Ransomware incidents surge 20 percent during first half 2026

Large enterprises and U.S. healthcare organizations face accelerating ransomware targeting, with enterprise attacks up 74% and healthcare enduring 2.3 attacks daily in H1 2026.

Ransomware attacks surged 20 percent in the first half of 2026, with approximately 5,275 recorded incidents according to NordStellar research. The increase reflects a sharpening criminal focus on high-value targets and growing sophistication in ransomware-as-a-service operations.

The threat remains geographically concentrated and sector-specific. The United States absorbed 1,721 of approximately 3,836 tracked global attacks in H1 2026—45 percent of all incidents, far exceeding any other country. Large enterprises, government agencies, and healthcare facilities face the most aggressive targeting.

Table of Contents

Geographic Concentration and the U.S. Advantage to Attackers

The United States' dominance as a ransomware target stems from enterprise density and ransom-paying capacity. American organizations represent more attacks than the nine next-most-targeted countries combined, meaning attackers calibrate their campaigns for maximum revenue yield in U.S. markets.

This concentration matters for risk assessment. Organizations operating in the U.S. should assume elevated exposure compared to equivalently-sized firms in lower-incident regions. International operations of U.S.-based companies remain similarly exposed due to global ransomware group reach.

Enterprise Targets See Steepest Increases

Large enterprises bore disproportionate attack growth. Attacks targeting companies with revenue exceeding $1 billion surged 74 percent, rising from 23 incidents in Q1 to 40 in Q2 2026.

This shift reflects criminal adaptation: larger targets typically manage more valuable data, operate mission-critical systems, and face pressure to pay. Mid-market and smaller firms remain at risk, but the acceleration among large enterprises suggests ransomware groups are shifting resources toward higher-value marks. This trend favors sophisticated, well-resourced attack groups over spray-and-pray tactics.

The Ransomware Groups Behind the Surge

Three ransomware-as-a-service groups dominated H1 2026. Qilin led with 641 victims, followed by The Gentleman with 464 and Akira with 317. However, momentum shifted sharply by mid-year: by June, The Gentleman surpassed Qilin as the most active group, claiming 94 victims in a single month—the group's highest monthly total on record.

This volatility illustrates the operational instability of ransomware leadership. Groups rise and fall based on law enforcement disruption, internal conflict, and victim payment patterns. Organizations should monitor emerging group tactics rather than treat any single group as a permanent threat.

Sector-Specific Impacts: Healthcare and Government at High Risk

Healthcare and government sectors face concentrated attack pressure. Healthcare organizations suffered an average of 2.3 ransomware attacks per day in H1 2026, representing a 14 percent increase from the second half of 2025.

Government entities worldwide experienced 187 attacks, averaging roughly one attack per day. Education sector attacks declined 13 percent, suggesting attackers are deprioritizing lower-revenue targets. Healthcare's critical infrastructure role and regulatory penalties for patient data breaches make it consistently lucrative; government's political sensitivity and operational importance make it strategically valuable regardless of immediate revenue.

Ransomware Revenue Accelerates

Financial returns on ransomware attacks are climbing sharply. Ransomware groups generated approximately $529.2 million in revenue during Q1 2026 alone, representing a 39 percent surge compared to Q1 2025.

This revenue explosion incentivizes further investment in attack infrastructure and recruitment of cybercriminals. The financial momentum suggests limited deterrence from payment monitoring or law enforcement seizures. Attackers continue scaling operations because ransom yields justify the operational risk.

Methodology Differences Affect Accuracy

Incident counts vary substantially across research organizations. Different security firms report different totals—NordStellar reports 5,275 H1 incidents versus CRIL's 3,836 tracked cases—due to varying methodologies and database coverage.

The 20 percent surge is consistent across sources, but absolute numbers should be treated as estimates rather than precise counts. This variation means individual organizations cannot reliably benchmark their incident exposure against "typical" attack rates. Focus instead on sector-specific threat models and your organization's security posture compared to peers.


You Might Also Like