The ransomware crew known as Crpx O has resurfaced after more than two weeks of silence, naming 10 US organizations on its dark web leak site in a single day. The new batch is a clear break from the group's debut, which was almost entirely small dental practices. This list is led by IT, hosting and cloud companies, alongside a law firm, two financial firms, an aviation caterer and an aerospace maintenance business. As with every leak site roster, these are unverified extortion claims posted by the attackers themselves, not confirmed breaches.
Crpx O first appeared in IntelFusions tracking on 2026-07-09, when it named six healthcare victims, five of them US dental offices, in an unusually narrow debut. It then went quiet for 18 days. The listings posted on 2026-07-27 take the crew's running total to 16 claimed victims, and every one of the new names is based in the United States.
Who the crew named
- Technology: Host & Protect (RedBlink), RnnR Cloud and CodeConductor.ai
- Professional services: FLP Law Group LLP and Performance Data Solutions
- Financial services: Prei Capital and Summit Hill Insurance
- Healthcare: ProSmile Family Dental Care
- Transportation: Qube Aviation Catering
- Manufacturing: MRO Aerospace
Why the shift matters
Three of the 10 are technology firms that host, run or build systems for other businesses. That is the detail defenders should watch. When an extortion crew reaches a hosting or cloud provider, the data it walks away with is often not just the provider's own, and customers usually learn about it last. Crpx O has published no data samples, ransom figures or intrusion details that would show how far into any of these environments it actually got, so the scale of any downstream exposure is unknown.
The one dental listing, ProSmile Family Dental Care, shows the crew has not dropped the clinics it started with. Widening from a single niche into whatever is reachable is a familiar path for a young extortion brand trying to build a reputation, and leak site debuts are frequently padded with recycled or stale victims to manufacture credibility. Two aviation linked names in the same batch, Qube Aviation Catering and MRO Aerospace, are worth noting but not enough on their own to establish a sector campaign. The crew joins a crowded month of new leak site brands, including the 28 victim debut of Global Secret Group.
What to do
Any organization on the list should assume data theft is possible, preserve logs and endpoint telemetry before rebuilding anything, and start the clock on breach notification duties rather than waiting for the claim to be proven. The dental practice and its patient records fall under HIPAA obligations regardless of whether the encryption stage ever ran.
For everyone else, the practical step is to ask which of your suppliers appear on lists like this one. Confirm that offline and tested backups exist, that multi factor authentication covers all remote access, VPN and email, and that administrative access held by your hosting or managed service providers is scoped and monitored. New listings are tracked on the Crpx O profile.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.