Ransomware weekly
1054 views

Ransomware Attacks This Week: 215 Victims Across 38 Groups (July 27 to August 2, 2026)

By ScruteX Published

Summary

This is the Scrutex ransomware weekly for the July 27 to August 2, 2026 window. Our CTI team tracked 215 unique ransomware victim claims across 38 active groups during the period. The Gentlemen posted 43 victims, their highest weekly total we have recorded, including a 32-name spree on Friday July 31. A brand most teams have never heard of, CRPxO, took second place outright with 31. Between them those two accounted for 34% of everything posted this week.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific CVEs these groups are exploiting to get in. The standout story is concentration. Last week read as three balanced campaigns. This week reads as two operators emptying queues on two specific days: Monday July 27 carried 56 postings and Friday July 31 carried 54, together half the week's volume, while Wednesday July 29 fell to 16. Manufacturing took the heaviest sector hit at 41 named victims, nearly double second-place technology. United States firms made up 43% of all victims, well above their long-run share of roughly 29%.
215 posts, 38 groups, 43 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names, resolved company names against bare domains that referred to the same victim, and dropped two re-listings that repeated an already-counted victim with the sector blanked. Where a single group backfills a large batch on one day, we flag it. This week two groups did, so read the headline total with that in mind.

In This Post

Section What it covers
This Week at a Glance Headline numbers and the two-day concentration
Group Activity Breakdown Who posted most, and the stories worth reading
New and Emerging Groups CRPxO, GammaX, and the week's newer names
Sector Targeting Analysis Which industries took the named hits
Country Distribution Where the 43 countries fall
Notable Claims and Incidents Five named claims with confidence lines
Headlines Beyond the Leak Sites Reported incidents that did not surface in our count
Top CVEs These Groups Are Exploiting The flaws driving initial access, including two new ones
Infrastructure and Operational Shifts What is changing in how these crews work
Key Takeaways for Defenders The short action list

This Week at a Glance

Metric Value
Total unique victims posted 215
Change on prior week Up 16% (from 185)
Active groups 38
Countries hit 43
Heaviest single day July 27 (56 posts, 20 from CRPxO)
Second heaviest day July 31 (54 posts, 32 from The Gentlemen)
Quietest day July 29 (16 posts)
Most targeted country United States (43% of postings)
Most targeted sector Manufacturing (41)
Top group by volume The Gentlemen (43 posts)
Notable major-brand claims Ernst & Young, Pertamina, Alcon, Coca-Cola (Fairlife), Malaysian Nuclear Agency
The week ran in two bursts. Monday July 27 opened with 56 postings, 20 of them from CRPxO and another 12 from NightSpire. Friday July 31 closed with 54, of which The Gentlemen alone posted 32. Together those two days carried 110 of 215 victims, just over half the week. The three days in between held between 16 and 30.
That shape matters for the headline. Two operators cleared queues on two days. Strip The Gentlemen's Friday spree and CRPxO's Monday batch, and the underlying field sits near 163. The top group took 20% of the week's volume on its own, and the top five together took 59%.

Group Activity Breakdown

The top 5 groups produced 59% of the week's volume (127 of 215 postings),Below the top five the list stays crowded: 19 groups posted two or fewer victims each, and 13 posted exactly one. The leak site space remains fragmented after the LockBit and ALPHV takedowns of 2024 to 2025. New brands keep entering, and CRPxO's arrival straight into second place is this week's clearest example.
Rank Group Victims Share Notable Activity
1 The Gentlemen 43 20% 32 posted in one Friday spree on July 31, manufacturing-heavy with company profiles attached: Pertamina (Indonesia), Malaysian Nuclear Agency, Philippine Savings Bank
2 CRPxO 31 14% New brand, 20 on Monday July 27 and 10 on Friday, US healthcare and legal firms plus a seven-name Turkish banking and industrial cluster
3 Qilin 29 13% Spread across six of seven days, thin per-victim profiles, France, Belgium, Spain, Australia, and US mid-market
4 INC Ransom 12 6% US-weighted, healthcare and manufacturing, plus a county government and a Swiss and Latin American tail
5 NightSpire 12 6% Entire run posted on July 27, manufacturing and engineering across India, Singapore, Thailand, UK, and US
6 SafePay 9 4% Single-day German cluster on July 27: retail, museums, schools, and industrial suppliers
7 ShinyHunters 6 3% Salesforce-linked extortion with specific record counts: Ernst & Young, Alcon, Questel, RingCentral, Brinks Home, Lumenis
8 Coinbase Cartel 6 3% UK and US construction and fertility clinics, plus the CEN and Cenelec standards bodies
9 KryBit 6 3% All six on August 2, South Africa, Nigeria, Singapore, France, and Mexico
10 DeadLock 5 2% Chile, UK, Turkey, Spain, and Italy mid-market
11 DragonForce 4 2% Sharply down from last week's 27, three of four posted July 31
12 Aurora 4 2% Netherlands and German manufacturing, laser and analytics firms
A long tail of groups (Booba Project, CMD Organization, GammaX, Genesis, Gunra, Akira, Chaos, Anubis, Play, LockBit, Insomnia, Termite, Interlock, Morpheus, Black X, Space Bears, BlackNevas, Global Secret Group, Silent Ransom Group, Section 9, Kyber, Kairos, Cl0p, LeakNet, Pear, and roughly a dozen more) each posted between one and four victims.
Three observations:
The Gentlemen ran the largest single-day spree we have recorded from them. Their 43 postings included 32 on Friday July 31, and the list leans hard into manufacturing and industrial suppliers: precision tooling, battery makers, fish processing, concrete pumping, signage, and CNC machining across the US, India, Poland, Israel, and Peru. They also named Pertamina, Indonesia's state oil and gas major, and the Malaysian Nuclear Agency. The Gentlemen, which Microsoft tracks as Storm-2697 and PRODAFT tracks as LARVA-368, attach company profiles and revenue figures to their postings, which makes their listings read as researched rather than scraped. Their Fortinet foothold and self-propagating Go encryptor are the mechanism behind that volume. See the CVE section.
CRPxO arrived at second place from nowhere. 31 victims in its first heavy week, 21 of them US and seven Turkish. The Turkish set is the part worth reading twice: Kuveyt Turk, Finansbank, Turkish Airlines, Dogan Holding, Anadolu Sigorta, Aselsan, and A101, meaning banks, a flag carrier, an insurer, a defence electronics maker, and a national grocery chain named in one run. Its US postings skew to small healthcare and legal practices with data volumes attached in gigabytes. That combination, marquee national names alongside small clinics, is unusual and worth treating carefully.
Qilin held steady but lost the lead. 29 postings spread across six days, and the profiles are thinner than usual with many entries carrying no sector or description at all. Qilin remains the most consistently active RaaS brand of 2026 on a multi-week view, and its edge-appliance focus across Fortinet and Check Point VPN is unchanged. DragonForce, fell to 4. A drop that steep in one week usually means a pause in posting rather than a pause in intrusions.

New and Emerging Groups

CRPxO: a new brand with a national-scale Turkish cluster

CRPxO posted 31 victims this week, straight into second place. The pattern splits cleanly in two. On the US side it named small healthcare and professional practices with a formulaic posting style: sector label, then a data volume in gigabytes. Dental practices, orthodontists, home health providers, small law firms, and insurance brokers, each with 7GB to 87GB claimed. On the Turkish side it named seven of the country's better-known institutions in a single cluster, including two banks, an insurer, the flag carrier, a defence electronics manufacturer, and a national retail chain.
The read on CRPxO is that the two halves probably have different origins. Small US practices with neat gigabyte counts look like bulk intake from an access broker or a credential feed. A cluster of large Turkish institutions named together looks like either one shared upstream compromise or, just as plausibly, a set of recycled claims dressed up to establish the brand. No sample data accompanied the Turkish postings. Treat the marquee Turkish names as unverified until proof surfaces, and treat the US practice listings as the more likely genuine intake.

GammaX, Section 9, and Silent Ransom Group: names to log, not to brief

GammaX posted three victims across the US, Panama, and Saudi Arabia, spanning real estate, water utilities, and trading. Section 9 posted one, a redacted Panamanian domain. Silent Ransom Group posted one, the US law firm Moses & Singer, which fits its long-running pattern of targeting legal and professional services through callback phishing and IT-helpdesk impersonation rather than encryption.
None of these three carries enough volume this week to change a defensive posture. They are worth logging because new brands with one to three postings are how most of this year's larger operators started. Silent Ransom Group is the exception in that it is not new, and its presence is a reminder that data-theft extortion without any encryption still gets counted the same way on a leak site.

