Sentrix

State of the threat

State of the threat, October 2025

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada48+2300 %2 the previous month
  • Québec00 the previous month
  • United States366+679 %47 the previous month
  • Europe142+788 %16 the previous month
  • World840+657 %111 the previous month

November 2025 →

Leading groups in Canada

  1. 01Qilin14 claims
  2. 02Akira5 claims
  3. 03Coinbasecartel4 claims
  4. 04INC Ransom4 claims+300 %
  5. 05SafePay3 claims

Leading groups worldwide

  1. 01Qilin210 claims · 25 %
  2. 02Sinobi72 claims · 9 %
  3. 03Akira71 claims · 8 %
  4. 04Shinyhunters46 claims · 5 %
  5. 05INC Ransom34 claims · 4 %

Sectors hit in Canada

  1. Manufacturing8 claims · INC Ransom
  2. Technology7 claims · Qilin
  3. Services and construction7 claims · Qilin
  4. Finance5 claims · Coinbasecartel
  5. Retail and hospitality3 claims · Qilin
  6. Healthcare2 claims · Qilin

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Qilinsince 2025-10-0461 claims
  • Akirasince 2025-10-0321 claims
  • SafePaysince 2025-10-1019 claims
  • Clopsince 2025-10-2718 claims
  • Playsince 2025-10-2817 claims
  • DragonForcesince 2025-10-2714 claims

Exploited vulnerabilities

31+94 %

vulnerabilities added to the KEV catalogue this month, 3 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft8
  2. Dassault Systèmes2
  3. Adobe2
  4. Oracle2
  5. Kentico2

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →