Ransomware Weekly
24 views
By ScruteXPublished

Ransomware Attacks This Week: 214 Victims Across 46 Groups (September 28 to October 4, 2026)

This is the Scrutex ransomware weekly for the September 28 to October 4, 2026 window. Our CTI team tracked 214 unique ransomware and extortion victim postings across 46 active groups and 45 countries. That is up 20% from 179 for September 21 to 27 on the same counting rules. The Gentlemen led with 34, 25 of them in one batch on Tuesday. Storm followed on 15 and Qilin on 14. The United States took 85 postings, 40% of the week, and manufacturing led the sectors with 47, ahead of healthcare on 35.
The rise is real, but it is not one crew getting busier. Three things arrived together. The Gentlemen's weekly batch was its largest in a month. SafePay came back with 12 listings after posting nothing the week before. And Lamashtu, a data extortion brand that first appeared in April, published ten victims in a single day, half of them German. Strip those three out and the rest of the field posted 158, close to last week's level.
Healthcare is the sector to read closely. It almost doubled, from 18 to 35, and the names are larger than usual: a Barcelona teaching hospital, a US glucose monitoring maker, a Florida senior care system and an Ontario hospital that had already told its community it was dealing with ransomware. Only that last one is confirmed by the organisation itself.
Law enforcement had the better week. A German led operation arrested the suspected 16 year old administrator of KillSec in Spain on September 30 and seized the crew's leak site and more than 110TB of data. An alleged ShinyHunters member was reported detained in Jordan the day before, and the group's two newest listings, DexCom and O'Reilly Automotive, were taken down within two days of going up.
214 posts, 46 groups, 45 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day.
A note on how to read the numbers. Each count is a unique organisation named on a leak site during the window. We merge duplicate listings, count a relisted incident once, in the week it first appeared, and leave out postings that do not name an organisation. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old.

In This Post

SectionWhat it covers
This Week at a GlanceHeadline numbers and a front loaded week
Group Activity BreakdownWho posted most, and what sits behind each run
New and Emerging GroupsLamashtu, Storm and Redact
Sector Targeting AnalysisManufacturing leads, healthcare nearly doubles
Country DistributionWhere the 45 countries fall
Notable Claims and IncidentsSix named claims, one confirmed by the victim
Top CVEs These Groups Are ExploitingThe flaws in play, and the crews with none
Infrastructure and Operational ShiftsArrests, relisting and a hospital heavy week
Key Takeaways for DefendersThe short action list

This Week at a Glance

MetricValue
Total unique victims posted214
Change on prior weekUp 20% (from 179)
Active groups46
Countries hit45
Heaviest single dayTuesday September 29 (52 posts, 24% of the week)
Quietest daySaturday October 3 (6 posts)
Most targeted countryUnited States (85 victims, 40% of postings)
Most targeted sectorManufacturing (47), then Healthcare (35)
Top group by volumeThe Gentlemen (34, 25 of them on September 29)
Notable claimsNipigon District Memorial Hospital, DexCom, O'Reilly Automotive, Graybar Electric, Hospital de Sant Pau, BCX, Advantech
The week was front loaded. Monday took 48, Tuesday 52 and Wednesday 38, which is 138 of 214 postings, 64%, in the first three days. Thursday fell to 24, Friday recovered to 33, and the weekend held 19 between Saturday's 6 and Sunday's 13.
Each of the first three days had a different driver. Monday belonged to SafePay, with nine listings, and 3AM, with seven. Tuesday was The Gentlemen's batch of 25 plus eight from Brain Cipher and six from M3RX. Wednesday was Lamashtu's ten and six from Storm. That matters for how you read the daily chart: three batches from six crews produced the shape, and a batch tells you when a crew published, not when it broke in.
The rise from 179 to 214 needs the same care. The Gentlemen went from 22 to 34, Storm from 5 to 15, SafePay from zero to 12 and Lamashtu from zero to 10. Against that, MetaEncryptor, Silent Ransom Group and Everest, which posted 24 between them last week, posted one this week. The top five groups took 85 of 214 postings, 40%, against 37% last week, and 28 groups posted three victims or fewer, together producing 46 postings. A note on last week's base: we published 172, and seven further listings dated to that week surfaced afterwards, which is why the comparison uses 179.

Group Activity Breakdown

The top five groups produced 85 of 214 postings, 40% of the week. Below them, 28 groups posted three or fewer victims each, together accounting for 46.
RankGroupVictimsShareNotable Activity
1The Gentlemen3416%25 on September 29 across 20 countries. Hospital de Sant Pau, Aware, Auren, LegalWise, Edcon, Telrad Networks
2Storm157%14 in the US and one Ontario hospital. Poca Valley Bank, Silvercup Studios, West County Health Centers
3Qilin147%Five of seven days. Thai Lion Air, Inova Semiconductors, three Japanese manufacturers
4SafePay126%Nine on September 28, three on the 30th. Eleven bare domains, eight countries, none in the US
5INC Ransom105%Eight in the US. BCX in South Africa, AHEAD, Guardian Pharmacy, an Alaska school district
6Lamashtu105%All ten on September 30. Five German firms, FIDUCIAL in France
7Akira84%Three days, five countries. Pacific Tank Lines, Wesmar, a Spanish architects' college
8Brain Cipher84%All eight on September 29, all bare domains. Trailer Bridge, Northeast Rehab
9KryBit84%Six countries. Two Indian listings, a French telecoms group, an Iranian healthcare site
103AM73%All seven on September 28, all bare domains across six countries
11Play73%Five US and two German firms, spread across three days
12Booba Project73%Five healthcare providers, University of Illinois Chicago, a Brazilian state foundation
A long tail of groups (M3RX, Emperador, Rhysida, MedusaLocker, N0n, WallStreet, Interlock, LockBit, Chaos, Kairos, Genesis, Doommageddon, Netrunner, Panzer, GammaX, Vexy, Aurora, DeadLock, ShinyHunters, Cry0, Payload, Silent Ransom Group, ULose, Eclipse, Black X, Morpheus, NightSpire, PayoutsKing, Redact, Audit Team, Barracuda, Spirals, DireWolf and Kazu) each posted between one and six victims.
Three observations:
The Gentlemen's batch held for a fifth week, and it grew. For four weeks the group published a batch of 18 to 30 on a Monday and then almost nothing. This week the batch was 25, dated Tuesday, with nine more spread over the rest of the week. The spread is the widest we have recorded for it: 20 countries, from a Senegalese services group to a Taiwanese drinks distributor to a primary school in Wiltshire. A crew working from a list of compromised appliances, which is how Group-IB describes this one, produces exactly that kind of geography. One entry deserves a flag. The Gentlemen listed Telrad Networks eight days after Qilin did. Two crews naming one victim usually means shared access, a shared affiliate or resold data, and it does not mean two intrusions.
Storm is the real mover. Fifteen listings against five, all but one in the United States, and spread over four separate days with no batch larger than six. That is a working rate, not a queue being flushed. Storm's leak site is two months old, and its victims are the mid sized US firms that fill most crews' lists: a West Virginia bank, a New York film studio, a California community health network, two machine tool makers. Its one non US listing, Nipigon District Memorial Hospital, is the week's only claim the victim has confirmed.
Bare domains are a third of four crews' output and all of some. 48 of the 214 postings are a domain name and nothing else. SafePay supplied 11, Brain Cipher 8, 3AM 7, and M3RX and KryBit 6 each. A domain only listing is a real threat to the organisation named, but it carries no description, no volume and no sample, which makes it the hardest kind to verify. SafePay's return is a case in point: 12 listings in three days, none in the US, and the only one with a name attached is a Holiday Inn in Vilnius.

