Desk live·
ForensicPost
Ransomware/Actors/File 25-1108

Qilin Named Victims Rose 420% to Lead All Operations in 2025

Qilin was the most prolific operation of 2025, with reporting describing a 420% year-on-year increase in named victims. Growth like that is an operating model, not a technique.

Constructed geometry · not a chart of case data
TargetRansomware ecosystem
ActorQilin
S. Rosler11 min readConfidence: medium2 sources reviewed

Qilin was reported as the most prolific ransomware operation of 2025, with a year-on-year increase in named victims described as around 420%.

That Is Affiliate Recruitment, Not Innovation

A fivefold increase in victims within a year cannot come from an operator working more efficiently. It comes from more people using the platform.

Ransomware-as-a-service separates the operation from the intrusion: the platform supplies encryption, negotiation, hosting and a leak site, and affiliates supply access and take a revenue share. Growth is therefore a function of how attractive the platform is to affiliates — payout terms, reliability, the credibility of its leak site.

Read against 25-0908, the picture resolves: LockBit’s affiliates went somewhere after Operation Cronos, and this is what the destination looks like in the numbers.

Which Makes Disruption A Commercial Question

If a platform’s scale depends on affiliate confidence, the effective intervention is the one that destroys it — demonstrating that the operators cannot protect their affiliates or will not pay them. Cronos did that, and 25-0908 records the brand nonetheless returning eighteen months later.

It is a more promising lever than arresting affiliates, of whom there is an effectively unlimited supply, and it targets the one genuinely scarce asset in the ecosystem.

The Usual Caution On The Figure

420% is growth in *named* victims, and 25-1230 sets out why that is a publication metric. A platform that lists aggressively will outgrow one that lists selectively without attacking more.

Graded medium. That Qilin was the most prolific lister of 2025 is well supported across sources; the precise multiple is not a measurement this desk would defend.

How we reported this

Compiled from published tracker analysis, listed below. Figures count named victims on leak sites, not confirmed intrusions. Corrections: corrections@forensicpost.com.

Sources
  1. Record number of ransomware victims and groups in 2025Infosecurity Magazine
  2. Ransomware groups claim record number of victims in 2025CIR Magazine
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary