KRYBIT and LOCKBIT5 Add New Victims
KRYBIT, LOCKBIT5, and INC Ransom added new victims, with most activity centered on the United States and fresh listings in 48 and 24 hours.
Security Arsenal logged 13 KRYBIT victims in 48 hours and five LOCKBIT5 victims in 24 hours, while INC Ransom added more cases tied to Ruby Seven Studios, Bencivil, and Oilquip Inc.
Security Arsenal reported that KRYBIT added 13 organizations to its leak site in a 48-hour window between Aug. 24 and Aug. 26, 2026. The victims were spread across India, Brazil, Guatemala, Gabon, Vietnam, the United States, and Germany. In that analysis, the source identified wmiemporium.com as a U.S. victim in the Retail and E-Commerce sector. Ransomware.live added that the entry was discovered on Aug. 26, 2026, and that the estimated attack date was also Aug. 26.
What did the LOCKBIT5 campaign show?
Security Arsenal said LOCKBIT5 added five new victims in 24 hours, with targets in Tunisia, the Netherlands, Belgium, Czechia, and the United States. Within that campaign, the source identified theheartcenterofmemphis.com as a U.S. victim in Healthcare. The same analysis pointed to a sector focus on healthcare, professional services, and technology.
What did RST Cloud’s report on Aurora show?
RST Cloud published The Aurora Files, a report that describes activity from an Aurora ransomware affiliate and lists TTPs including Bloodhound, Petitpotam, Printerbug, Eternalblue, Kerberoasting, AS-REP roasting, Netexec, shadow copy deletion, Certipy, Ntlmrelayx, DCSync, Kerbrute, Hashcat, Evil-WinRM, Chisel, Proxychains, and Metasploit. In its post, the account said the targets included manufacturing, food and agriculture, pharmaceutical and chemical distribution, and professional and consulting services, with a presence in the United States. RST Cloud later expanded on the information and said the exposed personal directory documented activity from April through July 2026, that the operator targeted more than 20 organizations in nine countries, gained domain-level or interactive access in 17 of them, and that four victims eventually appeared by name on Aurora’s leak site.
How did the Ruby Seven Studios case progress?
Ransomware.live maintains a listing for Ruby Seven Studios tied to INC Ransom, with a discovery date of Aug. 27, 2026, 114 GB of leaked data, 133,851 files, and 49,357 folders. GalaxyWarden added that the company was listed on INC Ransom’s leak site on Aug. 27 and that the group claims to have published a 114 GB archive with source code, game rules, assets, documents, financial reports, royalty statements, employee invention agreements, shareholder lists, and copies of identity documents or passports belonging to partners. RecentBreaches said the claim remains unverified and that the company has not issued a public confirmation. BreachSense placed the discovery date on Aug. 28 and described Ruby Seven Studios as a Nevada-based social casino gaming company focused on free-to-play apps.
What other INC Ransom victims appeared in the same wave?
GalaxyWarden documented that Benchmark Civil Engineering Services, Inc. was listed by INC Ransom on Aug. 27, 2026, and that there was no public confirmation from the company. RecentBreaches published a similar notice on Bencivil, warning that the entry suggests exposure of personal data for an unspecified number of individuals and that the claim is unverified. Darkfield later reported that Oilquip Inc was listed on Aug. 29, 2026, on INC Ransom’s leak site and linked to the specific post on the group’s Onion infrastructure, while GalaxyWarden said the group claims to have obtained internal data and that the company had not publicly confirmed the intrusion at the time of publication.
Sources
- KRYBIT Ransomware Gang: 13 Victims in 48 Hourssecurityarsenal.com· Security Arsenal
- Bencivil Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches
- LOCKBIT5 Ransomware: 5 Victims Posted in 24 Hours — Healthcare & Tech Sector Surge with Detection Rulessecurityarsenal.com· Security Arsenal
- Bencivil Listed by incransom Ransomware Groupgalaxywarden.com· GalaxyWarden
- Oilquip Inc data breach — Incransom ransomware leak (2026)darkfield.orizon.one· Darkfield (Orizon)
- Ruby Seven Studios Data Breach in 2026breachsense.com· BreachSense
- Oilquip Inc Listed by INC Ransom Ransomware Groupgalaxywarden.com· GalaxyWarden
- RST Cloud en X: #threatreport #HighCompleteness Caught in 4K: The Aurora Filesx.com· RST Cloud
- Victim: Ruby Seven Studiosransomware.live· ransomware.live
- Ruby Seven Studios Listed by incransom Ransomware Groupgalaxywarden.com· GalaxyWarden
- Victim: wmiemporium.comransomware.live· ransomware.live
- Ruby Seven Studios Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches



