Abyss (also tracked as Abyss Locker) surfaced on our tracker on June 1, 2026, with two claimed victims posted on the same date: School Facility Consultants, a business-services firm of unspecified location, and Landkreis Limburg-Weilburg, a German public-sector entity, marking a geographic pivot toward Europe that sits outside the North American concentration typically associated with this group. Both claims appeared simultaneously, suggesting either a coordinated posting cadence or a backlog release rather than real-time disclosure. Derived from the leaked Babuk source code, the group is reported to target Windows and Linux/VMware ESXi environments, with Linux variants known to terminate virtual machine processes before encrypting datastore files to maximize impact. Abyss operators are also reported to disable or tamper with backup and recovery tooling prior to deployment, pairing that with a data-leak site to apply double-extortion pressure on victims. With only two claims on record within our tracking window, the current operational tempo is low, but the cross-sector spread (public administration and business services) and the German victim entry point are worth noting.