Halcyon
All Statistics
Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
Qilin was responsible for 293 attack claims in Q2 2026, though its volume slid each month, from 113 in April to 108 in May and 72 in June.
Payload was responsible for 37 attack claims in Q2 2026, up from 24 in Q1 2026.
The Gentlemen reached 214 claims in H2 2026 and a single-day leak of 37 victims on May 6.
DragonForce was responsible for 143 claims in H2 2026.
PEAR was responsible for 35 claims in H2 2026, nearly triple the 13 posted the quarter before.
Akira posted 119 attack claims in H2 2026.
WorldLeaks was responsible for 28 claims in H2 2026.
LockBit ended H2 2026 with 102 claims.
In H2 2026, manufacturing (19.8%) was the most targeted industry by ransomware, followed by construction (10.1%), business services (9.0%), retail (8.4%), and software (6.8%).
The in-house GentleKiller framework fielded eight BYOVD variants targeting more than 400 processes across 48 security products.
64% of security leaders rank ransomware among their organization's top three business priorities.
89% of security leaders report some impact on business operations due to ransomware.
74% of security leaders say board inquiries are significantly shaping anti-ransomware investments.
25% of security leaders trust Endpoint Detection and Response (EDR) to defend against evolving ransomware threats.
78% of security leaders say AI has made ransomware attacks more effective.
99% of security leaders express confidence in their ability to detect ransomware attacks.
49% of ransomware victims admit they detected their last attack too late to prevent significant damage.
35% of security leaders call ransomware their organization's number-one business priority.
98% of organizations rely on Endpoint Detection and Response (EDR) for ransomware defense.
49% of security leaders report experiencing moderate to significant disruption to business operations from ransomware.
6% of security leaders believe AI has meaningfully improved their own ransomware defenses.
AI benefits attackers over defenders by a 13-to-1 ratio, with 78% saying AI makes attacks more effective versus 6% saying AI has improved defenses.
91% of security leaders report that recent high-profile ransomware incidents are moderately or significantly influencing their buying decisions.
97% of security leaders report being asked by their board or executive leadership about their ransomware defense strategy.
74% of security leaders say their organizations are more exposed to ransomware due to AI advancements.