Weekly intelligence Trend-first

Weekly ransomware & data leak landscape

A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.

Window: 2026-07-17 → 2026-07-23 UTC
Choose a report date
Previous week Next week
Observed events
195
Public claims in the selected week
Data leak indicators
114
58.5% of observed events
Active actors
35
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence

What changed this week?

•
Qilin generated the highest visible claim volume this week, representing 20.5% of observed events.
•
58.5% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 10 observed events.
•
4 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.

Coverage snapshot

As of 2026-07-23 UTC.
Leak sites observed this week
35
Leak sites online near report date
0
Threat actor profiles updated this week
3
Countries represented this week
45
Sectors represented this week
84

Top active actors

By observed claim volume
Qilin
40 events · 34 leak indicators
Gentlemen
34 events · 8 leak indicators
RALord
16 events · 0 leak indicators
Everest
11 events · 1 leak indicator
Krybit
11 events · 11 leak indicators
INC Ransom
10 events · 1 leak indicator
SAFEPAY
9 events · 9 leak indicators
Akira
8 events · 8 leak indicators

Emerging or resurfacing actors

No matching activity in prior 30 days
  • Coinbase Cartel 3 events
  • Kill Security 3 events
  • Kairos 2 events
  • Blackout 1 event

Country mix

Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States64
  • Qilin18 events · 15 leak indicators
  • Gentlemen10 events · 4 leak indicators
  • Akira6 events · 6 leak indicators
  • Everest5 events · 0 leak indicators
  • PLAY4 events · 4 leak indicators
  • Chaos3 events · 3 leak indicators
  • INC Ransom3 events · 0 leak indicators
  • Anubis2 events · 1 leak indicator
Canada18
  • Gentlemen3 events · 0 leak indicators
  • Qilin3 events · 3 leak indicators
  • Akira1 event · 1 leak indicator
  • Anubis1 event · 0 leak indicators
  • Chaos1 event · 1 leak indicator
  • Everest1 event · 0 leak indicators
  • INC Ransom1 event · 0 leak indicators
  • INTERLOCK1 event · 1 leak indicator
India12
  • Krybit3 events · 3 leak indicators
  • Everest2 events · 0 leak indicators
  • Gentlemen2 events · 1 leak indicator
  • LockBit 5.02 events · 2 leak indicators
  • Kill Security1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • Titan1 event · 1 leak indicator
Germany9
  • SAFEPAY7 events · 7 leak indicators
  • Qilin1 event · 1 leak indicator
  • SETTRA1 event · 1 leak indicator
Argentina7
  • Qilin3 events · 2 leak indicators
  • RALord2 events · 0 leak indicators
  • Gentlemen1 event · 0 leak indicators
  • LockBit 5.01 event · 1 leak indicator
France7
  • Gentlemen4 events · 1 leak indicator
  • RALord2 events · 0 leak indicators
  • Qilin1 event · 0 leak indicators
Australia6
  • Gentlemen3 events · 0 leak indicators
  • Kairos1 event · 1 leak indicator
  • SAFEPAY1 event · 1 leak indicator
  • SETTRA1 event · 1 leak indicator
Indonesia4
  • RALord3 events · 0 leak indicators
  • Everest1 event · 0 leak indicators

