Ransomware incidents surge 20 percent during first half 2026

Ransomware attacks reached 5,275 incidents in H1 2026, with threat actors now targeting large enterprises alongside traditional SMB victims.

Ransomware attacks surged 20 percent during the first half of 2026, according to the NordStellar report, marking a disturbing escalation in threats that organizations face. The data showed 5,275 recorded ransomware incidents across the first six months of the year, representing a significant year-over-year increase from previous periods. This surge reflects not just higher attack volumes, but also shifting threat actor strategies that have begun targeting large enterprises alongside the small and medium-sized businesses they’ve historically favored.

The threat landscape has fundamentally shifted. While Q2 2026 showed a slight 4 percent decrease compared to Q1—with 2,581 incidents in the second quarter alone—cybersecurity experts are warning that this represents a dangerous new baseline rather than a positive trend. The attacks have stabilized at approximately 2,500 incidents per quarter, suggesting that organizations face a persistent and elevated threat level that shows no signs of retreating. The consolidation around this quarterly baseline indicates threat actors have refined their operations to a scale they can sustain and profit from indefinitely.

Table of Contents

What’s Driving the Ransomware Surge in 2026?

The 20 percent increase in ransomware incidents during the first half of 2026 reflects intensifying competition among criminal ransomware-as-a-service groups. The Gentlemen gang escalated operations by 39 percent in Q2 2026, directly competing with the established Qilin gang, which saw its activity decline slightly during the same period. This competitive dynamic mirrors traditional business pressures—when one criminal organization gains market share, rivals either step up operations to match or risk losing their place in the ecosystem. The result is a pressure cooker effect that translates directly into more attacks across all sectors.

Competition at this level rarely abates on its own. Threat actors don’t back down when faced with rivals; they escalate. The Gentlemen’s aggressive expansion suggests confidence in their operational capabilities and likely indicates they’ve successfully monetized their attacks at scale. Meanwhile, Qilin’s slight decline doesn’t mean the group is weakening—it may simply indicate a strategic shift toward higher-value targets or a consolidation of their operations. The dynamic between these groups essentially sets the floor for ransomware activity across the entire industry.

Enterprise Organizations Face a 74 Percent Attack Surge

While small and medium-sized businesses with up to 200 employees and revenues under $25 million remained the primary ransomware targets, a far more alarming trend emerged in Q2 2026: large enterprises with revenues exceeding $1 billion experienced a 74 percent surge in attacks. This spike represented a jump from 23 incidents in Q1 to 40 incidents in Q2, signaling that threat actors have begun systematically targeting organizations with the deepest pockets and greatest ability to pay ransoms. This shift represents a calculated business decision by criminal groups.

Large enterprises typically have more substantial insurance coverage, more complex IT environments that are harder to defend comprehensively, and a greater willingness to negotiate ransom payments when critical operations are disrupted. The 74 percent increase among billion-dollar enterprises is particularly significant because it suggests threat actors view this segment as increasingly vulnerable or profitable. For organizations in this category, the risk profile has deteriorated substantially in just one quarter. A 74 percent increase in attacks on a segment previously considered less attractive signals that either defenses have weakened, or threat actors have developed new techniques to bypass them more effectively.

The New Quarterly Baseline and What It Means

The stabilization of ransomware attacks around 2,500 incidents per quarter creates a disquieting new normal that organizations must plan around. Unlike the volatility seen in previous years, when attacks might spike or dip unpredictably, the data from H1 2026 suggests threat actors have optimized their operations to a sustainable level. Q2’s 2,581 incidents sit close enough to this baseline that it represents a genuine settling point rather than an anomaly. Organizations can no longer hope that attack volumes will simply decrease over time.

This stability in attack volumes paradoxically makes threat planning more difficult, not easier. Organizations could once argue for delay in implementing security improvements by claiming that threats were temporary or cyclical. The consistent quarterly volume of approximately 2,500 incidents negates that argument. With attack volume locked at this level, the question becomes not whether your organization will be targeted, but when. The data suggests that threat actors have matured from experimental campaigns into a steady-state operational model, executing multiple attacks simultaneously and cycling through targets methodically.

