Ransomware Power Is Consolidating Around Qilin

Ransomware is consolidating around fewer operators, which makes the extortion market more durable for criminals even as individual brand names churn. The shift matters because disruption of one crew now tends to push affiliates, victims, and intelligence value into a smaller set of surviving platforms instead of breaking the ecosystem apart. Check Point puts Qilin at about 16% of the cybercriminal market, and Sophos says it listed 1,496 victims over the last 12 months from July 2026, more than Akira and The Gentlemen. The picture across both firms is the same: after pressure on LockBit, RansomHub, ALPHV, and others, experienced affiliates and higher victim volume concentrated around a technically mature RaaS operation with richer payouts and broader extortion services. That concentration does not mean the landscape is stable for defenders. It means fewer operators are carrying more of the market, so their infrastructure, affiliate base, and negotiation leverage matter more than the label on any single leak site.

Part of the PlainSec briefing for 2026-07-03

Sources