Qilin Ransomware Lists New Victims, Including Hawaii Family Dental

Qilin Ransomware Claims Attacks on Multiple Firms Across Sectors

HIGH
July 31, 2026
August 17, 2026
5m read
RansomwareData BreachThreat Actor

Related Entities(initial)

Threat Actors

Qilin

Other

ADPOAffinity CapitalAudio Precision, Inc.ByonyksDB Tarımsal EnerjiHawaii Family DentalQilin Ransomware

Full Report(when first published)

Executive Summary

The Qilin ransomware group has continued its prolific campaign, claiming responsibility for a series of attacks against organizations across multiple sectors worldwide. On its dark web leak site, updated on July 31, 2026, the group listed several new victims, including Hawaii Family Dental, a U.S.-based healthcare provider. Qilin asserts it has exfiltrated internal data from the dental practice as part of its double-extortion tactics. The group's recent list of targets also includes companies in logistics, technology, medical devices, energy, and financial services, demonstrating its industry-agnostic approach. These claims serve to publicly pressure victims into meeting ransom demands.


Threat Overview

Qilin operates as a Ransomware-as-a-Service (RaaS) and employs a standard double-extortion model. The group and its affiliates breach target networks, exfiltrate sensitive data, and then encrypt systems. If the victim refuses to pay the ransom for the decryption key, the group threatens to publish the stolen data on its leak site. The recent activity on July 31 shows a high operational tempo, with multiple victims from different countries and industries being named simultaneously.

Alleged Victims Listed on July 31, 2026:

  • Hawaii Family Dental (Healthcare, USA)
  • ADPO (Logistics/Chemicals, Belgium)
  • Audio Precision, Inc. (Technology, USA)
  • Byonyks (Medical Devices, USA)
  • DB Tarımsal Enerji (Energy, Turkey)
  • Affinity Capital (Financial Services, Philippines)

For the Hawaii Family Dental incident, the group did not provide proof of compromise or specify the nature of the stolen data in its initial post.


Technical Analysis

While the report does not detail the specific TTPs for these attacks, the Qilin ransomware group is known to use a variety of common ransomware tactics:

The group's ransomware is written in Go and is highly configurable, allowing affiliates to customize features for each attack.


Impact Assessment

The impact on the victims is significant. For Hawaii Family Dental, a breach could expose highly sensitive Protected Health Information (PHI), leading to severe regulatory penalties under HIPAA and a loss of patient trust. For the other industrial and financial victims, the impact includes operational downtime, financial loss from business interruption, and the potential exposure of intellectual property, customer data, and financial records. The public naming on a leak site adds reputational damage and can affect customer and partner relationships, regardless of whether a ransom is paid.


IOCs — Directly from Articles

No specific file hashes, IP addresses, or domains were provided in the source articles.


Cyber Observables — Hunting Hints

Security teams can hunt for generic ransomware precursors with the following observables:

Type
command_line_pattern
Value
reg.exe save HKLM\SAM
Description
Command to dump the SAM database for credential harvesting.
Context
Process monitoring (Event ID 4688), EDR.
Type
process_name
Value
rclone.exe
Description
A common tool used by ransomware groups to exfiltrate data to cloud storage.
Context
Process creation logs, EDR, network logs.
Type
network_traffic_pattern
Value
Anomalous SMB traffic
Description
Unusual SMB connections between workstations and servers can indicate lateral movement.
Context
Network traffic analysis, EDR logs.
Type
log_source
Value
VPN Logs
Description
Monitor for logins from unusual geographic locations or multiple failed login attempts followed by a success.
Context
SIEM, VPN appliance logs.

Detection & Response

Detection:

  • EDR and AV: Modern endpoint protection with behavioral analysis is key to detecting Qilin's activity, such as credential dumping attempts and the execution of its Go-based payload.
  • Network Monitoring: Monitor for large data uploads to known cloud storage providers or unusual external destinations.
  • Decoy Accounts: Use honeytokens and decoy accounts to detect lateral movement and credential access attempts early in the attack chain.

Response:

  1. Containment: Isolate compromised machines and network segments to prevent further spread.
  2. Backup Restoration: If encryption has occurred, restore from clean, offline backups.
  3. Credential Reset: Assume all credentials on the compromised network are stolen. Perform an enterprise-wide password reset, especially for privileged accounts.

Mitigation

Immediate Actions:

  1. Patch Vulnerabilities: Aggressively patch internet-facing systems and software to close common entry points.
  2. MFA Enforcement: Enforce MFA across all remote access solutions, email, and critical applications.
  3. User Training: Conduct regular phishing awareness training for all employees.

Strategic Recommendations:

  • Immutable Backups: Implement and regularly test immutable backups to ensure a reliable recovery path that is resilient to tampering by threat actors. This is a crucial implementation of D3FEND's File Restoration.
  • Network Segmentation: Divide the network into smaller zones to limit the blast radius of an attack. This prevents an initial compromise on a workstation from escalating to domain-wide encryption.
  • Privileged Access Management (PAM): Use PAM solutions to vault and rotate privileged credentials and monitor their usage, making it harder for attackers to gain and use powerful accounts.

Timeline of Events

1
July 31, 2026
Qilin ransomware group lists Hawaii Family Dental and other companies on its dark web leak site.
2
July 31, 2026
This article was published

Article Updates

August 10, 2026

Severity increased

Qilin ransomware group claims new victim, Chun Tai Sing Chemical Industry, on August 9, 2026, with alleged exfiltration of customer data.

The Qilin ransomware group has added Chun Tai Sing Chemical Industry, a Hong Kong-based firm, to its leak site on August 9, 2026. The group claims to have exfiltrated customer information after the company reportedly refused to pay a ransom, continuing Qilin's double-extortion tactics. The group's ransomware is noted to be written in both Go and Rust, making it adaptable across operating systems. Affiliates are also known to use tools like Mimikatz for credential theft, expanding on previously reported TTPs. The breach remains unconfirmed by the victim.

August 17, 2026

Severity increased

Qilin ransomware group claims new victim, MOSAID Technologies, a Canadian semiconductor firm, on August 17, 2026, indicating continued high-value targeting.

The Qilin ransomware group has added MOSAID Technologies, a Canadian semiconductor and intellectual property (IP) licensing firm, to its list of victims on August 17, 2026. This incident highlights Qilin's ongoing and aggressive double-extortion campaign, targeting high-value entities. The breach at MOSAID could result in the theft of highly sensitive IP, potentially compromising the company's competitive advantage and leading to severe business disruption and financial repercussions. This development underscores the persistent threat posed by Qilin across diverse sectors and its focus on exfiltrating valuable data.

Timeline of Events

1
July 31, 2026

Qilin ransomware group lists Hawaii Family Dental and other companies on its dark web leak site.

Sources & References(when first published)

Recent Data Breaches in 2026
breachsense.comJuly 31, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachDouble ExtortionHealthcareQilinRansomware

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.