Report | The State of Ransomware, Q2 2026
Explore the Q2 2026 State of Ransomware Report to uncover key ransomware trends, leading threat groups, AI-driven attacks, victim data, and defense strategies.

The State of Ransomware The State of Ransomware The State of Ransomware The State of Ransomware The State of Ransomware The State of Ransomware Insights into more groups, fewer players, and the same leaders holding the top
Q2
2026
Insights into more groups, fewer players, and the same leaders holding the top
The State of Ransomware The State of Ransomware The State of Ransomware The State of
Ransomware The State of
Ransomware The State of
Ransomware
Q2
2026
Table of
Contents:
010101010101
020202020202
030303030303
040404040404
050505050505
060606060606
070707070707
080808080808
090909090909
Key Findings
Ransomware in Q2 2026: Wider Participation, Same Leaders at the Top
Actor Spotlight: The Gentlemen
Ransomware Economics: A Shrinking, Shifting Payer Market
Law Enforcement in Q2 2026: Targeting Shared Infrastructure
Geographic Distribution of Victims in Q2 2026
Ransomware Attacks by Industry in Q2 2026
Closing the Gap Attackers Are Exploiting
How Check Point Addresses These Findings
Table of Contents:
010101010101 Key
Findings
020202020202 Ransomware in Q2 2026:
Wider Participation, Same Leaders at the Top
030303030303 Actor Spotlight: The Gentlemen
040404040404 Ransomware Economics:
A Shrinking, Shifting Payer Market
050505050505 Law Enforcement in Q2 2026:
Targeting Shared Infrastructure
060606060606 Geographic Distribution of Victims in Q2 2026
070707070707 Ransomware Attacks
by Industry in Q2 2026
080808080808 Closing the Gap Attackers Are Exploiting
090909090909 How Check Point
Addresses These Findings
010101010101 Key Findings
The top 10 groups continued to account for 57.6% of all victims in the second quarter, with Qilin and The Gentlemen together responsible for approximately one quarter of all reported attacks. The number of active groups rose from 71 to 93 during the same period. This reflects de-concentration rather than fragmentation.
Total victim volume did not change materially this quarter and remained at historically high levels. Data leak sites recorded 2,139 victims in the second quarter, essentially unchanged from the first quarter (an increase of 0.8%) and an increase of 33% YoY.
Qilin remained the most prominent group, though only by a narrow margin. Qilin posted 279 victims, a decline of 17%, and narrowly held off The Gentlemen, which posted 269 victims, an increase of 62%, and outpaced Qilin during the month of June.
An internal leak provided a rare view into The Gentlemen's operations. The leak revealed a core team of approximately nine operators, probably supported by a broader affiliate base, building a top three global ransomware operation using AI assisted tooling.
Ransom payment rates continued to decline. According to Coveware, payment rates fell to multi-year lows of approximately 23%, down from 85% in 2019, a trend that continues to push actors toward data theft extortion. Despite this decline, Chainalysis reports on-chain ransomware payments during 2025 still exceeded $820 million.
Law enforcement actions in the second quarter concentrated on infrastructure shared across multiple ransomware groups. Takedowns targeted money laundering platforms, cryptocurrency exchanges, code signing services, and infostealer and loader operations, disrupting services on which many groups depend simultaneously.
The window between vulnerability disclosure and exploitation continued to narrow, a trend accelerated by artificial intelligence. Exploitation now occurs within hours to days of disclosure, as AI reduces the cost of exploit development, a shift that ransomware operators have been among the fastest to exploit.
Check Point Software | The State of Ransomware Report - Q2 2026 03Check Point Software | The State of Ransomware Report - Q2 2026 03
The top 10 groups continued to account for
57.6% of all victims in the second quarter, with Qilin and The Gentlemen
together responsible for approximately one
quarter of all reported attacks. The number of active groups rose from 71 to 93
during the same period. This reflects de-concentration rather than fragmentation.
Total victim volume did not change
materially this quarter and remained at
historically high levels. Data leak sites recorded 2,139 victims in the
second quarter, essentially unchanged from the first quarter (an increase of 0.8%) and an increase of 33% YoY.
Qilin remained the most prominent group,
though only by a narrow margin. Qilin
posted 279 victims, a decline of 17%, and
narrowly held off The Gentlemen, which
posted 269 victims, an increase of 62%, and
outpaced Qilin during the month of June.
An internal leak provided a rare view into
The Gentlemen's operations. The leak
revealed a core team of approximately nine
operators, probably supported by a broader
affiliate base, building a top three global ransomware operation
using AI assisted tooling.
Ransom payment rates continued to
decline. According to Coveware, payment
rates fell to multi-year lows of approximately 23%, down from 85% in 2019,
a trend that continues to push actors
toward data theft extortion. Despite this decline, Chainalysis reports on-chain ransomware payments during 2025
still exceeded $820 million.
Law enforcement actions in the second
quarter concentrated on infrastructure shared across multiple ransomware
groups. Takedowns targeted money
laundering platforms, cryptocurrency exchanges, code signing services, and
infostealer and loader operations, disrupting services on which many groups depend simultaneously.
The window between vulnerability
disclosure and exploitation continued to
narrow, a trend accelerated by artificial intelligence. Exploitation now occurs within hours to days of disclosure,
as AI reduces the cost of exploit development, a shift that ransomware operators have been among the fastest to exploit.
010101010101 Key
Findings
020202020202 Ransomware in Q2 2026: Wider Participation, Same Leaders at the Top
During the second quarter of 2026, ransomware double-extortion actors published 2,139 new victims on the data leak sites (DLS) monitored for this report, essentially unchanged from Q1 2026 (2,122, +0.8%) and
approximately one third above Q2 2025 (1,607, +33%). Volume held at the elevated baseline established through 2025 but eased across the quarter: April recorded 744 victims, May 739, and June 656.
1000 945927 900
801800 744
730 732700 739707634635 727600 684603
656541 500 477
543534 531518400 494479
300 407 387 347200
100
00
Ju n
Au g
Se p
N ov
D ec
M ar
M ay
M ar
M ay
Fe b
Ju n
Au g
Se p
N ov
D ec
Fe b
Ju n
O ct
Ja n
Ap r
Ja n
Ap r
Ju l
O ctJu l
2024 2025 2026
Figure 1:Total Number of Reported Ransomware Victims in DLS, per month (June 2024 - June 2026).
Check Point Software | The State of Ransomware Report - Q2 2026 04Check Point Software | The State of Ransomware Report - Q2 2026 04
020202020202 Ransomware in Q2 2026:
Wider Participation, Same Leaders at the Top
During the second quarter of 2026,
ransomware double-extortion actors published 2,139 new victims on the data leak sites (DLS) monitored for this report, essentially unchanged from Q1 2026 (2,122, +0.8%) and
approximately one third above Q2 2025 (1,607, +33%). Volume held at the elevated baseline
established through 2025 but eased across the
quarter: April recorded 744 victims, May 739, and June 656.
Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun
20262024 2025
347
407
477
387
541 603
534
635
927
730
634
479 494 518 531 543
801
727
945
732
684 707
744
739
656
1000
900
800
700
600
500
400
300
200
100
00
Figure 1:Total Number of Reported Ransomware Victims in DLS, per month (June 2024 - June 2026).
A wider tail, within a concentrated market
The Q1 2026 report documented a sharp re- concentration: the top 10 groups accounted for 71% of victims and the active-group count contracted to 71. That reading eased in Q2: the
top-10 share fell to 57.6% and 93 distinct groups posted at least one victim, a field that remains concentrated but is now more active.
279Qilin
269The Gentlemen
140DragonForce
126Akira
105LockBit
92INC
59SafePay
58Nova
55KryBit
53ShinyHunters
903Other
Figure 2: Top-10 share and active group count, Q2 2026.
The market remains concentrated and top- RaaS-dominated, with Qilin and The Gentlemen together accounted for a quarter of the total (25.6%). The easing of the top-10 share is less a structural shift than a set of softer quarters at the top: Cl0p, whose mass- exploitation of Oracle E-Business Suite (CVE-2025-61882) helped drive Q1's concentration, all but vanished (127 victims to 2), and Qilin, Akira, LockBit and INC each posted fewer than in Q1 while the mid-tier filled in.
The criminal ecosystem does not operate as a stable or predictable system: operators pause, retire, and turn against one another (the newly active KryBit spent April in a public feud with the rival 0APT operation), so a quarter's group count and rankings move for reasons that are often not structural. Q1's 71% figure reflected a temporary combination of factors, including Cl0p's mass-exploitation burst and a spike from LockBit's relaunch, that did not continue into Q2, alongside a notable increase in law enforcement activity during the quarter (see Law Enforcement, below).
Check Point Software | The State of Ransomware Report - Q2 2026 05
The market remains concentrated and top-RaaS-dominated, with Qilin and
The Gentlemen together accounted for a quarter
of the total (25.6%). The easing of the top-10 share is less a structural shift than
a set of softer quarters at the top: Cl0p, whose mass-exploitation of Oracle E-Business Suite (CVE-2025-61882) helped drive Q1's concentration, all but vanished (127 victims to 2), and Qilin,
Akira, LockBit and INC each posted fewer than in Q1 while the mid-tier filled in.
The criminal ecosystem does not operate as a
stable or predictable system: operators pause,
retire, and turn against one another (the newly
active KryBit spent April in a public feud with the rival 0APT operation), so a quarter's group count and rankings move for reasons that
are often not structural. Q1's 71% figure reflected a temporary combination of factors,
including Cl0p's mass-exploitation burst and a spike from LockBit's relaunch, that did
not continue into Q2, alongside a notable increase in law enforcement activity during the quarter (see Law Enforcement, below).
Qilin 279
The Gentlemen 269
DragonForce 140
Akira 126
LockBit 105
INC 92
SafePay 59
Nova 58
KryBit 55
ShinyHunters 53
Other 903
Figure 2: Top-10 share and active group count, Q2 2026.
A wider tail, within a concentrated market
The Q1 2026 report documented a sharp re-concentration: the top 10 groups accounted
for 71% of victims and the active-group count contracted to 71. That reading eased in Q2: the
top-10 share fell to 57.6% and 93 distinct
groups posted at least one victim, a field that remains concentrated but is now more active.
Check Point Software | The State of Ransomware Report - Q2 2026 05
Qilin remained the most prolific operation for a fourth straight quarter, with 279 victims, but declined 17% QoQ and lost share. In June, The Gentlemen ransomware operation posted more victims than Qilin, with 116 victims compared with Qilin's 72. The Gentlemen finished within ten victims of the top spot after growing 62%, while DragonForce held third after growing 39%. Several Q1 leaders declined sharply: Cl0p -98% (127 to 2, as its Oracle EBS campaign ran its course), Sinobi -92% (80 to 6), Play -70% (121 to 36), and Nightspire -60% (82 to 33).
The number of active groups climbed to 93, a new high above the previous peak of 85 (Q3 2025), and the same volume spread across more names even as they maintained their position. This pattern reflects the reshuffle that followed RansomHub's 2025 retirement, which sent displaced affiliates to Qilin and the other surviving majors.
Check Point Software | The State of Ransomware Report - Q2 2026 06Check Point Software | The State of Ransomware Report - Q2 2026 06
Qilin remained the most prolific operation for a
fourth straight quarter, with 279 victims, but declined 17% QoQ and lost share. In June,
The Gentlemen ransomware operation posted
more victims than Qilin, with 116 victims
compared with Qilin's 72. The Gentlemen
finished within ten victims of the top spot after growing 62%, while DragonForce held
third after growing 39%. Several Q1 leaders declined sharply: Cl0p -98% (127 to 2, as its Oracle EBS campaign ran its course), Sinobi -92%
(80 to 6), Play -70% (121 to 36), and Nightspire -60% (82 to 33).
The number of active groups climbed to 93, a
new high above the previous peak of 85 (Q3
2025), and the same volume spread across
more names even as they maintained their
position. This pattern reflects the reshuffle that followed RansomHub's 2025 retirement,
which sent displaced affiliates to Qilin and the other surviving majors.
030303030303 Actor Spotlight: The Gentlemen (The View from Inside)
The Q1 2026 report tracked The Gentlemen's ascent, from 40 victims in Q4 2025 to 166 in Q1 (+315%), driven by pre-positioned access at scale rather than opportunistic exploitation: a large inventory of compromised FortiGate devices and VPN credentials, and an unusual non-Western victim base. The group is reportedly led by a former Qilin
120
100
80
60
38 3640
1720 1310
00 Sep Oct Nov Dec Jan Feb Mar Apr May Jun
2025 2026
Figure 3 - The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026.
What makes Q2 different is not the trajectory: it is the inside view. Two Check Point Research publications this quarter exposed the group's inner workings: a full digital-forensics and incident-response (DFIR) reconstruction of a Gentlemen intrusion with SystemBC command-and-control (C2) telemetry, and an
analysis of the group's own "Rocket" backend and chat logs, which leaked on 4 May 2026 after a hosting-provider compromise. Together they answer a question DLS data never can: not what the group did, but how little it now takes to build and run a top-tier operation, and how professionalized it has become.
Check Point Software | The State of Ransomware Report - Q2 2026 07
affiliate operating as “Hastalamuerte”. In Q2, the group consolidated that rise, posting 269 victims (+62% QoQ) to reach second place globally, finishing within ten victims of Qilin overall, and posting more victims than Qilin in June (116 to 72). Its US share was 25%, up from Q1's 13.3% but still far below the approximately 42% ecosystem average.
116
68
48
83
70
030303030303 Actor Spotlight: The Gentlemen (The View from Inside)
The Q1 2026 report tracked The Gentlemen's ascent, from 40 victims in Q4 2025 to 166 in
Q1 (+315%), driven by pre-positioned access
at scale rather than opportunistic exploitation: a large inventory of compromised FortiGate devices and VPN
credentials, and an unusual non-Western
victim base. The group is reportedly led by a former Qilin
affiliate operating as “Hastalamuerte”. In Q2, the
group consolidated that rise, posting 269 victims
(+62% QoQ) to reach second place globally,
finishing within ten victims of Qilin overall, and posting more victims than Qilin in June (116 to 72). Its US share was 25%, up from Q1's
13.3% but still far below the approximately 42% ecosystem average.
What makes Q2 different is not the trajectory: it is the inside view. Two Check Point
Research publications this quarter exposed the group's inner workings: a full digital-forensics and incident-response (DFIR) reconstruction of a Gentlemen
intrusion with SystemBC command-and-control (C2) telemetry, and an
analysis of the group's own "Rocket" backend
and chat logs, which leaked on 4 May 2026
after a hosting-provider compromise. Together they answer a question DLS data never can:
not what the group did, but how little it now takes to build and run a top-tier operation, and how professionalized it has become.
38
Sep
10
Oct
17
Nov
13
Dec
36
Jan
68
Feb
48
Mar
83
Apr
70
May
116
Jun
20262025
120
100
80
60
40
20
00
Figure 3 - The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026.
Check Point Software | The State of Ransomware Report - Q2 2026 07
A small core, running an affiliate network. The leak exposed a core team of roughly nine operators, with individual roles reconstructed from the chats: an admin who builds and runs the platform (Zeta88/ Hastalamuerte), a red-teamer, and others handling recon, credential brute-forcing, and initial access methods. This core is not the whole operation. The Gentlemen run an open RaaS, and the same leak points to a broader base of independent affiliates (eight affiliate identities appear in the logs) who carry out much of the intrusion work under the group's 90/10 split. The significance is the leverage, not the headcount: a small, tightly run core builds the tooling and infrastructure that lets a looser, larger affiliate base scale the operation to top- three DLS volume.
A hands-on founder, and documented AI-assisted tooling. The admin is not a hands-off platform landlord: Zeta88 personally participates in intrusions while building the locker, the RaaS panel, and the spreading mechanism, and managing payouts. Notably, Zeta88 built the group's "GLOCKER" management panel in about three days using AI coding assistants (including DeepSeek and Qwen), with the self- aware caveat that "you still need to understand what you are doing and be able to guide and correct the code it produces". This is genuine first-party evidence of AI use in ransomware's tooling development, though its scope is limited: the group used AI to write a management panel faster, not to run operations, negotiate, or select targets. Those uses remained theoretical in the chats.
A business, run like one. The leak confirms a professionalized structure: a 90/10 affiliate/operator split (the highest advertised in the market) often shared among two- to three-person affiliate teams; insurance-aware ransom pricing using ZoomInfo revenue estimates; and recruitment posts that position itself as an alternative to rival RaaS operations such as DragonForce and HelloKitty. It also confirms from the inside what the Q1 report could only infer: the group's initial access pipeline is sourced and maintained through a documented process: a RAMP-based broker, continuous VPN scanning, and a dedicated brute-force server.
Resilience is itself the story. A public backend leak would set most groups back. The Gentlemen acknowledged it on a forum within days, announced locker upgrades to evade endpoint detection and response (EDR) tools, and new storage infrastructure, and kept operating into June.
Check Point Software | The State of Ransomware Report - Q2 2026 08Check Point Software | The State of Ransomware Report - Q2 2026 08
A small core, running an affiliate network. The leak exposed a core team of roughly
nine operators, with individual roles reconstructed from the chats: an admin who
builds and runs the platform (Zeta88/Hastalamuerte), a red-teamer, and
others handling recon, credential brute-forcing, and initial access methods.
This core is not the whole operation. The Gentlemen run an open RaaS, and the same leak
points to a broader base of independent affiliates (eight affiliate identities appear in the logs) who carry out much of the
intrusion work under the group's 90/10 split. The
significance is the leverage, not the headcount: a small, tightly run core builds the tooling and infrastructure that lets a looser,
larger affiliate base scale the operation to top-three DLS volume.
A hands-on founder, and documented
AI-assisted tooling. The admin is not a hands-off platform
landlord: Zeta88 personally participates in intrusions while building the locker, the RaaS panel, and the spreading mechanism,
and managing payouts. Notably, Zeta88 built
the group's "GLOCKER" management panel in
about three days using AI coding assistants (including DeepSeek and Qwen), with the self-aware caveat that "you still need to understand what you are doing and be able to
guide and correct the code it produces". This
is genuine first-party evidence of AI use in ransomware's tooling development, though
its scope is limited: the group used AI to write a management panel faster, not to run operations, negotiate, or select targets.
Those uses remained theoretical in the chats.
A business, run like one.
The leak confirms a professionalized structure: a 90/10 affiliate/operator split (the highest advertised in the market) often shared among two- to three-person affiliate teams; insurance-aware ransom pricing using
ZoomInfo revenue estimates; and recruitment posts that position itself as an alternative to rival RaaS operations such as DragonForce and HelloKitty. It also confirms from the inside what the Q1 report could only infer: the group's initial access pipeline is sourced and maintained
through a documented process: a RAMP-based
broker, continuous VPN scanning, and a dedicated brute-force server.
Resilience is itself the story. A public backend leak would set most groups back.
The Gentlemen acknowledged it on a forum within days,
announced locker upgrades to evade endpoint
detection and response (EDR) tools, and new storage
infrastructure, and kept operating into June.
Figure 4:The Gentlemen referring to the leak in a criminal forum
The Q1 spotlight established what The Gentlemen had done and at what scale. The Q2 leak establishes how little is now required to build such an operation, a finding that reframes how the quarter's wider tail of new, smaller groups should be read. A top three ransomware operation was assembled in months by one experienced operator using pre-positioned access, an AI-assisted toolchain, and a proven open-affiliate playbook.
The Gentlemen is not evidence of "consolidation" or of "miniaturization" as a trend: a small core running a large affiliate base is the established RaaS model that LockBit exemplified. It demonstrates that the barriers to reaching the top tier have narrowed enough for a single capable operator to get there, and that same narrowing accounts for the wave of new, smaller groups observed in Q2.
Check Point Software | The State of Ransomware Report - Q2 2026 09
The Q1 spotlight established what The Gentlemen had done and at what scale. The Q2
leak establishes how little is now required to build such an operation, a finding that reframes how the quarter's wider tail of new, smaller groups should be read. A top three ransomware operation was assembled
in months by one experienced operator using
pre-positioned access, an AI-assisted
toolchain, and a proven open-affiliate playbook.
The Gentlemen is not evidence of
"consolidation" or of "miniaturization" as
a trend: a small core running a large affiliate base is the established RaaS
model that LockBit exemplified. It demonstrates that the barriers to reaching the
top tier have narrowed enough for a single capable operator to get there, and that same
narrowing accounts for the wave of new, smaller groups observed in Q2.
Check Point Software | The State of Ransomware Report - Q2 2026 09
Figure 4:The Gentlemen referring to the leak in a criminal forum
040404040404 Ransomware Economics: A Shrinking, Shifting Payer Market
Fewer victims pay. The share of victims who pay has fallen for six straight years, from 85% in early 2019 to 23% in 2026 in Coveware's caseload; the rate for data-exfiltration-only extortion has come down into a similar band (29% in 2026). With payment rates low across the board and tested backups increasingly defeating encryption, operators are leaning toward exfiltration-first extortion, where backups offer the victim no relief.
When victims do pay, the payer market is splitting. Average and median payments are diverging: in Coveware's latest quarter the average rose to $680,081 (+15%) while the median fell to $300,750 (−7%). A few severely- hit large enterprises still pay heavily and lift the average, while the mid-market increasingly refuses or settles small and pulls the median down, a "big-game up, mid-market resilient" split.
Falling rates do not mean falling dollars. Chainalysis, which sees the money that is paid but not the total universe of victims, tracked more than $820 million in on-chain ransomware payments in 2025, down about 8% on the year but still a vast revenue stream. Victim self-reporting captures only a sliver of it: the FBI's latest Internet Crime Report logged just $12.47 million for 2024, a figure IC3 itself calls "artificially low" because many affected organizations do not report losses to the FBI.
The groups that get noticed are not the ones that get paid. The actor that tops the leak-site count, The Gentlemen, is absent from Coveware's payer leaderboard (led by INC, Lone Wolf, and Akira); even Qilin, the most prolific by volume, sits only mid-table there. A DLS census is intended to increase visibility, a clear marketing strategy, not revenue. Taken together, the economics steer ransomware groups toward pure data theft and toward the few large targets that still pay: defense shifts toward stopping the theft itself, with data-loss prevention (DLP) and exfiltration detection now mattering as much as the ability to restore.
Check Point Software | The State of Ransomware Report - Q2 2026 10Check Point Software | The State of Ransomware Report - Q2 2026 10
040404040404 Ransomware Economics:
A Shrinking, Shifting Payer Market
Fewer victims pay. The share of victims who
pay has fallen for six straight years, from 85%
in early 2019 to 23% in 2026 in Coveware's
caseload; the rate for data-exfiltration-only extortion has come down
into a similar band (29% in 2026). With payment rates low across the board and tested backups increasingly defeating encryption, operators are leaning toward
exfiltration-first extortion, where backups offer the victim no relief.
When victims do pay, the payer market is
splitting. Average and median payments are
diverging: in Coveware's latest quarter the average rose to $680,081 (+15%) while the
severely-hit large enterprises still pay heavily and lift the average, while the mid-market increasingly refuses or settles small and pulls the median down, a "big-game
up, mid-market resilient" split.
Falling rates do not mean falling dollars.
Chainalysis, which sees the money that is paid but not the total universe of victims,
tracked more than $820 million in
on-chain ransomware payments in 2025, down about
8% on the year but still a vast revenue stream. Victim self-reporting captures only a sliver of it: the FBI's latest Internet Crime Report logged just $12.47 million for 2024,
a figure IC3 itself calls "artificially low" because many affected organizations do not report losses to the FBI.
The groups that get noticed are not the ones
that get paid. The actor that tops the leak-site count, The Gentlemen,
is absent from Coveware's payer leaderboard (led by INC, Lone Wolf, and Akira); even Qilin,
the most prolific by volume, sits only mid-table there. A DLS census is
intended to increase visibility, a clear marketing strategy, not revenue.
Taken together, the economics steer ransomware
groups toward pure data theft and toward
the few large targets that still pay: defense shifts toward stopping the theft
itself, with data-loss prevention (DLP) and exfiltration detection now mattering as much as the ability to restore.
050505050505 Law Enforcement in Q2 2026: Targeting Shared Infrastructure
Q2 2026 brought a run of law enforcement actions and private-sector takedowns that notably concentrated on the shared services the ransomware economy relies on rather than on the ransomware groups themselves. Several of the quarter's disruptions were led by software and security companies rather than police. Modern ransomware runs on a chain of specialized, cooperating criminal functions: infostealers that harvest credentials, initial- access brokers who package and sell them, RaaS operators and their affiliates, money- laundering services, malware-signing and loader services, and bulletproof or anonymizing hosting. This quarter's actions repeatedly struck those shared functions, where disrupting a single service degrades many groups at once. They are one part of a broader response to ransomware, working alongside payment- and breach-reporting regulation, stronger defenses such as tested backups and modern security controls, and continued enforcement against the groups themselves.
