RansomHouse has posted 14 claimed victims in the past 30 days, a pace that includes municipal governments (City of Beacon, City of McMinnville OR), a financial entity (TECHVENTURES BANK S.A.), and construction and holding companies, with victims spanning the US, Brazil, and Luxembourg rather than concentrating in one region or sector. The group operates as a double-extortion RaaS outfit and claims lineage to an operator tracked as "Jolly Scorpius," with public-facing claims of an upgraded encryption scheme, though such claims should be treated as attacker messaging rather than confirmed capability. Repeat postings of the same named victims (Beacon, TECHVENTURES) days apart suggest either re-listing for leverage or slow verification of prior claims rather than distinct new intrusions. Cataloged ATT&CK behavior associated with this group includes data exfiltration before encryption and public leak-site shaming to pressure payment, consistent with its double-extortion model. Current activity indicates a steady, opportunistic targeting