Sentrix

State of the threat

State of the threat, July 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada33+57 %21 the previous month
  • Québec4+300 %1 the previous month
  • United States323+62 %199 the previous month
  • Europe284+76 %161 the previous month
  • World980+35 %726 the previous month

← June 2026August 2026 →

Leading groups in Canada

  1. 01The Gentlemen4 claims+100 %
  2. 02Cmdorganization3 claims
  3. 03Chaos3 claims+200 %
  4. 04Akira3 claims
  5. 05Qilin3 claims0 %

Leading groups worldwide

  1. 01The Gentlemen178 claims · 18 %
  2. 02Qilin127 claims · 13 %
  3. 03Deadlock85 claims · 9 %
  4. 04DragonForce42 claims · 4 %
  5. 05INC Ransom39 claims · 4 %

Sectors hit in Canada

  1. Services and construction12 claims · Qilin
  2. Technology5 claims · Akira
  3. Education4 claims · Cmdorganization
  4. Manufacturing3 claims · Qilin
  5. Public sector2 claims · Interlock
  6. Retail and hospitality2 claims · Gammax

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Cmdorganizationsince 2026-07-073 claims
  • Krybitsince 2026-07-013 claims

Exploited vulnerabilities

26+13 %

vulnerabilities added to the KEV catalogue this month, 4 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft5
  2. Fortinet3
  3. Cisco2
  4. WordPress2
  5. Langflow2

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →