Ransomware Watch · Jul 27, 2026
⚠️ Collection note: direct access to the RansomLook API (
/api/posts?days=1) and its RSS feed was blocked by network policy inside the sandbox (empty responses), so this edition cross-checks recent disclosures via web search instead. The data is "representative of the week" rather than a strict 24h full set, and victim counts are omitted.
Overview
- Total new posts: N/A (direct RansomLook access blocked; no structured full set retrieved)
- Featured groups this edition: Anubis(Fairlife / Coca-Cola's dairy subsidiary), Qilin(continued market dominance)
- Watchlist hits: 2 (Qilin = group match; Fairlife = sector/keyword match)
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Anubis | Fairlife (Coca-Cola dairy subsidiary, valued at ~$4bn) | food/manufacturing | US | sector:manufacturing · kw:data leak · kw:double extortion · geo:us | BleepingComputer |
| Qilin | Multiple targets (~141 organizations across ≥25 countries in 30 days) | Cross-sector | global | group:qilin | Ransomware.live |
Representative Posts This Edition
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Anubis | Fairlife (Coca-Cola dairy) | Food / Dairy | US | Claim made public 2026-07-21/22 | SecurityWeek |
| Qilin | Leading the RaaS market, most new victims in a single week | Cross-sector | global | 2026-07 (ongoing) | Infosecurity |
Anubis / Fairlife Timeline (this edition's focus; the extortion deadline expires today)
- 2026-07-16— Coca-Cola disclosed via an SEC 8-K that some Fairlife systems (including production-related systems) were subject to unauthorized access; product quality and safety were unaffected, but US production was temporarily suspended, while Canadian operations continued normally.
- 2026-07-21/22— Anubis went public with its claim: it says it encrypted Fairlife's Nutanixsystems and stole 1TBof confidential data. No amount was specified ("a token agreement is all it takes"), with a deadline set for the morning of Monday, 2026-07-27, after which the data would be leaked.
- Group profile: Anubis is a financially motivated RaaS that surfaced in late 2024, with code resembling the earlier Sphinx malware.
Anomalies / Trend Notes
- The market keeps consolidating around Qilin: publicly listed victims hit a record for full-year 2026 (~7,551 organizations, 146 active groups), with Qilin up 443% year over year and becoming the top RaaS after LockBit and RansomHub were successively disrupted or collapsed. RansomHub fell from 736 organizations to zero within 12 months, confirming the coexistence of "brand volatility plus steadily rising totals."
- Rising risk to food and manufacturing: the Fairlife case shows that even a large consumer brand faces production-stopping impact once OT/production systems are touched.
- Data gap reminder: once direct RansomLook access is restored, backfill the full 24h victim list for this day for cross-verification.