Qilin appears across this database in 2025: most prolific operation overall at 25-1108, dominant in telecom at 25-1109, among the leading operations against US healthcare at 25-1215b, claimed at a Japanese brewer at 25-1101, behind the South Korean MSP campaign at 25-1110b, and claimed at a Canadian research organisation at 25-1127c.
No Specialisation Is Visible
Six sectors on three continents, with no discernible preference. This desk argued at 25-1215b that such breadth is an affiliate artefact: a platform does not choose targets, affiliates bring whatever access they have, and the largest platform receives the most of it.
The alternative reading — deliberate diversification — would predict some structure in the sequence. The corpus can see none.
Which Makes Actor-Based Defence Close To Useless
The corpus filed at 25-1004 that the top ten’s share of leak-site postings fell from 71% to 56% across three quarters, and concluded that controls should be organised around technique rather than actor.
Qilin sharpens that. Knowing this operation is active tells a defender nothing about their own exposure, because it is active everywhere. A threat intelligence product naming it is naming the weather.
And It Complicates The Counting
This desk recorded at 25-0808b that one activity set can carry two research designations, and that any tally of distinct actors risks overstating the population.
The reverse also holds. One brand appearing in six sectors may represent many independent affiliates with nothing in common except a platform — so a single name can understate the number of distinct operators. Graded medium: attribution throughout rests on claims and research assessments.
It synthesises attribution recorded across this database. Every underlying attribution is a group claim or a research assessment, not an identification. Corrections: corrections@forensicpost.com.
- BioPharma Services data breachBreachsense
- Record number of ransomware victims and groups in 2025Infosecurity Magazine