September 3, 2026
The Ransomware Crew Holding Your Files Has No Reputation to Protect
Two crews nobody had tracked before claimed 33 of this week’s 97 ransomware victims, and the top category in Coveware’s latest caseload has…
By S6 Tech
4 min read
Two crews nobody had tracked before claimed 33 of this week's 97 ransomware victims, and the top category in Coveware's latest caseload has no group name at all. Here is why paying stopped being a plan for a small business, and the free 60 minute test that replaces it.
The owner of a four chair dental practice outside Orlando came in early on a Sunday to catch up on charts.
The practice management software would not open. She restarted the server the way her IT guy had walked her through once, over the phone, two years ago.
Same screen.
Then she found the text file sitting on the desktop. A wallet address. A countdown. A link to a chat portal.
She did what almost everyone does. She started running numbers. Her brother in law's HVAC company had paid back in 2023 and had their files inside a week. Ugly, expensive, survivable. She spent the morning working out what she could raise and how fast.
She was pricing a transaction nobody had offered her.
The name at the top of that chat portal had first appeared on public ransomware trackers three and a half weeks earlier. Nobody had ever gotten files back from it. Not because it refuses. Because nobody has been there yet.
What just happened
Between August 25 and August 31, public leak trackers logged 97 organizations named by ransomware crews, spread across 24 separate operations. Two of those names, orova and zawoo, took 33 of the 97 between them. Neither had shown up in nineteen prior issues of this newsletter covering more than forty crews.
orova posted sixteen victims, and all sixteen went up on August 30. Seven were Florida small businesses: dental practices, veterinary clinics, HVAC contractors, homeowner association managers. The rest landed in Taiwan, Hong Kong, and the UK. Breachsense logged its first orova victim on August 5.
zawoo posted seventeen. Nine in Germany, the rest through the Czech Republic, Brazil, Canada, Austria, and New Zealand. Foundries, engineering firms, a machine monitoring company outside Frankfurt. Claimed volumes run from 4.3 GB to 90 GB.
Pull up zawoo's listings on Ransomware.live and one field repeats on every entry: estimated attack date, August 18. Published August 30. Twelve days between somebody getting inside and anybody finding out.
Established ransomware crews run franchises. Affiliates rent the tooling and the leak site, the operator takes a cut, and the brand is the actual product. When a crew like Akira or Qilin hands over a working decryptor, that is not decency. That is marketing. Every victim who pays and recovers becomes a data point the next victim's negotiator looks up. Insurers track it. Incident response firms track it.
The reputation is the collateral, and it is the only thing that makes the transaction work at all. A name that first appeared three weeks ago has none to lose.
Why your ransom plan didn't help
Rank the things people quietly assume will get them out of this, weakest first.
The promise to delete your stolen data. Worth nothing. When law enforcement seized LockBit's servers in 2024, they found the crew had kept victim data it promised to delete. Coveware, which negotiates these cases for a living, called it what it was: victims paid for a result never delivered. It repeated in June 2026, when a newer crew called Icarus hit a software provider, a ransom was reportedly paid for deletion, and a separate criminal group turned out to be holding the victim names and data samples.
Your cyber insurance policy. It pays for lawyers, forensics, and notification letters. It unpublishes nothing.
Doing your homework on the crew. Only works when there is homework to do. In Coveware's second quarter of 2026, the largest category in its caseload was Lone Wolf at 17 percent, ahead of ShinyHunters at 12 and Akira at 9. Lone Wolf is not a group. It is the absence of one.
The decryptor itself. Even from a crew with a history, decryption runs slow and partial. It is a recovery tool built by people with no reason to test it on your file server.
A restore you have timed with a stopwatch. The one that works, and the only item here that does not require a criminal to keep a promise.
One limit worth stating. Backups bring back what was encrypted. They do nothing about what was copied, and this week was mostly copying. What you control is how fast you open again, not whether the data stays private. That is still the difference between a bad week and a closed business.
What you can actually do this week
1. Time one restore, end to end. Free. About 60 minutes.
Pick a real file your team touches daily. Delete it from the working copy. Restore it from backup. Time it on your phone. Do this with the person who would actually be doing it at 6 a.m. on a Sunday, not your IT vendor. If nobody finishes inside an hour, you do not have a backup. You have an assumption.
2. Put one copy where your own network cannot reach it. Free if you use a drive you already own, low hundreds a year for immutable cloud storage. About 45 minutes.
CISA's guidance for small businesses is three copies, two kinds of storage, one offline. A cloud sync folder is not the third copy. It faithfully replicates whatever just happened to the original. The test is simple: if an attacker held full admin rights on your network right now, could they delete it? If yes, it does not count.
3. Write down who decides, before you need to know. Free. 30 minutes.
Name one person authorized to make the payment call. Write one line saying nobody else answers the chat portal without that person on the line. Add the numbers you would need at 6 a.m.: your insurance carrier's incident line, your attorney, your local FBI field office. Skip this and the decision gets made by whoever finds the note first.
If this was useful
I write S6 Ransomware Signal, a free weekly newsletter for small and mid-size businesses without a dedicated security team. It is the work this article came out of, seven days at a time.
This week's issue also covers the account takeover that skips the login page. On August 30, Anthropic began emailing Claude customers to say ordinary malware on their own machines had copied their logged in sessions, and an attacker used those accounts with no password and no second factor.
It covers Unit 42's Spring Ring breakdown: more than 150 employees at ten or more companies, called by external Microsoft Teams accounts posing as their own help desk. No link, no attachment, and one branch ending in an attempted takeover of the domain controller.
And a phishing console selling for about $500 that shows the operator your card number and your text code as you type them, with a timer counting down how long that code stays good.
Subscribe here. No cost, no pitch, one email a week.
The crews are writing this playbook a week at a time. The one your plan was built around got seized two years ago.