⌁ DAY 42

Ransomware gang activity surge reported mid-September

11 beadsAug 19 → Sep 25moved 4d ago

The wire

2026-09-25

Ransomware gangs claim fresh victims on dark web

broke 4d ago · 15 reports · other

Between September 25–27, 2026, multiple ransomware groups including Qilin, Genesis, Akira, AuditTeam, and Global Secret Group posted new victim claims on their dark-web blogs. The posts, tracked by infosec communities, listed manufacturing and technology companies, indicating ongoing extortion campaigns.

2026-09-23

Ransomware gangs post victim claims on disclosure sites

broke 6d ago · 15 reports · other

Multiple ransomware-as-a-service groups including Booba Project, qilin, rhysida, Spirals, and incransom posted new victim claims to their leak sites between 2026-09-23 and 2026-09-25, announcing compromised organizations across US counties and sectors.

2026-09-21

Ransomware groups claim victims on dark web blogs

broke 9d ago · 10 reports · other

From 2026-09-21 to 2026-09-22, an infosec Mastodon account posted alerts about ransomware groups including incransom, nightspire, qilin, BrainCipher, akira, kairos, and Booba Project publishing victim data and ransom demands on their dark web blogs. Posts document multiple alleged breaches and extortion attempts.

2026-09-14

Ransomware gang activity surge reported mid-September

broke 15d ago · 18 reports · other

Between 14 and 16 September 2026, multiple ransomware groups posted victim claims on their leak sites, including genesis (Dorfman Abrams Music and Bernath & Rosenberg), ShadowByt3$ (HandyTrac), anubis (Better Accounting Solutions), ransomhouse (Namibian Defence Force), kairos and qilin, and blacknevas (Mefa Group and subsidiaries). The posts were aggregated and shared across infosec monitoring channels.

2026-09-12

Ransomware groups post victims on leak sites

broke 17d ago · 13 reports · other

Between September 12 and 14, 2026, multiple ransomware gangs—including Krybit, Panzer, Qilin, and Eclipse—posted new victims on their extortion blogs. Targets included businesses and government entities such as airports (EAC Airports), manufacturing firms (Foremost Mfg, Minmer Global), contractors (Winston Contracting), and a school district (Dublin City Schools GA).

2026-09-09

Ransomware groups claim multiple victims September 2026

broke 20d ago · 11 reports · other

Between September 9 and 11, 2026, various ransomware groups including Qilin, Incransom, BlackLocks, Play, Global Secret Group, Dragonforce, and ShadowByt3$ posted claims of victims to their extortion blogs. Targeted victims included businesses like Jet Specialty, GT Distributors, Red Star Oil, and medical facilities.

2026-09-07

Ransomware groups post multiple new victim claims

broke 22d ago · 15 reports · other

Between September 7 and 9, 2026, multiple ransomware groups including Akira, Interlock, Safepay, Panzer, and Anubis posted new victims on their dark web blogs, claiming responsibility for attacks on companies spanning industrial engineering, auto wash, lending, and support services sectors. The posts were monitored and reported by cybersecurity researchers on Mastodon.

2026-09-04

Ransomware groups post new victim claims between early and mid-September

broke 25d ago · 13 reports · other

Between 4–6 September 2026, ransomware threat-intelligence feeds tracked six new victim announcements from groups pear, rhysida, qilin, chaos, SilentRansomGroup, and krybit, targeting healthcare, legal, port authority, and biotech sectors. No operational details or ransom demands were disclosed in the social posts.

2026-08-28

Ransomware groups post new victim claims on blogs

broke 32d ago · 13 reports · other

Between 2026-08-28 and 2026-08-30, ransomware groups Chaos, Qilin, Incransom, Lynx, Akira, and Global posted new victim claims on their respective blogs, listing companies including macallister.com, corematerials.com, Alter Consultores Legales, Newton County School System, Oilquip Inc, cutlercapital, Cetylite, Seabrook Island, Bihl, Alumax, Atcomm, and Shanghai Tunnel Engineering Co Ltd. Six consecutive posts tracked by cybersecurity monitoring services.

2026-08-24

Ransomware groups post victim claims on leak sites

broke 36d ago · 14 reports · other

Multiple ransomware groups—Qilin, Beast, Dragonforce, Deadlock, and AiLock—posted new victim claims to their leak blogs between August 24-26, 2026. The postings included claims against businesses such as A&E + SMA Design, Meridian Forest Services, Coldfish Seafood, Global Terminal Services, and others.

2026-08-19

Ransomware gang activity monitoring: multiple groups claim new victims

broke 41d ago · 15 reports · other

Between August 19 and 21, 2026, security threat-intelligence feeds tracked six ransomware groups (incransom, interlock, insomnia, dragonforce, rhysida, pear) publishing claimed victims on their leak blogs, including organizations ranging from universities to law firms and small businesses.