Ransomware Victim Analysis


Who Got Hit, and Why the Profile Changed

The Second Half Changed Everything


Black Kite observed 7,551 ransomware victims between April 1, 2025 and March 31, 2026, up from 6,046 in the previous reporting period. That represents a 24.9% year over year increase. On a monthly basis, the annual average rose from roughly 504 victims per month to 629.

But the annual average hides the real shift.

The first half of the period, from April through September 2025, produced 2,904 victims, or 484 per month on average. That pace was close to the prior year monthly baseline. The second half changed the picture entirely. From October 2025 through March 2026, ransomware disclosures rose to 4,647 victims, or 775 per month on average, a 60% acceleration from the first half.

March 2026 closed the period with 861 victims, the highest monthly total observed during the series. More importantly, the surge was sustained. Every month from October 2025 through March 2026 stayed above 700 victims, showing that the second half was not a single spike but a new operating tempo.

Ransomware victims between April 1, 2025 and March 31, 2026

Victims in the previous reporting period

Several forces contributed to this acceleration. Qilin scaled sharply in the second half and became the period’s clearest volume engine. New entrants also accumulated throughout the year, with 32 new groups appearing in the second half alone. These groups added fresh volume rather than merely replacing older brands. Some new groups also chose to announce their presence by disclosing large numbers of victims on a single day, using high-volume first appearances to signal immediate capability and establish market visibility. At the same time, some established groups declined or disappeared, showing that the market was not rising evenly. Momentum was shifting between brands.

H1 vs. H2 Monthly Victim Pace: The Acceleration That Didn't Stop

This is the first sign of the report’s larger theme: the ransomware ecosystem both grew year over year and became more structured. Volume operators expanded, new brands entered faster, and leak-site publishing became part of the market’s scaling behavior.

Monthly Victim Count by Threat Actor, April 2025–March 2026

Commentary by Dr. Ferhat Dikbiyik, Chief Research & Intelligence Officer, Black Kite


The Number That Matters Most Isn’t 7,551.

It is the jump from an average of 484 victims per month in the first half to 775 per month in the second half. Every month from October through March stayed above 700, so this was not a one-month spike. It was a new operating tempo, and three forces stacked to produce it.

  1. New groups piled on volume — 61 new groups entered, more than one a week, adding to incumbents rather than replacing them.
  2. New entrants targeted a different geography — established actors aimed 53.4% of attacks at the US; new entrants sent only 38.7% there, spreading the rest into Europe, Brazil, Thailand, and the UAE.
  3. Qilin redefined the unit of attack — one MSP compromise reached 32 South Korean financial institutions. One vendor, dozens of victims.

AI Lowered the Barrier. Humans Did the Rest.

The strangest signal is that these new groups die fast: a 4.9-month median lifespan, against 12.8 months for the prior cohort. The barrier to entry was always low, but the cost of building an original operation is now collapsing too.

Open-source LLMs and code agents put encryptor development within reach of operators who could not have written that code a year ago, and we saw an early hint of this with FunkSec. Ransomware is, at the end of the day, software, and vibe-coded software (rapidly built, AI-assisted code) tends to launch, post a batch of victims, then break. I cannot prove AI is the cause, but the acceleration, the flood of short-lived entrants, and the rising capability of actors who couldn't have participated a year ago, all land in the same window. The headline is not an autonomous attacker. It is a wider on-ramp.

The growth is human. AI just let more people show up at once.

Ransomware by Geography: The US Is Still the Biggest Target. The Rest of the World Is Growing Faster.


Ransomware remained global in reach, but its geographic pattern shifted in an important way. The United States was still the largest victim country by a wide margin, accounting for 49.3% of all observed victims. Yet its share declined from 51.9% in the previous reporting period, even as the absolute number of US victims increased by 19%.

That distinction matters. The US is not shrinking as a ransomware target. The rest of the world is growing faster.

Geography of Ransomware Victims

Europe showed some of the clearest signs of increased pressure across the period. Germany rose by 48% to 281 victims, Spain by 50% to 160, and France by 43% to 196. Italy recorded a 96% increase to 188 victims. These were not marginal shifts. In absolute terms, Europe's four largest victim countries added more than 250 new victims compared with the prior period, and several moved into or consolidated positions within the global top ten. The pattern suggests that ransomware operators are not moving away from established economic centers but expanding the map around them. For organizations operating across European markets, the implication is direct: third-party risk programs built primarily around US exposure profiles may underweight a region where growth is accelerating.

Victim Count vs. Ransomware Risk by Country, 2025–2026

The y-axis reflects each country's average Ransomware Susceptibility Index® (RSI™), Black Kite's measure of how exposed an organization is to ransomware based on externally visible signals. Higher RSI means higher likelihood of attack. Countries in the upper right carry both high victim counts and elevated risk profiles.

The sharpest percentage growth appeared in parts of Asia. Thailand increased by 406%, while South Korea increased by 407%. Those jumps point to a more specific pattern that becomes clearer in the actor analysis: some ransomware brands appear to concentrate volume in particular geographies, creating country level spikes that reflect operator behavior as much as victim distribution.

Risk profile added a second layer to the geography story. Mexico stood out with the strongest vulnerable country profile in the dataset, carrying an average Ransomware Susceptibility Index® (RSI™) of 0.659, putting it within the bracket that is 54x more likely to experience a ransomware attack than those with an RSI under 0.2. (RSI measures the likelihood of being on the ransomware groups’ radar. See a detailed explanation in Chapter 07). In other words, ransomware geography was as much about where visible susceptibility remained concentrated as where the most victims were located.

Top Victim Countries by Count and Year-Over-Year Change, 2025–2026

Together, these findings show a market that is still anchored in the United States, increasingly active across Europe, and capable of producing sharp country level surges when specific actors scale in specific regions.

Ransomware by Industry: Manufacturing Leads for the Fourth Year. Construction Is the Quiet Riser.


Industry distribution remained familiar at the top, but the middle of the table changed in a way that matters.

Manufacturing remained the leading ransomware victim sector, with 1,660 observed victims, accounting for 22.0% of all disclosures. This marks the fourth consecutive year in which Manufacturing held the top position in Black Kite’s ransomware dataset. The sector also dominated the month by month ranking, staying in first place for nearly the entire period. Professional, Scientific, and Technical Services followed with 1,389 victims, keeping its position as the second largest victim pool.

Together, these two sectors accounted for roughly 40% of all observed victims. The pattern remains consistent: ransomware disclosures are concentrated in sectors where operational disruption, sensitive information, and third party dependencies can create strong extortion leverage.

Ransomware Victims by Industry, April 2025–March 2026

Industry classifications are based on the North American Industry Classification System (NAICS), used to group organizations by primary business activity.

The quieter movement happened below the top two. Construction rose to third place with 541 victims and increased its share by 1.05 percentage points compared with the previous reporting period. This was not a single month anomaly. Construction stayed near the upper tier throughout the year, making it one of the clearest but least dramatic shifts in the industry data. Health Care, Wholesale Trade, Finance and Insurance, Information, and Retail Trade formed the next tier, each large enough to matter but not close to the two leaders.

Subindustry data helps explain why the leading sectors remain durable ransomware targets.

Year-Over-Year Share Change by Industry, 2025–2026

Manufacturing: No Single Subsector Dominates

Manufacturing Victims by Subsector, April 2025–March 2026

In Manufacturing, no single subsector dominated the total. The spread, visible in the chart above, shows that ransomware pressure in this sector is not limited to one industrial niche. It cuts across the broader production economy.

Professional Services: Concentrated Around Legal and IT

Professional Services Victims by Subsector, April 2025–March 2026

Professional Services showed a more concentrated pattern. Legal Services (370 victims) and Computer Systems Design (321) accounted for much of the sector's total. Legal organizations hold sensitive client information. Computer systems providers sit close to client technology environments, making them valuable both as direct targets and as access paths into wider ecosystems.

Construction: Distributed Across Trades

Construction Victims by Subsector, April 2025–March 2026

Construction deserves a separate note because its growth was quiet but consistent. The sector's victim pool spread across specialty trades, building construction, and civil engineering, pointing to a distributed ecosystem of contractors, subcontractors, and shared service relationships rather than a small set of centralized targets.

Education Tells a Different Story: Lower Volume Does Not Mean Lower Risk

Educational Services declined in absolute victim count and recorded 250 victims during the period. But lower volume did not mean lower risk. Education retained the weakest risk profile among major sectors, measured by the Ransomware Susceptibility Index® (RSI™), Black Kite's 0-1 index of external exposure signals like unpatched vulnerabilities and leaked credentials. Education’s average RSI is 0.608 and the highest average stealer log count at 70.2. That makes Education less of a volume story in this section and more of a persistence story, which we cover in Chapter 10, when the report turns from who was attacked to what exposure remained visible after the incident.

Taken together, the industry data shows a familiar top line with a changed middle. Manufacturing and Professional Services still anchor the ransomware victim pool. Construction is the quiet riser. Education is the reminder that attack count and exposure severity are not the same thing.

Side Note: The Publishing Rhythm

Ransomware disclosures also showed a clear timing signature. Weekdays accounted for 84.1% of all victim postings, with Wednesday the most active day at 17.8%. Sunday was the quietest at 6.6%. The pattern does not prove when intrusions began, but it does show when ransomware groups most often chose to publish, apply pressure, and operationalize extortion.

