Black Kite 2026 Report: Ransomware Attacks Surge by 24.9%

Ransomware Attacks Jump 25% as 146 Threat Groups Proliferate

HIGH
July 24, 2026
July 26, 2026
4m read
RansomwareThreat Intelligence

Related Entities(initial)

Threat Actors

Organizations

Black Kite

Full Report(when first published)

Executive Summary

The 2026 Ransomware Report from Black Kite reveals a continued and accelerating surge in ransomware activity, with a 24.9% year-over-year increase in publicly disclosed victims. The report, which analyzed data from April 2025 to March 2026, documented 7,551 victims, setting a new record for the fourth consecutive year. The ransomware ecosystem has become increasingly fragmented with 146 active groups, but is dominated by a few key players. The Qilin ransomware group was the most prolific, responsible for nearly 20% of all attacks. The manufacturing industry remains the primary target, and the United States continues to be the most affected country. A concerning finding is that 43.5% of victims failed to remediate critical vulnerabilities even after being breached, leaving them exposed to repeat attacks.


Threat Overview

The report paints a picture of a mature and evolving ransomware ecosystem. While the number of active groups has grown to 146, indicating a lower barrier to entry likely fueled by the Ransomware-as-a-Service (RaaS) model, the market is not evenly distributed. The top five most active groups accounted for 43.6% of all victims, demonstrating a concentration of power and capability.

Key Trends:

  • Record Volume: 7,551 victims were disclosed, a 24.9% increase from the previous year.
  • Market Fragmentation: 61 new ransomware groups emerged during the reporting period.
  • Dominant Players: The Qilin gang was the most active, claiming 1,358 victims—a 443% increase from the prior year.
  • Attack Acceleration: Attack volume surged by 60% in the second half of the reporting period, with March 2026 seeing a record 861 victims.

MITRE ATT&CK Techniques (Common Ransomware TTPs)

Impact Assessment

The impact is broad and severe across multiple dimensions.

  • Geographic: The United States is the most heavily targeted nation, representing 49.3% of all victims.
  • Industrial: For the fourth consecutive year, the Manufacturing sector was the most impacted industry with 1,660 victims. It was followed by Professional, Scientific, and Technical Services.
  • Systemic Risk: The finding that 43.5% of victims still had a critical (CVSS 9.0+) patch vulnerability post-incident highlights a systemic failure in remediation and a high likelihood of re-infection. This indicates that many organizations are not learning from breaches and are failing to address the root causes, creating a cycle of victimization.

IOCs — Directly from Articles

This article is a trend report and does not contain specific, actionable indicators of compromise.

Cyber Observables — Hunting Hints

To hunt for general ransomware activity, security teams should look for the following patterns:

  • Process Name: Execution of vssadmin.exe delete shadows /all /quiet or similar commands to delete volume shadow copies.
  • File Name: Creation of files with common ransom note names like README.txt, DECRYPT_INSTRUCTIONS.txt, or HOW_TO_RECOVER.txt across multiple directories.
  • Network Traffic Pattern: Large, unexpected outbound data transfers to cloud storage providers or unknown IP addresses, which could indicate data exfiltration prior to encryption.
  • File System: Rapid, widespread file modification activity where files are renamed with a new, consistent extension (e.g., .qilin, .lockbit).

Detection & Response

  • Behavioral Monitoring: Deploy EDR solutions that use behavioral analysis to detect ransomware activities, such as rapid file encryption and deletion of backups. This is a core part of D3-PA: Process Analysis.
  • File Integrity Monitoring (FIM): Use FIM on critical servers to alert on widespread, unauthorized file modifications or renames.
  • Decoy Files: Place honeypot files (canary files) on file shares. Any modification to these files should trigger a high-priority alert, as they are not meant to be touched by legitimate processes.

Mitigation

  • Patch Management: The report's finding on unpatched vulnerabilities underscores the critical importance of a robust and timely patch management program (M1051 - Update Software). Prioritize patching of internet-facing systems and known exploited vulnerabilities.
  • Backup and Recovery: Maintain offline, immutable, and regularly tested backups. This is the single most important mitigation for recovering from a ransomware attack.
  • Network Segmentation: Segment networks to prevent the rapid lateral movement of ransomware. Critical systems should be isolated from general-purpose workstations (M1030 - Network Segmentation).
  • Principle of Least Privilege: Enforce strict access controls and ensure user accounts only have the permissions necessary for their roles. This limits an attacker's ability to move laterally and access sensitive data (M1026 - Privileged Account Management).

Timeline of Events

1
April 1, 2025
Start of the 12-month reporting period for the Black Kite ransomware study.
2
March 31, 2026
End of the reporting period, with a total of 7,551 victims documented.
3
July 24, 2026
Black Kite releases its 2026 Ransomware Report.
4
July 24, 2026
This article was published

Article Updates

July 26, 2026

New details from Black Kite's 2026 Ransomware Report highlight AI-enhanced social engineering (vishing), expanded TTPs, and additional mitigation strategies.

MITRE ATT&CK Mitigations

Prioritize patching of internet-facing systems and known exploited vulnerabilities to prevent initial access.

Segment the network to inhibit lateral movement and contain a potential ransomware outbreak.

Enforce the principle of least privilege to limit an attacker's ability to escalate privileges and access critical systems.

Train users to identify and report phishing attempts, a common initial access vector for ransomware.

Timeline of Events

1
April 1, 2025

Start of the 12-month reporting period for the Black Kite ransomware study.

2
March 31, 2026

End of the reporting period, with a total of 7,551 victims documented.

3
July 24, 2026

Black Kite releases its 2026 Ransomware Report.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

RansomwareBlack KiteQilinThreat ReportRaaSManufacturing

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.