Ransomware weekly
57 views

Weekly Ransomware Intelligence Report, July 19, 2026

By ScruteX Published

Summary

This is the Scrutex ransomware weekly for the July 13 to 19, 2026 window. Our CTI team tracked 185 unique ransomware victim claims across 39 active groups during the period. That is down 24% on last week's 242, and this time the fall is real, not a reporting artefact. Last week's total was inflated by a single 64-name DeadLock batch dumped on one day. so this week's 185 is roughly flat on the genuine baseline. What changed is the shape. There was no mass free dump this week. Three groups ran the board on real, profiled activity: Qilin led with 33, DragonForce followed with 27, and The Gentlemen took third with 23. No other group broke 12. United States firms made up 29% of all victims, in line with the long-run share.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific CVEs these groups are exploiting to get in. The standout story this week is a clean three-way race. Daily volume held between 16 and 41 the whole week, with the only spike coming Thursday July 16 when The Gentlemen posted a 17-victim spree. Qilin spread its 33 across all seven days, DragonForce front-loaded 11 of its 27 onto Tuesday, and The Gentlemen concentrated theirs on one afternoon. Three deliberate campaigns, no queue-clearing backfill.
185 posts, 39 groups, 43 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names and resolved them to one entry, and we dropped four re-listings that repeated an already-counted victim with the sector blanked. Where a single group backfills a large batch on one day, we flag it. This week no group did, so the count reads cleaner than last week's.

In This Post

Section What it covers
This Week at a Glance Headline numbers and the three-way race
Group Activity Breakdown Who posted most, and the stories worth reading
New and Emerging Groups KryBit and Coinbase Cartel, the week's newer names
Sector Targeting Analysis Which industries took the named hits
Country Distribution Where the 43 countries fall
Notable Claims and Incidents Five named claims with confidence lines
Top CVEs These Groups Are Exploiting The flaws driving initial access
Infrastructure and Operational Shifts What is changing in how these crews work
Key Takeaways for Defenders The short action list

This Week at a Glance

Metric Value
Total unique victims posted 185
Change on prior week Down 24% (from 242)
Underlying prior-week total (minus DeadLock batch) 178
Active groups 39
Countries hit 43
Heaviest single day July 16 (41 posts, 17 from The Gentlemen)
Quietest day July 19 (16 posts)
Most targeted country United States (29% of postings)
Most targeted sector Business Services (32)
Top group by volume Qilin (33 posts)
Notable major-brand claims Ecopetrol, Military Sealift Command, Danone, Ferrovial, Panasonic Aero
The week ran steady. Daily volume held between 16 and 41 across all seven days, with the only real spike on Thursday July 16, when postings hit 41 and The Gentlemen accounted for 17 of them. There was no single-day, single-group dump like the DeadLock batch that skewed last week. Take The Gentlemen's Thursday run out and July 16 drops to 24, in line with the rest of the week.
This matters for the headline. The 24% fall on last week's 242 looks like a sharp drop, but last week's number was propped up by one 64-name DeadLock backfill. Measured against the genuine baseline of roughly 178, this week's 185 is essentially flat. The top group took 18% of the week's volume on its own, and the top five together took 55%, both healthier, less concentrated figures than last week. The field this week is three real campaigns and a long tail, not one operator emptying a queue.

