Qilin ransomware-as-a-service emerged as the most prominent ransomware threat affecting UK organizations in the first half of 2026, with 37 UK victims named on its Tor leak site—more than DragonForce and TheGentlemen. Reporting says the group averaged seven to nine UK disclosures per month and primarily hit SMEs across construction, manufacturing, legal services, technology, education, and healthcare. The campaign’s impact continued to reverberate from the 2024 Synnovis attack, after Bedfordshire Hospitals NHS Foundation Trust disclosed that more than 32,000 patient records linked to Synnovis tests had been exfiltrated.
Researchers and incident trackers also tied Qilin to fresh victim disclosures outside the UK, including INTERTRUST AUSTRALIA PTY LTD, a professional services firm in Australia associated with the domain www.seedoutsourcing.com. Prior reporting on Qilin’s operations describes a mature affiliate model and an extortion cycle of roughly six weeks from intrusion to public naming, with common tactics including exploitation of VPN gateways and BYOVD techniques to disable or evade EDR and antivirus tools. Separate reporting noted Salford City College appeared on both Qilin’s and DragonForce’s leak sites within days, raising the possibility of affiliate overlap or multiple compromises.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
INTERTRUST AUSTRALIA PTY LTD was identified as a ransomware victim attributed to the Qilin group. The incident was listed as a data breach affecting the professional services organization and associated with the domain www.seedoutsourcing.com.
On 1 June 2026, Bedfordshire Hospitals NHS Foundation Trust disclosed that more than 32,000 patient records related to Synnovis tests had been exfiltrated. The exposed data included names, patient numbers, dates of birth, postcodes, and test results.
Salford City College was also posted on DragonForce’s leak site on 10 March 2026, days after its appearance on Qilin’s site. The source says the reason for the dual listing was unknown.
Salford City College appeared on Qilin’s Tor data leak site on 6 March 2026. The later cross-posting was noted as unusual but not unprecedented.
Throughout the first half of 2026, Qilin had the highest number of UK-based victims on tracked leak sites, with 37 organizations listed. The source compares this with 21 for DragonForce and 18 for TheGentlemen.
The Qilin ransomware group attacked Synnovis in 2024, in an incident that later had downstream impact on NHS-related patient data. The reference identifies this as a 2024 attack but does not provide a more precise date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcehookphish.com
Open sourceransomware.live
Open sourceblog.bushidotoken.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.