State of the threat
State of the threat, March 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
- Canada20-37 %32 the previous month
- Québec00 the previous month
- United States336-4 %351 the previous month
- Europe177+8 %164 the previous month
- World845-3 %868 the previous month
Leading groups in Canada
- 01Qilin5 claims+150 %
- 02The Gentlemen3 claims
- 03SafePay3 claims+200 %
- 04Ailock2 claims
- 05Play2 claims0 %
Leading groups worldwide
- 01Qilin141 claims · 17 %
- 02Akira75 claims · 9 %
- 03Nightspire63 claims · 7 %
- 04DragonForce60 claims · 7 %
- 05INC Ransom56 claims · 7 %
Sectors hit in Canada
- Technology5 claims · Ailock
- Manufacturing3 claims · Payload
- Services and construction3 claims · Qilin
- Retail and hospitality2 claims · Coinbasecartel
- Healthcare1 claim · The Gentlemen
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
26-7 %
vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
