The Check Point Q2 2026 Ransomware Report Is Out

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it. 

Key takeaways 
  • Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% year over year
  • The top 10 groups still controlled 57.6% of all victims, but the number of active groups jumped from 71 to 93, a new high
  • Leaked chats from The Gentlemen ransomware operation showed how a core team of roughly nine people, aided by AI coding tools, built a top three global operation in a matter of months
  • Ransom payment rates fell to about 23%, yet on chain ransomware payments still topped $820 million in 2025, pushing operators toward data theft over encryption
  • Defending against this shift means treating initial access, exfiltration, and exposure reduction as equally urgent
What actually happened in Q2 2026? 

Data leak sites, where ransomware groups publish victims who refuse to pay, logged 2,139 victims in Q2, essentially flat against Q1 and up 33% year over year. The ecosystem is holding at the elevated baseline it settled into through 2025. 

What shifted is who’s doing the attacking. In Q1, the top 10 groups controlled 71% of victims across just 71 active groups, a tight, top heavy market. By Q2, that eased to 57.6%, and active groups climbed to 93, the highest on record. Cl0p, whose Oracle E-Business Suite campaign drove much of Q1’s numbers, nearly vanished, and a wider mid tier filled the gap. Qilin held the top spot for a fourth straight quarter with 279 victims, narrowly ahead of The Gentlemen, which grew 62% and outpaced Qilin in June. 

Figure 1 – Total Number of Reported Ransomware Victims in data leakage websites, per month
(June 2024 – June 2026)

Figure 2 – Top-10 share and active group count, Q2 2026

What did the leaked Gentlemen chat logs actually reveal? 

A leak of The Gentlemen’s own backend and chat history, giving researchers a rare inside view of a top tier operation. The core team was just nine people, running a 90/10 split with a broader affiliate base that carried out most of the intrusion work, the highest cut advertised in the market. 

The detail worth remembering: the group’s admin, Zeta88, built the operation’s ransomware management panel in about three days using AI coding assistants, with a candid admission that the tools still require someone who understands the code well enough to guide and correct it. That’s genuine evidence AI is speeding up how ransomware tooling gets built, though its use here was about writing software faster, not running operations or picking targets. The bigger signal: the barriers to building a serious ransomware business have narrowed enough that one experienced operator can reach the top tier in months. 

Figure 3 – The Gentlemen monthly victim trajectory, Sep 2025 – Jun 2026

Why does data theft matter more than encryption right now? 

Payment rates have fallen for six straight years, from 85% in 2019 to roughly 23% today, largely because backups have gotten better at neutralizing encryption. Backups don’t help against data theft, though. If files are already stolen and about to be published, restoring systems doesn’t stop the leak, which is why operators are leaning into exfiltration first extortion. Total dollars paid haven’t followed payment rates down: on chain payments still exceeded $820 million in 2025. 

Law enforcement spent the quarter chasing shared infrastructure rather than individual groups, dismantling a laundering platform, sanctioning exchanges tied to ransomware actors, and taking down a malware signing service and major infostealer networks. None of that shows up as a drop in Q2’s victim count, and seized infrastructure tends to get rebuilt elsewhere, but raising the cost of laundering, signing, and credential harvesting adds friction that compounds over time. 

What should defenders actually prioritize? 

A few things fall out of the quarter’s data. Initial access remains the fight that matters most: The Gentlemen’s own pipeline ran on VPN scanning, brute forcing, and brokered credentials, the same route used across most of the ecosystem, so phishing and exposed remote access deserve defense in proportion to how often they’re the opening move. Exfiltration detection now deserves the same weight backup and recovery has traditionally received, and remediation speed matters more too, since the gap between disclosure and exploitation is now measured in hours. Defenses still running on a human review cycle are working against AI assisted tooling that no longer waits for one. 

How does Check Point address what this Ransomware quarter found? 

Most of what this report documents starts with a person, usually through phishing or stolen credentials feeding the same pipeline The Gentlemen relied on. Workspace Security protects users across email, browsers, SaaS applications, and endpoints, using AI driven detection to stop ransomware delivery before execution and limit lateral movement and exfiltration after a compromise. 

Hybrid Mesh Network Security applies consistent, AI driven controls at every connectivity point, from firewalls that block malicious files before they reach devices to CASB scanning that catches malware entering through SaaS platforms like OneDrive and Slack, a route access brokers increasingly favor. If a compromise happens anyway, Zero Trust access through SASE Private Access limits the blast radius so ransomware can only reach what the compromised user was authorized to touch. 

Exposure Management answers the harder question of which vulnerabilities ransomware groups can actually reach and use, not just which ones exist. Check Point’s 2026 Exposure Gap Report found vulnerabilities now make up 42.6% of critical exposures, more than double the year before, and that they can realistically be closed in under an hour, with utilities sector organizations using the platform resolving 30% of theirs within that window. 

AI Security addresses the same tooling ransomware groups are learning to use. ThreatCloud AI keeps protection moving on the same accelerated timeline as AI assisted exploitation, AI Agent Security governs the agent permissions that let an admin like Zeta88 build tooling in days, AI Red Teaming tests an organization’s own AI applications before deployment, and Workforce AI Security stops credentials and data from leaking through the AI tools employees already use. 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading