Sentrix

State of the threat

State of the threat, August 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

  • Canada30-9 %33 the previous month
  • Québec0-100 %4 the previous month
  • United States415+28 %323 the previous month
  • Europe301+6 %284 the previous month
  • World1214+24 %980 the previous month

← July 2026September 2026 →

Leading groups in Canada

  1. 01Qilin6 claims+100 %
  2. 02INC Ransom3 claims
  3. 03Storm3 claims
  4. 04Settra2 claims+100 %
  5. 05The Gentlemen2 claims-50 %

Leading groups worldwide

  1. 01Qilin165 claims · 14 %
  2. 02The Gentlemen113 claims · 9 %
  3. 03Clop88 claims · 7 %
  4. 04Orova45 claims · 4 %
  5. 05INC Ransom44 claims · 4 %

Sectors hit in Canada

  1. Services and construction10 claims · Lgroup
  2. Technology4 claims · Settra
  3. Finance4 claims · Qilin
  4. Manufacturing3 claims · Qilin
  5. Retail and hospitality3 claims · Qilin
  6. Healthcare1 claim · Storm

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Stormsince 2026-08-148 claims
  • Kazusince 2026-08-232 claims
  • Metaencryptorsince 2026-08-232 claims
  • Lgroupsince 2026-08-072 claims

Exploited vulnerabilities

31+19 %

vulnerabilities added to the KEV catalogue this month, 2 of them tied to ransomware campaigns per CISA.

Most affected vendors

  1. Microsoft4
  2. PaperCut2
  3. Linux2
  4. Red Hat2
  5. TrueConf2

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →