Weekly Ransomware Intelligence Report, July 12, 2026
By ScruteX Published Updated
Summary
This is the Scrutex ransomware weekly for the July 6 to 12, 2026 window. Our CTI team tracked 242 unique ransomware victim claims across 37 active groups during the period. That is up 17% on last week's 207, but the rise is a mirage. One group, DeadLock, posted 64 victims in a single batch on July 10, and 63 of those landed on that one day. Strip the DeadLock backfill out and the underlying field sits at 178, below last week's genuine 207. The Gentlemen followed on real breadth with 40, Qilin held third with 32, and no other group broke 11. United States firms made up 27% of all victims, down from 34% last week, because the DeadLock dump skewed European and Latin American.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific CVEs these groups are exploiting to get in. The standout story this week is a single-day dump. Volume ran normal to quiet for six days, from 10 to 56 a day, then spiked to 93 on Friday July 10 when DeadLock emptied a batch of low-detail victims onto its blog. Read past that one day and the week was steady, led by two familiar names running deliberate campaigns rather than a mass release.
242 posts, 37 groups, 56 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names and resolved them to one entry. Where a single group backfills a large batch on one day, as DeadLock did this week, we flag it rather than letting it inflate the trend silently.
In This Post
| Section | What it covers |
|---|---|
| This Week at a Glance | Headline numbers and why the rise is a backfill |
| Group Activity Breakdown | Who posted most, and the stories worth reading |
| New and Emerging Groups | DeadLock and CRPxO, the week's volume newcomers |
| Sector Targeting Analysis | Which industries took the named hits |
| Country Distribution | Where the 56 countries fall |
| Notable Claims and Incidents | Five named claims with confidence lines |
| Top CVEs These Groups Are Exploiting | The flaws driving initial access |
| Infrastructure and Operational Shifts | What is changing in how these crews work |
| Key Takeaways for Defenders | The short action list |
This Week at a Glance
| Metric | Value |
|---|---|
| Total unique victims posted | 242 |
| Change on prior week | Up 17% (from 207) |
| Underlying total minus DeadLock batch | 178 |
| Active groups | 37 |
| Countries hit | 56 |
| Heaviest single day | July 10 (93 posts, 63 from DeadLock) |
| Quietest day | July 8 (10 posts) |
| Most targeted country | United States (27% of postings) |
| Most targeted sector | Business Services (43) |
| Top group by volume | DeadLock (64 posts) |
| Notable major-brand claims | Mercedes-Benz Turk, Frankfurt-Hahn Airport, Tonnies Group, Mercado Libre, Retelit |
The week reads calm until Friday. Daily volume held between 10 and 56 through Thursday, then jumped to 93 on July 10 before falling back to 16 and 12 over the weekend. That single spike is almost entirely one group. DeadLock posted 63 of its 64 weekly victims on July 10, a batch of thin, low-detail entries across Spain, Poland, Italy, and Germany. Take that batch out and July 10 drops to 30, in line with the rest of the week.
This matters for the headline. The 17% rise on last week's 207 is not a real increase in activity. It is one operator emptying a queue on one day. The top group took 26% of the week's volume on its own, and the top five together took 64%, both figures inflated by the DeadLock dump. Underlying fresh leak-site activity ran normal-to-quiet, and the true week-over-week trend is flat to slightly down once you weight for the batch.
Group Activity Breakdown
The top 5 groups produced 64% of the week's volume (154 of 242 postings), but that concentration is an artefact of the DeadLock batch rather than a genuine narrowing of the field. Below the top three the list stays crowded: 12 groups posted two or fewer victims each, and 10 posted exactly one. The leak site space remains fragmented after the LockBit and ALPHV takedowns of 2024 to 2025. New brands keep entering, and affiliate crews keep splitting off to launch their own programs.
