Ransomware weekly
204 views

Ransomware Attacks This Week: 287 Victims Across 53 Groups (August 17 to 23, 2026)

By ScruteX Published

Summary

This is the Scrutex ransomware weekly for the August 17 to 23, 2026 window. Our CTI team tracked 287 unique ransomware and extortion victim postings across 53 active groups during the period. That is down 9% on last week's 314, and for once the decline is the whole story rather than a cover for one enormous run.
The second story is the gap between how large this week's names are and how little evidence sits behind them. LockBit listed U.S. Bank. ShinyHunters listed ReliaQuest and BOK Financial. Everest listed Capgemini Engineering and Kingston Technology. Xpl0itrs listed BMW Group and Target. Six household names in seven days, and in every case the named organisation has either denied a compromise, reported that the intrusion attempt failed, or said nothing while the actor published no meaningful proof. The volume chart says quiet week. The masthead says otherwise. Both readings are wrong on their own.
Third, the item that changes how you should read every number below. Anthropic published threat intelligence in August describing criminal use of its Claude Code agent across the full attack chain: reconnaissance, initial access, custom tunnelling malware, analysis of stolen financial data to size a demand, and the drafting of the extortion note itself. One tracked operation hit at least 17 organisations without encrypting anything. A separate operator built and sold a ransomware product with the model's help. Anthropic links a further cluster of compromises to The Gentlemen at medium confidence. The reason this matters to a weekly victim count is simple: it lowers the skill floor for the exact activity that fills these tables.
287 posts, 53 groups, 54 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter.

This Week at a Glance

Metric Value
Total unique victims posted 287
Change on prior week Down 9% (from 314)
Active groups 53
Countries hit 54
Heaviest single day August 21 (58 posts, 20% of the week)
Second heaviest day August 20 (48 posts)
Quietest day August 17 (28 posts)
Most targeted country United States (109 victims, 38% of postings)
Most targeted sector Technology (22 named), Manufacturing (20), Healthcare (19)
Top group by volume Qilin (35 posts across six of seven days)
Largest single-day run The Gentlemen (22 on August 21)
Notable claims U.S. Bank, ReliaQuest, BOK Financial, Kingston Technology, Capgemini Engineering, BMW Group, Target
The week has a shape you can describe in one line: it built. Monday August 17 opened at 28, the quietest day. Tuesday reached 38, Wednesday 39, Thursday 48, Friday 58. Saturday fell back to 33 and Sunday closed at 43. No day carried more than a fifth of the total.
Compare that to the last three weeks and the difference is structural, not seasonal. Volume in this field has been dominated by publication events: a mass exploitation campaign naming its victims all at once, a new leak site emptying a backlog, an affiliate dumping thirty listings on a Wednesday. Strip those events out and the underlying field has been sitting between 220 and 250 for a month. This week there is nothing to strip. 287 is the underlying field, and the underlying field went up.
The top five groups took 42% of volume, down from 52% last week. That is the more useful number in the table. Concentration fell because the batch runs stopped, not because the leading operators slowed. Qilin posted 35 against 37. The Gentlemen posted 30 against 22. DireWolf posted 21 against 17. Three of the top five were more active than last week while the top five share dropped ten points.
The tail stayed long. 53 groups posted, 30 of them three victims or fewer, and 14 posted exactly once. Those 30 groups together produced 52 postings, which is 18% of the week spread across more than half the active brands.

