Sentrix

State of the threat

State of the threat, January 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada20-35 %31 the previous month
  • Québec10 %1 the previous month
  • United States192-39 %317 the previous month
  • Europe96-51 %196 the previous month
  • World544-38 %882 the previous month

← December 2025February 2026 →

Leading groups in Canada

  1. 01Clop6 claims
  2. 020apt3 claims
  3. 03Sinobi2 claims+100 %
  4. 04Qilin2 claims-60 %
  5. 05Play1 claim0 %

Leading groups worldwide

  1. 010apt91 claims · 17 %
  2. 02Qilin67 claims · 12 %
  3. 03Clop43 claims · 8 %
  4. 04The Gentlemen37 claims · 7 %
  5. 05Akira30 claims · 6 %

Sectors hit in Canada

  1. Technology3 claims · 0apt
  2. Energy3 claims · 0apt
  3. Finance2 claims · Sinobi
  4. Healthcare1 claim · Clop
  5. Manufacturing1 claim · Nitrogen
  6. Public sector1 claim · INC Ransom

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Nothing this month.

Exploited vulnerabilities

17-15 %

vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft3
  2. SmarterTools2
  3. Ivanti1
  4. Fortinet1
  5. GNU1

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →