Ransomware dossier

Lynx

An INC Ransom-derived crew; double extortion with a polished leak site.

Claimed victims

260

Top region

US

Top sector

Healthcare

Suspected origin

Unattributed

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-08-29cutlercapitalFinancial Services—
2026-08-06www.jerryleigh.comOtherUS
2026-08-06www.talbotdes.orgOtherGB
2026-06-18www.someco.comNot Found—
2026-06-18www.eastersealsia.orgHealthcareUS
2026-06-18www.wolfconstruction.netManufacturingUS
2026-06-11www.commonwealth-partners.comProfessional ServicesGB
2026-05-10lifelongaccess.orgHealthcareUS
2026-05-10st-annes.uk.comEducationGB
2026-05-10bayareaherbs.comRetail & E-CommerceUS

Regions targeted

US 9GB 4IN 1TW 1DE 1ES 1

Sectors targeted

Healthcare 3Manufacturing 3Financial Services 2Technology 2Retail & E-Commerce 2Construction 1

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups