Ransomware summary week 34, 2026

Clop’s exploitation of a PTC Windchill zero-day pulled General Electric, Philips, and Shell onto its leak site alongside dozens of other manufacturers, Qilin claimed six victims across four countries in a single day, and a federal advisory warned that Conti-derived Gunra ransomware is actively targeting US critical infrastructure.
ransomware
Published

August 22, 2026

Executive Summary

The week of August 14 to August 21 was shaped by two RaaS operators demonstrating just how much damage a single exploited flaw or a single busy affiliate day can inflict at scale. Clop’s ongoing campaign against internet-exposed PTC Windchill and FlexPLM product-lifecycle software, tracked as CVE-2026-12569, expanded to a claimed 43 victims, with General Electric, Philips, and Shell all confirming they are investigating data-theft claims tied to the flaw. Qilin, meanwhile, posted six new victims to its leak site on a single day, spanning manufacturers and a law firm across Germany, France, the United States, and the Philippines, underscoring how a mature affiliate program can convert one productive week into claims on four continents. Independent trackers logged 332 new leak-site disclosures in the seven days bracketing this window, with 304 attributed specifically to ransomware and extortion crews rather than pure data-theft groups. Education and healthcare absorbed the week’s most sensitive US incidents, with InterLock claiming 710 gigabytes of student and staff records from Southeastern Oklahoma State University and Anubis listing home-care and hospice staffing giant Interim HealthCare. A joint advisory from the FBI, CISA, NSA, and South Korean police also put defenders on notice that Gunra, a Conti-derived ransomware-as-a-service operation, is actively exploiting known VPN and edge-device vulnerabilities against US government, healthcare, and financial-services targets.

Key Statistics: - Global: 332 new leak-site disclosures recorded in the week bracketing August 14 to 20, with 304 attributed to ransomware and extortion crews; Clop, Qilin, The Gentlemen, ShinyHunters, and Gunra were among the most active - Europe: Qilin claimed German firms Motorenmaier GmbH and DELTA WAYS plus Jone Precision in France; Clop’s Windchill campaign hit Philips and Shell; Aurora claimed Czech HVAC manufacturer Lloyd Coils Europe; no confirmed European government or healthcare victim this week - Asia: The Gentlemen claimed an unnamed Japanese healthcare organization; Gunra claimed an Indonesian agricultural biotechnology firm; Qilin claimed Philippine construction group Megawide - US: InterLock claimed Southeastern Oklahoma State University, exposing records for more than 90,000 students; Anubis listed healthcare staffing firm Interim HealthCare; Clop’s Windchill campaign hit General Electric; Qilin claimed four separate US businesses in one day - Other: Qilin claimed Mexican construction firm Constructora Jimenez; Majinahanashi claimed Colombian retailer PIO PIO; Storm claimed Australian consultancy 3-point Australia


1. EUROPE

1.1 Government

No European government agency was publicly claimed by a ransomware operator this week.

1.2 Health, Municipalities & Non-commercial

No European healthcare or municipal ransomware victim was confirmed this week.

1.3 Business

Qilin’s affiliates had an unusually productive single day on August 16, posting six new victims to the group’s leak site at once, three of which were European: Motorenmaier GmbH and DELTA WAYS, both German firms hit within a day of each other, and Jone Precision, a French manufacturer. Separately, Aurora claimed Lloyd Coils Europe, a Czech manufacturer of HVAC and refrigeration coils, on August 17, threatening to publish exfiltrated data unless negotiations began. The Gentlemen added Euroscreen, an Italian maker of digital-printing and projection-screen technology, to its leak site around August 17 to 19. Clop’s exploitation of the PTC Windchill flaw reached European industrial giants directly, with Philips confirming that an enterprise server had been breached, though the company said the incident was contained and did not touch customer environments, while the group claimed roughly 13.5 gigabytes exfiltrated. Shell, now headquartered in London, was named in the same Windchill campaign with Clop claiming approximately 89 gigabytes taken from the energy major.


2. ASIA

2.1 Government

No Asian government agency was publicly claimed by a ransomware operator this week.

2.2 Health, Municipalities & Non-commercial

The Gentlemen, the RaaS operation that has driven much of 2026’s surge in education and healthcare targeting, claimed an unnamed Japanese healthcare organization this week, according to threat-intelligence monitoring of the group’s dark-web leak site. The group has been particularly active against Japan through 2026, with the country’s total ransomware incident count up 39 percent year over year through the first third of the year.

2.3 Business

Qilin claimed Megawide, a major Philippine construction and infrastructure group, on August 16, continuing the operator’s steady presence across Southeast Asian industrial and construction targets. Gunra, the Conti-derived ransomware-as-a-service operation named in this week’s joint US-South Korean law-enforcement advisory, listed an Indonesian agricultural biotechnology and fertilizer manufacturer on its leak site, extending its reach beyond the critical-infrastructure sectors called out in the advisory itself.


3. UNITED STATES

3.1 Government

No US federal, state, or local government agency was publicly claimed by a named ransomware operator this week, though the FBI, CISA, NSA, US Secret Service, the Department of Defense Cyber Crime Center, and South Korea’s National Police Agency jointly warned on August 10 that Gunra ransomware actors are actively targeting government services and facilities alongside healthcare and financial services, exploiting known vulnerabilities in internet-facing VPN gateways and other edge devices. Separately, water and wastewater utilities across at least seven states, including more than 30 systems in Minnesota and nine in Michigan, remained under investigation for intrusions into Rockwell Automation programmable logic controllers that began in late July and continued to surface through this week, though officials have stopped short of formally attributing the activity to a ransomware operator.

3.2 Health, Municipalities & Non-commercial

InterLock claimed Southeastern Oklahoma State University on August 19, alleging it had published 710 gigabytes of data tied to more than 90,000 current and former students, including Social Security numbers, grades, financial aid records, and disciplinary files, along with employee medical and injury records. The university had already spent parts of late July and early August recovering from a disruptive intrusion that closed its Durant campus for two days, and has not confirmed the actor or scope of the claimed data theft. Anubis listed Interim HealthCare, one of the largest US home-care, hospice, and healthcare-staffing companies, on August 15, alleging a breach of the company’s headquarters systems that could expose patient and staff information nationwide; the claim followed an earlier, separate assertion of compromise from a group calling itself Genesis, and neither has been confirmed by the company.

3.3 Business

Clop’s PTC Windchill and FlexPLM campaign claimed General Electric among its roughly 43 victims, with the group alleging 391 gigabytes of project and engineering data exfiltrated from the industrial conglomerate; GE said it was aware of the claim and assessing it. Qilin’s busy August 16 posting round added four American organizations to its leak site: Double H Equipment, an industrial equipment provider; Spoonful of Comfort, a care-package retailer; Ascii Group, a technology-services membership organization; and Arnall Golden Gregory, an Atlanta law firm, illustrating the operator’s continued willingness to target professional-services firms alongside manufacturers.


4. REST OF WORLD

4.1 Government

No incidents reported this week.

4.2 Health, Municipalities & Non-commercial

No incidents reported this week.

4.3 Business

Qilin claimed Constructora Jimenez, a Mexican construction company, on August 19, extending its footprint across Latin American industrial and building-sector targets. Majinahanashi, a newer Japanese-linked locker operation, claimed PIO PIO, a Colombian retail and e-commerce company, on August 16, alleging 6,306 files exfiltrated from the roughly 33-employee firm. In Oceania, Storm claimed 3-point Australia, a Victorian project-management consultancy, continuing a steady trickle of mid-market Australian victims that regional authorities have flagged alongside a broader rise in INC Ransom activity against Australia, New Zealand, and Pacific networks.


5. THREAT ACTOR ACTIVITY

Clop’s exploitation of a PTC Windchill and FlexPLM vulnerability, CVE-2026-12569, was the week’s most consequential campaign among established operators, expanding to a claimed 43 victims that now include General Electric, Philips, and Shell alongside dozens of smaller manufacturers. The pattern mirrors Clop’s established playbook of exploiting a single enterprise-software flaw against as many exposed instances as possible before surfacing victims on its leak site in coordinated batches, the same approach the group used against FIS Global and Fiserv the week before through a different vulnerability class.

Qilin’s decision to post six victims across Germany, France, the United States, and the Philippines within a single 24-hour window on August 16 is a reminder of how much throughput a mature RaaS affiliate structure can generate once initial access is in hand; the group has now sustained this kind of multi-country, multi-sector claim volume for months without any apparent loss of operational tempo. The federal advisory on Gunra ransomware, jointly issued by the FBI, CISA, the NSA, and South Korean law enforcement, formalizes what threat-intelligence trackers had already observed informally: a Conti-derived, double-extortion RaaS variant expanding rapidly since its April 2025 emergence, now confirmed to be actively probing government, healthcare, and financial-services targets in the US through exploitation of known CVEs in internet-facing devices rather than novel techniques. Extortion-only activity from ShinyHunters continued to develop through the week as well, with French intellectual-property firm Questel confirming that attackers reached its Microsoft 365 environment through a voice-phishing call, reinforcing that social-engineering-driven data theft without encryption malware remains a durable complement to traditional ransomware rather than a passing trend.


6. KEY TAKEAWAYS

Clop’s parallel claims against General Electric, Philips, and Shell through the same PTC Windchill flaw demonstrate that any organization running internet-exposed product-lifecycle-management software should treat CVE-2026-12569 as an active exploitation risk rather than a routine patch-cycle item, particularly given the group’s history of exploiting a single flaw against dozens of firms before most victims even learn they were affected. Qilin’s ability to claim six victims across four countries in a single day is a useful reminder that RaaS affiliate throughput, not just individual group sophistication, now drives much of the ecosystem’s visible volume, and that defenders should not read a quiet week from one operator as a sign the group’s capacity has diminished.

The Southeastern Oklahoma State University and Interim HealthCare incidents both highlight how ransomware claims against organizations holding combined health, financial, and personal records create compounding regulatory exposure, spanning FERPA, HIPAA, and state breach-notification law simultaneously, even before an organization has confirmed the underlying claim is accurate. Finally, the joint federal advisory on Gunra ransomware is a direct signal that patching known, already-public vulnerabilities in VPN gateways and other edge devices remains the highest-leverage defensive action available to government, healthcare, and financial-services organizations, since the group’s playbook relies entirely on exploiting flaws that already have vendor fixes available rather than on novel zero-days.


Sources

Primary Sources

Web Search Discoveries

RSS Feed Sources

  • news/rss-feeds-curated.opml (CPS/ransomware curated feeds)
  • news/rss-feeds-itsec.opml (CIO/CISO strategic IT security feeds)