Skip to main content
developing↑ EscalatingCyber

Qilin Ransomware Activity Escalates with PAN-OS Exploitation and Increased Attacks

The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks for the week of July 15-21, 2026, primarily targeting US government and military sectors.

Impact
7.8
Confidence
Medium-High
Evidence
2 sig · 2 src
Trajectory
↑ Escalating
Geo
US
First seen Jul 21·Updated Jul 22·Synthesized Jul 22
Export brief

Assessment

Medium-High confidence2/2 signals corroborated across 2 independent sources

The Qilin ransomware group has escalated its activity, leading global cyber incidents with 24 claimed attacks for the week of July 15-21, 2026, primarily targeting US government and military sectors. This surge is concurrent with confirmed exploitation of a critical Palo Alto Networks PAN-OS authentication bypass vulnerability in GlobalProtect VPNs, indicating enhanced capabilities against enterprise infrastructure. The total volume of compromised data attributed to Qilin is 29.6 TB, though this relies on self-reported claims.

Why it matters — The exploitation of a critical VPN vulnerability combined with increased attack volume poses a significant and immediate threat to global enterprise and government network security.

Established

  • ·Confirmed: Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN.
  • ·Confirmed: Global cyber activity reached 350 incidents across 58 countries for the week of July 15-21, 2026.
  • ·Claimed: Qilin ransomware group was responsible for 24 attacks during the week of July 15-21, 2026, leading global cyber activity.
  • ·Claimed: Qilin's activity contributed to 29.6 TB of compromised data.
  • ·Claimed: US government and military sectors remain primary targets for global cyber activity.
  • ·Unclear: The specific scope of victim impact from the PAN-OS vulnerability exploitation remains unquantified.

Indicators to watch

  • Quantification of victims impacted by Qilin's PAN-OS exploitation
  • Further details on specific targets of Qilin's recent attacks
  • Defensive measures or patches released by Palo Alto Networks

Evidence

Confirmed · 2 independent sources · 2 signals · 2 independent sources

Central claimQilin ransomware group leads global cyber activity with 24 claimed attacks for week of July 15-21, 202650% on claim

Corroborated1 · 1 src · best low 46%
Context1 · 1 src · best low 54%

Topics cybersecurity · ransomware · qilin · data-breach · threat-intelligence · vulnerability · vpn

Discussion

Sign in to add a note, contribute a source, or challenge the assessment.