Security1 publisher2 min readPublished
Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital
Cisco Talos's tally of Japanese ransomware for January to July 2026 hands the country lead to The Gentlemen, a crew that was not in last year's data and that listed 105 victims worldwide in July alone.
The Watch · Security desk

What happened
- Cisco Talos counted 90 Japanese organizations hit by ransomware between January and July 2026, against 86 in the same months of 2025, with April the heaviest month at 19 incidents.
- Victims capitalized under JPY 100 million made up 48% of the total, and those from JPY 100 million to JPY 1 billion another 30%.
- Talos names Qilin, the most active group in Japan last year and second this year, as using AI to improve the efficiency of its operations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Almost none of the groups seen in Japan in the first half of 2025 reappeared in 2026, so detection content and playbooks keyed to named families expire faster than the annual cycle most teams buy them on.
- exposure With 13.3% of cases arriving through overseas offices and subsidiaries, most often in Taiwan, a Japanese parent's response scope now includes networks its domestic security team may not monitor.
- capability If Qilin's use of AI holds up, victim throughput for that crew stops tracking headcount, and defenders lose the assumption that a small affiliate pool caps how many intrusions run at once.
The share moved more than the volume did. Talos counted four more Japanese victims than in the same seven months of 2025 [1]. Apply its capital brackets to both totals and the composition change shows up in whole companies: about 70 of this year's 90 victims were capitalized under JPY 1 billion, against about 59 of last year's 86 [2]. Victims at JPY 1 billion or more fell from roughly 27 to roughly 20 [3].
Talos states that shift two ways. Its summary says firms under JPY 1 billion are "approximately 80% of the total" and calls it "an increase of around 13% from the previous year" [7]. The body of the same post gives 78%, against 69% in 2025 [6]. The 13% is the ratio between the two shares; the gap between them is nine points [4]. Quoted as 13 points, the down-market move comes out half again as large as the data supports.
Fourteen of the 90 Japanese incidents were The Gentlemen's, about 16%, with Qilin and SafePay on seven each, so the top three carry 31% of the national total [8][5]. The group is far bigger outside Japan. Its leak site listed 48 victims worldwide in January, 87 in February and 105 in July [13]. It has run since about July 2025 as a ransomware-as-a-service operation using double extortion, and Talos says Russian-speaking individuals may be involved in its attacks [12][14].
Qilin is the continuity in the Japanese data: most active group there last year, runner-up this year [8][15]. Very few of the other groups seen from January to July 2025 turned up in the 2026 period [11], and this year's list also includes NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous and AiLock [10]. Nobody was tuned for The Gentlemen last year, because it had not started operating [6].
The AI finding sits at the level of a summary line. Talos writes that Qilin is "leveraging AI to improve the efficiency of its operations" [15], and at that point in the post does not say which part of the operation the AI touches. Efficiency is a claim about throughput, not about a new technique.
The industry mix held. Manufacturing took 34% of Japanese incidents, information and communications 11% and services 9% [5]. Monthly volume averaged about 13 [3]. Talos says the full post also covers The Gentlemen's tooling, attack flow and attribution [16].
What to watch
- Whether Talos publishes artifacts behind the Qilin AI finding rather than the efficiency claim alone.
- Whether The Gentlemen's leak-site listings hold above 100 a month after July or the peak was a batch dump.
- Whether the Russian-speaker attribution on The Gentlemen moves from possibility to a named affiliate set.