Qilin retakes the ransomware top spot from The Gentlemen

Qilin is back on top of the ransomware leak sites. Through 30 August the crew had named 159 organizations on its extortion site, against 94 for The Gentlemen, the group that ended Qilin's 13-month run at number one in July. That is Qilin's busiest month of 2026 so far, and it is running about 70% ahead of its rival.

The interesting part is what did not change. Across the 76 crews IntelFusions recorded in August, the total number of organizations named came to 1,041, against 1,026 in July. The league table moved. The volume behind it did not.

One crew drips, the other floods

Qilin posted on 27 separate days in August, and its busiest single day since the start of July carried 19 names. The Gentlemen posted on 13 days, and its busiest carried 41, all of them published in one batch on 1 July.

Averaged across the days each crew was actually active, The Gentlemen named about 16 organizations per posting day in July and about 7 in August. Qilin ran at roughly 5 and then 6. Qilin's month was also flat from start to finish, with 51 names in the first ten days, 53 in the second and 55 in the third. The Gentlemen's fell away, 41 then 25 then 28.

The ranking measures batch size

Put those habits side by side and the July to August swing looks less like a change in fortunes than a change in publishing schedule. The Gentlemen did not post on fewer days in August than in July, it posted on more, 13 against 11. What shrank was the size of each dump. A crew that empties its backlog in three enormous batches can win or lose a month on where those batches happen to fall. A crew that posts almost daily produces a number that tracks its actual workload.

None of this establishes how many organizations were genuinely compromised. Every entry on a leak site is an unverified claim written by the criminals themselves and published to apply pressure, and the date attached to it is the date the gang chose to post, not the date anyone was broken into. Victims who pay quietly never appear on these sites at all. August also has one day left to run at the time of writing.

Read the tempo, not the table

For anyone deciding whose tradecraft is worth studying this month, posting tempo across a quarter is a more useful measure than who topped the table in August. On that measure Qilin has been the steadier of the two all year, with 2,197 claims in IntelFusions' records against 549 for The Gentlemen, which posted its first victim in March. Monthly crowns change hands. The tooling and the entry points that put those names there change far more slowly.

The same caution applies to a single country's numbers. When Chilean organizations began appearing on leak sites at an unusual rate this month, much of the increase arrived on a handful of posting days. A spike in a small country is often one crew clearing its queue.

Nothing in August suggests the extortion economy grew or shrank. It suggests two crews with different filing habits took turns at the top of a table that mostly records when they got round to publishing.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions