Qilin Ransomware Claims Two New Australian Victims: Reddrop Group and Zig Inge Group
The Qilin ransomware-as-a-service (RaaS) operation has added two Australian organizations to its victim list: the Reddrop Group, a grocery store collective, and the Zig Inge Group, which operates the Prospect Hill Camberwell retirement community.
Reddrop was listed on September 16, followed by Zig Inge on September 24. Neither organization has responded to requests for comment, and the ransomware affiliate behind the claims has not released further details, including the scope of the breaches or evidence of the attacks.
Qilin, currently the world’s most active ransomware group, has recorded 2,323 victims since its emergence in 2022, averaging 100 listings per month in 2024. Operating under a RaaS model, the group provides affiliates with ransomware infrastructure in exchange for a share of ransom payments. Recent activity includes exploiting a vulnerability (CVE-2026-20316) in Cisco’s Secure Firewall Management Center, where attackers used static credentials to gain access, conduct reconnaissance, and deploy ransomware.
Reddrop Group, based in Alexandra, Victoria, employs over 1,300 people and operates 27 supermarkets under brands like Foodworks and IGA. The Zig Inge Group, a family-owned investment business, manages IPLiving, which oversees three Victorian retirement villages, including Prospect Hill Village in Camberwell.
This follows Qilin’s previous targeting of the Thorndale Foundation, a not-for-profit, earlier in September. The group’s continued expansion in Australia underscores its aggressive global campaign.
Reddrop Group TPRM report: https://www.rankiteo.com/company/reddropgroup
Zig Inge Group TPRM report: https://www.rankiteo.com/company/zig-inge-group
"id": "redzig1790562261",
"linkid": "reddropgroup, zig-inge-group",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Retail (Supermarkets)',
'location': 'Alexandra, Victoria, Australia',
'name': 'Reddrop Group',
'size': '1,300+ employees',
'type': 'Grocery store collective'},
{'industry': 'Healthcare / Aged Care',
'location': 'Victoria, Australia',
'name': 'Zig Inge Group',
'type': 'Investment business / Retirement community '
'operator'}],
'attack_vector': 'Exploitation of vulnerability (CVE-2026-20316) in Cisco’s '
'Secure Firewall Management Center using static credentials',
'data_breach': {'data_encryption': 'Yes (Ransomware)'},
'date_publicly_disclosed': '2024-09-24',
'description': 'The Qilin ransomware-as-a-service (RaaS) operation has added '
'two Australian organizations to its victim list: the Reddrop '
'Group, a grocery store collective, and the Zig Inge Group, '
'which operates the Prospect Hill Camberwell retirement '
'community. Reddrop was listed on September 16, followed by '
'Zig Inge on September 24. Neither organization has responded '
'to requests for comment, and the ransomware affiliate behind '
'the claims has not released further details, including the '
'scope of the breaches or evidence of the attacks.',
'initial_access_broker': {'entry_point': 'Exploitation of CVE-2026-20316 in '
'Cisco’s Secure Firewall Management '
'Center'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (Ransomware-as-a-Service)',
'ransomware': {'data_encryption': 'Yes', 'ransomware_strain': 'Qilin'},
'references': [{'source': 'Cyber Incident Description'}],
'threat_actor': 'Qilin Ransomware Group',
'title': 'Qilin Ransomware Claims Two New Australian Victims: Reddrop Group '
'and Zig Inge Group',
'type': 'Ransomware',
'vulnerability_exploited': 'CVE-2026-20316'}