ctipilot.ch

Qilin

actor · actor:qilin single-sourcesingle-source-victim

Qilin / Agenda — Rust-based ransomware-as-a-service; Q3 2025 German operational tempo tripled (GTIG); 23 Q1 2026 healthcare claims

Aliases: Agenda

Coverage timeline
28
first 2026-05-04 → last 2026-08-16
Peak priority
critical
1 critical · 5 high · 22 notable
Sources cited
61
48 hosts
Sections touched
10
active-threats, deep-dive, research
Co-occurring entities
8
see Related entities below
ATT&CK techniques
18
pinned v19.2 · see below
2026-05-0428 appearances2026-08-16

ATT&CK techniques

18 techniques observed across 11 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1587.001Develop Capabilities: Malware×1

Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

Evidence: 2026-07-19/weekly-w29-thegentlemen-storm2697-status · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×6

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · 2026-06-09/check-point-ikev1-vpn-authentication-bypass-cve-2026-50751 · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · ATT&CK page ↗

T1190Exploit Public-Facing Application×4

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-07-19/weekly-w29-thegentlemen-storm2697-status · 2026-07-12/weekly-w28-the-gentlemen-status · 2026-06-09/check-point-ikev1-vpn-authentication-bypass-cve-2026-50751 · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · ATT&CK page ↗

Execution TA0002

T1047Windows Management Instrumentation×1

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

Evidence: 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×6

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · 2026-06-09/check-point-ikev1-vpn-authentication-bypass-cve-2026-50751 · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×6

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · 2026-06-09/check-point-ikev1-vpn-authentication-bypass-cve-2026-50751 · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · ATT&CK page ↗

Stealth TA0005

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

T1078Valid Accounts×6

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · 2026-06-09/check-point-ikev1-vpn-authentication-bypass-cve-2026-50751 · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-25/mistic-backdoor-signed-defender-dll-sideloading-and-in-memor · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-07-12/weekly-w28-the-gentlemen-status · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×1

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · ATT&CK page ↗

T1213Data from Information Repositories×2

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-16/weekly-w33-compromised-party-was-not-the-notifying-party · 2026-08-02/weekly-w31-criminal-claims-outran-confirmation · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×6

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-07-29/uvvg-arad-romania-university-cyberattack-qilin-claim · 2026-07-19/weekly-w29-thegentlemen-storm2697-status · 2026-07-12/weekly-w28-the-gentlemen-status · 2026-06-10/dragos-q1-2026-industrial-ransomware-analysis-1-020-industri · ATT&CK page ↗

T1490Inhibit System Recovery×1

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-08-16/weekly-w33-q2-ransomware-reports-dragos-checkpoint · ATT&CK page ↗

Story timeline

  1. 2026-08-16Two independent Q2 2026 ransomware reports published three days apart agree the ecosystem is fragmenting without de-concentrating — and the industrial one carries a negative finding OT operators should plan against: no Q2 case reached control-system manipulation
    weekly-annual-reportsDragos and Check Point both counted Q2: 93 active groups against a 57.6% top-ten share, and zero incidents reaching ICS Stage 2
  2. 2026-08-16A third party was on the access path or holding the data in all six European public-sector and critical-infrastructure disclosures this week — and where the third party held the data, the duty to notify landed on organisations with no facts to write
    weekly-sector-patternsW33's European breaches all ran through a third party, and in two of them the notification duty landed where the intrusion did not
  3. 2026-08-10Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June — the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
    active-threatsA European carrier serving 193 public administrations disclosed a two-month-old Qilin intrusion in a right-of-reply, not a press release
  4. 2026-08-02Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse
    weekly-incidents-recapW31's extortion claims ran ahead of the facts in both directions — over-claiming actors, one real breach inside
  5. 2026-07-29Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
    active-threatsWest University Vasile Goldis Arad notifies DNSC, the data-protection authority and prosecutors after an attack on academic and administrative systems
  6. 2026-07-19The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week
    weekly-long-runningThe Gentlemen status — ReliaQuest ranks it Q2's most-active operator (300 vs Qilin's 289) on an AI-accelerated affiliate kit; it hit Metro Mondego (Portugal)
  7. 2026-07-12The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day
    weekly-long-runningThe Gentlemen status update — Unit 42 profiles 580 victims/77 countries, ArmCorp/Qilin lineage, 90% affiliate cut, suspected EDR-disable zero-day
  8. 2026-06-29ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
    weekly-annual-reports
  9. 2026-06-25"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
    active-threats
  10. 2026-06-22CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use
    weekly-vuln-rollup
  11. 2026-06-22Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named
    weekly-annual-reports
  12. 2026-06-14CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass exploited by a Qilin affiliate
    weekly-top-stories
  13. 2026-06-10Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
    deep-diveDragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion
  14. 2026-06-09CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate
    trending-vulnerabilities
  15. 2026-06-09CVE-2026-42271 — BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV
    trending-vulnerabilities
  16. 2026-06-09Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)
    deep-dive
  17. 2026-05-25Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot
    weekly-annual-reports
  18. 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
    research
  19. 2026-05-20Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
    active-threats
  20. 2026-05-18Fox Tempest — Microsoft DCU disrupts the malware-signing service feeding Rhysida, INC, Qilin and Akira
    weekly-long-running
  21. 2026-05-11Qilin / Agenda RaaS — April 2026 lead at 15% of global ransomware activity, Germany 5% of global victims
    weekly-long-running
  22. 2026-05-11Check Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victims
    weekly-annual-reports
  23. 2026-05-08Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
    active-threats
  24. 2026-05-04Qilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuity
    weekly-long-running
  25. 2026-05-04Media and political (HU, DE)
    weekly-sector-patterns
  26. 2026-05-04Mandiant M-Trends 2026
    weekly-annual-reports
  27. 2026-05-04Google Threat Intelligence Group — Europe data-leak landscape 2025
    weekly-annual-reports
  28. 2026-05-04Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims
    weekly-long-running

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

overlaps with

related to

attributed activity

Where this entity is cited

  • weekly-annual-reports7
  • weekly-long-running6
  • active-threats5
  • weekly-sector-patterns2
  • deep-dive2
  • trending-vulnerabilities2
  • research1
  • weekly-top-stories1
  • weekly-vuln-rollup1
  • weekly-incidents-recap1

Source distribution

  • attack.mitre.org4 (7%)
  • blog.checkpoint.com3 (5%)
  • therecord.media3 (5%)
  • bleepingcomputer.com2 (3%)
  • cloud.google.com2 (3%)
  • dragos.com2 (3%)
  • helpnetsecurity.com2 (3%)
  • rapid7.com2 (3%)
  • other41 (67%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (61)

Entries about Qilin (28)

2026-08-16 · view entry permalink →

NOTABLENATOB1

Two independent Q2 2026 ransomware reports published three days apart agree the ecosystem is fragmenting without de-concentrating — and the industrial one carries a negative finding OT operators should plan against: no Q2 case reached control-system manipulation

Two quarterly ransomware reports landed three days apart this week, counting different populations from different vantage points, and arriving at compatible descriptions of the same structural shift. Taken together they are the closest thing to an outside check on what the operational entries of the last quarter have shown one incident at a time.

Dragos's Industrial Ransomware Analysis for Q2 2026 counts incidents affecting industrial organisations: "Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, an 12% increase over the 1,020 recorded in Q1," with manufacturing the most affected sector at 747 incidents or 65%, and engineering firms, system integrators and equipment manufacturers second at 117 — a distribution that puts the industrial supply chain, not the plant, at the centre. The regional detail is where it becomes a European planning input rather than a US one: the United States remains the most impacted country by a wide margin at 431 incidents or 38% of the total, but "the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany" (Dragos, 2026-08-10) — an eighty-four per cent rise in a neighbouring jurisdiction whose industrial base overlaps heavily with the Swiss one.

Check Point Research's State of Ransomware Q2 2026 counts leak-site victims across all sectors and describes the ecosystem's shape: "The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report," against a total of 2,139 victims that was essentially flat quarter over quarter and up 33% year over year. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims despite its own count falling 17%, while The Gentlemen surged 62% to 269 and briefly outpaced it; the US share of victims fell from 50% to 42%, which Check Point attributes to the fastest-growing groups — The Gentlemen and the newly active Krybit — targeting the US less often than the ecosystem average (Check Point Research, 2026-08-13). That last point is the one European defenders should read twice: a falling US share in a flat total is not a reduction in activity, it is a redistribution toward everyone else. Check Point also records, independently of this pipeline's own observations this week, that "The exploitation window kept narrowing, with AI increasingly cited as the accelerant."

The single most consequential finding in either report is a negative one, and it belongs to Dragos: "Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualization systems on which OT depends."

Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, an 12% increase over the 1,020 recorded in Q1.

Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualization systems on which OT depends.

However, the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany.

Dragos 2026-08-10

The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report.

The exploitation window kept narrowing, with AI increasingly cited as the accelerant.

Check Point Research 2026-08-13
annual-report16 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-16 · view entry permalink →

HIGHNATOB1

A third party was on the access path or holding the data in all six European public-sector and critical-infrastructure disclosures this week — and where the third party held the data, the duty to notify landed on organisations with no facts to write

A prior weekly recorded European government's own operating infrastructure being compromised directly. This week the shape is different and, for planning purposes, harder: in all six of the week's European public-sector and critical-infrastructure disclosures a third party stood somewhere on the line — supplying the credentials the intruder used, holding the data that was taken, or owning the security work that was not done. In two of them that separation ran all the way to the notification, so the organisation that knows what happened and the organisation that owes an answer are not the same body.

Poland supplies the extreme case. MyDr, one of the country's largest electronic medical record providers, confirmed on 12 August that it was the target of a deliberate external criminal act, said the data is likely historical, and stated it cannot yet say what was taken (MyDr, 2026-08-12). The following day the theft was reported at almost 19 million patients' data, with Poland's digital affairs minister Krzysztof Gawkowski quoted calling it one of the largest incidents in the country's history (Notes from Poland, 2026-08-13); Gazeta Prawna puts the stolen database at over 2 TB (Gazeta Prawna, 2026-08-13), and the data-protection authority UODO stated that the obligation to notify affected individuals rests with the healthcare controllers that used MyDr's services (Gazeta Prawna, 2026-08-13) — around 12,000 medical facilities (Notes from Poland, 2026-08-13). That is not a technicality. It means the single organisation that knows what happened has no duty to tell anyone, and the twelve thousand organisations that have the duty know only what they read in the press. The same structure produced a smaller, cleaner illustration in the Netherlands: one intrusion at CEVA Logistics, the contract-logistics arm of CMA CGM, generated breach reports to the Dutch data-protection authority from ten separate organisations, because CEVA processes fulfilment data on behalf of unrelated clients (TechCrunch, 2026-08-10); bol.com, one of them, told its own partners that two order-processing systems at one fulfilment centre were involved and that customer data may have been viewed or copied (bol.com, 2026-08-06).

Where the third party is on the access path rather than the data path, the same asymmetry shows up as a detection problem. France's Direction générale des Finances publiques confirmed that intrusions in June and July used the stolen credentials of a DGFiP agent and of an authorised third party, and were used to view and extract data on 678,000 individuals and businesses (Ministère de l'Économie et des Finances, 2026-08-14). Żabka's confirmed intrusion reached its ticketing system through an external service provider's account (Niebezpiecznik, 2026-08-03). Retelit, one of Italy's largest business telecommunications and cloud operators, was compromised on 8 June in an extortion attack claimed by Qilin, and made no announcement through its own channels — the confirmation came as a right-of-reply after IrpiMedia published, scoping the damage to virtualisation infrastructure in three of its 38 data centres, one of them the site certified for Retelit's own backup and service continuity (IrpiMedia, 2026-08-04). Retelit serves 193 public administrations; those customers learned about a two-month-old intrusion from a newspaper.

