- How it starts
- Stolen, reused, purchased, or weakly protected administrative credentials provide VPN, remote-support, cloud, or management access.
- Attacker outcome
- Trusted access can bypass perimeter controls, shorten dwell time, and reach recovery-critical systems.
- What to monitor
- New VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, unusual support sessions, and unexplained privilege elevation.
U.S. SMB Ransomware Activity & Exposure Trends — Rolling 90-Day Intelligence Card (Apr 30–Jul 28, 2026)
This U.S. SMB-focused rolling card automatically queries the ransomware.live Pro, RansomLook, ThreatFox, and AlienVault OTX APIs; reconciles overlapping U.S. victim claims; measures sector and group concentration; and links group aliases to IntelliOS Threat Actor Cards. It complements the Global Ransomware Landscape card, which explains worldwide operator momentum and tradecraft. The two products answer different questions, and their counts, rankings, and source methodologies must remain separate.
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Ransomware activity and exposure patterns that materially affect U.S. small and midsize businesses during the active rolling 90-day window. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | First: is ransomware pressure, successful encryption, the amount demanded, the amount paid, or payment propensity increasing, decreasing, or holding steady from one quarter to the next—and which of those questions can the retained evidence actually answer? Then: where is visible ransomware pressure concentrating in the United States, which group labels are driving the change, which claims are observed by more than one collector, which actor names map to existing IntelliOS Threat Actor Cards, and what should an SMB security or IT leader do differently now? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The current answer is split, not a single arrow. Global public victim-post pressure increased 7% from Q1 to Q2 2026, from 2,135 to 2,279 reported victims. Successful-encryption incidence and initial ransom demands are not yet measurable quarter over quarter for U.S. SMBs: the tracker APIs do not carry those fields, and no completed Q2 casework source is available. The latest adjacent-quarter Coveware comparison shows paid amounts moving in opposite directions from Q4 2025 to Q1 2026—the average increased 15% to $680,081 while the median decreased 7% to $300,750—and payment propensity ticked up slightly to 23%. Arete's Q1 median demand was $571,000, below its $600,000 full-year 2025 median but above its $500,000 Q1 2025 baseline; that mixed, non-adjacent comparison cannot establish a Q2 direction. Separately, ransomware.live returned 789 U.S. victim claims first observed from April 28 through July 26, with 681 also observed by RansomLook.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][17][18][19]First cited source Apr 30, 2026 · Latest cited source Jul 26, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 19 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
Rolling 90-Day Intelligence Snapshot
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
Apr 30, 2026–Jul 28, 2026
90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
↑ 7% QoQ[18]
Public victim-post direction
Global Q2 posts: 2,279 versus 2,135 in Q1; not confirmed incidents or U.S. SMB-onlyEvidence dated Jul 9, 2026
Successful-encryption direction
Current U.S. tracker records lack a comparable encryption-outcome fieldFirst cited source Apr 30, 2026 · Latest cited source Jul 26, 2026
Not comparable[19]
Initial-demand direction
No completed Q2 casework benchmark; latest Arete Q1 median demand was $571KEvidence dated Jun 3, 2026
789[1]
U.S. claims observed
Actor-published victim claims; not confirmed incidentsEvidence dated Jul 26, 2026
Actor alignment
760 of 789 claims resolve to canonical Actor CardsEvidence dated Jul 26, 2026
0[1]
Verified SMB victims
Company size was not inferred from tracker recordsEvidence dated Jul 26, 2026
Quarter-over-quarter public victim-post pressure
GuidePoint's global public-post dataset increased from 2,135 reported victims in Q1 2026 to 2,279 in Q2, a 7% rise. This is the cleanest current directional activity signal, but it does not measure confirmed incidents, successful encryption, ransom demands, or U.S. SMB prevalence.[18]Evidence dated Jul 9, 2026
Paid ransom amounts moved in opposite directions
Coveware's adjacent-quarter casework shows why one headline number is inadequate: the average increased 15%, while the median decreased 7%. These are payments in Coveware-managed cases—not initial demands or a U.S. SMB-only population.[17]Evidence dated Apr 30, 2026
Latest retained ransom-demand benchmark
Arete's Q1 2026 median demand sits between two different baselines: above Q1 2025 but below the full-year 2025 median. This is useful context, but it is not an adjacent-quarter comparison and cannot establish a Q2 direction.[19]Evidence dated Jun 3, 2026
Where visible U.S. claims concentrated
The five leading sector labels account for 566 of 789 observed claims. “Other sectors” preserves the remainder instead of hiding the long tail. Sector labels come from the source records and do not establish company size or a confirmed incident.[1]Evidence dated Jul 26, 2026
789
observed claims
Actor-label concentration
Qilin, The Gentlemen, and INC Ransom account for 243 claims—30.8% of the observed population. The remaining 546 claims span 70 other labels, so the card preserves both concentration and fragmentation.[1]Evidence dated Jul 26, 2026
Evidence-Prioritized Access Paths
Top Initial Access & Account-Takeover Vectors
The victim trackers do not enumerate a verified initial-access method for each claim. These paths are therefore prioritized from retained operating research and official defensive guidance; they direct exposure review and hunting without assigning a vector to every listed victim.
- How it starts
- An exposed gateway, remote-support service, management interface, or unpatched edge system provides an entry point or credential-access opportunity.
- Attacker outcome
- The attacker may inherit trusted network position, credentials, sessions, or downstream administrative reach.
- What to monitor
- New management access, configuration changes, appliance-originated connections, suspicious child processes, credential access, and historical gaps in edge logs.
- How it starts
- A provider identity, remote-management tool, shared account, or cross-tenant workflow is compromised or abused.
- Attacker outcome
- One trusted path can create multi-customer reach, accelerate lateral movement, or complicate containment authority.
- What to monitor
- Cross-tenant anomalies, provider-account changes, access outside support windows, new tools, unusual customer-specific activity, and provider notices.
Human and session compromise
Phishing and user-assisted credential theft[4]Evidence dated Source date not published
Official prevention priority; victim-level prevalence is not measured here
- How it starts
- A user or administrator is induced to disclose credentials, approve access, execute content, or establish an attacker-controlled session.
- Attacker outcome
- The attacker gains reusable identity or endpoint access that can be escalated toward data theft, security-control changes, and encryption.
- What to monitor
- Suspicious authentication, inbox or forwarding changes, token issuance, remote tools, script execution, new persistence, and rapid access to administrative or shared data.
| Vector / Evidence | How It Starts | Attacker Outcome | What to Monitor |
|---|---|---|---|
| Stolen, reused, purchased, or weakly protected administrative credentials provide VPN, remote-support, cloud, or management access. | Trusted access can bypass perimeter controls, shorten dwell time, and reach recovery-critical systems. | New VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, unusual support sessions, and unexplained privilege elevation. | |
| An exposed gateway, remote-support service, management interface, or unpatched edge system provides an entry point or credential-access opportunity. | The attacker may inherit trusted network position, credentials, sessions, or downstream administrative reach. | New management access, configuration changes, appliance-originated connections, suspicious child processes, credential access, and historical gaps in edge logs. | |
| A provider identity, remote-management tool, shared account, or cross-tenant workflow is compromised or abused. | One trusted path can create multi-customer reach, accelerate lateral movement, or complicate containment authority. | Cross-tenant anomalies, provider-account changes, access outside support windows, new tools, unusual customer-specific activity, and provider notices. | |
4 Human and session compromise Phishing and user-assisted credential theft[4]Evidence dated Source date not published Official prevention priority; victim-level prevalence is not measured here | A user or administrator is induced to disclose credentials, approve access, execute content, or establish an attacker-controlled session. | The attacker gains reusable identity or endpoint access that can be escalated toward data theft, security-control changes, and encryption. | Suspicious authentication, inbox or forwarding changes, token issuance, remote tools, script execution, new persistence, and rapid access to administrative or shared data. |
Intended Reader and Decision Context
Persona / Audience
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentOwners, executives, IT leaders, security teams, managed service providers, incident-response owners, insurers, and continuity leaders supporting U.S. SMBs. |
| Audience fieldSMB definition | AssessmentSmall follows the applicable SBA NAICS size standard. Midsize is used as an operating-audience label because no single federal threshold applies. No tracker-listed organization is classified as an SMB without authoritative employee, revenue, affiliation, and industry evidence. |
| Audience fieldDecision perspective | AssessmentUse the card to prioritize remote access, identity, backup, service-provider, and recovery controls—not to infer that a particular company was compromised. |
| Audience fieldEvidence posture | AssessmentTracker posts are claims. Cross-collector agreement corroborates that a post was observed; it does not independently confirm the intrusion or establish company size. |
Chronology and Decision Milestones
Timeline of Notable Activity
Read this as an actor-activity chronology, not an IntelliOS work log. Tracker dates show when a listing was first discovered—not when access, theft, encryption, or business impact occurred. Research dates and observed exploitation periods are labeled separately, and daily counts can change when a collector backfills or reclassifies records.
Largest daily posting burst
PayoutsKING drives the window’s sharpest one-day surge
Forty U.S. claims carry an April 30 discovered date, with 29 attributed to the PayoutsKING source label. Qilin, ShinyHunters, and Everest add two each, making the spike unusually concentrated while still involving several operating brands.[1][5]
Rapid follow-on burst
FulcrumSec and 3AM sustain pressure immediately after the April peak
The next day contributes 29 more observed claims: FulcrumSec accounts for 12, 3AM for five, Pear for three, and Clop and BrainCipher for two each. Two consecutive high-volume days show how quickly the visible landscape can rotate from one dominant label to a different cluster.[1][5]
RaaS operating model exposed
A breach of The Gentlemen’s own backend reveals its access-to-extortion workflow
Check Point’s analysis of leaked internal material describes a compact operation centered on an administrator known as zeta88, a roughly 90/10 affiliate split, and access obtained through unpatched edge devices, purchased credentials, and infostealer logs. The documented chain moves through Active Directory discovery, credential and session theft, EDR disruption, data exfiltration, backup targeting, and domain-wide ransomware deployment; the researchers also describe victim-to-client credential reuse and rapid use of AI assistants to build internal tooling.[7]
Competing groups overlap
The Gentlemen, Akira, Qilin, and Silent Ransom Group share a 20-claim day
The Gentlemen leads with six U.S. claims, Akira and Silent Ransom Group contribute three each, and Qilin adds two. The mix matters because it is not a single-campaign event: several independently branded operations are visibly active against the same national market at once.[1][5]
Edge-device exploitation
A Qilin-associated actor exploits a Check Point VPN authentication bypass
Check Point dates the earliest observed exploitation of CVE-2026-50751 to May 7 and reports increased activity in early June against deployments using deprecated IKEv1 remote access. With medium confidence, the vendor associates the financially motivated activity with an actor using Qilin ransomware; that association applies to the investigated activity, not to every Qilin-listed victim in this card.[8]
Late-May acceleration
DragonForce gives way to a Qilin-heavy burst over four days
DragonForce leads May 25 with five of 13 observed claims and May 27 with six of 11. On May 28, Qilin accounts for nine of 22 claims while Everest contributes three. The sequence is more informative than a monthly total: different affiliate ecosystems can seize the visible lead within days.[1][5]
Qilin concentration spike
Qilin accounts for 11 of 18 claims first discovered in one day
Play, WorldLeaks, and Pear contribute two each, but Qilin alone represents more than three-fifths of the day’s observed U.S. volume. The burst occurs during the same period in which Check Point reported increased exploitation activity associated with a Qilin-using actor; the sources do not establish that the two populations are the same victims.[1][8]
Mid-month group rotation
ShinyHunters and The Gentlemen lead before Pear and NightSpire appear
On June 15, ShinyHunters contributes six claims and The Gentlemen five of the day’s 15. By June 18, ShinyHunters and Pear contribute three each while NightSpire and Lynx add two each. The movement illustrates why defenders should monitor operating clusters and access behaviors rather than build readiness around one permanent league table.[1][5]
Global leadership shift
The Gentlemen overtakes Qilin in Check Point’s separate worldwide dataset
Check Point counted 646 worldwide leak-site publications for June, up 33% year over year, and attributed 17% to The Gentlemen, 11% to Qilin, and 7% to LockBit. Its research describes The Gentlemen advertising about 14,000 pre-exploited FortiGate devices and shifting from a vulnerable-driver EDR-killing technique toward userland evasion; those worldwide measures provide operating context and are not added to this card’s U.S. total.[3][7]
Turn-of-month handoff
Settra leads twice before The Gentlemen opens July with another burst
Settra accounts for five claims on June 28 and another five on June 30. On July 1, The Gentlemen contributes eight of 20 observed claims, while BrainCipher and Qilin add three each and ShinyHunters adds two. The handoff shows how a quieter label can dominate individual days without displacing the window’s leading groups overall.[1][5]
Provisional-label emergence
CRPxO appears with five claims while Qilin adds four
Twelve U.S. claims are first discovered that day: five under CRPxO, four under Qilin, and two under BrainCipher. CRPxO remains a source label requiring identity resolution; it should not be silently merged into a known group merely because it appears beside established operators.[1][5]
Renewed Gentlemen activity
The Gentlemen produces another eight-claim U.S. posting burst
The day contains 15 observed claims, with The Gentlemen responsible for eight and Play and KillSec contributing two each. The recurrence reinforces that The Gentlemen’s June leadership was not only a one-month global ranking artifact; the group remained visibly active late in the U.S. window.[1][3][5]
Open-source technical signals
ThreatFox and OTX surface current ransomware payload and infrastructure evidence
ThreatFox’s seven-day API response includes 77 INC ransomware MD5 payload hashes and two BianLian command-and-control IP-and-port indicators. Across the 50 most recently returned subscribed OTX pulses, five ransomware-related pulses contain 70 indicators involving Prinz Eugen, a possible ransomware access broker, provisional data-extortion activity, Chaos msaRAT, and JADEPUFFER. These records create concrete hunt material while remaining separate from victim claims and incident attribution.[9][10][11][12][13][14][15]
New-label surge
Global Secret Group and ExfilSquad dominate the latest daily population
The collector’s edition view records 25 claims first discovered on July 26: 12 under Global Secret Group and nine under ExfilSquad, with DragonForce adding two. Both leading labels remain provisional in the canonical alignment, so the meaningful conclusion is a sharp new-label surge—not confident attribution to an established actor family.[1][5]
Bottom Line Up Front
BLUF
Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]
SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]
Trend verdict: visible pressure is increasing; encryption and demand direction are not yet measurable; paid amounts are mixed: GuidePoint recorded 2,279 global public victim posts in Q2, up 7% from Q1. The current U.S. tracker records do not disclose successful encryption or initial demands, and no comparable Q2 U.S. SMB casework is yet available. In the newest adjacent-quarter casework, Coveware's Q1 average payment rose 15% from Q4 to $680,081 while the median fell 7% to $300,750. That means ransomware visibility is up, but it is not defensible to say U.S. SMB encryption or ransom demands increased.[17][18][19]First cited source Apr 30, 2026 · Latest cited source Jul 9, 2026
The 90-day window shows broad U.S. pressure with a meaningful sector concentration: The population includes ransomware.live records whose discovered date falls from April 28 through July 26, 2026, inclusive—exactly 90 UTC calendar days. At the edition’s agent-run time it contained 789 U.S. victim claims across 73 group labels; later collector backfills, removals, or reclassification can change a subsequent run over the same dates.[1]Evidence dated Jul 26, 2026
Qilin led the U.S. 90-day view even though The Gentlemen led a separate global June view: Qilin, The Gentlemen, and INC Ransom accounted for 243 U.S. claims, or 30.8% of this card’s 90-day population, with Qilin first at 122. Check Point separately placed The Gentlemen first in its worldwide June dataset. The rankings do not conflict because the geography, period, and collection methods differ. Treat both as watch priorities—not incident attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026
Cross-collector agreement is strong enough to support direction, not incident confirmation: RansomLook also observed 681 of the 789 ransomware.live group-and-victim combinations, an 86.3% overlap. The result raises confidence that the posts existed while leaving the claimed intrusion, impact, and company size unconfirmed.[1][2]Evidence dated Jul 26, 2026
SMB is a defined decision lens—not an inferred victim count: Small follows the applicable SBA NAICS size standard, generally based on employees or average annual receipts and including affiliates. No single federal midsize threshold applies, so midsize is an operating-audience label. Because the trackers lack authoritative firmographics, this edition reports zero verified SMB classifications.[1][6]Evidence dated Jul 26, 2026
Technical and access-precursor sources add hunt context without altering the victim picture: ThreatFox returned 77 recent INC ransomware payload hashes and two BianLian command-and-control endpoints. Five recent OTX pulses contributed 70 additional indicators. Hudson Rock Cavalier is planned for infostealer-derived credential and domain exposure once authenticated. Validate every signal against local exposure; none changes victim metrics or confirms a named incident.[9][10][11][12][13][14][15][16]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026
The immediate management priority is recoverability under identity and infrastructure loss: SMBs should protect administrative access, remove unnecessary Internet-facing management, separate backup identities, monitor staging and egress, and prove restoration when production identity, virtualization, or provider access is unavailable.[4][7][8]First cited source May 13, 2026 · Latest cited source Jun 8, 2026
Decision Context
Executive Summary
Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]
SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]
The first management question now has an explicit answer. Publicly visible ransomware pressure increased: GuidePoint counted 2,279 global victim posts in Q2 2026, 7% more than Q1's 2,135. Successful encryption and initial ransom-demand direction remain indeterminate for U.S. SMBs because ransomware.live and RansomLook do not carry those outcome fields and no completed Q2 casework source provides a comparable SMB-specific denominator. The card will not substitute leak-site volume for encryption or demand.[1][2][18]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026
The newest adjacent-quarter casework shows mixed economics rather than a uniform increase. Coveware reported that the average paid ransom increased 15% from Q4 2025 to Q1 2026, reaching $680,081, while the median paid ransom decreased 7% to $300,750 and the payment rate ticked up slightly to 23%. The divergent average and median indicate that a smaller number of severe cases can pull the mean upward while the more typical paid case moves down. These are paid amounts in Coveware-managed cases—not initial demands and not a U.S. SMB census.[17]Evidence dated Apr 30, 2026
Arete's Q1 casework supplies the newest retained demand benchmark but not a clean quarter-over-quarter result: its $571,000 median demand was about 5% below the $600,000 full-year 2025 median and about 14% above the $500,000 Q1 2025 baseline. Until Arete, Coveware, or another comparable responder publishes Q2 demand and encryption outcomes, the correct labels are “direction not yet measurable” for demand and successful encryption—not “flat.”[19]Evidence dated Jun 3, 2026
This edition covers April 28 through July 26, 2026—90 UTC calendar days inclusive. The primary population includes ransomware.live records by the date the service first discovered the listing, not the estimated attack date. RansomLook matches must also carry a discovered date inside the same window. Within that boundary, ransomware.live recorded 789 U.S. victim claims across 73 group labels.[1][2]Evidence dated Jul 26, 2026
Small-business status follows the applicable SBA NAICS size standard, which generally uses employee count or average annual receipts and includes affiliates. There is no single federal midsize threshold, so this card uses midsize as an operating-audience label rather than a firmographic classification. The tracker records do not supply sufficient authoritative size data; consequently, the edition reports zero verified SMB victims.[1][6]Evidence dated Jul 26, 2026
The clearest business pattern is sector concentration. Professional services accounted for 197 claims, healthcare 111, manufacturing 98, technology 86, and retail and e-commerce 74. Together, those sectors represent 566 claims, or 71.7% of the observed population. For SMB leaders, the practical implication is exposure to downtime and client disruption through shared systems, remote administration, sensitive data, operational technology, payments, and third-party dependencies.[1]Evidence dated Jul 26, 2026
Actor visibility also concentrated without becoming narrow. Qilin accounted for 122 U.S. claims, The Gentlemen 63, and INC Ransom 58; together they represented 30.8% of this card’s rolling-window population, while 70 other labels made up the remaining 69.2%. Check Point’s separate worldwide June dataset placed The Gentlemen first; that is a complementary global momentum signal, not a contradiction or a number to add to this population. IntelliOS resolved 760 of 789 claims to canonical Actor Cards while preserving the rule that a tracker label alone does not establish attribution.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026
The strongest evidence conclusion is qualified confidence. RansomLook also observed 681 of the 789 group-and-victim combinations, an 86.3% overlap that supports the existence of most public posts. It does not confirm the underlying intrusion. Separately, a seven-day ThreatFox query returned 79 ransomware-tagged indicators and five current OTX pulses supplied 70 technical indicators. The next planned precursor source is Hudson Rock Cavalier for infostealer-derived credential, session, domain, and third-party exposure. It has not been queried for this edition; when enabled, it remains a hunt and exposure input—not an addition to victim totals or confirmation of a named incident.[1][2][9][10][11][12][13][14][15][16]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026
The executive response should therefore focus on reducing recoverability leverage rather than chasing every public name. Protect administrative and remote access with phishing-resistant controls, remove unnecessary Internet-facing management, isolate backup identities and infrastructure, monitor pre-encryption staging and egress, constrain service-provider trust, and test restoration with production identity, virtualization, and normal network paths unavailable. Leadership should also pre-authorize containment, communications, legal, insurance, and customer decisions before an extortion event compresses the timeline.[4]Evidence dated Source date not published
Executive Briefing Priorities
Top 10 Briefing Points
- 1
Do not collapse activity, encryption, demands, and payments into one trend — Global public victim posts increased 7% from Q1 to Q2, while adjacent-quarter Coveware payment data was mixed and neither retained tracker provides U.S. SMB encryption or demand outcomes. Executives should require a separate direction, denominator, period, and source for each measure.[1][2][17][18][19]First cited source Apr 30, 2026 · Latest cited source Jul 26, 2026
- 2
789 U.S. victim claims were observed in the rolling window — This is the visible claim population from ransomware.live for April 28–July 26, not a confirmed breach count. Use it to understand pressure and concentration, not to estimate national incident prevalence.[1]Evidence dated Jul 26, 2026
- 3
Professional services carried the largest visible share — Professional services accounted for 197 claims—about one quarter of the U.S. total. Firms with shared client data, remote administration, and deadline-driven operations should treat identity and recovery readiness as business controls.[1]Evidence dated Jul 26, 2026
- 4
Healthcare and manufacturing add 209 continuity-sensitive claims — Healthcare contributed 111 claims and manufacturing 98. Both sectors can face immediate operational harm when identity, scheduling, production, clinical, or recovery systems become unavailable.[1]Evidence dated Jul 26, 2026
- 5
Technology and retail complete the leading concentration — Technology recorded 86 claims and retail and e-commerce 74. The combined pattern puts SaaS administration, customer data, payment operations, and third-party access on the immediate review list.[1]Evidence dated Jul 26, 2026
- 6
Qilin led the U.S. claim set — Qilin accounted for 122 claims, or roughly 15% of the rolling-window population. Open the canonical Qilin Actor Card for retained aliases and behaviors, but require local or authoritative evidence before using the name in incident attribution.[1][5]Evidence dated Jul 26, 2026
- 7
The Gentlemen and INC Ransom remain material watch priorities — The Gentlemen accounted for 63 claims and INC Ransom 58. Their combined volume makes changes in their access model, affiliate behavior, or leak infrastructure operationally relevant to SMB defenders.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026
- 8
Cross-collector agreement is high but not complete — RansomLook also observed 681 of the 789 group-and-victim combinations, an 86.3% overlap. That strengthens confidence that the posts existed while leaving the claimed intrusion itself unconfirmed.[1][2]Evidence dated Jul 26, 2026
- 9
Canonical Actor Cards cover 96.3% of observed claim volume — Sixty-seven of 73 group labels, representing 760 of 789 claims, resolve to an IntelliOS Threat Actor Card. The six unmatched labels remain provisional instead of becoming silent duplicate or unsupported actor records.[1][5]Evidence dated Jul 26, 2026
- 10
Company size is unverified for every tracker record — Neither employee count nor revenue is a dependable field in the retained victim records. This card focuses on SMB-relevant sectors and decisions and will not convert U.S. claims into an unsupported SMB victim count.[1]Evidence dated Jul 26, 2026
