Ransomware groups add U.S. victims
INCRANSOM, THEGENTLEMEN, METAENCRYPTOR and EVEREST added victims in the U.S. across health, finance, technology
Security Arsenal attributed new victims to INCRANSOM, THEGENTLEMEN, METAENCRYPTOR and EVEREST in a run of posts between Aug. 16 and Aug. 23, 2026. The cases include Lansing Urgent Care, Third Coast Bancshares and Kingston Technology, with reported or claimed impact in the United States and across health, finance, technology, transportation and energy.
Security Arsenal said four ransomware groups added new victims in a series of posts published between Aug. 16 and Aug. 23, 2026. INCRANSOM listed 7 new victims, THEGENTLEMEN added 5, METAENCRYPTOR reported 7 in 24 hours, and EVEREST added 4 in a single day. Among the named cases are Lansing Urgent Care, Third Coast Bancshares and Kingston Technology, all with reported or claimed impact in the United States.
What did Security Arsenal say about INCRANSOM?
INCRANSOM posted 7 new victims between Aug. 16 and Aug. 18, 2026, including Lansing Urgent Care and Third Coast Bancshares. Security Arsenal placed that set across financial services, health care and professional services, and described a playbook that starts with initial access through VPNs or edge devices, follows with macro execution or RMM, and moves laterally using Cobalt Strike, WMI or PsExec before exfiltration and encryption.
The reporting on Lansing Urgent Care also remains in an investigative stage rather than a public confirmation. ClassAction.org said the clinic was being investigated as a possible victim of an incident attributed to INC Ransom, with early reports appearing on monitoring sites such as Ransomware.live and HookPhish, though the scope and nature of the alleged breach were still unconfirmed in the latest update. BreachSense also logged an incident attributed to INC_RANSOM against the organization, discovered on Aug. 19, 2026, without yet being able to determine the size of the leak.
Third Coast Bancshares followed a similar path in the trackers. GalaxyWarden documented that the firm was listed on the Inc Ransom leak site on Aug. 18, 2026, and that the group claimed to have obtained files from the Texas bank holding company, although the company had not publicly confirmed the incident or any possible exfiltration. BreachSense later placed the case as discovered on Aug. 19, 2026, with leak size still unknown.
What is known about THEGENTLEMEN and METAENCRYPTOR?
THEGENTLEMEN and METAENCRYPTOR widened the picture with short campaigns spanning multiple sectors and several countries. Security Arsenal said THEGENTLEMEN posted 5 new victims between Aug. 17 and Aug. 19, with coverage in defense, transportation, financial services and technology across five countries, and that its likely initial access would have exploited Check Point Security Gateway or IKEv1 authentication, with reference to CVE-2026-50751.
For METAENCRYPTOR, Security Arsenal reported 7 victims in 24 hours and said 4 of the 7 were in the United States. The affected sectors included transportation, energy and utilities, agriculture and food, and manufacturing. The same source attributed the group’s likely entry point to VPN and supply chain intrusion vectors, and mentioned ScreenConnect, CVE-2024-1708, as a means for persistent access and lateral movement.
How does Kingston Technology fit into the sequence?
Kingston Technology appeared in several records as a victim claimed by Everest, although public confirmation is still pending. Security Arsenal said EVEREST posted 4 new victims in a single day and included Kingston Technology in the United States among them, with a focus on technology and professional, engineering services. Different trackers agreed that the claim was listed on Aug. 20, 2026, and classified it as unconfirmed.
RecentBreaches said Everest claimed to have exfiltrated about 138 GB of data from Kingston Technology, while Rankiteo said the company was investigating the allegation of theft of roughly 138.5 GB of Asia-Pacific marketing materials, with content for markets including Taiwan, Japan, South Korea, Thailand, Vietnam, India, Australia, New Zealand, Malaysia and Singapore. The report added that Kingston acknowledged being aware of the claims, but said its operations were not known to be affected.
Ransomware.live placed the Everest listing discovery on Aug. 20, 2026, in the United States. RecentBreaches and GalaxyWarden repeated that this is an unconfirmed breach claim, and Breach House said the amount of data affected had not yet been disclosed.
GalaxyWarden also recorded Grupo DT as another victim posted by Everest in August 2026, without public confirmation from the company. The portal did not document the country or the impact, but did note the Spanish-language name in the same series of listings.
What does Cyfirma’s weekly report show?
Cyfirma said in its weekly report of Aug. 21, 2026, that the Gunra group is mainly targeting the United States, Spain, Thailand, South Korea and Brazil. In the public version reviewed, the firm only explicitly detailed a recent Krybit attack against a health care entity in Singapore, without adding more detail on Gunra beyond that geographic pattern.
Sources
- INCRANSOM Ransomware Gang: 7 New Victims Posted in 72 Hours — Cross-Sector Campaign Analysis and Detection Engineering Briefsecurityarsenal.com· Security Arsenal
- METAENCRYPTOR Ransomware Gang: 7 Victims in 24 Hours — Cross-Sector Blitz Targeting Transportation, Energy and Healthcare with VPN and Supply Chain Intrusion Vectorssecurityarsenal.com· Security Arsenal
- Lansing Urgent Care Data Breach? Lawyers Investigate ...classaction.org· ClassAction.org
- Lansing Urgent Care Data Breach in 2026breachsense.com· BreachSense
- Victim: Kingston Technology - Ransomware.liveransomware.live· Ransomware.live
- THEGENTLEMEN Ransomware Gang: 5 New Victims in 72 Hours — Cross-Sector Campaign Targeting Defense, Finance and Critical Transportsecurityarsenal.com· Security Arsenal
- EVEREST Ransomware Gang: 4 New Victims Posted in Single-Day Surge — Tech & Professional Services Targeting Analysis with Detection Rulessecurityarsenal.com· Security Arsenal
- Weekly Intelligence Report - 21 Aug 2026cyfirma.com· Cyfirma
- Third Coast Bancshares Listed by Inc Ransom ...galaxywarden.com· GalaxyWarden
- Third Coast Bancshares Data Breach in 2026breachsense.com· BreachSense
- Kingston Technology Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches
- Kingston Technologybreachsense.com· BreachSense
- Kingston Technology: Unconfirmed Breach Claims & DoxxScan™ Ratingrecentbreaches.com· RecentBreaches
- Kingston Technology Listed by Everest Ransomware Groupgalaxywarden.com· GalaxyWarden
- Kingston Technology — EVEREST Ransomware Attack | Breach Housebreach.house· Breach House
- Grupo DT Listed by Everest Ransomware Group | GalaxyWardengalaxywarden.com· GalaxyWarden
- Kingston Technology: Exclusive: RAM maker Kingston Technology investigating ransomware claimsblog.rankiteo.com· Rankiteo



