IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling U.S. SMB Ransomware Watch

U.S. SMB Ransomware Activity & Exposure Trends — Rolling 90-Day Intelligence Card (Jun 15–Sep 12, 2026)

This U.S. SMB-focused rolling card automatically queries the ransomware.live Pro, RansomLook, ThreatFox, and AlienVault OTX APIs; reconciles overlapping U.S. victim claims; measures sector and group concentration; and links group aliases to IntelliOS Threat Actor Cards. It complements the Global Ransomware Landscape card, which explains worldwide operator momentum and tradecraft. The two products answer different questions, and their counts, rankings, and source methodologies must remain separate.

Coverage
Jun 15–Sep 12, 2026
Record Version
v16
Updated
Sep 11, 2026
AI Monitor
Daily · midday ET
Evidence
34 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Jun 15, 2026Sep 12, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowDaily at midday ET

940[1]

U.S. claims observed

Actor-published claims; not confirmed incidentsEvidence dated Jul 26, 2026

840[1][2]

Cross-collector matches

89.4% also observed by RansomLookEvidence dated Jul 26, 2026

78.5%[1][5]

Actor alignment

738 of 940 claims linked to canonical actor cardsEvidence dated Jul 26, 2026

0[1]

Verified SMB victims

Company size was not inferred from tracker recordsEvidence dated Jul 26, 2026

Where visible U.S. claims concentrated

Leading sector labels in the active rolling window. The remainder is preserved as “Other sectors” instead of being hidden. Sector labels come from source records and do not establish company size or a confirmed incident.[1]Evidence dated Jul 26, 2026

observed claims

Actor-label concentration

The three leading source labels are shown against the rest of the observed population, preserving both concentration and the fragmented long tail.[1]Evidence dated Jul 26, 2026

qilin108 · 11.5%
thegentlemen80 · 8.5%
incransom57 · 6.1%
Other group labels695 · 73.9%

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

The victim trackers do not enumerate a verified initial-access method for each claim. These paths are prioritized from retained official guidance and connected actor context; they direct exposure review without assigning a vector to every listed victim.

1

Identity-led access

Valid accounts and remote administration[4]Evidence dated Source date not published

Standing defensive priority; not attributed to every tracker claim

How it starts
Stolen, reused, purchased, or weakly protected administrative credentials provide VPN, remote-support, cloud, or management access.
Attacker outcome
Trusted access can bypass perimeter controls, shorten dwell time, and reach recovery-critical systems.
What to monitor
New VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, unusual support sessions, and unexplained privilege elevation.
2

Externally reachable control plane

Internet-facing edge and management exposure[4]Evidence dated Source date not published

Source-backed exposure path; local reachability must be verified

How it starts
An exposed gateway, remote-support service, management interface, or unpatched edge system provides an entry point or credential-access opportunity.
Attacker outcome
The attacker may inherit trusted network position, credentials, sessions, or downstream administrative reach.
What to monitor
New management access, configuration changes, appliance-originated connections, suspicious child processes, credential access, and historical gaps in edge logs.
3

Third-party access

MSP and shared-service trust[4]Evidence dated Source date not published

High-consequence SMB dependency; not a claim-level attribution

How it starts
A provider identity, remote-management tool, shared account, or cross-tenant workflow is compromised or abused.
Attacker outcome
One trusted path can create multi-customer reach, accelerate lateral movement, or complicate containment authority.
What to monitor
Cross-tenant anomalies, provider-account changes, access outside support windows, new tools, unusual customer-specific activity, and provider notices.
4

Human and session compromise

Phishing and user-assisted credential theft[4]Evidence dated Source date not published

Official prevention priority; victim-level prevalence is not measured here

How it starts
A user or administrator is induced to disclose credentials, approve access, execute content, or establish an attacker-controlled session.
Attacker outcome
The attacker gains reusable identity or endpoint access that can be escalated toward data theft, security-control changes, and encryption.
What to monitor
Suspicious authentication, inbox or forwarding changes, token issuance, remote tools, script execution, new persistence, and rapid access to administrative or shared data.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentOwners, executives, IT leaders, security teams, managed service providers, incident-response owners, insurers, and continuity leaders supporting U.S. SMBs.
Audience fieldSMB definitionAssessmentSmall follows the applicable SBA NAICS size standard. Midsize is used as an operating-audience label because no single federal threshold applies. No tracker-listed organization is classified as an SMB without authoritative employee, revenue, affiliation, and industry evidence.
Audience fieldDecision perspectiveAssessmentUse the card to prioritize remote access, identity, backup, service-provider, and recovery controls—not to infer that a particular company was compromised.
Audience fieldEvidence postureAssessmentTracker posts are claims. Cross-collector agreement corroborates that a post was observed; it does not independently confirm the intrusion or establish company size.

Chronology and Decision Milestones

Timeline of Notable Activity

Read this as an actor-activity chronology, not an IntelliOS work log. Tracker dates show when a listing was first discovered—not when access, theft, encryption, or business impact occurred. Research dates and observed exploitation periods are labeled separately, and daily counts can change when a collector backfills or reclassifies records.

  1. Global leadership shift

    The Gentlemen overtakes Qilin in Check Point’s separate worldwide dataset

    Check Point counted 646 worldwide leak-site publications for June, up 33% year over year, and attributed 17% to The Gentlemen, 11% to Qilin, and 7% to LockBit. The research also describes a move from vulnerable-driver EDR killing toward userland evasion. These worldwide measures provide operating context and are not added to the U.S. API population.[3]

  2. Multi-group daily posting burst

    Global Secret Group leads a 34-claim U.S. day

    Global Secret Group contributes 13; ExfilSquad contributes 10; genesis contributes 5; dragonforce contributes 2; 4 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  3. Concentrated daily posting burst

    CRPxO leads a 30-claim U.S. day

    CRPxO contributes 19; nightspire contributes 3; shinyhunters contributes 3; Global Secret Group contributes 2; 3 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  4. Concentrated daily posting burst

    thegentlemen leads a 22-claim U.S. day

    thegentlemen contributes 11; dragonforce contributes 2; insomnia contributes 2; qilin contributes 2; 5 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  5. Concentrated daily posting burst

    Orova leads a 21-claim U.S. day

    Orova contributes 12; incransom contributes 2; play contributes 2; thegentlemen contributes 2; 3 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  6. Multi-group daily posting burst

    Dark Project leads a 31-claim U.S. day

    Dark Project contributes 13; everest contributes 6; orion contributes 5; dragonforce contributes 2; 5 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  7. Multi-group daily posting burst

    Orova leads a 27-claim U.S. day

    Orova contributes 10; qilin contributes 4; ransomhouse contributes 3; dragonforce contributes 2; 8 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  8. Multi-group daily posting burst

    L Group leads a 27-claim U.S. day

    L Group contributes 7; Storm contributes 7; thegentlemen contributes 6; Helix contributes 3; 4 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  9. Concentrated daily posting burst

    clop leads a 30-claim U.S. day

    clop contributes 18; incransom contributes 3; blacknevas contributes 2; Ethics contributes 2; 5 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  10. Multi-group daily posting burst

    Storm leads a 24-claim U.S. day

    Storm contributes 7; metaencryptor contributes 4; Barracuda contributes 2; kazu contributes 2; 9 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  11. Multi-group daily posting burst

    settra leads a 21-claim U.S. day

    settra contributes 4; incransom contributes 3; BrainCipher contributes 2; lockbit5 contributes 2; 10 additional claims are distributed across other labels. The counts describe listings first discovered by the collector on this date—not a same-day incident count—and remain subject to later backfill or reclassification.[1][5]

  12. Open-source infrastructure and precursor activity

    ThreatFox and OTX surface current ransomware-related hunt evidence

    ThreatFox by abuse.ch / Spamhaus: The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence. AlienVault OTX ransomware-related pulses: 7 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75). The records are technical leads and do not establish victim identity, incident confirmation, or campaign prevalence.[7][8][36][33][31][30][32][27][24]

Bottom Line Up Front

BLUF

Coverage periodJun 15, 2026Sep 12, 202690 calendar days, inclusiveUpdated Sep 11, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

  • The Jun 14–Sep 11, 2026 window shows broad U.S. pressure with meaningful sector concentration: 940 U.S. victim claims carried a ransomware.live discovered date inside the inclusive UTC window, across 86 group labels. Professional Services (158), Healthcare (153), Manufacturing (142) led the visible population. Counts are frozen at this agent run and may change after collector backfills, removals, or reclassification.[1]Evidence dated Jul 26, 2026

  • Three group labels account for a material share without defining the whole landscape: qilin (108), thegentlemen (80), incransom (57) generated 245 claims. Treat those labels as watch priorities, not local attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

  • Cross-collector agreement supports direction, not incident confirmation: 840 of 940 combinations (89.4%) were also observed by RansomLook. That supports the existence of a post while leaving the claimed intrusion and impact unconfirmed.[1][2]Evidence dated Jul 26, 2026

  • SMB is a defined decision lens—not an inferred victim count: Small follows the applicable SBA NAICS size standard, generally based on employees or average annual receipts and including affiliates. No single federal midsize threshold applies, so midsize remains an operating-audience label. The trackers lack sufficient firmographics to classify named victims.[1][6]Evidence dated Jul 26, 2026

  • The management priority is recoverability under identity and infrastructure loss: Protect administrative access, reduce exposed management, separate backup identities, monitor staging and egress, constrain provider trust, and prove restoration without normal production identity or network paths.[4]Evidence dated Source date not published

  • Open-source technical feeds add current hunt material without changing victim counts: ThreatFox by abuse.ch / Spamhaus: The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence. AlienVault OTX ransomware-related pulses: 7 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75).[7][8][36][33][31][30][32][27][24]First cited source Jul 26, 2026 · Latest cited source Sep 11, 2026

Decision Context

Executive Summary

Coverage periodJun 15, 2026Sep 12, 202690 calendar days, inclusiveUpdated Sep 11, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

This edition covers the inclusive UTC period Jun 14–Sep 11, 2026. The primary population includes ransomware.live records by the date the service first discovered the listing—not the estimated attack date—and RansomLook matches must carry a discovered date inside the same window. Within that boundary, ransomware.live recorded 940 U.S. victim claims across 86 group labels.[1][2]Evidence dated Jul 26, 2026

Small-business status follows the applicable SBA NAICS size standard, which generally uses employee count or average annual receipts and includes affiliates. There is no single federal midsize threshold, so midsize is an operating-audience label rather than a firmographic classification. Tracker records without authoritative size data are not classified as SMB victims.[1][6]Evidence dated Jul 26, 2026

The clearest business pattern is sector concentration. Professional Services accounted for 158; Healthcare accounted for 153; Manufacturing accounted for 142; Technology accounted for 94; Retail & E-Commerce accounted for 77. For SMB leaders, that distribution elevates downtime and client disruption tied to shared systems, remote administration, sensitive data, operational dependencies, payments, and third parties.[1]Evidence dated Jul 26, 2026

Actor visibility also concentrated without becoming narrow. qilin recorded 108 claims; thegentlemen recorded 80 claims; incransom recorded 57 claims. IntelliOS resolved 738 of 940 claims to canonical Actor Cards, providing governed alias and behavior context while preserving the rule that a tracker label does not establish local attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

The evidence supports qualified confidence: RansomLook also observed 840 combinations, or 89.4% of the ransomware.live population. That corroborates observation of a public post, not the underlying intrusion. Abuse.ch and OTX remain a separate technical-signal lane and cannot increase victim totals or corroborate a named victim claim.[1][2]Evidence dated Jul 26, 2026

The separate Active Infrastructure and Precursors lane adds current technical evidence without changing the victim picture. ThreatFox by abuse.ch / Spamhaus: The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence. AlienVault OTX ransomware-related pulses: 7 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75). These signals are retained for local matching, enrichment, and source-qualified blocking—not as incident confirmation, victim corroboration, or a measure of group prevalence.[7][8][36][33][31][30][32][27][24]First cited source Jul 26, 2026 · Latest cited source Sep 11, 2026

The executive response should reduce recoverability leverage: protect privileged and remote access, remove unnecessary Internet-facing management, isolate backup identities and infrastructure, monitor pre-encryption staging and egress, constrain service-provider trust, test restoration under identity and virtualization loss, and pre-authorize containment and communications decisions.[4]Evidence dated Source date not published

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    940 U.S. victim claims were observedThis is the visible leak-site claim population for Jun 14–Sep 11, 2026, not a confirmed breach count. Use it to measure concentration and direction, not national incident prevalence.[1]Evidence dated Jul 26, 2026

  2. 2

    Professional Services carried the largest visible shareProfessional Services accounted for 158 claims (16.8%). For SMBs in that operating environment, identity, shared-service access, and recovery readiness are business controls.[1]Evidence dated Jul 26, 2026

  3. 3

    The top three sectors accounted for 453 claimsProfessional Services (158), Healthcare (153), Manufacturing (142) concentrated the largest visible operating pressure. The common decision is whether essential services can continue while identity or core systems are unavailable.[1]Evidence dated Jul 26, 2026

  4. 4

    qilin led the group distributionqilin accounted for 108 claims (11.5%). It resolves to the canonical Qilin Actor Card.[1][5]Evidence dated Jul 26, 2026

  5. 5

    Three group labels generated 245 claimsqilin (108), thegentlemen (80), incransom (57). These labels define watch priorities; they do not establish attribution in any individual incident.[1][5]Evidence dated Jul 26, 2026

  6. 6

    86 group labels require canonical resolution63 labels covering 738 claims currently link to canonical IntelliOS Actor Cards. Unmatched names remain provisional rather than creating silent duplicate identities.[1][5]Evidence dated Jul 26, 2026

  7. 7

    840 claims appeared in both collectors89.4% of ransomware.live group-and-victim combinations were also observed by RansomLook. This strengthens confidence that the public post existed while leaving the underlying intrusion unconfirmed.[1][2]Evidence dated Jul 26, 2026

  8. 8

    100 claims remain single-collector observationsThese records should not drive company-level conclusions until the second collector, a victim disclosure, an official notice, or another authoritative source supplies additional evidence.[1][2]Evidence dated Jul 26, 2026

  9. 9

    Company size remains unverifiedThe retained tracker records do not supply dependable employee-count or revenue evidence. The card applies an SMB decision lens but does not describe the U.S. claim total as an SMB victim count.[1]Evidence dated Jul 26, 2026

  10. 10

    Open-source technical feeds add current hunt material without changing victim countsThreatFox by abuse.ch / Spamhaus: The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence. AlienVault OTX ransomware-related pulses: 7 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75).[7][8][36][33][31][30][32][27][24]First cited source Jul 26, 2026 · Latest cited source Sep 11, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationAll U.S. organizations named in the active tracker window[1][2]Evidence dated Jul 26, 2026SectorsCross-industry; 940 claims across the retained sector taxonomyGeographyUnited StatesConfirmation statusActor-published or collector-observed victim claims; not independently confirmed incidentsHow companies should use itUse the population to assess concentration and defensive priorities. Do not use it as a national incident rate or confirmed-victim census.
Victim / exposure populationProfessional Services organizations[1]Evidence dated Jul 26, 2026SectorsProfessional Services — 158 claims, 16.8%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itUse the professional services concentration to test identity, continuity, recovery, data, and provider assumptions that are specific to that operating environment.
Victim / exposure populationHealthcare organizations[1]Evidence dated Jul 26, 2026SectorsHealthcare — 153 claims, 16.3%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itUse the healthcare concentration to test identity, continuity, recovery, data, and provider assumptions that are specific to that operating environment.
Victim / exposure populationManufacturing organizations[1]Evidence dated Jul 26, 2026SectorsManufacturing — 142 claims, 15.1%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itUse the manufacturing concentration to test identity, continuity, recovery, data, and provider assumptions that are specific to that operating environment.
Victim / exposure populationTechnology organizations[1]Evidence dated Jul 26, 2026SectorsTechnology — 94 claims, 10.0%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itUse the technology concentration to test identity, continuity, recovery, data, and provider assumptions that are specific to that operating environment.
Victim / exposure populationRetail & E-Commerce organizations[1]Evidence dated Jul 26, 2026SectorsRetail & E-Commerce — 77 claims, 8.2%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itUse the retail & e-commerce concentration to test identity, continuity, recovery, data, and provider assumptions that are specific to that operating environment.
Victim / exposure populationOrganizations that may qualify as small or midsize businesses[1][5]Evidence dated Jul 26, 2026SectorsAll retained sectorsGeographyUnited StatesConfirmation statusZero tracker records are treated as verified SMB classifications because authoritative employee, revenue, affiliation, and NAICS evidence is absentHow companies should use itApply the applicable SBA NAICS size standard for small-business status. Treat midsize as an operating-audience lens unless a documented threshold and authoritative firmographics are available.

Distinct Operational Records

Ransomware Threat Actors & Operations

qilin accounts for 108 observed claims

qilin represents 11.5% of the active U.S. population. The label resolves to the canonical Qilin Actor Card. Use it as a watch priority, not local attribution.[1][5]Evidence dated Jul 26, 2026

thegentlemen accounts for 80 observed claims

thegentlemen represents 8.5% of the active U.S. population. The label resolves to the canonical The Gentlemen Actor Card. Use it as a watch priority, not local attribution.[1][5]Evidence dated Jul 26, 2026

incransom accounts for 57 observed claims

incransom represents 6.1% of the active U.S. population. The label resolves to the canonical INC Ransom Actor Card. Use it as a watch priority, not local attribution.[1][5]Evidence dated Jul 26, 2026

The long tail remains larger than the leading groups

695 claims sit outside the three leading labels. Control-based readiness must survive affiliate movement, rebrands, and groups that never reach the top-three list.[1][5]Evidence dated Jul 26, 2026

Current Group Labels, Canonical Identities, and Decision Use

Threat Actor Glossary

The ten leading source labels in this edition, ranked by observed U.S. claims and linked to governed Actor Cards. Counts measure published claims inside the coverage window—not confirmed incidents, unique operators, successful encryptions, or verified SMB victims.

Window measureResultHow to read it
Observed claims940Publicly posted victim claims; not confirmed incidents.
Source labels86Distinct group names present in the coverage window.
Aligned labels63/8623 labels remain provisional.
Aligned claim volume78.5%738 claims link to governed Actor Cards.
Top-three concentration26.1%245 observed claims.
Top-ten concentration47.7%448 observed claims.
Actor / source labelActivity in this windowSource-backed assessmentAttribution boundary / defender use
1

Source label: qilin

Qilin

108 (11.5%)

Canonical match

qilin is part of the leading three-label cluster. Rankings measure source-observed claims inside this run’s window, not confirmed incidents or operator market share.[1][5]Open the canonical Qilin Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
2

Source label: thegentlemen

The Gentlemen

80 (8.5%)

Canonical match

thegentlemen is part of the leading three-label cluster. Rankings measure source-observed claims inside this run’s window, not confirmed incidents or operator market share.[1][5]Open the canonical The Gentlemen Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
3

Source label: incransom

INC Ransom

57 (6.1%)

Canonical match

incransom is part of the leading three-label cluster. Rankings measure source-observed claims inside this run’s window, not confirmed incidents or operator market share.[1][5]Open the canonical INC Ransom Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
4

Source label: Storm

Storm

36 (3.8%)

Provisional

Storm sits in a tightly grouped middle tier where small count changes can reorder rankings without establishing a material change in capability.[1][5]Keep this source label provisional, avoid silently merging it with another identity, and require reviewed evidence before creating or asserting a canonical actor.
5

Source label: akira

akira

33 (3.5%)

Canonical match

akira sits in a tightly grouped middle tier where small count changes can reorder rankings without establishing a material change in capability.[1][5]Open the canonical akira Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
6

Source label: shinyhunters

shinyhunters

29 (3.1%)

Canonical match

shinyhunters sits in a tightly grouped middle tier where small count changes can reorder rankings without establishing a material change in capability.[1][5]Open the canonical shinyhunters Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
7

Source label: Global Secret Group

Global Secret Group

27 (2.9%)

Provisional

Global Secret Group sits in a tightly grouped middle tier where small count changes can reorder rankings without establishing a material change in capability.[1][5]Keep this source label provisional, avoid silently merging it with another identity, and require reviewed evidence before creating or asserting a canonical actor.
8

Source label: CRPxO

CRPxO

26 (2.8%)

Provisional

This label remains in the top ten, while the long tail outside the leading groups still represents substantial claim volume.[1][5]Keep this source label provisional, avoid silently merging it with another identity, and require reviewed evidence before creating or asserting a canonical actor.
9

Source label: direwolf

direwolf

26 (2.8%)

Canonical match

This label remains in the top ten, while the long tail outside the leading groups still represents substantial claim volume.[1][5]Open the canonical direwolf Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.
10

Source label: play

Play

26 (2.8%)

Canonical match

This label remains in the top ten, while the long tail outside the leading groups still represents substantial claim volume.[1][5]Open the canonical Play Actor Card for governed aliases and source-backed context. Require local or authoritative evidence before attributing an incident.

How to read actor language

TermMeaning in this card
Source labelThe group name exactly as supplied by the collector. It is preserved even when IntelliOS maps it to a different canonical spelling.
Canonical actorThe governed IntelliOS identity used to consolidate known spellings and aliases. A match improves navigation and watchlist quality; it does not prove attribution.
RaaS brandA ransomware-as-a-service identity may represent shared infrastructure, rules, tooling, or branding used by multiple affiliates rather than one fixed intrusion team.
AffiliateAn operator or crew using a ransomware program or brand. Affiliates can change brands, access methods, and targets, so brand-level behavior should not be applied automatically to every incident.
Observed claimA victim name or post collected from an extortion source. It shows that a claim was published—not that the intrusion, actor, timing, scope, or impact was independently confirmed.
Provisional labelA source name without a deterministic canonical or retained-alias match. It remains separate until reviewed evidence supports a merge or a new governed Actor Card.

Attribution rule: A tracker label, canonical match, affiliate association, infrastructure overlap, or second collector may justify investigation. None alone establishes who compromised a named organization.[1][2][5]

Enterprise Exposure

Affected Technologies & Trust Boundaries

Remote access and administrative control planes

VPNs, remote-support systems, management interfaces, and privileged administration can turn one stolen or exposed path into broad operational reach. Inventory them, require phishing-resistant access, and retain session and administrator telemetry.[4]Evidence dated Source date not published

Identity, sessions, and service accounts

Passwords are only one access artifact. Privileged sessions, tokens, enrolled authentication methods, dormant accounts, and service identities must be reviewable and rapidly revocable during containment.[4]Evidence dated Source date not published

Backup repositories and recovery orchestration

Recovery systems that share production identities or management paths may fail when needed most. Separate identities, isolate copies, monitor destructive administration, and prove restoration under production identity loss.[4]Evidence dated Source date not published

Virtualization and shared infrastructure

Hypervisors, storage, domain services, and shared management systems concentrate business impact. Treat administrative changes, mass shutdown, snapshot deletion, and unusual host access as recovery-critical signals.[4]Evidence dated Source date not published

MSP and third-party management tooling

Provider credentials and shared remote-management paths can extend a compromise across tenants. Require named access, isolation, complete logs, an emergency disable path, and joint response procedures.[4]Evidence dated Source date not published

Data staging, archives, and outbound transfer

Extortion pressure often depends on data theft before encryption. Monitor bulk reads, archive creation, unapproved cloud storage, large encrypted egress, and new transfer utilities as early containment opportunities.[4]Evidence dated Source date not published

Non-Victim Technical Evidence Lane

Access, Exposure, and Infrastructure Precursors

A separate evidence lane for malicious infrastructure, active exploitation, and credential or session exposure that may precede ransomware access. It supports local validation, hunting, and defensive prioritization; it is not a ransomware-victim dataset.

The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence.[7]

Operational use: Match retained hashes and network endpoints against endpoint, proxy, DNS, firewall, and historical telemetry. Re-check status and context before blocking.

7 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75).[8][36][33][31][30][32][27][24]

Operational use: Use pulse context to prioritize local IOC matching and pivot to each cited pulse before containment. Preserve provisional language and attribution limits.

Awaiting a valid Hudson Rock API key. The planned read-only lane will query infostealer-derived credential, session, employee, domain, and third-party exposure relevant to ransomware access paths.[14]

Operational use: Validate affected identities and services locally, then rotate credentials, revoke sessions, and investigate access. Never treat a stealer record as proof of ransomware access or a confirmed victim.

Hard boundary: ThreatFox, OTX, and Hudson Rock signals never increase ransomware victim totals, never corroborate a named victim claim, and never establish ransomware attribution by themselves. A signal is retained only when it is current, technically actionable, and source-linked; overlap with a victim or actor requires separate evidence.