Group Activity Breakdown

The top 5 groups produced 55% of the week's volume (102 of 185 postings), a more even spread than last week's batch-inflated 64%. Below the top four the list stays crowded: 22 groups posted two or fewer victims each, and 14 posted exactly one. The leak site space remains fragmented after the LockBit and ALPHV takedowns of 2024 to 2025. New brands keep entering, and affiliate crews keep splitting off to launch their own programs.
Rank Group Victims Share Notable Activity
1 Qilin 33 18% Steady across all seven days, broad international run: Danone/International Delights, Retelit-style telecom and healthcare targets
2 DragonForce 27 15% Front-loaded 11 on July 14, MSP and IT-services pivot, spread across China, Taiwan, Hong Kong, and Latin America
3 The Gentlemen 23 12% 17 posted in one Thursday spree on July 16: Ecopetrol (Colombia), Military Sealift Command (US), BRAC (Bangladesh)
4 INC Ransom 12 6% Asia-Pacific manufacturing cluster on July 18, including Taiwan Giant subsidiary and Vietnamese and Singapore food firms
5 Nova 7 4% Data-extortion brand, Brazil, Turkey, Indonesia, and Canada mix
6 Akira 6 3% US mid-market, VMware ESXi and VPN credential reuse
7 LockBit 6 3% LockBit 5.0 affiliates, Italy, India, Singapore, and UK
8 Arcus Media 6 3% Newer brand, Malaysia, Portugal, France, and Nigeria spread
9 KryBit 6 3% Bulgarian insurance cluster (Eurohold, Euroins) plus mixed geography
10 Play 5 3% European mid-market, thin per-victim profiles
11 Ailock 4 2% Japan and Spain, including Ferrovial
12 Chaos 4 2% US manufacturing and healthcare
A long tail of groups (Interlock, Settra, Pear, Coinbase Cartel, RansomHouse, Blackout, INC Ransom affiliates, Titan, NightSpire, Space Bears, ShinyHunters, Gunra, CMD Organization, Payload, 3AM, Black X, and roughly a dozen more) each posted between one and four victims.
Three observations:
Qilin led on breadth, not on a single dump. Its 33 postings spread across all seven days and crossed manufacturing, healthcare, telecom, food, and hospitality victims in many countries. That is the profile of the most consistently active RaaS brand of 2026, running steady intake rather than a one-day release. Qilin's edge-appliance focus, both Fortinet and Check Point VPN, is the throughline behind that volume. See the CVE section for the specific flaws.
DragonForce ran a supplier-heavy Tuesday. It posted 11 of its 27 on July 14, and the list leans towards IT, telecom, and managed-services firms across China, Taiwan, Hong Kong, and Latin America. Several of the named victims sit upstream of their own customers, which is the pattern to watch: an MSP or IT-services listing carries downstream reach beyond the named company. DragonForce's move onto SimpleHelp RMM is the mechanism behind that supplier tilt.
The Gentlemen concentrated on one afternoon. Its 23 postings were 17 on Thursday July 16, a spree that named companies with profiles attached rather than raw domains: Ecopetrol, Colombia's state oil major, Military Sealift Command, the US Navy's civilian logistics arm, and BRAC, the world's largest NGO. The Gentlemen, which Microsoft tracks as Storm-2697 and PRODAFT tracks as LARVA-368, has scaled fast since mid-2025 on the back of a Fortinet foothold and a self-propagating Go encryptor. Between Qilin, DragonForce, and The Gentlemen, the three ran 83 profiled victims this week, and that is where the real pressure sits.

New and Emerging Groups

KryBit: regional financial-sector clustering

KryBit posted 6 victims this week, and the standout is a two-day Bulgarian financial cluster: Eurohold Bulgaria and its insurance arm Euroins, both listed July 18 and 19. A holding company and its regulated insurer named on consecutive days points to a single access campaign into one corporate group rather than scattered intake. KryBit's other postings crossed Israel, Mexico, Malaysia, and the Czech Republic, a mixed spread typical of a newer data-extortion brand still building its affiliate base.
The read on KryBit is regulatory. Insurance and holding companies carry policyholder PII, financial records, and cross-border reporting obligations. A confirmed dump here would trigger GDPR notification across the EU and local Bulgarian regulators, whether or not any system was encrypted. There is no public source tying KryBit to a specific CVE, which is consistent with credential-feed and access-broker intake.

Coinbase Cartel: big-brand claims, thin proof

Coinbase Cartel posted a small number of victims but drew attention with a claim against Panasonic Avionics, the in-flight entertainment and connectivity unit, listed July 15. The brand also named Axiom Global, a US legal-services firm. Coinbase Cartel is a low-profile name with a short track record and a pattern of attaching recognisable companies to draw pressure.
Coinbase Cartel is worth watching less for tooling and more for how a newer brand front-loads marquee names to look established to affiliates. A global aerospace-adjacent name from an obscure actor with no sample data is the classic opening-pressure pattern. Treat a Coinbase Cartel listing as a prompt to confirm your own exposure, not as proof of a fresh compromise.

Sector Targeting Analysis

Across the 185 victim postings this week:
Sector Victims Share
Business Services 32 17%
Manufacturing 22 12%
Technology 19 10%
Agriculture and Food 15 8%
Healthcare 10 5%
Consumer Services 10 5%
Financial Services 8 4%
Hospitality and Tourism 6 3%
Transportation and Logistics 6 3%
Telecommunications 5 3%
Education 4 2%
A caveat on these shares. Roughly 36 of the 185 postings carried no usable sector label this week, most of them thin domain-only entries from the long tail. The percentages above are of all postings, so they understate each sector's real share of the classified victims. Read the counts, not just the percentages.
What this tells us:
Business Services led at 32 victims. Professional-services firms hold large volumes of client data on light security budgets, which keeps them the affiliate sweet spot. Qilin, DragonForce, and The Gentlemen all fed this sector this week.
Manufacturing took second at 22. Industrial firms with flat OT and IT networks run a low tolerance for downtime, and several claims here carry supply-chain weight: the Taiwan Giant subsidiary named by INC Ransom, a cluster of precision-parts and engineering makers, and Vietnamese and Japanese industrial firms. Manufacturing claims sit upstream of many other victims.
Technology followed at 19, and this is the sector to watch this week. DragonForce's Tuesday run swept up IT-services, telecom, and managed-services firms, and technology suppliers sit upstream of their own customers. An IT-services listing is worth checking for downstream reach into every client the vendor touches.
Agriculture and Food drew 15 named hits, higher than usual, pulled up by INC Ransom's food-and-beverage cluster (Vedan Vietnam, Pokka Singapore, Heartland Catfish) and Qilin's Danone-linked claim. Healthcare and Consumer Services tied at 10 each, with the healthcare list skewing towards clinics, ambulance services, and home-care providers rather than large hospital systems. These carry HIPAA and PHI exposure and skew towards organisations with thin IT teams.

Country Distribution

The United States accounts for 29% of all postings this week (54 of 185), in line with its long-run share of affiliate-driven extortion. Unlike last week, no European-weighted batch pulled the mix off centre, so the distribution reads closer to the steady state: the US as the single largest target market by a wide margin, with a long international tail behind it.
Rank Country Victims
1 United States 54
2 Canada 8
3 Japan 7
4 Argentina 6
5 Czech Republic 6
6 France 6
7 South Africa 6
8 United Kingdom 6
9 Brazil 6
10 Italy 5
11 India 4
12 Spain 4
13 China 4
14 Taiwan 4
15 Mexico 4
A further 28 countries had one to three victims each, including Turkey, Portugal, Colombia, UAE, Sweden, Germany, Singapore, Philippines, Poland, Malaysia, Saudi Arabia, Hong Kong, Finland, Netherlands, Vietnam, Bulgaria, Cameroon, Nigeria, Switzerland, Bangladesh, Yemen, Egypt, Botswana, Andorra, Hungary, Israel, Indonesia, and Peru.
The breadth, 43 countries in a single week, shows how affiliate-driven RaaS now operates globally. Geographic distribution tracks revenue opportunity, not threat actor location. DragonForce alone touched China, Taiwan, Hong Kong, Colombia, and Mexico in one run, while INC Ransom swept a China, Taiwan, Vietnam, Singapore, and Philippines manufacturing and food cluster. Operators follow data volume into whichever regional pocket is exposed.
For readers outside the United States, the Asia-Pacific tilt is the week's regional story. Japan drew 7 hits, Taiwan and China another 8 between them, and INC Ransom's Tuesday cluster concentrated on East and Southeast Asian manufacturers. Map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, before an incident forces the question.

Notable Claims and Incidents

The five claims below all appear on public leak sites. We name only what the actor posted, summarise the data categories claimed, and end each with a confidence line. None were independently confirmed as a compromise at the time of writing.

1. The Gentlemen claim Ecopetrol

The Gentlemen listed Ecopetrol, Colombia's state-owned oil and gas major, on July 18, claiming over 1TB of data. Ecopetrol is a real, publicly traded national energy operator with refineries, pipelines, and export terminals across Colombia and abroad. The group attaches company profiles to its postings rather than dumping raw domains.
Confidence: Low. A national energy operator claimed by an affiliate crew with no sample data is a high-value, unverified listing. A confirmed hit would carry operational and critical-infrastructure weight, so validate before treating it as a breach.

