Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-08-20
Ransomware·2026-08-20·2 Sources·64 Items

Ransomware Watch · Aug 20, 2026

64 attack disclosures claimed by ransomware groups were monitored over the past 36 hours, spanning roughly 20 active groups. All data below comes from ransomware leak-site claim posts aggregated by RansomLook ("claimed attacks") — unilateral statements by the groups, not independently verified.

This Edition at a Glance

qilin and shinyhunters were the two most active groups this edition. qilin claimed 9 attacks in 36 hours, with targets spread across pharmaceuticals (Medochemie), energy (Smart Energies), logistics (WIS Logistics), and finance (Philippe Hottinguer Finance), mostly small and mid-sized businesses. shinyhunters claimed 10 attacks (including one warning notice), with targets showing a pronounced healthcare and pharmaceutical cluster: medical device giant Baxter International, ophthalmic care giant Alcon, medical laser equipment maker Lumenis, and medical device firm Cook Medical, alongside consumer brand Carhartt, Logitech/Streamlabs, intellectual property services provider Questel, open source BI tool Metabase, and health platform Sharecare — a wide industry spread with high name recognition.

inc ransom claimed 9 attacks, with targets including Thai cable manufacturer BANGKOKCABLE, US listed bank holding company Third Coast Bancshares, and pharmaceutical firm Foresee Pharmaceuticals. krybit, direwolf, and the gentlemen claimed 4 each, with the gentlemen claiming UK defense and engineering giant Babcock and investment firm Senvest Capital.

Individual Cases Worth Watching

leaknet publicly released 11TB of archive data from NYC Health + Hospitals: the group claims to have made public 11TB of archives from one of the largest public hospital systems in the US — the largest in scale and widest in public-sector impact among this edition's disclosures.

leakeddata claims an attack on large law firm Troutman Pepper Locke: when law firm targets suffer a data leak, sensitive client legal documents are typically involved, giving the risk a wide spillover surface.

emperador claims an attack on the municipal government of Arcos, Brazil (Prefeitura Municipal de Arcos): government and municipal targets continue to be a common choice for ransomware groups operating in Latin America.

akira, coinbase cartel, nightspire, and insomnia each claimed 1–2 attacks this edition, with targets scattered across law firms, engineering consulting, and healthcare administration. Some victim names from nightspire and insomnia were redacted by the platform (possibly due to ongoing negotiations or legal restrictions).

← Prev
Ransomware Watch · Aug 18, 2026
Next →
Ransomware Watch · Aug 21, 2026