Ransomwere Weekly
156 views

Ransomware Attacks This Week: 247 Victims Across 52 Groups (August 24 to 30, 2026)

By ScrutexPublished
This is the Scrutex ransomware weekly for the August 24 to 30, 2026 window. Our CTI team tracked 247 unique ransomware and extortion victim postings across 52 active groups and 49 countries during the period. On the same counting rules we used last week the figure is 272, down 5% on last week's 287. The 247 you see in every table below is lower because we tightened three counting decisions this week, and we explain all three rather than quietly banking the drop.
The week has an unusual shape. Saturday August 29 was the heaviest day of the seven with 51 postings, 21% of the total, and Sunday August 30 was the lightest with 10. That is close to an inversion of the normal pattern, where volume builds through the working week and falls away at the weekend. Two operators produced the Saturday: The Gentlemen posted 15 and ZaWoo posted 12, so 27 of 51 came from two leak sites publishing on the same afternoon.
247 posts, 52 groups, 49 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.

This Week at a Glance

MetricValue
Total unique victims posted247
Change on prior weekDown 5% on like for like rules (272 against 287), down 14% on this week's tightened rules
Active groups52
Countries hit49
Heaviest single daySaturday August 29 (51 posts, 21% of the week)
Second heaviest dayWednesday August 26 (47 posts)
Quietest daySunday August 30 (10 posts)
Most targeted countryUnited States (72 victims, 29% of postings)
Most targeted sectorManufacturing (38 named), Business Services (29), Technology (28)
Top group by volumeQilin (42 posts across all seven days)
Largest single day runThe Gentlemen (15 on August 29)
Notable claimsATF, McKesson, Jack Henry and Associates, Elekta, Neogen, Glassdoor, KBZ Bank, AYA Bank
The week did not build. Monday opened at 38, Tuesday dropped to 27, Wednesday climbed to 47, Thursday held at 40, Friday eased to 34, Saturday jumped to 51, and Sunday collapsed to 10. The line is a sawtooth, not a ramp.
Saturday is the part worth explaining. Weekend posting is not new, and several crews have run Saturday publication for months because it lands a victim's crisis call outside business hours. What is different here is that Saturday was the peak rather than a secondary bump, and that two operators produced more than half of it. The Gentlemen published 15 victims across ten countries.
The top five groups took 43% of volume against 42% last week, so concentration was flat. That is the number to read alongside the headline decline. Volume fell, the shape of the field did not. Qilin posted 42 against 35 last week, its highest weekly count this quarter, and did it without a single run larger than nine.
The tail stayed long. 52 groups posted, 30 of them three victims or fewer, and 14 posted exactly once. Those 30 groups together produced 50 postings, 20% of the week spread across more than half the active brands. That distribution has been stable for two months and is the reason a single-vendor group watchlist keeps missing things.

Group Activity Breakdown

The top five groups produced 106 of 247 postings, 43% of the week. Below them, 30 groups posted three or fewer victims each, together accounting for 50 postings.
RankGroupVictimsShareNotable Activity
1Qilin4217%Every day of the week, no run larger than nine. The ATF listing, Brazosport College, WireCo, Newton County School System, Globalport Terminals
2The Gentlemen239%15 on August 29 across ten countries. Glassdoor, G R Infraprojects, ESB Puerto Rico, Thai Film Industries
3ZaWoo166%First appearance. 12 on August 29, 4 on August 30, nine of them German. Domain only listings
4KryBit135%12 of the 13 on August 26 alone. India, Brazil, Thailand, Vietnam, Egypt, Gabon, Guatemala
5Akira125%Spread over five days. US and German manufacturers, one oral surgery practice, one law firm
6Silent Ransom Group104%Redacted law firm stubs only, posted twice under two leak brands. No encryption, no samples
7Storm83%Two runs. City of Mitchell, a hospice in Indiana, three German firms, two Australian
8Dark Project62%All six US, all in two days. Engineering, staffing, a CPA firm, a dental practice
9INC Ransom62%Spread across four days. FFKR Architects, Ruby Seven Studios, Oilquip, one South African manufacturer
10The Crew62%All six on August 24. KBZ Bank, AYA Bank, Parami University, Cyprus Airways, an Indonesian police database
11Chaos62%Bare domains only, no company names. US, UK, Australia, Netherlands, China
12LockBit62%Four on August 27. Two US healthcare domains, one Czech, one Dutch, one Belgian, one Mexican
13DireWolf52%Three hospitals in one run on August 30, plus THQ Nordic and an Italian law firm
14Orova52%Taiwan and Hong Kong. Two accountancy and property groups, one hotel operator
15MedusaLocker52%All five on August 27. Australia, Brazil, Ghana, Mexico, Thailand
16ShinyHunters42%McKesson, Jack Henry, Elekta AB, Neogen. One deadline, four names, no samples
A long tail of groups (Booba Project, DragonForce, ShadowByt3$, IAH647, Emperador, Global, Panzer, Audit Team, Global Secret Group, Majinahanashi, Arcus Media, Beast, DeadLock, PayoutsKing, SafePay, Ailock, Aurora, Eclipse, Black X, Doommageddon, Rhysida, Falcon, Blackwater, Coinbase Cartel, CyberLeek, Genesis, Abyss, Pear, Meowciety403, Anubis, Money Message, Unsafe, 3AM, Lynx, M3RX and WallStreet) each posted between one and four victims.
Three observations:
Qilin posted its best week of the quarter by showing up every day. 42 victims, all seven days, no run larger than nine, and the same profile it has held since April: European and Latin American mid market manufacturers, professional services firms, regional financial firms and a steady trickle of education and local government. It has now led our chart every week this quarter without once producing the largest single day run. The ATF listing sits inside that pattern, not outside it. Qilin does not appear to have changed anything about how it operates. It simply landed on a target with a name.
ZaWoo is a listing event, not a campaign. Sixteen postings from a leak site nobody was tracking a week ago, twelve of them in one Saturday batch, nine of them German, almost all posted as a bare domain with no company name, no data volume and no sample. Four more listings on the same site carried nothing but a random placeholder identifier where the victim name should be. That is the signature of a new operator loading a backlog, and the backlog is usually bought rather than earned: an access broker's inventory published all at once to establish the brand. It does not mean sixteen German firms were compromised in the last week. It means sixteen listings appeared, and the underlying intrusions could be months old or, in some cases, could be resale of somebody else's work. Treat every one as worth triage and none as confirmed.

New and Emerging Groups

Four names in this section, and only one of them is a conventional ransomware crew.
ZaWoo. First observed August 29, sixteen postings in 48 hours, and a victim list that is unusually coherent: nine German firms plus one Austrian, one Czech, one Brazilian, one Canadian, one Chinese and one New Zealand. The German set is small and mid market industrial, a machine tool sensor maker, an engineering office, a workshop group, a winter road services firm, a property agent, a mountain hotel and a software house. Every listing is a bare domain. No encryption claim, no volume figure, no sample, no countdown. Only two of the four trackers carried the site at all. For a defender in the German Mittelstand the useful read is that somebody has assembled a regional access list and is now monetising it publicly. Watch for the follow up: a new site that posts and never publishes data is usually testing which victims answer the phone.
CyberLeek. Twelve leak site postings this week, and one incident behind all twelve. CyberLeek is the handle attached to the August 2026 Grand Theft Auto VI material, published in staged drops of gameplay footage and map images alongside a manifesto about digital pre-orders and paid single player content, and a memecoin. The twelve postings are the drops themselves, labelled by asset, not twelve organisations. We collapsed them to one row, which is why CyberLeek appears once in our tables rather than in the top five. Take-Two has responded with DMCA subpoenas to Microsoft and Discord rather than any negotiation, with a September 4 compliance date. The tradecraft lesson is the packaging: an actor with one data set can present it as a dozen victims, and a leak site tracker will faithfully count it that way.
The Crew. Six postings, all on August 24, all carried by a single tracker with no samples reaching the feed: KBZ Bank and AYA Bank, Myanmar's two largest private banks, Parami University, Htoo Hospitality, Cyprus Airways, and a data set described as an Indonesian police officer database. This reads as hacktivist adjacent data dumping rather than extortion. There is no encryption claim and no ransom figure. KBZ says its own checks found no compromise of bank systems. AYA acknowledged a cyberattack earlier in 2026 after a separate claim. For a Southeast Asian financial institution the point is the reporting gap: neither Myanmar nor several of its neighbours run a mandatory breach notification regime, so a leak site listing may be the only public signal that exists.
Falcon. Two postings, both on August 29, both US listed companies: DistributionNOW, an energy products distributor, and Globus Medical, a musculoskeletal implant manufacturer. Two victims is not a trend, but the selection is worth noting because it is the opposite of the ZaWoo pattern. Not a bought list of small firms, but two mid cap public companies posted on the same day by a brand with almost no history. Either an affiliate moved to a new operator, or somebody is opening with their best material.

