Q3 2026 threat intelligence report
Ransomware named more organisations than in any other quarter this year. The ways in were edge appliances and ClickFix.
Read the reportExecutive summary
Ransomware groups named more organisations on their leak sites in Q3 2026 than in any other quarter this year. Our collection logged 3,072 listings, up 75% on Q2's 1,758, posted by 110 groups (79 in Q2) and naming organisations in 126 countries. August was the peak, with 1,214 listings, the busiest month of 2026.
The groups doing the posting changed over the quarter. The Gentlemen overtook Qilin as the most prolific brand, 396 listings to 366. Brands posting for the first time arrived at volume, led by Storm (78) and Global Secret Group (48). Manufacturing was the most-listed sector (465), ahead of technology (371), professional services (291) and healthcare (284). Organisations in the United States made up 33% of all listings.
Leak sites show who the groups claim to have breached. The highest-scoring reporting of the quarter described the ways in. Exploitation of network edge and security appliances accounted for 7 of the 10 highest-scoring clusters, led by the Cisco ISE zero-day at 89, the top score of the quarter. The other 6 concerned Cisco Secure Firewall Management Center, SonicWall SMA1000, Arista VeloCloud Orchestrator, Citrix NetScaler, Cisco Secure Email Gateway and F5 BIG-IP APM. Clusters with "zero-day" in the title rose from 34 to 67. CISA added 64 CVEs to its Known Exploited Vulnerabilities (KEV) catalogue, against 47 in Q2, and 7 of the 10 CVEs named in the most clusters were in KEV by the end of September.
The other route that grew was ClickFix, where a fake web page talks the user into pasting and running a command. Clusters describing ClickFix and its variants (FileFix, fake CAPTCHA pages) rose from 16 to 42. Their average threat score of 67 was the highest of any theme we track. Infostealers, the usual payload, held level at 74 clusters against 70, although StealC drew 22 of its 34 mentions in September.
AI coverage grew 6% to 1,527 clusters at an average score of 47, because most of it is product and policy news. The part of it turning into security reporting, on AI agents and MCP, grew faster: up 43% to 299 clusters.
Healthcare featured in both sources of data. Its leak-site listings doubled to 284 and press coverage of the sector rose 35% to 620 tagged articles. Government coverage rose 31% to 1,242, education 19% to 276 and retail 59% to 178. Coverage of most countries fell, most sharply Iran (down 62%) and Israel (down 63%), while Australia (up 25%) and Poland (up 14%) rose. Supply-chain coverage fell 35% from a Q2 total that included the Shai-Hulud npm reporting.
All of this comes from a quarter in which we collected less. ThreatCluster processed 74,026 articles from 11,144 sources and grouped them into 6,166 clusters. Ingestion fell 12% on Q2 while the source base grew 4%, and clusters fell 8%, leaving 12.0 articles per cluster against 12.6. Collection was also uneven, with August held down by a fault in our fetcher (see the collection notes). The rise in zero-day and edge-device clusters came despite that drop.
The quarter in numbers
| Q3 2026 | Q2 2026 | Change | |
|---|---|---|---|
| Articles processed | 74,026 | 84,398 | -12% |
| Clusters | 6,166 | 6,676 | -8% |
| Unique sources | 11,144 | 10,672 | +4% |
| Articles per day | 813 | 938 | -13% |
| Articles per cluster | 12.0 | 12.6 | |
| Clusters scoring 80+ | 37 | 18 | +106% |
| Clusters scoring 65+ | 1,877 | 2,099 | -11% |
| Leak-site victim listings | 3,072 | 1,758 | +75% |
| Groups posting | 110 | 79 | +39% |
| Countries named in listings | 126 | 100 | +26% |
| CVEs added to CISA KEV | 64 | 47 | +36% |
| Validated indicators extracted | 2,681 | 1,109 | +142% |
Monthly volume
July had 24,170 articles in 1,911 clusters at an average score of 51.5. August had 17,707 articles in 1,335 clusters at 55.3, so fewer clusters at a higher average. September had 32,149 articles in 2,730 clusters at 50.1, and produced 23 of the quarter's 37 clusters scoring 80 or above.
Severity
Clusters scoring 80 or above more than doubled, from 18 to 37, while those scoring 65 or above fell 11% to 1,877. The quarter's highest score was 89, for the Cisco ISE zero-day on 16 September.
Sources
Linuxsecurity contributed the most articles (4,571), followed by Sploitus (2,796), cve.org (1,764), Microsoft MSRC (1,324), Redpacketsecurity (993), GBHackers (903), Cybersecuritynews (895), 4sysops (642), The Hacker News (606) and BleepingComputer (599). Advisory and exploit feeds hold the top 4 places, which raises the share of vulnerability material in every count below.
The quarter's stories
Microsoft's Patch Tuesday release of 8 September gathered 927 articles into one cluster, the largest of the quarter. Next came the coordinated attack on Minnesota water utilities (198 articles, score 77), the Microsoft Edge vulnerability bulletin (190), EU and UK sanctions on Russian cyber networks (125, score 78) and the SonicWall SMA1000 zero-day (123, score 81).
77
81
81
71Ransomware and the leak sites
Figures in this section come from our own collection of listings on ransomware groups' leak sites, which covers 239 groups. Press coverage of ransomware follows at the end of the section.
Volume
Listings ran at 980 in July, 1,214 in August and 878 in September. The quarter's 3,072 compares with 1,758 in Q2 and 2,257 in Q1.
New groups
The largest groups posting for the first time were Storm (78), Global Secret Group (48), Orova (47), Crpxo (37), Panzer (35), Emperador (34), Dark Project (30), L Group (28), Zawoo (25), Booba Project (24), Majinahanashi (22) and Section9 (20). These 12 account for 428 listings, 14% of the quarter.
| Group | Q3 | Q2 | |
|---|---|---|---|
| The Gentlemen | 396 | 193 | |
| Qilin | 366 | 213 | |
| Cl0p | 114 | 27 or fewer | |
| INC Ransom | 112 | 73 | |
| Krybit | 95 | 50 | |
| DeadLock | 91 | 27 or fewer | |
| Akira | 90 | 102 | |
| Storm | 78 | new | |
| SafePay | 77 | 43 | |
| DragonForce | 69 | 132 | |
| Direwolf | 60 | 27 or fewer | |
| LockBit 5.0 | 59 | 87 | |
| Settra | 56 | 27 or fewer | |
| Play | 50 | 34 | |
| Global Secret Group | 48 | new |
"27 or fewer" marks groups outside the Q2 top 15, whose lowest entry had 27 listings.
The Gentlemen doubled its listings and took first place from Qilin. DragonForce fell 48% and LockBit 5.0 fell 32%. Cl0p moved from outside the Q2 top 15 to third.
Vulnerabilities and zero-days
Clusters with "zero-day" in the title rose from 34 in Q2 to 67. Network edge or security appliances account for 7 of the 9 highest-scoring exploitation clusters, and in September alone we clustered in-the-wild exploitation of five of them. Clusters on edge devices and VPNs rose 34% over the quarter, from 124 to 166.
- 2 SepSonicWall SMA1000
- 14 SepCisco Secure Email Gateway
- 16 SepCisco ISE
- 22 SepF5 BIG-IP APM
- 26 to 28 SepCitrix NetScaler
89
81
82
82
82
84The quarter's exploitation clusters by score, whether or not the title uses the term "zero-day".
| Cluster | Date | Score | Articles | Edge |
|---|---|---|---|---|
| Cisco ISE zero-day under active exploitation | 16 Sep | 89 | 59 | yes |
| Cisco FMC authentication bypass exploited | Sep | 88 | 69 | yes |
| SonicWall SMA1000 vulnerabilities exploited | Sep | 87 | 42 | yes |
| Arista VeloCloud Orchestrator command injection exploited | Sep | 84 | 12 | yes |
| Citrix NetScaler zero-days exploited | 28 Sep | 82 | 67 | yes |
| Cisco Secure Email Gateway zero-day exploited | 14 Sep | 82 | 37 | yes |
| F5 BIG-IP APM zero-day, remote code execution | 22 Sep | 82 | 25 | yes |
| Lazarus exploits Windows zero-day against the defence sector | 12 Aug | 81 | 21 | |
| GitLab vulnerabilities exploited within hours of disclosure | Sep | 81 | 67 |
KEV and CVE volume
CVEs added to the CISA KEV catalogue in Q3 against Q2.
CVEs published by the CVE programme in the quarter, against 20,871 in Q2, a rise of 81% that is independent of our collection.
Most-covered CVEs that were in KEV by the end of September.
Actors, malware and techniques
Articles in which the group was tagged.
Groups
Lazarus Group led with 100 articles. Its August campaign against the defence sector, using a Windows zero-day, scored 81. APT28 followed with 72, then Kimsuky 62, APT29 50, ShinyHunters 41, Sandworm 34, Turla 30, Scattered Spider 26, Mustang Panda 24 and Volt Typhoon 23.
