Methodology
The findings in this report are the result of a comprehensive year-long investigation conducted by the Black Kite Research Group™, covering the period between April 1, 2025, and March 31, 2026. The methodology combines continuous monitoring of ransomware operations with detailed victim analysis and dark web intelligence gathering.
1. Ransomware Group Monitoring
The Black Kite Research Group monitored activity from nearly 300 ransomware groups, tracking their leak sites, extortion posts, and public disclosures. A group was considered “active” if it published at least one victim within the last 12 months. By June 2026, 146 groups met this threshold.
Legacy and new actor cohorts were classified by each actor brand’s first observed victim disclosure date across Black Kite’s combined current and historical ransomware dataset. Actors first observed before April 1, 2025 were classified as legacy, while those first observed on or after April 1, 2025 were classified as new.
2. Victim Enumeration and Analysis
A total of 7,551 victims were identified through leak site monitoring, cross-validated with open-source intelligence and internal telemetry. For each victim, the Black Kite Research Group analysts determined:
- Industry classification using NAICS codes
- Headquarters location by country
- Estimated company size based on publicly available financials or trusted databases
- Revenue analysis included more than 6,000 victims with known or reliably estimated annual revenue. Victims without sufficient revenue information were excluded from revenue-band calculations.
The Black Kite Research Group also leveraged the Black Kite platform to assess each victim’s cybersecurity posture before and after the incident, helping to identify patterns in susceptibility and exposure. Stealer-log exposure (the average number of stealer-log records associated with each victim) was measured at both points, comparing the value recorded at public disclosure against the latest available scan for the same victim population.
3. Dark Web and Telegram Intelligence
To complement leak site tracking, the Black Kite Research Group actively monitored ransomware blogs, Telegram channels, and dark web forums to identify group narratives, affiliate activity, and coordination patterns. This enabled the team to detect new groups quickly and contextualize victim disclosures beyond surface-level postings.
4. Limitations
The dataset reflects only publicly disclosed victims. Many incidents, especially those involving smaller companies or settled quietly, are never made public. As a result, this report represents a conservative baseline, with the actual number of ransomware attacks likely much higher.
The Black Kite Research Group uses standardized methodology to avoid overcounting. For example, attacks affecting chains of clinics, dealer networks, or affiliated subsidiaries are treated as a single victim where appropriate, unless separate disclosures exist.
About The Black Kite Research Group™
The Black Kite Research Group is Black Kite's dedicated threat research unit responsible for ransomware tracking, threat actor profiling, vulnerability intelligence, FocusTag® development, and the production of Black Kite's annual and periodic research publications.