The clearest cluster targeted the financial and cash-out layer, the chokepoint at which a group that cannot launder cannot profit. An international operation coordinated by the US Secret Service and IRS Criminal Investigation (IRS-CI) with Europol and Eurojust, across 11 countries, dismantled the AudiA6 cryptocurrency-laundering platform, which had laundered roughly €336 million for ransomware actors and other criminals since 2021 at a 3-10% fee; Europol linked it to more than 15 international cybercrime investigations, and two administrators, a Ukrainian and a Russian national, were arrested in Georgia. In parallel, the US Treasury's Office of Foreign Assets Control (OFAC) sanctioned Iran's four largest digital- asset exchanges (Nobitex, Wallex, Bitpin, and Ramzinex) for terror finance, sanctions evasion, and support to the IRGC, citing transactions with IRGC-affiliated ransomware actors; Nobitex alone processed over half of Iranian digital-asset inflows. Separately, the sanctioned Grinex exchange, a rebrand of the US-sanctioned Garantex that was directly accused of laundering ransomware proceeds, suspended operations after a $13.74 million hack whose sophistication pointed to a state- or law-enforcement-backed operation.
Check Point Software | The State of Ransomware Report - Q2 2026 11
050505050505 Law Enforcement in Q2 2026:
Targeting Shared Infrastructure
Q2 2026 brought a run of law enforcement
actions and private-sector takedowns that
notably concentrated on the shared services
the ransomware economy relies on rather than on
the ransomware groups themselves. Several of the quarter's disruptions were led by software and security companies rather than police. Modern ransomware runs on a chain of specialized, cooperating criminal functions: infostealers that harvest
credentials, initial-access brokers who package and sell them, RaaS operators and
their affiliates, money-laundering services, malware-signing and loader services, and bulletproof or anonymizing hosting. This quarter's actions repeatedly struck those shared functions, where disrupting a single service degrades many groups at once. They
are one part of a broader response to ransomware, working alongside payment- and
breach-reporting regulation, stronger defenses such as tested backups and modern security controls, and continued enforcement against the groups themselves.
Check Point Software | The State of Ransomware Report - Q2 2026 11
The clearest cluster targeted the financial and
cash-out layer, the chokepoint at which a group
that cannot launder cannot profit. An
international operation coordinated by the US
Secret Service and IRS Criminal Investigation
(IRS-CI) with Europol and Eurojust, across 11
countries, dismantled the AudiA6
cryptocurrency-laundering platform, which had laundered roughly €336 million for ransomware actors and other criminals
since 2021 at a 3-10% fee; Europol linked it to more than 15 international cybercrime investigations, and two administrators, a Ukrainian and a
Russian national, were arrested in Georgia. In parallel, the US Treasury's Office of Foreign Assets Control (OFAC) sanctioned Iran's four largest digital-asset exchanges (Nobitex, Wallex,
Bitpin, and Ramzinex) for terror finance, sanctions evasion, and support to the
IRGC, citing transactions with IRGC-affiliated ransomware actors; Nobitex
alone processed over half of Iranian digital-asset inflows. Separately, the sanctioned Grinex exchange, a rebrand of the
US-sanctioned Garantex that was directly accused of laundering ransomware proceeds,
suspended operations after a $13.74 million hack whose sophistication pointed to a state- or law-enforcement-backed operation.
A second cluster targeted the shared "as-a- service" enablers, where one takedown reaches many operators:
Fox Tempest — Microsoft's Digital Crimes Unit, with Resecurity, took down this malware-signing-as-a-service operation that abused Microsoft Artifact Signing to issue fraudulent code-signing certificates (up to $9,000 each; more than 1,000 issued) to ransomware customers including Qilin, Akira, INC, and (via the Vanilla Tempest actor) Rhysida.
Operation Endgame — the Europol- coordinated action disrupted the Amadey loader and StealC infostealer, seizing 326 servers and 142 domains and recovering 27 million stolen credentials. Infostealers are a foundational input to the ransomware supply chain: they harvest the credentials, session tokens, and VPN logins that initial- access brokers package and sell, and that affiliates use to gain their first foothold, so degrading them removes raw material at the very top of the intrusion chain.
First VPN — a separate operation led by France and the Netherlands, with Europol and Eurojust, dismantled this criminal anonymization service that had featured in almost every major Europol-supported cybercrime investigation.
The effect of any single quarter's enforcement is not measurable in real time, and these operations are best read as supplementary to, rather than a substitute for, the broader pressure of regulation, stronger defenses, and enforcement against the groups themselves. DLS volume did not fall in Q2:
the long decline in payment rates has several causes at once; and infrastructure takedowns may prove temporary where services are rebuilt or replaced. Even so, striking the laundering rails, signing and loader services, infostealer botnets, and anonymizing hosting that many groups share raises the cost and friction of operating at points in the chain that are expensive to reconstitute.
Check Point Software | The State of Ransomware Report - Q2 2026 12Check Point Software | The State of Ransomware Report - Q2 2026 12
A second cluster targeted the shared "as-a-service" enablers, where one
takedown reaches many operators:
The effect of any single quarter's enforcement is not measurable in real time, and these
operations are best read as supplementary to, rather than a substitute for, the
broader pressure of regulation, stronger defenses, and enforcement against the groups themselves. DLS volume did not fall in Q2:
the long decline in payment rates has several causes at once; and infrastructure takedowns
may prove temporary where services are
rebuilt or replaced. Even so, striking the laundering rails, signing and loader services, infostealer botnets, and anonymizing
hosting that many groups share raises the cost and friction of operating at points in the chain that are expensive to reconstitute.
Fox Tempest — Microsoft's Digital Crimes
Unit, with Resecurity, took down this malware-signing-as-a-service operation that abused Microsoft Artifact Signing to issue fraudulent code-signing certificates (up to $9,000 each; more than 1,000 issued) to ransomware customers including Qilin, Akira, INC, and (via the Vanilla Tempest actor) Rhysida.
Operation Endgame — the Europol-coordinated action disrupted the
Amadey loader and StealC infostealer, seizing 326 servers and 142 domains and recovering 27 million stolen credentials.
Infostealers are a foundational input to the ransomware supply chain: they harvest
the credentials, session tokens, and VPN logins that initial-access brokers package and sell, and that affiliates use to gain their first foothold, so degrading them removes raw material at the very top of the intrusion chain.
First VPN — a separate operation led by
France and the Netherlands, with Europol
and Eurojust, dismantled this criminal anonymization service that had featured in
almost every major Europol-supported
cybercrime investigation.
060606060606 Geographic Distribution of Victims in Q2 2026
United States
5%Canada
5%Germany
3%UK
3%Italy
3%France
3%Spain
2%Brazil
2%Thailand
2%Australia
30%Other
Figure 5: Top 10 targeted countries, Q2 2026. Grouped bar chart.
42%
The most notable shift is at the top: the US share fell from 50% to 42% QoQ, an eight-point drop. This is a direct consequence of the reshuffled leaderboard: several of the quarter's risers target well below the US average (LockBit 10% US, The Gentlemen 25%, KryBit 5%, SafePay 15%), so as they gained share, the ecosystem-wide US concentration diluted.
The Q1 report flagged possible US avoidance by individual operators, notably LockBit (after Operation Cronos) and The Gentlemen; Q2's ecosystem-wide dilution, led by operators like KryBit that barely touch the US, is consistent with that pattern. Alongside the low-US risers already noted, several groups skew heavily away from the US:
Alongside the low-US risers already noted, several groups skew heavily away from the US:
Payload ransom group targets the US just 5% of the time
SafePay concentrates on Germany (27%)
Lamashtu leans toward APAC
At the other pole, these groups remain almost exclusively US-focused:
ShinyHunters — 83% US
Play — 83% US
Pear — 79% US
Akira — 78% US
Check Point Software | The State of Ransomware Report - Q2 2026 13Check Point Software | The State of Ransomware Report - Q2 2026 13
060606060606 Geographic Distribution of Victims in Q2 2026
United States 42%
Canada 5%
Germany 5%
UK 3%
Italy 3%
France 3%
Spain 3%
Brazil 2%
Thailand 2%
Australia 2%
Other 30%
Figure 5: Top 10 targeted countries, Q2 2026. Grouped bar chart.
The most notable shift is at the top: the US share fell from 50% to 42% QoQ, an eight-point drop. This is a direct consequence of the reshuffled
leaderboard: several of the quarter's risers target well below the US average (LockBit 10% US, The Gentlemen 25%, KryBit
5%, SafePay 15%), so as they gained share, the ecosystem-wide US concentration diluted.
The Q1 report flagged possible US avoidance
by individual operators, notably LockBit (after Operation Cronos) and The Gentlemen;
Q2's ecosystem-wide dilution, led by operators like KryBit that barely touch the US, is consistent with that pattern. Alongside the low-US risers already
noted, several groups skew heavily away from the US:
Alongside the low-US risers already noted,
several groups skew heavily away from the US:
Payload ransom group targets the US just 5% of the time
SafePay concentrates on Germany (27%)
Lamashtu leans toward APAC
At the other pole, these groups remain almost
exclusively US-focused:
ShinyHunters — 83% US
Play — 83% US
Pear — 79% US
Akira — 78% US
KryBit, newly active to the top 10, is the clearest example of that dynamic. It first surfaced in April 2026 and was classified as an emerging group. It drew early notice for a mid- April feud with the rival 0APT crew: 0APT leaked KryBit's backend and threatened to expose its operators' identities. The panel contained approximately 20 victims in live negotiations, with ransom demands ranging from $40K to $100K. KryBit retaliated by breaching 0APT's servers and exposing that 0APT's claimed 190-plus victims were fabricated. Its Q2 footprint is strikingly global and almost entirely non-US: of 55 claimed victims, just 3 (5%) were in the United States; the rest spread thinly across Latin America, Europe, Asia, and the Middle East with no single country accounting for more than a handful.
Australia rose from 30 to 50 victims (+67% QoQ), entering the top 10. Unlike Q1, where Australian victims were driven largely by Cl0p's Oracle EBS campaign, the Q2 count is broad- based, spread across Qilin (10), INC Ransom (4), Nova (3), and a long tail of groups with two to three victims each. That makes it a more genuine signal of rising activity than a single- campaign artifact.
Check Point Software | The State of Ransomware Report - Q2 2026 14Check Point Software | The State of Ransomware Report - Q2 2026 14
KryBit, newly active to the top 10, is the clearest example of that dynamic. It first surfaced in April 2026 and was classified as an emerging group. It drew early notice for a
mid-April feud with the rival 0APT crew: 0APT leaked KryBit's backend and threatened
to expose its operators' identities. The panel contained approximately 20 victims in
live negotiations, with ransom demands ranging from $40K to $100K. KryBit retaliated by breaching 0APT's servers and
exposing that 0APT's claimed 190-plus
victims were fabricated. Its Q2 footprint is strikingly global and almost entirely non-US: of 55 claimed victims, just 3 (5%) were in the United States; the rest spread thinly across Latin America, Europe, Asia,
and the Middle East with no single country accounting for more than a handful.
Australia rose from 30 to 50 victims (+67%
QoQ), entering the top 10. Unlike Q1, where
Australian victims were driven largely by Cl0p's
Oracle EBS campaign, the Q2 count is broad-based, spread across Qilin (10), INC Ransom (4), Nova (3), and a long tail of groups with two to three victims each. That makes
it a more genuine signal of rising activity than a single-campaign artifact.
070707070707 Ransomware Attacks by Industry in Q2 2026
Ransomware victims in Q2 2026 spanned every major sector, though targeting remained concentrated at the top. Business Services led at 33% of victims, more than twice the share of the next-largest sector, followed by Consumer
Goods & Services (16%) and Industrial Manufacturing (12%); the remaining victims were distributed across the rest of the sector taxonomy in smaller numbers.
Business Services
16%Consumer Goods & Services
12%Industrial Manufacturing
6%Financial Services
6%Healthcare & Medical
5%Government
4%Information Technology
4%Education
3%Transportation & Logistics
3%Automotive
2%Real Estate
2%Media & Entertainment
2%Energy & Utilities
1%Construction & Engineering
Figure 6: Ransomware victims by industry, Q2 2026.
33%
At the actor level, one group stands apart: Pear has leaned toward Healthcare across several quarters (12% this quarter, and as high as 40% in Q4 2025).
Check Point Software | The State of Ransomware Report - Q2 2026 15Check Point Software | The State of Ransomware Report - Q2 2026 15
070707070707 Ransomware Attacks
by Industry in Q2 2026
Business Services 33%
Consumer Goods & Services 16%
Industrial Manufacturing 12%
Financial Services 6%
Healthcare & Medical 6%
Government 5%
Information Technology 4%
Education 4%
Transportation & Logistics 3%
Automotive 3%
Real Estate 2%
Media & Entertainment 2%
Energy & Utilities 2%
Construction & Engineering 1%
Figure 6: Ransomware victims by industry, Q2 2026.
Ransomware victims in Q2 2026 spanned every
major sector, though targeting remained
concentrated at the top. Business Services led at 33% of victims, more than twice the share
of the next-largest sector, followed by Consumer
Goods & Services (16%) and Industrial
Manufacturing (12%); the remaining victims were distributed across the rest of the
sector taxonomy in smaller numbers.
At the actor level, one group stands apart: Pear has leaned toward Healthcare
across several quarters (12% this quarter, and as high as 40% in Q4 2025).
080808080808 Closing the Gap Attackers Are Exploiting
Q2 2026 did not hand defenders a single dramatic headline so much as a set of quieter shifts that matter just as much. The ecosystem stayed concentrated even as its tail widened, with 93 active groups now sharing a market where the top 10 still account for well over half of all victims. The Gentlemen leak showed, from the inside, that a top three global operation can be built by a small core with pre positioned access, an AI assisted toolchain, and an affiliate base willing to do the rest.
ayment rates keep falling even as the dollars paid on chain stay enormous, and law enforcement is now aiming at the shared infrastructure many groups depend on at once rather than chasing individual actors one at a time. The patch window keeps narrowing at the perimeter, and AI is the reason.
Read together, these trends point toward a few concrete priorities:
Treat initial access as the fight that matters most. The Gentlemen leak confirmed what the data already suggested: the group's own pipeline runs on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem. Organizations should assume phishing, credential theft, and exposed remote access points remain the most likely opening move, and defend that opening move accordingly rather than concentrating resources on later stages of an attack.
Plan for data theft, not just encryption. With payment rates down to roughly 23% and tested backups increasingly defeating ransomware on the encryption side, operators are leaning harder into exfiltration first extortion, where a clean backup restore offers no protection at all. Detection and prevention around data leaving the network deserve the same weight traditionally given to backup and recovery.
Shrink the exposure that ransomware groups can actually reach. The narrowing gap between vulnerability disclosure and exploitation, now measured in hours rather than weeks, means that remediation speed on the assets attackers can realistically reach has become one of the more decisive factors in whether an incident turns into a breach.
Check Point Software | The State of Ransomware Report - Q2 2026 16Check Point Software | The State of Ransomware Report - Q2 2026 16
080808080808 Closing the Gap Attackers Are Exploiting
Q2 2026 did not hand defenders a single dramatic
headline so much as a set of quieter shifts that
matter just as much. The ecosystem stayed concentrated even as its tail widened, with 93 active
groups now sharing a market where the top 10 still account for well over half of all victims.
The Gentlemen leak showed, from the inside, that a
top three global operation can be built by a small
core with pre positioned access, an AI assisted
toolchain, and an affiliate base willing to do the rest.
ayment rates keep falling even as the dollars
paid on chain stay enormous, and law
enforcement is now aiming at the shared
infrastructure many groups depend on at once
rather than chasing individual actors one at a time. The patch window keeps narrowing at the
perimeter, and AI is the reason.
Read together, these trends point toward a few
concrete priorities:
Treat initial access as the fight that matters most.
The Gentlemen
leak confirmed what the data already
suggested: the group's own pipeline runs on VPN scanning, brute forcing,
and brokered credentials, the same route used across most of the ecosystem. Organizations should assume phishing,
credential theft, and exposed remote access points remain the most likely opening move, and defend that opening move accordingly rather than concentrating resources on later stages of an attack.
Plan for data theft, not just encryption. With payment rates down
to roughly 23% and tested backups increasingly defeating ransomware on the
encryption side, operators are leaning harder into exfiltration first extortion,
where a clean backup restore offers no protection at all. Detection and prevention around data leaving the network deserve the same weight traditionally given to backup and recovery.
Shrink the exposure that ransomware groups can actually reach.
The narrowing gap between vulnerability
disclosure and exploitation, now measured in hours rather than weeks, means that
remediation speed on the assets attackers
can realistically reach has become one of the more decisive factors in whether an incident
turns into a breach.
Recognize that AI has lowered the barrier to entry on both sides. The Gentlemen's admin built a management panel in three days using AI coding tools, and the report notes that same acceleration is showing up in how quickly disclosed vulnerabilities get weaponized. Defenses that still run on a human review cycle are working against tooling that no longer waits for one.
Assume infrastructure disruption is one part of the picture, not the whole of it. This quarter's law enforcement actions against laundering platforms, signing services, and infostealer infrastructure raise cost and friction across many groups at once, but DLS volume did not fall in Q2. Organizations should treat these takedowns as a tailwind rather than a substitute for their own controls.
Check Point Software | The State of Ransomware Report - Q2 2026 17Check Point Software | The State of Ransomware Report - Q2 2026 17
Recognize that AI has lowered the barrier to entry on both sides. The Gentlemen's admin built a
management panel in three days using AI
coding tools, and the report notes that same acceleration is showing up in
how quickly disclosed vulnerabilities get weaponized. Defenses
that still run on a human review cycle are working against tooling that no longer waits for one.
Assume infrastructure disruption is one part of the picture, not the whole of it. This quarter's law enforcement actions
against laundering platforms, signing services, and infostealer infrastructure
raise cost and friction across many groups at once, but DLS volume did not fall in Q2.
Organizations should treat these takedowns as a tailwind rather than a substitute for
their own controls.
090909090909 How Check Point Addresses These Findings
Workspace Security: protecting users as a primary entry point
Most of what this report documents starts with a person: a phishing email, a malicious link, a set of stolen credentials feeding into the same brute force and brokered access pipeline that groups like The Gentlemen rely on.
Workspace Security protects users across email, browsers, SaaS applications, and endpoints
The platform prevents credential abuse, disrupts command and control activity, and limits lateral movement and data exfiltration
AI driven detection and global threat intelligence stop ransomware delivery before execution
Unified, automated protection helps organizations contain an attack before it spreads or reaches the point of encryption
Hybrid Mesh Network Security (HMNS): stopping ransomware at the network and access layer
With attacks continuing daily and early prevention remaining the cheapest form of defense, Hybrid Mesh Network Security applies consistent, AI driven controls across every connectivity point.
Network firewalls block ransomware, zero day exploits, phishing, and malicious files before they reach devices
SASE Internet Access closes off malicious downloads at the connection point itself
CASB scans data at rest across SaaS platforms such as Salesforce, OneDrive, SharePoint, Google Drive, and Slack, catching malware that enters outside the traditional network perimeter, the same route increasingly used by initial access brokers
If a compromise does occur, Zero Trust access through SASE Private Access limits the blast radius, so ransomware can only reach the data the compromised user was ever authorized to touch, directly addressing the lateral movement pattern this report highlights
Check Point Software | The State of Ransomware Report - Q2 2026 18Check Point Software | The State of Ransomware Report - Q2 2026 18
090909090909 How Check Point
Addresses These Findings
Most of what this report documents starts with a person: a phishing email, a malicious link, a set of
stolen credentials feeding into the same brute force and brokered access pipeline that groups like The
Gentlemen rely on.
Workspace Security protects users across
email, browsers, SaaS applications, and
endpoints
AI driven detection and global threat
intelligence stop ransomware delivery before execution
The platform prevents credential abuse,
disrupts command and control activity, and limits lateral movement and data exfiltration
Unified, automated protection helps
organizations contain an attack before it
spreads or reaches the point of encryption
Hybrid Mesh Network Security (HMNS): stopping ransomware at the network and access layer
With attacks continuing daily and early prevention remaining the cheapest form of defense, Hybrid Mesh
Network Security applies consistent, AI driven controls across every connectivity point.
Network firewalls block ransomware, zero
day exploits, phishing, and malicious files before they reach devices
If a compromise does occur, Zero Trust
access through SASE Private Access limits
the blast radius, so ransomware can only
reach the data the compromised user was
ever authorized to touch, directly addressing the lateral movement
pattern this report highlights
SASE Internet Access closes off malicious
downloads at the connection point itself
CASB scans data at rest across SaaS
platforms such as Salesforce, OneDrive,
SharePoint, Google Drive, and Slack, catching malware that enters outside the traditional
network perimeter, the same route
increasingly used by initial access brokers
Workspace Security: protecting users as a primary entry point
Exposure Management (EM): reducing ransomware exposure before exploitation
As the window between disclosure and exploitation keeps narrowing, the question is no longer just what vulnerabilities exist but which ones ransomware groups can actually reach and use.
Exposure Management identifies the external assets, misconfigurations, and access paths that are realistically exploitable
The same report found that critical exposures can realistically be resolved in under an hour: Utilities-sector organizations using Check Point Exposure Management led the field, resolving 30% of critical exposures within that window, the fastest of any industry measured
Correlating that picture with live ransomware intelligence lets security teams focus remediation on the risks that matter rather than the full list of theoretical ones
Validating which controls can safely close a given path lets teams act preemptively, which matters most in an environment where AI has compressed the time available to respond
Check Point's 2026 Exposure Gap Report found that vulnerabilities now account for 42.6% of all critical exposures, more than double their 18.7% share the year before, confirming that this is where exploitable risk is concentrating fastest
AI Security: securing the same AI tooling ransomware groups are learning to exploit
The Gentlemen leak offered rare, first party confirmation that AI tooling is already part of how ransomware operations get built, not just how they get discussed.
ThreatCloud AI keeps defenses moving on the same accelerated timeline as AI assisted exploitation, rather than waiting on a human review cycle to catch up
Check Point AI Agent Security governs the same kind of agent permissions and configuration files that let an admin like Zeta88 build tooling in days, closing off that path into an organization's own AI infrastructure Workforce AI Security gives visibility into the
AI tools employees are actually using, and stops credentials, source code, and customer data from leaking through them, the same category of exposure that ultimately feeds the initial access brokers supplying ransomware affiliates
AI Red Teaming tests an organization's AI applications and agents for jailbreaks and excessive permissions before deployment, so internal AI tooling never becomes the easiest way in
Check Point Software | The State of Ransomware Report - Q2 2026 19
Exposure Management (EM): reducing ransomware exposure before exploitation
AI Security: securing the same AI tooling ransomware groups are learning to exploit
Check Point Software | The State of Ransomware Report - Q2 2026 19
As the window between disclosure and exploitation keeps narrowing, the question is no longer just what
vulnerabilities exist but which ones ransomware groups can actually reach and use.
Exposure Management identifies the
external assets, misconfigurations, and
access paths that are realistically exploitable
Correlating that picture with live ransomware intelligence lets security teams focus remediation on the risks that
matter rather than the full list of theoretical ones
Check Point's 2026 Exposure Gap
Report found that vulnerabilities now
account for 42.6% of all critical exposures, more than double their 18.7% share
the year before, confirming that this
is where exploitable risk is concentrating fastest
The same report found that critical
exposures can realistically be resolved in under an hour: Utilities-sector organizations using Check Point Exposure
Management led the field, resolving
30% of critical exposures within that window, the fastest of any industry measured
Validating which controls can safely close a given path lets teams act preemptively, which matters most in an
environment where AI has compressed
the time available to respond
The Gentlemen leak offered rare, first party confirmation that AI tooling is already part of how ransomware operations get built, not just how they get discussed.
ThreatCloud AI keeps defenses moving on the same accelerated timeline as AI
assisted exploitation, rather than waiting on a human review cycle to catch up
Workforce AI Security gives visibility into the AI tools employees are actually using,
and stops credentials, source code,
and customer data from leaking through them, the same category of exposure that ultimately feeds the initial access brokers supplying ransomware affiliates
Check Point AI Agent Security governs the
same kind of agent permissions and
configuration files that let an admin like Zeta88 build tooling in days, closing off that path into an organization's own AI infrastructure
AI Red Teaming tests an organization's AI
applications and agents for jailbreaks and
excessive permissions before deployment, so
internal AI tooling never becomes the easiest way in
© 2026 Check Point Software Technologies Ltd. All rights reserved.© 2026 Check Point Software Technologies Ltd. All rights reserved.