GuidePoint Security’s Q2 2026 Ransomware and Cyber Threat Insights Report reveals the ransomware ecosystem reached record activity levels in the second quarter, with threat actors claiming 2,279 victims — a 7% increase over Q1 2026 and a 43% year-over-year surge compared to Q2 2025. A record 91 ransomware groups were active across 108 countries, with the top five groups collectively accounting for over 40% of all attacks. ZeroFox’s independent Q2 Ransomware Wrap-Up corroborated the trend, recording at least 1,885 ransomware and digital extortion incidents, with June 2026 alone showing a 50.7% year-over-year spike — the steepest monthly growth rate of the quarter.
Qilin ransomware maintained its position as the most active group for the fourth consecutive quarter, accounting for 13% of all attacks and claiming over 500 victims in 2026 alone. GuidePoint identified a “four-headed monster” of dominant high-volume groups: Qilin, The Gentlemen (a rapidly emerging new entrant), Akira, and DragonForce. AI is increasingly being used by operators — not to automate attacks end-to-end, but to analyze exfiltrated data, personalize ransom negotiations, and apply psychological pressure on victims. Manufacturing remains the most targeted sector, accounting for nearly 15% of victims globally.
Source: CybersecurityDive | ZeroFox Q2 Wrap-Up | Industrial Cyber
Commentary: The 43% year-over-year jump reflects a structural shift, not just a bad quarter. The disruption of LockBit and RansomHub didn’t shrink the ransomware market — it fragmented it, creating space for smaller and more aggressive groups like The Gentlemen to gain footholds. With 91 active groups, defenders are no longer dealing with a handful of dominant threat actors they know well; the ecosystem has diversified to the point where IOC-based defenses are increasingly inadequate.
The AI angle deserves close attention. Ransomware operators using AI to personalize negotiations and maximize psychological pressure is a qualitative change in how these attacks unfold — it makes every victim’s situation feel uniquely targeted rather than cookie-cutter, which historically increases ransom payment rates. The industry needs to move from post-breach response to assumed-compromise postures with detection and containment capabilities that can actually match the pace of AI-assisted operations.