Malware
Pegasus led with 108 mentions, ahead of Mirai (42), Vidar (40), StealC (34), Lumma under two tags (LummaC2 and Lumma Stealer, 32 each), RedLine (28) and Cobalt Strike (28). StealC rose in September, which accounted for 22 of its 34 mentions.
Of the families first seen this quarter, those with sustained reporting were WeWorm (15 articles), NoviSpy (13), SparroWocky (12), RatHat (12), NeedyMantis (10) and RevStealer (10).
Themes and emerging technology
Clusters whose title or summary carries the theme, Q3 against Q2, with the average threat score of the Q3 clusters.
| Theme | Q3 | Q2 | Change | Avg score | |
|---|---|---|---|---|---|
| AI and LLMs (all) | 1,527 | 1,443 | +6% | 47 | |
| AI agents and MCP | 299 | 209 | +43% | 48 | |
| Deepfakes | 198 | 182 | +9% | 51 | |
| ClickFix, FileFix, fake CAPTCHA | 42 | 16 | +163% | 67 | |
| Zero-days | 128 | 88 | +45% | 65 | |
| Edge devices and VPNs | 166 | 124 | +34% | 59 | |
| Infostealers | 74 | 70 | +6% | 65 | |
| Cloud, identity and SaaS | 229 | 293 | -22% | 51 | |
| Supply chain (incl. npm, PyPI) | 210 | 322 | -35% | 54 | |
| Quantum | 115 | 152 | -24% | 28 |
The zero-day row counts title or summary matches, so it is broader than the title-only count of 67 used above.
AI is the largest theme by volume and among the lowest-scoring, because most of it is product and policy news. Within it, the agent and MCP subset carries the security reporting: vulnerabilities in MCP servers, agent hijacking, prompt injection through tool results, and organisations deploying agents without governance in place. Quantum coverage is almost entirely policy and vendor announcements, with an average score of 28. ClickFix is small and growing fast, and has the highest average score in the table.
Carried into Q4
- Agentic tooling as an attack surface, with CVEs in MCP and agent frameworks and clusters describing malware aimed at AI coding assistants.
- Deepfake-enabled fraud in executive impersonation and recruitment scams.
- Edge-device exploitation, with appliances from SonicWall, Cisco, Arista, F5 and Citrix all exploited in the wild during September.
- Attacks on water and other municipal utilities. The Minnesota cluster was the second most-covered of the quarter.
The platform in Q3
Validated indicators extracted from Q3 reporting, 2,681 in all. The false-positive gate rejected a further 12,249 candidates.
Corpus
500 of our 504 configured feeds were active at quarter end. Of the 6,166 clusters built, 87 (1.4%) were later marked out of scope by the new scope gate.
Users and API
Registered users grew 58% over the quarter, with September the biggest sign-up month to date, and the number of API keys in issue rose thirteen-fold. External weekly request volume grew 26 times between the week of 31 August and the week of 21 September. MCP tool calls rose 72% from July to September.
Distribution
threatcluster-mcp had 505 npm downloads in the quarter. On PyPI, where it appeared on 28 September, it had about 1,000 downloads in its first 3 days. Our 3 Hugging Face datasets (incident clusters, leak-site victims, CVE exploitation signals) have 221 downloads to date. The LLM recency benchmark published on 16 September found 8 models scored 0 of 150 on summer ransomware questions unaided and 158 of 158 with ThreatCluster records.
About this report
ThreatCluster collects security reporting from open sources and groups it into clusters using density-based semantic clustering. We then tag and count the entities in each cluster. "Mentions" is the number of distinct articles in which an entity was tagged, which measures attention in open reporting. Leak-site figures count listings on the groups' own sites. A listing is the group's claim, and some are false or recycled.
Collection notes
Ingestion fell 12% in Q3 after rising 55% in Q2. A memory fault in our fetcher depressed August's collection. In September, a source-retirement rule removed 121 feeds on the 11th until they were restored, and the summarisation service lapsed on the 26th. Every source was re-enabled on the 27th.
The source mix has moved towards advisory and exploit feeds, which lifts vulnerability counts relative to news.
On 1 October we introduced a relevance filter that removes entities tagged from sidebars, cited pages and roundups. The Q3 figures were computed after applying it to the whole corpus. The Q2 report's figures predate it, so the two quarters' entity counts are not strictly comparable.
League tables merge known aliases to canonical names. First-seen tallies do not merge aliases, and we have not used them for headline findings.
"Unique sources" counts every distinct publishing domain that appeared in the quarter; "configured feeds" counts the feeds we poll. One feed can surface many domains.