2. The Gentlemen claim Military Sealift Command

The Gentlemen posted Military Sealift Command, the US Navy's civilian-crewed logistics arm, on July 17. The claim references ITAR documentation, cargo manifests, and vessel blueprints, and the posting narrative describes attempts to contact named staff before threatening publication.
Confidence: Low. A defense-adjacent claim naming ITAR data is exactly the kind of listing built to draw attention, and no sample data or independent confirmation is available. The data categories named would carry national-security exposure if the claim is substantiated, so treat it as unverified until evidence surfaces.

3. Qilin claims Danone via International Delights

Qilin posted a claim tied to Danone, the French food and dairy multinational, through its International Delights unit on July 15. Danone is a real global brand that runs a mature security program, which makes a claim of this size worth heavy scrutiny.
Confidence: Low. The posting is real, but the target's scale and security maturity make an unverified claim worth close review. Confirm samples before anyone briefs this as a breach, and note that a claim against a subsidiary is not the same as a claim against the parent.

4. Ailock claims Ferrovial

Ailock listed Ferrovial, the Spanish infrastructure and construction multinational, on July 15. Ferrovial builds and operates airports, highways, and major transport infrastructure across Europe and North America. A confirmed dump would reach beyond the company into its projects and partners.
Confidence: Low. Ferrovial is a real, large multinational, and Ailock is a smaller brand with a short track record. The posting is genuine, but no sample data or company confirmation is available, so treat the impact as unconfirmed pending proof.

5. Interlock claims District of Columbia Housing Authority

Interlock posted the District of Columbia Housing Authority on July 16, claiming 1.6TB including resident databases, passports, and personal data. Public-housing authorities hold large volumes of citizen PII on constrained security budgets, which widens the exposure to residents directly.
Confidence: Medium. Interlock's posting pattern is consistent with genuine access, and a public-sector body holding resident PII at this scale is a credible target. The specific data scope is not independently corroborated, so validate before treating a citizen-data impact as confirmed.

