CYBERSECURITYTRACKER
TRACKING7,283 stories in this site build1,521 vulnerability news stories in this site build
Permanent story citation

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7613

As cited

Copy frozen at (site build).

ransomware

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Ransomware incidents in Japan grew 4.7% in the first half of 2026, with The Gentlemen emerging as the most active group and nearly doubling their leak site listings from 48 in January to 105 in July. Investigation of The Gentlemen's infrastructure revealed a multi-phase attack workflow targeting small and medium-sized enterprises through vulnerable VPNs, unpatched systems, and credential abuse, with evidence suggesting Russian-speaking threat actors. Qilin, the second most active group, deployed artificial intelligence (AI) to automate ransomware distribution and backup destruction across compromised networks.

Why it matters: Organizations in Japan with capital under JPY 1 billion are 80% of victims and must prioritize patching internet-facing VPNs and remote access systems, enforcing multifactor authentication (MFA), and monitoring for suspicious logins and lateral movement; practitioners should implement endpoint detection and response (EDR) monitoring for backup disabling and large-scale file modifications to detect attacks early.

VendorsMicrosoftCiscoVMwareVeeam
Actorslockbitqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary