More ransomware crews, but far fewer victims each

Published

Forty two ransomware crews posted victim names to their leak sites in the week to 12 September 2026. Between them they claimed 165 organizations, which works out at 3.9 victims per crew, the thinnest spread in any week IntelFusions has tracked since mid March.

The headline number is not the story. Quieter weeks have happened.

Four weeks in the past six months carried fewer claims than this one did. What makes the week to 12 September unusual is its shape: the crew count went up while the output went down. Across the 26 weeks to 12 September a typical week saw about 34 crews posting and roughly 6.2 victims each. Last week 42 crews posted, well above that, and each averaged under four.

A leaderboard with a very long tail

The Gentlemen led with 21 claimed victims, followed by Krybit on 12, SafePay on 11 and Dire Wolf on 10. Those four crews accounted for 54 of the 165 claims, about a third of the week's total. Everyone else split the remainder into small handfuls, and 13 of the 42 crews posted exactly one victim apiece.

The tail is getting longer, too. Nineteen crews turned up in our tracking for the first time during August, against 11 in each of June and July. Several of last week's names, including Vexy, Emperador, Panzer and MetaEncryptor, were not there two months ago.

Qilin went quiet at the top

The single biggest contributor to the drop was Qilin, which named six victims. In the two weeks before that it named 48 and then 45. Six is the crew's lowest weekly total in six months, and it lands a fortnight after we reported that Qilin had retaken the top spot from The Gentlemen. Put Qilin back at its own six month average and the week still ranks among the thinnest per crew in the window, but it stops looking exceptional, so the crowding and the Qilin lull are best read together rather than as a single trend.

What a quiet week does and does not prove

These are unverified extortion claims, not confirmed breaches. A leak-site post is a criminal group's own assertion that it holds somebody's data, published to pressure a victim into paying, and some posts are recycled, exaggerated or simply false. Posting volume moves in bursts rather than smooth trends, so one week is a data point and not a direction, and counts for the most recent days can still tick upwards as late posts are indexed. A crew that posts nothing for a week has not necessarily stopped working either, because the gap between an intrusion and a leak-site listing is usually measured in weeks.

Read it as more doors, not fewer

For defenders the practical reading is the opposite of reassuring. A market split across 42 active crews, a quarter of them first seen within the past two months, means less predictable tradecraft and fewer recognisable playbooks than a market run by three or four mature operations. Newer crews tend to lean on the same commodity access routes, exposed remote desktop, unpatched edge devices and bought credentials, so the defensive basics do not change even as the branding does. What changes is that intelligence keyed to a handful of big names will miss more of it. Settra's climb into the top five earlier this month came from a crew almost nobody was watching.

IntelFusions tracks leak-site activity through the public ransomware.live feed, which aggregates extortion posts across active leak sites.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions