Halliburton in August disclosed an unauthorized third-party accessed and removed data from its systems, causing disruptions and limited access to portions of its business applicat…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2024-11-01 → 2024-11-07 UTC
Choose a report date
Observed events
137
Public claims in the selected week
Data leak indicators
101
73.7% of observed events
Active actors
26
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence
What changed this week?
•
RansomHub generated the highest visible claim volume this week, representing 27.0% of observed events.
•
73.7% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 23 observed events.
•
4 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
Coverage snapshot
As of 2024-11-07 UTC.
Leak sites observed this week
26
Leak sites online near report date
0
Threat actor profiles updated this week
1
Countries represented this week
35
Sectors represented this week
55
Top active actors
By observed claim volumeRansomHub
37 events · 35 leak indicators
Qilin
16 events · 11 leak indicators
Helldown
15 events · 0 leak indicators
Kill Security
10 events · 10 leak indicators
Medusa
8 events · 7 leak indicators
PLAY
8 events · 8 leak indicators
Hunters International
5 events · 5 leak indicators
Lynx
5 events · 5 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Helldown 15 events
- Hellcat 3 events
- Embargo 2 events
- DarkVault 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States78
- RansomHub22 events · 20 leak indicators
- Qilin13 events · 9 leak indicators
- Helldown8 events · 0 leak indicators
- PLAY8 events · 8 leak indicators
- Medusa6 events · 5 leak indicators
- BianLian4 events · 3 leak indicators
- Lynx3 events · 3 leak indicators
- Embargo2 events · 0 leak indicators
France8
- Helldown2 events · 0 leak indicators
- Qilin2 events · 1 leak indicator
- Cactus1 event · 1 leak indicator
- Hellcat1 event · 1 leak indicator
- Hunters International1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
United Kingdom7
- Kill Security2 events · 2 leak indicators
- Cactus1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
Brazil4
- Kill Security1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
- RansomHouse1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Germany4
- Helldown3 events · 0 leak indicators
- RansomHub1 event · 1 leak indicator
India3
- Kill Security3 events · 3 leak indicators
Chile2
- MEOW1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
United Arab Emirates2
- DarkVault1 event · 1 leak indicator
- Kill Security1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction23
- RansomHub14 events · 14 leak indicators
- Medusa3 events · 3 leak indicators
- PLAY2 events · 2 leak indicators
- Helldown1 event · 0 leak indicators
- Hunters International1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Oil and Gas7
- Qilin3 events · 0 leak indicators
- RansomHub2 events · 2 leak indicators
- Helldown1 event · 0 leak indicators
- PLAY1 event · 1 leak indicator
Higher Education6
- INC Ransom2 events · 2 leak indicators
- Cactus1 event · 1 leak indicator
- Hellcat1 event · 1 leak indicator
- MEOW1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Law Practice6
- Helldown2 events · 0 leak indicators
- Qilin2 events · 2 leak indicators
- BianLian1 event · 1 leak indicator
- Hunters International1 event · 1 leak indicator
Government Administration5
- RansomHub2 events · 2 leak indicators
- Embargo1 event · 0 leak indicators
- Hellcat1 event · 1 leak indicator
- Helldown1 event · 0 leak indicators
Hospitals and Health Care5
- Embargo1 event · 0 leak indicators
- Helldown1 event · 0 leak indicators
- Kill Security1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
Medical Practice4
- Helldown1 event · 0 leak indicators
- Medusa1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Real Estate4
- Helldown1 event · 0 leak indicators
- Kill Security1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 41
- 11-50 employees 31
- 201-500 employees 18
- 1,001-5,000 employees 12
- 2-10 employees 9
- 501-1,000 employees 9
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Everest | Business Consulting and Services | United States | Claim only | 2024-11-07 |
| RansomHub | Industrial Machinery Manufacturing | United States | Data leak | 2024-11-07 |
| RansomHub | Oil and Gas | El Salvador | Data leak | 2024-11-07 |
| RansomHub | Accounting | Ireland | Data leak | 2024-11-07 |
| RansomHub | Construction | United States | Data leak | 2024-11-07 |
| Qilin | Real Estate | United States | Data leak | 2024-11-07 |
| Qilin | Law Practice | United States | Data leak | 2024-11-07 |
| DarkVault | Motor Vehicle Manufacturing | United Arab Emirates | Data leak | 2024-11-07 |
| MEOW | Legal Services | Chile | Claim only | 2024-11-07 |
| MEOW | Freight and Package Transportation | United Kingdom | Claim only | 2024-11-07 |
| RansomHub | Chemical Manufacturing | United States | Data leak | 2024-11-07 |
| Medusa | Retail | Brazil | Data leak | 2024-11-07 |
News and research context
Recent articles from the same time window.
Nach dem Cyberangriff vom letzten Oktoberwochenende auf den St. Galler Stiftsbezirk sind erste System wiederhergestellt worden. Computer, Telefone sowie die Drucker funktionieren…
Related actor: SAFEPAY
Microlise Group plc (AIM: SAAS), a leading provider of SaaS based transport technology solutions to fleet operators, reports that a large portion of the Company's services have be…
Related actor: BlackBasta
A case was reported to us last week that shows how criminals associated with the Black Basta group infect businesses with ransomware. Victims are bombarded with spam emails and th…
You could hear the cybersecurity product marketing departments groan in collective disgust following the unmasking and sanctioning of further members of the ‘Evil Corp’ ransomware…
Related actor: Embargo
BAINBRIDGE, Ga. (WALB) - A ransomware attack is impacting the record system for a hospital in Bainbridge.
The ransomware attack is impacting the Electronic Health Record system…
Related actor: INTERLOCK
A relatively new ransomware operation named Interlock attacks organizations worldwide, taking the unusual approach of creating an encryptor to target FreeBSD servers.
Launched…
South East Technological University (SETU) has experienced a cybersecurity incident targeting our IT systems.
The incident was identified at the earliest possible stage and our…
St. Anthony Regional Hospital (“St. Anthony”) is proving notice of a recent event that may impact the confidentiality of information related to certain current or former patients.…
ESE Hospital San Rafael de Pacho informa que, hemos sido victimas de un ataque cibernético
2024-11-03
La ESE Hospital San Rafael de Pacho informa que, hemos sido victimas de un ataque cibernético, por lo cual se ha activado un plan de contingencia para garantizar la normalidad en…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.