| Rank | Group | Victims | Share | Notable Activity |
|---|---|---|---|---|
| 1 | DeadLock | 64 | 26% | 63 posted in one batch on July 10, mostly thin domain and company entries across Spain, Poland, Italy, and Germany |
| 2 | The Gentlemen | 40 | 17% | Ran the week's widest real spree: Tonnies (Germany), Mercado Libre (Argentina), BDO Greece, INTERNET AG, spread over four days |
| 3 | Qilin | 32 | 13% | Broad international run across manufacturing, healthcare, and telecom, including Retelit (Italy) |
| 4 | SafePay | 10 | 4% | Concentrated German cluster on July 6, including Frankfurt-Hahn Airport |
| 5 | APT73 (Bashe) | 8 | 3% | Former LockBit affiliate, LockBit-style leak blog, mixed geography |
| 6 | Akira | 7 | 3% | US and UK mid-market, VMware ESXi and VPN access |
| 7 | Booba Project | 6 | 2% | Newer brand, US and European mix, thin victim profiles |
| 8 | DragonForce | 6 | 2% | SimpleHelp RMM pivot, MSP-to-client risk |
| 9 | CRPxO | 6 | 2% | Almost entirely US dental and medical practices |
| 10 | Doommageddon | 5 | 2% | Big-brand claims on thin proof, Mercedes-Benz Turk among them |
| 11 | Chaos | 4 | 2% | US manufacturing and financial services |
| 12 | Space Bears | 4 | 2% | Exfil-extortion brand, European and US targets |
A long tail of groups (CMD Organization, Anubis, M3rx, LockBit, Settra, Ailock, KryBit, INC Ransom, Play, Titan, Interlock, Payload, Brain Cipher, PayoutsKing, and roughly 12 more) each posted between one and four victims.
Three observations:
DeadLock drove the number, not the threat. Its 64 postings were 63 on one day, a queue-clearing dump of low-detail entries rather than 64 fresh intrusions. Many carried no sector label and only a company or domain name. DeadLock, active since early 2025, runs a data-leak extortion model and periodically releases large batches that inflate a single day. Treat its 64 as a backlog release, not a surge, and weight the count accordingly when you brief the week.
The Gentlemen ran the week's widest real spree. Its 40 postings spread across four days and named companies with profiles attached: Tonnies, one of Europe's largest meat processors, Mercado Libre, the Latin American e-commerce and fintech giant, BDO Greece, INTERNET AG in Germany, and a cluster of US and European firms. No mass free dump, just steady high-volume posting of identified companies. The Gentlemen, which Microsoft tracks as Storm-2697 and PRODAFT tracks as LARVA-368, has scaled fast since mid-2025 on the back of a Fortinet foothold and a self-propagating Go encryptor. See the CVE section for the specific flaws driving its intrusions.
Qilin held a genuine third on breadth. Its 32 postings crossed manufacturing, healthcare, telecom, and public-sector victims across many countries, in line with its profile as the most consistently active RaaS brand of 2026. Qilin's edge-appliance focus, both Fortinet and Check Point VPN, is the throughline behind that volume. Between The Gentlemen and Qilin, the two ran 72 real, profiled victims this week, more than the DeadLock batch and a better read on where the actual pressure sits.
New and Emerging Groups
DeadLock: batch-release data extortion
DeadLock posted 64 victims this week, all but one on July 10. Active since early 2025, it runs a data-leak extortion model with no substantiated encryptor tied to the 2026 postings, and its intake style, high volume with thin per-victim detail, points to feed-sourced access rather than hands-on intrusion of each named target. The July 10 batch spread across Spain, Poland, Italy, Germany, and Latin America, with many entries carrying no sector label.
DeadLock is worth watching less for tooling and more for how a single batch distorts a weekly count. New and mid-tier crews front-load volume to look established to affiliates, and a queue release on one day can add 60-plus names that are weeks or months old. Treat a DeadLock listing as a prompt to confirm your own exposure, not as proof of a fresh compromise. There is no public source tying DeadLock to a specific, verifiable CVE, so weight its count against the strong chance that most entries are backlog.
CRPxO: US healthcare and dental focus
CRPxO posted 6 victims, almost all US dental and medical practices, from pediatric dentistry to small clinics. It favours small healthcare providers with thin IT teams and high regulatory exposure, a target profile consistent with credential-feed and access-broker intake rather than a signature exploit.