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Identity

Remote and administrative access[3][4]Evidence dated Jul 9, 2026

Why it mattersStolen or reused access can move an incident past perimeter controls before defenders see encryption.What to monitorNew VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, privilege elevation, and unexplained service-account activity.IntelliOS coverage
2Threat / Category

Recovery

Backup and virtualization control planes[3][4]Evidence dated Jul 9, 2026

Why it mattersAttackers gain leverage when recovery systems share production identities or administrative paths.What to monitorRetention changes, repository deletion, new backup administrators, SSH enablement, mass VM shutdown, and failed restore tests.IntelliOS coverage
3Threat / Category

Third party

MSP and shared-service trust[3][4]Evidence dated Jul 9, 2026

Why it mattersA compromised provider credential or management platform can expand one intrusion into multiple SMB environments.What to monitorCross-tenant anomalies, shared accounts, remote-management changes, provider notices, and unusual customer-specific access.IntelliOS coverage
4Threat / Category

Pre-encryption

Staging and outbound transfer[3][4]Evidence dated Jul 9, 2026

Why it mattersData theft often precedes encryption and public pressure.What to monitorArchive creation, bulk file reads, unapproved cloud storage, unusual S3 transfers, compression tools, and large encrypted egress.IntelliOS coverage
5Threat / Category

Evidence

Claim confirmation workflow[1][2]Evidence dated Jul 26, 2026

Why it mattersA tracker post should trigger verification, not an automatic breach declaration.What to monitorVictim disclosure, regulatory notice, filing, law-enforcement statement, forensic evidence, extortion contact, and retained source changes.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

Six operating practices translate the 90-day evidence into controls an SMB can implement, rehearse, and prove. The lesson identifies the failure mode; the minimum operating standard states the evidence leadership should expect.

Coverage periodJun 15, 2026Sep 12, 202690 calendar days, inclusiveUpdated Sep 11, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

  1. 1

    Best Practice

    Make privileged and remote administration phishing-resistant[4]Evidence dated Source date not published

    Lesson Learned

    Operator names change, but stolen or replayed administrative access remains a durable path to rapid business impact.

    Minimum Operating Standard

    Cover every privileged, remote-management, backup, virtualization, and provider administrator with phishing-resistant authentication; eliminate shared accounts; use time-bounded elevation; review access quarterly; and retain proof of emergency session revocation.

  2. 2

    Best Practice

    Prove recovery without production identity or network dependencies[4]Evidence dated Source date not published

    Lesson Learned

    A backup is not a recovery capability when compromised production identities, management planes, or network paths are required to restore it.

    Minimum Operating Standard

    Maintain separate recovery identities and an isolated or immutable copy; test representative restores quarterly without production identity or normal network paths; and record RTO, RPO, integrity results, exceptions, and owners.

  3. 3

    Best Practice

    Constrain provider access to the smallest reversible trust path[4]Evidence dated Source date not published

    Lesson Learned

    One provider credential, remote-management tool, or cross-tenant workflow can expand a compromise into customer environments.

    Minimum Operating Standard

    Use named provider accounts, tenant isolation, least privilege, approved support windows, complete logs, monthly access reconciliation, an emergency disable path, and an annual joint containment-and-restoration exercise.

  4. 4

    Best Practice

    Detect and contain the pre-encryption sequence[4]Evidence dated Source date not published

    Lesson Learned

    Data staging, unusual egress, remote-tool changes, privilege escalation, and recovery-system administration can create a decision window before encryption.

    Minimum Operating Standard

    Alert on staging, outbound transfer, new remote tools, privileged-account changes, and backup or hypervisor tampering; assign a 24/7 decision owner; preserve evidence; and test containment against a defined response-time target.

  5. 5

    Best Practice

    Pre-authorize the ransomware decision chain[4]Evidence dated Source date not published

    Lesson Learned

    Containment, shutdown, insurer notice, legal, communications, and restoration decisions stall when authority is first negotiated during an incident.

    Minimum Operating Standard

    Maintain a one-page decision matrix with primary and after-hours owners, thresholds, insurer and counsel contacts, notification criteria, communications approval, and authority for disruptive containment; exercise it at least twice yearly.

  6. 6

    Best Practice

    Separate public claims, technical signals, and confirmed incidents in operations[1][2]Evidence dated Jul 26, 2026

    Lesson Learned

    A leak-site post, a second collector, an infrastructure indicator, and local forensic evidence answer different questions.

    Minimum Operating Standard

    Every alert records evidence state, controlling source, local exposure result, owner, next validation step, and deadline. Technical indicators can drive hunts but cannot increase victim totals; a named incident requires authoritative or defensible local evidence.

Who Contributed What

Source Contributions & Decision Role

Each source has a defined job in this edition. Collection, corroboration, operating context, defensive guidance, actor-name resolution, and the SMB definition remain separate so one source is never stretched beyond the evidence it actually supplies.

Contributorransomware.live

Ransomware.live Pro API — U.S. victim claims observed during the rolling window

ContributionSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1]Decision useMeasure visible claim pressure and concentration; trigger organization-level validation when a relevant name or pattern appears.Evidence boundaryDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current.
ContributorRansomLook

RansomLook recent posts API — independent collector reconciliation

ContributionProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2]Decision useIdentify cross-collector agreement and isolate records that need additional reconciliation.Evidence boundaryA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status.
ContributorCheck Point Research

A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

ContributionAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3]Decision useExplain why concentrated group activity matters and turn specific operating observations into monitoring questions.Evidence boundaryIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals.
ContributorCybersecurity and Infrastructure Security Agency

#StopRansomware Guide

ContributionSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4]Decision useSet the operational response baseline for identity protection, exposed services, backups, containment, evidence, and recovery.Evidence boundaryDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident.
ContributorIntelliOS

IntelliOS Threat Actor Cards

ContributionNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5]Decision usePrevent fragmented watchlists and route readers from a source label to the best available actor context.Evidence boundaryAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident.
ContributorU.S. Small Business Administration

Small Business Size Standards

ContributionControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6]Decision useDefine the intended small-business audience and prevent unsupported firmographic classification of tracker-listed organizations.Evidence boundaryProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record.
Contributorabuse.ch / Spamhaus

ThreatFox Community API — recent ransomware-tagged indicators

ContributionDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7]Decision useTurn a group name into concrete exposure questions about edge patching, purchased credentials, infostealer logs, session theft, Active Directory abuse, EDR resilience, backup isolation, and client-connected accounts.Evidence boundaryThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total.
ContributorAlienVault Open Threat Exchange

AlienVault OTX subscribed-pulse API — recent ransomware-related pulses

ContributionSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8]Decision usePrioritize exposure validation, hotfixing, IKEv1 retirement, log review, and threat hunting where the affected remote-access configuration exists.Evidence boundaryThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims.
ContributorAlienVault OTX

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

ContributionQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9]Decision useDrive endpoint, network, DNS, proxy, and historical telemetry matching against fresh, source-linked technical artifacts.Evidence boundaryIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking.
ContributorAlienVault OTX

New Backdoor May be Linked to Ransomware Access Broker

ContributionQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10]Decision usePrioritize emerging ransomware, access-broker, data-extortion, and specialized targeting hypotheses for local IOC matching and follow-up research.Evidence boundaryPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions.

Claim-Specific Evidence Authority

Source Weighting / Relevance

Weight is claim-specific, not a universal publisher score. An official source can control response guidance or the SMB definition while contributing nothing to current victim totals; an API can control measured claim volume while remaining unable to confirm an incident.

Sourceransomware.liveWeightHighRelevancePrimary quantitative claim sourceWhat it can supportSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1]LimitationDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current.
SourceRansomLookWeightHigh for post observationRelevanceIndependent collection checkWhat it can supportProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2]LimitationA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status.
SourceCheck Point ResearchWeightHigh for operating contextRelevanceIndependent threat researchWhat it can supportAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3]LimitationIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals.
SourceCybersecurity and Infrastructure Security AgencyWeightVery High for defensive guidanceRelevanceOfficial response authorityWhat it can supportSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4]LimitationDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident.
SourceIntelliOSWeightHigh for identity resolutionRelevanceGoverned internal alignmentWhat it can supportNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5]LimitationAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident.
SourceU.S. Small Business AdministrationWeightVery High for the SMB boundaryRelevanceOfficial firmographic definitionWhat it can supportControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6]LimitationProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record.
Sourceabuse.ch / SpamhausWeightHigh for documented tradecraftRelevancePrimary leaked-operation analysisWhat it can supportDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7]LimitationThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total.
SourceAlienVault Open Threat ExchangeWeightHigh for the affected-product findingRelevancePrimary exploitation telemetryWhat it can supportSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8]LimitationThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims.
SourceAlienVault OTXWeightHigh for retained IOC factsRelevanceCurrent technical hunt feedWhat it can supportQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9]LimitationIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking.
SourceAlienVault OTXWeightModerate to High for discoveryRelevanceCommunity and provider pulse contextWhat it can supportQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10]LimitationPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions.
Decision rule: ransomware.live controls observed claim totals; RansomLook controls only cross-collector observation; CISA controls defensive guidance; SBA controls the small-business definition; Check Point controls only its own research observations; and IntelliOS Actor Cards control internal name resolution. None independently confirms a named ransomware incident.

Automation Transparency

AI Agent Run Status

AgentU.S. SMB Ransomware Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceDaily at midday ET; publish only when claim volume, concentration, corroboration, or group alignment changes materially
Previous run26-Jul-2026 · midday ET · Run ACT-US-SMB-RANSOM-20260726-1215
Previous resultPublished the quarter-over-quarter trend lane while preserving explicit outcome-data gaps.
What the previous run found
  • Global public victim-post pressure increased 7% from Q1 to Q2
  • Successful-encryption and initial-demand direction remain not yet measurable for U.S. SMBs
  • Coveware Q4-to-Q1 paid amounts were mixed: average up 15%, median down 7%
  • 789 U.S. claims retained
  • 681 cross-collector matches
  • 73 group labels normalized
  • ThreatFox retained 79 current ransomware-tagged hunt indicators
  • OTX retained five cited pulses with 70 technical indicators
  • SMB size remained unverified and was not inferred
Next run27-Jul-2026 · midday ET
Sources monitored
  • ransomware.live Pro API
  • RansomLook public posts API
  • Coveware quarterly casework
  • Arete Crimeware Reports
  • GuidePoint GRIT quarterly reports
  • ThreatFox Community API
  • AlienVault OTX subscribed-pulse API
  • Hudson Rock Cavalier MCP (planned; awaiting API key)
  • IntelliOS Threat Actor Cards
  • U.S. Small Business Administration NAICS size standards
  • Retained official and primary ransomware research
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyAlert for a material change in public victim-post pressure, successful-encryption incidence, initial demands, paid amounts, payment propensity, concentration, corroboration, or evidence state. Suppress routine additions, date-only movement, and no-change runs.

Related Intelligence and CARDS Records

Other IntelliOS Products

Intelligence Alignment

Ransomware Group Alignment Engine

Deterministic canonical, alias, source-alias, and reviewed-override matching across tracker labels and IntelliOS Threat Actor Cards.

Open product

Threat Actor Cards

Canonical Ransomware Group Watchlist

Resolved group names, aliases, confidence, behaviors, and related IntelliOS intelligence.

Open product

Rolling Intelligence

Global Ransomware Landscape

Broader global ransomware ecosystem, initial-access, operator, and recovery context. Its worldwide and source-specific measures remain separate from this U.S. claim population.

Open product

CARDS Actor Record

Qilin Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Thegentlemen Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

INC Ransom Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Akira Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Shinyhunters Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Direwolf Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Play Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Campaign Record

The Gentlemen RAAS Operations Campaign Card

Connected campaign intelligence, activity timeline, affected technologies, actors, techniques, and source boundaries.

Open product

Publication History

Version Change Log

Versionv9Date26-Jul-2026ChangeMade the quarter-over-quarter ransomware direction the lead management question. Added separate verdicts and snapshot measures for public victim-post pressure, successful encryption, initial demands, paid amounts, and payment propensity; retained GuidePoint Q2, Coveware Q1, and Arete Q1 as methodologically separate sources; and labeled unavailable Q2 encryption and demand outcomes as not yet measurable rather than flat.MonitoringDaily claim monitoring; publish direction changes when comparable casework becomes available
Versionv8Date26-Jul-2026ChangeAdded an explicit product boundary with the Global Ransomware Landscape card. Clarified why Qilin can lead this 90-day U.S. dataset while The Gentlemen leads a separate worldwide June dataset, and prohibited combining the two products’ counts or rankings.MonitoringDaily material-change review
Versionv7Date26-Jul-2026ChangeRemoved an unused planned enterprise exploitation-context integration and its citation, precursor-lane, source-run, and agent-plan references.MonitoringContinue the retained and authenticated source plan
Versionv6Date26-Jul-2026ChangeDefined the read-only Hudson Rock Cavalier MCP integration for the SMB ransomware product. Added it to Citations, the precursor evidence lane, source-run dispositions, and the agent source plan while explicitly excluding it from victim totals, victim corroboration, and standalone incident attribution. The source was not queried for this edition.MonitoringActivate Hudson Rock after a valid API key is configured
Versionv5Date26-Jul-2026ChangeExpanded the automated source set beyond victim trackers. Added authenticated ThreatFox and OTX queries, retained 149 current technical indicators in the separate Active Infrastructure and Precursors lane, linked every finding to controlling citations, and preserved the prohibition against using infrastructure signals to increase victim totals or confirm incidents.MonitoringDaily material-change review
Versionv4Date26-Jul-2026ChangeRebuilt the timeline as a compact, intelligence-led chronology of ransomware posting bursts, actor rotation, exposed RaaS operations, and active edge-device exploitation. Removed internal reconciliation and identity-resolution milestones from the chronology and added source-bounded Check Point research without changing victim totals.MonitoringDaily material-change review
Versionv3Date26-Jul-2026ChangeAdded a comprehensive Threat Actor Glossary covering the ten leading source labels, canonical Actor Card resolution, claim count and share, decision-relevant facts, attribution limits, and glossary definitions. The card also summarizes top-three, top-ten, long-tail, aligned, and unresolved actor statistics.MonitoringDaily material-change review
Versionv2Date26-Jul-2026ChangeAdded Source Contributions and Source Weighting / Relevance cards. Defined the separate decision roles and evidence limits for ransomware.live, RansomLook, Check Point Research, CISA, IntelliOS Threat Actor Cards, and SBA size standards without changing victim totals or confirmation states.MonitoringDaily material-change review
Versionv1Date26-Jul-2026ChangeCreated the U.S. SMB ransomware rolling card with cross-collector reconciliation, explicit SMB-size limits, sector concentration, canonical actor links, and practical SMB decisions.MonitoringDaily material-change review

Citations

Retained Sources and Claim Treatment

Source1Publisherransomware.livePublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentLeak-site and extortion-tracker observations. A listed organization is an actor claim, not an independently confirmed intrusion; the API does not establish company size.SourceRansomware.live Pro API — U.S. victim claims observed during the rolling window

https://api-pro.ransomware.live/docs

Source2PublisherRansomLookPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentA second collector can corroborate that a post was observed, but shared appearance across collectors still does not confirm the underlying intrusion.SourceRansomLook recent posts API — independent collector reconciliation

https://www.ransomlook.io/doc/

Source3PublisherCheck Point ResearchPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentVendor analysis of ransomware data-leak-site activity and operating context; published attacks remain actor claims unless separately confirmed.SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/

Source4PublisherCybersecurity and Infrastructure Security AgencyPublishedNot availablePublication / evidenceSource indexofficialWhy used / claim treatmentStanding defensive guidance used for practical prevention, containment, evidence-preservation, and recovery decisions; it does not control current victim-count claims.Source#StopRansomware Guide

https://www.cisa.gov/stopransomware/ransomware-guide

Source5PublisherIntelliOSPublished2026-07-26Publication / evidenceSource indexprimary researchWhy used / claim treatmentCanonical identity and alias directory used to link tracker labels to source-backed actor cards. A name match does not establish incident attribution.SourceIntelliOS Threat Actor Cards

/threat-actor-cards

Source6PublisherU.S. Small Business AdministrationPublishedNot availablePublication / evidenceSource indexofficialWhy used / claim treatmentControlling definition for the card’s small-business boundary. SBA size standards vary by NAICS industry and generally use employee count or average annual receipts, including affiliates. The source does not define one universal midsize threshold.SourceSmall Business Size Standards

https://www.sba.gov/federal-contracting/contracting-guide/size-standards

Source7Publisherabuse.ch / SpamhausPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentSeven-day API query of community-submitted, non-expired malware indicators. Indicators support hunting and validation; they do not identify a victim, prove an intrusion, or establish ransomware prevalence.SourceThreatFox Community API — recent ransomware-tagged indicators

https://threatfox.abuse.ch/api/

Source8PublisherAlienVault Open Threat ExchangePublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentDiscovery query across the 50 most recently returned subscribed pulses. Pulse and indicator records are community and provider intelligence inputs, not confirmed incidents or victim-count evidence.SourceAlienVault OTX subscribed-pulse API — recent ransomware-related pulses

https://otx.alienvault.com/

Source9PublisherAlienVault OTXPublished2026-07-25Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 17 retained technical indicators. The pulse is a hunt input and does not confirm a victim or incident.SourcePrinz Eugen ransomware: a deep dive into a new Go-based encryptor

https://otx.alienvault.com/pulse/6a3d416ff54ce39010db1033

Source10PublisherAlienVault OTXPublished2026-07-24Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 42 retained technical indicators. The reported access-broker relationship remains source-qualified and does not establish ransomware attribution.SourceNew Backdoor May be Linked to Ransomware Access Broker

https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b

Source11PublisherAlienVault OTXPublished2026-07-23Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing four retained infrastructure indicators. The source title is explicitly provisional and is not promoted into a canonical threat-actor identity.SourceA New Name in the Data Extortion Ecosystem?

https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0

Source12PublisherAlienVault OTXPublished2026-07-23Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing two retained network indicators. Indicators require local validation and do not establish a victim or campaign prevalence.SourceChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0

Source13PublisherAlienVault OTXPublished2026-07-21Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing five retained indicators, including hashes, one CVE reference, and one IPv4 address. It is a discovery and hunt input, not victim evidence.SourceJADEPUFFER evolves: ransomware built to destroy AI models

https://otx.alienvault.com/pulse/6a5eb7c2617139caf1fe0f2d

Source14PublisherHudson RockPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentPlanned authenticated integration for infostealer-derived credential, employee, domain, and third-party exposure signals. It has not been queried for this edition and cannot increase victim totals, corroborate a victim claim, or prove ransomware access.SourceCavalier Infostealers API MCP Server

https://docs.hudsonrock.com/docs/mcp

Source15PublisherGuidePoint Security GRITPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentGlobal public victim-post and ecosystem monitoring. Its quarter-over-quarter totals measure reported victims, not confirmed incidents, successful encryption, ransom demands, or a U.S. SMB-only population.SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report

https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/

Source16PublisherAlienVault OTXPublished2026-09-03Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 15 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceAlmost Half of Malware Samples Communicate Direct to IP

https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365

Source17PublisherAlienVault OTXPublished2026-08-31Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 28 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceCampaign deploys a reverse tunnel through multistage intrusion

https://otx.alienvault.com/pulse/6a94c765ccca1cbf809fc70f

Source18PublisherAlienVault OTXPublished2026-09-03Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 7 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceImpersonating IT support: how threat actors turn a remote session into enterprise-wide access

https://otx.alienvault.com/pulse/6a98ece13ef339971e686ab5

Source19PublisherAlienVault OTXPublished2026-08-29Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 24 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceToy Ghouls’ new toy: the GenieLocker ransomware

https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0

Source20PublisherAlienVault OTXPublished2026-09-02Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 13 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceOne leftover build path links an infostealer, a remote-access tool, and a ransomware family

https://otx.alienvault.com/pulse/6a9756cad8fd625876d6a1a5

Source21PublisherAlienVault OTXPublished2026-09-03Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 11 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceInside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research

https://otx.alienvault.com/pulse/6a9869cb21bbf3f757424b7f

Source22PublisherAlienVault OTXPublished2026-09-03Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 180 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceNode.js: Old Technique Makes a Comeback

https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf

Source23PublisherAlienVault OTXPublished2026-09-04Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 21 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceThe Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d

Source24PublisherAlienVault OTXPublished2026-09-05Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 75 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769

Source27PublisherAlienVault OTXPublished2026-09-07Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 3 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceAngry Birds: Toy Ghouls’ new toys

https://otx.alienvault.com/pulse/6a9abac288231f0634632e30

Source30PublisherAlienVault OTXPublished2026-09-10Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 10 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceActive exploitation of Cisco Secure Firewall Management Center vulnerabilities

https://otx.alienvault.com/pulse/6aa1c2281252d98a241ae632

Source31PublisherAlienVault OTXPublished2026-09-10Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 200 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceMantax Otax: Indonesian Mobile Ransomware with Spyware Integration

https://otx.alienvault.com/pulse/6aa1c8a04d40933ab841482f

Source32PublisherAlienVault OTXPublished2026-09-10Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 14 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceGrand Theft Auto VI hype leads to malware

https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a

Source33PublisherAlienVault OTXPublished2026-09-10Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 9 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceActive Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

https://otx.alienvault.com/pulse/6aa2affe4ab7ba9012836da5

Source36PublisherAlienVault OTXPublished2026-09-11Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 38 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution.SourceSloppyRAT: A New Tool For Ransomware Attacks

https://otx.alienvault.com/pulse/6aa2ea5fc313035064df8d21

Source7PublisherCheck Point ResearchPublished2026-05-13Publication / evidenceSource indexprimary researchWhy used / claim treatmentPrimary vendor analysis of leaked internal material describing The Gentlemen’s operating model, access paths, tooling, affiliate economics, and victim-chain reuse. It does not independently confirm every actor or victim claim in the leaked material.SourceWhen the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk

https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/

Source8PublisherCheck Point ResearchPublished2026-06-08Publication / evidenceSource indexprimary researchWhy used / claim treatmentVendor incident and product telemetry describing active exploitation beginning May 7 and a medium-confidence association with a financially motivated actor using Qilin ransomware. It does not establish that every Qilin claim used this vulnerability.SourceActive exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments

https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/

Source17PublisherCoveware by VeeamPublished2026-04-30Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware Q1 2026 casework. Its Q4-to-Q1 payment comparisons describe Coveware-managed cases, not all U.S. incidents or a verified SMB-only population. Paid amounts are not initial ransom demands.SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era

https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/

Source19PublisherAretePublished2026-06-03Publication / evidenceSource indexincident responseWhy used / claim treatmentArete incident-response statistics for ransomware and extortion engagements, primarily involving cyber-insured organizations. Demand, payment, and payment-rate figures are bounded to Arete's case population and do not establish a Q2 or U.S. SMB-wide result.SourceArete 2026 Q1 Crimeware Report

https://areteir.com/resources/arete-s-2026-q1-crimeware-report

Source-Run Dispositions

Run-level accounting distinguishes evidence used in this edition from sources checked but not retained, unavailable during collection, or planned for a future lane.

Used · Checked—not retained · Unavailable · Planned

ransomware.liveVictim-claim observationUsedSep 11, 2026Primary structured U.S. claim population for the active window.Controls total
RansomLookVictim-claim observationUsedSep 11, 2026Used only to corroborate that a public post was observed.Observation corroboration only
Check Point Research — June ransomware landscapeActor activity and operating contextUsedSep 11, 2026Controls the separate worldwide June volume, group-share, and operating-change assertions. It does not alter the U.S. claim population.Excluded
Check Point Research — The Gentlemen internal leakActor tradecraft and operating modelUsedSep 11, 2026Controls the source-bounded description of The Gentlemen’s access, affiliate, credential, tooling, and extortion workflow.Excluded
Check Point Research — CVE-2026-50751 exploitation advisoryActive exploitation and precursor activityUsedSep 11, 2026Controls the observed exploitation timing and medium-confidence Qilin association; it cannot identify the access vector for all Qilin claims.Excluded
IntelliOS Threat Actor CardsActor-label resolutionUsedSep 11, 2026Canonical directory source: database. Used for label normalization, not incident attribution.Excluded
U.S. Small Business AdministrationFirmographic definitionUsedSep 11, 2026Controls small-business classification through industry-specific NAICS size standards. It does not provide victim firmographics or a universal midsize threshold.Excluded
Have I Been PwnedCredential-to-Ransomware Exposure Watch (paused)PlannedNot runHeld for the paused credential-exposure product; not used in this ransomware victim card.Excluded
ThreatFoxActive Infrastructure and PrecursorsUsedSep 11, 2026INFRA-PRECURSORS-20260911The seven-day API query returned 14 ransomware-tagged indicators (Unknown malware 6, Akira Stealer 3, Hades 3, BianLian 2; domain 9, ip:port 2, md5_hash 1, sha1_hash 1, sha256_hash 1). This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence.Excluded
AlienVault OTXActive Infrastructure and PrecursorsUsedSep 11, 2026INFRA-PRECURSORS-202609117 ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 349 indicators: SloppyRAT: A New Tool For Ransomware Attacks (38); Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms (9); Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration (200); Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (10); Grand Theft Auto VI hype leads to malware (14); Angry Birds: Toy Ghouls’ new toys (3); UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (75).Excluded
Hudson Rock Cavalier MCPCredential Exposure and Ransomware Access PrecursorsPlannedNot runAwaiting a valid Hudson Rock API key. Planned read-only queries remain excluded from victim totals, victim corroboration, and standalone ransomware attribution.Excluded