The City of Green River is dealing with a ransomware situation that has impacted its computer systems.
Chris Meats, the city’s finance director, confirmed to SweetwaterNOW the…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-06-20 → 2025-06-26 UTC
Choose a report date
Observed events
91
Public claims in the selected week
Data leak indicators
68
74.7% of observed events
Active actors
25
Distinct groups with observed activity
Torrent-linked events
8
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 19.8% of observed events.
•
74.7% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 6 observed events.
•
4 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
8 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
Coverage snapshot
As of 2025-06-26 UTC.
Leak sites observed this week
25
Leak sites online near report date
0
Threat actor profiles updated this week
0
Countries represented this week
22
Sectors represented this week
52
Top active actors
By observed claim volumeQilin
18 events · 12 leak indicators
Akira
12 events · 9 leak indicators
DragonForce
9 events · 8 leak indicators
Lynx
7 events · 5 leak indicators
Everest
5 events · 3 leak indicators
J Group
5 events · 0 leak indicators
INC Ransom
4 events · 4 leak indicators
PLAY
4 events · 4 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Hellcat 2 events
- CL0P 1 event
- Silent 1 event
- Underground 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States56
- DragonForce9 events · 8 leak indicators
- Qilin9 events · 6 leak indicators
- Akira8 events · 5 leak indicators
- Everest4 events · 3 leak indicators
- PLAY4 events · 4 leak indicators
- INC Ransom3 events · 3 leak indicators
- INTERLOCK3 events · 3 leak indicators
- Lynx3 events · 3 leak indicators
Spain5
- Qilin3 events · 2 leak indicators
- Data Leak1 event · 1 leak indicator
- Hellcat1 event · 1 leak indicator
United Kingdom5
- J Group2 events · 0 leak indicators
- Everest1 event · 0 leak indicators
- Lynx1 event · 0 leak indicators
- Qilin1 event · 0 leak indicators
Canada3
- Lynx2 events · 1 leak indicator
- Akira1 event · 1 leak indicator
France2
- Anubis1 event · 0 leak indicators
- J Group1 event · 0 leak indicators
Germany2
- Akira1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Italy2
- Akira1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Taiwan2
- Qilin1 event · 1 leak indicator
- Underground1 event · 0 leak indicators
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction6
- J Group2 events · 0 leak indicators
- Akira1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Embargo1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Law Practice6
- Everest2 events · 1 leak indicator
- Akira1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Silent1 event · 1 leak indicator
Financial Services5
- Akira4 events · 4 leak indicators
- Qilin1 event · 0 leak indicators
Medical Practice5
- Qilin2 events · 2 leak indicators
- Everest1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Hospitals and Health Care4
- Everest1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
Food and Beverage Services3
- NightSpire1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- Sarcoma1 event · 0 leak indicators
Hospitality3
- Lynx1 event · 1 leak indicator
- Metaencryptor1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Telecommunications3
- DragonForce1 event · 0 leak indicators
- Hellcat1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 23
- 11-50 employees 17
- 501-1,000 employees 11
- 2-10 employees 10
- 1,001-5,000 employees 8
- 201-500 employees 8
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| DragonForce | Medical Equipment Manufacturing | United States | Data leak | 2025-06-26 |
| DragonForce | Construction | United States | Data leak | 2025-06-26 |
| DragonForce | Wholesale | United States | Data leak | 2025-06-26 |
| PLAY | Consumer Goods | United States | Data leak | 2025-06-26 |
| Kairos | Engineering Services | United States | Data leak | 2025-06-26 |
| Lynx | Law Firm | Israel | Data leak | 2025-06-26 |
| Akira | Law Practice | United States | Data leak | 2025-06-26 |
| Akira | Law Firm | United States | Claim only | 2025-06-26 |
| Qilin | Consumer Services | Fiji | Claim only | 2025-06-26 |
| Akira | Motor Vehicle Manufacturing | Canada | Data leak | 2025-06-26 |
| Akira | Business Consulting and Services | Italy | Data leak | 2025-06-26 |
| Akira | Construction | United States | Claim only | 2025-06-26 |
News and research context
Recent articles from the same time window.
Related actor: ShinyHunters
Mais l’enquête de la BL2C continuait et les policiers spécialisés ont procédé en début de semaine à des arrestations dans les Hauts-de-Seine, en Seine-Maritime et à la Réunion. «…
Something is broken, and not only in the servers. In the past few hours, a computer attack in South Tyrol has brought entire areas of public and private life to their knees. From…
Related actor: Qilin
Please use the sharing tools found via the share button at the top or side of articles. Copying articles to share with others is a breach of FT.com T&Cs and Copyright Policy. Emai…
Glasgow City Council is currently being impacted by a cyber incident which is disrupting a number of online services and which may have involved the theft of customer data.
Ear…
The State of Ransomware 2025 - Sophos News
2025-06-25
Based on insights from a vendor-agnostic survey of 3,400 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the last year, the report c…
Related actor: REvil
Four REvil ransomware members arrested in January 2022 were released by Russia on time served after they pleaded guilty to carding and malware distribution charges.
As they con…
PETALING JAYA: CAB Cakaran Corp Bhd has revealed that the recent cyber attack on 51%-owned Farm's Best Food Industries Sdn Bhd, has not resulted in any material impact on the latt…
COLUMBUS, Ga., June 20, 2025 /PRNewswire/ -- On June 12, 2025, Aflac Incorporated (NYSE: AFL) identified suspicious activity on our network in the United States. We promptly initi…
Related actor: INC Ransom
Tonga’s National Health Information System is a victim of hackers who are demanding a ransom from the Tonga Government to release the nation’s medical records and health plans, th…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.