Ransomware statistics and trends
Ransomware attacks up 20% year-over-year as groups battle for dominance
Our latest ransomware analysis reveals a deepening rivalry between Qilin and The Gentlemen as attacks continue to surge in Q2 2026.
Last updated: July 2026

Why read our ransomware report?
We watch 200+ leak sites and the dark web nonstop, then turn what we find into clear quarterly data so you can see where ransomware is heading next. See the full methodology.
KEY FINDINGS
What ransomware trends stood out this quarter?
2,581 ransomware incidents were recorded from April to June of 2026, which is a 4% decrease from Q1 2026. Despite this quarterly dip, ransomware activity remained elevated, with attacks in the first half of 2026 increasing by 20% compared to the same period last year.
769
US remains the most targeted country with 769 attacks
#3
DragonForce broke straight into third place as a major new group
63%
Businesses with <200 staff were hit hardest, with 63% of attacks
+74%
Attacks on billion-dollar firms jumped 74%, with 40 hits in total
Small businesses hit hardest, but enterprise attacks increase
Small and medium-sized firms stayed at the bottom of the food chain and again took the bulk of the quarter’s attacks. The bigger shift sat at the top of the market, where attacks on organizations earning over $1B rose 74%, from 23 to 40, in Q1. And while that is only a few dozen incidents in absolute terms, it is an early, clear signal that dominant groups are reaching for larger, higher-profile targets as they compete for reputation.
Ransomware rivalries are driving up attack volume
Qilin led again with 299 attacks, despite a 16% fall, but The Gentlemen surged to 284 attacks. “While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated their operations with a 39% increase in attacks, further deepening the rivalry between the two groups,” says Mantas Sabeckis, Senior Threat Intelligence Researcher at Nord Security. The fight is playing out against a backdrop of rising attacks, with 5,257 recorded in the first half of 2026, up 20% from the year before.
DragonForce catches up with the incumbents
DragonForce broke into third place with 147 and posted its highest volume yet, a sign that smaller groups are under pressure to scale while the top two slug it out. “The more sophisticated and established a group becomes, the greater the threat it poses. This competition between Qilin and The Gentlemen could potentially drive an even higher baseline of activity. Each group is likely ramping up operations and casting a wider net to come out on top,” explains Mantas Sabeckis.
Coercion tactics are continuously maturing
Previous NordStellar findings show that ransomware actors use various schemes to coerce victims into paying, with 76.8% of negotiations including a threat to leak the data, and a limited-time discount offered in 45.5% of them. This is a reminder that no company is immune, and the it-won’t-happen-to-us mindset is one every security team should finally abandon, since even a quiet quarter leaves attackers with plenty of leverage once they are inside.
Curious how ransomware negotiations work?
We analyzed 246 leaked negotiation chats from 2020 to 2026, so you can see the exact playbook attackers use once they have your data.

the insider view
See what the experts say
Ransomware specialists at Nord Security share their insights on all the latest findings, trends, and events.
The slight decrease in attacks shouldn’t be a sign to relax just yet. Ransomware accelerated in the last quarter of 2025, reaching record highs, and although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter.

Vakaris Noreika
Cybersecurity Expert at NordStellar
While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated their operations with a 39% increase in attacks, further deepening the rivalry between the two groups. Even though DragonForce remains significantly less active than the top two, they are steadily scaling up – last quarter’s attack volume marked an all-time high for the group.

