Ransomware incidents in Japan: Investigation of The Gentlemen’s infrastructure and Qilin's AI use

Executive Summary

Ransomware attacks in Japan increased 4.7% year‑over‑year in H1 2026. The Gentlemen were the most active threat group, with leak‑site listings more than doubling from January to July. Qilin ranked second and evidence suggests it employed AI techniques. Small and medium enterprises with capital under JPY 1 billion accounted for 80% of victims. Data sourced from Cisco Talos.


Intelligence Metadata - Source Publisher: Cisco Talos - Published Date: 2026-09-17T10:00:43+00:00 - Category: research

Original Description: Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

"If you surrender to the wind, you can ride it."

— Toni Morrison
Source: Cisco Talos