Ransomware weekly
369 views

Ransomware Attacks This Week: 362 Victims Across 45 Groups (August 3 to 9, 2026 )

By ScruteXPublished

Summary

This is the Scrutex ransomware weekly for the August 3 to 9, 2026 window. Our CTI team tracked 362 unique ransomware victim postings across 43 active groups during the period. That is up 68% on last week's 215, and it is the heaviest week we have recorded this year.
The rise is real, but it is not spread evenly. One Wednesday carried it. On August 5 alone, 111 victims appeared, 31% of the whole week, and four groups supplied 93 of them. Cl0p accounted for 40 of those 93 in a single posting run that lines up with its PTC Windchill extortion campaign. Three brands most defenders have never briefed on, Dark Project, Everest and Orion, supplied the other 53.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific flaws these groups are exploiting to get in. The standout story is newcomers. Four brands that did not appear in last week's report at all, Orova with 35 postings, L Group with 26, Dark Project with 19 and Orion with 15, walked straight into the top eight. Add Helix, LeakedData, Storm, Panzer and Barracuda and the newer names account for 130 postings, 36% of the week. The established operators did not slow down either. The Gentlemen posted 39, Qilin 38.
362 posts, 43 groups, 45 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names, resolved company names against bare domains that referred to the same victim, and dropped two re-listings that repeated an already-counted victim with the sector blanked. Where a single group backfills a large batch on one day, we flag it. This week two groups did, so read the headline total with that in mind.

In This Post

SectionWhat it covers
This Week at a GlanceHeadline numbers and the August 5 concentration
Group Activity BreakdownWho posted most, and what sits behind each run
New and Emerging GroupsOrova, L Group, Dark Project, Orion, and Helix
Sector Targeting AnalysisWhich industries took the named hits
Country DistributionWhere the 45 countries fall
Notable Claims and IncidentsFive named claims with confidence lines
Headlines Beyond the Leak SitesReported incidents that shape the week
Top CVEs These Groups Are ExploitingThe flaws driving initial access, led by CVE-2026-12569
Infrastructure and Operational ShiftsWhat is changing in how these crews work
Key Takeaways for DefendersThe short action list

This Week at a Glance

MetricValue
Total unique victims posted362
Change on prior weekUp 68% (from 215)
Active groups43
Countries hit45
Heaviest single dayAugust 5 (111 posts, 40 from Cl0p)
Second heaviest dayAugust 6 (77 posts, 26 from L Group)
Quietest dayAugust 8 (19 posts)
Most targeted countryUnited States (143 victims, 40% of postings)
Most targeted sectorManufacturing (63)
Top group by volumeCl0p (42 posts, 40 of them masked names)
New brands in the top eightOrova, L Group, Dark Project, Orion
Notable claimsStadler Rail, FIS Global, Uber, Bridgestone Americas, eleven US law firms
The week had one spike and one long shoulder. Monday August 3 opened quietly at 31. Tuesday rose to 45, carried by Orova's 24-victim debut run. Wednesday August 5 produced 111, the single heaviest day we have recorded, with Cl0p posting 40, Dark Project 19, Everest 19 and Orion 15. Thursday held at 77, of which L Group supplied 26 in one batch. Friday came in at 46, with The Gentlemen posting 25 of them. The weekend fell away to 19 and 33.
Read the 68% rise carefully. Four batch runs on three days, Cl0p's 40, L Group's 26, The Gentlemen's 25 and Orova's 24, account for 115 postings on their own. Strip those and the underlying field sits near 247, still well above last week's 215 and the highest baseline we have seen, but not the near-doubling the headline implies. The concentration is also lower than last week: the top five groups took 50% of volume compared with 59% a week ago, because the volume came from more brands rather than fewer.
As a sanity check on our own numbers, an independent leak site tracker counted 336 listings for the same August 3 to 9 window, with Cl0p at 42, Qilin at 38, Orova at 35 and L Group at 26. Our per-group counts match on all four. Our higher total and our higher United States figure come from merging two collections rather than one, which recovers postings a single feed missed and fills in country labels a single feed left blank.

