Ransomware Watch · Aug 12, 2026
RansomLook logged 113 victim claim disclosures within a 36-hour window, aggregated by group below.
Group Activity
Two groups accounted for far more disclosures than the rest this window, with tightly clustered timestamps — suggesting a one-off bulk backfill rather than a single day's new activity:
- clop: 42 claims, including several well-known brands — Shell, General Electric (GE), Philips, Johnson & Johnson, Fiserv, ALDO and others — with leaked data spanning CAD drawings, system backups, financial records, and project files. The "revenue" figures shown on the disclosure pages vary wildly (from a few million to hundreds of billions of dollars), which suggests auto-generated company revenue estimates rather than actual ransom amounts; they are not taken at face value here.
- crpx0: 41 claims, concentrated on Turkish enterprises (banks including Kuveyt Türk, Finansbank, and Anadolubank; Turkish Airlines (THY); defense electronics maker ASELSAN; automaker TOGG; Hyundai's Turkish division) plus a number of US small and mid-sized businesses. Most are marked "Leaked," with deadlines clustered between late July and early August.
Other active groups: qilin (6 claims, mostly business-services targets); krybit (5, including a Taiwanese door-and-window manufacturer, an Indian laboratory instrument supplier, and a Singaporean maritime logistics firm); payload (3: a German hydraulic systems maker, a Swiss architecture practice, an Israeli technology distributor); inc ransom (3); leakeddata and settra (2 each); and direwolf, aurora, anubis, dragonforce, genesis, space bears, ransomhouse, kraken, and interlock with 1 each.
Individual Disclosures Worth Watching
- aurora claims FREYWILLE(Austrian fire-enamel jewelry brand with 70+ stores across Europe, North America, the Middle East, Russia, and Asia-Pacific) — the disclosure includes payslips and social security numbers (ELDA) for 142+ employees, employment contracts across 24 countries, COVID-19 vaccination records, and the brand's core process formulas (enamel color recipes) alongside cross-border litigation files.
- settra claims Frank Rim & Associates CPA(Denver, US tax advisory firm) — the disclosure includes a large volume of client IRS tax records, Social Security numbers, bank account balances, health insurance information, and complete CRM records.
- settra claims Profinergy / ProfiNRG(Dutch solar developer) — the disclosure includes group financial statements, commercial contracts with ENGIE and Tesla Energy, litigation files, and employee personal data.
- interlock claims AngMar Companies(US home health services network) — 710GB of data claimed, including patient medical records, Social Security numbers, and other sensitive health information.
All group activity levels and individual disclosures above are self-reported claims scraped from RansomLook within this window. None has been independently verified by a third party; treat as situational awareness only.