A new report from Black Kite, published July 26, 2026, indicates a severe and sustained increase in ransomware activity. The findings show a 24.9% year-over-year rise in publicly disclosed victims, totaling 7,551 incidents between April 2025 and March 2026. This marks the fourth consecutive year of record-breaking activity. The ransomware ecosystem is expanding, with 146 active groups by June 2026. The Qilin group has emerged as a dominant threat, responsible for 18% of all attacks in the reporting period. The manufacturing industry remains the most heavily targeted sector, while attackers are increasingly leveraging AI to enhance social engineering tactics like vishing. A critical finding reveals that 43.5% of breached organizations had unpatched critical vulnerabilities, highlighting systemic failures in patch management and a prolonged state of risk even after an attack.
The "2026 Ransomware Report" by Black Kite paints a grim picture of the current threat landscape. The 7,551 disclosed victims represent a significant acceleration, particularly in the latter half of the reporting period, which saw a 60% jump in volume. March 2026 alone set a single-month record with 861 victims.
The number of active ransomware gangs grew from 127 to 146 in just three months (March to June 2026). The Qilin ransomware-as-a-service (RaaS) operation was the most prolific, claiming 1,358 victims—a staggering 443% increase from its activity in the previous year. This highlights the effectiveness and scalability of the RaaS model, which lowers the barrier to entry for less sophisticated actors.
For the fourth year in a row, the manufacturing sector was the most victimized, with 1,660 attacks (22% of the total). This is likely due to the sector's low tolerance for downtime and complex supply chains, making them more likely to pay a ransom. The Professional, Scientific, and Technical Services sector followed with 1,389 victims (18.4%), and the construction industry rose to third place with 541 victims.
The report indicates a shift in attacker TTPs towards more sophisticated, AI-enhanced social engineering. While specific malware strains were not detailed, the behaviors described map to established MITRE ATT&CK techniques.
T1598.003 - Spearphishing Voice. This allows attackers to bypass technical controls by manipulating human targets with highly convincing impersonations.T1486 - Data Encrypted for Impact) and exfiltrating data for double extortion (T1537 - Transfer Data to Cloud Account).T1490 - Inhibit System Recovery by deleting volume shadow copies or destroying backups.The finding that 43.5% of victims had unpatched critical vulnerabilities suggests that many initial access events likely occurred through the exploitation of known flaws, mapping to
T1190 - Exploit Public-Facing Application.
The operational and financial impact of these attacks is substantial. For the manufacturing sector, downtime can halt production lines, leading to millions in lost revenue per day and severe supply chain disruptions. For professional services firms, the theft of sensitive client data can cause irreparable reputational damage and legal liability. The report's finding on unpatched vulnerabilities indicates that many organizations are not only failing to prevent attacks but are also struggling with the foundational security hygiene required for effective recovery. This suggests that recovery times are likely extended and costs are inflated due to the need to perform emergency patching and hardening during an active incident response.
No specific Indicators of Compromise (IOCs) such as file hashes, IP addresses, or domains were mentioned in the source article.
Security teams can hunt for generic ransomware precursors and behaviors. The following patterns could indicate related activity:
command_line_patternvssadmin.exe delete shadowscommand_line_patternwbadmin delete catalogprocess_namepowershell.exenetwork_traffic_patternevent_id4625 (Windows Security Log)Detecting modern ransomware requires a multi-layered approach focusing on behaviors rather than just static signatures.
vssadmin), and disabling of security services. This aligns with D3FEND's Process Analysis (D3-PA).D3-NTA).PsExec or WMI for lateral movement, and clearing of event logs.D3-DO) to detect lateral movement and file access attempts early in the attack chain. Alerts from these systems are high-fidelity indicators of compromise.Preventing and mitigating ransomware requires a defense-in-depth strategy.
D3-SU) countermeasure.D3-MFA) that disrupts many initial access techniques.D3-NI).New details from the Black Kite report highlight the US as the most targeted country (49.3%), with top 5 groups accounting for 43.6% of victims, including 'The Gentlemen'.
Addresses the 43.5% of victims with unpatched critical vulnerabilities by ensuring known exploits cannot be used for initial access or privilege escalation.
Mapped D3FEND Techniques:
Mitigates the effectiveness of AI-enhanced vishing and other social engineering tactics by educating users to recognize and report such attempts.
Provides a critical barrier against account compromise, even if credentials are stolen via phishing or other means.
Mapped D3FEND Techniques:
Contains the blast radius of a ransomware attack by preventing lateral movement from less critical network segments to high-value assets.
Mapped D3FEND Techniques:
Implement a rigorous patch management program that prioritizes critical vulnerabilities on internet-facing systems, as highlighted by the report. Use a risk-based approach to identify and remediate vulnerabilities exploited by active ransomware groups. Automate scanning and deployment where possible to reduce the window of opportunity for attackers. This directly counters the finding that 43.5% of victims had unpatched critical flaws, which often serve as the initial access vector for ransomware attacks. Verification of successful patching should be a mandatory step in the process.
Enforce phishing-resistant MFA across all remote access points (VPN, RDP), email systems, and privileged accounts. Given the rise in AI-powered vishing mentioned in the report, traditional SMS or push-based MFA can be vulnerable to prompt bombing or SIM swapping. Prioritize the use of FIDO2/WebAuthn security keys or number matching with application context to provide a stronger defense against social engineering and credential theft. This control is one of the most effective at preventing initial access via compromised credentials.
Strategically place decoy files and credentials (honeypots) on file shares and endpoints. These objects, when accessed, trigger high-fidelity alerts indicating an intruder is present in the network. For example, create fake documents with names like 'passwords.xlsx' or '2027_financial_projections.docx' on key servers. Any interaction with these decoys should be treated as a confirmed compromise, allowing security teams to respond before widespread encryption begins. This deception tactic is highly effective for early detection of lateral movement and reconnaissance activities common in ransomware attacks.
Start of the 12-month reporting period for Black Kite's ransomware analysis.
End of the 12-month reporting period, with 7,551 victims disclosed.
March 2026 sets a new record for a single month with 861 disclosed victims.
The number of active ransomware groups grew to 146.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.