Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-15
Ransomware·2026-07-15

Ransomware Watch · Jul 15, 2026

⚠️ The RansomLook API (/api/posts?days=1) and its RSS feed were both unreachable from the runner today (sandbox network restrictions; 403 tunnel). This page is compiled from public reporting rather than a structured RansomLook pull; per-victim detail will be backfilled once access is restored.

Overview

  • Data source: public reporting (direct RansomLook connection failed)
  • Watchlist hits: Qilin, Akira, LockBit (groups); healthcare / energy / manufacturing (sectors); us (geo)
  • Overall tone: Qilin still leading, with The Gentlemen rising into the top tier

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
QilinInter Power Engineeringenergy/engineeringUSgroup:qilin, sector:energyransomware.live
QilinShuttle Meadow Country ClubhospitalityUSgroup:qilinransomware.live
AkiraTransworld SignsmanufacturingUSgroup:akira, sector:manufacturingransomware.live

All New Posts (per public reporting)

GroupVictim / developmentSectorGeoDiscoveredLink
The Gentlemen~18 victims claimed within 24htech/software, constructionMultiple countries07-10PurpleOps
Qilin7 victims claimed within 24hMixedMultiple countries07-09ransomware.live
QilinInter Power Engineeringenergy/engineeringUS07-09ransomware.live
QilinShuttle Meadow Country ClubhospitalityUS07-13ransomware.live
AkiraTransworld Signs (estimated attack date 07-10)manufacturingUS07-13ransomware.live

Trend Notes

  • Qilin's dominance is stable: roughly 1,500–1,870 victims listed over the past 12 months, far ahead of Akira (~1,205).
  • The Gentlemen moving up: in Q1 2026, together with Qilin / LockBit / Akira, the four accounted for roughly 41% of all victims; the single-day burst of 18 is worth watching.
  • SafePay volatility: previously dropped 77% at one point (97 → 22), with intermittent leak-site silence; watch the cadence of any restart.
  • Sector concentration: US organizations make up the largest share; energy/engineering, manufacturing, construction, tech and healthcare are the most frequently hit.

Watchlist configuration lives in intel/ransomware/watchlist.yaml; this page will be backfilled with per-victim entries once structured pulls are restored.

← Prev
Ransomware Watch · Jul 14, 2026
Next →
Ransomware Watch · Jul 16, 2026