Report by BlackFog
Q2 2026 Ransomware Trends Report
Key Findings
The highest ransom demand in Q2 2026 was $25 million.
Qilin accounted for 285 undisclosed attacks (14%), The Gentlemen accounted for 219 (11%), and Dragon Force accounted for 137 (7%) in Q2 2026.
The number of undisclosed ransomware attacks fell 6% compared to the previous quarter.
Disclosed ransomware attacks targeting the services sector increased 221% compared to Q1 2026.
Publicly disclosed ransomware attacks totalled 306 in Q2 2026, a 16% increase compared to the previous quarter.
Victims were given an average of 7 days to meet ransom demands in Q2 2026.
Undisclosed ransomware attacks increased 40% year on year to 2,027 attacks in Q2 2026 from 1,446 in Q2 2025.
Among disclosed attacks, Shiny Hunters was responsible for 28 attacks (9%), Qilin for 19 attacks (6%), and INC for 13 attacks (4%) in Q2 2026.
30% of publicly disclosed ransomware incidents in Q2 2026 were not attributed to any known group.
Since first observed in June 2026, Settra claimed 22 victims, more than any other newly identified ransomware group in the quarter.
97% of disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded.
Healthcare accounted for 81 disclosed ransomware attacks (26%) in Q2 2026, making it the most targeted sector.
28 new ransomware groups emerged in Q2 2026, twice as many as in Q1 2026.
93 ransomware groups were active in Q2 2026, including 28 newly formed groups.
57 ransomware variants were associated with disclosed attacks in Q2 2026, a 21% increase from Q1 2026.
The USA accounted for 169 disclosed ransomware attacks (55%) and Australia accounted for 54 disclosed attacks (18%) in Q2 2026.
The services sector experienced 45 disclosed attacks (15%) and government experienced 30 disclosed attacks (10%) in Q2 2026.
Settra launched attacks across seven countries within its first four days of activity.
The average volume of data stolen per undisclosed ransomware incident reached 508 GB in Q2 2026.