Ransomware Statistics
2025-2026

 

How we track ransomware activity.

Ransomware remains a significant and growing threat. We examine ransomware attacks by extracting posts from ransomware-dedicated leak sites (DLS) and then use generative AI to identify the victim, their location, and sector. Contact us for a detailed analysis tailored to your company—covering ransomware groups, attack patterns, and strategies to protect your extended attack surface. Below, explore ransomware attack statistics from 2025-2026, updated monthly.

Ransomware attacks 2025-2026

Ransomware activity is expected to remain a significant cybersecurity threat in Q2 2026, with increasing sophistication and targeted attacks on critical sectors like healthcare and finance. Double extortion tactics, where attackers encrypt data and threaten to release it, will likely continue, alongside the proliferation of Ransomware-as-a-Service (RaaS) models. The use of cryptocurrencies for ransom payments is expected to persist despite regulatory scrutiny. Supply chain attacks may rise, amplifying the impact on multiple organizations. In response, organizations are anticipated to invest more in preventive measures, incident response strategies, and employee training, while governments and international bodies enhance efforts to combat ransomware through legislation and cooperation.

Most active ransomware groups

In the past 12 months, ransomware has been on the rise and led by Qilin with an estimated 1448 attacks. Below are the top ransomware victims per group.

Top ransomware victims per country

In the past 12 months, United States led all countries with 3975 attacks, or 36.2% of the total. Below are the top ransomware victims per country.

Top 10 countries

Top ransomware victims per sector

In the past 12 months, Manufacturing led all sectors with 1578 attacks, or 28.9% of the total. Below are the top ransomware victims per industry.

More signal, less noise. Latest ransomware headlines from Bitsight Pulse.

  • 2026-06-12 | SECOM Engineering and 1 other victim attacked by Anubis ransomware group
    The Anubis group has leaked a significant amount of data from SECOM Engineering, a division of the French FÉTIS Group. The leak i…
  • 2026-06-11 | California Water Facilities attacked by Handala ransomware group
    The Handala group has claimed responsibility for hacking water facilities in California, United States. This cyberattack is prese…
  • 2026-06-11 | Kewaunee Scientific attacked by INC Ransom ransomware group
    Kewaunee Scientific has been targeted by the INC Ransom group, resulting in a significant data breach. The attackers claim to hav…
  • 2026-06-11 | Highwoods Properties attacked by thegentlemen ransomware group
    Highwoods Properties, a publicly traded real estate investment trust, has been targeted in a ransomware attack by thegentlemen gr…
  • 2026-06-12 | Distinet Murcia S.L. attacked by Qilin ransomware group
    The Qilin group has targeted Distinet Murcia S.L., a company based in Murcia, Spain, in a ransomware attack. The attackers have l…

Bitsight Pulse consolidates the latest cybersecurity news, ransomware events and data breaches from hundreds of deep web, dark web, social and OSINT sources. Using Bitsight AI, Bitsight Pulse filters and personalizes these news events to your interests.

Free Benchmark Report

Free, customized cyber risk benchmark report

This custom report provides key takeaways regarding your company’s cybersecurity posture (likelihood of breach, industry benchmarks, and threat insights) using Bitsight data that has been independently verified to have the strongest correlation to the likelihood of a cyber incident.