Week in Ransomware — 2026-W34

Observation window 2026-08-17T00:00:00.000Z through 2026-08-24T00:00:00.000Z (exclusive UTC). This frozen digest describes provider-observed claim cadence for one complete ISO week; it is not an incident confirmation, targeting evidence, attribution, or a prediction of future risk.

Ranked signals

standout: IT rose to 9.6% of this week's observations

IT accounted for 25 newly observed claims — 9.6% of this week's reported country observations, versus a pooled baseline share of 3.5%.

Why this appeared: Target 25 ≥ 5, share 9.6% ≥ 1.5× baseline (3.5%), and absolute share up 6.1 ≥ 5 points.

standout: direwolf newly observed claims rose to 21 this week

Providers newly observed 21 claims attributed to direwolf in the target week, versus an 8-week median of 0.

Why this appeared: Target 21 ≥ 4 and ≥ 2× the median (0) and exceeds it by ≥ 3.

standout: xpl0itrs newly observed claims rose to 16 this week

Providers newly observed 16 claims attributed to xpl0itrs in the target week, versus an 8-week median of 0.

Why this appeared: Target 16 ≥ 4 and ≥ 2× the median (0) and exceeds it by ≥ 3.

notable: No new claims were observed for chaos this week

chaos had no newly observed claims in the target week after a baseline median of 3 per week across 7 of the prior 8 weeks. This describes provider observations only, not whether the group stopped operating.

Why this appeared: Target 0 claims with baseline median 3 ≥ 3 and activity in 7 ≥ 5 of 8 baseline weeks; all baseline providers healthy.

context: No new claims were observed for cmd organization this week

cmd organization had no newly observed claims in the target week after a baseline median of 3 per week across 6 of the prior 8 weeks. This describes provider observations only, not whether the group stopped operating.

Why this appeared: Target 0 claims with baseline median 3 ≥ 3 and activity in 6 ≥ 5 of 8 baseline weeks; all baseline providers healthy.

context: Iah647 was newly observed by providers this week

Iah647 first qualified as emerging within this ISO week, with 3 newly observed claims. Dates describe provider observations, not when the operation began.

Why this appeared: Qualifying tracker-first discovery timestamp falls inside the target ISO week; emergence derivation returned "emerging".

context: DYSPHOR1A was newly observed by providers this week

DYSPHOR1A first qualified as watch within this ISO week, with 7 newly observed claims. Dates describe provider observations, not when the operation began.

Why this appeared: Qualifying tracker-first discovery timestamp falls inside the target ISO week; emergence derivation returned "watch".

context: AUR0RA was newly observed by providers this week

AUR0RA first qualified as watch within this ISO week, with 4 newly observed claims. Dates describe provider observations, not when the operation began.

Why this appeared: Qualifying tracker-first discovery timestamp falls inside the target ISO week; emergence derivation returned "watch".

Related: all weekly signal digests, country and sector activity profiles, and the claim-publishing calendar for the surrounding weeks.

How to cite: Dragons Eye Ransomware Tracker, “Week in Ransomware 2026-W34”, provider-observed ransomware claim data as of 2026-08-26, this page's URL. Keep the observed-claim caveat with any reused figures; the methodology documents the evidence model and the data-quality dashboard quantifies screening and exclusions.

Ordered by measured change and, where available, AI-prioritized; every fact is calculated deterministically from provider observations. Records are provider-reported claims, not confirmed incidents. Source: reconciled leak-site victim claims across independent providers.

Source: reconciled leak-site victim claims aggregated from documented public monitoring providers. Independent providers are distinguished from mirrors, and no provider count verifies an underlying allegation. Definitions for every term used here are in the glossary.

Intelligence overview

Victim records are provider-reported allegations, not independently verified breaches. Published for research, defense, and educational use.