Ransomware Market Fragmented in 2026, New Groups Emerge Weekly
A new report indicates a significant shift in the ransomware landscape, with 61 new groups emerging between April 2025 and March 2026, averaging over one new group per week.

The ransomware landscape in 2026 has moved away from the dominance of a single threat actor or a major supply chain incident, instead becoming highly fragmented. Black Kite's 2026 Ransomware Report reveals that between April 2025 and March 2026, an average of more than one new ransomware group entered the market each week, with 61 new entities identified during this period. By June 2026, the total number of active threat groups had climbed to 146, indicating a substantial increase in the overall threat surface.
While the market is more crowded, the concentration of victims among the top players has slightly decreased. The five largest groups accounted for 43.6% of all observed victims, suggesting a broader distribution of attacks. "Previous years were often defined by a dominant ransomware group or a single major event. This year was different. We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half. Those shifts fundamentally changed the shape of the ransomware landscape," stated Ferhat Dikbiyik, Chief Research & Intelligence Officer at Black Kite.
The reporting period documented a total of 7,551 ransomware victims. Activity remained relatively stable in the first half of the year, mirroring previous years' monthly baselines. However, the latter half of the period, from October 2025 through March 2026, witnessed a significant surge in ransomware disclosures, increasing by 60% compared to the first half. This acceleration saw Qilin emerge as the largest volume operator, with new groups contributing to victim numbers without necessarily displacing established players.
Geographically, the United States continues to be the most targeted country, accounting for 49.3% of all observed victims. However, Europe has seen a notable increase in ransomware activity, with its four most affected countries collectively recording over 250 additional victims. Several European nations have strengthened their positions within the global top 10 targeted countries, highlighting a growing risk for organizations operating in the region. Additionally, parts of Asia experienced some of the largest percentage increases in victim counts.
Manufacturing remains the most heavily targeted industry sector, followed closely by professional, scientific, and technical services. Other significantly affected sectors include construction, healthcare, wholesale trade, finance and insurance, information, and retail trade. The timing of attacks also shows a pattern, with 84.1% of victim postings occurring on weekdays, and Wednesday being the most active day for ransomware disclosures.
Organizations with annual revenues between $50 million and $100 million represented the largest share of victims. While the proportion of victims with revenues exceeding $100 million declined compared to the previous reporting period, targeting strategies varied. Some groups focused on high-volume campaigns against more accessible organizations, while others continued to target higher-value enterprises.
Common warning signs and attack vectors identified across the victim base include security misconfigurations, exposed internet-facing remote access services, software vulnerabilities, compromised credentials, and botnet activity. Third-party services, such as SaaS platforms, ERP systems, and CRM applications, are increasingly becoming critical attack paths, exposing even organizations with strong internal controls to risk. Encryption remains the primary extortion method, often combined with data theft to increase pressure on victims.
Artificial intelligence is playing an increasingly significant role, accelerating reconnaissance, phishing, social engineering, and extortion messaging. AI tools are lowering the barrier to entry for less experienced attackers. Furthermore, advanced techniques like voice phishing, voice cloning, and deepfake audio are being employed to impersonate employees, manipulate help desk systems, and exploit identity-based workflows, making attacks more sophisticated and harder to detect.