Weekly Ransomware Intelligence Report, July 5, 2026
By ScruteX Team Published
Summary
This is the Scrutex ransomware weekly for the June 29 to July 5, 2026 window. Our CTI team tracked 207 unique ransomware victim claims across 37 active groups during the period. That is up 23% on last week's 168, and this time the rise is real rather than a single backfill artefact. The Gentlemen led again with 29, Qilin followed with 23, then APT73 (also tracked as Bashe) at 14 and INC Ransom at 12. United States firms made up 34% of all victims, a step up from last week's 27%.
This report covers who was most active, which sectors and countries were hit, the high-profile claims worth your attention, and the specific CVEs these groups are exploiting to get in. The standout story this week is tempo. Volume front-loaded hard into the start of the week, peaked at 55 on June 30, then fell off a cliff over the US Independence Day weekend, down to 9 posts on Saturday July 4. Two familiar names, The Gentlemen and Qilin, ran the widest campaigns, and a second tier of MedusaLocker, KryBit, and Settra each posted double digits.
207 posts, 37 groups, 43 countries in a single week. Reading every one to find the three that touch your own organisation or your suppliers is most of a working day, and that is before you cross-reference each group against the flaws sitting on your perimeter. The value is rarely in the full list. It is in the handful of lines that are actually about you.
A note on how to read the numbers. Counts reflect leak site postings, not confirmed compromises, and by the time a victim is posted the intrusion is usually 30 to 90 days old. We deduplicated postings that appeared under multiple names and resolved them to one entry. Where a single group backfills a large batch on one day, we flag it rather than letting it inflate the trend silently.
In This Post
| Section | What it covers |
|---|---|
| This Week at a Glance | Headline numbers and a real week-over-week rise |
| Group Activity Breakdown | Who posted most, and the stories worth reading |
| New and Emerging Groups | KryBit and Genesis, the week's double-digit newcomers |
| Sector Targeting Analysis | Which industries took the named hits |
| Country Distribution | Where the 43 countries fall |
| Notable Claims and Incidents | Five named claims with confidence lines |
| Top CVEs These Groups Are Exploiting | The flaws driving initial access |
| Infrastructure and Operational Shifts | What is changing in how these crews work |
| Key Takeaways for Defenders | The short action list |
This Week at a Glance
| Metric | Value |
|---|---|
| Total unique victims posted | 207 |
| Change on prior week | Up 23% (from 168) |
| Active groups | 37 |
| Countries hit | 43 |
| Heaviest single day | June 30 (55 posts) |
| Second-heaviest day | July 1 (53 posts) |
| Quietest day | July 4 (9 posts, US holiday) |
| Most targeted country | United States (34% of postings) |
| Most targeted sector | Business Services (33) |
| Top group by volume | The Gentlemen (29 posts) |
| Notable major-brand claims | Arkin Group, Port Angeles Composite, Primed Halberstadt, Melcor, Higuchi |
The week front-loaded and then faded. Monday to Wednesday carried 139 of the 207 postings, 67% of the total, peaking at 55 on June 30 and holding at 53 on July 1. From Thursday the count stepped down: 28 on July 2, 19 on July 3, then 9 on Saturday July 4, the lightest day, with a small Sunday rebound to 12. The July 4 trough lines up with the US Independence Day weekend, when the heavily US-focused affiliate crews eased off posting.
Unlike last week, the rise here is not a mirage. Last week's 168 sat below trend partly because the prior period had been inflated by a one-off DeadLock backfill. This week's 207 is spread across a healthy field: the top group took 14%, the top five together 43%, and no single operator dumped a metadata-less batch to pad the count. Underlying fresh leak-site activity ran hot in the first half of the week and normal-to-quiet in the second.