Sector Targeting Analysis

RankSectorVictimsShare of labelled
1Manufacturing3821%
2Business Services2916%
3Technology2815%
4Healthcare2313%
5Consumer Services137%
6Agriculture and Food127%
7Financial Services127%
8Transportation and Logistics105%
9Hospitality and Tourism53%
10Education53%
11Public Sector42%
12Energy42%
Read the counts, not the percentages. 64 of the 247 postings carried no sector label at all, and the missing labels are not random. They concentrate in the crews that post bare domains and redacted stubs, so the visible sector mix is skewed toward operators who publish tidy victim profiles. Qilin, The Gentlemen and Akira are over represented in this table simply because they fill in the fields.
Manufacturing at 38 is the volume leader and has been for most of the quarter. The reason is structural rather than strategic. Mid market manufacturers run flat networks connecting an office domain to production systems, they carry old Windows estates on the plant floor because the machine vendor will not certify anything newer, and their tolerance for downtime is measured in hours. Qilin, Akira, Storm and ZaWoo all fed this bucket, and none of them appear to be selecting for it. Manufacturing simply pays.
Healthcare at 23 is smaller than manufacturing and carries more consequence. The set includes McKesson, which is a distribution and health technology business sitting upstream of thousands of pharmacies and providers, Elekta, which builds radiotherapy systems, Globus Medical, three hospitals posted by DireWolf in a single run on August 30 including the Hospital Clinico Universidad de Chile and Erdem Hospital in Turkey, and two Indian clinical businesses posted by KryBit. Four of the 23 are healthcare technology, device or distribution businesses rather than care providers. That is the pattern to brief upward: attacking the supplier reaches more patient records than attacking the clinic, and it moves the incident out of your own logs and into somebody else's.
Financial services at 12 looks quiet until you read the names. Jack Henry and Associates provides core banking and payment processing to a large share of US community banks and credit unions. FE CREDIT is one of Vietnam's largest consumer finance companies. KBZ and AYA are Myanmar's two largest private banks. Northern Leasing Systems, Brookview Financial, DAB Investments, Providence Investments and Finoday Capital fill out the rest. One vendor listing in that set has more downstream reach than the other eleven combined.
Public sector at four is the smallest labelled category and contains the week's largest name. The ATF listing sits here alongside the Government of Vojvodina in Serbia, Portugal's Directorate-General for Education and the City of Mitchell in the United States. Local government keeps appearing at a rate of two or three a week and almost never makes the headlines.

