Actors
Threat actor profiles
Living profiles of the ransomware and extortion crews in the news: how they operate, what has happened to them, and which controls hold.
ACTOR / 01 · UPDATED 31 AUG 2026
Qilin
Likely Russia-based · Global · Ransomware-as-a-service; double extortion
On 26 August 2026 the US ATF confirmed a 'major incident' on a standalone system, the same day Qilin listed the agency on its leak site; on 31 August ATF said the claims concerned its legacy CALEA system, and Qilin…
Full profileACTOR / 02 · UPDATED 09 SEP 2026
The Gentlemen
Russian-speaking operators, per researchers · Global · Ransomware-as-a-service; double extortion
Comparitech counted 107 attacks by The Gentlemen in August 2026, second only to Qilin's 157. On 9 September 2026 Veradigm disclosed a patient data breach after the group listed it on 5 September; Veradigm did not name…
Full profileACTOR / 03 · UPDATED 28 SEP 2026
ShinyHunters
Global · financially motivated · SaaS data theft and extortion via vishing and stolen logins
Dutch police confirmed on 28 September 2026 the arrest of a 24-year-old man in their investigation into ShinyHunters; KrebsOnSecurity, citing sources, reported he was detained around 16 September. In September…
Full profileACTOR / 04 · UPDATED 16 JUL 2026
Scattered Spider
UK / US · English-speaking · Help-desk social engineering, SIM swaps and extortion
On 16 July 2026 Thalha Jubair and Owen Flowers were each sentenced to five years and six months over the 2024 Transport for London attack, after pleading guilty on 22 June; Jubair also faces a US complaint. In the US…
Full profileACTOR / 05 · UPDATED 08 SEP 2026
Akira
Global · financially motivated · VPN exploitation, fast encryption of Windows and hypervisors
CISA updated advisory AA24-109A on 13 November 2025. ThreatDown reported on 8 September 2026 that its MDR team had handled multiple recent Akira intrusions through SonicWall devices still unpatched against…
Full profileACTOR / 06 · UPDATED 20 JAN 2026
LockBit
Russia-based · Global · Ransomware-as-a-service; data theft and double extortion
LockBit announced version 5.0 in September 2025, with Windows, Linux and ESXi builds, and launched a new leak site in early December 2025; by January 2026 Arete counted more than 100 alleged victims posted there.…
Full profileACTOR / 07 · UPDATED 23 JAN 2026
Sandworm (APT44)
Russia · GRU Unit 74455 · Destructive wipers and attacks on energy and OT
ESET attributed, with medium confidence, a late-December 2025 attempt to deploy a new wiper, DynoWiper, against Poland's energy sector to Sandworm, and said it was not aware of any successful disruption (23 January…
Full profile