Mantas Sabeckis
Senior Threat Intelligence Researcher at Nord Security
PRIORITY TARGETS
Where is ransomware hitting businesses hardest?
Discover which types of businesses are most vulnerable, and assess your risk level by industry, country, and company size.
RANSOMWARE’S MOST WANTED
Which ransomware groups are most active right now?
Track the most notorious ransomware groups every quarter to see who is driving attacks and how the “most wanted” list changes as takedowns and new actors reshape it.
Qilin
Still the most active group with 299 attacks.
The Gentlemen
Climbed to second position with 284 attacks.
DragonForce
Broke straight into third with 147 attacks.
Akira
Slipped to fourth position with 140 recorded attacks.
HISTORICAL DATA
Track ransomware statistics by year and quarter
Review how ransomware threats and trends have evolved over time, with every figure updated as new incidents arise.
Q1 looked quiet at first, but late-reported victims kept landing for weeks, pushing the total well above the initial count.
- Total incidents reached 2,676 after late victims were counted, up from the 2,283 originally recorded at launch.
- The US was the top target with 914 incidents, followed by Canada with 86, while the UK climbed into third place with 79 attacks, up 27%.
- The manufacturing industry led with 323 incidents, followed by IT with 152.
- Ransomware group activities: Qilin was the top group with 356 incidents. The Gentlemen was second with 207 incidents.
- SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
The year closed on a two-year high as attackers exploited end-of-year staffing gaps and rushed holiday operations.
- Q4 recorded 2,910 incidents, the highest number in 2 years, and a 38% increase compared to Q4 2024.
- The US was hit hardest with 917 incidents, Canada came in second with 107, followed by Germany (64), the UK (62), and France (54).
- The manufacturing industry led with 386, followed by IT with 152 incidents.
- Ransomware group activities: Qilin dominated with 489 attacks.
- SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
Activity climbed steadily over the first 9 months as more groups joined and the RaaS model kept expanding.
- Between January and September 2025, 6,330 cases were exposed, a 47% increase compared to the same period last year.
- 1,943 recorded incidents in Q3 alone.
- The US accounted for 54% of all traced cases, with 686 incidents, followed by Canada at a distant second with 62.
- The manufacturing industry was hit hardest with 245 incidents, followed by IT with 103.
- Ransomware group activities: Qilin led with 241 incidents, followed by Akira (190), and INC (146)
- SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
The first half of the year brought a steep year-over-year rise, with attackers focused on the US and its manufacturing sector.
- In the first half of 2025, 4,198 cases were exposed on the dark web, marking a 49% surge compared to the same period in 2024. Of those, 1,758 were recorded in Q2 alone.
- The US was by far the most targeted country, accounting for 49% (596 incidents) of all attacks.
- The manufacturing sector was hit hardest, with 229 recorded cases.
- Ransomware group activities: Qilin was the most prolific, with 214 attacks; Safepay was a close second with 201.
- SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
FINAL THOUGHTS
“As leading ransomware groups compete for dominance and scale their operations, no company is immune. Abandoning the it-won’t-happen-to-us mindset has never been more critical. Companies should strengthen their defenses by focusing on basic cyber hygiene, which is too often overlooked. This includes enforcing multi-factor authentication, implementing strong password management policies, regularly patching systems and applications, and adopting a zero-trust approach to limit lateral movement.”
Vakaris Noreika, Cybersecurity Expert at NordStellar

PROTECT YOUR NETWORK
Build a ransomware-resistant business
These steps cut your exposure before an attack starts and limit the damage if one gets through, so a single incident never becomes a full shutdown.
- 1
Patch and update systems and apps on a fixed schedule.
- 2
Enforce multi-factor authentication and strong password policies.
- 3
Adopt a zero-trust framework to stop malware from spreading.
- 4
Back up data regularly and rehearse your incident response plan.
Additional info
Frequently asked questions
Ransomware is malware that locks or encrypts your files and holds them hostage until you pay a fee. Reviewing the latest ransomware statistics is the best way to understand how these attacks work and why they remain a constant threat to businesses.
Most attacks begin with phishing emails, stolen credentials, or unpatched software. Ransomware attack statistics consistently point to these routes, so closing them off does more to reduce your risk than almost any other single step.
RaaS lets affiliates rent ready-made ransomware from a core group in exchange for a share of the payout. This model is behind many of the ransomware trends we track, turning extortion into a scalable business that helps new gangs rise quickly.
Double extortion means attackers steal your data before encrypting it, then threaten to leak it unless you pay. It has become one of the defining ransomware facts of recent years, and our ransomware research shows that it is now a standard tactic.
Reliable, tested backups let you restore systems without paying, which removes the attacker’s main leverage. Yearly ransomware statistics consistently show that backups remain one of the most effective defenses against permanent data loss.
Dark web monitoring alerts you when your credentials or data surface on leak sites, often before an attack lands. Following the state of ransomware shows why that early warning matters, letting you reset access before a breach becomes an incident.