Ransomware Watch · Aug 16, 2026
RansomLook logged 39 intrusion claims within a 36-hour window, spanning 12 ransomware groups.
Group Activity
- Qilin: 15 of the 39, making it the most active group this round. Targets span food and beverage (Mulino Padano), furniture (WEBA Meubelen), finance (MOSAID Technologies), construction and infrastructure (Megawide, Philippines), and law firms (Arnall Golden Gregory, US), among other industries — a characteristic "wide net" attack profile.
- direwolf: 6 claims, including TOTVS (a major Brazilian ERP software vendor) and several healthcare and payments companies (Colla Health, PayrHealth, DodoPayments).
- lockbit5: 5 claims, concentrated on small and mid-sized businesses and local government bodies in France, Italy, and Germany (such as Verbandsgemeinde Rhein-Nahe).
- xpl0itrs: 4 claims, including Dynatrace (AI observability platform) and RapidFort (software supply chain security company) — attackers targeting security and observability vendors themselves, which is worth noting.
- Remainder: eclipse, ms13-089, securotrop, barracuda, blackwater (2 claims), anubis, panzer, and space bears with 1 each.
Targets Worth Watching
RapidFort (claimed by xpl0itrs) — a software supply chain security company itself becoming a ransomware target.
Dynatrace (claimed by xpl0itrs) — AI observability platform vendor.
TOTVS (claimed by direwolf) — one of Brazil's largest ERP and management software suppliers.
SEARS / Grupo Sanborns (claimed by space bears) — a large Mexican retail group under Grupo Carso.
VR Advogados (claimed by barracuda) — a Brazilian law firm; the attackers claim to have leaked roughly 3,000 client passports and power-of-attorney documents.
All of the above are unilateral claims made by attackers on dark web and public channels. None has been independently verified by a third party; treat as situational awareness only.