Executive Summary
The week of August 7 to August 14 was defined less by any single record-breaking breach and more by the sheer breadth of the ransomware ecosystem’s reach, with independent trackers logging well over 300 new leak-site victims across dozens of operators in the days bracketing this window. The most physically disruptive incident struck Health Sciences Centre in Winnipeg, Manitoba, Canada’s largest trauma hospital, where an August 10 ransomware intrusion knocked out door access controls, elevators, and heating and ventilation systems, forcing staff to prop doors open manually and raising alarm from the local nurses’ union about patient safety. Clop kept up its Oracle-adjacent extortion campaign against financial infrastructure providers, adding FIS Global and Fiserv to its leak site within the same week and claiming roughly 874 gigabytes of project and CAD data from each. Municipal government continued to absorb a disproportionate share of ransomware pain in the United States, with Suisun City, California, and Winchester, Kentucky, both disrupted within days of each other, following the City of Coweta, Oklahoma incident from the week before. A newly prominent extortion crew called Helix, which favors voice phishing and Microsoft OAuth abuse over traditional encryption malware, claimed two significant Canadian victims, insurer Westland Insurance and real estate group Morguard, both on August 7.
Key Statistics: - Global: Independent trackers recorded 336 new leak-site victims in the week bracketing August 3 to 9, led by Clop, Qilin, Orova, TheGentlemen, and the newly prolific L Group; INC ransomware accelerated its exploitation of SonicWall SMA 1000 flaws against targets in the US, Australia, the UAE, Colombia, and Switzerland - Europe: French industrial group Bouygues Energies & Services and Spanish firm Aletex Group were claimed by L Group and Qilin respectively; no confirmed European government or healthcare victim this week - Asia: Krybit claimed Indian instrumentation firm Labindia Instruments and Singaporean marine logistics company LHYK Marine, both on August 12; Barracuda claimed South Korean industrial automation firm RS Automation - US: Five municipal governments hit within roughly a week, most recently Suisun City, California and Winchester, Kentucky; Clop claimed financial-technology firms FIS Global and Fiserv - Other: Health Sciences Centre in Winnipeg suffered a physically disruptive attack on facility-management systems; Helix claimed Canadian firms Westland Insurance and Morguard; Colombia’s Ministry of Justice remained in recovery from an August 2 attack
1. EUROPE
1.1 Government
No European government agency was publicly claimed by a ransomware operator this week.
1.2 Health, Municipalities & Non-commercial
No European healthcare or municipal ransomware victim was confirmed this week. The structural exposure documented in last week’s Black Book Research index, which placed Poland, the United Kingdom, France, and Germany in the critical healthcare cyber-risk tier, remains the backdrop against which the sector’s leaders continue to brace for the next confirmed incident.
1.3 Business
The newly active L Group added Bouygues Energies & Services, a French industrial services firm belonging to the Bouygues conglomerate, to its leak site on August 6, part of a broader wave that saw the group claim 26 victims across 15 countries in a single week. Qilin claimed Aletex Group, a prominent Spanish organization, on August 14, continuing the group’s steady drumbeat of mid-market European manufacturing and services victims that has made it the most geographically consistent operator on the continent through 2026.
2. ASIA
2.1 Government
No Asian government agency was publicly claimed by a ransomware operator this week, though fallout continued from TheGentlemen’s late-July intrusion into Malaysia’s national nuclear regulatory agency, one of the more sensitive government targets claimed by the group so far this year.
2.2 Health, Municipalities & Non-commercial
No incidents reported this week.
2.3 Business
Krybit claimed two Asian victims on the same day, August 12: Labindia Instruments, an Indian scientific and analytical instrumentation company, and LHYK Marine, a Singapore-based marine logistics specialist founded in 1959. Separately, Barracuda listed RS Automation, a South Korean industrial automation manufacturer, on its leak site on August 6, claiming roughly 637 gigabytes of technical drawings, source code, and internal documents pulled from company servers and developer workstations.
3. UNITED STATES
3.1 Government
Suisun City, California suffered a ransomware intrusion that began moving through its municipal network around 5:45 a.m. on August 7, triggering an automated network shutdown that disrupted systems supporting 911 routing, police and fire dispatch, and public records for roughly 30,000 residents while the city council weighed the extortion demand. Three days later, on August 10, Qilin claimed responsibility for a cyberattack against the City of Winchester, Kentucky. Both incidents followed the City of Coweta, Oklahoma attack from the prior week, extending a run of small-city ransomware disruptions attributed to the RaaS ecosystem’s shift toward local government as a dependable revenue source.
3.2 Health, Municipalities & Non-commercial
No incidents reported this week.
3.3 Business
Clop’s ongoing campaign against financial infrastructure providers continued with two major claims. On its leak site the group listed FIS Global, one of the world’s largest financial technology providers, claiming approximately 874 gigabytes of project files, CAD files, and Windchill-related data, then followed on August 12 with a nearly identical claim against Fiserv, another major payments and banking technology firm, again citing roughly 874 gigabytes of exfiltrated project and CAD files. Barracuda claimed Micro-Comm, an Olathe, Kansas-based industrial automation company supplying water and wastewater control systems and SCADA software, on August 6, alleging 643 gigabytes of engineering schematics, employee data, and partner records now offered for sale at a $30,000 asking price. Separately, researchers documented an Akira affiliate whose attack on a US target beginning August 4 backfired after the intruder rebooted the victim’s systems into Safe Mode to disable security tools, a move that also broke the group’s own encryptor and left the target’s files intact.
