Report | The State of Ransomware, Q2 2026

Report | The State of Ransomware, Q2 2026

Explore the Q2 2026 State of Ransomware Report to uncover key ransomware trends, leading threat groups, AI-driven attacks, victim data, and defense strategies.

Report | The State of Ransomware, Q2 2026

The State of 
 Ransomware The State of 
 Ransomware The State of 
 Ransomware The State of
 Ransomware The State of 
 Ransomware The State of 
 Ransomware Insights into more groups, fewer players, and the same leaders holding the top

Q2

2026

Insights into more groups, fewer players, and the same leaders holding the top

The State of Ransomware The State of Ransomware The State of Ransomware The State of

Ransomware The State of

Ransomware The State of

Ransomware

Q2

2026

Table of

Contents:

010101010101

020202020202

030303030303

040404040404

050505050505

060606060606

070707070707

080808080808

090909090909

Key 
 Findings

Ransomware in Q2 2026: 
 Wider Participation, Same Leaders at the Top

Actor Spotlight: 
 The Gentlemen

Ransomware Economics: 
 A Shrinking, Shifting Payer Market

Law Enforcement in Q2 2026: Targeting Shared Infrastructure

Geographic Distribution of Victims in Q2 2026

Ransomware Attacks 
 by Industry in Q2 2026

Closing the Gap 
 Attackers Are Exploiting

How Check Point 
 Addresses These Findings

Table of Contents:

010101010101 Key

Findings

020202020202 Ransomware in Q2 2026:

Wider Participation, Same Leaders at the Top

030303030303 Actor Spotlight: The Gentlemen

040404040404 Ransomware Economics:

A Shrinking, Shifting Payer Market

050505050505 Law Enforcement in Q2 2026:

Targeting Shared Infrastructure

060606060606 Geographic Distribution of Victims in Q2 2026

070707070707 Ransomware Attacks

by Industry in Q2 2026

080808080808 Closing the Gap Attackers Are Exploiting

090909090909 How Check Point

Addresses These Findings

010101010101 Key
 Findings

The top 10 groups continued to account for 57.6% of all victims in the second quarter, with Qilin and The Gentlemen together responsible for approximately one quarter of all reported attacks. The number of active groups rose from 71 to 93 during the same period. This reflects de-concentration rather than fragmentation.

Total victim volume did not change materially this quarter and remained at historically high levels. Data leak sites recorded 2,139 victims in the second quarter, essentially unchanged from the first quarter (an increase of 0.8%) and an increase of 33% YoY.

Qilin remained the most prominent group, though only by a narrow margin. Qilin posted 279 victims, a decline of 17%, and narrowly held off The Gentlemen, which posted 269 victims, an increase of 62%, and outpaced Qilin during the month of June.

An internal leak provided a rare view into The Gentlemen's operations. The leak revealed a core team of approximately nine operators, probably supported by a broader affiliate base, building a top three global ransomware operation using AI assisted tooling.

Ransom payment rates continued to decline. According to Coveware, payment rates fell to multi-year lows of approximately 23%, down from 85% in 2019, a trend that continues to push actors toward data theft extortion. Despite this decline, Chainalysis reports on-chain ransomware payments during 2025 still exceeded $820 million.

Law enforcement actions in the second quarter concentrated on infrastructure shared across multiple ransomware groups. Takedowns targeted money laundering platforms, cryptocurrency exchanges, code signing services, and infostealer and loader operations, disrupting services on which many groups depend simultaneously.

The window between vulnerability disclosure and exploitation continued to narrow, a trend accelerated by artificial intelligence. Exploitation now occurs within hours to days of disclosure, as AI reduces the cost of exploit development, a shift that ransomware operators have been among the fastest to exploit.

Check Point Software | The State of Ransomware Report - Q2 2026 03Check Point Software | The State of Ransomware Report - Q2 2026 03

The top 10 groups continued to account for

57.6% of all victims in the second quarter, with Qilin and The Gentlemen

together responsible for approximately one

quarter of all reported attacks. The number of active groups rose from 71 to 93

during the same period. This reflects de-concentration rather than fragmentation.

Total victim volume did not change

materially this quarter and remained at

historically high levels. Data leak sites recorded 2,139 victims in the

second quarter, essentially unchanged from the first quarter (an increase of 0.8%) and an increase of 33% YoY.

Qilin remained the most prominent group,

though only by a narrow margin. Qilin

posted 279 victims, a decline of 17%, and

narrowly held off The Gentlemen, which

posted 269 victims, an increase of 62%, and

outpaced Qilin during the month of June.

An internal leak provided a rare view into

The Gentlemen's operations. The leak

revealed a core team of approximately nine

operators, probably supported by a broader

affiliate base, building a top three global ransomware operation

using AI assisted tooling.

Ransom payment rates continued to

decline. According to Coveware, payment

rates fell to multi-year lows of approximately 23%, down from 85% in 2019,

a trend that continues to push actors

toward data theft extortion. Despite this decline, Chainalysis reports on-chain ransomware payments during 2025

still exceeded $820 million.

Law enforcement actions in the second

quarter concentrated on infrastructure shared across multiple ransomware

groups. Takedowns targeted money

laundering platforms, cryptocurrency exchanges, code signing services, and

infostealer and loader operations, disrupting services on which many groups depend simultaneously.

The window between vulnerability

disclosure and exploitation continued to

narrow, a trend accelerated by artificial intelligence. Exploitation now occurs within hours to days of disclosure,

as AI reduces the cost of exploit development, a shift that ransomware operators have been among the fastest to exploit.

010101010101 Key

Findings

020202020202 Ransomware in Q2 2026: 
 Wider Participation, Same Leaders at the Top

During the second quarter of 2026, ransomware double-extortion actors published 2,139 new victims on the data leak sites (DLS) monitored for this report, essentially unchanged from Q1 2026 (2,122, +0.8%) and

approximately one third above Q2 2025 (1,607, +33%). Volume held at the elevated baseline established through 2025 but eased across the quarter: April recorded 744 victims, May 739, and June 656.

1000 945927 900

801800 744

730 732700 739707634635 727600 684603

656541 500 477

543534 531518400 494479

300 407 387 347200

100

00

Ju n

Au g

Se p

N ov

D ec

M ar

M ay

M ar

M ay

Fe b

Ju n

Au g

Se p

N ov

D ec

Fe b

Ju n

O ct

Ja n

Ap r

Ja n

Ap r

Ju l

O ctJu l

2024 2025 2026

Figure 1:Total Number of Reported Ransomware Victims in DLS, per month  
 (June 2024 - June 2026).

