The Community College of Beaver County is under a cyberattack, with unknown bad actors encrypting all college data and demanding ransom payments to lift it.
"We came to campus…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2026-03-04 → 2026-03-10 UTC
Choose a report date
Observed events
226
Public claims in the selected week
Data leak indicators
166
73.5% of observed events
Active actors
37
Distinct groups with observed activity
Torrent-linked events
19
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 19.5% of observed events.
•
73.5% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 21 observed events.
•
2 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
19 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
1 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2026-03-10 UTC.
Leak sites observed this week
37
Leak sites online near report date
1
Threat actor profiles updated this week
3
Countries represented this week
38
Sectors represented this week
88
Top active actors
By observed claim volumeQilin
44 events · 28 leak indicators
Akira
26 events · 19 leak indicators
LockBit 5.0
24 events · 24 leak indicators
DragonForce
21 events · 21 leak indicators
INC Ransom
16 events · 15 leak indicators
Gentlemen
13 events · 0 leak indicators
PLAY
12 events · 12 leak indicators
Genesis
8 events · 0 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- FulcrumSec 4 events
- Embargo 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States106
- Qilin22 events · 18 leak indicators
- Akira15 events · 10 leak indicators
- DragonForce12 events · 12 leak indicators
- INC Ransom12 events · 12 leak indicators
- PLAY10 events · 10 leak indicators
- Genesis8 events · 0 leak indicators
- NightSpire4 events · 4 leak indicators
- Payouts King3 events · 2 leak indicators
United Kingdom10
- DragonForce3 events · 3 leak indicators
- Qilin3 events · 1 leak indicator
- Akira1 event · 1 leak indicator
- Anubis1 event · 0 leak indicators
- FulcrumSec1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
Canada8
- Akira2 events · 2 leak indicators
- Brain Cipher2 events · 2 leak indicators
- Qilin2 events · 1 leak indicator
- AiLock1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Germany8
- Akira4 events · 3 leak indicators
- Qilin3 events · 1 leak indicator
- NightSpire1 event · 1 leak indicator
France5
- Gentlemen2 events · 0 leak indicators
- Akira1 event · 1 leak indicator
- Gunra1 event · 1 leak indicator
- SecP01 event · 0 leak indicators
Australia4
- BlackShrantac1 event · 0 leak indicators
- FulcrumSec1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
South Korea4
- Qilin2 events · 1 leak indicator
- Everest1 event · 0 leak indicators
- Kill Security1 event · 1 leak indicator
Spain4
- Akira1 event · 1 leak indicator
- Eraleignews1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- XP951 event · 0 leak indicators
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction21
- DragonForce8 events · 8 leak indicators
- PLAY3 events · 3 leak indicators
- Qilin3 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Anubis1 event · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- Gunra1 event · 1 leak indicator
IT Services and IT Consulting9
- Qilin3 events · 1 leak indicator
- Tengu2 events · 2 leak indicators
- Crypto241 event · 1 leak indicator
- FulcrumSec1 event · 1 leak indicator
- Kill Security1 event · 1 leak indicator
- PEAR1 event · 1 leak indicator
Medical Practice9
- Qilin4 events · 1 leak indicator
- INC Ransom2 events · 2 leak indicators
- BlackShrantac1 event · 0 leak indicators
- Genesis1 event · 0 leak indicators
- XP951 event · 0 leak indicators
Law Practice7
- Akira3 events · 2 leak indicators
- Genesis1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Trident1 event · 1 leak indicator
Financial Services6
- Qilin3 events · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- FulcrumSec1 event · 1 leak indicator
- Genesis1 event · 0 leak indicators
Architecture and Planning5
- DragonForce2 events · 2 leak indicators
- Akira1 event · 0 leak indicators
- Brain Cipher1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
Hospitals and Health Care5
- Gentlemen2 events · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Kairos1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Industrial Machinery Manufacturing5
- Akira2 events · 1 leak indicator
- Everest1 event · 0 leak indicators
- Genesis1 event · 0 leak indicators
- Qilin1 event · 0 leak indicators
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 63
- 51-200 employees 51
- 2-10 employees 23
- 201-500 employees 21
- 501-1,000 employees 15
- 1,001-5,000 employees 9
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
FulcrumSec
2026-03-04 UTC
Added newly observed Tox ID and Telegram user
New vuln / TTP intelligence
INC Ransom
2026-03-06 UTC
Updating TTP and MITRE ATT&CK data
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Anubis | Accounting | United States | Claim only | 2026-03-10 |
| Payouts King | Appliances, Electrical, and Electronics Manufacturing | United States | Data leak | 2026-03-10 |
| Payouts King | Retail | United States | Data leak | 2026-03-10 |
| Payouts King | Manufacturing | United States | Claim only | 2026-03-10 |
| Kairos | Hospitals and Health Care | Paraguay | Data leak | 2026-03-10 |
| Qilin | Defense and Space Manufacturing | United States | Data leak | 2026-03-10 |
| Leaknet Blog | Professional Training and Coaching | Switzerland | Data leak | 2026-03-10 |
| INC Ransom | Wholesale Building Materials | United States | Data leak | 2026-03-10 |
| Akira | Transportation, Logistics, Supply Chain and Storage | Germany | Data leak | 2026-03-10 |
| Eraleignews | Banking | Bangladesh | Data leak | 2026-03-10 |
| Eraleignews | Retail | Spain | Data leak | 2026-03-10 |
| Akira | Events Services | United States | Claim only | 2026-03-10 |
News and research context
Recent articles from the same time window.
Coalition, a cyber insurance and security company, has published the findings of its 2026 Cyber Claims Report, showing that initial ransomware demands in 2025 increased significan…
'Cyber incident' prompts London's health unit to shut down phone lines, software systems | CBC News
2026-03-07
London's health unit has shut down a number of its systems in response to what it's calling a "cybersecurity incident."
In a news release issued Friday afternoon, the Middlesex…
Related actor: INC Ransom
INC Ransom is a financially motivated cybercriminal group that emerged in mid-2023. INC Ransom provides a Ransomware-as-a-Service (RaaS) operation to its affiliate network. Affili…
A cyber attack on Passaic County’s IT systems has investigators scrambling to fix it and learn what caused it.
According to officials, a malware attack is affecting the IT syst…
Related actor: BQTlock
The Halcyon Ransomware Research Center observed a call to action for pro-Palestinian and pro-Iranian regime operators to move ransomware activity from Sicarii ransomware to Baqiya…
Related actor: Phobos
Greenbelt, Maryland – A Russian national pled guilty in federal court today to a charge connected to a ransomware conspiracy.
Evgenii Ptitsyn, 43, administered the sale, distri…
Related actor: FulcrumSec
American data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business informa…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.