LifestyleTechnology
Cybersecurity

What is Qilin, the ransomware network now targeting Belgian organisations?

Belgian furniture retailer WEBA said it suffered a cyberattack in August 2026 as the Qilin ransomware network intensified its activity against organisations in Belgium.

Belgium Impulse Editorial·31 August 2026·6 min read·
Well established· 1 primary source + 5 official documents + 2 independent reporting sources
TopicsQilin ransomwareWEBA cyberattackCentre for Cybersecurity BelgiumSafeonwebBelgian ransomwareSynnovis cyberattackransomware-as-a-service

In 30 seconds

  • WEBA said the attack occurred on 10 August 2026 and affected the Belgian furniture chain’s operations.
  • The CCB recorded 105 Belgian ransomware notifications in 2025, against 109 in 2024.
  • The CCB identified Qilin among the most active ransomware operations targeting Belgian organisations.
  • NHS England says the 2024 Synnovis attack disrupted pathology services and exposed stolen files.

Belgian furniture retailer WEBA suffered a cyberattack on 10 August 2026, company spokesperson Elias Couvreur told Het Nieuwsblad, in the latest reported Belgian incident associated with the Qilin ransomware operation. The chain, which has stores in

Place

Ghent

Flemish city with a WEBA outlet serving local customers.

Why it matters

Flemish city with a WEBA outlet serving local customers.

About

Ghent is a city and a municipality in the East Flanders province of the Flemish Region of Belgium. It is the capital and largest city of the province and the third largest in the country, after Brussels and Antwerp. It is a port and university city.

, Deinze, Tongeren and
Place

Mons

Walloon city with a WEBA outlet serving local customers.

Why it matters

Walloon city with a WEBA outlet serving local customers.

About

Mons is a commune in the Var department in the Provence-Alpes-Côte d'Azur region in southeastern France.

, restored its main operations after the disruption, but the full extent of any data theft had not been publicly established at the time of reporting. For customers, the immediate advice is practical: treat unexpected messages mentioning an order, delivery, refund or payment as suspicious, and contact WEBA through details found independently on its official website rather than through a link in the message.

What is Qilin?

Qilin is the name attached to a ransomware-as-a-service operation, also known in earlier reporting as Agenda. The core operators develop and maintain malicious software and an extortion platform, while affiliates conduct intrusions and share any proceeds. That structure means Qilin is better understood as a criminal network or brand than as one fixed team whose membership and location are conclusively known.

Once inside an organisation, Qilin-linked attackers can encrypt systems, steal files or combine both methods. The stolen material then becomes leverage: victims may be threatened with publication if they refuse to pay. Belgium’s Centre for Cybersecurity, or CCB, says this combination of encryption, data exfiltration and escalating pressure has made ransomware incidents more damaging even when the number of reported cases is relatively stable.

The CCB recorded 105 ransomware notifications in Belgium in 2025, compared with 109 in 2024. Its 2025 cyber-threat report identified Qilin, Akira and Clop among the active groups targeting Belgian organisations. It also assessed Qilin as a technically mature operator responsible for about 18% of claimed ransomware victims worldwide during 2025. A criminal group’s leak-site claim is not, however, independent proof that every alleged intrusion or stolen dataset is genuine.

Het Nieuwsblad reported that Qilin had entered the systems of 15 Belgian organisations in recent months before the WEBA incident. Separate threat-monitoring services also recorded a Qilin claim concerning Belgian travel company Connections in August, but no public technical evidence was available to verify the scale or method of that alleged intrusion. These distinctions matter: confirmed operational disruption, a criminal’s claim of responsibility and proof that particular customer records were stolen are three different things.

Why the group’s record commands attention

Qilin became internationally notorious after the June 2024 attack on Synnovis, a pathology provider serving several National Health Service hospitals in south-east London. NHS England says the attack severely reduced laboratory capacity, disrupted appointments and led to stolen files being published. Services were fully restored by December 2024.

The NHS subsequently recorded that a patient died unexpectedly during the disruption and that delayed blood-test results contributed to the death. That finding illustrates why ransomware is not merely an IT or privacy problem: when laboratories, retailers, logistics firms or public services lose access to essential systems, the consequences move rapidly into the physical world. British authorities and reporting linked Qilin to the Synnovis attack, although identifying individual perpetrators remains a law-enforcement challenge.

What should customers and residents do?

A breach at a familiar Belgian business can create a second wave of risk even before anyone knows exactly which records were taken. Criminals can use basic information—such as a name, email address, telephone number or knowledge of a recent purchase—to make a fraudulent message sound credible. A genuine-looking reference to a sofa delivery or unpaid balance does not prove that the sender is genuine.

If you receive such a message, do not use its link, attachment, telephone number or payment details. Open the retailer’s website yourself or call the store using a number from an invoice you already possess. Never disclose an itsme code, bank-card response code or password in response to an unsolicited request. Forward suspicious emails to [email protected]; in French-language guidance the same service is presented through Safeonweb’s “message suspect” pages. The federal portal is available in Dutch, French, German and English, which is useful for residents dealing with a gemeente or commune in a language other than their own.

Anyone who entered banking credentials should contact their bank immediately and call Card Stop on 078 170 170 if a payment card may be compromised. Change any exposed password, starting with the associated email account, and do not reuse it elsewhere. If money has been taken or there has been an extortion attempt, preserve messages, payment information and screenshots, then report the matter to your local police zone. The Federal Police advises ransomware victims to make a statement at the local police service; residents can find the appropriate zone by postcode through Police.be.

For a compromised home or work device, Safeonweb recommends disconnecting Wi-Fi or the network cable and removing external drives to limit further spread. Organisations should alert their IT or security lead, isolate affected systems, preserve evidence and use a separate communication channel. Both Safeonweb and the CCB advise against paying: payment provides no assurance that files will be restored, stolen data deleted or access routes closed. Decryption tools for some ransomware families are available through the international No More Ransom project.

The broader lesson for Belgium

Qilin’s prominence reflects an industrialised cybercrime market. Malware developers, access brokers and intrusion specialists can work as separate suppliers, allowing an operation to continue even when one affiliate or server is removed. The fall of LockBit did not end ransomware; according to the CCB, it produced a more fragmented environment in which several groups compete for victims.

Belgium is not among Europe’s most-targeted countries in absolute terms, the CCB says, but its retailers, healthcare providers, logistics businesses and multilingual customer databases remain attractive. The risk is national rather than confined to one region: a company may serve Dutch-speaking customers through a gemeente, French-speaking residents through a commune and international clients in English while relying on the same interconnected systems.

WEBA’s investigation and any legally required notifications should clarify whether personal information was extracted and which people, if any, need to take further action. Until then, customers should avoid assuming either that their data was stolen or that silence proves it was safe. The most useful response is measured vigilance: verify unusual requests, secure reused passwords and rely on updates from WEBA, the CCB, Safeonweb and the police rather than screenshots or claims circulating on social media.

Who’s affectedWEBA customersresidents of Ghent and Deinzeresidents of Tongeren and MonsBelgian retailersBelgian organisations handling customer dataBrussels expats and international residentscybersecurity teams in Belgium
Context & what happens next

What to do

If you have dealt with WEBA, be cautious about unexpected emails, texts or calls concerning payments, refunds, deliveries, passwords or account access, particularly following the reported 10 August 2026 attack. Do not use links, phone numbers or bank details contained in a suspicious message; contact WEBA through details obtained from its official website or existing paperwork. Never share passwords or one-time security codes. If a device is infected, Safeonweb advises disconnecting it from networks, not paying the ransom and reporting the incident to local police. Preserve suspicious messages and transaction records as evidence.

Impact

Regional — WEBA has outlets serving customers across Flanders and Wallonia, including Ghent, Deinze, Tongeren and Mons. Any customer communication therefore needs to be accessible in Dutch and French, with clear guidance for international residents where possible.

Evidence
Well established · 1 primary source + 5 official documents + 2 independent reporting sources
Explore evidence
Het Laatste Nieuws
Publication date unavailable
Retrieved by ODIN:
29 Aug 2026
Read original
Het Nieuwsblad
Published:
20 Aug 2026, 02:00
Retrieved by ODIN:
29 Aug 2026
Read original
Centre for Cybersecurity Belgium
Published:
26 Mar 2026, 01:00
Retrieved by ODIN:
29 Aug 2026
Read original
Safeonweb at Work
Published:
18 May 2026, 02:00
Retrieved by ODIN:
29 Aug 2026
Read original
Belgian Federal Police
Published:
30 Jun 2017, 02:00
Retrieved by ODIN:
29 Aug 2026
Read original
NHS England
Published:
10 Nov 2025, 01:00
Retrieved by ODIN:
29 Aug 2026
Read original
Associated Press
Published:
5 Jun 2024, 02:00
Retrieved by ODIN:
29 Aug 2026
Read original

Voices & reactions

What the main actors are doing

Reported positions, summarised — not direct quotations

Belgian cyber authorities and police

The CCB, Safeonweb and Federal Police advise organisations to isolate affected systems, preserve evidence, report the incident and avoid paying. Their position is that payment offers no reliable recovery guarantee and sustains the criminal ransomware economy.

Victim organisations facing operational collapse

Companies responsible for restoring payroll, deliveries, laboratories or other essential systems may face intense pressure to consider every recovery option. Their immediate priority can conflict with the authorities’ wider objective of making ransomware unprofitable, although paying still cannot guarantee deletion or restoration.

Ransomware operators and their affiliates

Qilin-linked criminals present leak-site listings as evidence of successful compromise and use publication deadlines to intensify pressure. Those claims serve an extortion purpose and should not be treated as verified accounts of what was accessed, stolen or encrypted.

The story, connected

Explore the people, places and ideas in this story

Go beyond the headline. Open a card for sourced context, maps, official links and the other subjects connected to this report.

Places

Ghent

Flemish city with a WEBA outlet serving local customers.

In this story

Flemish city with a WEBA outlet serving local customers.

Background

Ghent is a city and a municipality in the East Flanders province of the Flemish Region of Belgium. It is the capital and largest city of the province and the third largest in the country, after Brussels and Antwerp. It is a port and university city.

Places

Mons

Walloon city with a WEBA outlet serving local customers.

In this story

Walloon city with a WEBA outlet serving local customers.

Background

Mons is a commune in the Var department in the Provence-Alpes-Côte d'Azur region in southeastern France.

Continue reading

Powered by ODIN™An Ordinis creation · © 2026 Ordinis

This story was assembled from verified evidence, with its sources and reasoning recorded as it was written.

methodology.