Sentrix

State of the threat

State of the threat, November 2025

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada28-42 %48 the previous month
  • Québec20 the previous month
  • United States306-16 %366 the previous month
  • Europe109-23 %142 the previous month
  • World723-14 %840 the previous month

← October 2025December 2025 →

Leading groups in Canada

  1. 01Qilin10 claims-29 %
  2. 02INC Ransom3 claims-25 %
  3. 03Play3 claims+200 %
  4. 04Tridentlocker2 claims
  5. 05Rhysida2 claims0 %

Leading groups worldwide

  1. 01Qilin107 claims · 15 %
  2. 02Clop98 claims · 14 %
  3. 03Akira87 claims · 12 %
  4. 04INC Ransom53 claims · 7 %
  5. 05DragonForce27 claims · 4 %

Sectors hit in Canada

  1. Manufacturing7 claims · Play
  2. Technology3 claims · Tridentlocker
  3. Services and construction3 claims · Qilin
  4. Healthcare2 claims · Qilin
  5. Public sector2 claims · Qilin
  6. Education2 claims · Rhysida

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • The Gentlemensince 2025-11-2113 claims

Exploited vulnerabilities

11-65 %

vulnerabilities added to the KEV catalogue this month, none tied to ransomware campaigns per CISA.

Most affected vendors

  1. Fortinet2
  2. Gladinet2
  3. OpenPLC1
  4. Oracle1
  5. Google1

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →