Extortion claims rose to 289 in the last seven days, a 54% increase from the 188 claims expected if the rate of 27 per day (289/7) remained constant. Safepay listed nine organizations today, indicating continued, broad targeting. Recent CISA advisories detail vulnerabilities in network and web application infrastructure.
Unverified claims report 99 extortion listings in the last 48 hours and 289 in the last seven days. Killsec3 accounts for 46 of the 289 listings observed over the last seven days. This concentration suggests Killsec3 is currently the most active group. Likelihood: very likely. Confidence: high (multiple sources, including raw claim data).
Today, Safepay listed lfgholding.com, fedelmundo.com.ph, bio-strath.com, sumperk.cz, eagroep.com, Holiday Inn Vilnius, manno.ch, auromex.com, and cromados.com. 3am listed safescaffolding.net, coosalud.com, pistonespersan.com.ar, midwestbit.com, apexus.com, bhn-expertise.com, and stjames.wa.edu.au. Qilin listed Nissho Electric Manufacturing Co., Ltd.
Astrana Health, Inc. (ASTH) filed an 8-K Item 1.05 on 2026-09-23. Boston Scientific Corp (BSX) filed an 8-K Item 1.05 on 2026-09-08.
Our collection shows CISA issued advisories on 2026-09-27 and 2026-09-25 regarding vulnerabilities in Citrix NetScaler (CVE-2026-88772, CVE-2026-88771), MikroTik RouterOS (CVE-2026-67279), Microsoft SharePoint (CVE-2026-65660), WordPress Core (CVE-2026-87902), WSO2 Multiple Products (CVE-2026-5430), Adobe Commerce and Magento (CVE-2026-71362), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP APM (CVE-2026-94127), and Check Point Multiple Products (CVE-2026-93616, CVE-2026-85102). N0n listed Dediserve Ltd (GB) Technology. Emperador listed SiteProRentals (Hospitality) and Electrolux (SE, Manufacturing).
The current volume of 289 extortion claims over seven days is 100 more than the 189 claims expected if the rate of 27 per day remained constant. The listed groups—Killsec3, Clop, TheGentlemen, Qilin, MetaEncryptor, Akira, Safepay, IncRansom, SilentRansomGroup, Termite, 3am, and LeakedData—represent a diverse range of actors. Likelihood: likely. Confidence: moderate (based on claim data).
The increase in extortion claims suggests an elevated risk to organizations. The concentration of claims attributed to Killsec3 (46 of 289) indicates this group is actively engaged in operations. Likelihood: very likely. Confidence: high (based on claim data). A credible alternative explanation is that organizations are improving detection and reporting of incidents, leading to an increase in observed claims. However, this is unconfirmed. Gaps include the lack of information regarding the specific vulnerabilities exploited in the extortion events and the nature of the incidents disclosed in the SEC filings. We do not know if the SEC filings represent the same actors as the extortion claims.
Monadnock Cyber LLC · At the intersection of AI and Security



