
S6 RANSOMWARE SIGNAL
Week of June 2 to 8, 2026 | Published by S6 Tech
⚡ 60-SECOND VERSION
Biggest threat: Check Point released emergency patches this week after the Qilin ransomware crew weaponized a VPN zero-day. Attackers bypass authentication entirely on affected gateways.
Why it matters: If you run Check Point Remote Access VPN or Mobile Access, an attacker can sign in as a remote employee without a password and reach everything that employee can.
Do this now: Patch immediately or disable Check Point remote access until you can. Vendor guidance is here.
📋 EXECUTIVE SUMMARY
1. VPN appliances keep landing on the front page. The Check Point zero-day is the second confirmed perimeter-exploit story in two issues, following last week's DragonForce campaign against Fortinet, Cisco, and Pulse Secure. If your remote-access stack has been running on firmware older than 60 days, the bill is in the mail.
2. Phone-based social engineering has a new dedicated operator. We covered ShinyHunters' April vishing runs against ADT and Udemy. We covered the Tycoon2FA and Kali365 phishing kits in May. Silent Ransom Group is the next entry: a crew that calls law firm employees directly, claims to be internal IT, and walks the target through installing remote-control software. Mandiant confirmed the attribution. The phone is now an attack surface in the same way email was a decade ago.
3. Healthcare snapped back to 14 victims after last week's one-week pause, exactly the way we flagged it on May 25. Seven different ransomware crews contributed. The pause was scheduling, not retreat, and any practice manager who used the quiet week to defer patching or backup testing is now back inside the hot zone.
📊 METRICS & INTELLIGENCE
| Metric | This Week | What It Means |
|---|---|---|
| Total Disclosed Victims | 107 | Eighth straight week between 97 and 107. The tempo is structural. |
| Active Threat Actors | 32 | Most fragmented week of 2026. Smaller crews keep filling space behind the leaders. |
| The Gentlemen's Share | 27 (25.2%) | New volume leader. First top finish since the April 6 surge. |
| US-Based Victims | 29 (27.1%) | US share continues to drift down from its May 4 peak. Activity rebalances toward Asia. |
| Healthcare Sector Hits | 14 | Back to peak after last week's drop to 4. Seven different actors contributed. |
Germany (6), India (5), Thailand (4), and Canada (4) followed the US, with the remainder spread across more than twenty countries.
THREAT ACTOR MARKET SHARE, THIS WEEK
The Gentlemen claimed the top spot for the first time since April 6, displacing the rotation among Qilin, Akira, and DragonForce that defined May.
🚨 ACTIVE CAMPAIGNS
Check Point VPN Zero-Day, Qilin Exploitation 🏢
Active attacks confirmed before the patch was available. Authentication bypassed entirely.
What it does: The vulnerability sits inside Check Point Remote Access VPN and Mobile Access. An attacker hitting the gateway can bypass login completely. No stolen password is required. Once inside, the attacker holds the same network access as a remote employee on the corporate VPN.
Why it matters: Check Point disclosed active exploitation before the patch went out, which is the worst possible sequence for any organization that depends on the appliance. Qilin attribution is confirmed by Check Point's own analysis, and the group's playbook (profiled in our April 13 issue) moves from initial access to ransomware deployment in 4 to 24 hours. Qilin posted 16 victims to its leak site this week, including manufacturing giant Isuzu Motors. A volume leader with a fresh zero-day is the news.
Source: BleepingComputer
Silent Ransom Group Phone-Based Attacks on Law Firms 🏪🏢
Vishing operators impersonate IT support. Data theft completes within hours.
What it does: Attackers call attorneys and associates directly, often by name. The pitch is short: "We noticed unusual activity on your account. We need to get you connected to support right now." The target gets walked through installing legitimate remote-access software, typically AnyDesk or Zoho Assist. Once the install completes, the attacker has full keyboard and mouse control of the workstation. Data exfiltration runs in parallel.
Why it matters: Silent Ransom Group does not deploy ransomware. The entire business model is data theft followed by extortion through threat of publication. Legal practice malpractice exposure and client confidentiality push extortion demands three to five times higher than the typical industry average. Vishing as a primary attack vector has now appeared in three of our last six issues under different operator names: ShinyHunters against ADT and Udemy, the Tycoon2FA and Kali365 kits in May, and now Silent Ransom Group against legal targets. Same pattern, new specialist.
Source: BleepingComputer
Oxford University Breach via Group GTI CareerConnect 🏢
Third-party vendor compromise exposes student and alumni data across multiple universities.
What happened: Attackers compromised Group GTI, the vendor that runs the CareerConnect career-services platform used by Oxford and several other universities. Oxford was not breached directly. Student and alumni names, email addresses, and career-services records were exposed across every institution that shares the platform.
Why it matters: Vendor-route breaches keep landing in this newsletter. Snowflake and Anodot in April, Instructure (Canvas LMS) on May 4, the Shai-Hulud NPM and TanStack chain on May 18. Group GTI is the same problem in a different vertical. Universities face GDPR notification windows of 72 hours. Affected students get spear-phished using legitimate career-related context, which is the kind of phishing that lands because it doesn't feel like phishing. The defensive lesson is the one from May 4: a one-page inventory of every vendor with privileged access to your data, with named owners, is no longer a maturity-model nice-to-have.
Source: BleepingComputer
✅ JUST DO THIS
Patch Check Point VPN, or Disable It Until You Can
⏱️ 15 to 30 minutes to patch, 5 minutes to disable | 💰 Free (vendor hotfix)
Why now: Check Point confirmed active exploitation by the Qilin ransomware crew before the patch was available. That sequence means any organization running Check Point Remote Access VPN or Mobile Access has been exposed since at least the start of the week, and may already be compromised. Patching closes the door. Disabling the gateway until you can patch closes the door faster.
| Platform | Steps |
|---|---|
| Check Point customer | SmartConsole, then download the latest hotfix from the Check Point Support Portal. Apply to every gateway appliance. Confirm the Remote Access VPN blade is updated. If you cannot patch today, disable remote access on the gateway and tell remote users to expect a temporary outage. |
| Not sure if you have Check Point | Ask your IT provider or MSP in one sentence: "Do we use Check Point for our VPN or firewall?" If yes, get the patching status confirmed today. |
| Different vendor entirely | No specific action on this issue. Worth a 10-minute pass through your VPN vendor's recent security advisories anyway. Fortinet, Cisco, and Pulse Secure all had patched bugs in the last 90 days. |
Verify it worked: After patching, the gateway version in SmartConsole should match the patched release Check Point named in its advisory. If you disabled the VPN instead, confirm that remote users cannot connect. A successful connection means the disable was applied to the wrong policy.
🎯 THREAT ACTOR SPOTLIGHT
The Gentlemen 🏭
27 victims (25.2%). New volume leader. The self-propagating capability we covered last week is now visible in the leak-site numbers.
Why this group, this week: The volume leader rotated again. DragonForce held it on May 25, Akira on May 11, Qilin for five of the prior six weeks. The Gentlemen now claim the top spot with 27, the largest single-actor share since Akira's May 11 surge. Last week's issue covered Microsoft's forensic analysis of the group's self-propagating Go encryptor (21 simultaneous propagation methods, including stolen credentials, scheduled tasks on remote machines, and Windows management tools). This week, that capability is visible in the volume.
Target profile: SMB-heavy. Healthcare took 4 of the 27 spots this week, manufacturing 3, professional services 1. Revenue band roughly $5M to $100M. Geographic spread runs global: US, Germany, India, Taiwan, Thailand, Poland, Portugal, Guatemala, Singapore.
What's distinctive: Victim leak posts often include ZoomInfo-style company descriptions, which suggests pre-attack scraping of public business-intelligence platforms. Once inside, the worm-like spread runs without an attacker on the keyboard, which is unusual. Leak posts itemize file counts and exfiltration claims (24GB to 500GB), giving the victim no comfortable "maybe it isn't real" reading of the situation.
