Underground
Public ransomware leak-site postings, aggregated and stripped of attacker infrastructure. Tracks which groups are active, what sectors they hit, and where claimed victims are based. Useful as an early signal, not a breach confirmation.
By the numbers: the ransomware report →Claimed postings climbed to 545 for the week, up from 504, and the growth concentrated in three groups rather than spreading evenly across the field. Qilin posted 88 victims, the highest single-group total, but the sharper story is the gentlemen adding 43 week-over-week to reach 76 and direwolf adding 30 to reach 52. Together those three groups account for a large share of the week's total volume, while a cluster of new entrants (titan, xpl0itrs, lockbit5, Pure Extraction And Ransom) each posted double-digit victim counts in their first week of tracked activity.
Coinbase cartel's listings stood out less for volume (20 claimed, +12) than for spread: its named victims this week ranged from a Puerto Rican health system and a French engineering consultancy to Indonesian banking and manufacturing firms, indicating a leak-site posting pattern with no evident sector or regional focus. Sector distribution overall skewed toward technology and manufacturing, each near the low thirties, with professional services close behind, but no single sector approached dominance. Geographically the US led with 66 claimed listings, more than three times the next-closest country (Italy, 19), keeping the week's activity centered on North America even as European and Southeast Asian names surfaced in the coinbase cartel postings.
The net picture is one of consolidation among a small set of active groups rather than a broad surge across the ransomware field, with named victims spanning finance, healthcare, and manufacturing sectors across at least eight countries.
The vulnerabilities attackers are using right now. Where Underground shows who got hit, KEV shows what they came in through.