Ransomware Watch · Jul 6, 2026
⚠️ Data source degradation notice: Today RansomLook
/api/posts?days=1returned HTTP 403 (tunnel forbidden) from the sandbox egress, so structured API data could not be retrieved. This page is instead assembled from open-source disclosure reporting (WebSearch results from public mirrors such as Ransomware.live / Breachsense), covering new disclosures on Jul 3–4; field completeness is lower than the API. Re-verify against the ransomlook.io website the next day.
Overview
- Coverage window: 2026-07-03 ~ 07-04 (open-source disclosure basis)
- Active groups observed: ≥5 (qilin, inc_ransom, anubis, bashe, krybit)
- Watchlist hits: multiple (group qilin + healthcare / logistics / government sectors)
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Discovered |
|---|---|---|---|---|---|
| qilin | Chemco | Manufacturing/Chemicals | — | group:qilin · sector:manufacturing | 2026-07 |
| inc_ransom | City of Acworth, Georgia | Government (municipal) | US | sector:government · geo:us | 2026-07-03 |
| inc_ransom | Carvalima Transportes | Logistics/Transport | BR | sector:logistics | 2026-07-03 |
| anubis | Quest Healthcare Solutions | Healthcare (staffing) | — | sector:healthcare | 2026-07-03 |
All New Posts (open-source disclosure basis; fields may be incomplete)
| Group | Victim | Sector | Geo | Discovered |
|---|---|---|---|---|
| qilin | Chemco | Manufacturing/Chemicals | — | 2026-07 |
| inc_ransom | City of Acworth, Georgia | Government | US | 2026-07-03 |
| inc_ransom | Carvalima Transportes | Logistics/Transport | BR | 2026-07-03 |
| anubis | Ferrum Group | Manufacturing (industrial) | — | 2026-07-03 |
| anubis | Quest Healthcare Solutions | Healthcare | — | 2026-07-03 |
| bashe | Flazio | SaaS/Tech | IT | 2026-07-03 |
| krybit | Ford Motor Company (listed on leak forum) | Automotive | US | 2026-07 |
Anomalies / Trend Notes
- Qilin remains the main storyline: it carries the Check Point VPN zero-day (CVE-2026-50751) attribution while continuing to add victims to its leak site, consistent with the Q1 2026 figures of "338 victims, most active group in the industry."
- INC_RANSOM hits two sensitive categories: a municipal government (Acworth, Georgia, US) plus logistics/transport, matching its profile of favoring public-sector / critical-infrastructure-adjacent targets.
- ANUBIS on two fronts: industrial manufacturing + healthcare staffing; healthcare remains a target with high willingness to pay.
- Krybit listed Ford on a leak forum: big-brand listings require careful verification (a forum listing ≠ confirmed intrusion/encryption); cross-validate before assigning severity.
- Data-pipeline note: this API degradation exposed the dependence on a single RansomLook egress; if 403s recur, consider enabling the
ransomware.livefallback source (already configured but disabled insources.yaml) for cross-validation.
This page is an open-source patchwork edition for an API-degraded day; field completeness and dedup reliability are below a normal API day. Re-check against the RansomLook website the next day.