Sentrix

State of the threat

State of the threat, September 2026

What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.

Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·

Month in progress, data as of day 25: the comparison with the previous month is partial

  • Canada24-20 %30 the previous month
  • Québec30 the previous month
  • United States214-48 %415 the previous month
  • Europe142-53 %301 the previous month
  • World679-44 %1214 the previous month

← August 2026

Leading groups in Canada

  1. 01Storm5 claims+67 %
  2. 02Qilin4 claims-33 %
  3. 03Play3 claims+200 %
  4. 04Clop2 claims+100 %
  5. 05Krybit2 claims

Leading groups worldwide

  1. 01Qilin65 claims · 10 %
  2. 02The Gentlemen60 claims · 9 %
  3. 03Krybit34 claims · 5 %
  4. 04Akira34 claims · 5 %
  5. 05Auditteam29 claims · 4 %

Sectors hit in Canada

  1. Manufacturing7 claims · Play
  2. Retail and hospitality4 claims · Clop
  3. Technology2 claims · Arcusmedia
  4. Public sector2 claims · Qilin
  5. Services and construction2 claims · The Gentlemen
  6. Healthcare1 claim · Play

Newcomers in Canada

Groups whose first Canadian claim dates from this month.

  • Nothing this month.

Exploited vulnerabilities

39+26 %

vulnerabilities added to the KEV catalogue this month, none tied to ransomware campaigns per CISA.

Most affected vendors

  1. MikroTik3
  2. Microsoft3
  3. Linux3
  4. Cisco3
  5. Google3

CISA KEV · Today's advisories on the watch

What it changes for you

The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.

The regional board →Talk to the team →