Ransomware dossier

Qilin

Agenda/Qilin. Rust and Go payloads; hits healthcare, food & agriculture and financial services. Behind several high-impact 2025 healthcare outages.

Claimed victims

880

Top region

US

Top sector

Manufacturing

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-10-06CORBY ROCK MILLManufacturingIE
2026-10-06Delta MarineTransportationFI
2026-10-06J&D FinancialFinancial Services—
2026-10-05Global Security ConceptsProfessional ServicesUS
2026-10-05Asia Era OneNot FoundTH
2026-10-05OnsemiTechnologyUS
2026-10-04Unident GroupOtherUS
2026-10-04Chadwick SwitchboardsManufacturingAU
2026-10-04EmserManufacturingES
2026-10-04CotesmaManufacturingCL

Regions targeted

US 222GB 47DE 38CA 30FR 25AU 21ES 21IT 20

Sectors targeted

Manufacturing 129Professional Services 97Technology 54Retail & E-Commerce 49Healthcare 41Agriculture and Food Production 38

Suspected origin

Russia — Russian-speaking RaaS. Attribution reflects open-source consensus, not certainty.

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups