CyberMaxx’s Q2 2026 Ransomware Research Report revealed a return to significant growth in ransomware activity, with both attack volumes and active ransomware groups reaching record highs. A total of 2,579 attacks were recorded during the quarter, representing a 13% increase over Q1. At the same time, the number of active ransomware groups surged 54%, from 69 to 106.

A Growing and More Fragmented Threat Landscape

While the increase in attacks is notable, the more important story is how the threat landscape is evolving. The rise in active groups doesn’t necessarily mean more sophisticated attackers. Instead, we’re seeing greater fragmentation as affiliates split from established operations and launch their own brands, while AI-assisted tools continue to lower barriers to entry for cybercriminals.

For CISOs, this means preparing for a broader variety of threats, tactics, and attack methods rather than focusing on a handful of well-known ransomware names.

Business Services Emerges as the Top Target

One of the most significant shifts this quarter was industry targeting. Business Services became the most targeted sector, surpassing both Technology and Manufacturing. Organizations that support large customer bases, critical business functions, or supply chain operations continue to be attractive targets because disruption can quickly spread beyond a single organization.

Manufacturing also remained a high-priority target, reinforcing the fact that attackers continue to seek organizations where downtime creates immediate operational and financial pressure.

Focus on Exposure, Not Geography

The United States remained the most targeted country, accounting for 819 attacks. While ransomware activity is concentrated in larger economies, organizations across every major region continue to be impacted. Exposure matters far more than location. Threat actors follow opportunity, targeting organizations with valuable data, operational dependencies, and accessible attack surfaces.

Key Takeaways for CISOs

As ransomware becomes more diverse and adaptive, security leaders should focus on a few core priorities:

  • Validate incident response and recovery plans through realistic exercises.
  • Strengthen identity security and monitoring capabilities.
  • Prioritize vulnerability management to reduce exposure to known threats.
  • Build operational resilience rather than relying on threat predictions.

This CISO’s Take

The biggest takeaway from Q2 is that ransomware isn’t just growing—it’s evolving. Record attack volumes combined with a sharp increase in active groups indicate that organizations are likely to face a wider range of adversaries and tactics moving forward. The most effective strategy isn’t trying to predict every threat; it’s ensuring your organization can quickly detect, respond to, and recover from whatever comes next.