Ransomware: qilin named Air International Thermal Systems (GB)
1. Executive summary Ransomware.live has listed UK organisation Air International Thermal Systems as a victim attributed to “qilin”; the available material does not independently confirm
1. Executive summary Ransomware.live has listed UK organisation Air International Thermal Systems as a victim attributed to “qilin”; the available material does not independently confirm
1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim, INVENSITY, a Germany-based organisation (domain: www.invensity.com). Attribution to
1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim named DELTA WAYS, a Germany-based organisation (domain: www.deltaways.de)
1. Executive summary On 14 August 2026, the Qilin ransomware group publicly claimed a victim named "Connections," a Belgium-based organisation (domain www.connections.
1. Executive summary Check Point Research's Q2 2026 ransomware landscape report records 2,139 victims on data-leak sites — flat quarter-over-quarter but
1. Executive summary Q2 2026 saw sustained ransomware operational tempo against enterprise targets, with Qilin (no MITRE ATT&CK profile; attribution unconfirmed) accounting for 14.
1. Executive summary On 2026-08-08, the Qilin ransomware group publicly listed Clausing (Germany; www.clausing-tiefbau.com) as a victim on its leak site.
1. Executive summary On 4 August 2026, the Qilin ransomware operation publicly listed Galvin Brothers (Ireland, www.galvinbrothers.com) as a victim on its leak site.
1. Executive summary On 30 July 2026, the Qilin ransomware group listed Orimar (www.orimar.be), a Belgian organisation, as a victim on its leak site.
1. Executive summary On 28 July 2026, the Qilin ransomware group publicly claimed a victim named "Hoc" (domain: www.hocltd.com), a UK-based
1. Executive summary On 25 July 2026, the Qilin ransomware group listed GURR Abdichtungstechnik GmbH (Germany) as a victim on its leak site. Attribution to the
1. Executive summary On 24 July 2026, the Qilin ransomware group listed "GOP" (www.gopltd.com, GB) as a victim on its leak site.