The headline numbers, and why to treat them carefully
Bitdefender looked at September 1–30 and recorded 790 claimed ransomware victims. It says that is a 30% increase over September 2025. The word "claimed" matters. The data comes from data leak sites (DLSs), the pages where ransomware groups name victims. Bitdefender admits it can't independently verify every claim. It says the figures reflect what criminals say they did, not confirmed incidents or financial damage.
Treat the 790 as a trend indicator. It is not an audit.
Operation KillSwitch: KillSec loses its leak site
On September 30, 2026, law enforcement seized KillSec's data leak site and several of its servers. Bitdefender, which began tracking the group in 2024 and contributed to the operation, describes the site as holding more than 10 TB of data.
Other reporting gives a much larger figure. Security Affairs quotes Europol as saying authorities secured at least 110 terabytes of data against further unauthorised access. The two numbers differ, and Europol's is the official one. I would use the 110 TB figure and note that Bitdefender's wording is lower.
Other details from the press coverage:
- Scope: Europol describes an international investigation led by German authorities into around 1,000 suspected attacks worldwide.
- Arrests: Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom.
- Suspected operator: Investigators identified a 16-year-old as the group's suspected main operator. That is an allegation. It has not been tested in court.
- Infrastructure: CybersecAsia reports that investigators gained control of five central servers used to manage the operation and store stolen data.
- Participants: Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the UK and the US took part, with support from Europol, Eurojust, Bitdefender and Group-IB. Bitdefender's own list of participating countries is shorter. The arrests and searches were in four European countries, while the wider operation involved ten.
What KillSec actually did
KillSec began as a hacking crew and moved to ransomware-as-a-service (RaaS) around the end of Q2 2024. Bitdefender estimates it claimed at least 500 victims and carried out more than 1,000 attacks. Europol's figures are framed differently. Police say about 500 of the roughly 1,000 attacks have been confirmed as successful, and that count could change.
Bitdefender makes a point worth repeating. Many KillSec breaches involved no ransomware execution. The group could scan for weaknesses in cloud platforms, find data of interest and exfiltrate it. Europol's account matches this. It says KillSec gains access by exploiting software vulnerabilities and poorly secured entry points, particularly those connected to cloud storage.
Your defences can't depend on spotting encryption activity. A data-theft-only extortion run never trips a "files are being encrypted" alarm. Look at exposed cloud storage, unpatched internet-facing software and unusual outbound data transfers.
Takedowns are not funerals
Bitdefender is cautious about what this means. Some groups collapse after a takedown, but it says rebranding under a new name is far more common. It also points to hidden backup infrastructure, historical affiliate growth and outside partnerships that may survive. One security site put it similarly, saying the operation does not establish that the group was permanently eliminated.
Bitdefender's recommendations for organizations:
- If you are hit by ransomware, contact law enforcement and keep records. Victim reports help investigators track a group.
- Keep up with breach-notification rules and current policies.
- Make sure your digital forensics and incident response teams collect and analyze the relevant data properly.
- Review threat intelligence continuously, including current indicators of compromise.
- Harden systems after recovery and the lessons-learned phase, so the same actor can't walk back in.
- Don't wait for law enforcement to finish before seeking help with containment and recovery.
The rest of September's ransomware scene
The Gentlemen on top
The Gentlemen was the most active group in two of the last three months. In September it claimed 105 victims by Bitdefender's count. Its claims spanned regions beyond North America, including Southern Europe, South America and Western Europe. They also covered manufacturing, retail, construction, technology and healthcare. Bitdefender says the group uses a service called GentleCloud to protect its own infrastructure and make its site harder to crawl. Qilin and Akira also made the top ten, and Qilin's claimed victim count fell 50% from August.
ShinyHunters hacks Clop's leak site
Clop's own site was compromised. BleepingComputer reported that ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, uploaded a text file and replaced the site with a defacement page. BleepingComputer says it confirmed the defacement and the uploaded file. It has not independently verified ShinyHunters' claims that it stole server logs, source code or Clop's onion private keys.
That distinction matters. The defacement is observed fact. The theft is the attacker's claim.
According to BleepingComputer, ShinyHunters demanded an eight-figure payment and a public apology, with the demand rising over time. It framed this as retaliation in a feud that dates to Clop's 2025 Oracle E-Business Suite campaign. Bitdefender notes Clop claimed only two victims in September, a sharp drop. Bitdefender links that to the compromise. It is a plausible explanation, but it is not proven.
