Sentrix

State of the threat

State of the threat, December 2025

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada31+11 %28 the previous month
  • Québec1-50 %2 the previous month
  • United States317+4 %306 the previous month
  • Europe196+80 %109 the previous month
  • World882+22 %723 the previous month

← November 2025January 2026 →

Leading groups in Canada

  1. 01SafePay5 claims+150 %
  2. 02Qilin5 claims-50 %
  3. 03Devman5 claims
  4. 04Akira4 claims
  5. 05INC Ransom3 claims0 %

Leading groups worldwide

  1. 01Qilin178 claims · 20 %
  2. 02LockBit 5.0111 claims · 13 %
  3. 03Akira71 claims · 8 %
  4. 04SafePay68 claims · 8 %
  5. 05Sinobi54 claims · 6 %

Sectors hit in Canada

  1. Healthcare4 claims · DragonForce
  2. Manufacturing4 claims · SafePay
  3. Technology4 claims · Qilin
  4. Services and construction4 claims · SafePay
  5. Public sector2 claims · Medusa
  6. Education2 claims · Qilin

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Nothing this month.

Exploited vulnerabilities

20+82 %

vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Android2
  2. MongoDB1
  3. Digiever1
  4. WatchGuard1
  5. ASUS1

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →