Ransomware Activity Card
Ransomware Activity — June 2026
June 2026 ransomware reporting showed elevated public activity, rapid movement among leading RaaS brands, continued pressure on healthcare, services, and education, and multiple access paths that reward early identity, edge, and pre-encryption detection.
Top 10 Briefing Points
- 1
The Gentlemen moved to the top of Check Point's June ranking — Check Point attributed 17% of published attacks in its June dataset to The Gentlemen, ahead of Qilin at 11%; these are data-leak-site disclosures, not confirmed incident totals.[1]
- 2
Publicly visible ransomware activity increased — BlackFog counted 102 publicly disclosed attacks across 21 countries and 31 groups in June, while explicitly separating public disclosure from unverified actor attribution.[2]
- 3
Healthcare, services, and education remained prominent — BlackFog's June dataset recorded healthcare as its leading sector, followed by services and education, supporting continued scoping attention for sensitive-data and operational-disruption exposure.[2]
- 4
Dataset definitions cannot be combined into one victim count — Check Point reports published attacks, while BlackFog mixes public disclosures and qualified claims. Use each source for direction within its own methodology rather than adding the totals together.[1][2]
- 5
RaaS leadership can shift quickly — The Gentlemen's rise from a mid-2025 entrant to a leading published-activity position shows how affiliate movement and access inventory can change the operating landscape within months.[1][3]
- 6
Edge access and valid credentials remain briefing priorities — Research into The Gentlemen describes access through unpatched edge devices and purchased credentials, including FortiGate exposure, making edge logs and identity evidence central to early scoping.[3]
- 7
Cross-platform impact should be assumed during scoping — The Gentlemen maintains Windows, Linux, and VMware ESXi capability, so responders should include virtualization and backup infrastructure rather than limiting collection to Windows endpoints.[1][3]
- 8
Pre-encryption behavior remains detectable — ReliaQuest observed LeakNet using ClickFix, a Deno in-memory loader, DLL side-loading, PsExec lateral movement, and S3 staging before ransomware deployment.[4]
- 9
One compromise can create downstream client risk — Check Point documented The Gentlemen using information stolen from a service provider to support a later attack against the provider's client, reinforcing third-party scoping obligations.[3]
- 10
The practical response window begins before encryption — Prioritize edge authentication, credential misuse, lateral administration, data staging, security-control tampering, virtualization, and backup evidence as soon as ransomware is suspected.[3][4]
Activity Signals
- The Gentlemen activity acceleration
- Qilin remained a leading operator
- LeakNet ClickFix/Deno intrusion chain
- Third-party and downstream-client exposure
Initial Access Patterns
- Unpatched edge devices
- VPN and remote-access credentials
- Purchased or stolen credentials
- ClickFix social engineering
- Compromised service-provider information
Target Sectors
- Healthcare
- Professional and business services
- Education
- Manufacturing
- Technology
Business Impact
- Enterprise-wide encryption
- Data theft and public-release pressure
- Virtualization and backup disruption
- Regulatory and contractual exposure
- Downstream client compromise
Defensive Priorities
- Patch and monitor edge appliances
- Enforce phishing-resistant MFA
- Isolate and make backups immutable
- Monitor privileged administration and lateral movement
- Preserve identity, cloud, virtualization, and exfiltration evidence
Connected CARDS
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Why Used / Claim Treatment | Source |
|---|---|---|---|---|
| 1 | Check Point Researchprimary research | 2026-07 | Ransomware data-leak-site disclosures; published attacks are not independently confirmed incidents. | A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ |
| 2 | BlackFogecosystem monitor | 2026-07-02 | Public disclosures and actor claims are retained separately; disputed attribution remains qualified. | The State of Ransomware: June 2026 https://www.blackfog.com/the-state-of-ransomware-june-2026/ |
| 3 | Check Point Researchprimary research | 2026-05 | Tradecraft is based on vendor analysis of leaked internal material; victim totals remain actor-published claims. | When the Ransomware Gang Gets Hacked: The Gentlemen https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ |
| 4 | ReliaQuest Threat Researchincident response | 2026-03-17 | Observed intrusion-chain behavior across confirmed LeakNet incidents; not a universal playbook. | Casting a Wider Net: ClickFix, Deno, and LeakNet's Scaling Threat https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat/ |
