Ransomware Watch · Aug 25, 2026
44 victim claim postings from 15 groups were monitored over the past 36 hours (RansomLook).
Most Active Groups
qilin: 10 claims, mostly concentrated in manufacturing and professional services
Primary targets include Clear Align, Difor, Black Cat Engineering & Construction WLL, S.E.M.P. s.r.l., Studio BOLDRIN PAOLO, Euroflora srl, Tecnici Associati STP, and Aurore Development S.p.A., with industries skewing toward manufacturing, engineering and construction, and business services.
Sources: RansomLook
the crew: 6 claims, concentrated on critical industries in Myanmar
Claimed targets include two Myanmar banks, KBZ Bank and AYA Bank (Myanmar), plus Cyprus Airways, Htoo Hospitality, Parami University, and an "Indonesian police personnel database," showing the group is currently focused heavily on Myanmar's financial and public sectors.
Sources: RansomLook
booba team: 4 claims
Targets include furniture manufacturer Davroc, law firms Chernyy & Associates and Federis Abogados, and insurer Country-Wide Insurance, with stolen data volumes ranging from 15GB to 92GB.
Sources: RansomLook
cyberleek: 12 postings, but all media file leaks rather than corporate victims
All 12 postings from this group this period have titles pointing to "GTA 6"-related material (maps, video clips, and so on) and content related to a "Strip Club." No clear corporate or institutional victim is identifiable, making these different in nature from the data extortion claims of the other groups.
Priority Targets
ShinyHunters claims CyrusOne, demanding USD 13 million
ShinyHunters claims to have stolen 12.9 million Salesforce records and roughly 645GB (uncompressed) of SharePoint data from CyrusOne. An August 23 update states the company refused to pay the ransom, with the group threatening to escalate pressure within 24 hours.
Sources: RansomLook
lockbit5 claims security company adt.com (ADT)
Security and home automation provider ADT has been listed as a victim by LockBit5 — a certain irony in a security services provider itself falling to a ransomware attack.
Sources: RansomLook
emperador claims FRUCASTRO SL, with data release set for September 6
The group states it has stolen roughly 540MB of databases and significant documents from this manufacturing company, and has announced it will publish them on 2026-09-06.
Sources: emperador onion post