Ransomware Proliferates as Payment Demands Fall and Recovery Costs Climb

Ransomware has always followed a brutal economic logic: criminals encrypt data, demand payment, and organizations weigh the cost of rebuilding against the ransom. In 2026, that logic is fracturing. Threat actor groups are multiplying at a record pace, yet the median ransom demand has dropped by more than two-thirds from its peak. Meanwhile, the operational cost of recovering from an attack keeps climbing. The result is a paradox that is reshaping how enterprises, insurers, and defenders must think about resilience.

A Record Year for Ransomware Activity

The numbers paint a stark picture. Black Kite’s 2026 Ransomware Report identified 7,551 publicly disclosed ransomware victims between April 2025 and March 2026, a 24.9% increase over the previous reporting period. More striking is the acceleration: victim counts surged 60% in the second half of that window, closing with 861 victims in March 2026 alone — the highest monthly total in four years of tracking.

The proliferation of threat actors is driving this surge. More than 60 new ransomware groups entered the market during the reporting period, averaging more than one new group per week. By June 2026, there were 146 active ransomware operations. Yet this expansion at the bottom has not diluted the top: the five largest actors still controlled 43.6% of all victims. Qilin alone claimed over 1,300 victims, nearly twice as many as its nearest rival.

The Qilin-Gentlemen Duopoly

Among attacks that could be attributed to a known threat actor, Qilin accounted for 164 incidents in the most recent reporting cycle, while The Gentlemen — reportedly a Qilin splinter group — accounted for 116. Clop followed with 89 attributions, with Dire Wolf and INC Ransom each tied at 43. The Gentlemen has been described by security researchers as one of the fastest-scaling ransomware threats under active tracking, having briefly surpassed Qilin in victims claimed on data leak sites during June.

Ransom Demands Are Falling — But Recovery Costs Are Rising

Here is where the paradox deepens. The Sophos State of Ransomware 2026 report surveyed 2,158 IT and cybersecurity leaders across 17 countries and found a dramatic compression in ransom demands:

  • 2024: Median ransom demand of $2 million
  • 2025: Median demand fell to $1.32 million
  • 2026: Median demand dropped to $698,000

Payments followed a similar trajectory. The proportion of victims paying a ransom fell to 48%, while 66% recovered encrypted data using backups — a 12-percentage-point jump from 2025. This suggests that organizations are increasingly refusing to pay and relying on backup restoration instead, squeezing the revenue that ransomware groups can extract per victim.

But the financial relief is one-sided. While ransom demands are shrinking, the cost of recovery — including forensic investigation, system rebuilding, lost productivity, and reputational damage — continues to climb. Organizations are spending less on ransoms but more on the aftermath, a shift that demands a different budgeting mindset. The savings from refusing payment do not flow to the bottom line; they are redirected into incident response and operational downtime.

Identity Has Replaced Vulnerabilities as the Primary Entry Vector

The most significant structural shift in 2026 is how ransomware operators gain access to target networks. After three consecutive years as the top entry vector, exploited vulnerabilities dropped 14 percentage points to 18%. Identity compromise is now the leading delivery mechanism, with stolen credentials accounting for 79% of attack origins — nearly double the combined total of malicious email and phishing.

This finding aligns across multiple industry reports. The Mandiant M-Trends 2026 report highlights the growing role of Initial Access Brokers, specialized threat actors who compromise environments and hand off access to ransomware affiliates. As organizations deploy endpoint and extended detection and response solutions, ransomware actors have adapted by seeking out the corners of the environment where visibility is weakest.

The Email and Phishing Overlap

Malicious email (26%) and phishing (24%) still account for half of all ransomware root causes, but these vectors increasingly serve as identity compromise mechanisms rather than direct malware delivery. Attackers use phishing to harvest credentials, then pivot through legitimate access channels that evade traditional perimeter defenses. The overlap is significant: 67% of ransomware victims confirmed their incident was directly tied to their organization’s most significant identity breach.

Network Edge and VPN Exploitation

While identity is the dominant vector, network edge vulnerabilities remain a high-impact attack surface. Ransomware groups increasingly hammer VPN appliances and perimeter devices for access, with Akira, Qilin, and The Gentlemen identified as heavy users of these vectors. Targeted devices include systems from Fortinet, Citrix, and Check Point.

Attacks that begin with an exploited firewall vulnerability tend to carry higher ransom demands, with 59% asking for $1 million or more. This suggests that threat actors perceive perimeter breaches as higher-value footholds, warranting larger extortion demands — even as the overall median demand declines.

AI as a Force Multiplier

The Palo Alto Networks Global Incident Response Report 2026 identifies AI as a growing force multiplier for threat actors. Early signals included AI-generated logos embedded in data leak site HTML. More recently, documented cases show threat actors using AI to support full-scale ransomware campaign planning and execution, including target reconnaissance, phishing content generation, and even autonomous attack adaptation.

A particularly alarming development is the emergence of agentic ransomware — AI-driven systems capable of operating without human intervention. Security researchers have documented cases where AI agents autonomously compromised networks, adapted tactics on the fly, and demanded ransom, completing the attack cycle without direct operator involvement.

Supply Chain Compromise Intersects With Ransomware

Groups like Vect Ransomware and TeamPCP are exploiting CI/CD pipeline dependencies, particularly through npm and PyPI package compromise, to pivot from supply chain access into ransomware deployment. This emerging vector allows attackers to bypass traditional entry defenses entirely, riding trusted software updates into target environments.

Government and Critical Infrastructure Under Siege

Government entities experienced 89 confirmed and 98 unconfirmed ransomware attacks in the first half of 2026, according to Comparitech. US government agencies were targeted the most, accounting for 31% of those attacks. Globally, government ransomware attacks rose 13% to 187 incidents in the first half of the year, with The Gentlemen identified as the most active group against public sector targets.

The targeting of public services carries human costs that extend far beyond financial impact. When ransomware hits healthcare systems, emergency services, or municipal infrastructure, the consequences affect community safety and everyday services that residents rely on.

What Organizations Should Do Now

The data from 2026 reports points to several concrete defensive priorities:

  • Strengthen identity governance: With stolen credentials as the dominant entry vector, organizations must implement robust identity verification, privileged access management, and rapid credential revocation capabilities. Zero-trust principles, widely discussed but rarely implemented, are no longer optional.
  • Invest in backup maturity: The 66% backup recovery rate proves that reliable, tested backups are the single most effective ransomware defense. Organizations should regularly test restore procedures and maintain offline or immutable backup copies.
  • Secure the network edge: VPN appliances, firewalls, and perimeter devices require patching cadences measured in hours, not weeks. Monitor for credential harvesting and brute-force attempts against edge services.
  • Close critical vulnerabilities: Black Kite found that 43.5% of victims still carried critical patch vulnerabilities after incidents were disclosed, and 30.8% carried KEV exposure. Vulnerability management must be continuous, not periodic.
  • Verify vendor and supply chain integrity: As supply chain compromise intersects with ransomware, organizations must scrutinize software dependencies and implement package verification controls.
  • Train help desk and executive staff: Social engineering and executive impersonation remain effective entry vectors. Help desk escalation paths, employee reporting mechanisms, and vendor verification protocols need regular testing and reinforcement.

The Bottom Line

The 2026 ransomware landscape is defined by a counterintuitive dynamic: more attackers, lower per-victim payouts, but higher aggregate recovery costs. Organizations that continue to frame ransomware defense purely in terms of preventing encryption will find themselves unprepared for a threat that increasingly begins with a stolen password and ends with months of operational disruption. The path forward requires treating identity as the new perimeter, backups as the ultimate insurance policy, and resilience — not just prevention — as the measure of security maturity.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading