Threat reportRansomwareTL-2026-3183
GuidePoint GRIT Q3 2026 Ransomware Report: Record 2,760 Victims, New Top Group Edges Out Qilin, ShinyHunters Expands Extortion
GuidePoint GRIT Q3 2026 Ransomware Report (TL-2026-3183), also tracked as GRIT Q3 2026 Ransomware Report, is a high-severity ransomware operation, first published 2026-10-10. It is attributed to ShinyHunters with low confidence, affects PTC Windchill / FlexPLM, references 1 CVE (CVE-2026-12569), maps to 11 MITRE ATT&CK techniques (T1059.009, T1078.004, T1190), and is covered by 9 detection rules and 12 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 4ShinyHunters
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3183
- Threat ID
- TL-2026-3183
- Also known as
- GRIT Q3 2026 Ransomware Report
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- ShinyHunters, Clop, Medusa, The Gentlemen
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, technology, retail, health, finance, legal
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in GuidePoint GRIT Q3 2026 Ransomware Report
Malware and tooling: AgendaCrypt, Clop, MEDUSA - S1220, Rclone - S1040
How GuidePoint GRIT Q3 2026 Ransomware Report works
GuidePoint Security's GRIT Q3 2026 ransomware report page states 2,760 ransomware victims in Q3 2026, the most of any quarter and up 75% year over year. A new group narrowly surpassed Qilin as the leading operator, ShinyHunters expanded beyond traditional encryption, and payment rates fell by more than half while the average ransom payment rose.
GuidePoint Security's Research and Intelligence Team (GRIT) reports 2,760 ransomware victims in Q3 2026, the highest quarterly total ever recorded and a 75% year-over-year increase. The prior record was 2,287 victims in Q4 2025 (GRIT 2026 annual report). According to the GRIT Q3 2026 webinar page, a new group narrowly overtook Qilin as the leading operator; the group is not named in the content we could retrieve. ShinyHunters is described as rising and as operating beyond traditional encryption-based extortion. The page also describes an affiliate model that lowers the barrier to entry, attack windows shortened by AI capabilities, groups active across more countries than before, and one sector returning to the top 10. Payment rates fell by more than half, while the average ransom payment increased.
Collection limits: the GuidePoint blog post returned only its title with no article body, and the webinar page (scheduled October 22, 2026, 1:00pm ET) is a summary only. The identity of the new top group, the per-group victim counts, the sector and regional breakdowns and the exact payment figures could not be verified. Nothing has been inferred for them.
Corroborating context from the Bitdefender September 2026 Threat Debrief (August 2026 data): 1,000 claimed victims in the month, 83 active ransomware groups (a record, up from 66 in July), and Qilin reclaiming the top rank with 166 victims, with a focus on Germany, France and Italy and a U.S. federal organization also targeted. The Gentlemen ranked second. Bitdefender says ShinyHunters claimed 80+ victims in 2026 and that encryptors have not come into play in its recent attacks. Its methods are vishing, Okta SSO compromise and OAuth/SSO credential collection against Salesforce and Snowflake data. Bitdefender reports a healthcare breach in August 2026 (over 1TB, 200-300 million records claimed, $55 million demand) and a June cancer-facility breach with 10.9 million records released. ShinyHunters is associated with Scattered Spider and LAPSUS$ (MITRE ATT&CK G1057, aliases UNC6240, Bling Libra). Clop claimed 40+ victims in August by exploiting PTC Windchill and FlexPLM (CVE-2026-12569, unauthenticated access enabling RCE) and deploying JSP web shells. Medusa claimed 67 victims and was observed using Rclone paths added to Windows Defender exclusions. Press reporting says ShinyHunters breached Clop's Tor site on September 18, 2026 by exploiting a flaw in the Grav CMS and demanded an eight-figure bitcoin ransom; this comes from a search-result excerpt and the full article could not be fetched.
Defensive relevance: this is a trend and landscape report, not a single campaign. It carries no CVE of its own, no malware variants and no network IOCs. BeaconBeagle was not queried because no IP or domain indicators are sourced.
