Ransomware Watch · Jul 15, 2026
⚠️ The RansomLook API (
/api/posts?days=1) and its RSS feed were both unreachable from the runner today (sandbox network restrictions; 403 tunnel). This page is compiled from public reporting rather than a structured RansomLook pull; per-victim detail will be backfilled once access is restored.
Overview
- Data source: public reporting (direct RansomLook connection failed)
- Watchlist hits: Qilin, Akira, LockBit (groups); healthcare / energy / manufacturing (sectors); us (geo)
- Overall tone: Qilin still leading, with The Gentlemen rising into the top tier
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Inter Power Engineering | energy/engineering | US | group:qilin, sector:energy | ransomware.live |
| Qilin | Shuttle Meadow Country Club | hospitality | US | group:qilin | ransomware.live |
| Akira | Transworld Signs | manufacturing | US | group:akira, sector:manufacturing | ransomware.live |
All New Posts (per public reporting)
| Group | Victim / development | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| The Gentlemen | ~18 victims claimed within 24h | tech/software, construction | Multiple countries | 07-10 | PurpleOps |
| Qilin | 7 victims claimed within 24h | Mixed | Multiple countries | 07-09 | ransomware.live |
| Qilin | Inter Power Engineering | energy/engineering | US | 07-09 | ransomware.live |
| Qilin | Shuttle Meadow Country Club | hospitality | US | 07-13 | ransomware.live |
| Akira | Transworld Signs (estimated attack date 07-10) | manufacturing | US | 07-13 | ransomware.live |
Trend Notes
- Qilin's dominance is stable: roughly 1,500–1,870 victims listed over the past 12 months, far ahead of Akira (~1,205).
- The Gentlemen moving up: in Q1 2026, together with Qilin / LockBit / Akira, the four accounted for roughly 41% of all victims; the single-day burst of 18 is worth watching.
- SafePay volatility: previously dropped 77% at one point (97 → 22), with intermittent leak-site silence; watch the cadence of any restart.
- Sector concentration: US organizations make up the largest share; energy/engineering, manufacturing, construction, tech and healthcare are the most frequently hit.
Watchlist configuration lives in intel/ransomware/watchlist.yaml; this page will be backfilled with per-victim entries once structured pulls are restored.