ransomware weekly
61 views

Ransomware Attacks This Week: 179 Victims Across 44 Groups (September 7 to 13, 2026)

By ScruteXPublished

Summary

This is the Scrutex ransomware weekly for the September 7 to 13, 2026 window. Our CTI team tracked 179 unique ransomware and extortion victim postings across 44 active groups and 45 countries. Measured against the August 31 to September 6 window rebuilt today on the same feeds and the same counting rules, that is down 12% from 203. It is the second consecutive weekly fall and the lowest total we have recorded this quarter.
The week was decided on its first day. Monday September 7 carried 54 postings, 30% of the total, and The Gentlemen supplied 19 of them in a single run across 16 countries. From there volume faded to 29, 27, 24 and 13, rose to 23 on Saturday because KryBit uploaded 12 bare domains in one batch, and closed at 9 on Sunday. Take away the Monday run and the Saturday batch and the remaining 148 postings were spread thinly across the rest of the week.
The standout story is the gap between the size of the names and the weight of the evidence. The Gentlemen listed Air Canada and claims 51,409 files. ShinyHunters listed the State of Florida DMV with a September 11 deadline. Cl0p posted harley-davidson.com. MetaEncryptor named ST Engineering and Hologic in one run. We could not find a statement confirming any of those five. The one claim in this report where the organisation itself has confirmed data theft is a follow up from last week: Veradigm disclosed on September 8 that an attacker used a vendor's credentials to pull patient data through a customer service API.
The second thread is old data wearing new labels. Kazu listed Statistics South Africa and the Gauteng Provincial Government, two bodies a different crew claimed in March 2026, when Stats SA confirmed a breach. Audit Team published two slots labelled "Paid Victim" with a hex handle and nothing else. Leak sites are increasingly used to resell, relist and advertise, and a listing's date tells you when it was posted, not when anything happened.
179 posts, 44 groups, 45 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.

This Week at a Glance

MetricValue
Total unique victims posted179
Change on prior weekDown 12% (from 203, last week rebuilt on current feeds; 205 as published)
Active groups44
Countries hit45
Heaviest single dayMonday September 7 (54 posts, 30% of the week)
Second heaviest dayTuesday September 8 (29 posts)
Quietest daySunday September 13 (9 posts)
Most targeted countryUnited States (57 victims, 32% of postings)
Most targeted sectorTechnology (31 named), Business Services (28), Manufacturing (25)
Top group by volumeThe Gentlemen (21 posts, 19 of them on September 7)
Largest single day runThe Gentlemen (19 on September 7)
Notable claimsAir Canada, State of Florida DMV, Harley-Davidson, ST Engineering, Hologic, Kimberly-Clark, Statistics South Africa, Port of Tanjung Pelepas
The line has one peak and a long tail. Monday opened at 54, Tuesday dropped to 29, Wednesday 27, Thursday 24, Friday 13, Saturday rose to 23 and Sunday closed at 9. Monday alone was larger than the last three days of the week combined.
Monday is the part worth explaining, because it is not a one off. The Gentlemen published 19 victims across 16 countries on September 7, and the first day of the following window, September 14, opens with roughly 30 more from the same crew. That is a publication schedule rather than a coincidence. An affiliate programme that processes intake all week and publishes in one batch at the start of the next will put a spike on every Monday it runs, and the rest of the week will look quiet by comparison. A quiet Thursday in this field says very little about the field.
The top five groups took 36% of volume against 35% last week on the rebuilt figures, so concentration was flat again. What changed is who sits in the table. Settra, last week's leader on 17 bare domains, posted nothing. Silent Ransom Group, which produced three AmLaw 100 names last week, posted nothing. Qilin fell from 15 to 8. The Gentlemen doubled from 10 to 21. Week to week movement at the top of a leak site chart is mostly a record of which operators uploaded, and it should be read that way.
The tail stayed long but got shorter. 44 groups posted, 24 of them three victims or fewer, and 13 posted exactly once. Those 24 groups together produced 39 postings, 22% of the week.

Group Activity Breakdown

The top five groups produced 64 of 179 postings, 36% of the week. Below them, 24 groups posted three or fewer victims each, together accounting for 39 postings.
RankGroupVictimsShareNotable Activity
1The Gentlemen2112%19 on September 7 across 16 countries, then Air Canada and PharmaEssentia on September 9. Hollard Insurance Group, University of San Francisco, Metro, Yapi Merkezi
2KryBit137%Twelve bare domains on September 12 and one more on the 13th. Canada, UAE, Georgia, Kenya, Haiti, India, Mexico, France, Croatia, South Africa, Morocco, US
3Audit Team116%All eleven redacted to a few letters. Four in Russia, two in South Korea, one each in Ukraine, Germany, Argentina, Japan and India. Two further "Paid Victim" slots removed
4SafePay116%Ten bare domains on September 8, European heavy: Portugal, two in Spain, Italy, Austria. Plus compunnel.com, a US IT staffing firm, on September 11
5DireWolf84%Port of Tanjung Pelepas, RelyComply AML software, Lightcast, EMS1R, Precision Vehicle Logistics
6Qilin84%Five days, no run larger than two. Imperial Healthcare Solutions, Alaska Electrical Apprenticeship, Mitsuwa Trading, CARIDRO Val de Loire
7Kazu74%All seven on September 7. Statistics South Africa, two Gauteng government bodies, MSM Unify, two health data firms
8Akira74%Spread over three days. Kyodo USA, Brent Electric, CreateASoft, AK Stamping India
9Emperador63%Bosnia and Herzegovina Mine Action Center, BAYMER, Universal Starch-Chem, Navitrans
10Panzer53%Spain's State Meteorological Agency, Konica Minolta Bulgaria, Financiere d'Uzes, Aqualogus
11LockBit53%Bare domains only. South Africa, the Netherlands, Argentina, Brazil, Germany
12Rhysida53%General Santos Doctors Hospital in the Philippines, three US retail and manufacturing firms, one French staffing agency
13Vexy53%Second week running. i2k2 Networks, Strad Solutions, Logar Network Solutions, United Group
14MetaEncryptor42%All four on September 7. ST Engineering, Hologic, EllisDon, SIFCO Industries
15Storm42%All four on September 9, three of them Canadian
16NightSpire42%All four on September 11. Brazil, Colombia, Turkey, UAE
A long tail of groups (Dark Project, INC Ransom, Play, MedusaLocker, Everest, ShinyHunters, Chaos, WallStreet, ShadowByt3$, Aurora, Global, Global Secret Group, Cl0p, BlackNevas, Eclipse, Doommageddon, Barracuda, Unsafe, Securotrop, DragonForce, FulcrumSec, Pear, Beast, RansomHouse, Anubis, Embargo, Insomnia and Interlock) each posted between one and four victims.
Three observations:
The Gentlemen has become a Monday publisher. 19 of its 21 postings landed on one day, across Australia, South Africa, Italy, Portugal, Brazil, Georgia, the US, Peru, Chile, Turkey, Germany, Argentina, Denmark, Colombia, India and Egypt. No shared sector and no shared region, which is the signature of an affiliate programme clearing a queue rather than a campaign. The two postings after Monday are the ones to watch: Air Canada and PharmaEssentia, a Taiwanese biopharmaceutical company, both posted separately on September 9. Named, high value targets posted on their own day tend to be the ones an affiliate expects to negotiate over. Third party tracking puts the group above 600 claimed victims in 2026 alone.
KryBit and SafePay are a batch artefact, not a surge. 22 of their 24 postings arrived in two single day uploads, and 23 of the 24 are a bare domain with no company name, no data volume and no sample. KryBit's twelve span twelve countries with nothing connecting them. SafePay's ten lean European and small. Neither run tells you anything about new intrusions last week. Both tell you that two operators emptied a list. SafePay remains one of the more capable crews in the field, and Sygnia has documented it exfiltrating through OneDrive to stay inside allowed traffic, but this week's count is a spreadsheet upload.
Audit Team is posting against Russia. Four of its eleven listings are Russian organisations, with Ukraine, South Korea, Japan, Germany, Argentina and India making up the rest. Most extortion crews that originate in the former Soviet space avoid Russian targets entirely, so a group listing them repeatedly is either operating from outside that sphere or signalling something by doing it. Every Audit Team listing is redacted to a few letters and a country, and the crew has started publishing "Paid Victim" slots with a hex handle, which reads as advertising that someone paid. We could not attribute a single one of its eleven entries to a named organisation, and we report its count as an upper bound.

New and Emerging Groups

Four crews in this section. None is new this week, and each changed something about how it operates.
Audit Team. Eleven postings over six days, the group's busiest week in our collection. Every victim is masked to its first and last two letters plus a country code, and one tracker carries a duplicate of every listing with an "AUDIT ENTITY" prefix, which we fold together. The victim spread is unusual in two ways: Russian organisations make up the largest single country group, and South Korea and Japan together account for three. On September 13 the site added two entries labelled "Paid Victim" with a sixteen character hex identifier and no country, name or sector. We removed both from the count. For a defender the practical read is limited, because a redacted stub gives you nothing to match against your own estate, but the pattern of posting payment markers is worth noting as a pressure tactic aimed at the next victim rather than the last one.
MetaEncryptor. Four postings, all on September 7, and a clear step up in target size: ST Engineering, the Singapore defence and engineering group; Hologic, the US women's health and diagnostics manufacturer; EllisDon, one of Canada's largest construction firms; and SIFCO Industries, a US aerospace forging supplier. Two of the four, ST Engineering and SIFCO, sit in defence and aerospace supply chains. SOCRadar's tracking notes the ST Engineering listing as a move into government and defence for a group that has not focused there. No samples, no data volumes and no company statements accompanied any of the four. Treat the run as a signal of ambition before it is a signal of access.
Kazu. Seven postings on September 7, all carried by a single tracker, and the most useful thing about them is what they repeat. Statistics South Africa, the Gauteng Provincial Government and the Gauteng City Region Academy all appear. In March 2026 a crew called XP95 claimed both Stats SA and the Gauteng government, and Stats SA confirmed a breach and a ransom demand at the time. Kazu's listing adds no sample and no new volume. Two readings fit: Kazu bought or obtained the March data and is reselling it under its own brand, or Kazu is listing names it knows are already compromised because they are credible. Neither reading makes the September listing a new incident. Last month Kazu posted healthcare software platforms across Latin America. This month it posted recycled South African government names. That is a crew building a leak site catalogue, not working a target.
Panzer. Five postings, and the widest public sector reach of any small crew this week. Spain's State Meteorological Agency, AEMET, was listed on September 11 with a claimed 5 GB of data and a three week disclosure deadline, reported by Escudo Digital. Konica Minolta's Bulgarian subsidiary, the French asset manager Financiere d'Uzes, Portugal's Aqualogus and a Brazilian ceramics maker round out the set. Panzer emerged over the summer and last week listed Serbian and Portuguese government bodies. A crew that keeps landing on national agencies in southern Europe is a crew whose access source is worth identifying.

