Qilin was reported as the most prolific ransomware operation of 2025, with a year-on-year increase in named victims described as around 420%.
That Is Affiliate Recruitment, Not Innovation
A fivefold increase in victims within a year cannot come from an operator working more efficiently. It comes from more people using the platform.
Ransomware-as-a-service separates the operation from the intrusion: the platform supplies encryption, negotiation, hosting and a leak site, and affiliates supply access and take a revenue share. Growth is therefore a function of how attractive the platform is to affiliates — payout terms, reliability, the credibility of its leak site.
Read against 25-0908, the picture resolves: LockBit’s affiliates went somewhere after Operation Cronos, and this is what the destination looks like in the numbers.
Which Makes Disruption A Commercial Question
If a platform’s scale depends on affiliate confidence, the effective intervention is the one that destroys it — demonstrating that the operators cannot protect their affiliates or will not pay them. Cronos did that, and 25-0908 records the brand nonetheless returning eighteen months later.
It is a more promising lever than arresting affiliates, of whom there is an effectively unlimited supply, and it targets the one genuinely scarce asset in the ecosystem.
The Usual Caution On The Figure
420% is growth in *named* victims, and 25-1230 sets out why that is a publication metric. A platform that lists aggressively will outgrow one that lists selectively without attacking more.
Graded medium. That Qilin was the most prolific lister of 2025 is well supported across sources; the precise multiple is not a measurement this desk would defend.
Compiled from published tracker analysis, listed below. Figures count named victims on leak sites, not confirmed intrusions. Corrections: corrections@forensicpost.com.
- Record number of ransomware victims and groups in 2025Infosecurity Magazine
- Ransomware groups claim record number of victims in 2025CIR Magazine