Find notable cyber news and cases, enriched with sources, timelines, and signals.

Qilin ransomware leak-site surge and double-extortion activity in H2 2025

Malware Activity
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The Qilin ransomware operation sustained a leak-site surge in second half of 2025, publishing more than 40 victim listings per month and keeping pressure on victims. It used a double-extortion model, encrypting data and threatening to leak stolen information to coerce payment. Activity concentrated on manufacturing, with additional targeting of professional and scientific services and wholesale trade across the United States, Canada, the United Kingdom, France and Germany. The pace and breadth of postings indicate a mature ransomware operation with continuing global reach.

Related Happenings

Charter Communications hit by network compromise linked to ShinyHunters

Incident
First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: **Charter Communications** confirmed a **data breach** tied to **ShinyHunters** extortion, raising the risk of customer-data exposure and active follow-on pressure. The company sa...

7-Eleven hit by network compromise

Incident
First: 19.05.2026 17:16 Last: 19.05.2026 17:16 Sources 1

About this happening: **7-Eleven** is a **victim-focused breach incident** in which an **unauthorized third party** accessed systems used to store **franchisee documents** on **April 8, 2026**, trigger...

Gentlemen ransomware affiliate campaign expanding toolkit and infrastructure

Campaign
First: 20.04.2026 23:02 Last: 20.04.2026 23:02 Sources 1

About this happening: The **Gentlemen ransomware** campaign has now been tied to a **ransomware attack on Oltenia Energy Complex** on the **second day of Christmas**, disrupting **ERP systems**, **docu...

Akira group rapid double-extortion ransomware activity

Malware Activity
First: 02.04.2026 16:00 Last: 02.04.2026 16:00 Sources 1

About this happening: **Akira** ransomware activity now includes **AdaptixC2** abuse in active intrusions, alongside the group’s **under-one-hour** to **under-four-hours** attack cadence. A **Silent Pu...

ShinyHunters data-leak site exposing stolen attack data

Data Leak
First: 31.01.2026 17:02 Last: 31.01.2026 17:02 Sources 1

About this happening: The **ShinyHunters** extortion gang launched a **data-leak site**, beginning to publish data tied to the theft campaign and raising the exposure risk for victims.

Timeline

  1. 27.10.2025 18:45 1 articles · 7mo ago

    Qilin ransomware leak-site surge and double-extortion activity in H2 2025

    Initial Disclosure

    Qilin accelerated leak-site publishing in **2H 2025**, crossing **40 victim listings per month** and peaking at **100 postings** in **June and August**. The surge marked a sustained rise in ransomware pressure rather than a one-off burst.

    Show sources