A prominent Sydney law firm with close links to the NRL and A-League has been targeted by foreign cyber-attackers who are now extorting the business over hundreds of gigabytes of…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-03-07 → 2025-03-13 UTC
Choose a report date
Observed events
163
Public claims in the selected week
Data leak indicators
101
62.0% of observed events
Active actors
32
Distinct groups with observed activity
Torrent-linked events
3
Events intersecting with torrent intelligence
What changed this week?
•
Akira generated the highest visible claim volume this week, representing 16.6% of observed events.
•
62.0% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Hospitals and Health Care was the most represented sector in this window with 9 observed events.
•
5 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
3 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
1 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2025-03-13 UTC.
Leak sites observed this week
32
Leak sites online near report date
1
Threat actor profiles updated this week
4
Countries represented this week
42
Sectors represented this week
71
Top active actors
By observed claim volumeAkira
27 events · 3 leak indicators
BABUK 2.0
18 events · 0 leak indicators
PLAY
17 events · 17 leak indicators
RansomHub
12 events · 11 leak indicators
Lynx
10 events · 10 leak indicators
Qilin
10 events · 9 leak indicators
INC Ransom
9 events · 9 leak indicators
SAFEPAY
7 events · 7 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- BABUK 2.0 18 events
- NightSpire 6 events
- CrazyHunter 5 events
- Leaknet Blog 1 event
- Nitrogen 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States74
- PLAY12 events · 12 leak indicators
- Akira11 events · 1 leak indicator
- INC Ransom6 events · 6 leak indicators
- Lynx6 events · 6 leak indicators
- RansomHub6 events · 5 leak indicators
- Cactus5 events · 5 leak indicators
- Qilin5 events · 4 leak indicators
- BABUK 2.03 events · 0 leak indicators
Taiwan7
- CrazyHunter5 events · 5 leak indicators
- Akira1 event · 0 leak indicators
- Lynx1 event · 1 leak indicator
Canada6
- PLAY3 events · 3 leak indicators
- Fog1 event · 0 leak indicators
- Medusa1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
India6
- BABUK 2.02 events · 0 leak indicators
- Defray7771 event · 1 leak indicator
- FSOCIETY1 event · 0 leak indicators
- RansomHouse1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Germany5
- INC Ransom3 events · 3 leak indicators
- Akira1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Spain5
- Akira4 events · 0 leak indicators
- Arcus Media1 event · 0 leak indicators
Brazil4
- BABUK 2.03 events · 0 leak indicators
- Arcus Media1 event · 0 leak indicators
United Kingdom4
- Embargo1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
- Sarcoma1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Hospitals and Health Care9
- CrazyHunter3 events · 3 leak indicators
- Fog2 events · 0 leak indicators
- INC Ransom2 events · 2 leak indicators
- RansomHouse1 event · 0 leak indicators
- RansomHub1 event · 1 leak indicator
Construction7
- Akira3 events · 0 leak indicators
- PLAY2 events · 2 leak indicators
- Kairos1 event · 1 leak indicator
- Sarcoma1 event · 1 leak indicator
Hospitality6
- SAFEPAY2 events · 2 leak indicators
- Akira1 event · 0 leak indicators
- BABUK 2.01 event · 0 leak indicators
- Embargo1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
Telecommunications6
- Akira1 event · 0 leak indicators
- Arcus Media1 event · 0 leak indicators
- BABUK 2.01 event · 0 leak indicators
- BianLian1 event · 0 leak indicators
- PLAY1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Transportation, Logistics, Supply Chain and Storage6
- Akira3 events · 1 leak indicator
- Lynx1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Government Administration5
- BABUK 2.03 events · 0 leak indicators
- Qilin1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
IT Services and IT Consulting5
- CL0P2 events · 1 leak indicator
- BABUK 2.01 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Machinery Manufacturing5
- Akira2 events · 0 leak indicators
- Lynx1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- RansomHub1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 40
- 11-50 employees 36
- 201-500 employees 22
- 1,001-5,000 employees 19
- 501-1,000 employees 15
- 10,001+ employees 6
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| 3AM | Glass, Ceramics and Concrete Manufacturing | United States | Data leak | 2025-03-13 |
| Lynx | Chemical Manufacturing | United States | Data leak | 2025-03-13 |
| Lynx | Transportation, Logistics, Supply Chain and Storage | United States | Data leak | 2025-03-13 |
| PLAY | Wholesale Building Materials | United States | Data leak | 2025-03-13 |
| PLAY | Construction | Germany | Data leak | 2025-03-13 |
| PLAY | Motor Vehicle Manufacturing | United States | Data leak | 2025-03-13 |
| RansomHub | Law Practice | United States | Data leak | 2025-03-13 |
| Rhysida | Security and Investigations | United States | Data leak | 2025-03-13 |
| Qilin | Automation Machinery Manufacturing | United States | Data leak | 2025-03-13 |
| Embargo | Hospitality | United Arab Emirates | Data leak | 2025-03-13 |
| RansomHub | Textile Manufacturing | India | Data leak | 2025-03-13 |
| BABUK 2.0 | Industrial Machinery Manufacturing | Brazil | Claim only | 2025-03-13 |
News and research context
Recent articles from the same time window.
Tokyo, March 13 (Jiji Press)--Japanese police have received 222 reports of damage from ransomware attacks in 2024, up 25 from the previous year, National Police Agency data showed…
Déclaration concernant l’incident de sécurité chez Forvis Mazars en France - Forvis Mazars - France
2025-03-13
Related actor: BABUK 2.0
10/03/2025 | Chez Forvis Mazars, nous accordons la plus grande importance à la sécurité des données et mettons tout en œuvre pour assurer au quotidien les meilleurs niveaux de pro…
#StopRansomware: Medusa Ransomware | CISA
2025-03-12
Related actor: Medusa
Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of February 2025, Medusa developers and affiliates have impacted over 300 victims from a varie…
Dutch police disrupt half of ransomware operations, finds embedded PHD student | Computer Weekly
2025-03-12
Dutch police interventions successfully disrupt approximately half of the ransomware groups they target, according to PhD research at the University of Twente.
Conducted by T…
We are currently investigating a cyber incident affecting our networks. As soon as we became aware of this incident, our IT security team took precautionary measures. We then part…
The government of Mission, Texas, filed a state of emergency declaration this week after a cyberattack exposed all of the data held on city systems.
The city government notifie…
TOKYO, JAPAN, March 5, 2025 — NTT Communications Corporation (NTT Com), announced today that on February 5th, it determined that unauthorized access to its systems had occurred. O…
Related actor: Qilin
Since late February 2025, Microsoft has observed Moonstone Sleet, a North Korean state actor, deploying Qilin ransomware at a limited number of organizations. Qilin is a ransomwar…
National Presto Industries, Inc. - SEC.gov
2025-03-07
On March 1, 2025, the Registrant experienced a system outage caused by a cybersecurity incident. Upon discovery, the Registrant activated its incident response team, comprised of…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.