Ransomware Activity Surges Amidst Ecosystem Fragmentation and New Entrants
Ransomware attacks have accelerated significantly between October 2025 and March 2026, driven by a fragmented criminal ecosystem and the emergence of new threat actors rather than AI advancements.

Ransomware activity has seen a marked acceleration, with a substantial surge in incidents reported between October 2025 and March 2026. This period witnessed the entry of over 60 new threat groups into an increasingly crowded and competitive criminal landscape. For enterprises, this escalating trend translates not only to a higher volume of attacks but also to a more dynamic and challenging threat environment, requiring constant vigilance against a growing and evolving roster of adversaries.
Analysis of ransomware incidents from April 1, 2025, to March 31, 2026, revealed a 25% increase in known victims worldwide, totaling 7,551 organizations. The latter half of this period, from October 2025 to March 2026, was particularly active, accounting for 4,647 victims—a 60% increase compared to the preceding six months. March 2026 stood out as the busiest month, with an average of nearly 28 organizations falling victim each day.
Experts attribute this surge to several key factors, including the fragmentation of the ransomware ecosystem, the proliferation of new ransomware groups, and a strategic expansion of attacks targeting smaller, less defended organizations. Furthermore, third-party and supply chain compromises have become significant vectors, allowing attackers to leverage a single breach to impact multiple victims. Incidents involving compromised managed service providers (MSPs) have demonstrated the potential for widespread damage, with one MSP compromise reportedly affecting dozens of institutions.
A consistent pattern observed in the data is that a significant majority of victimized organizations exhibited high ransomware susceptibility index (RSI) scores, indicating a predisposition to attacks based on externally visible weaknesses. More than 90% of victims showed a notable increase in their RSI score shortly before being compromised. These weaknesses often include misconfigurations, exposed remote access points, credential stuffing, and the presence of stealer logs, making them easy targets.
While large corporations continue to be prime targets, the engine of volume growth has shifted towards mid-sized organizations, particularly those in the $50 million to $100 million revenue bracket, and even smaller entities in the $1 million to $5 million range. Manufacturing companies remained the most targeted sector, followed closely by professional, scientific, and technical services. Although US-based organizations constituted nearly half of all victims, ransomware attacks in Europe saw a more pronounced growth rate.
Contrary to some speculation, the acceleration in ransomware incidents is not primarily driven by advancements in Artificial Intelligence. While AI tools, such as open-source LLMs and code agents, have lowered the barrier to entry for less technically skilled actors and may be appearing in encryptors, the overall growth is attributed to human-driven factors. AI has enabled more individuals to participate in ransomware operations, but the core expansion is fueled by evolving attacker tactics and a more accessible criminal infrastructure.
Troublingly, many organizations that fall victim to ransomware attacks appear to do little to address the underlying vulnerabilities that made them targets in the first place. This reactive approach, often driven by a desire to quickly close the incident, leaves them exposed to repeat attacks. Security experts emphasize the need for continuous monitoring and structured exposure reviews post-incident to effectively mitigate future risks.
The evolving ransomware landscape demands a proactive and adaptive defense strategy. Organizations must prioritize addressing externally visible weaknesses, continuously monitor their attack surface, and implement robust incident response plans that include post-incident remediation. The increasing democratization of ransomware tools, coupled with the sheer volume of new actors, necessitates a heightened state of readiness across all sectors.