Skip to main content

RANSOMWARE TRACKER

2026 | Updated Daily

Ransomware Activity Tracker 2026

Live daily intelligence on ransomware campaigns, victim reports, threat actor activity, and IOCs. This page consolidates all daily ransomware reports into a single, searchable resource. Updated every day.

19 Reports
2 Months Covered
May 22, 2026 Last Updated

May 2026

May 22, 2026 CMD Ransomware Hits 5 Healthcare Nonprofits

CMD ransomware group is the most active, targeting five healthcare and nonprofit organizations, with the United States remaining the primary victim geography.

CMD Ransomware Hits 5 Healthcare Nonprofits

Statistical Overview

Victim Totals

  • This month: 561
  • This quarter: 1339
  • Year to date: 3965
  • Last 24h: 24

Quarterly Breakdown

Q1: 2631 | Q2: 1339 | Q3: 0 | Q4: 0

Ransomware activity continues to accumulate this quarter, with 24 new victims identified in the last 24 hours. This surge is predominantly influenced by groups such as CMD, Akira, APT73, and Qilin.

Introduction

Recent ransomware activity shows 24 new victim disclosures and sustained threat actor activity. Dominant groups included CMD, Akira, APT73, and Qilin, collectively responsible for over two-thirds of the reported incidents. Affected sectors include Healthcare, Nonprofit, Manufacturing, and Technology. Most organizations were targeted within the United States.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1CMD5Holy Name of Jesus, Houston Eye Associates, Raise the Bottom (+2)United States, CanadaNonprofit, Healthcare
2APT734Grupopetersen.com.ar, Minsa.com.mx, Tkgm.gov.tr (+1)Argentina, MexicoMedia & Entertainment, Government / Public Sector
3Akira4Buffalo niagara convention center, Function enterprises, Gitis (+1)United States, ItalyConstruction & Engineering, Hospitality & Travel
4Qilin4Roto immobilien, Semgrep, Snyder packaging (+1)United States, AustriaReal Estate, Technology / Software
5CoinbaseCartel2Openmind networks new, Pragmatic solutions newIreland, GibraltarTechnology / Software, Telecommunications
6DragonForce1Le pain quotidien usUnited StatesHospitality & Travel
7Gunra1Cablematic dos mil sluSpainTechnology / Software
8INC Ransom1threadinnovationsCanadaManufacturing
9Medusa Locker1Sgs gmbh demoGermanyManufacturing
10World Leaks1Bmj paperpackIndonesiaManufacturing

CMD was the most active ransomware group, impacting five organizations primarily in the Nonprofit and Healthcare sectors, including Holy Name of Jesus and Houston Eye Associates. Other significant actors, including APT73, Akira, and Qilin, each reported four new victims, diversifying their targeting across Media & Entertainment, Government, Construction & Engineering, Hospitality & Travel, Real Estate, and Technology sectors. This broad activity shows ongoing pressure across various industries, with the United States remaining a primary target geography, a trend observed across recent ransomware group activity updates.

Victim Distribution

By Country

  • United States: 11
  • Canada: 2
  • Spain: 1
  • Turkey: 1
  • Argentina: 1
  • Panama: 1
  • Mexico: 1
  • Italy: 1
  • Ireland: 1
  • Indonesia: 1

By Industry

  • Medical Practices: 2
  • Food and Beverage Manufacturing: 2
  • Manufacturing: 2
  • Electronics and Technology Distribution: 1
  • Religious Organization: 1
  • Packaging and Containers Manufacturing: 1
  • Law Firms & Legal Services: 1
  • Hospitality: 1
  • Healthcare: 1
  • Construction: 1

The concentration of attacks continues to be highest in the United States, representing nearly half of all new victims. Industrially, the threat environment shows a persistent focus on medical practices and the broader manufacturing sector, which points to strategic targeting of both critical services and industrial operations.

Ransomware News

Topline

Recent developments demonstrate persistent ransomware threats across multiple sectors, characterized by significant data exfiltration, service disruptions, and increasing legal ramifications.

Campaigns & Operations

The Ransom Home group claimed responsibility for a cyberattack on Hospital Clínic de Barcelona, demanding $4.5 million and threatening to release 4 TB of patient data, though authorities have stated they will not pay. Separately, Liberty Mutual is facing a federal class-action lawsuit following a data leak attributed to the Everest Group ransomware operation, which allegedly exfiltrated 108 GB of client information affecting over 15,630 individuals. In Japan, Enessance Holdings Co., Ltd. and Hokuyo Co., Ltd. both disclosed ransomware incidents; Enessance confirmed encryption and the exfiltration of approximately 365,000 customer and 2,000 employee records, while Hokuyo reported a system outage that has since been resolved. Austria's Rhomberg Bau Group also experienced an intrusion involving data exfiltration and ransom demands, prompting a police investigation and system segmentation.

Vulnerabilities & TTPs

The Everest Group's operational tactics frequently involve initial access via credential theft, phishing, or exploiting unpatched services. They then move laterally using legitimate administrative tools to blend with normal network traffic. Data exfiltration remains a consistent outcome across these varied incidents, showing its central role in modern ransomware and extortion campaigns.

Analyst Note

These incidents collectively demonstrate the persistent financial and reputational impact of ransomware, with an ongoing emphasis on data exfiltration as a primary means of coercion for threat actors.

Technical Takeaways

  • CMD is the most active group, primarily targeting Healthcare and Nonprofit sectors with five confirmed victims.
  • The United States remains the most frequently targeted country, accounting for nearly half of all new ransomware victim disclosures.
  • Data exfiltration is a prevalent tactic across multiple ransomware incidents, leading to significant financial and legal consequences for victim organizations, as seen in the Liberty Mutual case.
  • Beyond Healthcare, groups like Akira (see our ransomware threat update) and Qilin (detailed in our Qilin ransomware threat activity post) continue to diversify their targeting across Construction, Hospitality, Real Estate, and Technology.
  • The persistence of ransomware attacks necessitates strong incident response and data protection strategies, given ongoing exfiltration and operational disruption.
May 21, 2026 Ransomware Activity Driven by VPN Exploitation, Takedowns

VPN vulnerabilities and infrastructure takedowns are driving current ransomware activity, impacting 22 new victims across diverse sectors.

Ransomware Activity Driven by VPN Exploitation, Takedowns

Statistical Overview

Victim Totals

  • This month: 542
  • This quarter: 1320
  • Year to date: 3946
  • Last 24h: 22

Quarterly Breakdown Q1: 2631 | Q2: 1320 | Q3: 0 | Q4: 0

Ransomware activity continues at a consistent pace, with the observed 22 new victims in the last 24 hours contributing to the ongoing quarterly totals. This period reflects a diverse targeting approach across various sectors and geographies.

Introduction

The past 24 hours saw 22 new ransomware victims, indicating persistent activity across the threat environment. The most active groups included Payload (4 victims), APT73 (3 victims), CoinbaseCartel (3 victims), and The_Gentelman (3 victims). Affected sectors ranged from Transportation & Logistics and Healthcare to Technology/Software and Manufacturing, with many incidents in the United States.

Ransomware Summary Table

# Group Victims (24h) Sample Victims Geos Sectors
1 Payload 4 A-sonic logistic solutions, G theodor freese, Internal medicine and pediatrics of cullman (+1) Germany, Singapore Transportation & Logistics, Healthcare
2 APT73 3 Alkaloid.com.mk, Narit.or.th, Ungererandcompany.com United States, Thailand Pharmaceuticals & Biotech, Manufacturing
3 CoinbaseCartel 3 Openmind networks, Panasonic aero, Pragmatic solutions United States, Gibraltar Telecommunications, Technology / Software
4 The Gentelman 3 Grupo pasquel, Mbm corp, Ymca of columbia United States, Ecuador Retail & Ecommerce, Manufacturing
5 CMD 2 Goodstone Group, Ira & Larry Goldberg Coins & Collectibles United States Professional Services
6 Nova (RALord) 2 Neubox, Softseba Bangladesh, Mexico Technology / Software
7 Qilin 2 Hamer childs, Porter w yett United States, United Kingdom Legal, Construction & Engineering
8 3AM 1 Consultic.be Belgium Technology / Software
9 Brain Cipher 1 Sheppadviser.com.au Australia Media & Entertainment
10 LockBit 1 shottermill-jun.surrey.sch.uk United Kingdom Education

Payload emerged as the most prolific ransomware group in this period, predominantly impacting transportation and healthcare entities. Other notable activity includes APT73 targeting manufacturing and pharmaceuticals, CoinbaseCartel breaching telecommunications and technology firms, and The_Gentelman affecting retail and manufacturing across the Americas. Several groups, including Qilin and LockBit, continued to target diverse geographies and industries.

Victim Distribution

By Country

  • United States: 8
  • United Kingdom: 2
  • Singapore: 2
  • Thailand: 1
  • Australia: 1
  • North Macedonia: 1
  • Mexico: 1
  • Ireland: 1
  • Gibraltar: 1
  • Germany: 1

By Industry

  • Astronomical Research: 1
  • Office Equipment Manufacturing: 1
  • Numismatics and Collectibles: 1
  • Nonprofit Organization: 1
  • Healthcare: 1
  • Executive Coaching and Leadership Development: 1
  • Construction: 1
  • Chemical Manufacturing: 1
  • Aviation and Aerospace Component Manufacturing: 1
  • Law Firms & Legal Services: 1

The United States remains a primary target, with the highest number of victims, while industrial and technology sectors show broad exposure. This suggests a continued opportunistic targeting approach combined with a focus on economically vital infrastructure.

Ransomware News

Topline - Law enforcement significantly disrupted ransomware infrastructure while threat actors continued exploiting VPN vulnerabilities and targeting supply chain entities and financial institutions.

Campaigns & Operations - In a coordinated multinational effort, Europol executed "Operation Saffron," seizing the "First VPN" service and arresting its administrator, which was widely used by ransomware gangs for anonymity. Concurrently, ransomware attacks impacted Hongsu Technology, a TSMC CoWoS equipment factory in Taiwan, and Nostrum Co., Ltd. in Japan, which provides learning support services. ShinyHunters claimed a data breach against 7-Eleven, exfiltrating franchisee data. CoinbaseCartel and TeamPCP asserted data-leak claims against an Open-Source Visualization Platform and a major developer platform respectively. Reports also described ongoing threats to the Korean financial sector, involving a three-stage malware workflow. Various industrial organizations also faced APT and financial attacks from groups like Head Mare, LockBit 5.0, and DynoWiper/LazyWiper. For more information on recent threat activity, see our analysis of latest ransomware threat activity.

Vulnerabilities & TTPs - Threat actors continue to exploit poorly patched SonicWall SSL VPN appliances, specifically using CVE-2024-12802 for MFA bypass and credential brute-forcing. Beyond VPNs, initial access commonly involved phishing delivering backdoor-downloader-droppers and infostealers, as observed in the Korean financial sector. The threat environment also includes discussions on securing AI model pipelines from ransomware, which targets vulnerabilities in weights, training pipelines, and orchestration layers.

Analyst Note - The period shows a dual focus: disrupting established cybercrime infrastructure and confronting persistent exploitation of network perimeter vulnerabilities and expanding threats to emerging technologies.

Technical Takeaways

  • Europol's takedown of "First VPN" demonstrates an increased focus on disrupting core cybercrime infrastructure.
  • Persistent exploitation of VPN vulnerabilities, specifically SonicWall SSL VPN CVE-2024-12802, shows the need for complete patching and multi-factor authentication.
  • Ransomware activity includes targeting of supply chain entities, such as the attack on Hongsu Technology, a TSMC CoWoS equipment supplier.
  • Financial and industrial sectors face diverse attack chains, incorporating multi-stage malware, infostealers, and a variety of ransomware strains (e.g., Everest, Qilin, LockBit 5.0).
  • Emerging threats to AI infrastructure show vulnerabilities within model pipelines, training data, GPU clusters, and other components, which points to a future ransomware vector.
May 18, 2026 Ransomware Activity Insights and Real-Time Intelligence

Discover the latest ransomware activity and crucial threat intelligence. Uncover top groups, targeted sectors, and critical vulnerabilities impacting organizations today. Don't miss these insights!

Ransomware Report - 05/18/2026

Statistical Overview

Victim Totals

  • This month: 468
  • This quarter: 1246
  • Year to date: 3872
  • Last 24h: 28

Quarterly Breakdown

Q1: 2631 | Q2: 1246 | Q3: 0 | Q4: 0

Ransomware activity in Q2 continues at a steady pace, consistent with previous trends. The year-to-date victim count is substantial, with 28 new entities impacted in the last 24 hours.

Introduction

The past 24 hours saw 28 new ransomware victims publicly reported, showing the persistent threat across various sectors. Qilin and Titan were the most active groups, each claiming seven new victims. Manufacturing and Construction & Engineering sectors were impacted, and professional services and government entities across diverse geographies also continued to be targeted.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin7Buckeye paper, Fruits queralt, Majlis perbandaran alor gajah (+4)Canada, MalaysiaConstruction & Engineering, Media & Entertainment
2Titan7Abp autoricambi srl, Crit tunisie, Dfi america, llc (+4)United States, SingaporeConstruction & Engineering, Automotive
3AiLock2Design engineering & consulting, Jazz hipsterUnited States, TaiwanConstruction & Engineering, Manufacturing
4Akira2Healthtrax fitness & wellness, Vacu - lugUnited Kingdom, United StatesHealthcare, Manufacturing
5Doommageddon2Hiddenbay urla - serra sakli koy buti̇k turi̇zm i̇şletmeleri̇, Kolorkim kimyaTurkeyHospitality & Travel, Manufacturing
63AM1Molinoscabodi.com.arArgentinaAgriculture & Food
7Audit1Trésor publicSenegalGovernment / Public Sector
8CMD1stonehenge therapeutic communityCanadaNonprofit
9Chaos1Fallprotect.comUnited StatesManufacturing
10INC Ransom1bergen1.netUnited StatesEducation
11Lamashtu1Msmelt.comMalaysiaManufacturing
12Medusa Locker1Estrela demoIndiaProfessional Services

Ransomware activity over the last 24 hours was dominated by Qilin and Titan, collectively responsible for 14 of the 28 new victims. Manufacturing and Construction & Engineering sectors remain primary targets, experiencing attacks from multiple groups including AiLock, Akira, Doommageddon, and Lamashtu. Geographically, North America, particularly the United States and Canada, sustained a high volume of attacks. Targets today include Majlis perbandaran alor gajah (Malaysia) by Qilin, and Trésor public (Senegal) by Audit. This shows a continued focus on government and public-sector institutions. For more on Qilin's recent activity, see our Ransomware Victims Update - May 16 and Qilin Ransomware Threat Activity - May 14.

Victim Distribution

By Country

  • United States: 9
  • Canada: 3
  • Turkey: 2
  • Malaysia: 2
  • Spain: 1
  • United Kingdom: 1
  • Tunisia: 1
  • Taiwan: 1
  • Argentina: 1
  • Singapore: 1

By Industry

  • Manufacturing: 2
  • Public Administration: 2
  • Food and Beverage Services: 1
  • Industrial Machinery Manufacturing: 1
  • Higher Education: 1
  • Healthcare Services: 1
  • Health, Wellness & Fitness: 1
  • Food & Beverage: 1
  • Computer Hardware Manufacturing: 1
  • Architectural Services: 1

The concentration of attacks over the last 24 hours shows a continued focus on the United States and Canada, while the manufacturing sector remains a consistent high-value target for ransomware operators globally. Public administration also saw sustained pressure, which indicates diversified targeting.

Ransomware News

Topline

The past 24 hours saw several ransomware-related developments, including claims by the Qilin group, a GitHub breach impacting Grafana, an internal breach exposing The Gentlemen ransomware gang's operations, and new Q1 2026 threat intelligence.

Campaigns & Operations

The Qilin ransomware-as-a-service operation claimed Generation Life as a victim following a breach via an external service provider. Qilin's global victim tally reached 1,842. CoinbaseCartel claimed responsibility for breaching Grafana's GitHub environment using a stolen access token to download source code. Links were drawn to ShinyHunters/Lapsus$ affiliates. The Gentlemen ransomware gang experienced an internal breach in May 2026, exposing its backend infrastructure, affiliate program data, and operational tools, despite an estimated 1,570 victims. 3i Infotech Limited in India reported a ransomware cyber attack on May 16, 2026. A Check Point Research threat intelligence report also detailed breaches at Vodafone, West Pharmaceutical Services, and Foxconn's North American operations.

Vulnerabilities & TTPs

Threat intelligence showed critical vulnerabilities, including Claw Chain vulnerabilities in OpenClaw (CVE-2026-44112, CVSS 9.6), an unpatched macOS kernel exploit bypassing Memory Integrity on M5 chips, Windows zero-days YellowKey and GreenPlasma, and other flaws in NGINX (CVE-2026-42945), Catalyst SD-WAN (CVE-2026-20182), and Wi-Fi components (CVE-2026-28819). The Grafana breach showed the risk of GitHub token leakage and credential theft, while phishing campaigns deploying v0.dev to harvest credentials via Telegram bots continue to be prevalent.

Analyst Note

These incidents show a continued trend of supply chain targeting, credential theft for initial access, and persistent activity by established ransomware groups. Q1 2026 analyses from Check Point Research and Kaspersky confirmed widespread attacks, impacting thousands of users and introducing thousands of new ransomware variants.

Technical Takeaways

  • Increased Focus on Government Entities: Both Qilin and Audit groups targeted public administration bodies (Majlis perbandaran alor gajah, Trésor public). This indicates a persistent, high-value target sector.
  • Supply Chain & Credential Theft: The Grafana breach, attributed to CoinbaseCartel via a stolen GitHub token, shows how supply chain vulnerabilities and credential compromise are critical initial access vectors.
  • Group Activity: Qilin maintained a leading position with seven new victims, further extending its global reach. For more on Akira's activity, see our Ransomware Threat Update Intelligence - May 11.
  • Ongoing Q1 Threat Volume: Multiple threat intelligence reports show significant ransomware activity and new variant introductions in Q1 2026. This suggests a consistently high threat level extending into Q2.
  • Vulnerability Exploitation: Several critical CVEs across various platforms (OpenClaw, NGINX, Catalyst SD-WAN, Wi-Fi components) were flagged, which indicates potential for mass exploitation and continued TTP development by threat actors.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

A: In the past 24 hours, Qilin and Titan were the most active ransomware groups, each claiming 7 new victims. Other groups like AiLock, Akira, and Doommageddon also reported multiple new victims.

Q: What industries were most targeted by ransomware today?

A: Manufacturing and Construction & Engineering were the most frequently targeted industries, each seeing multiple attacks from various groups. Public Administration also experienced considerable targeting, including high-value government entities.

Q: What regions saw the most ransomware attacks today?

A: The United States recorded the highest number of ransomware victims with 9 incidents, followed by Canada with 3. Turkey and Malaysia also saw 2 reported victims each. This indicates a broad global distribution of attacks.

Q: Were there any major breaches or exposures involving ransomware gangs or major organizations?

A: Yes, the CoinbaseCartel group claimed responsibility for breaching Grafana's GitHub environment by stealing an access token and downloading source code. The Gentlemen ransomware gang also suffered an internal breach, exposing their backend infrastructure and operational data.

Q: What critical vulnerabilities were detailed in recent threat intelligence reports?

A: Recent reports flagged several critical vulnerabilities, including Claw Chain vulnerabilities in OpenClaw (CVE-2026-44112), unpatched Windows zero-days, and flaws in NGINX (CVE-2026-42945), Catalyst SD-WAN (CVE-2026-20182), and Wi-Fi components (CVE-2026-28819), and a macOS kernel exploit.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

May 16, 2026 Ransomware Victims Update and Threat Intelligence

Uncover the latest ransomware victims and threat intelligence instantly. This report details active groups like Qilin, LockBit, and emerging attack patterns. Stay informed!

Ransomware Report - 05/16/2026

Statistical Overview

Victim Totals

  • This month: 424
  • This quarter: 1202
  • Year to date: 3819
  • Last 24h: 24

Quarterly Breakdown

Q1: 2622Q2: 1202Q3: 0Q4: 0

Quarter 2 activity continues, with 1202 victims recorded to date. This follows an active Q1. The last 24 hours saw 24 new entities impacted, showing ongoing pressure across various sectors.

Introduction

In the last 24 hours, PurpleOps recorded 24 new ransomware victims, showing persistent threat actor activity. The most active groups included Qilin (8 victims), LockBit (6 victims), and DragonForce (4 victims). Targeting remained geographically diverse, though concentrated in the United States. Sectors such as Healthcare and Education experienced significant impact.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin8Australian college of business intelligence, B.care medical center, Common part groupings (+5)Thailand, United StatesFinancial Services, Education
2LockBit6centralromana.com.do, jec.co.id, lbreng.com.br (+3)Dominican Republic, NetherlandsEducation, Healthcare
3DragonForce4Advanced medical consultants, Advancedhealth, Advancedhealth. (+1)United StatesConstruction & Engineering, Healthcare
4CoinbaseCartel2Grafana, ZywaveUnited StatesTechnology / Software
5Exitium1Gastroenterology & hepatology of cny[full_leak]United StatesHealthcare
6Medusa Locker1Estrela industrial demoBrazilManufacturing
7Rhysida1Tower view primary schoolUnited KingdomEducation
8The Gentelman1Ross yerger insuranceUnited StatesInsurance

Today's ransomware activity was primarily led by Qilin, which accounted for a third of all new victims. The group's targets included financial services and education entities across Thailand and the United States. LockBit and DragonForce were also active, contributing to pressure on the healthcare sector. No specific high-value government or critical infrastructure targets were identified among the new victims in the last 24 hours. PurpleOps continues to monitor these groups, providing real-time ransomware threat activity updates.

Victim Distribution

By Country

  • United States: 11
  • Australia: 3
  • Brazil: 3
  • Thailand: 2
  • United Kingdom: 1
  • Peru: 1
  • Netherlands: 1
  • Indonesia: 1
  • Dominican Republic: 1

By Industry

  • Healthcare: 4
  • Education: 3
  • Healthcare Services: 1
  • Software Development: 1
  • Software: 1
  • Retail: 1
  • Pain Management Medicine: 1
  • Insurance: 1
  • Industrial Machinery & Equipment: 1
  • Industrial Distribution: 1

The United States remains the primary target for ransomware attacks, accounting for nearly half of the new victims. Industrially, the healthcare and education sectors show a concentration of attacks because attackers continue to exploit their sensitive data and critical operations.

Ransomware News

Topline

Recent activity shows ongoing ransomware threats, with Qilin allegedly breaching an Australian IT provider and ShinyHunters causing data leaks by exfiltrating data from cloud environments.

Campaigns & Operations

Qilin listed Australian hospitality IT provider Bluize on its dark web leak site. Details about the incident or sample data are unconfirmed, reflecting the group's sporadic posting and potential for extortion based on exposed databases. Separately, ShinyHunters has increased its extortion tactics, using persistent social engineering and voice-based pretexts to exfiltrate multi-terabyte datasets from cloud environments, especially Salesforce and other SaaS storage. Security researchers use AI for data classification to map exposed fields and estimate risk per breach.

Vulnerabilities & TTPs

ShinyHunters' operations show a reliance on social engineering and data exfiltration from cloud environments, resulting in public dumps of extensive personal and health-related data. The broader discussion around ransomware payments shows that promises to delete data often prove unreliable, which increases long-term risks for victims. Panels also warn that AI-assisted threats and non-human identities are increasing attacks, making AI for detection and rapid microsegmentation necessary.

Analyst Note

These developments show the expanding attack surface of cloud environments and the continued effectiveness of social engineering as a primary vector, alongside the unreliability of ransomware actors post-payment. Our recent intelligence covers the ransomware intelligence update and specific Qilin ransomware threat activity.

Technical Takeaways

  • Qilin showed high activity, becoming the most active group in the last 24 hours with 8 new victims, and maintained its activity level.
  • The healthcare and education sectors are often targeted, making up 7 out of 24 new victims, which shows their vulnerability to ransomware campaigns.
  • The United States continues to be the geographic focus for ransomware operators, with 11 organizations listed as victims today.
  • ShinyHunters' activities show a heavy reliance on data exfiltration from cloud environments and social engineering, leading to large-scale data leaks.
  • Observations suggest Qilin uses extortion tactics, possibly listing exposed databases to pressure victims without confirming full data exfiltration.

FAQ

Q: Which ransomware groups were most active on May 16, 2026?

Qilin was the most active ransomware group, claiming 8 new victims. LockBit followed with 6 victims, and DragonForce with 4 victims in the last 24 hours.

Q: What industries did ransomware groups target most today?

The healthcare sector was the most targeted industry with 4 reported victims, closely followed by Education with 3 victims. Other affected sectors included financial services, technology, and manufacturing.

Q: Which countries were most affected by ransomware attacks in the last 24 hours?

The United States was the most affected country, reporting 11 new ransomware victims. Australia and Brazil each recorded 3 new victims, while Thailand had 2.

Q: Are there any specific new TTPs observed in today's ransomware activity?

Today's intelligence shows ShinyHunters' increasing reliance on social engineering and voice-based pretexts to exfiltrate multi-terabyte datasets from cloud environments, especially SaaS platforms. Qilin also exhibited a pattern of listing potentially exposed databases for extortion.

About PurpleOps

PurpleOps is a cyber threat intelligence platform that uses AI, covering every threat vector, from ransomware tracking to attack surface discovery. Its AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

May 12, 2026 Real-Time Ransomware Intelligence: Q2 Groups & Tactics

Get critical real-time ransomware intelligence on Q2's top groups, emerging tactics, and victim trends. Stay ahead of threats with instant insights into global cyber attacks.

Ransomware Report - 05/12/2026


Statistical Overview

Victim Totals

  • This month: 336
  • This quarter: 1114
  • Year to date: 3731
  • Last 24h: 40

Quarterly Breakdown

Q1: 2622Q2: 1114Q3: 0Q4: 0

With 40 new victims identified in the last 24 hours, Q2 activity shows sustained ransomware operations across multiple threat groups.


Introduction

The past 24 hours added 40 new ransomware victims to dedicated leak sites, indicating ongoing pressure on various sectors globally. Genesis led activity with 7 victims, followed by Qilin, Akira, CoinbaseCartel, and Lamashtu, each claiming 4 or 5 new targets. Geographic targeting remained concentrated in the United States. Industries such as Technology, Professional Services, Manufacturing, and Healthcare continued to experience impact.


Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Genesis7Ben f. barcus and associates pllc, Casino gaming commission, Fargo moorhead west fargo chamber (+4)India, United KingdomTechnology / Software, Nonprofit
2Qilin5Appdirect, International customer care services, Keller williams real estate - exton (+2)Canada, United KingdomManufacturing, Technology / Software
3Akira4Kaplan companies, Manhattan broadcasting, Taylor clay products (+1)United StatesMedia & Entertainment, Professional Services
4CoinbaseCartel4Alpinion, Cass information systems, Jozef stefan institute (ijs) (+1)Slovenia, South KoreaProfessional Services, Manufacturing
5Lamashtu4Ddu.mx, Naraya.com, Saharuang.com (+1)Thailand, MexicoEnergy & Utilities, Healthcare
6Aur0ra3Avanti windows & doors, Northwest handling systems, Startec group of companiesCanada, United StatesManufacturing
7INC Ransom3Bideawee, lalsgroup.com, rbh aerospace incUnited Arab Emirates, United StatesRetail & Ecommerce, Nonprofit
8Kairos2Arwini, Ayuntamiento de valdemoroGermany, SpainHealthcare, Government / Public Sector
9Brain Cipher1Ice.org.ukUnited KingdomNonprofit
10Bravox1Rivadeneyra treviño ??MexicoLegal
11CMD1advanced software products groupUnited StatesTechnology / Software
12Fulcrum1avnetUnited StatesRetail & Ecommerce

Analysis of today's ransomware activity shows Genesis as the most active group, adding 7 new victims. Groups like Qilin ransomware and Akira ransomware continue with victim counts, alongside CoinbaseCartel. Sector targeting is diverse, including Technology, Professional Services, and Manufacturing. Geographically, attacks distributed across North America, Europe, and Asia.

Targets included a Casino gaming commission by Genesis, the Jozef Stefan Institute (IJS)-a research institute-by CoinbaseCartel, and the Ayuntamiento de Valdemoro (local government) by Kairos. These incidents show persistent targeting of public sector and research institutions.


Victim Distribution

By Country

  • United States: 22
  • Mexico: 3
  • United Kingdom: 3
  • Spain: 2
  • Canada: 2
  • Thailand: 2
  • Germany: 1
  • India: 1
  • Jamaica: 1
  • Slovenia: 1

By Industry

  • Real Estate: 2
  • Manufacturing: 2
  • Legal Services: 2
  • IT Services and IT Consulting: 1
  • Aviation and Aerospace Component Manufacturing: 1
  • Business Process Outsourcing: 1
  • Chamber of Commerce: 1
  • Educational Technology: 1
  • Electronics Distribution: 1
  • Healthcare: 1

The United States remains the main target for ransomware operators, accounting for over half of all new victims in the last 24 hours. While industry targeting is broad, Real Estate, Manufacturing, and Legal Services experienced multiple incidents, which suggests a focus on sectors with high-value data or critical operational dependencies.


Ransomware News

Topline

A major education provider paid extortion demands, and a ransomware group's internal operations were exposed through a data leak.

Campaigns & Operations

Instructure reached a ransom agreement with ShinyHunters to prevent a 3.65TB Canvas data leak after attackers exploited a vulnerability in a support-ticket flow, siphoning 275 million records. Ahmed Al-Kadi Private Hospital in South Africa confirmed a ransomware breach encrypting a portion of its network. West Pharmaceutical Services experienced a cyberattack on May 4 that exfiltrated data and encrypted core systems, disrupting global operations. INC Ransom listed Earth Systems, an Australian environmental firm, claiming 600 GB of stolen data. Spain's Notin, an IT provider for notaries, was hit by Crypto24 ransomware, which deployed LockBit 5.0 to encrypt files and disrupt client services. The April 2026 Threat Trend Report showed broad global targeting across Manufacturing, Healthcare, and financial sectors, noting the emergence of new groups alongside active groups like Qilin and INC Ransom.

Vulnerabilities & TTPs

The Instructure incident involved exploiting a vulnerability within a free-for-teacher support-ticket flow. A data leak from The Gentlemen ransomware group exposed internal chats detailing RaaS operations, including access via compromised Fortinet edge gear, OpenConnect VPNs, extensive reconnaissance, EDR evasion, and mapping of critical infrastructure. South Staffordshire Water was fined after a nearly two-year intrusion that began with phishing and exploited weak monitoring, inadequate privileged access management, and unpatched legacy systems. Notin's attack by Crypto24 utilized LockBit 5.0, gaining access through stolen credentials, phishing, or exposed RDP, followed by lateral movement and data exfiltration. Overall trends in 2026 indicate a shift toward encryptionless extortion, post-quantum ransomware, and industrialized initial access via Access-as-a-Service, often using RDWeb/RDP abuse.

