A Dutch healthcare software vendor has been knocked offline following a ransomware attack, officials say.
ChipSoft's website went down on April 7 and remains unreachable at the…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2026-04-02 → 2026-04-08 UTC
Choose a report date
Observed events
175
Public claims in the selected week
Data leak indicators
108
61.7% of observed events
Active actors
34
Distinct groups with observed activity
Torrent-linked events
3
Events intersecting with torrent intelligence
What changed this week?
•
Gentlemen generated the highest visible claim volume this week, representing 14.3% of observed events.
•
61.7% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 10 observed events.
•
2 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
3 observed events in this week intersected with torrent intelligence, which is useful for understanding data-distribution tactics beyond plain leak-site posts.
Coverage snapshot
As of 2026-04-08 UTC.
Leak sites observed this week
34
Leak sites online near report date
0
Threat actor profiles updated this week
3
Countries represented this week
40
Sectors represented this week
78
Top active actors
By observed claim volumeGentlemen
25 events · 1 leak indicator
DragonForce
21 events · 20 leak indicators
LockBit 5.0
19 events · 19 leak indicators
Akira
17 events · 8 leak indicators
NightSpire
11 events · 7 leak indicators
INC Ransom
9 events · 8 leak indicators
Coinbase Cartel
7 events · 2 leak indicators
LeakedData
7 events · 4 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- BQTlock 1 event
- Cry0 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States58
- Akira14 events · 5 leak indicators
- DragonForce9 events · 8 leak indicators
- Gentlemen7 events · 0 leak indicators
- NightSpire4 events · 2 leak indicators
- INC Ransom3 events · 3 leak indicators
- PLAY3 events · 2 leak indicators
- Coinbase Cartel2 events · 0 leak indicators
- INTERLOCK2 events · 2 leak indicators
Italy9
- LockBit 5.06 events · 6 leak indicators
- Anubis1 event · 0 leak indicators
- Cry01 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
United Kingdom9
- Coinbase Cartel2 events · 2 leak indicators
- DragonForce2 events · 2 leak indicators
- Anubis1 event · 0 leak indicators
- Brain Cipher1 event · 1 leak indicator
- BravoX1 event · 1 leak indicator
- Gentlemen1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
France7
- Akira2 events · 2 leak indicators
- LockBit 5.02 events · 2 leak indicators
- NightSpire2 events · 2 leak indicators
- XP951 event · 0 leak indicators
Canada6
- DragonForce3 events · 3 leak indicators
- Brain Cipher1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- MNT61 event · 1 leak indicator
Germany6
- AiLock1 event · 1 leak indicator
- Beast1 event · 1 leak indicator
- Coinbase Cartel1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- INC Ransom1 event · 0 leak indicators
Thailand6
- Gentlemen5 events · 0 leak indicators
- DragonForce1 event · 1 leak indicator
Australia5
- Anubis1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
- LockBit 5.01 event · 1 leak indicator
- Qilin1 event · 1 leak indicator
- Space Bears1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction10
- LockBit 5.03 events · 3 leak indicators
- NightSpire2 events · 1 leak indicator
- Akira1 event · 1 leak indicator
- Coinbase Cartel1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- Krybit1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Manufacturing9
- DragonForce3 events · 3 leak indicators
- LockBit 5.03 events · 3 leak indicators
- Akira1 event · 0 leak indicators
- Gentlemen1 event · 0 leak indicators
- RALord1 event · 1 leak indicator
Insurance6
- Akira2 events · 1 leak indicator
- Brain Cipher1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- LockBit 5.01 event · 1 leak indicator
- XP951 event · 0 leak indicators
Oil and Gas6
- Anubis1 event · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- Insomnia1 event · 1 leak indicator
- Payload1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
IT Services and IT Consulting5
- DragonForce2 events · 2 leak indicators
- Anubis1 event · 0 leak indicators
- Gentlemen1 event · 1 leak indicator
- XP951 event · 0 leak indicators
Law Practice5
- Beast1 event · 1 leak indicator
- DragonForce1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- Lynx1 event · 1 leak indicator
- PLAY1 event · 1 leak indicator
Pharmaceutical Manufacturing5
- DragonForce2 events · 2 leak indicators
- Gunra1 event · 1 leak indicator
- INC Ransom1 event · 1 leak indicator
- LockBit 5.01 event · 1 leak indicator
Retail5
- Gentlemen2 events · 0 leak indicators
- DragonForce1 event · 1 leak indicator
- Krybit1 event · 0 leak indicators
- LockBit 5.01 event · 1 leak indicator
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 11-50 employees 42
- 51-200 employees 40
- 201-500 employees 19
- 1,001-5,000 employees 16
- 501-1,000 employees 12
- 2-10 employees 9
Notable actor profile updates
Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
Kairos
2026-04-08 UTC
Adding new .onion domain, adding support email, mentioning SBU seizing old .onion domain in March 2026.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Qilin | Oil and Gas | United States | Claim only | 2026-04-08 |
| XP95 | Insurance | Nigeria | Claim only | 2026-04-08 |
| Payouts King | Architecture and Planning | United States | Data leak | 2026-04-08 |
| Gentlemen | Mental Health Care | United States | Claim only | 2026-04-08 |
| Lynx | Outsourcing and Offshoring Consulting | United States | Data leak | 2026-04-08 |
| Beast | Law Practice | Germany | Data leak | 2026-04-08 |
| Coinbase Cartel | Computers and Electronics Manufacturing | Taiwan | Claim only | 2026-04-08 |
| Coinbase Cartel | Government Administration | Brazil | Claim only | 2026-04-08 |
| Coinbase Cartel | Automation Machinery Manufacturing | Germany | Claim only | 2026-04-08 |
| Coinbase Cartel | Construction | United Kingdom | Data leak | 2026-04-08 |
| INC Ransom | Pharmaceutical Manufacturing | Australia | Data leak | 2026-04-08 |
| Coinbase Cartel | Software Development | United States | Claim only | 2026-04-08 |
News and research context
Recent articles from the same time window.
WINONA COUNTY, Minn. (WKBT) -- Governor Tim Walz issued an executive order on Tuesday providing emergency assistance to Winona County following a cyberattack that began on Monday,…
Related actor: Anubis
April 6, 2026 (Brockton, MA) – Signature Healthcare and Signature Healthcare Brockton Hospital are currently responding to a cybersecurity incident that has affected certain infor…
Related actor: Medusa
The financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 operates high-velocity ransomware campaigns that weaponize N-days, targeting v…
Related actor: Handala
St. Joseph County officials acknowledged a cyber attack by an Iranian-backed hacker group called Handala earlier this week.
County officials and council members held a news con…
Omax Autos Confirms Ransomware Attack, Operations Remain Unaffected | Whalesbook Corporate News
2026-04-04
Omax Autos Limited has confirmed a ransomware attack on its IT infrastructure, first detected on March 26, 2026. The company stated that while IT systems were affected, its core o…
An IT system used by schools across Northern Ireland has been targeted in a cyber attack, the Education Authority (EA) has said.
On Thursday, schools received a message that as…
The Uffizi Galleries in Florence have confirmed they were subject to a cyber-attack - but denied that the security systems protecting their famous works had been compromised.
T…
MINOT, ND (KXNET) — Hackers got into the Minot water treatment plant computer system earlier this month, but city officials stressed the water stayed safe and the plant never stop…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.