Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-16
Ransomware·2026-07-16

Ransomware Watch · Jul 16, 2026

Data source: RansomLook /api/posts?days=1 (this run returned successfully, covering all of 2026-07-15 UTC)
ℹ️ This endpoint returns only three fields — group_name / post_title / discovered — with no sector, geo or link. The Sector and Geo columns below are analyst inferences from the victim names, not source-provided data; do not treat them as authoritative fields.

Overview

  • Total new posts: 19
  • Groups involved: 10
  • Watchlist hits (strict literal matching): 4

Counts by group: dragonforce 5 · qilin 3 · ailock 3 · pear 2 · black x 1 · coinbase cartel 1 · akira 1 · leaknet 1 · shinyhunters 1 · ransomhouse 1

Watchlist Hits (read first)

Matched strictly against the groups list in watchlist.yaml (qilin and akira hit; the other groups are not on the list).

GroupVictimSector (inferred)Geo (inferred)HitDiscovered (UTC)
qilinLevin FurnitureRetail / furnitureUSgroup:qilin2026-07-15 07:55
qilinFeliubadalóLegal (law firm)ESgroup:qilin2026-07-15 10:55
qilinDanone (International Delights)Food & beverageFR / USgroup:qilin2026-07-15 20:50
akiraPioneer ConstructionConstructionUSgroup:akira2026-07-15 15:53

⚠️ Note on watchlist matching semantics: the playbook's matching logic performs a lowercase substring match against group_name + post_title. This produces two known problems, handled here by analyst judgment:

  1. Sector under-reporting: South Plains Rural Health Servicesand Carient Heart & Vascularare in fact healthcare organizations, but the watchlist lists healthcare/ medical/ hospital, which do not match literally → they are excluded from the table above. See "Analyst Additions" below.
  2. Geo false positives: usas a substring matches any word containing "us", such as Hughesor Isegen. Geo substring matching was notenabled for this edition; all Geo values are manual inferences.

All New Posts

GroupVictimSector (inferred)Geo (inferred)Discovered (UTC)
black xsanaa.centerThink tank / research (Sana'a Center)YE2026-07-15 05:59
qilinLevin FurnitureRetail / furnitureUS2026-07-15 07:55
qilinFeliubadalóLegalES2026-07-15 10:55
ailockFerrovialConstruction / infrastructureES2026-07-15 11:53
ailockSolid Advance Inc.Unknown—2026-07-15 11:53
ailockNihon Kotsu Co., Ltd.Transport / taxiJP2026-07-15 11:54
coinbase cartelPanasonicAeroAvionicsJP / US2026-07-15 11:54
pearSouth Plains Rural Health Services, Inc.HealthcareUS2026-07-15 13:52
pearCarient Heart & VascularHealthcare (cardiovascular)US2026-07-15 13:52
akiraPioneer ConstructionConstructionUS2026-07-15 15:53
dragonforceStephens PrecisionPrecision manufacturingUS2026-07-15 15:53
dragonforceShillen Mackall & SeldonLegalUS2026-07-15 15:53
dragonforceHughes Atwood & Mullaly pllcLegalUS2026-07-15 15:53
dragonforceIsegen South Africa (Pty) LtdChemicalsZA2026-07-15 15:53
leaknetAnglo Belgian Corp (claims 6TB of submarine / nuclear plant blueprints)Defense / marine enginesBE2026-07-15 15:53
dragonforceHeritage Mechanical LLCMechanical & electrical engineeringUS

Analyst Additions (beyond literal watchlist matching)

  • Four healthcare cases in a single day: pearposted South Plains Rural Health Services and Carient Heart & Vascular at once; shinyhuntersclaimed Abbott-owned Exact Sciences (genetic testing, holding highly sensitive health data). Judged by the watchlist's healthcareintent rather than its literal string, healthcare was the most concentrated sector of the day — recommend adding word stems such as health/ heart/ vascular/ clinicto the watchlist's sectors, or under-reporting will continue.
  • dragonforce posted 5 in one day, 3 of them small-to-midsize US law firms and engineering companies: the classic "bulk SMB targeting" cadence, consistent with its recent trajectory.
  • leaknet — Anglo Belgian Corp: claims 6TB including submarine and nuclear plant blueprints; if accurate, this would be a NATO supply-chain-sensitive event. Note: this is the attacker's own claim and is unverified— leak-site claims about data volume and content are frequently exaggerated.
  • Group names appearing in this database for the first time: ailock, pear, black x, coinbase carteland leaknetare all absent from the watchlist. Of these, coinbase carteland leaknethave a "branded/provocative" naming style; worth watching whether they are rebrands of existing groups.

Anomalies / Trend Notes

  • Data availability is itself today's biggest change: yesterday's brief (2026-07-15) recorded RansomLook as unreachable from the runner, forcing a roundup assembled from public reporting; this run connected to the API directly and succeeded(web_fetchvia the provenance allowlist). Today is the first ransomware daily in recent memory built on structured raw data.
  • Qilin is still on the board but no longer dominant on its own: today dragonforce (5) > qilin (3) = ailock (3). A single day's sample is not enough to assert a trend; recorded for the record only.
  • Watchlist coverage is low: only 4 of 19 posts matched (21%), mainly because the watchlist's groups list is frozen at the 2025–early-2026 top tier (lockbit / cl0p / blackcat / ransomhub / medusa, none of which appeared today), while the actually active ailock / pear / dragonforce / leaknet are all absent. Recommend updating the groups list at the next review.
← Prev
Ransomware Watch · Jul 15, 2026
Next →
Ransomware Watch · Jul 18, 2026
2026-07-15 16:51
shinyhuntersAbbott owned Exact Sciences CorporationHealthcare / genetic testingUS2026-07-15 17:50
qilinDanone (International Delights)Food & beverageFR / US2026-07-15 20:50
ransomhouseFidelity Services GroupSecurity servicesZA2026-07-15 22:50