Sector Targeting Analysis

RankSectorVictimsShare of labelled
1Technology3120%
2Business Services2818%
3Manufacturing2516%
4Consumer Services1610%
5Healthcare138%
6Transportation and Logistics96%
7Financial Services96%
8Public Sector75%
9Construction and Real Estate53%
10Hospitality and Tourism43%
11Education32%
12Energy32%
13Telecommunications11%
Read the counts, not the percentages. 25 of the 179 postings carried no sector label, and they concentrate in the redacted Audit Team stubs and the bare domain batches, so the visible mix leans toward crews that publish tidy victim profiles.
Technology at 31 leads for the first time this quarter, and it is worth being precise about why. A large share of it is sector labelling of bare domains and small IT service firms: KryBit's intherpro.com and kashkha.com, SafePay's gsngestion.es, Vexy's three Indian and British network service providers, Unsafe's watchops.com. The consequential entries are fewer. Lightcast sells labour market data to employers, universities and governments. RelyComply sells anti money laundering software to regulated financial firms. M800 and CINNOX run cloud communications for businesses across Asia. Each of those is a supplier whose compromise reaches customers who never appear on a leak site.
Business services at 28 includes four law firms this week against eleven last week, and Silent Ransom Group, which drove the legal category, did not post at all. The category remains the one where a single listing exposes the most third party material per record.
Manufacturing at 25 is its lowest share this quarter, largely because the two bulk uploaders this week, KryBit and SafePay, happened to list few manufacturers. The underlying names are the familiar mid market industrial set: Storm's Melitron in Canada, Dark Project's Master Manufacturing and Specchem, MetaEncryptor's SIFCO, Everest's Korber.
Healthcare at 13 is small and well spread. Hologic, Medela, PharmaEssentia and General Santos Doctors Hospital sit beside five US clinics and a medical supply retailer. No single operator supplied more than two. The healthcare story this week is not in this table at all. It is Veradigm, posted last week and confirmed this week, covered below.
Public sector at 7 is up from 4, and most of that rise is thin. Three of the seven are Kazu's South African listings, which repeat claims from March. One is the Florida DMV deadline post, unconfirmed by the agency. The remaining three are AEMET, the Bosnia and Herzegovina Mine Action Center and the Town of Sutton in Massachusetts, whose public school district Global listed on the same day. The Mine Action Center deserves a line on its own: it holds survey data on where landmines remain in Bosnia and Herzegovina, which is not the kind of data set that has a ransom market but is exactly the kind that should never be public.
Financial services at 9 is small and regionally interesting. CO-OP Urban Bank, an Indian urban cooperative bank, was listed by Global Secret Group. Hollard Insurance Group, one of South Africa's largest private insurers, was filed by an upstream tracker as manufacturing and we have corrected it. Ibn Sina Trust in the UAE and DiamondLease also appear. For Indian readers the cooperative bank entry is the one to route: urban cooperative banks carry RBI cyber reporting obligations and thin security teams, which is why they keep appearing.

Country Distribution

RankCountryVictimsShare
1United States5732%
2India127%
3Canada95%
4Brazil84%
5South Africa63%
6United Kingdom63%
7Germany53%
8Argentina53%
9Colombia42%
10Spain42%
11Turkey42%
12Russia42%
13France42%
14Singapore32%
15Italy32%
A further 30 countries recorded between one and three victims each, including the Philippines, Portugal, the UAE, Sweden, Peru, Australia, Georgia, South Korea, Japan, Slovakia, Switzerland, Denmark, Egypt, Chile, Ukraine, the Netherlands, Serbia, Austria, Bosnia and Herzegovina, Taiwan, Hong Kong, Indonesia, Malaysia, Bulgaria, Morocco, Croatia, Haiti, Kenya, Mexico and China. 3 postings carried no country.
The US share fell from 40% on last week's rebuilt figures to 32%. As with most share movements in this report, the composition explains it. The Gentlemen's Monday run touched the US twice in nineteen listings, and KryBit's and SafePay's bulk uploads leaned away from the US. Underlying US volume went from 81 to 57, a real decline in count, spread across nearly every operator rather than any one of them going quiet.
India at 12 is second for the second week running and the spread is wide: nine different operators, The Gentlemen, Vexy, Emperador, Akira, Global Secret Group, KryBit, MedusaLocker, Audit Team and Doommageddon. CO-OP Urban Bank is the entry with a regulator attached. Indian entities work to the tightest clock in this report: CERT-In directions require reporting of a covered incident within six hours of noticing it, and that clock does not wait for confirmation.
Canada at 9 carries the week's biggest name. Air Canada, EllisDon and MSM Unify sit beside Storm's three Canadian listings. Canadian private sector organisations must report a breach of security safeguards to the Office of the Privacy Commissioner where it creates a real risk of significant harm, and notify affected individuals. A leak site listing is not itself that trigger, but it starts the assessment.
South Africa at 6 is inflated by Kazu's three recycled public sector listings. Hollard Insurance Group, Capricorn Logistics and a law firm posted by LockBit are the new ones. POPIA section 22 requires notification to the Information Regulator and to data subjects as soon as reasonably possible after a compromise is discovered, and for Hollard the Prudential Authority's cyber standards apply in addition.
Russia at 4 is entirely Audit Team, and that is the unusual entry in the table for the reason set out above.
Elsewhere, Spain's AEMET listing falls under the national security framework (ENS) and CCN-CERT reporting for public bodies, and NIS2's 24 hour early warning clock applies to essential entities across the EU. ST Engineering in Singapore sits under the Cybersecurity Act's reporting duties for critical information infrastructure owners where relevant systems are involved, and MAS notification applies to financial institutions within an hour of discovery of a relevant incident.

