Ransomware Watch · Jul 26, 2026
⚠️ Data source note: both the RansomLook API (
/api/posts?days=1) and the RSS fallback were blocked by the sandbox's network egress controls (HTTP 000). This page is an indicative snapshot compiled from web search, not RansomLook's complete victim set for the day; victim counts and "discovered" times follow public reporting and may lag or be incomplete.
Overview
- Total new posts: roughly 8+ visible via web search (incomplete)
- Groups involved: ≥6
- Watchlist hits: 4 (groups: Qilin, INC; sectors: financial, manufacturing)
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Chemco | manufacturing/chemical | — | group:qilin, sector:manufacturing | breachsense |
| INC_RANSOM | tricountyhs.org | healthcare | US | group:inc, sector:healthcare | breachsense |
| Unsafe | Deutsche Bank (3rd-party) | financial/banking | DE | sector:financial, kw:data leak | cybernews |
| Gentlemen | Indra Group (subsidiary) | defense/aerospace | ES | kw:double extortion | sharkstriker |
All New Posts (portion visible via web search)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | Chemco | chemical/manufacturing | — | 2026-07 | link |
| INC_RANSOM | tricountyhs.org | healthcare | US | 2026-07-03 | link |
| ANUBIS | ferrum.net | — | — | 2026-07-03 | link |
| Bashe | flazio.com | — | — | 2026-07-03 | link |
| Unsafe | Deutsche Bank (third-party) | financial | DE | 2026-07 | link |
| Gentlemen | Indra Group | defense/aerospace | ES | 2026-07 | link |
| Krybit | Ford Motor Company | automotive | US | 2026-07 | link |
| ShinyHunters / ShadowByt3$ | Abbott Laboratories | healthcare/pharma | US | 2026-07 | link |
Anomalies / Trend Notes
- Financial and critical sectors named: Deutsche Bank (via a third party) and Indra (a member of NATO's cyber alliance) show that supply chains and defense contractors remain high-value targets.
- Multiple groups posting the same victim: Abbott was claimed separately by ShinyHunters and ShadowByt3$ — a signature of double or competing extortion.
- Data gap reminder: this page is not a complete set. Once direct access is restored, the day's full volume should be re-checked against RansomLook
/api/posts?days=1and backfilled.
Watchlist configuration at intel/ransomware/watchlist.yaml