Ransomware Weekly
24 views

Ransomware Attacks This Week: 221 Victims Across 47 Groups (September 14 to 20, 2026)

By ScruteXPublished
This is the Scrutex ransomware weekly for the September 14 to 20, 2026 window. Our CTI team tracked 221 unique ransomware and extortion victim postings across 47 active groups and 46 countries. Measured against the September 7 to 13 window rebuilt today on the same feeds and the same counting rules, that is up 19% from 186. It ends two consecutive weeks of decline and is the highest total since the end of August.
Two groups finished one apart and ran in opposite directions to get there. Qilin posted 31 victims spread across six of the seven days, with no run larger than seven. The Gentlemen posted 30, every one of them on Monday September 14, across 20 countries with no shared sector. Same scale, entirely different operating model: one works continuously, the other publishes a queue. If you rank crews by weekly count alone you cannot tell those two apart, which is most of what is wrong with ranking crews by weekly count. It also changes how stale a listing is. A batch entry tells you an affiliate finished with that victim some weeks ago and the queue reached the top of the pile. A steady posting sits closer to the event.
The standout claim is a single engineering firm listed by two unrelated crews on the same day. Brain Cipher posted aecom.com on September 17 claiming 670GB. MetaEncryptor posted AECOM the same day claiming 1.22TB. AECOM has not confirmed anything. Two brands, two volumes, one victim, one date.
The second thread is financial services. Storm listed five US institutions in four days: Insight Credit Union on September 15, then First Secure Bank and Trust, First Secure Community Bank, The State Bank and Johnson Investment Counsel on September 18. Two of those five are sister banks in the same group, which means the five listings are probably fewer than five intrusions. US banking agencies require notification within 36 hours of determining a notification incident, and credit unions work to a 72 hour rule, so the clock on those names started well before any of this reached a leak site.

This Week at a Glance

MetricValue
Total unique victims posted221
Change on prior weekUp 19% (from 186, last week rebuilt on current feeds; 179 as published)
Active groups47
Countries hit46
Heaviest single dayMonday September 14 (60 posts, 27% of the week)
Second heaviest dayFriday September 18 (42 posts)
Quietest daySaturday September 19 (7 posts)
Most targeted countryUnited States (73 victims, 33% of postings)
Most targeted sectorTechnology (50 named), Business Services (38), Manufacturing (22)
Top group by volumeQilin (31 posts across six days)
Largest single day runThe Gentlemen (30 on September 14)
Notable claimsAECOM, AT&T, Namibian Defence Force, AstraZeneca Turkiye, Fanatics, Nippon Steel, Pertamina, five US banks
The shape is two spikes and a collapse. Monday opened at 60, Tuesday fell to 34, Wednesday 32, Thursday 31, Friday rose to 42, Saturday collapsed to 7 and Sunday closed at 15. The two heaviest days hold 46% of the week between them.
Monday is one crew. The Gentlemen published all 30 of its victims that day, across Italy, India, the US, Sweden, Bulgaria, Peru, Singapore, Croatia, Switzerland, the UK, Brazil, Vietnam, South Africa, Japan, Israel, France, Finland, Spain, Germany and Argentina. This is the third Monday in a row the group has published a single large batch, which we flagged as a schedule in last week's report and can now treat as one. Friday is two crews: N0n's ten listings in one day and Storm's five financial institutions.
Qilin is the counterweight and the more informative number. 31 victims, six of the seven days, largest run seven. No batching, no theme beyond mid market, and a victim list running from an Argentine industrial group to a Swiss motoring club to a Turkish conglomerate. Qilin has led or nearly led our chart every week this quarter and has done it without ever producing the week's largest single day run.
The top five groups took 93 of 221 postings, 42%, against 36% last week. Concentration rose because two operators each cleared thirty, not because the field narrowed. The tail is still long: 32 groups posted three victims or fewer, together producing 60 postings, 27% of the week, and 11 groups posted exactly once.