Notable Claims and Incidents

Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation has said so, and where they have, we say which part they confirmed.
Update on last week: Veradigm confirms patient data theft. Last week we listed The Gentlemen's claim against Veradigm, the electronic health record and practice management vendor formerly known as Allscripts, at low confidence. On September 8 Veradigm disclosed that a threat actor obtained credentials from a third party vendor's environment for a Veradigm API used for customer services, and used that access to take patient data including names, contact details and, for some patients, Social Security numbers. Veradigm says the actor had access only to the API, that no servers, databases or other systems were compromised, and that clinical information was not affected. The Gentlemen claims 3.5 million patient records and set a September 11 deadline. Reported by BleepingComputer, HIPAA Journal and Healthcare IT News. Confidence: High that patient data was taken, because the company has said so. The 3.5 million figure remains the actor's number. This is the entry to brief upward this week, and the lesson is in the route: a vendor held a credential into Veradigm's API, and the vendor's environment was the one that fell.
The Gentlemen lists Air Canada. Posted September 9. The group claims 51,409 files and some aggregator coverage describes operational disruption. We found no Air Canada statement about this listing. The statement in circulation describing an unauthorised group obtaining "limited access to an internal Air Canada system" with employee records relates to Air Canada's disclosure in September 2023, and it should not be read as a response to this claim. No sample reached our collection. Confidence: Low. A major national carrier posted on its own day by the week's most active crew is worth watching closely, and the disruption language in secondary coverage is not supported by anything we could verify.
ShinyHunters lists the State of Florida DMV. Posted September 7 as a final warning with a September 11 deadline. ShinyHunters claims roughly 200,000 driver records from DAVID, the Driver and Vehicle Information Database that law enforcement uses, taken by abusing a password reset weakness to access accounts belonging to DMV employees and, it says, an FBI agent. BleepingComputer, CSO Online and Cybernews report the claim, and the agency has not confirmed a breach. The same week ShinyHunters listed Medela and Kimberly-Clark. Confidence: Low on the scale, because no sample has been verified publicly. The described route, a password reset flow accepting a request it should not have, is consistent with the crew's identity first tradecraft.
Cl0p posts harley-davidson.com. Posted September 10 alongside henrypratt.com, both as bare domains with no sample. Harley-Davidson has not confirmed an incident. Cybersecurity News reports researchers tying the timing to Cl0p's ongoing exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, the product lifecycle management platform manufacturers use to hold engineering data, a campaign that has already named more than 40 organisations including Shell, Philips and Fiserv according to SecurityWeek. Confidence: Low on the specific claim. Medium that if the claim is real, the route is Windchill, because Cl0p's victim selection in this campaign has been consistent.
MetaEncryptor names ST Engineering and Hologic in one run. Posted September 7 with EllisDon and SIFCO Industries. A Singapore defence and engineering group, a US medtech manufacturer, a Canadian construction major and a US aerospace forging supplier. No samples, no data volumes, no statements from any of the four. Confidence: Low. The target set is a notable step up for this crew, and two of the four sit in defence or aerospace supply chains, which puts the listing on the desk of contract security teams whether or not it proves out.
Kazu lists Statistics South Africa and the Gauteng government. Posted September 7, one tracker, no sample. Both bodies were claimed by XP95 in March 2026, and Stats SA confirmed a breach and a ransom demand at the time, reported by The Witness and MyBroadband. Confidence: Low that this reflects a new intrusion. Medium that it is a relisting of March data. If you are a supplier or contractor to either body, the useful question is not whether Kazu is telling the truth. It is whether your data was in the March set.
Low signal claims this week. 37 of the 179 postings are a bare domain with no company name, no volume and no proof, led by KryBit on 13, SafePay on 10 and LockBit on 5. Another 12 are redacted to a few letters, 11 of them from Audit Team. That leaves 130 postings, 73% of the week, that name an organisation at all. DireWolf's listing of RelyComply, the UK anti money laundering software firm, is the kind of name only claim we would route to a financial services supplier team without escalating: CyPro's bulletin notes there is no evidence of intrusion, data theft or encryption behind it.

