Ransomware Ecosystem Widens in Q2 2026, AI Accelerates Tooling
Check Point Research's latest report indicates a significant increase in active ransomware groups, while the 'The Gentlemen' operation demonstrates AI's role in rapid development of malicious tools.

The ransomware landscape in the second quarter of 2026 saw a notable expansion, with the number of active ransomware groups climbing to 93, a new high according to Check Point Research's "State of Ransomware Q2 2026" report. Despite this widening ecosystem, the top 10 groups still accounted for a substantial 57.6% of all victims, though this represents a decrease from the previous quarter's 71%. Victim volume remained elevated, with data leak sites recording 2,139 victims, a slight increase of 0.8% from Q1 and a 33% rise year-over-year.
Qilin and The Gentlemen emerged as the most prolific ransomware operations, vying for the top spot. Qilin maintained its lead for the fourth consecutive quarter with 279 victims, albeit with a 17% decrease in its victim count. The Gentlemen, however, experienced a significant surge of 62%, reaching 269 victims and even surpassing Qilin in June. This group's rapid ascent was partly attributed to its innovative use of technology.
An internal leak from The Gentlemen operation provided unprecedented insight into its inner workings, revealing a core team of approximately nine operators supported by a larger affiliate base. Crucially, the leak confirmed the group's use of AI coding assistants to develop its ransomware management panel in a remarkably short period of about three days. This marks a significant milestone, offering direct evidence of AI's accelerating impact on the development of sophisticated malicious tooling.
Ransom payment rates continued their downward trend, falling to a multi-year low of around 23%, a stark contrast to the 85% observed in 2019. Despite this decline, on-chain ransomware payments still exceeded $820 million in 2025. The payment landscape is also bifurcating: while the median payment has decreased, the average payment has risen, suggesting that large enterprises continue to pay substantial ransoms, while the mid-market is increasingly resistant or pays smaller amounts.
Law enforcement agencies focused their efforts in Q2 on disrupting shared infrastructure rather than targeting individual groups. Actions included the takedown of a cryptocurrency laundering platform used by multiple ransomware actors, sanctions against major Iranian digital asset exchanges, the dismantling of a malware signing service, and disruptions to infostealer and VPN anonymization networks essential for many ransomware operations.
The geographic distribution of ransomware victims saw a notable shift, with the U.S. share of victims decreasing from 50% to 42% quarter-over-quarter. This change is largely due to the fastest-growing groups, including The Gentlemen and the newly active Krybit, shifting their focus away from the U.S. market.
The report also highlights the ever-narrowing exploitation window for vulnerabilities. AI is increasingly cited as the primary accelerant, with exploits for disclosed vulnerabilities now appearing within hours or days. This rapid weaponization lowers the cost of exploit development for threat actors and intensifies the race to compromise victims before patches can be applied.
The findings underscore a dynamic and evolving ransomware threat landscape. While established groups continue to dominate, the barrier to entry for new operations appears to be lowering, partly due to advancements in AI-assisted development. The report emphasizes the ongoing cat-and-mouse game between defenders and attackers, with law enforcement actions and technological advancements playing critical roles in shaping the threat environment.