Bavacai is a newly tracked ransomware operation, first observed in late May 2026 and active through June, with five claimed victims to date and two posted in the last 30 days. The victim set spans disparate targets, including a Canadian community living society, a French municipal government (Mairie Thiverval Grignon), and entities with unclear identities or sectors, suggesting an opportunistic rather than sector-focused targeting pattern at this stage. No sector or country concentration data is available, and no MITRE ATT&CK techniques have been catalogued for the group yet, limiting technical assessment of its intrusion or encryption methodology. Claims of compromise are attributed solely to the group's own leak-site postings and have not been independently corroborated. Given the short operational history, current activity levels are best characterized as low-volume and still forming.