Manilatimes Record-High Ransomware Activity Reported Globally and in the Philippines
Article Content
- •Global ransomware victims reached 2,760 in Q3 2026, a 75% increase from last year.
- •The Philippines saw 31 ransomware claims in 2026, exceeding totals from the previous two years combined.
- •Qilin and the Gentlemen were the most active ransomware groups, with opportunistic targeting observed.
GuidePoint Security's Q3 2026 report indicates a record 2,760 ransomware victims globally, marking a 75% increase year-over-year. The number of active ransomware groups rose to 112, with the Gentlemen and Qilin being the most active. Despite a decline in payment rates, the average ransom payment increased by 34%. In the Philippines, ransomware claims surged, with 31 public claims recorded from January to August 2026, surpassing totals from 2024 and 2025 combined. The report noted that opportunistic targeting remains prevalent, with no single group dominating the landscape. Qilin was responsible for nine claims, contributing significantly to the rise. The overall threat landscape in the Philippines included 264 cyber incidents, with government agencies being the most affected. The use of AI in cybercrime was noted, although it primarily related to fraud rather than technical intrusions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Qilin and ShinyHunters in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What sectors are most affected by ransomware?
How many ransomware groups are currently active?
What measures can organizations take to mitigate ransomware risks?
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
CISA Adds Multiple Exploited Flaws in AI and Networking Tools to KEV Catalog On September 11, 2026, CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities include CVE-2026-42016, which has a CVSS score of 8.1. This update follows the addition of…