Qilin has become the most active ransomware operation on record — by claimed-victim count it topped the leaderboard through 2025 and into 2026, with more than 1,500 organisations named on its leak site since launch. It is a ransomware-as-a-service (RaaS) brand, not a single gang, and the two ways its affiliates get in are exactly the two initial-access routes a Nisura assessment prices. Here’s who Qilin is, why it exploded, and what the Synnovis attack shows about the real-world cost. (Leak-site figures are claimed victims — read counts as direction, not a verified ledger.)

Who is Qilin?

Qilin surfaced in July 2022 as “Agenda,” a Go-language RaaS, and rebranded to Qilin — after a creature from Chinese mythology — later that year. Parts of the encryptor were rewritten in Rust for speed, cross-platform reach (Windows and Linux/ESXi) and harder reverse-engineering. Like every mature RaaS, Qilin runs the full stack of a criminal business: affiliate recruitment on underground forums, an affiliate panel, a double-extortion leak site and a negotiation portal. Affiliates reportedly keep 80–85% of each ransom, with the rest going to the core operators.

Why it exploded in 2025

Qilin’s surge is a story of consolidation. Through 2024–2025 the biggest names fell — LockBit was disrupted by law enforcement, ALPHV/BlackCat pulled an exit scam, and RansomHub went dark around April 2025. Their skilled affiliates needed a new home, and Qilin’s well-run platform absorbed them. The result: security vendors tracked Qilin as the single most active group by claimed victims — hundreds of organisations across 60+ countries, and one tracker (MOXFIVE) puts it at ~1,500 claims since launch, 500+ in 2026 alone. Its favoured sectors line up with the wider EU picture: healthcare, manufacturing, professional services and government.

Our own data agrees. In the Nisura EU Ransomware Tracker, Qilin is the most-claimed group in the EU this quarter (Q3 2026) — 66 of 313 EU claims to date, ahead of The Gentlemen (the crew that splintered from it):

EU claims by group · Q3 2026 to date

Qilin
66
The Gentlemen
58
Deadlock
44
SafePay
23
LockBit 5
10
Cl0p
8

How Qilin gets in — and why it’s the exact risk Nisura models

Researchers consistently tie Qilin’s initial access to two paths above all — not exotic exploits:

  • Stolen or purchased credentials — VPN and webmail logins bought from access brokers or lifted from infostealer logs, especially where MFA is missing. This is the credential vector — invisible to a port scan, and often the dominant path.
  • Exposed remote-access appliances — internet-facing VPN/RDP and edge devices, sometimes via a known CVE. This is the external-exposure path a passive scan sees.

Those are the two initial-access routes Nisura’s engine prices for every organisation: known-exploited exposure on your perimeter, plus a non-CVE credential/RDP vector scaled by your identity exposure. Qilin isn’t doing anything novel — it’s industrialising the two doors most companies leave ajar.

The case that defined Qilin: Synnovis and the NHS

On 3 June 2024, Qilin affiliates hit Synnovis, a pathology provider for NHS hospitals in London. Initial access was through compromised credentials; an MFA gap has been widely cited as a contributing weakness. Before encrypting, the attackers exfiltrated data and issued a reported $50 million demand; when negotiations broke down they published roughly 400GB of sensitive patient data — names, dates of birth, NHS numbers and test results.

The operational damage was severe: blood testing halted across King’s College, Guy’s and St Thomas’, and Lewisham & Greenwich, forcing an O-negative blood shortage, the cancellation of 10,000+ outpatient appointments and postponement of 1,700+ operations. A subsequent review found the attack was a contributing factor in 170+ cases of patient harm — and, in one case, contributed to a patient’s death, a landmark acknowledgement of ransomware’s human toll. Synnovis later put its direct costs at more than £32 million and issued breach notifications in February 2026 after an ~18-month forensic review.

The lesson isn’t that healthcare is uniquely doomed — it’s that a single credential and a missing MFA control cascaded into a nine-figure, life-threatening event. That chain is measurable before it happens.

Can we project Qilin’s financial gains?

Honestly — not reliably, and it’s worth being clear about why. On-chain attribution for Qilin is thin: our Ransomwhere-based economics source returns no wallet data tied to the Qilin/Agenda family, and RaaS crews deliberately obscure revenue with fresh wallets, split payments and unknown pay rates. Any circulating “Qilin earned $X” figure is an estimate stacked on unknowns — victims claimed × an assumed pay rate × average ransom — which is exactly the kind of unsourced number we won’t put a euro sign on.

What is knowable is victim-side and documented: in the Synnovis case, a reported $50M demand and £32M+ in direct costs to a single organisation. So we flip the question. Nisura doesn’t estimate what an attacker earns — it estimates what a hit would cost you: your downtime, business interruption, forensics and regulatory liability, weighted by how reachable your perimeter and identities actually are. That’s a number you can source, defend, and act on — unlike a leak-site revenue guess.

What it means for you

Qilin picks targets by exposure and payability, not by sector prestige — and it gets in through unpatched edge devices and stolen logins. None of that is decided by whether you’re formally an NIS2 essential or important entity. Three steps, in order: confirm whether the Directive binds you with the NIS2 Scope Checker; watch the live picture on the EU Ransomware Tracker and read who’s leading the quarter in our Q3 2026 ransomware round-up; then turn it into your own number — run a free CRQ simulation to see your projected annual loss in euros from exactly these vectors.

Sources & references

Leak-site victim counts are claimed incidents and vary by tracker. Attack details reflect public reporting on the Synnovis incident.