The State of Ransomware Q2 2026
August 13, 2026 · Check Point Research · Severity: CRITICAL
The ransomware landscape in Q2 2026 shows a shift toward decentralization, with more groups active but lower dominance by top players. Payment rates continue to decline, but high-value targets still yield significant revenue. Law enforcement efforts focused on disrupting shared infrastructure to weaken multiple operations simultaneously.
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but the road to joining them has gotten a great deal shorter.
Key observed findings
- The ecosystem stayed concentrated even as its tail widened considerably. The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report.
- Victim volume held at an elevated baseline and did not meaningfully change QoQ. Data leak sites recorded 2,139 victims in Q2, essentially flat versus Q1 (up 0.8%) and up 33% year over year, keeping pace with the highs set through 2025.
- Qilin and The Gentlemen fought a close race for the top spot all quarter. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims, though its count fell 17%, while The Gentlemen surged 62% to 269 victims and actually outpaced Qilin during the month of June.
- An internal leak gave an unprecedented look inside The Gentlemen’s operation. Chat logs and platform data exposed a core team of roughly nine operators supported by a broader affiliate base, along with confirmation that the group used AI coding assistants to build its ransomware management panel in about three days, genuine first party evidence of AI accelerating malicious tooling development.
- Ransom payment rates fell to a multi year low near 23%, continuing a six year decline from 85% in 2019. Even so, on chain ransomware payments still exceeded $820 million in 2025, and the payer market itself is splitting: average payments are rising even as the median falls, a sign that large enterprises keep paying heavily while the mid market increasingly holds firm or settles small.
- Law enforcement concentrated its Q2 efforts on shared infrastructure rather than individual groups. Actions took down a cryptocurrency laundering platform used by multiple ransomware actors, prompted sanctions against major Iranian digital asset exchanges, dismantled a malware signing service abused by several RaaS operations, and disrupted large infostealer and VPN anonymization networks that many groups depend on at once.
- The geographic picture shifted meaningfully. The US share of victims fell from 50% to 42% quarter over quarter, largely because the quarter’s fastest growing groups, including The Gentlemen and the newly active Krybit, target the US far less often than the ecosystem average.
- The exploitation window kept narrowing, with AI increasingly cited as the accelerant. Vulnerabilities are now being weaponized within hours to days of disclosure, lowering the cost of exploit development and giving ransomware operators one more edge in the race to reach victims first.
To read the full findings, access the State of Ransomware Q2 2026 report from Check Point Research here.
The post The State of Ransomware Q2 2026 appeared first on Check Point Research.
Key Takeaways
- The ransomware ecosystem is becoming less concentrated, with the top 10 groups accounting for 57.6% of victims, down from 71% in Q1, while the number of active groups rose to 93.
- Ransom payment rates hit a multi-year low of 23%, yet on-chain payments still exceeded $820 million in 2025, with large enterprises paying more while mid-market victims resist.
- Law enforcement targeted shared infrastructure in Q2, disrupting cryptocurrency laundering platforms, malware signing services, and VPN anonymization networks used by multiple ransomware groups.