U.S. Hit by Nearly Half of Global Ransomware Attacks in Early 2026
The first half of 2026 saw the U.S. targeted by an unprecedented surge in ransomware attacks, accounting for 45% of the global total, according to research from Cyble Research and Intelligence Labs (CRIL). Between January and June, 1,721 ransomware incidents struck U.S. organizations more than the next nine most-targeted countries combined. Canada (179 attacks), Germany (155), and the U.K. (138) trailed far behind, with North America as a whole recording 1,981 attacks, over half of the 3,836 tracked worldwide.
Two ransomware-as-a-service (RaaS) groups drove the majority of the damage: Qilin, responsible for 370 attacks (19% of the regional total), and Akira, with 268. Together, they accounted for over half of North America’s ransomware activity, signaling a highly organized affiliate network rather than scattered opportunistic attacks.
Key Sectors Under Fire
Professional services particularly law firms bore the brunt of attacks, with INC Ransom showing a strong preference for high-value targets. Construction, manufacturing, and healthcare also faced significant pressure. AiLock stood out for a coordinated wave of disclosures on March 3, suggesting a mass-exploitation campaign. Meanwhile, LockBit maintained steady activity against public-sector and educational institutions, despite ongoing law enforcement efforts to dismantle the group.
Data breaches disproportionately impacted technology and financial services, which together made up 43% of incidents, reflecting the high value of their intellectual property and customer data. Notably, agriculture and livestock emerged as a growing target for initial access brokers, representing a third of all access listings in North America a shift that highlights rising risks to the food supply chain.
Initial Access Markets & Exploited Vulnerabilities
The initial access market was dominated by just two sellers, "redpin" and "xpl0itrs", who accounted for nearly all listings targeting North American organizations. Threat actors continued to exploit known and zero-day vulnerabilities in widely used enterprise platforms, including products from Ivanti and Palo Alto Networks.
Hacktivism’s Overlap with Cybercrime
Hacktivist collectives, including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID, contributed to 56 data leaks, affecting roughly 360 domains across government, technology, financial services, and telecommunications. However, Cyble’s findings suggest many of these groups operate as hybrid entities, blending ideological motives with profit-driven activities like stolen data brokerage and DDoS-for-hire services.
While the U.S. concentration of attacks reflects its large, digitally dense economy rather than inherently weaker defenses the scale underscores the need for heightened vigilance, particularly in patching high-risk vulnerabilities and monitoring initial access markets as early warning indicators.
Source: https://thecyberexpress.com/us-ransomware-attacks-in-h1-2026/
Ivanti cybersecurity rating report: https://www.rankiteo.com/company/ivanti
"id": "IVA1784875005",
"linkid": "ivanti",
"type": "Vulnerability",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['professional services',
'construction',
'manufacturing',
'healthcare',
'technology',
'financial services',
'public sector',
'education',
'agriculture',
'telecommunications'],
'location': 'United States',
'type': ['law firms',
'construction',
'manufacturing',
'healthcare',
'technology',
'financial services',
'government',
'education',
'agriculture',
'livestock',
'telecommunications']},
{'industry': ['government',
'technology',
'financial services',
'telecommunications'],
'location': 'North America',
'type': ['government',
'technology',
'financial services',
'telecommunications']}],
'attack_vector': ['exploited vulnerabilities', 'initial access brokers'],
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'high',
'type_of_data_compromised': ['intellectual property',
'customer data',
'personally identifiable '
'information']},
'date_detected': '2026-01-01',
'date_publicly_disclosed': '2026-06-30',
'description': 'The first half of 2026 saw the U.S. targeted by an '
'unprecedented surge in ransomware attacks, accounting for 45% '
'of the global total. Between January and June, 1,721 '
'ransomware incidents struck U.S. organizations, more than the '
'next nine most-targeted countries combined. Key sectors under '
'fire included professional services, construction, '
'manufacturing, healthcare, technology, and financial '
'services. Ransomware-as-a-service (RaaS) groups Qilin and '
'Akira drove the majority of the damage, with initial access '
'brokers exploiting vulnerabilities in enterprise platforms '
'like Ivanti and Palo Alto Networks.',
'impact': {'data_compromised': True, 'identity_theft_risk': True},
'initial_access_broker': {'data_sold_on_dark_web': True,
'entry_point': ['exploited vulnerabilities in '
'Ivanti and Palo Alto Networks '
'products'],
'high_value_targets': ['law firms',
'technology',
'financial services',
'agriculture']},
'lessons_learned': 'The scale of attacks underscores the need for heightened '
'vigilance, particularly in patching high-risk '
'vulnerabilities and monitoring initial access markets as '
'early warning indicators.',
'motivation': ['financial gain',
'ideological',
'data brokerage',
'DDoS-for-hire'],
'post_incident_analysis': {'root_causes': ['exploited known and zero-day '
'vulnerabilities',
'initial access broker activity',
'RaaS affiliate networks']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransomware_strain': ['Qilin',
'Akira',
'INC Ransom',
'AiLock',
'LockBit']},
'recommendations': ['patch high-risk vulnerabilities',
'monitor initial access markets',
'enhance sector-specific defenses'],
'references': [{'date_accessed': '2026-06-30',
'source': 'Cyble Research and Intelligence Labs (CRIL)'}],
'threat_actor': ['Qilin',
'Akira',
'INC Ransom',
'AiLock',
'LockBit',
'SOLDADOS DIGITALES – UNIÓN AMERICANA',
'LYSTIC TEAM #ID',
'redpin',
'xpl0itrs'],
'title': 'U.S. Hit by Nearly Half of Global Ransomware Attacks in Early 2026',
'type': 'ransomware',
'vulnerability_exploited': ['known vulnerabilities',
'zero-day vulnerabilities',
'Ivanti products',
'Palo Alto Networks products']}