Ransomware Watch · Jul 23, 2026
Data source: RansomLook
/api/posts?days=1. The API returns a limited field set (group_name / post_title / discovered) with no sector or geo, so those columns are left blank below.
Overview
- Total new posts: 5
- Groups involved: 4 (krybit, gunra, blackout, qilin)
- Watchlist hits: 2 (both group:qilin)
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| qilin | Famesa | — | — | group:qilin | RansomLook |
| qilin | City Ambulance Service | — | — | group:qilin | RansomLook |
All New Posts
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| qilin ⭐ | Famesa | — | — | 2026-07-19 | RansomLook |
| qilin ⭐ | City Ambulance Service | — | — | 2026-07-19 | RansomLook |
| krybit | euroins.bg | — | — | 2026-07-18 | RansomLook |
| gunra | Dissinger and Dissinger Law Firm | — | — | 2026-07-18 | RansomLook |
| blackout | bluebellgroup.com | — | — | 2026-07-18 | RansomLook |
Anomalies / Trend Notes
- qilinis a highly active group on the watchlist and accounts for both hits this round (including "City Ambulance Service", apparently emergency medical — worth noting its continued targeting of healthcare).
- krybit, gunraand blackoutare all small or new groups outside the watchlist, with one post each this round — watch whether they are rebrands or short-lived operations.
- The discovered dates returned by RansomLook
days=1this run cluster on 7/18–7/19 (earlier than the current date), likely ingestion lag on the API side; with a low post count, treat trend conclusions with caution.
Main brief for the day: intel/daily/2026-07-23.zh.md