Ransomware monitoring sources recorded a surge of victim claims led by Qilin, which posted attacks against organizations in the United States, Argentina, France, Italy, Peru, Brazil, Turkey, and the United Kingdom. Named victims included Cafar, Droguería Martorani, AK Preparedness, Armara, Sicc, KLD Labs, St Martha Catholic Church, Salina Supply, The Nueva School, City Ambulance Service, Famesa, Associated Theatrical Contractors, Don Tortaco Mexican Grill, Eana, PP+K, Synergy Products, and Bolt & Nut Manufacturing. The affected sectors spanned healthcare, education, manufacturing, agriculture and food production, hospitality, technology, business services, and religious organizations, underscoring broad opportunistic targeting rather than a single-industry campaign.
Other groups also continued to post new victims. Incransom claimed attacks on v-silicon.com in Taiwan, Reatile Group in South Africa, Vedan Corp in Vietnam, and V&P Nurseries in the United States; DragonForce claimed NewNet S.A. in Colombia and separately threatened Switzerland's Ifage with publication of 850 GB of allegedly stolen data after an earlier intrusion; Krybit listed Euroins Insurance Company AD in Bulgaria; and Akira claimed McKeever, Varga & Senko in the United States, alleging theft of 12 GB of corporate and personal data. A weekly ransomware trend report based on eCrime.ch data counted 187 claims for the period, down from 233 the prior week, but still identified Qilin as the most active group with 33 claims, ahead of DragonForce with 27.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
29 events from the most recent confirmed update back to the earliest known activity.
Postres Reina in Spain was identified as a victim of a ransomware attack attributed to Qilin. The incident was discovered on July 21, 2026 at 07:04 UTC and was described as a data breach affecting the food production company.
In the McKeever, Varga & Senko case, Akira claimed it would soon upload 12 GB of stolen corporate data. The threatened leak allegedly included client internal data, employee personal information, contracts, agreements, confidential files, and NDAs.
McKeever, Varga & Senko in the United States was identified as a victim of a ransomware incident attributed to Akira. The incident was reportedly discovered later the same day at 13:53 UTC.
Bolt & Nut Manufacturing in Great Britain was identified as a victim of a Qilin ransomware attack. The breach was listed at 09:40 UTC on July 20, 2026 and discovery at 09:41 UTC.
Roughly three months after the mid-April intrusion, DragonForce claimed responsibility for the Ifage incident. The group said it had stolen 850 GB of files, issued a ransom demand, and threatened to publish the exfiltrated data.
ICT Journal reported that the Fondation genevoise pour la formation des adultes (Ifage) in Geneva suffered a cyber intrusion in mid-April 2026. The incident involved exfiltration of personnel-related data.
PP+K in Brazil was identified as a victim of a ransomware attack attributed to Qilin. The breach and discovery were both listed at 18:10 UTC on July 19, 2026.
Eana in Argentina was reported as a victim of a Qilin ransomware attack. The breach was listed at 18:09 UTC on July 19, 2026 and discovery at 18:10 UTC.
Synergy Products in Turkey was reported as a victim of a ransomware attack attributed to Qilin. The incident was discovered on July 19, 2026 shortly after the reported breach time.
Don Tortaco Mexican Grill in the United States was identified as a victim of a ransomware attack attributed to Qilin. The breach was dated July 19, 2026 and discovery was recorded one minute later.
Associated Theatrical Contractors in the United States was reported as a victim of a Qilin ransomware attack. The breach was dated July 19, 2026 at 16:03 UTC and discovered at 16:04 UTC.
City Ambulance Service, a U.S. healthcare organization, was reported as a victim of a Qilin ransomware attack. The incident was identified on July 19, 2026 at 09:06 UTC.
Famesa in Peru was identified as a victim of a ransomware attack attributed to Qilin. The incident was discovered on July 19, 2026 at 09:05 UTC.
Euroins Insurance Company AD in Bulgaria was reported as a victim of a ransomware attack attributed to Krybit. The incident was discovered on July 18, 2026 at 16:26 UTC.
Salina Supply in the United States was identified as a victim of a Qilin ransomware attack. The breach occurred on July 18, 2026 at 13:35 UTC and was discovered at 13:36 UTC.
St Martha Catholic Church in the United States was identified as a victim of a ransomware attack attributed to Qilin. The breach was listed at 13:34 UTC on July 18, 2026 and discovery at 13:35 UTC.
The Nueva School in the United States was reported as a victim of a Qilin ransomware attack. The breach was listed at 13:33 UTC on July 18, 2026 and discovery at 13:34 UTC.
NewNet S.A. in Colombia was reported as a victim of a ransomware attack attributed to DragonForce. The incident was discovered on July 18, 2026, shortly after the reported breach time the same day.
KLD Labs, a U.S. technology organization, was reported as a victim of a Qilin ransomware attack. The breach was discovered on July 18, 2026 at 11:38 UTC.
Sicc in Italy was reported as suffering a ransomware attack attributed to Qilin. The breach and discovery were both listed at 11:39 UTC on July 18, 2026.
Armara in France was identified as a victim of a Qilin ransomware attack. The associated data breach was discovered on July 18, 2026 at 11:37 UTC.
AK Preparedness in the United States was reported as a victim of a ransomware attack attributed to Qilin. The breach was discovered on July 18, 2026 at 10:38 UTC.
Arizona-based V&P Nurseries was reported as a victim of an Incransom ransomware attack. The breach was listed at 01:32 UTC on July 18, 2026 and discovery at 02:00 UTC.
Vedan Corp in Vietnam was reported as a victim of Incransom. The breach was listed at 01:27 UTC on July 18, 2026 and discovery at 02:02 UTC.
South Africa's Reatile Group was reported as a victim of an Incransom ransomware attack. The breach time was listed as 01:30 UTC on July 18, 2026 and discovery at 02:00 UTC.
v-silicon.com, identified as 威视芯半导体(合肥)有限公司 serving smart display and visual technology markets, was reported as a victim of Incransom. The breach was listed at 01:22 UTC on July 18, 2026 and discovery at 02:03 UTC.
Droguería Martorani in Argentina was reported as a victim of a Qilin ransomware attack. The breach was listed at 00:05 UTC on July 18, 2026 and discovery at 00:06 UTC.
Cafar in Argentina was identified as a victim of a ransomware attack attributed to Qilin. The breach and discovery were both listed at 2026-07-17 16:57 UTC.
A CyberVeille weekly report covering 13 July to 19 July 2026, based on eCrime.ch data, reported 187 ransomware attack claims worldwide, down from 233 in week 28. It identified Qilin as the most active group with 33 claims, followed by DragonForce with 27 and Gentlemen with 23.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcecyberveille.ch
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcecyberveille.ch
Open sourceecrime.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.