Find notable cyber news and cases, enriched with sources, timelines, and signals.

Qilin ransomware leak-site surge and double-extortion activity in H2 2025

Malware Activity
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

The Qilin ransomware operation sustained a leak-site surge in second half of 2025, publishing more than 40 victim listings per month and keeping pressure on victims. It used a double-extortion model, encrypting data and threatening to leak stolen information to coerce payment. Activity concentrated on manufacturing, with additional targeting of professional and scientific services and wholesale trade across the United States, Canada, the United Kingdom, France and Germany. The pace and breadth of postings indicate a mature ransomware operation with continuing global reach.

Related Happenings

INC ransomware encryptors rewritten in Rust

Malware Activity
H score38 First: 18.06.2026 17:12 Last: 18.06.2026 17:12 Sources 1

About this happening: INC's Windows and Linux/ESXi encryptors were rewritten in Rust, improving cross-platform development and making reverse engineering harder. The malware line also gaine...

INC ransomware group’s RaaS expansion and victim growth in 2026

Threat Actor Meta
H score45 First: 18.06.2026 17:12 Last: 18.06.2026 17:12 Sources 1

About this happening: INC has grown from a RaaS startup into one of 2026’s most prolific ransomware groups, with 830+ victims since August 2023. The expansion followed affiliate migrati...

Adriatic Port Authority (Autorità di Sistema Portuale del hit by ransomware attack linked to Anubis

Incident
H score54 First: 15.06.2026 19:15 Last: 15.06.2026 19:15 Sources 1

About this happening: The Adriatic Port Authority suffered a ransomware breach that disrupted the Italian port of Ancona and exposed sensitive port records. The intrusion was tied to Anub...

Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

Threat Actor Meta
H score21 First: 07.06.2026 17:09 Last: 07.06.2026 17:09 Sources 1

About this happening: Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...

Silent Ransom Group US law firm IT impersonation campaign

Campaign
H score36 First: 29.05.2026 16:00 Last: 29.05.2026 16:00 Sources 1

About this happening: Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...

Timeline

  1. 27.10.2025 18:45 1 articles · 8mo ago

    Qilin ransomware leak-site surge and double-extortion activity in H2 2025

    Initial Disclosure

    Qilin accelerated leak-site publishing in 2H 2025, crossing 40 victim listings per month and peaking at 100 postings in June and August. The surge marked a sustained rise in ransomware pressure rather than a one-off burst.

    Show sources