Group Activity Breakdown

The top five groups produced 120 of 287 postings, 42% of the week. Below them, 35 groups posted four or fewer victims each, together accounting for 72 postings.
Rank Group Victims Share Notable Activity
1 Qilin 35 12% Active six of seven days, no batching. Italian, German, Mexican and US mid-market. Cinépolis, Medochemie, iPic, Quaker State Mexico
2 The Gentlemen 30 10% 22 on August 21 across 15 countries. Arbeiterkammern Austria, Layher Chile, Volktek Taiwan, AGS Cinemas India
3 DireWolf 21 7% Two runs, 4 on August 17 and 13 on August 21. Arizona State University, Mighty Kingdom, Reviso, ProSim Aviation
4 Coinbase Cartel 20 7% 13 on August 22, none encrypted. Crowe, Tower Insurance, Flecha Bus, two Indonesian financial firms
5 Storm 14 5% Split 7 on August 18 and 7 on August 23. US and Australian mid-market, insurance, manufacturing and one bank
6 INC Ransom 13 5% Spread across four days. Third Coast Bancshares, Foresee Pharmaceuticals, Otter Tail County Minnesota
7 Titan 9 3% All nine on August 20, all Italian, mostly industrial. Alto Calore Servizi, Elbor, ELCON MEGARAD
8 Kazu 9 3% All nine on August 23, eight of them healthcare software platforms across Latin America and Asia
9 Pear 8 3% US small business. Plastic surgery, casino, pharmacy, architectural glass
10 Settra 7 2% Bare domains only, no company names. US, Japan, Greece, Canada, Sweden
11 ShinyHunters 7 2% ReliaQuest, BOK Financial, CyrusOne, NovoCure, Logitech and Streamlabs, Brinks Home
12 DYSPHOR1A 7 2% Thailand, Myanmar, Indonesia and India. Police and university data sets, not corporate networks
13 MetaEncryptor 7 2% All seven on August 23. US, German, Japanese and Canadian manufacturers and suppliers
14 Everest 6 2% Five on August 20, including Capgemini Engineering and Kingston Technology
15 Play 6 2% Steady low-volume US posting, one Latvian manufacturer
16 KryBit 6 2% Six on August 19, Argentina, Italy, Thailand, Hong Kong and the Czech Republic
A long tail of groups (Aurora, DragonForce, Majinahanashi, IAH647, Rhysida, Barracuda, Global Secret Group, Insomnia, Anubis, Audit Team, LeakedData, Silent Ransom Group, Helix, NightSpire, L Group, Space Bears, Bravox, 3AM, Gunra, LeakNet, RansomHouse, Securotrop, Interlock, Orova, Kairos, Payload, Eclipse, Termite, Genesis and KillSec) each posted between one and three victims.
Three observations:
Qilin wins on turning up. 35 postings across six of the seven days, no run larger than 11, and the same victim profile it has held all quarter: European and Latin American mid-market manufacturers, professional services firms and cinema and hospitality operators. It has now finished at or near the top of our chart every week this quarter without producing the largest single-day run in any of them. Third-party tracking puts Qilin above 500 victims in 2026 alone and roughly 1,500 since launch, which makes it the most productive operation running by a clear margin. Steadiness, not spikes, is what that looks like week to week.
The Gentlemen posted its widest single run yet. 22 victims on August 21 across Austria, Chile, Taiwan, India, Japan, Norway, the UAE, Poland, Peru, Brazil, France, Italy, Mexico, Germany and the US. Fifteen countries in one publication. The group reached the top of the field in the second quarter of this year and reporting puts it above 330 public victims across more than 70 countries, with a peak month of 117 in June. What is notable in this run is not the count but the absence of a theme. No shared sector, no shared region, no shared supplier. That is the signature of an affiliate program working through whatever intake its operators bring, not a campaign.
Encryption-free extortion is now a fifth of the field. ShinyHunters, Coinbase Cartel, LeakedData, Silent Ransom Group, Xpl0itrs, Helix, LeakNet, Nasir Security, DYSPHOR1A, Audit Team and IAH647 produced 54 postings between them. None of those listings depends on an encryptor. Coinbase Cartel alone posted 20 and has now claimed more than 160 victims without ever deploying one, working almost entirely from infostealer credentials. Your ransomware playbook needs a branch for the case where nothing is encrypted, nothing is down, and the only pressure is a data set the attacker already holds.

The AI Angle

This is the item to brief upward this week, and it does not appear in any victim count.
Anthropic published threat intelligence in August describing how criminal operators used its Claude Code agent inside live intrusions. Three findings matter to anyone reading a weekly leak site roundup.
One operation ran the whole chain through the model. A cluster tracked as GTG-2002 hit at least 17 organisations across government, healthcare, financial services and emergency services. The model performed network reconnaissance, assisted with initial access, produced custom malware derived from the Chisel tunnelling tool for exfiltration, then analysed the stolen financial records to decide what the victim could pay and drafted the extortion note. Nothing was encrypted. Every one of those 17 would appear in a table like ours as a data-theft listing indistinguishable from any other.
A single operator built and sold a ransomware product. A separate actor, based in the UK, used the same tooling to develop a ransomware-as-a-service offering, including ChaCha20 stream cipher encryption and shadow copy deletion, and then commercialised it. That is a product build that historically required a development team.
The Gentlemen appears in the same reporting. Anthropic links a cluster of at least eight compromises to The Gentlemen RaaS at medium confidence, covering an Australian energy utility, a financial services firm in Mauritius, and manufacturers in Thailand and the United States, in a window ending in late June. Medium confidence is medium confidence, and we are not treating it as attribution. It is worth logging alongside the group's second place finish this week.
The defensive consequence is narrow and specific. This does not create a new attack technique. Every step described is one that skilled operators already performed by hand. What it changes is throughput and the skill floor. An operator who could not previously write a tunnelling implant, enumerate an unfamiliar Active Directory forest, or price a demand against a victim's own balance sheet can now do all three. Expect the count of small, capable, short-lived brands to keep rising, which is exactly the pattern our tail has shown all year: 53 groups this week, 30 of them with three victims or fewer.
None of the controls that catch this are new either. The activity still lands as credential use, tunnelling traffic, and bulk data movement out of your estate.

New and Emerging Groups

Kazu: nine healthcare platforms in one publication

Kazu posted nine victims on August 23, and eight of them are clinical software platforms rather than clinics. The list covers a cloud PACS platform in Brazil, telemedicine and patient management systems in Brazil and Mexico, a healthcare management platform serving practices in India and the US, an appointment management system in Canada, a specialised medical centre in Mexico, a neurology and sleep institute in Argentina, a teaching hospital in Pakistan, and a digital veterinary care platform.
Kazu has been active since around September 2025 as a double extortion operation, with a target profile centred on Southeast Asia, the Middle East and Latin America. Nine postings is a small number. The exposure behind it is not.
The pattern worth logging is the layer being hit. When an actor names a hospital, the patient records at risk belong to that hospital. When an actor names the PACS platform, the telemedicine system, or the practice management suite, the records at risk belong to every clinic on that platform, and none of those clinics appears on the leak site. If you are a small practice, your exposure this week is not measured by whether your name is on a list. It is measured by which of your clinical suppliers is.
Confidence: Medium. The listings are consistent across trackers and the victim descriptions are specific enough to identify real products. None of the named platforms has confirmed an incident and no sample data accompanied the notices at the time of writing.

Titan: nine Italian firms in one day

Titan posted nine victims on August 20 and every one is Italian. The list runs Alto Calore Servizi, a public water and sewerage utility serving municipalities in the provinces of Avellino and Benevento, alongside Elbor, ELCON MEGARAD, Termotecnica Industriale, TECNOLOGICA, CONDOR, CTP, POEMA and a professional partnership. Each listing is an extortion notice threatening publication unless negotiations start.
Read that list as one intake, not nine intrusions. Nine Italian firms in one day, mostly industrial, mostly in the same size band, is what a single affiliate working a bought target list looks like, or a shared managed service provider that opened several doors at once. Neither theory is confirmed. Both point Italian mid-market manufacturers at the same question: who else has remote access into your estate, and when did you last check what they can reach.
The Alto Calore listing is the one to watch for a different reason. A regional water utility is critical national infrastructure regardless of its size, and utilities of that scale rarely run a security team.
Confidence: Medium on the postings, Low on scope. The listings exist and are consistent across trackers. No data volumes, samples or encryption indicators accompanied them.

Pear and MetaEncryptor: two quiet brands working the US mid-market

Both entered our chart this week without a batch run or a headline.
Pear posted eight victims across four days, all but one US, all small business: a plastic surgery institute, a casino, a pharmacy and surgical supplier, a Californian services firm, an architectural glass and metal fabricator, a small financial firm, a law partnership and a Jamaican network provider. Small, local, unlikely to have a security function.
MetaEncryptor posted seven, all on August 23, spread across US, German, Japanese and Canadian manufacturers and suppliers: a seafood processor, a Japanese heating manufacturer, a kit car maker, a German pharmaceutical packager, a trucking firm, a water resources engineering company and a cedar products manufacturer.
Neither group is loud. Both are working exactly the band that pays: 200 to 2,000 employees, no dedicated security staff, enough revenue to make a demand worth issuing.

DYSPHOR1A and Nasir Security: claims that are not ransomware

Two brands in this week's data are publishing data sets rather than running extortion against a compromised network, and it is worth separating them out.
DYSPHOR1A posted seven listings across Thailand, Myanmar, Indonesia and India. The two that drew attention are an Indonesian police database, described as records for around 52,000 officers including names, contact details, passwords, location data and roughly 4,000 facial photographs, and the University of Delhi, claimed jointly with another actor and covering student personal data, academic and enrolment records and identification documents. The Delhi listing has since disappeared from at least one public tracker, and the university has not commented.
Nasir Security posted four listings in the Gulf and Israel, including UAE Customs, Dubai Airport, the Kuwait Ministry of Interior and the Yad Vashem museum, all on August 22 and all through a single tracker.
Both brands sit closer to hacktivism than to ransomware economics. There is no encryption, no negotiation portal in evidence, and the target selection follows political geography rather than ability to pay. We count them because they appear on leak sites and because a stolen data set is a stolen data set. Read the claims accordingly, and treat the government listings as unverified until an authority says otherwise.
Confidence: Low on all of them. Single-tracker sourcing, no samples verified independently at the time of writing, and one listing already withdrawn.

Sector Targeting Analysis

Across the 287 victim postings this week:
Sector Victims Share of all postings Share of classified
Technology 22 8% 16%
Manufacturing 20 7% 14%
Healthcare 19 7% 14%
Business Services 18 6% 13%
Financial Services 15 5% 11%
Transportation and Logistics 10 3% 7%
Energy 9 3% 6%
Consumer Services 7 2% 5%
Hospitality and Tourism 7 2% 5%
Education 6 2% 4%
Agriculture and Food 4 1% 3%
Public Sector 3 1% 2%
A caveat on these shares. 147 of the 287 postings carried no usable sector label, so only 140 are classified and the third column is the more honest read. Several operators in this week's data publish no sector at all, and two of the four upstream trackers use different sector vocabularies, so the label quality varies by which feed carried the posting.
What this tells us:
No sector dominates, and that is the finding. The top four sit within four postings of each other. Last week technology led on 48 because one mass exploitation campaign named its victims all at once. Strip that kind of event and the field returns to what it looks like underneath: a fairly even spread across whatever mid-market organisations happened to be reachable.
Healthcare at 19 is one operator, not a trend. Kazu supplied eight of the 19 in a single August 23 run against clinical software platforms. Storm added two, Barracuda two, and the rest are single postings from seven different brands. If you read healthcare exposure off the sector row this week you will draw the wrong conclusion. The concentration is not in hospitals. It is in the software that hospitals and clinics run on.
Financial services at 15 is unusually high for this table, and unusually unproven. The row includes U.S. Bank via LockBit, BOK Financial via ShinyHunters, Third Coast Bancshares via INC Ransom, two Indonesian financial institutions and a New Zealand insurer via Coinbase Cartel, a Philippine microfinance foundation, and a Kentucky community bank via Storm. Large banks normally stay off leak sites because detection is better, regulatory pressure is heavier, and the sanctions risk to the attacker is real. Three appearing in one week is either a genuine shift or a run of opportunistic listings against names that generate coverage. The public statements so far point at the second.
Technology at 22 keeps the supplier pattern going. ReliaQuest, CyrusOne, Kingston Technology, Capgemini Engineering, Aztec Software, InfoFlo CRM, ProSim Aviation Research, NetExam, Volktek and Questronix all sit upstream of their own customers. A technology listing is worth checking for downstream reach into every client that vendor touches, which is a different question from whether the vendor itself was breached.
Public sector at 3 understates the week. Otter Tail County in Minnesota, a Brazilian municipal government and a Spanish town council carry the label. The Indonesian police database, the UAE Customs and Kuwait interior ministry claims, and Vietnam Electricity all carry no sector label at all. Read the count as a floor.

Country Distribution

The United States accounts for 109 of 287 postings, 38% of the total and 40% of the 271 postings where a country was recorded. That is up from last week's 33% and almost exactly level on the share of classified postings, which held at 40%.
Rank Country Victims
1 United States 109
2 Italy 23
3 Germany 12
4 United Kingdom 9
5 Mexico 9
6 Canada 7
7 Brazil 6
8 United Arab Emirates 6
9 France 5
10 Switzerland 4
11 Sweden 4
12 Spain 4
13 Thailand 4
14 India 4
15 Indonesia 4
A further 39 countries recorded one to three victims each, including Australia, Taiwan, Japan, Argentina, Peru, Myanmar, the Philippines, Chile, South Korea, Malaysia, Hong Kong, the Czech Republic, the Netherlands, Israel, Trinidad and Tobago, Russia, Honduras, Mauritius, Greece, Turkey, Uruguay, Cyprus, Colombia, South Africa, Cameroon, Latvia, Denmark, Norway, Austria, Belize, Poland, Samoa, China, New Zealand, Vietnam, Kuwait, Jamaica, Pakistan and Qatar.
Three points stand out.
Italy at 23 is the highest non-US figure we have recorded this year, for the second week running. Last week it was 22 and the spread was wide, with nine operators involved. This week it is more concentrated: Titan posted nine in one day, Qilin six, The Gentlemen three, Panzer two, KryBit two and Xpl0itrs one. Six operators, one of them supplying almost half. Italian mid-market manufacturing is taking sustained pressure from more than one direction, and two consecutive weeks in second place is no longer a statistical accident.
Mexico at 9 and the UAE at 6 are the movers. Mexico's entries run across Qilin (Cinépolis, Quaker State Mexico, Constructora Jimenez), DireWolf (Aztec Software, iSON XPERIENCES), Kazu, The Gentlemen and 3AM. That is five operators, which suggests intake breadth rather than one affiliate working a region. The UAE entries divide between real corporate listings from The Gentlemen, DireWolf and INC Ransom, and the Nasir Security government claims, which we would not weight the same way.
The long tail is the real headline. 54 countries in one week, and 39 of them recorded three victims or fewer. Affiliate-driven extortion tracks revenue opportunity, not threat actor geography. This week that produced listings in Samoa, Belize, Cameroon, Honduras, Mauritius and Jamaica alongside the usual western concentrations.
For readers outside the United States the practical point is unchanged: map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, APRA CPS 234 in Australia, before an incident forces the question.

Notable Claims and Incidents

The five items below all appear on public leak sites or in named vendor reporting. We state what the actor claimed, what the named organisation has said, and end each with a confidence line. The common thread this week is that the claims are big and the evidence is thin.

1. LockBit 5 lists U.S. Bank with a September 3 deadline

On August 20, a LockBit 5 leak site listing appeared for usbank.com, giving the bank 14 days to meet an undisclosed demand before publication. The listing named no data volume, no affected systems and no data categories. U.S. Bank has said it is reviewing the claim and that it has no evidence its internal systems or network were accessed without authorisation.
Confidence: Low. A listing with no volume, no sample and no named system is a negotiation opening, not evidence. LockBit's brand has been rebuilding since the 2024 takedown and a large recognisable name generates the coverage a rebuilding brand wants. That does not make the claim false. It does mean nobody should brief this as a confirmed breach on the strength of the listing. What is worth doing is checking whether any third party holding your banking data has an exposure, since a supplier compromise is the more common route to a claim like this than a direct intrusion into a tier-one bank.

2. ShinyHunters names ReliaQuest, BOK Financial and CyrusOne, and ReliaQuest pushes back publicly

ShinyHunters listed BOK Financial on August 22 with a two-day ultimatum expiring August 24, then listed ReliaQuest, CyrusOne and NovoCure on August 23. It had already posted Logitech and Streamlabs on August 18 with a final warning expiring August 21, and Brinks Home earlier in the month.
ReliaQuest confirmed that an attack took place on August 22 and disputed the characterisation. Its account is that a social engineering attempt temporarily exposed one identity, that no applications or systems were accessed, and that no customer data was touched. The Logitech and Streamlabs listing arrived with no ransom figure and no file samples, screenshots or directory listings. Neither company has issued a statement.
Confidence: Low on the individual listings, High on the pattern. ShinyHunters has run a sustained campaign against enterprise cloud applications since mid-2025, most visibly Salesforce, working through voice phishing that persuades staff to authorise an attacker-controlled connected application. That campaign reportedly touched over 1,000 organisations. Earlier this month the group leaked 41GB from Brinks Home after that company declined to pay, having claimed roughly 4.9 million Salesforce records. So the operator is real and does follow through. What is unproven is whether these four specific listings represent successful intrusions. The control that matters here is not your backup or your endpoint agent. It is knowing which third-party applications hold OAuth tokens into your tenant, and having a help desk process that does not authorise a connection on a phone call.

3. Everest posts Capgemini Engineering and Kingston Technology on the same day

On August 20 Everest listed both a major French engineering services provider and a US memory and storage manufacturer. The Kingston listing claims roughly 138.5GB of marketing material and the only evidence published is a screenshot of a Windows file directory with folders bearing employee names. Kingston says it is aware of the claims and that operations remain unaffected. The Capgemini Engineering listing carries no data volume, no ransom figure, no screenshots and no technical narrative.
Confidence: Low. A directory screenshot is proof of a screenshot. Both listings follow the pattern of naming a large brand and letting the coverage do the pressure work. The reason to log them anyway is scope rather than certainty: an engineering services provider holds client design and project data, and a component manufacturer sits inside a long list of other companies' supply chains. If either turns out to be real, the exposure is not confined to the named company.

4. Kazu posts nine clinical software platforms in one run

On August 23 Kazu listed nine victims, eight of them healthcare software rather than healthcare providers: a Brazilian cloud PACS platform, telemedicine and patient management systems in Brazil and Mexico, practice management platforms serving clinics in India and the US, a Canadian appointment management system, a Mexican specialised medical centre, an Argentine neurology institute, a Pakistani teaching hospital and a digital veterinary care platform.
Confidence: Medium. The listings are consistent across trackers and the descriptions identify real products, which is more than most of this week's claims offer. No platform has confirmed an incident and no samples were published at the time of writing. The reason to brief this one is the layer, not the count. Every clinic running one of those platforms is downstream of a listing that does not carry its name, and none of them will receive a notification from a leak site.

5. Xpl0itrs claims BMW Group, then Target

Xpl0itrs listed BMW Group on August 17 and published sample archives described as around 800 motorcycle and dealership documents. Researchers who examined the samples found they cover used motorcycle listings, vehicle pricing, dealership records and employee contact details. The group also claimed configuration data, API data, fuel station data and subsidiary data, and the published samples do not support those claims. On August 20 the same actor claimed 8.6GB of Target source code.
Confidence: Low. This is the clearest example this week of the gap between a claim and its evidence. Real sample files were published, which puts the BMW listing above the pure-assertion claims elsewhere in this section, but the sample is narrower than the claim by a wide margin. Dealership pricing documents and employee contact details are a real data exposure and worth handling as one. They are not a compromise of a global manufacturer's engineering estate, and the difference matters when someone asks whether to brief the board.

