Qilin Ransomware Peaks in August, Then Halves in September
A record month, then a sharp drop
Qilin, the ransomware operation that has topped activity charts for well over a year, had its biggest month of 2026 in August. Its claimed victim count then fell by half in September. Taken together, the two months say less about Qilin weakening than about how volatile leak-site numbers can be, even for the most established crews.
ZeroFox counted at least 165 Qilin incidents in August 2026. That is the highest monthly total for any single ransomware and digital extortion collective so far this year. 1 NCC Group's August review reached a similar conclusion through different counting. It found Qilin overtook The Gentlemen as the most active group and accounted for 15% of the month's attacks. 3
The two figures fit together. Fifteen percent of NCC's 1,073 August attacks is roughly 160, close to ZeroFox's floor of 165. Neither firm's method is fully visible from the outside, but independent trackers landing near the same number gives the August peak some credibility.
One caution on framing: the data supports saying that Qilin made up about 15% of August's attack volume. It does not support saying Qilin caused 15% of the month-over-month increase. Those are different claims.
The broader August picture
Qilin's record came as overall ransomware activity also rose. NCC Group logged 1,073 attacks worldwide in August, up 12% from 960 in July. That made August the highest monthly total of 2026 in NCC's data. 34 Other details from the report:
- Sector: Industrial organizations were hit hardest, with 329 attacks, about 31% of the total. 34
- Region: North America took 473 attacks (44%), and Europe followed with 276 (26%). 3
NCC has described 2026 as a year of elevated but range-bound activity, so August is a high point rather than a break from the trend. 4
The methods behind those numbers are mostly familiar. NCC reports that operators kept using proven intrusion routes while leaning more heavily on data extortion. 3 Its incident responders also looked at an emerging group called Aurora. Aurora used VPN exploitation and credential harvesting against manufacturing, legal, R&D and transportation targets. 3 NCC also flagged newer tactics aimed at cloud identity. 4
Qilin's long reign
August's record extends a long run at the top. ZeroFox says Qilin has been the leading ransomware actor for 17 straight months, dating back to Q2 2025. 1 Over that period, the ten most active collectives were responsible for at least 6,453 incidents. Qilin's share of those incidents breaks down as follows: 1
| Group | Share of top-10 incidents since Q2 2025 |
|---|---|
| Qilin | Nearly 29% |
| Akira (next closest) | About 14% |
Qilin's lead over the next group is roughly two to one.
September: The Gentlemen move back ahead
September changed the picture quickly. Bitdefender's monthly analysis puts The Gentlemen at the top of the rankings. Qilin and Akira both stayed in the top ten, but Qilin's claimed victims dropped 50% from August. 2
Bitdefender also says The Gentlemen run a service called GentleCloud. The group uses it to protect its own infrastructure and make its leak site harder to crawl. 2 That matters for anyone reading these rankings. Researchers count victims largely by scraping leak sites, so a group that makes its site harder to crawl may also become harder to measure.
How to read the swing
This looks like normal fluctuation in leak-site data, not a sign that Qilin is collapsing. Several factors point that way:
- How the data is built: Monthly claim counts depend on when groups choose to post victims. A backlog published in one month can inflate that month's total and make the next month look weak by comparison.
- Halving from a record: A 50% drop from a record high still leaves Qilin in the top ten. 2
- The long-run record: Seventeen consecutive months as the leading group is not undone by one quieter month. 1
The Gentlemen's rise is real, and the group traded the top spot with Qilin across August and September. 23 Still, the September result does not yet show a lasting change in which groups dominate ransomware.
What defenders should take from it
For defenders, the practical lessons hold regardless of which group ranks first:
- Industrial firms remain the main target, taking close to a third of attacks. 34
- North American organizations absorb the most attacks, at 44% of the August total. 3
- Basic controls still matter most. The intrusion methods driving these numbers, including VPN exploitation, stolen credentials and data theft for extortion, are well understood. 3 Patching remote-access gear, hardening identity systems and planning for data-leak extortion cover most of the risk.
Whoever leads the October rankings, the overall volume of attacks is unlikely to drop.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01Flash Report: Qilin Claims Record Number of Monthly Attacks for 2026 — zerofox.com
- 02Citrix NetScaler CVE-2026-88779 Exploited: Patch SAML-Enabled ADC and Gateway Appliances — windowsforum.com
- 03Ransomware activity hits 2026 high as industrial sector bears 31% of attacks and Qilin dominates - Industrial Cyber — industrialcyber.co
- 04Ransomware Attacks August 2026: Up 12% to 1,073 — shattered.io