Introduction


How Ransomware Changed This Year

Ransomware has been growing for four years. This year, how it grows has changed.


Black Kite has tracked ransomware disclosures since 2022. In that time, the victim count moved from roughly 2,700 in the first reporting period to 4,893, then 6,046, and now 7,551. The active group count rose from 61 to 79, then 96, then 127 at the close of the current period, with post-period monitoring reaching 146 by June 2026. The trend line is clear: more victims, more operators, more market surface, every year.

Four Years of Growth: Victims and Active Groups, 2023–2026

But in previous years, the growth followed a recognizable narrative structure. There was usually a dominant actor, or a dramatic collapse, or a single supply chain event large enough to anchor the story. LockBit defined one year. The AlphV and LockBit disruptions defined the next. RansomHub's rapid rise gave the previous period its main character.

This year had no main character. It had a market.

The 2026 Market in Three Moves

Expanded at the bottom

61 new groups entered during the reporting period — more than one per week. They added volume on top of incumbents rather than replacing them, pushing the total active group count to 127 by period close and 146 by June 2026.

Concentrated at the top

Despite the flood of new entrants, the five largest actors still controlled 43.6% of all victims. More brands in the market did not mean more distributed power. It meant a crowded field with a dominant tier.

Accelerated in the second half

The first half tracked close to the prior year baseline. Then the second half outpaced it by 60%, closing with 861 victims in March 2026 — the highest monthly total in four years of tracking.

The most damaging incidents came from supply chain exposure, mass exploitation campaigns, SaaS integration abuse, and affiliate mobility across brands — not from a single dominant group.

The result is a ransomware economy that looks less like a hierarchy and more like a market: fragmented, operationalized, and scaling through multiple playbooks at once.

What Changed Year Over Year

2025 Report
2026 Report
Change
Total Victims
6,046
7,551
+24.9%
Active Groups
96
127 (146 by June 2026)
+32.3%
New Groups Entered
55
61
+10.9%
Top Actor
RansomHub (736 victims)
Qilin (1,358 victims)
—
Qilin Victims
250
1,358
+443%
US Share of Victims
51.9%
49.3%
-2.6pp
Mid-Market Victim Share
25.1%
29.3%
+4.2pp

The chapters that follow move from ecosystem scale to individual exposure. They begin with the numbers, move through actor models and supply chain pressure, examine the economics, and close with what the data shows about persistent exposure after the incident is over.

The ransomware threat became more structured, more distributed, and harder to read from victim count alone this year.

About This Dataset

This report covers the period from April 1, 2025 through March 31, 2026. The primary dataset includes 7,551 publicly disclosed ransomware victims identified through leak site monitoring and validated by the Black Kite Research Group™. Before and after security postures, current state exposure analysis, and post-period April–June 2026 activity are treated as separate scopes. Post-period data is used only as supplementary context and excluded from primary year over year calculations. Learn more about the methodology of this report.

Next: 7,551 victims. Here's who they were.

Geography, industry, and revenue all shaped who ransomware groups targeted.

PREVIOUS
NEXT