Headlines Beyond the Leak Sites

Two developments shape how you should read this week's numbers even though they are not victim counts.
CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalog in two days. On August 17 it added CVE-2025-62593, a code injection flaw in Ray, the open source distributed compute framework used to run machine learning workloads. On August 18 it added four more: CVE-2026-55040, a weak authentication flaw in Microsoft SharePoint; CVE-2026-59310, a path traversal flaw in Broadcom VMware vCenter; CVE-2026-33824, a double free flaw in the Microsoft Internet Key Exchange service extensions; and CVE-2026-65400, an improper authentication flaw in Apple macOS.
Two of those deserve more than a line. CVE-2026-55040 lets an unauthenticated remote attacker forge a valid authentication token and act as a SharePoint site user or administrator, by chaining four separate weak checks. It carries a CVSS score of 9.1 and exploitation followed the publication of proof-of-concept code. If your SharePoint is internet-reachable, that is a document repository with an authentication bypass in front of it.
CVE-2026-59310 is the more urgent one. It is a path traversal flaw in the vCenter syslog service that allows an unauthenticated attacker with network access to vCenter to execute arbitrary code, with a CVSS score of 9.8. Exploitation began five days after Broadcom disclosed it. Reporting describes the first compromised systems contacting attacker infrastructure on August 3, 151 further victim addresses the following day, and roughly 95% of a 361-system total appearing by August 5. A five-day window from disclosure to mass exploitation, and a two-day window from first exploitation to near-complete campaign, is faster than most patch approval cycles run. vCenter is the control plane for your virtual estate. Code execution there is code execution everywhere it manages, including the backup infrastructure you were counting on.
Ransomware operators are running agentic AI inside live intrusions. Covered in full above. The short version for a risk register: no new technique, materially higher throughput, and a lower skill floor for the operators filling the long tail of this report.

Top CVEs These Groups Are Exploiting

No single flaw dominated this week, which is itself the difference from the last three. The established operators continue to work the same set of VPN, firewall and virtualisation flaws they have worked all year, and the newest arrivals in our table have no published exploit attribution at all. Each attribution below is tied to a named vendor or government source, with a note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific actor, we left it out of the table and put it in the section above instead.
CVE Product Severity Who is using it Why it matters
CVE-2026-0257 Palo Alto Networks PAN-OS GlobalProtect Critical Qilin (affiliate) Authentication bypass in the GlobalProtect VPN interface, used to obtain authenticated access to victim networks before credential harvesting, lateral movement and locker deployment. Documented in a series of June 2026 intrusions that ended in Qilin ransomware (Arctic Wolf Labs; Palo Alto Networks).
CVE-2026-50751 Check Point Remote Access VPN and Mobile Access Critical Qilin (affiliate) Authentication bypass disclosed on June 8 after exploitation was traced back to May 7. Gives Qilin affiliates a second VPN route alongside Palo Alto and Fortinet (Check Point; analyst-reported group tie).
CVE-2024-55591 Fortinet FortiOS and FortiProxy 9.6 The Gentlemen, Qilin, Gunra Authentication bypass on the FortiGate management interface yielding super-admin privileges. Named as a primary vector for The Gentlemen's internet-facing intake and previously named in the Gunra advisory (Fortinet PSIRT; CISA AA26-222A).
CVE-2024-21762 Fortinet FortiOS SSL VPN 9.8 Qilin, The Gentlemen Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. Still producing access two years after the patch shipped, because the exposed device population never fully closed.
CVE-2024-40766 SonicWall SonicOS SSL VPN 9.3 Akira Improper access control affecting SonicOS 5, 6 and 7. Akira's SonicWall campaign has continued through August, driven by this flaw and by migrated local accounts whose passwords were never reset after upgrade (SonicWall; Rapid7).
CVE-2026-59310 Broadcom VMware vCenter 9.8 No ransomware group named yet Path traversal in the vCenter syslog service giving unauthenticated remote code execution. Mass exploitation began five days after disclosure and reached roughly 361 networks within a week. No extortion brand has been tied to it publicly, which given the target and the tempo is more likely a reporting lag than an absence (CISA KEV, added August 18; Broadcom).
CVE-2026-55040 Microsoft SharePoint 9.1 No ransomware group named yet Weak authentication allowing an unauthenticated attacker to forge a valid token and act as a site user or administrator. Exploitation followed public proof-of-concept code. Added to CISA KEV on August 18 (Rapid7; CISA KEV).
A note on attribution accuracy. Most of this week's volume has no verifiable exploit attribution at all. Titan, Kazu, Pear, MetaEncryptor, Settra, KryBit, Storm and DYSPHOR1A are newer or smaller brands with no published CVE tie, and their posting patterns fit access broker intake, credential feeds or phishing rather than a named flaw. ShinyHunters and Coinbase Cartel are not exploiting a software vulnerability in any of this week's listings: both work through valid credentials and connected cloud applications, which means patching does nothing and the controls that matter are connected-app review, token hygiene and infostealer monitoring. Roughly 80% of Coinbase Cartel's claimed victims had a documented prior infostealer infection.
A few practical notes:
Your virtualisation control plane is now a front-line target. vCenter went from disclosure to hundreds of compromised networks in under a week. Confirm your version, confirm whether the vCenter management interface is reachable from anywhere it should not be, and check whether the syslog service is exposed. Code execution on vCenter reaches every workload it manages and, in most estates, the backup infrastructure as well.
Your VPN is still where the ransomware volume comes from. Palo Alto, Check Point, Fortinet and SonicWall flaws drove access for Qilin, The Gentlemen and Akira this week. Two of those CVEs are more than eighteen months old. That is not a disclosure problem, it is an inventory problem.
Credentials, not exploits, drove the biggest names this week. Every large brand in the notable claims section above was reached, or claimed to be reached, through people and credentials rather than through a patchable flaw. Voice phishing at a help desk, an authorised connected application, an infostealer log bought from a market. No patch cycle addresses any of those.
Proof-of-concept publication is now the exploitation trigger. SharePoint moved into active exploitation after PoC code appeared. Track PoC releases for anything you run at the perimeter and treat that publication, rather than the vendor advisory date, as the start of your clock.
We report these as the flaws most associated with this week's most active actors. Knowing they are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch office firewall, an internet-reachable vCenter nobody in security knew was routable, or a SharePoint instance stood up for one project in 2021, is the part most teams cannot answer on a Monday morning.

Infrastructure and Operational Shifts

Big names, thin evidence, and a fortnight of unverified headlines. U.S. Bank, ReliaQuest, BOK Financial, Kingston Technology, Capgemini Engineering, BMW Group and Target all appeared in seven days. Not one of those listings arrived with a data volume, a file sample and a named affected system together. Two organisations have publicly stated that the claimed intrusion did not reach their systems. The listing is doing the work that evidence used to do, because the coverage arrives either way. Treat the appearance of a large brand on a leak site as a prompt to check your own exposure to that organisation as a supplier or customer, not as a confirmed breach.
The batch run is not the only volume model any more. For three weeks the field has been shaped by publication events. This week produced 287 postings with no run above 22, and the total was still the second highest of the month. More operators posting less each is a structurally different threat picture from a handful of operators posting a lot, and it is worse for defenders: it means more independent intake pipelines, more negotiation styles and fewer shared indicators.
Extortion without encryption reached a fifth of the field. 54 postings this week from eleven brands that do not deploy a locker. Coinbase Cartel alone has passed 160 claimed victims without ever encrypting anything, working from infostealer credentials and giving victims 48 hours to make contact and ten days to pay. If your incident response plan starts with restoring from backup, it does not cover this.
Actors are naming the platform instead of the customer. Kazu named clinical software rather than clinics. ShinyHunters names cloud application data rather than file servers. The technology sector row this week is full of vendors that sit upstream of their own customers. The company that gets named on a leak site is increasingly not the company whose data is at risk, and no supplier notification process is triggered by a leak site posting.
Agentic AI moved from research to operations. An operator ran reconnaissance, tunnelling malware development, ransom pricing and extortion note drafting through a coding agent, and another built and sold a ransomware product the same way. The techniques are old. The throughput is not.

Key Takeaways for Defenders

Patch vCenter now, and check whether it was reachable before you did. CVE-2026-59310 carries a CVSS score of 9.8, needs no authentication, and went from disclosure to hundreds of compromised networks in about a week. Confirm your build, confirm the management and syslog interfaces are not routable from untrusted networks, and hunt for anomalous outbound connections from vCenter hosts covering early August. Assume that anything vCenter manages, including backup infrastructure, is in scope if it was exposed.
Treat the SharePoint token bypass as an internet-facing problem. CVE-2026-55040 lets an unauthenticated attacker forge a valid token and act as a site administrator, and exploitation started once proof-of-concept code was public. Patch, then review authentication logs for the period before you patched. An externally reachable SharePoint holds exactly the documents an extortion crew wants and rarely appears in a perimeter inventory.
Fix the help desk, not just the firewall. Every one of this week's large-brand claims runs through credentials and people. Voice phishing that persuades staff to authorise a connected application, infostealer logs bought from a market, a single identity exposed in a social engineering attempt. Require out-of-band verification for any credential reset or application authorisation request, and inventory which third-party applications currently hold tokens into your cloud tenants.
Ask your clinical and industrial software suppliers the question directly. Kazu named nine platforms, not nine clinics. Titan named nine Italian firms in one day, which points at shared upstream access. Your supplier's leak site listing will not name you, and your supplier is under no obligation to tell you quickly. Ask now who has remote access into your estate and what it can reach.
Have an unverified-claim response ready before you need one. Six household names were claimed in seven days and at least two of those claims are disputed by the named organisation. Your communications team needs a pre-approved holding statement, and your CTI function needs a defined bar for what counts as evidence: a data volume, a verifiable sample, and a named affected system. A leak site listing on its own does not clear that bar.
Weight single-source claims lower, and say so in your reporting. 62 of this week's 287 postings rest on a single tracker, and 45 rows that looked like victims on one feed were web application test strings. If your threat intelligence pipeline consumes leak site data, corroboration across independent collections is the cheapest quality control available.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old. Watching external exposure, leaked credentials and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 287 posts down to the few that touch your domains, your brands and your vendors, then matching those actors to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: scrutex.ai/solution/threat.

