Blackout surfaced on tracking systems within the past week, posting four claimed victims in a tight 48-hour window spanning Japan, the United States, and the United Kingdom, with technology firms as the current concentration and one professional services target. The group is described in open-source reporting as active since early 2024, claiming a shift from initial healthcare-sector targeting in Canada, France, and Germany toward telecommunications, mining, and manufacturing, though this week's activity shows no sector loyalty beyond a technology tilt. Blackout is described as running a double-extortion model backed by a dedicated leak site, consistent with the repeated posting of bluebellgroup.com across two consecutive days, suggesting either a staged disclosure or a re-listing tactic. No MITRE ATT&CK technique set has been catalogued for this group yet, leaving its intrusion and encryption tooling unconfirmed. Given the short operational history on record, current volume and geographic spread should be read as an opening posture rather than an established pattern.