Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-12
Ransomware·2026-07-12

Ransomware Watch · Jul 12, 2026

Source: RansomLook Recent Posts API (?days=1) · Window approx. the past 24–48h (covering new disclosures from Jul 10 – Jul 11)

Overview

  • Total new posts: 16
  • Groups involved: 7 (akira, blackwater, gunra, interlock, payload, qilin, cmd organization)
  • Watchlist hits: 9 (qilin ×8, akira ×1)
  • Most active group: Qilin (8 posts, half the total), followed by gunra (3)

Watchlist Hits (read first)

GroupVictimSectorGeoHitDiscovered
qilinNavana Real EstateReal estate—group:qilin2026-07-10
qilinPromotora ZacapuReal estate / developmentMXgroup:qilin2026-07-10
qilinHilo——group:qilin2026-07-10
qilinRed Planet HotelsHospitalityAPACgroup:qilin2026-07-10
qilinCRZ ConstruccionesConstruction—group:qilin2026-07-10
qilinGlobal Strategic Business Process SolutionsBPO—group:qilin2026-07-10
qilinSPACElogicBuilding systems integrationSG?group:qilin2026-07-10
qilinEurodefiFinance / insurance—group:qilin2026-07-10
akiraVandalia RentalEquipment rentalUSgroup:akira2026-07-10

All New Posts

GroupVictimSectorDiscovered
akiraVandalia RentalEquipment rental2026-07-10
blackwatertxdkj.com—2026-07-10
gunraYuditec S.A.—2026-07-10
gunraon-us—2026-07-10
gunraPirámide SegurosInsurance2026-07-10
interlockBorger ISDEducation (K-12 school district)2026-07-10
payloadRoofinoxManufacturing (stainless steel)2026-07-10
qilinNavana Real EstateReal estate2026-07-10
qilinPromotora ZacapuReal estate / development2026-07-10
qilinHilo—2026-07-10
qilinRed Planet HotelsHospitality2026-07-10
qilinCRZ ConstruccionesConstruction2026-07-10
qilinGlobal Strategic Business Process SolutionsBPO2026-07-10
qilinSPACElogicBuilding systems integration2026-07-10
qilinEurodefiFinance / insurance2026-07-10
cmd organizationGolden Star ResourcesMining2026-07-11

Anomalies / Trend Notes

  • Qilin single-day burst: eight victims posted at once, spanning real estate, hospitality, construction, BPO and finance, and geographically dispersed (LATAM + APAC). This continues the group's high output over recent months and is the focus of this workbench's watchlist.
  • Interlock hits education: Borger ISD (an independent school district in Texas, US) — education remains a high-frequency ransomware target and warrants its own line.
  • New faces: blackwater, gunra, payloadand cmd organizationappear infrequently in recent data; watch whether they are new groups or rebrands (especially gunra, with 3 posts in a single day).
  • Off-leak-site events (media-reported, not necessarily in RansomLook's main table): Deutsche Bank was claimed as a victim by the "unsafe" group (the bank denies its corporate network was breached); Accenture was claimed by threat actor "888" to have had 35GB of source code plus cloud keys stolen (Accenture confirmed an intrusion the following day, said it had been remediated, and reported no operational impact).
← Prev
Ransomware Watch · Jul 10, 2026
Next →
Ransomware Watch · Jul 13, 2026