Multiple Lorain County departments have been affected by a computer network security incident that is being investigated by computer experts, county officials announced late Thurs…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-05-24 → 2025-05-30 UTC
Choose a report date
Observed events
160
Public claims in the selected week
Data leak indicators
123
76.9% of observed events
Active actors
36
Distinct groups with observed activity
Torrent-linked events
8
Events intersecting with torrent intelligence
What changed this week?
•
SAFEPAY generated the highest visible claim volume this week, representing 16.9% of observed events.
•
76.9% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 13 observed events.
•
8 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
8 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
3 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2025-05-30 UTC.
Leak sites observed this week
36
Leak sites online near report date
3
Threat actor profiles updated this week
0
Countries represented this week
38
Sectors represented this week
67
Top active actors
By observed claim volumeSAFEPAY
27 events · 26 leak indicators
Qilin
23 events · 11 leak indicators
Devman
17 events · 14 leak indicators
Akira
9 events · 8 leak indicators
PLAY
8 events · 7 leak indicators
Dire Wolf
7 events · 6 leak indicators
Data Leak
5 events · 5 leak indicators
NightSpire
5 events · 5 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Devman 17 events
- Dire Wolf 7 events
- Apos Security 4 events
- Crypto24 2 events
- MedusaLocker 2 events
- 3AM 1 event
- Chaos 1 event
- CiphBit 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States67
- SAFEPAY16 events · 15 leak indicators
- Qilin13 events · 8 leak indicators
- PLAY6 events · 5 leak indicators
- Akira4 events · 4 leak indicators
- Data Leak4 events · 4 leak indicators
- Medusa3 events · 3 leak indicators
- World Leaks3 events · 3 leak indicators
- Blacksuit2 events · 2 leak indicators
Canada10
- Qilin3 events · 0 leak indicators
- Akira1 event · 1 leak indicator
- Data Leak1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
Italy7
- Kill Security2 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Arcus Media1 event · 0 leak indicators
- DATACARRY1 event · 1 leak indicator
- Devman1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
Germany6
- SAFEPAY4 events · 4 leak indicators
- Crypto241 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
Brazil5
- Gunra2 events · 0 leak indicators
- Arcus Media1 event · 0 leak indicators
- Devman1 event · 1 leak indicator
- Rhysida1 event · 1 leak indicator
Spain5
- Akira2 events · 2 leak indicators
- Apos Security1 event · 1 leak indicator
- Devman1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Australia4
- Apos Security1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
South Africa4
- Devman3 events · 2 leak indicators
- Everest1 event · 0 leak indicators
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction13
- Data Leak3 events · 3 leak indicators
- SAFEPAY2 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Apos Security1 event · 1 leak indicator
- Embargo1 event · 1 leak indicator
- Kill Security1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Government Administration6
- Devman2 events · 2 leak indicators
- Cloak1 event · 0 leak indicators
- Hunters International1 event · 0 leak indicators
- Medusa1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Hospitality6
- Qilin2 events · 0 leak indicators
- Blacksuit1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
IT Services and IT Consulting5
- CiphBit1 event · 1 leak indicator
- Devman1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
- PLAY1 event · 0 leak indicators
- RALord1 event · 1 leak indicator
Legal Services5
- SAFEPAY2 events · 2 leak indicators
- Dire Wolf1 event · 1 leak indicator
- FSOCIETY1 event · 0 leak indicators
- Gunra1 event · 0 leak indicators
Printing Services5
- Arcus Media1 event · 0 leak indicators
- Medusa1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
- SAFEPAY1 event · 1 leak indicator
Transportation, Logistics, Supply Chain and Storage5
- Akira2 events · 1 leak indicator
- Data Leak1 event · 1 leak indicator
- Devman1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
Financial Services4
- Arkana1 event · 0 leak indicators
- Kill Security1 event · 1 leak indicator
- Leaknet Blog1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 55
- 11-50 employees 28
- 201-500 employees 15
- 501-1,000 employees 15
- 1,001-5,000 employees 12
- 2-10 employees 12
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Dire Wolf | IT Services and IT Consulting | Canada | Data leak | 2025-05-30 |
| INC Ransom | Individual and Family Services | Canada | Data leak | 2025-05-30 |
| Lynx | Farming | United States | Data leak | 2025-05-30 |
| Medusa | Government Administration | United States | Data leak | 2025-05-30 |
| SAFEPAY | Telecommunications | Germany | Data leak | 2025-05-30 |
| SAFEPAY | Sporting Goods | Germany | Data leak | 2025-05-30 |
| SAFEPAY | Non-profit Organizations | United States | Data leak | 2025-05-30 |
| SAFEPAY | Non-profit Organization Management | United States | Data leak | 2025-05-30 |
| SAFEPAY | Printing Services | United States | Data leak | 2025-05-30 |
| SAFEPAY | Automotive | United States | Data leak | 2025-05-30 |
| Qilin | Business Supplies and Equipment | Australia | Data leak | 2025-05-30 |
| Qilin | Motor Vehicle Manufacturing | Taiwan | Claim only | 2025-05-30 |
News and research context
Recent articles from the same time window.
Related actor: Everest
Extortionist-cum-information broker "Everest Group" has pulled off a swath of attacks against large organizations in the Middle East, Africa, Europe, and North America, and is now…
Related actor: Conti
The elusive boss of the Trickbot and Conti cybercriminal groups has been known only as “Stern.” Now, German law enforcement has published his alleged identity - and it’s a familia…
Related actor: DragonForce
Rundt klokken 07 tirsdag morgen ble det oppdaget et virusangrep mot en av Mediehuset Altapostens servere. Dette rammet blant annet tirsdagens papiravisutgave, samt Radio Alta.…
FLEMINGTON, NJ - Following a May 6 ransomware attack on the Flemington-Raritan School District’s system, superintendent Dr. Kari McGann talked about what was and wasn’t impacted.…
Some Australian businesses must now report to the government if they have paid a ransom after being extorted during a ransomware attack, under a new law which takes effect from Fr…
Related actor: INTERLOCK
The Interlock ransomware gang is deploying a previously undocumented remote access trojan (RAT) named NodeSnake against educational institutes for persistent access to corporate n…
Yesterday, the Information Technology team at Covenant Health detected a data security issue has necessitated a temporary system outage. We are continuing to see patients for offi…
LexisNexis Risk Solutions, a data broker that collects and uses consumers’ personal data to help its paying corporate customers detect possible risk and fraud, has disclosed a dat…
Wie jetzt bekannt wurde, haben die Arcona-Hotels am Freitag letzter Woche Unregelmäßigkeiten an einzelnen IT-Systemen festgestellt. Aktuellen Erkenntnissen zufolge sind die arcona…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.