Top CVEs These Groups Are Exploiting

Two supplier platforms joined the edge appliances this week. The table covers this week's active groups where a named source supports the attribution, plus one critical flaw with no attribution yet that belongs on this list anyway.
CVEProductCVSSWho is using itWhy it matters
CVE-2026-12569PTC Windchill PDMLink and FlexPLM, deserialisation leading to unauthenticated RCEn/aCl0pBleepingComputer, ReliaQuest and SecurityWeek document Cl0p exploiting it as a zero day from early June 2026, dropping JSP webshells and a custom implant to map and exfiltrate engineering files. PTC patched on June 17. Scored 9.3 under CVSS 4.0 and 9.8 in other reporting, so we leave the cell blank. More than 40 victims named so far
CVE-2026-86218N-able N-central, static code injection, pre-authentication RCE10.0Not yet attributedAdded to the CISA KEV catalogue on September 8 after exploitation before disclosure. Arctic Wolf and Huntress report it can be chained with CVE-2026-86206 and CVE-2026-86207 to create attacker controlled admin accounts. N-central is a remote monitoring and management platform, so one compromised server reaches every endpoint it manages. Fixed in 2026.3.1.14
CVE-2024-55591Fortinet FortiOS and FortiProxy, authentication bypassn/aThe GentlemenUnit 42 names FortiGate exploitation through this flaw as the group's predominant initial access route, with the operators holding an inventory of already compromised FortiGate devices and validated VPN credentials so affiliates skip reconnaissance
CVE-2025-7771ThrottleStop.sys driver, renamed ThrottleBlood.sys by the operatorsn/aThe GentlemenHuntress and Unit 42 document this as the group's bring your own vulnerable driver route to kernel level code execution, used to terminate EDR before deployment. Detection belongs on driver load
CVE-2026-50751Check Point Mobile Access, Remote Access VPN and Spark firewalls9.3Qilin affiliatesAn unauthenticated attacker bypasses authentication and establishes a VPN session. Exploited as a zero day for roughly a month before a patch existed
CVE-2026-0257Palo Alto Networks PAN-OS GlobalProtectn/aQilinReported by SecurityAffairs as an active Qilin route into corporate networks and on the CISA KEV catalogue since June 2026
CVE-2024-40766SonicWall SonicOS SSLVPN, improper access control9.3AkiraSonicWall's own advisory, Arctic Wolf and Darktrace tie sustained Akira activity to this flaw. SonicWall's guidance is that patching alone is insufficient and local SSLVPN passwords must be reset
Attribution accuracy note. Six of this week's top ten groups have no verifiable initial access CVE behind them.
KryBit and SafePay are the two bulk uploaders. SafePay's documented tradecraft, from Bitdefender and Sygnia, is valid credentials, legitimate remote tools and OneDrive based exfiltration, with no named access flaw. KryBit has a documented affiliate panel and builders but no named access CVE. Audit Team, Kazu and Emperador publish claims without any public reporting on how they obtain access. DireWolf is documented as a double extortion operation with no named initial access flaw. ShinyHunters, which produced the Florida DMV claim, describes a password reset weakness rather than a CVE, and Veradigm, the one confirmed data theft in this report, was reached through a vendor's API credentials.
Three practical notes follow. Supplier platforms now sit alongside edge appliances as the front door: a product lifecycle management server and a remote monitoring server each carry a blast radius far larger than the organisation that runs them. Credentials held by vendors, not just by your own staff, produced this week's one confirmed breach. And N-central's CVSS 10 flaw has no attributed crew yet, which is precisely the window in which patching is cheapest.

