IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling U.S. SMB Ransomware Watch

U.S. SMB Ransomware Activity & Exposure Trends — Rolling 90-Day Intelligence Card (Apr 30–Jul 28, 2026)

This U.S. SMB-focused rolling card automatically queries the ransomware.live Pro, RansomLook, ThreatFox, and AlienVault OTX APIs; reconciles overlapping U.S. victim claims; measures sector and group concentration; and links group aliases to IntelliOS Threat Actor Cards. It complements the Global Ransomware Landscape card, which explains worldwide operator momentum and tradecraft. The two products answer different questions, and their counts, rankings, and source methodologies must remain separate.

Coverage
Apr 30–Jul 28, 2026
Record Version
v9
Updated
Jul 28, 2026
AI Monitor
Daily · midday ET
Evidence
19 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowDaily at midday ET

↑ 7% QoQ[18]

Public victim-post direction

Global Q2 posts: 2,279 versus 2,135 in Q1; not confirmed incidents or U.S. SMB-onlyEvidence dated Jul 9, 2026

Not measurable[1][2][17]

Successful-encryption direction

Current U.S. tracker records lack a comparable encryption-outcome fieldFirst cited source Apr 30, 2026 · Latest cited source Jul 26, 2026

Not comparable[19]

Initial-demand direction

No completed Q2 casework benchmark; latest Arete Q1 median demand was $571KEvidence dated Jun 3, 2026

Mixed[17]

Paid-amount direction

Coveware Q4→Q1: average ↑15%; median ↓7%Evidence dated Apr 30, 2026

789[1]

U.S. claims observed

Actor-published victim claims; not confirmed incidentsEvidence dated Jul 26, 2026

681[1][2]

Cross-collector matches

86.3% also observed by RansomLookEvidence dated Jul 26, 2026

96.3%[1][5]

Actor alignment

760 of 789 claims resolve to canonical Actor CardsEvidence dated Jul 26, 2026

0[1]

Verified SMB victims

Company size was not inferred from tracker recordsEvidence dated Jul 26, 2026

Quarter-over-quarter public victim-post pressure

GuidePoint's global public-post dataset increased from 2,135 reported victims in Q1 2026 to 2,279 in Q2, a 7% rise. This is the cleanest current directional activity signal, but it does not measure confirmed incidents, successful encryption, ransom demands, or U.S. SMB prevalence.[18]Evidence dated Jul 9, 2026

reported victims

Paid ransom amounts moved in opposite directions

Coveware's adjacent-quarter casework shows why one headline number is inadequate: the average increased 15%, while the median decreased 7%. These are payments in Coveware-managed cases—not initial demands or a U.S. SMB-only population.[17]Evidence dated Apr 30, 2026

USD paid

Latest retained ransom-demand benchmark

Arete's Q1 2026 median demand sits between two different baselines: above Q1 2025 but below the full-year 2025 median. This is useful context, but it is not an adjacent-quarter comparison and cannot establish a Q2 direction.[19]Evidence dated Jun 3, 2026

USD demanded

Where visible U.S. claims concentrated

The five leading sector labels account for 566 of 789 observed claims. “Other sectors” preserves the remainder instead of hiding the long tail. Sector labels come from the source records and do not establish company size or a confirmed incident.[1]Evidence dated Jul 26, 2026

observed claims

Actor-label concentration

Qilin, The Gentlemen, and INC Ransom account for 243 claims—30.8% of the observed population. The remaining 546 claims span 70 other labels, so the card preserves both concentration and fragmentation.[1]Evidence dated Jul 26, 2026

Qilin122 · 15.5%
The Gentlemen63 · 8.0%
INC Ransom58 · 7.4%
Other group labels546 · 69.2%

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

The victim trackers do not enumerate a verified initial-access method for each claim. These paths are therefore prioritized from retained operating research and official defensive guidance; they direct exposure review and hunting without assigning a vector to every listed victim.

1

Identity-led access

Valid accounts and remote administration[3][4]Evidence dated Jul 9, 2026

Standing defensive priority; not attributed to every tracker claim

How it starts
Stolen, reused, purchased, or weakly protected administrative credentials provide VPN, remote-support, cloud, or management access.
Attacker outcome
Trusted access can bypass perimeter controls, shorten dwell time, and reach recovery-critical systems.
What to monitor
New VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, unusual support sessions, and unexplained privilege elevation.
2

Externally reachable control plane

Internet-facing edge and management exposure[3][4]Evidence dated Jul 9, 2026

Source-backed exposure path; local reachability must be verified

How it starts
An exposed gateway, remote-support service, management interface, or unpatched edge system provides an entry point or credential-access opportunity.
Attacker outcome
The attacker may inherit trusted network position, credentials, sessions, or downstream administrative reach.
What to monitor
New management access, configuration changes, appliance-originated connections, suspicious child processes, credential access, and historical gaps in edge logs.
3

Third-party access

MSP and shared-service trust[3][4]Evidence dated Jul 9, 2026

High-consequence SMB dependency; not a claim-level attribution

How it starts
A provider identity, remote-management tool, shared account, or cross-tenant workflow is compromised or abused.
Attacker outcome
One trusted path can create multi-customer reach, accelerate lateral movement, or complicate containment authority.
What to monitor
Cross-tenant anomalies, provider-account changes, access outside support windows, new tools, unusual customer-specific activity, and provider notices.
4

Human and session compromise

Phishing and user-assisted credential theft[4]Evidence dated Source date not published

Official prevention priority; victim-level prevalence is not measured here

How it starts
A user or administrator is induced to disclose credentials, approve access, execute content, or establish an attacker-controlled session.
Attacker outcome
The attacker gains reusable identity or endpoint access that can be escalated toward data theft, security-control changes, and encryption.
What to monitor
Suspicious authentication, inbox or forwarding changes, token issuance, remote tools, script execution, new persistence, and rapid access to administrative or shared data.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentOwners, executives, IT leaders, security teams, managed service providers, incident-response owners, insurers, and continuity leaders supporting U.S. SMBs.
Audience fieldSMB definitionAssessmentSmall follows the applicable SBA NAICS size standard. Midsize is used as an operating-audience label because no single federal threshold applies. No tracker-listed organization is classified as an SMB without authoritative employee, revenue, affiliation, and industry evidence.
Audience fieldDecision perspectiveAssessmentUse the card to prioritize remote access, identity, backup, service-provider, and recovery controls—not to infer that a particular company was compromised.
Audience fieldEvidence postureAssessmentTracker posts are claims. Cross-collector agreement corroborates that a post was observed; it does not independently confirm the intrusion or establish company size.

Chronology and Decision Milestones

Timeline of Notable Activity

Read this as an actor-activity chronology, not an IntelliOS work log. Tracker dates show when a listing was first discovered—not when access, theft, encryption, or business impact occurred. Research dates and observed exploitation periods are labeled separately, and daily counts can change when a collector backfills or reclassifies records.

  1. Largest daily posting burst

    PayoutsKING drives the window’s sharpest one-day surge

    Forty U.S. claims carry an April 30 discovered date, with 29 attributed to the PayoutsKING source label. Qilin, ShinyHunters, and Everest add two each, making the spike unusually concentrated while still involving several operating brands.[1][5]

  2. Rapid follow-on burst

    FulcrumSec and 3AM sustain pressure immediately after the April peak

    The next day contributes 29 more observed claims: FulcrumSec accounts for 12, 3AM for five, Pear for three, and Clop and BrainCipher for two each. Two consecutive high-volume days show how quickly the visible landscape can rotate from one dominant label to a different cluster.[1][5]

  3. RaaS operating model exposed

    A breach of The Gentlemen’s own backend reveals its access-to-extortion workflow

    Check Point’s analysis of leaked internal material describes a compact operation centered on an administrator known as zeta88, a roughly 90/10 affiliate split, and access obtained through unpatched edge devices, purchased credentials, and infostealer logs. The documented chain moves through Active Directory discovery, credential and session theft, EDR disruption, data exfiltration, backup targeting, and domain-wide ransomware deployment; the researchers also describe victim-to-client credential reuse and rapid use of AI assistants to build internal tooling.[7]

  4. Competing groups overlap

    The Gentlemen, Akira, Qilin, and Silent Ransom Group share a 20-claim day

    The Gentlemen leads with six U.S. claims, Akira and Silent Ransom Group contribute three each, and Qilin adds two. The mix matters because it is not a single-campaign event: several independently branded operations are visibly active against the same national market at once.[1][5]

  5. Edge-device exploitation

    A Qilin-associated actor exploits a Check Point VPN authentication bypass

    Check Point dates the earliest observed exploitation of CVE-2026-50751 to May 7 and reports increased activity in early June against deployments using deprecated IKEv1 remote access. With medium confidence, the vendor associates the financially motivated activity with an actor using Qilin ransomware; that association applies to the investigated activity, not to every Qilin-listed victim in this card.[8]

  6. Late-May acceleration

    DragonForce gives way to a Qilin-heavy burst over four days

    DragonForce leads May 25 with five of 13 observed claims and May 27 with six of 11. On May 28, Qilin accounts for nine of 22 claims while Everest contributes three. The sequence is more informative than a monthly total: different affiliate ecosystems can seize the visible lead within days.[1][5]

  7. Qilin concentration spike

    Qilin accounts for 11 of 18 claims first discovered in one day

    Play, WorldLeaks, and Pear contribute two each, but Qilin alone represents more than three-fifths of the day’s observed U.S. volume. The burst occurs during the same period in which Check Point reported increased exploitation activity associated with a Qilin-using actor; the sources do not establish that the two populations are the same victims.[1][8]

  8. Mid-month group rotation

    ShinyHunters and The Gentlemen lead before Pear and NightSpire appear

    On June 15, ShinyHunters contributes six claims and The Gentlemen five of the day’s 15. By June 18, ShinyHunters and Pear contribute three each while NightSpire and Lynx add two each. The movement illustrates why defenders should monitor operating clusters and access behaviors rather than build readiness around one permanent league table.[1][5]

  9. Global leadership shift

    The Gentlemen overtakes Qilin in Check Point’s separate worldwide dataset

    Check Point counted 646 worldwide leak-site publications for June, up 33% year over year, and attributed 17% to The Gentlemen, 11% to Qilin, and 7% to LockBit. Its research describes The Gentlemen advertising about 14,000 pre-exploited FortiGate devices and shifting from a vulnerable-driver EDR-killing technique toward userland evasion; those worldwide measures provide operating context and are not added to this card’s U.S. total.[3][7]

  10. Turn-of-month handoff

    Settra leads twice before The Gentlemen opens July with another burst

    Settra accounts for five claims on June 28 and another five on June 30. On July 1, The Gentlemen contributes eight of 20 observed claims, while BrainCipher and Qilin add three each and ShinyHunters adds two. The handoff shows how a quieter label can dominate individual days without displacing the window’s leading groups overall.[1][5]

  11. Provisional-label emergence

    CRPxO appears with five claims while Qilin adds four

    Twelve U.S. claims are first discovered that day: five under CRPxO, four under Qilin, and two under BrainCipher. CRPxO remains a source label requiring identity resolution; it should not be silently merged into a known group merely because it appears beside established operators.[1][5]

  12. Renewed Gentlemen activity

    The Gentlemen produces another eight-claim U.S. posting burst

    The day contains 15 observed claims, with The Gentlemen responsible for eight and Play and KillSec contributing two each. The recurrence reinforces that The Gentlemen’s June leadership was not only a one-month global ranking artifact; the group remained visibly active late in the U.S. window.[1][3][5]

  13. Open-source technical signals

    ThreatFox and OTX surface current ransomware payload and infrastructure evidence

    ThreatFox’s seven-day API response includes 77 INC ransomware MD5 payload hashes and two BianLian command-and-control IP-and-port indicators. Across the 50 most recently returned subscribed OTX pulses, five ransomware-related pulses contain 70 indicators involving Prinz Eugen, a possible ransomware access broker, provisional data-extortion activity, Chaos msaRAT, and JADEPUFFER. These records create concrete hunt material while remaining separate from victim claims and incident attribution.[9][10][11][12][13][14][15]

  14. New-label surge

    Global Secret Group and ExfilSquad dominate the latest daily population

    The collector’s edition view records 25 claims first discovered on July 26: 12 under Global Secret Group and nine under ExfilSquad, with DragonForce adding two. Both leading labels remain provisional in the canonical alignment, so the meaningful conclusion is a sharp new-label surge—not confident attribution to an established actor family.[1][5]

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

  • Trend verdict: visible pressure is increasing; encryption and demand direction are not yet measurable; paid amounts are mixed: GuidePoint recorded 2,279 global public victim posts in Q2, up 7% from Q1. The current U.S. tracker records do not disclose successful encryption or initial demands, and no comparable Q2 U.S. SMB casework is yet available. In the newest adjacent-quarter casework, Coveware's Q1 average payment rose 15% from Q4 to $680,081 while the median fell 7% to $300,750. That means ransomware visibility is up, but it is not defensible to say U.S. SMB encryption or ransom demands increased.[17][18][19]First cited source Apr 30, 2026 · Latest cited source Jul 9, 2026

  • The 90-day window shows broad U.S. pressure with a meaningful sector concentration: The population includes ransomware.live records whose discovered date falls from April 28 through July 26, 2026, inclusive—exactly 90 UTC calendar days. At the edition’s agent-run time it contained 789 U.S. victim claims across 73 group labels; later collector backfills, removals, or reclassification can change a subsequent run over the same dates.[1]Evidence dated Jul 26, 2026

  • Qilin led the U.S. 90-day view even though The Gentlemen led a separate global June view: Qilin, The Gentlemen, and INC Ransom accounted for 243 U.S. claims, or 30.8% of this card’s 90-day population, with Qilin first at 122. Check Point separately placed The Gentlemen first in its worldwide June dataset. The rankings do not conflict because the geography, period, and collection methods differ. Treat both as watch priorities—not incident attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

  • Cross-collector agreement is strong enough to support direction, not incident confirmation: RansomLook also observed 681 of the 789 ransomware.live group-and-victim combinations, an 86.3% overlap. The result raises confidence that the posts existed while leaving the claimed intrusion, impact, and company size unconfirmed.[1][2]Evidence dated Jul 26, 2026

  • SMB is a defined decision lens—not an inferred victim count: Small follows the applicable SBA NAICS size standard, generally based on employees or average annual receipts and including affiliates. No single federal midsize threshold applies, so midsize is an operating-audience label. Because the trackers lack authoritative firmographics, this edition reports zero verified SMB classifications.[1][6]Evidence dated Jul 26, 2026

  • Technical and access-precursor sources add hunt context without altering the victim picture: ThreatFox returned 77 recent INC ransomware payload hashes and two BianLian command-and-control endpoints. Five recent OTX pulses contributed 70 additional indicators. Hudson Rock Cavalier is planned for infostealer-derived credential and domain exposure once authenticated. Validate every signal against local exposure; none changes victim metrics or confirms a named incident.[9][10][11][12][13][14][15][16]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026

  • The immediate management priority is recoverability under identity and infrastructure loss: SMBs should protect administrative access, remove unnecessary Internet-facing management, separate backup identities, monitor staging and egress, and prove restoration when production identity, virtualization, or provider access is unavailable.[4][7][8]First cited source May 13, 2026 · Latest cited source Jun 8, 2026

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

The first management question now has an explicit answer. Publicly visible ransomware pressure increased: GuidePoint counted 2,279 global victim posts in Q2 2026, 7% more than Q1's 2,135. Successful encryption and initial ransom-demand direction remain indeterminate for U.S. SMBs because ransomware.live and RansomLook do not carry those outcome fields and no completed Q2 casework source provides a comparable SMB-specific denominator. The card will not substitute leak-site volume for encryption or demand.[1][2][18]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

The newest adjacent-quarter casework shows mixed economics rather than a uniform increase. Coveware reported that the average paid ransom increased 15% from Q4 2025 to Q1 2026, reaching $680,081, while the median paid ransom decreased 7% to $300,750 and the payment rate ticked up slightly to 23%. The divergent average and median indicate that a smaller number of severe cases can pull the mean upward while the more typical paid case moves down. These are paid amounts in Coveware-managed cases—not initial demands and not a U.S. SMB census.[17]Evidence dated Apr 30, 2026

Arete's Q1 casework supplies the newest retained demand benchmark but not a clean quarter-over-quarter result: its $571,000 median demand was about 5% below the $600,000 full-year 2025 median and about 14% above the $500,000 Q1 2025 baseline. Until Arete, Coveware, or another comparable responder publishes Q2 demand and encryption outcomes, the correct labels are “direction not yet measurable” for demand and successful encryption—not “flat.”[19]Evidence dated Jun 3, 2026

This edition covers April 28 through July 26, 2026—90 UTC calendar days inclusive. The primary population includes ransomware.live records by the date the service first discovered the listing, not the estimated attack date. RansomLook matches must also carry a discovered date inside the same window. Within that boundary, ransomware.live recorded 789 U.S. victim claims across 73 group labels.[1][2]Evidence dated Jul 26, 2026

Small-business status follows the applicable SBA NAICS size standard, which generally uses employee count or average annual receipts and includes affiliates. There is no single federal midsize threshold, so this card uses midsize as an operating-audience label rather than a firmographic classification. The tracker records do not supply sufficient authoritative size data; consequently, the edition reports zero verified SMB victims.[1][6]Evidence dated Jul 26, 2026

The clearest business pattern is sector concentration. Professional services accounted for 197 claims, healthcare 111, manufacturing 98, technology 86, and retail and e-commerce 74. Together, those sectors represent 566 claims, or 71.7% of the observed population. For SMB leaders, the practical implication is exposure to downtime and client disruption through shared systems, remote administration, sensitive data, operational technology, payments, and third-party dependencies.[1]Evidence dated Jul 26, 2026

Actor visibility also concentrated without becoming narrow. Qilin accounted for 122 U.S. claims, The Gentlemen 63, and INC Ransom 58; together they represented 30.8% of this card’s rolling-window population, while 70 other labels made up the remaining 69.2%. Check Point’s separate worldwide June dataset placed The Gentlemen first; that is a complementary global momentum signal, not a contradiction or a number to add to this population. IntelliOS resolved 760 of 789 claims to canonical Actor Cards while preserving the rule that a tracker label alone does not establish attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

The strongest evidence conclusion is qualified confidence. RansomLook also observed 681 of the 789 group-and-victim combinations, an 86.3% overlap that supports the existence of most public posts. It does not confirm the underlying intrusion. Separately, a seven-day ThreatFox query returned 79 ransomware-tagged indicators and five current OTX pulses supplied 70 technical indicators. The next planned precursor source is Hudson Rock Cavalier for infostealer-derived credential, session, domain, and third-party exposure. It has not been queried for this edition; when enabled, it remains a hunt and exposure input—not an addition to victim totals or confirmation of a named incident.[1][2][9][10][11][12][13][14][15][16]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026

The executive response should therefore focus on reducing recoverability leverage rather than chasing every public name. Protect administrative and remote access with phishing-resistant controls, remove unnecessary Internet-facing management, isolate backup identities and infrastructure, monitor pre-encryption staging and egress, constrain service-provider trust, and test restoration with production identity, virtualization, and normal network paths unavailable. Leadership should also pre-authorize containment, communications, legal, insurance, and customer decisions before an extortion event compresses the timeline.[4]Evidence dated Source date not published

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Do not collapse activity, encryption, demands, and payments into one trendGlobal public victim posts increased 7% from Q1 to Q2, while adjacent-quarter Coveware payment data was mixed and neither retained tracker provides U.S. SMB encryption or demand outcomes. Executives should require a separate direction, denominator, period, and source for each measure.[1][2][17][18][19]First cited source Apr 30, 2026 · Latest cited source Jul 26, 2026

  2. 2

    789 U.S. victim claims were observed in the rolling windowThis is the visible claim population from ransomware.live for April 28–July 26, not a confirmed breach count. Use it to understand pressure and concentration, not to estimate national incident prevalence.[1]Evidence dated Jul 26, 2026

  3. 3

    Professional services carried the largest visible shareProfessional services accounted for 197 claims—about one quarter of the U.S. total. Firms with shared client data, remote administration, and deadline-driven operations should treat identity and recovery readiness as business controls.[1]Evidence dated Jul 26, 2026

  4. 4

    Healthcare and manufacturing add 209 continuity-sensitive claimsHealthcare contributed 111 claims and manufacturing 98. Both sectors can face immediate operational harm when identity, scheduling, production, clinical, or recovery systems become unavailable.[1]Evidence dated Jul 26, 2026

  5. 5

    Technology and retail complete the leading concentrationTechnology recorded 86 claims and retail and e-commerce 74. The combined pattern puts SaaS administration, customer data, payment operations, and third-party access on the immediate review list.[1]Evidence dated Jul 26, 2026

  6. 6

    Qilin led the U.S. claim setQilin accounted for 122 claims, or roughly 15% of the rolling-window population. Open the canonical Qilin Actor Card for retained aliases and behaviors, but require local or authoritative evidence before using the name in incident attribution.[1][5]Evidence dated Jul 26, 2026

  7. 7

    The Gentlemen and INC Ransom remain material watch prioritiesThe Gentlemen accounted for 63 claims and INC Ransom 58. Their combined volume makes changes in their access model, affiliate behavior, or leak infrastructure operationally relevant to SMB defenders.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

  8. 8

    Cross-collector agreement is high but not completeRansomLook also observed 681 of the 789 group-and-victim combinations, an 86.3% overlap. That strengthens confidence that the posts existed while leaving the claimed intrusion itself unconfirmed.[1][2]Evidence dated Jul 26, 2026

  9. 9

    Canonical Actor Cards cover 96.3% of observed claim volumeSixty-seven of 73 group labels, representing 760 of 789 claims, resolve to an IntelliOS Threat Actor Card. The six unmatched labels remain provisional instead of becoming silent duplicate or unsupported actor records.[1][5]Evidence dated Jul 26, 2026

