Ransomware Watch · Jul 29, 2026
⚠️ Data note: this run could reach neither the RansomLook API (
/api/posts?days=1) nor the RSS fallback from the execution environment (sandbox network restrictions + web_fetch provenance gate). The items below are compiled from public reporting, not a structured RansomLook pull; the victim list is incomplete and covers only representative victims named on or around the day.
Overview
- Total new posts: N/A (RansomLook unreachable; the items below are public-reporting hits)
- Groups involved: ≥2 (Qilin, Anubis) + multiple groups exploiting edge devices at the ecosystem level
- Watchlist hits: 2 (both matching group:qilin / sector:healthcare|medical / geo:us)
Watchlist Hits (Read First)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin ⭐ | Stryker | Medical technology / manufacturing | US | group:qilin · sector:medical · geo:us | socradar |
| Anubis | Eagle Crest Communities (WI) | Senior care / healthcare | US | sector:healthcare · geo:us | techtimes |
Representative Recent Posts (Public Reporting)
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| Qilin | Stryker | Medical technology | US | 2026-07-24 | socradar |
| Anubis | Eagle Crest Communities | Senior care | US | 2026-07-27 | techtimes |
| Anubis | Fairlife (Coca-Cola subsidiary) | Food / dairy | US | 2026-07-20 | brightdefense |
Anomalies / Trend Notes
- Initial access is concentrating on edge devices: multiple ransomware crews (including Qilinaffiliates) are using Palo Alto, Fortinet, Citrix, and Check Point VPN/firewall appliances as their primary initial-access vector, chaining authentication bypasses, credential theft, and legacy-protocol weaknesses. Patching edge devices is the top priority. cybersecuritynews
- Anubis + Citrix Bleed 2 (CVE-2025-5777): Anubis gains access before encryption by bypassing MFA, with 91 victims to date; the healthcare/care sector has been hit noticeably hard.
- Qilin keeps the lead: roughly 1,496 victims listed on its leak site over the past 12 months; Akira around 1,205. The two remain the most active ransomware operations of 2026. infosecurity-magazine
Under normal conditions this page is generated automatically from the RansomLook API with watchlist highlighting; this edition is a public-reporting fallback, and structured pulls should resume tomorrow.