Top CVEs These Groups Are Exploiting

The groups leading this week mostly exploit a known set of edge-device, VPN, hypervisor, and driver flaws, plus credential reuse. Qilin and The Gentlemen both lean on Fortinet and, in Qilin's case, Check Point VPN for initial access. DragonForce leans on SimpleHelp RMM for an MSP-to-client pivot, which matters this week given its supplier-heavy Tuesday run. Akira leans on VMware ESXi and VPN credential reuse. INC Ransom, Nova, and KryBit show no verifiable CVE tie and rely on feed-sourced access. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution below is tied to a named vendor or government source, with a confidence note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific group, we left it out rather than padding the table.
CVE Product CVSS Who is using it Why it matters
CVE-2024-55591 Fortinet FortiOS / FortiProxy 9.6 The Gentlemen, Qilin Authentication bypass on the FortiGate management interface. The Gentlemen, a Qilin splinter Microsoft tracks as Storm-2697, keeps a large inventory of already-compromised FortiGate devices and valid VPN credentials for fast initial access. This is the load-bearing, first-party-confirmed vector for both groups (Fortinet PSIRT; Microsoft; PRODAFT; Trend Micro).
CVE-2024-21762 Fortinet FortiOS SSL VPN 9.8 Qilin Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. PRODAFT and FortiGuard tie Qilin's 2025 to 2026 campaign to this flaw. Tens of thousands of devices stayed exposed months after the patch.
CVE-2024-57727 SimpleHelp RMM 7.5 DragonForce Path-traversal flaw in SimpleHelp remote-management software, chained with two sibling flaws for an MSP-to-client pivot that reaches downstream victims in one move. DragonForce ran a supplier-heavy week, so this one-to-many vector is the top risk to watch (CISA AA25-163A; Sophos; Trend Micro).
CVE-2024-24919 Check Point Remote Access VPN 8.6 Qilin Information-disclosure flaw in the Check Point Security Gateway VPN blade that leaks sensitive files, including password hashes, from internet-facing gateways. Qilin affiliates use it alongside the Fortinet flaws to widen their VPN access options (Check Point; CISA).
CVE-2024-37085 VMware ESXi 6.8 Akira, The Gentlemen Authentication bypass that hands an attacker admin control of an ESXi host by creating a specific Active Directory group, enabling mass encryption of every VM on the host. First-party confirmed for Akira and Black Basta; The Gentlemen tie is analyst-reported (Microsoft; CISA AA24-109A).
CVE-2025-7771 ThrottleStop.sys driver (BYOVD) 7.8 The Gentlemen A legitimate driver with unrestricted access to physical memory, renamed and weaponised to disable Defender, CrowdStrike, and Bitdefender ahead of encryption. The Gentlemen are reported using this bring-your-own-vulnerable-driver technique (Kaspersky Securelist / GERT; Halcyon; group tie is analyst-reported).
CVE-2025-32433 Erlang/OTP SSH 10.0 The Gentlemen Unauthenticated pre-auth remote code execution in the Erlang/OTP SSH server, reaching root over the network. Reported as a secondary entry vector The Gentlemen adopted to diversify beyond Fortinet (Unit 42; Cisco PSIRT; group tie is analyst-reported).
CVE-2023-27532 Veeam Backup & Replication 7.5 The Gentlemen Lets an attacker inside the backup network pull stored credentials from the config database. Reported as part of The Gentlemen's move to seize or wipe backups before encryption (CISA KEV; Halcyon).
A note on attribution accuracy. We attribute a CVE to a group only where a named vendor or government source supports the link, and we flag where that link is analyst-reported rather than first-party. Several of this week's high-volume groups have no verifiable CVE tie at all. INC Ransom's Asia-Pacific manufacturing cluster shows the domain-and-profile posting style consistent with credential-feed and access-broker intake rather than a single signature flaw. Nova, KryBit, Arcus Media, and Coinbase Cartel all show feed-sourced or opportunistic intake with no named exploit. LockBit 5.0, released in September 2025, has no CVE tied to the 5.0 build itself; its affiliates bring their own access.
A few practical notes:
RMM is a single point of mass compromise. CVE-2024-57727 in SimpleHelp is this week's clearest one-to-many risk, and DragonForce's supplier-heavy Tuesday makes it the priority. One managed-services server can mean every client environment it touches. MSPs and their customers carry the top exposure here.
VPN appliances are the front door. Fortinet and Check Point gateways drove Qilin's and The Gentlemen's access this week. Internet-facing, unpatched, credential-exposed VPNs are how affiliates get in before any locker runs.
The credential-reuse angle. Patched devices still get hit when actors replay credentials stolen before the fix. Both Fortinet flaws above were used to harvest credentials that outlive the patch. Rotate VPN credentials and re-issue MFA enrolment for any device that was internet-facing while unpatched.
We are reporting these as the flaws most associated with this week's most active groups. Knowing these are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch-office firewall or an MSP's RMM server, is the part most teams cannot answer on a Monday morning. Confirm your own exposure rather than assuming a vendor advisory covers your specific version.

Infrastructure and Operational Shifts

A quiet week is a chance to read the real field. With no DeadLock-style batch to distort the count, this week's 185 shows the genuine baseline of affiliate activity: three groups running steady, profiled campaigns and a long tail of one-to-four-victim brands. When you benchmark week to week, this is closer to the true rate than a batch-inflated total. The signal this week was breadth from Qilin and supplier reach from DragonForce, not a mass release.
Supplier-focused runs are the pattern to watch. DragonForce's Tuesday leaned on IT, telecom, and managed-services firms, and its SimpleHelp RMM pivot turns one compromise into downstream reach across every client. A cluster of technology and MSP victims on a leak site is often a sign of one supplier compromise rippling outward, not many separate intrusions.
Regional clustering points to single access campaigns. KryBit's two Bulgarian financial firms on consecutive days and INC Ransom's East and Southeast Asian manufacturing cluster both look like one foothold worked into a regional or sector pocket rather than scattered global intake. A tight cluster on a leak site often traces back to one access broker or one shared flaw across a regional customer base.
Big-brand claims on thin proof are a recurring pattern. The Gentlemen's Ecopetrol and Military Sealift Command listings and Coinbase Cartel's Panasonic Avionics claim all name recognisable organisations without sample data. Marquee names draw attention and pressure, whether or not the underlying access is real. Validate the claim before the brand name drives your response.

