Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2090+ Articles
154+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Ransomware Is Accelerating — And It's Not Because of AI
Ransomware Is Accelerating — And It's Not Because of AI
NEWS

Ransomware Is Accelerating — And It's Not Because of AI

Black Kite's 2026 Ransomware Report reveals 7,551 publicly disclosed victims in a single year — a 24.9% increase — driven not by AI but by ecosystem fragmentation, 61 new groups entering the market, and the systematic targeting of less-defended organizations.

Dylan H.

News Desk

July 26, 2026
5 min read

Overview

Ransomware is accelerating — and blaming artificial intelligence is wrong.

That's the central argument of Black Kite's 2026 Ransomware Report, released in July 2026. The report covers April 1, 2025 – March 31, 2026 and documents 7,551 publicly disclosed ransomware victims, a 24.9% year-over-year increase from 6,046 the prior year. But the driving forces, researchers say, are structural: a fragmented threat ecosystem, record numbers of new criminal groups, and an expanding pool of underfended targets — not AI-generated attacks.


The Numbers

MetricValue
Total victims (Apr 2025–Mar 2026)7,551
Year-over-year growth+24.9%
Victims in H1 (Apr–Sep 2025)2,904
Victims in H2 (Oct 2025–Mar 2026)4,647 (+60%)
Single-month record (March 2026)861 victims — ~28/day
Additional victims (Apr–Jun 2026)2,230
Active ransomware groups (Jun 2026)146 (up from 105 a year earlier)
New groups in the reporting period61 — more than one per week

The acceleration was back-weighted. The first half of the reporting period accounted for 2,904 victims; the second half surged to 4,647 — a 60% jump in six months. March 2026 became the highest single-month victim count in four years, at 861 victims — roughly 28 attacks per day.


What's Actually Driving Growth

1. Ecosystem Fragmentation

The prior era of ransomware was characterized by dominant centralized groups — LockBit, RansomHub — that commanded large affiliate networks and set industry norms. That era is ending.

RansomHub, the dominant actor in 2024 with 736 victims, effectively went dark within the reporting period. No single group replaced it. Instead, five distinct operational models now coexist:

  • Mass-exploitation platforms (e.g., Clop): large-scale, vulnerability-driven
  • Encryption + theft operators (e.g., Qilin, Akira): dual-extortion
  • Credential-focused operations (e.g., World Leaks): identity-first attacks
  • Fast opportunistic actors (e.g., Play): speed over sophistication
  • AI-augmented newcomers: using AI for phishing personalization and automation, not as a primary attack vector

This multi-model landscape is harder for defenders to track. The centralized forums and coordination structures that previously allowed threat intelligence teams to monitor actor movement are shrinking.

2. Lower Barriers to Entry

Ransomware-as-a-Service (RaaS) has industrialized cybercrime. Modular toolkits, affiliate networks, and technical support infrastructure mean operators can launch campaigns with minimal technical expertise. 61 new groups entered the market in a single 12-month period — more than one per week. Their average lifespan was only 4.9 months (down sharply from over a year in 2024), but each new entrant generates victims before churning out.

3. Expansion to Less-Defended Targets

The target mix is shifting. Large enterprises have invested significantly in cyber defenses over the past decade. Mid-market companies, SMBs, and supply chain vendors — many with limited security budgets and small IT teams — are increasingly in scope. Less-defended organizations represent both easier access and lower-friction extortion (fewer incident response resources, greater operational pressure to pay).

The US remains the most-targeted geography at 49.3% of global victims, but its share is declining as European targeting accelerates: Germany +48%, Italy +96%, Spain and France both approximately +50% year-over-year.


On AI: Not the Culprit (Yet)

The report explicitly rejects the popular narrative that AI is fueling ransomware growth. While AI tools are being adopted for phishing personalization and some automation tasks, they are not the structural accelerant.

What is happening with AI in this space:

  • Phishing personalization: LLMs are used to craft more convincing lures
  • Automation of reconnaissance: some groups use AI-assisted target profiling
  • Newcomers with AI-augmented workflows: a small subset of new entrants are AI-native in their tooling

What is NOT happening:

  • AI is not enabling novel exploit discovery at scale (that remains human-driven)
  • AI is not replacing the core ransomware workflow
  • AI is not the primary reason for the 24.9% growth

The actual drivers — ecosystem fragmentation, RaaS commoditization, and target expansion — are structural and would be producing these numbers with or without AI.


Predictability: The RSI Signal

One of the report's more actionable findings involves the Ransomware Susceptibility Index (RSI):

  • Companies with an RSI above 0.8 were 291 times more likely to be victimized
  • 93.5% of victims showed meaningful RSI spikes before the attack was publicly disclosed

This suggests that for most victims, the attack was not unforeseeable — it was predictable from externally observable risk signals. The implication for defenders: continuous third-party risk monitoring, not just internal security hygiene, is now a baseline requirement.


What This Means for Defenders

The ransomware ecosystem in mid-2026 presents a fundamentally different threat landscape than 2022 or even 2024:

  1. There is no silver bullet threat actor to monitor. The collapse of dominant groups means no single actor's disruption materially reduces total risk.
  2. Speed is increasing. With 28 attacks per day in peak months, dwell time for defenders is shrinking.
  3. Supply chain is the soft underbelly. Attackers are routing through less-defended third-party vendors to reach better-defended primary targets.
  4. External risk signals matter. RSI and similar third-party risk scores are demonstrably predictive — organizations should be incorporating them into security programs.
  5. AI defenses should target phishing. While AI isn't driving most attacks, AI-assisted phishing personalization is real — invest accordingly in email security and user training.

References

  • Dark Reading — Ransomware Is Accelerating, but It's Not Because of AI
  • Black Kite — 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record
#Ransomware#Cybercrime#Threat Intelligence#RansomHub#Ecosystem Analysis

Related Articles

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Cisco Talos has detailed msaRAT, a Rust-based implant used by the Chaos ransomware group that hides its command-and-control channel inside the victim's own browser — using headless Chrome or Edge, WebRTC, and Twilio TURN to make C2 traffic appear as legitimate browser activity.

6 min read

In Other News: Dolphin X AI Malware, Car Anti-Theft Hack, 432 Linux Kernel CVEs

This week's security roundup covers an AI-prioritizing infostealer targeting developer machines, a hardcoded Bluetooth key in 2.2 million car anti-theft...

4 min read

Identity Attacks Overtake Exploits as Top Ransomware Cause

Sophos 2026: 79% of ransomware attacks start with stolen identities. MFA was present in 97% of credential-based cases yet failed to stop every one of them.

4 min read
Back to all News