The Community College of Beaver County is under a cyberattack, with unknown bad actors encrypting all college data and demanding ransom payments to lift it.
"We came to campus…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2026-03-05 → 2026-03-11 UTC
Choose a report date
Observed events
228
Public claims in the selected week
Data leak indicators
169
74.1% of observed events
Active actors
38
Distinct groups with observed activity
Torrent-linked events
18
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 21.5% of observed events.
•
74.1% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 18 observed events.
•
1 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
18 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
•
3 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2026-03-11 UTC.
Leak sites observed this week
38
Leak sites online near report date
3
Threat actor profiles updated this week
3
Countries represented this week
42
Sectors represented this week
89
Top active actors
By observed claim volumeQilin
49 events · 30 leak indicators
Akira
23 events · 20 leak indicators
LockBit 5.0
16 events · 16 leak indicators
DragonForce
13 events · 13 leak indicators
INC Ransom
13 events · 13 leak indicators
NightSpire
12 events · 11 leak indicators
PLAY
12 events · 12 leak indicators
Gentlemen
10 events · 0 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- Embargo 3 events
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States108
- Qilin24 events · 19 leak indicators
- Akira13 events · 10 leak indicators
- INC Ransom10 events · 10 leak indicators
- PLAY10 events · 10 leak indicators
- DragonForce9 events · 9 leak indicators
- Genesis8 events · 0 leak indicators
- NightSpire6 events · 5 leak indicators
- CipherForce3 events · 2 leak indicators
Canada9
- Akira2 events · 2 leak indicators
- Brain Cipher2 events · 2 leak indicators
- Qilin2 events · 1 leak indicator
- AiLock1 event · 1 leak indicator
- Coinbase Cartel1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
United Kingdom8
- Qilin3 events · 1 leak indicator
- DragonForce2 events · 2 leak indicators
- Akira1 event · 1 leak indicator
- Anubis1 event · 0 leak indicators
- Gentlemen1 event · 0 leak indicators
France7
- Gentlemen2 events · 0 leak indicators
- Akira1 event · 1 leak indicator
- Coinbase Cartel1 event · 1 leak indicator
- Gunra1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- SecP01 event · 0 leak indicators
Germany7
- Akira3 events · 3 leak indicators
- Qilin3 events · 1 leak indicator
- NightSpire1 event · 1 leak indicator
Australia5
- BlackShrantac1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
- SAFEPAY1 event · 1 leak indicator
South Korea5
- Qilin2 events · 1 leak indicator
- CipherForce1 event · 1 leak indicator
- Everest1 event · 1 leak indicator
- Kill Security1 event · 1 leak indicator
Spain5
- Akira1 event · 1 leak indicator
- Eraleignews1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
- XP951 event · 0 leak indicators
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction18
- DragonForce6 events · 6 leak indicators
- Qilin4 events · 3 leak indicators
- PLAY3 events · 3 leak indicators
- Anubis1 event · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Gunra1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- NightSpire1 event · 1 leak indicator
IT Services and IT Consulting9
- CipherForce2 events · 1 leak indicator
- Qilin2 events · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Eraleignews1 event · 1 leak indicator
- Kill Security1 event · 1 leak indicator
- PEAR1 event · 1 leak indicator
- Tengu1 event · 1 leak indicator
Medical Practice8
- Qilin3 events · 1 leak indicator
- INC Ransom2 events · 2 leak indicators
- BlackShrantac1 event · 0 leak indicators
- Genesis1 event · 0 leak indicators
- XP951 event · 0 leak indicators
Appliances, Electrical, and Electronics Manufacturing7
- Akira3 events · 3 leak indicators
- Qilin3 events · 1 leak indicator
- Payouts King1 event · 1 leak indicator
Financial Services5
- Qilin3 events · 1 leak indicator
- CipherForce1 event · 1 leak indicator
- Genesis1 event · 0 leak indicators
Hospitals and Health Care5
- Gentlemen2 events · 0 leak indicators
- Crypto241 event · 1 leak indicator
- Kairos1 event · 1 leak indicator
- SAFEPAY1 event · 1 leak indicator
Law Practice5
- Akira1 event · 1 leak indicator
- Genesis1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Trident1 event · 1 leak indicator
Real Estate5
- Akira3 events · 2 leak indicators
- Medusa1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 63
- 51-200 employees 50
- 201-500 employees 25
- 501-1,000 employees 18
- 2-10 employees 17
- 1,001-5,000 employees 11
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
AiLock
2026-03-11 UTC
Adding TOX ID 50601B7AB3E663174BD6BF9B58D3B92ACB25FE273A44BC6348A1F544568AEA5054422A334234
New vuln / TTP intelligence
INC Ransom
2026-03-06 UTC
Updating TTP and MITRE ATT&CK data
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| CipherForce | Telecommunications | United States | Claim only | 2026-03-11 |
| Qilin | Appliances, Electrical, and Electronics Manufacturing | Australia | Claim only | 2026-03-11 |
| Qilin | Appliances, Electrical, and Electronics Manufacturing | Argentina | Claim only | 2026-03-11 |
| Coinbase Cartel | Retail Office Equipment | United States | Data leak | 2026-03-11 |
| Coinbase Cartel | Retail Apparel and Fashion | France | Data leak | 2026-03-11 |
| Coinbase Cartel | Retail Apparel and Fashion | Canada | Data leak | 2026-03-11 |
| NightSpire | Aviation and Aerospace Component Manufacturing | United States | Claim only | 2026-03-11 |
| Embargo | Data Security Software Products | United States | Data leak | 2026-03-11 |
| CipherForce | IT Services and IT Consulting | Philippines | Claim only | 2026-03-11 |
| CipherForce | Internet Marketplace Platforms | United States | Data leak | 2026-03-11 |
| CipherForce | Staffing and Recruiting | South Korea | Data leak | 2026-03-11 |
| CipherForce | Software Development | United States | Data leak | 2026-03-11 |
News and research context
Recent articles from the same time window.
Coalition, a cyber insurance and security company, has published the findings of its 2026 Cyber Claims Report, showing that initial ransomware demands in 2025 increased significan…
'Cyber incident' prompts London's health unit to shut down phone lines, software systems | CBC News
2026-03-07
London's health unit has shut down a number of its systems in response to what it's calling a "cybersecurity incident."
In a news release issued Friday afternoon, the Middlesex…
Related actor: INC Ransom
INC Ransom is a financially motivated cybercriminal group that emerged in mid-2023. INC Ransom provides a Ransomware-as-a-Service (RaaS) operation to its affiliate network. Affili…
A cyber attack on Passaic County’s IT systems has investigators scrambling to fix it and learn what caused it.
According to officials, a malware attack is affecting the IT syst…
Related actor: BQTlock
The Halcyon Ransomware Research Center observed a call to action for pro-Palestinian and pro-Iranian regime operators to move ransomware activity from Sicarii ransomware to Baqiya…
Related actor: Phobos
Greenbelt, Maryland – A Russian national pled guilty in federal court today to a charge connected to a ransomware conspiracy.
Evgenii Ptitsyn, 43, administered the sale, distri…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.