Skip to main content

Ransomware statistics and trends

Ransomware attacks up 20% year-over-year as groups battle for dominance

Our latest ransomware analysis reveals a deepening rivalry between Qilin and The Gentlemen as attacks continue to surge in Q2 2026.

Last updated: July 2026

q2-2026-ransomware-report-cover-with-red-gradient-background-and-blurred-report-fragments

Why read our ransomware report?

We watch 200+ leak sites and the dark web nonstop, then turn what we find into clear quarterly data so you can see where ransomware is heading next. See the full methodology.

KEY FINDINGS

What ransomware trends stood out this quarter?

2,581 ransomware incidents were recorded from April to June of 2026, which is a 4% decrease from Q1 2026. Despite this quarterly dip, ransomware activity remained elevated, with attacks in the first half of 2026 increasing by 20% compared to the same period last year.

769

US remains the most targeted country with 769 attacks

#3

DragonForce broke straight into third place as a major new group

63%

Businesses with <200 staff were hit hardest, with 63% of attacks

+74%

Attacks on billion-dollar firms jumped 74%, with 40 hits in total

Small businesses hit hardest, but enterprise attacks increase 

Small and medium-sized firms stayed at the bottom of the food chain and again took the bulk of the quarter’s attacks. The bigger shift sat at the top of the market, where attacks on organizations earning over $1B rose 74%, from 23 to 40, in Q1. And while that is only a few dozen incidents in absolute terms, it is an early, clear signal that dominant groups are reaching for larger, higher-profile targets as they compete for reputation.

Enterprise building icon in crosshairs with 74% increase indicator showing rising attacks on large organizations

Ransomware rivalries are driving up attack volume

Qilin led again with 299 attacks, despite a 16% fall, but The Gentlemen surged to 284 attacks. “While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated their operations with a 39% increase in attacks, further deepening the rivalry between the two groups,” says Mantas Sabeckis, Senior Threat Intelligence Researcher at Nord Security. The fight is playing out against a backdrop of rising attacks, with 5,257 recorded in the first half of 2026, up 20% from the year before.

Bar chart comparing ransomware attacks: 5,257 in H1 2026 versus 4,387 in H1 2025, showing 20% increase

DragonForce catches up with the incumbents

DragonForce broke into third place with 147 and posted its highest volume yet, a sign that smaller groups are under pressure to scale while the top two slug it out. “The more sophisticated and established a group becomes, the greater the threat it poses. This competition between Qilin and The Gentlemen could potentially drive an even higher baseline of activity. Each group is likely ramping up operations and casting a wider net to come out on top,” explains Mantas Sabeckis.

Horizontal bar chart ranking top ransomware groups with Qilin at 299 attacks and The Gentleman at 284

Coercion tactics are continuously maturing 

Previous NordStellar findings show that ransomware actors use various schemes to coerce victims into paying, with 76.8% of negotiations including a threat to leak the data, and a limited-time discount offered in 45.5% of them. This is a reminder that no company is immune, and the it-won’t-happen-to-us mindset is one every security team should finally abandon, since even a quiet quarter leaves attackers with plenty of leverage once they are inside.

Bar chart showing ransomware coercion tactics: 76.8% threaten data leaks, 45.5% offer time-limited discounts

Curious how ransomware negotiations work?

We analyzed 246 leaked negotiation chats from 2020 to 2026, so you can see the exact playbook attackers use once they have your data.

Business professional reviewing ransomware negotiation chat about decryption, data deletion, and security report costs

the insider view

See what the experts say

Ransomware specialists at Nord Security share their insights on all the latest findings, trends, and events.

The slight decrease in attacks shouldn’t be a sign to relax just yet. Ransomware accelerated in the last quarter of 2025, reaching record highs, and although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter.

Vakaris Noreika

Cybersecurity Expert at NordStellar

While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated their operations with a 39% increase in attacks, further deepening the rivalry between the two groups. Even though DragonForce remains significantly less active than the top two, they are steadily scaling up – last quarter’s attack volume marked an all-time high for the group.

Mantas Sabeckis

Senior Threat Intelligence Researcher at Nord Security

PRIORITY TARGETS

Where is ransomware hitting businesses hardest?

Discover which types of businesses are most vulnerable, and assess your risk level by industry, country, and company size.

Donut chart showing top 20 industries targeted by ransomware with Manufacturing at 19.47% and IT at 10.72%

By industry

Manufacturing stayed the top target, accounting for 19.5% of all attacks, followed by IT at 10.7%. Next came professional, scientific, and technical services (8.3%), construction (7%), and healthcare (6.2%). Healthcare posted the smallest quarterly decline of any major sector, as its high-value data and low tolerance for downtime keep it firmly in attackers’ sights.

Bar chart ranking top 10 affected countries led by United States with 769 ransomware attacks in Q2 2026

By country

US businesses led by a wide margin with 769 attacks, though that was a 24% drop from last quarter. Meanwhile, Canada rose 13% to 97 attacks, overtaking Germany (83) and the UK (74), with France following behind with 51. This rise in Canada-based attacks suggests ransomware groups may be widening their geographic focus beyond the US and toward its northern neighbor.

Donut chart showing ransomware attacks by company size with 51-200 employees at 25.8% being most targeted

By company size

Small and medium-sized businesses with up to 200 employees and revenues under $25 million took the most hits once again this quarter. But the biggest shift was a 74% surge in attacks against billion-dollar enterprises, rising from 23 to 40.

RANSOMWARE’S MOST WANTED

Which ransomware groups are most active right now?

Track the most notorious ransomware groups every quarter to see who is driving attacks and how the “most wanted” list changes as takedowns and new actors reshape it.

