A new threat intelligence report from Check Point Research reveals a significant consolidation in the ransomware market. During March 2026, three dominant ransomware groups were responsible for 40% of all publicly claimed attacks. Qilin (also known as Agenda) was the most prolific, accounting for 20% of all incidents. The Akira ransomware group followed with 12%, and DragonForce was responsible for 8%. This trend indicates that while many ransomware groups exist, a few highly effective and organized operations are capturing a large market share, driving a 7% overall increase in attacks compared to the previous month.
The report paints a picture of a maturing, albeit criminal, market. The top groups are not just technically proficient but also have sophisticated business models.
Despite a general slowdown from the peaks of 2025, these dominant players are driving a resurgence in attack volume. Their focus remains on sectors where operational downtime has the highest financial impact, maximizing their leverage for extortion.
While the report focuses on attack volume, the TTPs of these top groups are well-documented and share common patterns:
T1190 - Exploit Public-Facing Application and T1566 - Phishing are primary vectors.T1059.001 - PowerShell and T1569.002 - Service Execution are common.T1041 - Exfiltrate Data to Cloud Storage) before encrypting files on the victim's network (T1486 - Data Encrypted for Impact). This gives them two points of leverage for payment.lsass.exe memory being accessed by an unusual process) are critical for detection.powershell.exe spawning from a Microsoft Office application. Use D3-FCR: File Content Rules on egress points to detect and block the exfiltration of sensitive data before encryption occurs.Q1 2026 ransomware activity stabilized at high levels, establishing a 'new normal'. 'The Gentlemen' surged as a top threat, and construction sector attacks increased significantly.
A new report from GuidePoint Security covering Q1 2026 indicates ransomware activity has stabilized at the high levels of 2025, establishing an 'elevated new normal'. While Qilin's activity dipped by 25% from Q4 2025, a new group, 'The Gentlemen', surged to become the second most prolific with 182 victims. Akira's activity also declined. The construction sector saw a 44% year-over-year increase in attacks, highlighting evolving targeting trends and the persistent, high-volume threat.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.