The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption.
Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
28 events from the most recent confirmed update back to the earliest known activity.
Poland-based manufacturing company Mera Metal was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.merametal.pl.
Austria-based manufacturing company STADLER Sensorik CNC-Technik was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.stadlercnc.at.
France-based Stade Francais was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.stadefrancais.com.
Ireland-based manufacturing company Galvin Brothers was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.galvinbrothers.com.
Germany-based RUPP Spritzguss was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.rupp-spritzguss.de.
WD Masonry & Concrete, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.wdmandc.com.
Service Electric, a U.S. organization in the energy and utilities sector, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.secv.com.
Freedom Claims Management, a U.S. financial services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.freedomclaimsinc.com.
Wire Products, a U.S.-based manufacturing organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.wireproducts.us.
The Saturday Evening Post, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.saturdayeveningpost.com.
Commercial Furniture Interiors, a U.S. organization in retail and e-commerce, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.cfioffice.com.
Germany-based Dienst Pack Systems was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.dienst-packsystems.de.
Ceragres, a Canada-based manufacturing company, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.ceragres.ca.
Austria-based Schreiner Trockenbau GmbH was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.schreiner-trockenbau.at.
Pointe Property Group, a U.S.-based organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.pointecre.com.
Questel SAS was listed as breached on August 1, 2026 in an incident attributed to ShinyHunters. The attackers claimed theft of more than 21 million Salesforce records and over 147GB of internal corporate data.
Community Management Associates, a U.S. professional services organization, was reported as the victim of a ransomware-related data breach attributed to Qilin. The affected domain was www.cmamanagement.com.
Qilin affiliates were confirmed exploiting the Palo Alto GlobalProtect campaign during July 2026. Reported post-exploitation activity included Impacket, NTLM relay, and forged cookies.
Citrix disclosed CVE-2026-8451, a CitrixBleed-style memory overread in the XML/SAML parser triggered via the NSC_TASS cookie. The flaw carried a CVSS score of 8.8.
Check Point VPN vulnerability CVE-2026-50751 was publicly disclosed. The flaw was described as an authentication bypass with a CVSS score of 9.3.
Handala breached California-based water utility Cal Water in June 2026, stole sensitive customer data, and published it. Experts found no evidence the group successfully accessed operational technology despite its claims.
The Fortibleed campaign targeting exposed Fortinet FortiGate devices was first identified in mid-June 2026. It involved mass extraction of configuration files and cracking of password hashes.
CISA added Palo Alto GlobalProtect CVE-2026-0257 to its Known Exploited Vulnerabilities catalog. This reflected confirmed in-the-wild exploitation.
Rapid7 released a proof of concept for the Palo Alto GlobalProtect vulnerability CVE-2026-0257. The publication provided additional technical detail for the actively exploited flaw.
Active exploitation of CVE-2026-0257 was confirmed days after disclosure. The campaign targeted Internet-exposed Palo Alto GlobalProtect systems.
The authentication bypass vulnerability CVE-2026-0257 in PAN-OS GlobalProtect was disclosed. The flaw was described as cookie-spoofing based and mapped to CWE-565.
Attackers began exploiting CVE-2026-50751 in Check Point VPN roughly a month before public disclosure. The exploitation abused a logical flaw in IKEv1 certificate validation.
A May 2026 attack on the Canvas education platform was linked to ShinyHunters. The incident reportedly affected nearly 9,000 schools and universities worldwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcedti.domaintools.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.