Skip to content
You can now search across every topic, entity and event.What's new
Qilin
Organisation

Qilin

Ransomware-as-a-service crew; led May 2026 victim tally and exploiting Check Point VPN zero-day for initial access.

Last refreshed: 14 June 2026 · Appears in 1 active topic

Key Question

How is Qilin using a VPN zero-day to break into organisations before patches exist?

Timeline for Qilin

#9 30 Jun

Held the most-active ransomware brand spot for a second consecutive month

Cybersecurity: Threats and Defences: Qilin leads ransomware a second month
#7 8 Jun

Gained post-compromise access to at least one organisation via the Check Point VPN zero-day

Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patch
#7 7 Jun
#6 31 May

Claimed 11 victims to lead all ransomware crews in May 2026

Cybersecurity: Threats and Defences: Ransomware tempo holds at 95 in May
View full timeline →

Background

Qilin is a ransomware-as-a-service (RaaS) operation that emerged in 2023 and has become one of the most consistently active crews in the global ransomware ecosystem. Operating on a commercial model in which core developers lease tooling to independent affiliates who Conduct attacks and share ransom proceeds, Qilin targets organisations across healthcare, manufacturing, professional services and education. In May 2026 it led all ransomware crews with 11 claimed victims out of 95 disclosed attacks across 37 active groups, according to BlackFog's monthly tracking, with no sign of consolidation narrowing the ecosystem.

Qilin gained particular notoriety in mid-2024 when it attacked Synnovis, a pathology service provider for NHS Trusts in London, causing widespread blood-test disruption at King's College Hospital, Guy's and St Thomas' and other major NHS sites. The attack forced thousands of appointment and operation cancellations and emergency appeals for O-negative blood, establishing Qilin as a crew willing to strike healthcare critical infrastructure where care-delivery downtime accelerates ransom payment decisions. That targeting posture has continued into 2026. In June 2026, a confirmed Qilin affiliate was identified in post-compromise activity following exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point's Remote Access VPN that had been actively abused for approximately one month before the hotfix shipped. CISA listed the flaw with an unprecedented three-day federal remediation window.

The Check Point VPN exploitation places Qilin squarely in the 2026 edge-device initial-access arc: rather than phishing or credential stuffing, the affiliate used a zero-day authentication bypass in the perimeter gateway itself, a technique that bypasses endpoint detection, MFA, and most zero-trust controls deployed behind the gateway. Bitdefender's June 2026 threat debrief noted that affiliates across RaaS programmes are increasingly cross-claiming victims, driven by a commoditised initial-access broker market and free movement between programmes. Qilin's consistent volume, willingness to attack healthcare, and adoption of VPN zero-days as an entry vector make it a persistent structural threat rather than a cyclical peak operator.

Common Questions
What is the Qilin ransomware group?
Qilin is a ransomware-as-a-service operation in which a core developer team leases ransomware tooling to independent affiliates, who Conduct attacks and split ransom proceeds with the developers. It has been active since 2023 and targets healthcare, manufacturing and professional services globally, using double-extortion tactics that combine file encryption with threatened data publication.Source: BlackFog / cybersecurity reporting
What did Qilin attack in the UK?
Qilin attacked Synnovis, a pathology services provider for NHS Trusts in London, in June 2024. The attack disrupted blood testing services across King's College Hospital, Guy's and St Thomas' and other major NHS sites, forced thousands of appointment cancellations, and triggered emergency appeals for O-negative blood. It is one of the most disruptive ransomware attacks on UK healthcare infrastructure.Source: NHS / UK media reporting
Why does Qilin target hospitals and healthcare providers?
Healthcare cannot tolerate extended system downtime: patient care, diagnostics and drug dispensing depend on real-time IT access. Ransomware groups including Qilin target hospitals because operational pressure to restore services quickly makes healthcare organisations more likely to pay ransoms faster and at higher amounts than most other sectors.Source: BlackFog State of Ransomware May 2026
How many victims did Qilin claim in May 2026?
Qilin claimed 11 victims in May 2026, leading all active ransomware groups that month. BlackFog's monthly tracking recorded 95 publicly disclosed ransomware attacks worldwide in May, with 37 active groups and healthcare taking the heaviest sector hit at 28 incidents.Source: BlackFog State of Ransomware May 2026
Is Qilin the same as Agenda ransomware?
Yes. Qilin ransomware is also tracked under the name Agenda by some security vendors. It was initially written in the Go programming language before being rewritten in Rust, and both names refer to the same operator group and RaaS platform.Source: Trend Micro / cybersecurity research
What is Qilin ransomware and who does it target?
Qilin is a ransomware-as-a-service operation active since 2023 that leases attack tooling to independent affiliates. It targets healthcare, manufacturing, professional services and education globally, gaining notoriety from the 2024 NHS Synnovis attack and leading May 2026's disclosed ransomware tally with 11 claimed victims.Source: BlackFog monthly report
How did Qilin get into systems via the Check Point VPN vulnerability?
A Qilin affiliate exploited CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point Remote Access VPN using a deprecated IKEv1 code PATH. The flaw allowed attackers to bypass credential checks entirely. Exploitation ran for approximately one month before a hotfix was available, during which post-compromise activity was confirmed at a number of organisations.Source: Check Point / CISA KEV
How many ransomware attacks did Qilin carry out in 2026?
Qilin claimed 11 victims in May 2026 alone, leading all tracked ransomware crews that month. Across 2026 it has been consistently among the top five most active groups by public leak-site postings.Source: BlackFog
What happened in the Qilin attack on the NHS in 2024?
In June 2024 Qilin attacked Synnovis, a pathology service provider for NHS Trusts in London. Blood-test services at King's College Hospital, Guy's and St Thomas' and other sites were severely disrupted, forcing thousands of appointment and operation cancellations and an emergency appeal for O-negative blood donations.Source: event
Is Qilin ransomware linked to a specific country or government?
No confirmed state attribution has been made. Qilin operates as a commercially structured RaaS programme with independent affiliates. Its operators are not publicly identified and no government has formally attributed the group to a nation-state sponsor.
Source Material