4. REST OF WORLD
4.1 Government
Colombia’s Ministry of Justice and Law remained in recovery this week from a ransomware attack disclosed August 2 that disrupted technology infrastructure supporting illicit-drug monitoring and legal case processing just five days before the country’s presidential transition. Officials said the ransomware payload ultimately failed to fully deploy due to insufficient virtual memory on target systems, and the acting justice minister denied that data had been exfiltrated, describing the impact as file encryption rather than theft.
4.2 Health, Municipalities & Non-commercial
Health Sciences Centre in Winnipeg, Manitoba, Canada’s largest hospital and trauma referral center, was struck by a ransomware attack disclosed August 10 that disrupted facility-management systems rather than clinical IT directly, disabling automated door access, elevators, and heating, ventilation, and air conditioning across the campus. Staff were forced to prop doors open manually to maintain access, and Manitoba’s health minister and the local nurses’ union both raised concerns about patient safety as recovery continued into the following days. No ransomware group had publicly claimed responsibility as of this writing, an unusual silence for an incident of this visibility that may reflect ongoing negotiation or law enforcement involvement. Separately, L Group listed uva.edu.br, a Brazilian educational institution, on its leak site on August 6.
4.3 Business
Helix, a newly prominent extortion operation that emerged in July 2026 and favors voice phishing and abuse of Microsoft OAuth against SharePoint repositories over conventional encryption malware, claimed two significant Canadian victims on August 7: Westland Insurance, a major Canadian insurance brokerage, and Morguard, a prominent Canadian real estate group. In both cases Helix’s leak-site postings described stalled negotiations, with the group characterizing Westland’s engagement as delay tactics rather than a serious offer. Qilin added Service d’usinage 9002, a Canadian manufacturing company, to its leak site on August 9, continuing the group’s heavy claimed footprint across the North American manufacturing sector.
5. THREAT ACTOR ACTIVITY
Clop’s pursuit of financial-technology infrastructure providers was the week’s most consequential trend among established operators, with FIS Global and Fiserv both added to its leak site carrying near-identical claims of roughly 874 gigabytes of exfiltrated project and CAD data. The pairing suggests either a shared initial-access vector between the two firms or a systematic campaign against the payments-processing sector broadly, consistent with Clop’s historical pattern of exploiting a single vulnerability class against many targets before surfacing victims on its leak site in batches.
Helix’s emergence as a functioning extortion brand less than a month after its first sighting, built entirely around voice-phishing social engineering and OAuth token abuse rather than custom encryption malware, continues a trend the ransomware ecosystem has leaned into throughout 2026: extortion without encryption lowers the technical bar for new entrants and complicates detection for defenders tuned to watch for file-encryption behavior rather than mass data exfiltration through legitimate cloud APIs. L Group’s rapid rise to 26 claimed victims across 15 countries in a single week places it among the most active newer operators alongside Orova, whose debut wave the prior week reached 35 victims across six countries, reinforcing that the roughly one-new-group-per-week cadence the ecosystem has sustained through 2026 shows no sign of slowing.
Qilin remained the most geographically dispersed established operator, claiming victims in Spain, Canada, and elsewhere within the week, while Krybit and Barracuda both demonstrated a preference for mid-market manufacturing and instrumentation targets across Asia. The Akira affiliate whose attack against a US target failed after a self-inflicted Safe Mode misconfiguration is a reminder that not every claimed intrusion converts into a successful encryption event, even as the broader trend of anti-EDR tradecraft, including forced reboots into limited-functionality startup modes, continues to spread across ransomware affiliate playbooks.
6. KEY TAKEAWAYS
The Winnipeg hospital incident underscores a pattern that has recurred across 2026: ransomware’s most consequential damage increasingly comes not from encrypted patient records but from disrupted building-management systems, door access, and HVAC, the physical infrastructure that keeps a hospital campus operable regardless of whether clinical IT itself is touched. Healthcare organizations should treat facility-management and building-automation networks as part of their ransomware blast radius, not a segmented afterthought, given how directly this incident threatened patient safety without a single clinical record being encrypted.
Clop’s parallel claims against FIS Global and Fiserv show that financial infrastructure providers remain a preferred target precisely because a single successful intrusion technique can be replayed against multiple firms serving the same sector, and organizations in payments and banking technology should assume any vulnerability actively exploited against a peer firm is being probed against their own perimeter in the same window. Five US municipal governments disrupted within roughly a week, spanning Oklahoma, California, and Kentucky, confirms that small local governments continue to offer ransomware affiliates a combination of weak defenses and public pressure to restore services quickly, a combination that shows no sign of pushing operators toward larger, better-defended targets instead.