Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationhealthcare-sector-threatoperational-disruptionunderground-data-leak

Ransomware Activity Updates: January 2026 Trends, Milkyway Variant, and Lakelands Public Health Incident

Updated 3mo agoFirst seen Feb 6, 20263 sources

Ransomware reporting in early February highlighted both broad January 2026 activity and specific new developments. BlackFog tracked 91 publicly disclosed ransomware attacks to open 2026, with healthcare the most targeted sector (27 incidents) and nearly half (49%) of recorded attacks not publicly claimed by a known group; among claimed activity, Qilin led with eight incidents and the U.S. accounted for 58% of disclosed attacks. Separately, CYFIRMA reported identifying a ransomware strain dubbed Milkyway, which encrypts files and appends the .milkyway extension, presents a full-screen ransom message, and uses typical extortion pressure (including threats to leak stolen data), with recovery generally dependent on offline/secure backups absent cryptographic flaws.

A healthcare-specific incident in Ontario was also disclosed: Lakelands Public Health reported a cybersecurity intrusion discovered Jan 29 and reported Feb 3, which disrupted internal systems and some public services during containment while stating infectious disease and clinical appointment systems were not impacted. The Lynx ransomware group publicly claimed responsibility by listing the organization on a leak site and implying data theft; Lakelands Public Health engaged a specialized cybersecurity firm and worked with law enforcement and forensics to validate the claim and determine scope. UpGuard characterized Lynx as a RaaS operation and an alleged successor to the INC ransomware group, consistent with double-extortion tactics (encryption plus threatened data exposure).

Share:
Ransomware Activity Updates: January 2026 Trends, Milkyway Variant, and Lakelands Public Health Incident
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 6, 20265mo ago

CYFIRMA documents Pulsar RAT malware campaign

CYFIRMA disclosed technical details of a stealthy, memory-resident Windows malware operation it labeled Pulsar RAT. The campaign was described as modular and in-memory, using a multi-stage infection chain for remote control, surveillance, and data theft with exfiltration over common online services.

CYFIRMA identifies emerging Milkyway ransomware strain

CYFIRMA reported a developing Windows-targeting ransomware strain dubbed Milkyway, describing its encryption behavior, ransom note, and tactics including persistence and shadow copy deletion. The report characterized the malware as using coercive extortion threats involving data leaks and outreach to victims' partners or authorities.

Feb 5, 20265mo ago

Lynx ransomware group claims Lakelands Public Health attack

The Lynx ransomware group listed Lakelands Public Health on its dark web leak site, claiming responsibility for the incident and implying data exfiltration. The health unit said those claims had not been verified and that affected individuals would be notified if confirmed.

Feb 3, 20265mo ago

Lakelands Public Health publicly reports cybersecurity incident

On February 3, 2026, Lakelands Public Health disclosed a significant cybersecurity incident. The organization said it had activated incident response protocols, engaged a specialized cybersecurity firm, and was working with law enforcement and forensic experts to determine scope and whether any personal or health information was compromised.

Jan 31, 20265mo ago

BlackFog reports 91 publicly disclosed ransomware attacks in January

BlackFog said January 2026 saw 91 publicly disclosed ransomware attacks worldwide, with healthcare the most targeted sector, followed by government and manufacturing. The report noted the United States accounted for 58% of disclosed attacks and that nearly half of incidents were not yet publicly claimed by a known ransomware group.

Jan 29, 20265mo ago

Lakelands Public Health detects network intrusion

Lakelands Public Health in Ontario detected a cybersecurity intrusion and began containment and investigation activities. Several internal systems and some non-urgent public services were later disrupted, while infectious disease and clinical appointment systems were reported unaffected.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

147 LINKEDOpen in app
Affected products
12 linked
WindowsFortigateConfluence Data CenterOutlookHg532Netscaler GatewayConfluence ServerExchange ServerNetscaler AdcConfluence Data Center And ServerTelegramZendesk
Organizations
93 linked
Natural IntelligenceThe Walt Disney CompanyBRICYFIRMAPoint WildMarvel EntertainmentHosokawa Micron CorporationArgaam Investment CompanyHandsome Industrial Company, LimitedImpressico Business SolutionsLinkUMKMAmerican Electric PowerNvidiaTeslaDelta Air LinesLuxshareNikeAppleTotalEnergiesTargetGlobal-eLedgerGrubhubSedgwickPickett and AssociatesTampa Electric CompanyDuke Energy FloridaBrightspeedManageMyHealthBosch Choice Welfare Benefit PlanPearlman Aesthetic SurgeryAssociated Radiologists of the Finger LakesProsuraGulshan Management Services, Inc.EndesaKyowon GroupAZ MonicaEurail B.V.Canadian Investment Regulatory OrganizationCrunchbaseValley Eye AssociatesImperial Beach Community ClinicRaagaMcDonald's IndiaHyatt Place Chelsea New YorkAdvanced Family Surgery CenterVida Y Salud-Health SystemsNissan Motor Co., Ltd.Laurel Health CentersCivil Service Employees AssociationWaltioColumbia Medical PracticeMACT Health BoardTriCity Family Services360 DentalKPMG NetherlandsLangley Twigg LawVladimir Bread FactoryGeoplinReproductive Medicine Associates of MichiganTulsa International AirportAvosina Healthcare SolutionsCopec S.A.J Grennan & SonsPaylogixMoenGorlick, Kravitz & ListhausFullBeauty BrandsSpindletop CenterGarner FoodsLand and Agricultural Development Bank of South AfricaDublin Medical CenterHale Makua Health ServicesLaidley Family DoctorsBolttechEnviro-Hub Holdings Ltd.Hilton HotelsMcDonald’s IndiaAppalachian Community Federal Credit UnionCressiCanopy HealthMcPhillamys GoldBrinks Poultry LtdASRock RackRegis ResourcesJu Teng International Holdings LimitedCytek BiosciencesEsquire BrandsRogers Capital CreditAndover Eye AssociatesDermatology AssociatesDenton County MHMR CenterSmartCOP
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.