Linthicum Heights, MD – July 29, 2026 – CyberMaxx, the leading managed detection and response (MDR) provider, released its Quarterly Ransomware Research Report today. The report reveals a significant increase in ransomware and data extortion activity during Q2 2026, with both attack volumes and the number of active ransomware groups reaching record highs.
A total of 2,579 ransomware attacks were recorded in Q2 (April–June) 2026, representing a 13% increase from the 2,282 attacks observed in Q1 2026. The findings indicate that ransomware activity has resumed its upward trajectory following the temporary slowdown seen earlier in the year and now exceeds the previous peak recorded in Q4 2025.
The report also found that the number of active ransomware groups increased dramatically from 69 to 106, a 54% increase quarter-over-quarter. This growth suggests a ransomware ecosystem that is becoming increasingly fragmented, driven by affiliates breaking away from established operations to launch independent groups, as well as the growing availability of AI-assisted tools that lower barriers to entry for cybercriminals.
Qilin remained the most active ransomware group during Q2 2026, recording approximately 300 successful attacks. TheGentlemen, DragonForce, Akira, and LockBit5 rounded out the top five most active groups. While established operators continue to account for a substantial share of overall activity, the sharp increase in active groups highlights an increasingly diverse and competitive threat landscape.
Industry targeting patterns also shifted during the quarter. Business Services became the most targeted sector, surpassing both Technology and Manufacturing, with approximately 355 recorded attacks. Manufacturing remained a highly attractive target due to the disruptive impact ransomware can have on operations, while Healthcare and Technology continued to experience elevated attack volumes compared to most other industries.
Geographically, ransomware activity remained concentrated in large developed economies. The United States accounted for 819 attacks, significantly more than any other country, followed by Germany, the United Kingdom, and Canada. However, organizations across Europe, Asia-Pacific, and Latin America continued to experience persistent ransomware activity, reinforcing the global nature of the threat.
The findings suggest that organizations are not simply facing more ransomware groups, but a broader range of adversaries employing diverse tactics, techniques, and targeting strategies. As AI-assisted tooling becomes more accessible and ransomware operations continue to evolve, organizations should prioritize resilience through strong vulnerability management, identity security, continuous monitoring, incident response readiness, and business continuity planning.
CyberMaxx’s cyber research team regularly investigates threats independently. These efforts aim to build shared knowledge across the cybersecurity community.
Access the full Ransomware Research Report here: Q2 2026 Ransomware Research Report
About CyberMaxx
CyberMaxx is a proactive MDR leader delivering a layered defense across the five critical attack vectors, identity, email, endpoint, network, and cloud, backed by a 24x7x365 human-led, AI-powered SOC and Threat Response Team. CyberMaxx delivers outcomes through zero-latency remediation on confirmed attacks, no matter where they originate, so the burden of response never falls on the customer. We use offensive-driven insights to strengthen our defense, helping customers anticipate emerging threats and outmaneuver attackers before they escalate. We don’t just monitor your environment. We defend it
For more information, visit www.cybermaxx.com.
CyberMaxx Media Contact
John Pinkham
jpinkham@cybermaxx.com