Qilin ransomware sweeps up US churches, schools and small businesses

Qilin, one of the most prolific ransomware-as-a-service operations of the past year, spent July 18 adding roughly a dozen fresh names to its dark web leak site, and an unusual share of them were small US community organizations rather than the large corporations that extortion crews normally parade. The newly listed victims include St Martha Catholic Church, The Nueva School (a private school), the family run contractor Powder River Heating and Air Conditioning, and Heartland Catfish, a Mississippi Delta seafood producer, alongside industrial supplier Salina Supply and technology firm KLD Labs.

These are claims, not confirmed breaches. Everything on a ransomware leak site is an unverified extortion post written by the attackers to pressure a victim into paying, and a listing can be exaggerated, recycled, or occasionally fabricated. None of the named organizations has publicly confirmed an intrusion, and the group has not published proof for most entries.

Why a church and a school are on the list

The mix matters. Faith groups, private schools, small manufacturers and local service firms rarely make headlines, but they are exactly the soft targets that ransomware affiliates increasingly favor: they hold sensitive personal and financial records, they often run lean IT teams without a dedicated security function, and they are more likely to quietly pay to make an incident disappear. Qilin''s July 18 batch reads less like a hunt for a single marquee victim and more like an affiliate working through whatever access it could find.

The spree was not limited to the United States. The same day, Qilin also listed the French firm Armara, Italy''s Sicc, and the Argentine pharmacy chain Drogueria Martorani, underscoring that the group''s affiliates cast a wide, opportunistic net across regions and sectors.

Who Qilin is

Qilin, also tracked under the name Agenda, runs a ransomware-as-a-service model: the core team maintains the encryptor and leak infrastructure while affiliates carry out the actual break-ins and split the proceeds. The crew has been among the busiest on the leak-site circuit through 2026, listing 31 victims across 15 countries in a single week earlier this month. You can review its history and known tooling on the IntelFusions Qilin profile. It is one of several high-volume crews flooding leak sites this month, alongside groups such as INC Ransom.

What you should do

Smaller organizations are not too small to be targeted, and the practical defenses are the same ones that blunt every ransomware affiliate: enforce multi-factor authentication on email, VPN and remote access; keep offline, tested backups so you can recover without paying; patch internet-facing systems and remote-access software promptly; and watch for unusual data transfers that can signal exfiltration before encryption. If your organization appears on a leak site, treat it as a genuine incident until proven otherwise, preserve logs, and engage law enforcement rather than negotiating alone.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions