Cyber Extortion Picks Up Pace

7,551 victims later.
Elizabeth Rigsby
Contributing Writer
Cyber news, ransomeware, victims, 2026, growth, disclosed, cyber, risk
stock.adobe.com

Ransomware continued its multiyear growth in 2026, with 7,551 publicly disclosed victims recorded between April 2025 and March 2026, up 24.9% from the previous year. Most of the increase came in the second half, when the monthly average rose from 484 victims to 775.

More ransomware groups entered the market, smaller and mid-sized organizations represented a larger share of victims, and several incidents involved technology providers or applications that already had trusted access to customer environments.

Many victims also had visible exposure before disclosure, while some of those issues remained after the incident.

AI is making it easier for smaller ransomware groups to take on work that once required more experience and resources.


Why It Matters: Ransomware risk has long extended outside an organization’s own systems, and that pattern continues. Vendors and connected applications remain sources of exposure that can be difficult to see and control, while weaknesses can persist even after an incident is resolved. That puts more weight on understanding where access exists, which technology relationships create risk, and whether recovery efforts are actually reducing exposure.

  • More Groups Are Entering the Market: The number of active ransomware groups rose from 96 the previous year to 127 at the end of the reporting period, reaching 146 by June 2026. 61 new groups entered during the period, yet the top 5 accounted for 43.6% of observed victims. Qilin alone claimed 1,358. Newer groups had a median lifespan of 4.9 months, compared with 12.8 months for the previous cohort. Frequent turnover means the disappearance of 1 ransomware brand may have limited effect on the people, access methods, or capabilities operating elsewhere in the market.
  • The Victim Profile Is Changing: $1 million to $5 million revenue band’s share of known-revenue victims increased from 3.0% to 5.1%, while the $50 million to $100 million segment rose from 25.1% to 29.3%. The $100 million-plus tier declined from 13.9% to 9.5%. The United States remained the largest victim country, although activity grew faster elsewhere. Manufacturing remained the most affected industry, while construction moved into third place. The changing mix makes company size or geography less useful on its own for determining where ransomware exposure is concentrated.
  • Third-Party Technology Extends the Attack Surface: Several incidents involved SaaS integrations, OAuth tokens, enterprise applications, and support platforms. Compromised OAuth tokens associated with Salesloft Drift were used to access Salesforce customer instances, while Oracle EBS demonstrated how a vulnerability in widely used enterprise software could affect many organizations. Vendor permissions and connected applications now need to be considered alongside internally managed systems when assessing ransomware exposure.
  • Exposure Can Be Visible Before an Incident: Before disclosure, 68.1% of victims had misconfiguration findings, 46.9% had exposed remote-access ports, 43.2% had software vulnerabilities, and 34.5% had stealer-log findings. More than 60% carried at least 1 ransomware-relevant finding involving software vulnerabilities, credential stuffing, or stealer logs. That visibility creates an opportunity to prioritize remediation before an organization appears on a ransomware leak site.
  • Recovery Does Not Always Remove the Exposure: Getting systems back online does not necessarily mean the underlying risk is gone. In the latest assessment, 43.5% of victims still had critical vulnerabilities, while stealer-log exposure was 175% higher in the before-and-after comparison. Some organizations improved their overall security posture after an incident, yet ransomware-related weaknesses remained, making what is still visible afterward an important part of measuring recovery.

Go Deeper -> 2026 Ransomware Report – Blackkite

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters