Ransomware Watch · Aug 14, 2026
This edition is based on 50 ransomware victim disclosures logged by RansomLook over the past 36 hours, spanning 15 different groups. All are unilateral "claimed attacks" published by the groups on their own leak sites; none has been independently confirmed by the victims or a third party, so do not treat them as verified incidents.
Group Activity
- the gentlemen: the most active this edition with roughly 15 disclosures, targeting US and European small businesses and retail chains, including KFC Kosova, Gravity Coffee, The Coffee Bean, Cityside Homes, Plaza Auto Mall, TOA, and Tempel. Industry distribution is scattered with no clear pattern.
- qilin: second most active with roughly 8 disclosures, including Radiant, Aletex Group, Urban Worldwide, PenLink, Lercher Werkzeugbau, and D & J Beverage Service — mostly mid-sized enterprises.
- coinbase cartel: 5 new victim disclosures, of which Hitachi High-Techand Turner and Townsend(a global cost-consulting and project management firm) are the largest and widest-reaching of this edition; also Serruya private equity and Sweet Water Holdings.
- akira: 4 disclosures, including Keystops, Cozad Asset Management, and CF Supply.
- inc ransom: 3 disclosures, of which cambrialawfirm.com is a law firm.
- ransomhouse: 2 confirmed disclosures (marked "DISCLOSED"), of which TECHVENTURES BANK S.A.is a financial institution and therefore relatively high-risk; the other is PCL Holding.
- clop: published an attack claim against ZEBRA.COM. Notably, the same group was also confirmed today to be under investigation by Shell over an alleged 89GB data theft (see the "Industry News" section of the daily brief), indicating Clop is operating at a high tempo, running two tracks on the same day.
- rhysida: 2 disclosures — local government body Pierce Township and healthcare provider SIA Medical Centre.
- The remaining groups (dragonforce, ailock, bluewhale, interlock, leakeddata, payload, m3rx) posted 1–2 disclosures each, including GB Group S.A, DAISEN, Yaomasa, Reminger (a law firm), and Zara Investment Holding. bluewhale's two targets (FiferFox Minecraft Server, Satellite Developer Server) are unusual, appearing to target gaming and development infrastructure rather than conventional enterprise targets.
Takeaways
No single group showed signs of a concentrated burst against one industry this edition; the picture is a routine, multi-group, multi-sector "wide net" tempo. The two cases warranting priority attention are financial institution TECHVENTURES BANK S.A. (ransomhouse) and large engineering consultancy Turner and Townsend (coinbase cartel), given the scale and sensitivity of the targets.