Threat Intelligence Report — June 18, 2026 | 0 New KEVs · 163 Victims

Report Date: 2026-06-18

New KEVs: 0  ▼ -7 vs last weekRansomware Victims: 163  ▲ +17 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference DragonForce. Ransomware activity is moderate with 163 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Top KEVs

No qualifying KEVs were identified in the current reporting window.

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

Threat Actors Mentioned

DragonForce

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

24 new victims posted today
7-day total: 163 via Ransomware.live

Infostealer Exposure: 1,226 employee credentials and 3,757,444 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 21 Shinyhunters 16 Qilin 12 Safepay 12 Dragonforce 8

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • ShinyhuntersShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • SafepaySafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
  • DragonforceDragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.

Most Targeted Sectors

Business Services 24 Technology 19 Manufacturing 19 Construction 10 Agriculture And Food Production 10

Top Countries

US (47), DE (14), SG (4), MY (4), IT (4)

Notable Incidents

  • Prince George County (Public Sector · US) — claimed by Ransomhouse. Prince George County is a local government entity focused on providing essential services and fostering community development. It offers a range of services including public safety, waste management, parks and recreation… Press coverage →
  • Mackay Sugar (Agriculture and Food Production · AU) — claimed by Thegentlemen. ***.com.au zoominfo.com/c/mackay-sugar-ltd/1147904633 Mackay Sugar is Australia's second-largest sugar manufacturer, headquartered in tropical North Queensland with over 140 years of rich industry heritage. Owned primari… Press coverage →
  • Novo Nordisk (Healthcare · DK) — claimed by Fulcrumsec. [AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditio… Press coverage →
  • GITHUB INTERNAL (Technology · US) — claimed by Lapsus$. Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free. Press coverage →
  • musenet.co.jp (Technology · JP) — claimed by Safepay. Founded in the twentieth century, the company serves as an intermediary between publishers and music retailers throughout Japan. Its online … Press coverage →

Vendor-Specific Risks

No vendors with confirmed KEV exploitation were identified this reporting window — a quiet week for the KEV catalog.

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.