The ransomware epidemic has continued its relentless growth, setting new records for the fourth consecutive year. According to the "2026 Ransomware Report" from cybersecurity firm Black Kite, the number of publicly claimed ransomware victims surged by 24.9% year-over-year, reaching a total of 7,551 organizations between April 2025 and March 2026. The report highlights a dramatic 60% acceleration in attack volume during the latter half of this period, with March 2026 marking the single worst month on record. The ransomware landscape has also become more fragmented, with the number of active groups growing to 146. The Qilin group emerged as the most dominant operator, while the manufacturing sector and organizations in the United States remained the most frequent targets.
The report paints a picture of a mature and evolving criminal industry. Key trends include:
While the report focuses on victimology trends, it reflects several underlying technical shifts in ransomware operations:
T1190 - Exploit Public-Facing Application). Phishing (T1566 - Phishing) and stolen credentials (T1078 - Valid Accounts) also remain primary vectors.The sustained increase in ransomware attacks has profound economic and operational impacts:
This article is a trend report and does not contain specific Indicators of Compromise.
To detect ransomware activity early, security teams should hunt for:
nltest /dclist, net group "Domain Admins", and AdFind.exe.LSASS memory (e.g., via Mimikatz) or the execution of tools that dump credentials from browser databases. This relates to T1003 - OS Credential Dumping.vssadmin.exe delete shadows /all /quiet). This is a classic ransomware precursor (T1562.001 - Disable or Modify Tools).Ransomware attacks climbed 33% in Q2 2026, with new reports confirming threat actors are leveraging AI to accelerate tool development and shrink exploit weaponization windows.
Maintain and test immutable backups to ensure recovery without paying a ransom.
Aggressively patch public-facing applications and VPNs to block common initial access vectors.
Segment networks to contain ransomware spread and protect critical assets.
Train users to identify and report phishing attempts, another primary initial access vector.
End of the 12-month reporting period (April 2025 - March 2026) analyzed by Black Kite.
March 2026 becomes the highest single-month total for ransomware victims recorded by Black Kite, with 861.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.