Ransomware Landscape Shifts as Active Groups Rise and Payment Rates Decline in Q2 2026

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The ransomware landscape is undergoing a notable transformation, as highlighted in the latest State of Ransomware Q2 2026 report from Check Point Research. While the conversation over the past year has largely focused on a few dominant Ransomware-as-a-Service (RaaS) operations, the current findings indicate a shift towards a more diverse ecosystem. Although the leading groups continue to exert significant influence, the barriers to entry for new players have diminished, resulting in a broader array of active groups competing for victims.

Shifting Dynamics in Ransomware Operations

The report reveals that the concentration of ransomware activity remains high, but the number of active groups has surged from 71 to 93, marking a new peak for the period tracked. The top ten ransomware groups accounted for 57.6% of all victims in Q2 2026, a decrease from 71% in the previous quarter. This widening tail suggests that while established players like Qilin and The Gentlemen still dominate, new entrants are beginning to carve out their share of the market.

Victim volume has remained stable, with data leak sites reporting 2,139 victims in Q2, reflecting a slight increase of 0.8% from Q1 and a significant 33% rise year-over-year. This consistency in victim numbers indicates that ransomware remains a persistent threat, maintaining the high levels seen throughout 2025.

Emerging Competitors and AI Integration

The competition between Qilin and The Gentlemen has intensified, with Qilin retaining its position as the most prolific operator for the fourth consecutive quarter, albeit with a 17% decline in victim count to 279. In contrast, The Gentlemen experienced a remarkable 62% increase, reaching 269 victims and even surpassing Qilin in June. An internal leak from The Gentlemen provided unprecedented insights into their operations, revealing a core team of approximately nine operators supported by a wider affiliate network. Notably, the group utilized AI coding assistants to develop their ransomware management panel in just three days, showcasing how AI is accelerating the development of malicious tools.

Despite the increase in activity, the report notes a significant decline in ransom payment rates, which have fallen to a multi-year low of around 23%. This marks a continued decrease from 85% in 2019. Interestingly, while the median ransom payments are decreasing, the average payments are on the rise, indicating that larger enterprises are still willing to pay substantial sums, while mid-market organizations are increasingly resistant to paying ransoms or opting for smaller settlements.

Law Enforcement and Geographic Trends

Law enforcement agencies have shifted their focus in Q2 2026, targeting shared infrastructure rather than individual groups. This strategy has led to the dismantling of a cryptocurrency laundering platform used by multiple ransomware actors, sanctions against major Iranian digital asset exchanges, and the disruption of malware signing services that several RaaS operations relied upon. Such coordinated efforts aim to undermine the operational capabilities of ransomware groups as a whole.

Geographically, the landscape is also changing. The share of victims in the United States has decreased from 50% to 42% quarter-over-quarter. This decline is attributed to the emergence of groups like The Gentlemen and Krybit, which are less focused on targeting U.S. entities compared to the average within the ecosystem.

As the exploitation window narrows, with vulnerabilities being weaponized within hours to days of disclosure, ransomware operators are gaining an additional advantage in their race to compromise victims. The integration of AI into their operations is likely to further enhance their capabilities, making it imperative for organizations to bolster their defenses against these evolving threats.

For a comprehensive overview of the findings, access the full report from Check Point Research here.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Japan’s Digital Agency Confirms Data Breach Exposing 246,000 Records

In a significant cybersecurity incident, Japan's Digital Agency has confirmed a data breach that exposed approximately 246,000 records. This breach, attributed to a vulnerability...

Canadian Privacy Commissioner Investigates IDScan.net Following Data Breach of 153 Million Driver’s Licenses

Privacy Commissioner of Canada Philippe Dufresne has initiated an investigation into IDScan.net following reports of a significant data breach affecting personal data and scans...

Dubai Government Launches Real-Time Cybersecurity Dashboard in Partnership with Microsoft

The Dubai Electronic Security Center (DESC) has partnered with Microsoft to launch a new Zero Trust assurance dashboard, providing real-time visibility into the cybersecurity...

INS Trishul arrives in Toulon with upgraded BrahMos missile capability

INS Trishul, the Indian Navy’s Talwar-class frigate, arrived at Toulon naval base in France on September 22, 2026, as part of its operational deployment...