Ransomware group
Qilin ransomware: victims and leak site activity
The Qilin ransomware group has listed 2,268 victims on its leak site since October 2022; its latest post is from 9 September 2026. Most affected countries: United States, United Kingdom and Canada. Most targeted sector: Manufacturing.
Total posts
2,268
First seen
2022-10-08
Latest post
2026-09-09
Countries hit
103
About Qilin
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Most targeted countries
- United States 971
- United Kingdom 109
- Canada 108
- France 106
- Germany 89
- Spain 72
- Italy 67
- Australia 40
- Japan 40
- Mexico 34
Most targeted sectors
- Manufacturing 479
- Professional Services 389
- Technology 256
- Healthcare 195
- Retail & E-Commerce 166
- Financial Services 149
- Agriculture and Food Production 104
- Government & Defense 95
- Education 87
- Transportation 84