Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-18
Ransomware·2026-07-18

Ransomware Watch · Jul 18, 2026

Data source: RansomLook /api/posts?days=1 (this batch returned items discovered 2026-07-15; upstream runs 2–3 days behind)

Overview

  • Total new posts: 19
  • Groups involved: 10
  • Watchlist hits: 4 (strict group-name match: qilin ×3, akira ×1); plus 2 healthcare victims (Pear, analyst-flagged)

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
qilinLevin FurnitureRetail / furnitureUSgroup:qilinRansomLook
qilinFeliubadalóJewelry retailESgroup:qilinRansomLook
qilinDanone (International Delights)Food manufacturingFR/USgroup:qilinRansomLook
akiraPioneer ConstructionConstructionUSgroup:akiraRansomLook
pearSouth Plains Rural Health Services, Inc.Healthcare (rural health)USsector:healthcare*RansomLook
pearCarient Heart & VascularHealthcare (cardiovascular)USsector:medical*RansomLook

* Semantic match (the title contains no strict keyword; sector assigned by analyst judgment).

All New Posts

GroupVictimSectorGeoDiscoveredLink
black xsanaa.centerThink tank / researchYE2026-07-15RansomLook
qilinLevin FurnitureRetail / furnitureUS2026-07-15RansomLook
qilinFeliubadalóJewelry retailES2026-07-15RansomLook
ailockFerrovialInfrastructure / engineeringES2026-07-15RansomLook
ailockSolid Advance Inc.Unknown—2026-07-15RansomLook
ailockNihon Kotsu Co., Ltd.Transport / taxiJP2026-07-15RansomLook
coinbase cartelPanasonicAeroAvionics / manufacturingJP/US2026-07-15RansomLook
pearSouth Plains Rural Health Services, Inc.HealthcareUS2026-07-15RansomLook
pearCarient Heart & VascularHealthcareUS2026-07-15RansomLook
akiraPioneer ConstructionConstructionUS2026-07-15RansomLook
dragonforceStephens PrecisionPrecision manufacturingUS

Anomalies / Trend Notes

  • New-face groups: black x, ailock, pear, leaknetand coinbase cartelhave only recently come into view — AiLock posted 3 in one batch and Pear targets healthcare exclusively; both warrant a profile.
  • Highly sensitive claim: LeakNet claims to have taken 6TB from Anglo Belgian Corp (a manufacturer of marine and submarine diesel engines), including submarine and nuclear plant blueprints. If accurate this would be a defense-supply-chain-level event; pending cross-validation.
  • DragonForce posted 5 in one day(2 law firms + 3 manufacturers), sustaining high output.
  • Healthcare concentration: Pear ×2 plus ShinyHunters (Exact Sciences, Abbott-owned) makes 3 US healthcare-related posts.
  • Q2 market view(GuidePoint/ReliaQuest/ZeroFox): "The Gentlemen" overtook Qilin for the top victim count; together Qilin and The Gentlemen accounted for 583 incidents in Q2, more than the next five groups combined.
← Prev
Ransomware Watch · Jul 16, 2026
Next →
Ransomware Watch · Jul 19, 2026
2026-07-15
RansomLook
dragonforceShillen Mackall & SeldonLaw firmUS2026-07-15RansomLook
dragonforceHughes Atwood & Mullaly pllcLaw firmUS2026-07-15RansomLook
dragonforceIsegen South Africa (Pty) LtdChemical manufacturingZA2026-07-15RansomLook
leaknetAnglo Belgian Corp (claims 6TB: submarine / nuclear plant blueprints)Defense / marine propulsionBE2026-07-15RansomLook
dragonforceHeritage Mechanical LLCMechanical engineeringUS2026-07-15RansomLook
shinyhuntersAbbott owned Exact Sciences CorporationMedical diagnosticsUS2026-07-15RansomLook
qilinDanone (International Delights)Food manufacturingFR/US2026-07-15RansomLook
ransomhouseFidelity Services GroupSecurity servicesZA2026-07-15RansomLook