ZeroFox Intelligence Flash Report - Qilin Claims Record Number of Monthly Attacks for 2026
|by Alpha Team

ZeroFox Intelligence Flash Report - Qilin Claims Record Number of Monthly Attacks for 2026
Product Serial: F-2026-09-09b
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a record breaking month of activity for the most active ransomware collective Qilin.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- ZeroFox observed that Qilin was the most prominent ransomware and digital extortion (R&DE) collective in August 2026, accounting for at least 165 incidents—a record number of incidents for one collective so far this year.
- Qilin has remained the most active R&DE collective globally, signaling both its dominance thus far into 2026 and an unbroken 17-month period as the leading ransomware threat actor since Q2 2025.
- Qilin accounted for a nearly 29 percent share of the top 10 most active collectives, which together were responsible for at least 6,453 incidents since April 2025 (Q2 2025). The next most active collective, Akira, had a share of approximately 14 percent, underpinning Qilin's continuous prominence.
- The collective is very likely to continue or exceed its current operational tempo—outpacing other collectives by a substantial margin—and will likely remain consistent with its established tactics, techniques, and procedures (TTPs) and continue to target geographically dispersed, multi-sector entities with double-extortion operations.
Tags: tlp:clear, threat actor