Defensive Priorities:
| # | Action | Plain English |
|---|---|---|
| 1 | Network segmentation | Separate workstations from servers, even loosely. One infected machine should not be able to reach every other machine on your network. This blocks the worm at the boundary. |
| 2 | Disable SMBv1 and restrict admin shares | Turn off the outdated SMBv1 file-sharing protocol and restrict access to default Windows shares (C$ and ADMIN$). One config change blocks four or more of the 21 propagation methods. |
| 3 | Deploy LAPS | Local Administrator Password Solution gives every machine a unique local-admin password. Compromising one machine no longer unlocks all of them, which kills credential reuse during lateral movement. |
Also Active: Qilin posted 16 victims (15.0%) including the Check Point VPN zero-day exploitation that drives this week's lead. Akira posted 11 (10.3%) with detailed PII exposure claims (passport scans, Social Security numbers, credit cards). Akira's playbook against small practices is the one we profiled on May 11.
🏭 SECTOR TARGETING
Healthcare, 14 victims 🏪
Threat actors: The Gentlemen (4), Qilin (2), Genesis (2), Nova, Akira, DragonForce, Worldleaks.
Notable incidents: Edgewood Surgical Hospital (US, attackers claim 500GB including surgical case reviews and anesthesia records, figure not independently verified), Central Arkansas Pediatrics (US), Michigan Surgical Center (US), Aspire Hospital (India), Central Florida Cosmetic & Family Dentistry (US), REHA-ACTIV (Germany), Family Medical Associates of Raleigh (US).
Data exposed per attacker posts: Patient PHI, surgical reviews, MRI scans, narcotic inventories.
📈 TRENDLINE: HEALTHCARE IN OUR COVERAGE
Apr 7-13: 12 victims · Apr 14-20: 6 · Apr 21-27: 9 · Apr 28-May 4: 12 · May 5-11: 12 · May 12-18: 14 · May 19-25: 4 (the pause) · This week: 14 (rebound)
Six weeks elevated, one week off, full recovery. The May 25 prediction ("watch the next two issues before you exhale") landed exactly. Seven different actors hit the sector this week, which means the rotation pattern is structural rather than the work of any single campaign.
Manufacturing, 12 victims 🏭
Threat actors: The Gentlemen (3), Qilin (2), Akira (2), Play (2), Payload.
Notable incidents: Isuzu Motors (Japan, Qilin's highest-profile victim this week), T/CCI Manufacturing (US), Hansoll Textile (Vietnam), IP Rings (India), Urschel Laboratories (US), Liztex Guatemala.
Professional Services, 9 victims 🏢
Threat actors: Akira (2), Play, INC Ransom, The Gentlemen, Blackbyte-Crux.
Notable incidents: Dallis Law Firm (US), Hal Otey Financial (US), 3E Accounting (Singapore), Quanticate (UK), Factors Western (Canada).
Last week's surge sector cooled by roughly a third. Worth noting: vishing-attack data theft (the Silent Ransom Group campaign in our Active Campaigns section) typically lags leak-site disclosure by weeks. Expect this number to rise in late June.
Construction and Engineering, 8 victims 🏭
Qilin (3) and The Gentlemen (2) carried the bulk. Notable incidents: Danzo Group (US), Ontario Home Builders' Association (Canada), Swim-Mor Pools (US), Geske Haus- und Versorgungstechnik (Germany).
⚠️ SMB Sector Alert: Healthcare
Edgewood Surgical Hospital is the headline. The body of this week's list is dental practices, pediatric clinics, and small specialty groups, most of them under 50 employees and most of them with no dedicated security staff. The combination of valuable PHI and weak access controls is the steady-state target profile. If you run a clinic, this is the week to verify your offline backups are recent and restorable.
🏪 SMB REALITY CHECK
If you're under 50 employees with no dedicated security staff, here's what actually matters this week:
The phone scam targeting law firms applies to every small business. If someone calls claiming to be "Microsoft support," "your IT help desk," or "your bank's fraud team" and asks you to install software, share your screen, or read out a code, hang up. Call the provider back using a number you already trust. This is the same opening move behind the April ShinyHunters vishing campaigns, behind the May Tycoon2FA and Kali365 kits, and now behind Silent Ransom Group's runs at law firms. The toolkit changes. The opening move does not.
The Check Point VPN zero-day probably does not affect you. Small businesses generally run consumer routers or basic firewalls, not enterprise Check Point gateways. If you're unsure, ask your IT provider in one sentence: "Do we use Check Point for our VPN?" Yes means patch today. No means move on.
💡 The phone is now an attack surface
A year ago, security training was about email links. Today it covers email links, browser pop-ups, fake software downloads, search-ad results, and unsolicited phone calls. The common thread is urgency. Every successful attack we have covered in 2026 had the same opening move: a message that wanted the employee to act now. The training that works isn't about the channel. It's about teaching the pause.
Your Stack, Your Actions:
| If You Use... | Do This | Time |
|---|---|---|
| Any business with a phone | Send one message to staff today: "IT will never call you to install software or read out a code. If anyone calls claiming to be IT, hang up and call [your IT person] at [known number]." | 5 min |
| AnyDesk, TeamViewer, Splashtop | Require a password for unattended access. Disable any installation not in active use. This is exactly how Silent Ransom Group lands. | 10 min |
| Microsoft 365 | Confirm last issue's device-code block is in place. Add a geographic block on countries you don't operate in (from our May 4 issue) if you haven't yet. | 15 min |
| Cloud backup (any) | Verify your last backup completed this week. Test a single-file restore. This is the cheapest sanity check in security and almost nobody runs it monthly. | 10 min |
📞 When to Call for Help
If anyone on your team accepted a remote-control invitation from a caller this week, took action on a screen-share they didn't initiate, or installed software based on a phone request, isolate that machine from the network and call your IT provider that day. Silent Ransom Group's playbook completes exfiltration in hours, not days.
Safe to ignore this week: the Dutch server seizure follow-up (we covered the original story on May 25 and the situation has not materially changed), the C0XMO router botnet news (router family used in well under 10% of SMB networks), and any AI-themed phishing emails referencing ChatGPT or Claude billing problems if you simply don't have an account (Looking Ahead covers this).
🔮 LOOKING AHEAD
AI brands as bait, not as targets
Microsoft documented phishing campaigns this week that impersonate AI brands at industrial scale, some exceeding 100,000 emails per day. Lures include fake ChatGPT subscription renewals, fraudulent "AI installer" downloads, and lookalike Claude and DeepSeek login pages. Credential theft and malware delivery are the payoffs.
What's changing: We covered the AI-tool malvertising wave on May 11 (Google Ads pushing fake Claude installers, a Hugging Face trending repo distributing infostealers, the JDownloader supply-chain compromise). That was the "search and download" surface. This week's campaign expands the same playbook to the inbox.
What to watch: Emails about "your ChatGPT account" or "your Claude billing" that arrive without your team having an account. Software downloads claiming to be AI installers from GitHub repositories. Web pages that mimic AI-tool login screens. The common signal is the unsolicited account or billing message.
Bottom line: Legitimate AI services communicate billing changes through their own platforms after you sign in. Type vendor URLs directly. Treat any unsolicited message about an account you don't remember opening as a phish.
📅 This Month's Priority
Refresh your incident-response retainer. Silent Ransom Group's attack model completes data theft within hours, which turns a Friday-evening incident with no after-hours coverage into a Monday-morning disclosure. Confirm your IT vendor or MSP has 24/7 availability documented in writing, and that the emergency contact information lives somewhere reachable when your main network is unavailable. Cost: zero if your retainer already covers this. $500 to $3,000 annually to upgrade if it doesn't.
CLASSIFICATION: TLP:CLEAR
Sources: BleepingComputer (Check Point/Qilin), Jun 8, 2026 · BleepingComputer (Silent Ransom Group), Jun 7, 2026 · BleepingComputer (Oxford/Group GTI), Jun 8, 2026 · Microsoft Security Blog (AI Brands), Jun 8, 2026 · Microsoft Security Blog (Gentlemen analysis), May 28, 2026 · Huntress (Gentlemen TTPs), May 21, 2026 · Unit 42 (Cyber Extortion Economy), May 27, 2026 · Ransomware.live API · RansomLook.io API
S6 RANSOMWARE SIGNAL
Your data is an asset. We guard it like one.
Intelligence cutoff: June 8, 2026 | Next edition: June 15, 2026
