Ransomware Attacks This Week: 314 Victims Across 50 Groups (August 10 to 16, 2026)
By ScruteX Published
Summary
This is the Scrutex ransomware weekly for the August 10 to 16, 2026 window. Our CTI team tracked 314 unique ransomware victim postings across 50 active groups during the period. That is down 13% on last week's 362, but the shape of the week matters more than the total.
Wednesday August 12 produced 119 postings, 38% of the whole week, and two groups supplied 87 of them. Cl0p posted 46 and CRPX0 posted 41. Those two runs have nothing in common except the date. Cl0p's run is the resolution of a story we opened last week: the 40 masked names it published on August 5 came back on August 12 with the masks removed. CRPX0's run is a brand new leak site emptying its backlog in one go.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific flaws these groups are exploiting to get in. Two things stand out. First, the flaw count that matters this week is two, not one: CVE-2026-12569 in PTC Windchill still drives Cl0p, and CVE-2026-72898 in Metabase became a CISA Known Exploited Vulnerability on August 11 after being exploited as a zero day with a severity score of 10.0. Second, the established operators did not go anywhere. Qilin posted 37 across six of seven days, The Gentlemen 22, DireWolf 17.
314 posts, 50 groups, 45 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names, resolved company names against bare domains that referred to the same victim, and dropped two re-listings that repeated an already-counted victim with the sector blanked. Where a single group backfills a large batch on one day, we flag it. This week two groups did, so read the headline total with that in mind.
In This Post
| Section | What it covers |
|---|---|
| This Week at a Glance | Headline numbers and the August 12 concentration |
| Group Activity Breakdown | Who posted most, and what sits behind each run |
| The Cl0p Unmasking | What the 46 named Windchill victims tell you |
| New and Emerging Groups | CRPX0, DireWolf, Majinahanashi, Settra, and BlackNevas |
| Sector Targeting Analysis | Which industries took the named hits |
| Country Distribution | Where the 45 countries fall |
| Notable Claims and Incidents | Five named claims with confidence lines |
| Headlines Beyond the Leak Sites | The Gunra advisory and the Metabase zero day |
| Top CVEs These Groups Are Exploiting | The flaws driving initial access, led by CVE-2026-12569 and CVE-2026-72898 |
| Infrastructure and Operational Shifts | What is changing in how these crews work |
| Key Takeaways for Defenders | The short action list |
This Week at a Glance
| Metric | Value |
|---|---|
| Total unique victims posted | 314 |
| Change on prior week | Down 13% (from 362) |
| Active groups | 50 |
| Countries hit | 45 |
| Heaviest single day | August 12 (119 posts, 87 from two groups) |
| Second heaviest day | August 14 (51 posts, 17 from The Gentlemen) |
| Quietest day | August 15 (17 posts) |
| Most targeted country | United States (103 victims, 33% of postings) |
| Most targeted sector | Technology (48) |
| Top group by volume | Cl0p (47 posts, 46 of them on one day) |
| New brands in the top eight | CRPX0, DireWolf, Majinahanashi |
| Notable claims | Shell, GE, Philips, Fiserv, Zebra, Baxter, Carhartt, Statista, Quirónsalud |
The week had one spike and two shoulders. Monday August 10 opened at 43, with DireWolf supplying 10 in its first run. Tuesday fell to 24. Wednesday August 12 produced 119, and 87 of those came from Cl0p and CRPX0 alone. Thursday dropped to 18, the second quietest day of the week. Friday recovered to 51, of which The Gentlemen supplied 17. Saturday fell to 17. Sunday August 16 closed at 42, with Qilin posting 19 of them.
Read the 13% decline carefully. Strip the two August 12 batch runs and the underlying field sits near 227, against roughly 247 on the same basis last week. The drop is real but modest. What actually changed is concentration in a different place: the top five groups took 52% of volume, almost exactly last week's 50%, but two of those five are brands that did not exist in our report a fortnight ago.
The tail also got longer. 50 groups posted this week against 43 last week, 27 of them posted three victims or fewer, and 11 posted exactly one. More brands, each doing less, is the direction this field has been moving all year.
Group Activity Breakdown
The top five groups produced 52% of the week's volume (164 of 314). Below them the field is more crowded than it has been: 34 groups posted four or fewer victims each, together accounting for 74 postings.
