Qilin
Qilin is a ransomware group that operates under an affiliate service model. It develops and rents out malware and has been linked to attacks against hospitals, critical infrastructure, and financial institutions worldwide.
- Incidents
- 3
- High impact
- 2
- First seen
- Jul 1, 2025
- Latest seen
- Apr 7, 2026
Linked incidents
Qilin Claims Responsibility for Attack on Banco Nacional de Crédito, C.A., and Banco Universal (April 2026)
On April 7, 2026, the Qilin (aka Agenda) ransomware group listed Banco Nacional de Crédito, C.A., Banco Universal (BNC) on its data leak site and threatened to publish allegedly stolen information if the bank did not negotiate. The allegedly exposed data—names, passport numbers, email addresses, bank account numbers, dates of birth, and ID numbers—is only visible in samples leaked or claimed by the actor and has not been confirmed by any public source. The bank has not issued any official statement acknowledging the attack. A platform incident reported on March 20, 2026, involved a simultaneous outage at several banks attributed to power outages and is unrelated to this ransomware claim. It is unclear whether the bank suffered any material losses as a result.
Qilin Reports an Attack on the Rio Supermarket
In December 2025, Rio Supermarket was the target of a ransomware attack by the Qilin threat group. The threat actor claimed responsibility for the attack on its leak site, although the full scope of the data breach and the material impact on the company’s operations have not yet been verified.
Qilin Claims Responsibility for Attack on Banco Nacional de Crédito, C.A., and Banco Universal (July 2025)
In July 2025, Banco Nacional de Crédito, C.A., Banco Universal (BNC) suffered a ransomware attack orchestrated by the threat actor Qilin. The incident began with platform disruptions on July 1, 2025, which the bank initially attributed to high transaction volumes and technical issues. However, an X user (@x00x01x01) publicly claimed responsibility for a ransomware attack, mocking the bank and accusing it of hiding money from the Iranian regime. Subsequent reports confirmed that the July 2025 incident was in fact a ransomware attack by Qilin, during which the group allegedly demanded a ransom of $8 million. The exact status of any data breach remains unknown.