State of the threat
State of the threat, May 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
- Canada15+50 %10 the previous month
- Québec10 the previous month
- United States161+10 %146 the previous month
- Europe120-11 %135 the previous month
- World447-24 %585 the previous month
Leading groups in Canada
- 01DragonForce4 claims+100 %
- 02Qilin4 claims+33 %
- 03SafePay2 claims
- 04Play2 claims
- 05Bravox1 claim
Leading groups worldwide
- 01Qilin76 claims · 17 %
- 02DragonForce52 claims · 12 %
- 03The Gentlemen40 claims · 9 %
- 04Akira25 claims · 6 %
- 05Nova24 claims · 5 %
Sectors hit in Canada
- Services and construction4 claims · Play
- Technology3 claims · DragonForce
- Manufacturing2 claims · DragonForce
- Retail and hospitality2 claims · DragonForce
- Healthcare1 claim · Qilin
- Finance1 claim · Pear
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
21-32 %
vulnerabilities added to the KEV catalogue this month, 3 of them tied to ransomware campaigns per CISA.
Most affected vendors
- Microsoft7
- Palo Alto Networks2
- Daemon1
- Nx1
- TanStack1
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
