Know your enemy
Who attacks here, and how
The ransomware groups claiming victims in the chosen region, the ones on the rise, and for each recognized actor a profile: since when, how it gets in, what it has done, what stops it.
As of Sep 20, 2026: 3 claims in the last thirty days, 13 over twelve months.
3
claims, 30 days
13
over 12 months
9
active groups, 12 months
Qilin
leading actor
Twelve months of claims
Targeted sectors, 12 months
- Education5
- Government & Defense2
- Business Services1
- Hospitality and Tourism1
- Public Sector1
Leading actors, 12 months
Share of the region's claims. Linked names have a profile.
- 01Qilin4 claims
- 02Kairos2 claims
- 03INC Ransom1 claim
- 04Cmdorganization1 claim
- 05Deadlock1 claim
- 06Worldleaks1 claim
- 07DragonForce1 claim
- 08SafePay1 claim
Emerging radar
Groups whose first claim in this region is less than six months old and that have posted again.
- Kairossince Jul 20, 20262 claims
Latest claims
Title as published by the group; an organization's name here does not prove it was compromised.
- Commission de la construction du Quebec (CCQ) · Government & DefenseQilin
- Multiver LtéeINC Ransom
- Commission de la construction du Quebec · Government & DefenseQilin
Actor profiles
Who they are, how they get in, what they have done, what stops them. Every fact carries its source and its date.
RaaSsince 2022-07
Qilin
Born as Agenda in 2022, Qilin is the most prolific ransomware operation of 2026 according to Check Point. Entry points, incidents and the controls that stop it.
Learn more →
RaaSsince 2023-03
Akira
Active since March 2023, Akira is one of the top three ransomware threats to Canada in 2024 according to the Cyber Centre. Entry points, incidents and controls.
Learn more →
Closed groupsince 2022-06
Play
Active since June 2022, Play had hit about 900 organizations by May 2025 per the FBI and is a top three ransomware threat to Canada. Access and controls.
Learn more →
RaaSsince 2021-06
Medusa
Identified in June 2021, Medusa had hit over 500 victims by April 2026 per CISA and is a top three ransomware threat to Canada. Access, incidents and controls.
Learn more →
Extortion without encryptionsince 2019-02
Clop
Profile of Clop, the group that exploits zero-days in file transfer tools and exposed business software to steal data at scale, then extorts without encrypting.
Learn more →
Cartelsince 2023-08
DragonForce
Profile of DragonForce, which moved from RaaS to cartel in March 2025: white-label brands for affiliates, help desk social engineering, UK retail attacks.
Learn more →
RaaSsince 2025-07
The Gentlemen
Profile of The Gentlemen, a RaaS from mid-2025 that exploits firewalls and VPNs, disables EDR and spreads a self-propagating Go encryptor. Targets and controls.
Learn more →
RaaSsince 2023-07
INC Ransom
Profile of INC Ransom, a RaaS active since July 2023 that gets in through RDP, phishing and Citrix, targets hospitals, schools and government, and leaks data.
Learn more →
Closed groupsince 2024-09
SafePay
Profile of SafePay, a closed ransomware group that emerged in 2024, gets in through VPN and RDP with valid credentials and encrypts in under twenty-four hours.
Learn more →
Official benchmarks
What the authorities measure, with their date. The claims above are the visible part; these figures give the scale.
13%
of Canadian businesses suffered a ransomware incident in 2023, up from 11% in 2021; 88% of victims did not pay.
Statistics Canada, Canadian Survey of Cyber Security and Cybercrime 2023, October 21, 2024+26%
a year on average: the growth of ransomware incidents in Canada since 2021. Akira, Play and Medusa were the main groups in 2024.
Canadian Centre for Cyber Security, Ransomware threat outlook 2025-2027, January 28, 2026514
confidentiality incident notices received in Québec in 2024-2025, up 16%; cyberattacks and ransomware are among the most frequent causes.
Commission d'accès à l'information du Québec, annual management report 2024-20253,611
ransomware complaints received by the FBI in 2025. Canada is the first foreign country by number of complainants, all fraud types combined.
FBI Internet Crime Complaint Center, 2025 annual report
What it changes for you
The same doors come back in every profile: VPN access without MFA, a stolen credential, a known unpatched vulnerability, poorly governed remote access. The controls that close them are known and measurable; our assessment services verify them and the platform's CTEM module tracks what stays open.
Today's official advisories are on the watch →Our analyses on the blog →
Sources
Claims are published by the groups themselves on their leak sites and recorded by independent observatories; a claim is not a confirmed incident and can be false or duplicated. Profiles rely on joint CISA and FBI advisories, the Canadian Centre for Cyber Security, ANSSI, the NCSC and the research teams named on each profile.
Ransomware is no longer a family of software, it is an economy: affiliate programs that recruit, brokers that sell initial access, infostealers that supply the credentials, and leak sites where the victim is named before any negotiation starts. The Canadian Centre for Cyber Security named Akira, Play and Medusa as the three main ransomware threats to Canada in 2024; in 2026 Qilin, The Gentlemen, INC Ransom and SafePay have moved to the front, while Clop strikes in waves on one software flaw at a time. What does not change is the door: remote access without multi-factor authentication, a stolen credential, an unpatched edge device. The profiles above say, for each group, what authorities and research teams report, and which controls close that door.
Frequently asked questions
- Why does Qilin dominate claims in Canada?
- Because it absorbed the affiliates of programs that disappeared. TrendAI notes RansomHub affiliates migrating to its infrastructure in mid-2025 and an alliance with DragonForce and LockBit announced in September 2025; Check Point Research ranks it the most prolific operator worldwide for a fourth consecutive quarter in the second quarter of 2026. Its Canadian targets range from construction to education, often mid-sized organizations with exposed remote access.
- How do these groups really get in?
- Through the same door, advisory after advisory: remote access without multi-factor authentication. The joint CISA and FBI advisory on Akira puts VPNs without MFA ahead of any vulnerability; Play and Medusa use valid credentials and unpatched edge devices; Clop prefers a zero-day in a widely deployed file-transfer product. Credentials stolen by infostealers and resold by access brokers feed all of them.
- Your organization appears on a leak site: what now?
- Treat the claim as an alert, not as proof, and confirm through incident response: remote access, recently created accounts, unusual outbound transfers. If personal information is involved, Québec's Law 25 requires notifying the Commission d'accès à l'information and the people concerned as soon as there is a risk of serious injury, and PIPEDA requires reporting to the federal Privacy Commissioner when there is a real risk of significant harm. The Canadian Centre for Cyber Security receives reports and publishes the advisories.
