
Qilin ransomware is the most active group of its kind in the world in 2026 — more than 500 victim organizations, with manufacturing its #1 target and logistics its #3. It breached CEVA Logistics and WIS Logistics, works the mid-market hard, and gets in through exposed remote access, phishing, and unpatched edge devices.
Who is Qilin (Agenda)?
Qilin — tracked by some researchers as Agenda — is a Ransomware-as-a-Service (RaaS) operation. That model matters. Qilin’s core team builds and maintains the ransomware, the leak site, and the payment infrastructure, then rents the whole kit to affiliates who do the actual break-ins and keep most of the payout. So there is no single Qilin playbook — there are dozens of affiliates using the same toolkit, which is why the group turns up across wildly different victims in the same week.
In 2026 that reach made Qilin the most active ransomware brand on earth. Its top five sectors — manufacturing, construction, professional services, technology, and retail — account for roughly 55% of its victims. Manufacturing sits at the top of that list, and transportation and logistics is close behind. If you run a plant or a third-party logistics (3PL) operation, you are not a bystander to this trend. You are the target profile.
How active is Qilin in 2026?
The numbers are not close. Across the trackers that follow ransomware activity, Qilin sits at or near the top of every 2026 list.
| Metric | 2026 figure | Source |
|---|---|---|
| Global rank | Most active ransomware group in the world | Cyble, Dragos |
| Industrial-org incidents (Q1 2026) | 198 — the most of any group | Dragos |
| Victim organizations posted (2026) | 500+ | Cyble |
| North America attacks (H1 2026) | ~370 — about 1 in 5 of all NA ransomware | Cyble |
| Europe and UK (H1 2026) | 158 | Cyble |
| Asia-Pacific (H1 2026) | 64 | Cyble |
| South America (H1 2026) | 40 | Cyble |
| #1 target sector | Manufacturing | Cyble |
| Transportation and logistics | 3rd most-impacted — 87 incidents (Q1 2026) | Dragos, Cyble |
Put plainly: in North America, roughly one in every five ransomware attacks in the first half of 2026 carried Qilin’s name. Industrial-security firm Dragos logged 198 industrial-organization incidents tied to Qilin in Q1 2026 alone — more than any other group.
How does Qilin get in?
Here is the part that should change how you spend your security budget: Qilin’s affiliates rarely need an exotic zero-day. In the intrusions researchers have documented, the entry points are the same four unglamorous doors we see across the mid-market every week:
- Internet-exposed remote access. RDP and VPN portals reachable from the open internet, often protected by a password alone. This is the single most common front door.
- Phishing. A convincing email that harvests a credential or drops a loader.
- Valid, stolen credentials. Passwords pulled from infostealer logs or reused from an old breach — no “hack” required, they simply log in.
- Unpatched public-facing devices. Firewalls, VPN concentrators, and other edge appliances running firmware that is months behind on security fixes.
None of those are sophisticated. All four are preventable. That is the good news buried in the threat — the controls that stop Qilin ransomware are controls you can actually deploy.
What does a Qilin ransomware double-extortion attack actually do?
Qilin runs double extortion, the now-standard two-pronged squeeze. First the affiliate quietly exfiltrates data — sometimes for days — then deploys the ransomware to encrypt your systems. Now they have two forms of leverage at once: you cannot operate because your files are locked, and they threaten to publish everything they stole on their leak site unless you pay.
The CEVA Logistics attack is the textbook case. Qilin ransomware claimed responsibility, and researchers reported roughly 157 GB of data exfiltrated. Because CEVA is a logistics provider woven into other companies’ supply chains, the fallout did not stop at CEVA — downstream victims reportedly included names as varied as ING and Valve’s Steam. Qilin ransomware also hit WIS Logistics. When a 3PL is encrypted, the damage radiates outward to every customer whose shipments, inventory, and data ran through it. If a vendor of yours is breached, we walk through the response in what to do when a vendor is breached; if it is your own environment, start with what to do after a ransomware attack.
Why does Qilin ransomware target the mid-market?
Qilin’s affiliates are running a business, and the mid-market is efficient. A 200-person manufacturer or a regional 3PL usually has real revenue worth extorting but a lean IT team — and that gap is the opportunity. Three weaknesses show up again and again:
- Resource-constrained IT. One or two admins keeping the lights on, with no time for hardening, patch cadence, or monitoring.
- Flat networks. Office IT, the ERP, and the plant floor all on one network, so a single compromised laptop can reach everything — including production systems.
- Untested backups. Backups that exist on paper but have never been restored, or that sit on the same network the ransomware encrypts.
That last one is where recovery plans die. We cover the operational side of a plant-floor hit in manufacturing ransomware and production shutdowns. The pattern is consistent: the attack lands on the IT side, and the plant stops because IT and OT were never separated.
How do you shut the door on Qilin?
Every item below maps to one of Qilin’s entry points. None of it is exotic. All of it is the daily work of a managed IT and security program:
- Turn on MFA everywhere — email, VPN, remote access, admin accounts. Prefer phishing-resistant methods (hardware keys, passkeys) over SMS codes.
- Eliminate internet-exposed remote access. No RDP or management ports open to the world. Put remote access behind a VPN or zero-trust gateway with MFA, and close everything else.
- Patch internet-facing and edge devices fast. Firewalls, VPN appliances, and gateways get security updates on a tight clock, not “next quarter.”
- Keep immutable, regularly tested backups. Copies the attacker cannot alter or delete, stored off the production network, and — the part everyone skips — restore-tested on a schedule so you know they work.
- Deploy EDR/MDR and watch it. Endpoint detection with a human team monitoring alerts catches the intrusion in the hours between the first login and the encryption.
- Segment the network. Separate IT from OT, and segment identity so one compromised account cannot reach everything. We detail this for plants in IT/OT network segmentation for manufacturing.
This is exactly the scope of our security administration and network security services — the layer that closes Qilin’s four doors.
What QOS MSP owns — and what we route out
We will be straight about our lane. QOS MSP has delivered managed IT since 2007 — nearly two decades — and what we own is the layer where Qilin ransomware actually operates: your identity, network, endpoints, backups, and monitoring, plus running the recovery when something gets through. That is prevention that works and a restore you have tested before you needed it.
What we are not: we are not ransomware negotiators, and we are not a digital-forensics (DFIR) firm that reconstructs an attacker’s every move for a legal case. If you are mid-incident and those are needed, we bring in the right specialists and coordinate with them — we do not pretend to be them. And we never program the PLCs or controllers on your plant floor; that stays with your OT and equipment partners. Our job is to make sure the ransomware never reaches them, and to get you back online if it tries.
If you run a manufacturing or logistics operation in Indianapolis or across Indiana and want an honest look at whether Qilin’s four doors are open in your environment, talk to us.
Frequently asked questions
What is Qilin ransomware?
Qilin, also tracked as Agenda, is a Ransomware-as-a-Service operation that rents its ransomware, leak site, and payment infrastructure to affiliates who carry out the break-ins. In 2026 it became the most active ransomware group in the world, with more than 500 victim organizations posted to its leak site.
What companies has Qilin attacked?
Qilin is the group behind the CEVA Logistics breach, where researchers reported roughly 157 GB of data was stolen and the impact reached downstream companies including ING and Valve’s Steam. It also hit WIS Logistics. Manufacturing is its most-targeted sector, and transportation and logistics ranks third.
How does Qilin ransomware get into a network?
Qilin affiliates rarely use zero-day exploits. The common entry points are internet-exposed remote access such as open RDP or VPN, phishing emails, stolen or reused passwords, and unpatched public-facing edge devices like firewalls and VPN appliances. All four are preventable with standard security controls.
Should you pay Qilin’s ransom?
Paying is rarely the fastest or safest recovery. Qilin uses double extortion, so paying to decrypt does not guarantee the stolen data is deleted, and payment funds more attacks. The reliable path back is immutable, restore-tested backups plus a practiced recovery plan. Ransom and legal decisions belong with your counsel and, where needed, a negotiation specialist.
How can a mid-sized manufacturer or 3PL defend against Qilin?
Turn on multi-factor authentication everywhere, remove all internet-exposed remote access, patch edge devices quickly, keep immutable and regularly tested backups, run EDR or MDR monitoring, and segment IT from OT. Each control closes one of Qilin’s common entry points, and together they take a mid-market network off the easy-target list.
Does QOS MSP negotiate with ransomware groups like Qilin?
No. QOS MSP secures the identity, network, endpoint, backup, and monitoring layer and runs the recovery, but it is not a ransomware negotiator or a digital-forensics firm. If an active incident needs those services, we coordinate the right specialists while we handle containment and restoration.