CRPx0 puts its toolkit up for sale
CRPx0 posted on its leak site that its source code, blog, command-and-control infrastructure and negotiation platform were for sale at $1,500. Its Hacking-as-a-Service program reportedly remains available. Bitdefender points out that this price could lower the barrier for newcomers to RaaS. It is also unclear whether CRPx0 is rebranding or joining another group. "Ending ransomware operations" is the group's framing, not a verified shutdown. The price is a claim in a criminal group's post, not a confirmed sale.
Regions and industries
Bitdefender says the US remained the largest region but fell significantly in claimed victims. Japan ranked tenth, with technology the most-claimed sector there. Manufacturing claims dropped. Education and research stayed in the top ten, and transportation rose to tenth. The report text I had doesn't include the full tables, so I won't invent totals.
The action item: Citrix NetScaler CVE-2026-88779
If you run NetScaler, this is the part that needs attention today. Bitdefender reports the flaw was added to the Known Exploited Vulnerabilities catalog. Citrix describes CVE-2026-88779 as a memory overflow that leads to denial of service, with a CVSS v4.0 base score of 8.7. Bitdefender says attackers are using it to crash NetScaler ADC and Gateway devices that have SAML logon enabled. The Canadian Centre for Cyber Security says CISA added it to the KEV catalog on October 4, 2026 and that Citrix indicates it is exploited in the wild.
Who is affected
The precondition is that the appliance is configured as a SAML service provider (SP) or SAML identity provider (IdP). The Citrix bulletin lists these affected supported builds:
| Product | Affected | Fixed in |
|---|---|---|
| NetScaler ADC and Gateway 14.1 | Before 14.1-73.41 | 14.1-73.41 and later |
| NetScaler ADC and Gateway 13.1 | Before 13.1-64.28 | 13.1-64.28 and later of 13.1 |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.41 FIPS | 14.1-73.41 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.282 | 13.1-37.282 and later |
Secure Private Access Hybrid deployments that use NetScaler instances are also affected, and those instances need upgrading. The bulletin applies to customer-managed appliances. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by Cloud Software Group.
How to check your exposure
Citrix says to inspect the NetScaler configuration for these entries:
add authentication samlActionmeans the appliance is configured as a SAML SP.add authentication samlIdPProfilemeans the appliance is configured as a SAML IdP.
If either is present and you are on an affected build, install the relevant update as soon as possible. If neither is present, the stated preconditions aren't met. You should still plan to upgrade.
Bitdefender frames this as SAML logon being enabled, which is a slightly looser description than Citrix's SP/IdP wording. Not every NetScaler deployment is vulnerable. Because the flaw is under active exploitation, it is cheaper to verify the configuration now than to explain an authentication outage later.
Analysis: what this month tells defenders
- Disruption is not elimination. KillSec's seizure is good news, but the cloud weaknesses it exploited are still out there. Rebranding is the usual aftermath.
- Extortion without encryption is mainstream. KillSec's approach is a reminder that data exposure, not encrypted files, is often the real damage.
- Criminals are attacking each other. The Clop incident shows that leak infrastructure runs on ordinary web software with ordinary bugs. That is amusing, but it doesn't make any of these groups less dangerous to you.
- Edge devices stay a favourite target. A Citrix appliance with a SAML configuration is exactly the kind of internet-facing system defenders need to inventory and patch quickly.
- Read the numbers critically. Leak-site counts are self-reported by criminals, and Bitdefender says so itself. A 30% year-over-year rise is a signal, not a measurement.
Bitdefender is a security vendor with a stake in how the threat landscape is described, so its framing deserves some scepticism. In this case its main claims line up with Europol's account and Citrix's bulletin, apart from the 10 TB versus 110 TB difference.
Quick checklist for admins
- Inventory NetScaler ADC and Gateway appliances, and check their build numbers against the table above.
- Search the configuration for
add authentication samlActionandadd authentication samlIdPProfile. - Patch affected appliances to the fixed builds. Don't forget Secure Private Access Hybrid instances.
- Audit cloud storage permissions and exposed access points, since KillSec's data theft relied on them.
- Watch for large outbound data transfers, not just encryption activity.
- Confirm your incident response plan covers law-enforcement reporting and breach-notification duties.
The KillSec arrests are a win for law enforcement. The Citrix flaw is a more immediate problem for most admins.
References
- Bitdefender Threat Debrief | October 2026 - Bitdefender Bitdefender · 2026-10-06T05:00:01+00:00
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779 support.citrix.com
- Citrix security advisory (AV26-996) - Canadian Centre for Cyber Security cyber.gc.ca