Sector Targeting Analysis

Across the 215 victim postings this week:
Sector Victims Share
Manufacturing 41 19%
Technology 23 11%
Financial Services 15 7%
Healthcare 14 7%
Business Services 13 6%
Energy 10 5%
Consumer Services 8 4%
Construction 8 4%
Hospitality and Tourism 6 3%
Public Sector 6 3%
Education 5 2%
Transportation and Logistics 4 2%
A caveat on these shares. 54 of the 215 postings carried no usable sector label this week, most of them bare-domain entries from Qilin and the long tail. The percentages above are of all postings, so they understate each sector's real share of the classified victims. Read the counts, not just the percentages.
What this tells us:
Manufacturing led at 41 victims, its highest share in the weeks we have tracked and nearly double the next sector. The Gentlemen alone fed 14 of those, and NightSpire and Aurora added another 7 between them. The named companies are mostly industrial suppliers rather than household brands: tooling, batteries, transformers, laser systems, welding, and precision components. Manufacturing claims sit upstream of many other victims, so a single supplier listing can carry weight far beyond the named company.
Technology followed at 23. The list mixes IT-services firms, hosting providers, and software vendors, several of which sit upstream of their own customers. An IT-services listing is worth checking for downstream reach into every client the vendor touches.
Financial Services took 15 and Healthcare 14, and both are shaped by CRPxO. Its Turkish cluster supplied two banks and an insurer, while its US intake supplied dental practices, orthodontists, and home health providers. Healthcare listings this week skew heavily towards small clinics rather than hospital systems, which carries HIPAA and PHI exposure at organisations with thin IT teams.
Energy at 10 is higher than usual and concentrated in The Gentlemen's activity. Their Friday run alone named Pertamina, a Chilean mining group, an Irish renewables provider, and an Austrian solar installer, and they had posted the Malaysian Nuclear Agency the day before. Critical-infrastructure names attract attention precisely because they are hard to verify quickly, which is why the confidence lines in the next section matter.

Country Distribution

The United States accounts for 43% of all postings this week (93 of 215), well above its long-run share of roughly 29%. Both of the week's batch operators were US-weighted: 21 of CRPxO's 31 victims are US firms, and The Gentlemen's Friday spree alone carried 15 US names. When a single operator clears a US-heavy queue, the country mix tilts with it.
Rank Country Victims
1 United States 93
2 United Kingdom 10
3 Turkey 10
4 India 9
5 France 9
6 Germany 9
7 Malaysia 4
8 Australia 4
9 Canada 4
10 Thailand 3
11 Singapore 3
12 Switzerland 3
13 Spain 3
14 Mexico 3
15 Panama 3
A further 28 countries had one to three victims each, including the Netherlands, Belgium, Israel, Ireland, Chile, Peru, Saudi Arabia, Poland, Brazil, Austria, South Africa, Russia, China, Italy, Colombia, Argentina, UAE, Denmark, Taiwan, Pakistan, Ecuador, South Korea, Tanzania, Sweden, Hong Kong, Algeria, the Philippines, and Nigeria.
Two regional stories stand out. Turkey at 10 is almost entirely CRPxO's single cluster, which is the difference between a country facing sustained pressure and a country appearing once because one actor posted a batch. Germany at 9 is largely SafePay's Monday run of retail, museum, school, and industrial targets, another single-operator concentration.
The breadth, 43 countries in a single week, shows how affiliate-driven RaaS now operates globally. Geographic distribution tracks revenue opportunity, not threat actor location. Map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, before an incident forces the question.

Notable Claims and Incidents

The five claims below all appear on public leak sites. We name only what the actor posted, summarise the data categories claimed, and end each with a confidence line. None were independently confirmed as a compromise at the time of writing.

1. ShinyHunters claim Ernst & Young

ShinyHunters listed Ernst & Young, the Big Four audit and advisory firm, on July 27 with an unusually direct message: a claim of responsibility, a statement that they had tried to make contact, and a July 31 deadline before publication. The posting sits alongside five other ShinyHunters listings this week that all reference Salesforce record counts.
Confidence: Low. The posting is real and the language is specific, but no sample data accompanied it and EY has not confirmed an incident. What raises the stakes is scope rather than certainty: an audit firm holds client financials and working papers across thousands of engagements, so a confirmed dump would reach far past the named company.

2. The Gentlemen claim Pertamina

The Gentlemen posted Pertamina, Indonesia's state-owned oil and gas major, on July 31 as part of their 32-victim Friday spree, with a revenue figure attached to the listing. Pertamina operates refineries, distribution networks, and energy infrastructure across Indonesia.
Confidence: Low. A national energy operator claimed by an affiliate crew with no sample data is a high-value, unverified listing. The group's habit of attaching researched company profiles makes their postings look authoritative, which is exactly why the underlying access needs separate proof. Validate before treating it as a breach.

3. ShinyHunters claim Alcon

ShinyHunters listed Alcon, the Swiss eye-care multinational, on August 2, claiming over 25 million records containing customer and employee PII. The same run named Questel at over 21 million records plus 147GB of corporate data, Lumenis at 1.1 million records and 176GB, and BH Security, the operator of brinkshome.com, at 4.9 million records.
Confidence: Medium. The record counts are specific and consistent across four postings, which is more than most extortion listings offer, and the Salesforce framing matches a known pattern of SaaS-connected-app token abuse rather than network intrusion. The specific figures are not independently corroborated, so validate scope before treating any single number as confirmed.

4. Anubis claim Coca-Cola through Fairlife

Anubis listed the Coca-Cola-owned dairy brand Fairlife on July 27, describing it as a major data breach at a company owned by Coca-Cola. The posting carried no data categories and no samples.
Confidence: Low. A subsidiary claim is not a parent-company claim, and this listing offers no evidence for either. Coca-Cola runs a mature security program, and the brand recognition here does more work than the claim itself. Treat it as unverified and confirm your own supplier exposure rather than the headline.

5. The Gentlemen claim Malaysian Nuclear Agency

The Gentlemen posted the Malaysian Nuclear Agency, the government body responsible for nuclear science research and development, on July 30. The agency handles regulated material, research data, and government-held records.
Confidence: Low. A state research body in this field carries national-security sensitivity, which is precisely why an unverified listing here should not drive escalation on its own. No samples were published. If substantiated, the regulatory and diplomatic weight would be well out of proportion to the group's usual mid-market intake.

