IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Global Ransomware Watch

Global Ransomware Landscape Rolling Intelligence Card

This global rolling 90-day landscape card synthesizes ransomware research, public-disclosure datasets, operator activity, access methods, AI-enabled social engineering, identity exposure, cross-platform impact, and recovery implications across regions and organization sizes. It is the strategic ecosystem companion to the U.S. SMB card—not a second U.S. victim tracker. Source methodologies remain separate, its figures must not be added to the U.S. SMB claim population, and evidence leaves the card when it ages beyond the active window.

Coverage
Apr 30–Jul 28, 2026
Record Version
v10
Updated
Jul 28, 2026
AI Monitor
Weekly · Mon midday ET
Evidence
13 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowWeekly on Monday at midday ET

17%[1]

Leading published share

The Gentlemen in Check Point's June data-leak-site datasetEvidence dated Jul 9, 2026

102[2]

Publicly disclosed attacks

BlackFog June dataset across 21 countriesEvidence dated Jul 2, 2026

31[2]

Groups represented

BlackFog June public-disclosure and claim trackingEvidence dated Jul 2, 2026

Healthcare[2]

Top BlackFog sector

30 incidents in BlackFog's June datasetEvidence dated Jul 2, 2026

7,551[11]

Annual disclosed victims

Black Kite April 2025-March 2026 public-disclosure dataset; not a 90-day incident countEvidence dated Jul 27, 2026

146[11]

Active groups by June

Black Kite active ransomware-group count after its reporting-period cutoffEvidence dated Jul 27, 2026

79%[12]

Identity-led attacks

Sophos survey share of ransomware attacks beginning with an identity-based approachEvidence dated Jul 22, 2026

65%[13]

AI made attack more effective

Proofpoint survey share of affected organizations reporting significant or somewhat increased attacker effectivenessEvidence dated Jul 21, 2026

Published ransomware activity share

Share of Check Point’s June data-leak-site dataset. These are public extortion listings, not independently confirmed intrusions.[1]Evidence dated Jul 9, 2026

The Gentlemen17%
Qilin11%
LockBit7%
Other listed groups65%

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

Current retained evidence places initial access across four separable lanes: edge and remote-access exposure, people/email interaction, valid identity abuse, and trusted provider or SaaS integration compromise. The sources do not assign one vector to every leak-site post or survey response; use the vectors to drive exposure review and hunting.

1

People-led access

Malicious email, phishing, and malicious links[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

Survey-backed current control priority; not assigned to every named victim

How it starts
A user interacts with a convincing email, link, impersonation, or AI-enhanced lure.
Attacker outcome
Credential theft, remote-session creation, data access, or first-stage execution before ransomware or extortion pressure.
What to monitor
URL clicks, phishing reports, suspicious downloads, new remote tools, mail-rule changes, impossible travel, and rapid access to sensitive data.
2

Identity-led access

Compromised credentials and MFA coverage gaps[7][10][12][13]First cited source Jul 17, 2026 · Latest cited source Jul 23, 2026

Survey and incident-response priority

How it starts
Credentials, sessions, tokens, or under-protected accounts provide valid access to SaaS, VPN, firewall admin, or legacy applications.
Attacker outcome
Trusted login, privilege escalation, lateral movement, data theft, and faster time to impact.
What to monitor
Dormant-account use, MFA changes, new tokens, device-code flows, service-account anomalies, and session revocation failures.
3

Externally reachable control plane

Internet-facing edge and remote-access exposure[3][9][11][12]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Research-backed and case-backed exposure path

How it starts
A firewall, VPN, gateway, remote-support tool, or related edge system is exploited, misconfigured, deprecated, or accessed with exposed credentials.
Attacker outcome
Network foothold, credential theft, provider access, ransomware staging, or customer-environment reach.
What to monitor
KEV and critical exposure, unknown admin logins, appliance-originated connections, configuration theft, credential reuse, and post-remediation exposure scans.
4

Third-party and connected-app access

Trusted provider, SaaS, OAuth, and API integration abuse[3][7][10][11]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Source-backed campaign and operating-context priority

How it starts
Stolen provider information, OAuth tokens, API keys, or connected-app credentials are reused against customer or SaaS environments.
Attacker outcome
Data theft or extortion can bypass several traditional network stages by entering through a trusted integration.
What to monitor
Connected-app changes, unusual API activity, customer data access, provider notices, Salesforce or SharePoint bulk access, and cross-tenant anomalies.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, boards, CISOs, CIOs, security and IT leaders, incident-response owners, business-continuity leaders, and cyber-insurance stakeholders who need a decision-ready ransomware view.
Audience fieldOrganization profileAssessmentA global, cross-industry ecosystem view for enterprises, managed service providers, healthcare, education, manufacturing, professional services, and organizations dependent on virtualization or shared service providers. U.S. SMB-specific claim concentration and firmographic limits belong in the companion U.S. SMB card.
Audience fieldDecision perspectiveAssessmentUse the brief to decide which edge systems and identities require immediate review, when suspicious activity becomes an incident, whether recovery systems can withstand attack, and which third-party relationships expand the investigation.
Audience fieldEvidence postureAssessmentLeak-site listings and actor claims are treated as directional intelligence. Local logs, forensic evidence, victim disclosure, or authoritative incident reporting are required before asserting that a specific organization was compromised.

Chronology and Decision Milestones

Timeline of Notable Activity

Operator activity, access and victim patterns, data-collection periods, and publication dates are separated so a later trend report is not mistaken for the date an intrusion occurred.

