Orion surfaced on our tracker on August 5, 2026, with a single claimed victim, the Indian firm nitrex.in, and no sector or country pattern has yet emerged given the sparse sample. The group is described in open-source reporting as having appeared in October 2025 with a leak site listing 13 alleged victims across financial services, manufacturing, and healthcare, though analysts assessed that list as recycled entries from earlier LockBit and BlackCat disclosures rather than original compromises, a claim that should be treated with skepticism given the group's apparent history of reused victim data. No MITRE ATT&CK techniques have been catalogued for this actor, and no confirmed technical tradecraft is currently attributable to it. With only one claim in the last 30 days and a one-day observation window, Orion's actual operational capacity, infrastructure, and targeting logic remain unverified. Continued monitoring is warranted to determine whether this is an active operation or another instance of leak-site recycling to inflate perceived activity.