GuidePoint Security
Reports
All Statistics
Ratios of non-human to human identities reach as high as 75 to 1.
77.3% of organizations report high or very high confidence they can see all identities across their environment.
18.5% of organizations run identity discovery continuously or in near real time.
There were 91 active ransomware groups operating across 108 countries in Q2 2026, a record high.
Q2 2026 recorded 2,279 reported ransomware victims, a 7% increase from Q1 2026 and a 43% increase from Q2 2025.
The five most prolific ransomware groups collectively claimed more than 40% of all recorded attacks.
The Gentlemen ransomware group increased from 35 victims in Q4 2025 to 182 victims in Q1 2026.
The construction industry experienced 131 ransomware victims in Q1 2026, a 44% year-over-year increase.
51% of observed ransomware victims in Q1 2026 were based in the United States; the United Kingdom and Canada each accounted for 4%.
There were 200 publicly claimed manufacturing organizations that were victims of ransomware attacks in Q2 2025.
The Qilin campaign claimed 29 financial organizations headquartered in the Republic of Korea as victims to their DLS in a mid-September Qilin campaign.
56.00% of global ransomware victims (organizations and individuals) in Q3 2025 were from the United States.
The number of active ransomware groups climbed from 45 in Q2 2024 to 71 in Q2 2025.
23% of observed ransomware victims in Q2 2025 were based in Singapore.
5% of observed ransomware victims in Q2 2025 were based in Canada.
There was also a record high number of active threat groups, with 70 identified in Q1 2025. This is a 55.5% year-over-year rise.
The industries most heavily impacted by ransomware in Q1 2025 were manufacturing, retail, and technology. Notably, the non-profit sector saw a dramatic surge in ransomware attacks, with incidents doubling quarter-over-quarter .
The first quarter of 2025 saw a record high in ransomware attacks, with 2,063 victims reported. This represents a 102% increase compared to the previous year.
Abused non-human identities are the initial entry point in 19% of the most recent confirmed identity incidents.
100% of participants report non-human identities are outpacing their identity and access management programs.
Phished or stolen credentials are the initial entry point in 19.5% of the most recent confirmed identity incidents.
Weekly victim postings never fell below 150 during Q2 2026.
Manufacturing accounted for nearly 15% of reported ransomware victims in Q2 2026.
Ransomware victim post rates averaged approximately 150–200 per week in Q1 2026 and remained steady quarter-over-quarter and year-over-year.
Activity from the Qilin ransomware group declined by 25% and activity from the Akira ransomware group declined by 22%.
SafePay impacted 111 organizations and individuals spread across 27 industries and 18 countries in Q2 2025.
Toha personally profited over €7 million from trading malware, stolen data, and malicious access on his platform.
Qilin's activity marks a 318% YoY increase.
In Q2 2025, there were 92 reports of ransomware attacks on healthcare organizations.
There were 1,576 total public posts related to ransomware victims (organizations and individuals) in Q3 2025.
IncRansom's Q3 2025 victim count was 126 organizations and individuals.
There were 252 publicly claimed manufacturing organizations that were victims of ransomware attacks in Q3 2025.
SafePay impacted 71 organizations and individuals across 19 industries and 16 countries in Q3 2025.
In Q2 2025, ransomware attacks on healthcare organizations accounted for 5.8% of all ransomware attacks.
In Q3 2025, manufacturing organizations experienced a 26% increase in ransomware attacks.
Qilin recorded 234 victims (organizations and individuals) in Q3 2025.
The emerging threat group 'The Gentlemen' posted 32 victims (organizations and individuals) on a single day once their data leak site went live in 2025.
2.35% of global ransomware victims (organizations and individuals) in Q3 2025 were from France.
Qilin claimed 10 healthcare organizations as victims in Q3 2025.
GLOBAL and BlackLock had four distinct names in a little over a year.
IncRansom, SafePay, and Qilin together accounted for 30% of the 118 healthcare organizations that were victims in Q3 2025.
There were 77 total ransomware groups active in Q3 2025.
2.79% of global ransomware victims (organizations and individuals) in Q3 2025 were from Canada.
2.03% of global ransomware victims (organizations and individuals) in Q3 2025 were from Spain.
Ransomware groups claimed 118 healthcare organizations as victims in Q3 2025.
During Q3 2025, Akira claimed one healthcare industry organization as a victim on their DLS.
The average number of public posts related to ransomware victims (organizations and individuals) per week in Q3 2025 was 121.
2.48% of global ransomware victims (organizations and individuals) in Q3 2025 were from the Republic of Korea.
Rhysida has claimed over 200 organizations and individuals as victims to their dark web DLS.
Akira had 133 victims (organizations and individuals) in Q2 2025.