Group Activity Breakdown

The top five groups produced 50% of the week's volume (180 of 362). Below them the field stays crowded: 22 groups posted three or fewer victims each, and 14 posted exactly one. What changed this week is not the shape of the tail but the top. Four of the eight busiest brands did not appear in last week's report at all.
RankGroupVictimsShareNotable Activity
1Cl0p4212%40 posted on August 5 with masked names, consistent with the PTC Windchill campaign. FIS Global claimed at 874GB
2The Gentlemen3911%Two runs, 25 on August 7 and 12 on August 9. Manufacturing and technology across Italy, Germany, Japan, Sweden and the US
3Qilin3810%The only group active on all seven days, closing the week with 13 on August 9. France, Germany, Romania, Japan, Taiwan and US mid-market
4Orova3510%New brand. 24 on August 4, US small business plus a Hong Kong and Taiwan cluster including Sanrio Hong Kong
5L Group267%New brand. All 26 on August 6, every listing a bare domain, spanning 15 countries including Bouygues Energies & Services
6Everest216%19 on August 5 including Stadler Rail, Al-Futtaim Group, Emirates Flight Catering, Keysight and EPM, then Ingersoll Rand and Omnicell on August 8
7Dark Project195%All on August 5, almost entirely US: Leviton, Thermo King, Mayco International, Ohio Living, Mile Bluff Medical Center
8Orion154%New brand. All on August 5 as bare domains, led by bridgestoneamericas.com and Hetero
9INC Ransom113%Spread across the week, US healthcare and manufacturing with a Vietnam, UK and Canada tail
10LeakedData113%Eleven US law firms in one August 8 run. This is Silent Ransom Group's leak site
11LockBit103%Nine of ten posted August 3, then silence for the rest of the week
12SafePay92%All nine on August 3, the same single-day German and European cluster pattern as last week
13Storm92%US only, banks, radiology practices and healthcare providers across August 6 and 7
14Play82%Steady low-volume posting, no batching
15RansomHouse72%Brazil, Italy and US mid-market
A long tail of groups (KryBit, DragonForce, Akira, Helix, Panzer, Barracuda, Anubis, Aurora, BlackNevas, Chaos, Gunra, Space Bears, Bravox, Lynx, Payload, 3AM, Global Secret Group, PayoutsKing, Triple X, Cry0, GammaX, Insomnia, LeakNet, NightSpire, Silent Ransom Group, Sovcali, ShinyHunters and Unsafe) each posted between one and seven victims.
Three observations:
Cl0p's masked run is the week's most consequential single event. All 40 of its August 5 postings use partially redacted names, a pattern Cl0p has used before to start the clock on negotiation without burning the victim publicly. The timing matters: security reporting through late July described Cl0p sending extortion emails with the subject line "Windchill PDMLink module serious data leak" while listing nothing on its leak site. This is the wave those emails were building towards. If you run PTC Windchill or FlexPLM and received one of those emails, treat the August 5 listings as evidence that the naming phase has started.
The newcomers are not one story, they are four different ones. Orova posted 35 across US small business and a Hong Kong and Taiwan cluster. L Group posted 26 bare domains in one batch, all large enterprises. Dark Project posted 19 named US mid-market firms with data volumes attached. Orion posted 15 bare domains including at least one with a backdated attack date from October 2025. Those are four different intake models, and only one of them, Dark Project, looks like conventional intrusion-led extortion. See the section below.
Qilin is the constant. 38 postings spread across all seven days, the only group in the set with no batch behaviour at all, finishing with 13 on August 9. Qilin has been the most consistently active operation of 2026 on a rolling 30-day view, and this week it kept that record without producing a single spike. The Gentlemen, by contrast, posted 39 in exactly two bursts. When you benchmark either group week to week, the difference between a steady operator and a batching operator matters more than the totals.

