Ransomware Watch · Jul 8, 2026
⚠️ RansomLook
api/posts?days=1and RSS were both unreachable from the sandbox in this run (Tunnel 403). Data on this page comes from public threat-intel / breach aggregation (WebSearch) and represents disclosure claims, not independent verification. The usual poisoning/exaggeration risks apply; cross-validate victim notification status and actual leak evidence.
Overview
- New disclosure posts in this window (aggregate estimate): ~10
- Groups involved: ≥7 (TheGentlemen, BlackField, Krybit, Wallstreet, PEAR, Genesis, Bashe, Payload, etc.)
- Watchlist hits: 4 (healthcare / insurance-financial / manufacturing)
Watchlist Hits (Priority)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| TheGentlemen | Arabia Falcon Insurance Company | Insurance / Financial | ME | sector:financial | breach roundup |
| Wallstreet | Asisken (medical assistance) | Healthcare / Medical | — | sector:medical | breach roundup |
| BlackField | Nidec | Manufacturing | JP | sector:manufacturing | The Hacker News |
| Krybit | Ford Motor Company | Manufacturing / Auto | US | sector:manufacturing, geo:us | breach roundup |
All New Posts (aggregated, not individually verified)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| PEAR | AC Beverage | Food & Beverage | — | 2026-07-06 | roundup |
| Bashe | Ahmet Aydeniz Group | Manufacturing/Industrial | TR | 2026-07-06 | roundup |
| Genesis | Apex Agro LLC | Agriculture | — | 2026-07-06 | roundup |
| TheGentlemen | Arabia Falcon Insurance Company | Insurance | ME | 2026-07-06 | roundup |
| Wallstreet | Asisken | Healthcare | — | 2026-07-06 | roundup |
| Payload | ENB Versich | Insurance | DE | 2026-07-05 | roundup |
| BlackField | Nidec | Manufacturing | JP | ~2026-07 | THN |
| Krybit | Ford Motor Company | Automotive | US | ~2026-07 | roundup |
Anomalies / Trend Notes
- TheGentlemen's growth curve is record-setting: Halcyon assesses that the victims it listed in its first five months match what took Akira 12 months and Qilin 18 months; formerly the Qilin affiliate ArmCorp, it went independent in 2025-07 after a profit-sharing dispute. Momentum remains high — an insurance-sector victim added today.
- First AI-driven extortion case(see AI Security in the main brief): JADEPUFFER, documented by Sysdig, is the first database extortion executed end-to-end by an autonomous LLM agent; the key never touched disk, so recovery is impossible even after payment — the "skill floor" for extortion has been pushed down to the cost of running an agent.
- Japanese manufacturing / key enterprises under concentrated pressure: Nidec (claimed by BlackField), Aflac, Sapporo, and KDDI disclosed or investigated security incidents in this window.
- Q1 2026 most-active baseline: Qilin 338, Akira 197, The Gentlemen 192, INC, Cl0p (Check Point).