Sentrix

State of the threat

State of the threat, February 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada32+60 %20 the previous month
  • Québec0-100 %1 the previous month
  • United States351+83 %192 the previous month
  • Europe164+71 %96 the previous month
  • World868+60 %544 the previous month

← January 2026March 2026 →

Leading groups in Canada

  1. 01Clop8 claims+33 %
  2. 02Akira5 claims+400 %
  3. 03INC Ransom3 claims+200 %
  4. 04Nightspire2 claims
  5. 05Play2 claims+100 %

Leading groups worldwide

  1. 01Qilin112 claims · 13 %
  2. 020apt99 claims · 11 %
  3. 03The Gentlemen85 claims · 10 %
  4. 04Clop79 claims · 9 %
  5. 05Akira46 claims · 5 %

Sectors hit in Canada

  1. Services and construction7 claims · Clop
  2. Manufacturing4 claims · Play
  3. Retail and hospitality4 claims · Akira
  4. Technology3 claims · Clop
  5. Healthcare2 claims · INC Ransom
  6. Public sector2 claims · Lynx

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Nothing this month.

Exploited vulnerabilities

28+65 %

vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft8
  2. Cisco2
  3. Roundcube2
  4. GitLab2
  5. SolarWinds2

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →