Ransomware Landscape Transforms: Active Groups Surge to 93 as Payment Rates Plummet in Q2 2026

Published:

The ransomware landscape is experiencing significant changes, as detailed in the recent findings from Check Point Research. The “State of Ransomware Q2 2026” report reveals a shift from a few dominant Ransomware-as-a-Service (RaaS) operations to a more varied ecosystem. While established groups maintain substantial influence, the barriers for new entrants have lowered, leading to an increase in active groups vying for victims.

Shifting Dynamics in Ransomware Operations

The report indicates that while ransomware activity remains concentrated, the number of active groups has risen from 71 to 93, reaching a new high. The top ten ransomware groups accounted for 57.6% of all victims in Q2 2026, down from 71% in the previous quarter. This trend suggests that although established players like Qilin and The Gentlemen continue to dominate, new competitors are beginning to establish their presence in the market.

Victim volume has remained relatively stable, with data leak sites reporting 2,139 victims in Q2. This figure represents a slight increase of 0.8% from Q1 and a notable 33% rise year-over-year. The consistency in victim numbers underscores the ongoing threat posed by ransomware, which has maintained high levels throughout 2025.

Emerging Competitors and AI Integration

The rivalry between Qilin and The Gentlemen has intensified, with Qilin remaining the most prolific operator for the fourth consecutive quarter, despite a 17% decline in victim count to 279. Conversely, The Gentlemen saw a remarkable 62% increase, reaching 269 victims and even surpassing Qilin in June. Insights from an internal leak within The Gentlemen revealed a core team of approximately nine operators supported by a broader affiliate network. Notably, the group employed AI coding assistants to develop their ransomware management panel in just three days, illustrating the role of AI in enhancing malicious tool development.

Despite the uptick in activity, the report highlights a significant decline in ransom payment rates, which have dropped to around 23%, a multi-year low. This marks a continued decrease from 85% in 2019. Interestingly, while median ransom payments are falling, average payments are increasing, indicating that larger enterprises are still willing to pay substantial amounts, whereas mid-market organizations are becoming more resistant to paying ransoms or are opting for smaller settlements.

Law Enforcement and Geographic Trends

In Q2 2026, law enforcement agencies have shifted their focus to targeting shared infrastructure rather than individual groups. This strategy has resulted in the dismantling of a cryptocurrency laundering platform used by multiple ransomware actors, sanctions against significant Iranian digital asset exchanges, and the disruption of malware signing services relied upon by several RaaS operations. These coordinated efforts aim to weaken the operational capabilities of ransomware groups as a whole.

Geographically, the victim landscape is also evolving. The share of victims in the United States has decreased from 50% to 42% quarter-over-quarter. This decline is attributed to the emergence of groups like The Gentlemen and Krybit, which are less focused on targeting U.S. entities compared to the average within the ecosystem.

As the exploitation window narrows, with vulnerabilities being weaponized within hours to days of disclosure, ransomware operators are gaining an additional edge in their efforts to compromise victims. The integration of AI into their operations is likely to further enhance their capabilities, making it essential for organizations to strengthen their defenses against these evolving threats.

For a comprehensive overview of the findings, access the full report from Check Point Research here.

For ongoing coverage and breaking updates, visit our Latest News section.

_Published on 2026-08-14 03:17:00 • By the Editorial Desk_

Share post:

[tds_leads title_text="Subscribe" input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" f_title_font_family="653" f_title_font_size="eyJhbGwiOiIyNCIsInBvcnRyYWl0IjoiMjAiLCJsYW5kc2NhcGUiOiIyMiJ9" f_title_font_line_height="1" f_title_font_weight="700" f_title_font_spacing="-1" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="3" input_radius="3" f_msg_font_family="653" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="600" f_msg_font_line_height="1.4" f_input_font_family="653" f_input_font_size="eyJhbGwiOiIxNCIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="653" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="700" f_pp_font_family="653" f_pp_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#ec3535" pp_check_color_a_h="#c11f1f" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjM1IiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="2" btn_bg="#ec3535" btn_bg_h="#c11f1f" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIxOCJ9" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0="]

Popular

More like this
Related

Eleven Emirati AI experts engage with Canadian institutions to enhance responsible AI applications

Eleven Emirati artificial intelligence experts from the National Experts Programme’s Artificial Intelligence track (NEP-AI) are currently engaging with leading Canadian institutions to explore the translation of advanced AI research into responsible applications. This international study visit, which commenced on Monday…

Kaspersky uncovers phishing campaign impersonating Zoom and Docusign targeting corporate emails

Kaspersky has identified an ongoing phishing campaign that impersonates official emails from Zoom and Docusign, targeting corporate accounts across various regions, including the Middle East, Latin America, and Western Europe. This revelation highlights the persistence of traditional phishing tactics, even…

June Oven’s app and cloud services shut down, leaving users with unsupported devices

June Oven's app and cloud services have been shut down, leaving users with unsupported devices, according to a report by The Verge. The June Oven, a smart cooking appliance developed by a team of former Apple engineers, was known for…

Microsoft enhances Copilot with code generation tool, Autopilot AI agent, and Office integration

Microsoft has announced significant enhancements to its Copilot application, introducing a new coding tool and an always-on AI agent, as reported by Emirates247. These updates aim to transform Copilot into a comprehensive solution for office workers, integrating essential Office applications…