Group Activity Breakdown
The top 5 groups produced 43% of the week's volume (89 of 207 postings), an even spread with no single-group dominance. The long tail stays crowded: 12 groups posted two or fewer victims each, and six posted exactly one. The leak site space remains fragmented after the LockBit and ALPHV takedowns of 2024 to 2025. New brands keep entering, and affiliate crews keep splitting off to launch their own programs.
| Rank | Group | Victims | Share | Notable Activity |
|---|---|---|---|---|
| 1 | The Gentlemen | 29 | 14% | Back at the top. Ran the widest spree of the week: Melcor (Canada), Au Vieux Campeur (France), Climax Technology (Taiwan), CTM India |
| 2 | Qilin | 23 | 11% | Broad international run across manufacturing, healthcare, and public sector |
| 3 | APT73 (Bashe) | 14 | 7% | Former LockBit affiliate, LockBit-style leak blog, mixed geography |
| 4 | INC Ransom | 12 | 6% | US business services and financial services cluster |
| 5 | Settra | 11 | 5% | Emerging crew, website-domain victims across US and APAC |
| 6 | MedusaLocker | 11 | 5% | Resurgent this week, RDP-and-phishing initial access, EDR-killer driver in the chain |
| 7 | KryBit | 11 | 5% | March 2026 newcomer, cross-platform builder, affiliate-fed intake |
| 8 | Genesis | 10 | 5% | Data-exfil-only extortion against US small and mid-market firms |
| 9 | Anubis | 6 | 3% | 2025 RaaS with an irreversible wiper mode, CitrixBleed 2 initial access |
| 10 | LockBit | 6 | 3% | LockBit 5.0 era, affiliate-dependent access, cross-platform payload |
| 11 | DragonForce | 5 | 2% | SimpleHelp RMM pivot, MSP-to-client risk |
| 12 | Pear | 5 | 2% | Exfil-extortion brand, thin victim profiles |
WorldLeaks, the rebrand of Hunters International, also posted 5. A long tail of groups (CMD Organization, Payload, Brain Cipher, Doommageddon, WallStreet, PayoutsKing, BlackNevas, Play, Gunra, Akira, SafePay, Stormous, and roughly 15 more) each posted between one and four victims.
Three observations:
The Gentlemen ran the week's widest single spree. Its 29 postings spanned continents in one run: Melcor Developments in Canada, Au Vieux Campeur in France, Climax Technology in Taiwan, CTM India tied to the Motherson group, and a cluster of US professional-services firms. No mass free dump, just steady high-volume posting of named companies with company profiles attached. The Gentlemen, which Microsoft tracks as Storm-2697 and PRODAFT tracks as LARVA-368, has scaled fast since mid-2025 on the back of a Fortinet foothold and a self-propagating, worm-like Go encryptor. See the CVE section for the specific flaws driving its intrusions.
Qilin held a close second on genuine breadth. Its 23 postings crossed manufacturing, healthcare, and public-sector victims across many countries, in line with its profile as the most consistently active RaaS brand of 2026. Qilin's edge-appliance focus, both Fortinet and Check Point VPN, is the throughline behind that volume.
The second tier is where the newer names sit. MedusaLocker, KryBit, and Settra each posted 11, and Genesis posted 10. That is four crews at or near double digits below the top four, a sign of how much of the current volume comes from mid-size operators rather than one or two dominant brands. We cover KryBit and Genesis in the emerging section, and MedusaLocker's tooling in the CVE section.
New and Emerging Groups
KryBit: the cross-platform March newcomer
KryBit posted 11 victims this week, enough to tie for sixth. Launched in March 2026, it ships a cross-platform builder that targets Windows, Linux, ESXi, and NAS devices, and it runs a standard affiliate model. Its intake style, high volume with thin per-victim detail, points to affiliate-fed access rather than hands-on intrusion of each named target.
KryBit is worth watching less for novel tooling and more for how quickly a four-month-old brand reached double digits in a single week. New crews often front-load volume to look established to affiliates before their real operational tempo settles. Treat a KryBit listing as a prompt to confirm your own exposure, not as proof of a fresh compromise. There is no public source tying KryBit to a specific, verifiable CVE, so weight its count against the strong chance that several entries are feed-sourced.
