ThreatVectr, a commercial tracker that counts postings on criminal leak sites, recorded 1,088 ransomware claims in August against 976 in July, a rise of 112, while the number of groups posting at least one victim went from 68 to 83 12. A leak site is the criminal-run page where a crew names an organisation it says it has breached, usually to pressure it into paying.
Qilin claimed 165 August victims after 127 in July and took first place. The Gentlemen fell from 137 to 116 and second place, having passed Qilin in a shorter tracker window over the turn of the month . Qilin has topped a monthly ranking before, on a different tracker's June count , so the order changing hands twice inside a summer says less about capability than about who is posting.
The country breakdown carries the finding. The United States share barely shifted, 34.1 per cent in July and 33.5 in August, so American claims grew roughly in step with the total: 333 of 976, then 365 of 1,088. That works out at 32 of the 112 additional claims. Italy rose faster than anywhere else, from 27 claims and seventh place to 50 and third, a jump of 85 per cent inside one month 34. Those 23 extra claims account for roughly a fifth of the month's growth, and the published breakdown does not say where the remaining half sits.
These are claims posted by criminals, not confirmed breaches, and ThreatVectr says as much: crews exaggerate, duplicate and occasionally invent. ThreatVectr also revised both months upward after first publishing them, as leak-site counts move when late postings are scraped, so treat the totals as an estimate rather than a closed number. BlackFog, a data-security vendor that counts publicly disclosed attacks instead of leak-site posts, recorded 111 disclosed attacks across 27 countries in July and named The Gentlemen the month's most active crew on 11 attacks 5. Two methods, two leaders, and what actually changed in August is who posts most.
