Executive Summary
Qilin, TheGentlemen, DragonForce, Akira, and LockBit now collectively account for the majority of documented ransomware victim postings globally, and the ecosystem producing them is expanding faster than law enforcement can contain it. Chainalysis tracked approximately $820 million in on-chain ransomware payments in 2025, down 8% in aggregate dollars, even as claimed victim counts rose 50% to a record 7,874, per NCC Group's Annual Cyber Threat Intelligence report. That divergence, payments falling while victims surge, signals that more organizations are refusing to pay while attackers compensate by hitting more targets, not fewer. The business and operational risk is rising even as the ransom-payment headline number deceives.
- CISOs and security operations: As of Q2 2026, Coveware by Veeam data shows the average ransom payment surged 176% quarter-over-quarter to $1.88 million, driven by exfiltration-focused actors. Validate your exfiltration detection coverage, not just your encryption defenses.
- Risk officers and underwriters: Total economic damage per ransomware breach averaged $5.08 million in IBM's Cost of a Data Breach 2025 report, excluding the ransom itself. Model your cyber insurance exposure on that figure, not on median payment data.
- Manufacturing, healthcare, and professional services executives: These three sectors absorbed the highest incident volumes through H1 2026 according to CYFIRMA and Check Point Research. Sector-specific threat intelligence, not generic frameworks, should drive your quarterly risk reviews.
The ransomware threat in mid-2026 is characterized by a widening gap between payment refusal and attack volume growth, making breach-cost management more important than ransom negotiation posture.
Key Findings
- Qilin has consolidated top-tier status and is actively pulling affiliate talent from disrupted RaaS platforms, making it the single greatest ransomware risk for enterprise defenders in 2026.
- TheGentlemen ransomware group is scaling at a rate that no comparable new entrant has matched since RansomHub's 2024 peak, and its affiliate economics are likely to accelerate that growth through Q4 2026.
- Professional services, manufacturing, and healthcare will absorb the highest ransomware attack volumes through the end of 2026, with manufacturing's surge continuing to accelerate.
- Ransom payment refusal is rising, but the economic logic of continuing attacks remains intact, meaning volume will keep growing regardless of improved victim posture.
- LockBit's apparent post-Cronos recovery, with 163 posted victims in Q1 2026 under version 5.0, demonstrates that law enforcement takedowns fragment operations temporarily rather than eliminate underlying capability.
The Payment Paradox: More Victims, Less Total Revenue
The most analytically significant development in the ransomware landscape through H1 2026 is not which group leads the victim count; it is what the aggregate payment data reveals about the ecosystem's structural economics. Chainalysis tracked approximately $820 million in on-chain ransomware payments across 2025, per its 2026 Crypto Crime Report, an 8% decline from the revised 2024 figure of $892 million. At the same time, NCC Group's Annual Cyber Threat Intelligence report counted 7,874 leak-site victim postings in 2025, a 50% increase over the prior year. Those two numbers, moving in opposite directions, require a structural explanation.
Coveware by Veeam's Q2 2026 quarterly report provides one piece: average ransom payments surged 176% from Q1 to $1.88 million in Q2 2026, driven by a small number of very large exfiltration-focused payments. The median, however, fell 50% to $150,000 over the same period. This divergence signals a bifurcated market: a handful of high-value targets are paying enormous ransoms while the majority refuse or negotiate sharply downward. Silent Ransom Group's campaign against law firms, documented by Coveware, drove much of the Q2 average spike by threatening to expose sensitive legal records exfiltrated through social engineering rather than technical exploits.
This translates directly into financial exposure that is systematically underestimated by organizations focused on ransom payment risk alone. IBM's Cost of a Data Breach 2025 report found the average ransomware breach costs $5.08 million, a figure that excludes the ransom entirely, measuring only detection, notification, post-breach response, and lost business costs. For organizations in manufacturing, healthcare, and professional services, that operational loss figure compounds against sector-specific downtime costs, where healthcare averages 24 days of disruption per incident per Axis Intelligence.