- 11
Open-source feeds add 149 current hunt indicators without adding a single victim — ThreatFox returned 79 ransomware-tagged indicators in its seven-day query, and five recent OTX pulses contributed 70 indicators. Use the hashes, domains, URLs, IP addresses, and related artifacts for local matching, enrichment, and carefully validated blocking; do not interpret the total as incidents, victims, or group prevalence.[9][10][11][12][13][14][15]First cited source Jul 21, 2026 · Latest cited source Jul 26, 2026
Source-Bound Exposure and Targeting
Victimology Matrix
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationAll U.S. organizations named in the active tracker window[1][2]Evidence dated Jul 26, 2026 | SectorsCross-industry; 789 claims across the retained sector taxonomy | GeographyUnited States | Confirmation statusActor-published or collector-observed victim claims; not independently confirmed incidents | How companies should use itUse the population to assess concentration and defensive priorities. Do not use it as a national incident rate or confirmed-victim census. |
| Victim / exposure populationProfessional-services organizations[1]Evidence dated Jul 26, 2026 | SectorsProfessional services — 197 claims, 25.0% of the observed population | GeographyUnited States | Confirmation statusTracker sector label and victim claim; company size and intrusion status remain unverified | How companies should use itPrioritize client-data access, shared repositories, remote administration, deadline-critical workflows, and provider trust. Test whether the firm can serve clients while identity or core systems are unavailable. |
| Victim / exposure populationHealthcare organizations[1]Evidence dated Jul 26, 2026 | SectorsHealthcare — 111 claims, 14.1% | GeographyUnited States | Confirmation statusTracker sector label and victim claim; not a confirmed breach or patient-impact count | How companies should use itValidate clinical and scheduling continuity, identity recovery, protected-data response, downtime procedures, and third-party notification paths. |
| Victim / exposure populationManufacturing organizations[1]Evidence dated Jul 26, 2026 | SectorsManufacturing — 98 claims, 12.4% | GeographyUnited States | Confirmation statusTracker sector label and victim claim; operational disruption is not established for every listing | How companies should use itProtect production scheduling, plant connectivity, engineering data, remote vendor access, virtualization, and recovery dependencies that can stop physical operations. |
| Victim / exposure populationTechnology, retail, and e-commerce organizations[1]Evidence dated Jul 26, 2026 | SectorsTechnology — 86 claims; retail and e-commerce — 74 claims | GeographyUnited States | Confirmation statusTracker classifications totaling 160 claims; individual incident facts remain unverified | How companies should use itScope SaaS administration, customer and payment data, cloud identities, software delivery, storefront availability, and third-party access together. |
| Victim / exposure populationOrganizations that may qualify as small or midsize businesses[1][6]Evidence dated Jul 26, 2026 | SectorsAll retained sectors | GeographyUnited States | Confirmation statusZero tracker records are treated as verified SMB classifications because authoritative employee, revenue, affiliation, and NAICS evidence is absent | How companies should use itApply the applicable SBA NAICS size standard for small-business status. Treat midsize as an operating-audience lens unless a separate documented threshold and authoritative firmographics are available. |
Distinct Operational Records
Ransomware Threat Actors & Operations
Qilin leads the U.S. claim population
Qilin accounted for 122 claims, or 15.5% of the rolling-window population. Use the linked canonical Actor Card to review aliases and source-backed behaviors, while requiring local evidence before attributing an incident.[1][5]Evidence dated Jul 26, 2026
The Gentlemen combines material U.S. visibility with current operating context
The Gentlemen accounted for 63 U.S. claims. Check Point’s separate research describes a fast-scaling ransomware operation and supplies operating context; its dataset is not added to the 789-claim U.S. total.[1][3][5]First cited source Jul 9, 2026 · Latest cited source Jul 26, 2026
INC Ransom remains a material watch priority
INC Ransom accounted for 58 claims in the active window. The source label is useful for watchlisting and connected intelligence, not incident attribution without local or authoritative confirmation.[1][5]Evidence dated Jul 26, 2026
The long tail remains larger than the leading groups
Seventy other labels accounted for 546 claims, or 69.2% of the observed population. Defenders need control-based readiness that survives affiliate movement, rebrands, and groups that never reach the top-three list.[1][5]Evidence dated Jul 26, 2026
Current Group Labels, Canonical Identities, and Decision Use
Threat Actor Glossary
The ten leading source labels in this edition, ranked by observed U.S. claims and linked to governed Actor Cards. Counts measure published claims inside the coverage window—not confirmed incidents, unique operators, successful encryptions, or verified SMB victims.
| Window measure | Result | How to read it |
|---|---|---|
| Observed claims | 789 | Publicly posted victim claims; not confirmed incidents. |
| Source labels | 73 | Distinct group names present in the coverage window. |
| Aligned labels | 67/73 | 6 labels remain provisional. |
| Aligned claim volume | 96.3% | 760 claims link to governed Actor Cards. |
| Top-three concentration | 30.8% | 243 observed claims. |
| Top-ten concentration | 59.6% | 470 observed claims. |
| Actor / source label | Activity in this window | Source-backed assessment | Attribution boundary / defender use |
|---|---|---|---|
1 Source label: qilin Qilin | 122 (15.5%) Canonical match | The largest single source label in the window, but still only about one-sixth of observed claims; the landscape is not dominated by one brand.[1][5] | Prioritize Qilin intelligence and watchlist changes, then require local evidence before using the name in incident attribution. |
2 Source label: thegentlemen The Gentlemen | 63 (8.0%) Canonical match | The second-largest U.S. source label. Check Point separately describes a fast-scaling operation, adding operating context without changing this card’s API-derived total.[1][3][5] | Track changes in access, affiliate, and leak-site behavior; keep Check Point’s separate dataset methodologically distinct. |
3 Source label: incransom INC Ransom | 58 (7.4%) Canonical match | Completes a top-three cluster responsible for 243 claims, or 30.8% of the rolling population.[1][5] | Use the Actor Card for aliases and connected reporting, but never infer INC attribution from a tracker post alone. |
4 Source label: akira Akira | 43 (5.4%) Canonical match | The first group outside the leading cluster and large enough to remain a material watch priority on its own.[1][5] | Keep Akira-specific intelligence available to responders while maintaining control-based readiness across all groups. |
5 Source label: dragonforce DragonForce | 35 (4.4%) Canonical match | Part of the middle concentration tier where several similarly sized brands collectively matter more than any individual ranking change.[1][5] | Monitor branding, affiliate, and infrastructure changes; do not treat brand continuity as proof of operator continuity. |
6 Source label: payoutsking PayoutsKING | 34 (4.3%) Canonical match | Nearly tied with DragonForce and Genesis, showing why ordinal rank alone can exaggerate small differences between groups.[1][5] | Use claim count and share together; avoid interpreting a one-position move as a material threat change without supporting evidence. |
7 Source label: genesis Genesis | 33 (4.2%) Canonical match | One of three adjacent labels separated by only two claims, reinforcing that the middle tier should be treated as a cluster.[1][5] | Route the source label to the canonical record and watch for aliases or reclassification before creating new identities. |
8 Source label: shinyhunters ShinyHunters | 30 (3.8%) Canonical match | The tracker label resolves to a governed Actor Card, but a canonical name match does not prove the operator behind a particular victim claim.[1][5] | Use the link for source-backed context and relationships; require victim, official, or local evidence for incident attribution. |
9 Source label: play Play | 28 (3.5%) Canonical match | Remains inside the top ten while representing only a small fraction of the overall population, illustrating the fragmented market.[1][5] | Retain Play-specific detection and response context without narrowing the ransomware program to the current leaderboard. |
10 Source label: pear Pear | 24 (3.0%) Canonical match | Closes a top-ten group accounting for 470 claims, or 59.6% of the window; the remaining 319 claims span 63 other labels.[1][5] | Treat the top ten as a prioritization aid, not an allowlist: the long tail still represents 40.4% of observed claims. |
How to read actor language
