Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-06
Ransomware·2026-07-06

Ransomware Watch · Jul 6, 2026

⚠️ Data source degradation notice: Today RansomLook /api/posts?days=1 returned HTTP 403 (tunnel forbidden) from the sandbox egress, so structured API data could not be retrieved. This page is instead assembled from open-source disclosure reporting (WebSearch results from public mirrors such as Ransomware.live / Breachsense), covering new disclosures on Jul 3–4; field completeness is lower than the API. Re-verify against the ransomlook.io website the next day.

Overview

  • Coverage window: 2026-07-03 ~ 07-04 (open-source disclosure basis)
  • Active groups observed: ≥5 (qilin, inc_ransom, anubis, bashe, krybit)
  • Watchlist hits: multiple (group qilin + healthcare / logistics / government sectors)

Watchlist Hits (Priority)

GroupVictimSectorGeoHitDiscovered
qilinChemcoManufacturing/Chemicals—group:qilin · sector:manufacturing2026-07
inc_ransomCity of Acworth, GeorgiaGovernment (municipal)USsector:government · geo:us2026-07-03
inc_ransomCarvalima TransportesLogistics/TransportBRsector:logistics2026-07-03
anubisQuest Healthcare SolutionsHealthcare (staffing)—sector:healthcare2026-07-03

All New Posts (open-source disclosure basis; fields may be incomplete)

GroupVictimSectorGeoDiscovered
qilinChemcoManufacturing/Chemicals—2026-07
inc_ransomCity of Acworth, GeorgiaGovernmentUS2026-07-03
inc_ransomCarvalima TransportesLogistics/TransportBR2026-07-03
anubisFerrum GroupManufacturing (industrial)—2026-07-03
anubisQuest Healthcare SolutionsHealthcare—2026-07-03
basheFlazioSaaS/TechIT2026-07-03
krybitFord Motor Company (listed on leak forum)AutomotiveUS2026-07

Anomalies / Trend Notes

  • Qilin remains the main storyline: it carries the Check Point VPN zero-day (CVE-2026-50751) attribution while continuing to add victims to its leak site, consistent with the Q1 2026 figures of "338 victims, most active group in the industry."
  • INC_RANSOM hits two sensitive categories: a municipal government (Acworth, Georgia, US) plus logistics/transport, matching its profile of favoring public-sector / critical-infrastructure-adjacent targets.
  • ANUBIS on two fronts: industrial manufacturing + healthcare staffing; healthcare remains a target with high willingness to pay.
  • Krybit listed Ford on a leak forum: big-brand listings require careful verification (a forum listing ≠ confirmed intrusion/encryption); cross-validate before assigning severity.
  • Data-pipeline note: this API degradation exposed the dependence on a single RansomLook egress; if 403s recur, consider enabling the ransomware.livefallback source (already configured but disabled in sources.yaml) for cross-validation.

This page is an open-source patchwork edition for an API-degraded day; field completeness and dedup reliability are below a normal API day. Re-check against the RansomLook website the next day.

← Prev
Ransomware Watch · Jul 5, 2026
Next →
Ransomware Watch · Jul 7, 2026