zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Qilin Claims Record Number of Monthly Attacks for 2026

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Qilin Claims Record Number of Monthly Attacks for 2026

Product Serial: F-2026-09-09b

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on a record breaking month of activity for the most active ransomware collective Qilin.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • ZeroFox observed that Qilin was the most prominent ransomware and digital extortion (R&DE) collective in August 2026, accounting for at least 165 incidents—a record number of incidents for one collective so far this year.
  • Qilin has remained the most active R&DE collective globally, signaling both its dominance thus far into 2026 and an unbroken 17-month period as the leading ransomware threat actor since Q2 2025.
  • Qilin accounted for a nearly 29 percent share of the top 10 most active collectives, which together were responsible for at least 6,453 incidents since April 2025 (Q2 2025). The next most active collective, Akira, had a share of approximately 14 percent, underpinning Qilin's continuous prominence.
  • The collective is very likely to continue or exceed its current operational tempo—outpacing other collectives by a substantial margin—and will likely remain consistent with its established tactics, techniques, and procedures (TTPs) and continue to target geographically dispersed, multi-sector entities with double-extortion operations.

Tags: tlp:clear threat actor