  1. Akira intrusion · initial access

    A poisoned software search turned an MSP workflow into ransomware access

    At-Bay’s case study traces an Akira intrusion to an MSP installing a trojanized AI tool found through a poisoned search result. The case is a concrete warning that administrator software sourcing, execution control, and MSP trust can bypass an otherwise ordinary perimeter.[4]

  2. Akira intrusion · recovery impact

    Akira encrypted 60 servers after destroying reachable backups

    The same case records destructive impact across 60 servers, unavailable backups, a $10 million demand, containment in roughly two hours, and a $1.5 million settlement. Those are one organization’s outcomes—not a benchmark—but they show why backup isolation and rapid containment authority materially change leverage.[4]

  3. The Gentlemen · operating model

    The Gentlemen combined access brokerage with multi-platform ransomware

    Check Point’s analysis describes affiliate recruitment, a stock of previously exploited FortiGate access, and Windows, Linux, and VMware ESXi encryption capability. The operation can therefore sell entry, support affiliates, steal data, and attack recovery infrastructure as one business model.[3]

  4. The Gentlemen · third-party propagation

    Stolen provider information supported a later attack on the provider’s client

    Check Point documented a downstream-client scenario in the leaked material. Shared administration, support tooling, customer data, and provider credentials must be scoped together instead of treating the service provider and customer as unrelated incidents.[3]

  5. The Gentlemen · scale and affiliate velocity

    The Gentlemen’s public disclosures accelerated through Q1 and early Q2

    LevelBlue counted 352 public claims through May 10 and found large batch-publication days in January, February, and April, consistent with multiple affiliates or coordinated disclosure. The figures measure public claims, while the velocity signals a scalable operation rather than a single crew working one victim at a time.[5]

  6. The Gentlemen · pre-encryption behavior

    Remote access, reconnaissance, defense tampering, and data theft preceded domain-wide deployment

    LevelBlue maps exposed services and valid accounts to AnyDesk or SystemBC persistence, network and Active Directory discovery, WinSCP exfiltration, security-tool impairment, Group Policy or NETLOGON staging, and Windows, Linux, NAS, BSD, and ESXi impact. That sequence gives defenders observable decisions before encryption.[5]

  7. Q2 incident response · extortion model

    More intrusions stopped short of ransomware—or monetized through data theft instead

    LevelBlue’s Q2 case population placed non-ransomware network intrusion second at 20% and attributed part of that position to earlier defensive interruption and extortion without encryption. Ransomware readiness therefore has to cover data theft and pressure even when no encryptor runs.[7]

  8. Q2 incident response · trusted integration abuse

    Stolen API credentials let the Klue compromise jump directly into connected Salesforce environments

    LevelBlue reports that compromised integration credentials enabled automated access to Salesforce-connected services and affected hundreds of organizations. OAuth grants, API keys, service accounts, and connected-app activity are now part of ransomware and extortion scoping because a trusted integration can skip several traditional intrusion stages.[7]

  9. Q2 incident response · edge exploitation

    Eight of LevelBlue’s nine most-observed Q2 CVEs affected perimeter devices

    The Q2 list concentrated on Ivanti, Fortinet, and Cisco edge or VPN technologies, many with authentication bypass or unauthenticated code execution. Emergency patching must be paired with management-interface restriction, credential review, and historical exploitation hunting.[7]

  10. Q2 incident response · attack speed

    Long-dwell cases fell while 3–10 day intrusions nearly doubled

    LevelBlue reports that 31-plus-day cases fell from 38% to 23%, while cases resolved within 3–10 days rose from 23% to 42%. Faster detection contributed, but the source also observed attackers compressing the path to their objective; weekly review cycles can now be slower than the intrusion.[7]

  11. June crimeware · actor mix

    Akira led Arete’s June observations, but 17 groups kept the operating field distributed

    Arete kept Akira, Qilin, and INC Ransom among the most active groups across a 17-group June population. The practical response is a behavior-led playbook for access, identity abuse, defense evasion, exfiltration, and recovery—not a plan built around one ransomware brand.[6]

  12. June crimeware · defense evasion

    Akira and DragonForce used vulnerable drivers to attack endpoint defenses

    Arete observed bring-your-own-vulnerable-driver activity and described GentleKiller as a framework aimed at multiple security products. Unexpected driver loading, security-service changes, and tamper attempts should trigger rapid containment before lateral deployment.[6]

  13. June victimology · public disclosures

    Healthcare led BlackFog’s 102 disclosed attacks across 21 countries

    BlackFog’s separate June dataset included 31 groups and placed healthcare ahead of services and education. It is a public-disclosure view, not a number to add to leak-site totals, but it identifies sectors where downtime and sensitive-data pressure remained visible.[2]

  14. June extortion market · operator ranking

    The Gentlemen displaced Qilin at the top of Check Point’s June leak-site dataset

    Across 646 ransomware data-leak-site posts, The Gentlemen represented 17%, Qilin 11%, and LockBit 7%; North America accounted for 44% of the dataset. These are public extortion listings, but the leadership change shows how quickly affiliate volume can reorganize.[1]

  15. The Gentlemen · cross-vendor confirmation

    Unit 42 documented a durable RaaS operation under its own Scorpius taxonomy

    Unit 42 connected The Gentlemen to RaaS behavior and related Scorpius activity clusters. The operational value is the repeated access, evasion, exfiltration, and encryption behavior; the original Unit 42 labels remain visible rather than being flattened into one universal attribution.[8]

  16. FortiBleed · access-to-ransomware path

    Harvested Fortinet credentials were linked to INC and Lynx operations

    Arete reported evidence connecting the credential-harvesting campaign to INC and Lynx ransomware activity. Organizations with affected FortiGate history should rotate exposed credentials, review prior administrative sessions, and hunt for follow-on access even after patching.[9]

  17. Helix · identity-led extortion

    Helix used Microsoft 365 identity and SharePoint data instead of requiring endpoint encryption

    Arete describes vishing, device-code phishing, MFA abuse, trusted-person impersonation, SharePoint discovery, and data theft. The campaign makes cloud sessions, OAuth activity, device codes, and bulk SaaS access part of the ransomware and extortion perimeter.[10]

  18. Helix · attribution discipline

    Operational overlap did not justify collapsing Helix into ShinyHunters or BlackFile

    Arete noted similarities and possible shared ecosystems while leaving the relationship unresolved. Defenders can correlate identity, SaaS, and extortion behaviors without claiming a single actor identity that the evidence does not establish.[10]

  19. AI-era ransomware survey

    Proofpoint made malicious links and AI-assisted trust abuse a ransomware entry concern

    Proofpoint's current survey reports malicious links as the leading entry vector, 65% of affected organizations saying AI made the attack more effective, 54% paying a ransom, 37% of payers facing a second demand, and 65% experiencing data theft. These are survey findings, not incident-response counts, but they materially shift monitoring toward people, identities, and trusted communications.[13]

  20. Ransomware survey · identity and economics

    Sophos reported identity-led entry, higher encryption incidence, and a widening small-organization outcome gap

    Sophos reports malicious email and phishing together at half of surveyed root causes, identity-based approaches in 79% of attacks, 56% of attacks encrypting data, average recovery cost at $1.7 million, and only 34% of 100-250 employee organizations stopping attacks before encryption or extortion. The source is a survey cohort, not a leak-site dataset.[12]

