iah647 surfaced on our tracker on 2026-08-20 with no prior activity history, immediately claiming three victims (acima, regencycenters, and marvin) on the same day, suggesting either a coordinated launch or a batch disclosure of pre-staged intrusions. No sector or country metadata is currently attached to the claims, and no MITRE ATT&CK techniques have been catalogued for the group, leaving its intrusion methods, encryption tooling, and extortion infrastructure unconfirmed. There is no description on file, so any claims of scale or capability the group may later post to a leak site should be treated as unverified attacker rhetoric rather than fact. Given the single-day, triple-victim debut, this appears to be either a newly formed operation or a rebrand testing its public claim mechanism, and its true operational tempo will only become clear with further observation.