anomalies / Trend Notes

  • Data did not refresh: the window RansomLook ?days=1returned this run is identical to 2026-06-25, with no post later than 06-25T00:22 — the API-side window has likely not rolled over yet. Tomorrow's run should pick up fresh data.
  • the gentlemenstill leads with 11 posts in a day, concentrated in manufacturing / construction / retail (mostly EU, plus Kuwait's Al Dhow and China's Chifeng Gold SEPON).
  • novashows duplicate postings (transvill / alejandria / lpgroup each posted twice, with and without the domain suffix); the real unique victim count is about 3.
  • stormousposted 6 entries, mostly e-commerce sites, 2 of which are "full data dump" updates (jaggroup, mlit.com.my at 10GB).
  • anubis → Quest Health Solutionsis a healthcare victim and worth watching (healthcare remains a high-value target).

Watchlist configuration: see intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 25, 2026
Next →
Ransomware Watch · Jun 27, 2026