What is Qilin, the ransomware network now targeting Belgian organisations?
Belgian furniture retailer WEBA said it suffered a cyberattack in August 2026 as the Qilin ransomware network intensified its activity against organisations in Belgium. Customers should watch for convincing phishing attempts, avoid acting on unexpected payment or password requests, and verify messages through the company’s official contact details.
The immediate concern for Belgian customers is follow-on fraud using personal or transactional details to make phishing messages credible. More broadly, Qilin demonstrates how ransomware can interrupt ordinary services and, in sectors such as healthcare, contribute to physical harm rather than merely financial or privacy losses.
Belgian furniture retailer suffered a cyberattack on 10 August 2026, company spokesperson Elias Couvreur told Het Nieuwsblad, in the latest reported Belgian incident associated with the ransomware operation. The chain, which has stores in , , and , restored its main operations after the disruption, but the full extent of any data theft had not been publicly established at the time of reporting. For customers, the immediate advice is practical: treat unexpected messages mentioning an order, delivery, refund or payment as suspicious, and contact WEBA through details found independently on its official website rather than through a link in the message.
## What is ?
is the name attached to a ransomware-as-a-service operation, also known in earlier reporting as Agenda. The core operators develop and maintain malicious software and an extortion platform, while affiliates conduct intrusions and share any proceeds. That structure means Qilin is better understood as a criminal network or brand than as one fixed team whose membership and location are conclusively known.
Once inside an organisation, -linked attackers can encrypt systems, steal files or combine both methods. The stolen material then becomes leverage: victims may be threatened with publication if they refuse to pay. ’s Centre for Cybersecurity, or , says this combination of encryption, data exfiltration and escalating pressure has made ransomware incidents more damaging even when the number of reported cases is relatively stable.
The recorded 105 ransomware notifications in in 2025, compared with 109 in 2024. Its 2025 cyber-threat report identified , Akira and Clop among the active groups targeting Belgian organisations. It also assessed Qilin as a technically mature operator responsible for about 18% of claimed ransomware victims worldwide during 2025. A criminal group’s leak-site claim is not, however, independent proof that every alleged intrusion or stolen dataset is genuine.
Het Nieuwsblad reported that had entered the systems of 15 Belgian organisations in recent months before the incident. Separate threat-monitoring services also recorded a Qilin claim concerning Belgian travel company Connections in August, but no public technical evidence was available to verify the scale or method of that alleged intrusion. These distinctions matter: confirmed operational disruption, a criminal’s claim of responsibility and proof that particular customer records were stolen are three different things.
## Why the group’s record commands attention
became internationally notorious after the June 2024 attack on Synnovis, a pathology provider serving several National Health Service hospitals in south-east London. NHS England says the attack severely reduced laboratory capacity, disrupted appointments and led to stolen files being published. Services were fully restored by December 2024.
The NHS subsequently recorded that a patient died unexpectedly during the disruption and that delayed blood-test results contributed to the death. That finding illustrates why ransomware is not merely an IT or privacy problem: when laboratories, retailers, logistics firms or public services lose access to essential systems, the consequences move rapidly into the physical world. British authorities and reporting linked to the Synnovis attack, although identifying individual perpetrators remains a law-enforcement challenge.
## What should customers and residents do?
A breach at a familiar Belgian business can create a second wave of risk even before anyone knows exactly which records were taken. Criminals can use basic information—such as a name, email address, telephone number or knowledge of a recent purchase—to make a fraudulent message sound credible. A genuine-looking reference to a sofa delivery or unpaid balance does not prove that the sender is genuine.
If you receive such a message, do not use its link, attachment, telephone number or payment details. Open the retailer’s website yourself or call the store using a number from an invoice you already possess. Never disclose an itsme code, bank-card response code or password in response to an unsolicited request. Forward suspicious emails to suspicious@.be; in French-language guidance the same service is presented through Safeonweb’s “message suspect” pages. The federal portal is available in Dutch, French, German and English, which is useful for residents dealing with a gemeente or commune in a language other than their own.
Anyone who entered banking credentials should contact their bank immediately and call Card Stop on 078 170 170 if a payment card may be compromised. Change any exposed password, starting with the associated email account, and do not reuse it elsewhere. If money has been taken or there has been an extortion attempt, preserve messages, payment information and screenshots, then report the matter to your local police zone. The Federal Police advises ransomware victims to make a statement at the local police service; residents can find the appropriate zone by postcode through Police.be.
For a compromised home or work device, recommends disconnecting Wi-Fi or the network cable and removing external drives to limit further spread. Organisations should alert their IT or security lead, isolate affected systems, preserve evidence and use a separate communication channel. Both Safeonweb and the advise against paying: payment provides no assurance that files will be restored, stolen data deleted or access routes closed. Decryption tools for some ransomware families are available through the international No More Ransom project.
## The broader lesson for
’s prominence reflects an industrialised cybercrime market. Malware developers, access brokers and intrusion specialists can work as separate suppliers, allowing an operation to continue even when one affiliate or server is removed. The fall of LockBit did not end ransomware; according to the , it produced a more fragmented environment in which several groups compete for victims.
is not among Europe’s most-targeted countries in absolute terms, the says, but its retailers, healthcare providers, logistics businesses and multilingual customer databases remain attractive. The risk is national rather than confined to one region: a company may serve Dutch-speaking customers through a gemeente, French-speaking residents through a commune and international clients in English while relying on the same interconnected systems.
