2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge | #ransomware | #cybercrime


Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year‑over‑year surge in Qilin activity that reshapes the threat landscape.

The data points to a structurally higher operating tempo, a middle‑market pivot, and attacker visibility that often outpaces defenders’ own understanding of their exposure.

Between April 2025 and March 2026, ransomware disclosures climbed from 6,046 to 7,551, a 24.9% increase and the fourth consecutive annual high in Black Kite’s reporting series.

Average monthly victims rose from roughly 504 to 629. However, that headline number masks a decisive inflection in the back half of the year.

The first six months produced 2,904 victims; the second half surged to 4,647, a 60% jump that held above 700 victims every month from October through March, culminating in 861 victims in March 2026 alone.

The threat actor ecosystem kept pace, with 61 new groups appearing during the period and the total climbing from 127 active operations at period close to 146 by June 2026.

This continues a multi‑year expansion of ransomware brands that other industry reporting has also observed, even as some analyses note renewed consolidation of volume around a smaller set of dominant groups.research.

Qilin is the headline outlier in Black Kite’s dataset, jumping from 250 to 1,358 victims year over year a 443% increase that left the group accounting for roughly one in every five to six disclosed cases across more than 50 countries.

Despite dozens of new entrants, the top five groups still control 43.6% of all victims, indicating a market that is fragmented at the long tail but concentrated at the top.

Qilin’s expansion aligns with independent assessments that place it among the most active RaaS operations in 2026, with sustained victim counts quarter over quarter.research.

2026 Ransomware Report

Black Kite frames 2026 as a “market, not a main character” year: Qilin scaled on volume and geographic breadth, Everest leaned into accumulated patch debt, Clop continued mass‑exploitation plays.

Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. World Leaks focused on credential exposure, and Play sustained fast, opportunistic campaigns across North America.

The rapid rise and fall of groups like RansomHub from 736 victims to zero inside 12 months illustrates how brand‑level volatility coexists with stable or rising aggregate volume.

Manufacturing remained the top victim sector for a fourth straight year with 1,660 victims (22% of disclosures), followed by Professional, Scientific, and Technical Services at 1,389; together they account for roughly 40% of incidents.

Construction quietly climbed into third place with 541 victims, gaining share steadily rather than through a single mass event.

Parallel research throughout 2026 similarly highlights industrial and business services targets as persistent hotspots for ransomware operators.

Geographically, the United States still represents the single largest victim pool at 49.3% of cases, but its share dropped from 51.9% even as raw U.S. victim numbers rose 19%, while Europe’s growth outpaced the U.S. with notable increases in Germany (48%), Italy (96%), Spain, and France.

That shift is echoed in Black Kite’s dedicated 2026 European Cyber Risk Report, which found a 55.1% year‑over‑year increase in ransomware incidents in the region and an elevated baseline of monthly attacks.

Revenue distribution no longer follows a simple “smaller is safer” gradient: organizations in the 50–100 million USD band grew from 25.1% to 29.3% of victims with known revenue, the largest jump of any segment, while the 100‑million‑plus tier fell from 13.9% to 9.5%.

The 1–5 million band nearly doubled its share, reinforcing a broader trend where small and mid‑sized businesses supply much of the growth even as large enterprises remain high‑impact outliers.

Trusted vendor platforms emerged as primary attack paths in 2026, with incidents like the Salesloft Drift campaign and Gainsight‑related disruptions underscoring the risks of OAuth token abuse and delegated SaaS trust chains rather than direct perimeter compromise.

Similar to prior MOVEit and Cleo mass‑exploitation events, Oracle E‑Business Suite exploitation tied to CVE‑2025‑61882 and later activity against PeopleSoft showed how a single widely‑used enterprise platform can yield many downstream victims, particularly when exploited as a zero‑day.

Post‑incident rescans tell a stark story: 43.5% of victims still exposed at least one CVSS 9.0+ vulnerability and 30.8% carried a Known Exploited Vulnerability (KEV), while 62.5% had at least one medium‑or‑higher patch issue and 58.9% showed misconfigured DMARC.

Stealer log exposure rose 175%, and average Ransomware Susceptibility Index (RSI) scores climbed from 0.557 to 0.616, even as overall cyber ratings and risk management scores improved evidence that incident recovery and risk exposure reduction are diverging efforts.

Black Kite’s telemetry reinforces RSI as a leading indicator: organizations with an RSI above 0.8 were 291 times more likely to be hit than those below 0.2, and 93.5% of victims exhibited at least one month‑over‑month RSI spike of 5% or more before disclosure, with 85.9% showing a jump of 10% or more.

This aligns with broader industry observations that attacker‑visible signals exposed credentials, unpatched software, and third‑party weaknesses are increasingly central to target selection, especially as AI tooling lowers operational costs for new and existing ransomware groups.

𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Best in 2026? Compare costs, Automation, and response: Download Free Guide



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW