In 2025, the ransomware gang has already claimed several hundred breaches targeting companies, government agencies, and hospitals, mainly in the United States.

The cybersecurity firm Cisco Talos published, on October 26, 2025, a report on the Russian-speaking ransomware gang Qilin, one of the most active cybercriminal organizations in the world. Operating on a Ransomware-as-a-Service (RaaS) model with a network of affiliates, the group has claimed several hundred attacks in 2025 targeting large companies, local governments, and hospitals.

In October 2025 alone, Qilin added 185 victims to its leak site. The RaaS group has claimed responsibility for recent breaches against Japan’s beverage giant Asahi, the city of Sugar Land in Texas, a county in North Carolina, and several power companies in Texas. Half of these attacks targeted the United States, but France, Canada, South Korea, and Spain also appear among its regular victims.

Active since 2022, Qilin has significantly increased its ransom demands in 2025. In February, the gang demanded 4 million dollars after crippling the municipal court of Cleveland. The following month, it asked for 10 million dollars following the attack on Kuala Lumpur International Airport in Malaysia.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.