  10. 10

    Company size is unverified for every tracker recordNeither employee count nor revenue is a dependable field in the retained victim records. This card focuses on SMB-relevant sectors and decisions and will not convert U.S. claims into an unsupported SMB victim count.[1]Evidence dated Jul 26, 2026

  11. 11

    Open-source feeds add 149 current hunt indicators without adding a single victimThreatFox returned 79 ransomware-tagged indicators in its seven-day query, and five recent OTX pulses contributed 70 indicators. Use the hashes, domains, URLs, IP addresses, and related artifacts for local matching, enrichment, and carefully validated blocking; do not interpret the total as incidents, victims, or group prevalence.[9][10][11][12][13][14][15]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationAll U.S. organizations named in the active tracker window[1][2]Evidence dated Jul 26, 2026SectorsCross-industry; 789 claims across the retained sector taxonomyGeographyUnited StatesConfirmation statusActor-published or collector-observed victim claims; not independently confirmed incidentsHow companies should use itUse the population to assess concentration and defensive priorities. Do not use it as a national incident rate or confirmed-victim census.
Victim / exposure populationProfessional-services organizations[1]Evidence dated Jul 26, 2026SectorsProfessional services — 197 claims, 25.0% of the observed populationGeographyUnited StatesConfirmation statusTracker sector label and victim claim; company size and intrusion status remain unverifiedHow companies should use itPrioritize client-data access, shared repositories, remote administration, deadline-critical workflows, and provider trust. Test whether the firm can serve clients while identity or core systems are unavailable.
Victim / exposure populationHealthcare organizations[1]Evidence dated Jul 26, 2026SectorsHealthcare — 111 claims, 14.1%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; not a confirmed breach or patient-impact countHow companies should use itValidate clinical and scheduling continuity, identity recovery, protected-data response, downtime procedures, and third-party notification paths.
Victim / exposure populationManufacturing organizations[1]Evidence dated Jul 26, 2026SectorsManufacturing — 98 claims, 12.4%GeographyUnited StatesConfirmation statusTracker sector label and victim claim; operational disruption is not established for every listingHow companies should use itProtect production scheduling, plant connectivity, engineering data, remote vendor access, virtualization, and recovery dependencies that can stop physical operations.
Victim / exposure populationTechnology, retail, and e-commerce organizations[1]Evidence dated Jul 26, 2026SectorsTechnology — 86 claims; retail and e-commerce — 74 claimsGeographyUnited StatesConfirmation statusTracker classifications totaling 160 claims; individual incident facts remain unverifiedHow companies should use itScope SaaS administration, customer and payment data, cloud identities, software delivery, storefront availability, and third-party access together.
Victim / exposure populationOrganizations that may qualify as small or midsize businesses[1][6]Evidence dated Jul 26, 2026SectorsAll retained sectorsGeographyUnited StatesConfirmation statusZero tracker records are treated as verified SMB classifications because authoritative employee, revenue, affiliation, and NAICS evidence is absentHow companies should use itApply the applicable SBA NAICS size standard for small-business status. Treat midsize as an operating-audience lens unless a separate documented threshold and authoritative firmographics are available.

Distinct Operational Records

Ransomware Threat Actors & Operations

Qilin leads the U.S. claim population

Qilin accounted for 122 claims, or 15.5% of the rolling-window population. Use the linked canonical Actor Card to review aliases and source-backed behaviors, while requiring local evidence before attributing an incident.[1][5]Evidence dated Jul 26, 2026

The Gentlemen combines material U.S. visibility with current operating context

The Gentlemen accounted for 63 U.S. claims. Check Point’s separate research describes a fast-scaling ransomware operation and supplies operating context; its dataset is not added to the 789-claim U.S. total.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026

INC Ransom remains a material watch priority

INC Ransom accounted for 58 claims in the active window. The source label is useful for watchlisting and connected intelligence, not incident attribution without local or authoritative confirmation.[1][5]Evidence dated Jul 26, 2026

The long tail remains larger than the leading groups

Seventy other labels accounted for 546 claims, or 69.2% of the observed population. Defenders need control-based readiness that survives affiliate movement, rebrands, and groups that never reach the top-three list.[1][5]Evidence dated Jul 26, 2026

Current Group Labels, Canonical Identities, and Decision Use

Threat Actor Glossary

The ten leading source labels in this edition, ranked by observed U.S. claims and linked to governed Actor Cards. Counts measure published claims inside the coverage window—not confirmed incidents, unique operators, successful encryptions, or verified SMB victims.

Window measureResultHow to read it
Observed claims789Publicly posted victim claims; not confirmed incidents.
Source labels73Distinct group names present in the coverage window.
Aligned labels67/736 labels remain provisional.
Aligned claim volume96.3%760 claims link to governed Actor Cards.
Top-three concentration30.8%243 observed claims.
Top-ten concentration59.6%470 observed claims.
Actor / source labelActivity in this windowSource-backed assessmentAttribution boundary / defender use
1

Source label: qilin

Qilin

122 (15.5%)

Canonical match

The largest single source label in the window, but still only about one-sixth of observed claims; the landscape is not dominated by one brand.[1][5]Prioritize Qilin intelligence and watchlist changes, then require local evidence before using the name in incident attribution.
2

Source label: thegentlemen

The Gentlemen

63 (8.0%)

Canonical match

The second-largest U.S. source label. Check Point separately describes a fast-scaling operation, adding operating context without changing this card’s API-derived total.[1][3][5]Track changes in access, affiliate, and leak-site behavior; keep Check Point’s separate dataset methodologically distinct.
3

Source label: incransom

INC Ransom

58 (7.4%)

Canonical match

Completes a top-three cluster responsible for 243 claims, or 30.8% of the rolling population.[1][5]Use the Actor Card for aliases and connected reporting, but never infer INC attribution from a tracker post alone.
4

Source label: akira

Akira

43 (5.4%)

Canonical match

The first group outside the leading cluster and large enough to remain a material watch priority on its own.[1][5]Keep Akira-specific intelligence available to responders while maintaining control-based readiness across all groups.
5

Source label: dragonforce

DragonForce

35 (4.4%)

Canonical match

Part of the middle concentration tier where several similarly sized brands collectively matter more than any individual ranking change.[1][5]Monitor branding, affiliate, and infrastructure changes; do not treat brand continuity as proof of operator continuity.
6

Source label: payoutsking

PayoutsKING

34 (4.3%)

Canonical match

Nearly tied with DragonForce and Genesis, showing why ordinal rank alone can exaggerate small differences between groups.[1][5]Use claim count and share together; avoid interpreting a one-position move as a material threat change without supporting evidence.
7

Source label: genesis

Genesis

33 (4.2%)

Canonical match

One of three adjacent labels separated by only two claims, reinforcing that the middle tier should be treated as a cluster.[1][5]Route the source label to the canonical record and watch for aliases or reclassification before creating new identities.
8

Source label: shinyhunters

ShinyHunters

30 (3.8%)

Canonical match

The tracker label resolves to a governed Actor Card, but a canonical name match does not prove the operator behind a particular victim claim.[1][5]Use the link for source-backed context and relationships; require victim, official, or local evidence for incident attribution.
9

Source label: play

Play

28 (3.5%)

Canonical match

Remains inside the top ten while representing only a small fraction of the overall population, illustrating the fragmented market.[1][5]Retain Play-specific detection and response context without narrowing the ransomware program to the current leaderboard.
10

Source label: pear

Pear

24 (3.0%)

Canonical match

Closes a top-ten group accounting for 470 claims, or 59.6% of the window; the remaining 319 claims span 63 other labels.[1][5]Treat the top ten as a prioritization aid, not an allowlist: the long tail still represents 40.4% of observed claims.

