Ransomware vs Phishing
Ransomware
1,181
statistics from 109 sources
Phishing
449
statistics from 98 sources
Latest Ransomware
Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.
Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
Ten active ransomware families operated simultaneously against the professional services sector in the first half of 2026, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
460 organizations in the professional services sector are actively detecting ransomware campaigns, representing the broadest exposure of any vertical.
7% of reported cybercrime cases in Africa in 2025 involved ransomware or Banking Trojan stealers.
The highest ransom demand in Q2 2026 was $25 million.
Qilin accounted for 285 undisclosed attacks (14%), The Gentlemen accounted for 219 (11%), and Dragon Force accounted for 137 (7%) in Q2 2026.
The number of undisclosed ransomware attacks fell 6% compared to the previous quarter.
41% of ransomware attacks exploited brand reputation.
35% of ransomware attacks exploited employee data.
31% of ransomware attacks exploited intellectual property.
Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.
Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.
Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
Latest Phishing
Vishing intrusions increased by 2x in 1H 2026.
17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing.
Monthly device code phishing attempts increased 15x in 1H 2026.
In the first half of 2026, 67% of phishing emails passed DMARC.
39% of phishing messages featured novel social engineering techniques.
VIP users were targeted in 25.8% of phishing attacks.
The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).
Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.
Before any training, roughly one in three employees is likely to engage with a phishing attempt.
Almost 86% of phishing attacks contain AI-generated elements.
The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
Phishing events detected on employee mobile devices have grown 380% since January 2025.
Phishing was the primary means of gaining initial access in over half of Cisco Talos Incident Response engagements this quarter, up from approximately one-third of engagements last quarter.
The ARToken panel exposed 80+ API endpoints for device code phishing, primary refresh token persistence, email access, BEC operations, and SharePoint exfiltration.
Microsoft was the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts.