The State of Ransomware in Q2 2026

The State of Ransomware in Q1 2026

In this post, we look at Q2 2026 ransomware activity and how it’s changed over the last three and a half years, going back to January 2023. The data used for the analysis comes from two excellent sources: RansomLook.io, and ransomware.live. These sites continually search the internet and the dark web for threat actor claims of new victims, although it’s important to remember that the actual number of victims is likely to be significantly higher than those reported. Together, they offer significant benefits for historical analysis of ransomware activity, including:

The data used for this analysis, representing victim claims from January 2023 to the end of June 2026, comprises 24,278 records from ransomware.live and 24270 records for RansomLook.io. That’s an impressively small 3.9% deviation in the size of their data sets over 42 months.

Since the beginning of 2023, the ransomware space has seen a lot of changes: international law enforcement activity has taken down forums and dark web DLS sites, individuals have been identified and, in some cases, brought to justice, ransomware groups have come and gone. What trends in ransomware data can be seen over this period?

Ransomware Victims Continue to Rise

Analyzing over three years of data from RansomLook.io and Ransomware.live produces grim results. The number of victims claimed has risen steadily for the last three and a half years, as can be seen in Figure 1. The number of ransomware victims in the first half of the year more than doubled between 2023 and 2026, from just over 2000 to well over 4500.

Figure 1: Ransomware victims 2023-2026

Figure 1: Ransomware victims 2023-2026

The Evolution of the Ransomware Ecosystem

You may have heard of the whack-a-mole game: every time a ransomware group is taken down by law enforcement, two or three new ones appear. Figure 2 shows the number of new ransomware groups appearing every month since January 2023. New groups present opportunities for new people to enter this area of online crime. Whether there’s a net positive from law enforcement activity disrupting ransomware infrastructure and indicting individuals beyond the reach of western justice is a legitimate question.

Figure 2: New ransomware groups 2023-2026

Figure 2: New ransomware groups 2023-2026

The problem is that more new groups appear than existing groups disappear, so the number of active ransomware groups – those claiming at least one victim in any given month – has been steadily increasing for years now. Figure 3 tells the tale of this relentless growth industry.

Figure 3: Active ransomware groups 2023-2026

Figure 3: Active ransomware groups 2023-2026

This churn in the ransomware ecosystem produces new working relationships between individuals, a cross-pollination that can result in shared knowledge and more effective criminal collaborations. Newer and smaller groups fill a role similar to farm leagues in sports: allowing new people to enter the game and hone their skills, while creating a career path for the skilled ones to make it to the big leagues where the real money is. This is true for the actual members of RaaS groups as well as the affiliates they rely on to identify and breach victims.

This system acts as a training ground, introducing more criminals into the industry, creating more groups including the successful ones that consistently compromise 50 or more victims per month. And the apex groups continue to evolve, relying on proven tactics while adapting to evolving cyber defense strategies by using their revenue to invest R&D to develop future threats. Figure 4 shows a heatmap of active ransomware groups every quarter since 2023, tracking their victim count by color.

Figure 4: Growth of active groups by quarter, ranked by victims claimed | 2023-2026

Figure 4: Growth of active groups by quarter, ranked by victims claimed | 2023-2026

A small number of groups have quietly been remarkably successful, chocking up large numbers of victims month over month for years. Some criminal groups include:

Ransomware groups that survive have learned to evade law enforcement by avoiding the attention drawn by controversial victims such as hospitals and federal government departments, and maintaining tight discipline and operational security with their teams and affiliates. The less competent groups, meanwhile, sometimes resort to making death threats, a reckless tactic that tends to accelerate their identification and arrest.

The Current Response to Ransomware

As the data clearly show, our current strategies for dealing with ransomware groups are having limited success:

A relatively recent strategy by western governments is to become more offensive in disrupting criminal cyber operations. Canada’s Communications Security Establishment (CSE) recently reported taking “action against 10 of the most significant ransomware groups causing harm to Canada and its allies”. New and different ideas are clearly needed to stem the tide of attacks.

One conclusion that can be drawn from this analysis is that every organization has to take their cyber defenses seriously. They can’t be relegated to a line item in an IT budget: an adequate defense needs board-level oversight, and it has to involve people and processes, along with technology.

Closing Remarks

Ransomware continues to evolve faster than the strategies used to combat it. Despite years of law enforcement operations, infrastructure takedowns, and indictments, the number of active groups and claimed victims continues to grow. The ecosystem has become increasingly resilient, with new groups quickly replacing those that disappear and experienced operators sharing knowledge across criminal networks.

Emsisoft Enterprise Security + EDR

Robust and proven endpoint security solution for organizations of all sizes. Start free trial

For organizations, the implication is clear: ransomware is not a temporary surge but a persistent business risk. Effective defense requires more than security software alone. Organizations need a layered approach that combines technology, skilled people, well-defined processes, and executive-level commitment. As threat actors continue to adapt, defenders must do the same.

Luke Connolly

Luke Connolly

Threat intelligence analyst. Keeps an eye on the dark shadows of the internet so you don’t have to.

What to read next