Threat Watch · Sep 5, 2026
Two of this window's leak-site posts are market listings rather than extortion notices. ShinyHunters used its slot for a purchase offer, bidding for "DL data" held by another broker at what it calls "a payment as large as what you would get paid in a ransom" — the post names no victim and does not identify the dataset. Dysphor1a listed MBT Telecom's 209,970 subscriber records simply as "For Sale". Encryption extortion, data extortion and straight sale listings are now sharing the same page.
Group activity
LockBit5 — 3 new claims
pscindustries.com (a supplier of insulation, gasketing, seals and adhesives for over 60 years), kalahealth.eu (nutraceutical manufacturing and distribution) and huisartsencentrumkleiniterson.nl (a Dutch primary-care practice). All three were recorded independently by both trackers.
Sources: RansomLook · ransomware.live
Vexy — 3 new claims
Annapurna Fashion (fabric and garment manufacture and export), Palsana Enviro (operator of a common effluent treatment plant for textile processors, 150 MLD stated capacity) and Sancity Soft Touch (IT services and payment gateways). All three are in India and clustered along the textile supply chain. Both trackers recorded them, one filing the group as Vexy Ransomware.
Sources: RansomLook · ransomware.live
The Gentlemen — 2 new claims
The listed healthcare data company Veradigm, and Zdrowit S.A., a Polish pharmacy chain operating since 2004 with over 1,000 employees across 40-plus cities in southern and central Poland. Both sit on the data-heavy side of healthcare.
Sources: RansomLook
Akira — 2 new claims
Stransky Heiz-Mess-Regeltechnik GmbH, a German heating and control-technology firm, and Worrell Corporation, an Indianapolis promotional products and print services company. Both posts pre-announce a specific volume — 50GB and 45GB respectively — and name employee personal information, contracts, financials and NDAs. Recorded by both trackers.
Sources: RansomLook · ransomware.live
Space Bears — 2 new claims
D-MAX Engineering, a San Diego environmental consultancy specializing in storm water services for government agencies, and Sports Endeavors, the North Carolina sporting goods retailer behind Soccer.com, WorldSoccerShop and 431 Sports. Sports Endeavors appears on both trackers.
Sources: RansomLook · ransomware.live
Pear — 2 new claims
EdgeChem Jamaica Limited, a manufacturer of automotive, industrial, decorative and furniture coatings, and Kovo Healthtech Corp, a Canadian AI process-automation company. Both recorded independently by the two trackers.
Sources: RansomLook · ransomware.live
DragonForce — 2 new claims
Homewood Sales Corporation, which supplies equipment life-extension products including automatic voltage regulators and controls, and Norwood Law Firm, a Tulsa practice covering personal injury, criminal defense, business and family law.
Sources: RansomLook
ShinyHunters — a purchase offer, not a victim claim
The group's leak-site slot this time carries an open message to another data broker, saying it has made several large offers by forum DM for the "DL data" the broker holds, that it is willing to pay what "can be considered a payment as large as what you would get paid in a ransom", and leaving a contact address. The post names no victim and does not identify the dataset.
Sources: RansomLook
Notable targets
Veradigm — claimed by The Gentlemen
Veradigm Inc. (OTC: MDRX, formerly Allscripts, headquartered in Chicago) is a US healthcare technology and data analytics company whose core asset is one of the largest multi-EHR data networks in US healthcare, with over 450,000 connected providers and 200M+ patient records. The group claims more than 3.5 million personal patient records and explicitly lists full name, address, social security number, email and phone, plus guarantor information. It is the most sensitive claim in this window.
Sources: RansomLook
Wolfram Research — claimed by Direwolf
The maker of Mathematica, Wolfram Alpha and the Wolfram Language, used widely across scientific research, education and data analysis. Both trackers recorded the same claim independently. The post carries no volume figure and no description of the data.
Sources: RansomLook · ransomware.live
MBT Telecom — claimed by Dysphor1a, listed for sale
Myanmar Broadband Telecom, a fiber ISP and network solutions provider established in 2013. The post claims a full customer database of 209,970 records spanning its FTTH, DIA and enterprise VPN services, with fields covering names, phone numbers, addresses, device types and account passwords. The group published a sample in which the passwords are in plaintext — that detail matters more than the record count. Recorded by both trackers.
Sources: RansomLook · ransomware.live
Judicial Branch of the Province of Jujuy, Argentina — claimed by Emperador
The body runs court information, digital case management, mediation services and publication of rulings for the province. The group claims its WordPress databases, login credentials to internal systems and email credentials, puts the volume at 4.2 GB, and presses for payment directly in the post. What makes a judiciary claim worth noting is not the volume but that case material and identity credentials sit in one place.
Sources: ransomware.live
Hochschule Heilbronn Bildungscampus — claimed by Panzer
The named body is the university's general students' committee (AStA), which represents students internally and externally and provides legal and tax counseling and a grievance service — meaning it holds student identity information and advisory records together. Recorded by both trackers.
Sources: RansomLook · ransomware.live
Kwangmyung Industry (광명산업(주)) — claimed by Blacklocks
A South Korean automotive parts manufacturer established in 1985, producing car seats, molds and jigs, with plants in Cheonan, Asan, Gwangju and Gyeongju and an export division. When a parts supplier is named, the risk usually travels up the supply chain toward the automakers it ships to.
Sources: ransomware.live
All of the above are claims published by the groups themselves, not confirmed intrusions. Both trackers mirror the groups' own leak sites; where an entry says both recorded it, that is the only cross-check available here.