The State of Ransomware – Q1 2026
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but the road to joining them has gotten a great deal shorter. Key observed findings The ecosystem stayed concentrated even as its tail widened considerably. The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report. Victim volume held at an elevated baseline and did not meaningfully change QoQ. Data leak sites recorded 2,139 victims in Q2, essentially flat versus Q1 (up 0.8%) and up 33% year over year, keeping pace with the highs set through 2025. Qilin and The Gentlemen fought a close race for the top spot all quarter. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims, though its count fell 17%, while The Gentlemen surged 62% to 269 victims and actually outpaced Qilin during the month of June. An internal leak gave an unprecedented look inside The Gentlemen’s operation. Chat logs and platform data exposed a core team of roughly nine operators supported by a broader affiliate base, along with confirmation that the group used AI coding assistants to build its ransomware management panel in about three days, genuine first party evidence of AI accelerating malicious tooling development. Ransom payment rates fell to a multi year low near 23%, continuing a six year decline from 85% in 2019. Even so, on chain ransomware payments still exceeded $820 million in 2025, and the payer market itself is splitting: average payments are rising even as the median falls, a sign that large enterprises keep paying heavily while the mid market increasingly holds firm or settles small. Law enforcement concentrated its Q2 efforts on shared infrastructure rather than individual groups. Actions took down a cryptocurrency laundering platform used by multiple ransomware actors, prompted sanctions against major Iranian digital asset exchanges, dismantled a malware signing service abused by several RaaS operations, and disrupted large infostealer and VPN anonymization networks that many groups depend on at once. The geographic picture shifted meaningfully. The US share of victims fell from 50% to 42% quarter over quarter, largely because the quarter’s fastest growing groups, including The Gentlemen and the newly active Krybit, target the US far less often than the ecosystem average. The exploitation window kept narrowing, with AI increasingly cited as the accelerant. Vulnerabilities are now being weaponized within hours to days of disclosure, lowering the cost of exploit development and giving ransomware operators one more edge in the race to reach victims first. To read the full findings, access the State of Ransomware Q2 2026 report from Check Point Research here . The post The State of Ransomware Q2 2026 appeared first on Check Point Research .
AI Analysis
Technical Summary
This analysis from Check Point Research details ransomware trends in Q2 2026, showing a less concentrated but expanding ransomware ecosystem. The top 10 ransomware groups now account for a smaller share of victims, while the total number of active groups has increased to 93. Ransom payment rates continue to decline, though total payments remain high due to large enterprise payouts. Law enforcement actions targeted shared infrastructure supporting multiple ransomware groups, including cryptocurrency laundering platforms and malware signing services. The US experienced a reduced share of ransomware victims, partly due to the targeting preferences of emerging groups. AI technologies are being leveraged to accelerate ransomware development and reduce exploit development time, enabling faster weaponization of vulnerabilities. The report provides unique insights into ransomware group operations, including the use of AI-assisted coding.
Potential Impact
The ransomware ecosystem is becoming more diverse with more active groups, potentially increasing the attack surface. Although ransom payment rates are declining, the total financial impact remains significant, exceeding $820 million in 2025. The use of AI to accelerate ransomware tooling and exploit development may increase the speed and scale of attacks. Law enforcement disruption of shared infrastructure may reduce operational capabilities of multiple groups simultaneously. The shift in geographic targeting, with fewer US victims proportionally, may affect regional risk profiles. Overall, the ransomware threat remains substantial with evolving tactics and a broadening attacker base.
Mitigation Recommendations
No specific patch or fix applies as this is a threat landscape analysis rather than a vulnerability. Organizations should monitor vendor advisories and threat intelligence for emerging ransomware tactics and exploit developments. Law enforcement efforts targeting shared infrastructure may reduce some risks, but vigilance against ransomware remains critical. The report does not indicate any 'no action required' status or existing mitigations that fully neutralize the threat. Mitigation should focus on ransomware defense best practices aligned with current threat intelligence.
The State of Ransomware – Q1 2026
Description
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but the road to joining them has gotten a great deal shorter. Key observed findings The ecosystem stayed concentrated even as its tail widened considerably. The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report. Victim volume held at an elevated baseline and did not meaningfully change QoQ. Data leak sites recorded 2,139 victims in Q2, essentially flat versus Q1 (up 0.8%) and up 33% year over year, keeping pace with the highs set through 2025. Qilin and The Gentlemen fought a close race for the top spot all quarter. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims, though its count fell 17%, while The Gentlemen surged 62% to 269 victims and actually outpaced Qilin during the month of June. An internal leak gave an unprecedented look inside The Gentlemen’s operation. Chat logs and platform data exposed a core team of roughly nine operators supported by a broader affiliate base, along with confirmation that the group used AI coding assistants to build its ransomware management panel in about three days, genuine first party evidence of AI accelerating malicious tooling development. Ransom payment rates fell to a multi year low near 23%, continuing a six year decline from 85% in 2019. Even so, on chain ransomware payments still exceeded $820 million in 2025, and the payer market itself is splitting: average payments are rising even as the median falls, a sign that large enterprises keep paying heavily while the mid market increasingly holds firm or settles small. Law enforcement concentrated its Q2 efforts on shared infrastructure rather than individual groups. Actions took down a cryptocurrency laundering platform used by multiple ransomware actors, prompted sanctions against major Iranian digital asset exchanges, dismantled a malware signing service abused by several RaaS operations, and disrupted large infostealer and VPN anonymization networks that many groups depend on at once. The geographic picture shifted meaningfully. The US share of victims fell from 50% to 42% quarter over quarter, largely because the quarter’s fastest growing groups, including The Gentlemen and the newly active Krybit, target the US far less often than the ecosystem average. The exploitation window kept narrowing, with AI increasingly cited as the accelerant. Vulnerabilities are now being weaponized within hours to days of disclosure, lowering the cost of exploit development and giving ransomware operators one more edge in the race to reach victims first. To read the full findings, access the State of Ransomware Q2 2026 report from Check Point Research here . The post The State of Ransomware Q2 2026 appeared first on Check Point Research .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This analysis from Check Point Research details ransomware trends in Q2 2026, showing a less concentrated but expanding ransomware ecosystem. The top 10 ransomware groups now account for a smaller share of victims, while the total number of active groups has increased to 93. Ransom payment rates continue to decline, though total payments remain high due to large enterprise payouts. Law enforcement actions targeted shared infrastructure supporting multiple ransomware groups, including cryptocurrency laundering platforms and malware signing services. The US experienced a reduced share of ransomware victims, partly due to the targeting preferences of emerging groups. AI technologies are being leveraged to accelerate ransomware development and reduce exploit development time, enabling faster weaponization of vulnerabilities. The report provides unique insights into ransomware group operations, including the use of AI-assisted coding.
Potential Impact
The ransomware ecosystem is becoming more diverse with more active groups, potentially increasing the attack surface. Although ransom payment rates are declining, the total financial impact remains significant, exceeding $820 million in 2025. The use of AI to accelerate ransomware tooling and exploit development may increase the speed and scale of attacks. Law enforcement disruption of shared infrastructure may reduce operational capabilities of multiple groups simultaneously. The shift in geographic targeting, with fewer US victims proportionally, may affect regional risk profiles. Overall, the ransomware threat remains substantial with evolving tactics and a broadening attacker base.
Defensive Guidance
No specific patch or fix applies as this is a threat landscape analysis rather than a vulnerability. Organizations should monitor vendor advisories and threat intelligence for emerging ransomware tactics and exploit developments. Law enforcement efforts targeting shared infrastructure may reduce some risks, but vigilance against ransomware remains critical. The report does not indicate any 'no action required' status or existing mitigations that fully neutralize the threat. Mitigation should focus on ransomware defense best practices aligned with current threat intelligence.
Technical Details
- Article Source
- {"url":"https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/","fetched":true,"fetchedAt":"2026-05-11T10:07:18.717Z","wordCount":3179}
- Classification
- {"confidence":0.93,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a01aa56cbff5d8610f2f39b
Added to database: 05/11/2026, 10:07:18 UTC
Last enriched: 08/13/2026, 13:04:40 UTC
Last updated: 09/10/2026, 12:03:06 UTC
Views: 180
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.