cognitive cybersecurity intelligence

News and Analysis

Search

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Qilin ransomware has grown from a fast-moving criminal operation into one of the most visible threats in the global extortion landscape.

The group encrypts systems and steals data, then pressures victims with the risk of public leaks. Its campaigns have disrupted organizations across sectors and countries, creating both operational and reputational damage.

Ransomware groups increasingly rely on exposed credentials, unpatched software, and trusted third-party connections to reach victims.

Qilin has also shown the ability to move quickly through compromised environments, including through techniques described in coverage of Qilin’s RDP history abuse, which can help attackers identify systems and accounts inside a network.

Black Kite said in a report shared with Cyber Security News (CSN) that Qilin claimed 1,358 victims during the period it tracked, a 443 percent rise from the prior year.

Analysts at Black Kite noted that the group operated across more than 50 countries and accounted for roughly one in every five to six disclosed ransomware victims.

The wider ransomware picture is also worsening. Black Kite recorded 7,551 publicly disclosed victims between April 2025 and March 2026, up 24.9 percent year over year, while March alone reached 861 victims, the highest monthly total the researchers had observed.

Qilin Ransomware Claims 1,358 Victims

Qilin’s 1,358 claimed victims place it at the center of a crowded and increasingly aggressive ransomware market.

The group’s rise came as the number of active ransomware operations expanded to 146 by June 2026, showing that criminal groups are still entering the market even as older brands disappear.

The report found that the top five ransomware groups controlled 43.6 percent of disclosed victims, but no single actor dominated the year in the way previous leading groups had.

Qilin stood out through the scale of its activity, while other groups focused on mass exploitation, exposed credentials, or specific regions.

Manufacturing remained the most targeted industry, recording 1,660 disclosed victims, followed by professional, scientific, and technical services with 1,389.

Organizations in the $50 million to $100 million revenue range also became a larger share of known victims, suggesting that mid-sized firms are facing growing pressure alongside major enterprises.

Qilin’s growth also reflects a wider shift in attacker behavior. Recent reporting on PAN-OS flaw deployment shows how threat actors can exploit authentication weaknesses in internet-facing systems to establish access and deploy ransomware, making rapid patching essential for exposed infrastructure.

Recovery Does Not End Risk

Black Kite’s post-incident scans found that many organizations remained exposed after their ransomware cases had closed.

Some 43.5 percent of victims still had a critical patch vulnerability, while 30.8 percent continued to carry a known exploited vulnerability that attackers could use.

The findings reinforce the need to treat recovery as more than restoring encrypted files.

Organizations should conduct structured external reviews at 30, 60, and 90 days after an incident, with attention to stolen credentials, critical vulnerabilities, and systems listed in the Known Exploited Vulnerabilities catalog.

Third-party applications need closer review as well. The report highlighted abuse of OAuth tokens and connected software as an important attack path, while the Salesloft Drift token theft incident demonstrated how compromised application access can expose data held in connected environments.

Security teams should prioritize patches based on active exploitation and severity rather than routine maintenance schedules.

They should also inventory connected applications, review OAuth permissions, rotate credentials after suspicious activity, and enforce multi-factor authentication across internal and vendor accounts.

These measures help reduce the openings that ransomware operators repeatedly exploit.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an
The post Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts