As cited
Copy frozen at (site build).
ransomware
The State of Ransomware Q2 2026
Check Point Research's Q2 2026 ransomware report shows the landscape shifting toward broader group participation even as top operators maintain dominance: the top 10 groups claimed 57.6% of victims (down from 71% in Q1), while active groups expanded from 71 to 93. Qilin led with 279 victims, though The Gentlemen surged to 269 and briefly took the top position in June; an internal leak revealed the group uses AI coding assistants to develop tools. Ransom payment rates hit a multi-year low near 23%, yet on-chain payments exceeded $820 million in 2025, with large enterprises continuing to pay while mid-market organizations increasingly resist.
Why it matters: Defenders need to monitor a rapidly expanding roster of active ransomware operators (up 31% quarter over quarter) and recognize that exploitation windows are collapsing due to AI-accelerated tooling, requiring faster patching cadences and incident response readiness.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
The State of Ransomware Q2 2026
Check Point Research's Q2 2026 ransomware report shows the ecosystem remaining concentrated but widening, with active groups rising from 71 to 93 while the top 10 groups' share dropped to 57.6% from 71% in Q1. Qilin and The Gentlemen battled for leadership, though ransom payment rates hit a multi-year low near 23%, and law enforcement disrupted shared criminal infrastructure including cryptocurrency laundering and malware signing services. Exploitation windows narrowed further as artificial intelligence accelerated both vulnerability weaponization and malicious tool development, with US victim concentration declining as certain groups shifted targeting geographically.
Why it matters: Enterprise defenders should monitor the rise of 22 new active ransomware groups and prepare for faster exploit development cycles driven by AI; mid-market organizations may face pressure as large enterprises continue paying ransoms while SMBs increasingly resist payment; incident responders and threat intelligence teams should track Qilin, The Gentlemen, and Krybit variants and expect hour-to-day exploitation windows for zero-day and newly disclosed vulnerabilities.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
The State of Ransomware Q2 2026
Check Point Research's Q2 2026 ransomware report shows the ecosystem remaining concentrated but widening, with active groups rising from 71 to 93 while the top 10 groups' share dropped to 57.6% from 71% in Q1. Qilin and The Gentlemen battled for leadership, though ransom payment rates hit a multi-year low near 23%, and law enforcement disrupted shared criminal infrastructure including cryptocurrency laundering and malware signing services. Exploitation windows narrowed further as artificial intelligence accelerated both vulnerability weaponization and malicious tool development, with US victim concentration declining as certain groups shifted targeting geographically.
Why it matters: Enterprise defenders should monitor the rise of 22 new active ransomware groups and prepare for faster exploit development cycles driven by AI; mid-market organizations may face pressure as large enterprises continue paying ransoms while SMBs increasingly resist payment; incident responders and threat intelligence teams should track Qilin, The Gentlemen, and Krybit variants and expect hour-to-day exploitation windows for zero-day and newly disclosed vulnerabilities.
- Source published
- First seen by Cybersecurity Tracker