Ransomware Watch · Aug 23, 2026
Source: RansomLook global dashboard, 124 new claim records over the past 36 hours, spanning roughly 20 groups.
Active Group Overview
Over the past 36 hours the the gentlemen group posted by a wide margin more than any other, but a substantial share of the "victim" names in its disclosures are in fact SSTI / path traversal / XSS probe strings (such as {{7*7}}, ${7*7}, <%=7*7%>, ../RCTRAV, RCSLASH/x, XSSPROBE, PROBEDIR, PROBEABS, IMGTRAV, ACLTEST, MASSIGN). These are clearly vulnerability scanning traffic aimed at the group's own leak site that was mistakenly ingested into the database, not genuine victim disclosures — this edition has excluded those anomalous entries and retained only named companies. The group's genuinely identifiable targets this edition include BIOPHARMA, Meridian Logistics Group, CAZ Investments, Aquasea, Layher, AGS Cinemas, Volktek, and Akatake Engineering.
Also posting in bulk were coinbase cartel (14 victim companies published at once, including financial institution BOK Financial) and direwolf (13, including US school district Deer Creek-Mackinaw CUSD). qilin disclosed 7 targets, including Cinépolis (cinema chain) and Quaker State Mexico.
Targets Worth Watching
- BOK Financial(US regional bank) — shinyhunters claims to have attacked it; a financial industry target, with a relatively high risk rating.
- Deer Creek-Mackinaw CUSD(US school district) — direwolf claims to have attacked it; education is once again a target.
- NovoCure Limited(medical device maker in tumor treating fields oncology therapy) — shinyhunters claims to have attacked it.
Other Active Groups
lockbit5, rhysida, pear, space bears, nightspire, akira, eclipse, l group, termite, majinahanashi, panzer, dragonforce, and others all posted scattered disclosures at smaller scale, with no other notably anomalous targets observed for now.
Source: RansomLook