Security News

Cybersecurity news aggregator

MEDIUM Attacks Dark Reading

Ransomware Is Accelerating, But It's Not Because of AI

  • What: Ransomware activity is accelerating due to a fragmented ecosystem and new attackers.
  • Impact: Enterprises face more attacks and a larger pool of adversaries.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK THREAT INTELLIGENCE NEWS Ransomware Is Accelerating, But It's Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations. Jai Vijayan,Contributing Writer July 21, 2026 4 Min Read SOURCE: FADFEBRIAN VIA SHUTTERSTOCK Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem. For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against. 25% Increase in Incident Volume Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack. Related:'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover "This isn't a problem we've contained," says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. "It's still a lucrative business, and the barrier to running one keeps getting lower." Black Kite attributed the growth in attack volume to a combination of factors, including the fragmentation of the ransomware ecosystem, the emergence of dozens of new groups, and an expansion of attacks on small and less defended organizations. The company also pointed to third-party and supply chain compromises, such as those involving Oracle and Salesforce as allowing attackers to leverage a single breach into multivictim campaigns. "Groups like Qilin redefined what a single attack looks like, with one [managed service provider or MSP] compromise reaching 32 South Korean financial institutions," Dikbiyik notes. "One vendor, dozens of victims." Many Victims Had Externally Visible Weaknesses One consistent pattern Black Kite uncovered was that many victims had high ransomware susceptibility index (RSI) scores — a measure the company uses to assesses an organization's exposure to ransomware attacks based on externally visible factors like exposed credentials and unpatched vulnerabilities. Some 41% of companies that had an RSI higher than 0.8 experienced a ransomware incident during the study period, compared to just 0.14% of organizations with scores below 0.2. More than 90% of victims showed a meaningful spike in their RSI score just before being hit. Susceptibility comes down to exposure and predisposition, Dikbiyik points out. "Exposure is what's externally visible: misconfigurations, exposed remote access, credential stuffing, stealer logs," he says. "Predisposition is who you are, your geography, your industry, your revenue band, the size of your digital footprint." Most victims, Dikbiyik adds, weren't breached because they were uniquely weak. "They were breached because they were visible, exposed, and a fit for what attackers were already looking for." Related:ClickFix's Mushrooming Ecosystem Demands New Defense Tactics As has been the case for some time, manufacturing companies remained the top target for ransomware actors and accounted for 1,660 victims. Close behind were 1,389 organizations in the professional, scientific, and technical services sector. Construction companies emerged as the third-most targeted sector. Nearly half the victims (49.3%) were US-based organizations but in terms of growth, ransomware attacks in Europe outpaced the US. Large companies remained big targets, but they were no longer the engine of volume growth, Black Kite discovered. Instead, a lot of the activity happened among organizations in the $50 million to $100 million revenue tier, and in the $1 million to $5 million range, meaning no company was too small a target for attackers. A Democratization of the Field? Large established threat groups like Qilin, Everest, Cl0p, and World Leaks continued to rack up victims and to focus largely on US-based organizations. Smaller and newer entrants, meanwhile, picked up most of their victims in Europe, South America, Africa, Asia, and the Middle East. AI did not accelerate ransomware incidents, but it did enable more threat actors with lesser technical skills to get into the game, though not always to stay in it for long. Ransomware operations that Black Kite observed launching between April and September 2025 lasted for a median period of just 4.9 months before dropping out. Black Kite estimated a total of 146 ransomware groups as presently active — up from 127 in March. Related:GigaWiper Lets Threat Actors Choose Their Own Destructive Attack What is most surprising is how the growth in ransomware volume has taken place without the need for any new kind of attacker, Dikbiyik says. "Open source LLMs and code agents lowered the cost of building an original operation, and we saw early signs of AI-assisted code showing up in encryptors," he says. But it's hard to say if AI drove an acceleration in ransomware attacks. "What I can say is the growth is human. AI just let more people show up at once." Troublingly, many victims of ransomware attacks appeared to do little to reduce their overall exposure to repeat incidents. Dikbiyik views that as a sign of victims being in a hurry to close the incident without addressing what made them a target in the first place. "My advice is to treat the post-incident period as ongoing work, not a closed case, with structured exposure reviews at 30, 60, and 90 days," he says. He also recommends prioritizing by what’s actually being exploited, not by CVSS score alone, and extending visibility into vendor and software-as-a-service (SaaS) relationships and implementing continuous monitoring. About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Editor's Choice VULNERABILITIES & THREATS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes byJai Vijayan JUL 14, 2026 5 MIN READ PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operat

Share this article