Monday , September 14 2026
871 ransomware

88 Group Active
871 ransomware victims recorded in April- 2026

871 ransomware victims were recorded in April- 2026 while 88 group active in ransomware arena. In total the world sees a victims of 3263 in different sectors across the world.

Top Threat Groups by Victim Count

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

A new study of ransomware shows the top 10 threat groups that target the most victims, showing that a few major players dominate the threat landscape.

Qilin is at the top, with almost 500 recorded victims. This makes it the most active group in the data. Next is TheGentlemen, with about 280 victims. There is a big difference from the leader, but it is still very active.

Other prominent groups include:
Akira (~240 victims)
IncRansom (~200 victims)
DragonForce (~180 victims)
NightSpire (~170 victims)

Lower in the top 10 but still impactful are:
LockBit5, Clop, and Play, each hovering around 120–150 victims
CoinbaseCartel, closing the list with just over 100 victims

Ransomware Attacks Surge in Early 2026, Sharp Drop in May

Ransomware activity in 2026 went up steadily and worryingly in the first four months, then suddenly dropped in May, based on the newest data tracking victims.

January begins with approximately 700 victims, setting a high baseline for the year
February climbs to around 780, indicating growing campaign momentum
March continues the upward trend with roughly 840 victims
April peaks at nearly 870 victims, marking the highest monthly total so far in 2026

However, the trend shifts dramatically in May, where reported victims drop sharply to around 60 cases—a significant deviation from previous months.

2026 Sector Impact Analysis Summary

Overall Sector Distribution

The Top 10 Sectors donut chart shows that Manufacturing, Business Services, and Technology are the three most important sectors in the data.

Primary Targets: Manufacturing and Business Services lead the distribution, followed closely by Technology and Healthcare.
Secondary Sectors: Consumer Services and Construction also maintain substantial shares.
Niche Impacts: The Public Sector, Financial Services, Transportation/Logistics, and Agriculture/Food Production round out the top ten with smaller, though notable, segments.

Monthly Distribution Trends (Jan–May 2026)

The stacked bar chart shows changes in activity in different sectors during the first five months of the year:

Business Services Surge: This sector (shown with the blue base) had a big jump in its share of the total distribution, going from about 12% in January to nearly 30% by May.

Sector Volatility:
Construction: Construction: It stayed mostly the same until March but dropped in its percentage share in April and May.
Healthcare (shown by the teal part) stayed steady but looked a bit smaller in May because Business Services grew.

April Anomaly: In April, the “Other” or higher-tier categories (top grey/purple segments) went up a lot compared to the mid-tier sectors. This suggests a short-term change in focus or how things were reported that month.

Top 20 Countries by Cyberattack Victims

Ransomware.live data shows that cyberattack victims are not spread evenly around the world. The United States has many more victims than all other countries put together. This means that attackers are mainly focusing on U.S. organizations because they have a lot of online presence and valuable resources.

A second group of affected countries is Germany, the United Kingdom, Canada, and France. They have moderate but much lower victim numbers than the U.S. These countries are still targets because of their strong economies and online systems.

The other countries like Italy, Spain, Brazil, India, Australia, Japan, Thailand, Taiwan, Mexico, and Switzerland have lower impacts, but they are still significant. This shows that cyber threats affect the whole world, not just certain areas.

Ransomware is still well-organized, able to grow, and focused. Top groups keep improving how they work. Companies need to focus on understanding threats, fixing software, and being ready to respond to incidents to reduce risks from these powerful groups.

Related post:

807 Ransomware Victims Hit in March by 67 Active Hacker Groups

779 Victims, 322 Groups: What February 2026 Ransomware report reveals

796 Victims, 315 Groups: What January 2026 Ransomware report reveals

Check Also

Interlock ransomware

CVE-2026-20131
Interlock Ransomware gang exploits Cisco FMC zero-day since January

The Interlock ransomware group has been exploiting a remote code execution (RCE) flaw in Cisco’s …