In this post, we look at Q2 2026 ransomware activity and how it’s changed over the last three and a half years, going back to January 2023. The data used for the analysis comes from two excellent sources: RansomLook.io, and ransomware.live. These sites continually search the internet and the dark web for threat actor claims of new victims, although it’s important to remember that the actual number of victims is likely to be significantly higher than those reported. Together, they offer significant benefits for historical analysis of ransomware activity, including:
- They use similar but independent methods to search and report victim claims. The fact that their datasets are similar in scope and size suggests their reliability;
- The data collection methods have been consistent for the period being analyzed, which supports the objective of looking for trends over an extended period;
- They both have data going back several years, allowing this sort of multi-year view;
- Both sites expose API access to their records.
The data used for this analysis, representing victim claims from January 2023 to the end of June 2026, comprises 24,278 records from ransomware.live and 24270 records for RansomLook.io. That’s an impressively small 3.9% deviation in the size of their data sets over 42 months.
Since the beginning of 2023, the ransomware space has seen a lot of changes: international law enforcement activity has taken down forums and dark web DLS sites, individuals have been identified and, in some cases, brought to justice, ransomware groups have come and gone. What trends in ransomware data can be seen over this period?
Ransomware Victims Continue to Rise
Analyzing over three years of data from RansomLook.io and Ransomware.live produces grim results. The number of victims claimed has risen steadily for the last three and a half years, as can be seen in Figure 1. The number of ransomware victims in the first half of the year more than doubled between 2023 and 2026, from just over 2000 to well over 4500.
The Evolution of the Ransomware Ecosystem
You may have heard of the whack-a-mole game: every time a ransomware group is taken down by law enforcement, two or three new ones appear. Figure 2 shows the number of new ransomware groups appearing every month since January 2023. New groups present opportunities for new people to enter this area of online crime. Whether there’s a net positive from law enforcement activity disrupting ransomware infrastructure and indicting individuals beyond the reach of western justice is a legitimate question.
The problem is that more new groups appear than existing groups disappear, so the number of active ransomware groups – those claiming at least one victim in any given month – has been steadily increasing for years now. Figure 3 tells the tale of this relentless growth industry.
This churn in the ransomware ecosystem produces new working relationships between individuals, a cross-pollination that can result in shared knowledge and more effective criminal collaborations. Newer and smaller groups fill a role similar to farm leagues in sports: allowing new people to enter the game and hone their skills, while creating a career path for the skilled ones to make it to the big leagues where the real money is. This is true for the actual members of RaaS groups as well as the affiliates they rely on to identify and breach victims.
This system acts as a training ground, introducing more criminals into the industry, creating more groups including the successful ones that consistently compromise 50 or more victims per month. And the apex groups continue to evolve, relying on proven tactics while adapting to evolving cyber defense strategies by using their revenue to invest R&D to develop future threats. Figure 4 shows a heatmap of active ransomware groups every quarter since 2023, tracking their victim count by color.
A small number of groups have quietly been remarkably successful, chocking up large numbers of victims month over month for years. Some criminal groups include:
- DragonForce, first appearing in December 2023 with possible ties to Malaysia, claiming victims monthly including 28 last month, 253 in the first half of 2026, and 590 so far;
- IncRansom, first appearing in August 2023, with victims claimed every month including 30 victims last month, almost 250 in the first half of this year, and over 800 in total. Identified by Australia as being based in Russia;
- Akira first appearing in April 2023, the Russian-language group has had victims claimed every month since then including 32 victims last month, more than 300 in the first half of this year, and an eye-watering total approaching 1500.
- Qilin, a Russian-speaking group of unknown location operating since 2022, is currently the most prolific group. It’s claimed victims every month since February 2023, including 78 victims last month, 665 in the first half of this year, and a staggering total fast approaching 2000. Qilin has claimed more victims than any other group every month since June 2025!
Ransomware groups that survive have learned to evade law enforcement by avoiding the attention drawn by controversial victims such as hospitals and federal government departments, and maintaining tight discipline and operational security with their teams and affiliates. The less competent groups, meanwhile, sometimes resort to making death threats, a reckless tactic that tends to accelerate their identification and arrest.
The Current Response to Ransomware
As the data clearly show, our current strategies for dealing with ransomware groups are having limited success:
- Relying on technology alone doesn’t provide sufficient protection;
- Targeting and taking down the infrastructure used by ransomware groups is easy to counter by bring up new servers;
- Identifying and indicting the leaders of ransomware operations, occasionally leading to arrests and convictions, has done nothing to reduce the number of victims.
A relatively recent strategy by western governments is to become more offensive in disrupting criminal cyber operations. Canada’s Communications Security Establishment (CSE) recently reported taking “action against 10 of the most significant ransomware groups causing harm to Canada and its allies”. New and different ideas are clearly needed to stem the tide of attacks.
One conclusion that can be drawn from this analysis is that every organization has to take their cyber defenses seriously. They can’t be relegated to a line item in an IT budget: an adequate defense needs board-level oversight, and it has to involve people and processes, along with technology.
Closing Remarks
Ransomware continues to evolve faster than the strategies used to combat it. Despite years of law enforcement operations, infrastructure takedowns, and indictments, the number of active groups and claimed victims continues to grow. The ecosystem has become increasingly resilient, with new groups quickly replacing those that disappear and experienced operators sharing knowledge across criminal networks.
Emsisoft Endpoint Protection: Award-Winning Security Made Simple
Experience effortless next-gen technology. Start Free TrialFor organizations, the implication is clear: ransomware is not a temporary surge but a persistent business risk. Effective defense requires more than security software alone. Organizations need a layered approach that combines technology, skilled people, well-defined processes, and executive-level commitment. As threat actors continue to adapt, defenders must do the same.
