Threat Watch · Sep 2, 2026
The two claims worth flagging today target critical infrastructure and government rather than the usual small-business victims: Qilin claimed a U.S. rural electric cooperative (Grayson Rural Electric Cooperative) and Quebec's construction-industry regulator (Commission de la construction du Québec).
Group Activity
Thegentlemen — 4 new victims
Targets include CareerSource Palm Beach County (a Florida workforce-development agency), Nasdaq-listed healthcare company Nutex Health (NUTX), IT services firm Seasia Infotech, and UK streetwear media platform The Sole.
Sources: RansomLook · ransomware.live
Qilin — 3 new victims, including two critical-infrastructure/government targets
Targets: Grayson Rural Electric Cooperative (US), Commission de la construction du Québec (Canada), and Uak University (UAE).
Sources: RansomLook · ransomware.live
Akira — 3 new victims
All claim stolen employee passports, Social Security numbers, and driver's licenses: Flex1 (desktop-as-a-service provider, 402GB), BYK Construction (homebuilder, 27GB), and Congressional Iron Works (metal-structures contractor, 35GB).
Sources: RansomLook · ransomware.live
Direwolf — 3 new victims
Targets: Honeycomb Programs Inc (insurance), PT Intraco Penta Tbk (Indonesian listed industrial-equipment company), and Oportunidados (business services).
Sources: RansomLook · ransomware.live
Everest — 3 new victims
Targets include Taiwanese surveillance-camera maker VIVOTEK, Rise UP, and Italtel Peru.
Sources: RansomLook
Notable Targets
Anubis claims Marlborough Partners, a capital-solutions advisory firm
The tracker logs it as a "major data breach" without specifying the volume.
Sources: RansomLook · ransomware.live
Holland & Knight, a large U.S. law firm, was claimed by two different groups across the two trackers
RansomLook logged the claim under leakeddata, while ransomware.live logged the same victim under SilentRansomGroup — neither source explains the discrepancy.
Sources: RansomLook · ransomware.live
Aurora claims Chip 1 Exchange, a Germany-headquartered global electronics distributor
The claim covers 13 years (2013-2026) of corporate operations data, including 40+ employee passport photos, I-9/W-4 forms with Social Security numbers, complete 2026 financials with bank account details, and 15+ exclusive manufacturer franchise agreements with pricing terms.
Sources: RansomLook · ransomware.live