The 2026 Ransomware Report from Black Kite reveals a continued and accelerating surge in ransomware activity, with a 24.9% year-over-year increase in publicly disclosed victims. The report, which analyzed data from April 2025 to March 2026, documented 7,551 victims, setting a new record for the fourth consecutive year. The ransomware ecosystem has become increasingly fragmented with 146 active groups, but is dominated by a few key players. The Qilin ransomware group was the most prolific, responsible for nearly 20% of all attacks. The manufacturing industry remains the primary target, and the United States continues to be the most affected country. A concerning finding is that 43.5% of victims failed to remediate critical vulnerabilities even after being breached, leaving them exposed to repeat attacks.
The report paints a picture of a mature and evolving ransomware ecosystem. While the number of active groups has grown to 146, indicating a lower barrier to entry likely fueled by the Ransomware-as-a-Service (RaaS) model, the market is not evenly distributed. The top five most active groups accounted for 43.6% of all victims, demonstrating a concentration of power and capability.
Key Trends:
T1486 - Data Encrypted for Impact: The core activity of all ransomware groups.T1071.001 - Web Protocols: Used for command and control and data exfiltration.T1190 - Exploit Public-Facing Application: A common initial access vector.T1021.001 - Remote Desktop Protocol: Frequently used for lateral movement.T1566 - Phishing: A primary method for gaining initial access through credential theft or malware delivery.T1657 - Financial Theft: The ultimate objective of ransomware operations through extortion.The impact is broad and severe across multiple dimensions.
This article is a trend report and does not contain specific, actionable indicators of compromise.
To hunt for general ransomware activity, security teams should look for the following patterns:
vssadmin.exe delete shadows /all /quiet or similar commands to delete volume shadow copies.README.txt, DECRYPT_INSTRUCTIONS.txt, or HOW_TO_RECOVER.txt across multiple directories..qilin, .lockbit).D3-PA: Process Analysis.M1051 - Update Software). Prioritize patching of internet-facing systems and known exploited vulnerabilities.M1030 - Network Segmentation).M1026 - Privileged Account Management).New details from Black Kite's 2026 Ransomware Report highlight AI-enhanced social engineering (vishing), expanded TTPs, and additional mitigation strategies.
Prioritize patching of internet-facing systems and known exploited vulnerabilities to prevent initial access.
Segment the network to inhibit lateral movement and contain a potential ransomware outbreak.
Enforce the principle of least privilege to limit an attacker's ability to escalate privileges and access critical systems.
Train users to identify and report phishing attempts, a common initial access vector for ransomware.
Start of the 12-month reporting period for the Black Kite ransomware study.
End of the reporting period, with a total of 7,551 victims documented.
Black Kite releases its 2026 Ransomware Report.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.