State of the threat
State of the threat, April 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
- Canada10-50 %20 the previous month
- Québec00 the previous month
- United States146-57 %336 the previous month
- Europe135-24 %177 the previous month
- World585-31 %845 the previous month
Leading groups in Canada
- 01Qilin3 claims-40 %
- 02DragonForce2 claims+100 %
- 03Secpo2 claims
- 04Shinyhunters1 claim
- 05Coinbasecartel1 claim0 %
Leading groups worldwide
- 01The Gentlemen77 claims · 13 %
- 02Qilin58 claims · 10 %
- 03DragonForce52 claims · 9 %
- 04Akira45 claims · 8 %
- 05Coinbasecartel43 claims · 7 %
Sectors hit in Canada
- Services and construction2 claims · Qilin
- Manufacturing1 claim · Secpo
- Technology1 claim · Qilin
- Finance1 claim · Shinyhunters
- Public sector1 claim · Qilin
- Retail and hospitality1 claim · Coinbasecartel
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
31+19 %
vulnerabilities added to the KEV catalogue this month, 9 of them tied to ransomware campaigns per CISA.
Most affected vendors
- Microsoft8
- Cisco3
- SimpleHelp2
- Adobe2
- Fortinet2
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
