The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption.
Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
58 events from the most recent confirmed update back to the earliest known activity.
B Wright Drywall, a U.S.-based manufacturing organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.bwrightdrywall.com.
The City of Winchester, a U.S.-based government and defense sector organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.winchesterky.com.
Synergy Interactive, a U.S.-based technology organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was listed as www.sinyc.com.
Taiwan-based Energetic Development Corp was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.edccorp.com.tw, and the victim was categorized in the energy and utilities sector.
Japan-based East Field Corporation was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was efc-tono.com, and the victim was categorized in the agriculture and food production sector.
Hong Kong-based manufacturing organization Chun Tai Sing Chemical Industry was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.crocoil.com.
Taiwan-based transportation organization Panda Logistics Taichung Branch was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.pandalog.com.
Germany-based energy and utilities organization pm-energy Die Solarexperten was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was pm-energy.de.
Romania-based manufacturing company Harplast SRL was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.HARPLAST.ro.
Mexico-based retail and e-commerce organization Price Shoes was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.priceshoes.com.
Finland-based Naval Interior Team was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.nit.fi, and the victim was categorized in the government and defense sector.
Thailand-based manufacturing organization Phithan Phanich was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.phithan-usedcar.com.
Belgium-based education-sector organization Université Libre de Bruxelles was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.ulb.be.
Peru-based manufacturing organization Grupo Diestra was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.grupodiestra.com.
Service d’usinage 9002, a Canada-based manufacturing organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.usinage9002.com.
Haiti-based Impact Centre Chrétien was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.impactcentrechretien.com.
Singapore-based CLLS Co Ltd was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was CLLS.com.sg.
Great Britain-based manufacturing company Filtronic was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.filtronic.com.
Astro Electroplating, a U.S.-based manufacturing organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.astroelectroplating.com.
Canada-based Nikan Awasisak Agency was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.nikanaa.ca.
Austria-based professional services firm EISNER ZT GMBH was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.zteisner.at.
Depona, a Sweden-based technology organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.depona.se.
John C Saunders, CPA, a U.S.-based professional services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.johncsaunderscpa.com.
Crystal Pharmatech, a U.S.-based healthcare organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.crystalpharmatech.com.
Jakle & Alexander, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.jaklelaw.com.
AmSpec, a U.S.-based organization in the energy and utilities sector, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.amspecgroup.com.
France-based professional services organization ALIZE was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was alize-sud.fr.
J&T Bank and Trust, a U.S.-based financial services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.jtbanktrust.com.
Turkey-based professional services firm Akuur Law Firm was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.akugurlaw.com.
Poland-based manufacturing company Mera Metal was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.merametal.pl.
Austria-based manufacturing company STADLER Sensorik CNC-Technik was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.stadlercnc.at.
France-based Stade Francais was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.stadefrancais.com.
Ireland-based manufacturing company Galvin Brothers was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.galvinbrothers.com.
Great Britain-based financial services firm Bloom Financials was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.bloomfinancials.com.
Germany-based RUPP Spritzguss was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.rupp-spritzguss.de.
WD Masonry & Concrete, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.wdmandc.com.
Service Electric, a U.S. organization in the energy and utilities sector, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.secv.com.
Freedom Claims Management, a U.S. financial services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.freedomclaimsinc.com.
Wire Products, a U.S.-based manufacturing organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.wireproducts.us.
The Saturday Evening Post, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.saturdayeveningpost.com.
Commercial Furniture Interiors, a U.S. organization in retail and e-commerce, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.cfioffice.com.
Germany-based Dienst Pack Systems was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.dienst-packsystems.de.
Ceragres, a Canada-based manufacturing company, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.ceragres.ca.
Austria-based Schreiner Trockenbau GmbH was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.schreiner-trockenbau.at.
Pointe Property Group, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.pointecre.com.
Questel SAS was listed as breached on August 1, 2026 in an incident attributed to ShinyHunters. The attackers claimed theft of more than 21 million Salesforce records and over 147GB of internal corporate data.
Community Management Associates, a U.S. professional services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.cmamanagement.com.
Qilin affiliates were confirmed exploiting the Palo Alto GlobalProtect campaign during July 2026. Reported post-exploitation activity included Impacket, NTLM relay, and forged cookies.
Citrix disclosed CVE-2026-8451, a CitrixBleed-style memory overread in the XML/SAML parser triggered via the NSC_TASS cookie. The flaw carried a CVSS score of 8.8.
Check Point VPN vulnerability CVE-2026-50751 was publicly disclosed. The flaw was described as an authentication bypass with a CVSS score of 9.3.
Handala breached California-based water utility Cal Water in June 2026, stole sensitive customer data, and published it. Experts found no evidence the group successfully accessed operational technology despite its claims.
The Fortibleed campaign targeting exposed Fortinet FortiGate devices was first identified in mid-June 2026. It involved mass extraction of configuration files and cracking of password hashes.
CISA added Palo Alto GlobalProtect CVE-2026-0257 to its Known Exploited Vulnerabilities catalog. This reflected confirmed in-the-wild exploitation.
Rapid7 released a proof of concept for the Palo Alto GlobalProtect vulnerability CVE-2026-0257. The publication provided additional technical detail for the actively exploited flaw.
Active exploitation of CVE-2026-0257 was confirmed days after disclosure. The campaign targeted Internet-exposed Palo Alto GlobalProtect systems.
The authentication bypass vulnerability CVE-2026-0257 in PAN-OS GlobalProtect was disclosed. The flaw was described as cookie-spoofing based and mapped to CWE-565.
Attackers began exploiting CVE-2026-50751 in Check Point VPN roughly a month before public disclosure. The exploitation abused a logical flaw in IKEv1 certificate validation.
A May 2026 attack on the Canvas education platform was linked to ShinyHunters. The incident reportedly affected nearly 9,000 schools and universities worldwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcedti.domaintools.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.