Ransomware Watch · Jul 31, 2026
⚠️ Data-source note: the RansomLook Recent Posts API was unreachable this run (network/provenance restrictions). Data on this page comes from secondary tracking sources and news reporting, not a structured API pull. Figures are approximate.
Overview
- New posts in the past 24h: ~29
- Most active groups: SafePay > Akira > AiLock
- Watchlist hits: Akira (group); LockBit (trend context)
Watchlist Hits (Read First)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| Akira | (multiple, not itemized) | Multi-sector | — | group:akira | State of Ransomware Q1 2026 |
| Qilin | ~1,500 cumulative (500+ in 2026) | Multi-sector | — | group:qilin | SecureBlink |
Key Disclosures This Week
| Group / Event | Victim | Sector | Scale | Discovered | Link |
|---|---|---|---|---|---|
| Data breach | DentaQuest | Healthcare / Dental benefits | 23M+ individuals | 2026-07-27 | ITSecurityNews |
| Ransomware exploitation | PTC Windchill (exploited) | Manufacturing / PLM | — | 2026-07-27 | ITSecurityNews |
All New Posts (Summary)
Roughly 29 new victim disclosures in the past 24h; the most active groups were SafePay, Akira, and AiLock. Per-victim detail requires a direct RansomLook API pull (unreachable this run) and will be backfilled on the next run.
Help Net — Ransomware in 2026
Anomalies / Trend Notes
- Cartelization continues: Qilin, Akira, "The Gentlemen", and LockBit together account for roughly 41% of all victims; Qilin is the most active operation of 2026.
- SafePay rose to most active for the day— worth watching whether this is the start of a new surge.
- Disclosure volume accelerating in H2: 7,551 victims over the 2026 reporting period, with second-half disclosures up 60% versus the first half; active groups now number ~146.
- Law enforcement: a Scattered Spider member was arrested.
Source configuration: intel/sources.yaml; watchlist: intel/ransomware/watchlist.yaml