Ransomware attacks on small businesses have taken a sharp turn for the worse. Two cybercrime operations, known as Qilin and The Gentlemen, are reportedly competing for dominance in the ransomware-as-a-service space, and small and mid-sized businesses (SMBs) are caught in the crossfire. Rather than a single dominant gang extorting victims, security researchers are now watching two aggressive operations racing to compromise networks, steal data, and demand payment, often from organizations that can least afford the disruption.

This rivalry matters because it changes the incentive structure for attackers. When two groups are competing for market share in the ransomware economy, both have reason to move faster, cast a wider net, and pursue easier targets rather than holding out for the biggest possible payday. SMBs, which typically run leaner IT teams and older infrastructure, fit that profile perfectly.

Why Qilin and The Gentlemen Are Targeting SMBs

Large enterprises tend to invest heavily in detection tools, dedicated security staff, and incident response retainers. Smaller businesses usually don't have that luxury. A ransomware operator weighing where to spend limited time and resources will often choose the path of least resistance, and that path increasingly leads to SMBs.

Competition between gangs like Qilin and The Gentlemen appears to be accelerating this trend. When affiliates within a ransomware-as-a-service model are incentivized to hit as many victims as possible, they gravitate toward organizations with fewer defenses and less capacity to negotiate or recover independently. The result is a volume-driven approach where SMBs become the default target rather than an afterthought.

How These Ransomware Gangs Gain Initial Access

Ransomware operators rarely need to write sophisticated custom malware to break in. In most campaigns tracked across the industry, initial access comes from far more mundane weaknesses: exposed or poorly secured remote access points, stolen or reused credentials, unpatched software, and phishing emails that trick an employee into handing over a login.

Once inside, attackers typically move laterally through the network, escalate privileges, and locate backup systems before deploying the actual encryption payload. If backups are reachable from the same compromised network, or if remote desktop and VPN access aren't tightly controlled, the attackers have everything they need to lock down operations and demand payment. Data theft frequently happens in parallel, giving gangs a second lever of pressure: pay up or see your stolen files published publicly. The World Leaks Mediaworks breach illustrates exactly how damaging that second stage can be once stolen data ends up on a leak site for anyone to download.

The Real Cost of a Ransomware Hit on a Small Business

For a large corporation, a ransomware incident is painful but survivable. For a small business, it can be existential. Downtime during recovery means lost revenue with no cushion to absorb it. Customer trust erodes quickly when payroll, client records, or health information gets exposed. Legal and regulatory obligations still apply regardless of company size, and the cost of forensic investigation, system rebuilding, and potential ransom payment can wipe out cash reserves that many SMBs rely on to stay afloat.

The rivalry between Qilin and The Gentlemen adds urgency here. When groups compete on speed and volume rather than selectivity, businesses that assume they're too small to be worth an attacker's time are increasingly proven wrong.

Layered Defenses: VPNs, Backups, and Access Controls That Actually Help

SMBs don't need enterprise-scale budgets to meaningfully reduce risk, but they do need to close the gaps attackers rely on most.

  • Secure remote access. If employees or contractors connect remotely, that access should run through a properly configured VPN or zero-trust access tool with multi-factor authentication enabled, not an exposed remote desktop port sitting open to the internet.
  • Isolate and test backups. Backups stored on the same network as production systems are a liability, not a safety net. Offline or immutable backups, tested regularly for restoration, are what actually allow a business to recover without paying a ransom.
  • Limit privileged access. Not every employee needs administrative rights. Restricting access reduces how far an attacker can move once they get a foothold.
  • Patch consistently. Many ransomware intrusions exploit known vulnerabilities that already have available fixes. A regular patching cadence closes doors attackers are actively scanning for.

What This Means For You

If you run or manage IT for a small business, the Qilin and The Gentlemen rivalry is a reminder that ransomware groups are actively hunting for organizations exactly like yours. Assuming you're too small to attract attention is no longer a safe bet. The businesses that recover fastest from ransomware incidents are almost always the ones that had offline backups, restricted access controls, and secured remote connections in place before the attack, not after.

Key Takeaways

  • Ransomware attacks on small businesses are intensifying as rival gangs compete for targets and speed.
  • Weak remote access and poor credential hygiene remain the most common entry points.
  • Offline, tested backups are the single most reliable way to avoid paying a ransom.
  • Limiting privileged access slows attackers down even after a breach occurs.
  • Data theft often accompanies encryption, meaning proactive security matters even if you never plan to pay a ransom.

Staying ahead of ransomware attacks on small businesses doesn't require a massive security budget. It requires closing the basic gaps that gangs like Qilin and The Gentlemen are actively exploiting right now.