The read on CRPxO is the same as on any small-provider-focused crew: the pressure is regulatory and reputational. A CRPxO listing means patient data is claimed to be out, with HIPAA and PHI exposure attached, not that a hospital system is down. As with DeadLock, no public source ties CRPxO to a specific CVE.
Sector Targeting Analysis
Across the 242 victim postings this week:
| Sector | Victims | Share |
|---|---|---|
| Business Services | 43 | 18% |
| Manufacturing | 32 | 13% |
| Construction | 21 | 9% |
| Technology | 19 | 8% |
| Healthcare | 18 | 7% |
| Financial Services | 14 | 6% |
| Consumer Services | 11 | 5% |
| Agriculture and Food | 11 | 5% |
| Energy | 8 | 3% |
| Real Estate | 7 | 3% |
| Transportation and Logistics | 6 | 2% |
A caveat on these shares. Roughly 37 of the 242 postings carried no usable sector label this week, most of them thin entries from the DeadLock batch and the long tail. The percentages above are of all postings, so they understate each sector's real share of the classified victims. Read the counts, not just the percentages.
What this tells us:
Business Services led at 43 victims. Professional-services firms hold large volumes of client data on light security budgets, which keeps them the affiliate sweet spot. The Gentlemen, Qilin, and the DeadLock batch all fed this sector this week.
Manufacturing took second at 32, a heavier week than usual. Industrial firms with flat OT and IT networks run a low tolerance for downtime, and several claims here carry supply-chain weight: Tonnies in food processing, and a cluster of engineering and precision-parts makers. Manufacturing claims sit upstream of many other victims.
Construction and Technology followed at 21 and 19. Construction is over-represented this week because the DeadLock batch swept up many real-estate and building firms across Europe and Latin America. Technology suppliers sit upstream of their own customers, which is why an IT-services listing is worth checking for downstream reach.
Healthcare drew 18 named hits. The list skews towards small clinics, dental practices, and device makers rather than large hospital systems, with CRPxO's dental cluster and several medical-management firms in the bucket. Healthcare claims carry HIPAA and PHI exposure, and the providers named skew towards organisations with thin IT teams.
Country Distribution
The United States accounts for 27% of all postings this week (66 of 242), down from 34% last week. The drop is not a US reprieve. It is the DeadLock batch pulling the mix towards Europe and Latin America, where 63 of its 64 victims sat. Strip that batch and the US share climbs back towards its long-run share of affiliate-driven extortion. The US remains the single largest target market by a wide margin.
| Rank | Country | Victims |
|---|---|---|
| 1 | United States | 66 |
| 2 | Germany | 19 |
| 3 | Italy | 17 |
| 4 | Spain | 11 |
| 5 | Argentina | 10 |
| 6 | United Kingdom | 9 |
| 7 | India | 7 |
| 8 | Brazil | 6 |
| 9 | Poland | 6 |
| 10 | Canada | 5 |
| 11 | Czech Republic | 5 |
| 12 | Mexico | 4 |
A further 44 countries had one to four victims each, including France, Singapore, China, Hungary, Turkey, Hong Kong, Australia, Saudi Arabia, Romania, Ireland, Ghana, Russia, Greece, Morocco, Colombia, UAE, Uruguay, Portugal, Netherlands, Croatia, Lithuania, Sweden, Denmark, Papua New Guinea, Norway, Switzerland, Angola, Gabon, Bulgaria, Mayotte, Philippines, Algeria, Iran, Pakistan, Kenya, Oman, Egypt, Paraguay, Taiwan, Belgium, Bolivia, Costa Rica, Malaysia, and the Dominican Republic.
The breadth, 56 countries in a single week, shows how affiliate-driven RaaS now operates globally, and a single European-weighted batch can widen the map fast. Geographic distribution tracks revenue opportunity, not threat actor location. The Gentlemen alone touched Germany, Argentina, Greece, and the US in one run, while Qilin and DeadLock spread across Europe and Latin America. Operators follow data volume into whichever regional pocket is exposed.
For readers outside the United States, the regional point holds this week. German industrial firms drew 19 hits, Italian and Spanish firms another 28 between them, and Argentina saw a retail and services cluster. Map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, before an incident forces the question.
Notable Claims and Incidents
The four claims below all appear on public leak sites. We name only what the actor posted, summarise the data categories claimed, and end each with a confidence line. None were independently confirmed as a compromise at the time of writing.
1. SafePay claims Frankfurt-Hahn Airport
SafePay posted the German regional airport hahn-airport.de on July 6, one of nine German targets the group listed the same day. SafePay ran a tight, geography-focused cluster rather than a scattered spread, which is consistent with a single access campaign into a regional pocket.
Confidence: Medium. The concentrated German run points to real access, and a transport hub carries operational and passenger-data exposure. The specific data scope is not corroborated, so validate before treating a service or data impact as confirmed.
2. The Gentlemen claim Tonnies Group
The Gentlemen listed Tonnies, one of Europe's largest meat processors, during the group's 40-victim week. Tonnies is a real German firm central to EU pork and food supply, and the group attaches company profiles to its postings rather than dumping raw domains.
Confidence: Medium. The posting is genuine and the company checks out, but no company confirmation or sample data is available, so the impact is unconfirmed. A confirmed breach here would carry food supply-chain weight across German and EU retail.
3. The Gentlemen claim Mercado Libre
The Gentlemen also listed Mercado Libre, Latin America's largest e-commerce and fintech platform, on July 7. A claim of this size against a company that runs its own mature security program is exactly the kind of listing built to draw headlines.
Confidence: Low. The posting is real, but the target's scale and security maturity make an unverified claim worth heavy scrutiny. Confirm samples before anyone briefs this as a breach.
4. Qilin claims Retelit
Qilin posted the Italian fibre and data-centre carrier Retelit on July 11, part of its broad international run. Telecom operators hold routing, connectivity, and customer records, which widens the exposure beyond the named firm.
Confidence: Medium. Retelit is a real Italian carrier and Qilin's posting pattern is consistent with genuine access, but the data scope is not independently corroborated. A confirmed dump would carry downstream risk for connected businesses.
Top CVEs These Groups Are Exploiting
The groups leading this week mostly exploit a known set of edge-device, VPN, hypervisor, and driver flaws, plus credential reuse. Qilin and The Gentlemen both lean on Fortinet and, in Qilin's case, Check Point VPN for initial access. Akira leans on VMware ESXi and VPN credential reuse. DeadLock and CRPxO show no verifiable CVE tie and rely on feed-sourced access. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution below is tied to a named vendor or government source, with a confidence note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific group, we left it out rather than padding the table.
| CVE | Product | CVSS | Who is using it | Why it matters |
|---|---|---|---|---|
| CVE-2024-55591 | Fortinet FortiOS / FortiProxy | 9.6 | The Gentlemen, Qilin | Authentication bypass on the FortiGate management interface. The Gentlemen, a Qilin splinter Microsoft tracks as Storm-2697, keeps a large inventory of already-compromised FortiGate devices and valid VPN credentials for fast initial access. This is the load-bearing, first-party-confirmed vector for both groups (Fortinet PSIRT; Microsoft; PRODAFT; Trend Micro). |
| CVE-2024-21762 | Fortinet FortiOS SSL VPN | 9.8 | Qilin | Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. PRODAFT and FortiGuard tie Qilin's 2025 to 2026 campaign to this flaw. Tens of thousands of devices stayed exposed months after the patch. |
| CVE-2024-24919 | Check Point Remote Access VPN | 8.6 | Qilin | Information-disclosure flaw in the Check Point Security Gateway VPN blade that leaks sensitive files, including password hashes, from internet-facing gateways. Qilin affiliates use it alongside the Fortinet flaws to widen their VPN access options (Check Point; CISA). |
| CVE-2024-37085 | VMware ESXi | 6.8 | Akira, The Gentlemen | Authentication bypass that hands an attacker admin control of an ESXi host by creating a specific Active Directory group, enabling mass encryption of every VM on the host. First-party confirmed for Akira and Black Basta; The Gentlemen tie is analyst-reported (Microsoft; CISA AA24-109A). |
| CVE-2025-7771 | ThrottleStop.sys driver (BYOVD) | 7.8 | The Gentlemen | A legitimate driver with unrestricted access to physical memory, renamed and weaponised to disable Defender, CrowdStrike, and Bitdefender ahead of encryption. The Gentlemen are reported using this bring-your-own-vulnerable-driver technique (Kaspersky Securelist / GERT; Halcyon; group tie is analyst-reported). |
| CVE-2025-32433 | Erlang/OTP SSH | 10.0 | The Gentlemen | Unauthenticated pre-auth remote code execution in the Erlang/OTP SSH server, reaching root over the network. Reported as a secondary entry vector The Gentlemen adopted to diversify beyond Fortinet (Unit 42; Cisco PSIRT; group tie is analyst-reported). |
| CVE-2025-33073 | Windows SMB Client (NTLM relay) | 8.8 | The Gentlemen | NTLM reflection flaw that escalates a low-privileged foothold to SYSTEM. The group is reported automating domain-wide relay after initial access (Microsoft; Synacktiv; group tie is analyst-reported). |
| CVE-2023-27532 | Veeam Backup & Replication | 7.5 | The Gentlemen | Lets an attacker inside the backup network pull stored credentials from the config database. Reported as part of The Gentlemen's move to seize or wipe backups before encryption (CISA KEV; Halcyon). |
| CVE-2024-57727 | SimpleHelp RMM | 7.5 | DragonForce | Path-traversal flaw in SimpleHelp remote-management software, chained with two sibling flaws for an MSP-to-client pivot that reaches downstream victims in one move (CISA AA25-163A; Sophos; Trend Micro). |
A note on attribution accuracy. We attribute a CVE to a group only where a named vendor or government source supports the link, and we flag where that link is analyst-reported rather than first-party. Several of this week's high-volume groups have no verifiable CVE tie at all. DeadLock's 64-name batch shows the domain-and-thin-profile posting style consistent with credential-feed and infostealer intake rather than a single signature flaw. APT73 (Bashe), a former LockBit affiliate, is reported using spear-phishing and stolen VPN and RDP credentials. SafePay, CRPxO, Booba Project, and Doommageddon all show feed-sourced or opportunistic intake with no named exploit. LockBit 5.0, released in September 2025, has no CVE tied to the 5.0 build itself; its affiliates bring their own access.
A few practical notes:
The credential-reuse angle. Patched devices still get hit when actors replay credentials stolen before the fix. Both Fortinet flaws above were used to harvest credentials that outlive the patch. Rotate VPN credentials and re-issue MFA enrolment for any device that was internet-facing while unpatched.
VPN appliances are the front door. Fortinet and Check Point gateways drove Qilin's and The Gentlemen's access this week. Internet-facing, unpatched, credential-exposed VPNs are how affiliates get in before any locker runs.
RMM is a single point of mass compromise. CVE-2024-57727 in SimpleHelp remains the clearest one-to-many risk. One managed-services server can mean every client environment it touches. MSPs and their customers carry the top exposure here.
We are reporting these as the flaws most associated with this week's most active groups. Knowing these are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch-office firewall or an MSP's RMM server, is the part most teams cannot answer on a Monday morning. Confirm your own exposure rather than assuming a vendor advisory covers your specific version.
Infrastructure and Operational Shifts
Single-day batch releases keep distorting weekly counts. DeadLock's 63-on-one-day dump is this week's clearest case: a queue of low-detail, mostly European victims released together, adding a false 17% to the headline. When you benchmark a week's numbers, check whether one group and one day drove the change before you treat it as a trend. The real signal this week was two groups, The Gentlemen and Qilin, running steady profiled campaigns.
Geography-focused clusters point to single access campaigns. SafePay's nine German victims on July 6 and DeadLock's Spain-Poland-Italy spread both look like one foothold worked into a regional pocket rather than scattered global intake. A tight country cluster on a leak site is often a sign of one compromised access broker or one shared vulnerability across a regional customer base.
Big-brand claims on thin proof are a recurring pattern. and The Gentlemen's Mercado Libre claim both name recognisable companies without sample data. Marquee names draw attention and pressure, whether or not the underlying access is real. Validate the claim before the brand name drives your response.
Key Takeaways for Defenders
Read the rise as a batch, not a surge. This week's 242 is up 17% on last week, but 64 of the postings are one DeadLock batch, 63 of them on July 10. Strip that out and the underlying total is 178, below last week's 207. When a leak-site count swings, check whether one group, one batch, or the calendar drove it before briefing it as a trend.
Patch the VPN and edge layer first. Confirm patch status for Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Check Point Remote Access VPN (CVE-2024-24919), VMware ESXi (CVE-2024-37085), and SimpleHelp (CVE-2024-57727). Rotate any credentials or session tokens exposed while a device was unpatched.
Turn on the vulnerable-driver blocklist estate-wide. The ThrottleStop BYOVD technique (CVE-2025-7771) shows up with The Gentlemen and others. The Microsoft Vulnerable Driver Blocklist stops the EDR-killer regardless of which crew brings it. Pair it with NTLM relay hardening (CVE-2025-33073) and Veeam backup patching (CVE-2023-27532) so backups survive an intrusion.
Validate the high-value claims before you react. Mercado Libre, and Frankfurt-Hahn Airport are exactly the names built to draw attention on thin proof. CTI should confirm samples and your communications team should hold a pre-approved response before anyone treats a claim as a breach.
Watch your suppliers, not just yourself. The Tonnies claim reaches food supply, the Retelit claim reaches telecom customers, and DragonForce's SimpleHelp pivot reaches every MSP client downstream. A supplier or partner appearing on a leak site is your problem too. Map your vendor exposure the same way you map your own.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old, and a batch release can be far older. Watching external exposure, leaked credentials, and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 242 posts down to the few that touch your domains, your brands, and your vendors, then matching those groups to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: https://scrutex.ai/solution/threat.
Frequently Asked Questions
How many ransomware attacks happened the week of July 6 to 12, 2026?
242 unique victim postings appeared on dark web leak sites in that window, across 37 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is up 17% on last week's 207, but 64 of the postings came from a single DeadLock batch on July 10, so the underlying activity was closer to 178.
Which ransomware group is most active right now?
DeadLock topped the raw count with 64, but 63 of those landed in one batch on July 10. On genuine, profiled activity The Gentlemen led with 40 and Qilin followed with 32. The Gentlemen and Qilin have traded the real lead for several weeks.
Why did postings spike to 93 on July 10?
DeadLock released a batch of 63 victims that day, a queue of thin, mostly European and Latin American entries posted together. Take that batch out and July 10 drops to 30, in line with the rest of the week. The spike is a single-group backfill, not a jump in real attack activity.
Did Mercado Libre get hit by ransomware?The Gentlemen posted Mercado Libre without sample data. A global brand named by an actor with no proof attached is a low-confidence claim. Treat both as unverified actor claims until evidence emerges.
What CVEs are these groups exploiting?
Mainly known VPN, edge, hypervisor, and driver flaws. Qilin and The Gentlemen use Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Qilin adds Check Point VPN (CVE-2024-24919), Akira and The Gentlemen use VMware ESXi (CVE-2024-37085), The Gentlemen use the ThrottleStop driver (CVE-2025-7771) to disable EDR, and DragonForce uses SimpleHelp (CVE-2024-57727). Several high-volume groups this week, including DeadLock, SafePay, and CRPxO, have no verifiable CVE tie and rely on stolen credentials and infostealer feeds.
What sectors should I worry about most this week?
Business Services led at 43 named victims, followed by Manufacturing at 32, Construction at 21, and Technology at 19. Manufacturing and construction ran higher than usual because the DeadLock batch and The Gentlemen's spree swept up industrial and real-estate firms. A high share of postings carried no sector label this week, so read the counts alongside the percentages.
Where can I get this data in real time?
Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands, and vendors, so you see only the postings that touch your domains, brands, or supply chain.