Key Takeaways for Defenders

Read the drop as a return to baseline, not a slowdown. This week's 185 is down 24% on last week's 242, but last week was inflated by a single 64-name DeadLock batch. Against the genuine baseline near 178, this week is flat. When a leak-site count swings, check whether one group, one batch, or the calendar drove it before briefing it as a trend.
Prioritise the RMM and supplier layer this week. DragonForce ran a supplier-heavy week on the back of SimpleHelp RMM (CVE-2024-57727). Confirm patch status on any remote-management software, and map which of your vendors and MSPs could carry a compromise into your environment. One RMM server is a one-to-many risk.
Patch the VPN and edge layer. Confirm patch status for Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Check Point Remote Access VPN (CVE-2024-24919), and VMware ESXi (CVE-2024-37085). Rotate any credentials or session tokens exposed while a device was unpatched. Turn on the Microsoft Vulnerable Driver Blocklist to stop the ThrottleStop BYOVD EDR-killer (CVE-2025-7771), and patch Veeam (CVE-2023-27532) so backups survive an intrusion.
Validate the high-value claims before you react. Ecopetrol, Military Sealift Command, Danone, and Panasonic Avionics are exactly the names built to draw attention on thin proof. CTI should confirm samples and your communications team should hold a pre-approved response before anyone treats a claim as a breach.
Watch your suppliers, not just yourself. DragonForce's SimpleHelp pivot reaches every MSP client downstream, INC Ransom's manufacturing cluster sits upstream of many supply chains, and KryBit's insurer claim reaches policyholders. A supplier or partner appearing on a leak site is your problem too. Map your vendor exposure the same way you map your own.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old. Watching external exposure, leaked credentials, and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 185 posts down to the few that touch your domains, your brands, and your vendors, then matching those groups to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: scrutex.ai/solution/threat.

Frequently Asked Questions

How many ransomware attacks happened the week of July 13 to 19, 2026? 185 unique victim postings appeared on dark web leak sites in that window, across 39 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is down 24% on last week's 242, but last week was inflated by a single DeadLock batch of 64, so this week's total is roughly flat on the genuine baseline near 178.
Which ransomware group is most active right now? Qilin topped the week with 33 postings spread across all seven days, followed by DragonForce with 27 and The Gentlemen with 23. These three have traded the real lead for several weeks, running steady profiled campaigns rather than mass free dumps.
Why was there no single-day spike this week? No group ran a queue-clearing batch like last week's DeadLock dump. The heaviest day, July 16 with 41 postings, was driven by a 17-victim spree from The Gentlemen, but the rest of the week held between 16 and 30 a day. The week reads as three deliberate campaigns rather than one backfill.
Did Ecopetrol, Danone, or Panasonic get hit by ransomware? The Gentlemen posted Ecopetrol, Qilin posted a Danone-linked claim through International Delights, and Coinbase Cartel posted Panasonic Avionics, all without sample data. A large brand named by an actor with no proof attached is a low-confidence claim. Treat all three as unverified actor claims until evidence emerges.
What CVEs are these groups exploiting? Mainly known VPN, edge, hypervisor, and driver flaws. Qilin and The Gentlemen use Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Qilin adds Check Point VPN (CVE-2024-24919), DragonForce uses SimpleHelp RMM (CVE-2024-57727) for MSP-to-client pivots, Akira and The Gentlemen use VMware ESXi (CVE-2024-37085), and The Gentlemen use the ThrottleStop driver (CVE-2025-7771) to disable EDR. Several high-volume groups this week, including INC Ransom, Nova, and KryBit, have no verifiable CVE tie and rely on stolen credentials and infostealer feeds.
What sectors should I worry about most this week? Business Services led at 32 named victims, followed by Manufacturing at 22, Technology at 19, and Agriculture and Food at 15. Technology ran higher than usual because DragonForce's supplier-heavy run swept up IT and managed-services firms. A high share of postings carried no sector label this week, so read the counts alongside the percentages.
Where can I get this data in real time? Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands, and vendors, so you see only the postings that touch your domains, brands, or supply chain.