eCommerceNews US - Technology news for digital commerce decision-makers
United States
Ransomware victims surge to 7,551 as attacks fragment

Ransomware victims surge to 7,551 as attacks fragment

Thu, 23rd Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Black Kite has published a report showing that publicly disclosed ransomware victims rose to 7,551 over a 12-month period, with attacks accelerating by 60% in the second half.

The figures cover April 2025 to March 2026 and suggest a sharper rise later in the year than the annual total alone indicates. March 2026 closed with 861 victims, the highest monthly total in four years of tracking.

Black Kite's analysis found ransomware activity became both more fragmented and more concentrated. More than 60 new groups entered the market during the reporting period, bringing the total number of active groups to 146 by June 2026. Yet the five largest actors still accounted for 43.6% of all victims.

One group stood out in the data. Qilin claimed more than 1,300 victims, nearly twice as many as its nearest rival, underscoring how a handful of established operators continue to dominate even as new entrants appear at a pace of more than one a week.

Black Kite said this marked a shift from earlier years, when ransomware trends were often defined by a single dominant group or one major event. Its latest assessment instead points to a broader, more operationalised ecosystem, with established actors scaling up while smaller groups continued to arrive.

"Ransomware didn't just grow this year; it evolved," said Ferhat Dikbiyik, Chief Research & Intelligence Officer at Black Kite.

"Previous years were often defined by a dominant ransomware group or a single major event. This year was different. We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half. Those shifts fundamentally changed the shape of the ransomware landscape," Dikbiyik said.

Supply chain focus

Several of the year's most visible incidents spread through trusted vendor platforms, including software-as-a-service integrations, enterprise applications, OAuth connections and support workflows. The report highlighted Oracle E-Business Suite and Salesforce ecosystem integrations as central to a number of prominent supply chain attacks.

That pattern reflects the growing importance of third-party access in ransomware operations. Rather than relying only on direct intrusion into a target, attackers are increasingly exploiting relationships, tools and workflows that organisations already trust.

Visible exposure

The study also examined the security posture of organisations before and after they became publicly disclosed ransomware victims. It found exposures frequently remained in place even after incidents came to light.

In Black Kite's latest assessment of victims, 43.5% still carried critical patch vulnerabilities, 30.8% had exposure tied to known exploited vulnerabilities, and 18.5% showed FocusTag signals. Its before-and-after comparison also found a 175% increase in stealer log exposure.

Those findings suggest that disclosure of an incident does not necessarily mean the underlying weaknesses have been removed. For defenders, that raises questions about patching speed, remediation discipline and whether suppliers are being monitored beyond formal questionnaires.

AI's role

Black Kite said artificial intelligence did not fundamentally redefine ransomware during the period studied. Instead, it argued that AI reduced the cost and effort involved in surrounding tasks such as reconnaissance, phishing, voice-based social engineering, victim research, script writing, translation and extortion messaging.

That matters because it lowers the barrier to entry for less sophisticated actors. In practical terms, Black Kite concluded that AI may have supported the growth in group numbers by making ransomware operations easier to run, even if it was not the direct cause of the rise in attacks.

The report warned this could set the stage for a further shift if AI begins to play a larger role in vulnerability discovery, exploitation cycles and social engineering at scale. For now, the data points to a market where operational efficiency and access to third-party systems are becoming more important.

Defensive steps

Among its recommendations, Black Kite urged organisations to prioritise vulnerabilities already known to be exploited in the wild and to extend third-party cyber risk management beyond questionnaire-based assessments. It also called for stronger controls around identity verification, help desk escalation, employee reporting, vendor verification and executive impersonation.

The underlying message is that ransomware defence now extends well beyond endpoint protection or perimeter security. The human layer, support processes and supplier ecosystem are increasingly central to the risk picture.

The report's main dataset was based on leak site monitoring and validation by the Black Kite Research Group, covering 7,551 publicly disclosed ransomware victims identified during the 12-month reporting period.