CiberLATAMbywhalemate

CoinbaseCartel, Storm Target US Victims

CoinbaseCartel, Storm, Qilin, DragonForce and SilentRansomGroup posted new victims in the US and Canada across health, finance

Whalemate Labs · AI-assisted researchPublished:4 min read

CoinbaseCartel, Storm, Qilin, DragonForce and SilentRansomGroup added new victims to their leak sites between Aug. 18 and Aug. 24, 2026, with a clear concentration in the United States and one victim in Canada. Threat intelligence reports place the attacks across health care, finance, government, manufacturing and professional services, using initial access methods that include VPNs, RMM tools, phishing, compromised RDP and exploitation of perimeter appliances.

CoinbaseCartel, Storm, Qilin, DragonForce and SilentRansomGroup posted new victims between Aug. 18 and Aug. 24, 2026, with a clear concentration in the United States and one victim in Canada. Reports from Security Arsenal, Threadlinqs, RecentBreaches, HackerFeeds and SatineTech place the cases across health care, finance, government, manufacturing and professional services, and describe initial access and extortion techniques ranging from VPNs and RMM tools to perimeter appliance exploitation, phishing and compromised RDP.

What do the latest posts from the groups show?

Security Arsenal said CoinbaseCartel posted 13 victim organizations in 24 hours, including Kessler Creative and Integrated Health Systems, both in the United States. For Storm, the same firm reported seven new posts in 72 hours, with six of the seven victims also in the United States and sectors spanning government, health care, finance and manufacturing.

Qilin added 15 new victims between Aug. 19 and Aug. 21, with iPic, The Pendas Law Firm and Thrifty Building Supply among the names cited by Security Arsenal. DragonForce, meanwhile, posted four new victims in 24 hours, with a North American presence and Brookview Financial, in Canada, among the entities listed.

SilentRansomGroup added three new posts to its leak site, and Security Arsenal said confirmed targeting in that window was exclusively in the United States. One of the cases cited was Troutman Pepper Locke, a U.S. law firm.

What do the reports say about the targets?

The available reports point to sustained pressure on high-value sectors. Security Arsenal said Storm’s victims were small and mid-sized U.S. businesses, including municipal government entities, health care, financial services and manufacturing. For Qilin, the victim mix included energy, hospitality, manufacturing and legal services.

Threadlinqs’ coverage of Troutman Pepper Locke adds that SilentRansomGroup, also tracked as UNC3753, Luna Moth and Chatty Spider, allegedly added the firm to its leak site LEAKEDDATA on Aug. 18, 2026. The report describes the case as a repeat attack against the same law firm and frames it as a high-severity ransomware and extortion campaign, with a focus on legal, financial services, insurance and health care.

Databreaches.net, cited by Malware.News, also said the attackers began leaking customer data and tens of thousands of Social Security numbers, while the firm kept its public communications limited.

What intrusion techniques appear in the reports?

Security Arsenal described DragonForce as using a technical chain that starts with initial access through VPN or RMM, then moves laterally with valid credentials using PsExec and WMI, and ends with staging, exfiltration, recovery inhibition and encryption. The same report lists TTPs associated with the activity, including T1190, T1078, T1133, T1021.001/.002, T1047, T1569.002, T1560, T1041, T1490 and T1486.

According to Security Arsenal, Qilin used exploitation of perimeter appliances, phishing and compromised RDP as initial vectors. That combination matches the warning Tech-Quire attributed to CISA, the FBI and HHS about Medusa, which mentions more than 500 critical infrastructure organizations compromised since June 2021 and two TrueConf Server flaws under active exploitation.

SatineTech added another technical angle with a joint advisory from NSA, CISA, FBI, EPA and DOE about Siemens S7 programmable logic controllers exposed to the internet in critical manufacturing, water and wastewater, energy, chemical, food, agriculture and defense sectors. In parallel, the same bulletin described a large Cl0p campaign based on CVE-2026-12569 against PTC Windchill PDMLink and FlexPLM, with about 50 organizations affected by around Aug. 14, including Shell, Philips, Fiserv, Zebra Technologies and Ingersoll Rand.

What regional pattern does this wave of incidents show?

The picture left by these posts is one of extortion campaigns that continue to concentrate in the United States, but with regional reach across North America in at least one of the waves observed. In the cases reported, the victims are mainly in health care, finance, government, manufacturing, professional services and transportation or logistics.

RecentBreaches and GalaxyWarden also collected several CoinbaseCartel listings from Aug. 22, including RXPE Group and entities identified as Patel or Flecha Bus. That set reinforces that the group is maintaining an active extortion campaign with impact on manufacturing and transportation or logistics, while several affected organizations still have not issued public statements.

Sources

View all