Black Kite: Ransomware increasing across all metrics in 2026

This year is shaping up to be another record-breaking year for ransomware attacks, with the amount of publicly disclosed victims having already increased by almost 25% from last year, according to one new report.  

In 2026, ransomware incursions have grown by 60% during the second half of the reporting period for Black Kite, vendor of a cyber risk management platform.

The cyber surveillance company’s 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record monitored activity from almost 300 ransomware groups from April 1, 2025, through March 31, 2026.  

Within that time, the firm identified 7,551 publicly disclosed ransomware victims, up 24.9% from the previous reporting period. Attacks accelerated by 60% during the second half of that reporting period, but the first half, from April to September 2025, produced 2,904 victims. From Oct. 2025 to March of this year, ransomware disclosures rose to 4,647 victims.

See also: Black Kite: Data breaches escalate to records amid slow disclosure by supply chain companies 

Black Kite also identified 146 active ransomware groups by June 2026, including 61 new actors entering during the reporting period. 

The report was released as manufacturers continue to struggle with ransomware and cyberattacks, as concerns rise in supply chain risks, business ecosystems, financial impacts of attacks, and overall safety issues when preparing for such incidents.  

Manufacturers were hit the hardest by ransomware attacks last year, with a 58% year-over-year increase in victims, according to one study. 

‘Defining pressures’ and AI as ‘attack chain glue’ 

Black Kite also reinforced why supply chain exposure is a concern, calling it “one of the year’s defining ransomware pressures.”  

The report found that major incidents centered on the systems around breached companies, such as vendor platforms, SaaS integration, ERP applications, and data stores.

See also: Workshop confronts manufacturing execs with the big stakes that ride on proper cybersecurity protocols 

The report states that since organizations cannot directly patch a vulnerability it does not own on a platform it does not run—often through a vendor relationship—an attack path can form.

Other key findings of the report include:  

  • Qilin, the Ransomware-as-a-Service operation, claimed more than 1,300 victims, nearly twice as many as the nearest threat actor.  

  • Over 40% of victims still carried critical patch vulnerabilities in the latest assessment, and 30.8% carried KEV exposure.  

  • About 175% higher stealer log exposure in the before-and-after security posture comparison.  

  • Oracle E-Business Suite and Salesforce ecosystem integrations defined several of the year’s most visible supply chain incidents. 

AI also is being used to accelerate attacks. The Black Kite report identified two different ways AI is entering the ransomware cybercrime business: as support for technical execution and as language for extortion pressure.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *