Oracle: 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge

Oracle: 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge

Ransomware Surges in 2026: Record Victims, Shifting Tactics, and a Dominant Threat Actor

Ransomware activity reached unprecedented levels in 2026, with 7,551 publicly disclosed victims a 24.9% year-over-year increase marking the fourth consecutive annual high, according to Black Kite’s latest report. Between April 2025 and March 2026, monthly victim counts rose from 504 to 629, with a sharp 60% surge in the second half of the year, peaking at 861 victims in March 2026 alone.

The threat landscape expanded alongside victim numbers, with 146 active ransomware groups by mid-2026 up from 127 including 61 new entrants. Despite this fragmentation, the top five groups controlled 43.6% of all victims, reflecting consolidation at the top. Qilin emerged as the standout threat, responsible for 1,358 victims (a 443% increase) and accounting for one in five to six disclosed cases across 50+ countries.

Key trends in 2026 included:

  • Industry targeting: Manufacturing (1,660 victims, 22% of cases) remained the hardest-hit sector for the fourth year, followed by Professional, Scientific, and Technical Services (1,389 victims) and Construction (541 victims).
  • Geographic shifts: The U.S. accounted for 49.3% of victims (down from 51.9%), while Europe saw rapid growth, with Germany (+48%), Italy (+96%), Spain, and France driving a 55.1% regional increase.
  • Revenue-based targeting: Mid-sized organizations ($50–100M revenue) saw the largest jump in victimization (29.3% of cases, up from 25.1%), while small businesses ($1–5M revenue) nearly doubled their share.
  • Attack vectors: Trusted vendor platforms became prime targets, with OAuth token abuse, SaaS trust chain exploits, and zero-day vulnerabilities (e.g., Oracle E-Business Suite, PeopleSoft) enabling mass downstream compromises.

Post-incident analysis revealed persistent security gaps: 43.5% of victims had at least one critical (CVSS 9.0+) vulnerability, 30.8% had a Known Exploited Vulnerability (KEV), and 58.9% had misconfigured DMARC policies. Stealer log exposure surged 175%, and Ransomware Susceptibility Index (RSI) scores rose to 0.616, with organizations scoring above 0.8 being 291 times more likely to be hit.

The report underscores a structural shift in ransomware operations, where attacker visibility often outpaces defensive awareness, and AI-driven tooling lowers operational costs, enabling both new and established groups to scale rapidly. While some groups (e.g., RansomHub) saw rapid declines, aggregate ransomware volume remained stable or rising, signaling a market-driven threat landscape rather than dominance by a single actor.

Source: https://gbhackers.com/2026-ransomware-report/

Oracle cybersecurity rating report: https://www.rankiteo.com/company/oracle

"id": "ORA1784644706",
"linkid": "oracle",
"type": "Ransomware",
"date": "4/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '7,551 publicly disclosed '
                                              'victims',
                        'industry': ['Manufacturing',
                                     'Professional, Scientific, and Technical '
                                     'Services',
                                     'Construction'],
                        'location': ['United States',
                                     'Germany',
                                     'Italy',
                                     'Spain',
                                     'France'],
                        'size': ['Mid-sized ($50–100M revenue)',
                                 'Small ($1–5M revenue)'],
                        'type': 'Organization'}],
 'attack_vector': ['OAuth token abuse',
                   'SaaS trust chain exploits',
                   'Zero-day vulnerabilities'],
 'data_breach': {'data_encryption': True, 'data_exfiltration': True},
 'date_publicly_disclosed': '2026-03-01',
 'description': 'Ransomware activity reached unprecedented levels in 2026, '
                'with 7,551 publicly disclosed victims, a 24.9% year-over-year '
                'increase. The threat landscape expanded with 146 active '
                'ransomware groups, with Qilin emerging as the dominant threat '
                'actor. Key trends included industry targeting (manufacturing '
                'hardest hit), geographic shifts (U.S. and Europe), '
                'revenue-based targeting, and exploitation of trusted vendor '
                'platforms and zero-day vulnerabilities.',
 'impact': {'data_compromised': True},
 'lessons_learned': 'Persistent security gaps include critical '
                    'vulnerabilities, misconfigured DMARC policies, and '
                    'stealer log exposure. Organizations with high Ransomware '
                    'Susceptibility Index (RSI) scores are significantly more '
                    'likely to be targeted.',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'root_causes': ['Critical vulnerabilities (CVSS '
                                            '9.0+)',
                                            'Known Exploited Vulnerabilities '
                                            '(KEV)',
                                            'Misconfigured DMARC policies',
                                            'Stealer log exposure']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': ['Qilin', 'RansomHub']},
 'references': [{'source': 'Black Kite’s latest report'}],
 'threat_actor': ['Qilin', 'RansomHub'],
 'title': 'Ransomware Surges in 2026: Record Victims, Shifting Tactics, and a '
          'Dominant Threat Actor',
 'type': 'Ransomware',
 'vulnerability_exploited': ['Oracle E-Business Suite',
                             'PeopleSoft',
                             'CVSS 9.0+ vulnerabilities',
                             'Known Exploited Vulnerabilities (KEV)']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.