Lamashtu has posted three new victim claims in the past 30 days, spanning food production and manufacturing targets in Egypt, Thailand, Malaysia, Austria, and Germany, with no repeated geographic or sector focus emerging beyond a light concentration in agriculture and food production. The group surfaced on trackers in mid-May 2026 and has claimed nine victims to date, a pace consistent with a newer extortion outfit still establishing a cadence rather than an entrenched, high-volume operation. It is described in its own materials as having hit energy, pharmaceutical, and film-sector organizations in France, Romania, and Thailand, though that self-reported victim history has not been independently verified and no MITRE ATT&CK technique set has been catalogued for the group. Critically, Lamashtu has not been confirmed to deploy actual file-encrypting malware; its claims to date are consistent with pure data-theft extortion rather than validated ransomware deployment. Activity remains scattered across unrelated countries and industries, suggesting opportunistic targeting rather than a