Sector Targeting: Who Bears The Concentrated Risk
CYFIRMA's May 2026 monthly ransomware report provides the clearest single-month cross-sector picture available. Professional Goods and Services led with 150 incidents, followed by Manufacturing at 93, Information Technology at 82, Healthcare at 76, and Real Estate and Construction at 72. Finance recorded 86 victims over a 90-day window in CYFIRMA's separate financial sector analysis, though this represented a 17% decline from the prior period, even as a concentrated South Korean campaign by Qilin attributed 20 of those 31 Qilin victims to Korean asset management firms in a single event.
The geographic concentration amplifies sector risk. CYFIRMA's May 2026 data showed the United States absorbing 336 incidents, roughly accounting for a substantial plurality of all recorded victims. Canada recorded 40, the United Kingdom 39, and Germany 29. That US concentration means organizations operating in American jurisdictions carry a disproportionate share of the global risk regardless of sector.
Two operational patterns drive this sector distribution. First, attackers prioritize organizations where operational downtime creates acute pressure to pay quickly, manufacturing production lines and hospital systems being the clearest examples, because time pressure is what makes the threat credible at scale. Second, professional services firms hold densely valuable third-party data on their clients, which creates a secondary extortion vector: threatening to release client data creates pressure not just on the firm but on its clients, as the Halcyon-tracked INC Ransom campaign against law firms demonstrated from late 2025 through Q1 2026. This supply-chain extortion logic connects the professional services targeting directly to downstream financial and reputational risk for the firms' corporate clients.
How Groups Operate And Why Disruption Has Not Worked
The five leading groups share a structural template that makes them resilient to individual takedowns: a Ransomware-as-a-Service (RaaS) model in which the core developers maintain infrastructure and tooling while independent affiliates execute attacks and split revenue. MITRE ATT&CK technique T1486 (Data Encrypted for Impact) combined with T1041 (Exfiltration Over C2 Channel) defines the double-extortion baseline that Kaspersky identifies as now across campaigns. The shift matters because encryption-only ransomware can be defeated by backups; exfiltration-plus-encryption cannot.
TheGentlemen, profiled by Cybereason and tracked by KPMG from a November 2025 advisory, uses a highly configurable platform targeting Windows, Linux, and ESXi environments. The group first active in July 2025 claimed over 30 attacks across 17 countries within its first few months per KPMG, and by Q1 2026 its incident count had grown tenfold. Its 85% affiliate revenue split is the most competitive in the current ecosystem, per Brandefense Q2 2026 analysis, and that economic differential explains its speed of affiliate acquisition better than any technical capability assessment.
Qilin's resilience rests on a different foundation. Securelist notes Qilin stands out as "one of the fastest-growing and dominant RaaS platforms" with a structured affiliate model that creates repeatable intrusion workflows. Its $50 million ransom demand against Synnovis, the NHS pathology provider, in June 2024 established its willingness to target critical public health infrastructure, a posture that generates both maximum leverage and maximum operational disruption simultaneously. DragonForce's influence extends beyond its own victim postings; Securelist assessed it as an ecosystem-level actor potentially linked to the disruption of competing groups, including reported involvement in the infrastructure of the former RansomHub.
AI-assisted tooling is moving from a distinguishing feature of a single group to an ecosystem-wide capability. Kaspersky's state-of-ransomware report documented FunkSec as the first group to deploy AI-generated ransomware code at scale, with "flawless comments likely produced by Large Language Models." The broader implication is that the barrier to producing functional ransomware is declining, and the Emsisoft January 2026 report counting between 126 and 141 active groups reflects exactly that dynamic.
Key Assumptions
The table below states the analytical premises this assessment rests on, alongside what evidence would invalidate each and what signal would confirm it first.
| Assumption | Supporting Evidence | Falsifying Evidence | Impact if Wrong | Monitoring Metric |
|---|---|---|---|---|
| Leak-site victim postings are a reasonable proxy for ransomware attack volume, even if they undercount true incidents | NCC Group, Chainalysis, and CYFIRMA all use this methodology as primary data; cross-source counts align directionally | If researchers found that a dominant group was systematically withholding victim postings (e.g., accepting large payments quietly), the 50% YoY growth figure would understate true activity even further | The volume growth finding is conservative; the true direction of travel remains the same, only the magnitude would shift | CISA Known Exploited Vulnerabilities (KEV) catalog update frequency, used as a proxy for active exploitation supporting ransomware delivery |
| Double-extortion will remain the dominant tactic through Q4 2026 | Kaspersky, Sophos, CYFIRMA, and Halcyon all document double-extortion as now; encryption-only attacks have declined as a share of observed incidents | A significant shift toward pure data theft without encryption (as observed with Silent Ransom / Luna Moth) becoming the majority approach would require revising defensive priorities away from backup recovery | Backup-centric defenses, currently the most common recommendation, would lose their primary value; exfiltration detection would become the critical control | Coveware quarterly report (next due Q3 2026) payment type breakdown |
| Law enforcement disruption cycles (90-180 days) do not permanently reduce the operational capacity of top-tier groups | LockBit's return with 163 Q1 2026 victims post-Cronos; RansomHub affiliate migration to DragonForce infrastructure per Securelist | A disruption campaign that removes core developers (not just affiliates), seizes cryptographic keys, and prevents rebrand would represent a qualitatively different outcome | The finding that volume will keep growing regardless of takedowns would require partial revision; targeted capability-reduction against developers would become the priority recommendation | US DOJ and Europol joint operation announcements targeting developer-tier actors specifically |
| The US will remain the primary geographic target through 2026 | CYFIRMA May 2026: 336 US victims in one month vs. 40 for Canada (next highest); Help Net Security July 2026 confirms US at 49.3% of all observed victims | A sustained shift in targeting toward non-US economies (e.g., rapid growth in Asia-Pacific or Gulf-region incidents without corresponding US decline) | Geographic risk models used by US-domiciled organizations would need upward recalibration; non-US organizations currently feel less exposed than evidence warrants | Monthly CYFIRMA threat landscape reports tracking US vs. non-US victim ratios |
Why it matters: Leak-site victim counts undercount true ransomware volume, so Finding 1's growth rate is conservative, the actual attack surge is likely steeper. If a dominant group withholds postings to avoid law enforcement attention, the 50% year-over-year rise masks even larger underlying activity.
Counterarguments
-
The leak-site growth figure overstates actual risk escalation: The 50% rise in 2025 victim postings (to 7,874, per NCC Group) coincides with a documented proliferation of new, lower-quality groups whose primary strategy is high-volume, low-return attacks on smaller targets. Flashpoint, Halcyon, and CYFIRMA all note that a large share of incidents involve organizations where ransom demands are measured in tens of thousands of dollars, not millions. If the majority of volume growth is concentrated in small-business, opportunistic attacks, enterprise risk managers may be misreading aggregate numbers as evidence of escalating enterprise-level exposure. The finding that Manufacturing saw a 61% YoY surge deserves the most weight here because Manufacturing incidents tend to be large-enterprise events.
-
TheGentlemen's rapid growth may plateau faster than current trajectory implies: Every high-growth RaaS entry follows an adoption curve, and several predecessors, including RansomHub, grew aggressively and then plateaued or went dormant within 12-18 months. Brandefense's own data, showing only 18 Q4 2025 incidents growing to 183 in Q1 2026, tracks a similar pattern to early-stage RansomHub. Law enforcement attention typically accelerates toward groups that achieve headline-level visibility, and TheGentlemen's June 2026 leaderboard position increases that probability. Readers should treat the current growth rate as an upper bound rather than a forecast.
-
Attribution confidence for many incidents is structurally limited: CYFIRMA's May 2026 report noted that roughly 40% of reported incidents in its Q3 tracking window had not been attributed to any specific group. The leading groups' victim counts are almost entirely drawn from their own leak-site postings, which groups control and which they have incentive to inflate for reputational effect. Mandiant and CrowdStrike IR teams regularly find discrepancies between what groups claim and what forensic evidence confirms. Any ranking of group activity by victim count should be understood as a reputational signal as much as an operational measurement.
Indicators To Watch
The table below identifies observable signals that would confirm or challenge the key findings. Each threshold is actionable, not aspirational.
| Indicator | Current State (as of July 2026) | Warning Threshold | Time Horizon |
|---|---|---|---|
| Qilin monthly victim postings on its leak site | ~111 per month (April-May 2026 average, CYFIRMA) | 150+/month sustained for two consecutive months | 30-60 days |
| TheGentlemen quarterly victim count | 183 incidents in Q1 2026 (Brandefense) | 300+ in Q3 2026, signaling continued acceleration rather than plateau | 30-90 days |
| Coveware quarterly payment rate (% of victims paying) | 20% in Q4 2025 (Coveware all-time low) | Drop below 15% or surge above 30%; either shift would signal a fundamental change in negotiation dynamics | 60-90 days |
| Manufacturing sector monthly incident volume | 93 incidents in May 2026 (CYFIRMA) | 120+/month; would confirm 61% YoY surge is accelerating rather than plateauing | 60 days |
| New ransomware groups entering per quarter | 18 new groups in Q3 2025 (BlackFog); 126-141 total active (Emsisoft Jan 2026) | 25+ new groups in a single quarter; indicates barrier to entry declining faster than observed | 90 days |
Near-term watch list: (1) Coveware Q3 2026 quarterly ransomware report (expected October 2026) - average and median payment figures will confirm whether the Q2 2026 spike to $1.88M average was structural or driven by the Silent Ransom outlier campaign; (2) CYFIRMA and Check Point Research monthly threat intelligence for September 2026 (expected early October) - TheGentlemen and DragonForce activity levels will indicate whether mid-year acceleration continued post-summer; (3) US DOJ or Europol announcement of any action targeting Qilin developer-tier infrastructure - this is the single highest-impact event that could materially alter the top-group outlook within a 30-day window.
Why it matters: Qilin crossing 111 monthly victims and TheGentlemen hitting 300+ quarterly attacks would confirm Finding 1 and 2 are accelerating, not stabilizing. Manufacturing surpassing 120 monthly incidents would signal Finding 3's sector concentration is deepening, not plateauing.
Decision Relevance
Scenario A (~55%): Sustained volume growth with partial payment resistance holding: The current trajectory continues. Attack counts rise, median payments remain in the $115,000-$150,000 range for most victims, and large-enterprise targets face occasional eight-figure demands. If your organization is in manufacturing, professional services, or healthcare, maintain and test your exfiltration detection stack alongside backups. Backup recovery protects against encryption; only behavioral analytics and network egress monitoring protect against the data-theft component. If you are not in these sectors, monitor CYFIRMA and Check Point's monthly threat intelligence as the earliest available signal of sector drift.
Scenario B (~30%): TheGentlemen or a comparable new entrant achieves RaaS market dominance by year-end and shifts the primary attack vector toward pure exfiltration: If your organization handles legally privileged, commercially sensitive, or personally identifiable data on behalf of third parties (law firms, payroll processors, CRM providers), exfiltration-only actors like Silent Ransom represent a threat your encryption-centric defenses do not address. Coveware's Q2 2026 report documented Silent Ransom driving average payment spikes through targeted social engineering against law firms specifically. Audit your third-party data sharing agreements and egress logging posture now, before a campaign targets your sector.
Scenario C (~15%): A major international law enforcement action disrupts two or more top-five groups simultaneously, temporarily suppressing leak-site postings: Post-Cronos history (LockBit returning with 163 victims in Q1 2026) suggests this window would last 90-180 days. If you are deferring security investment on the assumption that the enforcement environment is improving the landscape, the evidence does not support that posture. Accelerate endpoint detection and response (EDR) and network segmentation investments during any apparent lull; affiliate re-recruitment cycles are shorter than most procurement cycles.
