Black Kite today released its newest report, 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record, examining how ransomware is evolving, who is being targeted, and the externally visible risk signals organizations exhibited before they became publicly disclosed ransomware victims.
Black Kite identified 7,551 publicly disclosed ransomware victims between April 1, 2025 and March 31, 2026, up 24.9% over the previous reporting period. But the annual figure hides a sharper trend: after tracking close to the prior year’s pace through the first half of the reporting period, ransomware victim counts accelerated 60% in the second half, closing with 861 victims in March 2026 – the highest monthly total in four years.
The report identified three key trends that defined this year’s ransomware landscape:
- Expansion at the bottom: More than 60 new groups entered during the reporting period, more than one per week, bringing the total to 146 active groups by June 2026.
- Concentration at the top: Despite the influx of new entrants, the five largest actors still controlled 43.6% of all victims. Qilin alone claimed 1,300+ victims, nearly twice as many as its nearest rival.
- Acceleration in the second half: While the first half tracked close to the prior year baseline, the second half outpaced it by 60%, closing with 861 victims in March 2026, the highest monthly total in four years of tracking.
Many of the year’s most consequential attacks moved through trusted vendor platforms, including SaaS integrations, enterprise applications, OAuth connections, and support workflows.
Black Kite’s before-and-after security posture comparison also found that exposure often remained after incidents were disclosed: stealer log exposure increased 175%, while 43.5% of victims still carried critical vulnerabilities in the latest assessment.
The report concludes that AI did not redefine ransomware during the reporting period. Instead, it lowered the cost of the work around the attack by making reconnaissance faster, phishing and vishing more convincing, victim research more scalable, scripts cleaner, translation easier, and extortion messaging cheaper to produce. While AI did not create this year’s acceleration, it lowered the barrier to entry enough that more actors could participate, suggesting ransomware operations could be scaling in anticipation of what comes next: AI-accelerated vulnerability discovery, faster exploitation cycles, and social engineering at scale.
Key findings from the report:
- 7,551 publicly disclosed ransomware victims identified, up 24.9% year over year.
- 60% acceleration in ransomware activity during the second half of the reporting period.
- 146 active groups by June 2026, including 61 new groups entering during the reporting period.
- Qilin claimed more than 1,300 victims, nearly two-times as many as its nearest rival.
- 43.5% of victims still carried critical patch vulnerabilities in the latest assessment, 30.8% carried KEV exposure, and 18.5% carried FocusTag® signals.
- 175% higher stealer log exposure in the before and after security posture comparison.
- Oracle E-Business Suite (EBS) and Salesforce ecosystem integrations defined several of the year’s most visible supply chain incidents.
The report recommends prioritizing vulnerabilities known to be exploited in the wild, extending third-party cyber risk management beyond questionnaire-based assessments, and hardening the human layer against vishing and help desk impersonation. The report also recommends strengthening identity verification, help desk escalation paths, employee reporting, vendor verification, and executive impersonation controls.
To read the report, visit https://blackkite.com/reports/2026-ransomware-report/.
To learn how Black Kite’s Ransomware Susceptibility Index (RSI™) provides early warning of ransomware risk and helps organizations proactively identify susceptible third parties, visit https://blackkite.com/platform/ransomware-susceptibility-index
Methodology
The report covers the period from April 1, 2025 through March 31, 2026. The primary dataset includes 7,551 publicly disclosed ransomware victims identified through leak site monitoring and validated by the Black Kite Research Group™. Before and after security postures, current state exposure analysis, and post-period April-June 2026 activity are treated as separate scopes. Post-period data is used as supplementary context and excluded from primary year over year calculations.
Black Kite’s Manufacturing & Distribution Ransomware Report 2026 Confirms Manufacturing Remains #1 Target
Posted in Commentary with tags Black Kite on September 17, 2026 by itnerdBlack Kite today released Manufacturing & Distribution Ransomware Report 2026, Still the #1 Target, but the Victim Profile Moved Downmarket and Overseas (https://blackkite.com/reports/2026-manufacturing-distribution). Examining the pressure across the full supply chain – from manufacturers to the companies that move their products – the report provides a blueprint for ranking suppliers by observable ransomware susceptibility, rather than by revenue, tier, or the date of their last questionnaire.
Ransomware Attacks Continue to Accelerate
Manufacturing’s position at the top is consistent across Black Kite’s broader ransomware research. Black Kite’s 2026 Ransomware Report identified 7,551 publicly disclosed ransomware victims across all industries, with manufacturing ranking first for the fourth consecutive year accounting for 22% of all disclosures.
While ransomware activity is rising across industries, manufacturing stands apart for the consistency and pace of that growth. Ransomware attacks on manufacturers have more than doubled since 2023, and in the first half of 2026 alone, attacks increased nearly 40% year over year.
Manufacturing Ransomware is Going Global
The geographic footprint of manufacturing ransomware is expanding, driven by a sharp rise in European victims. Victim counts across Europe increased 85.4%, while the U.S. share of global manufacturing ransomware victims fell from 52.3% to 34.8%.
Germany saw particularly significant growth. Manufacturing accounts for nearly 20% of the country’s economy, and ransomware victims in the sector increased more than 83% in the first seven months of 2026 compared with the same period in 2025.
One group contributing to that pressure is SafePay. Black Kite’s European ransomware research previously identified the group’s concentration on German targets. SafePay accounted for 21.9% of German manufacturing ransomware victims in 2025 and remains among the country’s most active ransomware groups in 2026.
The Victim Profile: Mid-Market Bears the Brunt
Ransomware’s primary target is the mid-market, not the enterprise as widely assumed. The median ransomware victim generates $42.9 million in annual revenue, and from 2023 through the first half of 2026, 73% of ransomware attacks in North America and Europe hit mid-market companies.
For manufacturing, that concentration carries broader implications. Mid-sized manufacturers often sit within the supplier networks of larger enterprises, meaning attacks on the mid-market can create risk well beyond the initial victim. When suppliers are the primary target, a manufacturer’s vendor ecosystem becomes part of its attack surface.
Threat Actor Spotlight: The Gentlemen
The threat actor ecosystem has been rebuilt, with the hierarchy of players being replaced by Qilin, The Gentleman, Akira, DragonForce, and INC Ransom. Among the new arrivals, The Gentlemen stands out for how quickly it found its footing in manufacturing.
First appearing in Black Kite’s dataset in September 2025, The Gentlemen had claimed 142 manufacturing victims by mid-2026. Manufacturing now accounts for 23.1% of the group’s activity, one of the highest concentrations among major ransomware groups.
Key findings from the report:
The report measured every exposure from the outside, using the same vantage point available to an attacker. The findings show that many victims displayed measurable signs of ransomware susceptibility at the time of disclosure. Nearly three-quarters (74.4%) had an RSI above 0.4, placing them in the critical range, while more than one-third (35.1%) had an RSI of 0.6 or higher. The average victim scored 0.552.
For manufacturers and distributors, resilience depends on continuously measuring these external signals across their own organizations and third-party ecosystems, and acting on them before a breach occurs.
To read the report, visit https://blackkite.com/reports/2026-manufacturing-distribution.
Leave a comment »