Ransomware Report - 05/18/2026

Statistical Overview

Victim Totals

  • This month: 468
  • This quarter: 1246
  • Year to date: 3872
  • Last 24h: 28

Quarterly Breakdown

Q1: 2631 | Q2: 1246 | Q3: 0 | Q4: 0

Ransomware activity in Q2 continues at a steady pace, consistent with previous trends. The year-to-date victim count is substantial, with 28 new entities impacted in the last 24 hours.

Introduction

The past 24 hours saw 28 new ransomware victims publicly reported, showing the persistent threat across various sectors. Qilin and Titan were the most active groups, each claiming seven new victims. Manufacturing and Construction & Engineering sectors were impacted, and professional services and government entities across diverse geographies also continued to be targeted.

Ransomware Summary Table

#GroupVictims (24h)Sample VictimsGeosSectors
1Qilin7Buckeye paper, Fruits queralt, Majlis perbandaran alor gajah (+4)Canada, MalaysiaConstruction & Engineering, Media & Entertainment
2Titan7Abp autoricambi srl, Crit tunisie, Dfi america, llc (+4)United States, SingaporeConstruction & Engineering, Automotive
3AiLock2Design engineering & consulting, Jazz hipsterUnited States, TaiwanConstruction & Engineering, Manufacturing
4Akira2Healthtrax fitness & wellness, Vacu - lugUnited Kingdom, United StatesHealthcare, Manufacturing
5Doommageddon2Hiddenbay urla - serra sakli koy buti̇k turi̇zm i̇şletmeleri̇, Kolorkim kimyaTurkeyHospitality & Travel, Manufacturing
63AM1Molinoscabodi.com.arArgentinaAgriculture & Food
7Audit1Trésor publicSenegalGovernment / Public Sector
8CMD1stonehenge therapeutic communityCanadaNonprofit
9Chaos1Fallprotect.comUnited StatesManufacturing
10INC Ransom1bergen1.netUnited StatesEducation
11Lamashtu1Msmelt.comMalaysiaManufacturing
12Medusa Locker1Estrela demoIndiaProfessional Services

Ransomware activity over the last 24 hours was dominated by Qilin and Titan, collectively responsible for 14 of the 28 new victims. Manufacturing and Construction & Engineering sectors remain primary targets, experiencing attacks from multiple groups including AiLock, Akira, Doommageddon, and Lamashtu. Geographically, North America, particularly the United States and Canada, sustained a high volume of attacks. Targets today include Majlis perbandaran alor gajah (Malaysia) by Qilin, and Trésor public (Senegal) by Audit. This shows a continued focus on government and public-sector institutions. For more on Qilin's recent activity, see our Ransomware Victims Update - May 16 and Qilin Ransomware Threat Activity - May 14.

Victim Distribution

By Country

  • United States: 9
  • Canada: 3
  • Turkey: 2
  • Malaysia: 2
  • Spain: 1
  • United Kingdom: 1
  • Tunisia: 1
  • Taiwan: 1
  • Argentina: 1
  • Singapore: 1

By Industry

  • Manufacturing: 2
  • Public Administration: 2
  • Food and Beverage Services: 1
  • Industrial Machinery Manufacturing: 1
  • Higher Education: 1
  • Healthcare Services: 1
  • Health, Wellness & Fitness: 1
  • Food & Beverage: 1
  • Computer Hardware Manufacturing: 1
  • Architectural Services: 1

The concentration of attacks over the last 24 hours shows a continued focus on the United States and Canada, while the manufacturing sector remains a consistent high-value target for ransomware operators globally. Public administration also saw sustained pressure, which indicates diversified targeting.

Ransomware News

Topline

The past 24 hours saw several ransomware-related developments, including claims by the Qilin group, a GitHub breach impacting Grafana, an internal breach exposing The Gentlemen ransomware gang's operations, and new Q1 2026 threat intelligence.

