Key takeaways
- If it looked like ransomware was on the decline last year, research from multiple cybersecurity firms sheds new light on that idea.
- Before we dig deeper into the research data, let's review the nature of the threat.
- In recent years, threat actors have turned to ransomware to target enterprises, often demanding millions of dollars and pressuring victims…
What happened
If it looked like ransomware was on the decline last year, research from multiple cybersecurity firms sheds new light on that idea. Previous reports suggested that ransomware extortion attempts declined in 2025, replaced by techniques such as process injection, credential theft, and virtualization- or sandbox-evasion-based attacks. But more recent second-quarter 2026 reports suggest that vigilance against such extortion attempts remains as important as ever.
"Even when discounting the 300 victims attributed to Cl0P's mass February disclosure related to its exploitation of the Cleo file transfer platform, the numbers remain historically high," the cybersecurity firm said. Check Point recorded 629 ransomware attacks in February 2026 (a single month rather than a quarter), reflecting a 32% year-over-year decrease, but this drop was primarily due to the inflated rate in February 2025 driven by Cl0P's activities.
PDF) showed similar figures, with a total of 1180 attacks recorded in Q2 2025, a decline of 43% from Q1 2025, which was partially attributed to law enforcement disrupting Cl0P and other major ransomware operators. In other words, if we remove Cl0P from the equation, the baseline percentages suggest a different reality. 3% if we remove the Cl0P entry from both periods. 3%.
With groups like Qilin and The Gentlemen now taking over amid Cl0P's reduced activity of late, it may be that ransomware rates never really declined -- the ransomware industry was just undergoing a reshuffle. We may see more drastic shifts in this industry soon, too, as highlighted by the first fully agentic AI ransomware attack, recorded earlier this month.
" With AI becoming a weapon for ransomware groups to automate the attack process, we could see a rate increase in the coming quarters -- especially if ransomware-as-a-service (RaaS) groups start employing AI models. If we assume the worst -- that ransomware attacks are not in decline at all -- how should your business prepare for the worst?
Why it matters
Before we dig deeper into the research data, let's review the nature of the threat. Ransomware is a malicious software, aka malware, that can be spread across networks, computer systems, and endpoint devices. Once ransomware infiltrates your system, it can encrypt files and connected drives. Criminals behind a ransomware attack will demand payment in return for a decryption key -- which may or may not work.
In recent years, threat actors have turned to ransomware to target enterprises, often demanding millions of dollars and pressuring victims to pay to restore business operations. To further pile on the pressure, some cybercriminals will steal corporate data ahead of encryption and will threaten their victims with posting stolen information online unless payment is made.
Ransomware-as-a-Service (RaaS) has expanded the scope of these attacks, with some criminals developing and licensing ransomware tools that others use to target individuals and businesses alike. PDF), in Q2 2026, global ransomware attacks increased by 3% over the previous quarter. PDF) from Q4 2005. Qilin was the most active ransomware group for the 5th quarter in a row, accounting for 301 victims in Q2 2026 alone.
This threat actor was followed by The Gentlemen, with 238 victims, and Dragonforce, with 145 victims. A new player also entered the ransomware cybercriminal top 10 list: RaaS service KryBi has been linked to 56 victims during Q2. Let's compare this with Check Point data. 1% decline from 2,285 victims in Q1 2025 -- but there's more to come on this last statistic.
So, did ransomware rates really potentially drop, only to pick up again in 2026? When we consider the question, there is one major cybercriminal group we need to account for. Cl0P was the most prolific ransomware actor in Q1 2025, accounting for roughly 390 victims in a single February campaign. Overall, Check Point recorded 2,289 victims in the quarter, an increase of 126% compared to Q1 2024.
What to watch
The underlying growth trend in ransomware operations persists, even as the most dramatic spikes subside," the researchers said. So, here are some figures to consider: This isn't to suggest any of these figures are incorrect. Rather, a single threat group or attack can inflate baseline numbers, potentially impacting "increasing" or "declining" rates in future quarters.



