By ScruteXPublished
Ransomware Attacks This Week: 172 Victims Across 49 Groups (September 21 to 27, 2026)

This is the Scrutex ransomware weekly for the September 21 to 27, 2026 window. Our CTI team tracked 172 unique ransomware and extortion victim postings across 49 active groups and 45 countries. Measured against the September 14 to 20 window rebuilt today on the same feeds and the same counting rules, that is down 23% from 223. The Gentlemen led with 22, 18 of them on Monday, and Qilin followed on 17. The United States took 73 postings, 42% of the week, and technology, manufacturing and business services finished within one posting of each other.
The headline number needs a warning attached. Our pooled collector added a sixth upstream tracker, cti.fyi, around September 18, and on the rules we used last week this window would have read 293 victims, up 22%. It is 172 and falling. The difference is 115 rows that are not victims this week: 46 flag emoji scraped from KillSec's country filter, 20 file names from a Brain Cipher dump, 12 Cl0p pagination tiles, ten surnames of private individuals, four status notices, and 23 re-postings of incidents first published weeks or years earlier. If you read a leak site tally this week that rose, check whether its feed changed.
Two of this week's claims are backed by the named organisation. Revolut confirmed on September 12 that customer data left the company after fraudulent legal requests sent from a real Italian government mailbox, and ImNotAVillain's leak site followed on September 24. Fresenius Medical Care confirmed unauthorised access to a limited number of internal systems on September 22, the same day ShinyHunters listed it, although the company has not named the group or said that data was taken.
The sector story is law. Silent Ransom Group listed Hogan Lovells Cadwalader, Clark Hill and Cozen O'Connor in two days, and DataBreaches.net reports that the first of those followed a month of failed negotiation. Separately, Cl0p relisted Kirkland and Ellis, a MOVEit victim from 2023, while rebuilding a leak site that ShinyHunters had hijacked a week earlier.
172 posts, 49 groups, 45 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and this week a fifth of the raw rows would have sent you after file names, flags and three year old incidents first.
A note on how we counted. 315 rows landed in the window from one pooled collector that now merges six upstream trackers. The 115 non-victim and repost rows came out first, and the remaining 200 resolved to 172 unique victims after we normalised group names, folded spelling variants together and deduplicated on victim name, domain root and posted website. 142 of the 172 appeared on two or more trackers and 30 rest on a single feed. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old.
This Week at a Glance

| Metric | Value |
|---|---|
| Total unique victims posted | 172 |
| Change on prior week | Down 23% (from 223, last week rebuilt on current feeds; 221 as published) |
| Like for like on last week's rules | 293 against 240, up 22%, inflated by a new feed |
| Active groups | 49 |
| Countries hit | 45 |
| Heaviest single day | Monday September 21 (44 posts, 26% of the week) |
| Quietest day | Saturday September 26 (6 posts) |
| Most targeted country | United States (73 victims, 42% of postings) |
| Most targeted sector | Technology (33), Manufacturing (32), Business Services (32) |
| Top group by volume | The Gentlemen (22, 18 of them on September 21) |
| Notable claims | Revolut, Fresenius Medical Care, Hogan Lovells Cadwalader, Receita Federal do Brasil, GE Vernova, Flex, STMicroelectronics, Securitas |
The shape is a Monday and a slow fade. Monday took 44, Tuesday 31, Wednesday and Thursday 30 each, Friday 23, and the weekend held 14 between them. The Gentlemen's Monday batch explains much of the first day: 18 victims across 13 countries, including STMicroelectronics, the South African insurer Guardrisk and an Alabama hospital. That is the fourth consecutive Monday batch from this group. Last week we flagged early data suggesting the pattern might break; it did not, and 18 of its 22 postings this week landed on the Monday.
The weekend figure is partly a pull artefact and partly real. Our data was taken on September 29, and late backfill usually adds a handful of rows to the last two days. But the raw weekend was not quiet: September 27 carried 55 rows before cleaning, 46 of them KillSec flag tiles.
The fall from 223 to 172 is genuine once the new feed is accounted for. Qilin dropped from 31 to 17, The Gentlemen from 30 to 22, and last week's newcomers N0n and Spirals from 11 and 7 to 3 and 2. No single crew replaced that volume. The top five groups took 66 of 172 postings, 38%, against 42% last week, and 37 groups posted three victims or fewer, together producing 66 postings.
Group Activity Breakdown

The top five groups produced 66 of 172 postings, 38% of the week. Below them, 37 groups posted three or fewer victims each, together accounting for another 66.
| Rank | Group | Victims | Share | Notable Activity |
|---|---|---|---|---|
| 1 | The Gentlemen | 22 | 13% | 18 on September 21 across 13 countries. STMicroelectronics, Guardrisk, DW McMillan Memorial Hospital, Charles Keith, FTAPI Software |
| 2 | Qilin | 17 | 10% | Six of seven days, largest run six. Ikegami Tsushinki, Telrad Networks, Columbus Informatica, GDM Pipelines, Agora cooperative |
| 3 | Akira | 9 | 5% | Four days, six in the US. Coe Press Equipment, Apex Litigation Support, HIT in Slovenia |
| 4 | MetaEncryptor | 9 | 5% | Six on September 21, three on the 25th. Flex, Bruker, Astemo, GE Vernova, Platinum Healthcare Staffing |
| 5 | Silent Ransom Group | 9 | 5% | Three named US law firms and six redacted stubs. Upper bound, see note below |
| 6 | INC Ransom | 8 | 5% | Six countries. Lemon Law, a Macau law and IP firm, a Moroccan pharmaceutical maker |
| 7 | WallStreet | 7 | 4% | Catholic University of El Salvador, Tobin and Company, two UK firms |
| 8 | Booba Project | 6 | 3% | Two US counties, a California high school, an Italian economic development consortium |
| 9 | Everest | 6 | 3% | All six on September 25. Securitas, CENELEC, UNIRITA, Morula IVF |
| 10 | Storm | 5 | 3% | The Money Store, Applied Composites, Magna Legal Services, a Canadian developer |
| 11 | Termite | 4 | 2% | Four US firms including TruAmerica Multifamily and theLender |
| 12 | DragonForce | 4 | 2% | France, Taiwan, Thailand, an Arizona medical equipment supplier |
A long tail of groups (EndZone, LockBit, N0n, Pear, Barracuda, Cl0p, Emperador, MedusaLocker, KryBit, Anubis, Global Secret Group, Play, Audit Team, Titan, Arcus Media, Rhysida, Spirals, ImNotAVillain, Meowciety403, Panzer, 3AM, Doommageddon, Money Message, NightSpire, Unsafe, BlackLocks, Kairos, SecP0, ShinyHunters, Brain Cipher, PayoutsKing, Space Bears, Kazu, Vexy, M3RX, Shiba and TiMc) each posted between one and three victims.
Silent Ransom Group's nine is an upper bound. Three name an organisation and six are redacted stubs of the "W... B..." kind this crew posts beside its named victims. One stub, "W... B...", also appeared last week, and we cannot tell whether it is the same firm.
Three observations:
The Gentlemen are a schedule, Qilin is a process. Four Mondays in a row The Gentlemen have published a batch of 18 to 30 and then almost nothing. Qilin posted on six of seven days again and never more than six at once. Last week the two finished one apart; this week five apart. What does not change is what the two numbers mean. A Gentlemen total measures when the queue is flushed. A Qilin total is closer to a rate.
MetaEncryptor is the week's real mover. Nine listings, up from five, and the names are larger than anything the brand has posted in our series: Flex, the contract manufacturer, with a claimed 365GB; Bruker, the scientific instrument maker, with 121GB; Astemo, the Hitachi and Honda automotive supplier; and GE Vernova. None has confirmed and no samples were published. Last week MetaEncryptor also claimed AECOM on the same day Brain Cipher did. A crew posting this many large names with no evidence is either newly well supplied or building a reputation, and we do not yet have data to separate the two.
Two crews dropped out of the top because of cleaning, not activity. Brain Cipher would have ranked third with 20 and Cl0p fifth with 15 on raw rows. Brain Cipher's 20 were file names from a published dump, and it posted one real victim, goldstarfinancial.com. Cl0p's 15 were 12 page tiles and three historical victims, leaving three current listings. Neither belongs in a count of the week's victims, and a tally that includes them is ranking two crews on web page structure.
New and Emerging Groups
One new data extortion brand with a confirmed victim, and two crews that stepped up.
ImNotAVillain. Not a ransomware group in the encryption sense. According to SecurityWeek and KELA, the actor likely took Italian government mailbox credentials from infostealer logs and then spent five to six months sending fake legal data requests to Revolut Bank UAB in Lithuania. Revolut confirmed on September 12 that customer data had been disclosed through requests from a legitimate government email domain, and it says it received no direct demand. The actor's own account is a 6,000 XMR demand, about $3 million, followed by attempts to extort individual customers among 680 high net worth crypto holders. Its leak site went live around September 24 with two entries: Revolut and "The Italy Files", about 150GB it describes as Italian police, Interior Ministry and Justice Ministry material. Italy's Interior Ministry has confirmed that a certified mailbox at the Prefecture of Reggio Calabria was used, while Polizia Postale's preliminary checks found no breach of ministry systems. The tradecraft to detect is not an exploit. It is a disclosure request that arrives from a genuine government domain, and the control is out of band verification of every legal data request before anything is released. The site also listed ten surnames of private individuals, which we exclude and do not reproduce.
Booba Project. Six listings, up from two, all public sector or public facing: Washington County and Merrimack County in the US, Tulare Western High School in California, COSEF, the economic development consortium of Friuli in Italy, a Moldovan firm and a US eye clinic. The crew appeared in June or July 2026 and no named source has yet described its access routes. What stands out is the target mix: county governments and a school district in one week is the profile of a crew that has found a shared weakness in local government IT, whether a common hosting provider or a common appliance, rather than one choosing victims individually.
WallStreet. Seven listings on two days, September 24 and 25, across the US, the UK and El Salvador, including the Catholic University of El Salvador, a Hawaii cosmetic surgery clinic and a US law firm. First seen in April 2026, WallStreet has no published tradecraft from a named source. Seven in two days is a batch, not a campaign, and the spread of countries and sectors gives no theme to hunt on.
Sector Targeting Analysis

| Rank | Sector | Victims | Share of labelled |
|---|---|---|---|
| 1 | Technology | 33 | 20% |
| 2 | Manufacturing | 32 | 20% |
| 3 | Business Services | 32 | 20% |
| 4 | Financial Services | 15 | 9% |
| 5 | Healthcare | 14 | 9% |
| 6 | Consumer Services | 12 | 7% |
| 7 | Public Sector | 6 | 4% |
| 8 | Transportation and Logistics | 4 | 2% |
| 9 | Education | 3 | 2% |
| 10 | Construction and Real Estate | 3 | 2% |
| 11 | Agriculture and Food | 3 | 2% |
| 12 | Hospitality and Tourism | 2 | 1% |
| 13 | Energy | 2 | 1% |
11 of the 172 postings carried no usable sector label, the lowest this quarter, so the percentages are more reliable than usual.
The top three sit within one posting of each other, which says the field this week had no sector theme at the volume end. Technology at 33 is the usual mix of small IT and software firms plus a few that hold other organisations' data: FTAPI, a German secure file transfer vendor listed by The Gentlemen, and eTeam, a US staffing technology firm listed by EndZone. For anyone who uses FTAPI to move sensitive files, that listing matters more than its rank.
Manufacturing at 32 carries the week's largest names: STMicroelectronics, Flex, Bruker, Astemo, GE Vernova and Ikegami Tsushinki. All are claims, none confirmed. Large manufacturers are rarely listed for the value of their own records. The pressure point is intellectual property and supplier disruption, and a listing of a contract manufacturer like Flex puts its customers' designs in scope.
Business services at 32 and financial services at 15 together contain the week's clearest thread: law firms. Silent Ransom Group listed Hogan Lovells Cadwalader, Clark Hill and Cozen O'Connor. WallStreet listed Prater and Ridley, INC Ransom listed Lemon Law and a Macau IP firm, Akira listed Apex Litigation Support, and Storm listed Magna Legal Services. That is eight legal sector postings from five crews. Law firms hold other companies' deal documents, litigation files and privileged communications, which is why a single firm listing is a supply chain event for every client it serves.
Healthcare at 14 is mostly small: US clinics and practices, a fertility clinic in South Africa, a Moroccan pharmaceutical maker, a US senior living provider. Fresenius Medical Care is the exception and the only healthcare incident here the company has acknowledged.
Public sector at 6 includes Brazil's federal revenue service, Merrimack County in New Hampshire, a California high school, the Charlottesville Police Department's recruitment site, Angola's e-government platform and the Italy Files claim.
Country Distribution

| Rank | Country | Victims | Share |
|---|---|---|---|
| 1 | United States | 73 | 42% |
| 2 | Brazil | 8 | 5% |
| 3 | Italy | 8 | 5% |
| 4 | United Kingdom | 7 | 4% |
| 5 | Spain | 4 | 2% |
| 6 | Canada | 4 | 2% |
| 7 | Germany | 4 | 2% |
| 8 | France | 4 | 2% |
| 9 | Japan | 3 | 2% |
| 10 | Portugal | 3 | 2% |
| 11 | Mexico | 3 | 2% |
| 12 | South Africa | 3 | 2% |
| 13 | Colombia | 2 | 1% |
| 14 | Angola | 2 | 1% |
| 15 | Sweden | 2 | 1% |
A further 30 countries recorded one or two victims each: Finland, India, Argentina, Australia, South Korea, Israel, Austria, Moldova, Kazakhstan, Mali, Uzbekistan, Slovenia, Peru, Pakistan, Thailand, Bulgaria, the Czech Republic, Oman, Taiwan, Macau, Tanzania, Saudi Arabia, Uganda, Singapore, El Salvador, Belgium, Morocco, Indonesia, Kenya and the UAE. 8 postings carried no country, six of them Silent Ransom Group stubs.
The US count was unchanged at 73. Its share rose from 33% to 42% only because everything else fell. Akira and MetaEncryptor supplied six each. For the publicly listed US names, including GE Vernova, Flex and Bruker, the relevant clock is the SEC's: a Form 8-K within four business days of determining that an incident is material.
Germany fell from 11 to 4, the largest single country drop, with no concentration in either week. Italy held at 8, and the composition is worth reading because two of the eight are this week's merges: Rhysida's one Italian victim arrived under four labels and LockBit's under two. Italian entities under NIS2 report to ACN with a 24 hour early warning.
Brazil at 8 includes the Receita Federal claim. Brazil's LGPD, through ANPD's incident reporting regulation, requires notification to the authority and to affected individuals within three working days of becoming aware of an incident that may cause relevant risk or damage. For a tax authority holding every taxpayer's records, that threshold is not in doubt if the claim holds.
The UK at 7 includes Revolut. Revolut's affected entity is Revolut Bank UAB, supervised in Lithuania, so the GDPR 72 hour clock ran through the Lithuanian authorities rather than the UK ICO, which is a useful reminder that where a fintech is headquartered and where it is regulated are different questions.
India appears once, with Everest's Reliance Audit listing. Under CERT-In's 2022 directions, a reportable incident must reach CERT-In within six hours of being noticed, the shortest clock on this list. Japan's three listings, Astemo, UNIRITA and Ikegami Tsushinki, fall under APPI reporting to the Personal Information Protection Commission, with a preliminary report expected promptly and a final report within 60 days where an attack caused the leak.
Notable Claims and Incidents
Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation or an authority has said so.
ImNotAVillain lists Revolut, and Revolut has confirmed a data disclosure. Posted on the leak site around September 24, with the claim public since September 16. Revolut confirmed on September 12, via TechCrunch, that customer data was disclosed after fraudulent requests sent from a legitimate government email domain, and later told SecurityWeek it had received no direct contact or demand from the group. The actor claims KYC and identity documents, statements and crypto transaction histories for 680 high net worth customers. Confidence: High that customer data left Revolut through this route, because the company has said so. Low on the actor's customer count and ransom figure, which only the actor has stated. The detection lesson generalises to every regulated firm: a legal data request is only as trustworthy as the mailbox it came from, and a mailbox is only as trustworthy as the credentials on the machine that uses it.
ShinyHunters lists Fresenius Medical Care the day the company confirms an incident. Posted September 22 with a deadline of September 25 and no samples. Fresenius said the same day that it had detected unauthorised access to a limited number of internal systems, engaged external experts and notified law enforcement, with no impact on devices, patient care or manufacturing. The statement does not mention ShinyHunters, ransomware or data theft. Confidence: High that an incident occurred. Medium that ShinyHunters is responsible, since the timing fits and the company's wording does not contradict it. ShinyHunters spent the rest of the week posting three statements about the FBI, which we exclude as non-victims and cover under operational shifts.
Silent Ransom Group lists three US law firms in two days. Hogan Lovells Cadwalader on September 21, Clark Hill and Cozen O'Connor on September 22. DataBreaches.net reports, from chat logs and data it reviewed, that SRG first accessed Hogan Lovells Cadwalader on August 12, that negotiation ran from August 25 to September 21 and ended without payment, and that SRG attacked again on September 23. The group claims more than 50GB including around 500 passports, driving licences and Social Security numbers and more than 930 files marked privileged and confidential. None of the three firms has commented publicly. Confidence: Medium for Hogan Lovells Cadwalader, because an independent outlet reviewed material and the target fits SRG's documented focus on law firms. Low for Clark Hill and Cozen O'Connor, which rest on the listings alone. The FBI's May 2026 advisory on this group describes callback phishing, fake IT support calls and, more recently, in person visits to offices. None of that is an exploit, and none of it is blocked by patching.
Emperador lists Receita Federal do Brasil. Posted September 23. The actor claims 6.3GB including citizen documents and gov.br user records with passwords, and sets a release date of October 13. Receita Federal has not responded to this claim; its public denial in June concerned a different sale of a claimed 248 million records and should not be read as a response here. Confidence: Low. Emperador is two months old, has published no sample for this listing, and its other activity this week was reposting: its combined "Electrolux and Ontrac" entry on September 25 restated two listings it had already made, which we count once each in the weeks they first appeared.
MetaEncryptor lists GE Vernova, Flex, Bruker and Astemo. Six listings on September 21 and three on September 25. Named outlets and trackers report claimed volumes of 365GB for Flex and 121GB for Bruker and none for the others. No company has confirmed, and US law firms have opened class action investigations into Flex on the strength of the listing alone. Confidence: Low. The volume of large names from one crew in one week, following last week's AECOM claim, is the reason to watch MetaEncryptor rather than any single entry. Note that the "GE" in Cl0p's August Windchill campaign was General Electric, not GE Vernova, and the two should not be merged.
Low signal claims this week. 15 postings are a bare domain and 10 are redacted to a few characters, so 147 of 172, 85%, name an organisation. Among the named, several deserve a flag rather than a headline. The Gentlemen's STMicroelectronics listing names "internal data" with no volume. Everest's Securitas listing describes a 92GB archive of video security software packages, which is product installers rather than customer data, and its CENELEC listing follows a Coinbase Cartel claim on the same standards body in August, which suggests resale. EndZone's Trump Mobile listing claims eSIM QR codes and personal data, and the company separately confirmed a third party exposure of customer details in May, so the two may overlap. Doommageddon's Charlottesville Police Department listing concerns cpdcareers.com, a recruitment site, not police systems. 30 postings rest on a single tracker.
A Note on Data Quality
A new feed, and why the like for like figure went the wrong way. Our pooled collector added cti.fyi as a sixth upstream around September 18. It scrapes leak sites more literally than the other five, harvesting whatever sits in the title slot of a listing, and it stamps its own first seen time on postings it meets for the first time, so older victims re-enter the pool dated this week. On last week's rules this window reads 293 and last week's reads 240, up 22%. On the tightened rules the figures are 172 and 223, down 23%. We publish both for this issue so the change is auditable. The tightened figure is the one we stand behind.
