Ransomware activity hit second-highest Q1 on record

Check Point Research said the top 10 ransomware groups accounted for 71% of recorded victims, reflecting a growing focus on organizations where attackers already had access to vulnerable systems.

 


Global ransomware activity remains near historic highs, but the biggest shift in 2026 is the concentration of power among fewer attacker groups.

According to Check Point Research, the leading ransomware groups now account for 71% of recorded victims.


Ransomware activity during the first quarter of 2026 remained at elevated levels, although the main shift identified by Check Point Research was the growing consolidation of the ransomware ecosystem among fewer groups.

According to the report, the top 10 ransomware groups accounted for 71% of all victims recorded during the period.

The report documented 2,122 extorted organizations during the quarter, making it the second most active first quarter on record. According to the firm, this reflects how ransomware has moved beyond isolated incidents and consolidated into a persistent threat for organizations.

Attack concentration.

Qilin remained the most active group for the third consecutive quarter, with 338 recorded victims. Meanwhile, The Gentlemen increased from 40 victims in the fourth quarter of 2025 to 166 in the first quarter of 2026, while LockBit returned to the ranks of the most active operations following a previous disruption.

Access and vulnerabilities.

According to the analysis, prior access to vulnerable infrastructure, exposed VPNs and compromised systems is playing an increasingly important role in target selection. This means attackers are increasingly prioritizing environments where they already have access or an established presence, beyond sectors traditionally considered to have the highest economic value.

The report also identified a growing concentration of victims in Asia-Pacific and Latin America, while the United States remained the most affected country, accounting for 49.6% of recorded global victims.

Operational impact.

Sectors such as manufacturing, business services, healthcare and industry remain among the hardest hit due to operational sensitivity and the disruption caused by intrusions.

In practice, the operational costs associated with service disruptions are becoming one of the main cost drivers in these types of attacks.

Check Point Research also said ransomware is evolving toward more repeatable and scalable operations, built on pre-established access and faster attack cycles.

Sergey Shykevich, Threat Intelligence Group Manager at Check Point Software, said:

“Ransomware in 2026 is no longer about numbers, but about concentration and acceleration. When fewer, but more capable, groups drive most attacks, each incident carries greater operational and financial impact. At the same time, AI is beginning to shorten the attacker lifecycle, from access to exploitation, making existing vulnerabilities more dangerous than ever. Organizations must shift from reacting to ransomware incidents to proactively reducing exposure by closing access gaps, strengthening identity and network controls, and limiting lateral movement before attacks unfold at machine speed.”

Share:
Hosting Web
Most Read