  21. Annual public-disclosure baseline

    Black Kite added annual victim growth, active-group fragmentation, and post-incident exposure evidence

    Black Kite tracked 7,551 publicly disclosed victims in its April 2025-March 2026 reporting period, 146 active groups by June 2026, and continued critical-vulnerability, KEV, and stealer-log exposure in post-disclosure posture checks. The annual findings strengthen the card's fragmentation and exposure-management conclusions without changing June leak-site or U.S. SMB tracker totals.[11]

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  • The leading name changed quickly in the global June dataset: Check Point’s worldwide June leak-site dataset placed The Gentlemen first with 17% of published attacks, ahead of Qilin at 11%. The U.S. SMB card separately places Qilin first across a 90-day ransomware.live population. Both can be true because the geography, period, and collection methods differ; neither measure is a verified incident count.[1]Evidence dated Jul 9, 2026

  • The access problem starts at the edge: Check Point describes The Gentlemen using unpatched edge devices and purchased or stolen credentials, including access tied to exposed FortiGate systems. If your organization operates internet-facing VPN, firewall, or remote-access infrastructure, patch status alone is not enough; review historical logins and credential use.[3]Evidence dated May 13, 2026

  • Recovery infrastructure is part of the target: The Gentlemen supports Windows, Linux, and VMware ESXi encryption. Scope virtualization management, hypervisors, backup consoles, identity services, and privileged administration at the start of an investigation rather than after endpoint encryption is discovered.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

  • One provider compromise can reach a customer: Check Point documented stolen service-provider information being used to support a later attack against the provider’s client. MSPs and customers should treat shared credentials, support tooling, tenant access, and trust relationships as part of the same incident boundary.[3]Evidence dated May 13, 2026

  • Victim counts require discipline: Check Point and BlackFog collect different mixtures of leak-site posts, public disclosures, and qualified claims. Their figures describe momentum within each dataset and should not be combined into a larger headline number.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026

  • People and identity are now first-order ransomware controls: Sophos found malicious email plus phishing at half of surveyed ransomware root causes and identity-based approaches at 79% of attacks. Proofpoint separately found malicious links leading its surveyed entry vectors and AI making many attacks more effective. Ransomware readiness now has to cover email, user interaction, identity, MFA coverage gaps, and trusted communications before malware appears.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

  • Recovery does not equal exposure closure: Black Kite’s current-state rescan of disclosed victims found critical vulnerabilities and KEV exposure still visible after incidents. Treat post-incident closure as an exposure-management program: verify patched edge systems, credential rotation, stealer-log exposure, and third-party attack-surface cleanup after operations resume.[11]Evidence dated Jul 27, 2026

  • Executive decision: Require evidence that internet-facing access paths are owned and reviewed, privileged credentials are protected, email and malicious-link controls are measured, ESXi and backups are isolated, and responders can investigate identity, cloud, virtualization, staging, and third-party activity before attackers reach encryption.[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

Ransomware risk in the current window is defined less by one stable leader than by how quickly affiliates, access inventory, and extortion brands can reorganize. Check Point’s worldwide June data placed The Gentlemen at 17% of published attacks, Qilin at 11%, and LockBit at 7%. Those percentages come from ransomware data-leak sites, so they indicate public extortion activity rather than independently confirmed compromise totals. The result does not conflict with Qilin leading the companion U.S. SMB card’s separate 90-day U.S. dataset.[1]Evidence dated Jul 9, 2026

The Gentlemen matters because the operation combines a ransomware-as-a-service model with access brokerage. Check Point describes a self-service stock of previously exploited FortiGate devices, affiliate recruitment, and Windows, Linux, and VMware ESXi lockers. For a company, that means one neglected edge appliance can become the bridge from internet exposure to identity abuse, lateral movement, data theft, and attacks on recovery infrastructure.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

BlackFog provides a different but complementary view: 102 publicly disclosed attacks across 21 countries and 31 groups, with healthcare leading its June sector count. The figures should not be added to Check Point’s totals because the source methods differ. The useful conclusion is directional—ransomware remains distributed across many operators and sectors, even while a few brands gain visible momentum.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026

Regional data should shape preparation without creating false comfort. Check Point placed North America at 44% of reported ransomware incidents, APAC at 23%, and Europe at 22%. A U.S. organization should therefore prioritize readiness, but location alone cannot rule risk in or out; affiliates often select victims based on available access rather than a fixed geographic plan.[1]Evidence dated Jul 9, 2026

The operational lesson is to hunt before encryption. Edge authentication anomalies, new privileged sessions, credential reuse, remote administration, security-tool interference, large data staging, hypervisor access, and backup changes are more useful early-warning signals than waiting for a ransom note. Service providers and their customers should also review shared administration paths because stolen provider information can create downstream risk.[3]Evidence dated May 13, 2026

The newest annual and survey evidence broadens the initial-access story. Sophos reports malicious email plus phishing as half of surveyed ransomware root causes and identity-based approaches in 79% of attacks; Proofpoint reports malicious links as the leading surveyed entry vector and says AI made attacks more effective for many affected organizations. These survey results should not be mixed with leak-site or IR counts, but they materially change control prioritization toward people, identities, MFA coverage, malicious-link handling, and trusted-communication verification.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

Black Kite adds a post-incident exposure warning: in its April 2025-March 2026 public-disclosure cohort, the active-group count reached 146 by June 2026, Qilin scaled sharply in that dataset, and many disclosed victims still showed critical vulnerability or KEV exposure when rescanned. The practical lesson is that closing the ticket after restoration is not enough; organizations must prove the exploitable conditions, credentials, third-party paths, and stealer-log exposure that attackers can still see are closed.[11]Evidence dated Jul 27, 2026

Executives should ask for proof of resilience, not a list of security products: an owned inventory of exposed access systems, phishing-resistant authentication for privileged roles, measured email and malicious-link defenses, segmented and recoverable identity and virtualization services, immutable backups with tested restore times, and an incident plan that includes legal, communications, insurer, provider, and customer decisions before business operations stop.[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    The Gentlemen moved to the top of Check Point's June rankingCheck Point attributed 17% of published attacks in its June dataset to The Gentlemen, ahead of Qilin at 11%; these are data-leak-site disclosures, not confirmed incident totals.[1]Evidence dated Jul 9, 2026

  2. 2

    Publicly visible ransomware activity increasedBlackFog counted 102 publicly disclosed attacks across 21 countries and 31 groups in June, while explicitly separating public disclosure from unverified actor attribution.[2]Evidence dated Jul 2, 2026

  3. 3

    Healthcare, services, and education remained prominentBlackFog's June dataset recorded healthcare as its leading sector, followed by services and education, supporting continued scoping attention for sensitive-data and operational-disruption exposure.[2]Evidence dated Jul 2, 2026

  4. 4

    Dataset definitions cannot be combined into one victim countCheck Point reports published attacks, while BlackFog mixes public disclosures and qualified claims. Use each source for direction within its own methodology rather than adding the totals together.[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026

  5. 5

    RaaS leadership can shift quicklyThe Gentlemen's rise from a mid-2025 entrant to a leading published-activity position shows how affiliate movement and access inventory can change the operating landscape within months.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

  6. 6

    Edge access and valid credentials remain briefing prioritiesResearch into The Gentlemen describes access through unpatched edge devices and purchased credentials, including FortiGate exposure, making edge logs and identity evidence central to early scoping.[3]Evidence dated May 13, 2026

  7. 7

    Cross-platform impact should be assumed during scopingThe Gentlemen maintains Windows, Linux, and VMware ESXi capability, so responders should include virtualization and backup infrastructure rather than limiting collection to Windows endpoints.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

  8. 8

    Regional concentration should shape readiness without narrowing scopeCheck Point's retained dataset placed North America at 44% of reported ransomware incidents, followed by APAC at 23% and Europe at 22%. Use the distribution to inform readiness and third-party monitoring, not to rule out organizations in other regions.[1]Evidence dated Jul 9, 2026

  9. 9

    The ransomware investigation must extend beyond endpointsThe Gentlemen’s Windows, Linux, and VMware ESXi capability means responders should collect from identity, edge devices, hypervisors, backup systems, privileged administration, and data-staging locations before recovery work destroys evidence.[3]Evidence dated May 13, 2026

  10. 10

    One compromise can create downstream client riskCheck Point documented The Gentlemen using information stolen from a service provider to support a later attack against the provider's client, reinforcing third-party scoping obligations.[3]Evidence dated May 13, 2026

  11. 11

    Annual disclosures show a larger and more fragmented marketBlack Kite tracked 7,551 disclosed victims in its April 2025-March 2026 period and 146 active groups by June 2026. Those are annual public-disclosure and posture metrics, not current 90-day confirmed incident counts.[11]Evidence dated Jul 27, 2026

  12. 12

    Identity-led entry is now a ransomware control baselineSophos reports identity-based approaches in 79% of surveyed ransomware attacks, while malicious email and phishing together account for half of reported root causes. MFA must cover VPNs, firewall admin consoles, legacy apps, SaaS, and privileged roles, not only common user accounts.[12]Evidence dated Jul 22, 2026

  13. 13

    AI and malicious links raise the user-interaction riskProofpoint's current survey placed malicious links first among entry vectors and reported that AI made attacks more effective for many affected organizations. User training alone is too weak unless paired with URL isolation, reporting, identity telemetry, and rapid session revocation.[13]Evidence dated Jul 21, 2026

  14. 14

    Post-incident posture remains a live attack surfaceBlack Kite's rescan findings mean incident closure should include external exposure validation, KEV and critical vulnerability remediation, credential and stealer-log checks, and third-party risk review after business operations resume.[11]Evidence dated Jul 27, 2026

Company Exposure and Exploitability

Exploitable Technologies for Companies

Specific products and control interfaces elevated by the retained government record. Each row explains the exploitable condition, which companies should care, the business consequence, and the evidence a defender should monitor.

Technology

Internet-facing firewalls, VPNs, and edge appliances[3][9][11][12]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Exploitable condition

Unpatched exposure, deprecated access modes, vulnerable configurations, or stolen credentials provide a foothold or privileged network position.

Which companies should care

Edge devices are high-leverage access paths for ransomware affiliates and appear across Check Point, Sophos, Arete, and Black Kite evidence.

Business risk

Credential theft, lateral movement, data theft, seven-figure demands, and persistent exposure after apparent recovery.

What to monitor

Unsupported or exposed devices, admin login anomalies, stale sessions, VPN policy changes, credential reuse, KEV status, and external posture after remediation.

IntelliOS coverageNo dedicated product yet
Technology

Email, malicious links, and collaboration identity[7][10][12][13]First cited source Jul 17, 2026 · Latest cited source Jul 23, 2026

Exploitable condition

Users interact with convincing lures, malicious links, impersonation, device-code or OAuth workflows, or compromised trusted communications.

Which companies should care

Sophos and Proofpoint make people and identity a first-order ransomware surface; Arete's Helix and LevelBlue's Klue/Salesforce context show SaaS and identity abuse in extortion workflows.

Business risk

Account takeover, data theft, unauthorized SaaS access, repeat extortion, and delayed detection before malware is visible.

What to monitor

URL clicks, new tokens, MFA changes, device-code flows, OAuth grants, mail-forwarding rules, impossible travel, and bulk SharePoint or Salesforce access.

IntelliOS coverageNo dedicated product yet
Technology

VMware ESXi, backup platforms, and recovery identity[1][3][4]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Exploitable condition

Attackers reach hypervisors, backup consoles, repositories, or recovery credentials from production identity or shared administration paths.

Which companies should care

The Gentlemen and At-Bay Akira casework show why virtualization and backups belong in the first incident scope, not the recovery afterthought.

Business risk

Enterprise-wide encryption, unrecoverable backups, extended downtime, larger ransom pressure, and loss of evidence during restoration.

What to monitor

New hypervisor admin access, SSH enablement, mass VM shutdown, backup deletion, retention changes, repository access, and restore-test failures.

IntelliOS coverageNo dedicated product yet
Technology

Third-party, MSP, and SaaS integration trust[3][7][10][11]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Exploitable condition

Provider data, OAuth tokens, API keys, shared administration, or customer information are stolen and reused downstream.

Which companies should care

Check Point documents provider-to-client reuse, while LevelBlue and Arete describe trusted integration compromise and SaaS extortion paths.

Business risk

One compromise can become a multi-tenant or customer-impact incident with notification, contractual, and recovery complexity.

