One Group Now Owns Roughly One in Five Ransomware Claims
For most of ransomware’s history, the leaderboard churned. A group would surge, draw a law-enforcement takedown, splinter, and be replaced. What is happening in 2026 is different: a single operation has settled into durable dominance. In August 2026, the Qilin ransomware-as-a-service (RaaS) operation claimed 104 victims on its leak site, nearly doubling the 56 attacks reported by Akira, the only other group in the same tier. That result marked the fourth time in five months that Qilin topped the monthly rankings.
Zoom out and the concentration is stark. Since RansomHub collapsed in April 2026, Qilin has logged 398 claimed victims — 18.4% of all ransomware incidents recorded across that five-month window of 2,164 total attacks, with Akira a distant second at 10.7%. No other group crossed 10%. Over the longer arc, the 2026 ransomware report tallied 7,551 publicly disclosed victims, a 24.9% year-over-year rise across 146 active groups — and inside that total, Qilin’s own count exploded 443%, from 250 to 1,358 victims year over year. By its own leak-site accounting, the group had publicly claimed 2,271 victims, including 118 in the preceding 30 days, a figure that reflects public extortion claims rather than confirmed infections.
The scale is not an accident of a single prolific crew. It is the output of an industrialized affiliate machine — and, increasingly, a coordinated one.
Why “Cartelization” Is the Right Word
The word cartel is doing real work here, not just describing volume. In September 2025, the group DragonForce publicly proposed a coalition with LockBit and Qilin on Russian-language criminal forums. By October, security researchers had confirmed the three groups were coordinating to share techniques, resources, and infrastructure — a deliberate break from the historical pattern of rival gangs poaching affiliates and publicly insulting each other. The stated logic was market discipline: reduce internal conflict, pool tooling, and, in effect, set terms across the ecosystem.
That matters because these are not marginal players. Before its 2024 takedown, LockBit alone was estimated to have hit more than 2,500 victims and collected over $500 million in ransoms. Combine LockBit’s affiliate network, Qilin’s current output, and DragonForce’s reach, and the alliance concentrates a large share of global extortion under a shared playbook. Researchers found that Qilin, Akira, INC Ransom, Play and SafePay were together responsible for roughly 47% of all data-extortion attacks in the second and third quarters of 2025. When the top of that list starts cooperating rather than competing, the effect on defenders is a more uniform, better-resourced adversary.
Qilin’s own economics explain the affiliate gravity. The operation reportedly pays affiliates between 80% and 85% of each ransom, with operators keeping the remainder — an unusually generous split that pulls skilled intruders away from weaker programs. Cartelization simply removes the friction of competing for that talent.
Advertisement
The Front Door Is Still the VPN
The most operationally useful fact in the 2026 data is also the least glamorous: attackers are not, for the most part, deploying exotic zero-days. They are walking through the perimeter. According to Huntress telemetry cited by CSO Online, the VPN is the point of initial access roughly 70% of the time for advanced threat actors — and much of that traffic uses valid stolen credentials against accounts without multi-factor authentication, rather than exploitation at all.
Where exploitation does happen, it clusters on the same edge appliances every organization runs. The same reporting documented a “Fortibleed” campaign that exposed 75,000 FortiGate firewalls in June 2026, alongside active abuse of Palo Alto GlobalProtect (CVE-2026-0257), Citrix NetScaler, Check Point VPN, Cisco and Ivanti gateways. In NCC Group’s quarterly telemetry, Qilin was responsible for 14% of attacks, ahead of a field that included The Gentlemen (238 victims in the second quarter of 2026) and Akira (127). The through-line is unmistakable: the internet-facing VPN and firewall is the single most contested piece of real estate in enterprise security, and the groups winning are the ones that treat it as their primary entry vector.
What This Means for Security Teams
The cartel headline can feel abstract. The defensive implications are not — they collapse into a small number of high-leverage moves that follow directly from how Qilin and its peers actually break in.
1. Treat every internet-facing appliance as a patch-within-days asset, not a quarterly one
Because roughly 70% of advanced intrusions start at the VPN and edge exploits are weaponized within days of disclosure, the old quarterly patch cadence is a losing game for these devices specifically. Maintain a live inventory of every internet-facing VPN, firewall and gateway; subscribe to the vendor’s advisory feed; and commit to an emergency patch turnaround measured in days for edge appliances even when it means an off-hours maintenance window.
2. Make MFA on the VPN non-negotiable and kill standing local accounts
The data is blunt: much of the 70% figure is stolen credentials hitting non-MFA’d accounts, not exploitation. Enforce phishing-resistant MFA on every remote-access path, disable legacy protocols like IKEv1 where deprecated, and audit for local or service accounts that bypass the identity provider. A single exempted account is the whole control.
3. Assume double extortion and protect data, not just uptime
Today’s Qilin operations steal data before they encrypt it, so offline backups no longer neutralize the threat on their own. Classify and segment your most sensitive data, monitor for large outbound transfers, and rehearse the disclosure and legal path for a data-theft-only extortion — the scenario where the attacker never bothers to encrypt anything.
4. Instrument for the affiliate’s toolkit, not one group’s signature
Because cartelization means shared infrastructure and techniques, detection built around a single group’s indicators ages fast. Prioritize behavior-based detection — anomalous VPN logins, credential-dumping, lateral movement, and staging of exfiltration tools — over static IOCs tied to one brand.
The Structural Lesson
Ransomware in 2026 has finished a transition it began years ago: from a scene of freelancing intruders to an industry with dominant firms, standardized products, and now a cartel that coordinates rather than competes. Qilin’s 104-victim month is the visible tip of that consolidation, but the more durable story is the alliance forming underneath it and the boringly consistent entry vector feeding it. For defenders, the good news buried in the data is that the winning attacks are not clever — they are opportunistic, and they concentrate on assets you already own and can already control. The organizations that get breached in this environment are rarely out-innovated. They are out-maintained.
Frequently Asked Questions
How dominant is Qilin compared to other ransomware groups?
Substantially. Qilin claimed 104 victims on its leak site in August 2026, nearly double the 56 attacks reported by Akira, topping the monthly rankings for the fourth time in five months. Across that same five-month window, Qilin logged 398 claimed victims — 18.4% of 2,164 recorded incidents, with Akira second at 10.7% and no other group above 10%.
What does the LockBit-Qilin-DragonForce alliance change for defenders?
It makes the adversary more uniform and better resourced. DragonForce proposed the coalition on Russian-language criminal forums in September 2025, and by October researchers had confirmed the three groups were coordinating to share techniques, resources and infrastructure rather than poaching affiliates from each other. Because shared infrastructure and techniques travel between brands, detection built on one group’s static indicators ages quickly — behaviour-based detection holds up better.
What is the most common way these groups get in?
The internet-facing VPN. Huntress telemetry cited by CSO Online puts the VPN as the point of initial access roughly 70% of the time for advanced threat actors, and much of that traffic is valid stolen credentials against accounts without multi-factor authentication rather than exploitation at all. Where exploitation does occur it clusters on the same edge appliances everyone runs — the same reporting documented a campaign that exposed 75,000 FortiGate firewalls in June 2026.
Sources & Further Reading
- Qilin Ransomware Attack Impacts 104 Organizations in August — GBHackers
- 2026 Ransomware Report: 7,551 Victims, 146 Groups, Qilin’s 443% Surge — GBHackers
- LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem — The Hacker News
- Ransomware Groups Are Hammering Your Vulnerable VPNs — CSO Online
- Qilin Ransomware 2026: TTPs, Victims and Defense Guide — MOXFIVE
- Qilin Ransomware: Operating Model, Attack Chain, and Technical Profile — Proven Data














