ransomware weekly
23 views

Ransomware Attacks This Week: 205 Victims Across 52 Groups (August 31 to September 6, 2026)

By ScruteXPublished

Summary

This is the Scrutex ransomware weekly for the August 31 to September 6, 2026 window. Our CTI team tracked 205 unique ransomware and extortion victim postings across 50 active groups and 44 countries. Measured against the same window last week rebuilt on the same feeds and the same counting rules, that is down 24% from 271. It is the lowest weekly total we have recorded this quarter, and the decline is real rather than a counting artefact.
Read the composition before you read the drop. 61 of the 205 postings, 30% of the week, are a bare domain with no company name, no sector, no data volume and no sample. Four groups produced 48 of those 61, and those four groups hold ranks one, two, eight and ten in the table below. The top of the leak site chart this week is not a ranking of the most capable crews. It is a ranking of who bulk uploaded a list.
The standout story is a sector, not a group. Silent Ransom Group named Holland & Knight, Greenberg Traurig and Katten Muchin Rosenman on three consecutive days, three AmLaw 100 firms taken by phone calls rather than exploits. Widen the lens and 11 of the week's 27 business services postings are law firms, claimed by nine different operators. Legal is being worked as a category this week, by crews that have nothing else in common.
Two claims moved past the leak site and into the public record. Manchester Airports Group disclosed a breach that FulcrumSec says came from an Iterable API key left in public JavaScript, and the group published the data on September 3. Nutex Health told the SEC in an 8-K that patient, employee and financial data were taken, and The Gentlemen listed it with a nine day countdown. Those are the two entries in this report where the organisation, not the actor, is the source.
205 posts, 50 groups, 44 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.

This Week at a Glance

MetricValue
Total unique victims posted205
Change on prior weekDown 24% like for like (205 against 271 on identical feeds and rules)
Active groups50
Countries hit44
Heaviest single dayMonday August 31 (57 posts, 28% of the week)
Second heaviest dayTuesday September 1 (39 posts)
Quietest daySunday September 6 (7 posts)
Most targeted countryUnited States (79 victims, 39% of postings)
Most targeted sectorManufacturing (28 named), Business Services (27), Technology (25)
Top group by volumeSettra (17 posts, 16 of them bare domains)
Largest single day runKryBit (14 on September 1)
Bare domain postings61 of 205 (30%)
Notable claimsManchester Airports Group, Nutex Health, Holland & Knight, Greenberg Traurig, Katten Muchin Rosenman, Veradigm, DiaSorin
The week front loaded and then emptied out. Monday opened at 57, Tuesday fell to 39, Wednesday to 28, Thursday recovered to 31, Friday held at 27, Saturday dropped to 16 and Sunday closed at 7. The last three days together came to 50, fewer than Monday alone.
Monday is the part worth explaining, and the explanation is not that Monday was a heavy day of criminal activity. Four groups published batches into it: Brain Cipher posted 8, Settra 8, INC Ransom 6 and LockBit 6, which is 28 of the 57. All of Brain Cipher's eight, all of LockBit's six and seven of Settra's eight were bare domains. Take those four batches out and Monday is a 29 post day, which would have placed it third behind Tuesday and Thursday rather than eighteen postings clear of the field. The peak is the upload schedule, not the intrusion rate.
The top five groups took 36% of volume against 41% last week, so concentration fell alongside the total. That matters more than it looks. When a week gets smaller and also gets less concentrated, no single operator is driving the decline. Qilin, which has led our chart every week this quarter, dropped from 42 postings to 15 and still finished third. Nobody replaced it. The field simply posted less.
The tail stayed long and got longer in relative terms. 50 groups posted, 32 of them three victims or fewer, and 20 posted exactly once. Those 32 groups produced 49 postings, 24% of the week spread across nearly two thirds of the active brands. A watchlist built from last week's top ten groups covered 88 of this week's 205 postings, 43%.

Group Activity Breakdown

The top five groups produced 73 of 205 postings, 36% of the week. Below them, 32 groups posted three or fewer victims each, together accounting for 49 postings.
RankGroupVictimsShareNotable Activity
1Settra178%Two batches, 8 on Aug 31 and 9 on Sep 3. 16 of 17 are bare domains. Only named victim: DiaSorin S.p.A. Also zayo.com, medevolve.com, hatch.group
2KryBit168%14 of 16 in one run on Sep 1. Every listing a bare domain. India, Mexico, Thailand, China, Bhutan, Guatemala, Saudi Arabia
3Qilin157%Spread across six days, no run larger than seven. Philippine Ports Authority, Commission de la construction du Quebec, Uak University, Colonial Hyundai
4INC Ransom147%6 on Aug 31 and 7 on Sep 2. Policlinico Triestino, Westfield Public School District, New Century Ophthalmology, six bare domains
5Akira115%Spread over five days. US and German mid market manufacturers, a credit union, a car wash chain, an Austrian controls firm
6The Gentlemen105%Nutex Health and Veradigm in one week. Also CareerSource Palm Beach, Leo Schachter Diamonds, Seasia Infotech, Zdrowit
7Silent Ransom Group105%Three named AmLaw 100 firms plus seven listings redacted to initials. No encryption, no samples
8LockBit94%All nine bare domains, 6 on Aug 31 and 3 on Sep 4. Dutch, German, US and South Korean targets
9DireWolf94%Spread over five days, all named organisations. Wolfram Research, Cartrack Holdings, PTT Oil and Retail, three US healthcare providers
10Brain Cipher84%All eight on Aug 31, seven of them bare domains. Netherlands, Spain, USA, UAE, Germany
11Storm73%All seven on Sep 3, five of them financial services. Chicago Partners Wealth Advisors, GSAC Auto Financing, Macquarrie
12Vexy63%Posted under two brand strings on separate trackers. Brazil, Ecuador, India, Mexico. McDonald's Ecuador
13Aurora, Play, WallStreet, Everest, Panzer, Space Bears4 each2%Aurora on US professional services, Storm-adjacent. Space Bears on Italian and US healthcare and legal
A long tail of groups (Insomnia, NightSpire, ZaWoo, DragonForce, DYSPHOR1A, Global Secret Group, Orova, MedusaLocker, Eclipse, Pear, Audit Team, Gunra, Coinbase Cartel, Crypto24, Falcon, Interlock, Black X, Bravox, DeadLock, FulcrumSec, MajinaHanashi, RansomHouse, Rhysida, Anubis, Kairos, PayoutsKing, ShinyHunters, TridentLocker, BlackLocks, Emperador, Kazu, Chaos and LeakNet) each posted between one and three victims.
Three observations:
The top two groups this week are two domain lists. Settra posted 17 and KryBit posted 16, and 32 of those 33 listings are a bare domain with nothing else attached. No company name, no country in KryBit's case for two of them, no data volume, no sample, no countdown. Settra is a real operation with documented tradecraft, and MOXFIVE has published its attack chain in detail, but 16 of its 17 postings this week tell a defender nothing except that a domain is on a list. This is the single most important thing to understand about the week's ranking: rank one and rank two are not the two most dangerous crews in the field, they are the two crews that uploaded the most rows.
Qilin fell by two thirds and nothing took its place. 42 postings last week, 15 this week, and it still finished third. Qilin has led our chart every week this quarter, usually by showing up every day with small runs, and that pattern held here in miniature: six days, no run larger than seven, the same profile of mid market manufacturers, professional services firms and public sector bodies across Europe, Latin America and Asia. A single week is not a trend and we would not read a takedown or a retirement into it. What it does show is that the week's decline is broad. When the leader drops 27 postings and the total drops 66, the other 39 came from everywhere else.
Silent Ransom Group's 10 is really 3. Three of its ten listings name an organisation: Holland & Knight, Greenberg Traurig and Katten Muchin Rosenman. The other seven are redacted to initials and a trailing letter, in the style of "P... S..." and "H... C...", each carrying its own anchor on the group's leak site. We count them because they are distinct listings on the operator's own infrastructure, but only three of the ten are attributable to a named organisation. One of the seven, "G... ...g", sits alongside the separately listed Greenberg Traurig on the same day and may well be the same firm posted twice, which would make the true figure nine. We have left it at ten rather than guess, and we would treat any Silent Ransom Group count in this field, ours included, as an upper bound.

