Weekly intelligence Trend-first

Weekly ransomware & data leak landscape

A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.

Window: 2026-07-19 → 2026-07-25 UTC
Choose a report date
Previous week Next week
Observed events
181
Public claims in the selected week
Data leak indicators
111
61.3% of observed events
Active actors
41
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence

What changed this week?

Qilin generated the highest visible claim volume this week, representing 22.7% of observed events.
61.3% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
Construction was the most represented sector in this window with 11 observed events.
4 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.

Coverage snapshot

As of 2026-07-25 UTC.
Leak sites observed this week
41
Leak sites online near report date
0
Threat actor profiles updated this week
3
Countries represented this week
45
Sectors represented this week
80

Top active actors

By observed claim volume
Qilin
41 events · 38 leak indicators
Gentlemen
31 events · 6 leak indicators
RALord
15 events · 0 leak indicators
SAFEPAY
11 events · 11 leak indicators
Akira
7 events · 7 leak indicators
Everest
7 events · 1 leak indicator
Krybit
6 events · 6 leak indicators
PLAY
5 events · 5 leak indicators

Emerging or resurfacing actors

No matching activity in prior 30 days
  • Coinbase Cartel 3 events
  • Kairos 3 events
  • Kill Security 3 events
  • Triple X 1 event

Country mix

Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States68
  • Qilin21 events · 19 leak indicators
  • Gentlemen8 events · 3 leak indicators
  • Akira4 events · 4 leak indicators
  • Everest4 events · 0 leak indicators
  • PLAY4 events · 4 leak indicators
  • Chaos3 events · 3 leak indicators
  • Anubis2 events · 1 leak indicator
  • DragonForce2 events · 2 leak indicators
Canada16
  • Gentlemen3 events · 0 leak indicators
  • Qilin3 events · 3 leak indicators
  • Akira2 events · 2 leak indicators
  • Anubis1 event · 0 leak indicators
  • Chaos1 event · 1 leak indicator
  • Everest1 event · 0 leak indicators
  • INC Ransom1 event · 0 leak indicators
  • Kairos1 event · 1 leak indicator
Germany11
  • SAFEPAY7 events · 7 leak indicators
  • Qilin2 events · 2 leak indicators
  • DragonForce1 event · 1 leak indicator
  • SETTRA1 event · 1 leak indicator
India10
  • Krybit3 events · 3 leak indicators
  • Gentlemen2 events · 1 leak indicator
  • Everest1 event · 0 leak indicators
  • Kill Security1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • Titan1 event · 1 leak indicator
  • Triple X1 event · 1 leak indicator
Australia7
  • Gentlemen3 events · 0 leak indicators
  • Kairos1 event · 1 leak indicator
  • M3rx1 event · 0 leak indicators
  • SAFEPAY1 event · 1 leak indicator
  • SETTRA1 event · 1 leak indicator
France6
  • Gentlemen4 events · 1 leak indicator
  • RALord2 events · 0 leak indicators
Argentina5
  • Qilin2 events · 2 leak indicators
  • RALord2 events · 0 leak indicators
  • Gentlemen1 event · 0 leak indicators
Brazil4
  • Arcus Media1 event · 0 leak indicators
  • BlackWater1 event · 0 leak indicators
  • DOOMMAGEDDON1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators

Sector mix

Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction11
  • Qilin4 events · 4 leak indicators
  • Akira2 events · 2 leak indicators
  • Gentlemen2 events · 0 leak indicators
  • BravoX1 event · 1 leak indicator
  • Krybit1 event · 1 leak indicator
  • PEAR1 event · 1 leak indicator
Hospitals and Health Care10
  • Qilin3 events · 3 leak indicators
  • Anubis1 event · 0 leak indicators
  • Everest1 event · 0 leak indicators
  • Gentlemen1 event · 0 leak indicators
  • Kill Security1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • SAFEPAY1 event · 1 leak indicator
  • UnSafe1 event · 0 leak indicators
IT Services and IT Consulting9
  • RALord3 events · 0 leak indicators
  • Booba Project1 event · 1 leak indicator
  • Coinbase Cartel1 event · 0 leak indicators
  • Everest1 event · 0 leak indicators
  • Qilin1 event · 1 leak indicator
  • SAFEPAY1 event · 1 leak indicator
  • Titan1 event · 1 leak indicator
Real Estate9
  • Qilin4 events · 4 leak indicators
  • SAFEPAY3 events · 3 leak indicators
  • Kairos1 event · 1 leak indicator
  • PLAY1 event · 1 leak indicator
Retail Luxury Goods and Jewelry6
  • Gentlemen2 events · 0 leak indicators
  • Brain Cipher1 event · 1 leak indicator
  • CMD Organization1 event · 1 leak indicator
  • RALord1 event · 0 leak indicators
  • SETTRA1 event · 1 leak indicator
Industrial Machinery Manufacturing5
  • Arcus Media1 event · 0 leak indicators
  • Everest1 event · 0 leak indicators
  • Morpheus1 event · 0 leak indicators
  • RALord1 event · 0 leak indicators
  • SETTRA1 event · 1 leak indicator
Machinery Manufacturing5
  • Qilin3 events · 3 leak indicators
  • DragonForce1 event · 1 leak indicator
  • SAFEPAY1 event · 1 leak indicator
Retail5
  • Anubis1 event · 0 leak indicators
  • DOOMMAGEDDON1 event · 1 leak indicator
  • Gentlemen1 event · 0 leak indicators
  • INC Ransom1 event · 0 leak indicators
  • SETTRA1 event · 1 leak indicator

Organization size bands

Share of weekly events by employee-size group across the last 12 reporting windows.
  • 51-200 employees 53
  • 11-50 employees 42
  • 2-10 employees 19
  • 501-1,000 employees 14
  • 1,001-5,000 employees 11
  • 10,001+ employees 11

Notable actor profile updates

Active actor records only.
New ransom note observed
No ransom-note change logged in this reporting window.
New actor infrastructure / contact channel
CL0P
2026-07-21 UTC
Adding newly observed email addresses support@cryptohox.com support@cypherhex.com
New vuln / TTP intelligence
INC Ransom
2026-07-22 UTC
Adding newly observed vulns: CVE-2026-15409 and CVE-2026-15410

Recent signal samples

Selected weekly signals.
Actor Sector Country Leak proof Seen
Arcus Media Industrial Machinery Manufacturing Brazil Claim only 2026-07-25
Arcus Media Telecommunications Morocco Claim only 2026-07-25
Kairos Manufacturing United States Data leak 2026-07-25
BravoX Construction United States Data leak 2026-07-25
BlackWater Natural Gas Distribution Brazil Claim only 2026-07-25
Qilin Real Estate United States Data leak 2026-07-25
Qilin Environmental Services Croatia Claim only 2026-07-25
Qilin Non-profit Organizations United States Data leak 2026-07-25
Qilin Machinery Manufacturing United States Data leak 2026-07-25
Money Message Truck Transportation United States Data leak 2026-07-25
Qilin Hospitals and Health Care United States Data leak 2026-07-25
RALord IT Services and IT Consulting Italy Claim only 2026-07-25

News and research context

Recent articles from the same time window.
Origin Energy Limited (Origin) provides the following update on its data security incident. Origin can confirm there has been unauthorised access and disclosure of some custo…
Related actor: Qilin
The Centre for Cybersecurity Belgium published a new Cyber Threat Intelligence Report on Qilin, also known as Agenda or Qilin Locker. Qilin is a double extortion Ransomware-as-a-S…
Onsdag den 15. juli 2026 kl. 19.22 blev vi ramt af et ransomware-angreb udført fra russisk infrastruktur. Angrebet låste næsten alle vores systemer og gjorde dem ubrugelige. Vi…

Notes

  • Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
  • Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
  • Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
  • The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.

Method

  • The page uses a fixed seven-day window based on the selected date.
  • Only public-facing actor and event records are included.
  • Counts and breakdowns are designed for trend review, not incident confirmation.