Ransomware Attacks Surge 20% in First Half of 2026

ALN NEWS DESK
ALN NEWS DESK
Updated : Jul 15, 2026, 04:30 PM IST
5 min read
  • linkedin
  • twitter
  • facebook
  • instagram
  • whatsapp

A new report reveals a significant rise in ransomware incidents, driven by two competing groups, highlighting the evolving threat landscape.

The rise of ransomware attacks has become a pressing concern in the cybersecurity landscape, particularly as we move further into 2026. According to a recent report from NordStellar, there has been a significant surge in ransomware incidents, with a 20% increase year-over-year in the first half of the year, culminating in a total of 5,275 recorded attacks. The second quarter alone accounted for 2,581 of these incidents, underscoring the alarming trend of escalating cyber threats.

While the overall number of ransomware attacks saw a slight decrease of 4% in the second quarter compared to the first three months of the year, cybersecurity experts caution that this should not be interpreted as a sign of improvement. Vakaris Noreika, a cybersecurity expert from NordStellar, emphasizes the importance of vigilance, stating, "The slight decrease in attacks shouldn’t be a sign to relax just yet. Although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter." This perspective highlights the persistent and evolving nature of ransomware threats.

The landscape of ransomware attacks is largely shaped by two competing ransomware-as-a-service (RaaS) groups: Qilin and The Gentlemen. Qilin, which has been operational since at least 2022, has established itself as one of the most formidable ransomware operations globally. The group has targeted various organizations, including notable victims such as the healthcare group Synnovis and the Cleveland Municipal Court. Its notoriety is matched by its operational capacity, as it has been responsible for a significant number of attacks.

In contrast, The Gentlemen emerged from a split within Qilin in 2025 and has quickly gained traction, reportedly attacking hundreds of organizations across more than 66 countries and 20 different industries. In the second quarter of 2026, The Gentlemen was attributed with 284 attacks, a figure that, while lower than Qilin's 299, still represented a remarkable 39% increase from the previous year. This competition between the two groups illustrates a broader trend of sophistication and strategic maneuvering within the ransomware ecosystem.

NordStellar's analysis indicates that the growing influence of these two groups suggests a maturation of the ransomware ecosystem, which could pose even greater risks to businesses and individuals alike. Mantas Sabeckis, a senior threat intelligence researcher at Nord Security, notes, "Established ransomware groups have refined tools, affiliate networks, and negotiation infrastructures. The more sophisticated and established a group becomes, the greater the threat it poses." This maturation not only enhances the operational capabilities of these groups but also complicates the landscape for cybersecurity professionals trying to combat these threats.

Small and midsize businesses have emerged as primary targets for ransomware attacks, accounting for more than 60% of incidents in the first half of 2026. This trend is particularly concerning given that these organizations often lack the robust cybersecurity infrastructure of larger corporations. In fact, large companies with annual revenues exceeding $1 billion experienced a staggering 74% increase in attacks, rising from 23 incidents in the first quarter to 40 in the second. This shift in targeting patterns indicates that attackers are increasingly focusing on vulnerabilities within smaller organizations, which may be less equipped to defend against sophisticated cyber threats.

While NordStellar's report does not delve into the specific methods employed by hackers, a separate study conducted by the SANS Institute sheds light on the evolving tactics in use. The SANS report reveals that 78% of organizations have experienced confirmed or suspected AI-enabled attacks in the past year. As the capabilities of artificial intelligence continue to advance, a growing number of organizations are also leveraging this technology for protective purposes. The percentage of cybersecurity teams actively utilizing AI in their defenses has risen from 50% in 2025 to 78% in 2026. However, the effectiveness of AI in cybersecurity remains a topic of concern, with 63% of security teams reporting significant shortcomings in AI's ability to detect or respond to threats. This represents an increase of nearly 20% from the previous year, indicating that while AI technology is being adopted, its implementation is fraught with challenges.

Despite the shortcomings in AI's defensive capabilities, its offensive potential appears to be advancing rapidly. Earlier this month, cloud security firm Sysdig reported on a groundbreaking ransomware campaign named JadePuffer, which is notable for being operated entirely by a large language model. This AI-driven campaign demonstrated an alarming efficiency, managing to breach systems at a pace far exceeding that of traditional human-operated campaigns. In one instance, Sysdig documented an AI-driven ransomware tool that transitioned from a failed login attempt to a successful breach in just 31 seconds. This rapid evolution of offensive capabilities serves as a warning sign for cybersecurity professionals and organizations alike, suggesting that the landscape of cyber threats is shifting in unpredictable and potentially dangerous ways.

The implications of these trends are profound. As ransomware attacks become more sophisticated and widespread, organizations must prioritize cybersecurity measures and invest in advanced technologies to protect their data and infrastructure. The increasing prevalence of AI in both offensive and defensive strategies underscores the need for continuous adaptation and vigilance in the face of evolving threats. Moreover, the focus on small and midsize businesses as prime targets highlights the importance of ensuring that all organizations, regardless of size, have access to robust cybersecurity resources and support.

In conclusion, the surge in ransomware attacks in the first half of 2026 reflects a complex and evolving threat landscape. The competition between established ransomware groups, the growing use of AI in cyberattacks, and the shifting focus on smaller businesses all contribute to an environment where cybersecurity is more critical than ever. As organizations navigate these challenges, a proactive approach to cybersecurity, including the adoption of advanced technologies and strategies, will be essential in mitigating the risks posed by ransomware and ensuring the safety of sensitive information.

Get More Updates

To learn more about the latest developments in Crime & Law, stay updated with our exclusive reports and analyses on AiLensNews.

Related News