Ransomware Watch · Aug 17, 2026
42 RansomLook victim claims were read within a 36-hour window, from 11 different groups. All of the following are unilateral claims posted on ransomware groups' "data leak sites," not independently confirmed by the victims or a third party; treat as situational awareness only.
Activity
qilin dominated this round, claiming 19 victims in total across manufacturing, business services, finance, legal services, healthcare services, food and beverage, construction, and other industries, with targets spread across Italy, Germany, France, Malaysia, the Philippines, and elsewhere — a clear bulk-extortion profile. lockbit5 followed with 5 new claims, concentrated on small and mid-sized businesses in France and Italy (recruitment agencies, accounting firms, agricultural companies, engineering consultancies). direwolf and xpl0itrs added 4 each. The remainder: panzer (3), aurora (2), and inc ransom, dragonforce, bravox, emperador, and eclipse with 1 each.
Targets Worth Watching
- direwolf claims an attack on Arizona State University (ASU): a large US public university, an education-sector target.
- inc ransom claims an attack on Otter Tail County, Minnesota: a US local government body.
- emperador claims an attack on Albania's national teacher training portal: claims to have stolen roughly 100,000 records containing teacher names, national ID numbers, and qualification certificate PDFs, totaling 5.9GB, with public release planned for 2026-08-30.
- aurora claims an attack on Natco Home Group: a US furniture manufacturer; the stolen data is claimed to include plaintext Social Security numbers for roughly 100–120 employees dating as far back as 1979, plus ten years of ADP payroll data from 2017–2026 (payslips, W-2s, W-4s, 401k records, drug tests, and medical records for 700–1,000 employees).
- qilin claims an attack on Coface: the French credit insurance giant, and the case with the widest industry impact among qilin's bulk claims this round.