Meet us a Black Hat! Become a Black Kite Ranger to help protect the cyber ecosystem.Learn more
BlackKite: Home
Menu
gradient ecosystem background

2026 Ransomware Report

Of 7,551 Ransomware Victims Disclosed in 2026, Second-Half Volume Accelerated 60% Above the First-Half Pace

2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record laptop report image

by the Black Kite Research Group™

(No download required)

Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. That's a 24.9% increase over the previous reporting period, and the fourth straight year that ransomware disclosures have set a new high. The threat actor ecosystem grew right alongside the victim count, reaching 127 active groups by the close of the period and 146 by June 2026.

This report analyzes those 7,551 victims by geography, industry, and revenue band, then goes further. It pairs victim data with Black Kite's own security posture signals, captured before disclosure and rechecked after, to show what ransomware groups could already see and what stayed visible once the incident closed. It also maps five distinct actor models operating inside the same 12 months, tracks how trusted vendor platforms became attack paths, and measures where AI is already lowering the cost of running a ransomware operation.

The most consequential shift didn't happen at the top of the market. It happened in the middle. Growth accelerated 60% in the second half of the period, closing with 861 victims in March 2026 alone, the highest single month Black Kite has recorded. Stealer log exposure on already-breached victims came back 175% higher on rescan, and 43.5% of victims still carried a critical patch vulnerability when Black Kite checked their posture again. Recovering from an incident and closing the exposure that caused it turned out to be two different things.

This report is your blueprint for separating attacker visibility from attacker guesswork, and for building a third-party risk program around the signals ransomware groups actually use to pick their next target.

(No download required)

Key Findings From the 2026 Ransomware Report

7,551 Victims Mark a 24.9% Year-Over-Year Increase

Ransomware disclosures rose from 6,046 in the prior period to 7,551, continuing a four-year climb that has not slowed once. The monthly average moved from roughly 504 victims to 629, but that average understates how uneven the growth actually was across the year.

Second-Half Volume Outpaced the First Half by 60%

The first half of the period produced 2,904 victims, close to the prior year's baseline. The second half produced 4,647, a 60% jump in monthly pace that held above 700 victims every single month from October through March. This wasn't a spike. It was a new operating tempo.

146 Active Ransomware Groups Now Operate, Up From 127 at Period Close

Sixty-one new groups entered during the reporting period, more than one a week, and the threat actor count kept climbing after the cutoff. New entrants moved the total from 127 at the close of the period to 146 by June 2026, more than double the 61 active groups Black Kite counted in 2023.

Qilin Claimed 1,358 Victims, a 443% Jump From the Prior Year

Qilin alone accounted for roughly one in every five to six victims in the dataset, growing from 250 victims to 1,358 and operating across more than 50 countries. Despite the flood of new entrants, the top five actors still controlled 43.6% of all disclosed victims.

43.5% of Victims Still Carry Critical Patch Vulnerabilities Today

Black Kite's current-state rescan found that 43.5% of victims still carried a CVSS 9.0 or higher vulnerability, and 30.8% still carried a Known Exploited Vulnerability (KEV). Closing the incident didn't close the exposure that led to it.

Key Stats:

0
Victims
0.0%
YoY increase
0
Active groups
0
Qilin victims
0%
Higher stealer log exposure
0.0%
Still critically vulnerable
0x
More likely to be hit with an RSI of 0.8+

Who Got Hit in 2026: Manufacturing, Europe, and the Middle Market

Victim patterns shifted in three directions at once this year. The sector at the top stayed the same. The geography and the revenue profile underneath it did not.

Manufacturing Leads Ransomware Victims for a Fourth Consecutive Year

Manufacturing held the top spot again, with 1,660 victims and 22.0% of all disclosures. Professional, Scientific, and Technical Services followed with 1,389. Together the two sectors accounted for roughly 40% of the year's total. Construction was the quieter story, climbing to third place with 541 victims and gaining more than a full percentage point of share, a shift that built steadily rather than spiking in any single month.

Europe's Ransomware Growth Is Outpacing the United States

The US remained the largest single target, at 49.3% of all victims, but that share fell from 51.9% even as the raw US victim count rose 19%. Europe grew faster. 

  • Germany rose 48% to 281 victims
  • Italy rose 96% to 188
  • Spain and France both grew by roughly half. 

Organizations that built third-party risk management programs around a US-heavy exposure map are now underweighting the region growing fastest. Adjacent sectors told a similar story. Health Care and Financial Services both sat in the next tier of victim volume, alongside Wholesale and Retail Trade, each large enough to matter without approaching the top two sectors.

The $50M-$100M Band Grew to 29.3% of Ransomware Victims

Revenue distribution stopped following the old small-to-large logic. Victims in the $50M-$100M range climbed from 25.1% to 29.3% of those with known revenue, the biggest jump of any band, even as the $100M-plus tier fell from 13.9% to 9.5%. The $1M-$5M band nearly doubled its share too. Large enterprises didn't stop mattering. They stopped being the engine of this year's volume growth.

A Ransomware Market With No Single Dominant Actor

Every prior edition of this report had a main character. LockBit defined one year. RansomHub's rise defined the next. 2026 didn't have one. It had a market, and that market grew at the bottom while concentrating at the top.

Qilin

Qilin scaled through sheer volume across dozens of countries.

Everest

Everest built its pattern around accumulated patch debt rather than breadth.

Clop

Clop ran a mass-exploitation playbook, turning single enterprise vulnerabilities into hundreds of victims at once.

World Leaks

World Leaks concentrated on credential exposure with a UK focus.

Play

Play stayed a fast, opportunistic operator across the US and Canada.

Reading the market through these five models explains why it kept growing even as individual brands rose, fell, and disappeared entirely, the way RansomHub went from 736 victims and the top spot to 0 inside twelve months.

New Entrants Spread Wider While Legacy Groups Stayed US-Anchored

Expansion had a geographic split built into it. Legacy actors kept 63% of their victims inside North America, close to where they'd always operated. New entrants were still active there, but only 46% of their victims sat in the region, with the rest reaching further into Europe, Asia, South America, the Middle East, and Africa. More brands didn't just mean more volume. It meant ransomware pressure spreading into markets the established groups had mostly left alone.

Trusted Vendor Platforms Became 2026's Primary Ransomware Attack Path

A company could do everything right on its own systems and still be extorted over a breach it never touched.

Salesforce OAuth Abuse Exposed the Risk of Delegated SaaS Trust

The Salesloft Drift campaign moved through compromised OAuth tokens tied to a connected third-party application, not through a direct perimeter breach of each affected customer. Gainsight showed the same problem from a different angle days later, when unusual activity through its published Salesforce applications led Salesforce to disable the connection entirely. 

Every link in a delegated trust chain, from connected apps to support workflows, can become the entry point once one link is abused. That's why supply chain cyber risk management has to account for vendor identity and application access, not just the vendor's own perimeter.

Oracle EBS Extended a Familiar Mass-Exploitation Playbook

Like MOVEit and Cleo before it, the Oracle E-Business Suite campaign turned a single platform flaw into a mass event. One exposed system, many downstream victims. Public technical reporting tied the activity to CVE-2025-61882, exploited as a zero-day before a patch existed. 

PeopleSoft extended the same pattern into the post-period window, tied to a critical remote code execution flaw and attributed to the group also known as ShinyHunters. When a widely used enterprise application becomes the access path, the blast radius reaches far past any single breached company, which is exactly why Nth-party visibility into downstream vendor exposure matters more than a single vendor's own security rating.

Post-Incident Exposure Rose Even as Surface Hygiene Improved

Black Kite rescanned victims after their incidents closed and found a split result. Average Cyber Rating improved, and risk management methodology scores ticked up across the board as organizations cleaned up visible hygiene issues. But the ransomware-specific layer moved the wrong way. 

Stealer log exposure came back 175% higher, and average RSI rose from 0.557 to 0.616. Recovering from an incident and reducing the exposure that caused it are not the same project, and treating them as one is how the same organization ends up victimized twice.

What Attacker-Visible Signals Reveal Before and After Disclosure

Companies Above an RSI of 0.8 Were 291x More Likely to Be Hit

The Ransomware Susceptibility Index® (RSI™) scores how likely an organization is to land on a ransomware group's radar, based on externally visible signals like exposed credentials and unpatched software. The correlation is steep. 41% of companies with an RSI above 0.8 were hit during the period, against just 0.14% of companies below 0.2. A company in the highest band was roughly 291 times more likely to be attacked than one in the lowest.

93.5% of Victims Showed a Meaningful RSI Spike Before They Were Hit

RSI movement mattered as much as the raw score. 93.5% of victims showed at least one month-over-month RSI increase of 5% or more before disclosure, and 85.9% showed a jump of 10% or more. Some victims carried elevated risk for months before anyone noticed. Others jumped from a low band to a high one within weeks. Both patterns are visible from the outside before the incident, not after.

Current Exposure Still Runs Through Patch Debt and Identity Signals

Black Kite's latest rescan of the full victim population found the same signals still sitting there. 62.5% of victims still carry at least one medium-or-higher patch vulnerability, 58.9% still show misconfigured DMARC records, and FocusTag® alerts appear on 18.5% of victims, 87.1% of which are rated High or Very High severity. Victims carrying a FocusTag signal averaged an RSI of 0.705, well above the 0.588 average for those without one.

AI Lowered the Cost of Launching a Ransomware Operation in 2026

AI hasn't made ransomware autonomous. It's made more operators capable of running an operation that used to require a bigger team.

New Ransomware Groups Now Fold in a Median of 4.9 Months

Groups first observed between April and September 2025 lasted a median of 4.9 months, against 12.8 months for the prior year's cohort. The barrier to entry is falling faster than the barrier to staying in business, which is consistent with a market where more brands enter and fewer survive the year.

JADEPUFFER Points to Early Agentic Ransomware Execution

Sysdig researchers described JADEPUFFER as the first documented case of an AI agent orchestrating attack stages from reconnaissance through encryption with limited human direction during execution. It's one case, not a trend line yet, but it shows known vulnerabilities and weak credential handling becoming more dangerous once an agent can test and retry faster than a person can.

Voice Cloning and Deepfake Audio Are Scaling Human-Layer Attacks

The clearest change so far sits in the human-facing layer. Vishing scripts, multilingual phishing lures, and deepfake audio all got cheaper to produce this year. Several of the year's most disruptive intrusions, including the Scattered Spider help desk impersonation cases, succeeded by exploiting how people and support workflows operate, not by exploiting a technical flaw.

From Recovery to Exposure Reduction: Four Shifts for 2026 TPCRM Programs

Treat post-incident recovery as a 90-day exposure review, not a closed case

Closing an incident and closing the exposure behind it are different projects, and this year's data shows the gap between them clearly. Build a structured 30, 60, and 90-day external review into every post-incident process, covering stealer logs, KEV exposure, and critical patch vulnerabilities.

Prioritize patching by exploitability, not by convenience

30.8% of victims still carried a known-exploited vulnerability at the time of Black Kite's latest rescan. Weight patch prioritization toward known exploitation and severity scoring, not internal change management calendars.

Extend vendor assessments to SaaS tokens and connected applications

The year's most damaging incidents moved through OAuth tokens and connected apps, not through a vendor's own perimeter. Third-party risk management programs need connected-app inventories and OAuth token review sitting alongside standard vendor risk assessment questionnaires, plus a direct line into vendor remediation through a tool like The Bridge™.

Act on RSI Movement Before Disclosure

A high RSI tells a team where to look first. A sudden RSI spike tells them when to look again. The Ransomware Susceptibility Index® (RSI™) is exclusive to Black Kite, so pair continuous monitoring of RSI movement with credential rotation and MFA enforcement across your vendors. 

How Black Kite Built the 2026 Ransomware Report

Nearly 300 Ransomware Groups Monitored Across Leak Sites and Dark Web Channels

The Black Kite Research Group tracked activity from close to 300 ransomware groups, monitoring leak sites, extortion posts, and Telegram channels to identify new brands as they entered the market and confirm which ones stayed active.

7,551 Victims Cross-Validated Against OSINT and Internal Telemetry

Every victim in the dataset was identified through leak site monitoring, then validated against open-source intelligence and internal telemetry. Analysts classified each by NAICS industry code, headquarters country, and estimated revenue where reliable financial data existed for more than 6,000 of the 7,551 victims.

Security Posture Measured Before and After Disclosure for Every Victim

Black Kite used its own platform to assess each victim's cyber posture at the point of disclosure and again on the most recent available scan, comparing stealer log counts, RSI, and Cyber Rating across both points to isolate what changed and what didn't. This is the same ransomware threat intelligence discipline the Black Kite Research Group applies to its ongoing monitoring work.

The dataset reflects only publicly disclosed victims, so the true attack volume is almost certainly higher than what leak sites show. 

Full chapter-by-chapter detail, including the actor-model breakdown, the geography and revenue charts, and the complete AI section, is available in the interactive report.

(No download required)

Previous Editions

Related Resources