New and Emerging Groups

Orova: the fastest debut of the week

Orova posted 35 victims this week, 24 of them in one run on August 4. The group was first observed in May 2026 and was publicly flagged by threat intelligence trackers on August 4 when that bulk run landed. Its infrastructure is a Tor-hosted leak site, a separate Tor negotiation portal and a Tox contact identifier. Reporting classes it as a data broker operation running double extortion: encrypt where possible, exfiltrate always, then threaten publication.
The victim mix splits geographically. 23 of the 35 are United States firms, and they are small: veterinary clinics, dental practices, home improvement contractors, churches, a regional housing authority and a property owners association. The other cluster is Hong Kong and Taiwan, four victims each, and those are larger: Sanrio Hong Kong, Tat Fung Textile, JK Capital Management, SSI Holding (Far East), plus Taiwanese manufacturers Kingsson, Ultra Fame, DBM Reflex and Empyrean.
The read is that the two halves have different origins. A run of very small US organisations posted on one day looks like bulk intake from an access broker or a credential feed. A tight Hong Kong and Taiwan cluster of established firms looks like a separate campaign, possibly a shared upstream provider. Neither theory is confirmed. What is worth acting on is the Hong Kong concentration: five listed firms in one territory in one week is the kind of clustering that usually means a common supplier.

L Group: a newcomer that only posts large enterprises

L Group posted 26 victims, all on August 6, and every single listing is a bare domain rather than a company name. The spread is unusually wide for one batch: Argentina, Australia, Brazil, Canada, China, France, Germany, Hungary, India, Latvia, Luxembourg, Mexico, the US, Venezuela and Vietnam.
The detail that makes L Group worth logging is the target profile. Independent tracking of the group reports that every published victim generates more than 500 million dollars in annual revenue, which is unusual for a brand this new. Named examples include Bouygues Energies & Services, the French industrial and energy services arm, and Le & Associates, a Vietnamese human resources firm. The group steals data first and extorts second, with no evidence of an encryptor of its own.
Treat L Group as unproven but deliberately aimed. A new brand that only lists large enterprises either has genuine access to enterprise environments or is recycling data to establish credibility fast. There is not enough evidence yet to say which, and the bare-domain listing style gives defenders very little to verify against.

Dark Project and Orion: same day, opposite credibility

Both posted their entire week on August 5, and they are worth reading side by side because they look nothing alike under scrutiny.
Dark Project posted 19 named US and Canadian organisations with specifics attached. It emerged in late 2024 as a double-extortion operation, gains access through phishing and exposed remote desktop services, exfiltrates before deploying its locker, and publishes samples when victims refuse. Its listings this week include Leviton, Thermo King, Mayco International, Sutherland Packaging, Mile Bluff Medical Center, Ohio Living Home Health and Hospice, and the Canadian staffing firm Brainhunter, where reporting puts the stolen volume at more than 160GB. The Miller Group listing cites roughly 500GB. Named victims, stated volumes and a two-year history make this the most credible of the week's lesser-known brands.
Orion is the opposite case. It appeared recently by publishing 13 alleged victims at once and now lists 15 in our window, all bare domains. Analysis of the group finds no evidence of original ransomware development and no independently verified intrusions. Its public footprint is a leak site and promotional messaging. Its highest-profile listing, bridgestoneamericas.com, carries an attack date backdated to October 28, 2025. A new brand listing a year-old incident with no encryptor of its own is a recognisable pattern: resold, recycled, or repackaged data used to launch a leak site.

Helix: identity attacks, no encryption, and an Uber claim

Helix began operating in June 2026 and posted five victims this week: Uber, Morguard, Highwoods Properties, Westland Insurance and Venture Logistics. It does not encrypt. Reporting describes an identity-first playbook of voice phishing, device code phishing and multi-factor authentication abuse, used to reach and drain SharePoint environments.
That combination is the reason to brief it. Every control in a conventional ransomware playbook, backups, offline copies, locker detection, EDR tamper protection, is irrelevant to an attack that phones your service desk, walks a user through a device code prompt and downloads a document library. The Uber listing carried no sample data and should be treated as an unverified claim, but the technique behind it is well documented and does not depend on any software flaw you can patch.

Sector Targeting Analysis

Across the 362 victim postings this week:
SectorVictimsShare of all postings
Manufacturing6317%
Technology4512%
Business Services339%
Healthcare298%
Consumer Services257%
Financial Services216%
Construction and Real Estate164%
Energy113%
Transportation and Logistics113%
Education92%
Agriculture and Food92%
Hospitality and Tourism82%
A caveat on these shares. 75 of the 362 postings carried no usable sector label, most of them Cl0p's masked names and LeakedData's law firm run. The percentages above are shares of all postings, so they understate each sector's real share of the 287 classified victims. Read the counts, not just the percentages. Note also that our two sources use different sector vocabularies, and one of them combines construction with real estate, so that row holds both.
What this tells us:
Manufacturing led again at 63 victims, up from 41 last week, and it now sits at nearly 22% of everything we could classify. The Gentlemen fed a large share of it with their August 7 run of Italian, German, Swedish and Japanese industrial firms. Everest added Stadler Rail, Allied Telesis, Formulatrix and Ingersoll Rand. Dark Project added Leviton, Thermo King, Mayco and Sutherland Packaging. The pattern from last week holds: these are component makers, tooling firms and industrial suppliers rather than consumer brands, and a supplier listing carries weight far beyond the named company.
Technology followed at 45, and the composition is worth noting. It mixes IT services firms, software vendors and hosting providers, several of which sit upstream of their own customers. An IT services listing is worth checking for downstream reach into every client that vendor touches.
Business Services at 33 is inflated by the legal sector this week. LeakedData's eleven law firms all fall here, alongside architecture practices, staffing firms and marketing agencies. Law firms are a specific and repeating target: they hold litigation files, merger documents and client financials, and they are usually smaller and less defended than the clients whose data they hold.
Healthcare at 29 skews small again. The listings are dental practices, radiology associates, home health providers, a hospice and a handful of regional medical centres rather than hospital systems. That profile carries HIPAA and PHI exposure at organisations with thin IT teams and no dedicated security function.
Financial Services at 21 is the sector to read alongside the Cl0p caveat. The named entries are community banks and insurance brokers, but Cl0p's masked run includes stubs beginning fis, jpm and bri, and reporting has separately tied Cl0p's August 5 activity to a claim against FIS Global at 874GB. If the masked names resolve to financial technology providers, this sector's real number is materially higher than 21.

Country Distribution

The United States accounts for 143 of 362 postings, 40% of the total and 49% of the 294 postings where a country was recorded. That is close to last week's 43% and still well above the long-run share of roughly 29%.
RankCountryVictims
1United States143
2Germany14
3United Kingdom11
4France9
5Italy9
6India8
7Brazil8
8Canada7
9China6
10Taiwan6
11Argentina5
12Japan5
13Hong Kong5
14Switzerland4
15Romania3
A further 30 countries recorded one to three victims each, including Thailand, Vietnam, the UAE, Belgium, Singapore, Cyprus, South Korea, Indonesia, South Africa, Finland, Poland, Austria, Australia, Mexico, Hungary, Peru, Sweden, Israel, Spain, Egypt, Colombia, Malaysia, Latvia, Luxembourg, Venezuela, Turkey, Panama, Oman, the Czech Republic and Nigeria.
Two regional points stand out. Hong Kong and Taiwan together account for 11 victims, and eight of those come from Orova's single run. That is the difference between a territory under sustained pressure and a territory appearing because one actor posted a batch. Germany at 14 is spread across eight different operators, Qilin and The Gentlemen with three each, Orion and L Group with two each, and four more with one apiece. No single batch produced it, which makes it a more meaningful signal than a one-actor number.
The breadth, 45 countries in one week, shows how affiliate-driven extortion now operates globally. Geographic distribution tracks revenue opportunity, not threat actor location. For readers outside the United States the practical point is unchanged: map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, APRA CPS 234 in Australia, before an incident forces the question.

Notable Claims and Incidents

The five items below all appear on public leak sites or in named vendor reporting. We state what the actor claimed, the data categories where they were given, and end each with a confidence line.

1. Everest publishes the Stadler Rail data after a refused demand

Everest listed Stadler Rail, the Swiss rail vehicle manufacturer, on August 5 and published what it describes as a 201GB archive of more than 271,000 files, including technical documentation, configuration data and CCTV footage. Reporting states Stadler refused a 12.3 million dollar demand following a July intrusion, and that the attackers did not breach Stadler's own network. They used compromised credentials belonging to a supplier data exchange platform.
Confidence: High. The dataset is published rather than threatened, the volume and file count are stated and consistent across multiple reports, and the victim's refusal has been publicly reported. This is the clearest supply-chain lesson of the week. A hardened manufacturer was reached through a third-party file exchange, which means your own exposure assessment has to cover the platforms your suppliers use to send you files, not only the systems you own.

2. Cl0p claims FIS Global as part of the masked August 5 run

Cl0p posted 40 partially masked victim names on August 5. Separate reporting ties the group to a claim against FIS Global, the payments and banking technology provider, citing 874GB of exfiltrated data. One of the masked stubs in our data set begins with fis.
Confidence: Medium. The Cl0p posting run is confirmed and the FIS Global claim is reported by multiple outlets, but the masked listing format means the link between a specific stub and a specific company cannot be verified from the leak site alone, and the claimed volume is the attacker's figure. The scope is what matters here: a payments and banking technology provider sits upstream of the banks and credit unions that run on it, so downstream institutions should be asking their processor directly rather than waiting for a public confirmation.

3. LeakedData names eleven US law firms in one run

On August 8, LeakedData listed Mayer Brown, Fox Rothschild, Barclay Damon, Marshall Dennehey, Porter Wright, Rutan & Tucker, Farella Braun + Martel, Floyd Skeren Manukian Langevin, Moses & Singer, Ropers Majeski and Sandberg Phoenix. LeakedData is the data leak site that Silent Ransom Group publishes through, and Mayer Brown had already appeared under the Silent Ransom Group label a day earlier. Silent Ransom Group works through callback phishing and IT help desk impersonation, steals data and does not deploy an encryptor. Moses & Singer was named by the same operator in last week's report.
Confidence: Medium. The postings are real and the operator's focus on the legal sector is well documented across 2025 and 2026, but no sample data accompanied the run and none of the eleven firms has confirmed an incident. Read this as one campaign against one sector rather than eleven independent breaches, and note that the three-day ultimatum this operator typically issues means the window for a quiet resolution is short.

4. Helix claims Uber

Helix listed Uber on August 6, alongside Morguard, Highwoods Properties, Westland Insurance and Venture Logistics. Helix started operating in June 2026 and steals data through voice phishing, device code phishing and multi-factor authentication abuse against SharePoint environments rather than through software exploitation.
Confidence: Low. The listing carried no sample data, Uber has not confirmed an incident, and Helix is a new brand with a short track record. The claim itself should not drive escalation. The technique behind it should: if your help desk can be talked into approving a device code prompt, no patch cycle protects the document libraries behind it.

5. Orion claims Bridgestone Americas on a backdated incident

Orion listed bridgestoneamericas.com on August 5 with an attack date recorded as October 28, 2025, and a claim of 74 compromised user accounts. Orion's listings are all bare domains, and analysis of the group finds no evidence of its own encryptor and no independently verified intrusions.
Confidence: Low. A new leak site publishing an incident from nine months earlier, with no encryption indicator and no samples, is more consistent with resold or recycled data than with a fresh compromise. The "sold privately, no leak planned" framing that accompanies this style of listing is the tell. Validate independently before treating this as a current breach.

Headlines Beyond the Leak Sites

Two developments shape how you should read this week's numbers even though they are not victim counts.
Cl0p's Windchill campaign moved from email to leak site. Through late July, Cl0p sent extortion emails to large internal distribution lists at affected organisations with the subject line "Windchill PDMLink module serious data leak", while listing nothing publicly. As of late July, security reporting noted that no victims from the campaign had been named. The August 5 run of 40 masked listings is the naming phase beginning. Expect the masks to come off in stages, which is the pattern Cl0p has followed in previous mass-exploitation campaigns.
A Gentlemen affiliate is running command and control through Ethereum. Researchers detected an intrusion toolkit on August 4 belonging to a suspected affiliate of The Gentlemen, deploying a backdoor called EtherRAT. Instead of hardcoding command and control addresses, EtherRAT queries an Ethereum smart contract through public RPC services to retrieve a rotating C2 domain. The malware is a Node.js trojan delivered as an MSI through remote scheduled tasks, persisting through a Run key named "WindowsHost". EtherRAT was first documented by Sysdig in December 2025 with initial access through CVE-2025-55182 on Linux servers, and a Windows variant surfaced in March 2026.
That second item is an operational shift worth understanding. Blocking a C2 domain does nothing when the next one is published on a public blockchain that cannot be taken down or seized. Detection has to move to the behaviour, the scheduled task, the MSI, the Run key, the outbound queries to Ethereum RPC endpoints, rather than the address.