Analyst Note

These events show persistent reliance on known attack vectors like phishing and compromised credentials. They also demonstrate the increasing sophistication of data extortion tactics and the changing post-exploitation tradecraft documented in internal leaks.


Technical Takeaways

  • The United States consistently experiences the highest volume of ransomware attacks. This shows a continued focus on the region by threat groups.
  • Threat groups like INC Ransom, Genesis, and Crypto24 (LockBit 5.0) frequently use double-extortion tactics, combining data exfiltration with encryption to maximize pressure on victims.
  • Recent analysis shows a shift toward encryptionless extortion and the industrialization of initial access through Access-as-a-Service models, often using RDWeb/RDP abuse.
  • Internal leaks from ransomware groups, such as The Gentlemen, provide critical insights into their operational methods, including reconnaissance, EDR evasion, and how they structure affiliates.
  • Critical infrastructure and public sector organizations remain high-value targets, as shown by incidents affecting a Casino gaming commission and local government organizations.

FAQ

Q: Which ransomware groups were most active today?

Genesis was the most active ransomware group in the last 24 hours, accounting for 7 new victims. Other active groups included Qilin (5 victims), Akira (4 victims), CoinbaseCartel (4 victims), and Lamashtu (4 victims).

Q: What industries were primarily targeted in the last 24 hours?

Ransomware attacks in the last 24 hours targeted diverse industries. Real Estate, Manufacturing, and Legal Services each recorded two victims. IT Services, Aviation, Business Process Outsourcing, and Healthcare were also affected.

Q: Which geographical regions experienced the most ransomware attacks today?

The United States was the most targeted country, with 22 new ransomware victims reported in the last 24 hours. Mexico and the United Kingdom also experienced activity, each with 3 new victims.

Q: What notable technical insights emerged from recent ransomware activity?

Key technical insights include the use of vulnerabilities in support-ticket flows for data exfiltration. Also, internal group leaks provided detailed documentation of ransomware-as-a-service operations, showing continued reliance on initial access vectors like phishing, exposed RDP, or stolen credentials. There is also a shift toward encryptionless extortion and industrialization of initial access.


About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering all major threat vectors, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats and investigate incidents in natural language. Our intelligence solutions:

May 3, 2026 Ransomware Activity: Qilin Attacks & cPanel Exploits

Uncover the latest ransomware activity, Qilin attacks, and widespread cPanel exploits. Get immediate threat intelligence to secure your systems now.

Ransomware Report - 05/03/2026

Statistical Overview

Victim Totals

  • This month: 60
  • This quarter: 817
  • Year to date: 3435
  • Last 24h: 13

Quarterly Breakdown

Q1: 2622Q2: 817Q3: 0Q4: 0

Ransomware activity continues with 13 new victims in the last 24 hours, bringing the total to 60 victims this month. Q2 figures currently trail Q1's high volume, but sustained daily operations show threat actors continue pressure across various sectors, as detailed in our Breach Detection Report for May 3rd.

Introduction

In the past 24 hours, ransomware activity saw 13 new victims posted to leak sites. The Qilin group was active, accounting for six of these incidents, followed by M3RXDLS and SLSH. Targeting primarily concentrated on the United States, with Canada and Germany also affected. The technology and financial technology sectors bore the brunt of these attacks, alongside other industries.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin6Admins, Armstrong george cohen will ophthalmology, Lsm lee (+3)United States, CanadaMedia & Entertainment, Technology / Software
2M3RXDLS3Emtco.com, It-freitag.de, Manateeair.comUnited States, GermanyConstruction & Engineering, Technology / Software
3SLSH2Cushman & wakefield inc., Instructure holdings, inc. (canva lms, instructure.com)United StatesTechnology / Software, Real Estate
4Everest1FiservUnited StatesTechnology / Software
5MNT61PhotonicCanadaTechnology / Software

Today's activity was led by Qilin, responsible for nearly half of all reported incidents. Previous analyses, such as our Ransomware Threat Activity Update on May 1st, show Qilin continues to target broadly across North America. M3RXDLS also showed activity, impacting technology and construction firms, aligning with previous observations detailed in our M3RXDLS Ransomware Threat Activity report from April 26th. The Everest group attacked Fiserv, a major financial technology corporation in the United States, an incident that shows persistent pressure on critical financial infrastructure.

Victim Distribution

By Country

  • United States: 10
  • Canada: 2
  • Germany: 1

By Industry

  • Construction: 1
  • Quantum Computing: 1
  • Information Technology: 1
  • Architectural Signage Design and Fabrication: 1
  • Educational Technology: 1
  • Financial Technology: 1
  • Healthcare: 1
  • HVAC Services: 1
  • Manufacturing - Custom Machinery: 1
  • Newspaper Publishing: 1

The United States remains the primary target, accounting for most of today's ransomware victims. While a range of industries were impacted, the concentration of attacks within various technology sub-sectors (Information Technology, Educational Technology, Financial Technology, Quantum Computing) shows these entities hold continued high value for ransomware operators.

Ransomware News

Topline

A critical cPanel/WHM authentication bypass vulnerability, CVE-2026-41940, has been under mass exploitation in the wild, leading to widespread "Sorry" ransomware attacks.

Campaigns & Operations

The "Sorry" ransomware campaign has actively used a critical cPanel/WHM flaw, CVE-2026-41940, for mass exploitation since February. Attackers breached servers and deployed a Go-based Linux encryptor, appending the .sorry extension to encrypted files. Victims are directed to a Tox-based chat for negotiation, with Shadowserver identifying approximately 44,000 affected IP addresses.

Vulnerabilities & TTPs

The campaign exploits CVE-2026-41940, an authentication bypass vulnerability within cPanel/WHM. This involves gaining initial access through a critical software flaw to facilitate subsequent encryption and extortion.

Analyst Note

This incident shows a persistent threat actor strategy involving the mass exploitation of critical vulnerabilities in widely adopted enterprise software for initial access.

Technical Takeaways

  • Qilin continues to be a very active ransomware group, diversifying its targeting across sectors like Media & Entertainment and Technology/Software in North America.
  • The exploitation of CVE-2026-41940 in cPanel/WHM by the "Sorry" ransomware campaign shows a focus on mass exploitation of critical, widely used software for initial access.
  • The targeting of Fiserv by Everest shows ongoing threats specifically directed at the financial technology sector, which handles sensitive data and critical infrastructure.
  • Technology-related industries, broadly defined, consistently remain the most frequent targets, showing their perceived value and potential vulnerability.
  • Activity includes both very active, established groups (Qilin) and emerging or less frequently observed groups (M3RXDLS, SLSH), which shows dynamic threat actor activity.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

The Qilin ransomware group was the most active in the past 24 hours, publicly claiming six new victims. Following Qilin, M3RXDLS announced three new victims, and SLSH listed two.

Q: What industries were most affected by ransomware today?

The technology sector, encompassing information technology, educational technology, financial technology, and quantum computing, was most affected today. Other affected industries included construction, healthcare, real estate, and manufacturing.

Q: What countries saw the highest ransomware victim count on 05/03/2026?

The United States recorded the highest number of ransomware victims in the last 24 hours, with 10 incidents. Canada followed with two victims, and Germany reported one.

Q: Was any new vulnerability exploited by ransomware in the last 24 hours?

Yes, a critical cPanel/WHM authentication bypass flaw, identified as CVE-2026-41940, has been mass-exploited by the "Sorry" ransomware group since February. This vulnerability allowed attackers to breach servers and deploy their Linux encryptor.

Q: Were there any high-profile ransomware victims today?

Yes, Fiserv, a major financial technology provider in the United States, was listed as a victim by the Everest ransomware group. This is a high-value target due to its critical role in financial infrastructure.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

May 2, 2026 Ransomware Activity Instant Insights on Group Targets

Uncover the latest ransomware activity. See which groups are attacking, who they're targeting, and how to protect your organization with instant threat intelligence.

Ransomware Report - 05/02/2026

Statistical Overview

Victim Totals

  • This month: 47
  • This quarter: 804
  • Year to date: 3422
  • Last 24h: 35

Quarterly Breakdown

Q1: 2622 | Q2: 804 | Q3: 0 | Q4: 0

Ransomware activity in Q2, while lower than the peak of Q1, continues to add to the year-to-date victim count. The past 24 hours observed an increase, with 35 new victims reported.

Introduction

The past 24 hours saw a rise in ransomware activity, with 35 new victims added to public leak sites. The Fulcrum group was very active, responsible for most incidents, while CMD and Everest also attacked several targets. Geographically, the United States, United Kingdom, and Germany experienced the highest concentration of targeting. Financial Services, Healthcare, and Construction & Engineering sectors were most affected by attacks. For more information on recent trends, refer to our recent general ransomware activity update.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Fulcrum22analog-prospector, avnet-leaks, bookblock (+19)Japan, IndiaFinancial Services, Transportation & Logistics
2CMD3Cytek Biosciences, jg stewart construction, zampellUnited States, United KingdomPharmaceuticals & Biotech, Construction & Engineering
3Everest3Epiq global, Symcor, TsysUnited States, CanadaFinancial Services, Legal
4SafePay2Energyaction.com.au, Hpk.hamburgAustralia, GermanyEnergy & Utilities, Legal
5AiLock1Site design groupUnited StatesConstruction & Engineering
6Blackwater1TuopuChinaAutomotive
7INC Ransom1northshoreenv.comCanadaProfessional Services
8Krybit1Bomuhospital.orgKenyaHealthcare
9PEAR1Beyond measure & associates, inc.United StatesConstruction & Engineering

Today's ransomware activity saw Fulcrum as the primary actor, which posted 22 new victims across diverse geographies including Japan and India, primarily affecting Financial Services and Transportation & Logistics. Other groups like CMD and Everest targeted businesses in the United States, United Kingdom, and Canada, focused on Pharmaceuticals & Biotech, Construction & Engineering, and Financial Services. Our ongoing analysis, including previous reports on new ransomware victims and relevant industries, shows these key sectors remain under attack.

Notable targeting observed today includes Energyaction.com.au by SafePay, an attack on the Energy & Utilities sector in Australia, and Bomuhospital.org by Krybit, affecting the Healthcare sector in Kenya. The Everest group, which we have previously detailed in our reports on active ransomware groups, continues to target key financial service providers.

Victim Distribution

By Country

  • United States: 15
  • United Kingdom: 5
  • Germany: 3
  • Canada: 3
  • Australia: 2
  • None: 1
  • Kenya: 1
  • Japan: 1
  • India: 1
  • Denmark: 1

By Industry

  • Software Development: 4
  • Financial Services: 4
  • Healthcare: 3
  • Construction: 2
  • Military and Government Procurement: 1
  • Mining and Technology: 1
  • Legal and Business Services: 1
  • Landscape Architecture and Urban Design: 1
  • Information and Analytics: 1
  • Healthcare Technology: 1

The United States remains the primary target, with nearly half of the reported victims. However, the geographic spread across 10 countries shows ransomware operators use a broad, indiscriminate approach, with Financial Services and Healthcare consistently affected.

Ransomware News

Topline

Significant legal action against ransomware affiliates and ongoing operational disruptions from attacks show that the ransomware threat is persistent and evolving.

Campaigns & Operations

Two U.S. cybersecurity professionals, Ryan Goldberg and Kevin Martin, were sentenced to four years in prison for acting as affiliates for the ALPHV/BlackCat ransomware group in 2023. They used their incident response and negotiation skills in a ransomware-as-a-service model, extorting over 1,000 victims globally, taking a 20% developer cut and leaking patient data. Separately, Columbia Surgical Partners in Tennessee reported inaccessible electronic health records following a ransomware incident at its parent company, Advanced Diagnostic Imaging (ADI), which disrupted access to patient charts and surgical schedules across multiple offices.

Vulnerabilities & TTPs

While specific CVEs were not reported, the ALPHV affiliate case shows the insider threat vector and the abuse of legitimate cybersecurity expertise for ransomware operations. Frontier AI models like Mythos could give attackers faster, more capable extortion methods, possibly increasing average ransom payments. This requires strong defensive strategies such as real-time microsegmentation and continuous asset visibility.

Analyst Note

These events demonstrate two challenges: sophisticated human actors in ransomware operations and the emerging threat of AI orchestrating attacks. Both contribute to the persistent risk for critical sectors.

Technical Takeaways

  • Fulcrum was the most active ransomware group in the past 24 hours, responsible for 22 out of 35 reported victims.
  • The United States had the highest number of ransomware victims (15), followed by the United Kingdom (5) and Canada (3).
  • Financial Services and Software Development were the most targeted industries, each with 4 reported victims.
  • Critical infrastructure and healthcare entities, such as Energyaction.com.au (Energy & Utilities) and Bomuhospital.org (Healthcare), were among the high-value targets.
  • Several different ransomware groups, with nine distinct entities claiming victims, shows a fragmented but active threat environment.

FAQ

Q: Which ransomware groups were most active on May 2, 2026?

The Fulcrum ransomware group was the most active, responsible for 22 new victims in the last 24 hours. CMD and Everest were also active, each reporting 3 new victims.

Q: What industries did ransomware groups primarily target today?

Ransomware groups primarily targeted the Software Development and Financial Services industries, each had 4 new reported victims. Healthcare also had 3 new victims.

Q: Which countries experienced the most ransomware attacks in the last 24 hours?

The United States had the highest number of ransomware attacks with 15 victims in the last 24 hours. The United Kingdom followed with 5 victims, and Canada and Germany each reported 3 victims.

Q: Were there any notable high-value ransomware victims reported today?

Yes, high-value victims include Energyaction.com.au in Australia, which affected the Energy & Utilities sector, and Bomuhospital.org in Kenya, which affected the Healthcare sector. This shows continued targeting of critical infrastructure and services.

Q: What is the current cumulative ransomware victim count for the quarter?

As of May 2, 2026, the cumulative ransomware victim count for this quarter is 804. The year-to-date total is 3422 victims, showing ongoing high levels of ransomware activity.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

- Ransomware Tracking

- Dark Web Monitoring

- Credential Intelligence

- Supply Chain Risk

- All Solutions

April 2026

April 29, 2026 Track Ransomware Groups with Real-Time Threat Intelligence

Get real-time insights on active ransomware groups. Discover Aur0ra and Qilin's latest attacks, CISA KEVs, and emerging TTPs to strengthen your defenses now!

Ransomware Report - 04/29/2026

Statistical Overview

Victim Totals

  • This month: 718
  • This quarter: 718
  • Year to date: 3337
  • Last 24h: 23

Quarterly Breakdown

Q1: 2622 | Q2: 718 | Q3: 0 | Q4: 0

Ransomware activity continues into Q2, with 718 victims recorded this quarter after 2622 in Q1. This shows organizations globally face ongoing attacks.

Introduction

In the past 24 hours, 23 new ransomware victims appeared on leak sites. Aur0ra and Qilin were the most active groups, each claiming six targets. Other groups included INC_Ransom, M3RXDLS, and Blackwater. The United States remained the primary geographic target, and sectors like Transportation & Logistics, Education, and Government saw activity.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Aur0ra6Advanta genetics llc, Atlas metal industries inc, Baresque group (+3)United States, AustraliaTransportation & Logistics, Legal
2Qilin6Basch & keegan, Construction sciences, Eduporium (+3)United Kingdom, United StatesEducation, Construction & Engineering
3INC Ransom2nbd3pl.comUnited StatesTransportation & Logistics, Real Estate
4M3RXDLS2Boxtopia.co.uk, Osoftec.comIndia, United KingdomTechnology / Software, Manufacturing
5Blackwater1Shenzhen gongjin electronicsChinaTelecommunications
6Chaos1Cadencepetroleum.comUnited StatesEnergy & Utilities
7Everest1Indonesia's customs analytics platformIndonesiaGovernment / Public Sector
8Insomnia1Nephrology associatesUnited StatesHealthcare
9Interlock1Winona countyUnited StatesGovernment / Public Sector
10SecP01Color communications llcUnited StatesProfessional Services
11World Leaks1Mediaworks kftHungaryMedia & Entertainment

Aur0ra and Qilin were most active today, each claiming six victims across various sectors and regions. Aur0ra focused on Transportation & Logistics and Legal firms in the United States and Australia. Qilin affected Education and Construction & Engineering in the United Kingdom and United States. Everest targeted Indonesia's customs analytics platform, showing ongoing attacks on public-sector infrastructure. For more on Qilin's recent activities, see our ransomware threat activity update.

Victim Distribution

By Country

  • United States: 13
  • Australia: 2
  • United Kingdom: 2
  • Taiwan: 1
  • Maldives: 1
  • Indonesia: 1
  • India: 1
  • Hungary: 1
  • China: 1

By Industry

  • Information Technology and Services: 2
  • Clinical Toxicology and Molecular Diagnostics: 1
  • Warehousing: 1
  • Third-Party Logistics (3PL): 1
  • Property Management: 1
  • Oil and Gas: 1
  • Legal Services: 1
  • Law Firms & Legal Services: 1
  • Healthcare: 1
  • Government: 1

The United States was hit hardest by ransomware attacks today, accounting for over half of all new victims and showing continued targeting of North American entities. Many industries were affected, but no single sector dominated beyond IT and Legal services.

Ransomware News

Topline

Today's ransomware intelligence showed new groups appearing, critical vulnerabilities exploited, operational details of existing threats, and internal conflicts within the ransomware environment.

Campaigns & Operations

The new Vect ransomware-as-a-service (RaaS) operation uses a mature affiliate network, providing a Builder for custom encryptors across Windows, Linux, and ESXi, and is linked to TeamPCP. Meanwhile, Gelatissimo, Australia's largest gelato retailer, confirmed unauthorized network access after claims from the DragonForce ransomware group, which claims to have stolen 352.24 GB of data. Also, the M3RX ransomware group has appeared, and ShinyHunters claimed a data leak from a US interactive media company. A feud between ransomware groups 0APT and KryBit led to both leaking each other's operational data, including admin panels and access logs, offering insight into their infrastructure. Specific incidents included a ransomware attack on Pricon Microelectronics, Inc. (Philippines) affecting servers on April 22, 2026, and a confirmed encryption event at Mam Create Co., Ltd. (Japan) on April 7, 2024. For more information into M3RXDLS, review our threat activity report from April.

Vulnerabilities & TTPs

CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2024-1708, a high-severity path traversal in ConnectWise ScreenConnect enabling remote code execution, and CVE-2026-32202, a Windows Shell protection mechanism failure that could allow network spoofing. Exploitation of CVE-2024-1708/1709 has been linked to Medusa ransomware campaigns. Separately, Check Point's analysis revealed that Vect 2.0 ransomware, despite its intent, acts as a data wiper for large files due to a design error, making three-quarters of encrypted data unrecoverable across Windows, Linux, and VMware ESXi environments.

Analyst Note

This activity shows the changing nature of ransomware, with RaaS offerings becoming more professional, critical vulnerabilities quickly exploited, and unexpected tactical information emerging from inter-group conflicts.

Technical Takeaways

  • Dominant Groups: Aur0ra and Qilin accounted for over 50% of new ransomware victims in the last 24 hours, showing their high activity level.
  • Government Targeting: Everest specifically targeted Indonesia's customs analytics platform, showing continued attacks on public sector and critical government infrastructure.
  • Wiper Functionality: Vect 2.0 ransomware has been identified as acting as an accidental wiper for large files due to a design flaw, making most encrypted data unrecoverable.
  • Key Vulnerability Exploitation: CISA added CVE-2024-1708 (ConnectWise ScreenConnect) and CVE-2026-32202 (Windows Shell) to its KEV catalog. CVE-2024-1708 is noted for active exploitation in Medusa ransomware campaigns.
  • Internal Group Dynamics: The public feud between 0APT and KryBit, involving data leaks of each other's infrastructure, offers insights into ransomware operational practices and affiliate models.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

Aur0ra and Qilin were the most active ransomware groups, each claiming six new victims. Other groups like INC_Ransom, M3RXDLS, and Blackwater also recorded activity.

Q: Which industries were most targeted by ransomware today?

The primary industries targeted today were Transportation & Logistics, Education, and Construction & Engineering, based on the victim profiles of the most active ransomware groups.

Q: What geographic regions experienced the most ransomware attacks on April 29, 2026?

The United States was the most targeted geographic region, with 13 new victims. Australia and the United Kingdom followed, each recording two new victims.

Q: Were any new critical vulnerabilities (CVEs) added to CISA's KEV catalog today with ransomware relevance?

Yes, CISA added CVE-2024-1708 (ConnectWise ScreenConnect) and CVE-2026-32202 (Windows Shell) to its Known Exploited Vulnerabilities catalog. Exploitation of CVE-2024-1708 has been tied to Medusa ransomware operations.

Q: What is notable about the Vect 2.0 ransomware observed today?

Vect 2.0 ransomware has been identified as acting as a data wiper for large files. A design flaw causes the loss of most encryption nonces, making approximately three-quarters of each large file unrecoverable even if a ransom were paid.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 27, 2026 Real-Time Ransomware Intelligence Activity Update

Stay ahead of ransomware threats. Get instant insights into top groups, victim trends, and critical TTPs in our latest activity update. Protect your organization now.

Ransomware Report - 04/27/2026

Statistical Overview

Victim Totals

  • This month: 674
  • This quarter: 674
  • Year to date: 3294
  • Last 24h: 62

Quarterly Breakdown

Q1: 2622Q2: 674Q3: 0Q4: 0

Ransomware activity continues into Q2 at a steady pace, with 62 new victims recorded in the last 24 hours. The current quarter's total of 674 victims shows consistent operations from various threat groups.

Introduction

In the past 24 hours, 62 new ransomware victims were identified. Lapsus (14), DragonForce (13), APT73 (8), The_Gentelman (7), and Qilin were the most active groups (6 victims). The United States had the largest share of new targets. Affected sectors included Education, Pharmaceuticals & Biotech, and Financial Services. For broader context on recent trends, see our Ransomware Threat Activity Update from April 26.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Lapsus14Adidas extranet, Astrazeneca corp, Checkmarx.com (+11)Switzerland, SpainEducation, Pharmaceuticals & Biotech
2DragonForce13Andrewtjohnson.com, Aotco.com, Avalonflooring.com (+10)United States, AustraliaPharmaceuticals & Biotech, Financial Services
3APT738Algosaibi-gtb.com, Alx-pc.com, Arrawdah.org.sa (+5)Egypt, Saudi ArabiaPharmaceuticals & Biotech, Transportation & Logistics
4The Gentelman7Acfa regionale de calgary, Beaconhouse school system, Colegio notre dame campinas (+4)Brazil, JapanEducation, Technology / Software
5Qilin6A & a building material, Exclusive networks, Inspira (+3)Japan, NoneEducation, Technology / Software
6INC Ransom5BELFOR, MTCI, Selex-Gruppo Commerciale (+2)United States, ItalyProfessional Services, Construction & Engineering
7LockBit2planetsport.ma, pricon.com.phPhilippines, MoroccoRetail & Ecommerce, Manufacturing
8AiLock1Raich sp. z o.o.PolandTelecommunications
9Krybit1Narteks tekstil a.sTurkeyManufacturing
10PEAR1Mesquite plumbing inc.United StatesConstruction & Engineering
11Payload1Rural municipality of gimliCanadaGovernment / Public Sector
12PayoutsKing1SunsourceUnited StatesTransportation & Logistics

Lapsus was the most active group today, impacting entities in Switzerland and Spain, predominantly in Education and Pharmaceuticals. DragonForce and APT73 also showed high activity, targeting Pharmaceuticals, Financial Services, and Transportation in the United States, Australia, Egypt, and Saudi Arabia. A significant target was the Rural municipality of Gimli by Payload in Canada, showing continued interest in government and public sector entities. Qilin also continued its operations, as detailed in our Ransomware Threat Activity Update from April 25, with 6 new victims today.

Victim Distribution

By Country

  • United States: 20
  • France: 5
  • United Kingdom: 4
  • Canada: 4
  • Germany: 3
  • Singapore: 2
  • Italy: 2
  • Japan: 2
  • Saudi Arabia: 2
  • Spain: 1

By Industry

  • Manufacturing: 3
  • Healthcare: 3
  • Retail: 3
  • Education: 3
  • Insurance: 2
  • Textile Manufacturing: 2
  • Non-profit Organization: 2
  • Software Development: 2
  • Oil and Gas: 2
  • Healthcare Information Services: 1

The United States remains the primary target region, followed by France, the UK, and Canada. Attacks were broadly distributed across Manufacturing, Healthcare, Retail, and Education, suggesting active groups are not focusing on a single sector.

Ransomware News

Topline

Ransomware and extortion activity continued in the past 24 hours, with BlackFile, ShinyHunters, and the Coinbase Cartel using diverse tactics. A Check Point report also pointed out vulnerabilities and operational insights into the threat environment.

Campaigns & Operations

BlackFile, linked to The Com and tracked as UNC6671/Cordial Spider, actively escalates extortion by impersonating IT support through voice-phishing and social engineering. It compromises credentials and moves laterally within SaaS platforms and internal repositories. This group has used seven-figure ransom demands and tactics such as swatting executives. Medtronic confirmed a breach of its corporate IT environment after the ShinyHunters extortion group claimed to steal over 9 million records; no impact on patient safety was reported. Hudson Rock's investigation into the Coinbase Cartel shows it operates as an extortion-only group. It bypasses encryption by using aged infostealer credentials to access cloud and file-sharing infrastructure. An estimated 80% of its 164 victims had prior infostealer infections. Check Point's daily threat report also mentioned The Gentlemen ransomware-as-a-service.

Vulnerabilities & TTPs

Vulnerabilities and supply-chain compromises include Vercel's breach via a Context.ai compromise exploiting stolen OAuth tokens, a Bitwarden supply-chain compromise involving a malware-tainted npm release, and a Google Ads malvertising operation that stole over $1.27 million impersonating crypto platforms. Active exploitation windows for relevant CVEs include CVE-2026-40372 (Microsoft ASP.NET Core), CVE-2026-28950 (Apple iOS/iPadOS), CVE-2026-33626 (LMDeploy), and CVE-2025-29635 (D-Link DIR-823X).

Analyst Note

These incidents show the pervasive threat of credential compromise, supply-chain vulnerabilities, and the growing trend of extortion-only operations across various attack surfaces. For a full overview of today's broader threat environment, refer to our Cyber Operations Threat Briefing for April 27.

Technical Takeaways

  • Lapsus maintained high activity, accounting for 14 new victims across Education and Pharmaceuticals in Europe.
  • The Coinbase Cartel uses a pure extortion model, employing stale infostealer credentials for initial access rather than traditional encryption.
  • Public sector entities remain a target; Payload compromised a Canadian rural municipality.
  • Voice-phishing and social engineering, as seen with BlackFile, continue to be effective initial access methods for data exfiltration.
  • Several active CVEs, including CVE-2026-40372 and CVE-2026-28950, demonstrate the ongoing exploitation of known vulnerabilities in enterprise and mobile environments.

FAQ

Q: Which ransomware groups were most active in the past 24 hours?

Lapsus was the most active group, reporting 14 new victims, followed by DragonForce with 13, and APT73 with 8. The_Gentelman and Qilin also showed significant activity with 7 and 6 victims, respectively.

Q: Which industries were most targeted by ransomware today?

The most targeted industries were Manufacturing, Healthcare, Retail, and Education, each with 3 new victims. Other affected sectors included Insurance, Textile Manufacturing, Non-profit Organizations, and Software Development.

Q: What geographic regions experienced the highest volume of ransomware attacks?

The United States recorded the highest number of new victims with 20. Other significantly impacted countries included France (5), the United Kingdom (4), Canada (4), and Germany (3).

Q: Are there new ransomware groups leveraging unique TTPs?

The Coinbase Cartel is known for its "extortion-only" model, which bypasses encryption and primarily uses aged infostealer credentials to access cloud and file-sharing infrastructure. This is a distinct shift from traditional ransomware operations.

Q: Were any government or critical infrastructure entities targeted by ransomware today?

Yes, Payload claimed one victim, the Rural municipality of Gimli in Canada, a Government / Public Sector entity. This shows continued targeting of public sector institutions by ransomware operators.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform. It covers every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 26, 2026 What Are the Most Active Ransomware Groups Targeting You?

Uncover the most active ransomware groups exploiting diverse sectors. Get critical insights into current threats and how to protect your organization now.

Ransomware Report - 04/26/2026

Statistical Overview

Victim Totals

  • This month: 613
  • This quarter: 613
  • Year to date: 3234
  • Last 24h: 7

Quarterly Breakdown

Q1: 2622Q2: 613Q3: 0Q4: 0

Q2 ransomware activity shows a consistent pace. The 613 reported victims for the quarter reflect a steady, though slower, rate compared to Q1's peak. Current trends show ongoing activity across various sectors.

Introduction

PurpleOps observed 7 new ransomware victims in the past 24 hours, showing moderate activity in the threat environment. M3RXDLS was the most active group, with 5 new victims. Brain Cipher and Medusa each accounted for one. Targeting spanned diverse sectors, from Media & Entertainment to Healthcare Services, and multiple geographies, including the United States, United Kingdom, and Switzerland. For a broader perspective on recent trends, refer to our Ransomware Threat Activity Update - April 25.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1M3RXDLS5Airdriephysio.com, Anvilarts.org.uk, Dmschweiz.ch (+2)Switzerland, AustraliaMedia & Entertainment, Technology / Software
2Brain Cipher1Bridgeway-consulting.co.ukUnited KingdomConstruction & Engineering
3Medusa1Walman opticalUnited StatesHealthcare

M3RXDLS was the most active group in the last 24 hours, posting the majority of new victims and affecting organizations across Switzerland and Australia. Brain Cipher's only observed activity involved the United Kingdom's construction sector. Medusa continued its opportunistic targeting with one reported breach in the US healthcare sector. The ongoing activity of groups like Medusa shows persistent threats, as detailed in our Ransomware Intelligence Report - March 18.

Victim Distribution

By Country

  • United Kingdom: 2
  • United States: 2
  • Australia: 1
  • Canada: 1
  • Switzerland: 1

By Industry

  • Property Investment and Management Consultancy: 1
  • Healthcare Services: 1
  • Information Technology and Services: 1
  • Civil Engineering and Rail Infrastructure: 1
  • Performing Arts: 1
  • Automotive Services: 1
  • Medical Device: 1

The victim distribution over the last 24 hours shows no single concentrated geographical or industry-specific campaign. Instead, activity suggests a distributed, opportunistic targeting approach across various countries and diverse sectors. These include Healthcare Services, a sector frequently attacked, as seen in incidents like the Qilin ransomware attack on NHS.

Ransomware News

Topline - No significant ransomware-related news or public disclosures were observed within the past 24 hours, showing a period of low public reporting on new campaigns or vulnerabilities.

Campaigns & Operations - No specific new ransomware campaigns, actor activities, or reported incidents became public during this reporting period. The lack of public reporting does not preclude ongoing covert operations.

Vulnerabilities & TTPs - There were no new CVEs or notable changes in Tactics, Techniques, and Procedures (TTPs) publicly reported as being actively exploited by ransomware operators in the last 24 hours.

Analyst Note - The absence of public news may indicate a quiet reporting cycle rather than a complete halt in activity, as ransomware operations often maintain a covert posture.

Technical Takeaways

  • M3RXDLS was the most active ransomware group in the past 24 hours, responsible for 71% of newly reported victims.
  • M3RXDLS targeting showed geographical diversity, affecting organizations in Switzerland and Australia.
  • The Healthcare sector, including Medical Device and Healthcare Services, remains a target, with Medusa claiming a victim in the United States.
  • Observed activity indicates a broad and opportunistic targeting strategy rather than a focused campaign on specific critical infrastructure or government entities.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

M3RXDLS was the most active ransomware group in the past 24 hours, accounting for 5 of the 7 newly observed victims. Brain Cipher and Medusa each claimed one victim during this period.

Q: What industries were targeted by ransomware operators today?

Ransomware operators targeted a diverse range of industries. These included Property Investment and Management Consultancy, Healthcare Services, Information Technology and Services, Civil Engineering and Rail Infrastructure, Performing Arts, Automotive Services, and Medical Device manufacturing.

Q: Which countries experienced ransomware attacks on April 26, 2026?

Countries that experienced newly reported ransomware attacks on April 26, 2026, include the United Kingdom (2 victims), United States (2 victims), Australia (1 victim), Canada (1 victim), and Switzerland (1 victim).

Q: Is Medusa ransomware still active in the healthcare sector?

Yes, Medusa ransomware remains active. In the last 24 hours, Medusa claimed one victim, Walman optical, within the Healthcare sector in the United States, showing their continued targeting of this industry.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Our intelligence solutions include:

April 25, 2026 Proactive Ransomware Activity: Qilin, Vishing, CISA Alerts

Discover urgent insights into current ransomware activity. Uncover Qilin's surge, dominant vishing tactics, and critical CISA alerts shaping your cyber defense strategies.

Ransomware Report - 04/25/2026

Statistical Overview

Victim Totals

  • This month: 606
  • This quarter: 606
  • Year to date: 3227
  • Last 24h: 23

Quarterly Breakdown

Q1: 2622Q2: 606Q3: 0Q4: 0

Ransomware activity in Q2 continues, with the current victim count matching the quarterly total due to the reporting period's commencement. Year-to-date figures indicate sustained threat actor operations.

Introduction

In the past 24 hours, 23 new ransomware victims were reported. The Qilin ransomware group had the most activity, with 19 new listings. Other active groups included Lamashtu, INC_Ransom, and NightSpire, affecting various sectors. Geographic targeting remained broad, with the United States experiencing the most new attacks.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin19Buckley powder, Cahbo produkter, Chase cooper limited (risklogix solutions) (+16)Sweden, JapanFinancial Services, Agriculture & Food
2Lamashtu2Applefilm-group.com, Mnfsb.com.myThailand, MalaysiaMedia & Entertainment, Agriculture & Food
3INC Ransom1krauseundcoUnited StatesProfessional Services
4NightSpire1Swansea ambulance corpsUnited StatesHealthcare

The summary table shows notable activity from the Qilin ransomware group. It was responsible for most new victim postings, affecting organizations primarily in Financial Services and Agriculture & Food across regions like Sweden and Japan. Lamashtu was active in Southeast Asia, while INC Ransom and NightSpire each claimed one victim in the United States. For more information on Qilin's recent activities, see our Ransomware Threat Activity Report - April 22. Our daily ransomware reports often mention groups like NightSpire.

Victim Distribution

By Country

  • United States: 11
  • United Kingdom: 2
  • Germany: 2
  • Argentina: 1
  • Thailand: 1
  • Sweden: 1
  • Philippines: 1
  • Mexico: 1
  • Malaysia: 1
  • Japan: 1

By Industry

  • Banking: 2
  • Information Technology & Services: 1
  • Woodworking and Cabinet Manufacturing: 1
  • Retail: 1
  • Public Relations: 1
  • Propane Delivery and Services: 1
  • Non-Profit & Charitable Organizations: 1
  • Mining & Metals: 1
  • Healthcare: 1
  • Food Production: 1

The distribution of new victims shows a concentration in the United States across various industries, suggesting opportunistic targeting rather than a narrow sectoral focus. The global spread indicates threat actors continue to target a wide range of locations.

Ransomware News

Topline

Today's ransomware-relevant developments include critical vulnerability disclosures by CISA, the emergence of a new extortion group, and several disruptive county-level cybersecurity incidents.

Campaigns & Operations

Winona County, Minnesota, and Harrison County, West Virginia, both reported network disruptions due to cybersecurity incidents. Winona County confirmed a ransomware attack that affected vital services. ADT confirmed unauthorized access to customer data following a ShinyHunters leak threat, reportedly stemming from a vishing campaign targeting an employee's Okta SSO. A new financially motivated group, BlackFile (also tracked as CL-CRI-1116, UNC6671, and Cordial Spider), has been linked to a recent increase in data theft and extortion operations. It targets retail and hospitality firms, employing vishing tactics.

Vulnerabilities & TTPs

CISA has added four actively exploited vulnerabilities to its KEV catalog: CVE-2024-57726 and CVE-2024-57728 affecting SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9 Server, and CVE-2025-29635 in D-Link DIR-823X routers. These have reported links to DragonForce ransomware activity. BlackFile's operations heavily use vishing calls to spoof IT support, steal credentials, bypass multifactor authentication, and exfiltrate data from platforms like Salesforce and SharePoint via API functions.

Analyst Note

The continued reliance on credential theft and social engineering, demonstrated by Verizon DBIR findings on pre-compromised credentials and by new groups like BlackFile, shows initial access often relies on human factors.

Technical Takeaways

  • Qilin's Expanded Targeting: Qilin's large number of new victims indicates an active and potentially expanding campaign across various financial and agricultural sectors, with a presence in Europe and Asia.
  • Vishing Dominance in Initial Access: The tactics of the new BlackFile group and the ADT breach by ShinyHunters show the continued effectiveness of vishing campaigns and social engineering for initial access and credential compromise.
  • Federal Mandates for Vulnerability Patching: CISA's addition of four new CVEs to the KEV catalog, some linked to DragonForce ransomware, highlights the ongoing need for federal agencies and critical infrastructure to prioritize patching known exploited flaws.
  • Geographic Focus on US: Most new victim postings, including those from INC_Ransom and NightSpire, originated from the United States, showing this region remains a main target for ransomware operators.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

The Qilin ransomware group was the most active, reporting 19 new victims. Other groups with reported activity included Lamashtu (2 victims), INC_Ransom (1 victim), and NightSpire (1 victim).

Q: What industries were most targeted by ransomware today?

Financial Services and Agriculture & Food were main sectors affected by the Qilin group. Other industries impacted included Banking, Information Technology & Services, and Healthcare, reflecting a broad targeting approach.

Q: Which geographic regions experienced the most ransomware attacks today?

The United States reported the highest number of new ransomware victims, with 11 organizations affected. Other countries with new victims included the United Kingdom, Germany, Argentina, Thailand, Sweden, Philippines, Mexico, Malaysia, and Japan.

Q: Are there any new vulnerabilities being exploited by ransomware operators?

CISA has added four actively exploited vulnerabilities to its KEV catalog, including CVE-2024-57726 and CVE-2024-57728 for SimpleHelp, CVE-2024-7399 for Samsung MagicINFO 9 Server, and CVE-2025-29635 for D-Link DIR-823X routers. These flaws have been publicly linked to DragonForce ransomware activity.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Our intelligence solutions include:

April 24, 2026 Active Ransomware Groups Q2 Trends and Intelligence Update

Uncover the most active ransomware groups of Q2. Get vital stats, group insights, and technical observations to immediately enhance your cybersecurity posture against current threats.

Ransomware Report - 04/24/2026

Statistical Overview

Victim Totals

  • This month: 583
  • This quarter: 583
  • Year to date: 3204
  • Last 24h: 25

Quarterly Breakdown

Q1: 2622Q2: 583Q3: 0Q4: 0

Q2 activity began with 583 victims so far, contributing to the overall year-to-date total of 3204. The past 24 hours saw a steady number of new victims across various groups, showing global ransomware operations continue.

Introduction

The past 24 hours recorded 25 new ransomware victims, contributing to a year-to-date total of 3204. Qilin, Payload, and The_Gentleman were the most active groups, collectively accounting for 13 of the new incidents. The United States was the most targeted country. Financial Services, Transportation & Logistics, Education, and Healthcare sectors also experienced activity. For more insights into current threat actors, refer to our analysis on active ransomware groups.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin5B to b visions, City of napoleon, ohio, Clearview intelligence (+2)United States, United KingdomFinancial Services, Transportation & Logistics
2Payload4B3-bruck.at, Caravaningcity.com, Meditron.com.ve (+1)Spain, AustriaEducation, Healthcare
3The Gentelman4Coralina, Eec group, Lawson software (+1)Thailand, EgyptConstruction & Engineering, Professional Services
4INC Ransom2Dorotea Sweden, tlctrialteam.comSweden, United StatesGovernment / Public Sector, Legal
5LockBit2heinrichs-logistic.de, merlo.deGermanyTransportation & Logistics, Manufacturing
6SLSH2Adt, inc. (adt.com), Udemy, inc. (udemy.com)United StatesProfessional Services, Technology / Software
7AiLock1Mother's market & kitchenUnited StatesRetail & Ecommerce
8Akira1Rockville fuel & feedUnited StatesManufacturing
9Beast1Lessard dentalCanadaHealthcare
10Insomnia1Meto systemsUnited StatesManufacturing
11PayoutsKing1Flynn groupUnited StatesProfessional Services
12RansomHouse1Star Energy Geothermal SalakIndonesiaEnergy & Utilities

Qilin, Payload, and The_Gentleman were the most active ransomware groups over the last 24 hours. They targeted various industries and regions. Qilin focused on Financial Services and Transportation in the United States and United Kingdom. Payload impacted Education and Healthcare entities in Spain and Austria, while The_Gentleman concentrated on Construction and Professional Services across Thailand and Egypt. Qilin's activity, which included an incident against the "City of napoleon, ohio," aligns with observations detailed in our recent Qilin ransomware threat activity report. Incidents also include "Dorotea Sweden" targeted by INC Ransom and "Star Energy Geothermal Salak" in Indonesia compromised by RansomHouse, showing persistent threats to government and critical infrastructure.

Victim Distribution

By Country

  • United States: 10
  • Germany: 2
  • Canada: 2
  • Thailand: 1
  • Venezuela: 1
  • United Kingdom: 1
  • Austria: 1
  • Sweden: 1
  • Spain: 1
  • Paraguay: 1

By Industry

  • Information Technology and Services: 2
  • Legal Services: 2
  • Medical Equipment and Healthcare Infrastructure: 1
  • Security and Protection Services: 1
  • Retail (Grocery), Health Food Store: 1
  • Ready-Mixed Concrete Manufacturing: 1
  • Industrial Machinery & Equipment: 1
  • Government: 1
  • Franchising: 1
  • Education Technology: 1

The United States was the most targeted country, accounting for 40% of new victims. Various sectors were affected, suggesting attackers were opportunistic rather than focused on specific industries. Information Technology and Legal Services saw repeat hits.

Ransomware News

Topline

Recent threat intelligence shows Trigona ransomware re-emerging with a bespoke exfiltration tool and details a ransomware breach affecting a Hong Kong club.

Campaigns & Operations

Trigona ransomware returned after a 2023 disruption, deploying a custom command-line exfiltration tool, uploader_client.exe, in its March attacks. The tool enables faster data theft by using parallel uploads, rotating connections, and selectively exfiltrating files. Separately, the Yau Yat Chuen Garden City Club in Hong Kong disclosed a ransomware breach from October 28, 2025, impacting over 9,000 individuals due to vulnerabilities in outdated remote-access software and weak security controls.

Vulnerabilities & TTPs

Trigona's custom uploader_client.exe shows a shift from public tools to proprietary tools for covert data exfiltration. It uses techniques like kernel drivers (e.g., HRSword) to disable security. The Hong Kong club incident was attributed to compromised service-provider credentials exploiting an outdated remote-access software vulnerability, alongside dated antivirus and firewall protections.

Analyst Note

These incidents show the continued use of sophisticated data exfiltration tactics and the persistent risk from unpatched software and inadequate organizational security.

What are the main technical observations from today's ransomware activity?

  1. Custom Exfiltration Tools: The return of Trigona ransomware with a proprietary uploader_client.exe shows a move from publicly available tools for data exfiltration, suggesting efforts to evade detection and speed up data theft.
  2. Vulnerabilities in Older Systems: The Yau Yat Chuen Garden City Club breach shows that outdated remote-access software with known vulnerabilities, and weak authentication and security controls, continues to be the main way ransomware gets in.
  3. Diverse Targeting: While the United States was the most targeted country, the diverse geographic spread of victims, from Austria and Spain to Thailand and Indonesia, shows broad targeting by active ransomware groups.
  4. Government and Critical Infrastructure Remain Targets: Incidents involving "City of napoleon, ohio," "Dorotea Sweden," and "Star Energy Geothermal Salak" show that government and critical energy infrastructure sectors continue to face direct ransomware threats.
  5. Established and Emerging Groups Show Steady Activity: Groups like LockBit continue to be active, as do emerging groups like Payload and The_Gentleman. This adds to the steady number of new victims daily. LockBit continues to post new victims, reflecting broader trends often covered in our latest ransomware threat activity reports.

FAQ

Q: Which ransomware groups were most active today?

Qilin was the most active group in the past 24 hours with 5 reported victims, followed by Payload and The_Gentleman, both with 4 victims. These three groups accounted for over half of all new ransomware incidents reported.

Q: What industries experienced the highest number of ransomware attacks in the past 24 hours?

No single industry dominated attacks, showing broad targeting. Information Technology and Services, and Legal Services each recorded 2 victims, while a wide array of other sectors, including Healthcare, Retail, Government, and Manufacturing, each saw 1 reported incident.

Q: Which countries were most affected by ransomware activity today?

The United States was the most affected country, accounting for 10 of the 25 new victims reported in the last 24 hours. Germany and Canada each reported 2 victims, with other countries like Thailand, Venezuela, and the United Kingdom each seeing a single incident.

Q: Were there any new ransomware tactics or notable vulnerabilities reported today?

Yes, new intelligence shows Trigona ransomware is now using a custom exfiltration tool, uploader_client.exe, to speed up data theft and maintain a lower profile. Additionally, a breach at the Yau Yat Chuen Garden City Club highlighted the exploitation of outdated remote-access software with known vulnerabilities as a main entry point.

Q: Were any critical infrastructure or government entities targeted by ransomware today?

Yes, "City of napoleon, ohio" was listed as a victim of Qilin, and "Dorotea Sweden" was targeted by INC Ransom, both representing government entities. Furthermore, "Star Energy Geothermal Salak," an Energy & Utilities provider in Indonesia, was compromised by RansomHouse, showing continued targeting of critical infrastructure.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 23, 2026 Understand Active Ransomware Groups with Real-Time Data

Uncover the most active ransomware groups, their targets, and evolving tactics. Get real-time intelligence to stay ahead of cyber threats and secure your defenses.

Ransomware Report - 04/23/2026

Statistical Overview

Victim Totals

  • This month: 558
  • This quarter: 558
  • Year to date: 3179
  • Last 24h: 19

Quarterly Breakdown

Q1: 2622 | Q2: 558 | Q3: 0 | Q4: 0

Ransomware activity continues into Q2, with 558 victims already reported this quarter. This consistent activity places pressure on global organizations. The 19 new victims in the last 24 hours show ongoing threat actor operations.

Introduction

In the past 24 hours, PurpleOps observed 19 new ransomware victims, driven by groups such as CoinbaseCartel and INC Ransom, among others. The United States remains the most targeted country, with the Professional Services, Government/Public Sector, and Technology/Software sectors experiencing significant impact. Threat actors continue to diversify their approaches, using social engineering tactics and experimenting with new encryption techniques.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1CoinbaseCartel7Aptim, Integer holdings, Kementerian pertanian (+4)Brazil, IndonesiaGovernment / Public Sector, Technology / Software
2INC Ransom3krwlawyers.com, teamster773.org, trugreen.comUnited StatesNonprofit, Professional Services
3Akira2Alkegen, Gumpp kunststoffeUnited States, GermanyRetail & Ecommerce, Manufacturing
4Anubis1Marnell financial servicesNoneProfessional Services
5BlackShrantac1LenmaxFranceProfessional Services
6Bravox11st solution ctc ??GermanyProfessional Services
7DragonForce1IncyteUnited StatesPharmaceuticals & Biotech
8Kairos1Gregory jewellersAustraliaRetail & Ecommerce
9LeakedData1Jackson lewisUnited StatesLegal
10World Leaks1Virginia health servicesUnited StatesHealthcare

CoinbaseCartel was the most active group, accounting for seven new victims, targeting government and technology entities across Brazil and Indonesia. INC Ransom and Akira followed, focusing on Professional Services and manufacturing sectors primarily in the United States and Germany. A high-value breach includes Kementerian pertanian (Ministry of Agriculture) in Indonesia by CoinbaseCartel. This indicates persistent targeting of public-sector institutions.

Victim Distribution

By Country

  • United States: 10
  • Germany: 2
  • Australia: 1
  • Peru: 1
  • None: 1
  • Indonesia: 1
  • France: 1
  • Canada: 1
  • Brazil: 1

By Industry

  • Biopharmaceuticals: 1
  • Specialty Materials Manufacturing: 1
  • Medical Equipment Manufacturing: 1
  • Medical Devices: 1
  • Legal Services: 1
  • Legal Practice: 1
  • Lawn Care Services: 1
  • Labor Union: 1
  • Healthcare: 1
  • Environmental Services: 1

The United States continues to experience the highest concentration of ransomware attacks, consistent with historical trends. While the industries targeted today are diverse, Professional Services appeared multiple times. This suggests either an opportunistic or strategic approach to targeting business operations.

Ransomware News

Today's intelligence shows continuous evolution and diversity in ransomware operations, with technical advancements and new actors emerging.

Topline

Threat actors are employing social engineering and established ransomware-as-a-service (RaaS) models, alongside technical capabilities, to compromise organizations across various sectors, while also exploring new encryption methods.

Campaigns & Operations

The data exfiltration group ShinyHunters claimed breaches against a major U.S. convenience-store chain and a U.S. software development firm. This signals cross-sector risks related to dark web monitoring and data exfiltration. ASEC introduced Prinz Eugen, a new data-extortion group. "The Gentlemen" ransomware-as-a-service (RaaS) outfit has rapidly risen since mid-2025, deploying a GO-written, cross-platform locker, using SystemBC SOCKS5 proxy for covert operations, and showing an enterprise-scale intrusion capability via Active Directory Group Policy. Genealogy SA, an Australian nonprofit, confirmed a cyber incident with SafePay claiming exfiltrated data, while LockBit was speculatively linked to a February technology outage in Orange, Virginia.

Vulnerabilities & TTPs

Social engineering remains a critical vector, with the M&S breach showing how a single password reset, achieved via social engineering against a service desk, can lead to legitimate credential exfiltration and subsequent ransomware deployment. Kyber ransomware variants, analyzed by Rapid7, showcase technical experimentation, including a Windows build written in Rust that incorporates Kyber1024 for symmetric key protection and an experimental Hyper-V targeting option, alongside multi-platform capabilities for VMware ESXi environments. The Gentlemen group employs antivirus killers and complex infection chains for lateral movement.

Technical Takeaways

  • Persistence in Professional Services Targeting: Professional Services firms consistently appear among the top targeted industries. This indicates either opportunistic attacks or a strategic focus on entities handling sensitive client data.
  • Rise of New and Advanced Groups: The rapid ascent of "The Gentlemen" and the emergence of "Prinz Eugen" show a changing threat environment with new actors bringing advanced capabilities, including GO-written malware and advanced lateral movement.
  • Experimentation with Post-Quantum Cryptography: Kyber ransomware's implementation of Kyber1024 in its Windows variant, even if experimental, demonstrates a forward-looking approach by threat actors to encryption methodologies, potentially anticipating future cryptographic shifts.
  • Social Engineering as a Primary Vector: The M&S breach shows that social engineering, around password resets, remains an effective initial access technique, leading to significant financial and operational impact.
  • Geographic Concentration in the United States: The United States continues to be the most frequently targeted country, suggesting a sustained focus by ransomware groups on U.S.-based organizations.

FAQ

Q: Which ransomware groups were most active today, 04/23/2026?

CoinbaseCartel was the most active ransomware group in the past 24 hours, responsible for 7 new victims. INC Ransom followed with 3 victims, and Akira reported 2 new victims during this period.

Q: What industries were most targeted by ransomware today?

In the last 24 hours, Professional Services was a frequently targeted sector, with groups like INC Ransom, Anubis, and BlackShrantac impacting multiple organizations. Government/Public Sector and Technology/Software also saw targeting, especially by CoinbaseCartel.

Q: What geographic regions saw the most ransomware attacks in the last 24 hours?

The United States experienced the highest number of ransomware victims today, with 10 reported incidents. Germany followed with 2 victims, and Brazil, Indonesia, France, Australia, Peru, and Canada each reported one new victim.

Q: Were any new ransomware groups identified or highlighted in today's intelligence report?

Yes, today's intelligence introduced Prinz Eugen as a new data-extortion group. "The Gentlemen" ransomware-as-a-service outfit was also highlighted for its rapid ascent since mid-2025 and advanced technical capabilities, placing it among top-tier actors.

Q: What technical trends or tactics did threat actors employ in recent ransomware activity?

Recent activity showcases several key technical trends, including Kyber ransomware's experimentation with post-quantum encryption (Kyber1024) in its Windows variant and its multi-platform targeting of ESXi environments. Social engineering, for password resets, was also noted as an effective initial access method, leading to credential compromise and subsequent ransomware deployment.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 22, 2026 What Are The Latest Ransomware Victims Qilin Is Targeting?

Don't miss the latest ransomware victims report! Dive into Qilin's active targets, critical exploits, and essential threat intelligence to protect your organization.

Ransomware Report - 04/22/2026

Statistical Overview

Victim Totals

  • This month: 539
  • This quarter: 539
  • Year to date: 3160
  • Last 24h: 19

Quarterly Breakdown

Q1: 2622Q2: 539Q3: 0Q4: 0

Q2 ransomware activity started with 539 victims, adding to the year-to-date total of 3160. This figure indicates ransomware groups maintain their operational tempo, consistent with prior quarter trends. See our analysis of the most active ransomware groups for details on recent group activities.

Introduction

Over the last 24 hours, PurpleOps observed 19 new ransomware victims across various groups and sectors. Qilin emerged as the most active threat actor with 6 reported victims, followed by Akira and DragonForce. Geographically, the United States saw the highest number of incidents, while the Professional Services and Manufacturing sectors were prominently targeted. To understand the broader context of Q2 activity, refer to our Q2 victim report.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin6Heartland steel products, Huonker gmbh, Industrial carrocera arbuciense (+3)Turkey, SpainConstruction & Engineering, Technology / Software
2Akira2Kubiak melton & associates, S4k entertainmentUnited StatesMedia & Entertainment, Professional Services
3DragonForce2Primius law firm, The galliher law firmUnited States, GreeceLegal
4AiLock1PremcomUnited KingdomProfessional Services
5Anubis1TractialFranceFinancial Services
6Genesis1K2 electric, incUnited StatesConstruction & Engineering
7LeakedData1Rutan & tucker, llpUnited StatesLegal
8LockBit1bladex.comPanamaFinancial Services
9PEAR1Kinsmen telemiracleCanadaNonprofit
10RansomHouse1Jiangsu Zenergy Battery Technologies Group Co., Ltd.ChinaManufacturing
11Securotop1Synergy engineeringCanadaManufacturing
12World Leaks1Equatorial coca-cola bottlingMoroccoManufacturing

Qilin was most active today, impacting diverse sectors including construction and technology across Turkey and Spain. Akira and DragonForce maintained a presence, primarily targeting U.S.-based entities in Media & Entertainment, Professional Services, and Legal sectors. No high-value critical infrastructure or government entities were identified among the sample victims today. However, the diverse geographic and industry targeting shows ransomware operations are persistent and opportunistic. Our detailed analysis of Qilin ransomware victims and attacks provides more information on this group's tactics.

Victim Distribution

By Country

  • United States: 7
  • Canada: 3
  • Spain: 1
  • United Kingdom: 1
  • Turkey: 1
  • Panama: 1
  • Morocco: 1
  • Greece: 1
  • Germany: 1
  • France: 1

By Industry

  • Manufacturing: 2
  • Legal Services: 2
  • Warehousing and Storage: 1
  • Office Technology Solutions: 1
  • Law Practice: 1
  • Entertainment: 1
  • Electrical Contracting: 1
  • Accounting: 1
  • Printing and Direct Mail Services: 1
  • Construction and Contracting: 1

The United States continues to be the primary target for ransomware groups, accounting for over a third of today's observed victims. Industry-wise, Professional Services (including Legal and Accounting) and Manufacturing show a concentrated targeting trend, reflecting ongoing threat actor focus on organizations with valuable intellectual property or client data.

Ransomware News

Topline

Recent developments highlight persistent ransomware threats, including supply chain vulnerabilities, new campaign discoveries, significant legal actions against affiliates, and ongoing policy discussions.

Campaigns & Operations

The "The Gentlemen" ransomware operation has been linked to a SystemBC C2 server, revealing a botnet exceeding 1,570 victims globally. It uses SOCKS5 tunnels and custom RC4-encrypted protocols for payload delivery. At the same time, SafePay dumped a 237-gigabyte dataset from Favelle Favco's Australian operations, comprising passport scans and sensitive industrial data. This shows risks to personnel identity and critical assets in construction. Separately, a former DigitalMint ransomware negotiator, Angelo John Martino III, pleaded guilty to conspiring with BlackCat/ALPHV affiliates, extorting approximately $75.3 million from five U.S. victims by using confidential negotiation intelligence.

Vulnerabilities & TTPs

A surge in attacks exploiting Bomgar Remote Support (now BeyondTrust) RMM has been observed, using CVE-2026-1731, an unauthenticated remote code execution flaw. This vulnerability allows attackers to run arbitrary OS commands and pivot into upstream servers, demonstrating rapid lateral movement capabilities, as seen in incidents affecting dental software providers and MSPs where LockBit ransomware was deployed.

Analyst Note

These incidents show the critical challenges from supply chain vulnerabilities, insider threat potential, the continuous evolution of ransomware tactics and infrastructure, and they also bring policy debates regarding hospital ransomware to the forefront.

Technical Takeaways

  • Qilin's Sustained Activity: Qilin remains an active threat actor, capable of multi-sector targeting across diverse geographies.
  • Supply Chain Vulnerability Exploitation: The exploitation of Bomgar Remote Support (CVE-2026-1731) shows the ongoing risk from unpatched RMM solutions and their potential for widespread downstream impact.
  • Insider Threat & Negotiation Risks: The plea of a former ransomware negotiator exposes vulnerabilities within incident response, emphasizing the critical need for vetted partners and secure negotiation practices.
  • Persistent Targeting of Professional Services: Legal, accounting, and consulting firms continue to be attractive targets for ransomware groups, indicating the value of their sensitive client data and operational disruption potential.
  • Evolution of Ransomware-as-a-Service (RaaS) Infrastructure: The "The Gentlemen" operation using SystemBC shows RaaS capabilities, including multi-OS targeting and advanced lateral movement techniques.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

Qilin was the most active ransomware group in the last 24 hours, with 6 reported victims. Akira and DragonForce were also active, each claiming 2 new victims during this period.

Q: Which industries were most targeted by ransomware today?

Today, the Professional Services sector (including Legal Services, Law Practice, and Accounting) and Manufacturing were among the most targeted industries, each accounting for 2 reported victims. Construction & Engineering also saw activity.

Q: What regions saw the most ransomware attacks in the past 24 hours?

The United States experienced the highest concentration of ransomware attacks in the last 24 hours, with 7 victims. Canada followed with 3 victims, while Spain, the United Kingdom, and Turkey each reported 1 victim.

Q: Are there any new CVEs being exploited by ransomware operators that were reported today?

Yes, a new wave of attacks is actively exploiting CVE-2026-1731, an unauthenticated remote code execution flaw in Bomgar Remote Support (now BeyondTrust) RMM. This vulnerability allows attackers to run arbitrary OS commands and pivot into downstream systems, with LockBit ransomware observed in deployments using this flaw.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform. It tracks ransomware and discovers attack surfaces. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 21, 2026 Analyzing Q2 Ransomware Victims with Real-Time Intelligence

Uncover critical Q2 ransomware victim trends. Discover the most active groups, targeted industries, and technical insights from the latest real-time intelligence to fortify your defenses.

Ransomware Report - 04/21/2026

Statistical Overview

Victim Totals

  • This month: 520
  • This quarter: 520
  • Year to date: 3141
  • Last 24h: 32

Quarterly Breakdown

Q1: 2622Q2: 520Q3: 0Q4: 0

Ransomware activity in Q2 continues to accumulate, with the current month's victim count already reaching 520. This trajectory suggests a sustained threat environment, following a strong Q1.

Introduction

The past 24 hours saw 32 new ransomware victims added to leak sites, showing persistent global activity. Qilin emerged as the most prolific group, claiming 11 victims. Akira, CoinbaseCartel, and The_Gentelman each claimed 4 victims. Geographically, the United States, France, and Spain were mostly targeted, with the Manufacturing and Telecommunications sectors impacted.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin11Atkinson ritson solicitors limited, Avitrans, B&e juice (+8)Spain, NoneFinancial Services, Agriculture & Food
2Akira4Alva manufacturing, Arctic home living, Mac construction & excavating (+1)United StatesPharmaceuticals & Biotech, Construction & Engineering
3CoinbaseCartel4Commscope, Engie, Playmates toys (+1)France, United StatesTelecommunications, Energy & Utilities
4The Gentelman4Champion homes, Euro creations, Smartsystems (+1)Thailand, United StatesTelecommunications, Construction & Engineering
5Anubis2Samuel i. white, pc, ViaquestUnited StatesHealthcare, Legal
6Chaos1Polycorp.comCanadaManufacturing
7DragonForce1Champion homesAustraliaConstruction & Engineering
8Embargo1Cipsoft.comGermanyMedia & Entertainment
9INC Ransom1rheemUnited StatesManufacturing
10Kairos1Nordenta (a daughter company of lifco)DenmarkManufacturing
11Morpheus1GGIMyanmarInsurance
12Nova (RALord)1Charles conseil coordination (3ccc)FranceProfessional Services

The past 24 hours saw Qilin lead with 11 new victims, targeting broadly across Financial Services and Agriculture & Food. Several groups, including Akira, CoinbaseCartel, and The Gentelman, each claimed 4 victims, contributing to activity across various sectors. CoinbaseCartel targeted critical infrastructure entities like Commscope (Telecommunications) and Engie (Energy & Utilities). This shows persistent risks to vital services, a trend we monitor as part of our ransomware intelligence Q2 overview.