| Rank | Group | Victims | Share | Notable Activity |
|---|---|---|---|---|
| 1 | Cl0p | 47 | 15% | 46 on August 12, the PTC Windchill campaign renamed in full. Shell, GE, Philips, Fiserv, Zebra, Ingersoll Rand, Largan, Mammut, Toast |
| 2 | CRPX0 | 41 | 13% | All on August 12. Turkish conglomerates and banks alongside US dental practices and small law firms. No country or sector labels published |
| 3 | Qilin | 37 | 12% | Active on six of seven days, closing with 19 on August 16. Italian, German and US mid-market industrial and publishing firms |
| 4 | The Gentlemen | 22 | 7% | 17 on August 14 across Malaysia, Morocco, Kosovo, Japan, Brazil, Australia and the US. Consumer services heavy |
| 5 | DireWolf | 17 | 5% | Two runs, 10 on August 10 and 6 on August 15. Statista, Quirónsalud, TOTVS, AliveCor, Health Carousel |
| 6 | Majinahanashi | 14 | 4% | 10 on August 12. European mid-market: Son-Video, Grupo Starfoods, Camandona, Schmitz & Nittenwilm |
| 7 | Storm | 9 | 3% | 6 on August 14. US and Canadian healthcare, legal and manufacturing |
| 8 | Settra | 9 | 3% | 6 on August 11, all bare domains. US, German, Dutch and Ecuadorian mid-market |
| 9 | INC Ransom | 7 | 2% | Split across August 12 and 13, US professional services with an Australian and Canadian tail |
| 10 | Akira | 6 | 2% | Steady low-volume posting, US mid-market plus one UK imaging provider |
| 11 | BlackNevas | 6 | 2% | Every listing names the victim's IT services provider alongside the victim |
| 12 | ShinyHunters | 5 | 2% | All five on August 14: Baxter International, Carhartt, Cook Medical, Sharecare, Metabase |
| 13 | Panzer | 5 | 2% | Spread across four days, Thailand, Cyprus, Germany and the Czech Republic |
| 14 | KryBit | 5 | 2% | Argentina, Finland, Taiwan, India and Singapore, all bare domains |
| 15 | LockBit | 5 | 2% | All five on August 16, German, French and Italian small business |
| 16 | MedusaLocker | 5 | 2% | All five on August 16, a single European and South African cluster |
A long tail of groups (Global Secret Group, LeakedData, RansomHouse, Space Bears, Payload, Coinbase Cartel, Xpl0itrs, Ethics, Genesis, Silent Ransom Group, Anubis, Bravox, Emperador, Unsafe, WallStreet, DragonForce, Interlock, Orova, NightSpire, Ailock, Rhysida, BlueWhale, Blackwater, DeadLock, Aurora, PayoutsKing, Kairos, M3RX, SafePay, Barracuda, Securotrop, Eclipse and Helix) each posted between one and four victims.
Three observations:
One day carried the week, and it carried two unrelated stories. August 12 produced 119 postings. Cl0p's 46 are the naming phase of a mass exploitation campaign that began in June. CRPX0's 41 are a new leak site publishing its whole backlog at once. Reading the day as a single event would tell you the wrong thing about both. Volume spikes on leak sites are almost always publication decisions, not attack dates.
Qilin is the constant again. 37 postings across six of the seven days, no batch behaviour until the closing 19 on August 16, and a victim profile that has not changed in months: European and US mid-market manufacturers, publishers and logistics firms. Qilin has now finished at or near the top of our chart every week this quarter without ever producing the largest single-day run. When you benchmark operators, that steadiness is the more useful signal than a spike.
The Gentlemen halved. 22 postings against 39 last week, with the same batch pattern (17 in one August 14 run) and a noticeably different victim mix: coffee chains, kidswear retailers, auto dealerships and a KFC franchise in Kosovo rather than last week's industrial suppliers. One quiet week is not a trend. It is worth watching whether the group's intake shifted or its posting simply slipped.
The Cl0p Unmasking
Last week Cl0p posted 40 victims with partially redacted names such as
fis******* and jpm*******. On August 12 it republished the campaign with company names attached. Our data set holds 46 Cl0p postings on that date and one more on August 13. The named list confirms what the masked run implied. It is a product lifecycle management campaign, and the victim profile is exactly the PTC Windchill and FlexPLM customer base: Shell, GE, Philips, Zebra, Ingersoll Rand, Largan Precision, Mammut, Suunto, Thermos, LifeStraw, Aldo, Mamas & Papas, Atomberg, Starkey and Toast. Security reporting puts the campaign at 43 organisations, with 391GB listed against GE.com and 874GB against Fiserv, described as project files, CAD files and Windchill data.
Two details in the list are worth more than the household names.
Cl0p listed the implementation partners, not only the manufacturers. Among the 47 postings are ArcherGrey, SPK and Associates, and 9altitudes. Those are PTC consultancies. They implement, host and support Windchill for other companies. A single consultancy can hold engineering data belonging to dozens of clients, none of whom appear on the leak site under their own name. If your PLM environment is run by a partner, your exposure to this campaign is not measured by whether your own domain is listed.
The masked stubs resolved differently than the early reporting suggested.
fis******* is FISERV.COM. jpm******* is JPMGROUP.CO.IN. Both were reasonable to read as larger institutions a week ago, and both were wrong. Cl0p uses masking to start negotiation without burning the victim publicly, and the side effect is a week of confident public misattribution. If you are tempted to act on a masked listing, the useful action is to check your own PLM exposure, not to guess the name. Confidence on the campaign itself: High. PTC patched CVE-2026-12569 on June 17, CISA added it to the Known Exploited Vulnerabilities catalog at the end of June, and multiple vendors have documented the JSP web shells and the extortion emails titled "Windchill PDMLink module serious data leak". Confidence on any individual data volume: Low. Those are attacker figures, and Fiserv has publicly disputed the scope of what was taken.
