Black Kite’s 2026 Ransomware Report Finds a Faster, More Fragmented Threat Economy – Unite.AI | #ransomware | #cybercrime


Black Kite’s 2026 Ransomware Report describes a ransomware market that is no longer defined by one dominant gang, one headline-grabbing takedown, or one attack method. Between April 1, 2025, and March 31, 2026, the company identified 7,551 publicly disclosed victims, up from 6,046 in the previous reporting period. More important than the overall increase, however, is how the growth occurred. Activity accelerated sharply during the second half of the year, new ransomware groups appeared at a rapid pace, and trusted software platforms increasingly became routes into organizations that may have secured their own internal environments.

Ransomware Growth Has Changed Shape

Black Kite has tracked ransomware disclosures since 2022, when its first reporting period recorded roughly 2,700 victims. That total later rose to 4,893, then 6,046, and now 7,551, but the annual increase does not fully capture how sharply activity accelerated during the latest period.

The first six months produced 2,904 victims, compared with 4,647 from October 2025 through March 2026. March alone ended with 861 publicly disclosed victims, the highest monthly total Black Kite has recorded in four years. The momentum also continued beyond the reporting cutoff, with another 2,230 victims observed from April through June 2026.

Unlike previous ransomware cycles, the surge was not driven by one dominant group or a single major event. It reflected multiple operators expanding at once, established groups scaling their affiliate networks, and new entrants finding cheaper ways to participate.

A Crowded Market Still Has Powerful Leaders

Ransomware is no longer controlled by a small number of recognizable gangs operating as tightly organized criminal groups. It increasingly functions as a service economy. Core operators develop the malware, maintain leak sites, handle payments, and provide infrastructure, while affiliates find ways into corporate networks and deploy the attacks. This model allows groups to expand quickly without every participant needing advanced technical skills.

Black Kite identified 127 active ransomware groups during the reporting period, including 61 that appeared for the first time. Some were entirely new operations, while others may have been rebrands or splinter groups formed after established organizations disappeared. The result is a more fluid market in which actors can move between brands, reuse tools, or launch new leak sites without rebuilding their operations from scratch.

Despite this fragmentation, a small number of groups still generated a large portion of the activity. Qilin was the most prominent example, claiming 1,358 victims during the year, nearly twice as many as its closest competitor. The group operates through a ransomware-as-a-service structure that gives affiliates access to attack tools while centralizing functions such as negotiations, payments, and victim disclosures.

Other brands followed different paths. RansomHub, which had been one of the leading operations in the previous period, stopped posting victims in early 2026. LockBit returned after its earlier disruption, but its 186 claimed victims represented a limited recovery rather than a return to its former influence.

These shifts show why ransomware brands should not be viewed like conventional companies. A group can disappear while its affiliates, techniques, and infrastructure continue under other names. Operators may shut down after law enforcement action, internal disputes, or declining trust, only for familiar tactics to reappear through a new leak site weeks later.

The market has therefore become both more crowded and more concentrated. New entrants can appear quickly, but scale still depends on reliable access brokers, experienced affiliates, payment infrastructure, and a reputation for providing malware that works as promised.

The Target Profile Is Shifting

Ransomware attacks typically begin with access rather than encryption. Attackers may exploit an unpatched internet-facing system, steal credentials from employee devices, abuse remote-access software, or deceive a help desk into resetting an account. Once inside, they attempt to move through the organization, identify valuable systems, copy sensitive data, and create enough operational or reputational pressure to demand payment.

The United States remained the most frequently targeted country in Black Kite’s dataset, accounting for nearly half of observed victims. However, ransomware activity expanded more rapidly in several other markets. Germany, France, Spain, and Italy all recorded substantial increases, while a number of Asian countries also experienced sharp growth from smaller starting points.

This broader geographic spread reflects a market in which affiliates increasingly pursue any accessible organization rather than limiting themselves to a narrow set of countries. Language barriers and regional knowledge once made international expansion more difficult. Automated translation, widely available reconnaissance tools, and shared criminal infrastructure have reduced some of that friction.

Manufacturing remained the most targeted industry, with 1,660 disclosed victims. Manufacturers are attractive because even a brief outage can interrupt production, delay orders, and affect suppliers and customers. Many also operate a mixture of modern business systems and older operational technology, creating environments that can be difficult to patch or temporarily take offline.

Professional, scientific, and technical services ranked second. These companies often hold sensitive information belonging to multiple clients, meaning one intrusion can create pressure far beyond the original victim. Legal firms, engineering companies, consultancies, and technology providers may also possess credentials or access that can lead attackers into other organizations.

Construction moved into third place, reflecting the sector’s dependence on distributed project teams, contractors, cloud applications, and payment systems. Healthcare remained heavily targeted because service disruption can quickly become an operational and public-safety issue.

The report also shows attackers placing greater emphasis on mid-sized organizations. Companies generating between $10 million and $100 million accounted for much of the observed activity. These businesses may hold valuable data and have the ability to pay, but often lack the dedicated security teams and layered defenses available to the largest enterprises.

This does not mean major corporations are being ignored. Instead, ransomware operators appear to be balancing potential payouts against the cost and difficulty of an attack. A smaller manufacturer, regional contractor, or professional-services firm may offer a faster path to disruption than a multinational organization with extensive monitoring and incident-response resources.

Trusted Platforms Became Part of the Attack Surface

Some of the year’s most consequential incidents did not begin inside a victim’s core network. They moved through Software-as-a-Service integrations, OAuth tokens, enterprise resource planning applications, support platforms, and other systems connected to sensitive business data.

The report highlights Salesforce (CRM ) related campaigns as examples of how delegated trust can become an attack path. Compromised OAuth tokens associated with connected applications reportedly gave attackers access to customer Salesforce environments. Integrations with customer-service and customer-success platforms created additional routes to data.

In these cases, an organization could maintain strong internal controls and still be exposed through a vendor relationship it did not fully understand or monitor. A token issued months earlier, an application granted excessive permissions, or a poorly secured support account could give an attacker access without requiring a traditional malware infection.

Oracle (ORCL ) E-Business Suite illustrated the mass-exploitation version of the same problem. Black Kite describes a campaign involving claims of data theft from Oracle EBS environments and possible exploitation of CVE-2025-61882 before a patch was available.

Post-period activity involving PeopleSoft reinforced the broader lesson. One exposed platform can create a large downstream pool of victims, turning a vendor’s identity controls, permissions, or vulnerability into part of every customer’s ransomware exposure.

The Warning Signs Were Often Visible

Black Kite’s pre-disclosure analysis found that many victims showed externally observable weaknesses before appearing on ransomware leak sites. Security misconfigurations were present in more than two-thirds of the analyzed population, while exposed remote-access services, software vulnerabilities, fraudulent domains, and stolen credentials also appeared frequently.

More than 60% carried at least one of three ransomware-relevant findings: a known software vulnerability, credential exposure, or stealer logs. Nearly one in ten carried all three.

These signals do not prove which weakness caused a particular intrusion. An organization with exposed credentials may ultimately be compromised through a different vulnerability. Still, the findings show that many future victims were already visible as attractive targets before an attack became public.

The report’s Ransomware Susceptibility Index attempts to measure that exposure more directly. Black Kite found that companies in the highest risk band were far more likely to experience a disclosed ransomware incident than organizations in the lowest band.

The practical lesson is that ransomware risk is not evenly distributed. Attackers often focus on organizations where several weaknesses overlap, especially when unpatched systems, exposed credentials, and permissive identity controls create multiple possible entry points.

Lower Payment Rates Are Changing Extortion Tactics

The ransomware market expanded even as payment behavior became less dependable. Black Kite does not directly measure ransom payments, but it compares several external incident-response datasets that suggest fewer victims are choosing to pay.

One dataset reported a 26% payment rate in the second quarter of 2025. Another placed the rate at 23% in the following quarter, while data-exfiltration-only incidents produced a rate of 19%. These figures come from different populations and should not be read as one continuous market-wide measurement, but they point in the same direction.

The amounts paid by organizations that do comply can still be substantial. One dataset cited in the report found a median payment of $1 million among surveyed organizations that paid to recover data.

Lower conversion rates do not necessarily make ransomware less profitable. They may instead push operators to pursue more victims, reduce the cost of each attack, or apply more forms of pressure. Encryption is now frequently combined with data theft, public disclosure, impersonation, direct contact with customers, and threats involving regulators or business partners.

When fewer victims pay simply to restore encrypted systems, attackers have an incentive to create consequences that remain even after backups are restored.

Recovery Does Not Mean Exposure Has Disappeared

The report’s post-incident findings are among its most concerning. Some surface-level security measures improved after victims disclosed attacks. Average cyber ratings increased, while average botnet activity declined.

Deeper ransomware-specific indicators often moved in the opposite direction. Stealer-log exposure was substantially higher in the after-incident comparison, while ransomware susceptibility and software vulnerability exposure also increased among many victims.

The pattern suggests that organizations may fix the most visible hygiene problems while leaving behind the conditions that make them attractive to attackers. A company might close the vulnerability believed to have caused the initial breach but fail to revoke stolen credentials, review vendor access, remove dormant accounts, or investigate other exposed systems.

Black Kite’s current-state analysis reinforces that concern. Many past victims continued to show improperly configured email security records, critical unpatched vulnerabilities, known exploited vulnerabilities, and employee credentials circulating in stealer logs.

Incident response is often organized around restoring operations and containing the confirmed intrusion. The report argues that this is not enough. Recovery should include a fresh assessment of the organization’s entire externally visible attack surface, not only the system associated with the original incident.

AI Is Lowering the Cost of Participation

The report does not argue that artificial intelligence caused the surge in ransomware. Instead, it describes AI as a force multiplier that makes existing work faster and cheaper.

Reconnaissance can be summarized more quickly, phishing and voice-phishing scripts can be localized, stolen records can be organized into more persuasive narratives, and negotiation messages can be produced by smaller teams. Lower-level attackers can also use AI-assisted tools to troubleshoot scripts, modify malware, and automate repetitive tasks.

The clearest impact is currently in the human-facing layer. Voice cloning, multilingual lures, deepfake audio, help-desk manipulation, and real-time persona adaptation can make social engineering easier to scale. AI can help an attacker sound more credible in a language they do not speak or produce customized messages for hundreds of employees without manually writing each one.

Black Kite points to early signs of AI entering both technical execution and extortion branding. The near-term risk is not necessarily fully autonomous ransomware. It is semi-automated criminal operations in which smaller teams can perform work that once required more time, expertise, and coordination.

AI does not remove the need for access or skilled operators. It reduces friction between stages of an attack and gives more participants the ability to behave like organized ransomware businesses.

Future Implications

The central message is that ransomware is evolving from a market led by a few recognizable brands into a broader and more operationalized ecosystem. Defenders must still patch vulnerabilities and secure endpoints, but the data points toward a wider responsibility that includes continuously reviewing vendor access, Software-as-a-Service integrations, identity controls, email infrastructure, exposed credentials, and post-incident conditions.

Organizations should also reconsider how they measure recovery. Restoring systems may close the immediate incident, but it does not prove that stolen credentials have been invalidated, excessive vendor permissions have been removed, or other exposed assets have been addressed.

The 2026 Ransomware Report ultimately shows why victim counts alone are no longer enough. The threat is growing through a combination of sustained volume, high-output ransomware-as-a-service operators, expanding mid-market targeting, supply-chain leverage, and lower operating costs. Closing an incident may restore normal operations, but reducing the chance of another one requires treating exposure as an ongoing condition rather than a case that ends when the recovery process is complete.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW