Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.
For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.
25% Increase in Incident Volume
Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.
“This isn’t a problem we’ve contained,” says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “It’s still a lucrative business, and the barrier to running one keeps getting lower.”
Black Kite attributed the growth in attack volume to a combination of factors, including the fragmentation of the ransomware ecosystem, the emergence of dozens of new groups, and an expansion of attacks on small and less defended organizations. The company also pointed to third-party and supply chain compromises, such as those involving Oracle and Salesforce as allowing attackers to leverage a single breach into multivictim campaigns. “Groups like Qilin redefined what a single attack looks like, with one [managed service provider or MSP] compromise reaching 32 South Korean financial institutions,” Dikbiyik notes. “One vendor, dozens of victims.”
Many Victims Had Externally Visible Weaknesses
One consistent pattern Black Kite uncovered was that many victims had high ransomware susceptibility index (RSI) scores — a measure the company uses to assesses an organization’s exposure to ransomware attacks based on externally visible factors like exposed credentials and unpatched vulnerabilities. Some 41% of companies that had an RSI higher than 0.8 experienced a ransomware incident during the study period, compared to just 0.14% of organizations with scores below 0.2. More than 90% of victims showed a meaningful spike in their RSI score just before being hit.
Susceptibility comes down to exposure and predisposition, Dikbiyik points out. “Exposure is what’s externally visible: misconfigurations, exposed remote access, credential stuffing, stealer logs,” he says. “Predisposition is who you are, your geography, your industry, your revenue band, the size of your digital footprint.” Most victims, Dikbiyik adds, weren’t breached because they were uniquely weak. “They were breached because they were visible, exposed, and a fit for what attackers were already looking for.”
As has been the case for some time, manufacturing companies remained the top target for ransomware actors and accounted for 1,660 victims. Close behind were 1,389 organizations in the professional, scientific, and technical services sector. Construction companies emerged as the third-most targeted sector. Nearly half the victims (49.3%) were US-based organizations but in terms of growth, ransomware attacks in Europe outpaced the US.
Large companies remained big targets, but they were no longer the engine of volume growth, Black Kite discovered. Instead, a lot of the activity happened among organizations in the $50 million to $100 million revenue tier, and in the $1 million to $5 million range, meaning no company was too small a target for attackers.
A Democratization of the Field?
Large established threat groups like Qilin, Everest, Cl0p, and World Leaks continued to rack up victims and to focus largely on US-based organizations. Smaller and newer entrants, meanwhile, picked up most of their victims in Europe, South America, Africa, Asia, and the Middle East. AI did not accelerate ransomware incidents, but it did enable more threat actors with lesser technical skills to get into the game, though not always to stay in it for long. Ransomware operations that Black Kite observed launching between April and September 2025 lasted for a median period of just 4.9 months before dropping out. Black Kite estimated a total of 146 ransomware groups as presently active — up from 127 in March.
What is most surprising is how the growth in ransomware volume has taken place without the need for any new kind of attacker, Dikbiyik says. “Open source LLMs and code agents lowered the cost of building an original operation, and we saw early signs of AI-assisted code showing up in encryptors,” he says. But it’s hard to say if AI drove an acceleration in ransomware attacks. “What I can say is the growth is human. AI just let more people show up at once.”
Troublingly, many victims of ransomware attacks appeared to do little to reduce their overall exposure to repeat incidents. Dikbiyik views that as a sign of victims being in a hurry to close the incident without addressing what made them a target in the first place.
“My advice is to treat the post-incident period as ongoing work, not a closed case, with structured exposure reviews at 30, 60, and 90 days,” he says. He also recommends prioritizing by what’s actually being exploited, not by CVSS score alone, and extending visibility into vendor and software-as-a-service (SaaS) relationships and implementing continuous monitoring.
