Charlton Athletic were hit by a cyber attack in August which wiped "significant financial data" the club says.
However the accounts filed at Companies House carried a disclaime…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-04-05 → 2025-04-11 UTC
Choose a report date
Observed events
156
Public claims in the selected week
Data leak indicators
117
75.0% of observed events
Active actors
34
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 18.6% of observed events.
•
75.0% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 11 observed events.
•
8 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
Coverage snapshot
As of 2025-04-11 UTC.
Leak sites observed this week
34
Leak sites online near report date
0
Threat actor profiles updated this week
4
Countries represented this week
40
Sectors represented this week
71
Top active actors
By observed claim volumeQilin
29 events · 24 leak indicators
LeakedData
14 events · 14 leak indicators
PLAY
13 events · 13 leak indicators
Akira
11 events · 0 leak indicators
J Group
9 events · 0 leak indicators
INC Ransom
8 events · 8 leak indicators
DragonForce
7 events · 7 leak indicators
Crypto24
6 events · 6 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- J Group 9 events
- Crypto24 6 events
- BERT 2 events
- Brain Cipher 1 event
- Metaencryptor 1 event
- Run Some Wares 1 event
- SatanLock 1 event
- Underground 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States60
- PLAY12 events · 12 leak indicators
- Qilin10 events · 9 leak indicators
- DragonForce5 events · 5 leak indicators
- LeakedData5 events · 5 leak indicators
- INC Ransom4 events · 4 leak indicators
- CL0P3 events · 3 leak indicators
- LockBit 3.03 events · 3 leak indicators
- Medusa3 events · 2 leak indicators
Australia7
- Qilin3 events · 3 leak indicators
- Akira1 event · 0 leak indicators
- J Group1 event · 0 leak indicators
- Sarcoma1 event · 1 leak indicator
- Space Bears1 event · 1 leak indicator
Canada6
- Qilin3 events · 3 leak indicators
- Akira1 event · 0 leak indicators
- Crypto241 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Italy6
- Akira2 events · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- RansomHouse1 event · 0 leak indicators
- Sarcoma1 event · 1 leak indicator
Singapore6
- Qilin2 events · 1 leak indicator
- Sarcoma2 events · 1 leak indicator
- Akira1 event · 0 leak indicators
- LockBit 3.01 event · 1 leak indicator
Germany4
- Akira1 event · 0 leak indicators
- Hunters International1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- J Group1 event · 0 leak indicators
India4
- Crypto241 event · 1 leak indicator
- Hunters International1 event · 1 leak indicator
- J Group1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
China3
- Hellcat1 event · 1 leak indicator
- J Group1 event · 0 leak indicators
- Kill Security1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction11
- Qilin4 events · 2 leak indicators
- PLAY3 events · 3 leak indicators
- Brain Cipher1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
Machinery Manufacturing9
- Qilin5 events · 5 leak indicators
- Akira1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Law Practice7
- LeakedData3 events · 3 leak indicators
- DragonForce2 events · 2 leak indicators
- Crypto241 event · 1 leak indicator
- Morpheus1 event · 0 leak indicators
Government Administration5
- INC Ransom1 event · 1 leak indicator
- J Group1 event · 0 leak indicators
- NightSpire1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- SatanLock1 event · 0 leak indicators
Hospitality5
- Akira2 events · 0 leak indicators
- Qilin2 events · 2 leak indicators
- PLAY1 event · 1 leak indicator
IT Services and IT Consulting5
- Crypto241 event · 1 leak indicator
- Hellcat1 event · 1 leak indicator
- Hunters International1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Termite1 event · 1 leak indicator
Software Development5
- Akira1 event · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Hellcat1 event · 1 leak indicator
- Run Some Wares1 event · 1 leak indicator
- VanHelsing1 event · 0 leak indicators
Accounting4
- Crypto241 event · 1 leak indicator
- Hunters International1 event · 0 leak indicators
- LeakedData1 event · 1 leak indicator
- LockBit 3.01 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 39
- 51-200 employees 35
- 201-500 employees 21
- 1,001-5,000 employees 13
- 2-10 employees 9
- 501-1,000 employees 9
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Akira | Machinery Manufacturing | United States | Claim only | 2025-04-11 |
| Lynx | Machinery Manufacturing | United States | Data leak | 2025-04-11 |
| Termite | IT Services and IT Consulting | Belgium | Data leak | 2025-04-11 |
| Brain Cipher | Construction | United Arab Emirates | Claim only | 2025-04-11 |
| INC Ransom | Industrial Machinery Manufacturing | United States | Data leak | 2025-04-11 |
| PLAY | Real Estate | United States | Data leak | 2025-04-10 |
| PLAY | Architecture and Planning | United States | Data leak | 2025-04-10 |
| PLAY | Construction | Canada | Data leak | 2025-04-10 |
| PLAY | Wellness and Fitness Services | United States | Data leak | 2025-04-10 |
| PLAY | Packaging and Containers Manufacturing | United States | Data leak | 2025-04-10 |
| PLAY | Machinery Manufacturing | United States | Data leak | 2025-04-10 |
| PLAY | Hospitality | United States | Data leak | 2025-04-10 |
News and research context
Recent articles from the same time window.
Cyber security breaches survey 2025 - GOV.UK
2025-04-11
Whilst the prevalence of cyber crime overall remained static, the prevalence of ransomware among businesses has significantly increased between 2024 and 2025. The estimated percen…
DfE alerted to more than 50 school ransomware attacks in past three years – PublicTechnology
2025-04-10
“However, the department has been notified of 53 ransomware cases across the sector over the last three years,” the minister added, in response to a written parliamentary question…
This notice is provided on behalf of my client, Gooding County, Idaho (the “County”). On March 25, 2025, the County detected and responded to a ransomware incident impacting its c…
Related actor: Rhysida
SALEM, Ore. (KPTV) - Oregon’s DEQ computer systems will be down through the end of the week following a cyberattack on Wednesday, the agency said.
Just before 6 p.m., the agenc…
Sensata Technologies, a U.S.-based manufacturer or industrial technologies with operations in about a dozen countries, told federal regulators that a recent ransomware attack disr…
Virtual Routes is pleased to release the second report in the Pharos Series, The Ransomware Trust Paradox by Max Smeets.
Ransomware groups operate in a paradox: despite being…
SALT LAKE CITY (KUTV) — A ransomware attack on the Arizona Federal Public Defender’s Office has delayed progress in the Ralph Menzies death penalty case.
The office was forced…
Related actor: Defray777
Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulner…
Related actor: Everest
A leak site used by the Everest ransomware gang was hacked and defaced this weekend, TechCrunch has learned.
The leak site, which the ransomware gang uses to publish stolen fi…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.