Victim Distribution

By Country

  • United States: 14
  • France: 3
  • Spain: 2
  • Germany: 2
  • Switzerland: 1
  • United Kingdom: 1
  • Thailand: 1
  • Australia: 1
  • None: 1
  • Myanmar: 1

By Industry

  • Manufacturing: 3
  • Telecommunications: 2
  • Packaging and Containers: 1
  • Retail & Wholesale: 1
  • Product Safety and EMC Compliance: 1
  • Legal Services: 1
  • Healthcare Services: 1
  • Government: 1
  • Engineering Services: 1
  • Construction: 1

The United States is the primary target country, accounting for nearly half of all new victims in the last 24 hours. Manufacturing and Telecommunications sectors show a concentration of attacks, indicating exploitation of industrial and communication infrastructure.

Ransomware News

Threat intelligence today shows ongoing legal actions against ransomware affiliates, persistent exploitation of vulnerabilities, and changing tactics of established groups.

Angelo Martino, a former ransomware negotiator for BlackCat (ALPHV) affiliates, pleaded guilty to charges related to 2023-2025 attacks. He admitted to sharing confidential victim negotiation details. This conviction shows the legal risks for individuals involved in the ransomware ecosystem. Meanwhile, The Gentlemen ransomware group has expanded its operations by integrating SystemBC for bot-powered payload delivery and covert proxying, using Mimikatz for credential harvesting and Group Policy for lateral movement in targeted corporate environments. Additionally, the administration of Sprendlingen-Gensingen (Germany) reported a ransomware attack on April 16, 2026, causing network shutdown and an ongoing forensic investigation.

A reported uptick in compromised Bomgar RMM instances followed exploitation of CVE-2026-1731, with attackers deploying ransomware like LockBit LB3 and installing remote tools for reconnaissance and lateral movement. Observations indicate that approximately 70% of intrusions begin with VPN authentication, showing the need for strong cyber hygiene, including multi-factor authentication (MFA) and diligent patching. Ransomware trends show operations as a franchised, supply-chain-driven ecosystem, using tactics like data theft, double extortion, and Bring Your Own Vulnerable Driver (BYOVD) to bypass security solutions.

This activity shows the ongoing challenge from ransomware's changing operational models and the importance of a layered defense strategy.

Technical Takeaways

  • Group TTP Evolution: The Gentlemen ransomware now uses SystemBC for bot-powered attacks, alongside Mimikatz and RPC-based remote execution for lateral movement. This shows a mature toolchain.
  • Vulnerability Exploitation: Active exploitation of Bomgar RMM instances specifically targets CVE-2026-1731, leading to ransomware deployment and further network compromise.
  • Initial Access Vector Dominance: Huntress data indicates that roughly 70% of intrusions begin with VPN authentication. This reinforces VPNs as a primary initial access vector for ransomware actors.
  • Insider Threat Mitigation: The guilty plea of a former BlackCat ransomware negotiator shows the insider threat and the value of intelligence around negotiation tactics and insurance limits for threat actors.
  • Ecosystem Sophistication: Ransomware operations are increasingly supply-chain-driven, incorporating techniques like BYOVD, AI-assisted malware, and double extortion, requiring full defensive strategies.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

A: In the past 24 hours, Qilin was the most active ransomware group, responsible for 11 new victims. Akira, CoinbaseCartel, and The_Gentelman each claimed 4 victims, contributing significantly to the day's activity. For a broader view on recurring threats, our analysis of the most active ransomware groups provides further context.

Q: What industries were most targeted by ransomware today?

A: Manufacturing and Telecommunications were the most frequently targeted industries, each accounting for 3 and 2 victims respectively. Other affected sectors included Financial Services, Energy & Utilities, Agriculture & Food, and Healthcare.

Q: What regions saw the most ransomware attacks today?

A: The United States was the most targeted country, experiencing 14 of the 32 new ransomware incidents reported. France followed with 3 victims, while Spain and Germany each saw 2 new victims.

Q: Were there any new vulnerabilities or exploitation trends identified today?

A: Yes, an uptick in the exploitation of Bomgar RMM instances followed CVE-2026-1731, used by groups like LockBit LB3 to deploy ransomware. Additionally, VPN authentication is a dominant initial access vector, accounting for approximately 70% of intrusions.

Q: What new tactics are ransomware groups like The Gentlemen employing?

A: The Gentlemen ransomware group has been observed expanding its tactics to include the use of SystemBC as a proxy botnet for payload delivery and covert communication. This sophisticated approach involves credential harvesting via Mimikatz, RPC-based remote execution, and Group Policy-driven lateral movement.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform that covers every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats and investigate incidents in natural language 24/7.

Our intelligence solutions:

April 20, 2026 Identify Most Active Ransomware Groups & Latest Targets

Uncover the most active ransomware groups like Everest and Qilin. See their latest targets in financial, healthcare, and legal sectors, plus critical zero-day exploits. Stay informed.

Ransomware Report - 04/20/2026

Statistical Overview

Victim Totals

  • This month: 488
  • This quarter: 488
  • Year to date: 3109
  • Last 24h: 17

Quarterly Breakdown

Q1: 2622 | Q2: 488 | Q3: 0 | Q4: 0

Ransomware activity in Q2 currently stands at 488 victims. The 17 new victims identified in the last 24 hours indicate ongoing opportunistic and targeted operations by various groups.

Introduction

The past 24 hours recorded 17 new ransomware victims. Everest and Qilin were the most active groups, responsible for six and four incidents, respectively. Financial services, healthcare, and legal sectors were impacted across key geographies, particularly the United States and France. This activity shows the persistent and diversified targeting strategies ransomware operators use.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Everest6Citizens bank, Complete aircraft group, Frost bank (+3)Spain, United StatesFinancial Services, Transportation & Logistics
2Qilin4City'pro, Cooperativa de hospitales de antioquia - cohan, Gueguen avocats (+1)France, United StatesEducation, Healthcare
3Payload2Al sulaiti law firm, Better houseQatar, EgyptReal Estate, Legal
4Akira1Integra architectureCanadaConstruction & Engineering
5BlackShrantac1Banister primary schoolUnited KingdomEducation
6Krybit1Imbriefamilylaw.comUnited StatesLegal
7Lamashtu1Jesin.com.myMalaysiaReal Estate
8PEAR1Roger d. mason ii, p.a.United StatesLegal

Everest was the most active group, claiming six victims. They mainly targeted financial services, including Citizens Bank and Frost Bank in the United States, and transportation and logistics entities across the US and Spain. Qilin followed with four victims, affecting education and healthcare, notably Cooperativa de hospitales de antioquia - cohan. For more details on this group's operations, explore our Qilin ransomware victims and attack analysis. Legal services faced attacks from multiple groups, including Payload, Krybit, and PEAR. Akira's single victim, Integra Architecture, shows its continued but less frequent targeting; insights into their methods are available in our Akira ransomware TTP analysis.

Victim Distribution

By Country

  • United States: 6
  • France: 2
  • United Kingdom: 2
  • Canada: 1
  • Colombia: 1
  • Egypt: 1
  • Indonesia: 1
  • Malaysia: 1
  • Qatar: 1
  • Spain: 1

By Industry

  • Legal Services: 3
  • Architecture and Planning: 1
  • Healthcare and Pharmaceutical Distribution: 1
  • Real Estate Development: 1
  • Education and Training: 1
  • Law Firms & Legal Services: 1
  • E-commerce: 1
  • Property Development: 1
  • Aerospace and Unmanned Aerial Systems: 1
  • Aviation Solutions: 1

The United States recorded the highest number of new victims, confirming its status as a primary target for ransomware. Legal services saw concentrated attacks in the last 24 hours, suggesting either opportunistic targeting or a specific campaign focus.

Ransomware News

Topline

Recent intelligence indicates confirmed data breaches, alleged ransomware incidents affecting critical services, and active exploitation of multiple vulnerabilities.

Campaigns & Operations

The Kairos ransomware group claims to have breached NSW-based Strata Republic, exfiltrating 441GB of data, including sensitive personal and financial records, with a five-day publication deadline set. A ransomware attack on Hsinchu Logistics in Taiwan significantly disrupted operations, rendering systems inoperable and forcing manual processes. Cloud development platform Vercel also confirmed a security incident involving unauthorized access to internal systems. An attacker claiming to be ShinyHunters offered stolen access keys, source code, and employee data for a reported $2 million ransom.

Vulnerabilities & TTPs

The Hsinchu Logistics incident occurred amidst active exploitation of three Microsoft Defender zero-day vulnerabilities, including CVE-2026-33825, and a Fortinet FortiSandbox vulnerability (CVE-2026-39808) with public proof-of-concept. Attackers in this incident used Payouts King malware, designed to evade endpoint and EDR solutions by concealing itself within QEMU-VMs and employing Alpine-Linux-based backdoors.

Analyst Note

These events show the persistent targeting of supply chain entities, the urgency of strong vulnerability management, and the increasing sophistication of evasion techniques threat actors use.

Technical Takeaways

  • Financial Institutions Targeted: Everest's activity against major banks like Citizens Bank and Frost Bank shows a continued high-value focus on the financial sector.
  • Healthcare Sector Threats: Qilin's compromise of Cooperativa de hospitales de antioquia - cohan highlights ongoing threats to healthcare infrastructure.
  • Legal Services as a Target: Multiple groups, including Payload, Krybit, and PEAR, demonstrate legal services firms remain a frequent target, likely due to sensitive client data.
  • Zero-Day Exploitation: The Hsinchu Logistics incident involved active exploitation of CVE-2026-33825 and CVE-2026-39808, showing the immediate risk of unpatched vulnerabilities.
  • Advanced Evasion: Payouts King malware, used in QEMU-VMs with Alpine-Linux backdoors, showcases advanced methods to bypass detection.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

The most active ransomware groups observed in the last 24 hours were Everest (6 new victims), Qilin (4 victims), and Payload (2 victims).

Q: What industries were most impacted by ransomware today?

Legal services were highly impacted, with 3 reported victims. Financial services, healthcare, education, real estate, and transportation & logistics also saw significant targeting by various ransomware groups.

Q: Which countries reported the highest number of new ransomware victims?

The United States reported the highest number of new ransomware victims in the past 24 hours, with a total of 6 incidents. France and the United Kingdom each reported 2 victims.

Q: Were any critical vulnerabilities exploited in recent ransomware attacks?

Yes, the ransomware attack on Hsinchu Logistics occurred amidst active exploitation of Microsoft Defender zero-day vulnerabilities, including CVE-2026-33825, and a Fortinet FortiSandbox vulnerability, CVE-2026-39808.

About PurpleOps

PurpleOps is an AI-driven cyber threat intelligence platform that covers various threat vectors, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 18, 2026 Real-Time Ransomware Intelligence Reveals Q2 Threats

Uncover the latest Q2 ransomware threats. Dive into active groups like Black Nevas and Blackwater, and analyze advanced evasion techniques. Stay ahead of emerging attacks!

Ransomware Report - 04/18/2026

Statistical Overview

Victim Totals

  • This month: 456
  • This quarter: 456
  • Year to date: 3077
  • Last 24h: 23

Quarterly Breakdown

Q1: 2622 | Q2: 456 | Q3: 0 | Q4: 0

Ransomware activity continues at a steady pace into Q2, with 456 victims reported so far. This early-quarter activity shows continued pressure from threat actors across various sectors.

Introduction

In the last 24 hours, PurpleOps observed 23 new ransomware victims. Leading the activity were Black Nevas with 9 reported incidents, followed by CoinbaseCartel (4) and Blackwater (3). Affected sectors included Manufacturing, Real Estate, and Healthcare, while geographically, the United States, India, Turkey, and Germany saw the highest number of new compromises. This period shows continued targeting across a diverse set of industries and regions.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Black Nevas9Bohmler einrichtungshaus gmbh, Carrera casting corp., E-con packaging private limited (+6)China, ItalyProfessional Services, Manufacturing
2CoinbaseCartel4Altpro, Evict them for me, Mccuaig and associates engineering (+1)France, CanadaManufacturing, Construction & Engineering
3Blackwater3Grupo ebd, Medical-park, Minidoka memorial hospitalTurkey, BrazilHospitality & Travel, Healthcare
4INC Ransom2Mag. Fünder Hausverwaltungs GmbH, alupco.comAustria, Saudi ArabiaManufacturing, Real Estate
5Kairos1Strata republicAustraliaReal Estate
6Krybit1Rhode-hv.deGermanyManufacturing
7RansomEXX1Sogo auctionJapanRetail & Ecommerce
8RansomHouse1Winnitex (Americas) LimitedHong KongManufacturing
9SLSH1Marcus & millichap, inc.United StatesReal Estate

The summary table for today's activity shows a varied threat environment. Black Nevas targeted widely across China and Italy, primarily impacting professional services and manufacturing. CoinbaseCartel concentrated on manufacturing and construction in France and Canada, while Blackwater focused on hospitality and healthcare across Turkey and Brazil. Minidoka Memorial Hospital was listed as a victim of Blackwater, showing continued threats to critical infrastructure within the healthcare sector. For more granular insights into active groups, our Ransomware Tracking platform provides real-time data.

Victim Distribution

By Country

  • United States: 5
  • India: 2
  • Turkey: 2
  • Germany: 2
  • United Kingdom: 1
  • Saudi Arabia: 1
  • Japan: 1
  • Italy: 1
  • Australia: 1
  • Hong Kong: 1

By Industry

  • Manufacturing: 2
  • Property Management: 2
  • Healthcare: 2
  • Software Development: 1
  • Jewelry Manufacturing: 1
  • Commercial Real Estate: 1
  • Law Firms & Legal Services: 1
  • Construction Machinery Manufacturing: 1
  • Building Materials: 1
  • Used Construction Machinery Auctions: 1

The distribution indicates continued prevalence of attacks in the United States, while India, Turkey, and Germany appear as secondary targets. Industrially, the persistent targeting of Manufacturing and Real Estate shows these sectors' continued vulnerability to various ransomware campaigns.

Ransomware News

Topline

Recent intelligence shows historical incident disclosure failures and new ransomware operations using advanced technical evasion tactics.

Campaigns & Operations

The City of York, Pennsylvania, did not publicly disclose a July 2025 ransomware attack that disrupted municipal email and parking services. A subsequent February 2026 investigation revealed a $500,000 settlement backed by an insurer after negotiations. This incident shows potential gaps in public incident reporting and the financial implications for affected municipalities.

Vulnerabilities & TTPs

The Payouts King ransomware is using the QEMU CPU emulator to deploy hidden Alpine Linux virtual machines on compromised hosts. This technique allows payload execution, malicious file storage, and covert remote access, bypassing conventional endpoint security measures. Campaigns linked to this operation, identified as GOLD ENCOUNTER (STAC4713 and STAC3725), exploited exposed SonicWall VPNs, the SolarWinds Web Help Desk vulnerability CVE-2025-26399, and the CitrixBleed 2 vulnerability CVE-2025-5777 on NetScaler ADC/Gateway devices. Attackers then install QEMU, launch hidden VMs with tools like AdaptixC2, Chisel, and Rclone, harvest credentials, enumerate Active Directory, and exfiltrate data. Organizations are advised to monitor for unauthorized QEMU installations and unusual SSH activity.

