Ransomware Attacks Surge 60% in Second Half of 2025 as New Groups Proliferate

  • Black Kite identified 7,551 publicly disclosed ransomware victims between April 2025 and March 2026, up 24.9% year-over-year.
  • Ransomware attacks accelerated by 60% in the second half of 2025, with 861 victims in March 2026—the highest monthly total in four years.
  • More than 60 new ransomware groups emerged during the reporting period, bringing the total to 146 active groups by June 2026.
  • The five largest actors controlled 43.6% of all victims, with Qilin claiming over 1,300 victims—nearly twice as many as its nearest rival.

Ransomware is evolving into a more fragmented and operationalized ecosystem, with AI lowering the cost of attacks and enabling faster exploitation cycles. The surge in new groups and the concentration of victims among top actors highlight the need for proactive third-party cyber risk management. Organizations must prioritize vulnerabilities known to be exploited in the wild and strengthen identity verification controls to mitigate these growing threats.

AI Impact
How AI will further lower the barrier to entry for ransomware attackers and accelerate vulnerability discovery.
Supply Chain Risks
Whether organizations can effectively harden their supply chains against ransomware attacks moving through trusted vendor platforms.
Regulatory Response
The pace at which governments and industries will implement stricter cybersecurity regulations in response to the rising threat.