A personal data breach at a Disclosure and Barring Service (DBS) contractor has affected some people in Guernsey, officials have said.
The Office of the Data Protection Authori…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-08-22 → 2025-08-28 UTC
Choose a report date
Observed events
106
Public claims in the selected week
Data leak indicators
78
73.6% of observed events
Active actors
26
Distinct groups with observed activity
Torrent-linked events
5
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 15.1% of observed events.
•
73.6% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 7 observed events.
•
4 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
5 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
Coverage snapshot
As of 2025-08-28 UTC.
Leak sites observed this week
26
Leak sites online near report date
0
Threat actor profiles updated this week
4
Countries represented this week
23
Sectors represented this week
58
Top active actors
By observed claim volumeQilin
16 events · 8 leak indicators
Cephalus
15 events · 8 leak indicators
SAFEPAY
10 events · 10 leak indicators
Akira
9 events · 5 leak indicators
DragonForce
7 events · 7 leak indicators
INC Ransom
7 events · 7 leak indicators
World Leaks
6 events · 6 leak indicators
Dire Wolf
5 events · 4 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Cephalus 15 events
- Chaos 1 event
- Metaencryptor 1 event
- SECUROTROP 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States58
- Cephalus12 events · 7 leak indicators
- Qilin11 events · 5 leak indicators
- Akira6 events · 3 leak indicators
- PLAY4 events · 4 leak indicators
- Beast3 events · 0 leak indicators
- DragonForce3 events · 3 leak indicators
- INC Ransom3 events · 3 leak indicators
- INTERLOCK3 events · 3 leak indicators
Canada9
- Akira3 events · 2 leak indicators
- INC Ransom2 events · 2 leak indicators
- Anubis1 event · 0 leak indicators
- Metaencryptor1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
Germany6
- SAFEPAY6 events · 6 leak indicators
United Kingdom6
- Dire Wolf1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- INTERLOCK1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Australia3
- Dire Wolf1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Italy3
- DragonForce1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Sarcoma1 event · 1 leak indicator
France2
- DragonForce1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
Mexico2
- Qilin1 event · 0 leak indicators
- SAFEPAY1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction7
- Qilin4 events · 1 leak indicator
- Akira2 events · 1 leak indicator
- Sinobi1 event · 1 leak indicator
Law Practice7
- Cephalus3 events · 2 leak indicators
- PLAY2 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
Financial Services4
- INC Ransom2 events · 2 leak indicators
- Cephalus1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
Facilities Services3
- Akira1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- World Leaks1 event · 1 leak indicator
Higher Education3
- Kairos2 events · 2 leak indicators
- PEAR1 event · 1 leak indicator
Hospitals and Health Care3
- Cephalus2 events · 1 leak indicator
- Cloak1 event · 0 leak indicators
IT Services and IT Consulting3
- Cephalus1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Machinery Manufacturing3
- INC Ransom2 events · 2 leak indicators
- Qilin1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 35
- 11-50 employees 31
- 2-10 employees 11
- 201-500 employees 10
- 501-1,000 employees 9
- 1,001-5,000 employees 2
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| INC Ransom | Automotive | Canada | Data leak | 2025-08-28 |
| INC Ransom | Machinery Manufacturing | United States | Data leak | 2025-08-28 |
| PEAR | Non-profit Organizations | United States | Data leak | 2025-08-28 |
| SAFEPAY | Retail | Germany | Data leak | 2025-08-28 |
| Cloak | Hospitals and Health Care | United States | Claim only | 2025-08-28 |
| Qilin | Construction | United States | Claim only | 2025-08-28 |
| Rhysida | Alternative Medicine | United States | Data leak | 2025-08-28 |
| Kairos | Higher Education | United States | Data leak | 2025-08-28 |
| Cephalus | Non-profit Organizations | United States | Claim only | 2025-08-28 |
| Cephalus | Maritime Transportation | Netherlands | Claim only | 2025-08-28 |
| Cephalus | Hospitals and Health Care | United States | Claim only | 2025-08-28 |
| Anubis | Aviation and Aerospace | Canada | Claim only | 2025-08-28 |
News and research context
Recent articles from the same time window.
Single Central Record, also known as Online SCR, has written to its customers to inform them it has been notified by its software supplier Intradev Limited of a data breach.
Sc…
SEOUL, Aug 28 (Reuters) - South Korea's SK Telecom (017670.KS), opens new tab was fined on Thursday about 134 billion won ($96.53 million) after the country's largest mobile carri…
The Office of the Registrar General (ORG), formerly Registrar General's Department, has been hit by a cyber attack, which it says was an attempt to disrupt systems and gain access…
Storm-0501’s evolving techniques lead to cloud-based ransomware | Microsoft Security Blog
2025-08-28
Related actor: Storm-0501
Microsoft Threat Intelligence has observed financially motivated threat actor Storm-0501 continuously evolving their campaigns to achieve sharpened focus on cloud-based tactics, t…
Rochester, Indiana - August 25, 2025. On June 30, 2025, we learned that our computer network was accessed without permission. In response, we promptly took steps to confirm the se…
We are sharing insights on a ransomware development commercial operation that demonstrates how AI is transforming the creation and distribution of malware through Ransomware-as-a-…
Related actor: Underground
The Underground ransomware gang is launching continuous ransomware attacks against companies in various countries and industries, including South Korea. This post describes the an…
Related actor: Cephalus
In mid-August, we came across a ransomware variant called Cephalus in two separate incidents. Recently, we’ve seen a slew of newer ransomware families (like Crux and KawaLocker),…
WEST CHESTER TOWNSHIP, Ohio (WXIX) - West Chester Township says it might have been targeted by a “malicious hacking group.”
The township said around 6:45 a.m. Tuesday, they wer…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.