CRPx0 is a newly surfaced operation, first observed on July 9, 2026, that has already claimed 37 victims, with 31 of those posted in the last 30 days, indicating an aggressive launch tempo. Healthcare (13 claims) and financial services (7) dominate the target list, with the United States (26) as the primary geography alongside a concentrated burst against Turkish financial and conglomerate targets, including multiple banks and a national airline claimed on a single day, July 31. The group is currently running an affiliate recruitment drive, advertising a 70% revenue share, XMR/BTC payouts, and a $333 access fee, framing itself as a ransomware-as-a-service operation seeking to scale quickly. No MITRE ATT&CK technique set has been catalogued for this group yet given its recency, so claimed capabilities beyond the leak-site postings remain unverified. The clustering of near-simultaneous claims against unrelated Turkish financial institutions suggests either a coordinated campaign or opportunistic batch-posting to build leak-site credibility