Qilin Claims 1,358 Ransomware Victims as Global Disclosures Hit Record High


Qilin claimed 1,358 ransomware victims between April 1, 2025, and March 31, 2026, making it the most active operation in Black Kite’s latest dataset. Its activity increased 443% from 250 claims during the previous reporting period.

Global ransomware disclosures also reached a fourth consecutive annual record. The Black Kite 2026 Ransomware Report identified 7,551 publicly disclosed victims, up 24.9% from 6,046 one year earlier.

These figures include organizations named on ransomware leak sites and cases validated through open-source intelligence and Black Kite’s internal telemetry. They do not cover every ransomware attack, and a criminal group’s claim does not independently confirm that every listed organization suffered a successful intrusion.

Qilin Activity Increased 443% in One Year

Qilin accounted for approximately 18% of the 7,551 disclosed victims. That equals roughly one in every five to six cases in the dataset. The operation claimed organizations across more than 50 countries and recorded nearly twice as many victims as its closest competitor.

Qilin operates through a ransomware-as-a-service model. The operators maintain malware and extortion infrastructure, while affiliates conduct intrusions against selected organizations. Such arrangements allow a ransomware brand to expand quickly by supporting several independent attack teams.

Like many modern ransomware operations, Qilin combines encryption with data theft. Attackers can threaten to publish stolen information if a victim refuses to pay, creating legal, financial, operational, and reputational pressure.

Ransomware findingCurrent periodPrevious periodChange
Publicly disclosed victims7,5516,046Up 24.9%
Average monthly victimsApproximately 629Approximately 504Up approximately 25%
Qilin claims1,358250Up 443%
Active groups at period close127Not specifiedReached 146 by June 2026
New groups entering the market61Not specifiedMore than one per week

Ransomware Attacks Accelerated During the Second Half

The reporting period covered April 2025 through March 2026. Black Kite recorded 2,904 victims during the first six months and 4,647 during the second half.

That represented a 60% increase in the pace of disclosed attacks between the two halves. Monthly disclosures remained above 700 from October 2025 through March 2026.

March produced 861 disclosed victims, the highest monthly total in Black Kite’s four years of tracking. The sustained increase suggests that ransomware activity reached a higher operating level rather than experiencing a single temporary spike.

Reporting periodDisclosed victimsKey finding
April to September 20252,904Activity remained near the previous year’s baseline.
October 2025 to March 20264,647The pace increased 60% compared with the first half.
March 2026861Highest monthly total recorded by Black Kite.

More Ransomware Groups Entered the Market

Black Kite counted 127 active ransomware groups when the primary reporting period ended. Continued monitoring raised that total to 146 by June 2026, more than twice the 61 groups recorded in 2023.

Sixty-one new ransomware brands appeared during the reporting period, equivalent to more than one new group each week. However, many new operations remained active for only a short time.

Groups first observed between April and September 2025 operated for a median of 4.9 months. The equivalent group of new entrants from the previous year lasted a median of 12.8 months.

Despite the number of new brands, the five largest operations controlled 43.6% of disclosed victims. The figures show a divided market with many smaller entrants and a concentrated group of high-volume operators.

Qilin Led a Market With Different Attack Models

Black Kite found no single pattern behind the year’s ransomware growth. Qilin pursued global scale and high victim volume, while other prominent groups focused on unpatched software, stolen credentials, specific regions, or mass exploitation.

Ransomware groupObserved approach
QilinHigh-volume campaigns across more than 50 countries
EverestTargeting linked to accumulated patching failures
ClopMass exploitation of widely used enterprise software
World LeaksCredential exposure with a strong focus on the United Kingdom
PlayFast, opportunistic activity across the United States and Canada

Ransomware brands can also disappear without reducing overall attack volume. RansomHub, for example, went from 736 victims and a leading market position to no recorded victims within 12 months.

Affiliates and other criminals can move between ransomware services after a group shuts down. This movement allows the broader criminal ecosystem to continue operating despite disruptions affecting individual brands.

Manufacturing Remained the Most Targeted Industry

Manufacturing recorded 1,660 disclosed victims, representing 22% of the annual total. It remained the most targeted industry for the fourth consecutive year.

Professional, scientific, and technical services ranked second with 1,389 victims. Together, the two leading sectors accounted for approximately 40% of all ransomware disclosures.

Construction placed third with 541 victims. Its share increased steadily throughout the reporting period rather than rising because of one unusually large campaign.

IndustryDisclosed victimsShare or position
Manufacturing1,66022% of all disclosures
Professional, scientific, and technical services1,389Second most affected industry
Construction541Third most affected industry

Europe Recorded Faster Ransomware Growth

The United States remained the largest individual target, accounting for 49.3% of disclosed victims. Its share declined from 51.9%, although the number of US victims still increased by 19%.

Ransomware activity grew faster across several European countries. Germany recorded 281 victims, an increase of 48%, while Italy’s total increased 96% to 188.

Spain and France each recorded growth of approximately 50%. New ransomware groups also spread their activity more widely across Europe, Asia, South America, the Middle East, and Africa than established operations.

Mid-Sized Organizations Faced Growing Pressure

Organizations with annual revenue between $50 million and $100 million represented 29.3% of victims for which reliable revenue data was available. Their share increased from 25.1% during the previous period.

Meanwhile, organizations with more than $100 million in annual revenue fell from 13.9% to 9.5% of victims with known revenue. Companies in the $1 million to $5 million range nearly doubled their share.

The findings indicate that ransomware operators increasingly pursue smaller and mid-sized organizations alongside large enterprises. These businesses may hold valuable information and operate critical services while maintaining fewer security resources.

Critical Vulnerabilities Remained After Attacks

Black Kite rescanned affected organizations after their ransomware incidents and found that many continued to expose serious security weaknesses. In its latest assessment, 43.5% still had at least one vulnerability rated 9.0 or higher under the Common Vulnerability Scoring System.

Another 30.8% still had a vulnerability listed in the CISA Known Exploited Vulnerabilities Catalog. The catalog covers security flaws for which CISA has evidence of active exploitation.

Exposure linked to information-stealer logs increased 175% when researchers compared affected organizations before and after disclosure. This may indicate that stolen credentials and session information remained available to criminals even after initial recovery work ended.

The ransomware research recommends structured exposure reviews at 30, 60, and 90 days after an incident. These checks should cover stolen credentials, critical vulnerabilities, known exploited flaws, connected applications, and external attack surfaces.

Trusted Vendor Connections Create Additional Risk

Several major incidents during the reporting period involved trusted vendor platforms, OAuth tokens, SaaS integrations, enterprise applications, and support processes. Attackers can use one compromised connection to reach information belonging to several customers.

Traditional vendor questionnaires may not reveal stolen application tokens or changes in external exposure. Organizations need an inventory of connected applications and should understand what information each integration can access.

Security teams should review OAuth permissions, remove unused integrations, rotate suspicious tokens, and establish rapid procedures for disabling compromised vendor connections.

How Organizations Can Reduce Ransomware Exposure

Organizations should prioritize vulnerabilities that attackers already exploit rather than relying only on severity scores. Security teams can use the Known Exploited Vulnerabilities Catalog to identify flaws that require urgent attention.

  • Patch internet-facing systems and known exploited vulnerabilities quickly.
  • Require phishing-resistant multifactor authentication for important accounts.
  • Disable unused remote access services and restrict exposed management interfaces.
  • Monitor for stolen credentials and information-stealer log exposure.
  • Maintain offline, encrypted, and regularly tested backups.
  • Segment networks to limit lateral movement after an intrusion.
  • Review vendor access, OAuth tokens, and connected SaaS applications.
  • Train help desk staff to detect impersonation and account-reset fraud.
  • Test incident response plans through regular exercises.
  • Continue external exposure reviews for at least 90 days after an attack.

CISA’s StopRansomware resources provide guidance for preventing, detecting, responding to, and recovering from ransomware incidents. The guidance also recommends maintaining an incident response plan and testing backup restoration procedures.

Organizations should report ransomware incidents promptly and preserve relevant logs, suspicious files, ransom notes, and network evidence. Early reporting may help investigators connect an attack with other activity attributed to the same operators.

The CISA ransomware guidance advises victims to isolate affected systems, secure backups, coordinate response activities, and avoid deleting evidence needed for investigation.

FAQ

How many ransomware victims did Qilin claim?

Qilin claimed 1,358 victims between April 1, 2025, and March 31, 2026, according to Black Kite. This represented a 443% increase from 250 claims in the previous reporting period.

Were all 1,358 Qilin ransomware attacks independently confirmed?

No. The total represents publicly disclosed victims and Qilin leak-site claims tracked and validated through available intelligence. A ransomware group’s claim does not independently prove every detail of an attack.

How many ransomware victims were disclosed globally?

Black Kite identified 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. This was a 24.9% increase from 6,046 during the previous reporting period.

Which industry faced the most ransomware attacks?

Manufacturing remained the most affected industry, with 1,660 disclosed victims. It represented 22% of the total and ranked first for the fourth consecutive year.

How can organizations reduce Qilin ransomware risk?

Organizations should patch known exploited vulnerabilities, require strong multifactor authentication, secure remote access, monitor stolen credentials, segment networks, review vendor connections, and maintain tested offline backups.

Why can ransomware risk continue after recovery?

Stolen credentials, exposed sessions, unpatched systems, and compromised vendor connections may remain available after encrypted files have been restored. Organizations need continued exposure reviews after closing the initial incident.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages