Key Takeaways
- Qilin’s growth shows that encryption is usually the final visible stage of a longer intrusion.
- Identity controls, monitoring and network segmentation can limit attackers before deployment.
- Recovery depends less on ransom payment than on tested backups and coordinated response plans.
Ransomware becomes obvious when systems stop working, files acquire unfamiliar extensions and a demand appears on employees’ screens. By that point, however, the consequential part of the intrusion may have been underway for days or weeks.
Qilin’s expansion illustrates that gap between initial compromise and visible disruption. The ransomware-as-a-service operation follows a double-extortion model, combining encryption with threats to publish stolen information. That gives its affiliates more than one way to pressure victims. Even when an organization can restore encrypted systems, exposed customer, employee or commercial data can produce regulatory scrutiny, legal costs and reputational damage.
The recent numbers are substantial. Check Point Research recorded 338 Qilin victims on leak sites in Q1 2026. Qilin alone posted more victims than the 50 least-active ransomware groups combined. The same research counted 2,122 newly posted ransomware victims globally during the quarter, 117% above Q1 2024.
A separate analysis from Black Kite tracked 7,551 publicly disclosed victims between April 2025 and March 2026, an increase of 24.9% year over year. Qilin accounted for 1,358 claims, representing growth of 443%.
Leak-site claims are not identical to independently confirmed incidents, and criminal groups have incentives to exaggerate. Still, the direction is hard to dismiss. Qilin has become one of the most visible operations in a crowded ransomware economy that also includes LockBit and Akira.
Ransomware is better understood as the conclusion of an intrusion chain, not a single malicious program. Attackers may first obtain credentials through phishing, password reuse, exposed remote services or unpatched systems. They can then explore the environment, elevate privileges, disable security controls, locate backups and identify valuable data.
Exfiltration may begin before encryption. So can lateral movement into systems that were never exposed directly to the internet. The ransom note merely announces that those earlier defenses did not contain the intrusion.
That distinction matters to business leaders because an apparently routine identity or endpoint alert could represent the opening stage of a broader incident. Would the security team recognize several low-level events across different systems as one coordinated campaign? In many environments, fragmented tools and unclear ownership make that harder than it sounds.
Qilin’s impact also extends beyond conventional office IT. Activity associated with the operation has affected Synnovis, the UK pathology provider supporting the NHS, as well as the City of Abilene, Texas, and SK Inc. in South Korea. Such cases demonstrate how ransomware can interrupt public administration, healthcare workflows and large corporate operations. Restoring servers is only part of the job. Organizations may also need to validate data integrity, rebuild endpoints, notify affected parties and monitor stolen information.
Prevention therefore starts with reducing opportunities for quiet access. Multifactor authentication can help protect remote and privileged accounts, particularly when paired with controls that resist repeated approval prompts. Timely vulnerability remediation, restricted administrative privileges and network segmentation can make movement more difficult. Centralized logs and endpoint telemetry give responders a better chance of identifying unusual account behavior or large data transfers.
The NIST Cybersecurity Framework 2.0 places governance alongside identification, protection, detection, response and recovery. That is useful framing for ransomware because responsibility reaches beyond the security operations center. Executives, legal teams, communications staff, insurers and operational leaders may all have decisions to make during an incident.
Backups remain central, but simply having them is not enough. Copies stored offline or otherwise isolated from production credentials can reduce the chance that attackers encrypt or delete them. Restoration exercises can reveal missing dependencies, outdated documentation and recovery times that look acceptable on paper but fail operational requirements.
According to Kaspersky, the proportion of organizations paying ransoms fell to 28% in 2025. Yet refusing payment does not eliminate recovery costs, nor does paying resolve every problem. Decryption tools may be slow or unreliable, stolen data may remain exposed, and attackers can retain access if the original entry point survives.
The practical lesson from Qilin’s rise is straightforward. Organizations gain more options when they detect the intrusion before encryption starts. Once the note appears, the attacker has already shaped the terms of the crisis.
⬇️