π§ Subscribe to the podcast feed
Ransomware Activity
69 victims Β· 20 groups Β· 48-hour window ending 22 Aug 2026
β οΈ = healthcare or critical infrastructure
TheGentlemen β 16 victims
| Victim | Country | Sector |
|---|---|---|
| Ariel Energia | IT | Energy & Utilities |
| Aquasea | NO | Energy & Utilities |
| Oceanica Internacional | WS | Transportation |
| CAZ Investments | BZ | Financial Services |
| ARBEITERKAMMERN | AT | Professional Services |
| ESCON Group | US | Manufacturing |
| Akatake Engineering | JP | Manufacturing |
| Magdalena Grand Beach Golf Resort | MX | Hospitality |
| LOG Systems | PL | Technology |
| dlp motive | DE | Technology |
| UOLconsult | BR | Professional Services |
| Almeer | AE | Other |
| AWJ Holding | AE | Other |
| Geb Sas | FR | Other |
| Lexacaucho | β | Other |
| P**** R***** | β | Other |
Direwolf β 13 victims
| Victim | Country | Sector |
|---|---|---|
| Studee | β | Education |
| Deer Creek-Mackinaw CUSD | US | Education |
| Reviso Cloud Accounting Limited | DK | Financial Services |
| HP Carriers | US | Transportation |
| Allstar Industries | US | Manufacturing |
| ProSim Aviation Research | NL | Technology |
| Authenticate Information Systems | US | Technology |
| Aztec Software | MX | Technology |
| iSON XPERIENCES | MX | Hospitality |
| MCT Group of Companies | AE | Other |
| The Revel Collective | US | Other |
| Diaco Global | β | Other |
| NorthStar | CA | Other |
Qilin β 9 victims
| Victim | Country | Sector |
|---|---|---|
| Quaker State Mexico | MX | Energy & Utilities |
| Gindre India | IN | Manufacturing |
| The Pendas Law Firm | US | Professional Services |
| CinΓ©polis | MX | Hospitality |
| iPic | US | Hospitality |
| Questronix | PH | Technology |
| Trends And Concepts | ZA | Other |
| Blake Services | US | Other |
| Professional | US | Other |
Titan β 9 victims (Italy focus)
| Victim | Country | Sector |
|---|---|---|
| β οΈ Alto Calore Servizi SPA | IT | Energy & Utilities (water) |
| Termotecnica Industriale S.r.l. | IT | Manufacturing |
| Elbor S.p.A. | IT | Manufacturing |
| CONDOR SPA | IT | Manufacturing |
| ELCON MEGARAD S.p.A | IT | Manufacturing |
| TECNOLOGICA S.r.l. | IT | Technology |
| Tedesco & Partners STP srl | IT | Professional Services |
| POEMA S.r.l. | IT | Other |
| CTP S.r.l. | IT | Other |
Rhysida β 2 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ Fairview Dental Group | US | Healthcare |
| Battle Creek Public Schools | US | Education |
iah6477 β 3 victims
| Victim | Country | Sector |
|---|---|---|
| regencycenters | US | Retail & E-Commerce |
| acima | US | Financial Services |
| marvin | β | Technology |
Panzer β 2 victims
| Victim | Country | Sector |
|---|---|---|
| Nteitalia | IT | Technology |
| Frisian Flag Indonesia | ID | Agriculture & Food |
Play β 2 victims
| Victim | Country | Sector |
|---|---|---|
| Be Media | US | Technology |
| Latoplast | LV | Manufacturing |
MajinaHanashi β 2 victims
| Victim | Country | Sector |
|---|---|---|
| The Margo Hotel π¬π§ | GB | Hospitality |
| Grand Ion Delemen Hotel | β | Hospitality |
Single victims
| Group | Victim | Country | Sector |
|---|---|---|---|
| Anubis | β οΈ Interim HealthCare | US | Healthcare |
| Deadlock | JP Molyneux Studio π¬π§ | GB | Professional Services |
| LockBit5 | usbank.com | US | Financial Services |
| DragonForce | Hogan Omidi P.C. | US | Professional Services |
| Akira | JC Sales | US | Retail |
| Everest | CCA Bank | β | Financial Services |
| Payload | Qualiflex Datacenter | CH | Technology |
| Emperador | NetExam | β | Technology |
| ShinyHunters | Cyrus****** | β | Technology |
| xpl0itrs | Gruppo Spaggiari Parma | IT | Manufacturing |
| SilentRansomGroup | D... | β | Unknown |
Security News
Microsoft warns of max severity Entra ID flaw exploited in attacks (BleepingComputer)
Critical vulnerability in Microsoft's cloud identity platform actively exploited in the wild at time of disclosure β patch immediately if you run Microsoft cloud identity infrastructure.
Hundreds of leaked AWS keys give full control over corporate accounts (BleepingComputer)
Active AWS access keys found exposed in public repositories, each granting full admin access. If any AWS key has left your environment, rotate and audit now.
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5 (The Register)
Dense Cisco patch release β two CVEs rated 10, plus 9.9, 9.6, and 7.5. Review the full advisory if you have Cisco infrastructure in scope.
New SynkLoader malware pushed in Microsoft Teams phishing campaign (BleepingComputer)
Windows malware loader delivered via Teams external guest access phishing β a persistent blind spot that attackers continue to exploit.
New phishing toolkit uses passkeys to maintain access after password resets (SecurityWeek)
Attackers register attacker-controlled passkeys on compromised accounts, surviving password resets. Breaks the standard remediation playbook.
Critical isolated-vm vulnerability leads to RCE on host (SecurityWeek)
Sandbox escape in the popular Node.js isolated-vm library allows host-level code execution. Patch if it's in your stack.
Canada's Hospital for Sick Children attacked by cybercriminals again as employee data stolen (The Record)
Second ransomware attack on SickKids following last year's incident β employee and job applicant data stolen. Healthcare remains a primary target.
Rust supply chain attack linked to North Korean hackers (SecurityWeek)
The poisoned arrayref crate attack attributed to North Korean threat actors β a deliberate, state-sponsored developer credential operation, not opportunistic.
Encrypted prompts bypass AI safety guardrails in Grok and Gemini (SecurityWeek)
Prompt injection confirmed to bypass safety controls in multiple major AI platforms. The attack surface continues to expand.
Lawmakers call for investigation into impact of CISA staffing cuts (The Record)
US legislators formally request probe into whether CISA β the agency responsible for US civilian cyber defence β has been significantly degraded by personnel reductions.
UK & Critical National Infrastructure
No new NCSC advisories in the past 48 hours.
UK ransomware victims this cycle:
- The Margo Hotel (Hospitality) β claimed by MajinaHanashi, publication pending
- JP Molyneux Studio (London interior design) β claimed by Deadlock
Both are lower CNI criticality. The sharper UK angles are broader:
- The Microsoft Entra ID exploitation affects any organisation on Microsoft cloud identity β covering the majority of UK public sector and enterprise.
- Cisco's critical patch cluster applies equally to UK infrastructure operators.
- TheGentlemen's European energy sector targeting (Italy, Norway, Austria) is worth flagging to UK OT defenders.
- The Titan group's continuing focus on Italian utilities β including Alto Calore Servizi, a Campania water authority β is the most significant active CNI exposure in this cycle.
CISA Known Exploited Vulnerabilities
No new KEV entries added on 22 August 2026.