Sentrix

Know your enemy

Who attacks here, and how

The ransomware groups claiming victims in the chosen region, the ones on the rise, and for each recognized actor a profile: since when, how it gets in, what it has done, what stops it.

As of Sep 20, 2026: 3 claims in the last thirty days, 13 over twelve months.

3

claims, 30 days

13

over 12 months

9

active groups, 12 months

Qilin

leading actor

Twelve months of claims

Targeted sectors, 12 months

  1. Education5
  2. Government & Defense2
  3. Business Services1
  4. Hospitality and Tourism1
  5. Public Sector1

Leading actors, 12 months

Share of the region's claims. Linked names have a profile.

  1. 01Qilin4 claims
  2. 02Kairos2 claims
  3. 03INC Ransom1 claim
  4. 04Cmdorganization1 claim
  5. 05Deadlock1 claim
  6. 06Worldleaks1 claim
  7. 07DragonForce1 claim
  8. 08SafePay1 claim

Emerging radar

Groups whose first claim in this region is less than six months old and that have posted again.

  • Kairossince Jul 20, 20262 claims

Latest claims

Title as published by the group; an organization's name here does not prove it was compromised.

  1. Commission de la construction du Quebec (CCQ) · Government & DefenseQilin
  2. Multiver LtéeINC Ransom
  3. Commission de la construction du Quebec · Government & DefenseQilin

Actor profiles

Who they are, how they get in, what they have done, what stops them. Every fact carries its source and its date.

Official benchmarks

What the authorities measure, with their date. The claims above are the visible part; these figures give the scale.

What it changes for you

The same doors come back in every profile: VPN access without MFA, a stolen credential, a known unpatched vulnerability, poorly governed remote access. The controls that close them are known and measurable; our assessment services verify them and the platform's CTEM module tracks what stays open.

Today's official advisories are on the watchOur analyses on the blog

Sources

Claims are published by the groups themselves on their leak sites and recorded by independent observatories; a claim is not a confirmed incident and can be false or duplicated. Profiles rely on joint CISA and FBI advisories, the Canadian Centre for Cyber Security, ANSSI, the NCSC and the research teams named on each profile.

Ransomware is no longer a family of software, it is an economy: affiliate programs that recruit, brokers that sell initial access, infostealers that supply the credentials, and leak sites where the victim is named before any negotiation starts. The Canadian Centre for Cyber Security named Akira, Play and Medusa as the three main ransomware threats to Canada in 2024; in 2026 Qilin, The Gentlemen, INC Ransom and SafePay have moved to the front, while Clop strikes in waves on one software flaw at a time. What does not change is the door: remote access without multi-factor authentication, a stolen credential, an unpatched edge device. The profiles above say, for each group, what authorities and research teams report, and which controls close that door.

Frequently asked questions

Why does Qilin dominate claims in Canada?
Because it absorbed the affiliates of programs that disappeared. TrendAI notes RansomHub affiliates migrating to its infrastructure in mid-2025 and an alliance with DragonForce and LockBit announced in September 2025; Check Point Research ranks it the most prolific operator worldwide for a fourth consecutive quarter in the second quarter of 2026. Its Canadian targets range from construction to education, often mid-sized organizations with exposed remote access.
How do these groups really get in?
Through the same door, advisory after advisory: remote access without multi-factor authentication. The joint CISA and FBI advisory on Akira puts VPNs without MFA ahead of any vulnerability; Play and Medusa use valid credentials and unpatched edge devices; Clop prefers a zero-day in a widely deployed file-transfer product. Credentials stolen by infostealers and resold by access brokers feed all of them.
Your organization appears on a leak site: what now?
Treat the claim as an alert, not as proof, and confirm through incident response: remote access, recently created accounts, unusual outbound transfers. If personal information is involved, Québec's Law 25 requires notifying the Commission d'accès à l'information and the people concerned as soon as there is a risk of serious injury, and PIPEDA requires reporting to the federal Privacy Commissioner when there is a real risk of significant harm. The Canadian Centre for Cyber Security receives reports and publishes the advisories.