Threat reportRansomwareTL-2026-3183

GuidePoint GRIT Q3 2026 Ransomware Report: Record 2,760 Victims, New Top Group Edges Out Qilin, ShinyHunters Expands Extortion

highACTIVE

GuidePoint GRIT Q3 2026 Ransomware Report (TL-2026-3183), also tracked as GRIT Q3 2026 Ransomware Report, is a high-severity ransomware operation, first published 2026-10-10. It is attributed to ShinyHunters with low confidence, affects PTC Windchill / FlexPLM, references 1 CVE (CVE-2026-12569), maps to 11 MITRE ATT&CK techniques (T1059.009, T1078.004, T1190), and is covered by 9 detection rules and 12 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
4ShinyHunters
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3183

Threat ID
TL-2026-3183
Also known as
GRIT Q3 2026 Ransomware Report
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
ShinyHunters, Clop, Medusa, The Gentlemen
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
manufacturing, technology, retail, health, finance, legal
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
12

Malware and tooling in GuidePoint GRIT Q3 2026 Ransomware Report

Malware and tooling: AgendaCrypt, Clop, MEDUSA - S1220, Rclone - S1040

How GuidePoint GRIT Q3 2026 Ransomware Report works

GuidePoint Security's GRIT Q3 2026 ransomware report page states 2,760 ransomware victims in Q3 2026, the most of any quarter and up 75% year over year. A new group narrowly surpassed Qilin as the leading operator, ShinyHunters expanded beyond traditional encryption, and payment rates fell by more than half while the average ransom payment rose.

GuidePoint Security's Research and Intelligence Team (GRIT) reports 2,760 ransomware victims in Q3 2026, the highest quarterly total ever recorded and a 75% year-over-year increase. The prior record was 2,287 victims in Q4 2025 (GRIT 2026 annual report). According to the GRIT Q3 2026 webinar page, a new group narrowly overtook Qilin as the leading operator; the group is not named in the content we could retrieve. ShinyHunters is described as rising and as operating beyond traditional encryption-based extortion. The page also describes an affiliate model that lowers the barrier to entry, attack windows shortened by AI capabilities, groups active across more countries than before, and one sector returning to the top 10. Payment rates fell by more than half, while the average ransom payment increased.

Collection limits: the GuidePoint blog post returned only its title with no article body, and the webinar page (scheduled October 22, 2026, 1:00pm ET) is a summary only. The identity of the new top group, the per-group victim counts, the sector and regional breakdowns and the exact payment figures could not be verified. Nothing has been inferred for them.

Corroborating context from the Bitdefender September 2026 Threat Debrief (August 2026 data): 1,000 claimed victims in the month, 83 active ransomware groups (a record, up from 66 in July), and Qilin reclaiming the top rank with 166 victims, with a focus on Germany, France and Italy and a U.S. federal organization also targeted. The Gentlemen ranked second. Bitdefender says ShinyHunters claimed 80+ victims in 2026 and that encryptors have not come into play in its recent attacks. Its methods are vishing, Okta SSO compromise and OAuth/SSO credential collection against Salesforce and Snowflake data. Bitdefender reports a healthcare breach in August 2026 (over 1TB, 200-300 million records claimed, $55 million demand) and a June cancer-facility breach with 10.9 million records released. ShinyHunters is associated with Scattered Spider and LAPSUS$ (MITRE ATT&CK G1057, aliases UNC6240, Bling Libra). Clop claimed 40+ victims in August by exploiting PTC Windchill and FlexPLM (CVE-2026-12569, unauthenticated access enabling RCE) and deploying JSP web shells. Medusa claimed 67 victims and was observed using Rclone paths added to Windows Defender exclusions. Press reporting says ShinyHunters breached Clop's Tor site on September 18, 2026 by exploiting a flaw in the Grav CMS and demanded an eight-figure bitcoin ransom; this comes from a search-result excerpt and the full article could not be fetched.

Defensive relevance: this is a trend and landscape report, not a single campaign. It carries no CVE of its own, no malware variants and no network IOCs. BeaconBeagle was not queried because no IP or domain indicators are sourced.

MITRE ATT&CK techniques used in TL-2026-3183

Execution

T1059.009 Command and Scripting Interpreter: Cloud API

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application

Collection

T1213.006 Data from Information Repositories: Databases; T1530 Data from Cloud Storage

Persistence

T1505.003 Server Software Component: Web Shell

Credential Access

T1528 Steal Application Access Token

Lateral Movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

Affected products and versions in GuidePoint GRIT Q3 2026 Ransomware Report

  • PTC — Windchill / FlexPLM
    Vulnerable versions: Versions affected by CVE-2026-12569 (not enumerated in sources)
  • Salesforce — Salesforce platform (data theft via compromised SSO/OAuth)
  • Snowflake — Snowflake data platform (data theft via compromised credentials)
  • Okta — Okta SSO (compromise via vishing)

Remediation for GuidePoint GRIT Q3 2026 Ransomware Report

Patches

  • Apply the PTC Windchill/FlexPLM fix for CVE-2026-12569 where affected

Immediate actions

  • Audit OAuth application and token usage across SaaS platforms such as Salesforce and Snowflake
  • Rotate credentials and tokens for exposed systems
  • Restrict token creation and distribution to authorized accounts
  • Train help desk and staff to verify identity on voice calls and SSO reset requests (vishing)

Workarounds

  • Alert on new JSP web shells on Windchill servers
  • Alert on exclusion paths added to Windows Defender that reference remote-copy tools

Longer-term hardening

  • Segment SaaS platforms with unique logons and re-authentication prompts
  • Monitor for bulk data exfiltration and abuse of data-sync and file-transfer tooling such as Rclone
  • Prepare for non-encryption extortion, where backups alone do not prevent data-leak extortion
  • Track breach notification obligations (PCI and PHI regulations)

CVEs associated with GuidePoint GRIT Q3 2026 Ransomware Report

CVE-2026-12569

Timeline of GuidePoint GRIT Q3 2026 Ransomware Report

  • Q4 2025 set the previous quarterly record with 2,287 ransomware victims posted (GRIT 2026 annual report); December 2025 alone had 814 claimed attacks.
  • June 2026 (day not stated): ShinyHunters breached a cancer facility and exfiltrated 10.9 million records, which were publicly released (Bitdefender).
  • August 2026 (day not stated): 1,000 claimed victims and a record 83 active groups; Qilin reclaimed the top rank with 166 victims; Clop claimed 40+ victims via PTC Windchill/FlexPLM CVE-2026-12569 (Bitdefender).
  • August 2026 (day not stated): ShinyHunters breached a healthcare organization, reportedly accessing over 1TB across Salesforce and Snowflake and claiming 200-300 million records in 4 days, with a $55 million demand (Bitdefender).
  • ShinyHunters breached Clop's Tor site through a flaw in the Grav CMS, stole source code, logs and onion private keys, and demanded an eight-figure bitcoin ransom (press report; unverified full text).
  • Q3 2026 ends with 2,760 ransomware victims, a record quarter and up 75% year over year; a new group narrowly passes Qilin (GRIT; group not named in retrievable content).
  • GuidePoint GRIT presents the Q3 2026 Ransomware & Cyber Threat Report webinar, 1:00pm ET (Jason Baker, Grayson North, Justin Timothy, Nick Hyatt).

Sources cited for GuidePoint GRIT Q3 2026 Ransomware Report

Detection coverage for TL-2026-3183

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3183 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats