Ukraine
UARansomware victim intelligence profile ยท Ranked #105 globally ยท Updated: Sep 5, 2026
ThreatAI Analysis
Compiled from this database and the ransomware.live profiles of the groups active in Ukraine. Figures are computed from the tracked records, not inferred.
Ukraine has recorded six ransomware incidents globally, ranking 104th in terms of activity, with Qilin, Dragonforce, and Nova groups top among most active perpetrators across public sector, manufacturing, and transportation/logistics sectors where threats cluster heavily.
Ukraine in the global picture
Ukraine accounts for 6 of the ransomware disclosures tracked here, ranking #105 worldwide and making up 0% of the global total. The sectors listed most often are Public Sector, Manufacturing, Transportation/Logistics.
Who is most active in Ukraine
Qilin โ 4 victims in Ukraine. Qilin ransomware was first observed in July of 2022. Dragonforce โ 1 victims in Ukraine. Nova โ 1 victims in Ukraine. Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victimsโfiles and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
Where to report an incident in Ukraine
- Computer Security Incident Response Team of the National bank of Ukraine ยท [email protected]
National computer emergency response teams for Ukraine, as registered with ENISA and the teams themselves. Regional, sectoral and vendor response teams are excluded; verify current contact details before relying on them in an incident.
Ransomware Threat Profile: Ukraine
Ukraine ranks #105 globally for ransomware attacks, with 6 confirmed victims in this database โ representing 0% of the worldwide total. The most active ransomware groups targeting Ukraine include Qilin, Dragonforce, Nova.
The most frequently targeted industries in Ukraine are Public Sector, Manufacturing, Transportation/Logistics. Manufacturing organisations are attractive targets because production downtime directly impacts revenue, creating strong incentives to restore operations by paying the ransom.
Ukraine's attack volume reflects broader trends in ransomware targeting: the volume of attacks reflects the country's integration into the global economy and the proliferation of ransomware operations that target organisations of all sizes worldwide.
Organisations in Ukraine should consider the active threat groups documented here when assessing their cybersecurity posture, implementing detection rules, and prioritising incident response planning.
Recent Victims in Ukraine (showing 6 of 6)
| # | Organization | Group | Sector | Date |
|---|---|---|---|---|
| 1 | SHERIFF | Qilin | Public Sector | May 12, 2026 |
| 2 | Lexus | Qilin | Manufacturing | May 4, 2026 |
| 3 | wmsopko.com | Dragonforce | Manufacturing | Apr 27, 2026 |
| 4 | Stark Shipping | Nova | Transportation/Logistics | Nov 15, 2025 |
| 5 | Ministry of Foreign Affairs of Ukraine | Qilin | Public Sector | Mar 6, 2025 |
| 6 | favbet | Qilin | Business Services | Dec 16, 2024 |
Frequently Asked Questions
How many ransomware attacks have occurred in Ukraine?
Ukraine has recorded 6 ransomware victim disclosures in this database, ranking #105 globally. This represents 0% of all tracked ransomware attacks worldwide.
Which ransomware groups target Ukraine?
The ransomware groups most active in Ukraine are Qilin, Dragonforce, Nova. These groups collectively account for the majority of victim disclosures attributed to Ukraine.
Which industries are most targeted by ransomware in Ukraine?
In Ukraine, the most frequently targeted sectors are Public Sector, Manufacturing, Transportation/Logistics. These industries hold valuable data and often have critical operational requirements that make them attractive ransomware targets.
How does Ukraine rank globally for ransomware attacks?
Ukraine ranks #105 globally for ransomware attacks with 6 victim disclosures, representing 0% of the worldwide total of 21,376 tracked victims.
How can organisations in Ukraine protect against ransomware?
Organisations in Ukraine should implement a layered security approach including regular offline backups, network segmentation, multi-factor authentication, endpoint detection and response (EDR) tools, and employee security awareness training. Monitoring threat intelligence feeds for active groups targeting Ukraine is also recommended.