Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Qilin leads ransomware a second month

1 min read
12:09UTC

BlackFog's June report kept Qilin at the top of ransomware activity for a second month, despite Europol's Operation Saffron hitting 25 gangs in May.

TechnologyDeveloping
Key takeaway

Qilin led ransomware activity for a second month running, undented by Europol's 25-gang takedown in May.

BlackFog, a cybersecurity firm that tracks ransomware activity, named Qilin the most active brand in its State of Ransomware report for June 2026, at 16% of undisclosed attacks and 8% of disclosed. The June ranking marks Qilin's second consecutive monthly lead, after it also led BlackFog's May tally , and it held even as Europol's Operation Saffron disrupted around 25 gangs in May . 1

Qilin's run through that enforcement pressure points at its affiliate-recruitment model. Affiliates are the freelance operators who carry out attacks using a brand's tooling in exchange for a cut. As takedowns strand affiliates from smaller crews, the largest recruiter absorbs them rather than shrinking. Saffron hit the infrastructure of two dozen operations; it did not touch the labour market they draw from, and that is the gap the June figures expose.

Deep Analysis

In plain English

Ransomware gangs sometimes act like criminal franchises: a core group builds the malicious software and negotiates with victims, while 'affiliates' actually break into networks and split the ransom. A cyber-security firm called BlackFog tracks which gang is most active each month, and for the second month running that gang is called Qilin. What makes this notable is that European police had just run a big operation the month before, called Operation Saffron, disrupting around 25 different ransomware groups {{EVREF:/t/cyber-threats-and-defences/6/europol-seizes-first-vpn-in-saffron-raid/}}. Qilin still came out on top, which suggests that arresting or shutting down rival gangs does not necessarily reduce total ransomware activity; the criminals doing the actual break-ins often just switch to whichever gang is still standing.

Deep Analysis
Root Causes

Qilin runs a ransomware-as-a-service affiliate model with an unusually generous revenue split, reportedly up to 85% to affiliates versus the 70% more typical among rival brands, which is why disrupted gangs' affiliates tend to migrate to Qilin rather than disappear when law enforcement takes a competitor offline.

Operation Saffron's roughly 25 gang disruptions in May targeted infrastructure and arrests rather than the affiliate marketplace itself. Removing a service operator's servers does not remove the freelance affiliates who did the actual intrusions, and those affiliates simply re-register under whichever brand offers the best terms.

What could happen next?
  • Meaning

    Qilin's second consecutive monthly lead despite Operation Saffron suggests law-enforcement disruption campaigns reshuffle which brand affiliates use rather than reduce total ransomware volume.

  • Risk

    If Qilin continues absorbing displaced affiliates, its higher-than-median ransom demands could become the market's new benchmark rather than an outlier.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BlackFog· 4 Jul 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.