There were also outliers. On December 26, LockBit 5.0 disclosed 53 victims in a single day. This was a separate visibility event, not evidence of the broader weekday pattern: a high-volume disclosure placed in a holiday-adjacent window, when legal, communications, and IT teams may be slower to coordinate. In that sense, the case shows a different use of timing. Most disclosures followed a weekday rhythm; some large batches appear designed to create concentrated pressure when response capacity may be uneven.

Revenue & Target Selection: The Middle Market Became the Growth Zone


The revenue data no longer tells a simple story of “small companies at the bottom, large enterprises at the top.” This year, the distribution shifted in a more specific way: ransomware pressure expanded at the smallest end of the market, strengthened in the $50M to $100M mid-core segment, and contracted above $100M.

This analysis is based on more than 6,000 victims with known or estimated annual revenue. Victims without sufficient revenue data are excluded from the revenue distribution.

The largest single band remained $10M to $50M, the core mid-size companies, accounting for 37.4% of known-revenue victims. This lower-market segment is still the core small-business exposure zone: organizations large enough to hold meaningful data, customer relationships, vendor access, and operational dependency, but often without deep security staffing or mature crisis response capacity.

Ransomware Victims by Revenue Band: Mid-Market Dominates, April 2025–March 2026

But the year-over-year movement shows that the market did not simply stay centered there. The $10M to $50M band declined from 40.1% to 37.4% of known-revenue victims. It remained the largest pool, but its share narrowed.

The smallest end of the market moved upward. Companies below $10M increased from 21.0% to 23.9% of known-revenue victims. The sharpest jump came from the $1M to $5M band, which rose from 3.0% to 5.1%. That is the clearest signal that ransomware pressure reached further down into small businesses.

Victim Distribution by Revenue Band, Year Over Year: Mid-Market Holds, Enterprise Share Contracts

The $50M to $100M band showed the strongest share gain. It increased from 25.1% to 29.3%, making it the year’s most important upward movement in the revenue distribution. This mid-core market sits in a difficult middle ground: visible enough to create pressure, large enough to carry sensitive data and insurance coverage, operational enough to suffer meaningful disruption, but not always protected with the resilience of large enterprises.

The $100M+ segment moved in the opposite direction. Its share declined from 13.9% to 9.5%. That does not mean large organizations stopped mattering. It means they were not the growth engine of this year’s ransomware volume. The enterprise tier remained an impact tier, not the main expansion tier.

Companies below $10M

21.0% to

Companies $50M to $100M

25.1% to

Companies $100M+

13.9% to

Above $100M, the story becomes more selective. The $100M to $300M range accounted for 40.9% of the $100M+ segment, while $1B+ organizations accounted for 38.6%. The middle of the enterprise range was thinner. This suggests that upper-market ransomware pressure was not evenly distributed. It clustered around large-but-not-mega enterprises and the very largest organizations.

This shift likely reflects more than one force. Larger organizations may have stronger response programs, more mature backup and recovery strategies, and greater resistance to paying. At the same time, a more fragmented actor ecosystem may push newer or less mature groups toward targets that are easier to reach and pressure. The data points to a market where growth came less from hunting the largest enterprises and more from scaling across smaller and mid-core organizations.

Enterprise Victim Distribution: Pressure Clusters at $100–300M and $1B+

Revenue also changed the type of victim. Below $10M, the profile was more service-heavy, with Professional, Scientific, and Technical Services accounting for 24.2% of victims, compared with 17.1% for Manufacturing. That relationship reversed above $10M. Manufacturing rose to roughly 26% across the middle revenue bands and reached 36.5% among $1B+ organizations, while Professional Services declined steadily to 6.4%. The pattern shows a clear shift from service-oriented victims at the lower end of the market toward more operational and production-heavy organizations as revenue increases.

The sector mix makes the revenue story clearer. Smaller victims often create leverage through sensitive data, client relationships, and uneven response capacity. As revenue increases, the victim profile becomes more operational, with Manufacturing taking a larger share and disruption carrying broader consequences across production, logistics, suppliers, customers, and business continuity.

Enterprise Victim Distribution: Lower Mid-Market and Large Enterprise Bear the Most Pressure

Actor Lens: Not Every Group Hunts the Same Revenue Profile


Revenue also separated actor behavior. Qilin remained broad, appearing strongly across revenue bands. Sinobi leaned toward the lower-revenue market, making it closer to a small-business hunter. Coinbase Cartel showed the highest median victim revenue among the leading actors, while Clop and World Leaks also skewed toward higher-value victims. This reinforces the larger theme of the report: the ransomware market is not one playbook. Some actors scale through accessible volume. Others concentrate around higher-value targets.

Each Group Has a Revenue Sweet Spot

Threat actors with at least 50 victims were considered.

