Skip to main content
Pulse · daily intelligencehigh risk

Lamashtu Emerges From Zero, Safepay Accelerates Hard

Published 21 hours ago · Darkfield's AI analyst reads the past 24 hours of ransomware leaks, telegram chatter and blacklist additions, then writes a one-paragraph brief at 06:00 UTC every morning.

54
Victims · 24h
safepay
Top group
11 victims
US
Top country
17 victims
Manufacturing
Top sector
7 victims

Today's pulse

Oct 1, 2026

By Darkfield's AI analyst·Published 21 hours ago·24h window

The most significant development in the last 24 hours is the sudden emergence of Lamashtu, which went from zero recorded victims to 10 in a single cycle — a 1,000% spike that signals either a new group breaking cover or a rebranded actor executing a pre-staged bulk dump of compromised targets. Safepay compounded the pressure by doubling its own pace, posting 11 victims in 24 hours against 5 in the prior period, making it the single highest-volume group today and placing it on a trajectory to challenge thegentlemen's 7-day lead of 45 victims. The 54 total postings in 24 hours land against a 7-day average of roughly 49 per day, confirming this is an above-baseline surge rather than noise. Geographic and sector concentration sharpens the concern: the US absorbed 17 hits and Germany 10, while Manufacturing, Healthcare, and Technology collectively account for 17 of the 54 victims — sectors where operational disruption translates directly into leverage for faster ransom payment. If Lamashtu's debut volume holds or grows into tomorrow's window, defenders should treat it as an active, high-tempo threat actor with an established access pipeline, not a one-day anomaly.

Get this brief every morning at 06:01 UTC.

Pro subscribers receive the daily Pulse as an email digest plus real-time alerts whenever the corpus mentions a monitored asset. Cancel any time.

This week's briefing

Forecast

Source

Pulses, briefings and forecasts are written by Darkfield's AI analyst given the day's structured intelligence: ransomware victim disclosures, blacklist additions, breach catalog deltas, Telegram entity extraction, and cross-source correlations. The source data is the same we expose throughout the rest of this site.