Ransomware summary week 31, 2026

Anubis ransomware forced Coca-Cola’s Fairlife subsidiary to halt all US milk production this week, while Qilin and The Gentlemen continued trading the top spot on leak-site rankings across a wave of European manufacturing and Japanese transportation victims.
ransomware
Published

August 4, 2026

Executive Summary

The week of July 24 to July 31 was dominated by Anubis ransomware’s attack on Fairlife, the Coca-Cola-owned dairy brand, which halted every US production line after the group claimed to have stolen a terabyte of data and encrypted the company’s Nutanix infrastructure. Coca-Cola’s refusal to pay led to a data leak around July 28, and reporting points to CitrixBleed 2 or compromised VPN credentials as the likely entry point. Across the Atlantic, Qilin remained the most prolific European operator, adding French chocolate maker Cemoi and real estate firm Savills France to its leak site, while LockBit 5.0, Gunra, Play, and INC Ransom claimed victims scattered across Italy, Spain, and Switzerland. In Asia, the AiLock group disrupted dispatch and reservation systems at Nihon Kotsu, Japan’s largest taxi operator, and India’s Tikona Infinet and Bank of Baroda both faced extortion attempts, the latter via a newer actor calling itself TripleX. Leak-site tracking for the week immediately prior counted 224 new victims across 50 countries claimed by 43 distinct operators, consistent with a July that produced roughly 840 victims globally across 81 countries. On the enforcement side, the US Treasury sanctioned VPN provider First VPN Service and its Ukrainian administrator for enabling ransomware operators, a follow-up to May’s multinational Operation Saffron takedown, while the nonprofit Crime Stoppers International launched a bounty program targeting INC Ransom’s infrastructure.

Key Statistics: - Global: Roughly 840 victims added to leak sites in July across 81 countries and 63 operators, with the week of July 20-26 alone accounting for 224 new victims across 50 countries; The Gentlemen and Qilin continued to trade the top spot, with The Gentlemen posting 300 victims in the second quarter against Qilin’s 289 - Europe: At least seven named victims across Germany, France, Italy, Spain, and Switzerland, with Qilin, LockBit 5.0, Gunra, Play, and INC Ransom all active; regional incident counts rose 55.1 percent year over year through the first four months of 2026 - Asia: Japan’s largest taxi operator disrupted by AiLock, alongside extortion attempts against Indian telecom and banking firms; no confirmed healthcare or municipal victims identified this week - US: Fairlife’s nationwide production shutdown anchored the week, with Akira, Play, DragonForce, CMD Organization, and Deadlock claiming smaller manufacturing, transport, and biotech victims - Other: Victims confirmed in Australia, Argentina, and Canada; no named incidents surfaced in the Middle East or Africa despite targeted searches, a gap worth flagging rather than filling with speculation


1. EUROPE

1.1 Government

No ransomware group publicly claimed a European national government agency this week. The broader trend still points toward government being an increasingly attractive target: government-sector ransomware attacks rose 13 percent globally in the first half of 2026 to 187 incidents, with Germany recording nine and France eight, placing them second and third worldwide behind the United States. UK lawmakers advanced legislation during the week of July 14 that would ban ransom payments by public-sector bodies and critical national infrastructure operators, including the NHS and local councils, and would introduce mandatory 72-hour incident reporting. Separately, a breach affecting more than 80,000 Fortinet firewalls across 194 countries, dubbed FortiBleed, surfaced stolen credentials tied to NHS systems, pharmacies, medicine suppliers, and Derbyshire and Waltham Forest councils being sold for roughly £44,000. The breach is a precursor-access issue rather than a confirmed ransomware attack, but it raises the near-term risk profile for UK public-sector targets considerably.

1.2 Health, Municipalities & Non-commercial

German rehabilitation and healthcare services provider RehaVital Gesundheitsservice GmbH was claimed by Qilin this week, with operations disrupted and data encrypted. The incident fits a pattern researchers have tracked across the EMEA healthcare supply chain throughout 2026, where hospitals, diagnostic labs, pharmacies, rehabilitation providers, and medical suppliers have all been drawn into ransomware campaigns, often because they sit adjacent to better-defended hospital networks but hold equally sensitive patient data.

1.3 Business

Qilin’s most notable European claims this week were French chocolate manufacturer Cemoi, threatened with a data leak after an attack claimed on July 13, and Savills France, the real estate firm, where a breach was discovered on July 27. LockBit 5.0 claimed responsibility for an attack on Italy’s Ravagnan Group, while the Gunra group targeted Spanish manufacturer New Tiles S.L. and Play ransomware struck Spanish car rental company Record Go Alquiler on July 23. In Switzerland, INC Ransom claimed Della Casa Group AG on July 29. These incidents sit within a broader European surge: ransomware activity across the continent rose 55.1 percent year over year in the first four months of 2026, averaging 171 incidents a month, with Germany, the UK, France, Italy, and Spain accounting for nearly 69 percent of the 2,066 incidents recorded across 31 countries. Manufacturing alone made up 28 percent of European incidents, and Qilin was the single most common operator, appearing in 26 of the 31 countries tracked.


2. ASIA

2.1 Government

No Asian government agency was claimed by a ransomware operator this week. The most consequential government-adjacent development came from South Korea, where law enforcement disclosed around July 31 that the Lazarus Group has been sharing tools with ransomware-affiliated hackers, and that state-linked actors weaponized the country’s mandatory banking software, AnySign4PC, as a zero-day to install backdoors.

2.2 Health, Municipalities & Non-commercial

No incidents reported this week.

2.3 Business

The week’s most disruptive Asian incident hit Nihon Kotsu, Japan’s largest taxi and chauffeur dispatch operator, where the AiLock ransomware group claimed responsibility and disrupted dispatch, reservation, and internal IT systems. In India, telecommunications provider Tikona Infinet was claimed by The Gentlemen on July 23, which threatened to leak confidential data, while Bank of Baroda confirmed unauthorized access to an employee email account after a threat actor calling itself TripleX posted a terabyte of data for free on a dark web platform on July 24. The bank said its core banking systems were unaffected, and the incident reads more as data-theft extortion than confirmed encryption-based ransomware, but it illustrates how loosely the two tactics are now blurred in incident reporting.


3. UNITED STATES

3.1 Government

No US federal, state, or local government agency was confirmed as a ransomware victim this week.

3.2 Health, Municipalities & Non-commercial

No healthcare or municipal ransomware victims were confirmed in the United States this week, though the sector’s underlying exposure remains elevated: healthcare organizations worldwide recorded 410 ransomware attacks in the first half of 2026, up 14 percent from the second half of 2025, with a median ransom demand of roughly $310,000 against direct care providers. Qilin and The Gentlemen were the two most active operators against the sector.

3.3 Business

Fairlife, the dairy subsidiary Coca-Cola acquired in a deal that made it a nearly four-billion-dollar-a-year brand, was the week’s dominant story. Anubis ransomware added the company to its leak site on July 20, claiming a terabyte of stolen data and encryption of Fairlife’s Nutanix hyperconverged infrastructure, and every US production facility was shut down while Canadian operations continued normally. Coca-Cola disclosed the incident to regulators on July 16 and reportedly refused to pay, prompting Anubis to leak the stolen data around July 28. Investigators are examining CitrixBleed 2 or compromised VPN credentials as the likely point of entry, with the intrusion believed to have begun roughly a week before public disclosure. Smaller US incidents this week included trucking company L&A Transport, claimed by Akira; architecture firm Kreysler & Associates, claimed by Play; biotechnology company Syntron Bioresearch, claimed by DragonForce on July 26; electrical contractor Rondout Electric, claimed by the newer CMD Organization group on July 30; and Pasello, claimed by Deadlock on July 28.


4. REST OF WORLD

4.1 Government

No incidents reported this week.

4.2 Health, Municipalities & Non-commercial

No incidents reported this week.

4.3 Business

In Australia, the CMD Organization claimed Contact Group, a firm based in Tasmania, on July 30. Energy provider Origin Energy also confirmed unauthorized access to customer data including names, addresses, dates of birth, and partial payment details following an incident that began July 22, though no ransomware group has publicly claimed responsibility, leaving open the possibility this was a data-theft extortion attempt rather than encryption-based ransomware. In Argentina, the Deadlock group claimed hardware and building-supply company Relesa on July 25, and The Gentlemen were linked to activity against Argentine retailer Ferretería Scopazzo and multinational technology firm Indra, though exact dates for those two claims could not be confirmed against this week’s window. In Canada, Interlock ransomware claimed the Centre for Newcomers, a Calgary-based immigration services nonprofit, adding another community organization to the list of Canadian nonprofits targeted this year, with roughly 380 gigabytes of client and company data reportedly compromised. No named ransomware victims were identified in the Middle East or Africa this week despite targeted searches; both regions continue to show measurable ransomware activity in aggregate quarterly statistics, but no specific, dated incident from this week could be confirmed.


5. THREAT ACTOR ACTIVITY

The Gentlemen and Qilin spent July trading the title of most active ransomware operator. The Gentlemen posted 300 victims in the second quarter, narrowly ahead of Qilin’s 289, and recorded its highest monthly total yet in June with 117 victims, roughly four times its January count. The group originated as ArmCorp, a Qilin affiliate that split off in mid-2025 after a payment dispute over unpaid commission, and its attacks on the education sector are up 275 percent in the first half of 2026 compared with the second half of 2025, with four out of five of those attacks hitting colleges and universities.

Cl0p opened a large-scale extortion campaign against internet-exposed PTC Windchill PDMLink and FlexPLM servers, exploiting a critical deserialization flaw disclosed in June, with extortion emails sent from compromised internal accounts to hundreds of employees per victim organization. The campaign mirrors Cl0p’s earlier MOVEit and Oracle EBS playbooks and is concentrated on manufacturing, automotive, aerospace, and retail targets. Researchers also flagged JadePuffer as what may be the first publicly documented ransomware operation run end to end by an autonomous LLM agent, handling reconnaissance, credential theft, lateral movement, and encryption exploiting known Langflow and Alibaba Nacos vulnerabilities without human operation at each stage. Separately, a threat cluster tracked as STAC4749 has been using Microsoft Teams voice-call impersonation of IT support staff to talk targets into granting remote access, ultimately deploying Chaos ransomware against North American organizations.

The Scattered Spider, ShinyHunters, and LAPSUS$ alliance remains active, running concurrent campaigns against Salesforce Experience Cloud misconfigurations and EU institutional infrastructure, and researchers say the group is developing its own ransomware or crypto-locker platform, with at least one sample already observed in the wild. Seven newly tracked ransomware operators emerged in July: CRPxO, D1R, DOOMMAGEDDON, ExfilSquad, GAMMAX, Global Secret Group, and Wallstreet. INC Ransom, ranked sixth most active in June, passed 872 claimed victims by July 27 and was reportedly exploiting SonicWall SMA 1000 flaws in a follow-on campaign heading into August.

On the enforcement side, the US Treasury sanctioned First VPN Service and its Ukrainian administrator, Dmytro Rashevskyi, on July 13, marking the first time a VPN provider has been sanctioned specifically for enabling ransomware attacks on American hospitals, municipalities, and businesses. The action followed May’s Operation Saffron, a French and Dutch-led takedown supported by Europol, Eurojust, and the FBI that seized 33 servers across 27 countries. The same coordinated action saw the EU sanction the administrator behind the Trickbot malware family, operators of the LummaC2 infostealer, bulletproof hosting provider Media Land LLC, Russia’s GRU Unit 29155, and pro-Russia hacktivist groups CARR and Z-Pentest. Toward the end of the week, the nonprofit Crime Stoppers International launched Operation Silent Vector, offering a $22,000 reward for information leading to the identification or disruption of INC Ransom’s infrastructure, making the group the first target of the new bounty program.


6. KEY TAKEAWAYS

Ransomware operators are increasingly comfortable claiming household-adjacent brands rather than only mid-market firms, and Fairlife’s nationwide production shutdown is a reminder that a single compromised credential or unpatched edge device can cascade into a full stop of physical output at scale. Organizations running Citrix, VPN concentrators, or other remote-access infrastructure should treat credential rotation and patching for known exploited vulnerabilities as time-critical rather than routine maintenance, given how directly that access class has been tied to this week’s largest incident.

The Gentlemen’s rapid rise, its origins as a Qilin splinter group, and its disproportionate targeting of education illustrate how quickly the ransomware-as-a-service ecosystem reorganizes itself around payment disputes and affiliate defections, producing new high-volume operators within months rather than years. Defenders in manufacturing, automotive, aerospace, and retail should treat the Cl0p Windchill campaign as an active, ongoing threat rather than a one-time event, since the group’s pattern with MOVEit and Oracle EBS was to sustain extortion pressure over many months after initial compromise. Finally, this week’s international sanctions and bounty actions against enabling infrastructure, from VPN providers to bulletproof hosts, suggest that policy responses are shifting toward disrupting the supply chain that ransomware groups depend on rather than pursuing operators alone, a strategy that will take time to show measurable effect on incident volume.


Sources

Primary Sources

Web Search Discoveries

RSS Feed Sources

  • news/rss-feeds-curated.opml (CPS/ransomware curated feeds)
  • news/rss-feeds-itsec.opml (CIO/CISO strategic IT security feeds)