Campaigns & Operations

The Qilin ransomware-as-a-service operation claimed Generation Life as a victim following a breach via an external service provider. Qilin's global victim tally reached 1,842. CoinbaseCartel claimed responsibility for breaching Grafana's GitHub environment using a stolen access token to download source code. Links were drawn to ShinyHunters/Lapsus$ affiliates. The Gentlemen ransomware gang experienced an internal breach in May 2026, exposing its backend infrastructure, affiliate program data, and operational tools, despite an estimated 1,570 victims. 3i Infotech Limited in India reported a ransomware cyber attack on May 16, 2026. A Check Point Research threat intelligence report also detailed breaches at Vodafone, West Pharmaceutical Services, and Foxconn's North American operations.

Vulnerabilities & TTPs

Threat intelligence showed critical vulnerabilities, including Claw Chain vulnerabilities in OpenClaw (CVE-2026-44112, CVSS 9.6), an unpatched macOS kernel exploit bypassing Memory Integrity on M5 chips, Windows zero-days YellowKey and GreenPlasma, and other flaws in NGINX (CVE-2026-42945), Catalyst SD-WAN (CVE-2026-20182), and Wi-Fi components (CVE-2026-28819). The Grafana breach showed the risk of GitHub token leakage and credential theft, while phishing campaigns deploying v0.dev to harvest credentials via Telegram bots continue to be prevalent.

Analyst Note

These incidents show a continued trend of supply chain targeting, credential theft for initial access, and persistent activity by established ransomware groups. Q1 2026 analyses from Check Point Research and Kaspersky confirmed widespread attacks, impacting thousands of users and introducing thousands of new ransomware variants.

Technical Takeaways

  • Increased Focus on Government Entities: Both Qilin and Audit groups targeted public administration bodies (Majlis perbandaran alor gajah, Trésor public). This indicates a persistent, high-value target sector.
  • Supply Chain & Credential Theft: The Grafana breach, attributed to CoinbaseCartel via a stolen GitHub token, shows how supply chain vulnerabilities and credential compromise are critical initial access vectors.
  • Group Activity: Qilin maintained a leading position with seven new victims, further extending its global reach. For more on Akira's activity, see our Ransomware Threat Update Intelligence - May 11.
  • Ongoing Q1 Threat Volume: Multiple threat intelligence reports show significant ransomware activity and new variant introductions in Q1 2026. This suggests a consistently high threat level extending into Q2.
  • Vulnerability Exploitation: Several critical CVEs across various platforms (OpenClaw, NGINX, Catalyst SD-WAN, Wi-Fi components) were flagged, which indicates potential for mass exploitation and continued TTP development by threat actors.

FAQ

Q: Which ransomware groups were most active in the last 24 hours?

A: In the past 24 hours, Qilin and Titan were the most active ransomware groups, each claiming 7 new victims. Other groups like AiLock, Akira, and Doommageddon also reported multiple new victims.

Q: What industries were most targeted by ransomware today?

A: Manufacturing and Construction & Engineering were the most frequently targeted industries, each seeing multiple attacks from various groups. Public Administration also experienced considerable targeting, including high-value government entities.

Q: What regions saw the most ransomware attacks today?

A: The United States recorded the highest number of ransomware victims with 9 incidents, followed by Canada with 3. Turkey and Malaysia also saw 2 reported victims each. This indicates a broad global distribution of attacks.

Q: Were there any major breaches or exposures involving ransomware gangs or major organizations?

A: Yes, the CoinbaseCartel group claimed responsibility for breaching Grafana's GitHub environment by stealing an access token and downloading source code. The Gentlemen ransomware gang also suffered an internal breach, exposing their backend infrastructure and operational data.

Q: What critical vulnerabilities were detailed in recent threat intelligence reports?

A: Recent reports flagged several critical vulnerabilities, including Claw Chain vulnerabilities in OpenClaw (CVE-2026-44112), unpatched Windows zero-days, and flaws in NGINX (CVE-2026-42945), Catalyst SD-WAN (CVE-2026-20182), and Wi-Fi components (CVE-2026-28819), and a macOS kernel exploit.