The week's regulator supplied the governance version of the same gap, and it is the most directly usable finding here. The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office on 12 August after an intruder held access to its public website and content management system from August 2022 to March 2023 and staged the data of up to 10,920 people for theft. The ICO's stated cause is not a technology failure: ACRO had contracted patch management to third parties without establishing who internally was responsible for identifying and monitoring critical updates, and did not adequately investigate security alerts that would have surfaced the intrusion earlier. The ICO also names network segmentation among the mitigating factors it weighed, because it kept the attacker out of core systems (UK Information Commissioner's Office, 2026-08-12).

Triage: third-party account misuse is hard to separate from third-party account use, and the discriminators are contextual rather than atomic. A supplier or contractor account is defined by a narrow, repetitive and scheduled access pattern — a fixed set of systems, a working-hours profile matching the supplier's own jurisdiction, a stable set of source addresses belonging to the supplier's estate. The signals worth alerting on are deviations from that shape rather than the access itself: authentication from a network range with no prior relationship to that supplier, access to systems outside the contracted scope, use of the platform's own bulk export or reporting functions by an account that has never used them before, and activity continuing outside the contract's active periods. The DGFiP case adds the timing discriminator that matters most for scoping: the account was cut when the intrusion was detected, and the theft had already happened — so the review that establishes impact has to reconstruct what the account reached before containment, not merely confirm it stopped afterwards.

Builds on: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-15/mydr-poland-19-million-records-government-confirmed · 2026-08-11/ceva-logistics-fulfilment-breach-ten-controllers-notified · 2026-08-15/france-dgfip-tax-authority-credential-intrusion · 2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector · 2026-08-10/zabka-supplier-account-jira-access-confirmed · 2026-08-13/ico-acro-reprimand-patch-ownership-gap-segmentation

synthesis16 Aug 23:56Zmulti-sourceOpen finding ↗

2026-08-10 · view entry permalink →

HIGHNATOB1

Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June — the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site

Retelit is one of Italy's largest business telecommunications and cloud operators, co-owner of a transcontinental submarine fibre cable and operator of 38 data centres across the country. On 2026-08-04 the investigative outlet IrpiMedia reported that it had been compromised in an extortion attack claimed by Qilin, with hundreds of gigabytes of files taken and part of them already published (IrpiMedia, 2026-08-04). Qilin's leak-site page, screenshotted by the outlet on 1 August, listed 270,000 files; IrpiMedia estimated at least 300 GB, because the site itself displayed an apparent placeholder size. The listing first appeared on 11 July and a document-and-passport sample followed on 14 July. The first outlet to report it was not IrpiMedia but an Italian trade blog on 12 July, which IrpiMedia credits as having "riportato la prima volta" the attack (Bismark.it, 2026-07-12) — so the compromise was public knowledge in the Italian trade press for over three weeks before the investigation that finally drew a company response.

Why this reaches a Swiss or European public-sector reader is the customer roster rather than the victim's name: "Tra i clienti dell'azienda figurano società strategiche quali Leonardo, almeno tre gestori di identità digitali e 193 pubbliche amministrazioni" — among the company's customers are strategic firms such as Leonardo, at least three digital-identity providers, and 193 public administrations. That is a statement about who Retelit serves, and it must not be read as a statement about whose data was taken. On that narrower question there is one concrete finding, and it is the outlet's own rather than a criminal claim: IrpiMedia says it examined the published dump and found Internet connectivity provisioning documents for the defence and aerospace group Leonardo's Genoa and Turin offices, dated October 2025 and April 2026. No Italian public administration has confirmed downstream impact.

The disclosure behaviour is the second half of the story. As IrpiMedia recorded before publication, "Non è noto il momento in cui è avvenuto l'attacco, rivendicato da Qilin con un primo post sul proprio sito" — the timing of the attack was unknown, and the company had not communicated the incident publicly nearly two months after its probable discovery. What broke that was the article. Afterwards Retelit sent the outlet a right-of-reply, published in full, which is where the company's own account appears for the first time: "L'attacco informatico attribuito al gruppo criminale Qilin è avvenuto lo scorso 8 giugno, come notificato alle autorità competenti" — an 8 June attack attributed to Qilin, notified to the competent authorities. Retelit adds that it "non ha nascosto quanto avvenuto. Al contrario, ha prontamente informato i clienti impattati, l'Agenzia per la Cybersicurezza Nazionale (ACN), il Computer Security Incident Response Team (CSIRT), la Polizia Postale e, in via prudenziale e cautelativa, il Garante per la Protezione dei Dati Personali" — that it did not conceal the incident and promptly informed affected customers, the national cybersecurity agency, CSIRT, the postal police and, as a precaution, the data-protection authority. It also stood up a war room with the agency and CSIRT alongside external incident-response and forensics firms. Retelit's own scoping is narrower than the reporting implies: "3 dei 38 data center Retelit dislocati sul territorio nazionale e pari a circa il 7% dei sistemi distribuiti nei data center" — a limited part of the virtualisation infrastructure in 3 of 38 national data centres, around 7% of distributed systems. This pipeline reports both characterisations and resolves neither; the gap between them is itself the finding. Separately, this run confirmed against Retelit's own press-release index that no public statement about the incident appears there.

On mechanism the reporting is thinner than on chronology, and its own sourcing tier is lower, which is worth carrying rather than smoothing over. IrpiMedia relays an account from an unnamed source involved in the incident, in the Italian conditional: "Secondo quanto riferito da una fonte coinvolta nell'evento, l'attacco sarebbe partito dal computer di un amministratore di sistema nel quale sono state carpite le password che hanno permesso all'attaccante di compiere dei «movimenti laterali»" — the attack is said to have started from a system administrator's computer, from which passwords were captured that let the attacker move laterally. The detection failure is not reported as fact either but as the outlet's inference from the volume already published: "è deducibile che il presidio di sicurezza (Soc, Security Operations Center) non abbia rilevato i movimenti laterali né la cifratura dei server se non quando era troppo tardi" — it is deducible that the security operations centre did not detect the lateral movement or the encryption of servers until it was too late. Neither claim comes from Retelit, and Retelit's own statement addresses scope rather than sequence.

That sequence is nonetheless the part a responder can act on, because it is ordinary rather than exotic: a privileged administrator endpoint yields stored credentials, those credentials authenticate to systems the endpoint legitimately reaches, and the encryption stage arrives before anything flags the movement between the two. Telemetry-wise it lands in three classes — credential access on administrator workstations, authentication events showing an administrator account reaching hosts it does not normally touch, and volume anomalies on file and virtualisation infrastructure. Triage: an administrator account authenticating across many systems is precisely what administrator accounts do, so breadth alone discriminates nothing; what separates this from routine work is the pairing of credential-store access on the workstation with a subsequent authentication fan-out that does not match the operator's normal maintenance pattern or change window.

Two further facts cut against Retelit's account of its own communications and belong next to it. The company says it "ha prontamente informato i clienti impattati" — promptly informed affected customers — but the same article's 6 August update records the opposite experience from the customer side: after a notification circulated by Italy's public-administration CERT at the end of July, "numerosi clienti riferiscono di aver scritto a Retelit per chiedere come mai non fosse arrivata alcuna comunicazione in seguito al data breach" — numerous customers report having written to Retelit to ask why no communication had arrived after the breach. This pipeline does not adjudicate between the two; both are reported and attributed.

The second fact is the one with the most direct public-sector consequence, and it establishes a notification path that ran around the company rather than through it. IrpiMedia records that Italy's CERT for public administration learned of the incident only on 30 July, and on that date began warning the security officers of every public administration potentially involved or otherwise using Retelit's services — "Tra questi anche Cineca, Lepida e Infocamere", among them a university and research consortium that also acts as a certified digital-preservation provider, and two organisations the article describes as providing Italy's digital-identity and digital-signature services. Those organisations are named as recipients of a precautionary warning, not as confirmed-impacted parties, and the distinction matters: what the record shows is a sector CERT propagating a supplier incident to downstream public bodies seven weeks after it happened, because the supplier had not.

One detail deserves emphasis because it inverts the reassurance the 7% figure is meant to offer. "IrpiMedia è in grado di rivelare esattamente quali sono: Verona, Roma e Milano" — the outlet names the three affected sites, and reports that the Milan site is the one certified by the national agency for Retelit's own backup management and service continuity in the event of a cyber incident. It also reports that customers contacted the newsroom complaining of partial or total failure of backup recovery. A small percentage of an estate is not a small incident when the affected fraction includes the continuity capability itself.

Tra i clienti dell'azienda figurano società strategiche quali Leonardo, almeno tre gestori di identità digitali e 193 pubbliche amministrazioni.

Non è noto il momento in cui è avvenuto l'attacco, rivendicato da Qilin con un primo post sul proprio sito

IrpiMedia 2026-08-04

L'attacco informatico attribuito al gruppo criminale Qilin è avvenuto lo scorso 8 giugno, come notificato alle autorità competenti

3 dei 38 data center Retelit dislocati sul territorio nazionale e pari a circa il 7% dei sistemi distribuiti nei data center

Retelit non ha nascosto quanto avvenuto. Al contrario, ha prontamente informato i clienti impattati, l'Agenzia per la Cybersicurezza Nazionale (ACN), il Computer Security Incident Response Team (CSIRT), la Polizia Postale e, in via prudenziale e cautelativa, il Garante per la Protezione dei Dati Personali.

Retelit 2026-08-10

IrpiMedia è in grado di rivelare esattamente quali sono: Verona, Roma e Milano.

Secondo quanto riferito da una fonte coinvolta nell'evento, l'attacco sarebbe partito dal computer di un amministratore di sistema nel quale sono state carpite le password che hanno permesso all'attaccante di compiere dei «movimenti laterali»

è deducibile che il presidio di sicurezza (Soc, Security Operations Center) non abbia rilevato i movimenti laterali né la cifratura dei server se non quando era troppo tardi

IrpiMedia 2026-08-04
incident10 Aug 05:55Zmulti-sourceOpen finding ↗

Earlier coverage (25)

2026-08-02NOTABLENATOB2Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorseFour of this week's incident disclosures share a problem that is operational rather than editorial: the criminal claim and the confirmed fact diverged, and in different directions each time. ExfilSquad's leak site appeared on 2026-07-26 with 15 named victims, and a threat-intelligence vendor assesses fabrication as currently the more likely explanation for the list — yet the UK Department for Education independently confirmed a real breach of two portals and a police legal database inside it. Everest published a Stadler Rail archive and claimed it touches four other rail operators, a claim no second outlet reports and none of those operators confirms, while Stadler's own release maintains it lost no data. ShinyHunters claims the EY credentials reached Jira, GitHub and Azure, which EY has not confirmed and the reporting outlet says it cannot verify. And a Qilin listing is the only thing connecting an actor to the Romanian university incident. For anyone whose triage queue ingests leak-site feeds, the week is a calibration exercise.2026-07-29NOTABLENATOB2Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to itUniversitatea de Vest "Vasile Goldis" din Arad, a Romanian public university, issued a press release on 2026-07-28 confirming that a recently identified cyberattack affected its IT infrastructure and the digital services used in academic and administrative work, that it notified the national cybersecurity directorate DNSC, the data-protection authority ANSPDCP and organised-crime prosecutors DIICOT, and that technical teams are working with external specialists on gradual restoration. The university does not say which systems are unavailable, whether personal data was accessed or exfiltrated, when the attack occurred, or who was responsible. Separately, the Qilin ransomware operation listed the university on its leak site with an estimated attack date of 2026-07-26 — a claim carried only by a leak-site mirror, which none of the Romanian reporting mentions at all.2026-07-19NOTABLEexploitedupdateNATOB2The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this weekUpdate to the prior weekly's The Gentlemen (Storm-2697) profile. ReliaQuest's Q2 2026 threat-spotlight (2026-07-16) reports The Gentlemen posted 300 victims in the quarter versus Qilin's 289, ending Qilin's leaderboard dominance, and attributes the pace to aggressive affiliate recruitment plus a well-packaged intrusion kit (pre-compromised victim lists, custom EDR killers, GPO-based deployment tooling) and a "likely AI-accelerated iteration layer" for tool refresh — with Infosecurity Magazine independently corroborating the 300-vs-289 figures. A GuidePoint GRIT review (pre-window) frames the same concentration as a "four-headed monster" (Qilin, The Gentlemen, Akira, DragonForce), with the five most prolific Q2 groups collectively claiming over 40% of recorded attacks. Operationally, the group's reach touched the constituency this week: Portugal's Metro Mondego confirmed a 6 July ransomware attack claimed by The Gentlemen, contained to internal systems. No new initial-access CVE or vector is disclosed — the delta is the quantitative leaderboard reversal, the AI-tooling-cadence explanation, and the fresh European public-transport victim.2026-07-12NOTABLEupdateNATOB2The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-dayUnit 42 published (2026-07-10) the first full technical profile of The Gentlemen RaaS (Microsoft: Storm-2697), which this pipeline has tracked since May. New this week: 580 claimed victims across 77 countries through 3 July (a ~6x H2-2025-to-H1-2026 increase), an assessed lineage from 'ArmCorp' — an affiliate of Qilin — before the ~September 2025 rebrand to a 90%-payout RaaS, initial-access vectors now explicitly including Erlang/OTP SSH and Windows SMB flaws alongside the tracked FortiOS/FortiProxy path, and a third-party (Expel) report of a suspected zero-day used specifically to disable EDR, distinct from the previously-documented GentleKiller BYOVD framework.2026-06-29NOTABLEESET "Killing me gently" — a de-facto mid-year RaaS-tooling reportBackground. The Gentlemen emerged in late 2025 as a RaaS operation founded by "hastalamuerte" (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT).2026-06-25HIGH"Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTukeTwo new initial-access-broker toolsets surface — Mistic and Edgecution — Symantec details Mistic, sideloaded via a signed Microsoft Defender binary so its activity reads as legitimate Defender behaviour (Symantec, 2026-06-24); Zscaler details Edgecution, a malicious Edge extension that bridges the browser sandbox to a host Python backdoor via the Native Messaging API (today's deep dive) (Zscaler, 2026-06-23).2026-06-22NOTABLECheck Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany namedSurfaced this week for its CH/EU-specific findings, Check Point's Q1 2026 ransomware report (published 11 May, not covered in the dailies) documents a structural consolidation: the top 10 groups now hold 71.1% of all leak-site victims, the highest concentration since early 2024 and a reversal of two years of …2026-06-22NOTABLECVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate useStatus update on the W24 § 1 item: NCSC-NL updated its advisory on 2026-06-16 to note public proof-of-concept code is now available for the IKEv1 VPN authentication bypass, which a Qilin ransomware affiliate has used for initial access (Help Net Security; NCSC-NL NCSC-2026-0179; daily 06-17).2026-06-14NOTABLEexploitedCVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass exploited by a Qilin affiliateIf you did nothing this week: a Remote Access VPN gateway running the deprecated IKEv1 path is an active ransomware entry point — a Qilin affiliate is using this bypass for initial access.2026-06-10NOTABLEDragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion patternDragos' quarterly industrial-ransomware report (published 3 June) is the single periodic landscape report treated in this brief; the focus below is only on what changes a Swiss/EU public-sector and critical-infrastructure SOC's posture, not the full survey (Dragos, 2026-06-03).2026-06-09NOTABLEexploitedCheck Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)On 8 June 2026 Check Point disclosed and shipped a hotfix for CVE-2026-50751 (CVSS 9.3), an authentication bypass affecting Remote Access VPN and Mobile Access gateways configured for the deprecated IKEv1 key exchange (Check Point, 2026-06-08).2026-06-09HIGHexploitedCVE-2026-42271 — BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEVLiteLLM AI-gateway command injection (CVE-2026-42271) added to CISA KEV — host RCE via the MCP test endpoints, unauthenticated when chained with CVE-2026-48710; fixed in 1.83.7 (GitHub Advisory).2026-06-09CRITICALexploitedCVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliateCheck Point IKEv1 VPN auth bypass (CVE-2026-50751, CVSS 9.3) actively exploited by a Qilin affiliate since 7 May — a month before disclosure. Unauthenticated session forgery on Remote Access / Mobile Access gateways; NCSC-CH issued an Action-Required advisory and CISA added it to KEV (Check Point, 2026-06-08).2026-05-25NOTABLECheck Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivotHorizon research surfaced a quarterly report the dailies did not cover: Check Point's Q1 2026 State of Ransomware (published 2026-05-11).2026-05-23NOTABLERapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 daysRapid7 Labs published its Q1 2026 Threat Landscape Report on 2026-05-21 covering January–March 2026 IR data; the GlobeNewswire release accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:2026-05-20HIGHMicrosoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operationsMicrosoft Digital Crimes Unit disrupts Fox Tempest malware-signing-as-a-service. 1,000+ fraudulent short-lived Microsoft Artifact Signing certificates revoked; signspace[.]cloud seized via SDNY court order. Downstream customers include Vanilla Tempest (Rhysida), Storm-0501, Storm-2561, Storm-0249; ransomware families served include Rhysida, INC, Qilin, Akira (Microsoft Threat Intelligence, 2026-05-19). Detection: hunt for Microsoft-signed PE binaries with cert validity ≤72h from Trusted Signing issuers.2026-05-18NOTABLEFox Tempest — Microsoft DCU disrupts the malware-signing service feeding Rhysida, INC, Qilin and AkiraMicrosoft Threat Intelligence and the Digital Crimes Unit disrupted Fox Tempest, a malware-signing-as-a-service operation that supplied code-signing to multiple ransomware operations (daily 2026-05-20). Status: disrupted via combined intelligence exposure and a sealed US legal action.2026-05-11NOTABLEQilin / Agenda RaaS — April 2026 lead at 15% of global ransomware activity, Germany 5% of global victimsW19 long-running record (item:qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity) tracked Qilin's continued German activity.2026-05-11NOTABLECheck Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victimsCheck Point's April 2026 monthly threat report (published early May 2026) confirms Qilin / Agenda leading all ransomware operators with 15% of 707 published attacks in April; Germany is the third-most-targeted country globally at 5.0% of victims (US 41.6%); Europe accounts for 27% of ransomware victims globally.2026-05-08NOTABLEQilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)The German federal party Die Linke confirmed in April 2026 that the Qilin ransomware group (also known as Agenda, a Rust-based RaaS platform known for double extortion) encrypted and exfiltrated its systems, with the gang claiming 1.5 TB of internal data.2026-05-04NOTABLEAkira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victimsW1 horizon research added Q1 2026 healthcare quarterly context to the Groupe 3R item in § 1.2026-05-04NOTABLEQilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuityCurrent state: GTIG's Europe data-leak landscape (§ 6) documented Qilin tripling Q3 2025 operational tempo in Germany; Die Linke (Germany federal political party) confirmed Qilin encryption with 1.5 TB exfiltrated (covered 2026-05-08), state DPA notified — Qilin German activity continues into 2026-Q2.2026-05-04NOTABLEGoogle Threat Intelligence Group — Europe data-leak landscape 2025GTIG's Europe data-leak landscape analysis (published 2026-04-15, first covered 2026-05-07) is the second-tier annual reference that materially affects DACH defender posture and merits cross-week synthesis: Germany is the primary European ransomware target with SAFEPAY accounting for 25% of German data-leak-site …2026-05-04NOTABLEMandiant M-Trends 2026M-Trends 2026 (published 2026-03-23, first covered 2026-05-07) reinforces three cross-cutting trends visible in this week's incidents: voice phishing surged to the second most prevalent initial-access vector at 11% (overtaking email phishing at 6%) driven by IT help-desk impersonation and SaaS OAuth token theft …2026-05-04NOTABLEMedia and political (HU, DE)Two European political / media targets in the week: Mediaworks Kft (Hungary) — World Leaks claimed 8.5 TB of exfiltrated data including payroll, contracts, and internal editorial communications; Mediaworks confirmed "a significant amount of illegally obtained data may have come into the possession of unauthorized …