Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-08-25
Ransomware·2026-08-25·44 Sources·7 Items

Ransomware Watch · Aug 25, 2026

44 victim claim postings from 15 groups were monitored over the past 36 hours (RansomLook).

Most Active Groups

qilin: 10 claims, mostly concentrated in manufacturing and professional services

Primary targets include Clear Align, Difor, Black Cat Engineering & Construction WLL, S.E.M.P. s.r.l., Studio BOLDRIN PAOLO, Euroflora srl, Tecnici Associati STP, and Aurore Development S.p.A., with industries skewing toward manufacturing, engineering and construction, and business services.

Sources: RansomLook

the crew: 6 claims, concentrated on critical industries in Myanmar

Claimed targets include two Myanmar banks, KBZ Bank and AYA Bank (Myanmar), plus Cyprus Airways, Htoo Hospitality, Parami University, and an "Indonesian police personnel database," showing the group is currently focused heavily on Myanmar's financial and public sectors.

Sources: RansomLook

booba team: 4 claims

Targets include furniture manufacturer Davroc, law firms Chernyy & Associates and Federis Abogados, and insurer Country-Wide Insurance, with stolen data volumes ranging from 15GB to 92GB.

Sources: RansomLook

cyberleek: 12 postings, but all media file leaks rather than corporate victims

All 12 postings from this group this period have titles pointing to "GTA 6"-related material (maps, video clips, and so on) and content related to a "Strip Club." No clear corporate or institutional victim is identifiable, making these different in nature from the data extortion claims of the other groups.

Priority Targets

ShinyHunters claims CyrusOne, demanding USD 13 million

ShinyHunters claims to have stolen 12.9 million Salesforce records and roughly 645GB (uncompressed) of SharePoint data from CyrusOne. An August 23 update states the company refused to pay the ransom, with the group threatening to escalate pressure within 24 hours.

Sources: RansomLook

lockbit5 claims security company adt.com (ADT)

Security and home automation provider ADT has been listed as a victim by LockBit5 — a certain irony in a security services provider itself falling to a ransomware attack.

Sources: RansomLook

emperador claims FRUCASTRO SL, with data release set for September 6

The group states it has stolen roughly 540MB of databases and significant documents from this manufacturing company, and has announced it will publish them on 2026-09-06.

Sources: emperador onion post

← Prev
Ransomware Watch · Aug 24, 2026
Next →
Ransomware Watch · Aug 26, 2026