Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Landscape Fractures as New Groups Proliferate

City street with busy storefronts and office buildings, hinting at disruption.

“We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half.”

Rapid growth: more than one new ransomware group each week

The Black Kite Ransomware Report 2026, published on July 21, found 146 active ransomware groups that had publicly announced at least one victim, measured as of June 2026. That total marks a sharp rise from 105 active operations a year earlier. According to Black Kite, 2026 alone produced 61 new ransomware groups — the equivalent of more than one new operation every week.

Concentration amid fragmentation: a few dominate most victims

Despite the multiplication of groups, a small number of operations still account for a disproportionate share of visible harm. Between March 2025 and March 2026, 7,551 publicly disclosed victims were attributed to ransomware, and the top five operations were responsible for almost half of those cases — 44% in total. That five-pack was led by Qilin (1,358 claimed victims), followed by Akira (749), INC Ransom (436), Play (422) and SafePay (324).

The report listed 19 operations that claimed the most victims during that period, ranging from Qilin’s more-than-1,000 victims down to Rhysida with 80 victims. Black Kite also reported a combined total of 108 threat actors accounting for 1,918 confirmed attacks in the examined window.

The churn: short lifespans, fast turnover

Black Kite’s analysis shows the criminal ecosystem is not only expanding but also becoming more transient. The average lifespan of an active ransomware group in the report stood at 4.9 months — a substantial contraction from “over a year” in 2024. The pattern described by Ferhat Dikbiyik, chief research and intelligence officer at Black Kite, is a marketplace that both welcomes new entrants and sees operators disappear quickly, changing the overall shape of the ransomware landscape.

How attackers gain entry: critical vulnerabilities and initial access

The report highlights common vectors used across many disparate groups. Notably, vulnerabilities rated with a CVSS score of 9 or higher — classified as critical — were exploited to gain initial access in 44% of attacks. Black Kite’s recommendation is explicit: organizations should prioritize patching operating systems and software as soon as possible after new vulnerabilities emerge, with special attention to those scoring 9 or above on the CVSS scale.

Beyond patch cadence, Black Kite advised strengthening identity controls and processes that can close other common pathways used by extortion actors. The report specifically recommends improving identity verification, help desk escalation paths, employee reporting, vendor verification, and controls against executive impersonation.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: The data underlines a two-track problem — a flood of new, short-lived groups and a small set of prolific operators. Teams will need rapid patch management for high-CVSS flaws and bolstered identity and help-desk controls to reduce initial access opportunities, as Black Kite recommends.
  • Policymakers and regulators: The rapid emergence of groups and the concentration of victims among a few operators create competing policy priorities: accelerate vulnerability disclosure and patching practices while targeting resources at the most impactful operators, whose activity accounts for a large portion of disclosed victims.
  • Affected enterprises and procurement leaders: With 44% of attacks beginning via critical vulnerabilities and with several groups claiming large numbers of victims, procurement and vendor verification processes gain urgency. Black Kite’s advice to tighten vendor verification and help-desk escalation points directly addresses documented attack pathways.

The Black Kite report sketches a ransomware ecosystem that is simultaneously fragmented and concentrated: many new actors appear and disappear in months, while a handful of operators continue to drive large volumes of publicized victim disclosures. The recommendations are concrete and targeted — rapid patching for critical CVEs and reinforced identity, help-desk and vendor controls — but the record raises a practical question for organizations and regulators alike: will the systems and processes that Black Kite names be made fast enough to match the tempo of a threat landscape where a new extortion group appears more than once a week?

Source: Infosecurity Magazine — A New Ransomware Threat Actor Emerges Every Week, Warns Report