Top CVEs These Groups Are Exploiting

Two new flaws dominate the exploitation picture this week, and both sit in the Microsoft stack rather than the usual VPN and edge appliances. Alongside them, the groups leading this week's leak site volume continue to work a known set of edge-device, hypervisor, and driver flaws. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution is tied to a named vendor or government source, with a confidence note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific actor, we left it out rather than padding the table.
CVE Product Severity Who is using it Why it matters
CVE-2026-42897 Microsoft Outlook Web Access / Exchange Critical Laundry Bear (TA488 / Void Blizzard) Cross-site scripting flaw in OWA and Exchange, actively weaponised in half-click campaigns that fire on the act of opening an email. Reported payloads deploy credential-stealing implants including OWAReaper. This is the week's most urgent item because it needs no attachment click and no macro, and mail is exposed by design.
CVE-2026-54121 (Certighost) Microsoft Active Directory Certificate Services High Tracked by incident responders, no confirmed group attribution Elevation-of-privilege flaw in AD CS that opens domain impersonation. Certificate services sit at the trust root of a Windows estate, so a successful abuse turns a foothold into durable, credential-independent domain access that survives password resets.
CVE-2024-55591 Fortinet FortiOS / FortiProxy 9.6 The Gentlemen, Qilin Authentication bypass on the FortiGate management interface. The Gentlemen, a Qilin splinter Microsoft tracks as Storm-2697, keeps a large inventory of already-compromised FortiGate devices and valid VPN credentials for fast initial access. This remains the load-bearing, first-party-confirmed vector for both groups (Fortinet PSIRT; Microsoft; PRODAFT; Trend Micro).
CVE-2024-21762 Fortinet FortiOS SSL VPN 9.8 Qilin Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. PRODAFT and FortiGuard tie Qilin's 2025 to 2026 campaign to this flaw. Tens of thousands of devices stayed exposed months after the patch.
CVE-2024-24919 Check Point Remote Access VPN 8.6 Qilin Information-disclosure flaw in the Check Point Security Gateway VPN blade that leaks sensitive files, including password hashes, from internet-facing gateways. Qilin affiliates use it alongside the Fortinet flaws to widen their VPN access options (Check Point; CISA).
CVE-2024-37085 VMware ESXi 6.8 Akira, The Gentlemen Authentication bypass that hands an attacker admin control of an ESXi host by creating a specific Active Directory group, enabling mass encryption of every VM on the host. First-party confirmed for Akira and Black Basta; The Gentlemen tie is analyst-reported (Microsoft; CISA AA24-109A).
CVE-2025-7771 ThrottleStop.sys driver (BYOVD) 7.8 The Gentlemen A legitimate driver with unrestricted access to physical memory, renamed and weaponised to disable Defender, CrowdStrike, and Bitdefender ahead of encryption. The Gentlemen are reported using this bring-your-own-vulnerable-driver technique (Kaspersky Securelist / GERT; Halcyon; group tie is analyst-reported).
CVE-2025-32433 Erlang/OTP SSH 10.0 The Gentlemen Unauthenticated pre-auth remote code execution in the Erlang/OTP SSH server, reaching root over the network. Reported as a secondary entry vector The Gentlemen adopted to diversify beyond Fortinet (Unit 42; Cisco PSIRT; group tie is analyst-reported).
CVE-2024-57727 SimpleHelp RMM 7.5 DragonForce Path-traversal flaw in SimpleHelp remote-management software, chained with two sibling flaws for an MSP-to-client pivot that reaches downstream victims in one move. DragonForce posted only 4 victims this week, but the vector's one-to-many reach keeps it on the list (CISA AA25-163A; Sophos; Trend Micro).
A note on attribution accuracy. We attribute a CVE to an actor only where a named vendor or government source supports the link, and we flag where that link is analyst-reported rather than first-party. Several of this week's highest-volume groups have no verifiable CVE tie at all. CRPxO is a new brand with no published exploit attribution, and its formulaic postings are consistent with access-broker or credential-feed intake. ShinyHunters is not exploiting a CVE at all in these six listings: the Salesforce-linked pattern is abuse of OAuth tokens held by connected third-party applications, which means patching does nothing and the control that matters is auditing and revoking connected-app authorisations. NightSpire, SafePay, KryBit, Coinbase Cartel, and Aurora all show feed-sourced or opportunistic intake with no named exploit.
A few practical notes:
Mail is the new front door this week. CVE-2026-42897 changes the shape of the problem. A cross-site scripting flaw triggered by opening a message removes the user-error step defenders usually rely on. Patch OWA and Exchange first, and treat any unpatched internet-facing mail surface as an active incident risk rather than a backlog item.
Certificate services are a privilege escalation shortcut. CVE-2026-54121 in AD CS matters because certificate-based domain impersonation outlives credential rotation. If you patch the mail flaw but leave AD CS exposed, you have closed the door and left the master key on the step.
VPN appliances still carry the ransomware volume. Fortinet and Check Point gateways drove The Gentlemen's and Qilin's access this week, and those two groups posted 72 victims between them. Internet-facing, unpatched, credential-exposed VPNs are how affiliates get in before any locker runs.
SaaS tokens are not covered by your patch cycle. The ShinyHunters listings point at connected-app authorisations, not software versions. Review which third-party applications hold OAuth tokens into your CRM and revoke the ones nobody can justify.
We are reporting these as the flaws most associated with this week's most active actors. Knowing these are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch-office firewall, an unpatched OWA endpoint, or a certificate authority nobody has audited since 2019, is the part most teams cannot answer on a Monday morning. Confirm your own exposure rather than assuming a vendor advisory covers your specific version.

Infrastructure and Operational Shifts

Batch posting is back, and it distorts the count. Two operators produced 52 of this week's 215 postings on two specific days. When you benchmark week to week, separate the batch from the baseline before you read a trend into the total. The underlying field this week sits near 163, even though the headline number rose 16%.
New brands can enter at the top now. CRPxO went from unknown to second place in one week with 31 postings. The old assumption that a new leak site starts small and builds credibility over months no longer holds. Any brand can buy or inherit an access inventory and post at scale immediately, which means a name you have never seen is not automatically a low-priority name.
Extortion without encryption keeps growing. ShinyHunters' six listings reference record counts and SaaS platforms rather than encrypted estates, and Silent Ransom Group's listing follows the same data-theft-only model. Your ransomware playbook needs a branch for the case where nothing is encrypted, nothing is down, and the only pressure is a data set the attacker already holds.
Marquee names on thin proof remain the norm. Pertamina, Ernst & Young, Coca-Cola through Fairlife, the Malaysian Nuclear Agency, and CRPxO's Turkish banking cluster were all named without sample data. Recognisable names draw attention and pressure, whether or not the underlying access is real. Validate the claim before the brand name drives your response.

