logo

How the World’s Most Active Ransomware Operation Expanded in H1 2026

ID: 59fd6cb2-b443-5358-888f-7b1bfb7af574

STIX ID: report--59fd6cb2-b443-5358-888f-7b1bfb7af574

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Ashish Khaitan

...
...

Cyble Research and Intelligence Labs (CRIL) identified Qilin as the most active ransomware group in H1 2026, attributing hundreds of attacks across North America (370), Europe/UK (158), Asia-Pacific (64), and South America (40). The report describes Qilin's RaaS-driven model—using affiliates, initial access brokers, and purchased access—to target high-impact sectors (manufacturing, healthcare, construction, professional services) and urges organizations to reduce exposed attack surfaces, strengthen identity controls, monitor suspicious access, and prepare for both data theft and encryption-based extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.