Overview
Ransomware is accelerating — and blaming artificial intelligence is wrong.
That's the central argument of Black Kite's 2026 Ransomware Report, released in July 2026. The report covers April 1, 2025 – March 31, 2026 and documents 7,551 publicly disclosed ransomware victims, a 24.9% year-over-year increase from 6,046 the prior year. But the driving forces, researchers say, are structural: a fragmented threat ecosystem, record numbers of new criminal groups, and an expanding pool of underfended targets — not AI-generated attacks.
The Numbers
| Metric | Value |
|---|---|
| Total victims (Apr 2025–Mar 2026) | 7,551 |
| Year-over-year growth | +24.9% |
| Victims in H1 (Apr–Sep 2025) | 2,904 |
| Victims in H2 (Oct 2025–Mar 2026) | 4,647 (+60%) |
| Single-month record (March 2026) | 861 victims — ~28/day |
| Additional victims (Apr–Jun 2026) | 2,230 |
| Active ransomware groups (Jun 2026) | 146 (up from 105 a year earlier) |
| New groups in the reporting period | 61 — more than one per week |
The acceleration was back-weighted. The first half of the reporting period accounted for 2,904 victims; the second half surged to 4,647 — a 60% jump in six months. March 2026 became the highest single-month victim count in four years, at 861 victims — roughly 28 attacks per day.
What's Actually Driving Growth
1. Ecosystem Fragmentation
The prior era of ransomware was characterized by dominant centralized groups — LockBit, RansomHub — that commanded large affiliate networks and set industry norms. That era is ending.
RansomHub, the dominant actor in 2024 with 736 victims, effectively went dark within the reporting period. No single group replaced it. Instead, five distinct operational models now coexist:
- Mass-exploitation platforms (e.g., Clop): large-scale, vulnerability-driven
- Encryption + theft operators (e.g., Qilin, Akira): dual-extortion
- Credential-focused operations (e.g., World Leaks): identity-first attacks
- Fast opportunistic actors (e.g., Play): speed over sophistication
- AI-augmented newcomers: using AI for phishing personalization and automation, not as a primary attack vector
This multi-model landscape is harder for defenders to track. The centralized forums and coordination structures that previously allowed threat intelligence teams to monitor actor movement are shrinking.
2. Lower Barriers to Entry
Ransomware-as-a-Service (RaaS) has industrialized cybercrime. Modular toolkits, affiliate networks, and technical support infrastructure mean operators can launch campaigns with minimal technical expertise. 61 new groups entered the market in a single 12-month period — more than one per week. Their average lifespan was only 4.9 months (down sharply from over a year in 2024), but each new entrant generates victims before churning out.
3. Expansion to Less-Defended Targets
The target mix is shifting. Large enterprises have invested significantly in cyber defenses over the past decade. Mid-market companies, SMBs, and supply chain vendors — many with limited security budgets and small IT teams — are increasingly in scope. Less-defended organizations represent both easier access and lower-friction extortion (fewer incident response resources, greater operational pressure to pay).
The US remains the most-targeted geography at 49.3% of global victims, but its share is declining as European targeting accelerates: Germany +48%, Italy +96%, Spain and France both approximately +50% year-over-year.
On AI: Not the Culprit (Yet)
The report explicitly rejects the popular narrative that AI is fueling ransomware growth. While AI tools are being adopted for phishing personalization and some automation tasks, they are not the structural accelerant.
What is happening with AI in this space:
- Phishing personalization: LLMs are used to craft more convincing lures
- Automation of reconnaissance: some groups use AI-assisted target profiling
- Newcomers with AI-augmented workflows: a small subset of new entrants are AI-native in their tooling
What is NOT happening:
- AI is not enabling novel exploit discovery at scale (that remains human-driven)
- AI is not replacing the core ransomware workflow
- AI is not the primary reason for the 24.9% growth
The actual drivers — ecosystem fragmentation, RaaS commoditization, and target expansion — are structural and would be producing these numbers with or without AI.
Predictability: The RSI Signal
One of the report's more actionable findings involves the Ransomware Susceptibility Index (RSI):
- Companies with an RSI above 0.8 were 291 times more likely to be victimized
- 93.5% of victims showed meaningful RSI spikes before the attack was publicly disclosed
This suggests that for most victims, the attack was not unforeseeable — it was predictable from externally observable risk signals. The implication for defenders: continuous third-party risk monitoring, not just internal security hygiene, is now a baseline requirement.
What This Means for Defenders
The ransomware ecosystem in mid-2026 presents a fundamentally different threat landscape than 2022 or even 2024:
- There is no silver bullet threat actor to monitor. The collapse of dominant groups means no single actor's disruption materially reduces total risk.
- Speed is increasing. With 28 attacks per day in peak months, dwell time for defenders is shrinking.
- Supply chain is the soft underbelly. Attackers are routing through less-defended third-party vendors to reach better-defended primary targets.
- External risk signals matter. RSI and similar third-party risk scores are demonstrably predictive — organizations should be incorporating them into security programs.
- AI defenses should target phishing. While AI isn't driving most attacks, AI-assisted phishing personalization is real — invest accordingly in email security and user training.