Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-31
Ransomware·2026-07-31

Ransomware Watch · Jul 31, 2026

⚠️ Data-source note: the RansomLook Recent Posts API was unreachable this run (network/provenance restrictions). Data on this page comes from secondary tracking sources and news reporting, not a structured API pull. Figures are approximate.

Overview

  • New posts in the past 24h: ~29
  • Most active groups: SafePay > Akira > AiLock
  • Watchlist hits: Akira (group); LockBit (trend context)

Watchlist Hits (Read First)

GroupVictimSectorGeoHitLink
Akira(multiple, not itemized)Multi-sector—group:akiraState of Ransomware Q1 2026
Qilin~1,500 cumulative (500+ in 2026)Multi-sector—group:qilinSecureBlink

Key Disclosures This Week

Group / EventVictimSectorScaleDiscoveredLink
Data breachDentaQuestHealthcare / Dental benefits23M+ individuals2026-07-27ITSecurityNews
Ransomware exploitationPTC Windchill (exploited)Manufacturing / PLM—2026-07-27ITSecurityNews

All New Posts (Summary)

Roughly 29 new victim disclosures in the past 24h; the most active groups were SafePay, Akira, and AiLock. Per-victim detail requires a direct RansomLook API pull (unreachable this run) and will be backfilled on the next run.
Help Net — Ransomware in 2026

Anomalies / Trend Notes

  • Cartelization continues: Qilin, Akira, "The Gentlemen", and LockBit together account for roughly 41% of all victims; Qilin is the most active operation of 2026.
  • SafePay rose to most active for the day— worth watching whether this is the start of a new surge.
  • Disclosure volume accelerating in H2: 7,551 victims over the 2026 reporting period, with second-half disclosures up 60% versus the first half; active groups now number ~146.
  • Law enforcement: a Scattered Spider member was arrested.

Source configuration: intel/sources.yaml; watchlist: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 30, 2026
Next →
Ransomware Watch · Aug 9, 2026