# GuidePoint GRIT Q3 2026 Ransomware Report: Record 2,760 Victims, New Top Group Edges Out Qilin, ShinyHunters Expands Extortion

> GuidePoint Security's GRIT Q3 2026 ransomware report page states 2,760 ransomware victims in Q3 2026, the most of any quarter and up 75% year over year. A new group narrowly surpassed Qilin as the leading operator, ShinyHunters expanded beyond traditional encryption, and payment rates fell by more than half while the average ransom payment rose.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3183
- **ID:** TL-2026-3183
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-12569

## Description

GuidePoint Security's Research and Intelligence Team (GRIT) reports 2,760 ransomware victims in Q3 2026, the highest quarterly total ever recorded and a 75% year-over-year increase. The prior record was 2,287 victims in Q4 2025 (GRIT 2026 annual report). According to the GRIT Q3 2026 webinar page, a new group narrowly overtook Qilin as the leading operator; the group is not named in the content we could retrieve. ShinyHunters is described as rising and as operating beyond traditional encryption-based extortion. The page also describes an affiliate model that lowers the barrier to entry, attack windows shortened by AI capabilities, groups active across more countries than before, and one sector returning to the top 10. Payment rates fell by more than half, while the average ransom payment increased.

Collection limits: the GuidePoint blog post returned only its title with no article body, and the webinar page (scheduled October 22, 2026, 1:00pm ET) is a summary only. The identity of the new top group, the per-group victim counts, the sector and regional breakdowns and the exact payment figures could not be verified. Nothing has been inferred for them.

Corroborating context from the Bitdefender September 2026 Threat Debrief (August 2026 data): 1,000 claimed victims in the month, 83 active ransomware groups (a record, up from 66 in July), and Qilin reclaiming the top rank with 166 victims, with a focus on Germany, France and Italy and a U.S. federal organization also targeted. The Gentlemen ranked second. Bitdefender says ShinyHunters claimed 80+ victims in 2026 and that encryptors have not come into play in its recent attacks. Its methods are vishing, Okta SSO compromise and OAuth/SSO credential collection against Salesforce and Snowflake data. Bitdefender reports a healthcare breach in August 2026 (over 1TB, 200-300 million records claimed, $55 million demand) and a June cancer-facility breach with 10.9 million records released. ShinyHunters is associated with Scattered Spider and LAPSUS$ (MITRE ATT&CK G1057, aliases UNC6240, Bling Libra). Clop claimed 40+ victims in August by exploiting PTC Windchill and FlexPLM (CVE-2026-12569, unauthenticated access enabling RCE) and deploying JSP web shells. Medusa claimed 67 victims and was observed using Rclone paths added to Windows Defender exclusions. Press reporting says ShinyHunters breached Clop's Tor site on September 18, 2026 by exploiting a flaw in the Grav CMS and demanded an eight-figure bitcoin ransom; this comes from a search-result excerpt and the full article could not be fetched.

Defensive relevance: this is a trend and landscape report, not a single campaign. It carries no CVE of its own, no malware variants and no network IOCs. BeaconBeagle was not queried because no IP or domain indicators are sourced.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1190 Exploit Public-Facing Application
- T1078.004 Valid Accounts: Cloud Accounts
- T1059.009 Command and Scripting Interpreter: Cloud API
- T1505.003 Server Software Component: Web Shell
- T1528 Steal Application Access Token
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1530 Data from Cloud Storage
- T1213.006 Data from Information Repositories: Databases
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1657 Financial Theft

## Sources

- [GRIT Q3 2026 Ransomware Report: Top Takeaways (GuidePoint Security blog; fetched content had no article body)](https://www.guidepointsecurity.com/blog/ransomware-insights-q3-2026/)
- [GRIT Q3 2026 Ransomware and Cyber Threat Report webinar (webinar October 22, 2026)](https://www.guidepointsecurity.com/resources/grit-2026-q3-ransomware-cyber-threat-report-webinar/)
- [GuidePoint GRIT 2026 Ransomware & Cyber Threat Report (annual, covers 2025)](https://www.guidepointsecurity.com/resources/grit-2026-ransomware-and-cyber-threat-report/)
- [Bitdefender Ransomware Threat Debrief, September 2026](https://www.bitdefender.com/en-au/blog/businessinsights/bitdefender-ransomware-threat-debrief-september-2026)
- [MITRE ATT&CK Group G1057: ShinyHunters](https://attack.mitre.org/groups/G1057/)
- [ShinyHunters hacks Clop and threatens to extort the ransomware gang](https://pasqualepillitteri.it/en/news/17504/shinyhunters-hacks-clop-extort-ransomware-gang)
- [GuidePoint Security newsroom: Ransomware Victims and Threat Groups Surge to Record Levels](https://www.guidepointsecurity.com/newsroom/ransomware-victims-and-threat-groups-surge-to-record-levels/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3183
