Extortion activity and victim disclosures across active groups.
Data source: RansomLook recent-posts API (`https://www.ransomlook.io/api/posts?days=1`, public endpoint). This batch's discovered timestamps span **2026-06-14T17:45 → 2026-06-15T15:44**. The payload contains only `group_name` + `discovered`, with **no victim / sector / geo fields** — so the victim/sector columns below are left empty, and named victims are supplemented from news sources.
Data source: RansomLook recent-posts API (`?days=1`, public endpoint). The latest batch returned has discovered timestamps of **2026-06-08 → 2026-06-09** (no 06-14/15 posts appeared). The payload contains only `group_name` + `discovered`, with **no victim / sector / geo fields** — so the victim/sector columns below are left empty, and named victims are supplemented from news sources.
Data note: The RansomLook API / RSS and the ransomware.live API were blocked in the sandbox by egress/source policies (returned empty). This issue was reconstructed via WebSearch aggregation (Ransom-DB, Bitdefender, MOXFIVE, Check Point, and other tracking sources). Counts are a **lower bound**, not a complete leak-site snapshot.
Window: past 24 hours (2026-06-12 → 2026-06-13). **Degraded data-source notice**: RansomLook `/api/posts` and RSS could not be pulled directly from the sandbox this cycle (provenance/egress restrictions). The victim data below was reconstructed via WebSearch from **ransomware.live** and leak-tracking sites; it is **not a complete leak-site snapshot**, covers only the named victims that could be retrieved, and the counts are lower bounds.
Window: past 24–48 hours. **Degraded data-source notice**: RansomLook `/api/posts` returned **403 Forbidden** from the sandbox egress today, and RSS was likewise unreachable. The victim data below was reconstructed via WebSearch from **ransomware.live** and leak-tracking sites; it is **not a complete leak-site snapshot**, covers only the named victims that could be retrieved, and the counts are lower bounds.
Data source: RansomLook `/api/posts?days=1` (window ending 2026-06-09 14:50 UTC, the most recent data this API call returned). This call returned only `group_name` and `discovered`, **with no victim / sector / geo fields**, so the victim table is based mainly on group activity and sector / geography matching is unavailable today.
Window: past 24 hours (RansomLook `/api/posts?days=1`, covering 2026-06-08 16:49 → 2026-06-09 14:50 UTC, Monday-into-Tuesday weekday catch-up)
Window: past 24 hours (2026-06-08 → 2026-06-09, Monday into Tuesday, weekday catch-up beginning)
Window: past 24 hours (2026-06-07 → 2026-06-08, Sunday into Monday; DLS posting is light over the weekend and starts catching up on Monday)
Window: past 24 hours (2026-06-06 → 2026-06-07, a weekend, when new DLS posts are typically fewer)
Window: past 24 hours (2026-06-05 → 2026-06-06)
Time window: past 24 hours (2026-06-04 → 2026-06-05)
Time window: past 24 hours (2026-06-03 → 2026-06-04)
Time window: past 24 hours (2026-06-02 → 2026-06-03)
Time window: past 24 hours (2026-06-01 → 2026-06-02)
Time window: 2026-05-31 → 2026-06-01
Time window: 2026-05-29 → 2026-05-31 (rolled forward across the weekend)
Time window: 2026-05-25 → 2026-05-26
Time window: 2026-05-24 → 2026-05-25
Time window: 2026-05-23 → 2026-05-24 (including the tail end of late 5/22)
Window: 2026-05-21 → 2026-05-23 (early) · Sources: WebSearch + Ransomware.live + RansomLook public reporting
Window: 2026-05-21 → 2026-05-22 (24h)
Data from RansomLook public data cross-checked against industry news. The API was not reachable directly in WebSearch mode; this issue aggregates public leak-post signals from the past 24h.