The CyberMaxx team of cyber researchers conducts routine threat research independent of client engagements. The purpose of our research is to help foster collective intelligence among the cybersecurity community.
While conducting their research, the team discovers and analyzes ongoing ransomware attacks occurring in the wild.
Review Q2’s research here.
Video Transcript
Intro
Welcome to our Q2 2026 Ransomware Research and Data Extortion Threat Report. In this update, we examine how the ransomware landscape has evolved over the past quarter, analysing overall attack volumes, the activity of the most prominent ransomware groups, industry targeting, and global geographic trends. By comparing these findings with previous quarters, we identify key shifts in attacker behaviour and highlight the sectors and regions facing the greatest levels of risk. Whether you’re responsible for cybersecurity strategy, risk management, or incident response, this report provides practical insights to help organisations better understand the current threat landscape and prioritise their defensive security efforts.
Ransomware numbers
Ransomware activity increased significantly during Q2 2026, with recorded attacks rising from 2,282 in Q1 to 2,579—a 13 percent increase quarter over quarter. The number of active ransomware groups also grew substantially, increasing from 69 to 106 groups, an increase of more than 53 percent.
These figures mark a return to the upward trend following the slight decline observed in Q1. In fact, Q2 recorded the highest number of attacks and active ransomware groups in our reporting period, highlighting that the ransomware threat continues to expand.
The increase in active groups should not necessarily be interpreted as a proportional increase in organisational risk. Rather than indicating an influx of entirely new threat actors, it may reflect affiliates and operators separating from established ransomware operations to launch campaigns under new brands. At the same time, the growing availability of AI-assisted tools is reducing the technical barriers associated with developing phishing campaigns, malware, and supporting infrastructure, making it easier for threat actors to establish and maintain ransomware operations.
Looking at the broader trend over the past twelve months, ransomware and data extortion activity has continued to increase overall despite the temporary slowdown in Q1. The key takeaway is that organisations are now facing a more diverse ransomware landscape, with activity distributed across a larger number of groups employing a wider range of tactics and techniques.
For defenders, this reinforces the importance of maintaining strong cyber resilience. Effective vulnerability management, continuous monitoring, rapid detection and response, and well-tested business continuity and recovery plans remain essential for reducing both the likelihood and impact of ransomware incidents.
Groups Analysis
Turning to the ransomware groups themselves, Qilin remained the most active operator throughout Q2 2026, recording approximately 300 successful attacks and maintaining a clear lead over every other group. It was followed by TheGentlemen, with just over 250 attacks, while DragonForce and Akira ranked third and fourth with 148 and 122 attacks respectively. LockBit 5 also featured prominently, recording just over 100 attacks and remaining among the five most active groups during the quarter.
The consistency of these names at the top of the rankings demonstrates that a relatively small number of ransomware operations continue to account for a significant proportion of global activity. Despite the increase in active ransomware groups observed this quarter, the leading operators remain well established and continue to demonstrate the greatest operational impact.
Qilin’s continued dominance reflects its maturity as a ransomware-as-a-service, or RaaS, operation. Throughout the quarter, the group maintained broad targeting across multiple industry verticals and supported attacks against Windows, Linux, and VMware ESXi environments. Its ability to compromise diverse enterprise environments, combined with an established affiliate model, has enabled it to sustain a high volume of successful attacks over multiple consecutive quarters.
The continued presence of LockBit 5 is also notable. Although its activity remains below that of the original LockBit operation prior to international law enforcement action in 2024, the continued use of the LockBit name demonstrates the resilience of recognised ransomware brands. Established names continue to attract affiliates and retain credibility within the cybercriminal ecosystem, even after significant operational disruption.
The increase from 69 to 106 active ransomware groups should also be viewed in context. The data does not necessarily indicate the emergence of entirely new threat actors. Instead, it is likely that some of this growth reflects affiliates or operators separating from established ransomware organisations to form independent groups under new branding. At the same time, AI-assisted tooling is lowering the technical barrier to entry, simplifying tasks such as phishing content generation, malware development, and infrastructure management. Together, these developments are contributing to a larger number of active ransomware groups while allowing established operators to remain responsible for the majority of successful attacks.
Industry Breakdown
Looking at ransomware activity by industry, Q2 2026 saw a notable shift in targeting priorities. While Technology and Manufacturing dominated during the previous quarter, Business Services became the most targeted sector, recording approximately 355 attacks, followed by Manufacturing with around 310 incidents.
The prominence of Business Services reflects the strategic value of organisations that support multiple customers, business functions, or supply chains. A successful compromise within this sector can disrupt numerous downstream organisations, increasing operational impact and potentially strengthening the attackers’ position during extortion negotiations. Manufacturing also remained a consistently attractive target, where downtime can rapidly translate into production losses, financial impact, and increased pressure to restore operations.
Although Technology and Healthcare dropped to the third and fourth most targeted sectors, respectively, they continued to experience substantial ransomware activity, demonstrating that industries with valuable intellectual property, sensitive data, and complex digital environments remain high-value targets for threat actors.
Overall, the data shows that ransomware groups continue to prioritise sectors with a high dependence on information technology, limited tolerance for operational disruption, and a greater likelihood of paying a ransom to restore critical business functions. Rather than targeting industries indiscriminately, threat actors continue to focus on sectors where disruption creates the greatest financial and operational leverage.
Examining individual ransomware groups also reveals differences in targeting strategies. Qilin maintained broad activity across multiple sectors, recording particularly high numbers of attacks against Business Services and Manufacturing, while also remaining highly active within Technology, Healthcare, and Consumer Services. In contrast, TheGentlemen demonstrated a more concentrated targeting profile, focusing primarily on Manufacturing, Business Services, Healthcare, and Technology.
These findings suggest that while the leading ransomware groups share an interest in high-value industries, each continues to demonstrate its own operational priorities. Understanding these sector-specific targeting patterns allows organisations to better assess their exposure and align defensive measures with the threat actors most likely to target their industry.
Geographic Review
The geographic distribution of ransomware activity in Q2 2026 continues the trend of remaining heavily concentrated in a relatively small number of countries. The United States continued to be the primary target, recording 819 attacks—more than five times the number observed in the next most targeted country. Germany, the United Kingdom, and Canada followed with 138, 124, and 74 attacks respectively.
This pattern reflects a long-established trend. Threat actors continue to prioritise countries with large, digitally mature economies, where organisations are more likely to rely on complex IT infrastructure, hold valuable data, and possess the financial resources to meet ransom demands.
Beyond these leading countries, attack volumes declined noticeably. France and Italy each recorded around 60 attacks, while Australia, Spain, Brazil, Mexico, India, Japan, and Thailand experienced between 35 and 55 incidents during the quarter. Although these figures are significantly lower than those recorded in the United States, they reinforce that ransomware remains a global threat affecting organisations across North America, Europe, Asia-Pacific, and Latin America.
Outside the top ten, most countries recorded fewer than 30 attacks. However, this should not be interpreted as ransomware being confined to a handful of regions. Instead, it demonstrates that modern ransomware operations have global reach. The widespread adoption of ransomware-as-a-service models, affiliate programmes, and standardised tooling enables threat actors to conduct campaigns against organisations almost anywhere, with relatively little geographic limitation.
The key takeaway is that while ransomware groups have the capability to target organisations worldwide, they continue to prioritise countries where digital maturity, economic strength, and business reliance on technology provide the greatest opportunity for successful extortion. This targeting strategy has remained remarkably consistent over recent reporting periods and shows little sign of changing.
Conclusion
As we’ve seen throughout this report, ransomware remains one of the most persistent and adaptive cyber threats facing organisations. Q2 2026 saw record levels of both ransomware attacks and active groups, but the most significant takeaway is not simply the increase in numbers—it’s how the threat landscape continues to evolve.
For organisations, this reinforces the need to view ransomware as an ongoing business risk rather than an isolated cybersecurity issue. Reducing exposure requires more than preventative controls alone. It depends on strong vulnerability management, effective identity and access security, continuous monitoring, rapid detection and response, and well-rehearsed recovery and business continuity plans.
While the ransomware landscape will undoubtedly continue to evolve, the underlying objective of threat actors remains unchanged: identifying organisations where disruption creates maximum leverage. Understanding how these groups operate, who they target, and how those trends are changing enables organisations to make more informed security decisions and improve their overall cyber resilience.
Thank you for listening to our Q2 2026 Ransomware Research Report. We look forward to bringing you the next quarterly update.