Fast Track is issuing this statement regarding an isolated incident that occurred in early October.
Fast Track experienced a highly sophisticated cyber attack that specifically…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2025-10-08 → 2025-10-14 UTC
Choose a report date
Observed events
187
Public claims in the selected week
Data leak indicators
133
71.1% of observed events
Active actors
37
Distinct groups with observed activity
Torrent-linked events
14
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 35.3% of observed events.
•
71.1% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 13 observed events.
•
7 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
14 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
2 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2025-10-14 UTC.
Leak sites observed this week
37
Leak sites online near report date
2
Threat actor profiles updated this week
2
Countries represented this week
38
Sectors represented this week
77
Top active actors
By observed claim volumeQilin
66 events · 31 leak indicators
Sinobi
26 events · 25 leak indicators
Akira
15 events · 14 leak indicators
BrotherHood
10 events · 6 leak indicators
DragonForce
9 events · 9 leak indicators
SAFEPAY
8 events · 8 leak indicators
INC Ransom
7 events · 7 leak indicators
Medusa
4 events · 4 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- BrotherHood 10 events
- Kryptos 3 events
- BQTlock 2 events
- Dire Wolf 2 events
- INTERLOCK 2 events
- CL0P 1 event
- Payouts King 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States101
- Qilin34 events · 22 leak indicators
- Sinobi20 events · 19 leak indicators
- Akira13 events · 12 leak indicators
- BrotherHood4 events · 3 leak indicators
- INC Ransom4 events · 4 leak indicators
- SAFEPAY3 events · 3 leak indicators
- DragonForce2 events · 2 leak indicators
- INTERLOCK2 events · 2 leak indicators
France13
- Qilin12 events · 2 leak indicators
- Sinobi1 event · 1 leak indicator
Canada9
- BrotherHood2 events · 1 leak indicator
- Qilin2 events · 1 leak indicator
- SAFEPAY2 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- Kryptos1 event · 0 leak indicators
Spain8
- Qilin4 events · 1 leak indicator
- Space Bears2 events · 2 leak indicators
- BlackNevas1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
Australia6
- BrotherHood1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- Kryptos1 event · 0 leak indicators
- Qilin1 event · 0 leak indicators
- Scattered LAPSUS$ Hunters1 event · 0 leak indicators
Italy4
- DragonForce1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
- Sinobi1 event · 1 leak indicator
Colombia3
- Qilin2 events · 0 leak indicators
- Sinobi1 event · 1 leak indicator
Argentina2
- RALord1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction13
- Qilin5 events · 0 leak indicators
- Sinobi3 events · 3 leak indicators
- Akira2 events · 2 leak indicators
- Chaos1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Law Practice8
- Qilin4 events · 2 leak indicators
- Akira3 events · 2 leak indicators
- SAFEPAY1 event · 1 leak indicator
Transportation, Logistics, Supply Chain and Storage8
- Qilin2 events · 1 leak indicator
- Anubis1 event · 0 leak indicators
- BrotherHood1 event · 1 leak indicator
- Dire Wolf1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- Medusa1 event · 1 leak indicator
- Space Bears1 event · 1 leak indicator
Government Administration7
- Qilin4 events · 1 leak indicator
- Obscura1 event · 1 leak indicator
- RALord1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Real Estate6
- Qilin4 events · 2 leak indicators
- DragonForce1 event · 1 leak indicator
- Sinobi1 event · 1 leak indicator
Retail6
- Qilin3 events · 2 leak indicators
- 3AM1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Sinobi1 event · 1 leak indicator
Software Development6
- BrotherHood3 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Everest1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Hospitals and Health Care5
- Sinobi3 events · 3 leak indicators
- Qilin1 event · 0 leak indicators
- World Leaks1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 50
- 51-200 employees 45
- 201-500 employees 22
- 501-1,000 employees 18
- 1,001-5,000 employees 15
- 2-10 employees 15
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Gentlemen | Entertainment Providers | Italy | Claim only | 2025-10-14 |
| Qilin | Manufacturing | United States | Claim only | 2025-10-14 |
| Qilin | Packaging and Containers Manufacturing | United States | Data leak | 2025-10-14 |
| Qilin | Industrial Machinery Manufacturing | Malaysia | Claim only | 2025-10-14 |
| Qilin | Insurance | United States | Data leak | 2025-10-14 |
| Qilin | Information Technology and Services | Spain | Claim only | 2025-10-14 |
| Qilin | Food and Beverage Services | Colombia | Claim only | 2025-10-14 |
| Qilin | Staffing and Recruiting | France | Claim only | 2025-10-14 |
| Qilin | Construction | United States | Claim only | 2025-10-14 |
| Qilin | Construction | France | Claim only | 2025-10-14 |
| Qilin | Wholesale Building Materials | United States | Claim only | 2025-10-14 |
| Qilin | Cosmetics | France | Claim only | 2025-10-14 |
News and research context
Recent articles from the same time window.
Ansell Limited (ASX: ANN), one of Australia’s largest protective equipment manufacturers, has disclosed an Ansell cyber incident that exposed company data through vulnerabilities…
Related actor: Akira
Although the breach did not affect general election operations, the personal data of citizens, including names and addresses, was believed to have been compromised in April. These…
Singapore faces increasing ransomware attacks, with state-sponsored actors targeting businesses for payoffs, making it a prime target for cyber espionage. Companies hesitate to re…
Related actor: INTERLOCK
We want to inform you of an important situation impacting Kearney Public Schools. Last Friday, our district’s technology network was compromised by a cybersecurity attack. Since t…
Prosecutors are seeking a seven-year prison sentence for the 19-year-old Massachusetts man who pleaded guilty to hacking into an education technology company’s databases and steal…
Related actor: Obscura
The City of Michigan City has confirmed that the network disruption it experienced on Sept. 23 was a ransomware incident that affected a portion of the City’s data and impacted mu…
Paying off cyber criminals no guarantee stolen data won't be published - study - TechCentral.ie
2025-10-10
Almost three-quarters (70%) of Irish business who have experienced a ransomware attack paid a ransom in the past 12 months to prevent sensitive data being published, however, near…
Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign | Google Cloud Blog
2025-10-09
Related actor: CL0P
Beginning Sept. 29, 2025, Google Threat Intelligence Group (GTIG) and Mandiant began tracking a new, large-scale extortion campaign by a threat actor claiming affiliation with the…
Velociraptor leveraged in ransomware attacks
2025-10-09
Related actor: Warlock
In August 2025, Talos responded to a ransomware attack by actors who appeared to be affiliated with Warlock ransomware, based on their ransom note and use of Warlock’s data leak s…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.