Infrastructure and Operational Shifts

Leak sites are becoming resale catalogues. Kazu relisted two South African government bodies claimed six months ago by a different crew. Audit Team added "Paid Victim" markers that name no one. DireWolf, per CyPro, posts names with nothing behind them. None of those listings describes a new intrusion, and all of them count in a raw leak site total. The operational consequence is that a listing date is not an incident date, and a defender who reads a relisting as a fresh compromise will spend the first day of the response looking in the wrong six months of logs.
Supplier platforms are the new edge appliance. Cl0p is working PTC Windchill, where manufacturers keep their engineering data. N-central's pre-authentication flaw opens the platform managed service providers use to run their customers' endpoints. Veradigm was reached through a vendor's credentials into its API. In each case the organisation that gets posted is not the organisation whose weakness was used, and in two of the three the eventual victims will be customers who never ran the vulnerable product themselves.
The Monday run is a schedule. The Gentlemen published 19 on Monday September 7 and opens Monday September 14 with roughly 30 more. KryBit and SafePay each uploaded in a single day. The weekly posting curve in this field is increasingly a record of when three or four operators hit publish. If your leak site monitoring runs a daily digest, Monday's digest is now the one that matters, and a quiet midweek should not be read as a quiet field.
Bare domains fell, but not because anyone changed. 37 bare domains this week, 21% of the total, against 61 and 30% last week. Settra, which produced 17 of last week's, did not post. KryBit and SafePay produced 23 of this week's. The proportion tracks which bulk uploaders were active, not a change in how the field lists victims.
Extortion without encryption held steady. At least 17 postings came from crews whose listings this week carried no encryption claim and whose documented operations do not rely on one: Audit Team, ShinyHunters, Cl0p's Windchill campaign and FulcrumSec. The count is lower than last week's because Silent Ransom Group did not post, and it still produced two of this week's five named claims.

First Look at September 14

Our window closes on Sunday September 13, so here is what the next one opened with, stated as a raw count from a pull taken on September 16. September 14 carried 60 raw rows before deduplication, and The Gentlemen accounted for more than half of them in another single day run, including Vittoria Assicurazioni agencies and ACA Pescara in Italy, BGR Energy Systems in India, Hattiesburg Eye Clinic in the US, Dome Gold Mines in South Africa and High Oakham Primary School in the UK. Qilin posted six. MetaEncryptor followed on September 15 with Nippon Steel and SFA Engineering. Storm listed Insight Credit Union, Interlock listed the City of Fort Smith in Arkansas, and IAH647 posted veritiv.com. These are raw rows and will fall once cross tracker duplicates are merged. They will be counted in issue 37.