What came out, and why. 115 of 315 raw rows.
| Excluded | Rows | Reason |
|---|---|---|
| KillSec flag tiles | 46 | The leak site's country filter, scraped as victims on September 27 |
| Brain Cipher file names | 20 | Archive and backup files from a published dump ("Windiam_ACC_OFF.BAK") |
| Cl0p pagination tiles | 12 | ARCHIVE2 to ARCHIVE14 on the rebuilt leak site |
| Private individuals | 10 | Surnames posted by ImNotAVillain; we count organisations and do not republish names |
| Statements and markers | 4 | Three ShinyHunters FBI statements, one Doommageddon "PAID" marker |
| Reposts | 23 | Kazu's six South African and Peruvian victims from September 7; ULose's five Korean firms from June 9; Sovcali's six posts escalating an August 9 Lucid Motors claim; Cl0p's Kirkland and Ellis, Pan-American Life and E-Land Retail, all documented earlier Cl0p victims; Shiba's first listing from September 9; Emperador's combined Electrolux and OnTrac re-post; Storm's First Secure Bank Group, the holding company of two banks it listed on September 18 |
The week 37 rebuild was run through the same rules, and it absorbed 164 more Brain Cipher file names that cti.fyi had backfilled onto September 18. The rebuilt total is 223 against the 221 we published.
Merges. Rhysida's one Italian victim arrived under four labels: NEAD Pro, NEAD Pro Professionisti Riuniti, NEAD SRL and its legal name, North East Advisor S.R.L. LockBit posted corisricambi.it while RedACT carried CO.R.I.S. S.R.L. Money Message posted Wiedenbach Brown alone and with its parent. Termite posted bare URLs on one tracker and company names on three, and those now meet on the website's domain, which is a new dedupe key this issue.
Three Cl0p listings stay in, flagged. Valley Truck and Tractor, KSS Architects and Sweetlake Land and Oil came from the same September 23 batch as the three historical victims. We found no earlier Cl0p posting for them, so they count, but treat them as possible reposts.
A correction to last week. We gave CVE-2024-40766 a CVSS of 9.3, which is SonicWall's own score. NVD scores it 9.8, and this issue uses NVD scores throughout where one exists.
Top CVEs These Groups Are Exploiting
The table covers this week's active groups where a named source supports the attribution. CVSS is the NVD v3.1 base score unless marked otherwise.
| CVE | Product | CVSS | Who is using it | Why it matters |
|---|---|---|---|---|
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy, authentication bypass | 9.8 | The Gentlemen | Group-IB (March 2026) and Check Point Research (May 2026) name it the group's primary access route, with Group-IB reporting a database of around 14,700 compromised FortiGates. Four Monday batches in a row fit an operator working through that inventory |
| CVE-2023-27532 | Veeam Backup and Replication, credential exposure | 7.5 | The Gentlemen | Group-IB documents it after access, to pull stored credentials. Backup servers hold the keys to the rest of the estate |
| CVE-2026-0257 | Palo Alto Networks PAN-OS GlobalProtect, authentication bypass | 9.1 | Qilin | Arctic Wolf (July 2026) traced multiple June intrusions from this flaw to Qilin deployment. On the CISA KEV catalogue since May 29 |
| CVE-2026-50751 | Check Point Remote Access VPN and Mobile Access, IKEv1 authentication bypass | 9.3 (vendor) | Qilin affiliate | Exploited as a zero day from about May 7. Check Point confirmed Qilin affiliate activity after compromise in one case |
| CVE-2024-40766 | SonicWall SonicOS SSLVPN, improper access control | 9.8 | Akira | Arctic Wolf, Huntress and Darktrace tie sustained Akira activity to it, including reuse of credentials harvested before patching. VPN accounts without MFA were the entry point |
| CVE-2023-3519 | Citrix NetScaler ADC and Gateway, unauthenticated RCE | 9.8 | INC Ransom | Trend Micro's INC profile documents exploitation. The reporting is from 2024, and we found no newer named source attributing a CVE to INC |
| CVE-2026-12569 | PTC Windchill PDMLink and FlexPLM, deserialization RCE | 9.8 | Cl0p | ReliaQuest (August 2026) attributes the Windchill mass extortion campaign to Cl0p with high confidence. None of this week's Cl0p listings is linked to it in public reporting |
| CVE-2026-18577 | N-able N-central, authentication bypass | 8.1 | Storm-1175, not the Storm leak site | Microsoft reports likely exploitation by Storm-1175 deploying StormEncryptor. Microsoft's "Storm-" prefix is a naming scheme for actors under tracking, and nothing ties this to the Storm crew in our table |
Driver abuse matters as much as the access CVEs this week. Cisco Talos and Trend Micro describe Qilin loading a renamed ThrottleStop driver, rwdrv.sys, alongside a malicious hlpdrv.sys that can terminate hundreds of endpoint security drivers. Arctic Wolf reported the same pair in Akira intrusions. Group-IB and Trend Micro document The Gentlemen using ThrottleStop renamed ThrottleBlood.sys. Three of this week's top three crews share one vulnerable driver, which makes a block rule on its hash one of the most efficient controls on this page.
Attribution accuracy note. Six of this week's top ten groups have no verifiable access CVE. Silent Ransom Group works through callback phishing, fake IT support calls, legitimate remote access tools and physical visits, per the FBI's May 2026 advisory, Halcyon and Mandiant. Everest, per Halcyon, uses exposed RDP and VPN without MFA, bought credentials and an insider recruitment programme, with no CVE observed. MetaEncryptor, WallStreet, Storm, Booba Project and Emperador have no named source describing their access at all. The Storm leak site, first seen in August, should not be read as Microsoft's Storm-1175 or Storm-2570.
Two practical notes follow. The groups with named CVEs all enter through the edge: FortiGate, GlobalProtect, Check Point VPN, SonicWall, NetScaler. And the groups without them mostly enter through a person, which is why this week's two confirmed incidents, Revolut and the law firms, involve no exploit at all.
Infrastructure and Operational Shifts
Crews are attacking crews. ShinyHunters hijacked and defaced Cl0p's leak site on September 18 through a path traversal flaw in the Grav CMS it ran on, CVE-2026-42608, and claimed Cl0p's source code, server logs and onion private keys. BleepingComputer reports that Cl0p announced a new onion address on September 25. The listings on the rebuilt site included victims Cl0p first claimed in 2020 and 2023. Two consequences for defenders. A leak site being rebuilt republishes its back catalogue, so a name reappearing is not a new incident. And the private keys of a leak site in a rival's hands make every future posting on that address less trustworthy as evidence of anything.
Reposting has become a tactic, not an accident. Reposts from seven crews reached this week's raw data: Cl0p's back catalogue, Emperador bundling two earlier victims into one new threat, Storm listing the holding company of banks it had already named, Sovcali publishing essays about a victim it first claimed in August, and Kazu, ULose and Shiba, whose older postings a new feed met for the first time. A repost raises pressure on a victim that has not paid and costs the actor nothing. For anyone counting, it is the single largest source of inflation after scraping errors.
ShinyHunters is running press operations through its leak site. Its three excluded postings this week were statements about a claimed breach of FBIJobs.gov, which the FBI says it is investigating, and a demand that the FBI withdraw a May advisory. On September 28 the group said it would never publish the data and called the episode a marketing campaign. The leak site as a press office is not new, but it means the victim column on these sites increasingly carries content that is not about victims.
Data extortion without encryption produced both confirmed incidents. Revolut's disclosure came through forged legal process, and Silent Ransom Group does not deploy ransomware at all. Neither would appear in an encryption based incident count, and both would be missed by a control set built around ransomware detection alone.
First Look at September 28
Our window closed on Sunday September 27, so here is what the next one opened with, stated as raw counts from a pull taken on September 29 at 13:09 UTC. September 28 carried 75 raw rows. Eleven of them are ImNotAVillain reposting the same ten private surnames plus "The Italy Files" under a misspelled brand on a different tracker, which we will exclude. Global Cybernetic Collective posted seven on a single tracker, including a "WHO IS NEXT??" banner and Shanghai Tunnel Engineering, a name the Global crew posted on August 28, which suggests a rebrand. SafePay returned with nine bare domains after a quiet fortnight, and 3AM posted seven. MedusaLocker listed Junta de Andalucia and ATCO, and SafePay listed the Holiday Inn in Vilnius. These are raw rows and will fall once cross tracker duplicates and reposts are removed. They will be counted in issue 39.
Key Takeaways for Defenders
Verify every legal data request out of band. Revolut disclosed customer data to requests sent from a real government mailbox operated with stolen credentials. Keep a directory of law enforcement and regulator contacts, verify each request by phone to a number you already hold, and require a second approver before production. This applies to any firm that receives subpoenas or data requests, not only banks.
If you are a law firm, train for the phone call, not the exploit. Silent Ransom Group listed three large US firms in two days, and its route is a call from "IT support" that ends with remote access software installed. Block unapproved remote support tools, tell staff that IT will never ask them to install one on a call, and make sure reception knows the same applies to someone arriving in person.
If your supplier is a law firm, ask what they hold of yours. Eight legal sector listings from five crews this week. Establish which firms hold your deal, litigation and privileged material and what their incident notification commitment to you is.
Block the ThrottleStop driver. Qilin, Akira and The Gentlemen all use a renamed ThrottleStop driver to kill endpoint protection. Add its hash to your vulnerable driver block list and alert on any driver load outside your approved set.
Patch the edge, then rotate what sits behind it. FortiOS CVE-2024-55591, PAN-OS CVE-2026-0257 and SonicWall CVE-2024-40766 are the routes this week's named crews use. Each has shown that credentials captured before a patch keep working after it. Patch, reset local VPN accounts, enforce MFA, and review sessions that predate the patch.
Ask whether your feed changed before trusting a trend. This week the same data reads up 22% or down 23% depending on whether scraped junk and reposts are removed. Before a leak site total goes into a board update, ask how it was deduplicated and whether its sources changed.
Most of that work is triage before it is defence. Somebody has to read 315 raw rows, discard the 115 that are not victims, and work out which of the rest touch your organisation or your suppliers.
Where Scrutex Fits
Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface and your named suppliers, so a listing that names your domain or a vendor's domain reaches you as an alert rather than as a line in a weekly roundup. Vulnerability Insights prioritises flaws like the edge CVEs above by real world exploitability against your exposed assets rather than by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.
Start at scrutex.ai/signup or read more at scrutex.ai/solution/threat.
Frequently Asked Questions
How many ransomware attacks were there in the week of September 21 to 27, 2026?
We tracked 172 unique victim postings across 49 active groups and 45 countries. That is down 23% from 223 for September 14 to 20, rebuilt on the same feeds and rules. These are leak site postings rather than confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Why do other trackers show more victims this week?
A tracker that counts every row will include 46 flag icons from KillSec's leak site, 20 file names from a Brain Cipher dump, 12 Cl0p page tiles and 23 re-postings of older incidents. We removed 115 such rows. On our previous rules the week would have read 293 and appeared to rise 22%.
Which ransomware group was most active?
The Gentlemen, with 22, ahead of Qilin on 17. The Gentlemen published 18 of its 22 on Monday September 21, the fourth consecutive Monday batch. Qilin posted on six of seven days with no run larger than six.
Was Revolut hacked?
Revolut confirmed on September 12 that customer data was disclosed after fraudulent legal requests sent from a legitimate government email domain. The actor, ImNotAVillain, claims data on 680 high net worth customers and a $3 million demand; Revolut says it received no direct demand. We rate the disclosure high confidence and the actor's figures low.
Did Fresenius Medical Care suffer a cyberattack?
Fresenius confirmed on September 22 that it detected unauthorised access to a limited number of internal systems, with no impact on patient care or manufacturing. ShinyHunters listed the company the same day. Fresenius has not named the group or said data was taken.
Which law firms were listed by ransomware groups this week?
Silent Ransom Group listed Hogan Lovells Cadwalader, Clark Hill and Cozen O'Connor. WallStreet, INC Ransom, Akira and Storm listed five smaller legal and litigation support firms. None has confirmed. Cl0p also relisted Kirkland and Ellis, which was a MOVEit victim in 2023.
Which CVEs are these groups exploiting?
The Gentlemen use CVE-2024-55591 on FortiOS, Qilin uses CVE-2026-0257 on PAN-OS and CVE-2026-50751 on Check Point VPN, Akira uses CVE-2024-40766 on SonicWall, and Cl0p's current campaign uses CVE-2026-12569 in PTC Windchill. Qilin, Akira and The Gentlemen also share a vulnerable ThrottleStop driver. Six of the top ten groups have no verifiable access CVE.
Where can I get this in real time instead of weekly?
Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, so a relevant listing reaches you when it is posted rather than in the following Monday's roundup.