Triple X has surfaced on our tracker only since mid-June 2026, with three claimed victims to date and two posted in the last thirty days, suggesting a low-volume but active operation rather than a dormant listing. Its claimed targets span a US-focused legal services firm, an immigration-law site, and a large Indian financial institution (Bank of Baroda), pointing to opportunistic targeting across sectors and geographies rather than a defined niche. No sector or country aggregate data is populated for the group, and no MITRE ATT&CK technique set has been catalogued for it yet, limiting technical characterization at this stage. The group has not published a self-description on its leak infrastructure, so no claimed rhetoric or extortion messaging is available for review. Given the short operational window, the current victim set should be read as an early sample rather than an established pattern.