⚡ Key Takeaways

Qilin claimed 104 victims in August 2026, nearly double Akira’s 56, topping the monthly rankings for the fourth time in five months and logging 18.4% of all ransomware incidents since RansomHub collapsed. Behind the numbers is a declared LockBit-Qilin-DragonForce cartel coordinating techniques and infrastructure, funded by an 80-85% affiliate payout. The VPN remains the initial-access point roughly 70% of the time — often stolen credentials against non-MFA accounts.

Bottom Line: The winning attacks are opportunistic, not clever, and hit assets you already control. Treat every internet-facing appliance as a patch-within-days asset, make phishing-resistant MFA on the VPN non-negotiable, assume double extortion, and prioritize behavior-based detection over one group’s static indicators. Organizations breached here are out-maintained, not out-innovated.

Read Full Analysis ↓

🧭 Decision Radar

Relevance for Algeria
High

Algerian banks, telecom operators, hospitals and public agencies all run the same internet-facing VPN and firewall appliances that account for roughly 70% of advanced intrusions, and ransomware affiliates target by exposure rather than by geography.
Infrastructure Ready?
Partial

The edge appliances in question are already deployed locally, so the gap is maintenance cadence and remote-access identity controls rather than missing technology.
Skills Available?
Partial

Algerian security teams can enforce multi-factor authentication and patch edge devices, but behaviour-based detection and rehearsed data-theft extortion response remain thin outside the largest institutions.
Action Timeline
0-6 months

Edge exploits are weaponised within days of disclosure, so an inventory of internet-facing appliances and enforced MFA on remote access are immediate work, not annual planning.
Key Stakeholders
ARPT, Ministry of Post and Telecommunications, Bank of Algeria and Algerian banks, Algérie Télécom, hospital and public-sector IT departments, managed service providers
Decision Type
Operational

Every high-leverage move here is a configuration, patching and identity discipline change on assets the organisation already owns.

Quick Take: The Algerian takeaway is that these attacks are not clever, they are opportunistic — the winning entry vector is a VPN with a stolen password and no multi-factor authentication. An Algerian organisation that keeps a live inventory of its internet-facing appliances, patches them in days rather than quarters, enforces phishing-resistant MFA on every remote-access path with no exempted accounts, and plans for data theft without encryption has closed most of the path this cartel actually uses.

Advertisement

One Group Now Owns Roughly One in Five Ransomware Claims

For most of ransomware’s history, the leaderboard churned. A group would surge, draw a law-enforcement takedown, splinter, and be replaced. What is happening in 2026 is different: a single operation has settled into durable dominance. In August 2026, the Qilin ransomware-as-a-service (RaaS) operation claimed 104 victims on its leak site, nearly doubling the 56 attacks reported by Akira, the only other group in the same tier. That result marked the fourth time in five months that Qilin topped the monthly rankings.

Zoom out and the concentration is stark. Since RansomHub collapsed in April 2026, Qilin has logged 398 claimed victims — 18.4% of all ransomware incidents recorded across that five-month window of 2,164 total attacks, with Akira a distant second at 10.7%. No other group crossed 10%. Over the longer arc, the 2026 ransomware report tallied 7,551 publicly disclosed victims, a 24.9% year-over-year rise across 146 active groups — and inside that total, Qilin’s own count exploded 443%, from 250 to 1,358 victims year over year. By its own leak-site accounting, the group had publicly claimed 2,271 victims, including 118 in the preceding 30 days, a figure that reflects public extortion claims rather than confirmed infections.

The scale is not an accident of a single prolific crew. It is the output of an industrialized affiliate machine — and, increasingly, a coordinated one.

Why “Cartelization” Is the Right Word

The word cartel is doing real work here, not just describing volume. In September 2025, the group DragonForce publicly proposed a coalition with LockBit and Qilin on Russian-language criminal forums. By October, security researchers had confirmed the three groups were coordinating to share techniques, resources, and infrastructure — a deliberate break from the historical pattern of rival gangs poaching affiliates and publicly insulting each other. The stated logic was market discipline: reduce internal conflict, pool tooling, and, in effect, set terms across the ecosystem.

That matters because these are not marginal players. Before its 2024 takedown, LockBit alone was estimated to have hit more than 2,500 victims and collected over $500 million in ransoms. Combine LockBit’s affiliate network, Qilin’s current output, and DragonForce’s reach, and the alliance concentrates a large share of global extortion under a shared playbook. Researchers found that Qilin, Akira, INC Ransom, Play and SafePay were together responsible for roughly 47% of all data-extortion attacks in the second and third quarters of 2025. When the top of that list starts cooperating rather than competing, the effect on defenders is a more uniform, better-resourced adversary.

Qilin’s own economics explain the affiliate gravity. The operation reportedly pays affiliates between 80% and 85% of each ransom, with operators keeping the remainder — an unusually generous split that pulls skilled intruders away from weaker programs. Cartelization simply removes the friction of competing for that talent.

Advertisement

The Front Door Is Still the VPN

The most operationally useful fact in the 2026 data is also the least glamorous: attackers are not, for the most part, deploying exotic zero-days. They are walking through the perimeter. According to Huntress telemetry cited by CSO Online, the VPN is the point of initial access roughly 70% of the time for advanced threat actors — and much of that traffic uses valid stolen credentials against accounts without multi-factor authentication, rather than exploitation at all.

Where exploitation does happen, it clusters on the same edge appliances every organization runs. The same reporting documented a “Fortibleed” campaign that exposed 75,000 FortiGate firewalls in June 2026, alongside active abuse of Palo Alto GlobalProtect (CVE-2026-0257), Citrix NetScaler, Check Point VPN, Cisco and Ivanti gateways. In NCC Group’s quarterly telemetry, Qilin was responsible for 14% of attacks, ahead of a field that included The Gentlemen (238 victims in the second quarter of 2026) and Akira (127). The through-line is unmistakable: the internet-facing VPN and firewall is the single most contested piece of real estate in enterprise security, and the groups winning are the ones that treat it as their primary entry vector.

What This Means for Security Teams

The cartel headline can feel abstract. The defensive implications are not — they collapse into a small number of high-leverage moves that follow directly from how Qilin and its peers actually break in.

1. Treat every internet-facing appliance as a patch-within-days asset, not a quarterly one

Because roughly 70% of advanced intrusions start at the VPN and edge exploits are weaponized within days of disclosure, the old quarterly patch cadence is a losing game for these devices specifically. Maintain a live inventory of every internet-facing VPN, firewall and gateway; subscribe to the vendor’s advisory feed; and commit to an emergency patch turnaround measured in days for edge appliances even when it means an off-hours maintenance window.

2. Make MFA on the VPN non-negotiable and kill standing local accounts

The data is blunt: much of the 70% figure is stolen credentials hitting non-MFA’d accounts, not exploitation. Enforce phishing-resistant MFA on every remote-access path, disable legacy protocols like IKEv1 where deprecated, and audit for local or service accounts that bypass the identity provider. A single exempted account is the whole control.

3. Assume double extortion and protect data, not just uptime

Today’s Qilin operations steal data before they encrypt it, so offline backups no longer neutralize the threat on their own. Classify and segment your most sensitive data, monitor for large outbound transfers, and rehearse the disclosure and legal path for a data-theft-only extortion — the scenario where the attacker never bothers to encrypt anything.

4. Instrument for the affiliate’s toolkit, not one group’s signature

Because cartelization means shared infrastructure and techniques, detection built around a single group’s indicators ages fast. Prioritize behavior-based detection — anomalous VPN logins, credential-dumping, lateral movement, and staging of exfiltration tools — over static IOCs tied to one brand.

The Structural Lesson

Ransomware in 2026 has finished a transition it began years ago: from a scene of freelancing intruders to an industry with dominant firms, standardized products, and now a cartel that coordinates rather than competes. Qilin’s 104-victim month is the visible tip of that consolidation, but the more durable story is the alliance forming underneath it and the boringly consistent entry vector feeding it. For defenders, the good news buried in the data is that the winning attacks are not clever — they are opportunistic, and they concentrate on assets you already own and can already control. The organizations that get breached in this environment are rarely out-innovated. They are out-maintained.

Follow AlgeriaTech on LinkedIn for professional tech analysis Follow on LinkedIn
Follow @AlgeriaTechNews on X for daily tech insights Follow on X

Advertisement

Frequently Asked Questions

How dominant is Qilin compared to other ransomware groups?

Substantially. Qilin claimed 104 victims on its leak site in August 2026, nearly double the 56 attacks reported by Akira, topping the monthly rankings for the fourth time in five months. Across that same five-month window, Qilin logged 398 claimed victims — 18.4% of 2,164 recorded incidents, with Akira second at 10.7% and no other group above 10%.

What does the LockBit-Qilin-DragonForce alliance change for defenders?

It makes the adversary more uniform and better resourced. DragonForce proposed the coalition on Russian-language criminal forums in September 2025, and by October researchers had confirmed the three groups were coordinating to share techniques, resources and infrastructure rather than poaching affiliates from each other. Because shared infrastructure and techniques travel between brands, detection built on one group’s static indicators ages quickly — behaviour-based detection holds up better.

What is the most common way these groups get in?

The internet-facing VPN. Huntress telemetry cited by CSO Online puts the VPN as the point of initial access roughly 70% of the time for advanced threat actors, and much of that traffic is valid stolen credentials against accounts without multi-factor authentication rather than exploitation at all. Where exploitation does occur it clusters on the same edge appliances everyone runs — the same reporting documented a campaign that exposed 75,000 FortiGate firewalls in June 2026.

Sources & Further Reading