
2019
A ransomware group that emerged in 2026 and led BlackFog's June claimed-victim count with 12 victims.
"2019" is a ransomware group that emerged in 2026 under a bare-year name. BlackFog's June 2026 report names it the month's most active group, with 12 claimed victims against Qilin's 11 in May, though its origin and structure remain unconfirmed.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Timeline for 2019
Led BlackFog June 2026 ransomware tally with 12 claimed victims
Cybersecurity: Threats and Defences: Qilin's own affiliate now outposts itBackground
"2019" is a ransomware group whose existence is currently known only through claimed-victim tallies rather than any confirmed attribution, structure or nationality. BlackFog's June 2026 disclosed-attack report, read directly on 3 August 2026, names "2019" as June's most active group by claimed-victim count, with 12 claims against Qilin's 11 in May, inside a month that saw 102 disclosed attacks across 21 countries from 31 separate claiming groups.
BlackFog's report links "2019" to claims against the Melbourne International Film Festival, made via ticketing provider Ferve and covering roughly 26,700 customer records, a claim MIFF disputes and that remains unverified, and against Australian caterer Hampr, where more than 360,000 records were alleged taken.
Nothing in the available record establishes "2019"'s origin, nationality or affiliate structure, and the name itself, a bare year, is a genuine problem for readers and for search: it is close to unsearchable and easily confused with unrelated material dated 2019. This page will be updated as attribution firms up.