Country Distribution

RankCountryVictimsShare
1United States7229%
2Germany208%
3United Kingdom156%
4Brazil104%
5Mexico83%
6Australia62%
7Canada52%
8Argentina52%
9Italy52%
10India52%
11China42%
12Thailand42%
13Russia31%
14Malaysia31%
15Taiwan31%
A further 34 countries recorded between one and three victims each, including South Korea, the Czech Republic, Turkey, France, Portugal, South Africa, the UAE, Serbia, the Netherlands, Romania, Vietnam, Chile, Sweden, Austria, Hong Kong, Bolivia, Indonesia, Gabon, Guatemala, Egypt, Colombia, Belgium, Ghana, Singapore, the Philippines, Uruguay, Spain, Finland, Moldova, Malta, Puerto Rico, Switzerland, North Macedonia and New Zealand. 27 postings carried no country at all.
The US share fell from 38% to 29% in one week. Almost none of that is a change in US risk. Two things moved. First, the feed that carried most of last week's Italian and European small business volume contributed nothing this week, which removed rows from the denominator unevenly. Second, ZaWoo's German batch and KryBit's global batch both landed inside this window and neither touched the United States. Underlying US volume went from 109 to 72, which is a real decline, but it is a decline against a week that contained two large US heavy runs rather than evidence of a trend.
Germany at 20 is the number to look at, and it is one operator plus one. ZaWoo supplied nine of the twenty in a single weekend and Storm supplied three more. Strip those and Germany sits at eight, in line with its usual position. For German readers the practical consequence is the NIS2 clock: an essential or important entity has 24 hours from awareness to file an early warning with the BSI and 72 hours to follow with an incident notification, and a leak site listing that names your domain starts that awareness discussion whether or not you can find anything in your own logs yet.
Italy at five is the sharpest move in the table, down from 23. This is a collection artefact and we are stating it plainly rather than writing a story about Italian resilience. The tracker that specialises in Italian victims contributed two rows this week against eighteen last week. Italian volume is very likely closer to its usual mid teens. We will report the corrected figure when the feed returns.
India at five covers Simplex Engineering, G R Infraprojects, Jindal Life Science, the cancer care network Karkinos and Finoday Capital, three of them posted by KryBit in its August 26 run. Indian entities work to the tightest clock in this report: CERT-In directions require reporting of a covered incident within six hours of noticing it, and that clock does not wait for confirmation. If your domain appears on a leak site, the six hours has started.
Elsewhere, Australia's six sit under APRA CPS 234's 72 hour notification for regulated entities, Brazil's ten under the ANPD's LGPD reporting expectations, and the Myanmar listings under no mandatory regime at all. Four Chinese victims in one week is worth a note on its own: three of the four came from a single crew calling itself Global, and Chinese organisations appear on Western leak sites rarely enough that a small cluster is unusual.

Notable Claims and Incidents

Every entry below is a claim the actor posted. None is a confirmed breach unless the named organisation has said so, and where they have, we say which part they confirmed.
Qilin lists the US Bureau of Alcohol, Tobacco, Firearms and Explosives. Posted August 26. Qilin added the ATF to its leak site on the same day the agency publicly confirmed a major cybersecurity incident affecting a standalone system. The listing carried no file samples, no data volume, no proof screenshots and no public ransom demand, which is a departure from Qilin's normal practice of posting directory listings. The ATF has not attributed its incident to Qilin, and the Department of Justice has not linked the two events. Reporting notes this is the third US federal law enforcement body to confirm a compromise inside six months, after the FBI's Digital Collection System Network and DHS's Homeland Security Information Network. Confidence: Low on the linkage between Qilin and the ATF incident, because the two facts arrived on the same day and nothing else connects them yet. The agency incident itself is confirmed by the agency.
ShinyHunters lists McKesson and claims 284 million patient related records. Posted August 28. ShinyHunters claims it compromised multiple McKesson employees' Okta single sign on accounts through voice phishing, then pulled roughly 284 million patient related records from the company's Snowflake environment plus a parallel data set from Salesforce, across a four day window between August 21 and August 25. McKesson has disclosed a cybersecurity incident involving unauthorised access to third party applications and data theft, says it discovered the incident on August 25, and describes the investigation as early. Confidence: Medium. The company has confirmed an incident and the described route matches the crew's established tradecraft. The 284 million figure is the actor's number and no sample supports it.
ShinyHunters lists Jack Henry and Associates with a September 1 deadline. Posted August 28, alongside Elekta AB and Neogen, all four given until September 1 to make contact, with the Jack Henry post labelled a final warning. No sample, no volume, no description of the data. Jack Henry provides core banking, payments and digital channel software to thousands of US community banks and credit unions. Confidence: Low on the claim itself. The relevant exposure question is not whether Jack Henry paid. It is whether any of its customers' data sits inside whatever was taken, and that question belongs on the desk of every institution that runs Jack Henry software, today, regardless of how the claim resolves.
CyberLeek publishes Grand Theft Auto VI material across twelve postings. Posted August 24. Eleven listings labelled by asset plus one in game location, all part of one staged leak campaign of unreleased footage and map material that began in mid August. The actor pairs the drops with a manifesto against digital pre-orders and paywalled single player content, and with a memecoin, and has asked for roughly 400 XMR to open a conversation about advertising space on future drops. Take-Two has answered with DMCA subpoenas to Microsoft and Discord seeking user identifiers, with a September 4 compliance date. Confidence: Medium that the material is genuine, given the volume of independent coverage and the company's legal response. Low on how the actor obtained it, because no access route has been established publicly.
The Crew lists KBZ Bank, AYA Bank and four others in one day. Posted August 24. Six listings covering Myanmar's two largest private banks, Parami University, Htoo Hospitality, Cyprus Airways and an Indonesian police officer database. The actor has described sample material including a small number of banking and internet banking account records with email addresses, usernames and passwords. KBZ says its continuous checks found no compromise or unauthorised access to bank systems. One tracker carried the set and no samples reached our collection. Confidence: Low. A small credential sample and a large bank name is the cheapest claim in this field to make and the most expensive to disprove.
Low signal claims this week. Beyond the five above, 43 postings rest on a single tracker with no corroboration, 27 carry no country, and several carry victim labels that are not organisations at all: a city name, the single word Health, a placeholder identifier. 41 of the 247 listings are a bare domain with no company name, no volume and no proof, led by KryBit on 13, ZaWoo on 11, and Chaos and LockBit on 6 each. Domain only postings are the lowest signal category in this report. They still need triage, because the domain is real, but they inflate counts and they tell you nothing about scope.

