Ransomware Activity Tracker
Ransomware groups are actively exploiting newly disclosed software vulnerabilities and targeting critical infrastructure at scale, with Qilin leading by victim count at 674 documented cases as of August 2026, followed by Cl0p at 177 victims; the FBI and CISA have tracked Medusa hitting over 500 U.S. critical infrastructure organizations since mid-2021, while emerging groups like Dire Wolf, documented in May 2025, and established operations like INC Ransom target healthcare, government, and manufacturing sectors across North America and Europe. Recent campaigns have leveraged flaws in Microsoft SharePoint and Windows Task Host, with Cl0p specifically conducting data theft operations against PTC Windchill and FlexPLM instances, and ransomware infrastructure has been linked to state-sponsored actors including North Korea's Lazarus Group.
- qilin
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-relea…
- Cl0p
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat…
- direwolf
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather…
- akira
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group. It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackB…
- Židlochovice city
…s: https://www.denik.cz/regiony/zidlochovice-hackeri-kyberneticky-utok-vykupne-data-software-ransomware-kldr.html https://www.irozhlas.cz/zpravy-domov/poslete-bitcoiny-nebo-vas-nepustime-k-datum-urad-v-zidlochovicich-zjistuje-skody_2603172012_bva https://www.***.cz/cs/aktuality/d…
- Židlochovice city
…s: https://www.denik.cz/regiony/zidlochovice-hackeri-kyberneticky-utok-vykupne-data-software-ransomware-kldr.html https://www.irozhlas.cz/zpravy-domov/poslete-bitcoiny-nebo-vas-nepustime-k-datum-urad-v-zidlochovicich-zjistuje-skody_2603172012_bva https://www.zidlochovice.c
- North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group have been shared with ransomware criminals targeting South Korean organizations, indicating a deepening collaboration between Pyongyang-backed hackers and the ransomware…
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed that ransomware gangs have begun abusing a high-severity vulnerability in Microsoft SharePoint. This remote code execution flaw has been actively exploited since early July.
- Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips confirmed that they are investigating data theft claims. These claims allege that the Clop ransomware gang breached their systems and stole sensitive data.
- CISA: Windows Task Host flaw now exploited by ransomware gangs
…Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting a high-severity flaw. This vulnerability concerns Windows Task Host, which had previously been flagged as being exploited…
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The FBI reported that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. The incident was highlighted by CISA, noting the significant…
- US and South Korea warn of Gunra ransomware targeting govt agencies
…The warning specifically urged securing systems against potential Gunra ransomware attacks.
- Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
…SonicWall is investigating, while CISA has cataloged 17 exploited vulnerabilities in its products since 2021, including those linked to ransomware campaigns.
- How current is the ransomware data?
- The Underground tracker ingests leak-site and threat-actor activity continuously; this page refreshes on a short cache cadence so the evidence list stays close to live.
- Does this confirm a victim was breached?
- No. Leak-site postings are claims made by threat actors. The Nexus surfaces them alongside reporting so you can assess corroboration yourself.