Ransomware Landscape Shifts in Q2 2026 with Increased Group Activity

Ransomware Landscape Shifts in Q2 2026 with Increased Group Activity

First seen 14 Aug 2026, 00:36 UTC Research.CheckpointBlog.Checkpointcoveware.com 82% similarity 51.9

Article Content

Browse articles
ThreatCluster

In Q2 2026, ransomware attacks remained prevalent, with 2,139 victims reported, marking a 33% increase year-over-year. The distribution of attacks shifted as the top 10 ransomware groups controlled 57.6% of victims, down from 71% in Q1, with active groups rising to 93. The Gentlemen emerged as the leading group with 279 victims, while Cl0p's influence diminished. Notably, the core team of The Gentlemen consisted of just nine individuals, utilizing AI tools to expedite ransomware development. Payment rates for ransom have dropped to approximately 23%, attributed to improved backup solutions, although total payments exceeded $820 million in 2025. Law enforcement focused on dismantling shared infrastructure rather than targeting individual groups, indicating a strategic shift in combating ransomware.

Key Points: • Ransomware victims totaled 2,139 in Q2 2026, a 33% increase from the previous year. • The number of active ransomware groups rose to 93, with The Gentlemen leading at 279 victims. • Ransom payment rates have fallen to 23%, but total payments exceeded $820 million in 2025.

ThreatCluster AI How this analysis works

Timeline

2026-06-30
Q2 2026 ransomware victim count reported
Data leak sites logged 2,139 victims, flat from Q1 but up 33% year-over-year.
Blog.Checkpoint
2026-06-30
Active ransomware groups reach record high
The number of active ransomware groups increased to 93, the highest recorded.
Blog.Checkpoint
2026-06-30
The Gentlemen becomes leading ransomware group
The Gentlemen recorded 279 victims, surpassing its competitors in June 2026.
Blog.Checkpoint
2026-08-13
Ransomware payment rates decline
Ransom payment rates fell to approximately 23%, a significant decrease from previous years.
Blog.Checkpoint

Community

Browse all →