First place

Qilin

Still the most active group with 299 attacks.

Second place

The Gentlemen

Climbed to second position with 284 attacks.

Third place

DragonForce

Broke straight into third with 147 attacks.

Fourth place

Akira

Slipped to fourth position with 140 recorded attacks.

POWERED BY

Can these groups already access your logins?

Check to see if your company’s email domain has appeared on the dark web marketplaces and secret Telegram channels we track.

All fields are required

HISTORICAL DATA

Track ransomware statistics by year and quarter

Review how ransomware threats and trends have evolved over time, with every figure updated as new incidents arise.

Dashboard showing Q1 2026 ransomware statistics: 2,676 attacks with US at 914 incidents, Manufacturing at 332 incidents, and SMBs as top target

Q1 looked quiet at first, but late-reported victims kept landing for weeks, pushing the total well above the initial count.

  • Total incidents reached 2,676 after late victims were counted, up from the 2,283 originally recorded at launch.
  • The US was the top target with 914 incidents, followed by Canada with 86, while the UK climbed into third place with 79 attacks, up 27%.
  • The manufacturing industry led with 323 incidents, followed by IT with 152.
  • Ransomware group activities: Qilin was the top group with 356 incidents. The Gentlemen was second with 207 incidents.
  • SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
Dashboard showing Q4 2025 ransomware statistics: 2,910 attacks with US at 917 incidents, Manufacturing at 386 incidents, and SMBs as top target

The year closed on a two-year high as attackers exploited end-of-year staffing gaps and rushed holiday operations.

  • Q4 recorded 2,910 incidents, the highest number in 2 years, and a 38% increase compared to Q4 2024.
  • The US was hit hardest with 917 incidents, Canada came in second with 107, followed by Germany (64), the UK (62), and France (54).
  • The manufacturing industry led with 386, followed by IT with 152 incidents.
  • Ransomware group activities: Qilin dominated with 489 attacks.
  • SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
Dashboard showing Q3 2025 ransomware statistics: 1,943 attacks with US at 686 incidents, Manufacturing at 245 incidents, and SMBs as top target

Activity climbed steadily over the first 9 months as more groups joined and the RaaS model kept expanding.

  • Between January and September 2025, 6,330 cases were exposed, a 47% increase compared to the same period last year.
  • 1,943 recorded incidents in Q3 alone.
  • The US accounted for 54% of all traced cases, with 686 incidents, followed by Canada at a distant second with 62.
  • The manufacturing industry was hit hardest with 245 incidents, followed by IT with 103.
  • Ransomware group activities: Qilin led with 241 incidents, followed by Akira (190), and INC (146)
  • SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.
Dashboard showing Q2 2025 ransomware statistics: 1,758 attacks with US at 596 incidents, Manufacturing at 229 incidents, and SMBs as top target

The first half of the year brought a steep year-over-year rise, with attackers focused on the US and its manufacturing sector.

  • In the first half of 2025, 4,198 cases were exposed on the dark web, marking a 49% surge compared to the same period in 2024. Of those, 1,758 were recorded in Q2 alone.
  • The US was by far the most targeted country, accounting for 49% (596 incidents) of all attacks.
  • The manufacturing sector was hit hardest, with 229 recorded cases.
  • Ransomware group activities: Qilin was the most prolific, with 214 attacks; Safepay was a close second with 201.
  • SMBs – businesses with up to 200 employees and under $25 million in revenue – were the most targeted.

FINAL THOUGHTS

“As leading ransomware groups compete for dominance and scale their operations, no company is immune. Abandoning the it-won’t-happen-to-us mindset has never been more critical. Companies should strengthen their defenses by focusing on basic cyber hygiene, which is too often overlooked. This includes enforcing multi-factor authentication, implementing strong password management policies, regularly patching systems and applications, and adopting a zero-trust approach to limit lateral movement.”

Vakaris Noreika, Cybersecurity Expert at NordStellar

Professional headshot photo of Vakaris Noreika

PROTECT YOUR NETWORK

Build a ransomware-resistant business

These steps cut your exposure before an attack starts and limit the damage if one gets through, so a single incident never becomes a full shutdown.

  1. 1

    Patch and update systems and apps on a fixed schedule.

  2. 2

    Enforce multi-factor authentication and strong password policies.

  3. 3

    Adopt a zero-trust framework to stop malware from spreading.

  4. 4

    Back up data regularly and rehearse your incident response plan.

Additional info

Frequently asked questions

Ransomware is malware that locks or encrypts your files and holds them hostage until you pay a fee. Reviewing the latest ransomware statistics is the best way to understand how these attacks work and why they remain a constant threat to businesses.

Most attacks begin with phishing emails, stolen credentials, or unpatched software. Ransomware attack statistics consistently point to these routes, so closing them off does more to reduce your risk than almost any other single step.

RaaS lets affiliates rent ready-made ransomware from a core group in exchange for a share of the payout. This model is behind many of the ransomware trends we track, turning extortion into a scalable business that helps new gangs rise quickly.

Double extortion means attackers steal your data before encrypting it, then threaten to leak it unless you pay. It has become one of the defining ransomware facts of recent years, and our ransomware research shows that it is now a standard tactic.

Reliable, tested backups let you restore systems without paying, which removes the attacker’s main leverage. Yearly ransomware statistics consistently show that backups remain one of the most effective defenses against permanent data loss.

Dark web monitoring alerts you when your credentials or data surface on leak sites, often before an attack lands. Following the state of ransomware shows why that early warning matters, letting you reset access before a breach becomes an incident.