Group Activity Breakdown

The top five groups produced 93 of 221 postings, 42% of the week. Below them, 32 groups posted three or fewer victims each, together accounting for 60 postings.
RankGroupVictimsShareNotable Activity
1Qilin3114%Six of seven days, no run larger than seven. ADM, Zorlu Holding, Touring Club Suisse, Bravo Group, Resolve Law Group
2The Gentlemen3014%All 30 on September 14 across 20 countries. Vittoria Assicurazioni agencies, BGR Energy Systems, Dome Gold Mines, Hattiesburg Eye Clinic, High Oakham Primary School
3Audit Team115%Mixed format for the first time: named domains (gownet.net, dg.ac.kr, Wise IT) beside masked stubs. Russia, South Korea, Ukraine, Italy
4N0n115%First appearance. Ten on September 18, Fanatics on the 20th. AstraZeneca Turkiye, United Federation of Teachers, Argentina's education ministry
5Akira105%Spread over four days. Southern California Telephone, Bee Maid Honey, Pilot Precision, Javep Chevrolet
6INC Ransom105%Five names on one tracker only, five domains on all four. Chicago History Museum, Silicon Integrated Systems, Kendall Hunt
7SafePay94%All nine on September 15, all bare domains. Switzerland, Germany, Japan, Mexico, Peru, US
8Storm84%Five US financial institutions plus PANTHERx Rare, McCarthy Tire and American Casting
9Spirals73%Newly named family. Five US healthcare and benefits firms on September 14, then PITTSRAD and AnythingIT
10Emperador73%Electrolux, RDA Motors, a Brazilian municipal government, an Alabama women's health practice
11LockBit63%Bare domains and one Italian comune. Finland, Taiwan, Germany, Chile, Ethiopia
12Panzer63%Honda Peru, Universitat Hamburg, Stim, Inovapy. Second week of European public sector reach
13Settra63%All six on September 17, all bare domains. Australia, Brazil, US, Austria, Mexico
14MetaEncryptor52%Nippon Steel, AECOM, Beckman Coulter, SFA Engineering, Promantra
15Arcus Media42%Costa Rica, US, Canada, Brazil
16Brain Cipher31%aecom.com, hoyletanner.com, xpera.ca, all on September 17
A long tail of groups (Chaos, Insomnia, RansomHouse, Vexy, KryBit, Play, Anubis, Booba Project, DireWolf, Eclipse, Genesis, Interlock, NightSpire, Orova, Rhysida, ShadowByt3$, ShinyHunters, Silent Ransom Group, WallStreet, DragonForce, EndZone, Unsafe, BlackNevas, Bravox, Cry0, GammaX, Kairos, KillSec, Securotrop, IAH647, Dark Project and ZaWoo) each posted between one and four victims.
Three observations:
Two scales, two business models. Qilin and The Gentlemen finished one apart and share nothing else. The Gentlemen's 30 landed in a single afternoon across 20 countries with no sector logic, which is an affiliate programme flushing a queue. Qilin's 31 arrived in ones and twos over six days, which is continuous processing. Note which one took the top slot: Qilin got there without a batch, and it has now done that every week this quarter.
Audit Team changed format. For three weeks this crew posted only masked stubs, and we reported its totals as an upper bound because nothing could be matched to a real organisation. This week six of its eleven listings carry actual domains: gownet.net and dg.ac.kr in South Korea, Wise IT in Ukraine, a Russian pallet retailer, an Argentine site. Three remain masked. The crew also kept posting "Paid Victim" markers with a hex handle, which we exclude. A group moving from full redaction to named domains usually means either the redaction was not producing payments, or the operator now wants the publicity.
INC Ransom is half invisible. Five of its ten listings, including the Chicago History Museum, the City of Princeton and a Czech financial services firm, appear on one tracker only and carry no country or sector. The other five arrived on all four feeds as clean domains. Single tracker postings are the ones most likely to be missed by monitoring keyed to a single source, and this week they are 30 of 221 postings overall.

New and Emerging Groups

Three genuinely new names and one crew that changed behaviour.
N0n. Eleven postings, ten of them on September 18, from a site with no prior history in our collection. The victim list is unusually large for a first appearance: AstraZeneca Turkiye, where the group describes 940MB of network configuration data and 1.35 million connection records; the United Federation of Teachers, the New York City teachers' union, with a claim of more than 181,420 documents; Argentina's Ministry of Education; Transcom WorldWide, described in the listing through its PayPal support operations; Inter, Venezuela's largest internet provider; STOKR, a Luxembourg digital securities platform; and a Vietnamese betting operator. Fanatics followed on September 20 with a claim of 108GB of order files tied to the id.fanatics.com account portal. None of the named organisations has confirmed anything, and no samples reached our collection. The pattern to note is the descriptive labelling: this crew writes out what the victim does inside the victim field, which is marketing rather than tradecraft, and it usually signals a group that wants press coverage more than negotiation.
Spirals. Seven postings. Five on September 14 through one tracker only, all US healthcare and benefits administration firms including NCG Medical, P&A Group and BHS Connect, then PITTSRAD, a US radiology imaging business, and AnythingIT, an IT asset disposal firm serving federal agencies and defence contractors, both on September 18. Symantec's threat intelligence team named this family in June 2026 after a double extortion attack on an IT services company in South Asia, describing a ransom note that threatens publication after six days. The September victim set is narrower than that origin suggests: healthcare administration and IT asset disposal are both businesses that hold other organisations' records, which is the common thread.
EndZone. Two postings, both on September 18, and both large: AT&T and Accela, the cloud platform many US local governments run permitting and licensing on. The AT&T listing claims initial access through a customer experience contractor account used to make equipment changes and set up call forwarding, then prolonged VPN and virtual desktop access. The Accela listing claims more than 50GB including over two million lines of user data and six million citizen portal requests. Neither company has confirmed. A brand new site opening with a national carrier and a government software platform is either a serious operator or an attention play, and there is not yet evidence to separate those.

Sector Targeting Analysis

RankSectorVictimsShare of labelled
1Technology5026%
2Business Services3820%
3Manufacturing2212%
4Financial Services179%
5Consumer Services137%
6Healthcare105%
7Education95%
8Public Sector74%
9Transportation and Logistics63%
10Hospitality and Tourism53%
11Agriculture and Food53%
12Telecommunications42%
13Construction and Real Estate21%
14Energy21%
Read the counts, not the percentages. 31 of the 221 postings carried no sector label at all.
Technology at 50 is the highest we have recorded for the category, and most of it is not what the label suggests. The bulk is small IT service firms, web and software shops and managed service providers picked up in The Gentlemen's Monday batch and in the bare domain uploads. The entries that matter are the ones holding other people's data: Accela, which runs permitting and licensing for local governments; AnythingIT, which disposes of IT assets for federal agencies and defence contractors; STOKR; and Silicon Integrated Systems.
Financial services at 17 is the sharper signal despite ranking fourth. Storm supplied five of them in four days, all US deposit taking or wealth institutions. The rest spread across an Italian insurance agency, a Vietnamese investment group, a UK mortgage broker, an Ethiopian bank domain, a Brazilian legal services firm and several US accounting and law practices. For a US institution the regulatory position is the thing to internalise: the banking agencies' rule requires notification to the primary federal regulator within 36 hours of determining that a notification incident occurred, and the NCUA rule for credit unions is 72 hours. Both clocks start at determination, not at leak site publication, which means a listing is usually evidence that your clock already expired or never started.
Business services at 38 covers the law firms, accountancies, consultancies and staffing agencies that make up the standing majority of this field, spread this week across more than a dozen operators with nothing in common.
Healthcare at 10 is the lowest this quarter and is almost entirely small: three US clinics, a German pharmaceutical packager, a French medical firm, a Hong Kong biotech, a UK optometrist. AstraZeneca Turkiye is the exception in name recognition, and the claim there describes network configuration data rather than patient or trial records.
Public sector at 7 carries the week's only confirmed intrusion, the Namibian Defence Force, alongside Argentina's education ministry, an Italian comune, the City of Fort Smith in Arkansas, a Brazilian municipal government, a South Korean academic domain and the Peruvian government domain.

Country Distribution

RankCountryVictimsShare
1United States7333%
2Germany115%
3Italy94%
4Brazil94%
5Argentina73%
6Singapore52%
7United Kingdom52%
8Japan52%
9Turkey52%
10Canada52%
11France42%
12India42%
13Vietnam42%
14Sweden42%
15Switzerland42%
A further 31 countries recorded between one and four victims each, including Spain, Australia, Russia, Peru, South Korea, Mexico, Finland, Taiwan, Bulgaria, Chile, Israel, South Africa, Croatia, Norway, Costa Rica, Ukraine, the Czech Republic, Namibia, Iran, Indonesia, Montserrat, Austria, the Netherlands, Venezuela, Luxembourg, Paraguay, Ireland, Trinidad and Tobago, Ethiopia, Hong Kong and Thailand. 18 postings carried no country.
The US share held at 33% against 32% on last week's rebuilt figures, and the underlying count rose from 60 to 73. Qilin and Storm supplied eight each, Akira six.
Germany at 11 is spread across seven operators with no concentration, which is the normal pattern for the country and different from the ZaWoo driven spike we reported in August.
Italy at 9 is roughly back to its usual position after three weeks of unusually low counts, and the composition explains why we were cautious about reading anything into the dip: two come from The Gentlemen's Monday batch, two from Emperador, two from Audit Team's masked Italian stubs, and one each from LockBit, NightSpire and Vexy. Italian entities sit under NIS2 through the national implementation, with ACN as the reporting authority and a 24 hour early warning for essential and important entities.
Vietnam at 4 is worth a line because three of the four come from two crews that arrived this month, N0n and Vexy, and the fourth is a Gentlemen listing. Southeast Asian victims have been rising in this report for a month, and the newer crews are supplying most of that growth.
Namibia appears for the first time in our series, with the Defence Force listing. Namibia has a national CSIRT that responded publicly and quickly here, and the country's data protection legislation is still developing, so the public signal came from the incident response body rather than a privacy regulator.

Notable Claims and Incidents

Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation or an authority has said so.
RansomHouse lists the Namibian Defence Force, and Namibia confirms. Posted September 16, with the group dating the intrusion to September 12. Three days after the listing, Namibia's national cyber security incident response team confirmed the substance of the claim, reported by Namibian outlets including Informante and The Namibian. Confidence: High. This is the only claim in this report that a national authority has stood behind, and it is worth noting what confirmation looked like: not a corporate statement managing disclosure, but an incident response body saying plainly that an intrusion occurred. RansomHouse also listed Pertamina, Indonesia's state oil company, on September 17, which remains unverified.
Two crews claim AECOM on the same day. Posted September 17. Brain Cipher listed aecom.com claiming 670GB. MetaEncryptor listed AECOM claiming approximately 1.22TB. AECOM, a Fortune 500 engineering and infrastructure firm, has not publicly confirmed a breach or detailed any scope, and US class action firms have opened investigations on the strength of the claims alone. Confidence: Medium that the company was compromised, because two unrelated operators listing the same victim on the same day is difficult to explain as coincidence. Low on both data volumes, since neither published a sample and the two figures differ by a factor of nearly two. The most likely explanations are a shared access broker who sold the same access twice, or one crew reposting another's work to build its own reputation. Either would matter to AECOM's suppliers and clients more than the exact terabyte count does.
EndZone lists AT&T and Accela in its first week. Posted September 18. The AT&T listing claims access via a customer experience contractor's account, used to make equipment changes and set up call forwarding, followed by prolonged VPN and virtual desktop access. The Accela listing claims over 50GB including more than two million lines of user data and six million citizen portal requests, and names FBI agents and government workers among those affected. No files were published for either and neither company has confirmed. Confidence: Low. The contractor account detail is specific enough to be worth checking if you are an AT&T supplier, and unsupported enough that it should not be briefed as fact.
Storm lists five US financial institutions in four days. Insight Credit Union on September 15, then First Secure Bank and Trust, First Secure Community Bank, The State Bank and Johnson Investment Counsel on September 18. None has publicly confirmed. Confidence: Low on each individual claim, but the cluster is the finding rather than any one entry. First Secure Bank and Trust and First Secure Community Bank are sister institutions in the same banking group, so those two listings very likely represent one intrusion presented as two victims, which is a counting inflation pattern we have documented repeatedly. Community banks and credit unions share core processors, managed service providers and compliance vendors to a degree that larger institutions do not, and a run like this is worth checking against your own vendor list rather than treating as five unrelated events.
N0n posts ten organisations in one day. Posted September 18, with Fanatics added on the 20th. AstraZeneca Turkiye, the United Federation of Teachers, Argentina's Ministry of Education, Transcom WorldWide, Inter of Venezuela, STOKR, a Vietnamese betting operator and three more, across eight countries. The Fanatics listing claims 46,902 order files totalling 108GB, tied to the consumer account authentication portal, and describes customer account takeover activity. No organisation has confirmed, no regulator filing or named news outlet corroborates any of it, and no samples reached our collection. Confidence: Low across the set. A first appearance with ten large names and no evidence is the profile of a crew building a reputation, and the appropriate response is triage rather than escalation.
Low signal claims this week. 41 of the 221 postings are a bare domain with no company name, no volume and no proof, led by SafePay on 9, Settra on 6 and LockBit and INC Ransom on 5 each. Another 6 are redacted to a few characters. That leaves 174 postings, 79% of the week, that name an organisation. 30 postings rest on a single tracker, including five of INC Ransom's ten and all five of Spirals' September 14 listings.

