LIVE NEWS
  • Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests
  • Amboseli elephant deaths: Kenya Wildlife Service launches urgent inquiry after 14 carcasses found
  • Yemen’s Houthis claim missile attack on Saudi Arabia oil tanker | Houthis News
  • American Diabetes Association faces calls for resignations
  • Reaction wheel failures leave Swift rescue mission spinning in orbit
  • SpaceX, Blue Origin may get quicker launch OK with fewer environmental rules
  • Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
  • Is the Bitcoin bottom in? Key levels to watch after summer drop By Investing.com
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Ransomware Is Accelerating, But It’s Not Because of AI
Cybersecurity

Ransomware Is Accelerating, But It’s Not Because of AI

primereportsBy primereportsJuly 22, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Ransomware Is Accelerating, But It’s Not Because of AI
Share
Facebook Twitter LinkedIn Pinterest Email


Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.

For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.

25% Increase in Incident Volume

Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.

Related:‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover

“This isn’t a problem we’ve contained,” says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “It’s still a lucrative business, and the barrier to running one keeps getting lower.”

Black Kite attributed the growth in attack volume to a combination of factors, including the fragmentation of the ransomware ecosystem, the emergence of dozens of new groups, and an expansion of attacks on small and less defended organizations. The company also pointed to third-party and supply chain compromises, such as those involving Oracle and Salesforce as allowing attackers to leverage a single breach into multivictim campaigns. “Groups like Qilin redefined what a single attack looks like, with one [managed service provider or MSP] compromise reaching 32 South Korean financial institutions,” Dikbiyik notes. “One vendor, dozens of victims.”

Many Victims Had Externally Visible Weaknesses

One consistent pattern Black Kite uncovered was that many victims had high ransomware susceptibility index (RSI) scores — a measure the company uses to assesses an organization’s exposure to ransomware attacks based on externally visible factors like exposed credentials and unpatched vulnerabilities. Some 41% of companies that had an RSI higher than 0.8 experienced a ransomware incident during the study period, compared to just 0.14% of organizations with scores below 0.2. More than 90% of victims showed a meaningful spike in their RSI score just before being hit.

Susceptibility comes down to exposure and predisposition, Dikbiyik points out. “Exposure is what’s externally visible: misconfigurations, exposed remote access, credential stuffing, stealer logs,” he says. “Predisposition is who you are, your geography, your industry, your revenue band, the size of your digital footprint.” Most victims, Dikbiyik adds, weren’t breached because they were uniquely weak. “They were breached because they were visible, exposed, and a fit for what attackers were already looking for.”

Related:ClickFix’s Mushrooming Ecosystem Demands New Defense Tactics

As has been the case for some time, manufacturing companies remained the top target for ransomware actors and accounted for 1,660 victims. Close behind were 1,389 organizations in the professional, scientific, and technical services sector. Construction companies emerged as the third-most targeted sector. Nearly half the victims (49.3%) were US-based organizations but in terms of growth, ransomware attacks in Europe outpaced the US.

Large companies remained big targets, but they were no longer the engine of volume growth, Black Kite discovered. Instead, a lot of the activity happened among organizations in the $50 million to $100 million revenue tier, and in the $1 million to $5 million range, meaning no company was too small a target for attackers.

A Democratization of the Field?

Large established threat groups like Qilin, Everest, Cl0p, and World Leaks continued to rack up victims and to focus largely on US-based organizations. Smaller and newer entrants, meanwhile, picked up most of their victims in Europe, South America, Africa, Asia, and the Middle East. AI did not accelerate ransomware incidents, but it did enable more threat actors with lesser technical skills to get into the game, though not always to stay in it for long. Ransomware operations that Black Kite observed launching between April and September 2025 lasted for a median period of just 4.9 months before dropping out. Black Kite estimated a total of 146 ransomware groups as presently active — up from 127 in March.

Related:GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

What is most surprising is how the growth in ransomware volume has taken place without the need for any new kind of attacker, Dikbiyik says. “Open source LLMs and code agents lowered the cost of building an original operation, and we saw early signs of AI-assisted code showing up in encryptors,” he says. But it’s hard to say if AI drove an acceleration in ransomware attacks. “What I can say is the growth is human. AI just let more people show up at once.”

Troublingly, many victims of ransomware attacks appeared to do little to reduce their overall exposure to repeat incidents. Dikbiyik views that as a sign of victims being in a hurry to close the incident without addressing what made them a target in the first place.

“My advice is to treat the post-incident period as ongoing work, not a closed case, with structured exposure reviews at 30, 60, and 90 days,” he says. He also recommends prioritizing by what’s actually being exploited, not by CVSS score alone, and extending visibility into vendor and software-as-a-service (SaaS) relationships and implementing continuous monitoring.



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNearly 1 in 4 workers stay in jobs for health insurance, a survey says : NPR
Next Article Binance Sees Largest Daily BTC Outflow Since Late 2024, CryptoQuant Data Shows
primereports
  • Website

Related Posts

Cybersecurity

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard

July 28, 2026
Cybersecurity

How to remap the Copilot key on your keyboard to something more helpful

July 28, 2026
Cybersecurity

Data breach at medical billing firm MCBS affects 1.26 million people

July 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Cybersecurity
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests
  • Amboseli elephant deaths: Kenya Wildlife Service launches urgent inquiry after 14 carcasses found
  • Yemen’s Houthis claim missile attack on Saudi Arabia oil tanker | Houthis News
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.