Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-02
Ransomware·2026-07-02

Ransomware Watch · Jul 2, 2026

⚠️ RansomLook api/posts?days=1 returned an empty body from the sandbox (a fourth consecutive day with no new API data; sandbox network access is restricted). The data below was cross-checked against open reporting from ransomware.live and is centred on items discovered/published 2026-06-30.

Overview

  • New posts (visible via cross-checking): roughly 5-6
  • Groups involved: The Gentlemen, Brain Cipher, Anubis, Blackfield
  • Watchlist hits: 1 (Horizon Eye Care — healthcare / US)

Watchlist Hits (read these first)

GroupVictimSectorGeoHitLink
Horizon Eye CareHorizon Eye CarehealthcareUSsector:healthcare, geo:usransomware.live
BlackfieldNidec CorporationmanufacturingJPsector:manufacturing, kw:double extortionransomware.live

Note: Nidec does not directly match a highlighted group name on the watchlist, but it hits sector:manufacturing and is a major double-extortion case (a $2M ransom demand), so it has been pinned manually.

All New Posts (from 2026-06-30)

GroupVictimSectorGeoDiscoveredLink
The GentlemenPou Sheng International (Nike/adidas/PUMA distribution)retail / distributionTW/HK2026-06-30ransomware.live
The GentlemenSDEZ (textile rental / workwear / hygiene supplies)servicesFR2026-06-30ransomware.live
Brain CipherPAI Pharmapharma / healthcareUS2026-06-30ransomware.live
AnubisESMS Global LimitedservicesUK2026-06-30ransomware.live
— (attack)Horizon Eye CarehealthcareUS2026-06-30 (disclosed 07-01)ransomware.live
BlackfieldNidec CorporationmanufacturingJPreported 2026-07-01, $2M ransom demandBleepingComputer

Anomalies / Trend Notes

  • The Gentlemen stays highly active: continuing yesterday's assessment that it is "climbing to #2 by victim count", the group added 2 more today (including Pou Sheng, a Nike/adidas/PUMA distributor); the retail/distribution supply chain warrants attention.
  • Healthcare hit again: Horizon Eye Care (ophthalmology) plus PAI Pharma (pharmaceuticals) — two hits on the watchlist's healthcare category today.
  • Blackfield demands $2M from Nidec: a major Japanese manufacturer, double extortion, and the largest single known ransom demand in this edition.
  • Data availability note: the RansomLook API has been unavailable for 4 consecutive days. Recommend connecting to the API or RSS directly from a local terminal for cross-validation, rather than relying on open-source reporting alone over the long run.

Sources: RansomLook (api/rss, unavailable this edition) plus ransomware.live cross-checking; watchlist: see intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 1, 2026
Next →
Ransomware Watch · Jul 3, 2026