Predictive Intel Report
Ransomware, October 2026
173 organisations were named on ransomware leak sites in October 2026, led by Qilin with 19 claims.
Named victims
173
Active groups
8
Busiest group
Qilin
Top sector
Manufacturing
What we predict next
Predictions supplied by the Ninja Labz data-science lab. Method: Ninja Labz DS Lab — live trend leads over 21k dated claims + grounded AI inference
Rising actorconfidence 100%
If the surge is not an artifact, expect claim volume to grow or spread to adjacent sectors (e.g., logistics, industrial supply chain) within the next 30 days as the actor refines targeting.
Basis: {"claims_last_30d": 7, "prior_60d": 0, "surge_ratio": 7.0, "top_sector_30d": "Manufacturing", "window": "last 30d vs prior 60d (Signal live claims)"}
Rising actorconfidence 100%
Given its association with active ransomware-as-a-service and extortion actors, EndZone is likely to accelerate claim volume in the next 30 days, with Technology sector organizations at elevated risk of targeting; BYOD environments flagged in its connections may be a preferred initial-access vector.
Basis: {"claims_last_30d": 6, "prior_60d": 0, "surge_ratio": 6.0, "top_sector_30d": "Technology", "window": "last 30d vs prior 60d (Signal live claims)"}
Rising actorconfidence 100%
If claim volume continues to grow without sector resolution, Netrunner may be in a target-selection or tooling phase prior to a more visible campaign in the next 30-60 days.
Basis: {"claims_last_30d": 5, "prior_60d": 0, "surge_ratio": 5.0, "top_sector_30d": "Not Found", "window": "last 30d vs prior 60d (Signal live claims)"}
Rising actorconfidence 100%
Given the Snatch and Seven Seas Group connections and Transportation sector focus, Spirals is likely to continue targeting Transportation organizations in the near term, potentially escalating claim volume as it establishes its brand identity.
Basis: {"claims_last_30d": 5, "prior_60d": 0, "surge_ratio": 5.0, "top_sector_30d": "Transportation", "window": "last 30d vs prior 60d (Signal live claims)"}
Watchconfidence 100%
If claim volume continues at the current pace, ZaWoo is likely to expand targeting scope or escalate claim severity within the next 30-60 days as it seeks to build credibility.
Basis: {"first_seen": "2026-08-30", "claims_since": 25, "window": "first appeared <60d ago"}
Watchconfidence 100%
If claim velocity continues at the current rate, majinahanashi will likely cross thresholds that trigger broader graph-propagation alerts within the next 30 days, warranting preemptive tracking.
Basis: {"first_seen": "2026-08-12", "claims_since": 22, "window": "first appeared <60d ago"}
Watchconfidence 100%
If the current claim velocity holds, N0n could exceed 50 total claims within its first 90 days, elevating it from newcomer to established mid-tier threat actor and warranting escalated monitoring.
Basis: {"first_seen": "2026-09-18", "claims_since": 22, "window": "first appeared <60d ago"}
Watchconfidence 100%
New entrant: Vexy Ransomware
Basis: {"first_seen": "2026-09-03", "claims_since": 19, "window": "first appeared <60d ago"}
Watchconfidence 100%
Given the high verified victim count and absence of sanctions or known disruption activity in the evidence, Hunters is likely to continue opportunistic campaigns at scale in the near term.
Basis: {"importance": 0.633, "victims": 308, "dark_victims": 0, "sanctioned": false, "sources": ["darkweb", "lineage", "signal"]}
Rising actorconfidence 100%
If EndZone and eteam activity continues to escalate, BYOD-related incidents in Technology sector targets are likely to increase over the next 30 days, potentially spreading to adjacent sectors.
Basis: {"claims_last_30d": 5, "prior_60d": 0, "surge_ratio": 5.0, "top_sector_30d": "Technology", "window": "last 30d vs prior 60d (Signal live claims)"}
Watchconfidence 100%
If the current claim rate holds, emperador will surpass 70+ claims within the next 60 days and is likely to expand its entity connections further; early targeting patterns suggest cross-sector exposure including logistics and manufacturing verticals.
Basis: {"first_seen": "2026-08-12", "claims_since": 38, "window": "first appeared <60d ago"}
Rising actorconfidence 100%
Given the steep ramp from zero to 14 claims in a single month with no signs of slowdown, Lamashtu is likely to continue expanding victim count and sector breadth over the next 30 days, potentially moving further into Healthcare and Technology targets already connected in their network.
Basis: {"claims_last_30d": 14, "prior_60d": 0, "surge_ratio": 14.0, "top_sector_30d": "Manufacturing", "window": "last 30d vs prior 60d (Signal live claims)"}
Rising actorconfidence 100%
If the surge reflects an initial operational campaign, claim volume is likely to continue rising in the near term as newly active actors typically escalate before plateauing — watch for sector expansion beyond Technology.
Basis: {"claims_last_30d": 22, "prior_60d": 0, "surge_ratio": 22.0, "top_sector_30d": "Technology", "window": "last 30d vs prior 60d (Signal live claims)"}
Watchconfidence 100%
Given continued dark web activity and 4 recent dark_victims postings, lockbit5 is likely in an active extortion phase — additional victim disclosures across the connected sectors are probable in the near term.
Basis: {"importance": 1.0, "victims": 3181, "dark_victims": 4, "sanctioned": true, "sources": ["darkweb", "signal"]}
Rising actorconfidence 100%
If the sector attribution gap closes in the next 7-14 days, AuditTeam is likely opportunistically targeting multiple verticals simultaneously rather than a single campaign, which would indicate resource expansion or affiliate activity.
Basis: {"claims_last_30d": 31, "prior_60d": 6, "surge_ratio": 7.75, "top_sector_30d": "Not Found", "window": "last 30d vs prior 60d (Signal live claims)"}
Rising actorconfidence 100%
Surging now: emperador
Basis: {"claims_last_30d": 26, "prior_60d": 12, "surge_ratio": 3.71, "top_sector_30d": "Manufacturing", "window": "last 30d vs prior 60d (Signal live claims)"}
Watchconfidence 99%
Given Qilin's sustained operational tempo and expanding victim portfolio across multiple industries, further victim disclosures—particularly in under-monitored sectors like maritime and semiconductors—are likely in the near term.
Basis: {"importance": 0.585, "victims": 881, "dark_victims": 18, "sanctioned": false, "sources": ["darkweb", "signal"]}
Watchconfidence 98%
Given Snatch's broad peer connections and active victim count, it is likely operating as an affiliate feeder for larger RaaS brands; defenders should anticipate Snatch intrusions being followed by secondary payload deployment from connected operators.
Basis: {"importance": 0.579, "victims": 145, "dark_victims": 0, "sanctioned": false, "sources": ["signal"]}
Rising actorconfidence 98%
Surging now: Wallstreet
Basis: {"claims_last_30d": 16, "prior_60d": 7, "surge_ratio": 3.56, "top_sector_30d": "Healthcare", "window": "last 30d vs prior 60d (Signal live claims)"}
Likely next targetconfidence 95%
Geography heating up: BG
Basis: {"victims_30d": 5, "prior_30d": 0, "mom_change": 5.0}
Momentumconfidence 90%
Ecosystem momentum: down 19% week-on-week
Basis: {"claims_this_week": 184, "claims_last_week": 228, "wow_change_pct": -19, "most_active_this_week": "qilin"}
Watchconfidence 90%
Given sustained victim volume and no sanction pressure, Black Basta is likely to continue prolific targeting; watch for potential victim count acceleration if the group recruits displaced affiliates from disrupted rival crews.
Basis: {"importance": 0.497, "victims": 447, "dark_victims": 0, "sanctioned": false, "sources": ["darkweb", "lineage", "signal"]}
Watchconfidence 86%
New entrant: Eclipse
Basis: {"first_seen": "2026-08-16", "claims_since": 12, "window": "first appeared <60d ago"}
Likely next targetconfidence 85%
Sector in the crosshairs: Manufacturing (steady)
Basis: {"victims_30d": 160, "prior_30d": 152, "mom_change": 0.05, "trend": "steady"}
Watchconfidence 83%
New entrant: DYSPHOR1A
Basis: {"first_seen": "2026-08-20", "claims_since": 11, "window": "first appeared <60d ago"}
Watchconfidence 83%
New entrant: kazu
Basis: {"first_seen": "2026-08-23", "claims_since": 11, "window": "first appeared <60d ago"}
Likely next targetconfidence 80%
Geography heating up: TR
Basis: {"victims_30d": 13, "prior_30d": 6, "mom_change": 1.0}
Watchconfidence 77%
Given the high victim count and continued darkweb activity with zero dark (unreported) victims logged, RansomHub is likely maintaining aggressive public leak-site pressure tactics; victim counts are expected to continue climbing absent takedown action.
Basis: {"importance": 0.368, "victims": 963, "dark_victims": 0, "sanctioned": false, "sources": ["darkweb", "signal"]}
Watchconfidence 76%
Key operator: thegentlemen
Basis: {"importance": 0.364, "victims": 679, "dark_victims": 40, "sanctioned": false, "sources": ["darkweb", "signal"]}
Watchconfidence 76%
Key operator: rhysida
Basis: {"importance": 0.361, "victims": 235, "dark_victims": 3, "sanctioned": false, "sources": ["darkweb", "lineage", "signal"]}
The month in numbers
Most active groups
| Group | Claimed victims |
|---|---|
| Qilin | 19 |
| INC Ransom | 10 |
| safepay | 10 |
| Akira | 9 |
| TheGentlemen | 9 |
| krybit | 9 |
| VYPR | 7 |
| settra | 7 |
Most-hit sectors
| Sector | Claimed victims |
|---|---|
| Manufacturing | 36 |
| Healthcare | 22 |
| Technology | 20 |
| Professional Services | 19 |
| Other | 18 |
| Not Found | 12 |
| Transportation | 11 |
| Education | 9 |
Most-hit countries
| Country | Claimed victims |
|---|---|
| US | 65 |
| BR | 6 |
| DE | 5 |
| ES | 5 |
| GB | 5 |
| IT | 4 |
| CA | 4 |
| MX | 4 |
Volume trend
| Month | Named victims |
|---|---|
| August 2026 | 175 |
| September 2026 | 852 |
| October 2026 | 173 |
Methodology
Figures are drawn from the Ninja Signal threat-intelligence graph, which tracks ransomware groups' own public leak-site claims. A "named victim" is an organisation a group publicly listed in the stated month; counts are claims, not confirmed breaches, and listing is not confirmation an incident occurred. Groups are aggregated across their known aliases. Months are calendar months by the claim's discovered date; recent months are often revised upward as late claims arrive. The underlying numbers are published as open, machine-readable feeds — see the data feeds (CC BY 4.0).
Predictions are directional reads of the trend and recency in these same figures. We state the basis for each. Where the Ninja Labz data-science lab supplies model-based predictions, they are labelled as such with their method.
Track new victims every morning in the Daily, read the per-group dossiers on the ransomware index, or pull the raw data feeds.