Top CVEs These Groups Are Exploiting

The table covers this week's active groups where a named source supports the attribution.
CVEProductCVSSWho is using itWhy it matters
CVE-2026-50751Check Point Mobile Access, Remote Access VPN and Spark firewalls9.3Qilin affiliatesAn unauthenticated attacker bypasses authentication and establishes a VPN session. Exploited as a zero day for roughly a month before a patch existed. Check Point products drew two further KEV additions on September 22, just outside this window
CVE-2026-0257Palo Alto Networks PAN-OS GlobalProtectn/aQilinReported by SecurityAffairs as an active Qilin route into corporate networks and on the CISA KEV catalogue since June 2026
CVE-2024-55591Fortinet FortiOS and FortiProxy, authentication bypassn/aThe GentlemenUnit 42 names FortiGate exploitation through this flaw as the group's predominant initial access route, with the operators holding an inventory of already compromised devices and validated VPN credentials so affiliates skip reconnaissance. The group published 30 victims in one day this week from exactly that kind of queue
CVE-2025-7771ThrottleStop.sys driver, renamed ThrottleBlood.sys by the operatorsn/aThe GentlemenHuntress and Unit 42 document this as the group's bring your own vulnerable driver route to kernel level code execution, used to terminate endpoint protection before deployment. Detection belongs on driver load, not on the ransomware binary
CVE-2024-40766SonicWall SonicOS SSLVPN, improper access control9.3AkiraSonicWall's own advisory, Arctic Wolf, Rapid7 and Darktrace tie sustained Akira activity to this flaw, patched in August 2024 and still producing victims two years later. SonicWall's guidance is explicit that patching alone is insufficient and local SSLVPN passwords must be reset
CVE-2023-3519, CVE-2025-5777Citrix NetScaler ADC and Gatewayn/aINC RansomINC incident analysis names public facing application exploitation, including the original NetScaler RCE and Citrix Bleed 2, alongside spear phishing and credentials bought from access brokers
CVE-2024-57727SimpleHelp RMMn/aINC RansomNamed in INC Ransom incident reporting as an initial access route. Remote monitoring and management software is a recurring entry point for this crew and rarely sits inside the patching programme
CVE-2023-28252Windows Common Log File System Driver, privilege escalationn/aBrain CipherNamed in Brain Cipher profiles as the group's escalation route after access through phishing or an access broker. Its payload is LockBit 3.0 derived, which is worth knowing when reading detection guidance
CVE-2026-86218N-able N-central, pre-authentication RCE10.0Not attributedAdded to CISA KEV on September 8 and still unattributed to a named crew. N-central manages endpoints across an entire managed service provider customer base, so it stays on this list until the exploitation window closes. Fixed in 2026.3.1.14
CVSS is marked n/a where we could not confirm a score against a primary source.
CISA added two vulnerabilities to the KEV catalogue inside this window, both on September 18: CVE-2025-39964, a Linux kernel race condition, and CVE-2026-53266, a Linux kernel out of bounds write. Neither is attributed to a ransomware operator, and both matter more for privilege escalation on compromised hosts than for initial access.
Attribution accuracy note. Six of this week's top ten groups have no verifiable initial access CVE behind them. N0n, Spirals and EndZone are all new enough that no public reporting describes their access routes, although EndZone's own listing claims a contractor account rather than an exploit. Audit Team, SafePay and Storm have no named access flaw in public reporting; SafePay's documented tradecraft from Bitdefender and Sygnia is valid credentials, legitimate remote tooling and OneDrive based exfiltration. Settra's entry route, per MOXFIVE, is compromised VPN credentials followed by legitimate administrative tooling.
Two practical notes follow. The single most repeated route into this week's victims is a valid credential, whether phished, bought, or belonging to a contractor. And the one flaw on this list with a CVSS of 10 still has no crew attached to it, which is the cheapest moment to patch anything.

Infrastructure and Operational Shifts

One victim, two leak sites, same day. The AECOM listings by Brain Cipher and MetaEncryptor are the clearest example we have recorded of a pattern that breaks victim counts. Whether an access broker sold the same access twice or one crew reposted the other's material, the result is one organisation appearing as two victims with two different data volumes. We count it once. Most public leak site tallies count it twice, and neither total tells you whether AECOM was breached once, twice or not at all.
The Monday batch is now a three week pattern. The Gentlemen published 30 or more victims on each of the last three Mondays and almost nothing on the days between. Two consequences follow. Weekly totals for this group measure publication scheduling rather than activity, and a defender watching leak sites on a weekday rota will see one enormous day and six quiet ones, which is a poor basis for any trend line. The rest of the field does not behave this way: Qilin's 31 arrived across six days and took the top slot without a batch.
New brands are opening with national scale names. N0n opened with AstraZeneca Turkiye and a US teachers' union. EndZone opened with AT&T and a government software platform. Spirals moved from a South Asian IT services firm in June to US healthcare administration in September. None of the three published evidence. A new site that opens with recognisable names and no samples is making a reputation claim, and the correct handling is to triage the name quietly rather than to brief it upward as a breach.
Bank listings cluster around shared infrastructure. Storm's five financial institutions include two sister banks in one group. Community banks and credit unions concentrate risk in shared core processors and managed service providers, so a cluster of small institution listings in one week is a reason to ask which vendor they have in common before assuming five separate intrusions.
Named organisations rose to 79% of postings. 174 of 221 name a company, against 73% last week. This is a composition effect from which operators were active, not a change in the field's behaviour, and the bulk domain uploaders will reverse it the next time they publish.

