Qilin has become the most active ransomware operation on record — by claimed-victim count it topped the leaderboard through 2025 and into 2026, with more than 1,500 organisations named on its leak site since launch. It is a ransomware-as-a-service (RaaS) brand, not a single gang, and the two ways its affiliates get in are exactly the two initial-access routes a Nisura assessment prices. Here’s who Qilin is, why it exploded, and what the Synnovis attack shows about the real-world cost. (Leak-site figures are claimed victims — read counts as direction, not a verified ledger.)
Who is Qilin?
Qilin surfaced in July 2022 as “Agenda,” a Go-language RaaS, and rebranded to Qilin — after a creature from Chinese mythology — later that year. Parts of the encryptor were rewritten in Rust for speed, cross-platform reach (Windows and Linux/ESXi) and harder reverse-engineering. Like every mature RaaS, Qilin runs the full stack of a criminal business: affiliate recruitment on underground forums, an affiliate panel, a double-extortion leak site and a negotiation portal. Affiliates reportedly keep 80–85% of each ransom, with the rest going to the core operators.
Why it exploded in 2025
Qilin’s surge is a story of consolidation. Through 2024–2025 the biggest names fell — LockBit was disrupted by law enforcement, ALPHV/BlackCat pulled an exit scam, and RansomHub went dark around April 2025. Their skilled affiliates needed a new home, and Qilin’s well-run platform absorbed them. The result: security vendors tracked Qilin as the single most active group by claimed victims — hundreds of organisations across 60+ countries, and one tracker (MOXFIVE) puts it at ~1,500 claims since launch, 500+ in 2026 alone. Its favoured sectors line up with the wider EU picture: healthcare, manufacturing, professional services and government.
Our own data agrees. In the Nisura EU Ransomware Tracker, Qilin is the most-claimed group in the EU this quarter (Q3 2026) — 66 of 313 EU claims to date, ahead of The Gentlemen (the crew that splintered from it):
EU claims by group · Q3 2026 to date
How Qilin gets in — and why it’s the exact risk Nisura models
Researchers consistently tie Qilin’s initial access to two paths above all — not exotic exploits:
- Stolen or purchased credentials — VPN and webmail logins bought from access brokers or lifted from infostealer logs, especially where MFA is missing. This is the credential vector — invisible to a port scan, and often the dominant path.
- Exposed remote-access appliances — internet-facing VPN/RDP and edge devices, sometimes via a known CVE. This is the external-exposure path a passive scan sees.
Those are the two initial-access routes Nisura’s engine prices for every organisation: known-exploited exposure on your perimeter, plus a non-CVE credential/RDP vector scaled by your identity exposure. Qilin isn’t doing anything novel — it’s industrialising the two doors most companies leave ajar.
The case that defined Qilin: Synnovis and the NHS
On 3 June 2024, Qilin affiliates hit Synnovis, a pathology provider for NHS hospitals in London. Initial access was through compromised credentials; an MFA gap has been widely cited as a contributing weakness. Before encrypting, the attackers exfiltrated data and issued a reported $50 million demand; when negotiations broke down they published roughly 400GB of sensitive patient data — names, dates of birth, NHS numbers and test results.
The operational damage was severe: blood testing halted across King’s College, Guy’s and St Thomas’, and Lewisham & Greenwich, forcing an O-negative blood shortage, the cancellation of 10,000+ outpatient appointments and postponement of 1,700+ operations. A subsequent review found the attack was a contributing factor in 170+ cases of patient harm — and, in one case, contributed to a patient’s death, a landmark acknowledgement of ransomware’s human toll. Synnovis later put its direct costs at more than £32 million and issued breach notifications in February 2026 after an ~18-month forensic review.
The lesson isn’t that healthcare is uniquely doomed — it’s that a single credential and a missing MFA control cascaded into a nine-figure, life-threatening event. That chain is measurable before it happens.
Can we project Qilin’s financial gains?
Honestly — not reliably, and it’s worth being clear about why. On-chain attribution for Qilin is thin: our Ransomwhere-based economics source returns no wallet data tied to the Qilin/Agenda family, and RaaS crews deliberately obscure revenue with fresh wallets, split payments and unknown pay rates. Any circulating “Qilin earned $X” figure is an estimate stacked on unknowns — victims claimed × an assumed pay rate × average ransom — which is exactly the kind of unsourced number we won’t put a euro sign on.
What is knowable is victim-side and documented: in the Synnovis case, a reported $50M demand and £32M+ in direct costs to a single organisation. So we flip the question. Nisura doesn’t estimate what an attacker earns — it estimates what a hit would cost you: your downtime, business interruption, forensics and regulatory liability, weighted by how reachable your perimeter and identities actually are. That’s a number you can source, defend, and act on — unlike a leak-site revenue guess.
What it means for you
Qilin picks targets by exposure and payability, not by sector prestige — and it gets in through unpatched edge devices and stolen logins. None of that is decided by whether you’re formally an NIS2 essential or important entity. Three steps, in order: confirm whether the Directive binds you with the NIS2 Scope Checker; watch the live picture on the EU Ransomware Tracker and read who’s leading the quarter in our Q3 2026 ransomware round-up; then turn it into your own number — run a free CRQ simulation to see your projected annual loss in euros from exactly these vectors.
Sources & references
- Check Point — Qilin Ransomware (Agenda): A Deep Dive.
- Barracuda — Qilin ransomware is growing, but how long will it last?
- MOXFIVE — Qilin Ransomware 2026: TTPs, Victims and Defense Guide.
- SOCRadar — Dark Web Profile: Qilin (Agenda) Ransomware.
- BleepingComputer — Synnovis notifies of data breach after 2024 ransomware attack, and HIPAA Journal / Infosecurity Magazine on the Synnovis patient-harm findings.
Leak-site victim counts are claimed incidents and vary by tracker. Attack details reflect public reporting on the Synnovis incident.