Findings from the dark web reveal that discussions surrounding deepfakes as a service have exploded in 2026, already surpassing 2025’s totals and potentially paving the way for a new wave of business email compromise attacks
The latest findings from NordStellar, a threat exposure management platform, reveal that dark web discussions surrounding cybercrime as a service are trending upward in 2026. Deepfakes as a service is proving especially popular, with posts surging 39% in the first five months of 2026 — already surpassing the total volume recorded in 2025 and potentially giving cybercriminals new tools for “fake boss” scams.
According to data analyzed by NordStellar, 9,234 dark web posts discussed cybercrime as a service (CaaS) in 2025. Between January and May 2026 alone, that number has already reached 6,866 — representing 74% of last year’s total.
The analysis reveals that discussions about deepfakes as a service (DFaaS) are growing the fastest. In just the first five months of 2026, there were 924 posts — marking a 39% increase compared to the 663 posts recorded for all of 2025.

“The rapid growth in popularity of deepfakes as a service is likely accelerated by advancements in generative AI, which help cybercriminals in two ways — by speeding up the creation of deepfakes and making them hyper-realistic,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ultimately, this service lowers the barrier to entry for deepfake technology, enabling threat actors to deploy highly deceptive attacks at a larger scale, regardless of their personal technical skill set.”
Deepfakes for business email compromise attacks
Noreika highlights that the growing popularity of DFaaS is a key concern for businesses. Cybercriminals can leverage deepfakes not only to target individuals with sophisticated social engineering but also to amplify business email compromise (BEC), otherwise commonly known as “fake boss” scams. In these attacks, bad actors impersonate vendors, colleagues, or executives to manipulate employees.
The FBI reports that business email compromise was the second costliest cybercrime of 2025, with company losses exceeding $3 billion. This marks an 11% increase over $2.7 billion reported in 2024.
The real-life case covered by the World Economic Forum involving engineering firm Arup highlights the stakes: An employee was tricked into transferring $25 million after attending a video call where all other participants were AI-generated deepfakes.
“Deepfakes can be used to elevate business email compromise attacks to make them even harder to spot — instead of receiving fake payment instructions in an email, employees can now be targeted via highly realistic video and voice calls impersonating partners or managers asking them to transfer funds,” says Noreika. “As AI tools grow more sophisticated, deepfakes are evolving rapidly. It is now easier than ever to create convincing video or audio that lacks the usual telltale signs of AI generation, making it extremely challenging for users to spot the deception — especially when a sense of urgency is involved.”
He explains that cybercriminals usually deploy these attacks to obtain fake payments or confidential documents or to infiltrate the company’s network to launch a larger-scale attack. Advanced BEC attacks usually involve gathering extensive intel on the target to ensure that the attack itself contains convincing details, is context-appropriate, and is delivered at the right time — for example, when the recipient is already waiting for an incoming invoice.
Deepfake defense strategies in the era of AI
Noreika suggests that a deepfake-resistant cybersecurity strategy should focus on two main areas — prevention and employee education. While companies can’t control whether cybercriminals target them, robust security measures can make advanced BEC attacks much harder to execute.
“The more details and access attackers obtain, the easier it is for them to craft highly realistic, targeted attacks,” says Noreika. “Monitoring the dark web for leaked company information is a critical step in preventing cybercriminals from finding credentials to breach accounts or data to use as intel.”
He emphasizes that educating employees on BEC attacks is vital. However, he notes that fostering a positive cybersecurity culture is equally important.
“Attackers take advantage of their targets by creating a sense of urgency,” says Noreika. “Even if employees are aware of cybercriminals’ tactics, slowing down to double-check a request that’s coming from a person of authority can be daunting to most, especially if deadlines are tight. Efficiency shouldn’t come at the expense of possibly exposing the company to a cyberattack, and employees should feel safe and empowered to raise red flags when something is off, and take some time to inspect the request before diving headlong.”
Noreika stresses that having a robust cybersecurity strategy in place will help mitigate the aftermath of a BEC attack if threat actors succeed in tricking employees and gain access to the company’s network. He notes that security measures like network segmentation and multi-factor authentication can help prevent attackers from moving laterally inside the network as well as prevent them from accessing resources.
Methodology: The NordStellar platform was used to analyze underground discussions from dark web forums and monitored Telegram channels. NordStellar tracked 6 categories covering as-a-service offerings. For each category, NordStellar retrieved monthly post counts across both forums and Telegram for every month from January 2024 through May 2026. For more information, visit NordStellar’s blog post.
Disclaimer. This analysis is based on detected activity and is for informational purposes only; it does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only.















Guest Post: Ransomware attacks up 20% year-over-year as The Gentlemen and Qilin battle for dominance
Posted in Commentary with tags NordStellar on July 15, 2026 by itnerdThe latest findings from NordStellar, a threat exposure management platform, reveal that ransomware attack volumes remained high from April to June 2026, sustaining the elevated baseline. The analysis also points to an intensifying fight for dominance between the two most active ransomware groups, The Gentlemen and Qilin, as well as a notable shift in victim targeting.
According to findings from NordStellar, 2,581 ransomware incidents were recorded during April-June 2026. The number reflects a slight 4% decrease from 2,676 incidents recorded in Q1 2026. However, the attacks remain at a heightened baseline, indicating sustained threat activity.
