Sentrix

State of the threat

State of the threat, June 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada21+40 %15 the previous month
  • Québec10 %1 the previous month
  • United States199+24 %161 the previous month
  • Europe161+34 %120 the previous month
  • World726+62 %447 the previous month

← May 2026July 2026 →

Leading groups in Canada

  1. 01Qilin3 claims-25 %
  2. 02Brain Cipher2 claims
  3. 03Icarus2 claims
  4. 04The Gentlemen2 claims
  5. 05M3rx2 claims

Leading groups worldwide

  1. 01Qilin79 claims · 11 %
  2. 02The Gentlemen76 claims · 10 %
  3. 03LockBit 5.059 claims · 8 %
  4. 04Akira32 claims · 4 %
  5. 05INC Ransom31 claims · 4 %

Sectors hit in Canada

  1. Retail and hospitality5 claims · Settra
  2. Manufacturing3 claims · Chaos
  3. Services and construction3 claims · Aurora
  4. Healthcare2 claims · Interlock
  5. Technology2 claims · Icarus
  6. Finance1 claim · Qilin

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Settrasince 2026-06-284 claims
  • Chaossince 2026-06-224 claims

Exploited vulnerabilities

23+10 %

vulnerabilities added to the KEV catalogue this month, 3 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Cisco3
  2. Ubiquiti3
  3. Oracle2
  4. SimpleHelp1
  5. PTC1

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →