Ransomware Ecosystem Expansion: AI Lowers Barriers in Cybercrime
Check Point Software Technologies Ltd., a global leader in cybersecurity solutions, recently released its Ransomware Report for the second quarter of 2026 through Check Point Research (CPR). The findings underscore a concerning trend: ransomware incidents are at an all-time high, with a notable shift in attack focus from data encryption to data theft. Analysis of leaked internal chats from the ransomware group "The Gentlemen" sheds light on intriguing developments behind the scenes.
Key Findings from the Q2 2026 Report
1.
Record Number of Ransomware Incidents: There were 2,139 confirmed ransomware incidents reported in Q2 2026, nearly matching the previous quarter's total of 2,122. However, this represents a 33% increase compared to the same period last year, indicating a sustained high level of ransomware activity since 2025.
2.
Surge in Active Ransomware Groups: The number of active ransomware groups surged from 71 in Q1 to 93 in Q2, with the top 10 groups accounting for 57.6% of the total incidents. Leading the charge is the Qilin group, which recorded 279 incidents for four consecutive quarters.
3.
Operational Scale of Ransomware Organizations: Insights from analyzing the backend systems and internal chats of The Gentlemen reveal that the group operates with a core of about nine members, leveraging an extensive affiliate network to amplify their attacks.
4.
AI Accelerates Ransomware Development: The Gentlemen's chat logs indicate that their administrator, Zeta88, utilized AI coding tools such as DeepSeek and Qwen, constructing a ransomware management panel in about three days. Though autonomous AI attacks have not been confirmed, it is evident that AI tools are expediting the development of cybercrime tools and lowering the barriers to executing sophisticated attacks.
5.
Shift Towards Data Theft: The ransomware payment rate plummeted from 85% in 2019 to approximately 23% in Q2 2026, largely due to advances in backup technology. Nevertheless, the total ransomware-related payments on blockchain exceeded $820 million in 2025. Attackers have transitioned to using stolen data as leverage for extortion, making data theft the primary focus of their operations.
Expanding the Ransomware Ecosystem
A significant change in the ransomware landscape is the increased diversity of attacking entities. In Q1, 71 groups were active, with the top 10 accounting for 71% of the attacks, while in Q2, the number of groups rose to 93, reducing the top 10's share to 57.6%. Previously dominant groups, like Cl0p, have waned, paving the way for mid-tier groups to expand their activities. The Gentlemen’s attack count soared by 62% in June, surpassing Qilin.
This evolution indicates that ransomware is no longer solely managed by large professional groups; smaller groups are entering the market and making an outsized impact. Historically, successful ransomware attacks necessitated significant technical expertise and infrastructure, but the advent of AI-based development, Ransomware-as-a-Service (RaaS) models, and specialized criminal supply chains have dramatically lowered these entry barriers.
Charts and Data
- - Monthly Ransomware Incident Count (June 2024 – June 2026)
- - Top 10 Active Ransomware Groups and Incident Counts in Q2 2026
Changing Focus of Attacks
The decline in ransomware payment rates is closely tied to advancements in backup technology. While backups can mitigate damage from encryption, they cannot prevent the disclosure of previously stolen data. Consequently, attackers have pivoted from traditional encryption-focused attacks to dual extortion methods, threatening to publish stolen data to increase pressure on victims.
This shift necessitates new defensive measures. Organizations must prioritize not just recovery solutions but also protection of sensitive data and the detection of data leaks. The timeline for exploiting vulnerabilities is shrinking from weeks to mere hours or days, heightened by the rise in AI-assisted exploit development, which allows attackers to outpace organizational patching efforts.
Prioritizing Prevention
To counter the evolving ransomware landscape, organizations need to enhance their preventive strategies rather than merely responding post-breach. In the case of The Gentlemen, initial access methods included VPN scanning, brute force attacks, and credential theft from brokers, techniques that are now pervasive across the ransomware ecosystem.
Organizations must focus on blocking initial access from phishing attempts or leaked remote access credentials while identifying and rectifying exploitable exposures swiftly. Additionally, measures to contain lateral movement and data leaks in the event of a breach are paramount.
As Sergey Shykevich, Director of Threat Intelligence at Check Point, stated, "The most crucial finding this quarter is not the number of ransomware victims but rather how dramatically the barriers to entry for ransomware attacks have lowered. Evidence discovered by CPR demonstrates that even small teams can leverage AI-powered tools and affiliate networks to establish top-tier ransomware operations in just a few months. As AI accelerates software development and exploit generation, we anticipate a surge of new threat actors emerging with unprecedented speed." Organizations must transition from reactive security models to a prevention-first approach, concentrating on reducing exploitable exposures and safeguarding credentials and sensitive data, while also acknowledging that attackers will increasingly leverage AI for faster operations throughout the attack lifecycle.