| Term | Meaning in this card |
|---|---|
| Source label | The group name exactly as supplied by the collector. It is preserved even when IntelliOS maps it to a different canonical spelling. |
| Canonical actor | The governed IntelliOS identity used to consolidate known spellings and aliases. A match improves navigation and watchlist quality; it does not prove attribution. |
| RaaS brand | A ransomware-as-a-service identity may represent shared infrastructure, rules, tooling, or branding used by multiple affiliates rather than one fixed intrusion team. |
| Affiliate | An operator or crew using a ransomware program or brand. Affiliates can change brands, access methods, and targets, so brand-level behavior should not be applied automatically to every incident. |
| Observed claim | A victim name or post collected from an extortion source. It shows that a claim was published—not that the intrusion, actor, timing, scope, or impact was independently confirmed. |
| Provisional label | A source name without a deterministic canonical or retained-alias match. It remains separate until reviewed evidence supports a merge or a new governed Actor Card. |
Attribution rule: A tracker label, canonical match, affiliate association, infrastructure overlap, or second collector may justify investigation. None alone establishes who compromised a named organization.[1][2][5]
Enterprise Exposure
Affected Technologies & Trust Boundaries
Remote access and administrative control planes
VPNs, remote-support systems, management interfaces, and privileged administration can turn one stolen or exposed access path into broad operational reach. Inventory them, require phishing-resistant access, and retain session and administrator telemetry.[3][4]Evidence dated Jul 9, 2026
Identity, sessions, and service accounts
Passwords are only one access artifact. Privileged sessions, tokens, enrolled authentication methods, dormant accounts, and service identities must be reviewable and rapidly revocable during containment.[3][4]Evidence dated Jul 9, 2026
Backup repositories and recovery orchestration
Recovery systems that share production identities or management paths may fail when needed most. Separate identities, isolate copies, monitor destructive administration, and prove restoration under production identity loss.[4]Evidence dated Source date not published
Virtualization and shared infrastructure
Hypervisors, storage, domain services, and shared management systems concentrate business impact. Treat administrative changes, mass shutdown, snapshot deletion, and unusual host access as recovery-critical signals.[3][4]Evidence dated Jul 9, 2026
MSP and third-party management tooling
Provider credentials and shared remote-management paths can extend a compromise across tenants or downstream customers. Require named access, isolation, complete logs, an emergency disable path, and joint response procedures.[3][4]Evidence dated Jul 9, 2026
Data staging, archives, and outbound transfer
Extortion pressure often depends on data theft before encryption. Monitor bulk reads, archive creation, unapproved cloud storage, large encrypted egress, and new transfer utilities as early containment opportunities.[4]Evidence dated Source date not published
Non-Victim Technical Evidence Lane
Access, Exposure, and Infrastructure Precursors
A separate evidence lane for malicious infrastructure, active exploitation, and credential or session exposure that may precede ransomware access. It supports local validation, hunting, and defensive prioritization; it is not a ransomware-victim dataset.
The seven-day API query returned 79 ransomware-tagged indicators: 77 INC ransomware MD5 payload hashes and two BianLian command-and-control IP-and-port records. This is a freshness-bounded technical sample, not a measure of group activity or victim prevalence.[9]
Operational use: Match retained hashes and network endpoints against endpoint, proxy, DNS, firewall, and historical telemetry. Re-check status and context before blocking because infrastructure and indicator confidence can change.
Five ransomware-related pulses among the 50 most recently returned subscribed pulses contributed 70 indicators: 17 for Prinz Eugen, 42 for a possible ransomware access broker, four for provisional data-extortion activity, two for Chaos msaRAT, and five for JADEPUFFER.[10][11][12][13][14][15]
Operational use: Use pulse context to prioritize local IOC matching and pivot to the cited pulse before containment. Preserve provisional language and never use pulse overlap to confirm a named victim or actor attribution.
Once authenticated, the read-only publisher can query infostealer-derived employee, domain, third-party, credential, session, and infection exposure relevant to common ransomware access paths. No Hudson Rock account data was queried for this edition.[16]
Operational use: Use exposure results to identify credentials, sessions, remote-access portals, and third-party trust paths that require local validation, rotation, revocation, or investigation. Never treat a stealer record as proof of ransomware access or a confirmed victim.
Current Carry-Forward Watchlist
Top 10 Specific Threats to Monitor
Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category Identity Remote and administrative access[3][4]Evidence dated Jul 9, 2026 | Why it mattersStolen or reused access can move an incident past perimeter controls before defenders see encryption. | What to monitorNew VPN sessions, impossible travel, dormant-account use, MFA changes, new tokens, privilege elevation, and unexplained service-account activity. | IntelliOS coverage |
| 2 | Threat / Category Recovery Backup and virtualization control planes[3][4]Evidence dated Jul 9, 2026 | Why it mattersAttackers gain leverage when recovery systems share production identities or administrative paths. | What to monitorRetention changes, repository deletion, new backup administrators, SSH enablement, mass VM shutdown, and failed restore tests. | IntelliOS coverage |
| 3 | Threat / Category Third party MSP and shared-service trust[3][4]Evidence dated Jul 9, 2026 | Why it mattersA compromised provider credential or management platform can expand one intrusion into multiple SMB environments. | What to monitorCross-tenant anomalies, shared accounts, remote-management changes, provider notices, and unusual customer-specific access. | IntelliOS coverage |
| 4 | Threat / Category Pre-encryption Staging and outbound transfer[3][4]Evidence dated Jul 9, 2026 | Why it mattersData theft often precedes encryption and public pressure. | What to monitorArchive creation, bulk file reads, unapproved cloud storage, unusual S3 transfers, compression tools, and large encrypted egress. | IntelliOS coverage |
| 5 | Threat / Category Evidence Claim confirmation workflow[1][2]Evidence dated Jul 26, 2026 | Why it mattersA tracker post should trigger verification, not an automatic breach declaration. | What to monitorVictim disclosure, regulatory notice, filing, law-enforcement statement, forensic evidence, extortion contact, and retained source changes. | IntelliOS coverage |
Operational Standards from the Evidence
Best Practices and Lessons Learned
Six operating practices translate the 90-day evidence into controls an SMB can implement, rehearse, and prove. The lesson identifies the failure mode; the minimum operating standard states the evidence leadership should expect.
Window basis: ransomware.live discovered dates and RansomLook discovered dates must fall inside the same inclusive UTC window. Counts are frozen at the edition’s agent-run time; collector backfills, removals, or reclassification may change a later run over the same dates.[1][2]
SMB basis: “Small” follows the applicable SBA NAICS size standard. “Midsize” is an audience lens because no single federal threshold applies; no tracker-listed victim is classified without authoritative firmographics.[1][6]
- 1
Best Practice
Make privileged and remote administration phishing-resistant[3][4]Evidence dated Jul 9, 2026
Lesson Learned
Group brands and affiliates change, but stolen or replayed administrative access remains a durable path to rapid business impact. Ordinary user MFA and shared administrator accounts leave too much reusable trust.
Minimum Operating Standard
Cover every privileged, remote-management, backup, virtualization, and MSP administrator with phishing-resistant authentication; eliminate shared accounts; require named, time-bounded elevation; review access quarterly; and retain proof of emergency session revocation.
- 2
Best Practice
Prove recovery without production identity or network dependencies[4]Evidence dated Source date not published
Lesson Learned
A backup is not a recovery capability when the same compromised identities, management plane, DNS, virtualization stack, or network path is required to restore it.
Minimum Operating Standard
Maintain separate recovery identities and at least one isolated or immutable copy; document break-glass access; test representative restores quarterly with production identity and normal network paths unavailable; and record achieved RTO, RPO, integrity checks, exceptions, and remediation owners.
- 3
Best Practice
Constrain provider access to the smallest reversible trust path[3][4]Evidence dated Jul 9, 2026
Lesson Learned
SMBs often depend on MSPs and shared administration. One provider credential, remote-management tool, or cross-tenant workflow can expand a single compromise into customer environments.
Minimum Operating Standard
Use named provider accounts, tenant isolation, least privilege, approved support windows, complete logging, and an emergency disable path. Reconcile provider access monthly and run an annual joint exercise that includes evidence exchange, containment authority, customer notification, and restoration.
- 4
Lesson Learned
Archive creation, bulk file access, unusual egress, remote-tool changes, privilege escalation, and backup administration can provide a decision window before encryption or public extortion.
Minimum Operating Standard
Operate alerts for data staging, outbound transfer, new remote tools, privileged-account changes, and backup or hypervisor tampering; assign a 24/7 decision owner; preserve evidence automatically; and demonstrate in exercises that high-confidence activity can be contained within the organization’s defined response target.
- 5
Best Practice
Pre-authorize the ransomware decision chain[4]Evidence dated Source date not published
Lesson Learned
Containment, shutdown, insurer notice, legal privilege, customer communications, and restoration decisions stall when authority is first negotiated during the incident.
Minimum Operating Standard
Maintain a one-page decision matrix with primary and after-hours owners, financial and operational thresholds, insurer and counsel contacts, law-enforcement criteria, communications approval, and explicit authority for disruptive containment. Exercise it at least twice yearly and close documented decision gaps.
- 6
Best Practice
Separate public claims, technical signals, and confirmed incidents in operations[1][2]Evidence dated Jul 26, 2026
Lesson Learned
A leak-site post, a second collector, an Abuse.ch or OTX indicator, and local forensic evidence answer different questions. Combining them creates false victim counts, weak attribution, and wasted response effort.
Minimum Operating Standard
Every alert records an evidence state, controlling source, local exposure result, owner, next validation step, and deadline. Infrastructure signals may drive blocking or hunting but cannot increase victim totals; a named incident requires victim, official, filing, or defensible local evidence.
Who Contributed What
Source Contributions & Decision Role
Each source has a defined job in this edition. Collection, corroboration, operating context, defensive guidance, actor-name resolution, and the SMB definition remain separate so one source is never stretched beyond the evidence it actually supplies.
| Contributor | Contribution to this card | Decision use | Evidence boundary |
|---|---|---|---|
| Contributorransomware.live Ransomware.live Pro API — U.S. victim claims observed during the rolling window | ContributionSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1] | Decision useMeasure visible claim pressure and concentration; trigger organization-level validation when a relevant name or pattern appears. | Evidence boundaryDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current. |
| ContributorRansomLook RansomLook recent posts API — independent collector reconciliation | ContributionProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2] | Decision useIdentify cross-collector agreement and isolate records that need additional reconciliation. | Evidence boundaryA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status. |
| ContributorCheck Point Research A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide | ContributionAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3] | Decision useExplain why concentrated group activity matters and turn specific operating observations into monitoring questions. | Evidence boundaryIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals. |
| ContributorCybersecurity and Infrastructure Security Agency #StopRansomware Guide | ContributionSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4] | Decision useSet the operational response baseline for identity protection, exposed services, backups, containment, evidence, and recovery. | Evidence boundaryDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident. |
| ContributorIntelliOS IntelliOS Threat Actor Cards | ContributionNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5] | Decision usePrevent fragmented watchlists and route readers from a source label to the best available actor context. | Evidence boundaryAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident. |
| ContributorU.S. Small Business Administration Small Business Size Standards | ContributionControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6] | Decision useDefine the intended small-business audience and prevent unsupported firmographic classification of tracker-listed organizations. | Evidence boundaryProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record. |
| ContributorCheck Point Research When the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk | ContributionDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7] | Decision useTurn a group name into concrete exposure questions about edge patching, purchased credentials, infostealer logs, session theft, Active Directory abuse, EDR resilience, backup isolation, and client-connected accounts. | Evidence boundaryThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total. |
| ContributorCheck Point Research Active exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments | ContributionSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8] | Decision usePrioritize exposure validation, hotfixing, IKEv1 retirement, log review, and threat hunting where the affected remote-access configuration exists. | Evidence boundaryThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims. |
| Contributorabuse.ch / Spamhaus ThreatFox Community API — recent ransomware-tagged indicators | ContributionQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9] | Decision useDrive endpoint, network, DNS, proxy, and historical telemetry matching against fresh, source-linked technical artifacts. | Evidence boundaryIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking. |
| ContributorAlienVault Open Threat Exchange AlienVault OTX subscribed-pulse API — recent ransomware-related pulses | ContributionQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10] | Decision usePrioritize emerging ransomware, access-broker, data-extortion, and specialized targeting hypotheses for local IOC matching and follow-up research. | Evidence boundaryPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions. |
Claim-Specific Evidence Authority
Source Weighting / Relevance
Weight is claim-specific, not a universal publisher score. An official source can control response guidance or the SMB definition while contributing nothing to current victim totals; an API can control measured claim volume while remaining unable to confirm an incident.
| Source | Weight | Relevance | What it can support | Limitation |
|---|---|---|---|---|
| Sourceransomware.live | WeightHigh | RelevancePrimary quantitative claim source | What it can supportSupplies the primary structured population of U.S. leak-site and extortion claims discovered inside the inclusive rolling window. It controls the card’s claim count, source-provided sector distribution, group-label distribution, and first-observed dates.[1] | LimitationDoes not confirm an intrusion, establish company size, or prove that the source-provided sector label is complete or current. |
| SourceRansomLook | WeightHigh for post observation | RelevanceIndependent collection check | What it can supportProvides a separately operated collector used to determine whether the same group-and-victim post was also observed outside ransomware.live.[2] | LimitationA match confirms observation of a public post—not the underlying intrusion, victim impact, actor attribution, sector, or SMB status. |
| SourceCheck Point Research | WeightHigh for operating context | RelevanceIndependent threat research | What it can supportAdds external research context on current ransomware operating tempo and leading group behavior without being merged into the API-derived U.S. claim population.[3] | LimitationIts worldwide leak-site dataset and methodology are not interchangeable with the card’s U.S. API extract and do not alter victim totals. |
| SourceCybersecurity and Infrastructure Security Agency | WeightVery High for defensive guidance | RelevanceOfficial response authority | What it can supportSupplies authoritative prevention, containment, evidence-preservation, reporting, and recovery guidance used to convert observed ransomware pressure into defensive priorities.[4] | LimitationDoes not control current claim totals, confirm named victims, or establish which ransomware group caused a specific incident. |
| SourceIntelliOS | WeightHigh for identity resolution | RelevanceGoverned internal alignment | What it can supportNormalizes tracker spellings and aliases to governed IntelliOS Threat Actor Cards and provides links to the corresponding actor records.[5] | LimitationAn internal name match is not independent corroboration and does not establish attribution for a named victim or incident. |
| SourceU.S. Small Business Administration | WeightVery High for the SMB boundary | RelevanceOfficial firmographic definition | What it can supportControls the card’s definition of a U.S. small business through industry-specific NAICS employee or receipts standards, including applicable affiliate rules.[6] | LimitationProvides no victim firmographics and no universal midsize threshold; the card therefore does not infer SMB status from a company name or tracker record. |
| SourceCheck Point Research | WeightHigh for documented tradecraft | RelevancePrimary leaked-operation analysis | What it can supportDocuments The Gentlemen’s exposed RaaS operating model, including access sourcing, affiliate economics, identity and endpoint actions, backup targeting, data theft, victim-chain reuse, and rapid internal tool development.[7] | LimitationThe analysis controls assertions about the examined leaked material; it does not confirm every underground claim, prove the same workflow in every incident, or change the U.S. victim total. |
| SourceCheck Point Research | WeightHigh for the affected-product finding | RelevancePrimary exploitation telemetry | What it can supportSupplies product and incident telemetry for active exploitation of CVE-2026-50751, including the first observed date, early-June acceleration, affected deprecated IKEv1 deployments, and a medium-confidence Qilin association.[8] | LimitationThe association is medium confidence and incident-scoped. It cannot be generalized to every Qilin claim or used to infer the initial-access vector for tracker-listed victims. |
| Sourceabuse.ch / Spamhaus | WeightHigh for retained IOC facts | RelevanceCurrent technical hunt feed | What it can supportQueries recent, non-expired ThreatFox indicators and retains only records explicitly tagged or identified as ransomware-related. The current run contributes INC payload hashes and BianLian command-and-control endpoints.[9] | LimitationIndicator volume is not actor activity, victim prevalence, attribution, or proof that any company is compromised. Revalidate status and local exposure before blocking. |
| SourceAlienVault Open Threat Exchange | WeightModerate to High for discovery | RelevanceCommunity and provider pulse context | What it can supportQueries the most recently returned subscribed OTX pulses, filters for ransomware-related context, and retrieves the indicator set for each retained pulse. Individual pulse records remain separately cited.[10] | LimitationPulse inclusion and indicator overlap do not confirm a victim, prove attribution, measure prevalence, or independently validate the publisher’s analytical conclusions. |
Automation Transparency
AI Agent Run Status
| Agent | U.S. SMB Ransomware Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · rolling 90-day automation |
| Cadence | Daily at midday ET; publish only when claim volume, concentration, corroboration, or group alignment changes materially |
| Previous run | 26-Jul-2026 · midday ET · Run ACT-US-SMB-RANSOM-20260726-1215 |
| Previous result | Published the quarter-over-quarter trend lane while preserving explicit outcome-data gaps. |
| What the previous run found |
|
| Next run | 27-Jul-2026 · midday ET |
| Sources monitored |
|
| Publication and alert policy | Alert for a material change in public victim-post pressure, successful-encryption incidence, initial demands, paid amounts, payment propensity, concentration, corroboration, or evidence state. Suppress routine additions, date-only movement, and no-change runs. |
Related Intelligence and CARDS Records
Other IntelliOS Products
Intelligence Alignment
Ransomware Group Alignment Engine
Deterministic canonical, alias, source-alias, and reviewed-override matching across tracker labels and IntelliOS Threat Actor Cards.
