# Q3 2026 Record Ransomware Surge: 2,627 Claimed Attacks, Qilin and The Gentlemen Lead, Clop Resurgence via PTC Windchill CVE-2026-12569

> Comparitech data shows a record 2,627 claimed ransomware attacks in Q3 2026 (61% above Q3 2025), led by Qilin (357) and The Gentlemen (342), with Clop jumping from 1 claimed attack in Q2 to 48 after exploiting PTC Windchill/FlexPLM CVE-2026-12569. Finance, technology, education, healthcare, government and utilities all grew quarter over quarter.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3135
- **ID:** TL-2026-3135
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Qilin
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-12569, CVE-2025-3248, CVE-2021-29441, CVE-2024-55591, CVE-2024-1708

## Description

Comparitech's Q3 2026 ransomware roundup (published 2026-10-07; reported by Infosecurity Magazine on 2026-10-09) logged 2,627 claimed ransomware attacks, nearly 29 per day, a record quarter. Only 247 were confirmed by victims; 2,380 remain unconfirmed claims. The quarter-over-quarter increase is reported as 27% by Infosecurity Magazine and 29% by Comparitech (Q2 2026: 2,030 attacks); year-over-year growth is 61% (Q3 2025: 1,636). Average ransom demand was $602,400 and median $150,000; more than 641 TB of data was reportedly stolen, and 1,611,971 records were compromised in confirmed attacks.

Qilin led with 357 claims (27 confirmed, +24% vs Q2) followed by The Gentlemen with 342 (26 confirmed, +29%). Clop rose from 1 claimed attack in Q2 to 48 in Q3, and Direwolf rose 1,450%. Sector growth versus Q2: finance +72%, technology +70%, education +50% (75 attacks), healthcare +39% (188), government +36% (124) and utilities +32%; businesses accounted for 2,234 attacks (+27%). The US had 1,066 attacks (41%, +34%), followed by Germany (121), Canada (103), Italy (86) and India (80, +116%); Argentina rose 150%. The largest reported demands were $12.3M against Stadler Rail by Everest (July 2026), $2.3M against the State of Berlin and $674,000 against Kreishandwerkerschaft Borken, both by Rhysida. Largest confirmed data breaches: Saber Healthcare Group (427,084 people), Austrian Chamber of Labour (270,000) and Greenberg Traurig LLP (150,000).

The Clop resurgence is tied to a data-theft extortion campaign against internet-exposed PTC Windchill and FlexPLM instances exploiting CVE-2026-12569 (CVSS 9.3, unauthenticated RCE via unsafe deserialization/improper input validation). PTC warned on 2026-06-17 and patched on 2026-06-18, CISA added the flaw to KEV on 2026-06-25, and JSP webshells (hex-named, under Windchill login paths) were used to enumerate filesystems and exfiltrate engineering data. Extortion emails were sent from previously compromised accounts to many employees of victim organizations, and GE and Philips confirmed they were investigating Clop claims. Targeted sectors include aerospace, defense, automotive, heavy machinery, retail/apparel and medtech.

Other actors and trends reported for the quarter: The Gentlemen (RaaS-style operation tracked by PRODAFT as led by LARVA-368; active since March 2025) uses Fortinet FortiGate exploitation (CVE-2024-55591), stolen VPN/OWA credentials, Mimikatz variants, a custom G-BOT C2 framework, a modified Velociraptor, Rclone, AnyDesk, PsExec/WMI/GPO lateral movement, and an XChaCha20/Curve25519 cross-platform locker (Windows, Linux, NAS, BSD, ESXi) dropping README-GENTLEMEN.txt. Qilin affiliates use ConnectWise ScreenConnect (CVE-2024-1708) and VPN appliance flaws, Cobalt Strike, RDP/PsExec/WMI, shadow copy removal, and a Rust encryptor. The JadePuffer campaign (Sysdig, July 2026) is the first documented ransomware operation driven end-to-end by an LLM agent: it exploited Langflow CVE-2025-3248, pivoted to Alibaba Nacos (CVE-2021-29441 auth bypass) and MySQL, encrypted 1,342 Nacos configuration items with AES_ENCRYPT(), installed a cron beacon, and later staged the Go-based ENCFORGE binary aimed at AI/ML artifacts. The Gentlemen also reportedly targeted clients of MIP Holdings (South Africa, breached June 2026) via triple extortion.

Caveat: the headline statistics come from leak-site claims, most of which are unconfirmed. Network IOCs (IPs, domains, hashes) are not published in the primary sources; IOCs below are family, tool, filename, path and behavioral indicators only.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1078 Valid Accounts
- T1047 Windows Management Instrumentation
- T1059.001 PowerShell
- T1569.002 Service Execution
- T1505.003 Server Software Component: Web Shell
- T1053.003 Scheduled Task/Job: Cron
- T1484.001 Domain or Tenant Policy Modification: Group Policy Modification
- T1685.005 Clear Windows Event Logs
- T1685 Disable or Modify Tools
- T1003 OS Credential Dumping
- T1021.001 Remote Services: Remote Desktop Protocol
- T1219 Remote Access Tools
- T1567 Exfiltration Over Web Service
- T1490 Inhibit System Recovery
- T1485 Data Destruction

## Sources

- [Q3 2026 Sets New Record for Ransomware Attacks (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/q3-new-record-ransomware/)
- [Ransomware roundup Q3 2026: stats on attacks, ransoms and active gangs (Comparitech)](https://www.comparitech.com/news/ransomware-roundup-q3-2026-stats-on-attacks-ransoms-and-active-gangs)
- [Clop ransomware targets Windchill, FlexPLM in data theft attacks (BleepingComputer)](https://bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks)
- [JSP webshells being dropped on unpatched PTC Windchill instances (Help Net Security)](https://www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/)
- [The Gentlemen ransomware: Inside one of the fastest-growing extortion operations (Barracuda)](https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans)
- [The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm (The Hacker News)](https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html)
- [JadePuffer ransomware used AI agent to automate entire attack (BleepingComputer)](https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack)
- [JadePuffer Ransomware - First Reported Use of Agentic Ransomware (WaterISAC, TLP:CLEAR)](https://www.waterisac.org/tlpclear-jadepuffer-ransomware-first-reported-use-of-agentic-ransomware)
- [Watch Guard! Qilin affiliate exploits network appliances for initial access (CtrlAltIntel)](https://ctrlaltintel.com/research/Qilin/)
- [Qilin ransomware: Attack Chain, MITRE ATT&CK TTPs, and Incident Response Guide (Proven Data)](https://www.provendata.com/blog/qilin-ransomware)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3135
