Qilin ransomware group claims its 700th victim – all industry sectors now targeted

Ransomware attacks, I was assured by many security vendors armed with impressive-looking graphs late last year and into Q1 of this year, are on the decline. As reported at TechFinitive, I was dubious at the time, and despite moves by the UK government to make ransom payments illegal,ย Iโ€™m pretty sure I was right to be so.

With 78% of organisations now targeted by ransomware, new analysis showing that โ€œthrough the third quarter of 2025, ransomware attacks surged by 47%,โ€ especially when it came to small to medium-sized businesses, and now the Qilin ransomware-as-a-service group (RaaS) claiming its 700th victim, now isnโ€™t the time to get complacent.

An 23 October analysis from the threat specialists at Comparitech, has revealed that Qilin is now โ€œthe most prolific ransomware gang of the last few yearsโ€. Indeed, in just the first ten months of 2025, it has easily surpassed RansomHub, which ruled there roost last year with “just” 524 confirmed victims.

Qilin has been able to scale up its organisation to an alarming level,โ€ Rebecca Moody, Head of Data Research at Comparitech told TechFinitive, โ€œtargeting hundreds of organizations and with a large amount of success.โ€

The rise of Qilin ransomware group

The Russia-based group, which first hit the radar in 2022, has quadrupled its number of victims it had last year.

Qilin ransomware growth
Qilin’s growth in attacks (source: Comparitech)

Much of this can be attributed to the demise of RansomHub which saw threat affiliates flock to the Qilin RaaS instead. Unfortunately, such affiliates donโ€™t really give a flying fig when it comes to who they attack, and this can be seen by the sheer variety of industry sectors in the Qilin crosshairs: manufacturers, finance companies, retailers, healthcare providers and government agencies.ย 

The breakdown of this yearโ€™s attacks is, frankly, stunningly worrying:

  • 143 attacks on manufacturers
  • 108 attacks on service-based businesses
  • 69 attacks on finance companies
  • 50 attacks on retailers
  • 45 attacks on healthcare providers
  • 40 attacks on government entities
  • 34 attacks on construction companies
  • 6 attacks on the education sector

That these scumbags are prepared to target healthcare tells you all you need to know about the moral vacuum that these gangs work within. โ€œOver 596,000 records breached across the confirmed healthcare attacks,โ€ Comparitech reports, with 11.8TB of data stolen across all healthcare attacks.

โ€œQilin is causing mass disruption to businesses of all sizes this year and, if its 100+ victims in October are anything to go by,โ€ Moody concluded, โ€œits operation is only gaining momentum.”

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.