’s investigation and any legally required notifications should clarify whether personal information was extracted and which people, if any, need to take further action. Until then, customers should avoid assuming either that their data was stolen or that silence proves it was safe. The most useful response is measured vigilance: verify unusual requests, secure reused passwords and rely on updates from WEBA, the , and the police rather than screenshots or claims circulating on social media.
Impact
Regional — WEBA has outlets serving customers across Flanders and Wallonia, including Ghent, Deinze, Tongeren and Mons. Any customer communication therefore needs to be accessible in Dutch and French, with clear guidance for international residents where possible.
Local — WEBA serves customers through outlets in Ghent, Deinze, Tongeren and Mons, giving the incident a direct footprint across Flemish and Walloon cities. Customers in these areas may receive messages that appear credible because they reference genuine purchases or account details. WEBA’s incident communications should therefore be available clearly in Dutch and French, with accessible guidance for international residents. Local customers should verify unusual payment, delivery, refund or password requests through contact details obtained independently from WEBA’s official channels.
International — Qilin’s affiliate-based model makes the threat inherently cross-border: operators provide infrastructure that can be used against organisations in different countries, while attribution remains difficult. The 2024 Synnovis incident in England provides a concrete comparison, with NHS England reporting disrupted pathology services and exposure of stolen files. For EU institution staff and internationally mobile residents in Belgium, the practical risk is that stolen information can support convincing multilingual fraud regardless of where the attacker is located. No specific EU institutional response is identified in the article.
What it means for you
If you have dealt with WEBA, be cautious about unexpected emails, texts or calls concerning payments, refunds, deliveries, passwords or account access, particularly following the reported 10 August 2026 attack. Do not use links, phone numbers or bank details contained in a suspicious message; contact WEBA through details obtained from its official website or existing paperwork. Never share passwords or one-time security codes. If a device is infected, Safeonweb advises disconnecting it from networks, not paying the ransom and reporting the incident to local police. Preserve suspicious messages and transaction records as evidence.
Opposing perspectives
- Belgian cyber authorities and police
The CCB, Safeonweb and Federal Police advise organisations to isolate affected systems, preserve evidence, report the incident and avoid paying. Their position is that payment offers no reliable recovery guarantee and sustains the criminal ransomware economy.
- Victim organisations facing operational collapse
Companies responsible for restoring payroll, deliveries, laboratories or other essential systems may face intense pressure to consider every recovery option. Their immediate priority can conflict with the authorities’ wider objective of making ransomware unprofitable, although paying still cannot guarantee deletion or restoration.
- Ransomware operators and their affiliates
Qilin-linked criminals present leak-site listings as evidence of successful compromise and use publication deadlines to intensify pressure. Those claims serve an extortion purpose and should not be treated as verified accounts of what was accessed, stolen or encrypted.
Who, where and what
Key people, places and terms in this story
Country where WEBA operates and where authorities recorded 105 ransomware notifications in 2025.
Belgian region served by WEBA outlets and requiring Dutch-language customer communication.
Belgian region served by WEBA outlets and requiring French-language customer communication.
Flemish city with a WEBA outlet serving local customers.
Walloon city with a WEBA outlet serving local customers.
Show the full library (15)
Country where WEBA operates and where authorities recorded 105 ransomware notifications in 2025.
Belgian region served by WEBA outlets and requiring Dutch-language customer communication.
Belgian region served by WEBA outlets and requiring French-language customer communication.
Flemish city with a WEBA outlet serving local customers.
Walloon city with a WEBA outlet serving local customers.
Flemish city with a WEBA outlet serving local customers.
Flemish city with a WEBA outlet serving local customers.
Ransomware-as-a-service network identified among the most active operations targeting Belgian organisations.
Earlier name associated with the Qilin ransomware operation.
Belgian furniture retailer that reported a cyberattack affecting its operations on 10 August 2026.
Belgian national cybersecurity authority that recorded ransomware notifications and identified Qilin as a leading threat.
Abbreviation used for the Centre for Cybersecurity Belgium in the article’s key facts.
Belgian public cybersecurity service providing advice to ransomware victims and consumers.
Belgian cybersecurity resource providing ransomware guidance for organisations.
Police institution providing information on reporting ransomware crimes in Belgium.
Sources & evidence
- View sourceHet Laatste NieuwsPrimaryprimary· hln.beRetrieved 29 August 2026
- View sourceHet Nieuwsbladcorroborating· nieuwsblad.be· 20 August 2026Retrieved 29 August 2026· 43 days ago· Dated
- View sourceCentre for Cybersecurity Belgiumofficial· ccb.belgium.be· 26 March 2026Retrieved 29 August 2026· 190 days ago· Dated
- View sourceSafeonweb at Workofficial· atwork.safeonweb.be· 18 May 2026Retrieved 29 August 2026· 137 days ago· Dated
Related topics
Related to this story
Live connections from the Belgium Impulse ecosystem — not recommendations.
This briefing was prepared with AI assistance and reviewed by a Belgium Impulse editor before publication. methodology.



