Full Report
What HappenedThroughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results.In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to the date the victim is publicly named.This UK footprint highlights their aggressive pursuit of Small-to-Medium Enterprises (SMEs) as most organisations had a revenue between £10m and £250m.Interestingly, one of the Qilin victims, Salford City College, also appeared on both the Qilin and DragonForce Tor data leak site (DLS) only a few days apart from 6 March to 10 March 2026, respectively.Qilin’s UK-based victims from H1 2026 spanned a diverse range of sectors:Construction & Property DevelopmentManufacturing & EngineeringLegal & Professional ServicesTechnology & IT InfrastructureEducationHealthcareAnalyst Comment Many of the organisations targeted by Qilin operators are just large enough to have the funds to pay mid-tier ransoms but often never got around to making an investment into a 24/7 dedicated threat detection service, such as an outsourced Security Operations Centre (SOC). Such services are usually enough protection to prevent an attack. If a ransomware affiliate faces tough resistance from a target, they often move on to a weaker and easier one.One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom. The total number of victims by each group is often going to be higher.The reason for the cross-posting of Salford City College is unknown for now. However, it could indicate that an affiliate may be using both Qilin and DragonForce RaaS platforms. An alternative theory could be that the college was hit by two affiliates of each RaaS. Interestingly, cross-posting on multiple leak sites is not as uncommon as it seems. Some victims listed on the Qilin leak site have historically appeared on the leak sites of ALPHV/BlackCat and Conti as well.The Ransomware Vulnerability Matrix Group Profile for Qilin reveals a diverse set of exploits leveraged by its operators. Like many other ransomware gangs, Qilin operators have exploited corporate VPN gateways such as Fortinet, Check Point, and WatchGuard for initial access. Interestingly, the exploitation of SmarterTools SmarterMail and SolarWinds Web Help Desk is less common but are also exploited by the Warlock ransomware gang. Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.Defensive Takeaways Harden Common Attack Paths: Treat any web-facing helpdesk or mail server as a high-risk device. If it does not absolutely require open internet access, place it behind a zero-trust network access gateway or a strict VPN. Enforce strict phishing-resistant Multi-Factor Authentication (MFA) on all remote access points. Ensure processes are in place for rapid patching and integrity checks for all corporate VPN gateways.Overcoming SME Resource Caps: Organisations must bridge the gap with an outsourced MDR service. Ransomware execution routinely happens at 2:00 AM on Fridays and weekends. Outdated antivirus agents alone are not enough to stop a motivated human adversary.Utilise Free Support Services: Capitalise on sovereign and community-vetted threat intelligence feeds to block attacker infrastructure early. UK defenders should actively enroll in the National Cyber Security Centre’s MyNCSC portal and integrate community resources like the Spamhaus DROP list and Abuse.ch tracking into their perimeter firewalls to automatically block known ransomware command-and-control (C2) nodes. ShadowServer and Team Cymru also offer useful free community resources.Relevant Sources https://www.bbc.co.uk/news/articles/c1d2wwyd6qqohttps://www.bedfordshirehospitals.nhs.uk/news/notification-synnovis-cyber-incident/https://www.bleepingcomputer.com/news/security/qilin-ransomware-gang-linked-to-attack-on-london-hospitals/Relevant CTI Sourceshttps://www.ransomware.live/map/GBhttps://www.ransomware.live/group/qilinhttps://www.ransomware.live/id/c2FsZm9yZGNjLmFjLnVrQGRyYWdvbmZvcmNlhttps://www.ransomware.live/id/U2FsZm9yZCBDaXR5IENvbGxlZ2VAcWlsaW4https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/Qilin.mdhttps://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/Qilin.mdhttps://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
Analysis Summary
# Threat Actor: Qilin
## Attribution & Identity
Qilin is a Ransomware-as-a-Service (RaaS) operation. Historically, its victims have also appeared on data leak sites (DLS) associated with **ALPHV/BlackCat** and **Conti**, suggesting potential overlap in affiliate networks or the rebranding of veteran cybercriminals. There are also observed links to **DragonForce** and **Warlock** due to shared victims and overlapping exploit usage.
## Activity Summary
Throughout H1 2026, Qilin emerged as the most prolific ransomware threat to UK-based organizations, listing 37 victims on its Tor data leak site. The group maintained an average of seven to nine published UK victims per month during this period. Notable recent activity includes the long-term data exfiltration fallout from their 2024 attack on **Synnovis** and a March 2026 attack on **Salford City College** that involved "cross-posting" on multiple leak sites.
## Tactics, Techniques & Procedures
* **Initial Access:** Exploitation of edge-facing corporate VPN gateways and web-facing servers.
* **Vulnerability Exploitation:**
* VPN Gateways: Fortinet, Check Point, and WatchGuard.
* Web/Mail Applications: SmarterTools SmarterMail and SolarWinds Web Help Desk.
* **Defense Evasion:** Frequent use of **Bring Your Own Vulnerable Driver (BYOVD)** tactics to disable or bypass Endpoint Detection and Response (EDR) and Antivirus (AV) software.
* **Extortion Lifecycle:** Typically follows a six-week cycle from initial intrusion to public naming on the DLS.
* **Affiliate Operations:** Possible use of multiple RaaS platforms (Qilin and DragonForce) by the same affiliate to maximize pressure.
## Targeting
* **Sectors:** Construction & Property Development, Manufacturing & Engineering, Legal & Professional Services, Technology & IT Infrastructure, Education, and Healthcare.
* **Geography:** Heavy focus on the **United Kingdom**.
* **Victims:** Specifically targets Small-to-Medium Enterprises (SMEs) with revenues between £10m and £250m. Named victims include:
* Synnovis (2024)
* Bedfordshire Hospitals NHS Foundation Trust (Data related to Synnovis)
* Salford City College (March 2026)
## Tools & Infrastructure
* **Ransomware:** Qilin (RaaS)
* **Infrastructure:** Tor-based Data Leak Sites (DLS)
* **C2 Tracking:** Associated with nodes tracked by community resources such as:
* Spamhaus DROP list
* Abuse.ch
* ShadowServer
* Team Cymru
## Implications
Qilin’s strategic focus on "mid-tier" SMEs highlights a calculated approach: targeting organizations large enough to pay substantial ransoms but small enough to lack 24/7 dedicated security monitoring (SOC). Their aggressive footprint in the UK and their ability to bypass modern EDR through BYOVD tactics represent a high-tier threat to organizations with maturing but incomplete security postures.
## Mitigations
* **Harden Perimeter:** Place web-facing helpdesks and mail servers behind Zero-Trust Network Access (ZTNA) or strict VPNs.
* **Authentication:** Enforce phishing-resistant Multi-Factor Authentication (MFA) on all remote access points.
* **Monitoring:** Implement 24/7 Managed Detection and Response (MDR) or an outsourced SOC to detect late-night or weekend execution.
* **Patch Management:** Prioritize rapid patching and integrity checks for VPN gateways (Fortinet, Check Point, WatchGuard).
* **Intelligence Integration:** Enroll in National Cyber Security Centre (NCSC) portals and integrate automated blocklists (Spamhaus, Abuse.ch) into firewalls to block C2 nodes.