What to monitor

Provider account changes, cross-tenant anomalies, connected-app access, API-key use, customer-specific data access, and supplier compromise notices.

IntelliOS coverage

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationOrganizations named on ransomware leak sites[1]Evidence dated Jul 9, 2026SectorsBusiness services, consumer goods and services, industrial manufacturing, government, and other sectorsGeographyNorth America 44%; APAC 23%; Europe 22% in Check Point’s June datasetConfirmation statusActor-published victim listings; not independently confirmed incidentsHow companies should use itUse for sector and regional prioritization, external-attack-surface review, and third-party monitoring—not as a verified breach count.
Victim / exposure populationPublicly disclosed ransomware victims[2]Evidence dated Jul 2, 2026SectorsHealthcare led BlackFog’s June sector count, followed by services and educationGeography102 disclosures across 21 countriesConfirmation statusPublic disclosure and qualified claim tracking within BlackFog’s methodologyHow companies should use itHealthcare, education, and service organizations should validate downtime, sensitive-data, and recovery assumptions against the sector pattern.
Victim / exposure populationAnnual public-disclosure and posture population[11]Evidence dated Jul 27, 2026SectorsManufacturing led Black Kite's annual disclosure cohort, followed by professional, scientific, and technical services; construction rose to thirdGeographyU.S. remained the largest single country, while Europe grew faster in Black Kite's reporting-period comparisonConfirmation statusPublicly disclosed victims plus Black Kite posture observations; not a confirmed incident census or the same population as Check Point, BlackFog, or ransomware.liveHow companies should use itUse the annual view to validate sector, geography, revenue-band, and post-incident exposure assumptions before setting third-party and attack-surface monitoring thresholds.
Victim / exposure populationOrganizations hit by ransomware in Sophos and Proofpoint surveys[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026SectorsCross-industry survey respondents rather than named victimsGeographySophos global survey and Proofpoint 12-market surveyConfirmation statusSelf-reported ransomware experience from security and IT respondentsHow companies should use itUse the results to stress-test people, identity, email, malicious-link, and payment-decision controls; do not convert them into incident prevalence.
Victim / exposure populationOrganizations exposed through edge-device access[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026SectorsCross-industry; especially organizations with internet-facing FortiGate or remote-access infrastructureGeographyDevice-driven rather than limited to one countryConfirmation statusVendor analysis of Gentlemen access inventory and leaked internal materialHow companies should use itInventory edge systems, review historical administrative access, rotate exposed credentials, and investigate prior reachability even after patching.
Victim / exposure populationService providers and downstream customers[3]Evidence dated May 13, 2026SectorsMSPs, IT service firms, and customers reached through shared administration or stolen provider informationGeographyNot bounded to one region in retained reportingConfirmation statusDocumented downstream-client scenario in Check Point researchHow companies should use itScope provider and customer environments together when shared accounts, remote tooling, or customer data may have been exposed.

Distinct Operational Records

Ransomware Threat Actors & Operations

The Gentlemen rapid-scale RaaS and access-broker operation

Check Point describes a mid-2025 entrant that recruited affiliates, offered access to previously exploited FortiGate devices, developed Windows/Linux/ESXi capability, and reached the top position in its June leak-site dataset.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Downstream client targeting through stolen provider information

Check Point documented a scenario in which information stolen from a service provider supported a later attack against the provider’s client, making third-party trust a concrete ransomware investigation boundary.[3]Evidence dated May 13, 2026

AI-era people and identity pressure

Proofpoint and Sophos independently make people, malicious links, email, compromised credentials, and MFA coverage gaps current ransomware campaign constraints. The campaign-level implication is not a named actor; it is that ransomware operations increasingly reach objectives through trusted human and identity workflows.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

Post-incident exposure persistence

Black Kite’s annual report pairs disclosures with before-and-after posture signals, showing that incident recovery and exposure closure can diverge. Treat remediation as a continuing attack-surface and third-party-risk campaign rather than a one-time recovery milestone.[11]Evidence dated Jul 27, 2026

Source-Bound Actor Context

Notable Actors & Criminal Ecosystems

The Gentlemen

Fast-growing RaaS operator and initial-access broker; 17% of Check Point’s June published-attack dataset. Retained reporting describes FortiGate access inventory and Windows, Linux, and ESXi encryption capability.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Qilin

Established RaaS operation that represented 11% of Check Point’s June published attacks and remained a major affiliate destination even after losing the top position. Black Kite separately reports Qilin at 1,358 disclosed victims in its April 2025-March 2026 dataset, reinforcing Qilin as a cross-window watch priority without merging the datasets.[1][11]First cited source Jul 9, 2026 · Latest cited source Jul 27, 2026

LockBit

Long-running ransomware brand that rose from 1% to 7% of Check Point’s published-attack dataset between May and June, illustrating how visible activity can rebound quickly.[1]Evidence dated Jul 9, 2026

Malware, Implants, and Intrusion Tooling

Malware Summary

Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.

Malware / toolingThe Gentlemen lockers and GentleKiller[1][3][5][6][8]First cited source May 13, 2026 · Latest cited source Jul 10, 2026Classification and campaignRaaS locker family and EDR-disabling toolingCheck Point, LevelBlue, Arete, and Unit 42 describe The Gentlemen as a fast-scaling operation with Windows, Linux, ESXi, and defense-evasion capability.Capability and potential impactSupports data theft, security-tool impairment, and cross-platform encryption that can extend impact from endpoints into recovery-critical infrastructure.What defenders should monitorDriver loading, EDR tamper events, new ransomware binaries, ESXi access, unusual Group Policy or NETLOGON staging, and leak-site or negotiation changes.
Malware / toolingAkira ransomware[4][6]First cited source May 13, 2026 · Latest cited source Jul 6, 2026Classification and campaignRansomware operation and lockerAt-Bay casework and Arete June observations keep Akira prominent in both case impact and monthly activity.Capability and potential impactCan create server-scale encryption, backup destruction, large demands, and rapid business-continuity pressure.What defenders should monitorBackup deletion, high-volume encryption, anomalous remote administration, BYOVD activity, data staging, and Akira-branded extortion contact.
Malware / toolingINC/Lynx-related ransomware activity[6][9]First cited source Jul 6, 2026 · Latest cited source Jul 14, 2026Classification and campaignRansomware operations and reported code lineageArete links FortiBleed credential exposure to INC and Lynx operations and reports lineage overlap among INC, Lynx, and Sinobi.Capability and potential impactCredential access against edge devices can provide ransomware affiliates with reusable footholds and downstream access paths.What defenders should monitorFortiGate credential exposure, anomalous VPN sessions, INC or Lynx payload indicators, configuration theft, and post-patch credential use.
Malware / toolingHelix extortion tooling and SaaS data-theft workflow[10]Evidence dated Jul 17, 2026Classification and campaignIdentity-led extortion operation without required endpoint encryptionArete describes Helix using vishing, device-code phishing, Microsoft 365 identity abuse, and SharePoint data theft.Capability and potential impactShows how extortion can proceed through cloud sessions and data access even if endpoint ransomware never runs.What defenders should monitorDevice-code authentication, new OAuth grants, bulk SharePoint reads, unusual OneDrive or SharePoint export, vishing reports, and trusted-person impersonation.

Enterprise Exposure

Affected Technologies & Trust Boundaries

Internet-facing edge and remote-access systems

Unpatched appliances and valid credentials can create the initial foothold. Owned-asset inventory, historical authentication review, management-interface restriction, and privileged credential rotation are required when exposure is plausible.[3]Evidence dated May 13, 2026

Virtualization, identity, and backup control planes

Cross-platform ransomware capability means responders must include VMware ESXi, administrative consoles, identity services, backup infrastructure, and recovery credentials in the first collection and containment plan.[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Service-provider trust paths

Shared tooling, support accounts, tenant administration, and customer information can extend one compromise into downstream organizations.[3]Evidence dated May 13, 2026

Email, links, MFA coverage, and identity telemetry

Current survey evidence makes malicious email, phishing, malicious links, compromised credentials, and MFA gaps a ransomware exposure surface. Control reviews should prove coverage across SaaS, VPN, firewall admin, legacy applications, privileged roles, and session revocation.[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

External posture after incident closure

Critical vulnerabilities, KEV exposure, and stealer-log exposure can remain visible after a ransomware disclosure. Incident closure should include post-restoration external attack-surface validation and vendor-risk follow-up.[11]Evidence dated Jul 27, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Actor momentum

The Gentlemen leak-site and affiliate activity[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Why it mattersA fast-growing RaaS and access-broker operation led Check Point’s June published-attack dataset.What to monitorNew victim posts; affiliate recruitment; negotiation or infrastructure changes; updated Windows, Linux, or ESXi capability; new access inventory claims.IntelliOS coverage
2Threat / Category

Established RaaS

Qilin activity and affiliate movement[1][11]First cited source Jul 9, 2026 · Latest cited source Jul 27, 2026

Why it mattersQilin remained second in Check Point’s June dataset and Black Kite separately reports major annual growth for Qilin in its disclosure cohort.What to monitorLeak-site changes; affiliate recruitment; rebrands; shared infrastructure; movement of known affiliates or access brokers; Qilin mentions in edge-exploitation reporting.IntelliOS coverage
3Threat / Category

Initial access

Email, malicious links, and AI-assisted impersonation[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

Why it mattersSophos and Proofpoint make user interaction, malicious links, and AI-enhanced trust abuse current ransomware entry concerns.What to monitorHigh-risk URL clicks, phishing reports, new downloads, suspicious OAuth or device-code flows, impersonation reports, and employee interactions with realistic malicious content.IntelliOS coverage
4Threat / Category

Initial access

Internet-facing edge appliances[3][9][11][12]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

Why it mattersThe Gentlemen research, Arete FortiBleed reporting, Sophos firewall findings, and Black Kite posture data keep firewalls, VPNs, and gateways at the center of ransomware access review.What to monitorUnknown administrative logins; impossible travel; new VPN sessions; management-interface exposure; KEV/critical vulnerabilities; unexplained configuration or account changes.IntelliOS coverage
5Threat / Category

Identity

Stolen credentials and MFA coverage gaps[3][12][13]First cited source May 13, 2026 · Latest cited source Jul 22, 2026

Why it mattersValid access can shorten the path from entry to lateral movement and extortion; MFA must cover the systems attackers actually use.What to monitorPassword spraying; dormant-account use; MFA changes; new tokens or sessions; privilege elevation; service-account misuse; VPN, firewall-admin, SaaS, and legacy-app MFA exceptions.IntelliOS coverage
6Threat / Category

Recovery infrastructure

VMware ESXi and virtualization administration[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Why it mattersCross-platform locker capability places hypervisors and management consoles inside the primary ransomware target set.What to monitorNew root or administrative access; SSH enablement; mass VM shutdown; datastore changes; unfamiliar binaries or scripts.IntelliOS coverage
7Threat / Category

Recovery infrastructure

Backup deletion, policy change, or credential use[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Why it mattersAttackers gain leverage when backups and restoration paths are reachable from production identities.What to monitorRetention changes; repository deletion; new admin grants; failed restore tests; unusual access to backup consoles or secrets.IntelliOS coverage
8Threat / Category

Pre-encryption behavior

Data staging and large outbound transfers[1][2][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

Why it mattersDouble-extortion pressure usually depends on data theft before encryption or public posting.What to monitorArchive creation; unusual cloud or S3 transfers; bulk file access; new compression tools; egress to unapproved destinations.IntelliOS coverage
9Threat / Category

Third-party risk

Service-provider and customer trust paths[3]Evidence dated May 13, 2026

Why it mattersStolen provider information can support a later downstream-client attack.What to monitorShared accounts; remote-management access; cross-tenant anomalies; customer-specific data access; provider compromise notices.IntelliOS coverage
10Threat / Category

Exposure management

Post-incident unresolved vulnerabilities and stealer exposure[11]Evidence dated Jul 27, 2026

Why it mattersBlack Kite's annual posture findings show that restored organizations may still present exploitable conditions to attackers.What to monitorCritical CVSS exposure, KEV exposure, stealer-log hits, open management ports, vendor-risk exceptions, and external posture after incident closure.IntelliOS coverage
11Threat / Category

Victimology

Healthcare, manufacturing, services, education, and middle-market targeting[1][2][11][12]First cited source Jul 2, 2026 · Latest cited source Jul 27, 2026

Why it mattersRetained sources place these sectors or revenue bands prominently in their separate June, annual, and survey datasets.What to monitorSector-specific actor claims; vendor alerts; third-party access changes; outage or extortion reports; regional shifts; revenue-band concentration in disclosure datasets.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Separate claims from confirmed incidents[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026

    Lesson Learned

    Leak-site posts are useful momentum indicators but may be incomplete, duplicated, disputed, or strategically timed.

