Ransomware Watch · Aug 22, 2026
Over the past 36 hours, RansomLook's global victim disclosure feed logged 91 statements, spanning roughly 25 known ransomware groups.
Group Activity at a Glance
- the gentlemen: the most active group this edition with roughly 24 statements, targeting Germany, Austria, Chile, Saudi Arabia, Italy, Japan, Peru, Poland, the US, and elsewhere, across investment, logistics, power engineering, cinemas, optometry, IT consulting, chemical manufacturing, labor organizations, and other industries — a textbook opportunistic, industry-agnostic wide-net pattern.
- direwolf: roughly 13 statements posted in a single dense burst, with targets including flight simulation software vendor ProSim Aviation Research, identity verification provider Authenticate Information Systems, and educational institution Deer Creek-Mackinaw CUSD.
- qilin: roughly 10 statements, with targets including cinema chain Cinépolis and legal services firm The Pendas Law Firm — a fairly scattered industry distribution.
- pear, titan: titan concentrated on Italian small and mid-sized businesses (energy, legal, and construction-related industries); pear's targets were primarily US healthcare and legal small and mid-sized organizations.
- everest: fewer statements but standout target quality, including memory and storage manufacturer Kingston Technology, global IT engineering consultancy Capgemini Engineering, and CCA Bank.
Targets Worth Watching
- Kingston Technology(claimed by everest): a globally recognized memory and storage hardware manufacturer. If the data is genuine, the potential supply chain impact is broad — but at present there is only a unilateral group claim, and neither its authenticity nor the scope of the data can be verified.
- Capgemini Engineering(claimed by everest): the engineering consulting arm of France's Capgemini group; likewise only a unilateral group claim.
- Interim HealthCare [HQ](claimed by anubis): the headquarters of a large US healthcare franchise operation, implicating both employee and patient data risk. The anubis statement explicitly describes it as a "healthcare franchise HQ data breach."
- BIOPHARMA / Crystal Pharmatech: both biopharmaceutical/CRO companies, claimed by the gentlemen and eclipse respectively — two pharmaceutical industry cases this edition.
Notes
- All of the above are unilateral statementsposted by ransomware groups on their own data leak sites. None has been independently confirmed by the victims or a third party; do not treat them as verified data breach incidents.
- No confirmed cases targeting critical infrastructure (power grids, water utilities, transport hubs) were observed this edition.