logo

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat

ID: e90cfaa2-343c-5742-bd8c-d41672255d5e

STIX ID: report--e90cfaa2-343c-5742-bd8c-d41672255d5e

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

ReliaQuest's analysis of ransomware events from March–May 2026 found 1,368 victim claims across 99 countries and identified The Gentlemen as the most active ransomware operation (300 incidents), overtaking Qilin; the report attributes the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit and AI-accelerated tooling, and offers defensive recommendations such as restricting RDP, enforcing Microsoft's vulnerable-driver block list, monitoring blockchain RPC egress, and hardening identity against vishing and AiTM attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.