Decoding the world of cybersecurity

Ransomware fragments as data theft gains ground

Check Point recorded 2,139 ransomware leak-site victims in Q2 2026 as active groups reached a record 93 and smaller affiliate-driven operations gained ground.

Ransomware fragments as data theft gains ground
Summary
  • Ransomware leak sites recorded 2,139 victims in Q2 2026, up 33% year on year, while active groups increased from 71 to 93.
  • Leaked material from The Gentlemen shows a roughly nine-person core working with affiliates and using AI-assisted development.
  • Falling ransom-payment rates are increasing the value of stolen data as leverage even where victims can recover encrypted systems.

Ransomware remained at historically elevated levels during the second quarter of 2026, but the criminal market became more fragmented as a larger number of groups competed for victims and data theft continued to reduce the importance of encryption as the sole source of leverage.

Check Point Software Technologies recorded 2,139 victims on ransomware data-leak sites during Q2, broadly flat against the preceding quarter but 33% higher than the same period a year earlier. The number of active ransomware groups rose from 71 to 93, the highest level in its dataset.

The ten largest groups accounted for 57.6% of listed victims, down from 71% in Q1. Qilin remained the largest operation with 279 victims, while The Gentlemen expanded rapidly and overtook it during June.

Leak-site statistics capture only part of the market. Victims that pay may never appear publicly and attacker claims can contain errors or exaggeration. Used consistently, however, the data provides a view of how the public extortion ecosystem is distributed among competing groups.

Check Point’s separate examination of leaked internal material from The Gentlemen provides an unusually detailed view of the organisation behind one of those names. Researchers identified nine accounts actively communicating within the operation and at least eight affiliate identifiers in ransomware samples.

The operation uses a 90/10 revenue model in favour of affiliates, while its administrator manages infrastructure, ransomware development, payments and parts of the intrusion process. The small core is therefore able to expand its reach through outside operators rather than maintaining a large permanent attack team.

The leaked material also provides evidence of AI being used to accelerate criminal software development. Check Point says the administrator built a ransomware management panel in roughly three days while using coding assistants including DeepSeek and Qwen.

The evidence does not show an AI system autonomously selecting victims or conducting ransomware attacks. Human operators remain central to targeting, intrusion and extortion, while general-purpose models reduce some of the time and expertise needed to build supporting software.

Sergey Shykevich, Director, Threat Intelligence at Check Point Software, said: “The most important finding from this quarter isn’t the number of ransomware victims, but how dramatically the barriers to entry are falling. We now have evidence that a small team, supported by AI-assisted tooling and affiliate networks, can build a top-tier ransomware operation in a matter of months.”

Those lower development barriers coincide with a change in extortion economics. Check Point cites ransom-payment rates falling from around 85% in 2019 to approximately 23% today, while on-chain ransomware payments still exceeded $820 million during 2025.

Improved backup and recovery has weakened the leverage created by encryption because an organisation capable of restoring systems has less reason to pay purely for a decryption key. A completed data theft creates a different problem: restoration cannot prevent publication of confidential files that have already left the network.

As a result, ransomware incidents increasingly combine identity compromise, exploitation of edge infrastructure, data exfiltration and extortion without depending on a prolonged encrypted outage. The criminal supply chain around those incidents includes access brokers, affiliate networks, credential theft and specialised tooling.

European regulatory obligations reinforce the distinction. A recoverable systems outage and an incident involving stolen personal or regulated data can trigger different reporting, notification and contractual consequences under regimes such as NIS2, DORA and the GDPR.

The Q2 figures consequently describe an ecosystem that is expanding sideways rather than consolidating around a handful of dominant brands. Smaller groups can acquire access, tools and affiliates while AI-assisted development reduces some of the engineering cost of operating the underlying platform.

Lower payment rates have not removed ransomware’s commercial incentive. They have pushed operators towards forms of leverage that backups cannot neutralise, leaving sensitive data, credentials and access itself increasingly central to the business model.

×