Top CVEs These Groups Are Exploiting

Edge devices remain the front door for the crews that encrypt. The table covers this week's active groups where a named source supports the attribution.
CVEProductCVSSWho is using itWhy it matters
CVE-2026-50751Check Point VPN, certificate validation logic error9.3Qilin affiliatesSecPod research documents a Qilin affiliate using it for initial access, then credential harvesting and lateral movement. An unauthenticated attacker bypasses password authentication entirely and establishes a VPN session. It was exploited as a zero day for roughly a month before a patch existed, and CISA gave federal agencies three days to remediate
CVE-2026-0257Palo Alto Networks PAN-OS GlobalProtectn/aQilinReported by SecurityAffairs as an active Qilin route into corporate networks and added to the CISA Known Exploited Vulnerabilities catalogue in June 2026
CVE-2024-55591Fortinet FortiOS and FortiProxy, authentication bypassn/aThe Gentlemen, QilinUnit 42 names FortiGate exploitation through this flaw as The Gentlemen's predominant initial access route. Group-IB reporting describes the operators maintaining a curated inventory of already compromised FortiGate devices and validated brute forced VPN credentials, so affiliates skip reconnaissance entirely
CVE-2025-7771ThrottleStop.sys driver, renamed ThrottleBlood.sys by the operatorsn/aThe GentlemenHuntress and Unit 42 document this as the group's bring your own vulnerable driver route to kernel level code execution, used to disable endpoint protection before deployment. Detection belongs on driver load, not on the ransomware binary
CVE-2024-40766SonicWall SonicOS SSLVPN, improper access controln/aAkiraRapid7, Arctic Wolf and SonicWall's own advisory tie sustained Akira activity to this flaw. Multiple responders report MFA bypass where the second factor is a one time password, with privilege escalation and deployment inside hours of first access
CVE-2023-3519, CVE-2023-48788Citrix NetScaler, Fortinet FortiClient EMSn/aINC RansomOlder flaws, still named in INC Ransom incident analysis as initial access alongside spear phishing and purchased credentials. Reporting this year also places INC downstream of harvested Fortinet credentials rather than fresh exploitation
Attribution accuracy note. Five of this week's top ten groups have no verifiable CVE behind them, and that is the more useful finding than the table above.
Three practical notes follow from that split. Credential reuse and help desk social engineering now sit ahead of edge exploitation for the crews producing the biggest names, even though edge exploitation still produces more victims by count. Vulnerable driver abuse is the current defence evasion default and is detectable at driver load if you are watching. And every edge appliance in the table above is a device most organisations patch on a quarterly cycle while the exploitation window is measured in days.

Infrastructure and Operational Shifts

The weekend is now a publication slot, not a quiet period. Saturday carried 21% of the week and Sunday carried 4%. That is not random. Publishing on a Saturday afternoon puts the victim's first crisis call outside business hours, buys the actor a full weekend of unanswered inbound, and lands the story in Monday morning news cycles. If your leak site monitoring runs on a weekday schedule, you learned about ZaWoo's German batch on Monday. The affected firms had already had it published for 48 hours.
Identity is the front door for the largest names. McKesson through vishing against Okta, then Salesforce and Snowflake. Silent Ransom Group through help desk impersonation, then commercial remote access tooling. Neither chain has a CVE in it, neither triggers a perimeter alert, and both end in a very large data set leaving through an authorised session. The security control that would have caught either is a help desk verification procedure that does not accept a phone call as proof of identity.
Encryption free extortion held at 15%. 38 of 247 postings came from crews that do not deploy an encryptor: ShinyHunters, Silent Ransom Group, The Crew, IAH647, Audit Team, Global, Emperador, Coinbase Cartel, CyberLeek and Meowciety403. Nothing is down, nothing is encrypted, there is no recovery to run, and the entire incident is a negotiation about a data set the attacker already has. If your incident response plan starts with restore from backup, that branch does not exist for a sixth of this field.
New brands arrive fully loaded. ZaWoo went from zero to sixteen listings in 48 hours. Falcon opened with two US listed companies. A new leak site is rarely a new operation. It is usually a new brand over existing access, either an affiliate moving between programs or an access broker deciding to extort directly. The practical consequence is that a group watchlist built from last quarter's names covers less of the field every month.
Domain only listings keep growing. 41 of 247 postings this week are a bare domain and nothing else: no company name, no sector, no volume. KryBit contributed 13, ZaWoo 11, Chaos and LockBit 6 each. It points to automated intake from an access or credential feed rather than hands on keyboard reconnaissance, and it is why 27 of our 247 rows carry no country and 64 carry no sector.

Key Takeaways for Defenders

Patch the five edge flaws in the table above, in KEV order, and verify rather than assume. CVE-2026-50751 on Check Point VPN carries a three day federal remediation deadline and was exploited before a patch existed. CVE-2024-55591 on FortiOS is the route The Gentlemen used to reach 23 victims this week from an inventory of already compromised devices, which means patching alone does not evict an attacker who is already holding valid credentials. Rotate VPN credentials on any appliance that was unpatched during the exposure window.
Make the help desk an authentication boundary. Silent Ransom Group and ShinyHunters produced two of the week's five biggest claims and neither touched a vulnerability. Both called somebody and asked to be let in. Require a callback to a directory number, an out of band verification for any password or MFA reset, and a hard rule that remote access software is never installed at the request of an inbound caller. Then test it with your own call.
Inventory what your SaaS platforms can reach. The McKesson claim describes Okta accounts reaching Salesforce and Snowflake, and a data volume that no on premise system would have held. Know which identities can export in bulk from your customer data platform and your warehouse, cap what a single session can pull, and alert on volume rather than on login.
Watch your suppliers' leak site listings as if they were your own incidents. Jack Henry serves thousands of US community banks. McKesson sits upstream of thousands of pharmacies and providers. Elekta's systems run inside cancer centres. Four of this week's 23 healthcare victims were technology, device or distribution businesses rather than care providers. Build the list of vendors whose compromise becomes your notification obligation, and monitor those names specifically.
Add a branch to the incident response plan for the case where nothing is encrypted. 38 postings this week involved no encryptor. There is no outage, no restore, no obvious trigger, and the first indication is often the leak site post itself. Decide now who owns that call, what the legal and notification path looks like, and what you will say publicly, because the timeline in that scenario is set by the attacker's countdown and not by your recovery.
Treat a domain only listing as an open question, not a confirmed breach and not noise. 41 listings this week were a bare domain with no proof. The correct response is neither a public statement nor a shrug. It is a targeted hunt over the 30 to 90 days before the posting date, focused on VPN authentication, help desk tickets and bulk data movement, with a documented finding either way.
Most of that work is triage before it is defence. Somebody has to read 247 postings, work out which three touch your organisation or your suppliers, and cross reference each named group against the flaws actually exposed on your perimeter.

Where Scrutex Fits

Scrutex Threat Insights monitors ransomware leak sites and dark web sources continuously and maps what it finds against your own attack surface, so a listing that names your domain or a supplier's domain reaches you as an alert rather than as a line in a weekly roundup. Vulnerability Insights prioritises the flaws in the table above by real world exploitability against your exposed assets rather than by raw CVSS. Neither will tell you whether a claim is true. Both will tell you, quickly, whether it is about you.

Frequently Asked Questions

How many ransomware attacks were there in the week of August 24 to 30, 2026? We tracked 247 unique victim postings across 52 active groups and 49 countries. On the same counting rules we used last week the figure is 272, against 287 for August 17 to 23. These are leak site postings rather than confirmed compromises, and the underlying intrusion is usually 30 to 90 days older than the posting date.
Why is this week's number lower than last week's? Two reasons, and only one of them is about criminal activity. Underlying volume fell modestly, roughly 5% on like for like rules. The rest comes from us: we stopped counting one Grand Theft Auto VI leak as twelve victims, folded two leak brands run by the same operator into one, and dropped four placeholder listings. A separate collection change also removed most of this week's Italian volume, which is a feed problem rather than a change in Italian risk.
Which ransomware group was most active in August 2026? Qilin, with 42 postings, its highest weekly count this quarter. It posted every day of the week with no run larger than nine, which is the pattern it has held since April. The Gentlemen was second with 23, of which 15 came in a single Saturday run.
Did Qilin really breach the ATF? Qilin listed the Bureau of Alcohol, Tobacco, Firearms and Explosives on August 26, the same day the agency confirmed a major cybersecurity incident on a standalone system. Qilin posted no samples, no data volume and no ransom demand, and neither the ATF nor the Department of Justice has attributed its incident to Qilin. The agency incident is confirmed. The link to Qilin is not, and we rate it low confidence.
How reliable is ZaWoo's sudden appearance in third place? Treat it as a listing event. Sixteen postings from a site nobody was tracking a week ago, twelve of them in one Saturday batch, nine of them German, nearly all posted as a bare domain with no sample or data volume. That pattern usually means a new brand publishing existing access rather than sixteen fresh intrusions. Every listing still deserves triage. None of them is confirmed.
Which CVEs are these groups exploiting right now? The named source attributions this week are CVE-2026-50751 on Check Point VPN and CVE-2026-0257 on PAN-OS GlobalProtect for Qilin, CVE-2024-55591 on FortiOS and CVE-2025-7771 for driver abuse by The Gentlemen, and CVE-2024-40766 on SonicWall SSLVPN for Akira. Five of the top ten groups have no verifiable CVE behind them, because they use voice phishing, help desk impersonation and purchased credentials instead.
Which sectors were hit hardest this week? Manufacturing at 38 postings, business services at 29, technology at 28 and healthcare at 23. Read those as counts rather than shares, because 64 of the 247 postings carried no sector label. Healthcare is the set to watch despite its rank, because four of its 23 entries are technology, device and distribution businesses sitting upstream of many providers.
Where can I get this in real time instead of weekly? Scrutex Threat Insights monitors leak sites and dark web sources continuously and matches findings against your own asset inventory and your named suppliers, so a relevant listing reaches you when it is posted rather than in the following Monday's roundup.

Tags: ransomware, ransomware weekly, Qilin, The Gentlemen, ZaWoo, KryBit, Akira, Silent Ransom Group, ShinyHunters, CyberLeek, The Crew, Storm, INC Ransom, LockBit, DireWolf, Falcon, CVE-2026-50751, CVE-2026-0257, CVE-2024-55591, CVE-2025-7771, CVE-2024-40766, dark web monitoring, leak site monitoring