Orova surfaced on our tracker in early August 2026 and has already claimed 17 victims within thirty days, a pace consistent with an active, newly launched operation rather than a dormant or fading one. Targeting skews heavily toward the United States (14 of 17 claims), with a scattershot mix of small and mid-sized organizations: churches, HOAs, an HVAC contractor, a dental practice, and manufacturing and professional services firms, alongside three claims in Hong Kong. The "Other" category dominates the sector breakdown, suggesting the group is not concentrating on a single vertical but is instead opportunistic in victim selection. No MITRE ATT&CK techniques have yet been catalogued for this group, limiting technical attribution beyond its claim pattern. Orova's self-description on leak infrastructure should be treated as unverified attacker messaging rather than established fact.