New and Emerging Groups

Four names in this section, and only two of them run an encryptor.
Settra. First identified in June 2026, at 64 cumulative victims by the start of September, and top of our chart this week on 17. MOXFIVE's analysis is the useful document: initial access through compromised VPN credentials rather than an exploit, then NetExec and Netscan for discovery, Procdump and Mimikatz for credentials, PAExec for lateral movement and Mesh Agent for command and control. Defence evasion runs through a tool the operators call edr_blind, manual clearing of Windows event logs, and a known vulnerable driver, STProcessMonitor_v114.sys, loaded for kernel level execution. Nothing in that chain requires a CVE, and everything in it is detectable: a Mesh Agent install nobody requested, a driver load nobody scheduled, an event log that empties. The group also writes long form narrative posts about each victim rather than a metadata stub, which makes the 16 bare domains it published this week the exception in its own history and worth watching. Either it is loading a backlog, or it is testing which domains answer.
KryBit. A ransomware as a service operation first seen in the wild in late March 2026, with Windows, Linux, ESXi and NAS builders. Its affiliate panel was breached in April by a rival operator, 0APT, which published the contents and exposed five or six distinct onion domains tied to different affiliates. That is documented by SOCRadar and Halcyon. What is not documented anywhere is an initial access CVE. This week KryBit posted 16 bare domains, 14 of them in a single run on September 1, spread across India, Mexico, Thailand, China, Bhutan, Guatemala, Saudi Arabia, Switzerland, Canada, Germany and the USA. Eleven countries in one upload is not eleven fresh intrusions in one day. It is a list. Every domain on it is real and deserves triage, and the geographic spread is the tell that it was bought rather than worked.
DireWolf. Nine postings, all named organisations, all with a country and most with a sector, which makes it the cleanest data set in this week's top ten. First seen around May 2025, written in Go, delivered UPX packed, encrypting with Curve25519 and ChaCha20 to a .direwolf extension, deleting backups and disabling logging on the way. Its selection this week is the interesting part: Wolfram Research, Cartrack Holdings in South Africa, PTT Oil and Retail Business in Thailand, PT Intraco Penta in Indonesia, and three US healthcare providers in the last three days of the window. That is a crew working named targets across four continents rather than uploading a regional list, and it is the opposite of the pattern above it in the table.
FulcrumSec. One posting, and the best evidenced claim in the report. FulcrumSec listed Manchester Airports Group on September 1 and published on September 3. The route it describes is not a ransomware chain at all: an Iterable API key left visible in the airport group's public JavaScript, used to pull customer records with no server intrusion. Roughly 86 GB compressed, expanding to around 640 GB, covering close to 8.7 million customer profiles with email, name, mobile number, home town, postcode and residential IP, plus vehicle registrations, parking history, Fast Track purchases and lounge bookings. One posting from a crew with almost no history, and it produced more exposed individuals than the other 204 postings in this report combined. The lesson is not about ransomware. It is that a marketing platform key in client side code is an unauthenticated bulk export endpoint.

Sector Targeting Analysis

RankSectorVictimsShare of named
1Manufacturing2817%
2Business Services2716%
3Technology2515%
4Healthcare2314%
5Transportation and Logistics1610%
6Consumer Services138%
7Financial Services95%
8Education74%
9Hospitality and Tourism53%
10Public Sector53%
11Energy42%
12Agriculture and Food42%
Read those as counts, not shares of the week. 39 of the 205 postings carried no sector label at all, and the missing labels are not randomly distributed: they come overwhelmingly from the bare domain batches, where the tracker has a hostname and nothing else. The visible sector mix is therefore biased toward the groups that write proper victim profiles, which this week means Qilin, DireWolf, The Gentlemen, Akira and Storm rather than Settra, KryBit or LockBit.
Manufacturing leads on volume for the sixth week running, and the profile has not changed: mid market industrial firms in the US, Germany, Austria, Italy, Spain, India and Latin America, the kind of business that runs flat networks, long lived engineering workstations and an edge appliance nobody owns. It is targeted because recovery time is measured in shipped orders.
Business services is the sector to actually read this week. 27 postings, and 11 of them are law firms: Holland & Knight, Greenberg Traurig and Katten Muchin Rosenman from Silent Ransom Group, plus Bauman Law Group from Qilin, Norwood Law Firm from DragonForce, Schwartz Giannini Lantsberger & Adamson from Space Bears, Maglin Miskiv & Associates from Insomnia, Ishbia & Gagleard from Aurora, and three more posted as bare domains by LockBit, Settra and KryBit. Nine different operators, one target category, one week. No single crew is running a legal campaign. The category is being worked by the whole field at once, which is what happens when a sector becomes known as one that holds concentrated client data, carries privilege obligations that make disclosure expensive, and rarely runs a mature security programme outside the largest firms.
Healthcare at 23 carries the consequence rather than the volume, as it usually does. Four of the 23 are technology and services businesses sitting upstream of care delivery rather than providers themselves: Veradigm on EHR and revenue cycle, MedEvolve on practice management, eAssist Dental Solutions on billing, and DiaSorin in diagnostics. A provider compromise affects one organisation's patients. A compromise at any of those four is a question for every practice that runs them.
Financial services at 9 is low by our recent averages, and five of the nine came from a single Storm run on September 3. That is a batch, not a trend.

Country Distribution

RankCountryVictimsShare
1United States7939%
2Germany115%
3India115%
4United Kingdom84%
5Canada84%
6Netherlands63%
7Spain42%
8South Korea42%
9Brazil42%
10Mexico42%
11Italy42%
12Malaysia31%
13Taiwan31%
14Saudi Arabia31%
15France31%
A further 29 countries recorded between one and three victims each, including Myanmar, Singapore, Argentina, Indonesia, Thailand, Switzerland, Colombia, Poland, Australia, the UAE, Hong Kong, Ireland, New Zealand, Peru, Bhutan, China, Japan, Hungary, South Africa, Panama, Chile, Guatemala, Jamaica, Ecuador, Austria, Russia, Uruguay, Venezuela and the Philippines. 12 postings carried no country at all.
The US share rose to 39% from 29% last week, and that is a composition effect rather than a surge. US victim numbers barely moved, 78 last week against 79 this week. Everything else fell around them. Germany dropped from 20 to 11 and the UK from 14 to 8, which is most of the arithmetic.
India at 11 is the mover, up from 5, and it is worth knowing what it is made of before you read it as Indian risk rising. Six of the 11 arrived inside the KryBit and Vexy batch uploads as bare domains or short labels: southsign.in, vedantaainstitute.in, seashellhospital.com, plus Annapurna Fashion, Palsana Enviro and Sancity Soft Touch. Two more, Licindia and Complete Packaging Solutions, came from MedusaLocker and Qilin with proper profiles, and R L Fine Chem from Global Secret Group. So roughly half of India's rise is one operator's list. For an Indian entity the reporting obligation does not care which half it is: CERT-In's six hour incident reporting window starts from the point you become aware, and a leak site listing naming your domain is awareness.
Elsewhere the regional picture is thin but specific. DYSPHOR1A posted three Myanmar targets including a telecom, a payments platform and a government body, in a country with no mandatory breach notification regime, which means a leak site listing may be the only public signal that will ever exist. The Philippine Ports Authority listing from Qilin is a national logistics operator. For readers under NIS2 in the EU, the German and Dutch counts here are almost entirely small and mid market firms rather than the essential and important entities the directive covers, which is a reminder that leak site volume and regulatory exposure are different maps.

Notable Claims and Incidents

Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation has said so, and where they have, we say which part they confirmed.
FulcrumSec publishes 86 GB it says came from Manchester Airports Group. Posted September 1, published September 3. FulcrumSec says it found an Iterable API key exposed in publicly visible JavaScript and used it to export customer records, with no server intrusion required. The published set covers close to 8.7 million customer profiles across Manchester, Stansted and East Midlands airports, including email address, name, mobile number, home town, postcode and residential IP address, alongside vehicle registrations, parking history, Fast Track purchases and lounge bookings. MAG has disclosed the breach and states that passenger safety and aviation security were not compromised. The records have since been indexed by Have I Been Pwned. Confidence: High. The organisation has disclosed, the data is published and independently verifiable, and the described access route is consistent with the data set's shape.
The Gentlemen lists Nutex Health after the company files an 8-K. Posted August 31. Nutex Health notified the SEC on August 31 that patient, employee, financial and business information had been exfiltrated by a third party. The Gentlemen added the Houston based hospital operator to its leak site with a threat to publish within nine days. Confidence: High on the data theft, which the company has confirmed to its regulator. Medium on the attribution to The Gentlemen specifically, which rests on the group's listing rather than on anything Nutex has said about who took the data.
Silent Ransom Group names three AmLaw 100 firms in three days. Posted September 1 to 3. Holland & Knight, Greenberg Traurig and Katten Muchin Rosenman, listed one per day, alongside seven further listings redacted to initials. No samples reached our collection for any of the ten. Silent Ransom Group, also tracked as Luna Moth, Chatty Spider and UNC3753, does not exploit vulnerabilities: the FBI's advisory describes actors posing as IT support by phone and email to reach victim computers and exfiltrate through legitimate remote access tools, and Halcyon has documented the group escalating to sending a person to the victim's premises for physical access. There is no encryptor in this chain and no outage to detect. Confidence: Medium. The listings are consistent with the operator's established targeting and tradecraft, none of the three firms has publicly confirmed, and no sample supports any of them.
The Gentlemen lists Veradigm. Posted September 4. The second US health IT claim from the same crew in five days. Veradigm, formerly Allscripts, supplies electronic health record and revenue cycle systems to US practices. No sample, no data volume, no public statement from the company. Confidence: Low on the claim itself. The exposure question is not whether Veradigm negotiates. It is whether any practice data sits inside whatever was taken, and that question belongs with every provider running Veradigm software now, regardless of how the claim resolves.
Settra lists DiaSorin S.p.A. Posted September 3, as int.diasorin.com. The Italian diagnostics multinational is the only named organisation in a Settra set of 17 that was otherwise entirely bare domains. No sample, no data volume, no ransom figure, and no public statement from the company confirming encryption, exfiltration or disruption. Italian coverage notes the stock moved on the claim alongside an unrelated index change. Confidence: Low. A recognisable listed company name with no supporting material is the cheapest claim in this field to make.
Low signal claims this week. Beyond the five above, 27 postings rest on a single tracker with no corroboration, 12 carry no country and 39 no sector. 61 of the 205 listings are a bare domain with no company name, no volume and no proof, led by Settra and KryBit on 16 each, LockBit on 9, Brain Cipher on 7 and INC Ransom on 6. Three further postings were leak site furniture rather than organisations and we removed them before counting: a note ShinyHunters addressed to a rival data broker, a teaser banner reading "WHO IS NEXT?", and a boilerplate intrusion notice from Meowciety403. Domain only postings remain the lowest signal category in this report. They still need triage, because the domain is real, but they inflate counts and they tell you nothing about scope.

A Note on Data Quality

Three things changed in the pipeline this week, and one thing we told you last week turned out to be wrong.
The missing feed came back. Last week we reported that breach.house carried 158 rows into the August 17 to 23 collection and zero into August 24 to 30. It has since returned to the pool and backfilled. Rebuilding the August 24 to 30 window today, on the current feeds and this week's counting rules, gives 271 unique victims rather than the 247 we published. The 247 was not wrong when we published it, it was simply everything we could see. This is why every comparison in this report runs against 271. If you are keeping the series, the honest week over week is 271 to 205, down 24%. Comparing this week's 205 against last week's published 247 would show a 17% fall and would be measuring our feed coverage, not the field.
A conclusion we drew last week did not survive. We wrote that Italy's fall from 23 victims to 5 was a collection change and not a change in Italian risk, on the reasoning that breach.house carried most of the Italian volume. breach.house is now back and backfilled, and the rebuilt August 24 to 30 window still shows Italy at 5. This week it is 4. The feed was not the explanation. Italian volume genuinely fell and has stayed down for three weeks, and we would now read it as a real change in that market rather than an artefact. We would rather correct this in public than let the earlier read stand.
Two normalisation bugs cost us four rows. Our name matching reduced victim names to their ASCII characters before comparing them, which meant a name written in a non-Latin script reduced to nothing and could never match its own duplicate. BlackLocks posted one Korean manufacturer on four feeds and it survived as two separate rows, one of them carrying the sector and one not. Separately, our mojibake repair only fired on a fixed set of lead characters, so it missed both that Korean name and a US grocery chain posted with a mangled apostrophe. Both are fixed, and the fix is why this report says 205 rather than 209. We mention it because these are exactly the errors that inflate a leak site count quietly, and every tracker in this space has some version of them.
The wider point is the 30%. 61 of this week's 205 postings are a domain and nothing else. That proportion has grown every week this quarter. A count built mostly from bare domains is a count of rows in somebody's spreadsheet, and the crews producing those rows benefit from the row count being large. Any leak site figure quoted without a stated counting method, and without the domain only proportion alongside it, is close to meaningless. Ours this week is 205, of which 144 name an organisation.

Top CVEs These Groups Are Exploiting

Edge devices remain the front door for the crews that encrypt. The table covers this week's active groups where a named source supports the attribution.
CVEProductCVSSWho is using itWhy it matters
CVE-2026-50751Check Point Mobile Access, Remote Access VPN and Spark firewalls9.3Qilin affiliatesAn unauthenticated attacker bypasses authentication and establishes a VPN session. Exploited as a zero day for roughly a month before a patch existed, and CISA added it to the Known Exploited Vulnerabilities catalogue on June 9 2026 with a two day federal remediation deadline
CVE-2026-0257Palo Alto Networks PAN-OS GlobalProtect portals and gatewaysn/aQilinReported by SecurityAffairs as an active Qilin route into corporate networks, an authentication bypass against GlobalProtect. Qilin affiliates have moved decisively toward VPN appliances as the preferred initial access vector
CVE-2024-55591Fortinet FortiOS and FortiProxy, authentication bypassn/aThe GentlemenUnit 42 names FortiGate exploitation through this flaw as the group's predominant initial access route, and describes the operators maintaining a curated inventory of roughly 14,700 already compromised FortiGate devices and 969 validated brute forced VPN credentials, so affiliates skip reconnaissance entirely
CVE-2025-7771ThrottleStop.sys driver, renamed ThrottleBlood.sys by the operatorsn/aThe GentlemenHuntress and Unit 42 document this as the group's bring your own vulnerable driver route to kernel level code execution, paired with custom tooling (All.exe, Allpatch2.exe) that terminates EDR and antivirus at the kernel. Detection belongs on driver load, not on the ransomware binary
CVE-2024-40766SonicWall SonicOS SSLVPN, improper access control9.3AkiraSonicWall's own advisory, Arctic Wolf and Darktrace tie sustained Akira activity to this flaw, patched in August 2024 and still being exploited. SonicWall's guidance is explicit that patching alone is insufficient and local SSLVPN account passwords must be reset
CVE-2023-3519, CVE-2025-5777Citrix NetScaler ADC and Gatewayn/aINC RansomINC incident analysis names public facing application exploitation, including the original NetScaler RCE and Citrix Bleed 2, alongside spear phishing and credentials bought from access brokers
CVE-2024-57727SimpleHelp RMMn/aINC RansomNamed in INC Ransom incident reporting as an initial access route. Remote monitoring and management software is a recurring entry point for this crew and rarely sits inside the patching programme
CVE-2023-28252Windows Common Log File System Driver, privilege escalationn/aBrain CipherNamed in Brain Cipher profiles as the group's escalation route after access through phishing or an access broker. Its payload is LockBit 3.0 derived, which is worth knowing when you read detection guidance
CVSS is marked n/a where we could not confirm a score against a primary source. We would rather leave the cell empty than publish a number from memory.
Attribution accuracy note. Five of this week's top ten groups have no verifiable initial access CVE behind them, and that is the more useful finding than the table above.
Settra does not need one: MOXFIVE documents compromised VPN credentials as the entry point, then legitimate administrative tooling throughout, with the only vulnerability in the chain being a driver it brings itself. KryBit has a well documented affiliate panel, thanks to a rival crew breaching it in April and publishing the contents, and no source names an access CVE. Silent Ransom Group exploits nothing at all: the FBI's advisory describes phone and email impersonation of IT support, then legitimate remote access software, then exfiltration with no encryption, and Halcyon has documented the group physically sending someone to a victim's office. LockBit 5.0 is a relaunched brand whose 2026 reporting covers its loader, its ChaCha20 and Curve25519 encryption and its cross platform builders, but not a named access flaw. FulcrumSec used an API key that was published on the victim's own website.
Three practical notes follow from that split. Valid credentials, whether phished, bought or found in client side code, are now the entry route for the crews producing this week's biggest names, even though edge exploitation still produces more victims by count. Vulnerable driver abuse is the current defence evasion default across three groups in this report and is detectable at driver load if you are watching. And every edge appliance in the table above is a device most organisations patch on a quarterly cycle while the exploitation window is measured in days.

Infrastructure and Operational Shifts

Bulk domain listing is now the dominant posting format at the top of the chart. 61 of 205 postings this week were a bare domain, 30% of the week, and four groups produced 48 of them. The proportion has risen every week this quarter. It points to automated intake from an access or credential feed rather than hands on keyboard reconnaissance, and it is why 39 of our rows carry no sector and 12 no country. The operational consequence for a defender is that leak site monitoring keyed on company names now misses a third of the field. Monitor your domains and your suppliers' domains, not just your legal entity names.
One target category, nine unrelated operators. Eleven law firms this week, claimed by Silent Ransom Group, Qilin, DragonForce, Space Bears, Insomnia, Aurora, LockBit, Settra and KryBit. There is no shared infrastructure and no shared tradecraft between those nine. What they share is a read of the category: concentrated client data, privilege obligations that make disclosure expensive, and security maturity that outside the largest firms is thin. When a sector becomes fashionable across the whole field at once, the driver is usually a payment rate rather than a vulnerability.
Extortion without encryption held at roughly a tenth of the field. 21 of the 205 postings came from crews whose listings this week carried no encryption claim: Silent Ransom Group, ShinyHunters, FulcrumSec, Audit Team, Coinbase Cartel, LeakNet, Global Secret Group and DYSPHOR1A. Nothing is down, nothing is encrypted, there is no recovery to run, and the entire incident is a negotiation about a data set the attacker already has. It produced two of this week's five notable claims and by far its largest number of exposed individuals. If your incident response plan starts with restore from backup, that branch does not exist for a tenth of this field and for the part of it that generates the headlines.
Client side secrets are now an extortion vector in their own right. The single largest data set in this report, roughly 8.7 million customer profiles, came from an API key in a public JavaScript bundle. No malware, no CVE, no lateral movement, no leak site countdown mechanics until after the fact. Any marketing, analytics or messaging platform key that reaches the browser should be treated as published, and its permissions scoped as though an anonymous internet user holds it, because one does.
The week shape inverted. Last week peaked on a Saturday at 21% of volume. This week peaked on the Monday at 28% and fell away to 7 postings on the Sunday. Neither shape is the norm, and the reason is the same in both cases: two or four batch uploads land wherever the operator happens to schedule them and swamp the underlying rhythm. Weekly posting curves are now mostly a chart of when lists were uploaded. Do not read a quiet Sunday as a quiet field.

First Look at September 7

Our window closes on Sunday September 6, but readers ask what the next week opened with, so here is the first full day. Monday September 7 produced 63 deduplicated postings on its own, more than any single day inside this report's window. Two operators supplied 35 of them: The Gentlemen posted 19 across sixteen countries including Hollard Insurance Group, the University of San Francisco, Metro and Yapi Merkezi, and a crew posting as Kazu published 16, almost all of them healthcare and telemedicine platforms across Canada, Brazil, Argentina, Pakistan, South Africa and India. MetaEncryptor added four named manufacturers and ST Engineering. ShinyHunters listed the State of Florida DMV. That is a single day at 31% of this entire week's total, and it will be counted in issue 36. Treat it as a direction indicator, and treat the pairing of a quiet week with a very heavy Monday as the pattern this quarter keeps producing.

Key Takeaways for Defenders

Patch the edge flaws in the table above in KEV order, then rotate the credentials behind them. CVE-2026-50751 on Check Point VPN carried a two day federal remediation deadline and was exploited before a patch existed. CVE-2024-40766 on SonicWall was patched in August 2024 and Akira is still landing on it. SonicWall's own guidance is that patching is not sufficient and local SSLVPN passwords must be reset, and the same logic applies to every appliance in the table: The Gentlemen operates from an inventory of already compromised devices and validated credentials, so an appliance you patched last month may still be holding a valid session for somebody else.
Make the help desk an authentication boundary, and assume the caller may show up in person. Silent Ransom Group produced three AmLaw 100 names this week without touching a vulnerability, and Halcyon has documented the group sending a person to the premises when the phone call does not work. Require a callback to a directory number, out of band verification for any password or MFA reset, a hard rule that remote access software is never installed at the request of an inbound caller, and a visitor process that does not let an unescorted stranger reach a logged in workstation. Then test all four yourself.
Audit every secret that reaches the browser. The largest data set in this report came from an Iterable API key in public JavaScript. Inventory the keys in your client side bundles for marketing, analytics, messaging, search and support platforms, check what each one can read and export rather than what it was meant to do, and scope them to the single operation the page actually needs. Treat any key that has ever been served to a browser as compromised and rotate it.
Monitor domains, not company names. 30% of this week's postings carried no company name at all, only a hostname. If your leak site monitoring or your brand protection is keyed to legal entity names, it did not see a third of the field this week and the proportion is rising. Feed it your domain inventory, including the subdomains, acquisitions and country sites you no longer maintain, plus the domains of the suppliers whose compromise becomes your notification obligation.
Treat law firm and professional services suppliers as an exposure of yours. Nine unrelated operators worked the legal category this week. Your outside counsel holds your litigation files, your deal data, your regulatory correspondence and your employee matters, and a claim against them is a claim against material you own. Ask which firms hold your data, what their breach notification commitment to you is, and how quickly you would learn. For most organisations the honest answer today is that you would learn from a leak site.
Add a branch to the incident response plan for the case where nothing is encrypted. 21 postings this week involved no encryptor and they produced the week's two best evidenced claims. There is no outage, no restore and no obvious trigger, and the first indication is often the leak site post itself. Decide now who owns that call, what the legal and notification path looks like under CERT-In, SEC, GDPR and NIS2, APRA CPS 234 or MAS as applicable, and what you will say publicly, because the timeline in that scenario is set by the attacker's countdown rather than by your recovery.
Most of that work is triage before it is defence. Somebody has to read 205 postings, work out which three touch your organisation or your suppliers, and cross reference each named group against the flaws actually exposed on your perimeter.

Where Scrutex Fits

Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface, so a listing that names your domain or a supplier's domain reaches you as an alert rather than as a line in a weekly roundup. That domain matching is the part that matters in a week where 30% of postings carried no company name. Vulnerability Insights prioritises the flaws in the table above by real world exploitability against your exposed assets rather than by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.

Frequently Asked Questions

How many ransomware attacks were there in the week of August 31 to September 6, 2026? We tracked 205 unique victim postings across 50 active groups and 44 countries. Rebuilding the previous week on the same feeds and the same rules gives 271, so the week over week change is down 24%. These are leak site postings rather than confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Why is this week's number so much lower than last week's? Because the field posted less, broadly rather than in one place. The leader, Qilin, fell from 42 postings to 15, and no group replaced it. Top five concentration fell from 41% to 36% at the same time, which tells you the decline is spread across the field rather than caused by one operator going quiet. Note that our published figure for last week was 247, not 271: a feed returned to our collection and backfilled that window afterwards. Comparing 205 against 247 would measure our own coverage rather than criminal activity.
Which ransomware group was most active in September 2026? Settra, with 17 postings, ahead of KryBit on 16 and Qilin on 15. That ranking needs a caveat: 16 of Settra's 17 and all 16 of KryBit's were bare domains with no company name, no sector and no sample. By volume of named organisations, Qilin, INC Ransom and Akira did more identifiable work.
How reliable is the claim that Settra and KryBit are the top two groups? Treat it as a ranking of upload volume rather than of capability. 32 of the 33 postings from those two groups are a domain and nothing else, and KryBit put 14 of its 16 into a single run across eleven countries on one day. That pattern usually means a purchased access list published in a batch, not sixteen fresh intrusions. Every domain still deserves triage. None of them is confirmed.
Did Manchester Airports Group and Nutex Health actually confirm being breached? Yes, both did, which is why they are the only two high confidence entries in this report. Manchester Airports Group disclosed the breach and the data has been published and independently indexed. Nutex Health told the SEC in an 8-K filing on August 31 that patient, employee and financial data were exfiltrated. In both cases the data theft is confirmed by the organisation. The attribution to FulcrumSec and The Gentlemen respectively rests on the actors' own listings.
Which CVEs are these groups exploiting right now? The named source attributions this week are CVE-2026-50751 on Check Point VPN and CVE-2026-0257 on PAN-OS GlobalProtect for Qilin, CVE-2024-55591 on FortiOS and CVE-2025-7771 for driver abuse by The Gentlemen, CVE-2024-40766 on SonicWall SSLVPN for Akira, CVE-2023-3519, CVE-2025-5777 and CVE-2024-57727 for INC Ransom, and CVE-2023-28252 for Brain Cipher escalation. Five of the top ten groups have no verifiable access CVE, because they use stolen VPN credentials, help desk impersonation, purchased access and, in one case, an API key published on the victim's own website.
Which sectors were hit hardest this week? Manufacturing at 28 postings, business services at 27, technology at 25 and healthcare at 23. Read those as counts rather than shares, because 39 of the 205 postings carried no sector label. Business services is the set to watch: 11 of its 27 entries are law firms, claimed by nine different operators in one week.
Where can I get this in real time instead of weekly? Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, including domain level matching, so a relevant listing reaches you when it is posted rather than in the following Monday's roundup.