Ransomware Surges in 2026: Record Victims, Shifting Tactics, and a Dominant Threat Actor
Ransomware activity reached unprecedented levels in 2026, with 7,551 publicly disclosed victims a 24.9% year-over-year increase marking the fourth consecutive annual high, according to Black Kite’s latest report. Between April 2025 and March 2026, monthly victim counts rose from 504 to 629, with a sharp 60% surge in the second half of the year, peaking at 861 victims in March 2026 alone.
The threat landscape expanded alongside victim numbers, with 146 active ransomware groups by mid-2026 up from 127 including 61 new entrants. Despite this fragmentation, the top five groups controlled 43.6% of all victims, reflecting consolidation at the top. Qilin emerged as the standout threat, responsible for 1,358 victims (a 443% increase) and accounting for one in five to six disclosed cases across 50+ countries.
Key trends in 2026 included:
- Industry targeting: Manufacturing (1,660 victims, 22% of cases) remained the hardest-hit sector for the fourth year, followed by Professional, Scientific, and Technical Services (1,389 victims) and Construction (541 victims).
- Geographic shifts: The U.S. accounted for 49.3% of victims (down from 51.9%), while Europe saw rapid growth, with Germany (+48%), Italy (+96%), Spain, and France driving a 55.1% regional increase.
- Revenue-based targeting: Mid-sized organizations ($50–100M revenue) saw the largest jump in victimization (29.3% of cases, up from 25.1%), while small businesses ($1–5M revenue) nearly doubled their share.
- Attack vectors: Trusted vendor platforms became prime targets, with OAuth token abuse, SaaS trust chain exploits, and zero-day vulnerabilities (e.g., Oracle E-Business Suite, PeopleSoft) enabling mass downstream compromises.
Post-incident analysis revealed persistent security gaps: 43.5% of victims had at least one critical (CVSS 9.0+) vulnerability, 30.8% had a Known Exploited Vulnerability (KEV), and 58.9% had misconfigured DMARC policies. Stealer log exposure surged 175%, and Ransomware Susceptibility Index (RSI) scores rose to 0.616, with organizations scoring above 0.8 being 291 times more likely to be hit.
The report underscores a structural shift in ransomware operations, where attacker visibility often outpaces defensive awareness, and AI-driven tooling lowers operational costs, enabling both new and established groups to scale rapidly. While some groups (e.g., RansomHub) saw rapid declines, aggregate ransomware volume remained stable or rising, signaling a market-driven threat landscape rather than dominance by a single actor.
Source: https://gbhackers.com/2026-ransomware-report/
Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle
"id": "ORA1784644706",
"linkid": "oracle",
"type": "Ransomware",
"date": "4/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '7,551 publicly disclosed '
'victims',
'industry': ['Manufacturing',
'Professional, Scientific, and Technical '
'Services',
'Construction'],
'location': ['United States',
'Germany',
'Italy',
'Spain',
'France'],
'size': ['Mid-sized ($50–100M revenue)',
'Small ($1–5M revenue)'],
'type': 'Organization'}],
'attack_vector': ['OAuth token abuse',
'SaaS trust chain exploits',
'Zero-day vulnerabilities'],
'data_breach': {'data_encryption': True, 'data_exfiltration': True},
'date_publicly_disclosed': '2026-03-01',
'description': 'Ransomware activity reached unprecedented levels in 2026, '
'with 7,551 publicly disclosed victims, a 24.9% year-over-year '
'increase. The threat landscape expanded with 146 active '
'ransomware groups, with Qilin emerging as the dominant threat '
'actor. Key trends included industry targeting (manufacturing '
'hardest hit), geographic shifts (U.S. and Europe), '
'revenue-based targeting, and exploitation of trusted vendor '
'platforms and zero-day vulnerabilities.',
'impact': {'data_compromised': True},
'lessons_learned': 'Persistent security gaps include critical '
'vulnerabilities, misconfigured DMARC policies, and '
'stealer log exposure. Organizations with high Ransomware '
'Susceptibility Index (RSI) scores are significantly more '
'likely to be targeted.',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': ['Critical vulnerabilities (CVSS '
'9.0+)',
'Known Exploited Vulnerabilities '
'(KEV)',
'Misconfigured DMARC policies',
'Stealer log exposure']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransomware_strain': ['Qilin', 'RansomHub']},
'references': [{'source': 'Black Kite’s latest report'}],
'threat_actor': ['Qilin', 'RansomHub'],
'title': 'Ransomware Surges in 2026: Record Victims, Shifting Tactics, and a '
'Dominant Threat Actor',
'type': 'Ransomware',
'vulnerability_exploited': ['Oracle E-Business Suite',
'PeopleSoft',
'CVSS 9.0+ vulnerabilities',
'Known Exploited Vulnerabilities (KEV)']}