State of the threat
State of the threat, January 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
- Canada20-35 %31 the previous month
- Québec10 %1 the previous month
- United States192-39 %317 the previous month
- Europe96-51 %196 the previous month
- World544-38 %882 the previous month
Leading groups in Canada
Leading groups worldwide
- 010apt91 claims · 17 %
- 02Qilin67 claims · 12 %
- 03Clop43 claims · 8 %
- 04The Gentlemen37 claims · 7 %
- 05Akira30 claims · 6 %
Sectors hit in Canada
- Technology3 claims · 0apt
- Energy3 claims · 0apt
- Finance2 claims · Sinobi
- Healthcare1 claim · Clop
- Manufacturing1 claim · Nitrogen
- Public sector1 claim · INC Ransom
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
17-15 %
vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.
Most affected vendors
- Microsoft3
- SmarterTools2
- Ivanti1
- Fortinet1
- GNU1
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
