CMD, a ransomware crew that first surfaced in May 2026, spent July working steadily through small and mid-sized organizations, and schools keep turning up on its list. The group has posted 12 victims to its leak site since July 7, including three educational institutions in Canada and Colombia, according to leak-site claims tracked by IntelFusions.
One caveat governs everything below. These are unverified extortion claims posted by the group itself, and a leak-site listing is a sales pitch rather than a confirmed breach. Crews routinely overstate what they took, recycle old data, and occasionally list organizations they never reached. None of the victims named here has publicly confirmed an incident, and CMD has published no proof that IntelFusions has reviewed.
Who CMD is claiming
The latest run is five claims in four days. On July 31 the crew listed Stewart Belland & Associates, a Canadian professional services firm. The day before it posted three at once: Contact Group in Australia, the US electrical contractor Rondout Electric, and Collège Mont Notre-Dame de Sherbrooke, a private school in Quebec. B-K Tool & Design, a US manufacturer, went up on July 28.
Earlier in the month the group claimed T Simon Jewelers in the US, Saint George's School in Colombia, Target Energy Solutions, the autism charity Els for Autism, the mining firm Golden Star Resources in Ghana, Finance Yorkshire in the UK, and Mount Royal University in Canada. That is six countries in a little over three weeks.
Why the pattern matters
Three of the 12 July claims are schools or universities, which continues a theme rather than starting one. Education, small professional services firms and charities share a profile that extortion crews find attractive: real personal data, limited security staffing, and enough operational pressure to make paying feel like the fast way out. CMD is not running anything like the volume of Qilin or INC Ransom, with 43 claims in total since it appeared on May 2, but it is consistent, and it has not slowed since we first wrote about it hitting a Norwegian municipality and healthcare firms in June. Canada accounts for three of the July claims, and our Canada threat profile tracks how the wider picture there is shifting.
What you should do
For organizations that fit the profile CMD favors, the useful work is unglamorous. Keep offline backups and actually test a restore from them, enforce multi-factor authentication on remote access and administrator accounts, and make sure somebody would notice bulk data leaving the network at three in the morning. Schools in particular should confirm who holds student and parent records, including anything sitting with a third-party supplier, since that is where this kind of data usually leaks from. If your organization does appear on a leak site, treat it as a possible data breach and start the notification clock rather than waiting to see whether the crew publishes. Our CMD profile is updated as new claims are posted.
This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.