Technology

Ransomware Attacks Jump 25% as New Groups Flood In

Ransomware victims rose 25% in a year as dozens of new groups entered the field, but researchers say AI is not the main driver.

Ransomware did not just keep growing this year. It sped up, and the acceleration came from an unexpected place: people, not algorithms.

A 25% Jump in a Single Year

Security firm Black Kite tracked ransomware incidents between April 2025 and March 2026 and counted 7,551 known victims worldwide, a 25% rise over the prior 12 months. Most of that growth landed in the back half of the period. Victim counts climbed from 2,904 between April and September 2025 to 4,647 between October and March, a 60% jump in six months. March 2026 alone saw 861 organizations hit, close to 28 a day.

Ferhat Dikbiyik, chief research and intelligence officer at Black Kite, frames it plainly: the barrier to running a ransomware operation keeps dropping.

Why the Numbers Moved

Black Kite points to three overlapping forces: the ransomware ecosystem splintering into more, smaller groups, a wave of new entrants, and attackers pushing further into small and midsize organizations that traditionally flew under the radar. Supply chain compromises added fuel too. Breaches tied to Oracle and Salesforce let single intrusions cascade into dozens of victims at once, with one MSP compromise reportedly reaching 32 South Korean financial institutions through the Qilin group.

Exposure mattered more than most victims realized. Companies with a high ransomware susceptibility score, a measure based on visible weaknesses like exposed credentials and unpatched systems, were far more likely to get hit. More than 90% of victims showed a spike in that score shortly before the attack landed.

Manufacturing stayed the top target with 1,660 victims, followed by professional and technical services at 1,389, then construction. Nearly half of all victims were US based, though Europe saw faster growth in attack volume than the US did.

AI's Role Was Smaller Than Assumed

Here is the twist: established groups like Qilin, Everest, Cl0p, and World Leaks still drove most of the volume among large US targets, while newer, less skilled entrants picked up victims across Europe, Latin America, Africa, Asia, and the Middle East. Many of those newer operations did not last. The median lifespan for a group launched between April and September 2025 was under five months.

Black Kite counts roughly 146 active groups today, up from 127 in March. Open source language models and code agents lowered the cost of building an operation and early signs of AI assisted code showed up in encryptors, but Dikbiyik is careful not to overstate it: the growth, in his words, is human, and AI simply let more people show up at once.

What This Means for Defenders

One uncomfortable finding: many victims did little afterward to reduce their odds of getting hit again. That points to organizations treating an incident as closed rather than as a signal to fix what made them a target in the first place. Dikbiyik recommends structured exposure reviews at 30, 60, and 90 days post-incident, prioritizing patches based on what attackers are actually exploiting rather than CVSS scores alone, and extending visibility into vendor and SaaS relationships.

The democratization of ransomware tooling means smaller security teams can no longer assume they are too unimportant to be a target. The next wave of attackers may not be more skilled, just more numerous, and that alone is reshaping the threat landscape faster than any single piece of malware could.