How to read actor language

TermMeaning in this card
Source labelThe group name exactly as supplied by the collector. It is preserved even when IntelliOS maps it to a different canonical spelling.
Canonical actorThe governed IntelliOS identity used to consolidate known spellings and aliases. A match improves navigation and watchlist quality; it does not prove attribution.
RaaS brandA ransomware-as-a-service identity may represent shared infrastructure, rules, tooling, or branding used by multiple affiliates rather than one fixed intrusion team.
AffiliateAn operator or crew using a ransomware program or brand. Affiliates can change brands, access methods, and targets, so brand-level behavior should not be applied automatically to every incident.
Observed claimA victim name or post collected from an extortion source. It shows that a claim was published—not that the intrusion, actor, timing, scope, or impact was independently confirmed.
Provisional labelA source name without a deterministic canonical or retained-alias match. It remains separate until reviewed evidence supports a merge or a new governed Actor Card.

Attribution rule: A tracker label, canonical match, affiliate association, infrastructure overlap, or second collector may justify investigation. None alone establishes who compromised a named organization.[1][2][5]

Enterprise Exposure

Affected Technologies & Trust Boundaries

Remote access and administrative control planes

VPNs, remote-support systems, management interfaces, and privileged administration can turn one stolen or exposed access path into broad operational reach. Inventory them, require phishing-resistant access, and retain session and administrator telemetry.[3][4]Evidence dated Jul 9, 2026

Identity, sessions, and service accounts

Passwords are only one access artifact. Privileged sessions, tokens, enrolled authentication methods, dormant accounts, and service identities must be reviewable and rapidly revocable during containment.[3][4]Evidence dated Jul 9, 2026

Backup repositories and recovery orchestration

Recovery systems that share production identities or management paths may fail when needed most. Separate identities, isolate copies, monitor destructive administration, and prove restoration under production identity loss.[4]Evidence dated Source date not published

Virtualization and shared infrastructure

Hypervisors, storage, domain services, and shared management systems concentrate business impact. Treat administrative changes, mass shutdown, snapshot deletion, and unusual host access as recovery-critical signals.[3][4]Evidence dated Jul 9, 2026

MSP and third-party management tooling

Provider credentials and shared remote-management paths can extend a compromise across tenants or downstream customers. Require named access, isolation, complete logs, an emergency disable path, and joint response procedures.[3][4]Evidence dated Jul 9, 2026

Data staging, archives, and outbound transfer

Extortion pressure often depends on data theft before encryption. Monitor bulk reads, archive creation, unapproved cloud storage, large encrypted egress, and new transfer utilities as early containment opportunities.[4]Evidence dated Source date not published

Non-Victim Technical Evidence Lane

Access, Exposure, and Infrastructure Precursors

A separate evidence lane for malicious infrastructure, active exploitation, and credential or session exposure that may precede ransomware access. It supports local validation, hunting, and defensive prioritization; it is not a ransomware-victim dataset.

The seven-day API query returned 79 ransomware-tagged indicators: 77 INC ransomware MD5 payload hashes and two BianLian command-and-control IP-and-port records. This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence.[9]

Operational use: Match retained hashes and network endpoints against endpoint, proxy, DNS, firewall, and historical telemetry. Re-check status and context before blocking because infrastructure and indicator confidence can change.

Five ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 70 indicators: 17 for Prinz Eugen, 42 for a possible ransomware access broker, four for provisional data-extortion activity, two for Chaos msaRAT, and five for JADEPUFFER.[10][11][12][13][14][15]

Operational use: Use pulse context to prioritize local IOC matching and pivot to the cited pulse before containment. Preserve provisional language and never use pulse overlap to confirm a named victim or actor attribution.

Once authenticated, the read-only publisher can query infostealer-derived employee, domain, third-party, credential, session, and infection exposure relevant to common ransomware access paths. No Hudson Rock account data was queried for this edition.[16]

Operational use: Use exposure results to identify credentials, sessions, remote-access portals, and third-party trust paths that require local validation, rotation, revocation, or investigation. Never treat a stealer record as proof of ransomware access or a confirmed victim.

Hard boundary: ThreatFox, OTX, and Hudson Rock signals never increase ransomware victim totals, never corroborate a named victim claim, and never establish ransomware attribution by themselves. A signal is retained only when it is current, technically actionable, and source-linked; any claimed overlap with a victim or actor requires separate authoritative or local evidence.

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Identity

Remote and administrative access[3][4]Evidence dated Jul 9, 2026

Why it mattersStolen or reused access can move an incident past perimeter controls before defenders see encryption.What to monitorNew VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, privilege elevation, and unexplained service-account activity.IntelliOS coverage
2Threat / Category

Recovery

Backup and virtualization control planes[3][4]Evidence dated Jul 9, 2026

Why it mattersAttackers gain leverage when recovery systems share production identities or administrative paths.What to monitorRetention changes, repository deletion, new backup administrators, SSH enablement, mass VM shutdown, and failed restore tests.IntelliOS coverage
3Threat / Category

Third party

MSP and shared-service trust[3][4]Evidence dated Jul 9, 2026

Why it mattersA compromised provider credential or management platform can expand one intrusion into multiple SMB environments.What to monitorCross-tenant anomalies, shared accounts, remote-management changes, provider notices, and unusual customer-specific access.IntelliOS coverage
4Threat / Category

Pre-encryption

Staging and outbound transfer[3][4]Evidence dated Jul 9, 2026

Why it mattersData theft often precedes encryption and public pressure.What to monitorArchive creation, bulk file reads, unapproved cloud storage, unusual S3 transfers, compression tools, and large encrypted egress.IntelliOS coverage
5Threat / Category

Evidence

Claim confirmation workflow[1][2]Evidence dated Jul 26, 2026

Why it mattersA tracker post should trigger verification, not an automatic breach declaration.What to monitorVictim disclosure, regulatory notice, filing, law-enforcement statement, forensic evidence, extortion contact, and retained source changes.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

Six operating practices translate the 90-day evidence into controls an SMB can implement, rehearse, and prove. The lesson identifies the failure mode; the minimum operating standard states the evidence leadership should expect.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]

SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]

  1. 1

    Best Practice

    Make privileged and remote administration phishing-resistant[3][4]Evidence dated Jul 9, 2026

    Lesson Learned

    Group brands and affiliates change, but stolen or replayed administrative access remains a durable path to rapid business impact. Ordinary user MFA and shared administrator accounts leave too much reusable trust.

    Minimum Operating Standard

    Cover every privileged, remote-management, backup, virtualization, and MSP administrator with phishing-resistant authentication; eliminate shared accounts; require named, time-bounded elevation; review access quarterly; and retain proof of emergency session revocation.

  2. 2

    Best Practice

    Prove recovery without production identity or network dependencies[4]Evidence dated Source date not published

    Lesson Learned

    A backup is not a recovery capability when the same compromised identities, management plane, DNS, virtualization stack, or network path is required to restore it.

    Minimum Operating Standard

    Maintain separate recovery identities and at least one isolated or immutable copy; document break-glass access; test representative restores quarterly with production identity and normal network paths unavailable; and record achieved RTO, RPO, integrity checks, exceptions, and remediation owners.

  3. 3

    Best Practice

    Constrain provider access to the smallest reversible trust path[3][4]Evidence dated Jul 9, 2026

    Lesson Learned

    SMBs often depend on MSPs and shared administration. One provider credential, remote-management tool, or cross-tenant workflow can expand a single compromise into customer environments.

    Minimum Operating Standard

    Use named provider accounts, tenant isolation, least privilege, approved support windows, complete logging, and an emergency disable path. Reconcile provider access monthly and run an annual joint exercise that includes evidence exchange, containment authority, customer notification, and restoration.

  4. 4

    Best Practice

    Detect and contain the pre-encryption sequence[3][4]Evidence dated Jul 9, 2026

    Lesson Learned

    Archive creation, bulk file access, unusual egress, remote-tool changes, privilege escalation, and backup administration can provide a decision window before encryption or public extortion.

    Minimum Operating Standard

    Operate alerts for data staging, outbound transfer, new remote tools, privileged-account changes, and backup or hypervisor tampering; assign a 24/7 decision owner; preserve evidence automatically; and demonstrate in exercises that high-confidence activity can be contained within the organization’s defined response target.

  5. 5

    Best Practice

    Pre-authorize the ransomware decision chain[4]Evidence dated Source date not published

    Lesson Learned

    Containment, shutdown, insurer notice, legal privilege, customer communications, and restoration decisions stall when authority is first negotiated during the incident.

    Minimum Operating Standard

    Maintain a one-page decision matrix with primary and after-hours owners, financial and operational thresholds, insurer and counsel contacts, law-enforcement criteria, communications approval, and explicit authority for disruptive containment. Exercise it at least twice yearly and close documented decision gaps.

  6. 6

    Best Practice

    Separate public claims, technical signals, and confirmed incidents in operations[1][2]Evidence dated Jul 26, 2026

    Lesson Learned

    A leak-site post, a second collector, an Abuse.ch or OTX indicator, and local forensic evidence answer different questions. Combining them creates false victim counts, weak attribution, and wasted response effort.

    Minimum Operating Standard

    Every alert records an evidence state, controlling source, local exposure result, owner, next validation step, and deadline. Infrastructure signals may drive blocking or hunting but cannot increase victim totals; a named incident requires victim, official, filing, or defensible local evidence.

Who Contributed What

Source Contributions & Decision Role

Each source has a defined job in this edition. Collection, corroboration, operating context, defensive guidance, actor-name resolution, and the SMB definition remain separate so one source is never stretched beyond the evidence it actually supplies.

Contributorransomware.live

Ransomware.live Pro API — U.S. victim claims observed during the rolling window

ContributionSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1]Decision useMeasure visible claim pressure and concentration; trigger organization-level validation when a relevant name or pattern appears.Evidence boundaryDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current.
ContributorRansomLook

RansomLook recent posts API — independent collector reconciliation

ContributionProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2]Decision useIdentify cross-collector agreement and isolate records that need additional reconciliation.Evidence boundaryA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status.
ContributorCheck Point Research

A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

ContributionAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3]Decision useExplain why concentrated group activity matters and turn specific operating observations into monitoring questions.Evidence boundaryIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals.
ContributorCybersecurity and Infrastructure Security Agency

#StopRansomware Guide

ContributionSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4]Decision useSet the operational response baseline for identity protection, exposed services, backups, containment, evidence, and recovery.Evidence boundaryDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident.
ContributorIntelliOS

IntelliOS Threat Actor Cards

ContributionNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5]Decision usePrevent fragmented watchlists and route readers from a source label to the best available actor context.Evidence boundaryAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident.
ContributorU.S. Small Business Administration

Small Business Size Standards

ContributionControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6]Decision useDefine the intended small-business audience and prevent unsupported firmographic classification of tracker-listed organizations.Evidence boundaryProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record.
ContributorCheck Point Research

When the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk

ContributionDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7]Decision useTurn a group name into concrete exposure questions about edge patching, purchased credentials, infostealer logs, session theft, Active Directory abuse, EDR resilience, backup isolation, and client-connected accounts.Evidence boundaryThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total.
ContributorCheck Point Research

Active exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments

ContributionSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8]Decision usePrioritize exposure validation, hotfixing, IKEv1 retirement, log review, and threat hunting where the affected remote-access configuration exists.Evidence boundaryThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims.
Contributorabuse.ch / Spamhaus

ThreatFox Community API — recent ransomware-tagged indicators

ContributionQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9]Decision useDrive endpoint, network, DNS, proxy, and historical telemetry matching against fresh, source-linked technical artifacts.Evidence boundaryIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking.
ContributorAlienVault Open Threat Exchange

AlienVault OTX subscribed-pulse API — recent ransomware-related pulses

ContributionQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10]Decision usePrioritize emerging ransomware, access-broker, data-extortion, and specialized targeting hypotheses for local IOC matching and follow-up research.Evidence boundaryPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions.

Claim-Specific Evidence Authority

Source Weighting / Relevance

Weight is claim-specific, not a universal publisher score. An official source can control response guidance or the SMB definition while contributing nothing to current victim totals; an API can control measured claim volume while remaining unable to confirm an incident.

Sourceransomware.liveWeightHighRelevancePrimary quantitative claim sourceWhat it can supportSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1]LimitationDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current.
SourceRansomLookWeightHigh for post observationRelevanceIndependent collection checkWhat it can supportProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2]LimitationA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status.
SourceCheck Point ResearchWeightHigh for operating contextRelevanceIndependent threat researchWhat it can supportAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3]LimitationIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals.
SourceCybersecurity and Infrastructure Security AgencyWeightVery High for defensive guidanceRelevanceOfficial response authorityWhat it can supportSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4]LimitationDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident.
SourceIntelliOSWeightHigh for identity resolutionRelevanceGoverned internal alignmentWhat it can supportNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5]LimitationAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident.
SourceU.S. Small Business AdministrationWeightVery High for the SMB boundaryRelevanceOfficial firmographic definitionWhat it can supportControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6]LimitationProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record.
SourceCheck Point ResearchWeightHigh for documented tradecraftRelevancePrimary leaked-operation analysisWhat it can supportDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7]LimitationThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total.
SourceCheck Point ResearchWeightHigh for the affected-product findingRelevancePrimary exploitation telemetryWhat it can supportSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8]LimitationThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims.
Sourceabuse.ch / SpamhausWeightHigh for retained IOC factsRelevanceCurrent technical hunt feedWhat it can supportQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9]LimitationIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking.
SourceAlienVault Open Threat ExchangeWeightModerate to High for discoveryRelevanceCommunity and provider pulse contextWhat it can supportQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10]LimitationPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions.
Decision rule: ransomware.live controls observed claim totals; RansomLook controls only cross-collector observation; CISA controls defensive guidance; SBA controls the small-business definition; Check Point controls only its own research observations; and IntelliOS Actor Cards control internal name resolution. None independently confirms a named ransomware incident.

Automation Transparency

AI Agent Run Status

AgentU.S. SMB Ransomware Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceDaily at midday ET; publish only when claim volume, concentration, corroboration, or group alignment changes materially
Previous run26-Jul-2026 · midday ET · Run ACT-US-SMB-RANSOM-20260726-1215
Previous resultPublished the quarter-over-quarter trend lane while preserving explicit outcome-data gaps.
What the previous run found
  • Global public victim-post pressure increased 7% from Q1 to Q2
  • Successful-encryption and initial-demand direction remain not yet measurable for U.S. SMBs
  • Coveware Q4-to-Q1 paid amounts were mixed: average up 15%, median down 7%
  • 789 U.S. claims retained
  • 681 cross-collector matches
  • 73 group labels normalized
  • ThreatFox retained 79 current ransomware-tagged hunt indicators
  • OTX retained five cited pulses with 70 technical indicators
  • SMB size remained unverified and was not inferred
Next run27-Jul-2026 · midday ET
Sources monitored
  • ransomware.live Pro API
  • RansomLook public posts API
  • Coveware quarterly casework
  • Arete Crimeware Reports
  • GuidePoint GRIT quarterly reports
  • ThreatFox Community API
  • AlienVault OTX subscribed-pulse API
  • Hudson Rock Cavalier MCP (planned; awaiting API key)
  • IntelliOS Threat Actor Cards
  • U.S. Small Business Administration NAICS size standards
  • Retained official and primary ransomware research
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyAlert for a material change in public victim-post pressure, successful-encryption incidence, initial demands, paid amounts, payment propensity, concentration, corroboration, or evidence state. Suppress routine additions, date-only movement, and no-change runs.

Related Intelligence and CARDS Records

Other IntelliOS Products

Intelligence Alignment

Ransomware Group Alignment Engine

Deterministic canonical, alias, source-alias, and reviewed-override matching across tracker labels and IntelliOS Threat Actor Cards.

Open product

Threat Actor Cards

Canonical Ransomware Group Watchlist

Resolved group names, aliases, confidence, behaviors, and related IntelliOS intelligence.

Open product

Rolling Intelligence

Global Ransomware Landscape

Broader global ransomware ecosystem, initial-access, operator, and recovery context. Its worldwide and source-specific measures remain separate from this U.S. claim population.

Open product

CARDS Actor Record

Qilin Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Thegentlemen Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

INC Ransom Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Akira Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Payoutsking Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Dragonforce Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Genesis Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Shinyhunters Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Play Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

Pear Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Campaign Record

The Gentlemen RAAS Operations Campaign Card

Connected campaign intelligence, activity timeline, affected technologies, actors, techniques, and source boundaries.

Open product

Publication History

Version Change Log

Versionv9Date26-Jul-2026ChangeMade the quarter-over-quarter ransomware direction the lead management question. Added separate verdicts and snapshot measures for public victim-post pressure, successful encryption, initial demands, paid amounts, and payment propensity; retained GuidePoint Q2, Coveware Q1, and Arete Q1 as methodologically separate sources; and labeled unavailable Q2 encryption and demand outcomes as not yet measurable rather than flat.MonitoringDaily claim monitoring; publish direction changes when comparable casework becomes available
Versionv8Date26-Jul-2026ChangeAdded an explicit product boundary with the Global Ransomware Landscape card. Clarified why Qilin can lead this 90-day U.S. dataset while The Gentlemen leads a separate worldwide June dataset, and prohibited combining the two products’ counts or rankings.MonitoringDaily material-change review
Versionv7Date26-Jul-2026ChangeRemoved an unused planned enterprise exploitation-context integration and its citation, precursor-lane, source-run, and agent-plan references.MonitoringContinue the retained and authenticated source plan
Versionv6Date26-Jul-2026ChangeDefined the read-only Hudson Rock Cavalier MCP integration for the SMB ransomware product. Added it to Citations, the precursor evidence lane, source-run dispositions, and the agent source plan while explicitly excluding it from victim totals, victim corroboration, and standalone incident attribution. The source was not queried for this edition.MonitoringActivate Hudson Rock after a valid API key is configured
Versionv5Date26-Jul-2026ChangeExpanded the automated source set beyond victim trackers. Added authenticated ThreatFox and OTX queries, retained 149 current technical indicators in the separate Active Infrastructure and Precursors lane, linked every finding to controlling citations, and preserved the prohibition against using infrastructure signals to increase victim totals or confirm incidents.MonitoringDaily material-change review
Versionv4Date26-Jul-2026ChangeRebuilt the timeline as a compact, intelligence-led chronology of ransomware posting bursts, actor rotation, exposed RaaS operations, and active edge-device exploitation. Removed internal reconciliation and identity-resolution milestones from the chronology and added source-bounded Check Point research without changing victim totals.MonitoringDaily material-change review
Versionv3Date26-Jul-2026ChangeAdded a comprehensive Threat Actor Glossary covering the ten leading source labels, canonical Actor Card resolution, claim count and share, decision-relevant facts, attribution limits, and glossary definitions. The card also summarizes top-three, top-ten, long-tail, aligned, and unresolved actor statistics.MonitoringDaily material-change review
Versionv2Date26-Jul-2026ChangeAdded Source Contributions and Source Weighting / Relevance cards. Defined the separate decision roles and evidence limits for ransomware.live, RansomLook, Check Point Research, CISA, IntelliOS Threat Actor Cards, and SBA size standards without changing victim totals or confirmation states.MonitoringDaily material-change review
Versionv1Date26-Jul-2026ChangeCreated the U.S. SMB ransomware rolling card with cross-collector reconciliation, explicit SMB-size limits, sector concentration, canonical actor links, and practical SMB decisions.MonitoringDaily material-change review

Citations

Retained Sources and Claim Treatment

Source1Publisherransomware.livePublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentLeak-site and extortion-tracker observations. A listed organization is an actor claim, not an independently confirmed intrusion; the API does not establish company size.SourceRansomware.live Pro API — U.S. victim claims observed during the rolling window

https://api-pro.ransomware.live/docs

Source2PublisherRansomLookPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentA second collector can corroborate that a post was observed, but shared appearance across collectors still does not confirm the underlying intrusion.SourceRansomLook recent posts API — independent collector reconciliation

https://www.ransomlook.io/doc/

Source3PublisherCheck Point ResearchPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentVendor analysis of ransomware data-leak-site activity and operating context; published attacks remain actor claims unless separately confirmed.SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide

https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/

Source4PublisherCybersecurity and Infrastructure Security AgencyPublishedNot availablePublication / evidenceSource indexofficialWhy used / claim treatmentStanding defensive guidance used for practical prevention, containment, evidence-preservation, and recovery decisions; it does not control current victim-count claims.Source#StopRansomware Guide

https://www.cisa.gov/stopransomware/ransomware-guide

Source5PublisherIntelliOSPublished2026-07-26Publication / evidenceSource indexprimary researchWhy used / claim treatmentCanonical identity and alias directory used to link tracker labels to source-backed actor cards. A name match does not establish incident attribution.SourceIntelliOS Threat Actor Cards