Frequently Asked Questions

How many ransomware attacks happened the week of August 17 to 23, 2026? 287 unique victim postings appeared on dark web leak sites in that window, across 53 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is down 9% on last week's 314. Unlike recent weeks there was no batch publication run: the heaviest single day took 58 postings, 20% of the week.
Which ransomware group is most active right now? Qilin, on any measure that rewards consistency. It posted 35 victims across six of the seven days this week with no run larger than 11, and third-party tracking puts it above 500 victims in 2026 and roughly 1,500 since launch. The Gentlemen came second on 30, including a single 22-victim run spanning 15 countries on August 21, and reached the top of the field in the second quarter of this year. DireWolf posted 21 and Coinbase Cartel 20.
Did U.S. Bank get hit by ransomware? LockBit 5 listed usbank.com on August 20 with a 14 day countdown expiring September 3, naming no data volume and no affected systems. U.S. Bank has said it has no evidence that its internal systems or network were accessed without authorisation. Treat the claim as unverified. A listing with no sample, no volume and no named system is a negotiation opening rather than evidence of compromise.
Did ShinyHunters breach ReliaQuest? ReliaQuest confirmed an attack took place on August 22 and disputed the group's characterisation of it, saying a social engineering attempt temporarily exposed one identity, that no applications or systems were accessed, and that no customer data was touched. ShinyHunters listed the company on August 23 without publishing verified samples. The group's wider campaign against enterprise cloud applications is real and has reportedly touched over 1,000 organisations, but this specific listing is unproven.
What is CVE-2026-59310 and why does it matter? It is a path traversal vulnerability in the Broadcom VMware vCenter syslog service that lets an unauthenticated attacker with network access to vCenter execute arbitrary code. It carries a CVSS score of 9.8 and CISA added it to the Known Exploited Vulnerabilities catalog on August 18. It matters because exploitation began five days after disclosure and reached roughly 361 networks within a week, and because vCenter is the control plane for the virtual estate. Code execution there reaches every workload it manages, backup infrastructure included.
What did CISA add to the KEV catalog this week? Five vulnerabilities across two days. On August 17, CVE-2025-62593, a code injection flaw in the Ray distributed compute framework. On August 18, CVE-2026-55040 in Microsoft SharePoint, CVE-2026-59310 in Broadcom VMware vCenter, CVE-2026-33824 in the Microsoft Internet Key Exchange service extensions, and CVE-2026-65400 in Apple macOS.
Are ransomware groups using AI now? Yes, and August brought the clearest documentation of it so far. Anthropic published threat intelligence describing an operator that used its Claude Code agent for reconnaissance, initial access support, custom tunnelling malware built from the Chisel tool, analysis of stolen financial data to size the ransom, and drafting of the extortion notes, across at least 17 organisations with no encryption involved. A separate UK-based operator used the same tooling to build and sell a ransomware product. The techniques are not new. The change is throughput and a lower skill floor, which is consistent with the long tail we report every week: 53 groups this week, 30 of them with three victims or fewer.
Why did you remove 45 postings from this week's count? One upstream tracker attributed 46 entries to The Gentlemen on August 22 whose victim names were web application test payloads rather than organisations, including server-side template injection probes, cross-site scripting probes and path traversal strings. All arrived on a single feed with no claim URL. Left in, they would have made August 22 the heaviest day of the week, put The Gentlemen in first place on 76, and lifted the weekly total to 332. One genuine listing on that date was kept.
What sectors should I worry about most this week? The top four are unusually close: Technology 22, Manufacturing 20, Healthcare 19 and Business Services 18. Healthcare is the one to read carefully, because a single operator supplied eight of the 19 in one run against clinical software platforms rather than against clinics. 147 of the 287 postings carried no sector label, so read the counts alongside the percentages.
Where can I get this data in real time? Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands and vendors, so you see only the postings that touch your domains, brands or supply chain.