
Qilin
Ransomware-as-a-service crew; led May 2026 victim tally and exploiting Check Point VPN zero-day for initial access.
Qilin is a ransomware-as-a-service crew active since 2023 whose own former affiliate, The Gentlemen, split away in July 2025 and by early August 2026 was posting more leak-site claims than its parent.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How is Qilin using a VPN zero-day to break into organisations before patches exist?
Timeline for Qilin
Qilin's own affiliate now outposts it
Cybersecurity: Threats and DefencesHeld the most-active ransomware brand spot for a second consecutive month
Cybersecurity: Threats and Defences: Qilin leads ransomware a second monthGained post-compromise access to at least one organisation via the Check Point VPN zero-day
Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patchMentioned in: Crews now cross-claim each rival victim
Cybersecurity: Threats and DefencesClaimed 11 victims to lead all ransomware crews in May 2026
Cybersecurity: Threats and Defences: Ransomware tempo holds at 95 in MayBackground
Qilin is a ransomware-as-a-service (RaaS) operation that emerged in 2023 and has become one of the most consistently active crews in the ransomware ecosystem, leasing tooling to independent affiliates who Conduct attacks and share ransom proceeds. It gained particular notoriety in mid-2024 for the Synnovis attack on NHS pathology services in London, which forced widespread blood-test cancellations, establishing a willingness to strike healthcare infrastructure that has continued since.
In May 2026, BlackFog's tracking placed Qilin first among all ransomware crews with 11 claimed victims out of 95 disclosed attacks across 37 active groups . That report has since been corrected on the record: BlackFog's June tracker named a newly emerged group, '2019', as the following month's leader with 12 claimed victims, not Qilin for a second consecutive month as this publication previously reported.
Qilin's most consequential 2026 tradecraft shift was affiliate exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point's Remote Access VPN, active for roughly a month before the June hotfix . Structurally, Qilin is now also notable as the incubator of a rival: The Gentlemen began inside its own affiliate programme under the handle ArmCorp before splitting off in a dispute over unpaid commission, a lineage that leak-site trackers show narrowing Qilin's lead through the summer.