Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Crews now cross-claim each rival victim

4 min read
12:09UTC

Bitdefender's June debrief found affiliates now claiming victims already posted by rival crews, one group adding physical break-ins, and construction overtaking manufacturing as the most-targeted sector.

TechnologyDeveloping
Key takeaway

Affiliates cross-claiming rival victims signals a ransomware market churning faster than takedowns can thin it.

Bitdefender's June threat debrief flags a structural shift in the ransomware market: affiliates are now claiming victims already posted by rival crews 1. Affiliates are the independent operators who lease attack tooling from a ransomware-as-a-service brand and split the proceeds. The cross-claiming is a symptom of how freely they now move between programmes, and of how commoditised the IAB (initial access broker) market has become. The same brokered, pre-authenticated access that a Check Point VPN zero-day supplies in bulk a few sections up feeds this churn directly.

The Silent Ransomware Group has added physical on-site infiltration against legal and financial firms, pairing a network intrusion with a person through the door. MedusaLocker has rebranded as Bavacai and re-entered the top ten, a familiar move that lets a crew shed law-enforcement heat without losing its tooling 2.

Construction has overtaken manufacturing as the most-targeted sector 3. The logic is unglamorous: construction firms combine project-stage cash-flow pressure with weaker security maturity than manufacturing, which makes them quicker to pay and slower to detect. Enforcement is working the same market from the other end. The Europol seizure that disrupted at least 25 gangs helped push two crews out of the top tier after law-enforcement visibility rose, set against May's baseline of 95 disclosed victims across 37 active groups . The picture is a market under pressure but not consolidating: crews rebrand and re-enter faster than takedowns remove them.

Deep Analysis

In plain English

Ransomware is a type of cyberattack where criminals break into a company's computer systems, lock up or steal the data, and demand money to unlock it or not publish it. These criminal groups have become organised like businesses, with some providing the technical tools and others renting access to those tools to run actual attacks, a model called ransomware-as-a-service. A security company called Bitdefender found several notable changes in this criminal market in June 2026. Different criminal groups are now both claiming credit for the same attack on the same victim, because they independently bought access to the victim's network from the same underground broker. One group called the Silent Ransomware Group has gone further: its members physically showed up at the offices of law firms and financial companies to steal documents, combining an old-fashioned break-in with a cyberattack. Construction firms overtook manufacturers as the most commonly targeted industry, possibly because construction companies hold contract pricing, planning documents, and subcontractor relationships that fetch high ransoms, but typically invest less in security.

What could happen next?
  • Consequence

    Affiliate cross-claiming creates a dual-extortion negotiation problem for victims: paying one RaaS programme does not resolve the parallel claim from a second affiliate who purchased the same IAB access.

    Immediate · Assessed
  • Risk

    Silent Ransomware Group's physical infiltration tactic against legal and financial firms represents a hybrid cyber-physical threat requiring physical security controls alongside network defences for high-value document environments.

    Short term · Reported
  • Consequence

    Construction sector overtaking manufacturing as the most-targeted vertical will prompt cyber insurers to revise construction-sector exposure models and increase premium rates for firms without demonstrated security baselines.

    Medium term · Reported
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

Bitdefender· 14 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.