Skip to content
The Nexus
Topic · Cyber285 cited itemsLatest Aug 26, 2026

Ransomware Activity Tracker

Ransomware groups are actively exploiting newly disclosed software vulnerabilities and targeting critical infrastructure at scale, with Qilin leading by victim count at 674 documented cases as of August 2026, followed by Cl0p at 177 victims; the FBI and CISA have tracked Medusa hitting over 500 U.S. critical infrastructure organizations since mid-2021, while emerging groups like Dire Wolf, documented in May 2025, and established operations like INC Ransom target healthcare, government, and manufacturing sectors across North America and Europe. Recent campaigns have leveraged flaws in Microsoft SharePoint and Windows Task Host, with Cl0p specifically conducting data theft operations against PTC Windchill and FlexPLM instances, and ransomware infrastructure has been linked to state-sponsored actors including North Korea's Lazarus Group.

Underground278 matches
  • Aug 26, 2026Group · 721 victims
    qilin

    Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-relea…

  • Aug 14, 2026Group · 177 victims
    Cl0p

    The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat…

  • Aug 25, 2026Group · 86 victims
    direwolf

    Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather…

  • Aug 26, 2026Group · 176 victims
    akira

    The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group. It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackB…

  • Jul 10, 2026Victim · Public Sector · CZ
    Židlochovice city

    …s: https://www.denik.cz/regiony/zidlochovice-hackeri-kyberneticky-utok-vykupne-data-software-ransomware-kldr.html https://www.irozhlas.cz/zpravy-domov/poslete-bitcoiny-nebo-vas-nepustime-k-datum-urad-v-zidlochovicich-zjistuje-skody_2603172012_bva https://www.***.cz/cs/aktuality/d…

  • Jun 15, 2026Victim
    Židlochovice city

    …s: https://www.denik.cz/regiony/zidlochovice-hackeri-kyberneticky-utok-vykupne-data-software-ransomware-kldr.html https://www.irozhlas.cz/zpravy-domov/poslete-bitcoiny-nebo-vas-nepustime-k-datum-urad-v-zidlochovicich-zjistuje-skody_2603172012_bva https://www.zidlochovice.c

Articles7 matches
Frequently asked
How current is the ransomware data?
The Underground tracker ingests leak-site and threat-actor activity continuously; this page refreshes on a short cache cadence so the evidence list stays close to live.
Does this confirm a victim was breached?
No. Leak-site postings are claims made by threat actors. The Nexus surfaces them alongside reporting so you can assess corroboration yourself.
More topics