Ransomware surges in 2026: The Gentlemen rises as top threat to Japanese organizations and global manufacturing, while Qilin reportedly adopts AI
Cisco Talos counted 90 ransomware incidents against Japanese organizations in January-July 2026, led by The Gentlemen with 14 incidents, while Black Kite recorded 1,183 disclosed manufacturing/distribution incidents in the first seven months of 2026, up 40%…
Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year (an average of 13 incidents monthly), with manufacturing the most affected sector at 34% of victims, followed by information/communications at 11%, and firms capitalized under JPY 1 billion representing about 78% of victims. The Gentlemen was the most active group in Japan with 14 incidents, followed by Qilin and SafePay with seven each; Talos also notes Qilin is leveraging AI to improve operational efficiency. Globally, Black Kite's 2026 Manufacturing & Distribution Ransomware Report counted 1,183 disclosed incidents in the first seven months of 2026, a 40% year-over-year increase led by Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom; the two reports' rankings differ by scope, with Talos covering Japanese organizations overall and Black Kite covering global manufacturing. The Gentlemen, first observed in September 2025, operates RaaS with double extortion (with possible Russian-speaking involvement), saw its leak-site listings grow 2.2x from 48 in January to 105 in July, claimed 142 manufacturing victims, and was behind 12% of this year's manufacturing attacks per Black Kite. European targeting grew 85%, with Germany (77), Italy (57), the UK (43), and France (40) as top victims, while the US share fell from 52% to 35%. Black Kite cites the Jaguar Land Rover attack — estimated by the UK Cyber Monitoring Centre at £1.9 billion in impact with 4,000 announced job cuts, disrupting roughly 1,000 vehicles daily and affecting 5,000+ companies — as the most economically damaging cyberattack in UK history, and notes the UK Cyber Security and Resilience Bill aims to curb downstream supply chain risk.
- Cisco Talos: 90 ransomware incidents against Japanese organizations January-July 2026, up about 4.7% year over year, averaging 13 incidents monthly
- Talos: The Gentlemen was the most active group in Japan with 14 incidents; Qilin and SafePay followed with seven each
- Talos: Qilin is leveraging AI to improve operational efficiency
- Talos: The Gentlemen leak-site listings rose 2.2x, from 48 in January 2026 to 105 in July 2026
- Talos: Manufacturing accounted for 34% of Japanese victims, information/communications 11%; firms capitalized under JPY 1 billion represented about 78% of victims
- Talos: The Gentlemen operates RaaS with double extortion, with possible Russian-speaking involvement
- Black Kite: 1,183 disclosed manufacturing/distribution ransomware incidents in the first seven months of 2026, a 40% year-over-year increase, led by Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom
- Black Kite: The Gentlemen, first observed in September 2025, claimed 142 manufacturing victims and was behind 12% of 2026 manufacturing attacks
Coverage timelineoldest first · each row is one article
- · 4h agoRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Cisco Talos· 62
Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.
- · 1h agoRansomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
SecurityWeek· 55
Black Kite reports manufacturing ransomware incidents up 40% in 2026, with new gang The Gentlemen responsible for 12% of attacks.