CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ransomware and Cyber Extortion in Q2 2026

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2690

As cited

Copy frozen at (site build).

ransomware

Ransomware and Cyber Extortion in Q2 2026

A ransomware threat report covering Q2 2026 activity found that group rankings shifted significantly, with "The Gentlemen" claiming the top spot while previously dominant groups like Qilin and DragonForce declined. Notable developments include Deadlock's resurgence with blockchain-based command and control and kernel-level endpoint detection and response (EDR) evasion techniques, alongside steady targeting patterns favoring professional, scientific, and technical services sectors across 90 groups in 99 countries. Despite quarterly fluctuations in victim counts, underlying attack techniques remained consistent, with the US absorbing approximately 49 percent of victim activity.

Why it matters: Security teams must prioritize detection of ransomware behaviors (remote-service abuse, identity compromise, lateral movement, defense evasion) rather than tracking group rankings, and should immediately assess exposure to Deadlock's blockchain-based command and control and kernel-level EDR termination tactics that may evade current defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Ransomware and Cyber Extortion in Q2 2026

A ransomware threat report covering Q2 2026 activity found that group rankings shifted significantly, with "The Gentlemen" claiming the top spot while previously dominant groups like Qilin and DragonForce declined. Notable developments include Deadlock's resurgence with blockchain-based command and control and kernel-level endpoint detection and response (EDR) evasion techniques, alongside steady targeting patterns favoring professional, scientific, and technical services sectors across 90 groups in 99 countries. Despite quarterly fluctuations in victim counts, underlying attack techniques remained consistent, with the US absorbing approximately 49 percent of victim activity.

Why it matters: Security teams must prioritize detection of ransomware behaviors (remote-service abuse, identity compromise, lateral movement, defense evasion) rather than tracking group rankings, and should immediately assess exposure to Deadlock's blockchain-based command and control and kernel-level EDR termination tactics that may evade current defenses.

Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary