Sentrix

Know your enemy

Who attacks here, and how

The ransomware groups claiming victims in the chosen region, the ones on the rise, and for each recognized actor a profile: since when, how it gets in, what it has done, what stops it.

As of Sep 20, 2026: 29 claims in the last thirty days, 313 over twelve months.

29

claims, 30 days

313

over 12 months

65

active groups, 12 months

Qilin

leading actor

Twelve months of claims

Targeted sectors, 12 months

  1. Manufacturing47
  2. Technology41
  3. Professional Services17
  4. Financial Services16
  5. Construction16
  6. Consumer Services14

Leading actors, 12 months

Share of the region's claims. Linked names have a profile.

  1. 01Qilin60 claims
  2. 02Akira21 claims
  3. 03INC Ransom21 claims
  4. 04SafePay19 claims
  5. 05Play17 claims
  6. 06Clop16 claims
  7. 07DragonForce14 claims
  8. 08The Gentlemen13 claims

Emerging radar

Groups whose first claim in this region is less than six months old and that have posted again.

  • Stormsince Aug 14, 20267 claims
  • Settrasince Jun 28, 20264 claims
  • Chaossince Jun 22, 20264 claims
  • Cmdorganizationsince Jul 7, 20263 claims
  • Krybitsince Jul 1, 20263 claims
  • Kazusince Aug 23, 20262 claims
  • Metaencryptorsince Aug 23, 20262 claims
  • Lgroupsince Aug 7, 20262 claims

Latest claims

Title as published by the group; an organization's name here does not prove it was compromised.

  1. Schneider’s Computing · TechnologyArcusmedia
  2. Inglewood Golf · HospitalityPlay
  3. Vista Plastic Solutions · ManufacturingPlay
  4. xpera.ca · TechnologyBrain Cipher
  5. Bee Maid Honey · Agriculture and Food ProductionAkira
  6. In The Company of HuskiesQilin
  7. www.metalware.ca · ManufacturingKrybit
  8. Grunthal Welding & Supplies · ManufacturingPlay

Actor profiles

Who they are, how they get in, what they have done, what stops them. Every fact carries its source and its date.

Official benchmarks

What the authorities measure, with their date. The claims above are the visible part; these figures give the scale.

What it changes for you

The same doors come back in every profile: VPN access without MFA, a stolen credential, a known unpatched vulnerability, poorly governed remote access. The controls that close them are known and measurable; our assessment services verify them and the platform's CTEM module tracks what stays open.

Today's official advisories are on the watchOur analyses on the blog

Sources

Claims are published by the groups themselves on their leak sites and recorded by independent observatories; a claim is not a confirmed incident and can be false or duplicated. Profiles rely on joint CISA and FBI advisories, the Canadian Centre for Cyber Security, ANSSI, the NCSC and the research teams named on each profile.

Ransomware is no longer a family of software, it is an economy: affiliate programs that recruit, brokers that sell initial access, infostealers that supply the credentials, and leak sites where the victim is named before any negotiation starts. The Canadian Centre for Cyber Security named Akira, Play and Medusa as the three main ransomware threats to Canada in 2024; in 2026 Qilin, The Gentlemen, INC Ransom and SafePay have moved to the front, while Clop strikes in waves on one software flaw at a time. What does not change is the door: remote access without multi-factor authentication, a stolen credential, an unpatched edge device. The profiles above say, for each group, what authorities and research teams report, and which controls close that door.

Frequently asked questions

Why does Qilin dominate claims in Canada?
Because it absorbed the affiliates of programs that disappeared. TrendAI notes RansomHub affiliates migrating to its infrastructure in mid-2025 and an alliance with DragonForce and LockBit announced in September 2025; Check Point Research ranks it the most prolific operator worldwide for a fourth consecutive quarter in the second quarter of 2026. Its Canadian targets range from construction to education, often mid-sized organizations with exposed remote access.
How do these groups really get in?
Through the same door, advisory after advisory: remote access without multi-factor authentication. The joint CISA and FBI advisory on Akira puts VPNs without MFA ahead of any vulnerability; Play and Medusa use valid credentials and unpatched edge devices; Clop prefers a zero-day in a widely deployed file-transfer product. Credentials stolen by infostealers and resold by access brokers feed all of them.
Your organization appears on a leak site: what now?
Treat the claim as an alert, not as proof, and confirm through incident response: remote access, recently created accounts, unusual outbound transfers. If personal information is involved, Québec's Law 25 requires notifying the Commission d'accès à l'information and the people concerned as soon as there is a risk of serious injury, and PIPEDA requires reporting to the federal Privacy Commissioner when there is a real risk of significant harm. The Canadian Centre for Cyber Security receives reports and publishes the advisories.