Incident analysis
Hagiva Yh was listed by Qilin ransomware, a group with 2,388 victims recorded in this database. The listing appeared on the group's leak site on October 9, 2026.
Hagiva Yh is based in Israel. Israel ranks #21 worldwide for ransomware disclosures, with 147 victims in this database.
Qilin typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.