
How the World’s Most Active Ransomware Operation Expanded in H1 2026
The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem.
CRIL observed Qilin targeting organizations across multiple regions and industries, with activity spanning North America, Europe, Asia-Pacific, South America, and other global markets. Its widespread campaigns highlight how modern ransomware groups leverage affiliate networks, purchased access, and proven extorti...