Open productThreat Actor Cards
Canonical Ransomware Group Watchlist
Resolved group names, aliases, confidence, behaviors, and related IntelliOS intelligence.
Open productRolling Intelligence
Global Ransomware Landscape
Broader global ransomware ecosystem, initial-access, operator, and recovery context. Its worldwide and source-specific measures remain separate from this U.S. claim population.
Open productCARDS Actor Record
Qilin Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Thegentlemen Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
INC Ransom Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Akira Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Payoutsking Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Dragonforce Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Genesis Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Shinyhunters Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Play Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Pear Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Campaign Record
The Gentlemen RAAS Operations Campaign Card
Connected campaign intelligence, activity timeline, affected technologies, actors, techniques, and source boundaries.
Open productPublication History
Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv9 | Date26-Jul-2026 | ChangeMade the quarter-over-quarter ransomware direction the lead management question. Added separate verdicts and snapshot measures for public victim-post pressure, successful encryption, initial demands, paid amounts, and payment propensity; retained GuidePoint Q2, Coveware Q1, and Arete Q1 as methodologically separate sources; and labeled unavailable Q2 encryption and demand outcomes as not yet measurable rather than flat. | MonitoringDaily claim monitoring; publish direction changes when comparable casework becomes available |
| Versionv8 | Date26-Jul-2026 | ChangeAdded an explicit product boundary with the Global Ransomware Landscape card. Clarified why Qilin can lead this 90-day U.S. dataset while The Gentlemen leads a separate worldwide June dataset, and prohibited combining the two products’ counts or rankings. | MonitoringDaily material-change review |
| Versionv7 | Date26-Jul-2026 | ChangeRemoved an unused planned enterprise exploitation-context integration and its citation, precursor-lane, source-run, and agent-plan references. | MonitoringContinue the retained and authenticated source plan |
| Versionv6 | Date26-Jul-2026 | ChangeDefined the read-only Hudson Rock Cavalier MCP integration for the SMB ransomware product. Added it to Citations, the precursor evidence lane, source-run dispositions, and the agent source plan while explicitly excluding it from victim totals, victim corroboration, and standalone incident attribution. The source was not queried for this edition. | MonitoringActivate Hudson Rock after a valid API key is configured |
| Versionv5 | Date26-Jul-2026 | ChangeExpanded the automated source set beyond victim trackers. Added authenticated ThreatFox and OTX queries, retained 149 current technical indicators in the separate Active Infrastructure and Precursors lane, linked every finding to controlling citations, and preserved the prohibition against using infrastructure signals to increase victim totals or confirm incidents. | MonitoringDaily material-change review |
| Versionv4 | Date26-Jul-2026 | ChangeRebuilt the timeline as a compact, intelligence-led chronology of ransomware posting bursts, actor rotation, exposed RaaS operations, and active edge-device exploitation. Removed internal reconciliation and identity-resolution milestones from the chronology and added source-bounded Check Point research without changing victim totals. | MonitoringDaily material-change review |
| Versionv3 | Date26-Jul-2026 | ChangeAdded a comprehensive Threat Actor Glossary covering the ten leading source labels, canonical Actor Card resolution, claim count and share, decision-relevant facts, attribution limits, and glossary definitions. The card also summarizes top-three, top-ten, long-tail, aligned, and unresolved actor statistics. | MonitoringDaily material-change review |
| Versionv2 | Date26-Jul-2026 | ChangeAdded Source Contributions and Source Weighting / Relevance cards. Defined the separate decision roles and evidence limits for ransomware.live, RansomLook, Check Point Research, CISA, IntelliOS Threat Actor Cards, and SBA size standards without changing victim totals or confirmation states. | MonitoringDaily material-change review |
| Versionv1 | Date26-Jul-2026 | ChangeCreated the U.S. SMB ransomware rolling card with cross-collector reconciliation, explicit SMB-size limits, sector concentration, canonical actor links, and practical SMB decisions. | MonitoringDaily material-change review |
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | Publisherransomware.live | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentLeak-site and extortion-tracker observations. A listed organization is an actor claim, not an independently confirmed intrusion; the API does not establish company size. | SourceRansomware.live Pro API — U.S. victim claims observed during the rolling window https://api-pro.ransomware.live/docs |
| Source2 | PublisherRansomLook | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentA second collector can corroborate that a post was observed, but shared appearance across collectors still does not confirm the underlying intrusion. | SourceRansomLook recent posts API — independent collector reconciliation https://www.ransomlook.io/doc/ |
| Source3 | PublisherCheck Point Research | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentVendor analysis of ransomware data-leak-site activity and operating context; published attacks remain actor claims unless separately confirmed. | SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ |
| Source4 | PublisherCybersecurity and Infrastructure Security Agency | PublishedNot available | Publication / evidenceSource indexofficial | Why used / claim treatmentStanding defensive guidance used for practical prevention, containment, evidence-preservation, and recovery decisions; it does not control current victim-count claims. | Source#StopRansomware Guide https://www.cisa.gov/stopransomware/ransomware-guide |
| Source5 | PublisherIntelliOS | Published2026-07-26 | Publication / evidenceSource indexprimary research | Why used / claim treatmentCanonical identity and alias directory used to link tracker labels to source-backed actor cards. A name match does not establish incident attribution. | SourceIntelliOS Threat Actor Cards /threat-actor-cards |
| Source6 | PublisherU.S. Small Business Administration | PublishedNot available | Publication / evidenceSource indexofficial | Why used / claim treatmentControlling definition for the card’s small-business boundary. SBA size standards vary by NAICS industry and generally use employee count or average annual receipts, including affiliates. The source does not define one universal midsize threshold. | SourceSmall Business Size Standards https://www.sba.gov/federal-contracting/contracting-guide/size-standards |
| Source7 | PublisherCheck Point Research | Published2026-05-13 | Publication / evidenceSource indexprimary research | Why used / claim treatmentPrimary vendor analysis of leaked internal material describing The Gentlemen’s operating model, access paths, tooling, affiliate economics, and victim-chain reuse. It does not independently confirm every actor or victim claim in the leaked material. | SourceWhen the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ |
| Source8 | PublisherCheck Point Research | Published2026-06-08 | Publication / evidenceSource indexprimary research | Why used / claim treatmentVendor incident and product telemetry describing active exploitation beginning May 7 and a medium-confidence association with a financially motivated actor using Qilin ransomware. It does not establish that every Qilin claim used this vulnerability. | SourceActive exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ |
| Source9 | Publisherabuse.ch / Spamhaus | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentSeven-day API query of community-submitted, non-expired malware indicators. Indicators support hunting and validation; they do not identify a victim, prove an intrusion, or establish ransomware prevalence. | SourceThreatFox Community API — recent ransomware-tagged indicators https://threatfox.abuse.ch/api/ |
