Threat Intelligence Report — June 19, 2026 | 0 New KEVs · 148 Victims

Report Date: 2026-06-19

New KEVs: 0  ▼ -7 vs last weekRansomware Victims: 148  ▼ -15 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference Evil Corp. Ransomware activity is moderate with 148 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Top KEVs

No qualifying KEVs were identified in the current reporting window.

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

Threat Actors Mentioned

Evil Corp

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

15 new victims posted today
7-day total: 148 via Ransomware.live

Infostealer Exposure: 1,110 employee credentials and 3,756,776 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 21 Qilin 15 Shinyhunters 12 Safepay 12 Krybit 8

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • ShinyhuntersShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
  • SafepaySafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
  • KrybitKrybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.

Most Targeted Sectors

Business Services 22 Manufacturing 18 Technology 15 Construction 10 Public Sector 9

Top Countries

US (42), DE (13), CA (4), MY (4), SG (4)

Notable Incidents

  • www.courdescomptes.sn (Public Sector · SN) — claimed by Krybit. La Cour des Comptes du Sénégal (The Court of Auditors of Senegal) is an independent supreme audit institution of Seneg… Press coverage →
  • Prince George County (Public Sector · US) — claimed by Ransomhouse. Prince George County is a local government entity focused on providing essential services and fostering community development. It offers a range of services including public safety, waste management, parks and recreation… Press coverage →
  • Mackay Sugar (Agriculture and Food Production · AU) — claimed by Thegentlemen. ***.com.au zoominfo.com/c/mackay-sugar-ltd/1147904633 Mackay Sugar is Australia's second-largest sugar manufacturer, headquartered in tropical North Queensland with over 140 years of rich industry heritage. Owned primari… Press coverage →
  • Novo Nordisk (Healthcare · DK) — claimed by Fulcrumsec. [AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditio… Press coverage →
  • Commune d'Eyguires (Public Sector · FR) — claimed by Qilin. N/A Press coverage →

Vendor-Specific Risks

No vendors with confirmed KEV exploitation were identified this reporting window — a quiet week for the KEV catalog.

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.