State of the threat
State of the threat, September 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-09-25 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.09.25 ·
Month in progress, data as of day 25: the comparison with the previous month is partial
- Canada24-20 %30 the previous month
- Québec30 the previous month
- United States214-48 %415 the previous month
- Europe142-53 %301 the previous month
- World679-44 %1214 the previous month
Leading groups in Canada
Leading groups worldwide
- 01Qilin65 claims · 10 %
- 02The Gentlemen60 claims · 9 %
- 03Krybit34 claims · 5 %
- 04Akira34 claims · 5 %
- 05Auditteam29 claims · 4 %
Sectors hit in Canada
- Manufacturing7 claims · Play
- Retail and hospitality4 claims · Clop
- Technology2 claims · Arcusmedia
- Public sector2 claims · Qilin
- Services and construction2 claims · The Gentlemen
- Healthcare1 claim · Play
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
39+26 %
vulnerabilities added to the KEV catalogue this month, none tied to ransomware campaigns per CISA.
Most affected vendors
- MikroTik3
- Microsoft3
- Linux3
- Cisco3
- Google3
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
