Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Qilin leads ransomware a second month

1 min read
16:08UTC

BlackFog's June report kept Qilin at the top of ransomware activity for a second month, despite Europol's Operation Saffron hitting 25 gangs in May.

TechnologyDeveloping
Key takeaway

Qilin led ransomware activity for a second month running, undented by Europol's 25-gang takedown in May.

BlackFog, a cybersecurity firm that tracks ransomware activity, named Qilin the most active brand in its State of Ransomware report for June 2026, at 16% of undisclosed attacks and 8% of disclosed. The June ranking marks Qilin's second consecutive monthly lead, after it also led BlackFog's May tally , and it held even as Europol's Operation Saffron disrupted around 25 gangs in May . 1

Qilin's run through that enforcement pressure points at its affiliate-recruitment model. Affiliates are the freelance operators who carry out attacks using a brand's tooling in exchange for a cut. As takedowns strand affiliates from smaller crews, the largest recruiter absorbs them rather than shrinking. Saffron hit the infrastructure of two dozen operations; it did not touch the labour market they draw from, and that is the gap the June figures expose.

Deep Analysis

In plain English

Ransomware gangs sometimes act like criminal franchises: a core group builds the malicious software and negotiates with victims, while 'affiliates' actually break into networks and split the ransom. A cyber-security firm called BlackFog tracks which gang is most active each month, and for the second month running that gang is called Qilin. What makes this notable is that European police had just run a big operation the month before, called Operation Saffron, disrupting around 25 different ransomware groups {{EVREF:/t/cyber-threats-and-defences/6/europol-seizes-first-vpn-in-saffron-raid/}}. Qilin still came out on top, which suggests that arresting or shutting down rival gangs does not necessarily reduce total ransomware activity; the criminals doing the actual break-ins often just switch to whichever gang is still standing.

Deep Analysis
Root Causes

Qilin runs a ransomware-as-a-service affiliate model with an unusually generous revenue split, reportedly up to 85% to affiliates versus the 70% more typical among rival brands, which is why disrupted gangs' affiliates tend to migrate to Qilin rather than disappear when law enforcement takes a competitor offline.

Operation Saffron's roughly 25 gang disruptions in May targeted infrastructure and arrests rather than the affiliate marketplace itself. Removing a service operator's servers does not remove the freelance affiliates who did the actual intrusions, and those affiliates simply re-register under whichever brand offers the best terms.

What could happen next?
  • Meaning

    Qilin's second consecutive monthly lead despite Operation Saffron suggests law-enforcement disruption campaigns reshuffle which brand affiliates use rather than reduce total ransomware volume.

  • Risk

    If Qilin continues absorbing displaced affiliates, its higher-than-median ransom demands could become the market's new benchmark rather than an outlier.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BlackFog· 4 Jul 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.