Ransomware Watch · Aug 21, 2026
Data from RansomLook global leak site monitoring (roughly 60 victim disclosures over the past ~36 hours) plus media reporting. These are attacker claims only, not verified case by case.
Most Active Ransomware Groups
- qilin— the largest disclosure volume of the day, with victims spanning manufacturing, logistics, finance, construction, and other industries, including Medochemie, Semana, Questronix, Provite, Movitecnica, WIS Logistics, and Philippe Hottinguer Finance, among more than a dozen.
- titan— concentrated on Italian companies: Elbor S.p.A., CTP S.r.l., Condor SPA, Elcon Megarad, Alto Calore Servizi, Tecnologica, and others, many marked "fully encrypted."
- everest— skewing toward larger targets: Kingston Technology, Capgemini Engineering, CCA Bank, Grupo DT, Experts Entreprendre.
- inc ransom / krybit / pear— inc ransom posted bulk disclosures (BangkokCable, Uniplastics, and others); krybit spanned Thailand, Italy, Germany, Argentina, and the Czech municipality of Jilemnice; pear focused on healthcare and gaming in California, US (Club One Casino, Austin Plastic Surgery, and others).
Targets Worth Noting
- lockbit5 claims an attack on U.S. Bank (usbank.com)— if accurate, this involves a multinational financial institution. https://www.ransomlook.io/
- xpl0itrs claims an attack on Target— the US general merchandise retail giant.
- the gentlemen— claims attacks on BioPharma, a Taiwanese biopharmaceutical company specializing in hematological disease and oncology treatment, and on Babcock, an engineering and asset management company (Africa / critical infrastructure).
- shinyhunters— issued an ultimatum-style threat: make contact before August 24 or the data leaks.
Media Reports and Ecosystem Developments
- CISA/FBI: Medusa has breached 500+ US critical infrastructure organizations(since June 2021). Critical infrastructure operators should check against the official IOCs. https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/
- Rogue affiliate posing as a "recovery firm"— a suspected ransomware affiliate has been impersonating a ransom recovery service called "Ransom Busters," contacting victims before the attack becomes public and claiming it can supply decryption keys and delete stolen data for a fee. Victims should be alert to this secondary fraud. https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
- China: Sorry ransomware breaking out at multiple sites— Anquanke reports the ransomware has surfaced at multiple locations across China, singling out small and mid-sized businesses and locking servers outright. https://www.anquanke.com/post/id/315994