Global Threat Intelligence Report:
2026 Mid Year Edition
Data, insights, and key takeaways on the most impactful threats of 2026—from AI and infostealers to ransomware and vulnerabilities.
Ransomware Operations, Multi-Extortion Cartels, and Financial Risk
This section analyzes victimized organizations announced on ransomware blogs and dark web leak sites monitored by Flashpoint. The intelligence presented here reflects activity directly observed as part of Flashpoint’s proprietary collections from January 1, 2026 to June 30, 2026.
Ransomware Overview
January 2026 – June 2026
6,256
Victim Count*
↑ 32%
Ransomware Revenue
*Total on-chain ransomware payments fell by 8%,
with 28% of victims choosing to pay.
What Is the Current Scale of Global Ransomware Attacks?
Flashpoint analysts documented a highly aggressive and volatile extortion landscape in the first half of 2026, recording 6,256 verified ransomware victims globally—a staggering 45% surge compared to the first half of 2025. Cybercriminal operations during this six-month window demonstrated a clear strategy of high-volume targeting paired with intense economic opportunism.
Geographically, the threat remains highly concentrated within Western economies, with the United States suffering 2,669 attacks—accounting for 43% of the global total. This distinct geographic targeting is followed by the United Kingdom, Germany, and Canada.
From an industry perspective, threat actors ruthlessly prioritized industries burdened by low downtime tolerance and highly interconnected operational environments. As such, Manufacturing led all sectors, sustaining 18% of all recorded attacks, followed by Business and Consulting, and Healthcare.
The massive volume of active victims was heavily driven by a shifting roster of Ransomware-as-a-Service (RaaS) operations. Qilin led the landscape with 901 claimed victims, followed by Akira (565), 0APT (550), The Gentlemen (476), and Dragon Force (252). Together, the top five RaaS groups accounted for 44% of all 2026 ransomware activity.
What Are the Defining Ransomware Trends and Insights for 2026?
Ransomware Revenue Falls To Record Lows
Flashpoint research, coupled with findings from Chainalysis, shows a rising volume of ransomware attacks and falling revenue. Despite a 45% volume increase compared to the same period last year, total on-chain ransomware payments fell by approximately 8% to USD $820 million.
This divergence is largely due to the share of victims choosing to pay ransoms dropping to a potential all-time low of 28%. As organizations improve their incident response, implement viable data backups, and face increased regulatory scrutiny, the frequency of payouts has plummeted. However, to compensate for this trend, attackers are successfully extracting larger sums from victims that do pay.
AI Acceleration Forces a Rapid Collapse in Ransomware Response Windows
AI has transitioned from a conceptual novelty into an operational force multiplier for ransomware operators, fundamentally compressing defensive timelines. Throughout H1 2026, Flashpoint has observed threat actors creating and releasing agentic systems that automate initial access. This has created an oversupply of automated tooling that has driven the average cost of sold initial access down by 69%—from USD $1,427 to USD $439.
As a result, ransomware syndicates are actively leveraging these agents to scale operations exponentially by continuously scraping target data, adjusting exploitation messaging for specific corporate environments, and executing credential stuffing across thousands of enterprise VPNs, SaaS platforms, and cloud endpoints simultaneously.
What Are the Essential Ransomware Key Takeaways?
1
A Record-Low 28% Payout Rate Triggers Higher Ransom Demands
While global ransomware volume experienced a staggering 45% surge compared to H1 2025—culminating in 5,410 verified victims—total on-chain cybercriminal revenue actually fell by approximately 8% to USD $820 million. This structural decoupling is driven by a defensive milestone: the share of victims choosing to pay extortion demands has dropped to a historic low of just 28%. As enterprises improve their incident response and implement viable data backups, the profitability of broad campaigns has eroded, forcing threat actors to demand significantly larger individual sums from the shrinking pool of victims that do pay.
2
Agentic AI Lowers Barriers to New Ransomware Entrants
Artificial intelligence has matured into a highly commoditized utility, fundamentally expanding threat actor operational scale. Throughout H1 2026, ransomware operations aggressively deployed autonomous, agentic systems. This automation has created a massive oversupply of entry tools across the cybercriminal underground, driving the average market cost of sold initial access down by 69%—from USD $1,427 to just USD $439—and drastically lowering the financial barrier to entry for amateur threat actors.
3
Syndicates Target Low-Downtime Sectors and Western Economies
The distribution of H1 2026 data reveals that RaaS syndicates are prioritizing maximum operational disruption to enforce extortion leverage. Geographically, campaigns remain heavily concentrated within Western nations, led by the United States with 2,669 successful compromises representing 43% of the global total. Operationally, syndicates are focusing automated tools on interconnected industries with low downtime tolerance.
What Are the Best Defenses for Disrupting Ransomware Campaigns?
Neutralize Ransomware Through Immutable Backups and Strict Zero-Trust Isolation
Implement decoupled, multi-site immutable backups that utilize separate, air-gapped authentication domains entirely independent of your primary Active Directory. Concurrently, isolate critical industrial, production, and clinical operational networks into micro-segmented zones. This containment strategy prevents RaaS lockers from moving laterally and guarantees a clean, uncompromised restore path that completely neutralizes threat actor extortion leverage.
Harden Cloud, VPN, and SaaS Identity Controls to Combat Agentic AI Automation
Mandate phishing-resistant, hardware-backed Multi-Factor Authentication (MFA) across all enterprise VPNs, remote desktops, and SaaS platforms. Establish behavioral monitoring baselines to detect anomalous, automated login behavior. Any endpoint attempting rapid, successive connection sequences across multiple corporate accounts must trigger an immediate automated device quarantine and session revocation before agentic tools can establish a beachhead.
Shift Threat Tracking Focus to Shared Underground Enabling Infrastructure
The H1 2026 data shows that while individual group brands shift, the top five RaaS networks manage to account for 44% of all global activity. This high efficiency is achieved because syndicates do not operate in isolation; they function as tenants within shared underground networks, utilizing centralized proxies, secure hosting, and commodity evasion tools.