Why Ransomware Accelerated 60% in Six Months
Published
Jul 28, 2026
Authors
Introduction
7,551 ransomware victims between April 2025 and March 2026. That's a 24.9% jump year over year, enough on its own to demand attention. But the annual average buries the more important story: Ransomware jumped 60% in the latest six-month window.
The Acceleration, By the Numbers
The first half of the reporting period looked almost boring. From April through September 2025, Black Kite tracked 2,904 ransomware victims, an average of 484 a month, close to where the prior year's baseline sat. Then October hit, and the market changed shape.
From October 2025 through March 2026, monthly victim counts jumped to 775 on average. That's a 60% acceleration in six months. March 2026 alone closed the period at 861 victims, the highest single month in four years of tracking.
This wasn't a one-month fluke. Every month from October through March stayed above 700 disclosed victims. Six consecutive months above 700 means the ransomware economy found a new operating tempo, not a temporary surge.
Three Forces Stacked at Once
No single group, exploit, or vulnerability explains a 60% jump. Three separate dynamics compounded in the same six-month window, and any one of them alone would have been a notable story on its own.
- New groups piled on volume. Sixty-one new ransomware groups entered the ecosystem during the reporting period, more than one a week, and 32 of them showed up in the second half alone, stacking directly on top of an incumbent base that kept operating right alongside them.
- New entrants shifted the map. Established actors still aimed the majority of their attacks (53%) at the US. New entrants sent only 38.7% of their attacks there, spreading the rest into Europe, Brazil, Thailand, and the UAE. The market got bigger. It also got wider.
- Qilin redefined the unit of attack. One compromise of a managed service provider gave Qilin reach into 32 South Korean financial institutions in a single event. One vendor, dozens of victims, one incident that counted as 32 in the data.
Qilin's math alone explains a lot of the acceleration. The group went from 250 victims in the prior reporting period to 1,358 this year, a 443% increase, making it responsible for roughly one in every five to six victims Black Kite observed. That kind of scale comes from finding one vendor everyone downstream trusts. Black Kite flagged the same pattern when ShinyHunters compromised Salesforce's Experience Cloud and when stolen OAuth tokens turned the Salesloft Drift breach into a multi-tenant Salesforce incident. This year's ransomware story and its supply chain risk story were never really two different stories.
AI Lowered the Barrier. Humans Did the Rest.
Ransomware reports usually lead with victim counts. This year's strangest data point is a lifespan. Groups that first appeared between April and September 2025 lasted a median of 4.9 months. Groups that first appeared in that same window a year earlier lasted 12.8 months. New ransomware brands don't last half as long as they used to.
That tracks with how cheap it's become to build and launch a ransomware operation. Open-source LLMs and code assistants put ransomware development within reach of operators who couldn't have written a functioning encryptor a year ago. FunkSec gave us an early look at what that produces: software that launches, posts a batch of victims, and breaks. Ransomware is still software, and vibe-coded software behaves like vibe-coded software everywhere else.
I want to be careful here. I can't prove AI caused this acceleration. What I can say is that the timing lines up too well to ignore: the flood of short-lived entrants, the rising capability of groups that shouldn't have existed a year ago, and the acceleration itself all land in the same six-month window. AI's contribution is a wider on-ramp: more people able to show up and try their hand at it.
The Surge Held and Became the Floor
If the second half was a fluke, the numbers should have come back down. They didn't. Post-period data through June 2026 shows ransomware volume holding at 743 victims a month, well above the first-half baseline and only slightly under the second-half pace. Active groups kept climbing too, from 127 at the close of the reporting period to 146 by June, with 29 more new entrants in just three months.
Geography kept shifting in the same direction, too. US concentration fell again, from 49.3% during the reporting period to 39.9% in the post-period window. Every trend line from the acceleration held steady after the cutoff instead of correcting.
That's the throughline of this report, and every report before it. Ransomware doesn't get better. It gets more distributed, more procedural, and harder to read from victim count alone.
How to See the Next Surge Coming
Victim counts tell you what already happened. Ransomware Susceptibility Index® (RSI™) tells you what's likely to happen next. Across this year's victim population, organizations sitting in the higher RSI bands carried dramatically higher odds of being hit. Companies with an average RSI between 0.6 and 0.8 were 54 times more likely to experience a ransomware attack than those with an RSI under 0.2. Companies in the 0.8 to 1.0 range were 291 times more likely, and 41% of them were actually hit.
That gap is the entire point of building a susceptibility model instead of counting breaches after the fact. RSI combines exposure, the technical indicators like unpatched vulnerabilities, misconfigurations, and stealer logs, with predisposition, the intrinsic factors like industry, geography, and revenue that don't change no matter how well a vendor patches. A cyber rating tells you how a vendor looks today. RSI tells you how likely that vendor is to end up on a leak site next.
In a year where volume jumped 60% in six months and the floor never came back down, waiting for a breach notification isn't a strategy. Neither is treating this year's acceleration as a one-time anomaly. Every prior Black Kite ransomware report has found the same pattern with different numbers attached to it: the ecosystem gets bigger, more fragmented, and harder to read from a victim count alone. This year just made the case more forcefully than most.
Read the full 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record for the complete data set, and see how RSI flags rising ransomware risk across your vendor ecosystem before it becomes your problem.
Dr. Ferhat Dikbiyik is the Chief Research & Intelligence Officer at Black Kite, where he leads the Black Kite Research Group™ analyzing ransomware trends, threat actor behavior, and third-party breach data.