Ransomware Watch · Jul 30, 2026
⚠️ Data-source note: the RansomLook API / RSS was unreachable from the execution sandbox this round (restricted network egress). The following is a compilation of recent representative activity based on public intelligence reporting, not live per-post RansomLook data. Watchlist hits are marked with ⭐.
Overview
- Recent new posts tracked (estimate): ~18
- Most active groups: Qilin, The Gentlemen, Akira (the three trade the top spot week by week)
- Watchlist hits: 4 categories (
qilin,akira,healthcare,manufacturing)
Watchlist Hits (Read First)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Qilin | Stryker | Manufacturing (medical devices) | US | group:qilin / sector:manufacturing | dexpose |
| Qilin | Next Clinics | Healthcare | — | group:qilin / sector:healthcare | recentbreaches |
| Akira | (multiple) | Mixed | — | group:akira | dexpose 2026 groups |
Landscape / All New Posts (Compiled)
| Group | Note | Sector | Link |
|---|---|---|---|
| Qilin | Claimed nearly 300 victims in Q2 2026, trading the weekly top spot with The Gentlemen | Mixed | dailysecurityreview |
| The Gentlemen | Claimed nearly 300 victims in Q2 2026, tied with Qilin at the top | Mixed | industrialcyber |
| Akira / DragonForce / LockBit | In the 2026 top tier alongside Qilin | Mixed | checkpoint Q1 2026 |
Anomalies / Trend Notes
- Ecosystem reconsolidation: the top 10 groups now account for 71.1% of all victims, the highest since Q1 2024; the number of active groups has fallen from 85 to 71. The head-of-market effect is intensifying.
- Qilin vs The Gentlemen race: the two traded the top spot week by week in July, reportedly driven by their "rivalry".
- Signs of cartelization: DragonForce publicly proposed (2025-09) an alliance with LockBit and Qilin to "avoid conflict and dominate the market" — worth watching whether it materializes.
- Priority-sector hits: manufacturing (Stryker) and healthcare (Next Clinics) were both named by Qilin this round — critical infrastructure and healthcare remain high-value targets.
Configuration: ransomware section of intel/sources.yaml; watchlist: intel/ransomware/watchlist.yaml