IntelliOS Threat Intel Operating System
← Activity Cards

Ransomware Activity Card

Ransomware Activity — June 2026

June 2026 ransomware reporting showed elevated public activity, rapid movement among leading RaaS brands, continued pressure on healthcare, services, and education, and multiple access paths that reward early identity, edge, and pre-encryption detection.

Published · v4June 1–30, 20264 retained sources

17%[1]

Leading published share

The Gentlemen in Check Point's June data-leak-site dataset

102[2]

Publicly disclosed attacks

BlackFog June dataset across 21 countries

31[2]

Groups represented

BlackFog June public-disclosure and claim tracking

Healthcare[2]

Top BlackFog sector

30 incidents in BlackFog's June dataset

Top 10 Briefing Points

  1. 1

    The Gentlemen moved to the top of Check Point's June rankingCheck Point attributed 17% of published attacks in its June dataset to The Gentlemen, ahead of Qilin at 11%; these are data-leak-site disclosures, not confirmed incident totals.[1]

  2. 2

    Publicly visible ransomware activity increasedBlackFog counted 102 publicly disclosed attacks across 21 countries and 31 groups in June, while explicitly separating public disclosure from unverified actor attribution.[2]

  3. 3

    Healthcare, services, and education remained prominentBlackFog's June dataset recorded healthcare as its leading sector, followed by services and education, supporting continued scoping attention for sensitive-data and operational-disruption exposure.[2]

  4. 4

    Dataset definitions cannot be combined into one victim countCheck Point reports published attacks, while BlackFog mixes public disclosures and qualified claims. Use each source for direction within its own methodology rather than adding the totals together.[1][2]

  5. 5

    RaaS leadership can shift quicklyThe Gentlemen's rise from a mid-2025 entrant to a leading published-activity position shows how affiliate movement and access inventory can change the operating landscape within months.[1][3]

  6. 6

    Edge access and valid credentials remain briefing prioritiesResearch into The Gentlemen describes access through unpatched edge devices and purchased credentials, including FortiGate exposure, making edge logs and identity evidence central to early scoping.[3]

  7. 7

    Cross-platform impact should be assumed during scopingThe Gentlemen maintains Windows, Linux, and VMware ESXi capability, so responders should include virtualization and backup infrastructure rather than limiting collection to Windows endpoints.[1][3]

  8. 8

    Pre-encryption behavior remains detectableReliaQuest observed LeakNet using ClickFix, a Deno in-memory loader, DLL side-loading, PsExec lateral movement, and S3 staging before ransomware deployment.[4]

  9. 9

    One compromise can create downstream client riskCheck Point documented The Gentlemen using information stolen from a service provider to support a later attack against the provider's client, reinforcing third-party scoping obligations.[3]

  10. 10

    The practical response window begins before encryptionPrioritize edge authentication, credential misuse, lateral administration, data staging, security-control tampering, virtualization, and backup evidence as soon as ransomware is suspected.[3][4]

Activity Signals

  • The Gentlemen activity acceleration
  • Qilin remained a leading operator
  • LeakNet ClickFix/Deno intrusion chain
  • Third-party and downstream-client exposure

Initial Access Patterns

  • Unpatched edge devices
  • VPN and remote-access credentials
  • Purchased or stolen credentials
  • ClickFix social engineering
  • Compromised service-provider information

Target Sectors

  • Healthcare
  • Professional and business services
  • Education
  • Manufacturing
  • Technology

Business Impact

  • Enterprise-wide encryption
  • Data theft and public-release pressure
  • Virtualization and backup disruption
  • Regulatory and contractual exposure
  • Downstream client compromise

Defensive Priorities

  • Patch and monitor edge appliances
  • Enforce phishing-resistant MFA
  • Isolate and make backups immutable
  • Monitor privileged administration and lateral movement
  • Preserve identity, cloud, virtualization, and exfiltration evidence

Connected CARDS

Citations

Retained Sources and Claim Treatment

#PublisherPublishedWhy Used / Claim TreatmentSource
1Check Point Researchprimary research2026-07Ransomware data-leak-site disclosures; published attacks are not independently confirmed incidents.A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/

2BlackFogecosystem monitor2026-07-02Public disclosures and actor claims are retained separately; disputed attribution remains qualified.The State of Ransomware: June 2026

https://www.blackfog.com/the-state-of-ransomware-june-2026/

3Check Point Researchprimary research2026-05Tradecraft is based on vendor analysis of leaked internal material; victim totals remain actor-published claims.When the Ransomware Gang Gets Hacked: The Gentlemen

https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/

4ReliaQuest Threat Researchincident response2026-03-17Observed intrusion-chain behavior across confirmed LeakNet incidents; not a universal playbook.Casting a Wider Net: ClickFix, Deno, and LeakNet's Scaling Threat

https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat/