Government entities experienced 89 confirmed and 98 unconfirmed ransomware attacks in the first half of 2026, according to a report from Comparitech. US government agencies were targeted the most, accounting for 31% of those attacks, though at a rate 23% less than 2H 2025. Industries under increasing attack over the past six months include transportation (52%), healthcare (35%), retail (28%), and technology (23%), Comparitech found.
Most active threat actors
Ransomware groups Qilin and The Gentlemen came in No. 1 and No. 2 in both NCC Group’s list for most attacks in Q2 2026 and Comparitech’s list for 1H 2026, though Comparitech notes that The Gentlemen, reportedly a Qilin splinter group, topped Qilin in victims claimed on their respective data leak sites for the month of June. Cyber resilience platform vendor Halcyon recently called The Gentlemen “one of the fastest-scaling ransomware threats” it has tracked.
Akira, DragonForce, Lockbit, and INC rounded out both lists’ top 6 most active threat ransomware actors. NCC Group also singled out KryBit as a notable emerging group — first observed in March 2026 — that operates as ransomware-as-a-service specializing in targeting Windows, Linux, VMware ESXi, and NAS devices. According to Halcyon, KryBit’s activity model gives the group notable growth potential.
