Qilin Ransomware Surges, Claiming Over 1,300 Victims Globally
The Qilin ransomware group has seen a dramatic increase in activity, reporting 1,358 victims worldwide, a 443% year-over-year rise, as the overall ransomware threat landscape continues to expand.

The Qilin ransomware operation has evolved into a prominent threat within the global extortion landscape, significantly escalating its attacks. The group employs a dual-threat strategy, encrypting victim systems while simultaneously exfiltrating sensitive data, which is then leveraged for further pressure through the threat of public disclosure. This tactic has led to widespread disruption across various industries and geographical regions, causing substantial operational and reputational damage to affected organizations.
Attackers like Qilin increasingly rely on a combination of compromised credentials, unpatched software vulnerabilities, and compromised third-party connections to infiltrate target networks. Qilin, in particular, has demonstrated a rapid ability to move laterally within compromised environments. Techniques such as abusing Remote Desktop Protocol (RDP) history have been observed, enabling threat actors to efficiently identify and exploit systems and accounts within a network.
Recent analysis by Black Kite indicates a staggering 443% increase in claimed victims for Qilin over the past year, reaching a total of 1,358. The group's operations span over 50 countries, accounting for approximately one in every five to six publicly disclosed ransomware victims. This surge occurs against a backdrop of a worsening overall ransomware environment, with Black Kite recording 7,551 publicly disclosed victims between April 2025 and March 2026, a 24.9% year-over-year increase. March 2026 alone saw a record 861 victims reported.
The ransomware market remains highly competitive, with the number of active ransomware operations expanding to 146 by June 2026. While the top five ransomware groups collectively accounted for 43.6% of disclosed victims, no single actor has dominated the market as in previous years. Qilin's prominence stems from the sheer scale of its activity, differentiating it from groups focusing on mass exploitation, credential stuffing, or regional targeting.
Manufacturing continues to be the most heavily targeted sector, with 1,660 disclosed victims, followed closely by professional, scientific, and technical services, which reported 1,389 victims. Notably, organizations with revenues between $50 million and $100 million are increasingly becoming targets, indicating that mid-sized businesses are facing escalating pressure alongside larger enterprises.
Qilin's growth also reflects broader shifts in attacker methodologies. The exploitation of authentication weaknesses in internet-facing systems, as seen with recent PAN-OS flaw deployments, highlights the critical need for rapid patching of exposed infrastructure. This trend underscores how easily attackers can gain initial access and deploy ransomware if perimeter defenses are not meticulously maintained.
Compounding the problem, post-incident investigations reveal that many organizations remain vulnerable even after their ransomware incidents have been resolved. Black Kite's scans found that 43.5% of victims still had critical patch vulnerabilities, and 30.8% harbored known exploited vulnerabilities that could be leveraged by attackers. This underscores the necessity of comprehensive recovery processes that extend beyond restoring encrypted files to include thorough security reviews.
To mitigate these risks, organizations should conduct structured external reviews post-incident, focusing on stolen credentials, critical vulnerabilities, and systems listed in the Known Exploited Vulnerabilities catalog. Prioritizing patches based on active exploitation and severity, inventorying connected applications, reviewing permissions, rotating credentials, and enforcing multi-factor authentication are crucial steps to reduce the attack surface exploited by ransomware operators.