Sector mix

Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction10
  • Qilin4 events · 4 leak indicators
  • Akira2 events · 2 leak indicators
  • Gentlemen2 events · 0 leak indicators
  • INTERLOCK1 event · 1 leak indicator
  • Krybit1 event · 1 leak indicator
IT Services and IT Consulting10
  • Everest2 events · 0 leak indicators
  • Coinbase Cartel1 event · 0 leak indicators
  • DragonForce1 event · 1 leak indicator
  • LockBit 5.01 event · 1 leak indicator
  • M3rx1 event · 0 leak indicators
  • Qilin1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • SAFEPAY1 event · 1 leak indicator
Hospitals and Health Care9
  • Gentlemen2 events · 0 leak indicators
  • Qilin2 events · 2 leak indicators
  • Anubis1 event · 0 leak indicators
  • Everest1 event · 0 leak indicators
  • Kill Security1 event · 1 leak indicator
  • Krybit1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
Real Estate9
  • Qilin3 events · 3 leak indicators
  • SAFEPAY3 events · 3 leak indicators
  • Kairos1 event · 1 leak indicator
  • M3rx1 event · 0 leak indicators
  • PLAY1 event · 1 leak indicator
Manufacturing7
  • Qilin3 events · 1 leak indicator
  • Everest1 event · 0 leak indicators
  • Gentlemen1 event · 0 leak indicators
  • INC Ransom1 event · 0 leak indicators
  • SAFEPAY1 event · 1 leak indicator
Retail Luxury Goods and Jewelry7
  • Gentlemen2 events · 0 leak indicators
  • Blackout1 event · 1 leak indicator
  • Brain Cipher1 event · 1 leak indicator
  • CMD Organization1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • SETTRA1 event · 1 leak indicator
Retail6
  • Gentlemen2 events · 0 leak indicators
  • Anubis1 event · 0 leak indicators
  • DOOMMAGEDDON1 event · 1 leak indicator
  • INC Ransom1 event · 0 leak indicators
  • SETTRA1 event · 1 leak indicator
Automotive5
  • Akira1 event · 1 leak indicator
  • INC Ransom1 event · 1 leak indicator
  • Krybit1 event · 1 leak indicator
  • NightSpire1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators

Organization size bands

Share of weekly events by employee-size group across the last 12 reporting windows.
  • 51-200 employees 54
  • 11-50 employees 49
  • 201-500 employees 19
  • 1,001-5,000 employees 15
  • 2-10 employees 15
  • 501-1,000 employees 14

Notable actor profile updates

Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
CL0P
2026-07-21 UTC
Adding newly observed email addresses support@cryptohox.com support@cypherhex.com
New vuln / TTP intelligence
INC Ransom
2026-07-22 UTC
Adding newly observed vulns: CVE-2026-15409 and CVE-2026-15410

Recent signal samples

Selected weekly signals.
Actor Sector Country Leak proof Seen
Everest Medical Practice United States Claim only 2026-07-23
INC Ransom Medical Practice United States Claim only 2026-07-23
PLAY Wholesale United States Data leak 2026-07-23
PLAY Travel Arrangements Spain Data leak 2026-07-23
PLAY Real Estate United States Data leak 2026-07-23
CMD Organization Retail Luxury Goods and Jewelry United States Data leak 2026-07-23
Everest IT Services and IT Consulting India Claim only 2026-07-23
Krybit Oil and Gas South Sudan Data leak 2026-07-23
Qilin Construction Canada Data leak 2026-07-23
Qilin Machinery Manufacturing Canada Data leak 2026-07-23
Anubis Hospitals and Health Care United States Claim only 2026-07-23
Krybit Construction Thailand Data leak 2026-07-23

News and research context

Recent articles from the same time window.
Related actor: Qilin
The Centre for Cybersecurity Belgium published a new Cyber Threat Intelligence Report on Qilin, also known as Agenda or Qilin Locker. Qilin is a double extortion Ransomware-as-a-S…
Onsdag den 15. juli 2026 kl. 19.22 blev vi ramt af et ransomware-angreb udført fra russisk infrastruktur. Angrebet låste næsten alle vores systemer og gjorde dem ubrugelige. Vi…
Related actor: Everest
Nach einem Datendiebstahl über eine Austauschplattform eines Zulieferers sieht Stadler die eigenen IT-Systeme nicht betroffen. Die Täter verlangen 10 Millionen Franken Lösegeld.…
Hackerangriff: Die Stiftung Wagerenhof in Uster wurde Opfer eines umfangreichen Ransomware-Angriffes. Dieser erfolgte am Abend des 9. Juli. Es wurden umgehend Massnahmen ergriffen…

Notes

  • Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
  • Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
  • Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
  • The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.

Method

  • The page uses a fixed seven-day window based on the selected date.
  • Only public-facing actor and event records are included.
  • Counts and breakdowns are designed for trend review, not incident confirmation.