FLINT, Mich. (WJRT) - The FBI and the Attorney General's Office are investigating a criminal ransomware attack on the city of Flint that began Wednesday morning.
The attack cau…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2024-08-10 → 2024-08-16 UTC
Choose a report date
Observed events
103
Public claims in the selected week
Data leak indicators
69
67.0% of observed events
Active actors
28
Distinct groups with observed activity
Torrent-linked events
1
Events intersecting with torrent intelligence
What changed this week?
•
LockBit 3.0 generated the highest visible claim volume this week, representing 15.5% of observed events.
•
67.0% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Accounting was the most represented sector in this window with 6 observed events.
•
3 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
1 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
1 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2024-08-16 UTC.
Leak sites observed this week
28
Leak sites online near report date
1
Threat actor profiles updated this week
2
Countries represented this week
27
Sectors represented this week
58
Top active actors
By observed claim volumeLockBit 3.0
16 events · 16 leak indicators
RansomHub
12 events · 12 leak indicators
Helldown
10 events · 0 leak indicators
MEOW
9 events · 0 leak indicators
PLAY
8 events · 7 leak indicators
Qilin
8 events · 8 leak indicators
Rhysida
5 events · 4 leak indicators
BianLian
4 events · 4 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Helldown 10 events
- CiphBit 2 events
- Trinity 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States52
- LockBit 3.010 events · 10 leak indicators
- RansomHub8 events · 8 leak indicators
- MEOW6 events · 0 leak indicators
- PLAY6 events · 6 leak indicators
- Rhysida5 events · 4 leak indicators
- Qilin4 events · 4 leak indicators
- BianLian3 events · 3 leak indicators
- Helldown2 events · 0 leak indicators
Italy7
- CiphBit2 events · 2 leak indicators
- Helldown2 events · 0 leak indicators
- Blacksuit1 event · 1 leak indicator
- Hunters International1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Canada5
- BianLian1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
- Metaencryptor1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
United Kingdom5
- LockBit 3.01 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
- Trinity1 event · 0 leak indicators
Poland4
- Helldown2 events · 0 leak indicators
- Hunters International1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
France3
- Brain Cipher1 event · 0 leak indicators
- Helldown1 event · 0 leak indicators
- LockBit 3.01 event · 1 leak indicator
South Africa3
- DarkVault2 events · 2 leak indicators
- LockBit 3.01 event · 1 leak indicator
Austria2
- Helldown1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Accounting6
- DarkVault2 events · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- Rhysida1 event · 1 leak indicator
- Trinity1 event · 0 leak indicators
Construction5
- Helldown2 events · 0 leak indicators
- Abyss1 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Hospitals and Health Care4
- BianLian1 event · 1 leak indicator
- DarkVault1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Retail4
- Akira1 event · 1 leak indicator
- Cicada33011 event · 0 leak indicators
- MEOW1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Software Development4
- Brain Cipher1 event · 0 leak indicators
- Defray7771 event · 1 leak indicator
- Helldown1 event · 0 leak indicators
- Kill Security1 event · 0 leak indicators
Financial Services3
- BianLian1 event · 1 leak indicator
- Helldown1 event · 0 leak indicators
- Medusa1 event · 1 leak indicator
Machinery Manufacturing3
- Blacksuit1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
Motor Vehicle Manufacturing3
- Hunters International1 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- PLAY1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 34
- 51-200 employees 32
- 201-500 employees 10
- 1,001-5,000 employees 7
- 501-1,000 employees 6
- 2-10 employees 5
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| RansomHub | Telecommunications | United States | Data leak | 2024-08-16 |
| CiphBit | Architecture and Planning | Italy | Data leak | 2024-08-16 |
| MEOW | Motor Vehicle Manufacturing | Sweden | Claim only | 2024-08-16 |
| MEOW | Accounting | United Kingdom | Claim only | 2024-08-16 |
| Hunters International | Food and Beverage Manufacturing | Poland | Data leak | 2024-08-16 |
| RansomHub | Banking | United States | Data leak | 2024-08-16 |
| Qilin | Non-profit Organizations | United States | Data leak | 2024-08-16 |
| Qilin | Construction | Austria | Data leak | 2024-08-16 |
| Qilin | IT Services and IT Consulting | United Kingdom | Data leak | 2024-08-16 |
| Qilin | Civic and Social Organization | Brazil | Data leak | 2024-08-16 |
| Qilin | Education Administration Programs | Lebanon | Data leak | 2024-08-16 |
| Hunters International | Biomass Electric Power Generation | Italy | Claim only | 2024-08-16 |
News and research context
Recent articles from the same time window.
The Ransomware Tool Matrix
2024-08-16
Ransomware attacks are becoming increasingly damaging, but one thing remains consistent: the tools these cybercriminals rely on. The Ransomware Tool Matrix is a comprehensive reso…
Aggregate illicit activity on-chain has dropped by almost 20% year-to-date, demonstrating that legitimate activity is growing more quickly than illicit activity.
Despite the dec…
Related actor: Hunters International
EDMONTON, AB, Aug. 13, 2024 /CNW/ - AutoCanada Inc. ("AutoCanada or the "Company") (TSX: ACQ) announced that it identified a cybersecurity incident on August 11, 2024 that has imp…
Related actor: INC Ransom
Interestingly, Inc victims do have a degree of recourse available to them in the hours after an attack. In a newly published report, GuidePoint Security describes how it can inter…
Related actor: Brain Cipher
Deep dive into Brain Cipher ransomware group's activities and techniques, and how they are seemingly linked to other ransomware groups such as EstateRansomware and SenSayQ.
On…
Don’t get Mad, get wise – Sophos News
2024-08-14
Related actor: Mad Liberator
The Sophos X-Ops Incident Response team has been examining the tactics of a ransomware group called Mad Liberator. This is a fairly new threat actor, first emerging in mid-July 2…
Evolution Mining Limited (“Evolution” or “The Company”) became aware on 8 August 2024 of a ransomware attack impacting its IT systems. The Company has been working with its extern…
Related actor: Dispossessor
CLEVELAND (WKBN) — We’ve all heard of businesses and organizations getting hit with ransomware and then having their private information, including client information, held hostag…
Aug 12 (Reuters) - Schlatter Industries' (STRN.S), opens new tab IT network was attacked with malware on Friday and it can be assumed this was a professional attack, the Switzerla…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.