Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Emerging Ransomware Group Claims Around 20 Victims After Launching Leak Site

Emerging Ransomware Group Claims Around 20 Victims After Launching Leak Site

Last updated:July 27, 2026
Human Written
  • A new ransomware group calling itself Global Secret Group (GSG) has launched a data leak site.

  • The group listed about 20 possible victims, while labeling many more as potential victims they’re targeting to hit soon.

  • These are yet to be verified and hence require cautious attention.

Emerging Ransomware Group Claims Around 20 Victims After Launching Leak Site

A fresh ransomware group that no one has heard of before has entered the cybercrime scene. The operation, calling itself Global Secret Group (GSG), has already launched its own data leak site.

The group has published around 20 alleged victims and promises more to come. Several additional entries on its site are labeled as “coming soon.”

A New Player in the Already Crowded Cybercrime Landscape

Global Secret Group arrives at a time when ransomware activity is at an all-time high. Security researchers are tracking a record number of active ransomware groups in 2O26. According to GuidePoint Security’s GRIT Q2 2O26 Ransomware & Cyber Threat Insights Report, there are now 91 active ransomware groups. That is the highest number ever recorded.

These groups claimed 2,279 victims in the second quarter alone. This is an increase of 7% from the previous quarter and 43% compared to the same quarter in the previous year. Victim postings weekly were never below 150 for the quarter.

A slogan on the GSG website states, “We find what others cannot find or see.” The purpose of this statement is to create credibility with future victims and cyber criminals.

Victims Span the Globe

Based on public leak site listings, GSG has targeted organizations in several countries, including the US, Canada, Iraq, Brazil, China, and the UK. The victims represent a wide mix of industries.

For example, data published by ransomware tracking sites shows GSG has listed a furniture manufacturer in Indiana, a food and beverage company in Iraq, and a convenience store chain in Canada.

One of the companies named on the leak site is Al Hayat Company for General Trading, an Iraqi food and beverage distributor and Pepsi bottler. The group claims to have stolen 138 GB of data from the company.

Another alleged victim is OFS, a furniture manufacturer based in Indiana, which the group claims to have hit with a 321 GB data theft. Other organizations include Portman Finance Group in the UK, a Cyprus-based investment firm called One Plus Capital, and Chinese electronics manufacturer Uniview Technologies.

GSG claims it stole internal company files during each ransomware attack. However, the listings provide very few technical details. They generally do not include the number of affected people or the amount of ransom demanded.

Why Caution is Necessary

Listing a company’s name on a leak site does not always mean the attackers have successfully hacked the company. Security analysts have issued warnings that ransomware gangs tend to lie about their attacks to either draw attention to themselves or gain more respect from other criminals.

Analysts typically look for additional evidence before treating a leak site post as confirmed. The same caution applies to other dark web claims, an unverified claim of 1.4 billion Tencent records has emerged, requiring careful scrutiny. This evidence may include a public statement from the victim or samples of stolen data.

Confirmation from incident response firms or government agencies also counts as proof. Until then, the GSG listings should be viewed as unverified attacker claims. Ransomware.live, a site that tracks ransomware groups, explicitly notes that GSG is an “emerging group” and all claims “should be treated with caution until independently verified”.

A Sign of Ransomware’s Continued Growth

The appearance of GSG reflects a broader trend. When established ransomware operations disappear, new brands often emerge to replace them. Some are entirely new groups. Others consist of experienced operators rebranding under different names. This can happen after internal disputes or increased law enforcement pressure.

At this stage, there is no public evidence linking Global Secret Group to any previously known ransomware family. Its emergence is an indication that the ransomware ecosystem is very active regardless of arrests, infrastructure seizure, and law enforcement activities internationally.

The manufacturing industry still suffers the most attacks, with nearly 15% of ransomware attacks reported in Q2 2O26. That sector has held the top spot for several years. The top five most prolific ransomware groups collectively claimed more than 40% of all attacks in the second quarter.

What Organizations Should do

Even though GSG is new, the risks it represents are familiar. Organizations should monitor for unusual network activity. Ensure all users enable multi-factor authentication. More importantly, regularly update all internet-facing systems; delay is dangerous.

Also, maintain offline backups; they’re handy in keeping operations running in the case of ransomware attacks. Check privileged account access often, these steps go a long way toward stopping problems before they start.

A lot of ransomware attacks still start with stealing someone’s credentials or compromising remote access services. Staying calm when a company’s name appears on the leak site of a ransomware group is the first smart move.

Instead, they should immediately begin an internal investigation. They should preserve forensic evidence and engage incident response specialists if necessary. They should also notify regulators or affected parties when required by law.

Global Secret Group is still in its earliest stage. It’s hard to assess the group’s long-term capabilities or to predict whether it will grow into a prominent ransomware operation.

What can be said for sure is that the group has acted promptly to establish its public identity. It is attempting to gain credibility by providing the names of companies from various sectors in different countries. It remains unclear if the group’s claims can withstand outside evaluation.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.