Analyst Note

The observed technical complexity, particularly the use of virtual machines and exploitation of known vulnerabilities, suggests a trend towards more complex evasion tactics and diversified initial access vectors. This shows the importance of strong Dark Web Monitoring for early warning of emerging TTPs.

Technical Takeaways

  • Diverse Group Activity: Black Nevas, CoinbaseCartel, and Blackwater were the most active groups, collectively responsible for over 70% of reported victims in the last 24 hours, showing a distributed threat environment rather than a single dominant actor.
  • Persistent Healthcare Sector Targeting: The compromise of Minidoka Memorial Hospital by Blackwater shows the ongoing threat to the healthcare sector, classified as critical infrastructure.
  • Manufacturing and Real Estate Vulnerability: Manufacturing and Real Estate sectors continue to experience high targeting, accounting for 20% of today's new victims, showing persistent vulnerabilities or value proposition for ransomware groups.
  • Advanced Evasion Techniques: The Payouts King ransomware's use of QEMU virtual machines to bypass endpoint security represents an advanced TTP designed to achieve stealthy persistence and execution.
  • Exploitation of Known Vulnerabilities: Ransomware campaigns continue to use critical vulnerabilities such as CVE-2025-26399 (SolarWinds) and CVE-2025-5777 (CitrixBleed 2) for initial access, showing the critical need for timely patching.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

A: In the past 24 hours, Black Nevas was the most active ransomware group, accounting for 9 victims. CoinbaseCartel followed with 4 victims, and Blackwater was responsible for 3, showing concentrated activity from these three entities.

Q: Which industries were primarily targeted by ransomware today?

A: Today's ransomware activity primarily targeted the Manufacturing, Property Management, and Healthcare sectors, each experiencing 2 new victims. Other affected industries include Software Development, Commercial Real Estate, and Law Firms & Legal Services.

Q: Were there any significant geographic shifts in ransomware targeting today?

A: The United States remained the most targeted country with 5 new victims. Beyond the US, India, Turkey, and Germany each saw 2 new victims, suggesting these regions are experiencing significant, though lesser, ransomware activity.

Q: What new technical insights or vulnerabilities were reported in today's ransomware activity?

A: Today's intelligence shows the Payouts King ransomware using QEMU virtual machines for payload execution and evasion, exploiting CVE-2025-26399 (SolarWinds) and CVE-2025-5777 (CitrixBleed 2) for initial access. This indicates an increasing reliance on advanced virtualized environments and known vulnerabilities to bypass security controls.

Q: What is the status of overall ransomware victim counts this quarter?

A: As of 04/18/2026, Q2 has accumulated 456 reported ransomware victims. This contributes to a year-to-date total of 3077 victims, showing a significant and sustained level of global ransomware activity at the start of the current quarter.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 16, 2026 Ransomware Report Update on Q2 Activity & Threat Trends

Unlock the latest ransomware report. Discover Q2 victim trends, top active groups, critical vulnerabilities exploited, and supply chain risks threatening your organization now.

Ransomware Report - 04/16/2026

Statistical Overview

Victim Totals

  • This month: 405
  • This quarter: 405
  • Year to date: 3026
  • Last 24h: 19

Quarterly Breakdown

Q1: 2622Q2: 405Q3: 0Q4: 0

Q2 ransomware activity shows 405 victims this quarter. 19 new victims were recorded in the last 24 hours.

Introduction

In the past 24 hours, 19 new ransomware victims appeared, showing ongoing targeting across multiple sectors. Payload had the most activity with 5 reported incidents, followed by Akira (3), Qilin (2), and Vect (2). The United States was the most targeted nation, and Financial Services, Manufacturing, and Legal services sectors were impacted by these operations.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Payload5Franziskusschule wilhelmshaven, Marino food products pvt, Orientalweavers.com (+2)Hong Kong, EgyptManufacturing, Transportation & Logistics
2Akira3Law offices of jamesc shields, Pharmathek, R roese contractingItaly, United StatesManufacturing, Construction & Engineering
3Qilin2Clearwater marine aquarium, LimkonTurkey, United StatesHospitality & Travel, Agriculture & Food
4Vect2GUESTY, LITELLM/TRIVY CAMPAIGN (TEAMPCP), S&PGLOBAL, LITELLM/TRIVY CAMPAIGN (TEAMPCP)United StatesFinancial Services, Technology / Software
5DragonForce1Empower groupUnited StatesFinancial Services
6Interlock1Uniwersytet warszawskiPolandEducation
7Kairos1Friendlycare pharmacyAustraliaRetail & Ecommerce
8Lamashtu1Biotehnos.roRomaniaPharmaceuticals & Biotech
9LeakedData1Harris beach murthaUnited StatesLegal
10RansomEXX1GotipJapanMedia & Entertainment
11SLSH1Alert 360 opco inc. (alert360.com)United StatesProfessional Services

Payload was the most active group in the last 24 hours, listing five new victims in Manufacturing and Transportation & Logistics sectors across Hong Kong and Egypt. Akira was also active with three new victims, primarily in Manufacturing and Construction & Engineering in Italy and the United States. Qilin and Vect each added two victims; Qilin impacted Hospitality & Travel and Agriculture & Food, while Vect targeted Financial Services and Technology/Software in the United States. No critical infrastructure or government entities were listed among new victims for this period. For monitoring these threats, our Ransomware Tracking solutions offer real-time intelligence.

Victim Distribution

By Country

  • United States: 8
  • Romania: 1
  • Turkey: 1
  • Australia: 1
  • Poland: 1
  • Philippines: 1
  • Japan: 1
  • Italy: 1
  • India: 1
  • Hong Kong: 1

By Industry

  • Financial Services: 2
  • Pharmaceuticals: 1
  • Property Management Software: 1
  • Museums, Historical Sites, and Zoos: 1
  • Legal Services: 1
  • Law Practice: 1
  • Home and Business Security: 1
  • Construction: 1
  • Food & Beverage: 1
  • Pharmaceutical Retail: 1

The United States was the primary target geography, with 8 of the 19 new victims. Financial Services and Legal sectors experienced many attacks, which indicates a broad, opportunistic targeting approach.

Ransomware News

Topline

The past 24 hours showed several threats: new ransomware groups, critical vulnerability exploitation, and persistent campaigns across various sectors.

Campaigns & Operations

Several new ransomware groups - TiMC, BlackWater, and Lamashtu - have been identified, indicating changes in threat actors often tracked through Dark Web Monitoring. The VECT & TeamPCP campaign conducted a supply-chain intrusion, exploiting a global travel platform to deploy ransomware. These incidents show the need for Supply Chain Risk assessments. Kairos ransomware claimed a breach of Queensland's FriendlyCare Pharmacy, exfiltrating 113 GB of medical and personal data, similar to attacks on other Australian targets like Seagrass Boutique Hospitality Group in February 2026. A six-year, low-dollar, high-volume JanaWare ransomware campaign targeting Turkish homes and SMBs via modified Adwind RAT loaders was uncovered, often exploiting weak SMB defenses. Autovista (Germany and Australia) confirmed a ransomware disruption around April 12, while Guatemala's Laboratorio Nacional de Salud recovered from a March 9 intrusion, with internal files encrypted but no evidence of patient data compromise.

Vulnerabilities & TTPs

Exploitation remains an important vector, with a Defender zero-day chain involving BlueHammer and RedSun after CVE-2026-33825, and continued attacks using the 17-year-old Excel RCE CVE-2009-0238. Persistent brute-force attempts against SonicWall and FortiGate devices show the need for strong Credential Intelligence and hygiene, along with supply-chain and credential abuse, such as the WordPress Essential Plugin compromise. SmokedHam malvertising delivers Qilin ransomware.

Analyst Note

These developments show continued reliance on both novel and legacy vulnerabilities, the expansion of ransomware actor groups, and the persistent threat of supply-chain targeting across various attack vectors.

Technical Takeaways

  • Ransomware Group Activity: Many ransomware groups, including newly identified actors like TiMC, BlackWater, and Lamashtu, alongside established players like Payload and Akira, show a fragmented but persistent threat environment.
  • Persistent US Targeting: The United States continues to be the most frequently targeted country, accounting for 8 of the 19 new victims, with Financial Services and Legal sectors impacted.
  • Vulnerability Exploitation: Ransomware campaigns are actively using both recent vulnerabilities like the Defender 0-Day (CVE-2026-33825) and older RCEs such as the 17-year-old Excel flaw (CVE-2009-0238).
  • Supply Chain as an Attack Vector: The VECT & TeamPCP campaign's supply-chain intrusion via a global travel platform shows the ongoing risk associated with third-party dependencies.
  • Geofenced, High-Volume Campaigns: The six-year JanaWare campaign targeting Turkish SMBs demonstrates a model of low-value, high-volume ransomware attacks focused on specific geographies via modified Adwind RAT.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

Payload was the most active ransomware group, claiming 5 new victims. Akira followed with 3 victims, while Qilin and Vect each reported 2 new victims. A total of 11 groups posted new victims on their leak sites.

Q: What industries were most frequently targeted by ransomware today?

Financial Services and Manufacturing were among the most frequently targeted industries, each had multiple new victims. Other sectors impacted were Hospitality & Travel, Agriculture & Food, Construction & Engineering, and various professional services.

Q: Which geographic regions experienced the most ransomware attacks today?

The United States recorded the highest number of new ransomware victims, with 8 incidents. Other affected countries included Romania, Turkey, Australia, Poland, Japan, Italy, India, Hong Kong, and the Philippines, each with one reported victim.

Q: Have any new vulnerabilities (CVEs) been exploited by ransomware operators recently?

Yes, recent threat intelligence reports the exploitation of a Defender 0-Day chain (CVE-2026-33825) and the 17-year-old Excel RCE (CVE-2009-0238) in campaigns. These vulnerabilities affect ongoing ransomware activity and initial access vectors.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform covering every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats 24/7 and investigate incidents in natural language.

Explore our intelligence solutions:

April 11, 2026 Qilin Ransomware Victims: Critical Analysis of Attacks

Analyze Qilin ransomware victims and attack patterns across global sectors. Discover targeted industries and defense strategies against evolving threats.

Ransomware Report - 04/11/2026

Statistical Overview

Victim Totals

  • This month: 257
  • This quarter: 257
  • Year to date: 2879
  • Last 24h: 8

Quarterly Breakdown Q1: 2622 | Q2: 257 | Q3: 0 | Q4: 0

The second quarter started with 257 ransomware victims, bringing the year-to-date total to 2879. This continued activity shows threat actors operating globally.

Introduction

Eight new ransomware victims were reported in the last 24 hours. Qilin was the most active group with three new listings, followed by INC_Ransom with two. Krybit, LockBit, and NightSpire also reported victims. Attacks targeted sectors like Retail & Ecommerce, Manufacturing, Construction & Engineering, and Education, mainly affecting organizations in North America and Europe.

Ransomware Summary Table

# Group Victims (24h) Sample Victims Geos Sectors
1 Qilin 3 Hofland, Peuker & alexander, Sadtek Canada, Turkey Retail & Ecommerce, Manufacturing
2 INC Ransom 2 wright-ryan.com, www.campbell.edu United States Construction & Engineering, Education
3 Krybit 1 Conrepsa.ro Romania Construction & Engineering
4 LockBit 1 cegasa.com None Professional Services
5 NightSpire 1 Sahara air products United States Manufacturing

In the past 24 hours, Qilin and INC Ransom were the most active groups; they were responsible for over half of the new victim postings. Geographically, the United States had multiple new victims, with additional targets in Canada, Turkey, and Romania. Key sectors affected include Manufacturing, Retail & Ecommerce, Construction & Engineering, and Education, showing these groups target various sectors.

Victim Distribution

By Country

  • United States: 3
  • Australia: 1
  • Canada: 1
  • None: 1
  • Romania: 1
  • Turkey: 1

By Industry

  • Building Materials: 1
  • Floral and Giftware Wholesale: 1
  • None: 1
  • Construction and Contracting: 1
  • Defense, Aerospace, and Marine Engineering: 1
  • Construction: 1
  • Higher Education: 1
  • Machinery: 1

The United States had the most new victims, and activity also occurred in Canada, Romania, and Turkey. Industries like Construction & Engineering and Manufacturing continue to be hit, suggesting they remain attractive targets.

Ransomware News

Topline Two distinct incidents involving data exfiltration and public disclosure show ongoing threats to sensitive organizational data.

Campaigns & Operations INC Ransom claimed a cyberattack on NSW-based Rx Management, a pharmacy management firm, listing it on dark web leak sites and claiming the exfiltration of over 180GB of data. WorldLeaks took responsibility for exposing approximately 340,000 sensitive LAPD files, totaling 7.7 terabytes. This breach resulted from unauthorized access to a passwordless file-sharing tool used by the Los Angeles City Attorney's Office, not a direct LAPD system compromise.

Vulnerabilities & TTPs INC Ransom continues to use spear-phishing for initial access, followed by data exfiltration and extortion. The LAPD incident shows the persistent risks from misconfigured or insecure third-party file-sharing tools in public sector environments.

Analyst Note These events collectively show critical threats to sensitive data across healthcare supply chains and public institutions, often by exploiting common TTPs or vulnerabilities in third-party services.

What are the key technical takeaways from today's ransomware activity?

Key observations from the latest activity:

  • Qilin's Consistent Activity: The group remains active, showing continued targeting of different sectors in various geographies.
  • Supply Chain and Third-Party Risk: The INC Ransom attack on Rx Management shows the ongoing vulnerability of supply chains, especially in healthcare. The LAPD data leak by WorldLeaks shows the critical risk from insecure third-party tools and data transfer methods.
  • Persistent Industry Targeting: Construction & Engineering and Manufacturing sectors remain highly targeted because of their value to ransomware operators.
  • Geographic Breadth: Ransomware activity shows broad geographic activity, affecting North America and Europe, instead of hyper-focused regional campaigns.

FAQ

Q: Which ransomware groups were most active today, 04/11/2026?

A: On 04/11/2026, Qilin was the most active ransomware group with three reported victims. INC Ransom had two victims. Krybit, LockBit, and NightSpire each claimed one.

Q: What industries were targeted by ransomware on 04/11/2026?

A: Ransomware attacks on 04/11/2026 predominantly targeted the Retail & Ecommerce, Manufacturing, Construction & Engineering, and Education sectors. Other affected industries included Building Materials, Floral and Giftware Wholesale, and Professional Services.

Q: Which geographic regions experienced ransomware attacks on 04/11/2026?

A: On 04/11/2026, ransomware victims were reported in the United States (3 victims), Canada (1 victim), Romania (1 victim), and Turkey (1 victim). One victim had no specified geography.

Q: What ransomware incidents were reported on 04/11/2026?

A: Incidents included INC Ransom's alleged breach of NSW-based Rx Management, a pharmacy management firm, claiming 180GB of data was exfiltrated. WorldLeaks took responsibility for exposing approximately 340,000 sensitive LAPD files, stemming from a compromised file-sharing tool used by the Los Angeles City Attorney's Office.

Q: Were any new ransomware TTPs or vulnerabilities observed on 04/11/2026?

A: No new CVEs were specifically identified in today's reports. However, INC Ransom continued to use spear-phishing for initial access, followed by data exfiltration and extortion. The LAPD incident showed insecure third-party file-sharing tools were a significant access vector.

About PurpleOps

PurpleOps is an AI-first cyber threat intelligence platform. It covers every threat vector, from ransomware tracking to attack surface discovery. Our AI agents JINX and BUGSY triage threats and investigate incidents 24/7 in natural language. Explore our intelligence solutions:

← Back to Resources