Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationunderground-data-leakdata-exfiltration-methodfinancial-sector-threat

Qilin Ransomware's Surge and High-Profile Attacks on Global Organizations

Updated 3mo agoFirst seen Nov 21, 20253 sources

The Qilin ransomware group has emerged as one of the most prolific ransomware operations, claiming responsibility for over 500 attacks in the past six months and targeting major organizations worldwide. Notably, Qilin has allegedly stolen 10 GB of data from International Game Technology (IGT), a multinational provider in the gaming and fintech sectors, with over 21,000 files reportedly exfiltrated. The group has also targeted other high-profile victims, including Cornerstone Staffing Solutions, Spark Power, and Habib Bank AG Zurich, and is known to collaborate with other ransomware operations such as DragonForce and LockBit. Qilin, along with Akira and INC, accounted for 65% of ransomware attacks in Q3 2025, with a significant portion of these incidents facilitated by compromised VPN credentials.

Ransomware activity has seen a marked increase globally, with leak posts rising by 11% over the previous quarter and a surge in attacks reported in October. Attackers are increasingly exploiting vulnerabilities in VPNs and external services, and the prevalence of zero-day vulnerabilities has also grown, with notable bugs affecting Citrix NetScaler, CrushFTP, and Microsoft SharePoint. Security experts recommend organizations implement multi-factor authentication and strengthen vulnerability management practices to mitigate the escalating ransomware threat landscape.

Share:
Qilin Ransomware's Surge and High-Profile Attacks on Global Organizations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Nov 20, 20257mo ago

Qilin claims hack of International Game Technology

Qilin ransomware claimed responsibility for a cyberattack against International Game Technology. The claim was reported publicly by November 20, 2025.

Oct 31, 20258mo ago

KnowBe4 reports global ransomware surge in October 2025

A KnowBe4 report said ransomware attacks surged globally in October 2025. The report was published on November 20, 2025, but the underlying event concerns increased attack activity during October.

Sep 30, 20259mo ago

Zero-day advisories increase sharply in Q3 2025

Zero-day advisories rose by 38% during the third quarter of 2025. Major disclosures involved Citrix NetScaler, CrushFTP, and Microsoft SharePoint ToolShell vulnerabilities.

Stolen VPN credentials dominate ransomware initial access in Q3

In Q3 2025, stolen VPN credentials were the most common initial access vector in ransomware incidents, appearing in 48% of cases. Akira was noted for exploiting SonicWall SSL VPN devices that lacked multi-factor authentication and proper policies.

Ransomware leak posts rise in Q3 2025

Between July and September 2025, ransomware leak posts increased by 11% compared with the previous quarter. Akira, Qilin, and INC accounted for 65% of ransomware attacks during the quarter.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
3 linked
Organizations
10 linked
CrushftpAkiraInfosecurity MagazineQilinCitrix SystemsBeazley SecurityMicrosoft CorporationNational Institute of Standards and TechnologyInc.Sonicwall
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.