Qilin ransomware group leads global cyber activity with 24 claimed attacks for week of July 15-21, 2026
Global cyber activity reached 350 incidents across 58 countries, with the U.S. government and military sectors remaining the primary targets. Qilin emerged as the most active threat actor, contributing to a total of 29.6 TB of compromised data, though the attribution relies on self-reported claims by threat actors.
Score Breakdown
Intelligence Tags
Entities
Part of 2 situations
Qilin Ransomware Activity Escalates with PAN-OS Exploitation and Increased Attacks
The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks for the week of July 15-21, 2026, primarily targeting US government and military sectors. This increased activity is concurrent with confirmed exploitation of a critical Palo Alto Networks PAN-OS authentication bypass vulnerability to gain network access. The total volume of compromised data is claimed to be 29.6 TB, though attribution relies on self-reported claims.