Qilin has grown from a relatively small ransomware operation launched under the Agenda name in 2022 into one of the most prolific ransomware-as-a-service groups operating globally, combining data theft, encryption and extortion with an affiliate model capable of targeting organizations across healthcare, government, technology and other sectors.
The group’s activity has accelerated considerably. Security researchers ranked Qilin as the most prolific ransomware operation for four consecutive quarters through the second quarter of 2026, when its data leak site recorded 279 victims. In July, Qilin remained among the most active ransomware groups globally.
Its expanding victim list has included healthcare providers, multinational corporations and government organizations. Most recently, Qilin claimed responsibility for an intrusion involving the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives. ATF independently confirmed that a standalone system was compromised and said senior Department of Justice officials designated the incident a “major incident.”
From Agenda to a major ransomware operation
Qilin first appeared in 2022 under the name Agenda before adopting its current identity later that year. The operation follows a ransomware-as-a-service model in which affiliates conduct intrusions using ransomware, infrastructure and services supplied by the operation.
Early versions of the Agenda ransomware were written in Go, while later versions were developed in Rust. Researchers have identified versions targeting Windows systems as well as Linux builds capable of encrypting VMware ESXi environments.
Qilin affiliates have used multiple initial-access techniques rather than relying on a single intrusion method. Documented activity has included phishing, exposed remote services, compromised credentials and exploitation of vulnerabilities affecting internet-facing infrastructure.
Once inside an organization, affiliates can steal data before deploying ransomware, allowing the group to use both encryption and threatened publication of stolen information as leverage. Victims that do not reach an agreement can subsequently be listed on Qilin’s data leak site.
Exploitation of edge devices expands Qilin’s playbook
Qilin’s 2026 activity has increasingly demonstrated how vulnerable edge infrastructure can provide affiliates with another route into enterprise networks.
In June, BreachNews reported on Qilin-linked exploitation involving a Check Point VPN vulnerability. Check Point researchers assessed with medium confidence that the financially motivated actor exploiting the flaw used Qilin ransomware and observed indications that the same infrastructure was targeting other VPN vulnerabilities.
A separate campaign later examined by BreachNews linked Qilin ransomware attacks to exploitation of a PAN-OS VPN authentication bypass, further illustrating the importance of exposed perimeter systems in attacks associated with the operation.
The activity shows that organizations facing Qilin are not dealing with a single fixed intrusion chain. As a RaaS operation, individual affiliates can bring their own access methods and tooling while ultimately deploying the same ransomware and using Qilin’s extortion infrastructure.
Healthcare has remained a recurring target
Healthcare organizations have repeatedly appeared in Qilin activity, creating risks that extend beyond stolen information and encrypted computers to the availability of clinical services.
One of the group’s most disruptive attacks occurred against pathology provider Synnovis in June 2024. The ransomware attack severely reduced pathology capacity across parts of southeast London and resulted in the postponement of thousands of appointments and procedures. Stolen data was subsequently published.
Healthcare targeting has continued. BreachNews previously reported Qilin’s claim against healthcare platform Doctor.com, where the group alleged that approximately 205 GB of data had been stolen.
The repeated targeting of healthcare organizations is particularly significant because ransomware can disrupt systems supporting patient care even when an attack is initially motivated by financial extortion.
Danone claim adds another global enterprise victim
Qilin’s victimology extends well beyond healthcare.
In August 2026, Qilin claimed a ransomware attack against Danone and alleged the theft of approximately 221 GB of internal data.
The Danone listing reinforced Qilin’s ability to attract affiliates targeting large international organizations while maintaining a steady flow of smaller victims across multiple sectors.
ATF confirms major incident after Qilin claim
Qilin’s latest high-profile claim involves the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives.
The ransomware operation listed ATF on its data leak site on Aug. 26, 2026. ATF separately confirmed the same day that a cybersecurity incident compromised a standalone system.
The agency said the affected environment operates separately from its enterprise network and that there was no indication the incident affected the broader ATF enterprise network, ATF eForms or other ATF systems.
ATF disconnected the affected environment and launched incident-response and forensic work in coordination with the Department of Justice. Senior department officials formally designated the event a “major incident.”
The agency said its operations were not affected.
ATF has not publicly attributed the intrusion to Qilin. The timing of Qilin’s leak-site listing and ATF’s confirmed incident establishes a clear overlap, but the ransomware group’s responsibility remains a claim unless the agency or investigators formally attribute the attack.
Qilin remains one of ransomware’s largest operations
Qilin’s scale has become increasingly important as the ransomware ecosystem consolidates around several large RaaS brands.
Check Point researchers recorded 338 Qilin victim postings during the first quarter of 2026, making it the most prominent ransomware operation for the third consecutive quarter. Qilin followed with 279 victim postings during the second quarter, retaining the top position for a fourth consecutive quarter despite a 17% quarterly decline.
By July, Qilin and The Gentlemen were each responsible for approximately 14% of publicly reported ransomware victim postings tracked by Check Point.
Those figures represent organizations posted to ransomware data leak sites rather than a verified count of successful attacks. Some victims may never be publicly listed, while leak-site claims are not independently confirmed in every case.
The operation’s longevity also distinguishes it from many ransomware brands that disappear, rebrand or fracture after relatively short periods. Qilin has continued operating since 2022 while expanding its affiliate ecosystem and maintaining a high volume of victim claims.
Latest activity tracker
This section is continuously updated as new Qilin activity is reported.
August 2026: Qilin claims the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives as a victim. ATF confirms a standalone system was compromised in a cybersecurity incident designated a “major incident.”
August 2026: Qilin claims a ransomware attack against Danone and alleges the theft of approximately 221 GB of internal data.
July 2026: Qilin-linked ransomware attacks exploit a PAN-OS VPN authentication bypass as affiliates continue targeting internet-facing infrastructure.
June 2026: Check Point VPN vulnerability exploitation is linked to an actor deploying Qilin ransomware.
June 2026: Qilin targets healthcare platform Doctor.com and claims to have stolen approximately 205 GB of data.
All Qilin coverage
BreachNews continues to track Qilin ransomware attacks, vulnerability exploitation, victim claims and confirmed incidents associated with the operation.