Key Takeaways for Defenders

If you are a US community bank or credit union, check your shared vendors this week. Storm listed five institutions in four days and two of them are sister banks. Identify the core processor, managed service provider and compliance vendors you share with the named institutions, ask each whether they have seen anything, and confirm you know who makes the 36 hour notification determination in your organisation and on what evidence. The banking agencies' clock runs from determination, and the NCUA's 72 hour rule works the same way.
Treat a contractor account as a privileged account. EndZone's AT&T claim describes a customer experience contractor's account used to change equipment settings and configure call forwarding. Whether or not that claim holds, the control is the same: inventory third party and outsourced accounts, apply the same MFA, session limits and monitoring you apply to employees, and review what a support tier account can change without a second approval.
Patch the edge flaws, then rotate what sits behind them. CVE-2024-40766 on SonicWall is two years old and still delivering Akira victims. CVE-2024-55591 on FortiOS feeds a queue The Gentlemen is still publishing from, which means a device you patched recently may still be holding valid credentials somebody else captured. Patch, then reset local VPN accounts, then check for sessions that predate the patch.
Keep N-central on the list until it is boring. CVE-2026-86218 is a CVSS 10 pre-authentication RCE on a platform that manages entire endpoint fleets, added to KEV on September 8 and still with no crew publicly attached. Confirm on premises servers are on 2026.3.1.14, review administrator accounts created since early September, and ask any managed service provider you use when they patched.
Do not let one incident count as two, or two brands count as one crew. AECOM was listed by two operators on the same day with different volumes. First Secure's two banks are one group. Two of The Gentlemen's Italian victims reached us twice under different legal names, which is why this report says 221 and not 223. When a name reaches you, establish whether the listing is a fresh intrusion, a resale, a repost or a sister entity of something you already know about, before the number drives the response.
Triage new leak sites, do not escalate them. N0n, Spirals and EndZone between them named AT&T, AstraZeneca Turkiye, a US teachers' union, a government software platform and Fanatics in one week, with no samples and no confirmations. Check whether the name touches you or a supplier, log it, and wait for evidence. A new crew's opening week is the least reliable data in this field.
Most of that work is triage before it is defence. Somebody has to read 221 postings, work out which three touch your organisation or your suppliers, and cross reference each named group against the flaws actually exposed on your perimeter.

Where Scrutex Fits

Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface and your named suppliers, so a listing that names your domain or a vendor's domain reaches you as an alert rather than as a line in a weekly roundup. Vulnerability Insights prioritises flaws like the edge and RMM CVEs above by real world exploitability against your exposed assets rather than by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.

Frequently Asked Questions

How many ransomware attacks were there in the week of September 14 to 20, 2026? We tracked 221 unique victim postings across 47 active groups and 46 countries. That is up 19% from 186 for September 7 to 13, rebuilt on the same feeds and rules. These are leak site postings rather than confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Which ransomware group was most active? Qilin, with 31, just ahead of The Gentlemen on 30. They got there differently: Qilin spread 31 across six days with no run larger than seven, while The Gentlemen published all 30 in a single batch on Monday September 14 across 20 countries.
Was AECOM breached? AECOM has not confirmed anything. Two unrelated crews, Brain Cipher and MetaEncryptor, listed the company on September 17 claiming 670GB and 1.22TB respectively. We rate it medium confidence that a compromise occurred, because two independent listings on one day are hard to explain otherwise, and low confidence on both data volumes, since neither published a sample.
Did AT&T get hacked? A new group called EndZone listed AT&T on September 18, claiming access through a customer experience contractor's account followed by VPN and virtual desktop access. No files were published and AT&T has not confirmed. We rate the claim low confidence.
Why were five US banks listed in one week? Storm listed Insight Credit Union, First Secure Bank and Trust, First Secure Community Bank, The State Bank and Johnson Investment Counsel between September 15 and 18. None has confirmed. Two of the five are sister banks in the same group, so the cluster probably represents fewer than five intrusions, and it is worth checking for a shared core processor or managed service provider rather than assuming five separate events.
Which claim this week is actually confirmed? The Namibian Defence Force. RansomHouse listed it on September 16 and Namibia's national cyber security incident response team confirmed the intrusion three days later. It is the only claim in this report that a national authority has stood behind.
Which CVEs are these groups exploiting? Qilin uses CVE-2026-50751 and CVE-2026-0257, The Gentlemen uses CVE-2024-55591 on FortiOS and CVE-2025-7771 for driver abuse, Akira continues on CVE-2024-40766 on SonicWall, INC Ransom uses Citrix NetScaler and SimpleHelp flaws, and Brain Cipher uses CVE-2023-28252 for escalation. Six of the top ten groups have no verifiable access CVE, and the unattributed CVE-2026-86218 in N-able N-central remains the highest severity open item.
Where can I get this in real time instead of weekly? Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, so a relevant listing reaches you when it is posted rather than in the following Monday's roundup.