📊 Key Data
  • 2,027 undisclosed ransomware attacks tracked in Q2 2026 (up 40% year-on-year)
  • 97% of incidents involve data exfiltration, with an average of 508 GB stolen per attack
  • 28 new ransomware groups emerged in Q2 2026, double the number from Q1
🎯 Expert Consensus

Experts agree that the hidden scale of ransomware attacks—driven by data exfiltration and underreporting—poses a growing threat to cybersecurity, requiring urgent defensive shifts like Anti-Data Exfiltration (ADX) strategies.

1 day ago
The Silent Surge: Ransomware's Hidden War Is Larger Than We Know

The Silent Surge: Ransomware's Hidden War Is Larger Than We Know

SAN FRANCISCO, CA – July 30, 2026 – The ransomware attacks you read about in the headlines represent a mere fraction of the real war being waged against businesses and governments worldwide. The true scale of this digital siege is happening in the shadows, on dark web leak sites where criminals name and shame victims who refuse to pay. New analysis reveals this hidden epidemic is not only vast but also growing at an alarming rate.

A stark Q2 2026 report from cybersecurity firm BlackFog, a recognized leader in anti-data exfiltration (ADX), exposes this reality with chilling precision. While 306 ransomware attacks were publicly disclosed last quarter—a significant 16% increase from Q1—they are dwarfed by the 2,027 undisclosed attacks the company tracked. This silent victim list, up 40% year-on-year, confirms that for every company that goes public with a breach, nearly six others are grappling with the same crisis in secret. This isn't a new development; it's the acceleration of a dangerous trend toward a two-tiered reality in cybersecurity: the attacks we see, and the much larger, invisible crisis we don't.

The Shadow Epidemic of Undisclosed Attacks

The disparity between public and private incidents underscores a fundamental flaw in our collective understanding of the ransomware threat. By combining public reports with intelligence gathered from ransomware groups' own leak sites, BlackFog’s methodology paints a more complete, and far more concerning, picture. The data suggests that as much as 86% of all ransomware attacks may go unreported.

The reasons for this silence are complex. Organizations fear reputational damage, customer backlash, and regulatory penalties. The decision to stay quiet is often a calculated risk, weighing the immediate fallout of disclosure against the hope of a quiet recovery. However, this culture of non-disclosure creates a dangerous feedback loop. It obscures the true scope of the problem, starves threat intelligence platforms of vital data, and provides a false sense of security for industries that believe they are not being targeted. The 2,027 undisclosed attacks in a single quarter are not just statistics; they represent thousands of compromised networks, stolen datasets, and agonizing decisions being made behind closed boardroom doors.

Data Exfiltration: The New Ransom Economy

The modern ransomware attack is no longer primarily about encryption. It is a meticulously orchestrated data heist. The report’s most critical finding may be that 97% of all incidents now involve data exfiltration—the highest rate ever recorded. Attackers are not just locking down systems; they are stealing the crown jewels. The average volume of data stolen per undisclosed incident reached a staggering 508 GB, with victims given an average of just seven days to pay before their sensitive information is leaked or sold.

This marks a definitive strategic realignment in the cybercrime economy. The leverage is no longer the disruption caused by encrypted files, but the existential threat of corporate secrets, customer data, and intellectual property being exposed to the world. A highest ransom demand of $25 million in Q2 illustrates the confidence attackers have in this model.

“The trends we’ve identified over the last quarter, underline not only the scale of the ransomware threat, but also how quickly new groups can emerge and establish themselves,” commented Dr. Darren Williams, Founder and CEO of BlackFog. “While the tactics used by these groups continue to evolve, one objective remains consistent: stealing data. Data exfiltration is at the heart of modern ransomware... Preventing data exfiltration is no longer just a part of the ransomware defence strategy - it is the strategy.”

This analysis pivots the entire defensive paradigm. Traditional security focused on preventing intrusion. The new reality, where intrusion is often a matter of when, not if, demands a focus on preventing data from leaving. Technologies like Anti-Data Exfiltration (ADX), which BlackFog pioneered, are built on this very premise: control the endpoint, and you can stop the theft, collapsing the attacker's leverage.

A Hyper-Evolving Threat Landscape

The forces behind this surge are as dynamic as they are dangerous. The ransomware ecosystem is highly fragmented and constantly evolving. The second quarter of 2026 saw the emergence of 28 new ransomware groups, double the number from Q1. This indicates a low barrier to entry and a continuous churn of new actors seeking to claim their share of the lucrative market.

Most notable is the arrival of Settra, a group that appeared “fully formed” in June. Instead of a slow ramp-up, Settra launched a sophisticated global campaign from day one, claiming 22 victims across seven countries in its first four days. This debut signals a new level of professionalism and ambition, where criminal startups can launch with the infrastructure and reach of established enterprises.

Meanwhile, veteran groups continue to dominate. Qilin remains the most prolific, responsible for 14% of all undisclosed attacks, followed by The Gentlemen and Dragon Force. Yet, the challenge of attribution remains immense; in 30% of publicly disclosed incidents, the culprit is unknown. This chaotic, multi-actor environment makes defense incredibly challenging, as security teams must contend with a diverse and unpredictable array of tactics and motivations.

Critical Sectors in the Crosshairs

Ransomware gangs are not indiscriminate; they are strategic. The report highlights a clear and continued focus on sectors where disruption causes maximum pain and data holds maximum value. Healthcare remains the most besieged industry, accounting for 81 disclosed attacks (26%). For hospitals, the combination of life-or-death operational urgency, valuable patient data, and often-outdated IT infrastructure creates a perfect storm of vulnerability.

Perhaps most striking is the explosive 221% increase in disclosed attacks targeting the services sector compared to the previous quarter. This broad category, encompassing everything from legal firms to managed service providers, is a treasure trove of sensitive client data and a potential gateway into larger supply chains. The surge suggests attackers are increasingly targeting the softer underbelly of the corporate world, exploiting smaller firms to create cascading effects.

Government agencies also remain a prime target, accounting for 10% of attacks. The goal here is twofold: access to highly sensitive citizen and national security data, and the potential to disrupt public services. The persistent targeting of these critical sectors demonstrates a calculated effort to apply maximum pressure where society is most vulnerable, moving these attacks from a corporate issue to a matter of public safety and national security.

Topics & Related

Sector:
Cybersecurity
Theme:
Threat Landscape
Ransomware

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 45477