    Minimum Operating Standard

    Report source-specific counts and require independent evidence before calling an organization a confirmed victim.

  2. 2

    Best Practice

    Treat edge exposure as an investigation trigger[3]Evidence dated May 13, 2026

    Lesson Learned

    Patching closes a current path but does not prove attackers never used the system or its credentials.

    Minimum Operating Standard

    For historically exposed edge systems, review logs and identities, rotate credentials, and escalate unexplained access into incident response.

  3. 3

    Best Practice

    Measure people and identity defenses as ransomware controls[12][13]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026

    Lesson Learned

    Current survey evidence places malicious email, phishing, malicious links, compromised credentials, and MFA coverage gaps at the start of many ransomware stories.

    Minimum Operating Standard

    Track phishing reporting and click outcomes, isolate risky links, enforce phishing-resistant MFA for privileged and remote access, close MFA exceptions on VPN/firewall/SaaS/legacy systems, and rehearse rapid token and session revocation.

  4. 4

    Best Practice

    Protect recovery as a separate security zone[1][3]First cited source May 13, 2026 · Latest cited source Jul 9, 2026

    Lesson Learned

    Windows-only assumptions miss ESXi, backup, identity, and management-plane exposure.

    Minimum Operating Standard

    Segment recovery infrastructure, use separate privileged identities, monitor administrative actions, and test restoration under attack conditions.

  5. 5

    Best Practice

    Hunt before encryption[3]Evidence dated May 13, 2026

    Lesson Learned

    Identity abuse, remote administration, staging, and security-control changes appear earlier than the ransom note.

    Minimum Operating Standard

    Maintain detections and response playbooks for pre-encryption behavior and empower responders to contain before business impact is visible.

  6. 6

    Best Practice

    Scope trusted third parties[3]Evidence dated May 13, 2026

    Lesson Learned

    Provider data and access can create a second victim beyond the initially compromised organization.

    Minimum Operating Standard

    Include MSPs, customers, shared tooling, tenant access, and contractual notification paths in ransomware tabletop exercises.

  7. 7

    Best Practice

    Close exposure after restoration[11]Evidence dated Jul 27, 2026

    Lesson Learned

    Black Kite's posture findings show that recovery and exposure closure can diverge; attackers can still see unresolved critical vulnerabilities, KEVs, and credential exposure after public disclosure.

    Minimum Operating Standard

    Before declaring closure, validate external posture, KEV and critical remediation, credential rotation, stealer-log cleanup, vendor exposure, and proof that the original access path no longer works.

  8. 8

    Best Practice

    Make ransomware a continuity decision[1][2][3][11][12][13]First cited source May 13, 2026 · Latest cited source Jul 27, 2026

    Lesson Learned

    The central question is whether the business can operate and recover while identity, virtualization, email, SaaS, or key vendors are unavailable.

    Minimum Operating Standard

    Set maximum tolerable downtime, recovery priorities, decision authority, communications triggers, payment and nonpayment thresholds, and restoration evidence before an incident.

Automation Transparency

AI Agent Run Status

AgentRansomware Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceWeekly on Monday at midday ET; publish only when retained evidence materially changes the card
Previous run27-Jul-2026 · 12:00 PM ET · Run ACT-RANSOM-20260727-1200
Previous resultPublished v10 after retaining Black Kite, Sophos, and Proofpoint as separate annual or survey datasets; no email or external notification was sent by this local job.
What the previous run found
  • Retained The Gentlemen leadership and access-broker findings
  • Added Black Kite annual disclosure, active-group, and post-incident exposure posture findings
  • Added Sophos identity, email, encryption, recovery-cost, and small-organization outcome findings
  • Added Proofpoint AI-era malicious-link, data-theft, payment, repeat-demand, and user-trust findings
  • Preserved separate leak-site, public-disclosure, incident-response, annual-disclosure, posture, and survey methodologies
  • Official CISA/FBI/DOJ/Europol sources were checked and not promoted to a new global trend claim
  • PETRA report database and structured report events were checked for current-window routing and did not supersede retained primary sources
Next run03-Aug-2026 · midday ET
Sources monitored
  • Check Point Research ransomware reporting
  • BlackFog ransomware reporting
  • Black Kite ransomware reports
  • Sophos State of Ransomware and incident-response research
  • Proofpoint ransomware, AI-era, and human-risk research
  • At-Bay incident-response casework
  • LevelBlue frontline TTP briefings
  • Arete crimeware and ransomware research
  • Unit 42 ransomware research
  • CISA/FBI/DOJ/Europol official ransomware and cybercrime material
  • Ransomware ecosystem and actor source tracker
  • Structured report events
  • PETRA report database
  • Connected IntelliOS actor and campaign records
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyPublish and alert only for a material source-backed change; do not notify for no-change checks or date-only rolling-window movement.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv10Date27-Jul-2026ChangeRetained Black Kite's 2026 Ransomware Report, Sophos State of Ransomware 2026, and Proofpoint's 2026 AI-Era Ransomware Report as distinct annual and survey datasets. Updated Research Framing, BLUF, Executive Summary, metrics, victimology, initial access, exploitable technologies, malware/tooling, monitoring priorities, best practices, AI Agent Status, and source audit while preserving the rule that leak-site claims, disclosures, surveys, posture signals, and U.S. SMB tracker counts are never merged.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv9Date26-Jul-2026ChangeExpanded Timeline of Notable Activity from seven high-level entries to 18 operational developments spanning Akira casework, The Gentlemen affiliate scale and pre-encryption behavior, Q2 identity and supply-chain abuse, edge exploitation, dwell-time compression, BYOVD, public victimology, an edge-credential campaign, and Helix identity-led extortion. Added seven direct sources and kept their case, research, IR, leak-site, and disclosure populations separate.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv8Date26-Jul-2026ChangeRepositioned the product as the global ransomware ecosystem and operations view; corrected the stored coverage period to the full Apr 28–Jul 26 rolling window; explicitly separated worldwide June rankings from the companion U.S. SMB claim population; and removed an out-of-window March source from retained citations.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv7Date24-Jul-2026ChangeAdded the PETRA report database to the governed source audit and weekly monitor. The 90-day query returned no qualifying Apr 26–Jul 24 publication, so PETRA is recorded as checked but not used rather than presented as current-period evidence.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv6Date24-Jul-2026ChangeReplaced the abbreviated four-class Research Framing source summary with a complete Tier 0–Tier 8 audit showing checked, candidate-hit, selected, and not-used counts plus the retained and excluded source names in every tier.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv5Date24-Jul-2026ChangeAdded a source-cited donut chart showing The Gentlemen, Qilin, LockBit, and other listed-group shares in Check Point’s June public extortion dataset; retained the distinction between leak-site listings and independently confirmed intrusions.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv4Date24-Jul-2026ChangeRebuilt Research Framing with explicit source roles, methodology boundaries, and an executive decision standard; moved Timeline of Notable Activity ahead of BLUF; and expanded the timeline from four to seven milestones covering operator intelligence, downstream-provider exposure, leak-site activity, public victimology, pre-encryption decisions, and publication dates.MonitoringWeekly Monday rolling 90-day check and material-change publication
Versionv3Date24-Jul-2026ChangeRebuilt the card to the Government Activity gold standard with shared banner, Research Framing, Persona / Audience, BLUF, Executive Summary, victimology, campaign and actor context, technology trust boundaries, timeline, top-10 monitoring table, best practices, AI Agent status, related IntelliOS products, and source-bound defaults.MonitoringWeekly Monday rolling 90-day check and cumulative publication
Versionv2Date24-Jul-2026ChangeConverted the product to a rolling 90-day window and removed evidence that aged outside the active display period.MonitoringSuperseded by v3
Versionv1Date17-Jul-2026ChangeInitial Ransomware Rolling Intelligence Card publication.MonitoringSuperseded by v3

