Actors

Threat actor profiles

Living profiles of the ransomware and extortion crews in the news: how they operate, what has happened to them, and which controls hold.

ACTOR / 01 · UPDATED 31 AUG 2026

Qilin

Likely Russia-based · Global · Ransomware-as-a-service; double extortion

On 26 August 2026 the US ATF confirmed a 'major incident' on a standalone system, the same day Qilin listed the agency on its leak site; on 31 August ATF said the claims concerned its legacy CALEA system, and Qilin…

Full profile

ACTOR / 02 · UPDATED 09 SEP 2026

The Gentlemen

Russian-speaking operators, per researchers · Global · Ransomware-as-a-service; double extortion

Comparitech counted 107 attacks by The Gentlemen in August 2026, second only to Qilin's 157. On 9 September 2026 Veradigm disclosed a patient data breach after the group listed it on 5 September; Veradigm did not name…

Full profile

ACTOR / 03 · UPDATED 28 SEP 2026

ShinyHunters

Global · financially motivated · SaaS data theft and extortion via vishing and stolen logins

Dutch police confirmed on 28 September 2026 the arrest of a 24-year-old man in their investigation into ShinyHunters; KrebsOnSecurity, citing sources, reported he was detained around 16 September. In September…

Full profile

ACTOR / 04 · UPDATED 16 JUL 2026

Scattered Spider

UK / US · English-speaking · Help-desk social engineering, SIM swaps and extortion

On 16 July 2026 Thalha Jubair and Owen Flowers were each sentenced to five years and six months over the 2024 Transport for London attack, after pleading guilty on 22 June; Jubair also faces a US complaint. In the US…

Full profile

ACTOR / 05 · UPDATED 08 SEP 2026

Akira

Global · financially motivated · VPN exploitation, fast encryption of Windows and hypervisors

CISA updated advisory AA24-109A on 13 November 2025. ThreatDown reported on 8 September 2026 that its MDR team had handled multiple recent Akira intrusions through SonicWall devices still unpatched against…

Full profile

ACTOR / 06 · UPDATED 20 JAN 2026

LockBit

Russia-based · Global · Ransomware-as-a-service; data theft and double extortion

LockBit announced version 5.0 in September 2025, with Windows, Linux and ESXi builds, and launched a new leak site in early December 2025; by January 2026 Arete counted more than 100 alleged victims posted there.…

Full profile

ACTOR / 07 · UPDATED 23 JAN 2026

Sandworm (APT44)

Russia · GRU Unit 74455 · Destructive wipers and attacks on energy and OT

ESET attributed, with medium confidence, a late-December 2025 attempt to deploy a new wiper, DynoWiper, against Poland's energy sector to Sandworm, and said it was not aware of any successful disruption (23 January…

Full profile