Ransomware activity accelerated sharply from late 2025 into early 2026, with Black Kite tracking 7,551 known victims worldwide during a 12-month study period and attributing the rise to a fragmented criminal ecosystem rather than AI alone. More than 60 new ransomware groups entered the market, established operators including Qilin, Everest, Cl0p, and World Leaks remained active, and attackers increasingly shifted toward smaller, less-defended organizations. Manufacturing was the most targeted sector, US organizations accounted for nearly half of observed victims, and Europe recorded a faster growth rate than the US.
The surge is intensifying pressure on victims to decide whether to pay, with reporting citing 2025 Sophos research that nearly half of targeted companies ultimately paid ransom demands and that median demands are rising globally. Security practitioners and policy debates are now focusing on whether public-sector payment bans would curb attacker profits or instead raise cyber-insurance costs and expand demand for negotiators, incident responders, and breach coaches. Across the reporting, defenders emphasized that the most effective response is stronger exposure management, continuous monitoring, MFA, least-privilege access, resilient backups, and better visibility into third-party and SaaS risk before compromise occurs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Black Kite's 2026 Ransomware Report said 61 new ransomware groups entered the market during its April 2025 to March 2026 study period, and the number of active groups reached 146 by June 2026. The report also identified Qilin as the highest-volume operator amid a fragmented ecosystem.
A 2025 Sophos study found that nearly half of companies targeted by ransomware ultimately paid a ransom to recover data or systems. The reporting also noted that median ransom demands were rising globally.
According to Black Kite, ransomware activity increased significantly from October 2025 through March 2026. The acceleration was attributed primarily to the splintering ransomware landscape rather than AI alone.
Black Kite identified 7,551 known ransomware victims worldwide during its study period spanning April 2025 to March 2026. The report cited ecosystem fragmentation, more than 60 new groups, and increased targeting of smaller organizations as key drivers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcedarkreading.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.