Ransomware victim numbers flat as active groups hit record
Thu, 13th Aug 2026 (Yesterday)
Ransomware victim numbers stayed broadly flat in the second quarter, while the number of active groups reached a record high, according to Check Point. Leaked material from The Gentlemen offered a rare look at how a small team built a leading operation.
Data leak sites recorded 2,139 ransomware victims in the quarter, little changed from the previous quarter but 33% higher than a year earlier. The figures suggest the ransomware market remains at the elevated level seen through 2025, even as activity shifted away from a handful of dominant groups.
Attack concentration eased during the period. The top 10 ransomware groups accounted for 57.6% of victims in the quarter, down from 71% in the first quarter, while the number of active groups rose from 71 to 93.
That shift followed a sharp fall in activity from Cl0p, whose campaign targeting Oracle E-Business Suite had driven much of the first-quarter total. As that campaign faded, a broader group of operators filled the gap.
Qilin held the top position for a fourth consecutive quarter with 279 victims. The Gentlemen moved close behind after growing 62% during the quarter and overtaking Qilin in June.
Inside a group
Researchers also examined leaked backend systems and chat logs tied to The Gentlemen. The material pointed to a core team of about nine people working with a larger affiliate network, with affiliates carrying out most of the intrusion work under a 90/10 revenue split.
The leaked chats showed the group's administrator, known as Zeta88, built its ransomware management panel in about three days using AI coding assistants. The account suggests AI tools are shortening software development time for criminal groups, while still requiring people with enough technical knowledge to guide and correct the code.
For defenders, that matters because it lowers the practical barrier to entry. An experienced operator can now assemble the software and business structure for a significant ransomware operation in months rather than years.
Extortion shift
The report also highlighted a continued move toward data theft as a primary pressure tactic. Payment rates have fallen for six straight years, from 85% in 2019 to about 23% now, as better backup practices have reduced the leverage attackers gain from encrypting systems alone.
That decline has not translated into a collapse in proceeds. On-chain ransomware payments still exceeded USD $820 million in 2025, indicating that a smaller share of victims is still producing substantial returns for operators.
The economics help explain why exfiltration has become central. Organisations can restore systems from backups after encryption, but backups do not stop attackers from releasing stolen files, customer data, or internal records.
That shift has implications for incident response. Companies that focus mainly on recovery after encryption may still face major legal, financial, and reputational damage if attackers have already removed sensitive information before they are detected.
Law enforcement pressure
Authorities spent much of the quarter targeting supporting infrastructure rather than individual ransomware brands. Actions included moves against laundering platforms, exchanges linked to ransomware actors, a malware-signing service, and large infostealer networks.
Those interventions did not show up in a clear reduction in victim numbers during the quarter. Even so, pressure on the services that support credential theft, money movement, and malware distribution can raise costs for criminal groups and complicate their operations.
Defensive priorities
Initial access remains the most important battleground. The Gentlemen's methods included VPN scanning, brute-force attacks, and the use of brokered credentials, all common routes into corporate systems.
That points organisations back to familiar weak spots such as phishing, exposed remote access services, and poor credential hygiene. It also suggests companies should treat exfiltration detection with the same urgency as backup and recovery planning.
Speed is becoming more important as well. In some cases, the gap between disclosure of vulnerabilities and exploitation is now measured in hours, making slow review and patching cycles harder to defend.
Check Point linked that problem to broader exposure management trends. Vulnerabilities accounted for 42.6% of critical exposures in its 2026 Exposure Gap Report, more than double the level seen a year earlier.
The findings add to a picture of a ransomware market no longer defined only by a few outsized brands. Victim totals may have held steady, but the spread of activity across more groups and the evidence of faster tool-building point to a market that is becoming more fragmented and easier to enter.
The leaked chats from The Gentlemen captured that shift in unusually direct terms, showing how a compact team and AI-assisted coding were enough to create a top-tier operation within months.