Skip to content
You can now search across every topic, entity and event.What's new
Qilin
Organisation

Qilin

Ransomware-as-a-service crew; led May 2026 victim tally and exploiting Check Point VPN zero-day for initial access.

Qilin is a ransomware-as-a-service crew active since 2023 whose own former affiliate, The Gentlemen, split away in July 2025 and by early August 2026 was posting more leak-site claims than its parent.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

How is Qilin using a VPN zero-day to break into organisations before patches exist?

Timeline for Qilin

#12 2 Aug

Qilin's own affiliate now outposts it

Cybersecurity: Threats and Defences
#9 30 Jun

Held the most-active ransomware brand spot for a second consecutive month

Cybersecurity: Threats and Defences: Qilin leads ransomware a second month
#7 8 Jun

Gained post-compromise access to at least one organisation via the Check Point VPN zero-day

Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patch
#7 7 Jun
#6 31 May

Claimed 11 victims to lead all ransomware crews in May 2026

Cybersecurity: Threats and Defences: Ransomware tempo holds at 95 in May
View full timeline →

Background

Qilin is a ransomware-as-a-service (RaaS) operation that emerged in 2023 and has become one of the most consistently active crews in the ransomware ecosystem, leasing tooling to independent affiliates who Conduct attacks and share ransom proceeds. It gained particular notoriety in mid-2024 for the Synnovis attack on NHS pathology services in London, which forced widespread blood-test cancellations, establishing a willingness to strike healthcare infrastructure that has continued since.

In May 2026, BlackFog's tracking placed Qilin first among all ransomware crews with 11 claimed victims out of 95 disclosed attacks across 37 active groups . That report has since been corrected on the record: BlackFog's June tracker named a newly emerged group, '2019', as the following month's leader with 12 claimed victims, not Qilin for a second consecutive month as this publication previously reported.

Qilin's most consequential 2026 tradecraft shift was affiliate exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point's Remote Access VPN, active for roughly a month before the June hotfix . Structurally, Qilin is now also notable as the incubator of a rival: The Gentlemen began inside its own affiliate programme under the handle ArmCorp before splitting off in a dispute over unpaid commission, a lineage that leak-site trackers show narrowing Qilin's lead through the summer.

Common Questions

Reference

What happened in the Qilin attack on the NHS in 2024?
In June 2024 Qilin attacked Synnovis, a pathology service provider for NHS Trusts in London. Blood-test services at King's College Hospital, Guy's and St Thomas' and other sites were severely disrupted, forcing thousands of appointment and operation cancellations and an emergency appeal for O-negative blood donations.Source: event
Is Qilin ransomware linked to a specific country or government?
No confirmed state attribution has been made. Qilin operates as a commercially structured RaaS programme with independent affiliates. Its operators are not publicly identified and no government has formally attributed the group to a nation-state sponsor.
Is Qilin the same as Agenda ransomware?
Yes. Qilin ransomware is also tracked under the name Agenda by some security vendors. It was initially written in the Go programming language before being rewritten in Rust, and both names refer to the same operator group and RaaS platform.Source: Trend Micro / cybersecurity research
Why does Qilin target hospitals and healthcare providers?
Healthcare cannot tolerate extended system downtime: patient care, diagnostics and drug dispensing depend on real-time IT access. Ransomware groups including Qilin target hospitals because operational pressure to restore services quickly makes healthcare organisations more likely to pay ransoms faster and at higher amounts than most other sectors.Source: BlackFog State of Ransomware May 2026
What is the Qilin ransomware group?
Qilin is a ransomware-as-a-service operation in which a core developer team leases ransomware tooling to independent affiliates, who Conduct attacks and split ransom proceeds with the developers. It has been active since 2023 and targets healthcare, manufacturing and professional services globally, using double-extortion tactics that combine file encryption with threatened data publication.Source: BlackFog / cybersecurity reporting
How did Qilin get into systems via the Check Point VPN vulnerability?
A Qilin affiliate exploited CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point Remote Access VPN using a deprecated IKEv1 code PATH. The flaw allowed attackers to bypass credential checks entirely. Exploitation ran for approximately one month before a hotfix was available, during which post-compromise activity was confirmed at a number of organisations.Source: Check Point / CISA KEV
How many ransomware attacks did Qilin carry out in 2026?
Qilin claimed 11 victims in May 2026 alone, leading all tracked ransomware crews that month. Across 2026 it has been consistently among the top five most active groups by public leak-site postings.Source: BlackFog
What is Qilin ransomware and who does it target?
Qilin is a ransomware-as-a-service operation active since 2023 that leases attack tooling to independent affiliates. It targets healthcare, manufacturing, professional services and education globally, gaining notoriety from the 2024 NHS Synnovis attack and leading May 2026's disclosed ransomware tally with 11 claimed victims.Source: BlackFog monthly report
How many victims did Qilin claim in May 2026?
Qilin claimed 11 victims in May 2026, leading all active ransomware groups that month. BlackFog's monthly tracking recorded 95 publicly disclosed ransomware attacks worldwide in May, with 37 active groups and healthcare taking the heaviest sector hit at 28 incidents.Source: BlackFog State of Ransomware May 2026
Source Material