Ransomware Victims Surge to 7,551 as Black Kite Report Reveals 146 Active Groups and AI-Driven Threats Reshape 2026

Ransomware Victims Surge to 7,551 as Black Kite Report Reveals 146 Active Groups and AI-Driven Threats Reshape 2026

Ransomware Victims Surge to 7,551 as Black Kite Report Reveals 146 Active Groups and AI-Driven Threats Reshape 2026

The number of publicly disclosed ransomware victims hit 7,551 over the past year, a 24.9 percent jump from the prior period, according to Black Kite's 2026 Ransomware Report. The figure marks the fourth straight year that ransomware disclosures have set a new high, and the pace is not slowing down — the second half of the reporting period outpaced the first by 60 percent.

"This year was different. We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half," said Ferhat Dikbiyik, Chief Research and Intelligence Officer at Black Kite. The report, covering April 2025 through March 2026, found that 61 new ransomware groups emerged during those 12 months — more than one per week — pushing the total active threat actor count to 127 by period close and to 146 by June 2026.

Hooded figure working at a multi-monitor computer setup in a dimly lit room, symbolizing a hacker or cybersecurity threat actor

The surge is being driven by a perfect storm: falling barriers to entry for new ransomware crews, the weaponization of artificial intelligence to automate attacks, and the continued exploitation of unpatched vulnerabilities in widely used enterprise software. Forescout's separate 2026 H1 Threat Review, released this month, corroborates the trend — it recorded 4,544 ransomware attack claims in the first half of 2026 alone, a 25 percent year-over-year increase, alongside a 51 percent jump in newly published vulnerabilities to 37,137.

Ransomware Growth Accelerates in the Second Half

The first half of the reporting period produced 2,904 victims, roughly in line with the prior year's baseline. But the second half delivered 4,647 victims — a 60 percent acceleration in monthly pace that pushed every month from October through March above 700 disclosures. March 2026 itself set a new single-month record with 861 victims.

Manufacturing remained the most targeted sector for the fourth consecutive year, absorbing 1,660 victims or 22 percent of all disclosures. Professional, scientific, and technical services followed with 1,389 victims. Together the two sectors accounted for roughly 40 percent of the year's total. Construction climbed to third place with 541 victims, gaining more than a full percentage point of share.

Geographically, the United States remained the single largest target at 49.3 percent of all victims, but that share fell from 51.9 percent even as the raw US victim count rose 19 percent. Europe grew faster: Germany rose 48 percent to 281 victims, Italy jumped 96 percent to 188, and Spain and France each grew by roughly half, according to the Black Kite report.

The New Ransomware Playbook: Supply Chain, AI, and Persistent Exposure

Black Kite's report identifies a structural shift in how ransomware groups operate. Rather than a single dominant actor — LockBit defined 2023, RansomHub defined 2024 — the 2026 threat environment is fragmented across many groups. The top five still controlled 43.6 percent of all victims, but 146 active groups now compete for targets.

Qilin emerged as the highest-volume operator, claiming 1,358 victims — a 443 percent increase from the prior year. Everest built its pattern around accumulated patch debt. Clop continued its mass-exploitation playbook, turning single enterprise vulnerabilities into hundreds of victims. World Leaks concentrated on credential exposure with a UK focus, while Play stayed a fast, opportunistic operator across the US and Canada.

The most consequential shift is the growing role of trusted vendor platforms as attack pathways. The report highlights Salesforce OAuth abuse, the Oracle E-Business Suite campaign exploiting CVE-2025-61882 as a zero-day, and a related PeopleSoft campaign attributed to ShinyHunters. "Every link in a delegated trust chain — from connected apps to support workflows — can become the entry point once one link is abused," the report notes.

Black Kite rescanned ransomware victims after their incidents closed and found a troubling pattern: average Cyber Rating improved, but stealer log exposure came back 175 percent higher, and average Ransomware Susceptibility Index rose from 0.557 to 0.616. Recovering from an incident and closing the exposure that caused it turned out to be two different things.

Linux terminal windows showing network monitoring tools, system metrics, and command-line utilities — the tools cybersecurity professionals use to detect and analyze threats

AI Lowers the Cost of Running a Ransomware Operation

Artificial intelligence is reshaping cybercrime economics. "AI hasn't made ransomware autonomous. It's made more operators capable of running an operation that used to require a bigger team," Dikbiyik said.

New ransomware groups first observed between April and September 2025 lasted a median of just 4.9 months, compared to 12.8 months for the prior year's cohort. The barrier to entry is falling faster than the barrier to staying in business. The report flags JADEPUFFER, documented by Sysdig researchers, as the first observed case of an AI agent orchestrating attack stages from reconnaissance through encryption with limited human direction.

Taiwan's Administration for Cybersecurity separately warned this week that AI is making ransomware faster, more automated, and more targeted. In a July 28 alert, the agency said cybercriminals are using AI to accelerate phishing, deepen double-extortion tactics, and produce deepfake audio for vishing attacks. The FBI's IC3 Annual Report recorded 3,611 ransomware complaints last year, up 14 percent from 2024, with reported financial losses surging to $32.32 million from $12.47 million.

In Taiwan itself, at least five companies have reported ransomware attacks so far in 2026, spanning papermaking, biotechnology manufacturing, semiconductor equipment, and electronic components. On July 17, a hacker claiming access to more than 90 Taiwanese organizations — including AUO Corp and Hiwin Technologies — posted a target list on Telegram.

Patch Debt and the Vulnerability Explosion

Underlying the ransomware surge is a vulnerability discovery machine running at full speed. Forescout's H1 2026 Threat Review found that 37,137 new vulnerabilities were published in the first six months of 2026, a 51 percent year-over-year increase. More than half were rated high or critical severity. Yet 46 percent of additions to CISA's Known Exploited Vulnerabilities catalog were CVEs published before 2026 — older flaws that attackers continue to exploit because organizations have not patched them.

Black Kite's data paints an even starker picture: 43.5 percent of ransomware victims still carried a CVSS 9.0 or higher vulnerability when rescanned after their incident. "Recovering from an incident and reducing the exposure that caused it are not the same project," the report states. "Treating them as one is how the same organization ends up victimized twice."

For cybersecurity teams, the implications are clear. The $50 million to $100 million revenue band grew to 29.3 percent of ransomware victims, up from 25.1 percent, becoming the largest share of any revenue band. Mid-market organizations are increasingly in the crosshairs, and they face the same threats as large enterprises with fewer resources to defend themselves.

What Organizations Must Do Now

Experts across multiple reports agree on the fundamentals. Organizations should prioritize patching known exploited vulnerabilities, implement multi-factor authentication across all externally facing services, segment networks to limit lateral movement, and maintain offline backups tested regularly for recovery. Supply chain risk management must account for vendor identity and application access, not just perimeter security, given the rise of trusted-platform attacks.

The Administration for Cybersecurity in Taiwan advises companies to disable unnecessary externally accessible interfaces, update credentials and software on internet-facing systems, and check for suspicious login activity in VPNs, firewalls, and cloud services. If a ransomware attack is suspected, organizations should disconnect affected systems immediately, preserve evidence, and seek assistance from cybersecurity experts — but should not pay the ransom.

The breadth of the threat underscores the scale of the challenge. With 146 active groups launching thousands of attacks each month, the attack surface has never been wider. The 2026 data shows that ransomware is not a problem that can be solved with any single fix — it requires sustained attention to basic hygiene, continuous monitoring, and a supply chain security program that matches the reality of how attackers now operate.

For more cybersecurity coverage, visit the Cybersecurity section of news.jualin.id.

← Back to Home