With 78% of organisations now targeted by ransomware, new analysis showing that โthrough the third quarter of 2025, ransomware attacks surged by 47%,โ especially when it came to small to medium-sized businesses, and now the Qilin ransomware-as-a-service group (RaaS) claiming its 700th victim, now isnโt the time to get complacent.
An 23 October analysis from the threat specialists at Comparitech, has revealed that Qilin is now โthe most prolific ransomware gang of the last few yearsโ. Indeed, in just the first ten months of 2025, it has easily surpassed RansomHub, which ruled there roost last year with “just” 524 confirmed victims.
Qilin has been able to scale up its organisation to an alarming level,โ Rebecca Moody, Head of Data Research at Comparitech told TechFinitive, โtargeting hundreds of organizations and with a large amount of success.โ
The rise of Qilin ransomware group
The Russia-based group, which first hit the radar in 2022, has quadrupled its number of victims it had last year.
Qilin’s growth in attacks (source: Comparitech)
Much of this can be attributed to the demise of RansomHub which saw threat affiliates flock to the Qilin RaaS instead. Unfortunately, such affiliates donโt really give a flying fig when it comes to who they attack, and this can be seen by the sheer variety of industry sectors in the Qilin crosshairs: manufacturers, finance companies, retailers, healthcare providers and government agencies.ย
The breakdown of this yearโs attacks is, frankly, stunningly worrying:
143 attacks on manufacturers
108 attacks on service-based businesses
69 attacks on finance companies
50 attacks on retailers
45 attacks on healthcare providers
40 attacks on government entities
34 attacks on construction companies
6 attacks on the education sector
That these scumbags are prepared to target healthcare tells you all you need to know about the moral vacuum that these gangs work within. โOver 596,000 records breached across the confirmed healthcare attacks,โ Comparitech reports, with 11.8TB of data stolen across all healthcare attacks.
โQilin is causing mass disruption to businesses of all sizes this year and, if its 100+ victims in October are anything to go by,โ Moody concluded, โits operation is only gaining momentum.”
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.