Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-26
Ransomware·2026-07-26

Ransomware Watch · Jul 26, 2026

⚠️ Data source note: both the RansomLook API (/api/posts?days=1) and the RSS fallback were blocked by the sandbox's network egress controls (HTTP 000). This page is an indicative snapshot compiled from web search, not RansomLook's complete victim set for the day; victim counts and "discovered" times follow public reporting and may lag or be incomplete.

Overview

  • Total new posts: roughly 8+ visible via web search (incomplete)
  • Groups involved: ≥6
  • Watchlist hits: 4 (groups: Qilin, INC; sectors: financial, manufacturing)

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
QilinChemcomanufacturing/chemical—group:qilin, sector:manufacturingbreachsense
INC_RANSOMtricountyhs.orghealthcareUSgroup:inc, sector:healthcarebreachsense
UnsafeDeutsche Bank (3rd-party)financial/bankingDEsector:financial, kw:data leakcybernews
GentlemenIndra Group (subsidiary)defense/aerospaceESkw:double extortionsharkstriker

All New Posts (portion visible via web search)

GroupVictimSectorGeoDiscoveredLink
QilinChemcochemical/manufacturing—2026-07link
INC_RANSOMtricountyhs.orghealthcareUS2026-07-03link
ANUBISferrum.net——2026-07-03link
Basheflazio.com——2026-07-03link
UnsafeDeutsche Bank (third-party)financialDE2026-07link
GentlemenIndra Groupdefense/aerospaceES2026-07link
KrybitFord Motor CompanyautomotiveUS2026-07link
ShinyHunters / ShadowByt3$Abbott Laboratorieshealthcare/pharmaUS2026-07link

Anomalies / Trend Notes

  • Financial and critical sectors named: Deutsche Bank (via a third party) and Indra (a member of NATO's cyber alliance) show that supply chains and defense contractors remain high-value targets.
  • Multiple groups posting the same victim: Abbott was claimed separately by ShinyHunters and ShadowByt3$ — a signature of double or competing extortion.
  • Data gap reminder: this page is not a complete set. Once direct access is restored, the day's full volume should be re-checked against RansomLook /api/posts?days=1and backfilled.

Watchlist configuration at intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 25, 2026
Next →
Ransomware Watch · Jul 27, 2026