Key Takeaways for Defenders

Patch N-central now, then hunt, because the flaw has no attributed crew yet. CVE-2026-86218 is a CVSS 10 pre-authentication RCE on a remote monitoring and management platform, exploited before disclosure and added to CISA KEV on September 8. Upgrade on premises servers to 2026.3.1.14, review administrator accounts for anything created since early September, and check whether any managed service provider you use runs N-central against your endpoints. If they do, ask them when they patched, in writing.
Patch PTC Windchill and FlexPLM, and treat an unpatched instance as already breached. Cl0p exploited CVE-2026-12569 as a zero day before the June 17 fix and has named more than 40 organisations. Hunt for JSP files in Windchill web directories that your deployment did not ship, review outbound transfers from the PLM server, and assume engineering drawings, supplier pricing and product roadmaps are the data at stake.
Inventory every vendor credential that reaches your APIs. Veradigm, this week's one confirmed breach, fell through credentials held in a vendor's environment. List the third parties holding API keys, OAuth tokens or service accounts into your customer and patient data, scope each one to the operations it genuinely needs, rotate on a schedule, and alert on volume rather than authentication. The vendor's security posture is now part of yours.
Treat password reset as an authentication event, not a support convenience. The Florida DMV claim describes a reset flow that accepted requests it should not have. Require the same assurance to reset a credential as to use it, notify the account holder on every reset through a channel the requester does not control, and rate limit and log reset attempts against privileged and law enforcement accounts in particular.
Check whether an old breach is the real exposure before chasing a new one. When a crew lists an organisation that was breached months earlier, as Kazu did with Stats SA and Gauteng, the useful response is to confirm whether your own data sat in the original set and whether anything from it has resurfaced. Keep a register of the historic breaches that touched your suppliers, so a relisting becomes a lookup rather than an investigation.
Staff the Monday digest. Three operators produced 41 of this week's postings, 23%, in three single day uploads, and the biggest of them publishes on Mondays. Make sure Monday leak site monitoring covers your domains, your subsidiaries' domains and your critical suppliers' domains, with someone assigned to triage it that morning.
Most of that work is triage before it is defence. Somebody has to read 179 postings, work out which three touch your organisation or your suppliers, and cross reference each named group against the flaws actually exposed on your perimeter.

Where Scrutex Fits

Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface and your named suppliers, so a listing that names your domain or a vendor's domain reaches you as an alert rather than as a line in a weekly roundup. Vulnerability Insights prioritises flaws like the two supplier platform CVEs above by real world exploitability against your exposed assets rather than by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.

Frequently Asked Questions

How many ransomware attacks were there in the week of September 7 to 13, 2026? We tracked 179 unique victim postings across 44 active groups and 45 countries. That is down 12% from 203 for August 31 to September 6, rebuilt on the same feeds and rules. These are leak site postings rather than confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Did The Gentlemen really hack Air Canada? The Gentlemen listed Air Canada on September 9 and claims 51,409 files. We found no Air Canada statement about this listing, and the statement about limited employee records that is being shared online relates to a separate incident Air Canada disclosed in 2023. No sample has been verified. We rate the claim low confidence.
Which ransomware group was most active in September 2026? The Gentlemen, with 21 postings, 19 of them published in a single run on Monday September 7 across 16 countries. It opened the following week with roughly 30 more on September 14, which suggests a regular Monday publication schedule rather than a surge.
Is the Veradigm breach confirmed? Yes, in part. Veradigm disclosed on September 8 that an attacker used credentials from a third party vendor's environment to access a customer service API and take patient data, including Social Security numbers for some patients. It says clinical information and other systems were not affected. The Gentlemen's figure of 3.5 million records has not been confirmed by the company.
Which CVEs are ransomware groups exploiting right now? Cl0p is exploiting CVE-2026-12569 in PTC Windchill and FlexPLM. CVE-2026-86218, a CVSS 10 flaw in N-able N-central, was added to CISA KEV on September 8 with no group attributed yet. The Gentlemen uses CVE-2024-55591 on FortiOS and CVE-2025-7771 for driver abuse, Qilin uses CVE-2026-50751 and CVE-2026-0257, and Akira uses CVE-2024-40766 on SonicWall. Six of the week's top ten groups have no verifiable CVE behind them.
Are the Statistics South Africa and Gauteng listings new breaches? Probably not. Kazu listed both on September 7 with no sample, but a different crew, XP95, claimed both bodies in March 2026, when Stats SA confirmed a breach. The September listing is most likely a relisting or resale of the March data, and we treat it that way until new evidence appears.
Which sectors were hit hardest this week? Technology at 31 postings, business services at 28 and manufacturing at 25. Read those as counts rather than shares, because 25 of the 179 postings carried no sector label, and a large part of the technology count is bare domains and small IT service firms.
Where can I get this in real time instead of weekly? Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, so a relevant listing reaches you when it is posted rather than in the following Monday's roundup.