Ransomware summary week 32, 2026

A newly surfaced group called Orova claimed dozens of victims across six countries within days of its debut, while LockBit 5.0 kept up a steady drumbeat of manufacturing and communications victims across France, Germany, India, and Brazil, and Anubis ransomware struck a second target just a week after halting Fairlife’s US milk production.
ransomware
Published

August 8, 2026

Executive Summary

The week of July 31 to August 7 was shaped less by a single headline incident and more by the sudden arrival of Orova, a previously unseen ransomware operator that posted at least 24 victims across six countries within its first day on the dark web and grew that tally toward 35 by August 6, spanning the United States, Hong Kong, Taiwan, Brazil, Egypt, and Japan. The group’s debut coincided almost exactly with Hong Kong’s Securities and Futures Commission issuing its first ever ransomware-related enforcement fine, a systemic-failings penalty against Luk Fook Securities tied to a years-old incident, underscoring how regulatory consequences continue to lag years behind the attacks that trigger them. LockBit 5.0 remained the week’s most geographically consistent operator, claiming French industrial machinery maker Setic Pourtier, US electronics supplier Microphase, Indian insulated-panel manufacturer Pioneer Coldstore and Cladding, and Brazilian communications group Grupo Rái within a five-day span. Qilin added Polish metals firm Mera Metal and US insurance claims processor Freedom Claims Management to its leak site, while newer entrants Payload and Aurora struck German manufacturers Hans and Jos. Kronenberg and GILDE Handwerk Macrander respectively. On the government side, the City of Coweta, Oklahoma became the latest local government hit by Anubis ransomware, the same strain that shut down Fairlife’s US dairy production the week before, a reminder that a single active operator can move from a household-name supply chain target to a small-town city hall within days.

Key Statistics: - Global: Orova’s debut added at least 24 to 35 victims across six countries within its first three days; LockBit 5.0, Qilin, Payload, and Aurora all claimed multiple named victims across at least four continents - Europe: Four named business victims across France, Germany, and Poland, claimed by LockBit 5.0, Payload, Qilin, and Aurora; a new Black Book Research index placed Poland, the UK, France, and Germany in the critical healthcare cyber risk tier - Asia: Orova’s opening wave hit Hong Kong, Taiwan, and Japan, alongside LockBit 5.0’s claim against an Indian manufacturer; Hong Kong’s securities regulator issued its first ransomware-linked fine the same week - US: City of Coweta, Oklahoma disrupted by Anubis ransomware; Qilin, LockBit 5.0, and Orova claimed insurance, electronics, masonry, and IT services victims - Other: Brazil’s Grupo Rái claimed by LockBit 5.0, with additional Orova victims reported in Brazil and Egypt


1. EUROPE

1.1 Government

No European government agency was publicly claimed by a ransomware operator this week.

1.2 Health, Municipalities & Non-commercial

No specific European healthcare or municipal ransomware victim was confirmed this week, though the sector’s structural exposure was underscored by Black Book Research’s Europe’s Healthcare Cybersecurity Hotspots 2026 index, published August 7 and covering 30 countries. The report placed Poland, the United Kingdom, France, and Germany in its critical risk-pressure tier, with nine additional countries rated very high risk, citing legacy technology, fragmented IT environments, and delayed regulatory implementation as the underlying drivers. The UK’s exposure was tied to National Health Service scale and outsourced diagnostics, France’s to its electronic patient record rollout and history of hospital ransomware incidents, and Germany’s to a large, decentralized hospital footprint with high medical-device density.

1.3 Business

LockBit 5.0 claimed French industrial machinery manufacturer Setic Pourtier on August 2, threatening to leak stolen corporate data. The newer Payload group struck Hans and Jos. Kronenberg, a German elevator-components manufacturer founded in 1932, on August 3, claiming roughly 54 gigabytes of data with a publication deadline of six to seven days. Qilin added Mera Metal, a Polish metals firm, to its leak site with the breach discovered August 5. Aurora, another recently active operator, claimed German wholesale group GILDE Handwerk Macrander on August 4, leaking employee identity documents and tax certificates spanning the family-owned Mittelstand company’s more than 50 legal entities across Germany, Austria, the Netherlands, France, the UK, and Hong Kong.


2. ASIA

2.1 Government

No Asian government agency was claimed by a ransomware operator this week.

2.2 Health, Municipalities & Non-commercial

No incidents reported this week.

2.3 Business

The week’s dominant Asian story was the debut of Orova, a ransomware group first observed in early August that claimed five Hong Kong organizations, including asset manager JK Capital Management and Sanrio Hong Kong, discovered August 4. The group also hit Taiwan-based electroforming firm DBM Reflex and telecom accessories maker Empyrean International Techno Devices, both claimed August 4, and Japanese office equipment company Apollo Office System, claimed the same day. The Orova wave landed within roughly 24 hours of Hong Kong’s Securities and Futures Commission issuing its first ever ransomware-related enforcement action, a fine against Luk Fook Securities for systemic cybersecurity failings tied to an earlier attack that had disrupted the firm’s trading systems for more than two weeks. Separately, LockBit 5.0 claimed Pioneer Coldstore and Cladding, an Indian manufacturer of insulated panels, on August 2, threatening to release stolen data absent negotiation.


3. UNITED STATES

3.1 Government

The City of Coweta, Oklahoma suffered a system-wide ransomware attack on August 5 attributed to Anubis, the same strain that forced Coca-Cola’s Fairlife subsidiary to halt all US dairy production the week prior. The attack encrypted local files, Word and Excel documents, and municipal financial systems across city hall, though the city’s website, third-party billing portal, and police and fire dispatch systems, which run on off-site servers, remained unaffected. City officials said they would not open a line of communication with the attackers and were restoring systems from backup rather than negotiating.

3.2 Health, Municipalities & Non-commercial

No incidents reported this week.

3.3 Business

Qilin claimed Freedom Claims Management, a US mortgage insurance claims processor, on August 3, and added masonry and concrete contractor WD Masonry and Concrete on August 4. LockBit 5.0 claimed electronics supplier Microphase Corporation, with the listing dated August 2 following an initial post on July 29. Orova’s opening wave was heavily weighted toward the United States, accounting for 13 of its first-week victims, including Florida-based IT services firm FixIT Tek, claimed August 5.


4. REST OF WORLD

4.1 Government

No incidents reported this week.

4.2 Health, Municipalities & Non-commercial

No incidents reported this week.

4.3 Business

LockBit 5.0 claimed Grupo Rái, one of Brazil’s largest independent communications groups encompassing six specialized companies, on August 2, with the listing citing compromised employee and third-party credentials alongside stolen internal data. Orova’s debut wave also reached Brazil and Egypt with one claimed victim in each country, though neither organization’s identity has been independently confirmed beyond the group’s own leak site listings.


5. THREAT ACTOR ACTIVITY

Orova was the week’s most consequential new entrant, moving from first sighting to at least 24 named victims within a single day and toward 35 across six countries by August 6, according to Darkfield’s tracking. The group’s target spread, spanning US IT services firms, Hong Kong asset managers, Taiwanese electronics manufacturers, and single victims in Japan, Brazil, and Egypt, suggests either a large existing access broker pipeline or automated, opportunistic scanning rather than a curated campaign, a pattern increasingly common among the roughly one-new-group-per-week cadence the ransomware ecosystem has sustained through 2026. Its arrival landed the same week Hong Kong’s Securities and Futures Commission handed down its first cybersecurity enforcement fine tied directly to a ransomware incident, a reminder that financial regulators are only now building the enforcement muscle that ransomware operators have exploited for years.

LockBit 5.0 sustained the broadest geographic footprint of any established operator this week, claiming victims in France, the United States, India, and Brazil within a five-day window, evidence that the rebranded LockBit variant continues to attract affiliates willing to operate across manufacturing, electronics, and communications targets regardless of region. Qilin and newer groups Payload and Aurora each claimed European manufacturing or wholesale victims, continuing the pattern from prior weeks in which Qilin remains the most consistently active operator across the continent while smaller, newer brands pick up adjacent mid-market targets. Cl0p’s ongoing campaign against internet-exposed PTC Windchill and FlexPLM installations, exploiting CVE-2026-12569 and sending mass extortion emails to employees at affected manufacturing, automotive, aerospace, and retail organizations, continued into this week without the group yet publicly listing victims on its leak site, consistent with its historical pattern of a long silent extortion period before public disclosure.

Anubis ransomware’s move from Fairlife’s nationwide dairy production shutdown directly into a small Oklahoma city government illustrates how a single operator can pursue targets of wildly different scale and sector back to back, with no apparent specialization beyond opportunistic access. KRYBIT and Aur0ra, two other recently active smaller operators, added a US heavy civil construction firm and the German GILDE Handwerk Macrander wholesale group respectively to their claims this week, further evidence of the fragmented, high-churn state of the ransomware-as-a-service market.


6. KEY TAKEAWAYS

A new ransomware operator reaching dozens of victims across six countries within 72 hours of its first sighting shows how little lead time defenders now get between a group’s debut and its first wave of real-world impact, and organizations should treat any newly named leak site as an active threat rather than wait for attribution research to mature before checking their own exposure. Hong Kong’s first ransomware-specific regulatory fine landing in the same week as a fresh wave of attacks against Hong Kong financial firms is a pointed illustration of how enforcement consistently trails the threat it targets by years, and organizations in jurisdictions without mature ransomware-specific regulation should not assume the absence of enforcement history reflects an absence of risk.

LockBit 5.0’s continued reach across manufacturing, electronics, and communications sectors on four continents confirms that the rebranded LockBit brand retains meaningful affiliate capacity despite years of law enforcement pressure on its predecessors, and defenders in those sectors should treat LockBit tooling and TTPs as a persistent baseline threat rather than a legacy concern. Anubis striking a small municipal government one week after halting a major food and beverage manufacturer’s production reinforces that ransomware targeting decisions remain opportunistic rather than strictly tiered by victim size, meaning smaller organizations cannot rely on obscurity as a defense simply because a group has recently claimed a large, high-profile victim.


Sources

Primary Sources

Web Search Discoveries

RSS Feed Sources

  • news/rss-feeds-curated.opml (CPS/ransomware curated feeds)
  • news/rss-feeds-itsec.opml (CIO/CISO strategic IT security feeds)