BlackFog Logo
Ransomware Research Center2026-09-25T16:04:28+01:00

ransomware research center

The definitive record of modern ransomware.

Home to the award-winning State of Ransomware report and the research behind it. Six years of tracked attacks, threat-actor analysis, and the data journalists and security teams cite worldwide.

The State Of Ransomware

UPDATED QUARTERLY

Q2 2026 attacks tracked

Undisclosed attacks

2027

Disclosed attacks

306

Only 1 in 8 attacks is ever made public.

Attacks ending in exfiltration

97%

Most active group

Qilin

q2 2026 at a glance

306

publicly disclosed ransomware attacks in Q2 2026, level with Q2 2025 after five years of growth.

97%

of disclosed attacks ended in data exfiltration – the highest rate ever recorded.

1 in 8

attacks is ever made public. We identified 2,027 undisclosed attacks in Q2 2026 alone.

$25M

largest disclosed ransom demand of the quarter, made against Novo Nordisk.

The State Of Ransomware

Our analysts track every publicly disclosed attack and model the far larger undisclosed volume from anonymized endpoint telemetry across hundreds of organizations. Published quarterly, tracked continuously since 2020.

  • Quarterly disclosed & undisclosed attack volumes

  • Threat-actor rankings and emerging variants

  • Sector and geographic breakdowns

Q2 2026 State of Ransomware Report

Most-targeted sectors
Share of disclosed attacks, Q2 2026

Healthcare

26%

Services

15%

Government

10%

Technology

9%

Education

8%

Manufacturing

8%

Most active ransomware groups
Undisclosed attacks, Q2 2026 · 93 active groups

01 Qilin

285

02 The Gentlemen

219

03 DragonForce

137

04 Akira

120

method

Figures are drawn from the BlackFog Console over a quarterly report period, from publicly disclosed incidents, and from continuous monitoring of ransomware leak sites. Industry classifications follow the ICB Supersector standard used by the NYSE. All events are based on data exfiltration observed at the device endpoint across major platforms.

The report portfolio

One dataset, three cadences.

The same tracking pipeline feeds a definitive annual, a quarterly deep-dive on emerging actors, and a monthly attack log. Read at the depth you need.

State of Ransomware

The definitive year in review: full-year volumes, exfiltration rate, sector and country breakdowns, and the trends shaping the year ahead.

1174

attacks tracked

130

groups profiled

DEEP-DIVE

Quarterly Threat Report

Focused analysis of emerging variants, threat-actor movements, and the tactics defining the quarter.

Q2

latest, 2026

1 in 8

made public

LIVE

Monthly Tracker

Every publicly disclosed attack, logged and analyzed as it happens. Six years of continuous coverage.

72

monthly editions

2020

reporting started

THREAT ACTOR INDEX

Know the groups behind the numbers.

Profiles of the ransomware operators our analysts track most closely, drawn directly from the report dataset. Updated as the landscape shifts.

Quilin

aka Agenda

First seen

2022

Attacks, Q2 ’26

285

Top sectors

Healthcare · Manufacturing

Most active group of the quarter on leak sites, and second by disclosed attacks with 19.

The Gentlemen

emerged 2025

First seen

2025

Attacks, Q2 ’26

219

Top sectors

Manufacturing · Construction

Second by leak-site volume, sustaining the pace set since its 2025 debut.

DragonForce

affiliate model

First seen

2023

Attacks, Q2 ’26

137

Top sectors

Services · Retail

Third by leak-site volume in Q2 2026, up sharply on the previous quarter.

Shiny Hunters

extortion crew

First seen

2020

Attacks, Q2 ’26

28

Top sectors

Retail · Education

Led all attributed disclosed attacks. Behind the Canvas breach and the Q2 retail campaign.

Akira

Megazord-linked

First seen

2023

Attacks, Q2 ’26

120

Top sectors

Manufacturing · Construction

Sustained double-extortion operator with fast encryption.

Settra

emerged June 2026

First seen

2026

Attacks, Q2 ’26

22

Top sectors

Manufacturing · Technology

22 victims across seven countries in its first four days, half with proof of compromise.

explore the research

Everything we know about modern ransomware.

Double Extortion

How attackers steal data first, then encrypt, so backups alone no longer end the threat.

Threat Actors & Gangs

Profiles of Qilin, The Gentlemen, DragonForce and the 94 groups shaping the landscape.

Data Exfiltration 

The theft step behind 97% of attacks, and why the endpoint is where it must be stopped.

Ransomware-as-a-Service 

How affiliate models and leak sites industrialized extortion at global scale.

Sector & Geography 

Where attacks concentrate, from healthcare and services to 98 countries worldwide.

Recovery & Response 

What effective prevention looks like when paying the ransom cannot undo a leak.

from the research desk

Ransomware, as it happens.

cited worldwide

“Attackers aren’t just breaking in – they’re intent on stealing data to power extortion.”

DWDr. Darren Williams, Founder & CEO, BlackFog

The State of Ransomware is referenced across national press and the security industry, and has earned Gold at the Globee Awards for outstanding research contributions.

Reuters

National press

TechRepublic

Industry

Cybersecurity Breakthrough

Award

Globee Awards

Gold, research

common questions

Ransomware, answered.

How does BlackFog stop ransomware?2026-09-01T15:56:17+01:00

BlackFog focuses on the exfiltration step. ADX runs on the endpoint and blocks the unauthorized outbound transfer of data in real-time, by behavior rather than signatures. Stopping the theft removes the leverage behind double extortion before encryption or an extortion demand can follow.

Which sectors and countries are most targeted?2026-09-01T15:54:51+01:00

Healthcare was the most-targeted sector in Q2 2026 at 26% of disclosed attacks (81 incidents), followed by services (15%) and government (10%). The United States absorbed 55% of disclosed incidents and Australia 18%, with organizations across 98 countries hit in total, underscoring ransomware’s global reach.

Why do so many ransomware attacks go unreported?2026-09-01T15:53:41+01:00

Only about 1 in 8 attacks ever becomes public. In Q2 2026 alone we identified 2,027 undisclosed attacks against 306 disclosed — 2,333 in total, of which 87% never surfaced publicly. We identify the undisclosed volume through continuous monitoring of ransomware leak sites.

What share of ransomware attacks involve data exfiltration?2026-09-01T15:52:34+01:00

In our Q2 2026 research, 97% of publicly disclosed ransomware attacks involved data exfiltration, the highest rate we have ever recorded. Data theft, not encryption, is now the primary source of leverage in an attack.

What is double-extortion ransomware?2026-09-01T15:51:26+01:00

Double extortion is the now-dominant model in which attackers first exfiltrate sensitive data, then encrypt systems, and finally threaten to publish or sell the stolen data. Because the information is already gone, restoring from backup no longer removes the threat, which is why 97% of attacks now involve data theft.

STAY AHEAD OF THE CURVE

Get the latest research, as it’s published

Go to Top