Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-30
Ransomware·2026-07-30

Ransomware Watch · Jul 30, 2026

⚠️ Data-source note: the RansomLook API / RSS was unreachable from the execution sandbox this round (restricted network egress). The following is a compilation of recent representative activity based on public intelligence reporting, not live per-post RansomLook data. Watchlist hits are marked with ⭐.

Overview

  • Recent new posts tracked (estimate): ~18
  • Most active groups: Qilin, The Gentlemen, Akira (the three trade the top spot week by week)
  • Watchlist hits: 4 categories (qilin, akira, healthcare, manufacturing)

Watchlist Hits (Read First)

GroupVictimSectorGeoHitLink
QilinStrykerManufacturing (medical devices)USgroup:qilin / sector:manufacturingdexpose
QilinNext ClinicsHealthcare—group:qilin / sector:healthcarerecentbreaches
Akira(multiple)Mixed—group:akiradexpose 2026 groups

Landscape / All New Posts (Compiled)

GroupNoteSectorLink
QilinClaimed nearly 300 victims in Q2 2026, trading the weekly top spot with The GentlemenMixeddailysecurityreview
The GentlemenClaimed nearly 300 victims in Q2 2026, tied with Qilin at the topMixedindustrialcyber
Akira / DragonForce / LockBitIn the 2026 top tier alongside QilinMixedcheckpoint Q1 2026

Anomalies / Trend Notes

  • Ecosystem reconsolidation: the top 10 groups now account for 71.1% of all victims, the highest since Q1 2024; the number of active groups has fallen from 85 to 71. The head-of-market effect is intensifying.
  • Qilin vs The Gentlemen race: the two traded the top spot week by week in July, reportedly driven by their "rivalry".
  • Signs of cartelization: DragonForce publicly proposed (2025-09) an alliance with LockBit and Qilin to "avoid conflict and dominate the market" — worth watching whether it materializes.
  • Priority-sector hits: manufacturing (Stryker) and healthcare (Next Clinics) were both named by Qilin this round — critical infrastructure and healthcare remain high-value targets.

Configuration: ransomware section of intel/sources.yaml; watchlist: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 29, 2026
Next →
Ransomware Watch · Jul 31, 2026