The ransomware landscape is experiencing significant changes, as detailed in the recent findings from Check Point Research. The “State of Ransomware Q2 2026” report reveals a shift from a few dominant Ransomware-as-a-Service (RaaS) operations to a more varied ecosystem. While established groups maintain substantial influence, the barriers for new entrants have lowered, leading to an increase in active groups vying for victims.
Shifting Dynamics in Ransomware Operations
The report indicates that while ransomware activity remains concentrated, the number of active groups has risen from 71 to 93, reaching a new high. The top ten ransomware groups accounted for 57.6% of all victims in Q2 2026, down from 71% in the previous quarter. This trend suggests that although established players like Qilin and The Gentlemen continue to dominate, new competitors are beginning to establish their presence in the market.
Victim volume has remained relatively stable, with data leak sites reporting 2,139 victims in Q2. This figure represents a slight increase of 0.8% from Q1 and a notable 33% rise year-over-year. The consistency in victim numbers underscores the ongoing threat posed by ransomware, which has maintained high levels throughout 2025.
Emerging Competitors and AI Integration
The rivalry between Qilin and The Gentlemen has intensified, with Qilin remaining the most prolific operator for the fourth consecutive quarter, despite a 17% decline in victim count to 279. Conversely, The Gentlemen saw a remarkable 62% increase, reaching 269 victims and even surpassing Qilin in June. Insights from an internal leak within The Gentlemen revealed a core team of approximately nine operators supported by a broader affiliate network. Notably, the group employed AI coding assistants to develop their ransomware management panel in just three days, illustrating the role of AI in enhancing malicious tool development.
Despite the uptick in activity, the report highlights a significant decline in ransom payment rates, which have dropped to around 23%, a multi-year low. This marks a continued decrease from 85% in 2019. Interestingly, while median ransom payments are falling, average payments are increasing, indicating that larger enterprises are still willing to pay substantial amounts, whereas mid-market organizations are becoming more resistant to paying ransoms or are opting for smaller settlements.
Law Enforcement and Geographic Trends
In Q2 2026, law enforcement agencies have shifted their focus to targeting shared infrastructure rather than individual groups. This strategy has resulted in the dismantling of a cryptocurrency laundering platform used by multiple ransomware actors, sanctions against significant Iranian digital asset exchanges, and the disruption of malware signing services relied upon by several RaaS operations. These coordinated efforts aim to weaken the operational capabilities of ransomware groups as a whole.
Geographically, the victim landscape is also evolving. The share of victims in the United States has decreased from 50% to 42% quarter-over-quarter. This decline is attributed to the emergence of groups like The Gentlemen and Krybit, which are less focused on targeting U.S. entities compared to the average within the ecosystem.
As the exploitation window narrows, with vulnerabilities being weaponized within hours to days of disclosure, ransomware operators are gaining an additional edge in their efforts to compromise victims. The integration of AI into their operations is likely to further enhance their capabilities, making it essential for organizations to strengthen their defenses against these evolving threats.
For a comprehensive overview of the findings, access the full report from Check Point Research here.
For ongoing coverage and breaking updates, visit our Latest News section.

