Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Crews now cross-claim each rival victim

4 min read
16:08UTC

Bitdefender's June debrief found affiliates now claiming victims already posted by rival crews, one group adding physical break-ins, and construction overtaking manufacturing as the most-targeted sector.

TechnologyDeveloping
Key takeaway

Affiliates cross-claiming rival victims signals a ransomware market churning faster than takedowns can thin it.

Bitdefender's June threat debrief flags a structural shift in the ransomware market: affiliates are now claiming victims already posted by rival crews 1. Affiliates are the independent operators who lease attack tooling from a ransomware-as-a-service brand and split the proceeds. The cross-claiming is a symptom of how freely they now move between programmes, and of how commoditised the IAB (initial access broker) market has become. The same brokered, pre-authenticated access that a Check Point VPN zero-day supplies in bulk a few sections up feeds this churn directly.

The Silent Ransomware Group has added physical on-site infiltration against legal and financial firms, pairing a network intrusion with a person through the door. MedusaLocker has rebranded as Bavacai and re-entered the top ten, a familiar move that lets a crew shed law-enforcement heat without losing its tooling 2.

Construction has overtaken manufacturing as the most-targeted sector 3. The logic is unglamorous: construction firms combine project-stage cash-flow pressure with weaker security maturity than manufacturing, which makes them quicker to pay and slower to detect. Enforcement is working the same market from the other end. The Europol seizure that disrupted at least 25 gangs helped push two crews out of the top tier after law-enforcement visibility rose, set against May's baseline of 95 disclosed victims across 37 active groups . The picture is a market under pressure but not consolidating: crews rebrand and re-enter faster than takedowns remove them.

Deep Analysis

In plain English

Ransomware is a type of cyberattack where criminals break into a company's computer systems, lock up or steal the data, and demand money to unlock it or not publish it. These criminal groups have become organised like businesses, with some providing the technical tools and others renting access to those tools to run actual attacks, a model called ransomware-as-a-service. A security company called Bitdefender found several notable changes in this criminal market in June 2026. Different criminal groups are now both claiming credit for the same attack on the same victim, because they independently bought access to the victim's network from the same underground broker. One group called the Silent Ransomware Group has gone further: its members physically showed up at the offices of law firms and financial companies to steal documents, combining an old-fashioned break-in with a cyberattack. Construction firms overtook manufacturers as the most commonly targeted industry, possibly because construction companies hold contract pricing, planning documents, and subcontractor relationships that fetch high ransoms, but typically invest less in security.

What could happen next?
  • Consequence

    Affiliate cross-claiming creates a dual-extortion negotiation problem for victims: paying one RaaS programme does not resolve the parallel claim from a second affiliate who purchased the same IAB access.

    Immediate · Assessed
  • Risk

    Silent Ransomware Group's physical infiltration tactic against legal and financial firms represents a hybrid cyber-physical threat requiring physical security controls alongside network defences for high-value document environments.

    Short term · Reported
  • Consequence

    Construction sector overtaking manufacturing as the most-targeted vertical will prompt cyber insurers to revise construction-sector exposure models and increase premium rates for firms without demonstrated security baselines.

    Medium term · Reported
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

Bitdefender· 14 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.