Check Point Software | The State of Ransomware Report - Q2 2026 04Check Point Software | The State of Ransomware Report - Q2 2026 04

020202020202 Ransomware in Q2 2026:

Wider Participation, Same Leaders at the Top

During the second quarter of 2026,

ransomware double-extortion actors published 2,139 new victims on the data leak sites (DLS) monitored for this report, essentially unchanged from Q1 2026 (2,122, +0.8%) and

approximately one third above Q2 2025 (1,607, +33%). Volume held at the elevated baseline

established through 2025 but eased across the

quarter: April recorded 744 victims, May 739, and June 656.

Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun

20262024 2025

347

407

477

387

541 603

534

635

927

730

634

479 494 518 531 543

801

727

945

732

684 707

744

739

656

1000

900

800

700

600

500

400

300

200

100

00

Figure 1:Total Number of Reported Ransomware Victims in DLS, per month (June 2024 - June 2026).

A wider tail, within a concentrated market

The Q1 2026 report documented a sharp re- concentration: the top 10 groups accounted for 71% of victims and the active-group count contracted to 71. That reading eased in Q2: the

top-10 share fell to 57.6% and 93 distinct groups posted at least one victim, a field that remains concentrated but is now more active.

279Qilin

269The Gentlemen

140DragonForce

126Akira

105LockBit

92INC

59SafePay

58Nova

55KryBit

53ShinyHunters

903Other

Figure 2: Top-10 share and active group count, Q2 2026.

The market remains concentrated and top- RaaS-dominated, with Qilin and The Gentlemen together accounted for a quarter of the total (25.6%). The easing of the top-10 share is less a structural shift than a set of softer quarters at the top: Cl0p, whose mass- exploitation of Oracle E-Business Suite (CVE-2025-61882) helped drive Q1's concentration, all but vanished (127 victims to 2), and Qilin, Akira, LockBit and INC each posted fewer than in Q1 while the mid-tier filled in.

The criminal ecosystem does not operate as a stable or predictable system: operators pause, retire, and turn against one another (the newly active KryBit spent April in a public feud with the rival 0APT operation), so a quarter's group count and rankings move for reasons that are often not structural. Q1's 71% figure reflected a temporary combination of factors, including Cl0p's mass-exploitation burst and a spike from LockBit's relaunch, that did not continue into Q2, alongside a notable increase in law enforcement activity during the quarter (see Law Enforcement, below).

Check Point Software | The State of Ransomware Report - Q2 2026 05

The market remains concentrated and top-RaaS-dominated, with Qilin and

The Gentlemen together accounted for a quarter

of the total (25.6%). The easing of the top-10 share is less a structural shift than

a set of softer quarters at the top: Cl0p, whose mass-exploitation of Oracle E-Business Suite (CVE-2025-61882) helped drive Q1's concentration, all but vanished (127 victims to 2), and Qilin,

Akira, LockBit and INC each posted fewer than in Q1 while the mid-tier filled in.

The criminal ecosystem does not operate as a

stable or predictable system: operators pause,

retire, and turn against one another (the newly

active KryBit spent April in a public feud with the rival 0APT operation), so a quarter's group count and rankings move for reasons that

are often not structural. Q1's 71% figure reflected a temporary combination of factors,

including Cl0p's mass-exploitation burst and a spike from LockBit's relaunch, that did

not continue into Q2, alongside a notable increase in law enforcement activity during the quarter (see Law Enforcement, below).

Qilin 279

The Gentlemen 269

DragonForce 140

Akira 126

LockBit 105

INC 92

SafePay 59

Nova 58

KryBit 55

ShinyHunters 53

Other 903

Figure 2: Top-10 share and active group count, Q2 2026.

A wider tail, within a concentrated market

The Q1 2026 report documented a sharp re-concentration: the top 10 groups accounted

for 71% of victims and the active-group count contracted to 71. That reading eased in Q2: the

top-10 share fell to 57.6% and 93 distinct

groups posted at least one victim, a field that remains concentrated but is now more active.

Check Point Software | The State of Ransomware Report - Q2 2026 05

Qilin remained the most prolific operation for a fourth straight quarter, with 279 victims, but declined 17% QoQ and lost share. In June, The Gentlemen ransomware operation posted more victims than Qilin, with 116 victims compared with Qilin's 72. The Gentlemen finished within ten victims of the top spot after growing 62%, while DragonForce held third after growing 39%. Several Q1 leaders declined sharply: Cl0p -98% (127 to 2, as its Oracle EBS campaign ran its course), Sinobi -92% (80 to 6), Play -70% (121 to 36), and Nightspire -60% (82 to 33).

The number of active groups climbed to 93, a new high above the previous peak of 85 (Q3 2025), and the same volume spread across more names even as they maintained their position. This pattern reflects the reshuffle that followed RansomHub's 2025 retirement, which sent displaced affiliates to Qilin and the other surviving majors.

Check Point Software | The State of Ransomware Report - Q2 2026 06Check Point Software | The State of Ransomware Report - Q2 2026 06

Qilin remained the most prolific operation for a

fourth straight quarter, with 279 victims, but declined 17% QoQ and lost share. In June,

The Gentlemen ransomware operation posted

more victims than Qilin, with 116 victims

compared with Qilin's 72. The Gentlemen

finished within ten victims of the top spot after growing 62%, while DragonForce held

third after growing 39%. Several Q1 leaders declined sharply: Cl0p -98% (127 to 2, as its Oracle EBS campaign ran its course), Sinobi -92%

(80 to 6), Play -70% (121 to 36), and Nightspire -60% (82 to 33).

The number of active groups climbed to 93, a

new high above the previous peak of 85 (Q3

2025), and the same volume spread across

more names even as they maintained their

position. This pattern reflects the reshuffle that followed RansomHub's 2025 retirement,

which sent displaced affiliates to Qilin and the other surviving majors.

030303030303 Actor Spotlight:
 The Gentlemen (The View from Inside)

The Q1 2026 report tracked The Gentlemen's ascent, from 40 victims in Q4 2025 to 166 in Q1 (+315%), driven by pre-positioned access at scale rather than opportunistic exploitation: a large inventory of compromised FortiGate devices and VPN credentials, and an unusual non-Western victim base. The group is reportedly led by a former Qilin

120

100

80

60

38 3640

1720 1310

00 Sep Oct Nov Dec Jan Feb Mar Apr May Jun

2025 2026

Figure 3 - The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026.

What makes Q2 different is not the trajectory: it is the inside view. Two Check Point Research publications this quarter exposed the group's inner workings: a full digital-forensics and incident-response (DFIR) reconstruction of a Gentlemen intrusion with SystemBC command-and-control (C2) telemetry, and an

analysis of the group's own "Rocket" backend and chat logs, which leaked on 4 May 2026 after a hosting-provider compromise. Together they answer a question DLS data never can: not what the group did, but how little it now takes to build and run a top-tier operation, and how professionalized it has become.

Check Point Software | The State of Ransomware Report - Q2 2026 07

affiliate operating as “Hastalamuerte”. In Q2, the group consolidated that rise, posting 269 victims (+62% QoQ) to reach second place globally, finishing within ten victims of Qilin overall, and posting more victims than Qilin in June (116 to 72). Its US share was 25%, up from Q1's 13.3% but still far below the approximately 42% ecosystem average.

116

68

48

83

70

030303030303 Actor Spotlight: The Gentlemen (The View from Inside)

The Q1 2026 report tracked The Gentlemen's ascent, from 40 victims in Q4 2025 to 166 in

Q1 (+315%), driven by pre-positioned access

at scale rather than opportunistic exploitation: a large inventory of compromised FortiGate devices and VPN

credentials, and an unusual non-Western

victim base. The group is reportedly led by a former Qilin

affiliate operating as “Hastalamuerte”. In Q2, the

group consolidated that rise, posting 269 victims

(+62% QoQ) to reach second place globally,

finishing within ten victims of Qilin overall, and posting more victims than Qilin in June (116 to 72). Its US share was 25%, up from Q1's

13.3% but still far below the approximately 42% ecosystem average.

What makes Q2 different is not the trajectory: it is the inside view. Two Check Point

Research publications this quarter exposed the group's inner workings: a full digital-forensics and incident-response (DFIR) reconstruction of a Gentlemen

intrusion with SystemBC command-and-control (C2) telemetry, and an

analysis of the group's own "Rocket" backend

and chat logs, which leaked on 4 May 2026

after a hosting-provider compromise. Together they answer a question DLS data never can:

not what the group did, but how little it now takes to build and run a top-tier operation, and how professionalized it has become.

38

Sep

10

Oct

17

Nov

13

Dec

36

Jan

68

Feb

48

Mar

83

Apr

70

May

116

Jun

20262025

120

100

80

60

40

20

00

Figure 3 - The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026.

Check Point Software | The State of Ransomware Report - Q2 2026 07

A small core, running an affiliate network. 
 The leak exposed a core team of roughly nine operators, with individual roles reconstructed from the chats: an admin who builds and runs the platform (Zeta88/ Hastalamuerte), a red-teamer, and others handling recon, credential brute-forcing, and initial access methods. This core is not the whole operation. The Gentlemen run an open RaaS, and the same leak points to a broader base of independent affiliates (eight affiliate identities appear in the logs) who carry out much of the intrusion work under the group's 90/10 split. The significance is the leverage, not the headcount: a small, tightly run core builds the tooling and infrastructure that lets a looser, larger affiliate base scale the operation to top- three DLS volume.

A hands-on founder, and documented
 AI-assisted tooling.
 The admin is not a hands-off platform landlord: Zeta88 personally participates in intrusions while building the locker, the RaaS panel, and the spreading mechanism, and managing payouts. Notably, Zeta88 built the group's "GLOCKER" management panel in about three days using AI coding assistants (including DeepSeek and Qwen), with the self- aware caveat that "you still need to understand what you are doing and be able to guide and correct the code it produces". This is genuine first-party evidence of AI use in ransomware's tooling development, though its scope is limited: the group used AI to write a management panel faster, not to run operations, negotiate, or select targets. 
 Those uses remained theoretical in the chats.

A business, run like one.
 The leak confirms a professionalized structure: a 90/10 affiliate/operator split (the highest advertised in the market) often shared among two- to three-person affiliate teams; insurance-aware ransom pricing using ZoomInfo revenue estimates; and recruitment posts that position itself as an alternative to rival RaaS operations such as DragonForce and HelloKitty. It also confirms from the inside what the Q1 report could only infer: the group's initial access pipeline is sourced and maintained through a documented process: a RAMP-based broker, continuous VPN scanning, and a dedicated brute-force server.

Resilience is itself the story.
 A public backend leak would set most groups back. The Gentlemen acknowledged it on a forum within days, announced locker upgrades to evade endpoint detection and response (EDR) tools, and new storage infrastructure, and kept operating into June.

Check Point Software | The State of Ransomware Report - Q2 2026 08Check Point Software | The State of Ransomware Report - Q2 2026 08

A small core, running an affiliate network. The leak exposed a core team of roughly

nine operators, with individual roles reconstructed from the chats: an admin who

builds and runs the platform (Zeta88/Hastalamuerte), a red-teamer, and

others handling recon, credential brute-forcing, and initial access methods.

This core is not the whole operation. The Gentlemen run an open RaaS, and the same leak

points to a broader base of independent affiliates (eight affiliate identities appear in the logs) who carry out much of the

intrusion work under the group's 90/10 split. The

significance is the leverage, not the headcount: a small, tightly run core builds the tooling and infrastructure that lets a looser,

larger affiliate base scale the operation to top-three DLS volume.

A hands-on founder, and documented

AI-assisted tooling. The admin is not a hands-off platform

landlord: Zeta88 personally participates in intrusions while building the locker, the RaaS panel, and the spreading mechanism,

and managing payouts. Notably, Zeta88 built

the group's "GLOCKER" management panel in

about three days using AI coding assistants (including DeepSeek and Qwen), with the self-aware caveat that "you still need to understand what you are doing and be able to

guide and correct the code it produces". This

is genuine first-party evidence of AI use in ransomware's tooling development, though

its scope is limited: the group used AI to write a management panel faster, not to run operations, negotiate, or select targets.

Those uses remained theoretical in the chats.

A business, run like one.

The leak confirms a professionalized structure: a 90/10 affiliate/operator split (the highest advertised in the market) often shared among two- to three-person affiliate teams; insurance-aware ransom pricing using

ZoomInfo revenue estimates; and recruitment posts that position itself as an alternative to rival RaaS operations such as DragonForce and HelloKitty. It also confirms from the inside what the Q1 report could only infer: the group's initial access pipeline is sourced and maintained

through a documented process: a RAMP-based

broker, continuous VPN scanning, and a dedicated brute-force server.

Resilience is itself the story. A public backend leak would set most groups back.

The Gentlemen acknowledged it on a forum within days,

announced locker upgrades to evade endpoint

detection and response (EDR) tools, and new storage

infrastructure, and kept operating into June.

Figure 4:The Gentlemen referring to the leak in a criminal forum

The Q1 spotlight established what The Gentlemen had done and at what scale. The Q2 leak establishes how little is now required to build such an operation, a finding that reframes how the quarter's wider tail of new, smaller groups should be read. A top three ransomware operation was assembled in months by one experienced operator using pre-positioned access, an AI-assisted toolchain, and a proven open-affiliate playbook.

The Gentlemen is not evidence of "consolidation" or of "miniaturization" as a trend: a small core running a large affiliate base is the established RaaS model that LockBit exemplified. It demonstrates that the barriers to reaching the top tier have narrowed enough for a single capable operator to get there, and that same narrowing accounts for the wave of new, smaller groups observed in Q2.

Check Point Software | The State of Ransomware Report - Q2 2026 09

The Q1 spotlight established what The Gentlemen had done and at what scale. The Q2

leak establishes how little is now required to build such an operation, a finding that reframes how the quarter's wider tail of new, smaller groups should be read. A top three ransomware operation was assembled

in months by one experienced operator using

pre-positioned access, an AI-assisted

toolchain, and a proven open-affiliate playbook.

The Gentlemen is not evidence of

"consolidation" or of "miniaturization" as

a trend: a small core running a large affiliate base is the established RaaS

model that LockBit exemplified. It demonstrates that the barriers to reaching the

top tier have narrowed enough for a single capable operator to get there, and that same

narrowing accounts for the wave of new, smaller groups observed in Q2.

Check Point Software | The State of Ransomware Report - Q2 2026 09

Figure 4:The Gentlemen referring to the leak in a criminal forum

040404040404 Ransomware Economics:
 A Shrinking, Shifting Payer Market

Fewer victims pay. The share of victims who pay has fallen for six straight years, from 85% in early 2019 to 23% in 2026 in Coveware's caseload; the rate for data-exfiltration-only extortion has come down into a similar band (29% in 2026). With payment rates low across the board and tested backups increasingly defeating encryption, operators are leaning toward exfiltration-first extortion, where backups offer the victim no relief.

When victims do pay, the payer market is splitting. Average and median payments are diverging: in Coveware's latest quarter the average rose to $680,081 (+15%) while the median fell to $300,750 (−7%). A few severely- hit large enterprises still pay heavily and lift the average, while the mid-market increasingly refuses or settles small and pulls the median down, a "big-game up, mid-market resilient" split.

Falling rates do not mean falling dollars. Chainalysis, which sees the money that is paid but not the total universe of victims, tracked more than $820 million in on-chain ransomware payments in 2025, down about 8% on the year but still a vast revenue stream. Victim self-reporting captures only a sliver of it: the FBI's latest Internet Crime Report logged just $12.47 million for 2024, a figure IC3 itself calls "artificially low" because many affected organizations do not report losses to the FBI.

The groups that get noticed are not the ones that get paid. The actor that tops the leak-site count, The Gentlemen, is absent from Coveware's payer leaderboard (led by INC, Lone Wolf, and Akira); even Qilin, the most prolific by volume, sits only mid-table there. A DLS census is intended to increase visibility, a clear marketing strategy, not revenue. Taken together, the economics steer ransomware groups toward pure data theft and toward the few large targets that still pay: defense shifts toward stopping the theft itself, with data-loss prevention (DLP) and exfiltration detection now mattering as much as the ability to restore.

Check Point Software | The State of Ransomware Report - Q2 2026 10Check Point Software | The State of Ransomware Report - Q2 2026 10

040404040404 Ransomware Economics:

A Shrinking, Shifting Payer Market

Fewer victims pay. The share of victims who

pay has fallen for six straight years, from 85%

in early 2019 to 23% in 2026 in Coveware's

caseload; the rate for data-exfiltration-only extortion has come down

into a similar band (29% in 2026). With payment rates low across the board and tested backups increasingly defeating encryption, operators are leaning toward

exfiltration-first extortion, where backups offer the victim no relief.

When victims do pay, the payer market is

splitting. Average and median payments are

diverging: in Coveware's latest quarter the average rose to $680,081 (+15%) while the

severely-hit large enterprises still pay heavily and lift the average, while the mid-market increasingly refuses or settles small and pulls the median down, a "big-game

up, mid-market resilient" split.

Falling rates do not mean falling dollars.

Chainalysis, which sees the money that is paid but not the total universe of victims,

tracked more than $820 million in

on-chain ransomware payments in 2025, down about

8% on the year but still a vast revenue stream. Victim self-reporting captures only a sliver of it: the FBI's latest Internet Crime Report logged just $12.47 million for 2024,

a figure IC3 itself calls "artificially low" because many affected organizations do not report losses to the FBI.

The groups that get noticed are not the ones

that get paid. The actor that tops the leak-site count, The Gentlemen,

is absent from Coveware's payer leaderboard (led by INC, Lone Wolf, and Akira); even Qilin,

the most prolific by volume, sits only mid-table there. A DLS census is

intended to increase visibility, a clear marketing strategy, not revenue.

Taken together, the economics steer ransomware

groups toward pure data theft and toward

the few large targets that still pay: defense shifts toward stopping the theft

itself, with data-loss prevention (DLP) and exfiltration detection now mattering as much as the ability to restore.

050505050505 Law Enforcement in Q2 2026:
 Targeting Shared Infrastructure

Q2 2026 brought a run of law enforcement actions and private-sector takedowns that notably concentrated on the shared services the ransomware economy relies on rather than on the ransomware groups themselves. Several of the quarter's disruptions were led by software and security companies rather than police. Modern ransomware runs on a chain of specialized, cooperating criminal functions: infostealers that harvest credentials, initial- access brokers who package and sell them, RaaS operators and their affiliates, money- laundering services, malware-signing and loader services, and bulletproof or anonymizing hosting. This quarter's actions repeatedly struck those shared functions, where disrupting a single service degrades many groups at once. They are one part of a broader response to ransomware, working alongside payment- and breach-reporting regulation, stronger defenses such as tested backups and modern security controls, and continued enforcement against the groups themselves.

The clearest cluster targeted the financial and cash-out layer, the chokepoint at which a group that cannot launder cannot profit. An international operation coordinated by the US Secret Service and IRS Criminal Investigation (IRS-CI) with Europol and Eurojust, across 11 countries, dismantled the AudiA6 cryptocurrency-laundering platform, which had laundered roughly €336 million for ransomware actors and other criminals since 2021 at a 3-10% fee; Europol linked it to more than 15 international cybercrime investigations, and two administrators, a Ukrainian and a Russian national, were arrested in Georgia. In parallel, the US Treasury's Office of Foreign Assets Control (OFAC) sanctioned Iran's four largest digital- asset exchanges (Nobitex, Wallex, Bitpin, and Ramzinex) for terror finance, sanctions evasion, and support to the IRGC, citing transactions with IRGC-affiliated ransomware actors; Nobitex alone processed over half of Iranian digital-asset inflows. Separately, the sanctioned Grinex exchange, a rebrand of the US-sanctioned Garantex that was directly accused of laundering ransomware proceeds, suspended operations after a $13.74 million hack whose sophistication pointed to a state- or law-enforcement-backed operation.

Check Point Software | The State of Ransomware Report - Q2 2026 11

050505050505 Law Enforcement in Q2 2026:

Targeting Shared Infrastructure

Q2 2026 brought a run of law enforcement

actions and private-sector takedowns that

notably concentrated on the shared services

the ransomware economy relies on rather than on

the ransomware groups themselves. Several of the quarter's disruptions were led by software and security companies rather than police. Modern ransomware runs on a chain of specialized, cooperating criminal functions: infostealers that harvest

credentials, initial-access brokers who package and sell them, RaaS operators and

their affiliates, money-laundering services, malware-signing and loader services, and bulletproof or anonymizing hosting. This quarter's actions repeatedly struck those shared functions, where disrupting a single service degrades many groups at once. They

are one part of a broader response to ransomware, working alongside payment- and

breach-reporting regulation, stronger defenses such as tested backups and modern security controls, and continued enforcement against the groups themselves.

Check Point Software | The State of Ransomware Report - Q2 2026 11

The clearest cluster targeted the financial and

cash-out layer, the chokepoint at which a group

that cannot launder cannot profit. An

international operation coordinated by the US

Secret Service and IRS Criminal Investigation

(IRS-CI) with Europol and Eurojust, across 11

countries, dismantled the AudiA6

cryptocurrency-laundering platform, which had laundered roughly €336 million for ransomware actors and other criminals

since 2021 at a 3-10% fee; Europol linked it to more than 15 international cybercrime investigations, and two administrators, a Ukrainian and a

Russian national, were arrested in Georgia. In parallel, the US Treasury's Office of Foreign Assets Control (OFAC) sanctioned Iran's four largest digital-asset exchanges (Nobitex, Wallex,

Bitpin, and Ramzinex) for terror finance, sanctions evasion, and support to the

IRGC, citing transactions with IRGC-affiliated ransomware actors; Nobitex

alone processed over half of Iranian digital-asset inflows. Separately, the sanctioned Grinex exchange, a rebrand of the

US-sanctioned Garantex that was directly accused of laundering ransomware proceeds,

suspended operations after a $13.74 million hack whose sophistication pointed to a state- or law-enforcement-backed operation.

A second cluster targeted the shared "as-a- service" enablers, where one takedown reaches many operators:

Fox Tempest — Microsoft's Digital Crimes Unit, with Resecurity, took down this malware-signing-as-a-service operation that abused Microsoft Artifact Signing to issue fraudulent code-signing certificates (up to $9,000 each; more than 1,000 issued) to ransomware customers including Qilin, Akira, INC, and (via the Vanilla Tempest actor) Rhysida.

Operation Endgame — the Europol- coordinated action disrupted the Amadey loader and StealC infostealer, seizing 326 servers and 142 domains and recovering 27 million stolen credentials. Infostealers are a foundational input to the ransomware supply chain: they harvest the credentials, session tokens, and VPN logins that initial- access brokers package and sell, and that affiliates use to gain their first foothold, so degrading them removes raw material at the very top of the intrusion chain.

First VPN — a separate operation led by France and the Netherlands, with Europol and Eurojust, dismantled this criminal anonymization service that had featured in almost every major Europol-supported cybercrime investigation.

The effect of any single quarter's enforcement is not measurable in real time, and these operations are best read as supplementary to, rather than a substitute for, the broader pressure of regulation, stronger defenses, and enforcement against the groups themselves. DLS volume did not fall in Q2:

the long decline in payment rates has several causes at once; and infrastructure takedowns may prove temporary where services are rebuilt or replaced. Even so, striking the laundering rails, signing and loader services, infostealer botnets, and anonymizing hosting that many groups share raises the cost and friction of operating at points in the chain that are expensive to reconstitute.

Check Point Software | The State of Ransomware Report - Q2 2026 12Check Point Software | The State of Ransomware Report - Q2 2026 12

A second cluster targeted the shared "as-a-service" enablers, where one

takedown reaches many operators:

The effect of any single quarter's enforcement is not measurable in real time, and these

operations are best read as supplementary to, rather than a substitute for, the

broader pressure of regulation, stronger defenses, and enforcement against the groups themselves. DLS volume did not fall in Q2:

the long decline in payment rates has several causes at once; and infrastructure takedowns

may prove temporary where services are

rebuilt or replaced. Even so, striking the laundering rails, signing and loader services, infostealer botnets, and anonymizing

hosting that many groups share raises the cost and friction of operating at points in the chain that are expensive to reconstitute.

Fox Tempest — Microsoft's Digital Crimes

Unit, with Resecurity, took down this malware-signing-as-a-service operation that abused Microsoft Artifact Signing to issue fraudulent code-signing certificates (up to $9,000 each; more than 1,000 issued) to ransomware customers including Qilin, Akira, INC, and (via the Vanilla Tempest actor) Rhysida.

Operation Endgame — the Europol-coordinated action disrupted the

Amadey loader and StealC infostealer, seizing 326 servers and 142 domains and recovering 27 million stolen credentials.

