Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise.
At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
Cyble Research and Intelligence Labs reported that North and South America recorded 2,188 ransomware attacks in H1 2026 out of 3,836 tracked globally, making the region the most heavily targeted worldwide. The report said Qilin was the most active group across the Americas with 410 attacks, while The Gentlemen led South America with 46 attacks.
Check Point Research published its State of Ransomware Q2 2026 report, saying active ransomware groups rose from 71 in Q1 to 93 in Q2 while data leak sites recorded 2,139 victims in the quarter. The report said Qilin remained the most prolific operator for a fourth straight quarter with 279 victims, while The Gentlemen surged to 269 victims and overtook Qilin during June.
Comparitech published its Education Ransomware Roundup for the first half of 2026, documenting increased targeting of universities and rising ransom demands in the sector.
Reporting on July 3 described Qilin as the dominant ransomware-as-a-service operation, citing Check Point and Sophos data showing it had gained market share amid consolidation after pressure on rivals. The same reporting highlighted The Gentlemen as a fast-rising competitor.
Check Point Research reported that global ransomware victims reached 964 in July 2026, up 87% year-on-year and 49% from June. The report identified The Gentlemen and Qilin as the most prevalent ransomware groups that month, each accounting for 14% of published attacks.
Black Kite published its 2026 European Cyber Risk Report, finding publicly disclosed ransomware incidents across Europe rose 55.1% year-over-year in the first four months of 2026. The report identified Qilin as the most common ransomware family and highlighted supply-chain compromise as a growing attack vector.
On June 9, Check Point disclosed that Qilin had targeted a vulnerability in Check Point Remote Access VPN and Mobile Access solutions. The exploitation reportedly affected one customer.
The largest education-sector extortion case in the first half of 2026 affected Mount Royal University in Canada, where attackers demanded $1.9 million, claimed to have stolen more than 10TB of data, and deleted entire data drives. Reporting said the university was still experiencing significant disruption a month after the attack.
Comparitech found The Gentlemen's attacks on the education sector rose 275% in the first half of 2026 compared with the second half of 2025, with 80% of those attacks aimed at colleges and universities. The group and Qilin each claimed 15 education-sector attacks during the period.
Comparitech recorded 104 ransomware attacks against the global education sector between January and June 2026, with 36 cases confirmed by victims. The data showed attacks on higher education rose 8% while overall education-sector incidents declined because attacks on primary and secondary schools fell.
Comparitech data cited in the reporting said The Gentlemen became the most prolific ransomware strain in June 2026 with 115 victims, surpassing Qilin's 78 victims that month.
A leak of The Gentlemen's internal database in May exposed information about the group's infrastructure, affiliates, victims, and ransom negotiations. ESET said the leak also helped confirm that the group's leader discussed maintaining EDR-killer packages.
Black Kite reported that more than 30 ransomware incidents could be traced to the compromise of Swedish software supplier Miljödata. The compromise was explicitly anchored to August 2025.
ESET said The Gentlemen emerged in late 2025 and was founded by a former Qilin affiliate. This marks the group's appearance in the ransomware ecosystem.
Qilin was described as active since at least October 2022, establishing the earliest dated point for the group mentioned in the references.
Black Kite published its Ransomware Report 2026, stating that the top five ransomware operations accounted for 44% of 7,551 publicly disclosed victims between March 2025 and March 2026. The report also said critical vulnerabilities with CVSS scores of 9 or higher were exploited for initial access in 44% of attacks.
Black Kite reported that 146 active ransomware groups had publicly announced at least one victim as of June 2026, up from 105 a year earlier. It also said 61 new groups emerged during 2026 alone and that the average group lifespan fell to 4.9 months.
ESET published an analysis detailing The Gentlemen's operator-supplied GentleKiller framework, which uses bring-your-own-vulnerable-driver techniques to disable endpoint security products before encryption. The report said the toolkit targeted more than 400 processes across roughly 48 security products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cert.dk
Open sourcecyble.com
Open sourcemalware.news
Open sourceresearch.checkpoint.com
Open sourceinfosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourceblackkite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.