On April 18th, our systems experienced a ransomware attack that temporarily disrupted our usual operations. The impact is unknown at this time; however, we continue to assess and…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2024-04-20 → 2024-04-26 UTC
Choose a report date
Observed events
76
Public claims in the selected week
Data leak indicators
55
72.4% of observed events
Active actors
25
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence
What changed this week?
•
dAnon generated the highest visible claim volume this week, representing 10.5% of observed events.
•
72.4% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Medical Practice was the most represented sector in this window with 7 observed events.
•
5 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
2 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2024-04-26 UTC.
Leak sites observed this week
25
Leak sites online near report date
2
Threat actor profiles updated this week
4
Countries represented this week
22
Sectors represented this week
42
Top active actors
By observed claim volumedAnon
8 events · 8 leak indicators
PLAY
8 events · 7 leak indicators
Qiulong
6 events · 1 leak indicator
RansomHub
6 events · 5 leak indicators
8BASE
5 events · 5 leak indicators
Medusa
5 events · 4 leak indicators
RansomHouse
5 events · 0 leak indicators
BianLian
4 events · 3 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- dAnon 8 events
- Qiulong 6 events
- Eraleignews 2 events
- Embargo 1 event
- MedusaLocker 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States39
- PLAY7 events · 7 leak indicators
- dAnon6 events · 6 leak indicators
- BianLian4 events · 3 leak indicators
- Medusa3 events · 3 leak indicators
- RansomHub3 events · 2 leak indicators
- Blacksuit2 events · 1 leak indicator
- Hunters International2 events · 2 leak indicators
- INC Ransom2 events · 2 leak indicators
Brazil7
- Qiulong6 events · 1 leak indicator
- DarkVault1 event · 1 leak indicator
Germany3
- 8BASE2 events · 2 leak indicators
- Eraleignews1 event · 1 leak indicator
United Kingdom3
- BlackBasta1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Australia2
- Hunters International1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Canada2
- Everest1 event · 0 leak indicators
- Medusa1 event · 0 leak indicators
France2
- 8BASE1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Italy2
- 8BASE1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Medical Practice7
- Qiulong5 events · 1 leak indicator
- BianLian2 events · 2 leak indicators
Construction4
- dAnon1 event · 1 leak indicator
- Embargo1 event · 1 leak indicator
- Everest1 event · 0 leak indicators
- PLAY1 event · 1 leak indicator
Financial Services4
- BianLian1 event · 1 leak indicator
- MyData1 event · 0 leak indicators
- PLAY1 event · 1 leak indicator
- RansomHub1 event · 0 leak indicators
Hospitals and Health Care4
- dAnon1 event · 1 leak indicator
- Hunters International1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- Medusa1 event · 0 leak indicators
IT Services and IT Consulting4
- DarkVault1 event · 1 leak indicator
- Eraleignews1 event · 1 leak indicator
- PLAY1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Architecture and Planning3
- BlackBasta1 event · 1 leak indicator
- dAnon1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Law Practice3
- BianLian1 event · 0 leak indicators
- BlackBasta1 event · 1 leak indicator
- dAnon1 event · 1 leak indicator
Retail3
- Medusa1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- Qiulong1 event · 0 leak indicators
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 22
- 11-50 employees 18
- 2-10 employees 8
- 1,001-5,000 employees 7
- 201-500 employees 6
- 501-1,000 employees 4
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Qiulong | Medical Practice | Brazil | Claim only | 2024-04-26 |
| PLAY | Oil and Gas | United States | Data leak | 2024-04-26 |
| PLAY | IT Services and IT Consulting | Mexico | Claim only | 2024-04-26 |
| PLAY | Financial Services | United States | Data leak | 2024-04-26 |
| PLAY | Aviation and Aerospace Component Manufacturing | United States | Data leak | 2024-04-26 |
| PLAY | Food and Beverage Services | United States | Data leak | 2024-04-26 |
| LockBit 3.0 | Oil and Gas | United States | Data leak | 2024-04-26 |
| PLAY | Construction | United States | Data leak | 2024-04-26 |
| PLAY | Retail | United States | Data leak | 2024-04-26 |
| BlackBasta | Architecture and Planning | United States | Data leak | 2024-04-26 |
| Eraleignews | IT Services and IT Consulting | Germany | Data leak | 2024-04-26 |
| Cactus | Book and Periodical Publishing | Netherlands | Data leak | 2024-04-26 |
News and research context
Recent articles from the same time window.
Related actor: Cactus
The effectiveness of the public-private partnership called Melissa [2] is increasingly evident. The Melissa partnership, which includes Fox-IT, has identified overlap in a specifi…
Russian-Canadian hacker sentenced for global ransomware scheme to be extradited | CTV News
2024-04-25
Related actor: LockBit 3.0
Convicted cybercriminal Mikhail Vasiliev has been sentenced to nearly four years in jail after pleading guilty last month to eight counts of cyber extortion, mischief and weapons…
The program would warn organizations running software or hardware with vulnerabilities being exploited by ransomware gangs.
The Cybersecurity and Infrastructure Security Agency…
Coalition reveals uptick in cyber insurance claims driven by ransomware in 2023 - SiliconANGLE
2024-04-24
As ransomware payments hit $1 billion globally, Coalition ransomware severity dropped by 54%. Ransomware severity, frequency, and demands all dropped in 2H 2023, though not enough…
Learn how data leak site operators like RansomHub and Dispossessor are feeding a new extortion cycle as the ransomware ecosystem evolves.
Ransomware Task Force: Doubling Down
2024-04-24
In April 2021, the Ransomware Task Force (RTF) published Combating Ransomware: A Comprehensive Framework for Action (“the Report”), which outlined 48 recommendations for industry,…
Ransomware groups are rebranding and making friends with businesses. This was one of the key points made by cybersecurity expert Lisa Forte, partner at Red Goat Cybersecurity, whe…
Cyber attackers are experimenting with their latest ransomware on businesses in Africa, Asia and South America before targeting richer countries that have more sophisticated secur…
Related actor: LockBit 3.0
Logistikbolaget Skanlog blev utsatt för en ransomware-attack vilket kan leda till varubrist på Systembolaget.
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.