The ransomware crew NightSpire spent most of July posting one victim at a time. On 27 July it posted 12 at once, spread across nine countries in Europe, Asia and North America, its largest single-day batch since April 2025.
These are claims, not confirmed breaches. Every name comes from the gang's own data-leak site, where extortion crews list organisations they say they have hacked in order to pressure them into paying. Listings are sometimes old data, sometimes exaggerated, and sometimes recycled from another crew's haul. IntelFusions has not verified any of the twelve.
Who was named
The batch is weighted towards industry rather than household names: manufacturers in France, Thailand, Turkey and the United States, technology companies in Singapore and Switzerland, a US professional services firm, a US financial services firm, a Malaysian hospitality business, two Indian companies and a UK business. Four of the twelve are manufacturers, and only three are US-based, a wide geographic spread for a single day of postings.
The listing for the Turkish manufacturer MKS Transformator is the only one carrying a data inventory, and it is expansive: accounting and finance records, project data, purchasing and procurement documents, quality and document-control records, maintenance logs, HR files and production data. That inventory is the standard proof-of-exfiltration format on double extortion leak sites. It describes what the crew says it holds, not anything we have confirmed about the company's network.
Why the pattern matters
Batch posting usually reflects how a crew is organised rather than a sudden burst of hacking. Victims accumulate quietly during a private negotiation window, and the listings go up together when the deadlines lapse. In practice that means the intrusions behind a 12-victim drop may be weeks or months old, and other organisations caught in the same wave may still be inside a countdown nobody has told them about.
NightSpire has been running since March 2025 and now accounts for 247 leak-site claims across 51 countries in our tracking, up from the 166 victims in 33 countries we counted in March. Our February profile of the group traced it as a rebrand that moved from plain data theft to double extortion within weeks of appearing. One day of postings now accounts for three quarters of everything it has claimed in the past 30 days, which is the tempo of a crew working in bursts, not a crew winding down.
Other crews have posted comparable batches this month, including Deadlock's July batch of industrial victims. The exposure is the same in each case: industrial suppliers hold contract, engineering and personnel data that matters well beyond their own walls.
What you should do
If your organisation or one of your suppliers turns up in a leak-site listing, treat it as a live incident until you can prove otherwise. Preserve logs before rebuilding anything, review remote access and VPN accounts for unfamiliar logins, reset credentials on every account that touched an affected system, and assume data left the building even if nothing was encrypted. Manufacturers in particular should check whether engineering and production file shares are reachable with the same accounts that read email, which is a common route to the valuable files.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.