Between May 29 and June 1, 2026, criminal leak sites and security blogs surfaced another wave of ransomware marketing across payments processors, law firms, packaging suppliers, and municipal governments. BreachHistory added canonical rows for the highest-signal names; unless a company publishes a forensic notice, treat each as an actor-claimed event.
Everest financial-sector cluster
- Fiserv — U.S. core banking and payments technology
- Symcor — Canadian transaction processor
- Epiq Global — legal managed services (May 2 listing)
- VVO Finance — Germany (June 1)
Law firms (SilentRansomGroup)
- Fox Rothschild
- Orrick
- Sandberg Phoenix (May 6)
June 1 manufacturing and government claims
- Carton Craft Supply (Qilin)
- Grupo Mauá (BravoX, Brazil)
- Limburg-Weilburg County (Abyss, Germany)
- Schneebeli AG (AiLock, Switzerland)
Other notable May 29 listings
See also Shoreline Sightseeing, CommScope, Cognizant, Balfour Beatty, HumanEdge, and Interzero.
Pair this with our late May roundup and MyDukaan forum claim coverage. Enable monitoring for vendor names you rely on.
Sources: DeXpose intel feeds, Hookphish ransomware blog