Ransomware Watch · Aug 15, 2026
RansomLook logged 44 ransomware group disclosures within a 36-hour window, spanning 16 groups. The following are selected by activity level and target significance.
Group Activity
the gentlemen was the most active this period, disclosing 16 victims at once, covering a Brazilian metallurgical firm, a Japanese construction contractor, an Italian labor union, a Greek education accreditation body, and retail and food service chains across multiple countries (KFC Kosova, The Coffee Bean Malaysia, Plaza Auto Mall, and others) — a textbook bulk-dump posting, with targets highly dispersed by industry and geography. It does not focus on any particular sector; this is indiscriminate pressure tactics.
qilin disclosed 8 victims across a broad industry spread: Italian animal feed producer FERRARI MANGIMI, software company PenLink, industrial machinery maker Lercher Werkzeugbau, and others.
coinbase cartel disclosed 3 victims, concentrated in finance and private equity: engineering consulting giant Turner and Townsend (listed revenue USD 1.6 billion), Serruya private equity, and Sweet Water Holdings.
inc ransom / akira / bluewhale / blackwater disclosed 2 victims each.
Targets Worth Watching
rhysida claims an attack on Pierce Township, Ohio, US (local government), saying it holds grand jury subpoena responses (including hospital medical records), public records requests, fire investigation reports, employee PII such as SSNs and CDLs, litigation settlement documents, and internal emails from government officials — a local government body as target, with highly sensitive data. RansomLook
global secret group claims an attack on Columbia University (dental-related systems), asserting it holds 296GB across more than 280,000 files, including access control and employee information; Columbia University's annual revenue is listed as USD 6.6 billion. RansomLook
qilin's attack on software company PenLink — the company supplies communications data analysis tools to law enforcement and intelligence agencies; if the disclosure is accurate, the potential downstream impact warrants attention.
Note
This tally excludes one disclosure involving an individual (not a business) that carried allegations of illegal content; the details are not suitable for restating in a brief. RansomLook scrapes ransomware groups' own claims, which have not been independently verified — victims' official statements should be treated as authoritative.