The Qilin ransomware operation has added COFACE, the French-headquartered global trade credit insurance and business information group, to its dark web victim list. The listing was detected on August 16, 2026, according to monitoring attributed to the ThreatMon Threat Intelligence Team and reported by Undercode News. As of publication, COFACE has issued no statement, no regulator filing has surfaced, and no independent incident response firm has corroborated an intrusion. This remains an actor claim, not a confirmed breach. It is worth stating plainly: the only source currently carrying the COFACE listing is a single OTHER-tier outlet relaying a third-party monitoring feed, so every detail below about COFACE specifically should be read as unverified.
What Happened
Undercode News reports that Qilin listed COFACE among its victims during dark web activity observed on August 16, 2026, identifying the actor as Qilin and the victim as COFACE. The report contains no ransom figure, no stated data volume, no encryption claim, and no proof-of-breach sample description. That absence matters. In comparable Qilin listings tracked by SOCRadar and Dark Eye, leak site entries typically arrive with a victim domain, an employee band, a sector tag, and screenshots of exfiltrated files. None of those corroborating artifacts have been reported for COFACE.
Undercode itself flags the caveat directly, noting that a group listing an organization "does not automatically prove that a successful intrusion occurred, nor does it establish that the attackers obtained sensitive information," and that confirmation would require evidence from COFACE, law enforcement, incident responders, or independent researchers.
There is also a broader reliability caution embedded in the source set. Two different trackers describe the same Qilin victim, CPCG, in incompatible terms: DeXpose records CPCG as a US-based organization claimed on July 22, 2026, while Dark Eye's record for the same listing places it in Brazil under Construction and Real Estate, with a disclosure date of May 4, 2026 that predates the leak site posting by 79 days. Accounts differ, and leak site metadata is frequently wrong. Apply the same discount to the COFACE entry until a primary source speaks.
What Was Taken
Nothing has been established. No source reports a record count, a file tree, a data category, or a sample dump tied to COFACE. Any figure circulating without attribution should be treated as invented.
What can be said is what a successful compromise of an organization like this would put at risk. COFACE operates in trade credit insurance, business information, risk management, and debt collection support for companies trading across borders. As Undercode notes, firms performing credit assessment and trade risk analysis hold information not just about their own customers but about those customers' buyers, suppliers, and payment behaviour. That is a concentrated, resale-friendly data pool: counterparty credit scores, payment default histories, policy and claims records, and commercially sensitive trade exposure across thousands of third parties who never contracted with the insurer directly.
Qilin practises double extortion, per ShellCodeX, demanding payment both for a decryptor and for non-release of stolen data. So if the listing is genuine, exfiltration is the working assumption, not an open question.
Why It Matters
Qilin is not a marginal operator. Check Point research cited by Undercode found the group was the leading ransomware operation in the first quarter of 2026, with 338 victims posted to leak sites. SOCRadar's rolling counts show the same tempo continuing through the summer: 135 other victims in the 60 days before its August 6 Bloom Financials listing, and 146 in the 60 days before its August 9 Price Shoes listing. On August 6 alone, Bloom Financials was one of six new Qilin entries.
Targeting profiles differ slightly between trackers. ShellCodeX ranks Qilin's preferred sectors as Manufacturing (71), Business Services (67), Consumer Services (37), Healthcare (34), Construction (31), and Agriculture and Food Production (29), with victim countries led by the US (175), UK (33), Germany (25), Canada (22), France (16), and Australia (15). SOCRadar describes the same top three sectors but ranks the geography as the United States, France, and Germany, with the UK absent from its top tier. The discrepancy is worth noting rather than resolving: different collection windows and different leak site parsing produce different tallies.
The financial services angle is the live thread. SOCRadar records recent Qilin claims against J&T Bank and Trust, Freedom Claims Management, Affinity Capital, and Triton Trading, alongside Bloom Financials. SOCRadar's own read is that this reflects broad opportunistic targeting rather than a deliberate sector campaign. A trade credit insurer of COFACE's scale would nonetheless be a step up in profile from the mid-market organisations that dominate the group's leak site.
The Attack Technique
No initial access vector has been reported for the COFACE claim. Qilin's recent, documented tradecraft is the better guide.
SC Media reported on July 21, 2026 that Arctic Wolf Labs observed a series of June 2026 intrusions ending in Qilin ransomware deployment and data exfiltration, all originating from exploitation of CVE-2026-0257 (CVSS 9.1) in Palo Alto Networks GlobalProtect VPN firewalls. The timeline is damning: Palo Alto shipped a fix and disclosed exploit attempts on May 13, Rapid7 saw broad exploitation by May 17, and CISA added the flaw to the KEV catalog on May 29 with a three-day remediation deadline for federal agencies. The ransomware deployments landed in June, weeks after both the patch and the directive.
Bradley Smith, senior vice president and Deputy CISO at BeyondTrust, told SC Media that patching does not evict an attacker who established a session in May, because the flaw allowed unauthorized VPN connections that "look like a legitimate login rather than an exploit artifact." Smith added that Arctic Wolf's finding of varied tradecraft across affiliates means indicator matching alone will miss intrusions. Shadowserver counts more than 167,000 GlobalProtect portals exposed to the internet, patch status unknown.
Beyond that campaign, ShellCodeX maps Qilin's initial access to Valid Accounts, Exploit Public-Facing Application, and phishing including spearphishing via service. SOCRadar's stealer-log telemetry reinforces the credential path: nine corporate identity records tied to the Bloom Financials domain across cloud accounting, bookkeeping, tax filing, and e-signature platforms, spanning roughly ten months from September 25, 2025; and for Price Shoes, one confirmed employee credential tied to a Microsoft identity provider plus around two dozen customer-tier credentials. SOCRadar assesses infostealer-harvested credentials as a common Qilin initial access vector. Post-access, ShellCodeX documents PowerShell and Unix shell execution, scheduled tasks and SSH authorized key manipulation for persistence, LSASS credential dumping, parent PID spoofing and code-signing abuse for evasion, and RDP, SMB, and SSH for lateral movement. The payload is written in Golang with operator-selectable encryption modes.
What Organizations Should Do
- Audit GlobalProtect exposure and session history. If you run Palo Alto GlobalProtect, confirm CVE-2026-0257 is patched and then review VPN session and account activity back to May 13, 2026, per BeyondTrust's guidance. A patch closes the door; it does not remove anyone already inside.
- Hunt for identity abuse, not just exploit artifacts. Because this flaw produces sessions that resemble legitimate logins, prioritise detections on impossible travel, new device or geo enrollments, and anomalous VPN account behaviour over IOC matching alone.
- Pull your own stealer-log exposure. SOCRadar's case data shows corporate credentials for SaaS platforms sitting in infostealer dumps for months before a listing appears. Query your primary and subsidiary domains, force resets on anything found, and check whether MFA was enrollable by an attacker holding those credentials.
- Enforce phishing-resistant MFA on every external entry point. Qilin's documented initial access set is dominated by valid accounts and public-facing application exploitation. SMS and push-approval MFA are insufficient against session-level compromise.
- Treat third-party and counterparty data as your incident too. If you carry trade credit cover, your buyer ledgers, payment histories, and exposure data may sit inside an insurer's environment. Ask your carriers what they hold, where, and under what retention schedule.
- Validate immutable, offline backups and rehearse the exfiltration case. Double extortion means restoration solves half the problem. Have the legal, regulatory notification, and communications track ready before you need it, and engage incident response and counsel before any contact with the actor or a ransom broker, as DeXpose recommends.
Sources: Qilin Ransomware Claims COFACE as Its Latest Victim, Raising Fresh... | Qilin exploits Palo Alto Networks GlobalProtect VPN firewalls news... | Qilin Ransomware Group: Victims, TTPs and Activity ShellCodeX | Qilin Ransomware Claims Two New Victims in a Single Day as HARPLAST... | Bloom Financials Data Breach Business Services Data Breach Intell... | Qilin Ransomware Attack on CPCG Reveals Data Breach - DeXpose | Price Shoes Data Breach Retail and E-commerce Data Breach Intelli... | Cpcg — QILIN Ransomware Attack Dark Eye