En av Region Västerbottens leverantörer har utsatts för en cyberatack. Regionen har nu därför gått upp i stabsläge. - Det påverkar inte våra patienter i nuläget. Vi har samlats i…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2024-02-24 → 2024-03-01 UTC
Choose a report date
Observed events
108
Public claims in the selected week
Data leak indicators
69
63.9% of observed events
Active actors
26
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence
What changed this week?
•
PLAY generated the highest visible claim volume this week, representing 15.7% of observed events.
•
63.9% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 8 observed events.
•
3 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
1 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2024-03-01 UTC.
Leak sites observed this week
26
Leak sites online near report date
1
Threat actor profiles updated this week
3
Countries represented this week
25
Sectors represented this week
67
Top active actors
By observed claim volumePLAY
17 events · 15 leak indicators
LockBit 3.0
15 events · 14 leak indicators
AlphVM
9 events · 3 leak indicators
Mogilevich (SCAM!!)
7 events · 0 leak indicators
BlackBasta
6 events · 6 leak indicators
Medusa
5 events · 5 leak indicators
8BASE
4 events · 4 leak indicators
Akira
4 events · 0 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Blackout 2 events
- CiphBit 1 event
- Dunghill Leak 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States58
- PLAY12 events · 10 leak indicators
- LockBit 3.08 events · 7 leak indicators
- Medusa4 events · 4 leak indicators
- AlphVM3 events · 1 leak indicator
- BlackBasta3 events · 3 leak indicators
- CL0P3 events · 0 leak indicators
- Data Leak3 events · 1 leak indicator
- DragonForce3 events · 2 leak indicators
Canada10
- PLAY4 events · 4 leak indicators
- AlphVM2 events · 1 leak indicator
- Blackout1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
Germany4
- LockBit 3.03 events · 3 leak indicators
- AlphVM1 event · 0 leak indicators
Netherlands3
- RansomHouse2 events · 0 leak indicators
- Cactus1 event · 1 leak indicator
Sweden3
- Akira1 event · 0 leak indicators
- LockBit 3.01 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
United Kingdom3
- 3AM1 event · 1 leak indicator
- AlphVM1 event · 0 leak indicators
- BlackBasta1 event · 1 leak indicator
Australia2
- LockBit 3.01 event · 1 leak indicator
- Mogilevich (SCAM!!)1 event · 0 leak indicators
France2
- Blackout1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction8
- AlphVM2 events · 1 leak indicator
- Blacksuit2 events · 2 leak indicators
- PLAY2 events · 1 leak indicator
- BlackBasta1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
Hospitals and Health Care7
- LockBit 3.02 events · 2 leak indicators
- Abyss1 event · 1 leak indicator
- BianLian1 event · 1 leak indicator
- Blackout1 event · 1 leak indicator
- Monti1 event · 0 leak indicators
- Rhysida1 event · 0 leak indicators
Medical Practice4
- AlphVM1 event · 0 leak indicators
- BianLian1 event · 0 leak indicators
- Data Leak1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
Truck Transportation4
- 8BASE1 event · 1 leak indicator
- BlackBasta1 event · 1 leak indicator
- Cactus1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Law Practice3
- BlackBasta2 events · 2 leak indicators
- INC Ransom1 event · 1 leak indicator
Machinery Manufacturing3
- Blackout1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Trigona1 event · 0 leak indicators
Retail3
- BlackBasta1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Accounting2
- AlphVM2 events · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 29
- 11-50 employees 21
- 1,001-5,000 employees 15
- 201-500 employees 15
- 501-1,000 employees 8
- 2-10 employees 6
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| PLAY | Mechanical Or Industrial Engineering | United States | Data leak | 2024-03-01 |
| PLAY | Food and Beverage Manufacturing | United States | Data leak | 2024-03-01 |
| PLAY | Aviation and Aerospace Component Manufacturing | United States | Data leak | 2024-03-01 |
| PLAY | Software Development | Canada | Data leak | 2024-03-01 |
| PLAY | Paper and Forest Products | Sweden | Data leak | 2024-03-01 |
| PLAY | Leasing Real Estate | United States | Data leak | 2024-03-01 |
| PLAY | Plastics Manufacturing | Canada | Data leak | 2024-03-01 |
| PLAY | Strategic Management Services | United States | Data leak | 2024-03-01 |
| PLAY | Retail | United States | Data leak | 2024-03-01 |
| PLAY | IT Services and IT Consulting | United States | Claim only | 2024-03-01 |
| PLAY | Truck Transportation | United States | Data leak | 2024-03-01 |
| PLAY | Construction | United States | Claim only | 2024-03-01 |
News and research context
Recent articles from the same time window.
Miscreants have plenty of ways to gain access to a business's internal systems. For example, they can brute-force their way in, logging into accounts with weak, default, or easily…
#StopRansomware: Phobos Ransomware
2024-02-29
Related actor: Phobos
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are r…
Related actor: LockBit 3.0
This is the Greek mythological story about Cronos, the name of which was likely chosen for the most epic operation against ransomware known to this day. On February 20, 2024, the…
Prominent Sacramento law firm sues for $1 million after falling prey to ransomware attack
2024-02-29
Related actor: BlackBasta
A prominent Sacramento law firm that represents police officers and sheriff’s deputies in the capital region is suing a computer firm for more than $1 million alleging that, after…
Related actor: BlackBasta
On 8 February 2024, we became aware that an unauthorised third party accessed our system and encrypted some files. Working with our cyber security experts, we took immediate steps…
On December 4th, our Information Security Team received notification that an unauthorized user had successfully accessed a third-party system utilized by Fairway.
Related actor: AlphVM
This blog post provides a detailed look at the TTPs of a ransomware affiliate operator. In this case, the endpoint had been moved to another infrastructure (as illustrated by vari…
Irish foreign affairs ministry says ‘no evidence’ of cyber breach following extortion claim
2024-02-28
Related actor: Mogilevich
A new cybercrime group listed Ireland's Department of Foreign Affairs on its extortion site. The claim is bogus, according to the government.
ISLAMABAD: The University of Management and Technology (UMT) Lahore was recently hit by a highly advanced ransomware attack, it emerged on Wednesday.
The UMT, is a private univ…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.