Follow ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- Ransomware may not be on the decline after all, according to new research.
- A single ransomware campaign’s success can distort the historical data.
- Ransomware remains a threat that business leaders must continue to defend against.
If it looked like ransomware was on the decline last year, research from multiple cybersecurity firms sheds new light on that idea.
Previous reports suggested that ransomware extortion attempts declined in 2025, replaced by techniques such as process injection, credential theft, and virtualization- or sandbox-evasion-based attacks. But more recent second-quarter 2026 reports suggest that vigilance against such extortion attempts remains as important as ever.
Before we dig deeper into the research data, let’s review the nature of the threat.
What is ransomware?
Ransomware is a malicious software, aka malware, that can be spread across networks, computer systems, and endpoint devices. Once ransomware infiltrates your system, it can encrypt files and connected drives. Criminals behind a ransomware attack will demand payment in return for a decryption key — which may or may not work.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
In recent years, threat actors have turned to ransomware to target enterprises, often demanding millions of dollars and pressuring victims to pay to restore business operations. To further pile on the pressure, some cybercriminals will steal corporate data ahead of encryption and will threaten their victims with posting stolen information online unless payment is made.
Ransomware-as-a-Service (RaaS) has expanded the scope of these attacks, with some criminals developing and licensing ransomware tools that others use to target individuals and businesses alike.
Ransomware data: Does it tell the full story?
According to NCC Group’s second-quarter cyber threat intelligence report (.PDF), in Q2 2026, global ransomware attacks increased by 3% over the previous quarter. In total, NCC Group recorded 2,229 ransomware attacks, compared to 2,165 in Q1 2026, which in turn saw a 3% decrease (.PDF) from Q4 2005.
Qilin was the most active ransomware group for the 5th quarter in a row, accounting for 301 victims in Q2 2026 alone. This threat actor was followed by The Gentlemen, with 238 victims, and Dragonforce, with 145 victims. A new player also entered the ransomware cybercriminal top 10 list: RaaS service KryBi has been linked to 56 victims during Q2.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
Let’s compare this with Check Point data.
In Q1 2026, Check Point researchers identified 2,122 new victims, a 12.2% decline from Q4 2025 and a 7.1% decline from 2,285 victims in Q1 2025 — but there’s more to come on this last statistic.
So, did ransomware rates really potentially drop, only to pick up again in 2026? When we consider the question, there is one major cybercriminal group we need to account for.
Enter Cl0P.
Cl0P was the most prolific ransomware actor in Q1 2025, accounting for roughly 390 victims in a single February campaign. Overall, Check Point recorded 2,289 victims in the quarter, an increase of 126% compared to Q1 2024.
“Even when discounting the 300 victims attributed to Cl0P’s mass February disclosure related to its exploitation of the Cleo file transfer platform, the numbers remain historically high,” the cybersecurity firm said.
Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
Check Point recorded 629 ransomware attacks in February 2026 (a single month rather than a quarter), reflecting a 32% year-over-year decrease, but this drop was primarily due to the inflated rate in February 2025 driven by Cl0P’s activities.
NCC Group’s previous reports (.PDF) showed similar figures, with a total of 1180 attacks recorded in Q2 2025, a decline of 43% from Q1 2025, which was partially attributed to law enforcement disrupting Cl0P and other major ransomware operators.
A ransomware industry reshuffle?
In other words, if we remove Cl0P from the equation, the baseline percentages suggest a different reality. In a follow-up analysis of Q1 2025 to Q1 2026, Check Point said that Q1 2025 numbers were heavily inflated by Cl0P’s Cleo mass-exploitation campaign, which transforms the previously mentioned 7.1% decline into an actual increase of 5.3% if we remove the Cl0P entry from both periods.
“If we exclude Cl0P from both periods, there were 1,894 victims in Q1 2025 versus 1,995 in Q1 2026, an actual YoY increase of 5.3%. The underlying growth trend in ransomware operations persists, even as the most dramatic spikes subside,” the researchers said.
So, here are some figures to consider:
- NCC Group reports a Q1 2026 3% decrease and a Q2 2026 3% increase
- Check Point reports a Q1 2025 5.3% increase, and a 33% increase, comparing June 2025 to June 2026.
Also: 5 ways to fortify your network against the new speed of AI attacks
This isn’t to suggest any of these figures are incorrect. Rather, a single threat group or attack can inflate baseline numbers, potentially impacting “increasing” or “declining” rates in future quarters. With groups like Qilin and The Gentlemen now taking over amid Cl0P’s reduced activity of late, it may be that ransomware rates never really declined — the ransomware industry was just undergoing a reshuffle.
We may see more drastic shifts in this industry soon, too, as highlighted by the first fully agentic AI ransomware attack, recorded earlier this month. According to Black Kite, low- and mid-tier ransomware attackers are already using AI to streamline the attack model, as “more stages of the operation can now be assisted, chained, or accelerated by AI.”
With AI becoming a weapon for ransomware groups to automate the attack process, we could see a rate increase in the coming quarters — especially if ransomware-as-a-service (RaaS) groups start employing AI models.
Defense advice for your organization
If we assume the worst — that ransomware attacks are not in decline at all — how should your business prepare for the worst? Cybersecurity experts make the following four recommendations:
Also: Best VPN services: Expert tested and recommended
- VPNs: NCC Group’s latest report suggests that ransomware groups are increasingly targeting corporate VPNs. VPNs are necessary for many businesses today, so ensure that employee credentials are secure and rotated frequently, and that software is kept up to date.
- Firewalls: Firewalls, too, are frequently targeted. Monitor them, check configurations and rules for any security gaps, and investigate suspicious activity.
- Patch cycles: While not every vulnerability discovered will impact your organization, maintaining a frequent patch cycle and triaging risks can mitigate the risk of exploitation.
- Enable multi-factor authentication: Stolen credentials are a preferred way for threat actors to quietly infiltrate corporate networks. Deploying 2FA/MFA requirements adds an additional layer of security to employee accounts. Even if a password is leaked, this doesn’t mean an account is immediately compromised.
“Threat intelligence, whether done internally or provided by a third party, is also invaluable in assisting defenders as it can alert teams to vulnerabilities and trends in attacker behavior before they are targeted,” the NCC Group added.


