Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.
Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Rhysida ransomware hit Berlin's state government weeks before the September 20 election, claiming 5.79 TB stolen; officials refused the ransom.
Berlin's government confirmed an August cyberattack on its administrative network, with data exfiltrated between August 7 and August 12 and departments isolated on August 17. The Rhysida group claimed responsibility on August 28, alleging theft of 5.79 TB and 1.44 million files including personal data on 12,076 individuals, payroll files, plaintext credentials, and vulnerability analyses of Berlin's water supply. Officials said election systems were not affected and refused to pay; Rhysida has claimed roughly 280 victims since 2023, entering via VPNs without MFA, Zerologon, or phishing.