MITRE ATT&CK techniques used in TL-2026-3183
Execution
T1059.009 Command and Scripting Interpreter: Cloud API
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application
Collection
T1213.006 Data from Information Repositories: Databases; T1530 Data from Cloud Storage
Persistence
T1505.003 Server Software Component: Web Shell
Credential Access
T1528 Steal Application Access Token
Lateral Movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Reconnaissance
T1598 Phishing for Information
Impact
Affected products and versions in GuidePoint GRIT Q3 2026 Ransomware Report
- PTC — Windchill / FlexPLM
Vulnerable versions: Versions affected by CVE-2026-12569 (not enumerated in sources) - Salesforce — Salesforce platform (data theft via compromised SSO/OAuth)
- Snowflake — Snowflake data platform (data theft via compromised credentials)
- Okta — Okta SSO (compromise via vishing)
Remediation for GuidePoint GRIT Q3 2026 Ransomware Report
Patches
- Apply the PTC Windchill/FlexPLM fix for CVE-2026-12569 where affected
Immediate actions
- Audit OAuth application and token usage across SaaS platforms such as Salesforce and Snowflake
- Rotate credentials and tokens for exposed systems
- Restrict token creation and distribution to authorized accounts
- Train help desk and staff to verify identity on voice calls and SSO reset requests (vishing)
Workarounds
- Alert on new JSP web shells on Windchill servers
- Alert on exclusion paths added to Windows Defender that reference remote-copy tools
Longer-term hardening
- Segment SaaS platforms with unique logons and re-authentication prompts
- Monitor for bulk data exfiltration and abuse of data-sync and file-transfer tooling such as Rclone
- Prepare for non-encryption extortion, where backups alone do not prevent data-leak extortion
- Track breach notification obligations (PCI and PHI regulations)
CVEs associated with GuidePoint GRIT Q3 2026 Ransomware Report
Timeline of GuidePoint GRIT Q3 2026 Ransomware Report
- Q4 2025 set the previous quarterly record with 2,287 ransomware victims posted (GRIT 2026 annual report); December 2025 alone had 814 claimed attacks.
- June 2026 (day not stated): ShinyHunters breached a cancer facility and exfiltrated 10.9 million records, which were publicly released (Bitdefender).
- August 2026 (day not stated): 1,000 claimed victims and a record 83 active groups; Qilin reclaimed the top rank with 166 victims; Clop claimed 40+ victims via PTC Windchill/FlexPLM CVE-2026-12569 (Bitdefender).
- August 2026 (day not stated): ShinyHunters breached a healthcare organization, reportedly accessing over 1TB across Salesforce and Snowflake and claiming 200-300 million records in 4 days, with a $55 million demand (Bitdefender).
- ShinyHunters breached Clop's Tor site through a flaw in the Grav CMS, stole source code, logs and onion private keys, and demanded an eight-figure bitcoin ransom (press report; unverified full text).
- Q3 2026 ends with 2,760 ransomware victims, a record quarter and up 75% year over year; a new group narrowly passes Qilin (GRIT; group not named in retrievable content).
- GuidePoint GRIT presents the Q3 2026 Ransomware & Cyber Threat Report webinar, 1:00pm ET (Jason Baker, Grayson North, Justin Timothy, Nick Hyatt).
Sources cited for GuidePoint GRIT Q3 2026 Ransomware Report
- GRIT Q3 2026 Ransomware Report: Top Takeaways (GuidePoint Security blog; fetched content had no article body)
- GRIT Q3 2026 Ransomware and Cyber Threat Report webinar (webinar October 22, 2026)
- GuidePoint GRIT 2026 Ransomware & Cyber Threat Report (annual, covers 2025)
- Bitdefender Ransomware Threat Debrief, September 2026
- MITRE ATT&CK Group G1057: ShinyHunters
- ShinyHunters hacks Clop and threatens to extort the ransomware gang
- GuidePoint Security newsroom: Ransomware Victims and Threat Groups Surge to Record Levels
Detection coverage for TL-2026-3183
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3183 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.