2026 Ransomware Report
Why Every Year Becomes the Worst Year on Record
By The Black Kite Research Group™
Executive Summary
Between April 2025 and March 2026, Black Kite observed 7,551 publicly disclosed ransomware victims, a 24.9% increase from the previous reporting period. The threat actor ecosystem grew at an accelerated pace in the second half, reaching 127 active groups by the end of the reporting period, and continued to fragment after the cutoff, reaching 146 active groups by June 2026. It also became more operationalized in how actors launched brands, timed disclosures, and converted access into pressure.
The year's most consequential events came through the supply chain, where trusted vendor platforms became attack paths. The before and after security posture comparison also showed that exposure did not close when incidents did: stealer log exposure was 175% higher, and the latest security posture analysis showed that 43.5% of victims still carried critical patch vulnerabilities. In addition, AI did not redefine ransomware, but it lowered the cost of the attack and the work around it.
How to Read This Report
Ransomware is getting more complicated, year over year. This year it got more structured, more distributed, and harder to read from victim count alone.
- Volume surged 60% in the second half of the reporting period and has not come back down.
- New groups entered at a rate of more than one per week.
- AI hasn’t created that acceleration (yet), but it lowered the cost of entry enough that more actors could participate and suggests they could be scaling in anticipation of what comes next: AI-accelerated vulnerability discovery, faster exploitation cycles, and social engineering at scale.
This report is designed to give you the full picture and a clear path to action.
1 | Establish scale with victim data.
You'll see how 7,551 victims broke down by geography, industry, and revenue — and what signals those organizations were already carrying before ransomware groups ever showed up. These are likely the same signals visible in your vendors' environments right now.
2 | Map the ransomware operators.
The ecosystem expanded rapidly, but volume remained concentrated. A handful of operators accounted for a disproportionate share of all disclosed victims. The question is why the number keeps climbing and what that signals about where ransomware is headed.
3 | Examine attack methods and the supply chain surface they exploit.
The year's most consequential attacks moved through trusted vendor platforms via SaaS integrations, enterprise applications, OAuth connections, and support workflows. The perimeter, for many organizations, is now wherever their vendors are.
Chapter 05 | Actor Models and Chapter 06 | Supply Chain Attacks
4 | See where Black Kite data shows risk actually sits.
You’ll see who carried the most exposure before being hit and what the Ransomware Susceptibility Index® (RSI™) and FocusTag® risk intelligence signals reveal about where ransomware risk is visible before an attack happens and what stays exposed after one does.
5 | Dig deeper into AI and more.
For readers who want to go deeper, the final chapters cover payment pressure tactics, the persistence of post-incident exposure, what the signal layer shows today, and what AI actually changed — and didn't change — about how ransomware operates.
Chapter 08 | Ransomware Payments, Chapter 09 | The Aftermath, Chapter 10 | Current Exposure, and Chapter 11 | AI and Ransomware
Key Findings
ransomware victims observed — up 24.9% year over year.
the acceleration in second half volume above first half pace; March 2026 set an all-time monthly record at 861 victims.
active groups by June 2026, up from 127 at period close, with 61 new groups entering during the reporting period.
victims claimed by Qilin — nearly 2x its nearest rival.
Nearly doubled:
the $1M–$5M revenue band's share of victims, while the $100M+ enterprise tier contracted from 13.9% to 9.5%.
of known-revenue victims fell in the $50M–$100M mid-core segment, up from 25.1% — the strongest share gain of any band.
of victims still carried critical patch vulnerabilities in the latest assessment; 30.8% carried KEV exposure and 18.5% carried FocusTag® signals.
higher stealer log exposure in the before and after security posture comparison.
Oracle E-Business Suite (EBS) and Salesforce
ecosystem integrations defined several of the year's most visible supply chain incidents.
Mixed payment pressure:
payment rates remained low in some datasets, while large data theft incidents still produced significant payment amounts
What Makes This Report Different
Most ransomware research focuses on the attacker side — threat actor profiles, TTPs, attribution. That has value, but it tells you who is doing this, not who is getting hit and why.
This report focuses on victims. Every one of the 7,551 organizations in this dataset was identified through direct monitoring of ransomware group leak sites and validated by the Black Kite Research Group™, a dedicated team of researchers who track ransomware operations, develop risk intelligence, and publish the vulnerability and breach analysis that feeds directly into the Black Kite platform. That foundation makes it possible to analyze victim patterns at scale: where they operate, what industries they're in, what revenue bands they fall into, and what signals they were already carrying before they were ever named.
That last part is what separates this analysis. Black Kite held external security posture data on victims captured before their disclosures, and continued monitoring after incidents closed. The warnings were often already visible. And in most cases, the exposure didn't fully close when the incident did.
That combination — victim-pattern analysis, pre-disclosure signals, and post-incident persistence — is what makes the findings here different from a headcount. The numbers describe the scale. The posture data explains why it keeps growing.

TABLE OF CONTENTS

02 | INTRODUCTION
How Ransomware Changed This Year

03 | RANSOMWARE VICTIM ANALYSIS
Who Got Hit, and Why the Profile Changed

04 | THREAT ACTORS SURGE
One New Group Every Week

05 | ACTOR MODELS
How Ransomware Groups Choose Their Targets

06 | SUPPLY CHAIN ATTACKS
How One Vendor Becomes Many Victims

07 | AVOIDING RANSOMWARE
How Black Kite Pinpoints Ransomware Risk

08 | RANSOMWARE PAYMENTS
What Ransomware Actually Costs

09 | THE AFTERMATH
Did the Risk Actually Go Away?

10 | CURRENT EXPOSURE
What Victims Are Still Showing Today

11 | AI AND RANSOMWARE
Lowering the Cost of the Attack

12 | NEXT STEPS
From Intelligence to Action

13 | METHODOLOGY
Next: Four years of growth, but this year, the growth changed shape.
Volume alone doesn't capture what shifted in 2026. Learn what makes this year's data different from the four that came before it.