Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts

GuidePoint also documented DragonForce's use of large language models during extortion negotiations.

 


Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the previous quarter and a 43% jump compared with the same period last year, according to GuidePoint Security's latest quarterly ransomware report. Researchers also recorded the highest number of active ransomware groups seen in a single quarter, reflecting an ecosystem that continues to attract new threat actors even as attacks remain concentrated among a relatively small number of established operations.

Despite the growing number of ransomware groups, a handful of operators continue to dominate victim claims. GuidePoint found that the five most active groups were collectively responsible for more than 40% of all publicly reported ransomware incidents during the quarter, suggesting that while new groups continue to emerge, only a few have achieved sustained operational scale.

Qilin remained the most active ransomware operation during Q2, accounting for approximately 13% of all recorded victim claims. It was closely followed by The Gentlemen, a comparatively new group that has expanded rapidly in recent months. Together with Akira and DragonForce, the two groups make up what GuidePoint describes as a "four-headed monster," representing the most prolific ransomware operations currently shaping the threat landscape.

Rather than relying on a single dominant ransomware syndicate, today's ransomware ecosystem is distributed across several highly active groups capable of absorbing affiliates from disrupted operations. Researchers noted that this structure could reduce the long-term impact of law enforcement takedowns, as affiliates displaced from one ransomware-as-a-service (RaaS) platform may quickly transition to another established operation without substantially disrupting attack activity.

The United States remained the country most frequently targeted by ransomware groups during the quarter, accounting for 40% of publicly claimed victims. Germany ranked second with 32%. However, GuidePoint observed a noticeable shift in targeting patterns, with the U.S. accounting for a smaller proportion of victims than in previous quarters, when roughly half of all reported incidents involved American organizations.

Researchers linked this broader geographic distribution to increased activity from groups including Qilin, The Gentlemen and LockBit, each of which claimed a larger share of victims outside the United States during Q2. The findings suggest that ransomware affiliates are expanding their operations across a wider range of regions instead of concentrating primarily on U.S.-based organizations.

Alongside changes in victim targeting, the report examined how artificial intelligence is being incorporated into ransomware operations. While concerns have grown around the possibility of AI creating entirely new forms of cyberattacks, GuidePoint found little evidence to support that scenario. Instead, threat actors are primarily using large language models (LLMs) to accelerate tasks that previously required significant manual effort, allowing them to improve efficiency without fundamentally changing their attack methods.

One case study highlighted in the report involved the data extortion group FulcrumSec. After obtaining a large volume of stolen information, the group reportedly used an LLM to examine complex databases and identify individuals appearing across multiple datasets. According to researchers, completing this level of analysis manually would have required either extensive knowledge of the victim's database architecture or a substantial investment of time by human operators.

The information extracted from the stolen data was then paired with AI-generated negotiation messages written in English. By demonstrating a detailed understanding of the compromised information, FulcrumSec strengthened its position during ransom negotiations, providing victims with evidence of the data in its possession while using those findings to justify its ransom demands.

GuidePoint also documented DragonForce's use of large language models during extortion negotiations. Researchers said the group generated convincing messages that sought to increase pressure on victims, including claims that it had legal counsel available to advise its operations. Although the report describes that assertion as almost certainly false, it illustrates how AI can help cybercriminals produce persuasive communications intended to exploit concerns around regulatory obligations, legal consequences and reputational damage.

According to the researchers, the effectiveness of these messages does not necessarily depend on their accuracy. Instead, their value lies in presenting information in a manner that appears credible enough to influence decision-making during negotiations. Large language models, which are capable of generating fluent and convincing text within seconds, are increasingly being used to support these psychological tactics.

Taken together, the findings indicate that AI is currently serving as an operational force multiplier rather than introducing an entirely new category of ransomware attacks. Tasks such as analyzing stolen data, organizing information, preparing victim communications and drafting negotiation messages can now be completed more quickly, enabling threat actors to devote more time to other stages of their operations.

At the same time, the continued concentration of attacks among a small group of highly active ransomware operations suggests that scale, organization and affiliate networks remain key drivers of today's ransomware economy. While new groups continue to enter the ecosystem, a limited number of established operators continue to account for a disproportionate share of publicly claimed attacks, reinforcing their influence across the global ransomware ecosystem.

Share it:

AI

Cyber Attacks

Cyber Extortion

LLMs

LockBit

qilin

RaaS

Ransomware