Ransomware activity remained stubbornly high in the second quarter of 2026, with 2,139 victims reported on data leak sites—largely unchanged from Q1 but 33% higher year over year. However, new research suggests the bigger shift is happening beneath the headline numbers, with ransomware becoming more fragmented and increasingly reliant on data theft and AI-assisted tooling.
According to research from Check Point Research, the number of active ransomware groups rose from 71 in Q1 to 93 in Q2, the highest level recorded. At the same time, the market became less concentrated, with the top 10 groups accounting for 57.6% of reported victims, compared with 71% in the previous quarter.
Qilin remained the most active group for the fourth consecutive quarter, recording 279 victims. The Gentlemen followed closely, with its victim count increasing 62% during the quarter and surpassing Qilin in June.
Smaller teams, bigger impact
One of the most significant revelations came from leaked backend data and chat logs belonging to The Gentlemen ransomware operation. The material provided researchers with an unusual look into how a high-performing ransomware group operates.
The operation reportedly had a core team of around nine people, supported by a broader network of affiliates responsible for carrying out intrusions. The group’s administrator, known as Zeta88, reportedly used AI coding assistants to build its ransomware management panel in approximately three days.
While the research does not suggest AI is independently conducting ransomware attacks, it demonstrates how AI coding tools can accelerate the development of criminal infrastructure. More importantly, the findings point to a lower barrier to entry for technically capable individuals looking to establish ransomware operations.
The Gentlemen reportedly reached the upper tier of the ransomware ecosystem within months, highlighting how the threat landscape is becoming increasingly accessible to smaller, highly skilled groups.
Data theft takes centre stage
The changing economics of ransomware are also influencing attacker behaviour.
Ransom payment rates have declined for six consecutive years, falling from around 85% in 2019 to approximately 23% today. Improvements in backup and recovery capabilities have made encryption less effective as a standalone extortion mechanism.
Data theft, however, remains difficult for organisations to neutralise through recovery alone. Once sensitive information has been exfiltrated, restoring systems does little to prevent attackers from publishing or selling the stolen data.
As a result, ransomware operators are increasingly adopting exfiltration-first extortion, placing greater emphasis on stealing data before or instead of encrypting systems.
Despite lower payment rates, the financial impact remains substantial. On-chain ransomware payments exceeded $820 million in 2025, according to Chainalysis.
Initial access remains a critical weakness
The research also highlights the continued importance of initial access. The Gentlemen’s operation reportedly relied on techniques including VPN scanning, brute-forcing and compromised credentials—methods that remain common across the ransomware ecosystem.
For organisations, this reinforces the need to strengthen exposed remote access, identity controls and phishing protection while improving visibility into unusual data transfers and potential exfiltration.
The findings also point to the need for faster vulnerability remediation. As attackers increasingly automate parts of their operations, organisations operating on slow, manual security processes risk losing valuable response time.
A more fragmented ransomware ecosystem
The Q2 numbers suggest that ransomware is not necessarily declining—it is spreading across a broader ecosystem of groups.
While major operators such as Qilin continue to dominate, the rise in active groups indicates a more distributed threat landscape. Disruptions to individual ransomware groups may therefore have a limited impact if affiliates, infrastructure and criminal services can quickly migrate to other operations.
For security leaders, this means defending against ransomware requires more than tracking the biggest groups. Organisations need to focus on the techniques that underpin the wider ecosystem: preventing initial access, protecting identities, detecting data exfiltration and reducing exploitable exposure.
The second quarter’s numbers ultimately point to a ransomware landscape that is becoming more fragmented, more efficient and harder to disrupt through targeting individual groups alone. As attackers make greater use of automation and AI-assisted development, organisations will need to shorten the gap between exposure, detection and response to keep pace.






Discussion about this post