Ransomware Attacks Up 25% Year-Over-Year: Black Kite Report

Ransomware Attacks Surged 25% in a Year, Reaching 7,551 Victims

HIGH
July 29, 2026
August 17, 2026
5m read
RansomwareThreat IntelligenceData Breach

Related Entities(initial)

Threat Actors

Qilin The Gentlemen

Organizations

Full Report(when first published)

Executive Summary

The ransomware epidemic has continued its relentless growth, setting new records for the fourth consecutive year. According to the "2026 Ransomware Report" from cybersecurity firm Black Kite, the number of publicly claimed ransomware victims surged by 24.9% year-over-year, reaching a total of 7,551 organizations between April 2025 and March 2026. The report highlights a dramatic 60% acceleration in attack volume during the latter half of this period, with March 2026 marking the single worst month on record. The ransomware landscape has also become more fragmented, with the number of active groups growing to 146. The Qilin group emerged as the most dominant operator, while the manufacturing sector and organizations in the United States remained the most frequent targets.


Threat Overview

The report paints a picture of a mature and evolving criminal industry. Key trends include:

  • Record-Breaking Volume: 7,551 victims were posted on data leak sites, a 24.9% increase from the previous year.
  • Accelerating Pace: After a relatively stable start, attack volume exploded by 60% from October 2025 to March 2026.
  • Fragmented Ecosystem: The number of active Ransomware-as-a-Service (RaaS) groups grew from 127 to 146, with over 60 new groups emerging. This indicates a low barrier to entry but also intense competition.
  • Market Concentration: Despite the fragmentation, the top 5 most active groups were responsible for 43.6% of all victims, demonstrating significant market concentration. The top groups identified were Qilin and The Gentlemen.

Technical Analysis

While the report focuses on victimology trends, it reflects several underlying technical shifts in ransomware operations:

  • Initial Access: As detailed in other reports, many of these attacks leverage unpatched vulnerabilities in public-facing infrastructure, especially VPNs and other network edge devices (T1190 - Exploit Public-Facing Application). Phishing (T1566 - Phishing) and stolen credentials (T1078 - Valid Accounts) also remain primary vectors.
  • Double Extortion: The victim numbers are based on posts to data leak sites, confirming that double extortion (encrypting data AND threatening to leak it) is the standard operating procedure for virtually all major groups.
  • Geographic and Industry Targeting: The United States remains the primary target, accounting for 49.3% of victims. However, attacks in Europe are growing at a faster rate. For the fourth year in a row, the manufacturing sector was the most heavily victimized industry, likely due to its lower tolerance for downtime and perceived lower security maturity.

Impact Assessment

The sustained increase in ransomware attacks has profound economic and operational impacts:

  • Business Disruption: The primary impact of a ransomware attack is severe business disruption, leading to lost revenue, production halts, and an inability to serve customers.
  • Financial Costs: Costs include ransom payments (if made), recovery and remediation expenses, legal fees, and regulatory fines.
  • Supply Chain Disruption: Attacks on manufacturers and logistics companies have a cascading effect, disrupting downstream supply chains and impacting other businesses.
  • Data Breach Consequences: The double extortion model means every ransomware attack is also a data breach, triggering costly notification requirements and exposing organizations to liability for compromised sensitive information.

IOCs — Directly from Articles

This article is a trend report and does not contain specific Indicators of Compromise.


Cyber Observables — Hunting Hints

To detect ransomware activity early, security teams should hunt for:

  • Discovery Commands: Look for the execution of commands used for network and system discovery, such as nltest /dclist, net group "Domain Admins", and AdFind.exe.
  • Credential Dumping: Monitor for processes accessing LSASS memory (e.g., via Mimikatz) or the execution of tools that dump credentials from browser databases. This relates to T1003 - OS Credential Dumping.
  • Disabling Security Tools: Search for commands or scripts attempting to disable or tamper with security software (AV, EDR) or delete volume shadow copies (vssadmin.exe delete shadows /all /quiet). This is a classic ransomware precursor (T1562.001 - Disable or Modify Tools).

Detection & Response

  1. EDR and XDR: Deploy advanced endpoint (EDR) and extended detection and response (XDR) solutions that use behavioral analysis to detect ransomware TTPs, rather than just relying on file signatures.
  2. Canary Files: Place decoy files (canaries) on file shares and endpoints. Use file integrity monitoring to generate a high-priority alert if these files are modified or encrypted, as this is a strong signal of active ransomware.
  3. Active Directory Monitoring: Closely monitor Active Directory for signs of privilege escalation, creation of new admin accounts, or changes to group policies, as these are common lateral movement techniques.

Mitigation

  1. Immutable Backups: Maintain multiple, isolated, and immutable backups of critical data. Regularly test your backup and recovery process to ensure you can restore operations without paying a ransom. This aligns with M1053 - Data Backup.
  2. Patch Management: Aggressively patch internet-facing systems, especially VPNs, firewalls, and remote access servers. This remains the most common initial access vector for ransomware groups.
  3. Network Segmentation: Segment your network to prevent ransomware from spreading laterally from the initial point of compromise. Isolate critical assets and backup systems on separate network segments. This is a key principle of M1030 - Network Segmentation.

Timeline of Events

1
March 1, 2026
March 2026 becomes the highest single-month total for ransomware victims recorded by Black Kite, with 861.
2
March 31, 2026
End of the 12-month reporting period (April 2025 - March 2026) analyzed by Black Kite.
3
July 29, 2026
This article was published

Article Updates

August 17, 2026

Ransomware attacks climbed 33% in Q2 2026, with new reports confirming threat actors are leveraging AI to accelerate tool development and shrink exploit weaponization windows.

MITRE ATT&CK Mitigations

Maintain and test immutable backups to ensure recovery without paying a ransom.

Aggressively patch public-facing applications and VPNs to block common initial access vectors.

Segment networks to contain ransomware spread and protect critical assets.

Train users to identify and report phishing attempts, another primary initial access vector.

Timeline of Events

1
March 31, 2026

End of the 12-month reporting period (April 2025 - March 2026) analyzed by Black Kite.

2
March 1, 2026

March 2026 becomes the highest single-month total for ransomware victims recorded by Black Kite, with 861.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

RansomwareBlack KiteQilinThreat IntelligenceCybercrimeData Breach

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.