Sentrix

State of the threat

State of the threat, April 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada10-50 %20 the previous month
  • Québec00 the previous month
  • United States146-57 %336 the previous month
  • Europe135-24 %177 the previous month
  • World585-31 %845 the previous month

← March 2026May 2026 →

Leading groups in Canada

  1. 01Qilin3 claims-40 %
  2. 02DragonForce2 claims+100 %
  3. 03Secpo2 claims
  4. 04Shinyhunters1 claim
  5. 05Coinbasecartel1 claim0 %

Leading groups worldwide

  1. 01The Gentlemen77 claims · 13 %
  2. 02Qilin58 claims · 10 %
  3. 03DragonForce52 claims · 9 %
  4. 04Akira45 claims · 8 %
  5. 05Coinbasecartel43 claims · 7 %

Sectors hit in Canada

  1. Services and construction2 claims · Qilin
  2. Manufacturing1 claim · Secpo
  3. Technology1 claim · Qilin
  4. Finance1 claim · Shinyhunters
  5. Public sector1 claim · Qilin
  6. Retail and hospitality1 claim · Coinbasecartel

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Nothing this month.

Exploited vulnerabilities

31+19 %

vulnerabilities added to the KEV catalogue this month, 9 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft8
  2. Cisco3
  3. SimpleHelp2
  4. Adobe2
  5. Fortinet2

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →