Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-08-26
Ransomware·2026-08-26·50 Sources·29 Items

Ransomware Watch · Aug 26, 2026

RansomLook recorded roughly 40 genuine corporate and institutional victim disclosures within a 36-hour window (a further 10 postings were "GTA 6" leak hype from cyberleek, unrelated to real ransomware attacks, and have been excluded). The selection below covers the 6 most active groups.

Group Activity

the crew: focused on Myanmar institutions (6 claims)

Within a single batch it claimed, in sequence, AYA Bank (Myanmar), KBZ Bank, Htoo Hospitality, and Parami University among Myanmar institutions, plus Cyprus Airways and an Indonesian police personnel database. The dense concentration of Myanmar targets is worth noting — over the same period, security researchers disclosed "Operation QUICSILVER," an espionage campaign against Myanmar's government and IT sector (which Seqrite Labs attributes to a China-linked group). There is no evidence at present that the two are connected; this is recorded only as a concurrent regional risk signal.

dark project: 6 claims

Victims include a Connecticut dental practice (roughly 8,000 client files, including some Social Security numbers), Pump Engineering (120,000 files / 115GB), New York corporate short-term apartment operator Furnished Quarters (155GB, including banking and financial information), and architecture and engineering firm Design-Aire Engineering (377GB, including employee personal information and building drawings).

qilin: 6 claims

Targets span agriculture, finance, manufacturing, insurance, and other industries, including AGROLAND and Structured Settlement Capital LLC.

booba team: 4 claims

Mostly professional services targets, including two law firms (Chernyy & Associates, Federis Abogados) and insurer Country-Wide Insurance (92GB).

dragonforce: 4 claims

Among them, the Brookview Financial disclosure involves financially sensitive data for thousands of clients — credit reports, Social Security numbers, home addresses — putting it in a higher risk tier.

akira: 3 claims

Targets include thermal equipment supplier Boustead International Heaters (392GB, containing a large volume of employee personally identifiable information).

Note

The RansomLook feed also carried 10 postings from an account named "cyberleek," all consisting of purported "GTA 6" leak material (maps, videos, and so on) rather than ransomware attack disclosures against real companies. This brief does not count them in the group activity tally.

← Prev
Ransomware Watch · Aug 25, 2026
Next →
Ransomware Watch · Aug 27, 2026