Citations

Retained Sources and Claim Treatment

Source1PublisherCheck Point ResearchPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentRansomware data-leak-site disclosures; published attacks are not independently confirmed incidents.SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/

Source2PublisherBlackFogPublished2026-07-02Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentPublic disclosures and actor claims are retained separately; disputed attribution remains qualified.SourceThe State of Ransomware: June 2026

https://www.blackfog.com/the-state-of-ransomware-june-2026/

Source3PublisherCheck Point ResearchPublished2026-05-13Publication / evidenceSource indexprimary researchWhy used / claim treatmentTradecraft is based on vendor analysis of leaked internal material; victim totals remain actor-published claims.SourceWhen the Ransomware Gang Gets Hacked: The Gentlemen

https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/

Source4PublisherAt-BayPublished2026-05-13Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party case study of one Akira incident. The server count, demand, negotiated amount, and response timing are case-specific—not landscape prevalence or expected outcomes.SourceInside an Akira Ransomware Attack: 60 Servers, Destroyed Backups, and an 85% Negotiated Reduction

https://www.at-bay.com/case-studies/akira-ransomware-attack-case-study/

Source5PublisherLevelBlue SpiderLabsPublished2026-05-18Publication / evidenceSource indexprimary researchWhy used / claim treatmentLevelBlue separates observed and public operational evidence from an unverified underground offer of alleged Gentlemen-related data. Leak-site counts and underground material are not confirmed victim incidents.SourceA Closer Look at The Gentlemen's Alleged Leak

https://www.levelblue.com/blogs/spiderlabs-blog/a-closer-look-at-the-gentlemens-alleged-leak

Source6PublisherAretePublished2026-07-06Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete incident-response observations. Actor mix, tooling, and access findings remain bounded to Arete's evidence and are not a universal incident census.SourceRansomware Trends & Data Insights: June 2026

https://areteir.com/resources/ransomware-trends-data-insights-june-2026

Source7PublisherLevelBluePublished2026-07-23Publication / evidenceSource indexincident responseWhy used / claim treatmentFrontline Q2 incident-response findings across LevelBlue's integrated teams. Percentages describe the stated case population; they are not a global ransomware or victim census.SourceLevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

https://www.levelblue.com/blogs/spiderlabs-blog/ttp-briefing-q2-2026

Source8PublisherPalo Alto Networks Unit 42Published2026-07-10Publication / evidenceSource indexprimary researchWhy used / claim treatmentUnit 42 ransomware-operation analysis. Its Scorpius cluster names and attribution boundaries are preserved rather than silently merged with another vendor's actor identity.SourceNo Manners Here: The Ruthless Rise of The Gentlemen Ransomware

https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/

Source9PublisherAretePublished2026-07-14Publication / evidenceSource indexprimary researchWhy used / claim treatmentArete synthesis of reported campaign evidence. Credential exposure and reported actor links do not prove that every exposed device was compromised or used for ransomware.SourceFortiBleed Campaign Linked to INC and Lynx Ransomware Operations

https://areteir.com/resources/fortibleed-campaign-linked-to-inc-and-lynx-ransomware-operations

Source10PublisherAretePublished2026-07-17Publication / evidenceSource indexprimary researchWhy used / claim treatmentSource-qualified analysis of a newly reported identity-led extortion group. Suggested relationships to other actor ecosystems remain unresolved.SourceHelix Extortion Group Debuts in SharePoint Data Theft Attacks

https://areteir.com/resources/helix-extortion-group-debuts-in-sharepoint-data-theft-attacks

Source11PublisherBlack KitePublished2026-07-27Publication / evidenceSource indexprimary researchWhy used / claim treatmentBlack Kite annual public-disclosure and exposure-posture research. The April 2025-March 2026 victim count, June 2026 active-group count, and post-disclosure posture findings remain Black Kite methodology and are not added to June leak-site or U.S. SMB tracker populations.Source2026 Ransomware Report

https://blackkite.com/reports/2026-ransomware-report

Source12PublisherSophosPublished2026-07-22Publication / evidenceSource indexprimary researchWhy used / claim treatmentVendor-agnostic survey of 2,158 IT and security leaders whose organizations were hit by ransomware in the previous 12 months. Survey outcomes inform preparedness and control priorities; they are not a measured incident-response or leak-site population.SourceThe State of Ransomware 2026: Payments Drop as Encryption Climbs

https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026

Source13PublisherProofpointPublished2026-07-21Publication / evidenceSource indexprimary researchWhy used / claim treatmentGlobal survey of security professionals on ransomware, AI-enabled social engineering, malicious-link entry, payment behavior, repeat extortion, and data theft. The survey measures respondent experience and perception, not verified incident prevalence.Source2026 AI-Era Ransomware Report

https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report