Ransomware Hits Record 7,551 Victims as 61 New Groups Enter the Market

Ransomware hit a genuinely staggering 7,551 victims between April 2025 and March 2026, according to a new Black Kite report, with 61 new ransomware groups entering the market during that period, averaging more than one new group per week, and active threat groups reaching 146 by June 2026. The United States accounted for 49.3% of all observed victims, remaining by far the most targeted country. The report’s release lands the same week two leaders of the Scattered Spider hacking group received 66-month jail sentences in Britain’s biggest cybercrime prosecution to date, after disrupting London’s transport authority and causing $39 million in losses and recovery costs.

Why the Ransomware Landscape Genuinely Changed Shape This Year

Black Kite’s Chief Research and Intelligence Officer Ferhat Dikbiyik specifically noted that previous years were often defined by a single dominant ransomware group or major event, but 2026 proved genuinely different, with more groups entering the market simultaneously as established operators continued scaling and overall attack volume accelerated sharply in the second half of the reporting period. Ransomware disclosures increased 60% in the second half compared with the first, a genuinely dramatic acceleration that suggests the ransomware ecosystem’s fragmentation into more numerous, smaller groups has not reduced overall attack volume, but rather compounded it.

This structural shift carries several important implications for how organizations should think about ransomware risk going forward:

  • Market fragmentation has not reduced total risk — with 146 active groups compared to a landscape historically dominated by a handful of major operations, defenders face a genuinely broader, more diverse set of threat actors and tactics simultaneously
  • Third-party and SaaS attack paths have become genuinely mainstream — the report specifically identifies SaaS platforms, ERP systems, CRM applications, OAuth tokens, and connected business software as common attack paths, confirming that even organizations with strong internal controls face genuine third-party exposure
  • Double extortion remains the dominant, but not universal, strategy — groups like Qilin and Akira specifically paired encryption with data theft to increase operational disruption and payment pressure, though the report notes targeting strategies genuinely differ by group and target revenue band

The Five Largest Groups Still Command Outsized Share

Despite the market’s genuine fragmentation into 146 active groups, the five largest ransomware operations still accounted for 43.6% of all victims, illustrating that scale advantages continue concentrating a meaningful share of attack volume among a relatively small number of dominant operators even as the broader ecosystem diversifies. Europe’s four most affected countries collectively recorded more than 250 additional victims during the reporting period, reinforcing that this remains a genuinely global threat pattern extending well beyond the heavily US-focused targeting the aggregate statistics might otherwise suggest.

Scattered Spider Leaders Receive Britain’s Harshest Cybercrime Sentences

Two leaders of the Scattered Spider hacking group received 66-month jail sentences in Britain’s biggest cybercrime prosecution to date, following their disruption of London’s transport authority that caused $39 million in losses and recovery costs. Sentences of this severity for Scattered Spider leadership specifically send a genuinely significant deterrence signal, given the group’s broader reputation for sophisticated social engineering attacks against major Western organizations throughout 2025 and 2026.

The Chaos Ransomware Group Runs Command-and-Control Through Browsers

Cisco Talos has detailed msaRAT, a Rust-based implant that allows the Chaos ransomware group to run its command-and-control infrastructure directly through the victim’s own browser, found on a compromised Windows machine ahead of encryptor deployment. This browser-based command-and-control approach extends the same broader evasion logic already visible in DragonForce’s Microsoft Teams-hidden traffic, reinforcing that hiding malicious infrastructure inside legitimate, expected application traffic has become a genuinely standard technique across multiple distinct ransomware operations.

What Organizations Should Do Now

Given the confirmed 60% second-half acceleration in ransomware disclosures, organizations should treat current threat intelligence and detection budgets as needing genuine, proportional expansion rather than assuming last year’s security investment levels remain adequate for this year’s meaningfully larger, more fragmented threat landscape. Organizations should specifically audit third-party SaaS, ERP, and CRM integrations for OAuth token and access scope risk, given the report’s explicit identification of these as common attack paths capable of exposing even organizations with otherwise strong internal security controls. And organizations should train detection systems to identify browser-based command-and-control traffic patterns, given Chaos ransomware’s demonstrated use of exactly this technique through msaRAT.

Black Kite’s 7,551-victim, 146-active-group findings confirm what this year’s steady drumbeat of individual ransomware disclosures had already suggested: 2026 represents a genuinely structural shift in the ransomware landscape, one defined by fragmentation and accelerating volume rather than a single dominant threat actor, making comprehensive, adaptive defense considerably more important than targeting any specific group’s known tactics alone.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading