Ransomware activity remained at historically high levels as new reporting showed attackers increasingly gaining entry through phishing, malicious email, and compromised identities rather than software exploits. Sophos reported that malicious email accounted for 26% of ransomware intrusions, phishing for 24%, and compromised credentials for 23%, while exploitation of vulnerabilities fell to 18% from 32% in the prior survey. The findings indicate that identity compromise now sits at the center of ransomware operations, with nearly four in five attacks tied to compromised identities and 67% of organizations describing ransomware as their most serious identity-related incident.
Industry reporting also said claims of a ransomware slowdown are misleading. Check Point previously recorded a 126% year-over-year increase in public extortion cases in early 2025, while NCC Group counted 2,229 ransomware attacks in Q2 2026, a 3% rise from the prior quarter. Qilin remained the most active group for a fifth straight quarter, with The Gentlemen, Dragonforce, and KryBi also prominent. Researchers warned that attackers are bypassing MFA through adversary-in-the-middle phishing, stolen browser cookies, session tokens, and MFA fatigue, and urged organizations to strengthen identity defenses, patch internet-facing systems, secure VPNs and firewalls, and deploy phishing-resistant authentication and continuous monitoring.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Sophos' State of Ransomware 2026 report found that malicious email, phishing, and compromised credentials had overtaken software vulnerability exploitation as the leading initial access paths for ransomware. The report was based on responses from 2,158 IT and cybersecurity leaders across 17 countries whose organizations experienced ransomware in the prior year.
Coveware's Q2 2026 cyber extortion analysis said ransom payment rates fell to record lows, including a 15% payment rate in data-exfiltration-only cases, while the average payment rose to $1,880,612 and the median fell to $150,000. The report attributed some of the largest payments to Silent Ransom, also known as Luna Moth, whose social-engineering-led attacks targeted law firms.
Check Point published its Q1 2025 ransomware assessment, describing a record-breaking 126% year-over-year increase in public extortion cases. This marked a notable escalation in observed ransomware activity.
An unusually large Cl0P campaign mass-exploited the Cleo file transfer platform, creating a distortion in 2025 ransomware trendlines cited by later reporting. The event is referenced as a major campaign rather than a general background condition.
Q2 2026 reporting said Qilin was the most active ransomware group for the fifth consecutive quarter. The same reporting highlighted The Gentlemen, Dragonforce, and KryBi as other prominent actors, indicating a reshuffling among leading groups.
New Q2 2026 reporting from NCC Group recorded 2,229 ransomware attacks, which was described as a 3% increase from Q1 2026. The figures were cited as evidence that ransomware activity remained historically high.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
coveware.com
Open sourcezdnet.com
Open sourcecysecurity.news
Open sourceblog.checkpoint.com
Open sourceinsights.nccgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.