/threat-actor-cards

Source6PublisherU.S. Small Business AdministrationPublishedNot availablePublication / evidenceSource indexofficialWhy used / claim treatmentControlling definition for the card’s small-business boundary. SBA size standards vary by NAICS industry and generally use employee count or average annual receipts, including affiliates. The source does not define one universal midsize threshold.SourceSmall Business Size Standards

https://www.sba.gov/federal-contracting/contracting-guide/size-standards

Source7PublisherCheck Point ResearchPublished2026-05-13Publication / evidenceSource indexprimary researchWhy used / claim treatmentPrimary vendor analysis of leaked internal material describing The Gentlemen’s operating model, access paths, tooling, affiliate economics, and victim-chain reuse. It does not independently confirm every actor or victim claim in the leaked material.SourceWhen the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk

https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/

Source8PublisherCheck Point ResearchPublished2026-06-08Publication / evidenceSource indexprimary researchWhy used / claim treatmentVendor incident and product telemetry describing active exploitation beginning May 7 and a medium-confidence association with a financially motivated actor using Qilin ransomware. It does not establish that every Qilin claim used this vulnerability.SourceActive exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments

https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/

Source9Publisherabuse.ch / SpamhausPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentSeven-day API query of community-submitted, non-expired malware indicators. Indicators support hunting and validation; they do not identify a victim, prove an intrusion, or establish ransomware prevalence.SourceThreatFox Community API — recent ransomware-tagged indicators

https://threatfox.abuse.ch/api/

Source10PublisherAlienVault Open Threat ExchangePublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentDiscovery query across the 50 most recently returned subscribed pulses. Pulse and indicator records are community and provider intelligence inputs, not confirmed incidents or victim-count evidence.SourceAlienVault OTX subscribed-pulse API — recent ransomware-related pulses

https://otx.alienvault.com/

Source11PublisherAlienVault OTXPublished2026-07-25Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 17 retained technical indicators. The pulse is a hunt input and does not confirm a victim or incident.SourcePrinz Eugen ransomware: a deep dive into a new Go-based encryptor

https://otx.alienvault.com/pulse/6a3d416ff54ce39010db1033

Source12PublisherAlienVault OTXPublished2026-07-24Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing 42 retained technical indicators. The reported access-broker relationship remains source-qualified and does not establish ransomware attribution.SourceNew Backdoor May be Linked to Ransomware Access Broker

https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b

Source13PublisherAlienVault OTXPublished2026-07-23Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing four retained infrastructure indicators. The source title is explicitly provisional and is not promoted into a canonical threat-actor identity.SourceA New Name in the Data Extortion Ecosystem?

https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0

Source14PublisherAlienVault OTXPublished2026-07-23Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing two retained network indicators. Indicators require local validation and do not establish a victim or campaign prevalence.SourceChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0

Source15PublisherAlienVault OTXPublished2026-07-21Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentOTX pulse containing five retained indicators, including hashes, one CVE reference, and one IPv4 address. It is a discovery and hunt input, not victim evidence.SourceJADEPUFFER evolves: ransomware built to destroy AI models

https://otx.alienvault.com/pulse/6a5eb7c2617139caf1fe0f2d

Source16PublisherHudson RockPublished2026-07-26Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentPlanned authenticated integration for infostealer-derived credential, employee, domain, and third-party exposure signals. It has not been queried for this edition and cannot increase victim totals, corroborate a victim claim, or prove ransomware access.SourceCavalier Infostealers API MCP Server

https://docs.hudsonrock.com/docs/mcp

Source17PublisherCoveware by VeeamPublished2026-04-30Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary Coveware Q1 2026 casework. Its Q4-to-Q1 payment comparisons describe Coveware-managed cases, not all U.S. incidents or a verified SMB-only population. Paid amounts are not initial ransom demands.SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era

https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/

Source18PublisherGuidePoint Security GRITPublished2026-07-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentGlobal public victim-post and ecosystem monitoring. Its quarter-over-quarter totals measure reported victims, not confirmed incidents, successful encryption, ransom demands, or a U.S. SMB-only population.SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report

https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/

Source19PublisherAretePublished2026-06-03Publication / evidenceSource indexincident responseWhy used / claim treatmentArete incident-response statistics for ransomware and extortion engagements, primarily involving cyber-insured organizations. Demand, payment, and payment-rate figures are bounded to Arete's case population and do not establish a Q2 or U.S. SMB-wide result.SourceArete 2026 Q1 Crimeware Report

https://areteir.com/resources/arete-s-2026-q1-crimeware-report

Source-Run Dispositions

Run-level accounting distinguishes evidence used in this edition from sources checked but not retained, unavailable during collection, or planned for a future lane.

Used · Checked—not retained · Unavailable · Planned

ransomware.liveVictim-claim observationUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Primary structured U.S. claim population for the active window.Controls total
RansomLookVictim-claim observationUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Used only to corroborate that a public post was observed.Observation corroboration only
IntelliOS Threat Actor CardsActor-label resolutionUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Used to normalize group labels; does not establish incident attribution.Excluded
CISA #StopRansomwareDefensive guidanceUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Retained for defensive decisions, not claim measurement.Excluded
U.S. Small Business AdministrationFirmographic definitionUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Controls the small-business definition through industry-specific NAICS size standards; does not supply victim firmographics or one universal midsize threshold.Excluded
Check Point Research — June ransomware landscapeActor activity and operating contextUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Controls June worldwide ransomware volume, group-share, and operating-change assertions. Its dataset is not combined with U.S. victim totals.Excluded
Check Point Research — The Gentlemen internal leakActor tradecraft and operating modelUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Controls the timeline’s source-bounded description of The Gentlemen’s access, affiliate, credential, tooling, and extortion workflow. It does not confirm every victim claim.Excluded
Check Point Research — CVE-2026-50751 exploitation advisoryActive exploitation and precursor activityUsedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Controls the May 7 first-observed exploitation date, early-June acceleration, and medium-confidence Qilin association. It does not identify the access path for all Qilin claims.Excluded
GuidePoint GRIT Q2 2026Quarter-over-quarter public victim-post directionUsedJul 26, 2026RANSOM-TREND-20260726Controls the global Q1-to-Q2 public victim-post comparison: 2,135 to 2,279, up 7%. It does not measure U.S. SMBs, confirmed incidents, encryption, demands, or payments.Excluded
Coveware Q1 2026 quarterly caseworkQuarter-over-quarter paid amount and payment propensityUsedJul 26, 2026RANSOM-TREND-20260726Controls the Q4-to-Q1 Coveware comparison: average paid ransom up 15%, median down 7%, and payment rate slightly up to 23%. It does not measure initial demands or a U.S. SMB-only population.Excluded
Arete Q1 2026 Crimeware ReportRansom-demand benchmarkUsedJul 26, 2026RANSOM-TREND-20260726Supplies the latest retained median-demand benchmark. Because the comparison baselines are Q1 2025 and full-year 2025 rather than adjacent Q4 and Q1 quarters, the card labels current demand direction not comparable.Excluded
Ransom-DBVictim-claim discoveryChecked—not retainedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Checked but not retained as a controlling source for this edition.Excluded
eCrime.chVictim-claim discoveryChecked—not retainedJul 26, 2026ACT-US-SMB-RANSOM-20260726-1215Checked but not retained as a controlling source for this edition.Excluded
ThreatFoxActive Infrastructure and PrecursorsUsedJul 26, 2026INFRA-PRECURSORS-20260726Seven-day authenticated API query returned 79 ransomware-tagged indicators: 77 INC payload hashes and two BianLian command-and-control endpoints.Excluded
AlienVault OTXActive Infrastructure and PrecursorsUsedJul 26, 2026INFRA-PRECURSORS-20260726Checked the 50 most recently returned subscribed pulses and retained five ransomware-related pulses containing 70 indicators.Excluded
Hudson Rock Cavalier MCPCredential Exposure and Ransomware Access PrecursorsPlannedNot runAwaiting a valid Hudson Rock API key. Planned read-only queries cover infostealer-derived credential, session, domain, employee, and third-party exposure; results will require local validation and will remain excluded from victim counts and corroboration.Excluded
Have I Been PwnedCredential-to-Ransomware Exposure Watch (paused)PlannedNot runHeld for the paused credential-exposure product; not used in this ransomware victim card.Excluded