Infostealers are a foundational input to the ransomware supply chain: they harvest

the credentials, session tokens, and VPN logins that initial-access brokers package and sell, and that affiliates use to gain their first foothold, so degrading them removes raw material at the very top of the intrusion chain.

First VPN — a separate operation led by

France and the Netherlands, with Europol

and Eurojust, dismantled this criminal anonymization service that had featured in

almost every major Europol-supported

cybercrime investigation.

060606060606 Geographic Distribution 
 of Victims in Q2 2026

United States

5%Canada

5%Germany

3%UK

3%Italy

3%France

3%Spain

2%Brazil

2%Thailand

2%Australia

30%Other

Figure 5: Top 10 targeted countries, Q2 2026. Grouped bar chart.

42%

The most notable shift is at the top: the US share fell from 50% to 42% QoQ, an eight-point drop. This is a direct consequence of the reshuffled leaderboard: several of the quarter's risers target well below the US average (LockBit 10% US, The Gentlemen 25%, KryBit 5%, SafePay 15%), so as they gained share, the ecosystem-wide US concentration diluted.

The Q1 report flagged possible US avoidance by individual operators, notably LockBit (after Operation Cronos) and The Gentlemen; Q2's ecosystem-wide dilution, led by operators like KryBit that barely touch the US, is consistent with that pattern. Alongside the low-US risers already noted, several groups skew heavily away from the US:

Alongside the low-US risers already noted, several groups skew heavily away from the US:

Payload ransom group targets the US just 5% of the time

SafePay concentrates on Germany (27%)

Lamashtu leans toward APAC

At the other pole, these groups remain almost exclusively US-focused:

ShinyHunters — 83% US

Play — 83% US

Pear — 79% US

Akira — 78% US

Check Point Software | The State of Ransomware Report - Q2 2026 13Check Point Software | The State of Ransomware Report - Q2 2026 13

060606060606 Geographic Distribution of Victims in Q2 2026

United States 42%

Canada 5%

Germany 5%

UK 3%

Italy 3%

France 3%

Spain 3%

Brazil 2%

Thailand 2%

Australia 2%

Other 30%

Figure 5: Top 10 targeted countries, Q2 2026. Grouped bar chart.

The most notable shift is at the top: the US share fell from 50% to 42% QoQ, an eight-point drop. This is a direct consequence of the reshuffled

leaderboard: several of the quarter's risers target well below the US average (LockBit 10% US, The Gentlemen 25%, KryBit

5%, SafePay 15%), so as they gained share, the ecosystem-wide US concentration diluted.

The Q1 report flagged possible US avoidance

by individual operators, notably LockBit (after Operation Cronos) and The Gentlemen;

Q2's ecosystem-wide dilution, led by operators like KryBit that barely touch the US, is consistent with that pattern. Alongside the low-US risers already

noted, several groups skew heavily away from the US:

Alongside the low-US risers already noted,

several groups skew heavily away from the US:

Payload ransom group targets the US just 5% of the time

SafePay concentrates on Germany (27%)

Lamashtu leans toward APAC

At the other pole, these groups remain almost

exclusively US-focused:

ShinyHunters — 83% US

Play — 83% US

Pear — 79% US

Akira — 78% US

KryBit, newly active to the top 10, is the clearest example of that dynamic. It first surfaced in April 2026 and was classified as an emerging group. It drew early notice for a mid- April feud with the rival 0APT crew: 0APT leaked KryBit's backend and threatened to expose its operators' identities. The panel contained approximately 20 victims in live negotiations, with ransom demands ranging from $40K to $100K. KryBit retaliated by breaching 0APT's servers and exposing that 0APT's claimed 190-plus victims were fabricated. Its Q2 footprint is strikingly global and almost entirely non-US: of 55 claimed victims, just 3 (5%) were in the United States; the rest spread thinly across Latin America, Europe, Asia, and the Middle East with no single country accounting for more than a handful.

Australia rose from 30 to 50 victims (+67% QoQ), entering the top 10. Unlike Q1, where Australian victims were driven largely by Cl0p's Oracle EBS campaign, the Q2 count is broad- based, spread across Qilin (10), INC Ransom (4), Nova (3), and a long tail of groups with two to three victims each. That makes it a more genuine signal of rising activity than a single- campaign artifact.

Check Point Software | The State of Ransomware Report - Q2 2026 14Check Point Software | The State of Ransomware Report - Q2 2026 14

KryBit, newly active to the top 10, is the clearest example of that dynamic. It first surfaced in April 2026 and was classified as an emerging group. It drew early notice for a

mid-April feud with the rival 0APT crew: 0APT leaked KryBit's backend and threatened

to expose its operators' identities. The panel contained approximately 20 victims in

live negotiations, with ransom demands ranging from $40K to $100K. KryBit retaliated by breaching 0APT's servers and

exposing that 0APT's claimed 190-plus

victims were fabricated. Its Q2 footprint is strikingly global and almost entirely non-US: of 55 claimed victims, just 3 (5%) were in the United States; the rest spread thinly across Latin America, Europe, Asia,

and the Middle East with no single country accounting for more than a handful.

Australia rose from 30 to 50 victims (+67%

QoQ), entering the top 10. Unlike Q1, where

Australian victims were driven largely by Cl0p's

Oracle EBS campaign, the Q2 count is broad-based, spread across Qilin (10), INC Ransom (4), Nova (3), and a long tail of groups with two to three victims each. That makes

it a more genuine signal of rising activity than a single-campaign artifact.

070707070707 Ransomware Attacks 
 by Industry in Q2 2026

Ransomware victims in Q2 2026 spanned every major sector, though targeting remained concentrated at the top. Business Services led at 33% of victims, more than twice the share of the next-largest sector, followed by Consumer

Goods & Services (16%) and Industrial Manufacturing (12%); the remaining victims were distributed across the rest of the sector taxonomy in smaller numbers.

Business Services

16%Consumer Goods & Services

12%Industrial Manufacturing

6%Financial Services

6%Healthcare & Medical

5%Government

4%Information Technology

4%Education

3%Transportation & Logistics

3%Automotive

2%Real Estate

2%Media & Entertainment

2%Energy & Utilities

1%Construction & Engineering

Figure 6: Ransomware victims by industry, Q2 2026.

33%

At the actor level, one group stands apart: Pear has leaned toward Healthcare across several quarters (12% this quarter, and as high as 40% in Q4 2025).

Check Point Software | The State of Ransomware Report - Q2 2026 15Check Point Software | The State of Ransomware Report - Q2 2026 15

070707070707 Ransomware Attacks

by Industry in Q2 2026

Business Services 33%

Consumer Goods & Services 16%

Industrial Manufacturing 12%

Financial Services 6%

Healthcare & Medical 6%

Government 5%

Information Technology 4%

Education 4%

Transportation & Logistics 3%

Automotive 3%

Real Estate 2%

Media & Entertainment 2%

Energy & Utilities 2%

Construction & Engineering 1%

Figure 6: Ransomware victims by industry, Q2 2026.

Ransomware victims in Q2 2026 spanned every

major sector, though targeting remained

concentrated at the top. Business Services led at 33% of victims, more than twice the share

of the next-largest sector, followed by Consumer

Goods & Services (16%) and Industrial

Manufacturing (12%); the remaining victims were distributed across the rest of the

sector taxonomy in smaller numbers.

At the actor level, one group stands apart: Pear has leaned toward Healthcare

across several quarters (12% this quarter, and as high as 40% in Q4 2025).

080808080808 Closing the Gap
 Attackers Are Exploiting

Q2 2026 did not hand defenders a single dramatic headline so much as a set of quieter shifts that matter just as much. The ecosystem stayed concentrated even as its tail widened, with 93 active groups now sharing a market where the top 10 still account for well over half of all victims. The Gentlemen leak showed, from the inside, that a top three global operation can be built by a small core with pre positioned access, an AI assisted toolchain, and an affiliate base willing to do the rest.

ayment rates keep falling even as the dollars paid on chain stay enormous, and law enforcement is now aiming at the shared infrastructure many groups depend on at once rather than chasing individual actors one at a time. The patch window keeps narrowing at the perimeter, and AI is the reason.

Read together, these trends point toward a few concrete priorities:

Treat initial access as the fight that matters most. 
 The Gentlemen leak confirmed what the data already suggested: the group's own pipeline runs on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem. Organizations should assume phishing, credential theft, and exposed remote access points remain the most likely opening move, and defend that opening move accordingly rather than concentrating resources on later stages of an attack.

Plan for data theft, not just encryption. With payment rates down to roughly 23% and tested backups increasingly defeating ransomware on the encryption side, operators are leaning harder into exfiltration first extortion, where a clean backup restore offers no protection at all. Detection and prevention around data leaving the network deserve the same weight traditionally given to backup and recovery.

Shrink the exposure that ransomware groups can actually reach. 
 The narrowing gap between vulnerability disclosure and exploitation, now measured in hours rather than weeks, means that remediation speed on the assets attackers can realistically reach has become one of the more decisive factors in whether an incident turns into a breach.

Check Point Software | The State of Ransomware Report - Q2 2026 16Check Point Software | The State of Ransomware Report - Q2 2026 16

080808080808 Closing the Gap Attackers Are Exploiting

Q2 2026 did not hand defenders a single dramatic

headline so much as a set of quieter shifts that

matter just as much. The ecosystem stayed concentrated even as its tail widened, with 93 active

groups now sharing a market where the top 10 still account for well over half of all victims.

The Gentlemen leak showed, from the inside, that a

top three global operation can be built by a small

core with pre positioned access, an AI assisted

toolchain, and an affiliate base willing to do the rest.

ayment rates keep falling even as the dollars

paid on chain stay enormous, and law

enforcement is now aiming at the shared

infrastructure many groups depend on at once

rather than chasing individual actors one at a time. The patch window keeps narrowing at the

perimeter, and AI is the reason.

Read together, these trends point toward a few

concrete priorities:

Treat initial access as the fight that matters most.

The Gentlemen

leak confirmed what the data already

suggested: the group's own pipeline runs on VPN scanning, brute forcing,

and brokered credentials, the same route used across most of the ecosystem. Organizations should assume phishing,

credential theft, and exposed remote access points remain the most likely opening move, and defend that opening move accordingly rather than concentrating resources on later stages of an attack.

Plan for data theft, not just encryption. With payment rates down

to roughly 23% and tested backups increasingly defeating ransomware on the

encryption side, operators are leaning harder into exfiltration first extortion,

where a clean backup restore offers no protection at all. Detection and prevention around data leaving the network deserve the same weight traditionally given to backup and recovery.

Shrink the exposure that ransomware groups can actually reach.

The narrowing gap between vulnerability

disclosure and exploitation, now measured in hours rather than weeks, means that

remediation speed on the assets attackers

can realistically reach has become one of the more decisive factors in whether an incident

turns into a breach.

Recognize that AI has lowered the barrier to entry on both sides. 
 The Gentlemen's admin built a management panel in three days using AI coding tools, and the report notes that same acceleration is showing up in how quickly disclosed vulnerabilities get weaponized. Defenses that still run on a human review cycle are working against tooling that no longer waits for one.

Assume infrastructure disruption is one part of the picture, not the whole of it. 
 This quarter's law enforcement actions against laundering platforms, signing services, and infostealer infrastructure raise cost and friction across many groups at once, but DLS volume did not fall in Q2. Organizations should treat these takedowns as a tailwind rather than a substitute for their own controls.

Check Point Software | The State of Ransomware Report - Q2 2026 17Check Point Software | The State of Ransomware Report - Q2 2026 17

Recognize that AI has lowered the barrier to entry on both sides. The Gentlemen's admin built a

management panel in three days using AI

coding tools, and the report notes that same acceleration is showing up in

how quickly disclosed vulnerabilities get weaponized. Defenses

that still run on a human review cycle are working against tooling that no longer waits for one.

Assume infrastructure disruption is one part of the picture, not the whole of it. This quarter's law enforcement actions

against laundering platforms, signing services, and infostealer infrastructure

raise cost and friction across many groups at once, but DLS volume did not fall in Q2.

Organizations should treat these takedowns as a tailwind rather than a substitute for

their own controls.

090909090909 How Check Point 
 Addresses These Findings

Workspace Security:
 protecting users as a primary entry point

Most of what this report documents starts with a person: a phishing email, a malicious link, a set of stolen credentials feeding into the same brute force and brokered access pipeline that groups like The Gentlemen rely on.