Top CVEs These Groups Are Exploiting

One flaw dominates this week, and it is the reason the top of the chart looks the way it does. Alongside it, the established operators continue to work the same set of edge, hypervisor and driver flaws. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution is tied to a named vendor or government source, with a note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific actor, we left it out.
CVEProductSeverityWho is using itWhy it matters
CVE-2026-12569PTC Windchill and FlexPLM9.3Cl0pUnsafe deserialization giving unauthenticated remote code execution on internet-exposed product lifecycle management servers. Cl0p affiliates exploited it as a zero-day from early June 2026, dropping JSP web shells and exfiltrating engineering and product data. Patched June 17, added to the CISA KEV catalog at the end of June. This is the week's priority item and the source of Cl0p's 40 masked listings.
CVE-2024-55591Fortinet FortiOS and FortiProxy9.6The Gentlemen, QilinAuthentication bypass on the FortiGate management interface. The Gentlemen, tracked by Microsoft as Storm-2697, maintains a large inventory of compromised FortiGate devices and valid VPN credentials for fast initial access. This remains the load-bearing, first-party-confirmed vector for both groups (Fortinet PSIRT; Microsoft; Unit 42).
CVE-2024-21762Fortinet FortiOS SSL VPN9.8QilinOut-of-bounds write allowing unauthenticated remote code execution on FortiGate. Tens of thousands of devices remained exposed months after the patch shipped.
CVE-2024-24919Check Point Remote Access VPN8.6QilinInformation disclosure in the Check Point Security Gateway VPN blade that leaks sensitive files, including password hashes, from internet-facing gateways. Used alongside the Fortinet flaws to widen VPN access options (Check Point; CISA).
CVE-2025-32433Erlang/OTP SSH10.0The GentlemenUnauthenticated pre-auth remote code execution reaching root over the network. Reported as a secondary entry vector adopted to diversify beyond Fortinet (Unit 42; Cisco PSIRT; group tie is analyst-reported).
CVE-2025-7771ThrottleStop.sys driver (BYOVD)7.8The GentlemenA legitimate signed driver with unrestricted physical memory access, renamed and weaponised to disable Defender, CrowdStrike and Bitdefender before encryption runs (Kaspersky GERT; Halcyon; group tie is analyst-reported).
CVE-2024-37085VMware ESXi6.8Akira, The GentlemenAuthentication bypass that hands an attacker admin control of an ESXi host by creating a specific Active Directory group, enabling mass encryption of every virtual machine on the host. First-party confirmed for Akira; The Gentlemen tie is analyst-reported (Microsoft; CISA AA24-109A).
CVE-2025-55182React2ShellCriticalEtherRAT operators, including a suspected Gentlemen affiliateThe original initial-access vector for the EtherRAT backdoor against Linux servers, first documented by Sysdig in December 2025. Relevant this week because the same backdoor now appears in a Gentlemen affiliate toolkit with blockchain-based C2.
A note on attribution accuracy. Several of this week's highest-volume groups have no verifiable exploit attribution at all. Orova, L Group, Dark Project and Orion are newer brands with no published CVE tie, and their posting patterns are consistent with access-broker intake, credential feeds, phishing or exposed remote desktop rather than a named flaw. Helix and LeakedData are not exploiting a software vulnerability in any of this week's listings: both use identity and social engineering, which means patching does nothing and the controls that matter are help desk verification, device code policy and connected-application review.
A few practical notes:
Product lifecycle management is now an internet-facing crown jewel. Windchill and FlexPLM hold engineering drawings, bills of materials, supplier terms and product roadmaps. Most organisations classify those systems as internal even when the server is reachable from the internet. If you run either product, confirm the June 17 patch is applied, check for JSP web shells rather than assuming the patch closed the incident, and treat any organisation that received a "Windchill PDMLink module serious data leak" email as already in scope.
The patch is not the remediation when web shells are involved. Cl0p exploited this flaw for roughly two weeks before a fix existed. Patching stops new exploitation and does nothing about a web shell already dropped in June. Hunt before you close the ticket.
VPN appliances still carry the ransomware volume. Fortinet and Check Point gateways drove access for The Gentlemen and Qilin this week, and those two groups posted 77 victims between them. Internet-facing, unpatched, credential-exposed VPNs are how affiliates get in before any locker runs.
Your help desk is now an attack surface with no patch. Helix, Silent Ransom Group and its LeakedData leak site produced 17 postings this week, covering 16 organisations, using voice phishing, callback phishing and device code abuse. Write down who is allowed to approve an MFA reset or a device enrolment, and make verification mandatory rather than discretionary.
We report these as the flaws most associated with this week's most active actors. Knowing they are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch office firewall, an internet-exposed PLM server nobody in security knew was reachable, or a supplier's file exchange platform, is the part most teams cannot answer on a Monday morning.

Infrastructure and Operational Shifts

Mass exploitation is back at the top of the chart. Cl0p reached number one this week without running a single conventional intrusion campaign. One unauthenticated flaw in one enterprise product produced 40 listings in a day. That model, find an internet-exposed enterprise application with a deserialization bug, exploit it broadly, then extort in waves, has now produced the largest single-day posting run of the year.
The barrier to launching a leak site brand has collapsed. Four brands entered the top eight this week. Orova was first seen in May, Helix in June, Orion within the last few months. Two of them, L Group and Orion, list only bare domains with no encryption indicator and no samples. A leak site is now cheap enough that publishing recycled or resold data is a viable way to establish a brand, which means a name you have never seen is neither automatically low priority nor automatically credible. Judge the listing, not the logo.
Extortion without encryption is now a large share of the field. Helix, LeakedData, Silent Ransom Group, L Group and Orion together produced 58 postings this week, covering 57 organisations, and not one of those listings depends on an encryptor. Your ransomware playbook needs a branch for the case where nothing is encrypted, nothing is down, and the only pressure is a data set the attacker already holds. The legal, communications and regulatory work in that branch is most of the response.
Command and control is moving somewhere it cannot be seized. The EtherRAT toolkit resolves its C2 from an Ethereum smart contract through public RPC endpoints. Domain takedowns and sinkholing do not apply to a contract on a public blockchain. Detection engineering has to shift to the delivery chain and the outbound query pattern.
Supplier platforms are the reliable way into a hardened target. Stadler Rail was reached through a supplier data exchange platform, not through its own network, and the result was 271,000 files published. The company that gets named is not always the company that was breached.

Key Takeaways for Defenders

Find every internet-exposed PTC Windchill and FlexPLM server today. CVE-2026-12569 is an unauthenticated remote code execution flaw with a 9.3 severity score, it is in the CISA KEV catalog, and Cl0p exploited it as a zero-day from early June before the June 17 patch existed. Confirm the patch, then hunt for JSP web shells regardless of patch status. If anyone in your organisation received an email titled "Windchill PDMLink module serious data leak", treat that as an active incident, not spam.
Assume the masked Cl0p names come off. Forty organisations are currently listed under partial names. That is a negotiation tactic, not a permanent state. If you have any reason to think you are one of them, start the disclosure and legal work now rather than after your name appears in full.
Audit the file exchange platforms your suppliers use. Stadler Rail refused a 12.3 million dollar demand and had 271,000 files published, reached through a supplier's data exchange platform rather than its own network. Inventory the third-party portals your engineering, procurement and finance teams send documents through, and confirm who holds credentials to each.
Write down who can approve an MFA reset or a device enrolment. Helix, Silent Ransom Group and LeakedData produced 17 postings this week, covering 16 organisations, using voice phishing, callback phishing and device code abuse against SharePoint and legal document stores. No patch addresses this. A named verification procedure at the help desk does.
Treat manufacturing suppliers as this week's supply-chain risk again. Manufacturing took 63 named hits, up from 41 last week, and most were component makers, tooling firms and industrial suppliers rather than recognisable brands. Map which of your inputs come from firms that would never make a headline. Those are the listings that reach you indirectly.
Judge new brands on evidence, not novelty. Four brands entered the top eight. Dark Project publishes named victims with stated data volumes and has a two-year history. Orion publishes bare domains with a backdated incident and no encryptor. Those two deserve very different responses, and the volume ranking does not tell you which is which.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old. The Bridgestone Americas listing this week carries an attack date from October 2025. Watching external exposure, leaked credentials and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 362 posts down to the few that touch your domains, your brands and your vendors, then matching those actors to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at https://scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: https://scrutex.ai/solution/threat.

Frequently Asked Questions

How many ransomware attacks happened the week of August 3 to 9, 2026? 362 unique victim postings appeared on dark web leak sites in that window, across 43 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is up 68% on last week's 215. Four batch runs account for 115 of those postings, so the underlying field sits closer to 247, which is still the highest baseline we have recorded this year.
Which ransomware group is most active right now? Cl0p topped this week with 42 postings, but 40 of them landed in a single mass-exploitation run with masked victim names. On sustained activity, Qilin is the more accurate answer: 38 postings spread across all seven days, with no batching, continuing a pattern that has made it the most consistently active operation of 2026. The Gentlemen posted 39 in two bursts.
What is CVE-2026-12569 and why does it matter? It is an unsafe deserialization vulnerability in PTC Windchill and FlexPLM with a severity score of 9.3, allowing unauthenticated remote code execution on internet-exposed servers. Cl0p affiliates exploited it as a zero-day from early June 2026, dropped JSP web shells and stole engineering and product data. PTC patched it on June 17 and CISA added it to the Known Exploited Vulnerabilities catalog at the end of June. It matters because product lifecycle management systems hold designs, bills of materials and supplier terms, and because patching alone does not remove a web shell dropped before the fix.
Who are Orova, L Group, Dark Project and Orion? Four brands that entered the top eight this week. Orova was first seen in May 2026 and posted 35 victims, mostly small US firms plus a Hong Kong and Taiwan cluster. L Group posted 26 bare domains in one batch and reportedly lists only companies above 500 million dollars in revenue. Dark Project emerged in late 2024, posted 19 named US and Canadian victims with stated data volumes, and is the most credible of the four. Orion posted 15 bare domains, has no evidence of its own encryptor and no verified intrusions, and listed one victim with an attack date backdated to October 2025.
Did Uber, Bridgestone or FIS Global get hit by ransomware? Helix posted an Uber claim with no sample data, Orion posted a Bridgestone Americas domain with a backdated October 2025 attack date, and Cl0p is reported to claim 874GB from FIS Global as part of its masked August 5 run. None of the three has been confirmed by the named company. Treat the Uber and Bridgestone claims as low confidence and the FIS Global claim as medium confidence, and validate before reacting to any of them.
What happened to Stadler Rail? Everest published what it describes as 201GB and more than 271,000 files, including technical documentation, configuration data and CCTV footage, after Stadler Rail refused a 12.3 million dollar demand following a July intrusion. Reporting states the attackers did not breach Stadler's network directly. They used compromised credentials for a supplier data exchange platform. This is the week's clearest supply-chain lesson.
What CVEs are these groups exploiting? CVE-2026-12569 in PTC Windchill and FlexPLM leads this week and drove Cl0p to the top of the chart. On the established side, The Gentlemen and Qilin use Fortinet FortiOS (CVE-2024-55591, CVE-2024-21762), Qilin adds Check Point VPN (CVE-2024-24919), The Gentlemen use Erlang/OTP SSH (CVE-2025-32433) and the ThrottleStop driver (CVE-2025-7771) to disable endpoint protection, and Akira and The Gentlemen use VMware ESXi (CVE-2024-37085). Orova, L Group, Dark Project and Orion have no published exploit attribution. Helix and LeakedData are not exploiting a software flaw at all: they use voice phishing, device code abuse and MFA manipulation.
What sectors should I worry about most this week? Manufacturing led at 63 named victims, ahead of Technology at 45, Business Services at 33 and Healthcare at 29. Manufacturing ran high because The Gentlemen, Everest and Dark Project all targeted industrial and component suppliers. 75 of the 362 postings carried no sector label, so read the counts alongside the percentages.
Where can I get this data in real time? Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands and vendors, so you see only the postings that touch your domains, brands or supply chain.