Why SMBs Remain Primary Targets Despite Enterprise Escalation

Small and medium-sized businesses continue to represent the majority of ransomware victims, even as enterprises face a 74 percent surge in attacks. This persistence reflects a fundamental reality of economics: SMBs are far more numerous than large enterprises, making them statistically attractive targets. An attacker can hit twenty small businesses in the time it takes to compromise one large enterprise, and the cumulative ransom payments from those twenty SMBs often exceed a single large payout. Threat actors pursue both strategies simultaneously—high-volume attacks on smaller organizations supplemented by selective high-value targeting of major enterprises.

The limitation of this dual-targeting approach lies in operational complexity. Threat actors must maintain two separate playbooks: the fast, automated attack chains designed for SMBs that can be executed rapidly and scaled across dozens of organizations, and the surgical, targeted campaigns needed to penetrate and move laterally through large enterprise environments. This split operational model has slowed the rate at which threat actors can scale their infrastructure, which explains why SMB targeting remains the primary volume driver even as enterprise targeting expands. For SMBs, this reality is sobering: they remain attractive targets not because defenses have weakened, but because their sheer numbers make them statistically inevitable victims.

Threat Actor Infrastructure and Its Vulnerabilities

The competitive pressure between groups like The Gentlemen and Qilin creates operational stress on threat actor infrastructure. Supporting a 39 percent increase in attack volume requires significant investment in servers, malware distribution networks, and decryption key management. The Gentlemen’s expansion likely means they’ve invested substantially in their technical infrastructure—more payment servers, more redundancy, more operational security. However, this expansion also creates a larger attack surface that law enforcement and cybersecurity vendors can target.

A critical limitation in relying on operational complexity as a defense is that organizations cannot see or directly act on threat actor infrastructure problems. The stabilization of attacks around 2,500 per quarter indicates that despite law enforcement actions and vendor disruption efforts, threat actors have sufficient redundancy and resilience to maintain operations at this level indefinitely. The 20 percent year-over-year increase suggests that any disruption efforts have been outpaced by growth in threat actor capabilities. For defenders, this means that external mitigation through infrastructure takedowns or law enforcement actions will likely not significantly reduce attack volume in the near term.

The Financial Reality Behind the Surge

The 5,275 ransomware incidents recorded in H1 2026 represent millions of dollars in attempted extortion, regardless of payment rates. Even if only 10 percent of victims pay ransoms, the total value flowing to threat actors would be substantial enough to fund recruitment, R&D on new malware variants, infrastructure expansion, and payment laundering. The data suggests this economic model is working sustainably for major groups. The Gentlemen’s 39 percent operational increase correlates directly with visible profitability—if the attacks weren’t generating revenue, the group would have no incentive to expand.

This economic sustainability problem reveals why the surge is particularly concerning. Previous ransomware campaigns occasionally collapsed due to cryptocurrency tracking, law enforcement action, or payment processor shutdowns. None of these factors have disrupted the current model at scale. The ability of The Gentlemen and Qilin to not only continue operations but actively expand them suggests they’ve solved the monetization problem in ways that are resistant to current law enforcement countermeasures.

What H1 2026 Data Reveals About Threat Actor Confidence

The data from the first half of 2026 reveals threat actor confidence in several key areas: They believe they can successfully compromise large enterprises with sufficient frequency to justify targeting them. They believe their payment laundering and extortion infrastructure can handle the increased volume without triggering regulatory or law enforcement intervention. They believe competitive pressure will only drive further growth rather than lead to consolidation or industry collapse.

Each of these beliefs is reflected in the operational decisions visible in the statistics—the targeting shift, the operational expansion, and the sustained focus on high-volume attacks. The 5,275 incidents across H1 2026 and the achievement of a new baseline of approximately 2,500 per quarter represent not a temporary surge but a permanent shift in threat actor ambition and capability. The quarter-to-quarter consistency suggests this level of activity has become institutionalized within criminal organizations. For organizations assessing their security posture, treating this as the new normal operational threat level rather than a temporary spike is more likely to lead to appropriate defensive investment and security architecture decisions.


You Might Also Like