State of the threat
State of the threat, December 2025
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
- Canada31+11 %28 the previous month
- Québec1-50 %2 the previous month
- United States317+4 %306 the previous month
- Europe196+80 %109 the previous month
- World882+22 %723 the previous month
Leading groups in Canada
- 01SafePay5 claims+150 %
- 02Qilin5 claims-50 %
- 03Devman5 claims
- 04Akira4 claims
- 05INC Ransom3 claims0 %
Leading groups worldwide
- 01Qilin178 claims · 20 %
- 02LockBit 5.0111 claims · 13 %
- 03Akira71 claims · 8 %
- 04SafePay68 claims · 8 %
- 05Sinobi54 claims · 6 %
Sectors hit in Canada
- Healthcare4 claims · DragonForce
- Manufacturing4 claims · SafePay
- Technology4 claims · Qilin
- Services and construction4 claims · SafePay
- Public sector2 claims · Medusa
- Education2 claims · Qilin
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
20+82 %
vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.
Most affected vendors
- Android2
- MongoDB1
- Digiever1
- WatchGuard1
- ASUS1
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