New and Emerging Groups

One brand most readers will not have met, one that has grown up quickly, and one that only lists large companies.
Lamashtu. Ten listings, all on September 30. Five are German mid market firms, among them a logistics operator, a toolmaker and a security video specialist. The others are FIDUCIAL in France, an Italian dental supplier, a US energy firm, an Australian IT provider and an Argentine medical practice. Lamashtu first appeared in April 2026 and, so far, nobody has shown that it encrypts anything. Its listings read as data theft extortion: a countdown, a statement that the full leak follows unless a company representative makes contact, and stolen files offered for download. For defenders that changes what to look for. There may be no ransom note and no outage. The first sign is large outbound transfers from file servers and document management systems, and the control is egress monitoring, not backup.
Storm. First seen in August 2026 and already at a steady double digit week. The group says it does not target the Commonwealth of Independent States and has been recruiting affiliates, which is the standard profile of a Russian speaking ransomware as a service operation. No named research team has yet published how its affiliates get in, and we will not guess. Two cautions. This is not Microsoft's Storm-1175 or any other "Storm-" designation, which is Microsoft's label for actors it has not yet named. And with 14 of 15 listings in the US, any American organisation in manufacturing, healthcare or local financial services is squarely in its range.
Redact. One listing this week, Graybar Electric, and only three in total since late June. All three are large US companies: a medical technology firm, an insurer and now one of the country's biggest electrical distributors. The Graybar entry claims 606GB. A brand that lists rarely and only names large firms is either selective or reselling someone else's access, and one tracking account describes Redact as a rebrand of an earlier crew called BlackFile. We could not confirm that. Treat every Redact claim as unverified until the named company speaks.

Sector Targeting Analysis

RankSectorVictimsShare of labelled
1Manufacturing4725%
2Healthcare3519%
3Technology2011%
4Business Services2011%
5Consumer Services158%
6Transportation and Logistics95%
7Education84%
8Agriculture and Food74%
9Public Sector63%
10Energy63%
11Financial Services63%
12Hospitality and Tourism53%
13Construction and Real Estate11%
29 of the 214 postings could not be assigned a sector, most of them bare domains, so the percentages above are shares of the 185 that could.
Manufacturing at 47 is back in a clear lead after last week's three way tie. It is broad and mostly mid sized: German industrial firms from Lamashtu, US machine shops from Storm, Japanese component makers from Qilin. The two names with reach beyond their own walls are Advantech, the Taiwanese industrial computing firm listed by Chaos, and Inova Semiconductors in Germany, listed by Qilin. Manufacturers are listed for downtime pressure and for what they hold of their customers' designs, and an industrial computing supplier holds a lot of both.
Healthcare at 35 is the week's story. It was 18 last week. Twenty crews contributed, so this is not one campaign, but two patterns stand out. Booba Project posted five medical providers in two days, having spent last week on county governments and a school. And four listings name organisations that deliver care at scale: Hospital de la Santa Creu i Sant Pau in Barcelona, MorseLife Health System in Florida, St. Francis Healthcare System of Hawaii and Nipigon District Memorial Hospital in Ontario. The rest are small clinics, practices and pharmacies, where a leak exposes patient records with little capacity to respond. Health data cannot be reissued the way a card number can, which is why it holds its price and why crews keep coming back.
Technology and business services, at 20 each, include the suppliers whose compromise travels. BCX is one of South Africa's largest IT services firms. AHEAD is a US infrastructure and cloud consultancy. Consilio handles eDiscovery and document review for law firms and corporate legal teams, so a listing there is a question for every client with a matter on its platform. Last week's law firm run did not repeat: six legal sector listings from five crews, all small practices apart from Consilio and LegalWise, a South African legal insurer.
Education at 8 spans a Vietnamese language school chain, a Western Australian school, a Vermont school district and the University of Illinois Chicago. Public sector at 6 includes the Junta de Andalucia, an Alaskan school district, a Western Australian emergency service and an Argentine digital government platform.

Country Distribution

RankCountryVictimsShare
1United States8540%
2Germany126%
3United Kingdom126%
4Brazil84%
5Spain73%
6Canada63%
7France52%
8Argentina42%
9Australia42%
10UAE42%
11India42%
12Switzerland42%
13Japan42%
14South Africa42%
15Colombia31%
A further 30 countries recorded between one and three victims each: Mexico, Belgium, Taiwan, South Korea, Sweden, the Philippines, the Czech Republic, Greece, Italy, Vietnam, Bangladesh, Malaysia, Lithuania, Bulgaria, New Zealand, Poland, Austria, Senegal, Nicaragua, Puerto Rico, Indonesia, Israel, Ecuador, Thailand, Denmark, Lebanon, Saudi Arabia, Turkey, Iran and Chile. Four postings carried no country.
The US rose from 79 to 85 while its share fell from 44% to 40%, because the rest of the world rose faster. Storm supplied 14, The Gentlemen 10 and INC Ransom 8. For listed US companies named this week, including DexCom, O'Reilly Automotive and Aware, the relevant clock is the SEC's: a Form 8-K within four business days of determining that an incident is material. For the US healthcare providers, HIPAA sets notification to affected individuals without unreasonable delay and no later than 60 days after discovery.
Germany went from 3 to 12, the largest move on the table, and five of the twelve are Lamashtu's single batch. One crew choosing to publish its German victims together is not a German campaign, but for the firms named the obligations are the same: GDPR notification to the state data protection authority within 72 hours, and for entities in scope of NIS2, an early warning to the BSI within 24 hours.
The UK at 12 is spread across eight crews with no theme: a hosting provider, a facade manufacturer, a dental group, a primary school. Reports go to the ICO within 72 hours where personal data is at risk.
Spain at 7 carries two public bodies, the Junta de Andalucia and Hospital de Sant Pau. Both fall under the Esquema Nacional de Seguridad as well as GDPR, with notification to the AEPD within 72 hours and incident reporting through CCN-CERT.
Canada at 6 includes the confirmed Nipigon incident. Ontario's health privacy law, PHIPA, requires a health information custodian to notify affected individuals at the first reasonable opportunity and to report qualifying breaches to the Information and Privacy Commissioner.
South Africa's four are worth more than their rank suggests: BCX, LegalWise, the retailer Edcon and the medical scheme Samwumed. POPIA requires notification to the Information Regulator and to data subjects as soon as reasonably possible after discovery. India's four fall under CERT-In's 2022 directions, with a six hour reporting window from the moment an incident is noticed, the shortest clock on this list. Australia's four fall under the Notifiable Data Breaches scheme, with APRA's CPS 234 adding a 72 hour notification for regulated financial entities. Japan's four report to the Personal Information Protection Commission under APPI.
Italy fell from 9 to 2, with no change in any single crew behind it.

Notable Claims and Incidents

Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation or an authority has said so.
Storm lists Nipigon District Memorial Hospital, which had already disclosed a ransomware incident. Posted October 4. The Ontario hospital told its community in mid September that it was responding to a ransomware incident, that encrypted files contained personal and health information, and that laboratory and imaging services were closed, as reported by SNnewswatch on September 18. Storm's listing arrived about two and a half weeks later. Confidence: High that the incident occurred, because the hospital said so. Medium that Storm is responsible, since the hospital has not named a group and a leak site listing is a claim. A small rural hospital losing lab and imaging is the practical meaning of healthcare ransomware: patients travel further for a scan.
ShinyHunters lists DexCom and O'Reilly Automotive, then removes both. Hackread reports the two entries were posted on October 1 and deleted on October 3, and Cybernews reports they carried a threat to publish by the end of Friday. The listings described no data types and no volume, and neither company has commented. Confidence: Low. The week's context matters here. An alleged member of the group using the name "Rey" was reported detained in Jordan on September 29, Dutch police arrested a 24 year old, the FBI published a video urging members to surrender, and the group's leak site was offline for part of the week. Listings that appear and vanish during that kind of pressure may be real, may be bluff, and cannot be told apart from outside.
Redact lists Graybar Electric. Posted October 1 with a claimed 606GB. Graybar has made no public statement. Confidence: Low. The claim rests on the listing alone, and the brand has only two earlier listings to judge it by. A separate incident at a Graybar subsidiary in March 2026 should not be read as confirmation of this one.
The Gentlemen list Hospital de la Santa Creu i Sant Pau. Posted October 2 with no volume, sample or deadline. Spanish outlets Escudo Digital and ADSLZone report that neither the hospital nor the Generalitat has confirmed an incident. Confidence: Low. Sant Pau is one of Barcelona's main teaching hospitals, and the 2023 attack that disrupted Hospital Clinic in the same city was a different hospital and a different group. In the same batch The Gentlemen listed Aware, a US biometrics company, with a claimed 400GB and no company statement.
INC Ransom lists BCX. Posted September 29. The actor claims 500GB and more than 4.2 million files, including source code, technical documentation for six business applications and what it calls numerous vulnerabilities in current applications. Neither BCX nor its parent Telkom has commented. Confidence: Low to Medium. The claim is unusually specific, which costs an actor credibility if it is false, but nothing independent supports it. BCX runs IT for South African banks, retailers and government bodies, so its customers should ask now what an exposure of application source code would mean for them.
Chaos lists Advantech. Posted September 29 with a claimed 500GB, a statement that 5% has been published and a 48 hour ultimatum to management. Advantech has not commented on this claim. Confidence: Low to Medium. Advantech disclosed a ransomware attack by a different group several years ago, and coverage of that older incident still ranks highly in search results. Do not mistake it for a response to this one.
Low signal claims this week. 48 postings are a bare domain and four are redacted to a few characters, so 162 of 214, 76%, name an organisation. Among the named, several deserve a flag. WallStreet titled a listing "World Cup 2034"; the target is the Saudi branch of a Chinese construction group building a stadium, not the tournament or its organiser, and the claimed 17TB is unverified. Booba Project shows the same 344GB figure against both the University of Illinois Chicago and MorseLife, which suggests a template, not a measurement. MedusaLocker's Junta de Andalucia and ATCO listings carry no stated volume, and the Junta's press office had not replied to Escudo Digital at the time of its report. N0n set an October 3 deadline on MCAP, a Canadian mortgage lender, with no statement from the company. Eclipse listed The Japan Times, and LockBit listed Consilio with no inventory.
Updates on last week's claims. DataBreaches.net reported on September 28 that Silent Ransom Group is demanding $20 million from Hogan Lovells Cadwalader and that the firm had offered $5.34 million; the firm did not respond to the outlet. Silent Ransom Group posted one redacted stub this week and no named firm. Emperador's stated release date for the Receita Federal claim is October 13. We found no new statement on Revolut, Fresenius Medical Care, Flex, Bruker or GE Vernova.

Top CVEs These Groups Are Exploiting

The table covers this week's active groups where a named source supports the attribution. CVSS is the NVD v3.1 base score unless marked otherwise.
CVEProductCVSSWho is using itWhy it matters
CVE-2024-55591Fortinet FortiOS and FortiProxy, authentication bypass9.8The GentlemenGroup-IB (March 2026) and Check Point Research (May 2026) name it the group's primary access route. A batch spanning 20 countries fits an operator working through a list of exposed appliances, not choosing targets
CVE-2023-27532Veeam Backup and Replication, credential exposure7.5The GentlemenGroup-IB documents its use after access, to pull stored credentials. This is credential theft, not the way in, and the backup server holds the keys to the rest of the estate
CVE-2026-0257Palo Alto Networks PAN-OS GlobalProtect, authentication bypass9.1QilinArctic Wolf (July 2026) traced intrusions from this flaw to Qilin deployment. On the CISA KEV catalogue since May 29. Palo Alto scores it 7.8 under CVSS v4, so do not triage it by the lower number
CVE-2026-50751Check Point Remote Access VPN and Mobile Access, IKEv1 authentication bypass9.3 (vendor, CVSS v4)Qilin affiliateCheck Point confirmed Qilin affiliate activity after compromise in one case. On the CISA KEV catalogue since June 8
CVE-2024-40766SonicWall SonicOS SSLVPN, improper access control9.8AkiraArctic Wolf ties sustained Akira activity to it. Huntress (August 2026) describes Akira entering through credential spraying against a SonicWall SSL VPN without MFA, with no CVE needed
CVE-2023-3519Citrix NetScaler ADC and Gateway, unauthenticated RCE9.8INC RansomTrend Micro's INC profile documents exploitation in late 2023. Treat it as historical: we found no newer named source attributing a CVE to INC
CVE-2026-35273Oracle PeopleSoft9.8 (as reported by Arctic Wolf)ShinyHunters, by its own claimArctic Wolf (June 2026) reported active exploitation in a campaign the group claimed. The attribution rests on the actor's statement, and the group's usual route is still the phone, not an exploit
One vulnerable driver matters as much as the access flaws. Cisco Talos describes Qilin loading a renamed ThrottleStop driver, rwdrv.sys, alongside a separate malicious driver, hlpdrv.sys, to shut down endpoint protection. Trend Micro and Group-IB document The Gentlemen using the same ThrottleStop driver renamed ThrottleBlood.sys, and GuidePoint has reported the pairing in Akira intrusions. Three of this week's top seven crews share it, which makes a block rule on that driver one of the most efficient controls on this page.
Attribution accuracy note. Six of this week's top ten groups have no verifiable access CVE: Storm, SafePay, Lamashtu, Brain Cipher, KryBit and 3AM. For 3AM, Sophos describes a route with no exploit in it at all: an email flood, a phone call from someone posing as IT support, then Microsoft Quick Assist. SafePay is generally described as entering through VPN gateways with stolen credentials and no MFA, although no research team on our named list has published on it recently. Storm, Lamashtu, KryBit, Booba Project and M3RX have no named reporting on access. Several commentary sites link these crews to recent VPN flaws by inference. We have left those out.
Watch list, not attribution. CISA added three Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogue in the last ten days, CVE-2026-88771 and CVE-2026-88772 on September 27 and CVE-2026-88779 on October 4, along with flaws in Check Point gateways and F5 BIG-IP APM on September 22. None is flagged for ransomware use yet, and Mandiant ties part of the NetScaler activity to suspected state actors. NetScaler has been a ransomware entry point before. Patch on the assumption it will be again.
Two corrections to last week. We wrote that ReliaQuest attributed the PTC Windchill campaign (CVE-2026-12569) to Cl0p with high confidence in August. ReliaQuest reported in July and described the actor as unconfirmed, with tradecraft resembling Cl0p; the attribution came from other researchers. We also credited Arctic Wolf with reporting the ThrottleStop driver in Akira intrusions. That reporting was GuidePoint's.

Infrastructure and Operational Shifts

Law enforcement reached two crews in two days. On September 30 an operation led by Hamburg police and prosecutors, with Spain's Guardia Civil, the Mossos d'Esquadra, the FBI, Europol and Romania's DIICOT, moved against KillSec. The Record and The Hacker News report that the suspected administrator, aged 16, was arrested in Alicante, with further arrests in the UK and Romania, and that the leak site, five servers and more than 110TB of data were seized. Investigators are examining about 1,000 attacks. A day earlier an alleged ShinyHunters member was reported detained in Jordan. Two lessons follow. If KillSec ever listed your organisation, investigators now hold the data it took, which may bring a notification you were not expecting. And an arrest does not end exposure: affiliates keep their access and their copies.
Relisting is now routine. Three sets of listings this week were older incidents presented again. A brand called Bavacai, first seen in May, carried 30 entries, and every identifiable one matches a MedusaLocker victim first posted between mid August and late September. A site calling itself Global Cybernetic Collective listed seven victims that the Global crew had posted between August 28 and September 12, including Sutton Public Schools and the Town of Sutton in Massachusetts. And Emperador, Audit Team and ImNotAVillain each reposted victims from September. We count each of those once, in the week it first appeared. If your organisation's name reappears under a new brand, check the date of the original claim before treating it as a second incident.
Data theft without encryption keeps spreading down market. Lamashtu has not been shown to encrypt, Silent Ransom Group never has, and ShinyHunters works through stolen sessions and phone calls. Booba Project's university listing is described as data theft only. A control set built around detecting encryption sees none of this until the listing appears. The detection that works is at the exit: unusual volumes leaving file servers, new cloud storage destinations, and archive tools running where they do not normally run.
Healthcare is being listed by newer crews. Of the 35 healthcare postings, at least 13 came from groups first seen in the last twelve months, among them Booba Project, Storm, WallStreet, Genesis and Lamashtu. Established crews have at times said they avoid hospitals. Newer ones make no such claim, and the Nipigon incident shows the result.

Key Takeaways for Defenders

If you run a hospital or clinic, rehearse the outage, not only the breach. Healthcare listings nearly doubled to 35, and the one confirmed incident closed a hospital's lab and imaging. Test how long you can run diagnostics, pharmacy and patient records on paper, and confirm your backups for those systems restore.
Watch the exit as well as the door. Lamashtu, Silent Ransom Group and ShinyHunters take data and never encrypt. Alert on large outbound transfers from file and document servers, on new cloud storage destinations, and on archive utilities running on servers.
Patch the edge, then rotate what sits behind it. FortiOS CVE-2024-55591, PAN-OS CVE-2026-0257, Check Point CVE-2026-50751 and SonicWall CVE-2024-40766 are the routes this week's named crews use. Add the three new NetScaler entries on the CISA catalogue. Credentials captured before a patch keep working after it, so reset local VPN accounts and enforce MFA.
Block the ThrottleStop driver. Qilin, Akira and The Gentlemen all use a renamed copy to kill endpoint protection. Add it to your vulnerable driver block list and alert on any driver load outside your approved set.
Ask your IT and legal suppliers what they hold of yours. BCX, AHEAD and Consilio were all listed this week. Establish which providers hold your source code, your infrastructure credentials and your legal documents, and what their notification commitment to you is.
Check the date before you escalate a listing. Three sets of this week's postings were earlier incidents under a new name. Before a listing reaches your incident process or your board, confirm whether the claim is new.
Most of that work is triage before it is defence. Somebody has to read the week's postings, set aside the relistings and the unverifiable, and work out which of the rest touch your organisation or your suppliers.

Where Scrutex Fits

Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface and your named suppliers, so a listing that names your domain or a vendor's domain reaches you as an alert and not as a line in a weekly roundup. Vulnerability Insights prioritises flaws like the edge CVEs above by real world exploitability against your exposed assets, not by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.

Frequently Asked Questions

How many ransomware attacks were there in the week of September 28 to October 4, 2026? Scrutex tracked 214 unique victim postings across 46 active groups and 45 countries. That is up 20% from 179 for September 21 to 27. These are leak site postings, not confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Why did ransomware postings rise this week? Three crews account for the increase. The Gentlemen posted 34 against 22, SafePay returned with 12 after none the week before, and Lamashtu published ten victims in a single day. Without those three the rest of the field posted 158, close to last week's level.
Which ransomware group was most active? The Gentlemen, with 34, ahead of Storm on 15 and Qilin on 14. The Gentlemen published 25 of its 34 in one batch on September 29, across 20 countries. Storm tripled its previous week with 14 US victims and one Canadian hospital.
Was KillSec taken down? A German led operation on September 30 arrested the suspected 16 year old administrator of KillSec in Alicante, Spain, with further arrests in the UK and Romania. Police seized the leak site, five servers and more than 110TB of data, and are investigating about 1,000 attacks.
Were DexCom and O'Reilly Automotive breached? ShinyHunters listed both at the start of October with a deadline and removed both by October 3. The listings described no data and neither company has commented. We rate the claims low confidence.
Which sectors were hit hardest? Manufacturing led with 47 postings and healthcare followed with 35, almost double last week's 18. Healthcare listings included a Barcelona teaching hospital, a Florida senior care system and an Ontario hospital that had already disclosed a ransomware incident.
Which CVEs are these groups exploiting? The Gentlemen use CVE-2024-55591 on FortiOS, Qilin uses CVE-2026-0257 on PAN-OS and CVE-2026-50751 on Check Point VPN, and Akira uses CVE-2024-40766 on SonicWall. Qilin, Akira and The Gentlemen also share a vulnerable ThrottleStop driver. Six of the top ten groups have no verifiable access CVE.
Where can I get this in real time instead of weekly? Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, so a relevant listing reaches you when it is posted and not in the following Monday's roundup.