Genesis: quiet data-exfil extortion
Genesis posted 10 victims, most of them US small and mid-market firms across agriculture, IT, healthcare, and construction. Genesis runs a data-exfil-only model with no substantiated encryptor, so its pressure comes from publication, not lockout. Emerging since late 2025, it favours smaller organisations with thin IT teams and limited breach-response capacity.
The read on Genesis is the same as on any exfil-only crew: the pressure is reputational and regulatory rather than operational. A Genesis listing means data is claimed to be out, not that systems are down. As with KryBit, no public source ties Genesis to a specific CVE, and its target profile is consistent with credential-feed and access-broker intake.
Sector Targeting Analysis
Across the 207 victim postings this week:
| Sector | Victims | Share |
|---|---|---|
| Business Services | 33 | 16% |
| Healthcare | 21 | 10% |
| Manufacturing | 20 | 10% |
| Technology | 19 | 9% |
| Consumer Services | 17 | 8% |
| Agriculture and Food | 10 | 5% |
| Public Sector | 8 | 4% |
| Hospitality and Tourism | 8 | 4% |
| Financial Services | 7 | 3% |
| Construction | 6 | 3% |
| Energy | 5 | 2% |
A caveat on these shares. Roughly 45 of the 207 postings carried no usable sector label this week, most of them domain-only entries from Settra, KryBit, and the long tail. The percentages above are of all postings, so they understate each sector's real share of the classified victims. Read the counts, not just the percentages.
What this tells us:
Business Services led at 33 victims. Professional-services firms hold large volumes of client data on light security budgets, which keeps them the affiliate sweet spot. The Gentlemen, INC Ransom, and Akira all leaned into this sector this week.
Healthcare took the number two spot with 21 named victims, a heavier week than usual. The list skews towards small clinics, medical practices, and device makers rather than large hospital systems. Aurora's claim against a German medical-device maker and several US clinic listings sit in this bucket. Healthcare claims carry HIPAA and PHI exposure, and the providers named skew towards organisations with thin IT teams.
Manufacturing and Technology followed close behind at 20 and 19. Industrial firms with flat OT and IT networks run a low tolerance for downtime, and technology suppliers sit upstream of many other victims. The Port Angeles Composite claim, an aerospace parts maker, is the supply-chain case worth watching in this group.
Financial Services drew a lighter seven named hits this week, down from last week's cluster, though INC Ransom and Qilin both worked banks and insurers. Banking and insurance claims carry regulatory and customer-data exposure that outlasts any downtime.
Country Distribution
The United States accounts for 34% of all postings this week (70 of 207), up from 27% last week and back in line with the long-run average once you strip out the occasional Europe-weighted batch. The US remains the single largest target market for affiliate-driven extortion by a wide margin, and the July 4 dip shows how much of the weekly rhythm those US-focused crews set.
| Rank | Country | Victims |
|---|---|---|
| 1 | United States | 70 |
| 2 | Germany | 16 |
| 3 | Italy | 12 |
| 4 | France | 10 |
| 5 | United Kingdom | 9 |
| 6 | Brazil | 9 |
| 7 | Taiwan | 6 |
| 8 | Spain | 5 |
| 9 | Switzerland | 4 |
| 10 | Canada | 4 |
| 11 | Turkey | 4 |
| 12 | India | 3 |
A further 31 countries had one to two victims each, including Japan, Argentina, Thailand, Pakistan, Czech Republic, UAE, Vietnam, Australia, Norway, Sri Lanka, South Korea, Poland, Nicaragua, Tunisia, Venezuela, Hong Kong, Uruguay, Georgia, Laos, Montenegro, Slovakia, Paraguay, Netherlands, Macau, Austria, Portugal, Singapore, Malaysia, Mexico, Ecuador, and Iran.
The breadth, 43 countries in a single week, shows how affiliate-driven RaaS now operates globally. Geographic distribution tracks revenue opportunity, not threat actor location. The Gentlemen alone touched Canada, France, Taiwan, and India in one run, while Qilin spread across Europe and Latin America. Operators follow data volume into whichever regional pocket is exposed.
For readers outside the United States, the regional point holds this week. German industrial firms drew 16 hits, Italian and French firms another 22 between them, and Taiwan saw a technology cluster. Map your incident reporting obligations to your own regime, CERT-In's six-hour window in India, the SEC disclosure rules in the US, GDPR notification in the EU, before an incident forces the question.
Notable Claims and Incidents
The five claims below all appear on public leak sites. We name only what the actor posted, summarise the data categories claimed, and end each with a confidence line. None were independently confirmed as a compromise at the time of writing.
1. BlackNevas claims the Arkin Group
BlackNevas posted the hotel and resort operator Arkin Group on June 30, claiming more than 1 TB of guest and casino records, including KYC and AML documents, and attaching an 8 BTC auction. BlackNevas is a real group, a Trigona derivative active since late 2024, but the post carried no sample data.
Confidence: Low. A national-attention hospitality name, a headline data volume, and a Bitcoin auction with no proof attached is the classic pattern of an opening extortion play. Treat as unconfirmed until evidence emerges.
2. CMD Organization claims Port Angeles Composite
CMD Organization listed Port Angeles Composite, a Washington-state aerospace parts supplier. The supply-chain angle is real and verifiable on its own terms: Honda Aircraft Company acquired the firm, formerly Angeles Composite Technologies, at the end of October 2025, and now runs it as a wholly owned subsidiary making HondaJet components. A genuine breach here would carry supply-chain risk for commercial and business aviation programs.
Confidence: Medium. The Honda Aircraft ownership is confirmed, which raises the stakes, but the breach claim itself is not independently corroborated. Validate before reacting.
3. Aurora claims Primed Halberstadt Medizintechnik
Aurora posted the German medical-device maker Primed Halberstadt Medizintechnik on June 30, listing a multi-volume server exfiltration that included employee home directories and a Czech subsidiary. Device makers hold both patient data and product design files, which widens the exposure.
Confidence: Medium. Primed Halberstadt is a real medtech firm and the file-tree detail points to real access, but the specific data-volume figure the actor cited is not corroborated in the sources available. Validate the scope before treating it as confirmed.
4. The Gentlemen claim Melcor Developments
The Gentlemen listed Melcor Developments, the Edmonton real estate developer, on July 1, one of 29 victims the group posted this week. Melcor is a real Canadian firm, listed on the Toronto exchange and operating since 1923.
Confidence: Medium. The posting is genuine and the company profile checks out, but no company confirmation or sample data is available, so the impact is unconfirmed. The claim is most useful as a data point on The Gentlemen's tempo rather than as a verified breach.
5. Stormous disputes the Higuchi Inc. disclosure
Stormous posted a dispute against the Japanese firm Higuchi Inc. around June 28, contradicting the company's own breach notice. The group says the incident hit three branches rather than one and claims roughly 102 GB of accounting backups, with an eight-day deadline. No files are out yet.
Confidence: Low. The dispute between actor and victim is genuine, but the scope Stormous claims is an unverified assertion and no data has been released. This reads as pre-leak pressure rather than a confirmed dump.