The takeaway is clear: revenue shapes ransomware leverage, not just ability to pay. Very small companies became more visible. The $10M to $50M lower market remained the largest victim pool. The $50M to $100M mid-core market showed the strongest share gain. The $100M+ enterprise tier contracted by share, but remained important for impact. Ransomware operators are scaling across several financial profiles at once, with different forms of pressure at each level.

Before Disclosure: Warning Signs Were Already Visible


Ransomware incidents rarely begin in complete darkness. In many cases, the warning signs were already visible before the disclosure.

Pre-Disclosure Exposure Signals Across Ransomware Victims, April 2025–March 2026

Across the victim population analyzed by Black Kite, the pre-disclosure exposure profile showed a familiar pattern: exposed information, misconfiguration, open remote access, software vulnerabilities, stealer logs, and credential-related findings were already present across large portions of the victim population. Misconfiguration appeared in 68.1% of victims. Fraudulent domains appeared in 52.0%. Remote access ports appeared in 46.9%. Software vulnerabilities appeared in 43.2%. Stealer logs appeared in 34.5%, and credential stuffing appeared in 21.6%.

The most important signal was the combination. More than 60% of victims carried at least one of the three critical ransomware-relevant findings: software vulnerability, credential stuffing, or stealer logs. Nearly one in ten carried all three. These exposures may not have caused every incident — but before many victims appeared on leak sites, ransomware-relevant weakness was already visible from the outside.

That pre-disclosure picture sets up the next question: once a victim appears publicly, does the exposure actually close?

Post-Period Pulse: The 700+ Tempo Held


Post-period data provides an early view of whether the second-half acceleration continued after March 31, 2026.

Post-period monthly victims

Post-period victim pace stayed above 700 every month, April–June

Post-period active groups

Fragmentation continued 29 new groups appeared in the post-period window

Post-period victim count: Qilin

Qilin remained first with 306 victims, but The Gentlemen narrowed the gap with 267

US share of post-period victims

Down from 49.3% during the reporting period

Volume Held Above 700, Every Month

The clearest finding is that ransomware volume did not return to the first-half baseline. Black Kite observed 2,230 additional ransomware victims from April through June 2026, with monthly totals of 737 in April, 716 in May, and 777 in June. The pace eased from the March peak, but it remained above 700 victims every month, well above the first-half average of 484. That makes the post-period signal less about decline and more about persistence. The elevated operating tempo held.

Ransomware Victim Volume Holds Above 700 Post-Cutoff

Fragmentation Kept Rotating, Not Shrinking

The actor ecosystem also remained dynamic. By the end of June 2026, the trailing twelve-month active group count reached 146, compared with 127 at the close of the reporting period. But the more important signal was not the small increase from May to June. It was the movement beneath the active-group count. Some groups that contributed volume in the second half of the reporting period did not publish new victims in the post-period window, yet the overall monthly pace stayed above 700. In other words, the ransomware cybercrime market did not depend on the same set of brands to maintain output. Disclosure activity rotated, and new or rising groups filled the visible volume.

That reinforces one of the report’s core findings: ransomware fragmentation is not only about how many brands exist but also about how quickly visible output can shift between them.

Qilin's Lead Narrows

Post-period actor momentum also became more competitive. Qilin remained the largest actor by post-period victim count, but the gap narrowed as The Gentlemen accelerated sharply and DragonForce moved well above its earlier pace. This does not prove a leadership change, but it does show that the volume layer remained fluid after the cutoff. In today’s ransomware market, a reporting-period leader’s position can shift within a single quarter.

US Concentration Keeps Sliding

The geography signal continued to widen. The United States remained the most targeted country, but its post-period share fell to 39.9%, down from 49.3% during the reporting period. That notable drop in US concentration supports the broader finding that ransomware pressure remains anchored in the United States while growing faster across other regions.

Revenue and Industry: A Signal to Watch, Not Confirm

Revenue and industry distributions should be read more cautiously over a three-month window. Industry mix remained broadly stable. The revenue distribution showed a modestly larger post-period share in the $50M–$100M and $100M+ bands, while smaller revenue bands represented a smaller share than during the reporting period. Because the observation window is short, this should be treated as a signal to monitor rather than a confirmed shift.

The post-period data did not produce a new story. It confirmed the one this report already tells: a cybercrime market that sustains its tempo, rotates visible output between brands, and spreads its pressure wider.

The primary reporting period for this report closed on March 31, 2026. Post-period data from April through June 2026 is not included in the year-over-year calculations in this report.

Next: More groups entered this year than any year prior.

The victim count reflects a rapidly expanding field of actors. See who was operating, how fast the market grew, and what the surge in new groups actually means.

PREVIOUS
NEXT