Exploited in the wild The Gentlemen ransomware Qilin Cisco Talos ai-ml
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
CVE Tools coverage
Cisco Talos recorded 90 ransomware incidents affecting Japanese organizations from January through July 2026, with The Gentlemen the most frequently observed group and Qilin second. Talos linked The Gentlemen infrastructure to reconnaissance, credential theft, lateral movement, data theft and attempted exploitation of CVE-2025-2479 and CVE-2025-24799, while Qilin scripts showed signs of generative AI assistance for ransomware deployment and backup destruction.
Thursday, September 17, 2026 06:00
- Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.
- In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.
- Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year.
- The total number of listings on The Gentlemen’s leak site increased from 48 in January to 105 in July, representing approximately a 2.2-fold increase in activity. Additionally, there is a possibility that Russian-speaking individuals are involved in The Gentlemen’s attacks.
- Qilin, which recorded the second-highest number of observed incidents in 2026 after The Gentlemen, is leveraging AI to improve the efficiency of its operations.…