Expert Integration
Expert Consensus Assessment
Industry researchers at Kaspersky, CYFIRMA, Halcyon, Check Point Research, Brandefense, and Coveware by Veeam converge on a consistent picture for the first half of 2026: Qilin leads by victim volume, TheGentlemen is the fastest-growing new entrant, and professional services, manufacturing, and healthcare absorb the largest share of attacks. There is meaningful debate on payment trajectory and on what the divergence between falling on-chain payments and rising victim counts actually means for enterprise risk.
Expert Disagreement Areas
- Payment direction: Chainalysis 2026 Crypto Crime Report shows 2025 on-chain payments down 8% to $820 million, while Coveware's Q2 2026 data shows average payments up 176% to $1.88 million quarter-over-quarter. These are not contradictory (they measure different time windows and populations) but they point in opposite directions for planning purposes, and Verizon's 2026 DBIR median of $139,875 differs from both.
- Group ranking stability: Cyber threat landscape data from March 2026 identified INC Ransom as a top-five group alongside Qilin and Akira, while Check Point Research's June 2026 report placed TheGentlemen at number one. Rankings shift meaningfully within a single quarter, which limits their forecasting value beyond 60-90 days.
- AI-enabled attack velocity: Kaspersky and the World Economic Forum's Global Cybersecurity Outlook 2026 treat AI-assisted tooling as already shaping the threat landscape, while Mandiant M-Trends data as of late 2025 had not yet documented AI tools as a confirmed accelerant in confirmed IR engagements. The capability is real; its current operational deployment at scale remains uncertain.
Systematic-Expert Alignment
Alignment: MIXED
This assessment aligns with expert consensus on direction (volume rising, Qilin dominant, professional services and manufacturing most exposed) but diverges from the simpler narrative that "ransomware is declining" that some coverage implies by pointing to falling total on-chain payments. The payment decline is real and documented; the risk decline it is sometimes read as implying is not supported by victim count, sector distribution, or breach-cost data from IBM. The assessment treats both the payment and victim data as valid and draws the structural implication: attack volume growth is outpacing payment-per-victim decline, keeping economic incentive intact.
Analytical Limitations
- Leak-site victim counts are self-reported by threat actors and should be treated as a floor on actual activity, not a ceiling. Groups have incentive to inflate postings for reputational effect, but also to withhold postings when victims pay quickly. The true incident volume is higher than any public dataset captures.
- Ransom payment data from Chainalysis covers on-chain cryptocurrency transactions and misses payments made through intermediaries, off-chain settlements, or channels obscured by mixing services. The $820 million 2025 figure is best read as a lower bound.
- Sector incident counts from CYFIRMA's monthly reports are drawn from open-source intelligence including leak sites, public disclosures, and media reports. Organizations that resolve incidents quietly, common in financial services and government, are systematically underrepresented, which likely understates Finance and Government figures relative to Manufacturing and Healthcare.
- No public source currently provides validated, real-time data on TheGentlemen's full victim population. The Q1 2026 figures from Brandefense are the most specific available, but the group's newness means its geographic and sector concentration patterns could shift rapidly in Q3-Q4 2026.
- Attribution confidence for approximately 40% of reported incidents remains open, per CYFIRMA Q3 2025 tracking. Any group-level analysis is therefore based on the attributed 60%, and the unattributed portion may include activity from groups not yet in the public taxonomy.
Sources & Evidence Base
- UngradedMost Active Ransomware Groups in 2026
dexpose.io
- Ungraded
- Ungraded10 of the most notorious ransomware groups in 2026
swisscyberinstitute.com
- Ungraded10 Most Infamous Ransomware Groups to Watch in 2026
nordlayer.com
- UngradedIR Trends: Ransomware on the rise, while technology becomes most targeted sector
blog.talosintelligence.com
- Ransomware Groups Increasingly Deploy EDR Kill Techniques - Infosecurity Magazine
infosecurity-magazine.com
- UngradedMarch 2026 Ransomware Report: 808 Victims, 65 Groups
breachsense.com