State of the threat
State of the threat, October 2026
What ransomware groups claimed this month, region by region, and what entered the catalogue of exploited vulnerabilities. Every figure is compared with the previous month.
Claims read on 2026-10-02 (ThreatCluster, CC BY 4.0) · KEV catalogue version 2026.10.01 ·
Month in progress, data as of day 02: the comparison with the previous month is partial
- Canada1-97 %29 the previous month
- Québec0-100 %3 the previous month
- United States22-92 %275 the previous month
- Europe10-95 %200 the previous month
- World51-94 %878 the previous month
Leading groups in Canada
- 01Boobaproject1 claim
Leading groups worldwide
- 01Akira6 claims · 12 %
- 02Boobaproject6 claims · 12 %
- 03Krybit6 claims · 12 %
- 04INC Ransom6 claims · 12 %
- 05Settra4 claims · 8 %
Sectors hit in Canada
- Healthcare1 claim · Boobaproject
Newcomers in Canada
Groups whose first Canadian claim dates from this month.
- Nothing this month.
Exploited vulnerabilities
1-98 %
vulnerabilities added to the KEV catalogue this month, none tied to ransomware campaigns per CISA.
What it changes for you
The leading groups come in through the same doors every month: remote access without MFA, stolen credentials, unpatched edge devices. The regional board says who is active near you; the actor profiles say how they get in; the KEV catalogue says what to fix first.
