Skip to content

The Edge of the Cyber World See the latest

Apps

Panzer Ransomware Hits 16 Firms as August Sets 997-Attack Record [2026]

A ransomware crew that did not exist on August 4, 2026 had hit 16 companies across 11 countries by early September. Panzer, the group’s self-chosen name, launched a leak site on August 5 and, within roughly a month, built an affiliate network offering cross-platform encryptors for Windows, Linux, FreeBSD, and VMware ESXi. Researchers who track ransomware-as-a-service (RaaS) startups say Panzer’s growth curve is unusual: most new brands take months to reach double-digit victim counts and multi-country reach. Panzer got there in about three weeks.

The timing matters. Panzer surfaced during the worst single month for ransomware that Comparitech’s tracking has ever recorded. August 2026 logged 997 known or suspected ransomware attacks worldwide, according to Comparitech’s monthly roundup, a 23% jump from July’s 809 attacks and higher than the previous record of 988 set in February 2025. Panzer is one data point inside that spike, but its speed and structure offer a case study in how fast a criminal “startup” can now professionalize.

What Panzer Ransomware Actually Is

Panzer is a ransomware-as-a-service operation, meaning the core group builds the encryption tooling, hosts the leak site, and runs the affiliate portal, while independent “affiliates” carry out the actual intrusions and split the proceeds. Security researcher Andrea Fortuna documented the group’s emergence on August 5, 2026, noting it launched with both a leak site and what he described as a fully featured affiliate platform from day one — an unusual level of readiness for a brand with no prior track record.

Threat intelligence write-ups from CyberXtron and DeafNews independently flagged the same anomaly: a new group typically needs time to build the back-office infrastructure — victim tracking, payment negotiation chat, data-leak staging — that established gangs like LockBit or Qilin refined over years. Panzer arrived with most of that already working. CyberXtron’s profile of the operation pegs the affiliate revenue split at 80/20 in favor of affiliates, a notably generous cut compared to industry norms, which researchers interpret as a deliberate strategy to poach experienced affiliates away from bigger, more established brands.

Technically, Panzer’s payloads target four platforms: Windows, Linux, FreeBSD, and VMware ESXi, according to reporting from GBHackers and analysis from Xpert4Cyber. The ESXi-specific build is significant because virtualization hosts run dozens of virtual machines at once — encrypting the hypervisor layer can take down an entire data center in one shot, which is why ESXi targeting has become a signature move for ransomware crews chasing maximum leverage with minimal effort. No public reporting has yet confirmed the specific encryption algorithm Panzer uses, and independent researchers including Fortuna caution that no verified malware samples, file hashes, or command-and-control infrastructure have been publicly confirmed as of mid-September 2026. That gap in technical detail is itself notable — it means most of what defenders know about Panzer comes from its own leak-site claims rather than reverse-engineered code.

The Victim List: 16 Organizations, 11 Countries

By early September, multiple threat intelligence outlets converged on a count of 16 confirmed victims posted to Panzer’s leak site, spanning 11 countries, though a few trackers put the figure as high as 19 to 21 depending on how “claimed” versus “verified” victims are counted. Thailand leads with three listed victims, while Italy, Indonesia, and Serbia each show two. The remaining single-victim countries include Curaçao, South Korea, Spain, the Czech Republic, Germany, Nigeria, and Switzerland.

Two named Italian victims illustrate the group’s sector focus. Doimo Cucine, a kitchen manufacturer based in Treviso, was listed on August 17 with roughly 30 GB of claimed stolen data. NTE Italia, a telecommunications engineering firm in Catanzaro, appeared on the leak site on August 21 with about 16 GB claimed. Both are mid-sized industrial or infrastructure-adjacent companies — precisely the profile that has drawn the most ransomware attention in 2026 as attackers shift away from headline-grabbing enterprise targets toward operationally critical but security-under-resourced firms.

No verified per-victim ransom demand amounts have been published for any Panzer intrusion. Security outlets covering the group, including CyberPress and GBHackers, note that public reporting has focused on victim counts, sectors, and the group’s affiliate economics rather than dollar figures, meaning any ransom total cited elsewhere should be treated as unconfirmed.

Table: Panzer Victims by Country

Country Confirmed Victims Notable Sector
Thailand 3 Mixed enterprise
Italy 2 Manufacturing, telecom
Indonesia 2 Mixed enterprise
Serbia 2 Mixed enterprise
Curaçao 1 Unspecified
South Korea 1 Unspecified
Spain 1 Unspecified
Czech Republic 1 Unspecified
Germany 1 Unspecified
Nigeria 1 Unspecified
Switzerland 1 Unspecified

Source: CyberXtron, DeafNews, and GBHackers threat intelligence reporting, September 2026.

Why August 2026 Set a Ransomware Record

Panzer’s launch did not happen in a vacuum. Comparitech’s August 2026 ransomware roundup recorded 997 known or suspected attacks worldwide, of which 77 were confirmed directly by the victim organizations. That is the highest single-month total in Comparitech’s tracking history, edging past the prior record of 988 set in February 2025. The United States absorbed the largest share by far, with 417 recorded attacks, followed by Germany and Italy at 48 each, the UK at 36, and Canada at 35.

Breaking the August total down by sector, business targets accounted for 861 of the 997 attacks, healthcare organizations saw 69, and utility-sector attacks doubled from 5 in July to 10 in August. Two established groups, Qilin and a newer outfit called The Gentlemen, together accounted for more than 26% of the month’s total incident volume, according to Industrial Cyber’s analysis of the Comparitech data — meaning that even as headline-grabbing startups like Panzer emerge, the bulk of ransomware volume still flows through a small number of dominant, established brands.

Manufacturing has borne a specific and growing share of that pressure. SecurityWeek’s analysis of the sector found 1,183 ransomware incidents against manufacturers in the first seven months of 2026, a 40% increase over the same period in 2025. Within Europe, Italy logged 57 manufacturing-sector incidents, the UK 43, and France 40 — a pattern that lines up directly with Panzer’s early choice to target an Italian kitchen manufacturer and telecom engineering firm rather than a bank or a tech company.

Table: August 2026 Ransomware Attacks by Country

Country Attacks (August 2026) Share of Total
United States 417 ~42%
Germany 48 ~5%
Italy 48 ~5%
United Kingdom 36 ~4%
Canada 35 ~4%
Rest of world 413 ~40%

Source: Comparitech Ransomware Roundup, August 2026 (997 total incidents, 77 confirmed by victims).

Why RaaS Affiliate Economics Are Shifting

The 80/20 affiliate split that CyberXtron attributes to Panzer is worth pausing on because it signals a competitive labor market inside the ransomware economy itself. Established RaaS brands have historically kept a larger cut for the core operators who build and maintain the encryptor, the leak-site infrastructure, and the negotiation tooling — often splitting closer to 70/30 or 60/40 in the operators’ favor. A startup offering affiliates the lion’s share of the take is effectively subsidizing its own market entry, betting that rapid growth in victim count and reputation will make up for thinner margins per attack.

This mirrors a pattern security researchers have tracked since law enforcement takedowns disrupted LockBit’s infrastructure and reputation. When a dominant brand gets bruised — through a takedown, a leak of its own source code, or a high-profile arrest — its affiliates do not retire, they migrate. Newer, hungrier platforms compete for that displaced talent pool by offering better terms, more platform coverage, and faster payout cycles. Panzer’s simultaneous support for Windows, Linux, FreeBSD, and ESXi from launch suggests its operators anticipated this migration and built for affiliates who already have exploitation playbooks for virtualized enterprise environments.

The practical effect for defenders is that the ransomware landscape is fragmenting rather than consolidating. Instead of a handful of brands controlling most of the market, 2026’s data shows dozens of active or semi-active operations competing for the same pool of vulnerable, under-patched targets, each with slightly different tooling and slightly different sector preferences.

Comparing Panzer to Established Ransomware Brands

Sixteen confirmed victims puts Panzer nowhere near the scale of the groups currently dominating monthly incident counts. Qilin and The Gentlemen combined represented more than a quarter of the 997 attacks logged in August 2026 alone — meaning either group individually likely posted more victims in that single month than Panzer has accumulated across its entire existence to date. LockBit, despite years of law enforcement pressure and a major 2024 disruption operation, continues to appear in monthly rankings as one of the more persistent legacy brands, though public 2026-specific victim-count comparisons across all active groups are not consistently published by any single tracker.

What distinguishes Panzer from typical startup activity is not scale but velocity and polish. Most new RaaS brands spend their first months iterating on a single-platform encryptor and slowly building a leak site’s credibility. Panzer skipped that phase, launching with cross-platform builds and an affiliate portal that researchers describe as resembling the infrastructure of operators several years into their run. That gap between technical maturity and operational history is the detail driving most of the current analyst attention, more so than the victim count itself.

Table: New vs. Established Ransomware Operations, September 2026

Group Status First Observed Reported Scale (2026)
Panzer New RaaS August 5, 2026 16 victims, 11 countries
Qilin Established Pre-2026 Part of >26% of August incidents (with The Gentlemen)
The Gentlemen Newer, scaled fast 2025-2026 Part of >26% of August incidents (with Qilin)
LockBit Legacy, post-takedown Pre-2024 Continues sporadic activity despite 2024 disruption
Rhysida Established Pre-2026 Active in government-sector double-extortion cases

Source: Comparitech, Industrial Cyber, CyberXtron, and GBHackers reporting, September 2026. Figures reflect available public reporting and are not a complete ranked census of all active groups.

How Panzer Fits the Double-Extortion Playbook

Double extortion — stealing data before encrypting it, then threatening to publish the data regardless of whether the ransom is paid — has been the dominant ransomware model since roughly 2020, and Panzer follows the pattern exactly. CyberPress’s coverage describes Panzer as built specifically to support affiliate-driven double-extortion campaigns, with its leak site serving as the public pressure mechanism once a victim organization declines or delays payment.

The model has proven durable because it gives attackers leverage even against organizations with solid backup practices. A company that can restore encrypted systems from backups within hours still faces the separate threat of stolen customer records, financial data, or intellectual property appearing publicly. That second leverage point is why ransomware payment rates have not collapsed even as backup and disaster-recovery adoption has improved industry-wide — the encryption is often now the secondary threat, not the primary one.

Panzer’s early data-volume claims — roughly 30 GB from Doimo Cucine and 16 GB from NTE Italia — are modest compared to the largest double-extortion breaches of 2026, but they follow the same template: enough data to be credible and damaging, published incrementally to maximize pressure during negotiation.

Historical Context: From Single Extortion to RaaS Marketplaces

Ransomware’s evolution over the past decade tracks a consistent arc toward professionalization. Early ransomware campaigns in the mid-2010s were largely single-extortion: encrypt files, demand payment, hope the victim has no backups. The 2019-2020 period saw the rise of leak sites and double extortion as backup adoption made pure encryption less reliable as leverage. By 2021-2022, the RaaS model matured into something resembling a franchise business, with core operators licensing tooling to affiliates in exchange for a revenue cut — the structure that groups like LockBit and Conti scaled to hundreds of victims per year before law enforcement action disrupted both.

What Panzer represents in September 2026 is the next iteration of that arc: a RaaS platform that launches pre-professionalized, skipping the years-long maturation process because the tooling, business logic, and target profile are now well-understood commodities within the criminal ecosystem. The barrier to entry for building a credible ransomware brand has dropped substantially, which helps explain why monthly attack volumes keep setting new records even as law enforcement disrupts individual groups.

Market Impact: Cyber Insurance and Enterprise Security Budgets

Record monthly attack volumes have direct downstream effects on cyber insurance pricing and enterprise security budgeting. Insurers price ransomware coverage based partly on incident frequency data from trackers like Comparitech, and a record month tends to feed into renewal pricing across the following one to two quarters, particularly for manufacturing and mid-market industrial policyholders who are increasingly the segment absorbing the sharpest premium increases given the 40% year-over-year rise in sector-specific incidents that SecurityWeek documented.

For enterprise security teams, the emergence of ESXi-capable RaaS platforms like Panzer reinforces a budget priority that has been building for two years: virtualization infrastructure needs the same patching discipline and network segmentation as traditional endpoints. Xpert4Cyber’s analysis specifically recommends organizations lock down VPN and RDP access and segment ESXi infrastructure in response to Panzer’s emergence, guidance that echoes broader industry advisories following a wave of ESXi-targeted ransomware campaigns throughout 2024-2026.

What Defenders Should Watch For

Because no confirmed malware samples or indicators of compromise have been publicly attributed to Panzer as of mid-September 2026, specific detection signatures are not yet available. That absence is itself a useful signal: organizations in manufacturing, telecom, and adjacent mid-market sectors should treat generic RaaS defensive guidance as the current best practice rather than waiting for Panzer-specific threat intelligence to mature.

Practical priorities include auditing external-facing VPN and RDP endpoints for weak or reused credentials, since affiliate-driven RaaS operations overwhelmingly rely on remote-access abuse and credential theft rather than novel exploits for initial access. Segmenting ESXi management interfaces from general corporate networks reduces the blast radius if an affiliate does gain a foothold. And because double extortion depends on data theft succeeding before encryption begins, egress monitoring and data-loss-prevention tooling tuned to detect bulk outbound transfers can sometimes catch an intrusion during the reconnaissance-and-exfiltration phase, before ransom notes ever appear.

Predictions: Where This Goes Next

  • Panzer’s victim count will likely grow past 30-40 by the end of October 2026 if its affiliate recruitment continues at its current pace, based on the group’s first-month trajectory.
  • Expect at least one more new RaaS brand with similarly pre-professionalized tooling to emerge before year-end, following the pattern of fast-launching platforms competing for displaced LockBit- and Conti-era affiliates.
  • Manufacturing and industrial mid-market firms will remain the fastest-growing ransomware target segment into 2027, continuing the 40% year-over-year growth trend SecurityWeek documented for the first seven months of 2026.
  • Cyber insurance renewal pricing for manufacturing and industrial policyholders is likely to tighten further in Q4 2026 and Q1 2027 as insurers digest August’s record incident count.
  • ESXi-specific ransomware builds will become close to standard for any new RaaS platform launching from this point forward, given how consistently virtualization targeting now appears across both established and startup groups.

Frequently Asked Questions

What is Panzer ransomware?

Panzer is a ransomware-as-a-service (RaaS) operation first observed on August 5, 2026, when its leak site went live. It builds encryption tooling for Windows, Linux, FreeBSD, and VMware ESXi and runs an affiliate program that lets independent attackers use its tools in exchange for a revenue share.

How many victims has Panzer claimed?

Threat intelligence trackers reported 16 confirmed victims across 11 countries as of early September 2026, with some sources citing figures as high as 19 to 21 depending on how claimed-versus-verified victims are counted.

Which countries has Panzer targeted?

Reported victims span Thailand, Italy, Indonesia, Serbia, Curaçao, South Korea, Spain, the Czech Republic, Germany, Nigeria, and Switzerland, with Thailand showing the highest single-country count at three victims.

Is Panzer’s ransom demand amount known?

No. Public reporting as of mid-September 2026 has not disclosed specific ransom amounts for any confirmed Panzer victim. Coverage has focused on victim counts, sectors, and the group’s affiliate revenue-split model instead.

How does Panzer compare to record August 2026 ransomware totals?

August 2026 saw 997 total ransomware attacks worldwide, per Comparitech, the highest monthly figure on record. Panzer’s 16 victims represent a small fraction of that total; dominant groups like Qilin and The Gentlemen together accounted for more than a quarter of the month’s incidents.

What makes Panzer’s affiliate model unusual?

Researchers at CyberXtron reported an 80/20 revenue split favoring affiliates, more generous than terms typically offered by established RaaS brands. This is seen as a strategy to attract experienced affiliates away from bigger, longer-running operations.

Why does Panzer’s ESXi targeting matter?

VMware ESXi hosts often run dozens of virtual machines simultaneously. Encrypting the hypervisor layer can disable an organization’s entire virtualized infrastructure in one attack, making ESXi-capable ransomware disproportionately damaging compared to endpoint-only encryptors.

What should organizations do to defend against groups like Panzer?

Security researchers recommend auditing and locking down external VPN and RDP access, segmenting ESXi management interfaces from general networks, and monitoring for bulk outbound data transfers that could indicate the exfiltration phase of a double-extortion attack in progress.

Related Coverage

Source: Tech Insider