Workspace Security protects users across email, browsers, SaaS applications, and endpoints

The platform prevents credential abuse, disrupts command and control activity, and limits lateral movement and data exfiltration

AI driven detection and global threat intelligence stop ransomware delivery before execution

Unified, automated protection helps organizations contain an attack before it spreads or reaches the point of encryption

Hybrid Mesh Network Security (HMNS):
 stopping ransomware at the network and access layer

With attacks continuing daily and early prevention remaining the cheapest form of defense, Hybrid Mesh Network Security applies consistent, AI driven controls across every connectivity point.

Network firewalls block ransomware, zero day exploits, phishing, and malicious files before they reach devices

SASE Internet Access closes off malicious downloads at the connection point itself

CASB scans data at rest across SaaS platforms such as Salesforce, OneDrive, SharePoint, Google Drive, and Slack, catching malware that enters outside the traditional network perimeter, the same route increasingly used by initial access brokers

If a compromise does occur, Zero Trust access through SASE Private Access limits the blast radius, so ransomware can only reach the data the compromised user was ever authorized to touch, directly addressing the lateral movement pattern this report highlights

Check Point Software | The State of Ransomware Report - Q2 2026 18Check Point Software | The State of Ransomware Report - Q2 2026 18

090909090909 How Check Point

Addresses These Findings

Most of what this report documents starts with a person: a phishing email, a malicious link, a set of

stolen credentials feeding into the same brute force and brokered access pipeline that groups like The

Gentlemen rely on.

Workspace Security protects users across

email, browsers, SaaS applications, and

endpoints

AI driven detection and global threat

intelligence stop ransomware delivery before execution

The platform prevents credential abuse,

disrupts command and control activity, and limits lateral movement and data exfiltration

Unified, automated protection helps

organizations contain an attack before it

spreads or reaches the point of encryption

Hybrid Mesh Network Security (HMNS): stopping ransomware at the network and access layer

With attacks continuing daily and early prevention remaining the cheapest form of defense, Hybrid Mesh

Network Security applies consistent, AI driven controls across every connectivity point.

Network firewalls block ransomware, zero

day exploits, phishing, and malicious files before they reach devices

If a compromise does occur, Zero Trust

access through SASE Private Access limits

the blast radius, so ransomware can only

reach the data the compromised user was

ever authorized to touch, directly addressing the lateral movement

pattern this report highlights

SASE Internet Access closes off malicious

downloads at the connection point itself

CASB scans data at rest across SaaS

platforms such as Salesforce, OneDrive,

SharePoint, Google Drive, and Slack, catching malware that enters outside the traditional

network perimeter, the same route

increasingly used by initial access brokers

Workspace Security: protecting users as a primary entry point

Exposure Management (EM):
 reducing ransomware exposure before exploitation

As the window between disclosure and exploitation keeps narrowing, the question is no longer just what vulnerabilities exist but which ones ransomware groups can actually reach and use.

Exposure Management identifies the external assets, misconfigurations, and access paths that are realistically exploitable

The same report found that critical exposures can realistically be resolved in under an hour: Utilities-sector organizations using Check Point Exposure Management led the field, resolving 30% of critical exposures within that window, the fastest of any industry measured

Correlating that picture with live ransomware intelligence lets security teams focus remediation on the risks that matter rather than the full list of theoretical ones

Validating which controls can safely close a given path lets teams act preemptively, which matters most in an environment where AI has compressed the time available to respond

Check Point's 2026 Exposure Gap Report found that vulnerabilities now account for 42.6% of all critical exposures, more than double their 18.7% share the year before, confirming that this is where exploitable risk is concentrating fastest

AI Security: securing the same AI tooling ransomware groups are learning to exploit

The Gentlemen leak offered rare, first party confirmation that AI tooling is already part of how ransomware operations get built, not just how they get discussed.

ThreatCloud AI keeps defenses moving on the same accelerated timeline as AI assisted exploitation, rather than waiting on a human review cycle to catch up

Check Point AI Agent Security governs the same kind of agent permissions and configuration files that let an admin like Zeta88 build tooling in days, closing off that path into an organization's own AI infrastructure Workforce AI Security gives visibility into the

AI tools employees are actually using, and stops credentials, source code, and customer data from leaking through them, the same category of exposure that ultimately feeds the initial access brokers supplying ransomware affiliates

AI Red Teaming tests an organization's AI applications and agents for jailbreaks and excessive permissions before deployment, so internal AI tooling never becomes the easiest way in

Check Point Software | The State of Ransomware Report - Q2 2026 19

Exposure Management (EM): reducing ransomware exposure before exploitation

AI Security: securing the same AI tooling ransomware groups are learning to exploit

Check Point Software | The State of Ransomware Report - Q2 2026 19

As the window between disclosure and exploitation keeps narrowing, the question is no longer just what

vulnerabilities exist but which ones ransomware groups can actually reach and use.

Exposure Management identifies the

external assets, misconfigurations, and

access paths that are realistically exploitable

Correlating that picture with live ransomware intelligence lets security teams focus remediation on the risks that

matter rather than the full list of theoretical ones

Check Point's 2026 Exposure Gap

Report found that vulnerabilities now

account for 42.6% of all critical exposures, more than double their 18.7% share

the year before, confirming that this

is where exploitable risk is concentrating fastest

The same report found that critical

exposures can realistically be resolved in under an hour: Utilities-sector organizations using Check Point Exposure

Management led the field, resolving

30% of critical exposures within that window, the fastest of any industry measured

Validating which controls can safely close a given path lets teams act preemptively, which matters most in an

environment where AI has compressed

the time available to respond

The Gentlemen leak offered rare, first party confirmation that AI tooling is already part of how ransomware operations get built, not just how they get discussed.

ThreatCloud AI keeps defenses moving on the same accelerated timeline as AI

assisted exploitation, rather than waiting on a human review cycle to catch up

Workforce AI Security gives visibility into the AI tools employees are actually using,

and stops credentials, source code,

and customer data from leaking through them, the same category of exposure that ultimately feeds the initial access brokers supplying ransomware affiliates

Check Point AI Agent Security governs the

same kind of agent permissions and

configuration files that let an admin like Zeta88 build tooling in days, closing off that path into an organization's own AI infrastructure

AI Red Teaming tests an organization's AI

applications and agents for jailbreaks and

excessive permissions before deployment, so

internal AI tooling never becomes the easiest way in

© 2026 Check Point Software Technologies Ltd. All rights reserved.© 2026 Check Point Software Technologies Ltd. All rights reserved.


Item Type: pdf