Key Takeaways for Defenders

Patch OWA and Exchange before anything else this week. CVE-2026-42897 is being weaponised in half-click campaigns that trigger on opening an email, dropping credential-stealing implants including OWAReaper. There is no user-behaviour control that reliably stops this one. Confirm your Exchange and OWA patch level today, and hunt for anomalous OWA sessions and mail-rule changes while you do it.
Audit Active Directory Certificate Services. CVE-2026-54121 turns a foothold into durable domain impersonation that survives password resets. If you have never audited certificate template permissions and enrolment rights, this is the week. A patched mail server behind an abusable CA is not a fixed estate.
Read the 16% rise as two batches, not a surge. The Gentlemen posted 32 victims on one Friday and CRPxO posted 20 on one Monday. Against the underlying baseline near 163, activity was flat to slightly down. When a leak-site count swings, check whether one group, one batch, or the calendar drove it before briefing it as a trend.
Treat manufacturing suppliers as this week's supply-chain risk. Manufacturing took 41 named hits, nearly double the next sector, and most were industrial component and tooling suppliers rather than consumer brands. Map which of your inputs come from firms that would never make a news headline. Those are the listings that reach you indirectly.
Revoke SaaS connected-app tokens you cannot justify. The ShinyHunters listings against Ernst & Young, Alcon, Questel, RingCentral, Brinks Home, and Lumenis point at OAuth token abuse in connected third-party applications, not at an unpatched server. Patching does not touch this. Reviewing and revoking app authorisations does.
Validate the high-value claims before you react. Pertamina, Ernst & Young, Coca-Cola through Fairlife, the Malaysian Nuclear Agency, and CRPxO's seven Turkish institutions are exactly the names built to draw attention on thin proof. CTI should confirm samples and your communications team should hold a pre-approved response before anyone treats a claim as a breach.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old. Watching external exposure, leaked credentials, and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 215 posts down to the few that touch your domains, your brands, and your vendors, then matching those actors to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: scrutex.ai/solution/threat.

Frequently Asked Questions

How many ransomware attacks happened the week of July 27 to August 2, 2026?215 unique victim postings appeared on dark web leak sites in that window, across 38 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly.but two single-day batches drove the rise, so the underlying field sits closer to 163.
Which ransomware group is most active right now? The Gentlemen topped the week with 43 postings, including 32 on Friday July 31. CRPxO, a brand that had not featured before, took second with 31, and Qilin came third with 29. The Gentlemen and Qilin have traded the lead for several weeks; CRPxO is new and unproven.
Who is CRPxO? CRPxO is a new leak site brand that posted 31 victims this week, its first heavy run. Its US listings are small healthcare, dental, and legal practices with data volumes given in gigabytes. Its Turkish listings name seven large institutions including two banks, an insurer, the flag carrier, a defence electronics maker, and a national retailer, all without sample data. Treat the large Turkish names as unverified claims until evidence surfaces.
What is CVE-2026-42897 and why does it matter? It is a critical cross-site scripting vulnerability in Microsoft Outlook Web Access and Exchange, actively weaponised in half-click campaigns that fire when a message is opened, deploying credential-stealing implants including OWAReaper. It matters because it removes the click-the-attachment step that most user-awareness training relies on. Patch internet-facing OWA and Exchange as a priority.
Did Ernst & Young, Pertamina, or Coca-Cola get hit by ransomware? ShinyHunters posted Ernst & Young, The Gentlemen posted Pertamina, and Anubis posted a Coca-Cola-linked claim through the Fairlife brand, all without sample data. A large brand named by an actor with no proof attached is a low-confidence claim. Treat all three as unverified actor claims until evidence emerges.
What CVEs are these groups exploiting? Two new flaws lead this week: CVE-2026-42897 in Outlook Web Access and Exchange, used by the espionage group Laundry Bear, and CVE-2026-54121 in Active Directory Certificate Services. On the ransomware side, The Gentlemen and Qilin use Fortinet FortiOS (CVE-2024-55591, CVE-2024-21762), Qilin adds Check Point VPN (CVE-2024-24919), Akira and The Gentlemen use VMware ESXi (CVE-2024-37085), The Gentlemen use the ThrottleStop driver (CVE-2025-7771) to disable EDR, and DragonForce uses SimpleHelp RMM (CVE-2024-57727). CRPxO, NightSpire, SafePay, and KryBit have no verifiable CVE tie. ShinyHunters is abusing SaaS OAuth tokens, not a software flaw.
What sectors should I worry about most this week? Manufacturing led at 41 named victims, nearly double Technology at 23, followed by Financial Services at 15 and Healthcare at 14. Manufacturing ran high because The Gentlemen's Friday spree targeted industrial and component suppliers. 54 of the 215 postings carried no sector label, so read the counts alongside the percentages.
Where can I get this data in real time? Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands, and vendors, so you see only the postings that touch your domains, brands, or supply chain.