The ransomware landscape is undergoing a notable transformation, as highlighted in the latest State of Ransomware Q2 2026 report from Check Point Research. While the conversation over the past year has largely focused on a few dominant Ransomware-as-a-Service (RaaS) operations, the current findings indicate a shift towards a more diverse ecosystem. Although the leading groups continue to exert significant influence, the barriers to entry for new players have diminished, resulting in a broader array of active groups competing for victims.
Shifting Dynamics in Ransomware Operations
The report reveals that the concentration of ransomware activity remains high, but the number of active groups has surged from 71 to 93, marking a new peak for the period tracked. The top ten ransomware groups accounted for 57.6% of all victims in Q2 2026, a decrease from 71% in the previous quarter. This widening tail suggests that while established players like Qilin and The Gentlemen still dominate, new entrants are beginning to carve out their share of the market.
Victim volume has remained stable, with data leak sites reporting 2,139 victims in Q2, reflecting a slight increase of 0.8% from Q1 and a significant 33% rise year-over-year. This consistency in victim numbers indicates that ransomware remains a persistent threat, maintaining the high levels seen throughout 2025.
Emerging Competitors and AI Integration
The competition between Qilin and The Gentlemen has intensified, with Qilin retaining its position as the most prolific operator for the fourth consecutive quarter, albeit with a 17% decline in victim count to 279. In contrast, The Gentlemen experienced a remarkable 62% increase, reaching 269 victims and even surpassing Qilin in June. An internal leak from The Gentlemen provided unprecedented insights into their operations, revealing a core team of approximately nine operators supported by a wider affiliate network. Notably, the group utilized AI coding assistants to develop their ransomware management panel in just three days, showcasing how AI is accelerating the development of malicious tools.
Despite the increase in activity, the report notes a significant decline in ransom payment rates, which have fallen to a multi-year low of around 23%. This marks a continued decrease from 85% in 2019. Interestingly, while the median ransom payments are decreasing, the average payments are on the rise, indicating that larger enterprises are still willing to pay substantial sums, while mid-market organizations are increasingly resistant to paying ransoms or opting for smaller settlements.
Law Enforcement and Geographic Trends
Law enforcement agencies have shifted their focus in Q2 2026, targeting shared infrastructure rather than individual groups. This strategy has led to the dismantling of a cryptocurrency laundering platform used by multiple ransomware actors, sanctions against major Iranian digital asset exchanges, and the disruption of malware signing services that several RaaS operations relied upon. Such coordinated efforts aim to undermine the operational capabilities of ransomware groups as a whole.
Geographically, the landscape is also changing. The share of victims in the United States has decreased from 50% to 42% quarter-over-quarter. This decline is attributed to the emergence of groups like The Gentlemen and Krybit, which are less focused on targeting U.S. entities compared to the average within the ecosystem.
As the exploitation window narrows, with vulnerabilities being weaponized within hours to days of disclosure, ransomware operators are gaining an additional advantage in their race to compromise victims. The integration of AI into their operations is likely to further enhance their capabilities, making it imperative for organizations to bolster their defenses against these evolving threats.
For a comprehensive overview of the findings, access the full report from Check Point Research here.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.