“The slight decrease in attacks shouldn’t be a sign to relax just yet,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ransomware accelerated in the last quarter of 2025, reaching record highs, and although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter.”
A total of 5,257 ransomware attacks were recorded during January-June 2026. This marks a 20% increase from the 4,387 attacks recorded during the same period last year, signaling that the ransomware threat is growing despite quarterly fluctuations.
Rivalry between Qilin and The Gentlemen intensifies
Qilin emerged as the most active ransomware group in Q2 2026 with 299 attacks, followed closely by The Gentlemen with 284 attacks. Activity from other groups trailed significantly, with DragonForce ranking third at 147 attacks.
“While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated its operations with a 39% increase in attacks, further deepening the rivalry between the two groups,” says Mantas Sabeckis, senior threat intelligence researcher at Nord Security. “Even though DragonForce remains significantly less active than the top two, it is steadily scaling up — last quarter’s attack volume marked an all-time high for the group.”
According to Sabeckis, the fact that Qilin and The Gentlemen have managed to establish themselves as the two dominant ransomware groups and more or less maintain their positions highlights a concerning trend — the ransomware threat landscape is stabilizing and maturing.
“Established ransomware groups have refined tools, affiliate networks, and negotiation infrastructures. The more sophisticated and established a group becomes, the greater the threat it poses,” explains Sabeckis. “This competition between Qilin and The Gentlemen could potentially drive an even higher baseline of activity. Each group is likely ramping up operations and casting a wider net to come out on top, and as affiliates move between groups, the balance of power could shift in the coming months.”
He adds that in a landscape like this, smaller groups such as DragonForce are under growing pressure to scale. They’re more likely to accelerate their operations to prove themselves among more dominant players, further inflating the overall threat landscape.
Q2 ransomware victims: SMBs dominate, but attackers are shifting their gaze to enterprises
NordStellar findings reveal that small and medium-sized businesses (SMBs) — those with up to 200 employees and revenues under $25 million — bore the brunt of ransomware activity. However, attacks against large enterprises with revenues exceeding $1 billion surged by 74%, rising from 23 incidents in the first quarter to 40 incidents during the second.
“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack. This recent spike in enterprise targeting is unusual and may be a temporary fluctuation,” says Noreika. “This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.”
The data also reveals that ransomware actors continue to primarily target companies in the US, with 769 recorded ransomware cases in Q2 2026. The US was followed by Canada with 97 cases, then Germany with 83 cases, the United Kingdom with 74 cases, and France with 51 cases.
As seen in previous quarters, companies in manufacturing were hit the hardest, making up for 19.5% of all attacks. The information technology sector came second (10.7% of attacks), followed by professional, scientific, and technical services (8.3%), construction (7%), and healthcare (6.2%).
“Companies in the US experienced a slight decline in attacks compared to the previous quarter, while attacks on companies in Canada increased by 13%, suggesting that attackers might be shifting their geographical focus,” says Noreika. “Businesses operating in the manufacturing and information technology sectors continue to be hit hardest by the attacks. However, the healthcare industry recorded the smallest quarterly decline among major sectors, signaling that ransomware actors continue to prioritize it due to its high-value data and the operational sensitivity of critical services, where even limited downtime can create intense pressure to restore systems quickly.”
Safeguarding against ransomware in a sophisticated threat landscape
According to Noreika, the increasing maturity of the current ransomware landscape calls for companies to stay on high alert. Businesses can expect more refined and complex attacks, making it critical to identify and patch vulnerabilities before attackers can exploit them.
“The current ransomware ecosystem is growing and expanding. Groups like Qilin and The Gentlemen don’t operate like amateur hackers — they operate like well-structured organizations,” says Noreika. “They have extensive resources that allow them to scale their operations, broaden their victim pool, invest in more efficient initial-access methods, and escalate pressure tactics such as double and triple extortion.”
Previous findings from NordStellar reveal that ransomware actors utilize various schemes to coerce victims into payment, with 76.8% of ransomware negotiations including threats to publish or leak the data, and limited-time price discounts being offered in 45.5% of the negotiations.
“As leading ransomware groups compete for dominance and scale their operations, no company is immune. Abandoning the ‘it won’t happen to us’ mindset has never been more critical,” says Noreika. “Companies should strengthen their defenses by focusing on basic cyber hygiene, which is too often overlooked. This includes enforcing multi-factor authentication, implementing strong password management policies, regularly patching systems and applications, and adopting a zero trust approach to limit lateral movement.”
Noreika emphasizes the importance of early threat prevention and detection — ransomware actors can use data leaked on the dark web to gain initial access, and catching these leaks early alerts the organization to take action by resetting passwords and revoking access keys before it’s too late. He adds that backing up critical data is crucial to reduce downtime in the event of a successful ransomware attack, while having a recovery plan in place is essential to speed up incident mitigation.
Methodology
NordStellar continuously monitors over 200 blogs run by ransomware groups. Analyzing the listings published by attackers, NordStellar discovered 2,581 ransomware attacks during April-June 2026. The full methodology can be found in the report, located here: https://nordlayer.com/intelligence/ransomware-statistics/.
Leave a comment »