Business Insights Cybersecurity Blog by Bitdefender

Bitdefender Threat Debrief | September 2026

Written by Jade Brown | Sep 08, 2026

The ShinyHunters Playbook: Widespread Extortion without Encryption

This edition of the Bitdefender Threat Debrief covers the latest developments in the ransomware threat landscape, including ShinyHunters’ recent activity, an update on Qilin’s ranking, and our Top 10 Groups. This release also covers Clop’s exploitation of different software, Medusa’s operational milestone, and more.

As ransomware continues to evolve, our goal with this monthly Bitdefender Threat Debrief is to help you stay ahead of the curve. To do this, we combine information from openly available sources (OSINT) - things like news reports and research – with data we gather by analyzing Data Leak Sites (DLSs), websites where ransomware groups post details about their victims. We can't independently verify all these claims, but we are confident in the trends we see over time.

For this month's report, we analyzed data from August 1 to August 31 and recorded 1,000 claimed ransomware victims. This is the second-highest number of ransomware victims claimed since our detailed tracking began in 2023.

Featured Story: The ShinyHunters Playbook: Widespread Extortion without Encryption

What Happened?

ShinyHunters recently claimed responsibility for a breach that gave them access to more than one terabyte of records across a healthcare environment using Salesforce and Snowflake. While the total number of victims (18) reported thus far for this group appears to be a small figure, the scope of their breaches has scaled to impact thousands.

The Scaled Attack Against a Healthcare Organization

At the beginning of August, ShinyHunters used playbook tactics they developed alongside their partners Scattered Spider and Lapsus$ to hit an organization in healthcare. Vishing, combined with the successful compromise of Okta SSO and the Salesforce and Snowflake ecosystems, resulted in the exfiltration of what the group claims is more than 200 million records in a four-day window. Then, ShinyHunters sent a $55 million ransom demand; while the amount is exorbitant, the threat actor had no qualms about disclosing this demand to the public. No response to this demand has been documented or publicized.

The records contained staff names, addresses, and Social Security numbers in addition to PHI (Protected Health Information). However, the number of 200-300million is most likely inflated because it does not necessarily represent individual patient records but a range of data just separated by multiple rows.

Where Do Encryptors Fit into ShinyHunter’s Recent Campaigns?

Despite initial announcements calling attention to ShinySp1d3r’s deployment in early 2026, encryptors have not come into play for ShinyHunter’s recent attacks. This time last year, ShinySp1d3r was described as a unique RaaS platform that would offer more versatile mechanisms to evade defenses. ShinyHunters’ focus for several months, however, has been on collecting credentials [OAuth/SSO] and exfiltrating sensitive data without encryption. The distribution of credentials and other sensitive data are their primary revenue streams.

While there has been some mention of ShinySp1d3r in previous months, there have been no verified reports of recent incidents involving ShinySp1d3rr or any affiliated ransomware samples. A lack of a validated ransomware release or any news of the updated platform may serve as a buffer until the threat actor establishes more confidence with their tooling or can invest their resources in other services beyond the commodity malware and RaaS economy.

ShinyHunters’ Victimology: Who Does the Group Target?

ShinyHunters targets organizations across industry verticals, including those in financial services and technology/software where it hurts most: at the service provider level rather than only the client-side ecosystem. This approach raises the stakes as the threat actor can continue onward with supply chain attacks or provide that data to others who engage in repeated extortion attempts.

ShinyHunters has also targeted multiple healthcare organizations, including those organizations at the nexus of medication and treatment. In early June, the group claimed an organization that was a cancer diagnosis facility. ShinyHunters used similar social engineering tactics to infiltrate and steal sensitive information in that case, exfiltrating 10.9 million records across customer, health care provider, and patient data. Rather than keep the datasets in a closed-off system or make them available only to interested buyers, ShinyHunters released them to the public.

While the approach may come off as heartless to some, it shows they’re a no-holds-barred criminal enterprise. Hitting a cancer diagnostic and treatment center comes across as a striking distinction from other groups who claim to avoid these care facilities or refrain from making leaks and other information available via public disclosures.

What Actions Are Recommended for Organizations?

ShinyHunters has publicly claimed 80+ victims this year. However, the scale of most of their attacks makes a significant impact and must be considered beyond just the number of organizations they attacked directly in the past 12 months. If you look at the organizations affected by these attacks, the number extends into the thousands.

As threat actors like ShinyHunters continue to compromise identity-based platforms at scale, organizations must remain informed and take proactive steps such as the following:

  • Audit OAuth usage across interconnected platforms
  • Segment platforms using other controls, e.g. unique logons, new prompts for authentication with each new session.
  • Enforce access control policies to restrict the creation and distribution of tokens, limiting it to authorized accounts and systems
  • Ensure that the lifetimes of these tokens are also restricted
  • Rotate credentials for any systems that may be at risk of exposure
  • Remain informed about regulations and current policies concerning breach notification, especially for the compromise of PCI and PHI to report and respond accordingly when breaches occur.

Other Notable Ransomware News

Now, let’s explore the notable news and findings since last month’s Threat Debrief.

  • Qilin returns to the top rank: Qilin claimed 166 victims in August, reclaiming the top rank from The Gentlemen. Germany, France, and Italy continue to represent the largest victim demographic outside North America affected by Qilin ransomware. The group also recently claimed a federal organization based in the United States.
    While unconventional when considering the odds of collecting a ransom demand, this action may have been taken to generate interest for potential buyers eyeing sensitive federal data. It’s also possible that the threat actor claimed such a victim to save face as they operate in a highly competitive RaaS space.

  • Clop’s second 2026 campaign focuses on exploitation, claims 40+ victims: Clop is known for their focus on exploitation and, the group has changed their approach by targeting platforms like FlexPLM and PTC Windchill, which are used to manage product lifecycles in engineering plants and other firms. Threat actors initially targeted a FlexPLM vulnerability to gather system information and chain it with the exploitation of a PTC Windchill vulnerability. Threat actors exploit CVE-2026-12569 to gain unauthenticated access to the Windchill server and execute remote code. The threat actor then drops JSP web shells to complete the execution and exfiltration stages of an attack.

    Clop is known for launching email extortion campaigns in rapid succession and, in recent months, notifying numerous users of the compromise and encouraging them to reach out for support. Organizations using FlexPLM and PTC Windchill are advised to regularly review the vendor documentation to ensure that patches are current and vulnerable devices remain segmented to minimize the risk of further exposure.

  • August 2026 yields the largest number of active ransomware groups: August not only had the second-largest number of ransomware victims claimed in the past year but also hit another milestone: it had the highest number of active reported ransomware groups during that timeframe. A total of 83 unique ransomware groups claimed victims during August. This marks a 25% increase in the number of active ransomware groups compared to July 2026 (which had a total of 66 unique groups). The rapid shift in the number of ransomware groups may be attributed to several variables, including copycat groups, affiliate transfer, and the growth of AI adoption amongst leading and emerging groups. It’s a shift that Bitdefender will continue to analyze as more movements in the ransomware threat landscape develop.

  • Medusa ransomware reaches 500+ victim milestone: Medusa emerged in mid-2022 and has hit hundreds of critical infrastructure organizations since then. As of 2026, the group has claimed 67 victims; their top targeted industries include government, retail, and manufacturing. Earlier this year. Medusa engaged in common ransomware playbook tactics observed by other groups, including exploiting remote access services and using EDR killers. However, the recent publication from CISA also references the group’s use of a different defense evasion tactic. This tactic involves staging Rclone in a Windows Defender exclusion path to combat the detection of exfiltration activity. Organizations are advised to assess the recommended actions in CISA’s release to establish the measures essential to mitigate the impact of Medusa attacks.

Top 10 Ransomware Families

Bitdefender's Threat Debrief analyzes data from ransomware data leak sites, where groups publicize their claimed number of compromised organizations. This approach provides valuable insights into overall RaaS market activity. However, it comes with a trade-off: while it reflects attackers' self-proclaimed success, the information comes directly from criminals and may be unreliable. Additionally, this method captures the number of victims claimed, not the actual financial impact of these attacks.

The Top 10 ransomware groups in August include Qilin, The Gentlemen, Clop, and DireWolf. While Qilin secured the top rank, other groups like Clop and DireWolf saw a rise in their victims following a decline in activity over the past two months. KryBit and Akira have also continued to claim victims month to month.

Top 10 Most Attacked Regions

Ransomware gangs prioritize targets where they can squeeze the most money from victims. In many cases, this means focusing on developed countries with higher projected growth rates. Threat actors may also launch strategic attacks during geopolitical conflicts or periods of social unrest.

Italy claims the 2nd rank in the Top 10 Regions: Historically, regions like Germany and Canada have typically ranked in second and third place, just behind the United States. However, in August, Italy rose to the second-highest rank. The groups claiming victims based in Italy last month included top groups such as The Gentlemen, Clop, Qilin, and Titan.

Top 10 Most Attacked Industries

Ransomware gangs may target organizations in critical infrastructure sectors, select other organizations that offer services tailored to consumers, or attack organizations that fall into both categories. Understanding the trends and ramifications associated with specific industries, and how specialized services and clientele are impacted, is crucial for assessing risk. Here are the Top 10 industries affected by ransomware attacks.

In August, the manufacturing industry saw an increase in the total victim population. The construction industry remained in the 5th rank. Lawyers' offices also returned to the Top Industries targeted list.

About Bitdefender Threat Debrief

The Bitdefender Threat Debrief (BDTD) is a monthly series analyzing threat news, trends, and research from the previous month. Don’t miss the next BDTD release, subscribe to the Business Insights blog, and follow us on Twitter. You can find all previous debriefs here.

Bitdefender provides cybersecurity solutions and advanced threat protection to hundreds of millions of endpoints worldwide. More than 180 technology brands have licensed and added Bitdefender technology to their product or service offerings. This vast OEM ecosystem complements telemetry data already collected from our business and consumer solutions. To give you some idea of the scale, Bitdefender Labs discover 400+ new threats each minute and validate 30 billion threat queries daily. This gives us one of the industry’s most extensive real-time views of the evolving threat landscape.

We would like to thank Bitdefenders Stefan Hanu, Mihai Leonte, Gabriel Macovei, and Andrei Mogage for their help putting this report together.