Ransomware Landscape Expands as New Groups Emerge at Record Pace
The ransomware ecosystem is growing at an unprecedented rate, with 146 active groups publicly claiming at least one victim as of June 2026 up from 105 just a year earlier. According to the Black Kite Ransomware Report 2026, released on July 21, 61 new ransomware operations have emerged in 2026 alone, averaging more than one per week.
The lifespan of these groups remains short, with the average active period now 4.9 months, down from over a year in 2024. Despite this volatility, a small number of operations dominate the threat landscape. The top five groups Qilin (1,358 victims), Akira (749), INC Ransom (436), Play (422), and SafePay (324) accounted for 44% of 7,551 publicly disclosed attacks between March 2025 and March 2026.
The report highlights the rapidly shifting dynamics of ransomware threats. For example, The Gentlemen, the most prolific group in July 2026, ranked only seventh in the earlier period with 286 victims. Meanwhile, 19 major operations were responsible for the bulk of attacks, with Qilin leading at over 1,000 victims and Rhysida at the lower end with 80.
A key finding reveals that 44% of ransomware attacks exploited critical vulnerabilities (CVSS 9+) for initial access, underscoring the importance of timely patching. While tactics vary among groups, common weaknesses such as unpatched systems, weak identity controls, and vendor risks remain prevalent entry points.
Source: https://www.infosecurity-magazine.com/news/new-ransomware-weekly/
SafePay Systems cybersecurity rating report: https://www.rankiteo.com/company/safepaysys
"id": "SAF1784644589",
"linkid": "safepaysys",
"type": "Ransomware",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '7551'}],
'attack_vector': ['Exploitation of critical vulnerabilities (CVSS 9+)',
'Unpatched systems',
'Weak identity controls',
'Vendor risks'],
'date_publicly_disclosed': '2026-07-21',
'description': 'The ransomware ecosystem is growing at an unprecedented rate, '
'with 146 active groups publicly claiming at least one victim '
'as of June 2026. The Black Kite Ransomware Report 2026 '
'highlights the emergence of 61 new ransomware operations in '
'2026 alone, with the top five groups accounting for 44% of '
'7,551 publicly disclosed attacks between March 2025 and March '
'2026. Key findings include the short lifespan of groups (4.9 '
'months on average) and the exploitation of critical '
'vulnerabilities (CVSS 9+) in 44% of attacks.',
'lessons_learned': 'Timely patching and addressing common weaknesses such as '
'unpatched systems, weak identity controls, and vendor '
'risks are critical to mitigating ransomware attacks.',
'post_incident_analysis': {'root_causes': ['Exploitation of critical '
'vulnerabilities (CVSS 9+)',
'Unpatched systems',
'Weak identity controls',
'Vendor risks']},
'ransomware': {'ransomware_strain': ['Qilin',
'Akira',
'INC Ransom',
'Play',
'SafePay',
'The Gentlemen',
'Rhysida']},
'recommendations': 'Organizations should prioritize patching critical '
'vulnerabilities, strengthen identity controls, and manage '
'vendor risks to reduce the likelihood of ransomware '
'attacks.',
'references': [{'date_accessed': '2026-07-21',
'source': 'Black Kite Ransomware Report 2026'}],
'threat_actor': ['Qilin',
'Akira',
'INC Ransom',
'Play',
'SafePay',
'The Gentlemen',
'Rhysida'],
'title': 'Ransomware Landscape Expansion 2026',
'type': 'Ransomware',
'vulnerability_exploited': ['Critical vulnerabilities (CVSS 9+)']}