A newly published threat actor profile is shining a light on Qilin, a ransomware operation that has built its business around a partnership model and a punishing double-extortion strategy. Rather than launching attacks itself, Qilin supplies affiliates with ransomware tools and technical support, then takes a cut of whatever ransom those affiliates manage to extract from their victims. It is a structure that has become increasingly common in the ransomware world, and understanding how it works is the first step toward protecting your own data.
How Qilin's Affiliate Model Works
Qilin operates as a Ransomware-as-a-Service (RaaS) provider. Instead of a single group carrying out every attack, Qilin builds the malicious software and support infrastructure, then licenses it out to affiliates who do the actual hacking. Those affiliates identify targets, gain access to networks, and deploy the ransomware, then split the profits with Qilin once a victim pays.
This division of labor is what makes RaaS operations so persistent and hard to shut down. Even if law enforcement disrupts one affiliate or takes down a piece of infrastructure, the core group and its toolkit can keep operating, and new affiliates can step in to launch fresh attacks. It also means the pool of people capable of running a Qilin-style attack is larger than a traditional hacking crew, since affiliates don't need to build ransomware from scratch, they just need access to a network and the willingness to deploy the tool they're given.
The Double-Extortion Playbook
What sets Qilin apart from older, simpler ransomware is its double-extortion approach. In a traditional ransomware attack, files are encrypted and the victim is asked to pay for a decryption key. Qilin adds a second layer of pressure: before encrypting a victim's files, its affiliates quietly steal sensitive data from the network. If the victim refuses to pay, or even after they do, the attackers threaten to publish that stolen data publicly or sell it to other criminals.
This tactic dramatically raises the stakes for victims. Even organizations with solid backup systems, ones that could restore encrypted files without paying a ransom, still face the threat of a damaging data leak. That leverage is exactly why double-extortion has become the default playbook across the ransomware ecosystem. We've seen similar dynamics play out in other recent incidents, including the Ecopetrol ransomware attempt that exposed thousands of accounts and the 700GB data claim from the Genesis ransomware group targeting a staffing agency. In both cases, the threat of exposed data, not just locked files, was the real pressure point.
Why Stolen Data Keeps Turning Up Elsewhere
Once data is exfiltrated in a double-extortion attack, it doesn't necessarily stay with the original attackers. Stolen records often end up circulating on dark web forums or get repackaged by other threat actors looking to profit further. That's a pattern echoed in incidents like the Iliad Italia customer dataset that surfaced for sale on a dark web forum, where compromised information found a second life well after the initial breach. It's also worth noting how aggressive some groups have become in pressuring victims, as seen when the ShinyHunters group escalated its Canvas campaign by defacing school login portals to force payment. Qilin's model fits squarely within this broader trend: steal first, encrypt second, and use the threat of public exposure as leverage long after the initial intrusion.
What This Means For You
If you're an individual, Qilin and similar ransomware operations are a reminder that your personal data is often collateral damage in attacks aimed at the organizations you do business with, employers, healthcare providers, schools, and service companies. You generally can't stop these attacks yourself, but you can limit how much damage a breach does to you personally by minimizing the sensitive data you share, using unique passwords for every account, and monitoring for signs your information has appeared in a leak.
If you manage IT for a business, the affiliate-based, double-extortion nature of Qilin means prevention has to happen before data ever leaves your network. Network segmentation limits how far an attacker can move after an initial breach, reducing the amount of data available to steal even if one system is compromised. Encrypting sensitive data at rest and in transit adds another layer of protection, since stolen data that's properly encrypted is far less useful to attackers threatening to publish it.
Actionable Takeaways
Segment your network so a single compromised device or account doesn't grant access to your entire infrastructure. Maintain offline, tested backups so encryption alone doesn't force a payment decision. Encrypt sensitive files so stolen data has less value even if it's exfiltrated. And treat any notification from a service provider about a ransomware incident seriously, since double-extortion groups like Qilin routinely follow through on leak threats. Staying informed about how groups like Qilin operate is one of the most practical steps you can take toward protecting your data before it becomes part of the next leak.




