Mass-Victim Weeks
Every year or two a single crew converts one access route into a wave of leak-site listings that lands across every sector and region at once. Cl0p published 236 victims in the week beginning 2025-02-24: 32.6% of its entire recorded output, 644 days after its first listing (measured 2026-08-29).
That shape is invisible to every other view we publish. A sector page aggregates one industry, a country page one geography, and a wave is defined by neither — it is defined by time and by a shared access route, and it hits everything at once precisely because the victims have nothing in common except a piece of software.
The method is the product, and it is on the page. Peak-week share of lifetime output finds the bursts; days-from-debut separates them from the thing that looks identical and is not. Eight of the groups whose peak week reaches twenty claims peak in their FIRST week — a new leak site publishing its backlog on day one, not a mass exploitation event. A burst leaderboard without that column puts its loudest false positive at the top.
- Curated entries: 8
- Incidents attributed in the last 90 days: 169
- Members in the CISA KEV catalog: 3
- 35 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Remote Access Tools (T1219) 3/3 here · 16/211 tracked
- Financial Theft (T1657) 3/3 here · 20/211 tracked
- Remote System Discovery (T1018) 3/3 here · 46/211 tracked
- Valid Accounts (T1078) 3/3 here · 61/211 tracked
- Software Deployment Tools (T1072) 2/3 here · 8/211 tracked
- Encrypted Channel: Asymmetric Cryptography (T1573.002) 2/3 here · 12/211 tracked
- Proxy: Multi-hop Proxy (T1090.003) 2/3 here · 13/211 tracked
- Establish Accounts: Email Accounts (T1585.002) 2/3 here · 20/211 tracked
- Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) 2/3 here · 33/211 tracked
- Data Encrypted for Impact (T1486) 2/3 here · 40/211 tracked
Shared tooling
- Rclone 2/4 here · 31/255 tracked
- PsExec 2/4 here · 64/255 tracked
- Mimikatz 2/4 here · 73/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- Cl0p 236 of 725 claims in the week of 2025-02-24 · 32.6% of lifetime output · 644 days after its debut
- ShinyHunters 42 of 160 claims in the week of 2025-09-29 · 26.3% of lifetime output · peaked in its DEBUT week
- Akira 43 of 1,455 claims in the week of 2025-01-27 · 3% of lifetime output · 385 days after its debut
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Cl0p 725 incidents — Ransomware · Russia — 2026-09-10 — The clearest wave in our corpus: 236 claims in one week, 644 days after its debut.
- ShinyHunters 160 incidents — Ransomware · Unknown — 2026-09-22 — A large burst that lands in its own debut week — the false positive this method exists to separate.
- Medusa Ransomware 372 incidents — Ransomware · Unknown — 2026-02-14 — Negative control. Its busiest week never reaches the threshold this table uses, so it is absent from it — which is the finding.
- Akira 1,455 incidents — Ransomware · Unknown — 2026-09-22 — Negative control: the largest steady output here and the flattest curve.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2024-55956 KEV · ransomware — CVSS 9.8 · EPSS 94.0% · KEV added 2024-12-17 — Cleo, published 2024-12-13. A managed-file-transfer flaw disclosed ahead of a Cl0p wave — a sequence, not an established cause.
- CVE-2025-61882 KEV · ransomware — CVSS 9.8 · EPSS 99.7% · KEV added 2025-10-06 — Oracle E-Business Suite, published 2025-10-05, ahead of the wave later the same month.
- CVE-2023-34362 KEV · ransomware — CVSS 9.8 · EPSS 99.9% · KEV added 2023-06-02 — MOVEit — the counterexample. The event this pattern is named after contributes no victims to our corpus.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Exploit Public-Facing Application 54 groups — initial-access — Exploit Public-Facing Application: one flaw, every victim at once.
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Coe Press Equipment 2026-09-22 · Akira
- PSA - READ THIS NOW 2026-09-22 · ShinyHunters
- TDMI 2026-09-22 · Akira
- DI.C.S.EL. S.R.L. 2026-09-22 · Akira
- Fresenius Medical Care 2026-09-22 · ShinyHunters
- Prestige Management 2026-09-21 · Akira
- Note to Cl0p-_- 2026-09-20 · ShinyHunters
- Anderson Industries 2026-09-18 · Akira
- Vetta 2026-09-17 · Akira
- Practice Management (maximizedrevenue.com) 2026-09-17 · Akira
- Javep Chevrolet 2026-09-17 · Akira
- Manders 2026-09-16 · Akira
- Blossomland Accounting 2026-09-16 · Akira
- Bee Maid Honey 2026-09-16 · Akira
- Southern California Telephone Company 2026-09-15 · Akira
- Lazyboyz 2026-09-15 · Akira
- Pilot Precision 2026-09-15 · Akira
- Kimberly-Clark 2026-09-13 · ShinyHunters
- Eagle Construction 2026-09-10 · Akira
- George Cameron Nash 2026-09-10 · Akira
Our coverage
The 12 most recent of 35 briefings that mention a member of this collection.
- Extortion crews turn on ports and fuel terminals 2026-09-21
- Bug bounty hunter planted an AI-written stealer on npm 2026-09-16
- Some of August's biggest breach claims were fabricated 2026-09-14
- LockBit leads a four-fold jump in Dutch leak-site listings 2026-09-05
- Settra quietly became one of the busiest extortion crews 2026-09-04
- Exploited bugs up 34% as attackers beat the patch cycle 2026-09-03
- ShinyHunters claims 284 million records from McKesson 2026-08-31
- New ransomware crew Za Woo opens with 10 German victims 2026-08-30
- Drug distribution giant McKesson confirms data theft 2026-08-29
- Veeam bug wrote backup credentials into plain text logs 2026-08-26
- New crew Storm goes after US clinics, banks and factories 2026-08-25
- Abandoned e-learning platform has 13 flaws and no patch 2026-08-20
How this list was chosen. Membership here is illustrative and small on purpose: the burst table computes live over an incidents table the importer grows every three hours, but only for the actors on this list — a new wave appears here when a curator adds the crew, not on its own. Medusa and Akira are included as negative controls — both heavy exploiters with very large lifetime output and no burst. EVERY DATE ON THIS PAGE IS A LEAK-SITE PUBLICATION DATE, not a date of compromise; victims in these windows were typically breached weeks or months before our rows exist. Debut is a tracker date too: days-from-debut counts from a crew's first listing in our corpus, so a leak site onboarded by the tracker mid-life clears the debut-week filter and its backlog can score as a wave — a false-positive class the two columns cannot see. The two CVEs are carried for a computable date relationship to a wave, not as an established cause: we hold no link between any individual victim and any vulnerability. MOVEit is included as the counterexample — the event this page is usually named after contributes no victims to our corpus at all.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.