Mass-Victim Weeks
Every year or two a single crew converts one access route into a wave of leak-site listings that lands across every sector and region at once. Cl0p published 236 victims in the week beginning 2025-02-24: 34.9% of its entire recorded output, 644 days after its first listing (measured 2026-08-06).
That shape is invisible to every other view we publish. A sector page aggregates one industry, a country page one geography, and a wave is defined by neither — it is defined by time and by a shared access route, and it hits everything at once precisely because the victims have nothing in common except a piece of software.
The method is the product, and it is on the page. Peak-week share of lifetime output finds the bursts; days-from-debut separates them from the thing that looks identical and is not. Seven of the groups whose peak week reaches twenty claims peak in their FIRST week — a new leak site publishing its backlog on day one, not a mass exploitation event. A burst leaderboard without that column puts its loudest false positive at the top.
- Curated entries: 8
- Incidents attributed in the last 90 days: 127
- Members in the CISA KEV catalog: 3
- 16 linked briefings
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- Cl0p 236 of 676 claims in the week of 2025-02-24 · 34.9% of lifetime output · 644 days after its debut
- ShinyHunters 42 of 139 claims in the week of 2025-09-29 · 30.2% of lifetime output · peaked in its DEBUT week
- Akira 43 of 1,400 claims in the week of 2025-01-27 · 3.1% of lifetime output · 385 days after its debut
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Cl0p 676 incidents — Ransomware · Russia — 2026-07-31 — The clearest wave in our corpus: 236 claims in one week, 644 days after its debut.
- ShinyHunters 139 incidents — Ransomware · Unknown — 2026-08-02 — A large burst that lands in its own debut week — the false positive this method exists to separate.
- Medusa Ransomware 374 incidents — Ransomware · Unknown — 2026-02-14 — Negative control. Its busiest week never reaches the threshold this table uses, so it is absent from it — which is the finding.
- Akira 1,400 incidents — Ransomware · Unknown — 2026-08-06 — Negative control: the largest steady output here and the flattest curve.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2024-55956 KEV · ransomware — CVSS 9.8 · EPSS 93.8% · KEV added 2024-12-17 — Cleo, published 2024-12-13. A managed-file-transfer flaw disclosed ahead of a Cl0p wave — a sequence, not an established cause.
- CVE-2025-61882 KEV · ransomware — CVSS 9.8 · EPSS 99.7% · KEV added 2025-10-06 — Oracle E-Business Suite, published 2025-10-05, ahead of the wave later the same month.
- CVE-2023-34362 KEV · ransomware — CVSS 9.8 · EPSS 99.9% · KEV added 2023-06-02 — MOVEit — the counterexample. The event this pattern is named after contributes no victims to our corpus.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Exploit Public-Facing Application 44 groups — initial-access — Exploit Public-Facing Application: one flaw, every victim at once.
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Basic Grain Products 2026-08-06 · Akira
- Pharma Test Apparatebau AG 2026-08-06 · Akira
- University SprinklerSystems 2026-08-04 · Akira
- Albers Mechanical Contractors 2026-08-03 · Akira
- Belasco Electric 2026-08-03 · Akira
- Lumenis Ltd. 2026-08-02 · ShinyHunters
- Alcon Inc. 2026-08-02 · ShinyHunters
- Questel SAS 2026-08-02 · ShinyHunters
- BLUEVISTALLC.COM 2026-07-31 · Cl0p
- Northwood Country Club 2026-07-29 · Akira
- Franz Krause artworksgroup 2026-07-28 · Akira
- BH Security, LLC. (brinkshome.com) 2026-07-27 · ShinyHunters
- RingCentral, Inc. 2026-07-27 · ShinyHunters
- Ernst & Young 2026-07-27 · ShinyHunters
- Emerge2 Digital 2026-07-24 · Akira
- Kruse Construction 2026-07-22 · Akira
- University Sprinkler Systems 2026-07-22 · Akira
- Novasport s.r.o. 2026-07-21 · Akira
- Finer & Finer 2026-07-21 · Akira
- McKeever , Varga & Senko 2026-07-20 · Akira
Our coverage
The 12 most recent of 16 briefings that mention a member of this collection.
- Extortion crew claims Ernst and Young, RingCentral and Brinks Home 2026-07-29
- Abbott probes two breaches as extortion gangs claim patient data theft 2026-07-20
- ShinyHunters leaks data on 2.3 million Moody Bible supporters 2026-07-14
- Critical Oracle, Kemp, and Linux flaws come under active attack 2026-07-06
- ShinyHunters claims to hit test gear maker Fluke and distributor Ingram Content 2026-07-02
- Hackers poison Bing search results to drop Akira ransomware on companies 2026-06-29
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12
- LockBit floods its leak site with 26 victims in two days 2026-06-12
- ShinyHunters breached universities through an Oracle PeopleSoft zero-day 2026-06-12
How this list was chosen. Membership here is illustrative and small on purpose: the computation runs corpus-wide over an incidents table the importer grows every three hours, so the next wave surfaces without anyone editing this list. Medusa and Akira are included as negative controls — both heavy exploiters with very large lifetime output and no burst. EVERY DATE ON THIS PAGE IS A LEAK-SITE PUBLICATION DATE, not a date of compromise; victims in these windows were typically breached weeks or months before our rows exist. The two CVEs are carried for a computable date relationship to a wave, not as an established cause: we hold no link between any individual victim and any vulnerability. MOVEit is included as the counterexample — the event this page is usually named after contributes no victims to our corpus at all.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.