Ransomware Watch · Jul 9, 2026
⚠️ Data source note: in this run the RansomLook API (
/api/posts?days=1) was unreachable (sandbox egress blocked, curl exit 56), and the RSS fallback did not yield per-post data either. The tables below are an aggregate picture based on public reporting, not same-day real-time victim details. Per-item details will be backfilled once the API recovers.
Overview
- Same-day per-post details: unavailable(source degraded)
- Landscape (past 30 days, public reporting): Qilin most active, Akira second, RansomHub third
- Watchlist hits (by group/sector): Qilin, Akira, and RansomHub are all on the watchlist; healthcare / critical infrastructure highlighted on the sector side
Watchlist Hits (landscape-level, not per-post)
| Group | Notes | Sector focus | Hit | Source |
|---|---|---|---|---|
| Qilin | Most active of 2026, ~1,871 cumulative victims; frequently ranks first worldwide in weekly new victims | healthcare / critical-infra | group:qilin, sector:healthcare | Barracuda |
| Akira | Second worldwide, ~1,357 cumulative victims | manufacturing / general | group:akira | CybelAngel |
| RansomHub | ~842 cumulative victims | general | group:ransomhub | SOCRadar |
All New Posts
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| — | Per-item details unavailable (RansomLook source degraded) | — | — | 2026-07-09 | ransomware.live |
Around Jul 7 new victims were listed by Qilin, Akira, and other groups (multi-source reporting), but structured per-item data could not be pulled from the API this run, so they are not listed individually to avoid errors.
Anomalies / Trend Notes
- Qilin's dominance continues: after RansomHub's contraction, Qilin absorbed much of the affiliate traffic and keeps leading weekly new-victim counts; healthcare and public services are its high-risk targets (including the patient harm caused by the earlier London healthcare incident).
- Initial access coupled to KEV: in-the-wild exploitation of SharePoint CVE-2026-45659 has been observed for initial access followed by ransomware/tool deployment — the linkage between the vulnerability side and the ransomware side is worth continued tracking.
- Data-source resilience: this repo needs a stable fallback for when direct RansomLook access is unavailable (RSS / mirrors / ransomware.live cross-checks); recommend verifying API reachability first on the next run.
Watchlist config: intel/ransomware/watchlist.yaml