Microsoft, Novo Nordisk and NSW Rural Fire Service: The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]

Microsoft, Novo Nordisk and NSW Rural Fire Service: The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]

June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a Fragmented Threat Landscape

In June 2026, the ransomware ecosystem saw a dramatic shift as The Gentlemen, a previously obscure group, claimed 94 victims enough to unseat Qilin from its five-month reign as the most active ransomware operation. The shakeup reflects a broader trend: a 9% month-over-month increase in ransomware attacks, with 707 victims across 87 countries, according to tracking firm Breachsense.

A Volatile Leaderboard

The top three groups in June accounted for over a third of all attacks, underscoring how a small number of well-resourced affiliate crews can rapidly reshape the threat landscape:

  • 1st: The Gentlemen (94 victims) – A newcomer that surged to the top in its first major tracked month.
  • 2nd: DeadLock (81 victims) – Another new entrant, debuting at second place, likely absorbing affiliates from disbanded operations.
  • 3rd: Qilin (71 victims) – Dropped after a five-month dominance, though still a major player.

This churn is typical of the ransomware-as-a-service (RaaS) model, where groups rebrand, dissolve, or lose affiliates to rivals almost overnight. The rapid rise of The Gentlemen and DeadLock suggests they may have poached affiliates from established crews by offering better payouts or infrastructure.

Key Incidents and Targets

June’s attacks highlighted ransomware’s focus on high-value data and critical infrastructure:

  • FulcrumSec demanded $25 million from Novo Nordisk, stealing 1.3 TB of clinical trial data and AI models a prime target for resale or secondary extortion.
  • Nova targeted Australia’s NSW Rural Fire Service, exfiltrating 300 GB of sensitive data, demonstrating ransomware’s persistent threat to public-sector organizations.
  • Unpatched vulnerabilities remained the primary entry point, with CVE-2026-20230 (Cisco Unified CM) and CVE-2026-41089 (Windows Netlogon) exploited to gain initial access.

Payment Rates Decline, Extortion Tactics Evolve

Despite the surge in attacks, 69% of victims refused to pay in 2026 a trend driven by better backups, stricter cyber insurance policies, and law enforcement discouragement. This has pushed gangs toward data-theft-only extortion, where stolen data (rather than encryption) is the primary leverage.

Regulatory and Market Impact

The 9% rise in attacks and ransomware’s 48% share of all breaches (per Verizon’s 2026 DBIR) are pressuring cyber insurance underwriters to tighten requirements, while security teams must adapt to rapidly shifting threat groups. The fragmented RaaS market where new groups can dominate within weeks means defenders must focus on behavior-based detection rather than tracking specific gangs.

Outlook for 2026

The rest of the year is expected to see:

  • Further leaderboard churn, with new groups likely cracking the top three.
  • Continued decline in payment rates, accelerating the shift to data-theft extortion.
  • Persistent exploitation of unpatched edge devices, keeping patch management a critical priority.
  • Faster disclosures due to stricter regulatory reporting, making monthly victim counts appear more volatile.

June’s surge is less an anomaly than a continuation of the post-2024 ransomware landscape, where no group stays on top for long, affiliates move quickly, and defenders must prioritize fundamental security controls over chasing the latest threat actor.

Source: https://tech-insider.org/the-gentlemen-ransomware-tops-qilin-94-victims-2026/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-threat-intelligence

Novo Nordisk TPRM report: https://www.rankiteo.com/company/novotech

NSW Rural Fire Service TPRM report: https://www.rankiteo.com/company/brunswick-group

"id": "micnovbru1784427884",
"linkid": "microsoft-threat-intelligence, novotech, brunswick-group",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'name': 'Novo Nordisk',
                        'size': 'Large',
                        'type': 'Pharmaceutical'},
                       {'industry': 'Public Safety',
                        'location': 'Australia',
                        'name': 'NSW Rural Fire Service',
                        'size': 'Large',
                        'type': 'Government'}],
 'attack_vector': ['Unpatched vulnerabilities',
                   'Exploitation of CVE-2026-20230 (Cisco Unified CM)',
                   'Exploitation of CVE-2026-41089 (Windows Netlogon)'],
 'data_breach': {'data_encryption': 'Partial (ransomware cases)',
                 'data_exfiltration': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Clinical trial data',
                                              'AI models',
                                              'Sensitive operational data']},
 'date_detected': '2026-06-01',
 'date_publicly_disclosed': '2026-06-30',
 'description': 'In June 2026, the ransomware ecosystem saw a dramatic shift '
                'as The Gentlemen, a previously obscure group, claimed 94 '
                'victims, unseating Qilin from its five-month reign. The surge '
                'reflects a 9% month-over-month increase in ransomware '
                'attacks, with 707 victims across 87 countries. The top three '
                'groups accounted for over a third of all attacks, '
                'highlighting the volatility of the ransomware-as-a-service '
                '(RaaS) model. Key incidents included high-profile attacks on '
                'Novo Nordisk and Australia’s NSW Rural Fire Service, with '
                'unpatched vulnerabilities remaining the primary entry point. '
                'Payment rates declined to 31%, pushing gangs toward '
                'data-theft-only extortion.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': ['1.3 TB of clinical trial data and AI models '
                                 '(Novo Nordisk)',
                                 '300 GB of sensitive data (NSW Rural Fire '
                                 'Service)']},
 'initial_access_broker': {'entry_point': 'Unpatched vulnerabilities',
                           'high_value_targets': ['Novo Nordisk',
                                                  'NSW Rural Fire Service']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The fragmented RaaS market requires defenders to focus on '
                    'behavior-based detection rather than tracking specific '
                    'gangs. Unpatched vulnerabilities remain a critical entry '
                    'point, and payment rates continue to decline due to '
                    'better backups and stricter cyber insurance policies.',
 'motivation': ['Financial gain', 'Data extortion', 'Secondary extortion'],
 'post_incident_analysis': {'corrective_actions': ['Enhanced patch management',
                                                   'Behavior-based detection '
                                                   'implementation',
                                                   'Improved backup '
                                                   'strategies'],
                            'root_causes': ['Unpatched vulnerabilities '
                                            '(CVE-2026-20230, CVE-2026-41089)',
                                            'Fragmented RaaS affiliate model '
                                            'enabling rapid group shifts']},
 'ransomware': {'data_encryption': 'Partial',
                'data_exfiltration': 'Yes',
                'ransom_demanded': '$25 million (Novo Nordisk)'},
 'recommendations': ['Prioritize patch management for edge devices and '
                     'critical systems.',
                     'Implement behavior-based detection to counter rapidly '
                     'shifting threat groups.',
                     'Enhance backup strategies to reduce reliance on ransom '
                     'payments.',
                     'Adopt stricter cyber insurance requirements to mitigate '
                     'financial risks.'],
 'references': [{'date_accessed': '2026-06-30', 'source': 'Breachsense'},
                {'date_accessed': '2026-06-30', 'source': 'Verizon 2026 DBIR'}],
 'threat_actor': ['The Gentlemen', 'DeadLock', 'Qilin', 'FulcrumSec', 'Nova'],
 'title': 'June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a '
          'Fragmented Threat Landscape',
 'type': 'Ransomware',
 'vulnerability_exploited': ['CVE-2026-20230', 'CVE-2026-41089']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.