ransomware research center
The definitive record of modern ransomware.
Home to the award-winning State of Ransomware report and the research behind it. Six years of tracked attacks, threat-actor analysis, and the data journalists and security teams cite worldwide.
The State Of Ransomware
UPDATED QUARTERLY
Q2 2026 attacks tracked
Undisclosed attacks
2027
Disclosed attacks
306
Only 1 in 8 attacks is ever made public.
Attacks ending in exfiltration
97%
Most active group
Qilin
q2 2026 at a glance
306
publicly disclosed ransomware attacks in Q2 2026, level with Q2 2025 after five years of growth.
97%
of disclosed attacks ended in data exfiltration – the highest rate ever recorded.
1 in 8
attacks is ever made public. We identified 2,027 undisclosed attacks in Q2 2026 alone.
$25M
largest disclosed ransom demand of the quarter, made against Novo Nordisk.
The State Of Ransomware
Our analysts track every publicly disclosed attack and model the far larger undisclosed volume from anonymized endpoint telemetry across hundreds of organizations. Published quarterly, tracked continuously since 2020.
Quarterly disclosed & undisclosed attack volumes
Threat-actor rankings and emerging variants
Sector and geographic breakdowns

Most-targeted sectors
Share of disclosed attacks, Q2 2026
Healthcare
26%
Services
15%
Government
10%
Technology
9%
Education
8%
Manufacturing
8%
Most active ransomware groups
Undisclosed attacks, Q2 2026 · 93 active groups
01 Qilin
285
02 The Gentlemen
219
03 DragonForce
137
04 Akira
120
method
Figures are drawn from the BlackFog Console over a quarterly report period, from publicly disclosed incidents, and from continuous monitoring of ransomware leak sites. Industry classifications follow the ICB Supersector standard used by the NYSE. All events are based on data exfiltration observed at the device endpoint across major platforms.
The report portfolio
One dataset, three cadences.
The same tracking pipeline feeds a definitive annual, a quarterly deep-dive on emerging actors, and a monthly attack log. Read at the depth you need.
State of Ransomware
The definitive year in review: full-year volumes, exfiltration rate, sector and country breakdowns, and the trends shaping the year ahead.
1174
attacks tracked
130
groups profiled
DEEP-DIVE
Quarterly Threat Report
Focused analysis of emerging variants, threat-actor movements, and the tactics defining the quarter.
Q2
latest, 2026
1 in 8
made public
LIVE
Monthly Tracker
Every publicly disclosed attack, logged and analyzed as it happens. Six years of continuous coverage.
72
monthly editions
2020
reporting started
THREAT ACTOR INDEX
Know the groups behind the numbers.
Profiles of the ransomware operators our analysts track most closely, drawn directly from the report dataset. Updated as the landscape shifts.
Quilin
aka Agenda
First seen
2022
Attacks, Q2 ’26
285
Top sectors
Healthcare · Manufacturing
Most active group of the quarter on leak sites, and second by disclosed attacks with 19.
The Gentlemen
emerged 2025
First seen
2025
Attacks, Q2 ’26
219
Top sectors
Manufacturing · Construction
Second by leak-site volume, sustaining the pace set since its 2025 debut.
DragonForce
affiliate model
First seen
2023
Attacks, Q2 ’26
137
Top sectors
Services · Retail
Third by leak-site volume in Q2 2026, up sharply on the previous quarter.
Shiny Hunters
extortion crew
First seen
2020
Attacks, Q2 ’26
28
Top sectors
Retail · Education
Led all attributed disclosed attacks. Behind the Canvas breach and the Q2 retail campaign.
Akira
Megazord-linked
First seen
2023
Attacks, Q2 ’26
120
Top sectors
Manufacturing · Construction
Sustained double-extortion operator with fast encryption.
Settra
emerged June 2026
First seen
2026
Attacks, Q2 ’26
22
Top sectors
Manufacturing · Technology
22 victims across seven countries in its first four days, half with proof of compromise.
explore the research
Everything we know about modern ransomware.
Double Extortion
How attackers steal data first, then encrypt, so backups alone no longer end the threat.
Threat Actors & Gangs
Profiles of Qilin, The Gentlemen, DragonForce and the 94 groups shaping the landscape.
Data Exfiltration
The theft step behind 97% of attacks, and why the endpoint is where it must be stopped.
Ransomware-as-a-Service
How affiliate models and leak sites industrialized extortion at global scale.
Sector & Geography
Where attacks concentrate, from healthcare and services to 98 countries worldwide.
Recovery & Response
What effective prevention looks like when paying the ransom cannot undo a leak.
from the research desk
Ransomware, as it happens.
- Categories: Cybersecurity, Data Exfiltration, Research, Technology
Integrating Anti Data Exfiltration (ADX) solutions is essential for enterprise cybersecurity. This article examines how BlackFog's ADX enhances existing technologies by focusing on prevention and the shift-left paradigm. It illustrates ADX's effectiveness against ransomware and its support for modern managed security service providers, demonstrating how ADX integration creates a comprehensive security solution.
- Categories: Cybersecurity, Data Exfiltration, Research, Technology
Integrating Anti Data Exfiltration (ADX) solutions into an enterprise is crucial for effective cybersecurity. This article examines how BlackFog's commercial ADX solution enhances existing detection and response technologies by focusing on prevention and the shift-left paradigm. Using ransomware threats as an example, we illustrate how ADX mitigates device risks in typical business environments. Additionally, we explore how ADX supports the evolving needs of modern managed security service providers, ensuring comprehensive and proactive security measures.
- Categories: Cybersecurity, Data Exfiltration, Research, Technology
Implementing Anti Data Exfiltration (ADX) solutions is critical for enterprise security. This article provides guidance on establishing effective ADX deployment policies, with a focus on aligning them with business objectives and threat perceptions. Highlighting BlackFog's ADX solution, it explores proactive strategies to prevent data exfiltration, offering valuable insights for practitioners aiming to enhance their security posture.
cited worldwide
“Attackers aren’t just breaking in – they’re intent on stealing data to power extortion.”
The State of Ransomware is referenced across national press and the security industry, and has earned Gold at the Globee Awards for outstanding research contributions.
Reuters
National press
TechRepublic
Industry
Cybersecurity Breakthrough
Award
Globee Awards
Gold, research
common questions
Ransomware, answered.
BlackFog focuses on the exfiltration step. ADX runs on the endpoint and blocks the unauthorized outbound transfer of data in real-time, by behavior rather than signatures. Stopping the theft removes the leverage behind double extortion before encryption or an extortion demand can follow.
Healthcare was the most-targeted sector in Q2 2026 at 26% of disclosed attacks (81 incidents), followed by services (15%) and government (10%). The United States absorbed 55% of disclosed incidents and Australia 18%, with organizations across 98 countries hit in total, underscoring ransomware’s global reach.
Only about 1 in 8 attacks ever becomes public. In Q2 2026 alone we identified 2,027 undisclosed attacks against 306 disclosed — 2,333 in total, of which 87% never surfaced publicly. We identify the undisclosed volume through continuous monitoring of ransomware leak sites.
In our Q2 2026 research, 97% of publicly disclosed ransomware attacks involved data exfiltration, the highest rate we have ever recorded. Data theft, not encryption, is now the primary source of leverage in an attack.
Double extortion is the now-dominant model in which attackers first exfiltrate sensitive data, then encrypt systems, and finally threaten to publish or sell the stolen data. Because the information is already gone, restoring from backup no longer removes the threat, which is why 97% of attacks now involve data theft.
STAY AHEAD OF THE CURVE
