Ransomware Watch · Aug 29, 2026
Scanned 103 ransomware-category items (RansomLook + ransomware.live, cross-verified) from the last 36 hours; roughly 60 distinct new victim claims across about 20 groups.
Most active groups
Qilin led with 14 new claims: DigiGround, Tramigo, Cosmocolor SA de CV, Infinnium, Whitehouse, GPS Grothkopp und Partner, DAB Investments, Displaydata, Providence Investments, LGG Advisors, Open Sports, Kling Automaten, Dotlines, and Globalport Terminals.
Sources: RansomLook · ransomware.live
Akira and Storm each claimed 6 victims. Akira: Alumax, BEPeterson, JRT Mechanical, Cetylite, CGP MEP, Seabrook Island. Storm: Agrimac, Sprachakademie Rhein-Ruhr, Otto Sieve GmbH, ITD Informations technologie, Our Hospice of South Central Indiana, National Salvage.
Sources: RansomLook · ransomware.live
Lockbit5 and Medusalocker each claimed 5 victims. Lockbit5: tnmed.org, fpmanagement.nl, theheartcenterofmemphis.com, dece.cz, takt.be. Medusalocker: Jgsee, Servifruit, Hungry Lion, Qualisteel, and health.nsw.gov.au.
Sources: ransomware.live
Notable targets
Rhysida claimed Valley Health Team, a US clinic network, saying it holds 9,056,196 files (3.28 TB) including 160,870 patients' records, 4.18 million diagnoses, 7.6 million unencrypted EHR scans, and SSNs and passport data.
Sources: RansomLook · ransomware.live
Rhysida also claimed a Berlin, Germany municipal target, citing 5.79 TB across roughly 1.44 million files spanning maps/geo data, legal complaints, financial records, contracts, HR files, government-supervisory documents, and passwords.
Sources: ransomware.live
Medusalocker claimed health.nsw.gov.au, the New South Wales (Australia) health department's domain, saying it extracted 103 emails.
Sources: ransomware.live
Panzer claimed Portugal's Directorate-General for Education (DGEEC), the government agency responsible for national education and science statistics.
Sources: ransomware.live
Emperador claimed Hanwha Renewables, saying it extracted roughly 12 GB of sensitive financing data across four solar projects -- Bonanza Peak, Boulder Solar III, the Obreron Portfolio, and Project Sprout.
Sources: RansomLook · ransomware.live
Incransom claimed Ruby Seven Studios, a gaming company, saying it holds 114 GB (133,851 files) including source code, game design documents, and royalty/tax records.
Sources: ransomware.live