Ransomware Groups Claim Record 7,551 Victims as Qilin Activity Jumps 443%

Ransomware groups publicly named 7,551 victims from April 2025 through March 2026, a 24.9% rise from the previous reporting period.

The surge was led by Qilin, which claimed 1,358 victims up 443% year over year while the broader ecosystem expanded to 146 active groups by June 2026.

The figures reflect publicly disclosed or leak-site claims and may not represent every ransomware incident.

Black Kite’s reporting shows the increase accelerated late in the period. The first six months recorded 2,904 victims, while the second half reached 4,647 a 60% rise in operating pace. March 2026 alone produced 861 claimed victims, the highest monthly volume in the dataset.

Manufacturing remained the most affected sector for a fourth consecutive year, with 1,660 victims or 22% of all disclosures. Professional, scientific, and technical services followed with 1,389 victims.

Construction rose to third place with 541 victims, underlining how ransomware operators continue to pursue organizations whose downtime can quickly disrupt revenue, supply chains, and operations.

The United States accounted for 49.3% of identified victims. However, its share declined from 51.9% even as the absolute number of US victims grew.

European activity grew faster, Germany reportedly rose 48% to 281 victims, while Italy nearly doubled to 188. This shift means security teams should avoid relying on US-centric exposure assumptions when assessing third-party and supplier risk.

The middle market became a major growth target. Organizations with annual revenue of $50 million to $100 million represented 29.3% of victims with known revenue, rising from 25.1% in the previous period.

The $1 million to $5 million segment also sharply increased its share, showing that attackers are expanding beyond traditional large-enterprise targeting.

Qilin Fuels Record Ransomware Victims

Qilin’s 1,358 claimed victims accounted for roughly one in five or six victims in the dataset.

The group, also known as Agenda, operates a ransomware-as-a-service model in which affiliates conduct intrusions and deploy ransomware, commonly combining encryption with data theft and leak threats.

The group’s growth occurred amid a crowded and fragmented market. Black Kite tracked 127 active groups at the reporting-period close and 146 by June 2026, including 61 new entrants during the 12-month window.

Despite this influx, the top five operations controlled 43.6% of disclosed victims, indicating that ransomware is becoming both more competitive and still highly concentrated.

Different groups increasingly follow distinct operating models. Qilin scaled through broad, high-volume activity; Clop focused on mass exploitation of enterprise software flaws; and other groups emphasized credential exposure, patch debt, or opportunistic regional targeting.

Public reporting also describes Qilin affiliates using phishing, exposed remote services, compromised VPN accounts, infostealer-derived credentials, RMM tools, and double-extortion tactics, blackkite said.

Trusted business platforms also emerged as high-impact access paths.

The report points to SaaS OAuth abuse, vendor application connections, and mass exploitation of enterprise software as routes that can expose many downstream organizations from a single compromise.

This makes third-party risk management more than a vendor questionnaire exercise: organizations must continuously assess connected applications, privileged integrations, identity permissions, and downstream providers.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories