Qilin, The Gentlemen & the Ransomware Long Tail: August 2026
The Gentlemen and Qilin led August 2026 ransomware claims, while 40 of 68 groups posted five victims or fewer. Why fragmentation makes defense harder.

Bitdefender counted 83 ransomware groups claiming victims in August 2026, up from 66 in July, with roughly 1,000 claimed victims — its second-highest monthly total since tracking started in 2023.
A 25% jump in active groups sounds like 17 new threats. Our leak-site data says it's mostly the ecosystem splintering into smaller pieces.

[Figure: Active ransomware groups, July vs August 2026]
What we tracked
Across the leak sites SINON monitors, August produced 725 claimed victims across 68 distinct groups. Our 68 is lower than Bitdefender's 83 — no two trackers watch the same set of sites — but the direction matches.
Two groups accounted for most of the volume. The Gentlemen claimed 101 victims and Qilin 80: between them, over a quarter of everything we logged. Coinbase Cartel (37), DireWolf (26), and INC Ransom (23) followed. The other 63 groups shared what was left.

[Figure: Top August groups by claimed victims]
Most groups are tiny
Of the 68 groups we saw in August, 40 claimed five victims or fewer. Fifteen claimed exactly one. Two claimed more than 40.

[Figure: August group-size distribution]
A group with one victim and a leak page is not a second Qilin. In the long tail we can see three things:
One-off extortion. A single breach, a single post, often no encryption.
Rebrands. "LockBit5" appears in our August data — a known brand on its latest version number, not a new operation.
Data-leak crews, not ransomware. ShinyHunters (20 claims) extorts stolen data without encrypting. CyberLeek spent August posting Grand Theft Auto 6 material. LeakedData and LeakNet are data brokers. All three land on the leak-site trackers that produce the group count, so they inflate it.
"83 groups" is accurate. It is not 83 mature encryption operations.
Why the fragmentation matters anyway
A crowd of small groups is harder to defend against than a few large ones, for two reasons.
First, intelligence goes stale faster. When five RaaS brands dominated, their tooling and negotiation patterns were documented and shared. A field that turns over most of its names every month erases that head start. The affiliate who breaches you may be running a leaked LockBit builder under a name that is 30 days old.
Second, small groups have no reputation to protect. An established operation has some incentive to delete data after payment because its next victim is watching. A one-victim crew that vanishes next month does not. Paying it is a worse bet — and there are more of them every month.
What to do about it
Track techniques and initial-access vectors, not brand names — the names now change monthly, the TTPs don't. Build a response plan that works without recognising the actor. Feed data-leak crews into the same monitoring as ransomware, since they use the same infrastructure. And watch the long tail: this month's one-victim newcomer is where the next Qilin starts.
Barriers to entry keep dropping — leaked builders and off-the-shelf kits mean anyone can stand up a leak page in an afternoon. August's 83 groups is not a spike to wait out. It's the baseline now.