The Gentlemen and Qilin continue a ransomware dominance battle in July 2026
Threat Actor Meta
Summary
Hide ▲
Show ▼
The Gentlemen and Qilin continued a ransomware dominance battle in July 2026, together accounting for 33% of claimed attacks and concentrating a large share of the market in two crews. The Gentlemen claimed 135 attacks while Qilin claimed 125, keeping them ahead of other groups by a wide margin. A prior March-May 2026 comparison had already placed The Gentlemen ahead of Qilin, showing that leadership at the top of the ransomware ecosystem is still shifting.
Related Happenings
Ransomware victim concentration remained dominated by the top five operations
Trend
H score44
First: 21.07.2026 16:00
Last: 21.07.2026 16:00
Sources 1
About this happening:
Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44%...
Ransomware victim concentration remained dominated by the top five operations
TrendAbout this happening: Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44%...
Ransomware ecosystem fragments as new groups emerge weekly
Threat Actor Meta
H score47
First: 21.07.2026 16:00
Last: 21.07.2026 16:00
Sources 1
About this happening:
Ransomware operations are fragmenting and expanding, with more than one new group per week entering the market and increasing extortion volatility. As of June 2026...
Ransomware ecosystem fragments as new groups emerge weekly
Threat Actor MetaAbout this happening: Ransomware operations are fragmenting and expanding, with more than one new group per week entering the market and increasing extortion volatility. As of June 2026...
The Gentlemen ransomware gang's affiliate-driven rise to most-active RaaS operator
Threat Actor Meta
H score36
First: 17.07.2026 12:00
Last: 17.07.2026 12:00
Sources 1
About this happening:
The Gentlemen ransomware gang became the most-active ransomware-as-a-service operator over a three-month period, overtaking Qilin with 300 incidents. Its rise...
The Gentlemen ransomware gang's affiliate-driven rise to most-active RaaS operator
Threat Actor MetaAbout this happening: The Gentlemen ransomware gang became the most-active ransomware-as-a-service operator over a three-month period, overtaking Qilin with 300 incidents. Its rise...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor Meta
H score39
First: 03.07.2026 16:00
Last: 03.07.2026 16:00
Sources 1
How related:
Comparitech’s analysis, published on August 5, found that The Gentlemen and Qilin groups together accounted for 33% of all attacks in July, the former claiming 135 attacks and the latter 125.
About this happening:
Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor MetaHow related: Comparitech’s analysis, published on August 5, found that The Gentlemen and Qilin groups together accounted for 33% of all attacks in July, the former claiming 135 attacks and the latter 125.
About this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor Meta
H score26
First: 10.06.2026 17:03
Last: 10.06.2026 17:03
Sources 1
How related:
Comparitech’s analysis, published on August 5, found that The Gentlemen and Qilin groups together accounted for 33% of all attacks in July, the former claiming 135 attacks and the latter 125.
About this happening:
The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor MetaHow related: Comparitech’s analysis, published on August 5, found that The Gentlemen and Qilin groups together accounted for 33% of all attacks in July, the former claiming 135 attacks and the latter 125.
About this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
Timeline
-
05.08.2026 03:00 2 articles · 2d ago
The Gentlemen and Qilin claim 33% of July ransomware attacks
Campaign Scope UpdateComparitech's August 5 analysis found that The Gentlemen and Qilin together accounted for 33% of all claimed ransomware attacks in July 2026, with The Gentlemen claiming 135 attacks and Qilin 125. The pair remained significantly more active than DragonForce, INC, CRPx0 and SafePay, underscoring an ongoing leadership contest at the top of the ransomware ecosystem.
Show sources
- Ransomware Surges in July After Q2 Lull — www.infosecurity-magazine.com — 07.08.2026 11:20
- Ransomware Surges in July After Q2 Lull — www.infosecurity-magazine.com — 07.08.2026 11:20