Top CVEs These Groups Are Exploiting
The groups leading this week mostly exploit a known set of edge-device, VPN, hypervisor, and driver flaws, plus credential reuse. Qilin and The Gentlemen both lean on Fortinet and, in Qilin's case, Check Point VPN for initial access. MedusaLocker's resurgence this week is tied to a defense-evasion driver rather than a new entry vector. If you run any of the products below and have not confirmed patching, treat this as your priority list. Each attribution below is tied to a named vendor or government source, with a confidence note where the link is analyst-reported rather than first-party. Where we could not tie a flaw to a specific group, we left it out rather than padding the table.
| CVE | Product | CVSS | Who is using it | Why it matters |
|---|---|---|---|---|
| CVE-2024-55591 | Fortinet FortiOS / FortiProxy | 9.6 | The Gentlemen, Qilin | Authentication bypass on the FortiGate management interface. The Gentlemen, a Qilin splinter Microsoft tracks as Storm-2697, keeps a large inventory of already-compromised FortiGate devices and valid VPN credentials for fast initial access. This is the load-bearing, first-party-confirmed vector for both groups (Fortinet PSIRT; Microsoft; PRODAFT; Trend Micro). |
| CVE-2024-21762 | Fortinet FortiOS SSL VPN | 9.8 | Qilin | Out-of-bounds write allowing unauthenticated remote code execution on FortiGate. PRODAFT and FortiGuard tie Qilin's 2025 to 2026 campaign to this flaw. Tens of thousands of devices stayed exposed months after the patch. |
| CVE-2024-24919 | Check Point Remote Access VPN | 8.6 | Qilin | Information-disclosure flaw in the Check Point Security Gateway VPN blade that leaks sensitive files, including password hashes, from internet-facing gateways. Qilin affiliates use it alongside the Fortinet flaws to widen their VPN access options (Check Point; CISA). |
| CVE-2025-5777 | Citrix NetScaler ADC / Gateway | 9.3 | INC Ransom, Anubis | CitrixBleed 2, a pre-authentication out-of-bounds memory read that leaks session tokens and bypasses MFA on internet-facing NetScaler. Anubis is documented using it for initial access at scale, and INC Ransom is reported using it as well (CISA KEV; ReliaQuest; Arctic Wolf; Trend Micro). |
| CVE-2025-7771 | ThrottleStop.sys driver (BYOVD) | 7.8 | MedusaLocker, The Gentlemen | A legitimate driver with unrestricted access to physical memory. Kaspersky GERT documented it renamed and weaponised to disable Defender, CrowdStrike, and Bitdefender ahead of a MedusaLocker deployment. The Gentlemen are reported using the same bring-your-own-vulnerable-driver technique (Kaspersky Securelist / GERT; Halcyon). |
| CVE-2025-32433 | Erlang/OTP SSH | 10.0 | The Gentlemen | Unauthenticated pre-auth remote code execution in the Erlang/OTP SSH server, reaching root over the network. Reported as a secondary entry vector The Gentlemen adopted to diversify beyond Fortinet (Unit 42; Cisco PSIRT; group tie is analyst-reported). |
| CVE-2025-33073 | Windows SMB Client (NTLM relay) | 8.8 | The Gentlemen | NTLM reflection flaw that escalates a low-privileged foothold to SYSTEM. The group is reported automating domain-wide relay after initial access (Microsoft; Synacktiv; group tie is analyst-reported). |
| CVE-2023-27532 | Veeam Backup & Replication | 7.5 | The Gentlemen | Lets an attacker inside the backup network pull stored credentials from the config database. Reported as part of The Gentlemen's move to seize or wipe backups before encryption (CISA KEV; Halcyon). |
| CVE-2024-37085 | VMware ESXi | 6.8 | Akira, The Gentlemen | Authentication bypass that hands an attacker admin control of an ESXi host by creating a specific Active Directory group, enabling mass encryption of every VM on the host. First-party confirmed for Akira and Black Basta; The Gentlemen tie is analyst-reported (Microsoft; CISA AA24-109A). |
| CVE-2024-57727 | SimpleHelp RMM | 7.5 | DragonForce | Path-traversal flaw in SimpleHelp remote-management software, chained with two sibling flaws for an MSP-to-client pivot that reaches downstream victims in one move (CISA AA25-163A; Sophos; Trend Micro). |
A note on attribution accuracy. We attribute a CVE to a group only where a named vendor or government source supports the link, and we flag where that link is analyst-reported rather than first-party. Several of this week's high-volume groups have no verifiable CVE tie at all. APT73 (Bashe), a former LockBit affiliate, is reported using spear-phishing and stolen VPN and RDP credentials, not a named exploit. Settra, KryBit, Genesis, and Pear all show the domain-batch and exfil-only posting style consistent with credential-feed and infostealer intake rather than a single signature flaw. MedusaLocker's own CISA advisory (AA22-181A) names vulnerable RDP and phishing as its primary access, with no CVEs, so the ThrottleStop driver above is a defense-evasion tool, not an entry point. LockBit 5.0, released in September 2025, has no CVE tied to the 5.0 build itself; its affiliates bring their own access.
A few practical notes:
The credential-reuse angle. Patched devices still get hit when actors replay credentials stolen before the fix. Both Fortinet flaws above were used to harvest credentials that outlive the patch. Rotate VPN credentials and re-issue MFA enrolment for any device that was internet-facing while unpatched.
VPN appliances are the front door. Fortinet and Check Point gateways drove Qilin's and The Gentlemen's access this week, and CitrixBleed 2 drove Anubis and INC Ransom. Internet-facing, unpatched, credential-exposed VPNs are how affiliates get in before any locker runs.
RMM is a single point of mass compromise. CVE-2024-57727 in SimpleHelp remains the clearest one-to-many risk. One managed-services server can mean every client environment it touches. MSPs and their customers carry the top exposure here.
We are reporting these as the flaws most associated with this week's most active groups. Knowing these are being exploited is the easy part. Knowing whether any of them sit on your own external perimeter right now, on a forgotten branch-office firewall or an MSP's RMM server, is the part most teams cannot answer on a Monday morning. Confirm your own exposure rather than assuming a vendor advisory covers your specific version.
Infrastructure and Operational Shifts
Posting tempo tracks the working week, and this week the holiday proved it. Volume ran at 55 and 53 on Monday and Tuesday, then collapsed to 9 by Saturday July 4 before a soft Sunday rebound. The heavily US-focused crews that drive most of the weekly total simply posted less over the Independence Day weekend. When you benchmark a week's numbers, weight the days: a quiet Saturday is calendar, not a change in threat.
Bring-your-own-vulnerable-driver is now a shared technique, not one group's signature. The ThrottleStop driver flaw that surfaced with The Gentlemen earlier in 2026 appeared this week tied to a MedusaLocker deployment. A legitimate signed driver that grants physical-memory access is a portable EDR-killer that multiple crews can pick up, which is why turning on the vulnerable-driver blocklist matters across your whole estate, not just against one actor.
Website domains keep replacing company names in high-volume postings. Settra, KryBit, and several long-tail crews leaned on raw domain lists rather than curated victim profiles, a style that points to automated intake from access or credential feeds and inflates weekly counts with lower-confidence entries that still need triage.
Key Takeaways for Defenders
Read the rise, but weight the calendar. This week's 207 is a genuine 23% increase on last week, not a backfill artefact, and it was front-loaded into Monday to Wednesday. The July 4 drop to 9 is a US holiday effect, not a de-escalation. When a leak-site count swings, check whether one group, one batch, or the calendar drove it before briefing it as a trend.
Patch the VPN and edge layer first. Confirm patch status for Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Check Point Remote Access VPN (CVE-2024-24919), Citrix NetScaler (CVE-2025-5777, CitrixBleed 2), and SimpleHelp (CVE-2024-57727). Rotate any credentials or session tokens exposed while a device was unpatched.
Turn on the vulnerable-driver blocklist estate-wide. The ThrottleStop BYOVD technique (CVE-2025-7771) now shows up across multiple groups, MedusaLocker included. The Microsoft Vulnerable Driver Blocklist stops the EDR-killer regardless of which crew brings it. Pair it with NTLM relay hardening (CVE-2025-33073) and Veeam backup patching (CVE-2023-27532) so backups survive an intrusion.
Validate the high-value claims before you react. Arkin Group, Port Angeles Composite, and the German medtech maker are exactly the names built to draw attention on thin proof. CTI should confirm samples and your communications team should hold a pre-approved response before anyone treats a claim as a breach.
Watch your suppliers, not just yourself. The Port Angeles Composite claim reaches an aerospace program, and DragonForce's SimpleHelp pivot reaches every MSP client downstream. A supplier or partner appearing on a leak site is your problem too. Map your vendor exposure the same way you map your own.
Leak site appearance is a late signal. By the time a victim is posted, the intrusion is typically 30 to 90 days old, and a domain batch can be far older. Watching external exposure, leaked credentials, and dark web chatter as it happens is what closes that gap.
Everything above points to the same gap: the threat data is public, but the work of filtering 207 posts down to the few that touch your domains, your brands, and your vendors, then matching those groups to the flaws on your own perimeter, is what nobody has time for on a Monday. That is the gap Scrutex closes. It surfaces only the leak site activity tied to you and your supply chain, and flags the exploited CVEs that sit on your external surface.
Start a free workspace at scrutex.ai/signup. No credit card. Five minutes to first signal.
See how Scrutex Threat Intelligence works: scrutex.ai/solution/threat.
Frequently Asked Questions
How many ransomware attacks happened the week of June 29 to July 5, 2026?
207 unique victim postings appeared on dark web leak sites in that window, across 37 distinct ransomware and extortion groups. This counts leak site postings, not all attacks, and many incidents are settled privately and never appear publicly. The figure is up 23% on last week's 168, driven by a busy first half of the week rather than a single group's backfill.
Which ransomware group is most active right now?
The Gentlemen led this week with 29 postings, followed by Qilin at 23, APT73 (Bashe) at 14, and INC Ransom at 12. The Gentlemen and Qilin have traded the lead for several weeks. This week a second tier of MedusaLocker, KryBit, and Settra each posted 11.
Why did postings drop to 9 on July 4?
July 4 was the US Independence Day holiday, and the affiliate crews that drive most of the weekly total are heavily US-focused. Volume fell from a midweek peak of 55 to 9 on Saturday before a small Sunday rebound. The dip is a calendar effect, not a fall in real attack activity.
Did the Arkin Group or Port Angeles Composite get hit by ransomware?
BlackNevas posted Arkin Group with a 1 TB claim and a Bitcoin auction but no sample data, so treat it as low confidence. CMD Organization posted Port Angeles Composite, an aerospace supplier that Honda Aircraft Company acquired in October 2025. The Honda ownership is confirmed, but the breach claim itself is not independently corroborated. Both are unverified actor claims until evidence emerges.
What CVEs are these groups exploiting?
Mainly known VPN, edge, hypervisor, and driver flaws. Qilin and The Gentlemen use Fortinet FortiOS (CVE-2024-21762, CVE-2024-55591), Qilin adds Check Point VPN (CVE-2024-24919), and Anubis and INC Ransom use Citrix NetScaler CitrixBleed 2 (CVE-2025-5777). MedusaLocker and The Gentlemen use the ThrottleStop driver (CVE-2025-7771) to disable EDR, DragonForce uses SimpleHelp (CVE-2024-57727), and Akira uses VMware ESXi (CVE-2024-37085). Several high-volume groups this week, including APT73, Settra, KryBit, and Genesis, have no verifiable CVE tie and rely on stolen credentials and infostealer feeds.
What sectors should I worry about most this week?
Business Services led at 33 named victims, followed by Healthcare at 21, Manufacturing at 20, and Technology at 19. Healthcare's number two spot skews towards small clinics and device makers. A high share of postings carried no sector label this week because of domain-only entries, so read the counts alongside the percentages.
Where can I get this data in real time?
Scrutex Threat Insights surfaces ransomware leak site activity filtered to your organisation, brands, and vendors, so you see only the postings that touch your domains, brands, or supply chain.