Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure.
Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A Black Kite report said Qilin claimed 1,358 victims during the tracked April 2025 to March 2026 period, representing a 443% increase from the prior year. The report described Qilin as operating in more than 50 countries amid a broader rise in ransomware activity.
GuidePoint Security's GRIT Q2 2026 report said 2,279 victims were publicly named from April through June 2026, with Qilin remaining the most active group for the fifth consecutive quarter and The Gentlemen rising rapidly to second. The report also highlighted increased AI use by threat actors, more supply-chain attacks, and a shift toward data-only extortion.
ReliaQuest's Q2 2026 ransomware analysis found 2,252 total victims across 90 groups and 99 countries, with The Gentlemen posting 300 victims to become the most active named group ahead of Qilin. The report also noted the US accounted for about 49% of observed victim activity and that professional, scientific, and technical services remained the top-targeted sector for the fifth consecutive quarter.
ReliaQuest reported that Deadlock resurfaced after 11 months of public silence during Q2 2026. Its updated operations used blockchain-hosted command-and-control via a Polygon smart contract and a BYOVD technique exploiting CVE-2024-51324 to terminate EDR at the kernel level.
A ransomware.live incident listing identified Zaner Group in connection with an “Insomnia” threat or incident label. The excerpt states the incident was discovered on 2026-02-25 and gives an estimated attack date of 2026-02-04, but provides no further technical or impact details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceemsisoft.com
Open sourcecysecurity.news
Open sourcecyberveille.ch
Open sourcereliaquest.com
Open sourceransomware.live
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.