Ransomware Watch · Aug 11, 2026
Source material: RansomLook (global disclosure RSS), 54 victim disclosures within a 36-hour window.
Most Active Groups
- direwolf: claimed 13 victims in this window across a wide industry spread, including healthcare (AliveCor, Health Carousel, Quironsalud — a large Spanish healthcare group), data services (Statista GmbH), finance (Osmo Wallet), technology (Swyft Inc., Merge, BigSpark), and legal tech (Chat Jurídico). RansomLook
- qilin: 5 disclosures, covering advertising and marketing (Service Evaluation Concepts), construction (tommer construction, B Wright Drywall), government (City of Winchester), and South Korean industrial machinery maker HIGEN MOTOR(flagged "critical data").
- ethics: 4 disclosures, including US insurer Philadelphia Insurance Companies and law firm Holstrom, Block & Parke.
- payload / akira / storm / global secret group: 3 each; akira's disclosure of Alcast (aluminum casting, serving defense, heavy equipment, and marine supply chains) came with claims of employee passports, driver's licenses, Social Security numbers, and other personal data.
- settra / bravox / krybit / wallstreet: 2 each; settra's two disclosures (Denver tax advisory firm Frank Rim & Associates, Dutch solar developer Profinergy/ProfiNRG) carried exceptionally detailed data-sample descriptions (IRS correspondence, employee SSNs, consolidated financial statements covering EUR 35 million in assets, and commercial documents involving ENGIE and BNG Bank).
Targets Worth Watching
- FREYWILLE (Austrian enamel jewelry brand, claimed by aurora): the disclosure covers payroll and social security numbers (ELDA) for 142+ employees, employment contracts across 24 countries, COVID-19 vaccination records, and the brand's core trade secrets — the SPHINX/JOYB2/Entwurf series enamel formulas; plus defense materials from more than 40 cross-border lawsuits.
- LT Group / Fortune Tobacco Corp (large Philippine conglomerate, claimed by deadlock): the disclosed file is a single PDF (related to Tan Johnny James).
- Cleaver-Brooks (US industrial manufacturer, claimed by anubis): described as a "major data breach at an industry-leading manufacturer."
- Interim HealthCare / Consolidated Medical Practices of Memphis (claimed by genesis): two disclosures involving healthcare and elder-care providers.
- AngMar Companies (US home health care network, claimed by interlock): 710GB of confidential data claimed, including patient medical records, Social Security numbers, home addresses, and phone numbers.
Takeaways
RansomLook recorded activity from 26 distinct ransomware groups within the window. Healthcare, industrial manufacturing, and professional services (legal, insurance, tax) were the three hardest-hit sectors this round; direwolf and qilin were markedly more active than the rest. A number of disclosures (the direwolf series, plus some payoutsking and leakeddata entries) list only a victim name with no detailed summary, so the actual scope of impact cannot yet be assessed.