One open-source tracker counted roughly 315 victim posts from 40 active ransomware groups in the seven days to 9 August 2026. Eight of those names were new to its weekly view. The figures come from RansomLook and were compiled by DataBreach.com. They count leak-site posts, not confirmed breaches, and those are not the same thing.
Treat the absolute number with suspicion. Treat the shape of it seriously. Eight new brands in a single week is not a reporting artefact.
That breaks something most security teams still rely on. If your detection content, your intel briefings and your tabletop scenarios are organised by group name, you are maintaining a list that turns over faster than you can write rules against it.
The trackers disagree on nearly everything except direction
Line the main counts up and they refuse to reconcile.
| Source | Window | Victims or posts | Active groups |
|---|---|---|---|
| RansomLook, via DataBreach.com | 7 days to 9 Aug 2026 | ~315 leak-site posts | 40 (8 new to the weekly view) |
| Breachsense | August 2026 | 964 claimed victims, up 19% on July | 83, up from 66 in July |
| Black Kite | Apr 2025 — Mar 2026 | 7,551 disclosed victims, up 24.9% | 146 by June 2026; 61 new in the period |
| IBM X-Force | Calendar 2025 | Not directly comparable | 109 distinct extortion groups, against 73 in 2024 |
Different windows, different deduplication rules, different definitions of what counts as a group. Black Kite sells third-party cyber risk ratings, so it has a commercial interest in the curve pointing upwards; its figures are still the most methodologically transparent of the four. IBM X-Force also reports that the ten largest groups lost a quarter of their share of observed activity.
The DataBreach.com analysis makes the sharpest methodological point in the whole debate: a new name is not necessarily a new gang, and a leak-site post is not necessarily a verified breach. Reposted victims, resold datasets, exit-scam noise and outright fabrication all inflate these counts. Breachsense recorded five of August's top ten groups as unranked the previous month. That is either an ecosystem reorganising itself monthly or a measurement system that cannot hold identity stable. Probably both.
Takedowns disperse capacity, they do not remove it
The pattern is now well documented. When the FBI and international partners seized ALPHV/BlackCat infrastructure in December 2023, the group re-pointed its .onion domain within hours; Recorded Future's Allan Liska explained at the time that the operator simply installed the existing key pair on a new server. Operation Cronos hit LockBit in February 2024 and took infrastructure, source code and decryption keys. Neither operation arrested most of the people doing the work.
What those operations did achieve was the destruction of trust inside large affiliate programmes. Trellix's John Fokker described the resulting dynamic as a "Mexican standoff" of mutual suspicion, according to reporting by The Record, which also cited Malwarebytes tracking 41 new gangs between July 2024 and June 2025. Affiliates who no longer trust a brand to pay them, and who have watched two flagship operations get infiltrated, have an obvious alternative: run their own shop.
The tooling is free. The LockBit 3.0 builder leaked in September 2022 after a falling-out with a developer, and copycat operations have been compiling binaries from it ever since. DataBreach.com reports that Global Secret Group surfaced in June 2026, went public in July, and paired LockBit 3.0 code with an existing workflow. That claim rests on that single report and we could not confirm it independently — but the mechanism is real and four years old.
A rule keyed to a group name detects last quarter's incident. A rule keyed to a domain admin account deleting shadow copies at three in the morning detects next quarter's, under whatever logo it arrives.
The chain is identical under every logo
Compare two CISA advisories issued two years apart, for groups with no shared branding. RansomHub (AA24-242A, August 2024) and Gunra (AA26-222A, 10 August 2026) describe substantially the same operation.
Access. RansomHub affiliates used phishing, password spraying against breached credentials, and a list of known CVEs. Gunra actors hit FortiOS and FortiProxy authentication bypasses — CVE-2024-55591 and CVE-2025-24472 — then harvested VDI credentials off SSL-VPN traffic and modified portal files to accept a predetermined OTP value. Cisco Talos put valid accounts at 24 per cent of its Q1 2026 engagements and found MFA weaknesses in 35 per cent.
Discovery. RansomHub ran AngryIPScanner, Nmap and PowerShell. Gunra used Impacket — secretsdump.py against domain controllers, psexec.py and smbclient.py for lateral movement — plus pass-the-hash and pass-the-ticket. Different binaries, one behaviour: authenticated enumeration of the domain from a foothold, fast.
Recovery inhibition. RansomHub called vssadmin.exe to delete volume shadow copies. Gunra used WMIC.exe shadowcopy ... delete and, per CISA, deleted backup data at both primary and disaster-recovery sites. Same ATT&CK technique, T1490, either way.
Exfiltration. RansomHub: WinSCP, Rclone, PuTTY, AWS S3 tooling, raw HTTP POST. Gunra: 7-Zip and WinRAR to stage, then Rclone, Mega and FileZilla to move what CISA describes as up to tens of terabytes.
Encryption. Only at the end, and only as the billing mechanism.
Four of those five stages are noisy, slow relative to encryption, and происходят on hosts you already log. The brand is decided at stage five. Every defensive decision worth making happens before it.
What to instrument this quarter
- Alert on shadow copy and backup deletion as a P1, every time. Cover
vssadmin delete shadows,wmic shadowcopy delete,wbadmin delete catalogandbcdedit /set recoveryenabled No. Legitimate use is rare enough that the false-positive cost is low and the signal value is enormous. - Treat first-seen VPN authentication from a new ASN or geography as a hunt trigger, not a log line. Pair it with what happens in the next fifteen minutes: SMB enumeration, LDAP queries, port scanning.
- Detect the exfiltration utilities by behaviour, not hash. Rclone, WinSCP, FileZilla and MEGAsync are legitimate software. Outbound volume anomalies from servers that have never egressed data, and archive creation by 7-Zip or WinRAR on file servers, are the actual tells.
- Alert on EDR and logging tampering. Service stops, driver loads matching known vulnerable-driver lists, Windows event log clears. CISA documented both groups clearing logs.
- Make your backups immutable and test a restore against a real RTO. If an attacker with domain admin can reach the backup system, you do not have backups.
- Rescan your own edge estate against KEV monthly. Not quarterly.
That last point deserves the closing word. Black Kite rescanned the organisations in its victim dataset after the fact and found 43.5 per cent still carrying a CVSS 9.0-or-higher vulnerability and 30.8 per cent still carrying a Known Exploited Vulnerability. The group that hit them may have rebranded twice since. The unpatched appliance that let them in is still there, still listening, waiting for whichever logo turns up next week.