| Source10 | PublisherAlienVault Open Threat Exchange | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentDiscovery query across the 50 most recently returned subscribed pulses. Pulse and indicator records are community and provider intelligence inputs, not confirmed incidents or victim-count evidence. | SourceAlienVault OTX subscribed-pulse API — recent ransomware-related pulses https://otx.alienvault.com/ |
| Source11 | PublisherAlienVault OTX | Published2026-07-25 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 17 retained technical indicators. The pulse is a hunt input and does not confirm a victim or incident. | SourcePrinz Eugen ransomware: a deep dive into a new Go-based encryptor https://otx.alienvault.com/pulse/6a3d416ff54ce39010db1033 |
| Source12 | PublisherAlienVault OTX | Published2026-07-24 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 42 retained technical indicators. The reported access-broker relationship remains source-qualified and does not establish ransomware attribution. | SourceNew Backdoor May be Linked to Ransomware Access Broker https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b |
| Source13 | PublisherAlienVault OTX | Published2026-07-23 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing four retained infrastructure indicators. The source title is explicitly provisional and is not promoted into a canonical threat-actor identity. | SourceA New Name in the Data Extortion Ecosystem? https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0 |
| Source14 | PublisherAlienVault OTX | Published2026-07-23 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing two retained network indicators. Indicators require local validation and do not establish a victim or campaign prevalence. | SourceChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0 |
| Source15 | PublisherAlienVault OTX | Published2026-07-21 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing five retained indicators, including hashes, one CVE reference, and one IPv4 address. It is a discovery and hunt input, not victim evidence. | SourceJADEPUFFER evolves: ransomware built to destroy AI models https://otx.alienvault.com/pulse/6a5eb7c2617139caf1fe0f2d |
| Source16 | PublisherHudson Rock | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentPlanned authenticated integration for infostealer-derived credential, employee, domain, and third-party exposure signals. It has not been queried for this edition and cannot increase victim totals, corroborate a victim claim, or prove ransomware access. | SourceCavalier Infostealers API MCP Server https://docs.hudsonrock.com/docs/mcp |
| Source17 | PublisherCoveware by Veeam | Published2026-04-30 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware Q1 2026 casework. Its Q4-to-Q1 payment comparisons describe Coveware-managed cases, not all U.S. incidents or a verified SMB-only population. Paid amounts are not initial ransom demands. | SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/ |
| Source18 | PublisherGuidePoint Security GRIT | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentGlobal public victim-post and ecosystem monitoring. Its quarter-over-quarter totals measure reported victims, not confirmed incidents, successful encryption, ransom demands, or a U.S. SMB-only population. | SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/ |
| Source19 | PublisherArete | Published2026-06-03 | Publication / evidenceSource indexincident response | Why used / claim treatmentArete incident-response statistics for ransomware and extortion engagements, primarily involving cyber-insured organizations. Demand, payment, and payment-rate figures are bounded to Arete's case population and do not establish a Q2 or U.S. SMB-wide result. | SourceArete 2026 Q1 Crimeware Report https://areteir.com/resources/arete-s-2026-q1-crimeware-report |
Source-Run Dispositions
Run-level accounting distinguishes evidence used in this edition from sources checked but not retained, unavailable during collection, or planned for a future lane.
Used · Checked—not retained · Unavailable · Planned
| Source | Evidence Lane | Disposition | Checked / Run | Treatment | Victim Metrics |
|---|---|---|---|---|---|
| ransomware.live | Victim-claim observation | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Primary structured U.S. claim population for the active window. | Controls total |
| RansomLook | Victim-claim observation | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Used only to corroborate that a public post was observed. | Observation corroboration only |
| IntelliOS Threat Actor Cards | Actor-label resolution | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Used to normalize group labels; does not establish incident attribution. | Excluded |
| CISA #StopRansomware | Defensive guidance | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Retained for defensive decisions, not claim measurement. | Excluded |
| U.S. Small Business Administration | Firmographic definition | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Controls the small-business definition through industry-specific NAICS size standards; does not supply victim firmographics or one universal midsize threshold. | Excluded |
| Check Point Research — June ransomware landscape | Actor activity and operating context | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Controls June worldwide ransomware volume, group-share, and operating-change assertions. Its dataset is not combined with U.S. victim totals. | Excluded |
| Check Point Research — The Gentlemen internal leak | Actor tradecraft and operating model | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Controls the timeline’s source-bounded description of The Gentlemen’s access, affiliate, credential, tooling, and extortion workflow. It does not confirm every victim claim. | Excluded |
| Check Point Research — CVE-2026-50751 exploitation advisory | Active exploitation and precursor activity | Used | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Controls the May 7 first-observed exploitation date, early-June acceleration, and medium-confidence Qilin association. It does not identify the access path for all Qilin claims. | Excluded |
| GuidePoint GRIT Q2 2026 | Quarter-over-quarter public victim-post direction | Used | Jul 26, 2026RANSOM-TREND-20260726 | Controls the global Q1-to-Q2 public victim-post comparison: 2,135 to 2,279, up 7%. It does not measure U.S. SMBs, confirmed incidents, encryption, demands, or payments. | Excluded |
| Coveware Q1 2026 quarterly casework | Quarter-over-quarter paid amount and payment propensity | Used | Jul 26, 2026RANSOM-TREND-20260726 | Controls the Q4-to-Q1 Coveware comparison: average paid ransom up 15%, median down 7%, and payment rate slightly up to 23%. It does not measure initial demands or a U.S. SMB-only population. | Excluded |
| Arete Q1 2026 Crimeware Report | Ransom-demand benchmark | Used | Jul 26, 2026RANSOM-TREND-20260726 | Supplies the latest retained median-demand benchmark. Because the comparison baselines are Q1 2025 and full-year 2025 rather than adjacent Q4 and Q1 quarters, the card labels current demand direction not comparable. | Excluded |
| Ransom-DB | Victim-claim discovery | Checked—not retained | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Checked but not retained as a controlling source for this edition. | Excluded |
| eCrime.ch | Victim-claim discovery | Checked—not retained | Jul 26, 2026ACT-US-SMB-RANSOM-20260726-1215 | Checked but not retained as a controlling source for this edition. | Excluded |
| ThreatFox | Active Infrastructure and Precursors | Used | Jul 26, 2026INFRA-PRECURSORS-20260726 | Seven-day authenticated API query returned 79 ransomware-tagged indicators: 77 INC payload hashes and two BianLian command-and-control endpoints. | Excluded |
| AlienVault OTX | Active Infrastructure and Precursors | Used | Jul 26, 2026INFRA-PRECURSORS-20260726 | Checked the 50 most recently returned subscribed pulses and retained five ransomware-related pulses containing 70 indicators. | Excluded |
| Hudson Rock Cavalier MCP | Credential Exposure and Ransomware Access Precursors | Planned | Not run | Awaiting a valid Hudson Rock API key. Planned read-only queries cover infostealer-derived credential, session, domain, employee, and third-party exposure; results will require local validation and will remain excluded from victim counts and corroboration. | Excluded |
| Have I Been Pwned | Credential-to-Ransomware Exposure Watch (paused) | Planned | Not run | Held for the paused credential-exposure product; not used in this ransomware victim card. | Excluded |
