Blackwater has claimed six victims in the past 30 days, a pace consistent with steady, opportunistic activity rather than a targeted campaign, with recent postings spanning Argentina, India, Brazil, and China across professional services, energy and utilities, and hospitality sectors. The group first appeared on tracking systems in June 2026 and describes itself as a double-extortion operation combining file encryption with data theft, though this framing is the group's own claim and unverified. Its all-time victim count stands at ten, suggesting a young, still-scaling operation rather than an established franchise. No MITRE ATT&CK techniques have been catalogued for this group to date, limiting visibility into its actual intrusion and encryption methodology beyond its self-reported extortion model. Victim naming so far shows no clear sectoral or regional concentration, indicating the group is likely casting a wide net rather than specializing.