New and Emerging Groups
CRPX0: a new leak site that emptied its backlog in one day
CRPX0 launched a leak site on both the clear web and Tor on August 7 and listed 41 victims in our window, all on August 12. It publishes no country and no sector label, which is why 41 of this week's 56 unlabelled-country postings belong to it.
The victim list splits into two halves that do not fit together. One half is Turkish large enterprise: ASELSAN, Turkish Airlines, TOGG, A101, Doğan Holding, Anadolu Sigorta, Kuveyt Türk, Anadolubank and Finansbank. The other half is US small business: eight dental practices, several small law firms, insurance agencies, a hospice provider and a data entry company. Johnson & Johnson and Hyundai appear alongside both, listed without qualification.
Reporting describes CRPX0 as a double extortion operation that moved into ransomware from earlier fraud activity, and notes it put victim data up for sale on August 15 when its deadlines expired. Independent trackers put its total at 47 listings since the site opened.
Treat CRPX0 as unverified and treat the largest names on the list as the least likely to be genuine. A brand new leak site whose first publication run pairs a national aerospace and defence contractor with a suburban orthodontist is describing an aggregated data set, not a coherent intrusion campaign. The small US victims may well be real. The Turkish conglomerates and the two global brands need independent confirmation before anyone acts on them, and the Hyundai claim has been reported as roughly 1.5GB of assessment data, which is not the profile of a manufacturer-wide compromise.
DireWolf: mid-size targets, recognisable names
DireWolf posted 17 victims across two runs, 10 on August 10 and 6 on August 15. It is not new, having first appeared around May 2025 as a double extortion operation, but this is the most visible week it has had in our data.
The victim mix is more recognisable than the volume suggests: Statista, the German data portal; Quirónsalud, one of Spain's largest private healthcare groups; TOTVS, the Brazilian enterprise software vendor; AliveCor, the US cardiac monitoring firm; Health Carousel, a healthcare staffing company; and DXS International, a UK clinical systems supplier. Six of the 17 are healthcare or health technology, four are technology, three are financial services.
The pattern worth logging is the concentration in health data and healthcare supply. Quirónsalud and AliveCor hold patient records directly. Health Carousel and DXS sit next to them. A group posting six healthcare-adjacent victims in a week is either working a sector deliberately or has intake from a source that skews that way. Neither theory is confirmed. Both mean healthcare providers should read DireWolf listings as a supplier question, not only a peer question.
Majinahanashi and Settra: two new brands, two different profiles
Both entered our top eight for the first time.
Majinahanashi posted 14 victims, 10 of them on August 12, and every listing carries a full company name and a domain. The spread is European and Latin American mid-market: Son-Video in France, Grupo Starfoods in Portugal, Camandona in Switzerland, Schmitz & Nittenwilm in Germany, UAB Biotecha in Lithuania, Kaliman Caribe in Colombia, plus a US jeweller and an Indian conglomerate. Named victims with working domains and a plausible size band make this the more credible of the two.
Settra posted 9, six of them on August 11, and every listing is a bare domain with no company name. Reporting describes it as a brand that emerged during 2026 and appeared quickly in claim tracking alongside other new names, with victims across North America, Europe, Africa and Asia in construction, business services and e-commerce. Our nine fit that: US tax and technology firms, a German lighting manufacturer, a Dutch energy consultancy and an Ecuadorian distributor.
The difference between them is the difference we flagged last week between Dark Project and Orion. Full names with domains and stated sectors give defenders something to verify. Bare domains with no encryption indicator give them nothing. Judge the listing, not the logo.
BlackNevas: the only group naming the MSP as well as the victim
BlackNevas posted six victims, and every one of its listings follows the same format: the victim's name, then the phrase "serviced by an IT company" followed by that provider's name. This week that produced Enteroptyx and Westbrook Greenhouse Systems in the US, Computer Country and Networks and the Rutherford Group in Canada, Portable Intelligence, and ASCOM in Italy alongside its provider Emilcom.
BlackNevas first appeared in November 2024 as a Trigona derivative and runs as a centralised operation rather than a RaaS. It does not host its own leak site and instead publishes through partner infrastructure.
Six postings is a small number and this is the item on the list with the widest gap between volume and significance. A group that consistently names the managed service provider is telling you how it got in. If you are an MSP with remote management access into client environments, your client's leak site listing is a description of your own perimeter.
Sector Targeting Analysis
Across the 314 victim postings this week:
| Sector | Victims | Share of all postings | Share of classified |
|---|---|---|---|
| Technology | 48 | 15% | 23% |
| Manufacturing | 34 | 11% | 16% |
| Business Services | 29 | 9% | 14% |
| Healthcare | 25 | 8% | 12% |
| Consumer Services | 23 | 7% | 11% |
| Financial Services | 13 | 4% | 6% |
| Agriculture and Food | 11 | 4% | 5% |
| Hospitality and Tourism | 8 | 3% | 4% |
| Transportation and Logistics | 6 | 2% | 3% |
| Energy | 5 | 2% | 2% |
| Public Sector | 5 | 2% | 2% |
| Education | 4 | 1% | 2% |
A caveat on these shares. 103 of the 314 postings carried no usable sector label, 41 of them from CRPX0 alone, which publishes none. Only 211 postings are classified, so the third column is the more honest read. Note also that our two sources use different sector vocabularies, and one combines construction with real estate.
What this tells us:
Technology took the top slot for the first time in months, at 48. Manufacturing led every recent week, and it did not collapse this week so much as get overtaken. The technology number is inflated by composition rather than by a single campaign: Cl0p's Windchill listings include PLM consultancies and IT services firms, Settra and KryBit posted software and hosting providers, and DireWolf added TOTVS, Swyft, Merge and DXS. Several of these sit upstream of their own customers, so an IT services listing is worth checking for downstream reach into every client that vendor touches.
Manufacturing at 34 is down from 63, and the drop is a Cl0p artefact. Last week The Gentlemen, Everest and Dark Project all ran industrial batches. This week The Gentlemen went consumer, and Cl0p's manufacturers are largely classified as technology or consumer goods by the feeds because the listings are bare domains for well-known brands. Read manufacturing exposure through the Windchill campaign rather than through this row.
Healthcare at 25 is where the sharpest single-actor concentration sits. DireWolf supplied six, ShinyHunters three, Storm two. The listings are a mix this week rather than the usual small-practice skew: Baxter International and Cook Medical are large device manufacturers, Quirónsalud is a national hospital group, and AliveCor and PayrHealth are health technology. That is a different risk profile from a week of dental practices.
Business Services at 29 keeps the legal pattern going. Riker Danzig, Reminger, Hinman Straub, Tapper Cuddy, Cambria Law, Holstrom Block & Parke, Schorr Law, Simpkins Law and FLP Law Group all appear across LeakedData, Silent Ransom Group, Storm, INC Ransom, Ethics and CRPX0. Six different brands touching law firms in one week is a sector signal, not an operator signal.
Financial Services at 13 understates the week badly. Fiserv is classified here, but the sector's real exposure this week runs through Cl0p's payments and banking technology listings and CRPX0's four Turkish banks, most of which carry no sector label at all.
Country Distribution
The United States accounts for 103 of 314 postings, 33% of the total and 40% of the 258 postings where a country was recorded. That is down from last week's 40% and 49%, and it is closer to the long-run share of roughly 29% than we have seen in a month.
| Rank | Country | Victims |
|---|---|---|
| 1 | United States | 103 |
| 2 | Italy | 22 |
| 3 | Germany | 16 |
| 4 | United Kingdom | 12 |
| 5 | India | 8 |
| 6 | Canada | 8 |
| 7 | Brazil | 6 |
| 8 | Australia | 6 |
| 9 | Switzerland | 5 |
| 10 | Netherlands | 5 |
| 11 | France | 5 |
| 12 | Japan | 5 |
| 13 | Philippines | 4 |
| 14 | Spain | 4 |
| 15 | Austria | 3 |
A further 30 countries recorded one to three victims each, including Chile, Belgium, Mexico, Taiwan, Singapore, Greece, Thailand, Argentina, Finland, Colombia, Malaysia, South Korea, Hong Kong, Cyprus, Pakistan, China, Slovakia, Hungary, Portugal, Lithuania, Turkey, Poland, Jordan, Denmark, Morocco, Kosovo, Albania, South Africa, the Czech Republic and Ecuador.
Three points stand out.
Italy at 22 is the highest non-US figure we have recorded this year. It is also genuinely spread: Qilin posted six, Cl0p four, The Gentlemen three, Bravox two, Majinahanashi two, Space Bears two, and BlackNevas, LockBit and Xpl0itrs one each. Nine operators reaching one country in one week is a different signal from one operator posting a batch. Italian mid-market manufacturing and publishing is taking sustained pressure.
Turkey is the biggest gap in this table. It shows one victim, and that single entry is probably a feed mislabel. CRPX0's nine Turkish enterprise listings carry no country label at all, so they fall out of the country data entirely. If those claims hold up, Turkey belongs in the top five. We are not putting it there on an unverified leak site dump, but you should not read the 1 as the answer either.
The US decline is a composition effect, not a de-escalation. Cl0p's Windchill campaign is global by nature, since PLM servers sit wherever the engineering does, and CRPX0's 41 postings are unlabelled. Strip both August 12 runs and the US share of the remainder returns to roughly the level we have been reporting all quarter.
The breadth, 45 countries in one week, shows how affiliate-driven extortion now operates globally. Geographic distribution tracks revenue opportunity, not threat actor location. For readers outside the United States the practical point is unchanged: map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, APRA CPS 234 in Australia, before an incident forces the question.
Notable Claims and Incidents
The five items below all appear on public leak sites or in named vendor reporting. We state what the actor claimed, the data categories where they were given, and end each with a confidence line.
1. Cl0p names Shell, GE, Philips and Fiserv in the Windchill campaign
On August 12, Cl0p republished its PTC Windchill and FlexPLM campaign with company names attached, listing 46 organisations in our data set on that date. Security reporting puts the campaign at 43 organisations and cites 391GB against GE.com and 874GB against Fiserv, described as project files, CAD files, Windchill files and software backups. The entry vector is CVE-2026-12569, exploited as a zero day from early June before PTC patched it on June 17.
Confidence: High on the campaign, Low on individual volumes. The vulnerability, the patch date, the KEV listing and the web shell activity are all documented by first-party sources. The data volumes are attacker claims, and Fiserv has publicly stated it found no evidence that customer, banking, transaction or personal data was compromised. What defenders should take from this is not the volume figures but the target class: internet-exposed product lifecycle management, including instances run for you by a consultancy.
2. CRPX0 lists Turkish conglomerates alongside US dental practices
CRPX0 published 41 victims on August 12, spanning ASELSAN, Turkish Airlines, TOGG, Kuveyt Türk, Finansbank, Anadolubank, Doğan Holding, Anadolu Sigorta, A101, Hyundai and Johnson & Johnson at one end, and eight US dental practices, several small law firms and a hospice provider at the other. The group opened its leak site on August 7 and put victim data up for sale on August 15 when its deadlines expired.
Confidence: Low. The listings are real postings on a real site, but a first publication run that pairs a defence contractor with a suburban orthodontic practice is characteristic of aggregated or resold data rather than a single intrusion campaign. Reporting on the Hyundai claim describes roughly 1.5GB of assessment data, which does not match a manufacturer-wide compromise. Validate independently before treating any of the large names as a current breach, and note that the small US victims are the ones most likely to be genuine.
3. ShinyHunters names Baxter, Carhartt, Cook Medical and Sharecare
On August 14, ShinyHunters listed five US organisations. Reporting describes over 7.1 million Salesforce records taken from Baxter International, and a 3.3 million dollar demand against Carhartt covering millions of customer records plus employee and corporate data, which Carhartt did not negotiate. Cook Medical and Sharecare were named the same day.
Confidence: Medium for Carhartt and Baxter, Low for Cook Medical. The Carhartt claim has been reported in detail with a stated demand and a refusal. Cook Medical has issued no public confirmation and no regulator has confirmed an incident. The common thread is SaaS rather than infrastructure: these are connected-application and cloud CRM data sets, not encrypted file servers. Your backup strategy is not the control that matters here. Your connected-app inventory in Salesforce is.
4. DireWolf claims Statista, Quirónsalud and TOTVS
DireWolf listed Statista on August 10, Quirónsalud the same day, and TOTVS on August 15, alongside AliveCor, Health Carousel, DXS International and Leafwell. The postings are extortion notices threatening publication unless negotiations begin, in the standard double extortion format.
Confidence: Medium. The listings are consistent across trackers and the group has a track record going back to May 2025, but none of the three named organisations has confirmed an incident and no sample data accompanied the notices at the time of writing. The reason to brief this one is scope rather than certainty: Quirónsalud operates hospitals, Statista holds licensed research and subscriber data, and TOTVS is enterprise software sitting inside Brazilian mid-market IT estates.
5. Metabase appears on the ShinyHunters site as its CVE hits the KEV catalog
Metabase disclosed CVE-2026-72898 on August 6, an unauthenticated SQL injection in the password reset endpoint of self-hosted deployments that yields administrator access. It carries a severity score of 10.0 and was exploited as a zero day. CISA added it to the Known Exploited Vulnerabilities catalog on August 11. A Metabase listing appeared on the ShinyHunters blog on August 14.
Confidence: Low on the listing, High on the vulnerability. Analysts describe the leak site entry as a placeholder with no scope named and around 7GB of data, which does not fit the pattern of the other listings on that site. The listing may be opportunistic branding on the back of a well-publicised flaw. The flaw itself is not in question, and thousands of self-hosted instances were exposed when it landed.
Headlines Beyond the Leak Sites
Two developments shape how you should read this week's numbers even though they are not victim counts.
Six agencies published a joint advisory on Gunra. On August 10, CISA, the FBI, DC3, the NSA, the US Secret Service and the Republic of Korea National Police Agency released advisory AA26-222A on Gunra ransomware. Gunra appeared in April 2025 as a Conti-derived double extortion variant and formalised into a RaaS by January 2026. Two findings matter beyond the group itself. Gunra gains initial access by exploiting Fortinet authentication bypass flaws CVE-2024-55591 and CVE-2025-24472, and it defeats multi-factor authentication by modifying the authentication processing files on the victim's own VDI portal server so that one specific attacker-chosen one-time password always succeeds. Separately, a key generation flaw in the Linux variant means victims who preserved encrypted files may be able to reconstruct decryption keys from timestamps without paying.
That MFA finding is the item to brief. Every MFA control assumes the authentication server is trustworthy. Gunra attacks that assumption directly, and once the server is modified, MFA continues to report success while providing no protection at all. Integrity monitoring on authentication infrastructure is the control that catches it. Nothing on the endpoint will.
Two more edge flaws went under active exploitation. CISA added CVE-2026-20349 to the KEV catalog on August 11, an insufficient error checking flaw in the Cisco ASA and FTD remote access SSL VPN service that lets an unauthenticated attacker force a reload, with a severity score of 8.6. Cisco confirmed active exploitation in August. It is a denial of service rather than an access vector, so we have not put it in the actor table below, but an internet-facing VPN gateway that can be crashed by anyone is an availability problem worth patching on the same cycle. CISA also added CVE-2026-8037, a command injection flaw in Progress LoadMaster, on August 7. No ransomware group has been tied to either.
Top CVEs These Groups Are Exploiting
Two flaws dominate this week. Alongside them, the established operators continue to work the same set of VPN and firewall flaws they have worked all year. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution is tied to a named vendor or government source, with a note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific actor, we left it out of this table.
| CVE | Product | Severity | Who is using it | Why it matters |
|---|---|---|---|---|
| CVE-2026-12569 | PTC Windchill and FlexPLM | 9.3 | Cl0p | Improper input validation giving unauthenticated remote code execution on internet-exposed product lifecycle management servers. A Cl0p affiliate chained a FlexPLM information disclosure with the Windchill RCE to plant JSP web shells and exfiltrate engineering and product data. Exploited as a zero day from early June, patched June 17, added to the CISA KEV catalog at the end of June. This produced all 47 Cl0p listings this week (PTC; CISA KEV). |
| CVE-2026-72898 | Metabase (self-hosted, 0.58 through 0.63) | 10.0 | Exploited in the wild as a zero day; a Metabase listing appeared on the ShinyHunters blog | Unauthenticated SQL injection through the /api/session/reset_password endpoint, giving administrator takeover of the instance. Disclosed August 6, added to the CISA KEV catalog August 11. Metabase instances hold direct query access to production databases, so admin on the BI tool is usually read access to everything it connects to. The ShinyHunters tie is a leak site listing only, not a confirmed intrusion (Metabase GHSA-vwf4-m7j8-wcjf; CISA KEV). |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | 9.6 | Gunra, Qilin, The Gentlemen | Authentication bypass on the FortiGate management interface yielding super-admin privileges. Named as a primary Gunra initial access vector in CISA advisory AA26-222A, and the long-standing vector for Qilin and The Gentlemen (CISA AA26-222A; Fortinet PSIRT; Microsoft). |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy | 8.1 | Gunra | The second authentication bypass named in the Gunra advisory, disclosed February 2025 and still producing access more than a year later. Used in the same intrusion chain that then modifies the VDI authentication server to defeat MFA (CISA AA26-222A). |
| CVE-2024-40766 | SonicWall SonicOS SSL VPN | 9.3 | Akira | Improper access control affecting SonicOS 5, 6 and 7. Akira's SonicWall campaign resurfaced through August, with the current activity traced back to exploitation of this flaw and to migrated local accounts whose passwords were never reset after upgrade (SonicWall; Rapid7; Arete). |
| CVE-2026-50751 | Check Point Remote Access VPN and Mobile Access | Critical | Qilin (affiliate) | Authentication bypass disclosed by Check Point on June 8 after tracing exploitation back to May 7. A Qilin affiliate was linked to exploitation in the May to June window, giving the group a second VPN option alongside Fortinet (Check Point; analyst-reported group tie). |
| CVE-2024-21762 | Fortinet FortiOS SSL VPN | 9.8 | Qilin | Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. Still producing access two years after the patch shipped, because the exposed device population never fully closed. |
A note on attribution accuracy. Most of this week's volume has no verifiable exploit attribution at all. CRPX0, Majinahanashi, Settra, Storm and KryBit are newer or smaller brands with no published CVE tie, and their posting patterns fit access broker intake, credential feeds or phishing rather than a named flaw. ShinyHunters and Coinbase Cartel are not exploiting a software vulnerability in any of this week's listings: both work through valid credentials and connected SaaS applications, which means patching does nothing and the controls that matter are connected-app review, token hygiene and infostealer monitoring. Reporting on Coinbase Cartel found that roughly 80% of its victims had a prior infostealer infection.
A few practical notes:
Business intelligence tools are now perimeter systems. Metabase sits between your users and your production databases by design. An unauthenticated admin takeover on the BI layer is read access to every data source that instance is wired into, without touching a single database credential. Confirm your version, patch to 0.58.28, 0.59.25, 0.60.21, 0.61.15, 0.62.13 or 0.63.10 or the matching Enterprise build, and check whether the instance was ever reachable from the internet.
Product lifecycle management is still the crown jewel nobody inventories. Cl0p's named list this week includes global manufacturers and the consultancies that run Windchill for them. Confirm the June 17 patch, hunt for JSP web shells regardless of patch status, and ask your PLM implementation partner the same two questions about their environment.
Your VPN is where the ransomware volume still comes from. Fortinet, SonicWall and Check Point flaws drove access for Gunra, Akira and Qilin this week. Three of those four CVEs are more than eighteen months old. The exposure is not a disclosure problem, it is an inventory problem.
MFA is not a control if the authentication server is compromised. The Gunra advisory documents an attacker editing the auth server so a chosen OTP always works. Add file integrity monitoring on authentication infrastructure and alert on changes to authentication processing files.
We report these as the flaws most associated with this week's most active actors. Knowing they are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch office firewall, an internet-exposed PLM server nobody in security knew was reachable, or a self-hosted BI instance a data team stood up two years ago, is the part most teams cannot answer on a Monday morning.
Infrastructure and Operational Shifts
Masked listings are now a standard negotiation stage, and they generate a week of public misattribution. Cl0p masked 40 names on August 5 and unmasked them on August 12. In between, reputable outlets attributed
fis******* to FIS Global and the 874GB claim followed it into a dozen articles. The listing was Fiserv. The lesson for defenders is procedural: a masked listing is a signal to audit your own exposure to the named campaign, and nothing more. It is not a signal to brief an executive on a company name. The barrier to launching a leak site keeps falling, and the tail keeps growing. 50 groups posted this week against 43 last week and 34 posted four or fewer victims. CRPX0 went from launching a site on August 7 to second place on our chart on August 12. A brand name tells you nothing about capability, history or whether the data is real.
Extortion without encryption is now roughly a fifth of the field. ShinyHunters, Coinbase Cartel, LeakedData, Silent Ransom Group, CRPX0, Xpl0itrs and Helix produced 62 postings this week, covering 60 organisations, and none of those listings depends on an encryptor. Your ransomware playbook needs a branch for the case where nothing is encrypted, nothing is down, and the only pressure is a data set the attacker already holds.
The supply chain listing is becoming explicit. BlackNevas names the victim's IT services provider in every posting. Cl0p listed PLM consultancies alongside their clients' brands. ShinyHunters is publishing SaaS platform data rather than file servers. Three different operators, three different mechanisms, one shared shape: the company that gets named is increasingly not the company that was breached.
Authentication infrastructure is now a target in its own right. Gunra modifies the auth server to defeat MFA. Coinbase Cartel buys the credentials from infostealer logs. Silent Ransom Group talks the help desk into resetting them. Three distinct routes to the same outcome, none of which a patch cycle addresses.
Key Takeaways for Defenders
Patch Metabase today if you self-host it. CVE-2026-72898 has a severity score of 10.0, needs no authentication, was exploited as a zero day before disclosure on August 6, and entered the CISA KEV catalog on August 11. Admin on your BI tool is read access to every database behind it. Patch to the fixed release for your branch, then check access logs on
/api/session/reset_password for the period before you patched. Ask your PLM partner the Windchill questions, not just your own team. Cl0p's named list includes ArcherGrey, SPK and Associates and 9altitudes, all PTC implementation partners. If a consultancy hosts or supports your Windchill or FlexPLM environment, your engineering data is in scope whether or not your domain appears on the leak site. Confirm the June 17 patch and hunt for JSP web shells in both estates.
Add integrity monitoring to your authentication servers. The Gunra advisory documents actors editing authentication processing files so a chosen one-time password always validates. MFA keeps reporting success throughout. Alert on any change to those files, and review the Fortinet flaws named in the advisory, CVE-2024-55591 and CVE-2025-24472, against your own estate.
Inventory your connected SaaS applications, starting with Salesforce. ShinyHunters claimed over 7.1 million Salesforce records from Baxter and named four more organisations the same day. Coinbase Cartel works from infostealer credentials with roughly 80% of its victims showing a prior infection. Neither is stopped by a backup, an endpoint agent or a patch. Both are stopped by knowing which third-party apps hold tokens into your tenant.
Treat a new brand's first big run as unproven. CRPX0 opened a leak site on August 7 and posted 41 victims on August 12, pairing a national defence contractor with suburban dental practices. That is what an aggregated data set looks like, not a campaign. Verify before you escalate, and remember the small victims on those lists are usually the real ones.
If you are an MSP, read your client's listing as your own. BlackNevas names the IT services provider in every posting it publishes. Six listings this week each identified a provider by name. The provider's remote access is the shared component, and it is on the leak site in plain text.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old. Cl0p exploited CVE-2026-12569 from early June and the names landed on August 12, roughly ten weeks later. Watching external exposure, leaked credentials and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 314 posts down to the few that touch your domains, your brands and your vendors, then matching those actors to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at https://scrutex.ai/signupNo credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: scrutex.ai/solution/threat.
Frequently Asked Questions
How many ransomware attacks happened the week of August 10 to 16, 2026?
314 unique victim postings appeared on dark web leak sites in that window, across 50 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is down 13% on last week's 362. Two batch runs on August 12, Cl0p's 46 and CRPX0's 41, account for 87 of those postings, so the underlying field sits closer to 227.
Which ransomware group is most active right now?
Cl0p topped this week with 47 postings, but 46 of them landed on a single day as the naming phase of one mass exploitation campaign. On sustained activity, Qilin remains the more accurate answer: 37 postings across six of the seven days with no batching until the final day, continuing the pattern that has kept it at or near the top of our chart every week this quarter.
Who did Cl0p name in the PTC Windchill campaign?
On August 12, Cl0p republished its masked August 5 listings with company names attached. The named victims include Shell, GE, Philips, Fiserv, Zebra, Ingersoll Rand, Largan Precision, Mammut, Suunto, Thermos, LifeStraw, Aldo, Mamas & Papas, Atomberg, Starkey and Toast, alongside PTC implementation partners ArcherGrey, SPK and Associates and 9altitudes. Security reporting puts the campaign at 43 organisations, citing 391GB against GE.com and 874GB against Fiserv. The data volumes are attacker claims and Fiserv has disputed the scope.
Was it FIS Global or Fiserv?
Fiserv. Last week Cl0p's listing showed only the masked stub
fis*******, and early reporting attributed it to FIS Global. The August 12 unmasking shows the listing is FISERV.COM. Fiserv has said its review found no evidence that customer, banking, transaction or personal data was compromised. The related jpm******* stub resolved to JPMGROUP.CO.IN, an Indian group, not JPMorgan. What is CVE-2026-72898 and why does it matter?
It is an unauthenticated SQL injection vulnerability in self-hosted Metabase, reachable through the
/api/session/reset_password endpoint, that gives an attacker administrator access to the instance. It carries a severity score of 10.0, affects versions 0.58 through 0.63, was disclosed on August 6 after being exploited as a zero day, and CISA added it to the Known Exploited Vulnerabilities catalog on August 11. It matters because Metabase holds live query access to production databases, so administrator access to the BI tool is usually read access to everything behind it. Fixed releases are 0.58.28, 0.59.25, 0.60.21, 0.61.15, 0.62.13 and 0.63.10, plus the matching Enterprise builds. Who is CRPX0?
A new extortion brand that opened a leak site on the clear web and Tor on August 7 and published 41 victims on August 12. The list pairs Turkish large enterprise, including ASELSAN, Turkish Airlines, TOGG, Kuveyt Türk, Finansbank, Anadolubank, Doğan Holding and A101, with US dental practices, small law firms and insurance agencies. Reporting describes it as a double extortion operation that moved into ransomware from earlier fraud activity, and it put victim data up for sale on August 15. Treat the large names as unverified.
What did CISA say about Gunra ransomware?
Advisory AA26-222A, published August 10 by CISA, the FBI, DC3, the NSA, the US Secret Service and the Republic of Korea National Police Agency, describes Gunra as a Conti-derived double extortion operation that became a RaaS in January 2026. It gains initial access through Fortinet authentication bypass flaws CVE-2024-55591 and CVE-2025-24472, and defeats MFA by editing authentication processing files on the victim's own VDI portal server so a chosen one-time password always validates. A key generation flaw in the Linux variant may let victims recover files without paying.
What CVEs are these groups exploiting?
CVE-2026-12569 in PTC Windchill and FlexPLM drove all 47 Cl0p listings. CVE-2026-72898 in Metabase entered the KEV catalog on August 11 with a 10.0 severity score. Gunra uses Fortinet CVE-2024-55591 and CVE-2025-24472. Akira is working SonicWall CVE-2024-40766. Qilin uses Fortinet CVE-2024-21762 and CVE-2024-55591 plus Check Point CVE-2026-50751. CRPX0, Majinahanashi, Settra, Storm and KryBit have no published exploit attribution. ShinyHunters and Coinbase Cartel are not exploiting a software flaw at all: they work through valid credentials and connected SaaS applications.
What sectors should I worry about most this week?
Technology led at 48 postings, ahead of Manufacturing at 34, Business Services at 29 and Healthcare at 25. Technology took the top slot largely because Cl0p's Windchill listings include PLM consultancies and IT services firms that sit upstream of their own customers. 103 of the 314 postings carried no sector label, 41 of them from CRPX0, so read the counts alongside the percentages.
Where can I get this data in real time?
Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands and vendors, so you see only the postings that touch your domains, brands or supply chain.