CYOPS · Cyber Operations

Volume up, encryption down: what 2026’s ransomware data changes

Victim counts hit records while the share of cases involving encryption fell. Extortion is separating from ransomware, and most response plans are still written for the old shape of the incident.

Two figures from the 2026 datasets do not fit together comfortably. Ransomware victim counts are at record levels: 7,551 organisations named on leak sites between April 2025 and March 2026, a 24.9% rise, with March 2026 alone producing 861 — the highest single month recorded. [1] Meanwhile, in incident response work, encryption showed up in only 78% of extortion cases, down from over 90%. [3] More victims, less encryption. The activity is growing and changing shape at the same time.

The market has more sellers

Black Kite counted 146 active groups by June 2026, more than double the 61 operating in 2023, with 61 new entrants inside the period — yet the top five still accounted for 43.6% of victims. Qilin dominated with 1,358 victims, a 443% increase year on year, roughly one in five to six of all victims. Manufacturing led targeted sectors for a fourth consecutive year at 1,660 victims, 22% of the total, and growth in Europe outpaced the United States, with Germany up 48% and Italy up 96%. Companies in the $50m–$100m revenue band were the fastest-growing segment. [1]

Bitsight's independent tracking of the same underlying leak-site material gives a similar shape with different totals: roughly 1,562 attacks attributed to Qilin over twelve months, the United States leading at 4,294 incidents or 36.1%, manufacturing first by sector at 1,641. [2] The two sets differ because the counting method differs — both are derived from criminal leak-site posts, which are self-reported by offenders, include unverified and duplicated claims, and exclude every victim who paid quietly. Treat all of these numbers as a floor for activity, not a census.

The incident is getting shorter

Unit 42's 2026 global incident response report, drawn from more than 750 major incidents, is where the operational change shows. The fastest quartile of intrusions reached data exfiltration in 1.2 hours, against 4.8 hours the previous year. Identity weaknesses played a material role in nearly 90% of investigations; 87% of intrusions involved activity across multiple attack surfaces, and around 48% involved browser-based activity. Over 90% of breaches were enabled by preventable gaps. [3,4]

The economics moved too: median ransom demands rose to $1.5m, while negotiated payments settled around $500,000 — a 61% reduction from the opening demand. [3] Verizon's 2026 DBIR, working from a much broader breach corpus, has ransomware present in 48% of breaches, up from 44%, with 69% of victims refusing to pay. [8]

If the fastest attackers are out with the data inside 90 minutes, a response plan whose first milestone is a crisis call the next morning has already conceded the outcome it was written to prevent.

R3KONX analysis desk

Extortion without encryption changes the playbook

When encryption is absent, the controls people rehearse — immutable backups, restore drills, recovery time objectives — do not address the actual harm. Data is already gone before anyone is asked for money. That moves the decisive work earlier: egress monitoring, identity telemetry, and detection of staging and archive activity, rather than recovery engineering. It also changes the legal and communications track, because a notification obligation may be triggered in a case where every system stayed available.

Group-IB's incident response framing splits readiness into anticipate, contain, communicate, recover and learn, and makes the point that the bottleneck is usually not the technology but whether the plan has ever been executed under pressure. The cost evidence it cites from IBM's 2025 breach study is blunt: organisations with tested incident response plans saved an average of $2.66m per breach, and ransomware incidents averaged $5.08m. [5]

The regional picture

Asia-Pacific is inside this, not adjacent to it. Group-IB tracked The Gentlemen claiming 29 attacks in February 2026 across APAC. [5] Weekly intelligence reporting from early September 2026 places Krybit at a Thai manufacturer and The Gentlemen at a Japanese equipment manufacturer, with India and Thailand recurring across victim lists. [6] For Malaysia, one third-party compilation drawing on ransomware.live and MyCERT advisories counts more than 30 confirmed incidents in the first half of 2026 — government and public sector around 28%, manufacturing 22%, financial services 18% — while stating plainly that the real figure is higher. [7] That compilation is not an official statistic and should be cited as what it is: a leak-site derived estimate. The absence of an authoritative public national count is itself the finding.

Where this connects to the perimeter

The dividing line between crimeware and state activity keeps thinning at the point of entry. Cisco Talos's September analysis of exploitation against Secure Firewall Management Center identified three clusters on the same platform, one attributed to Sandworm and another to a Qilin ransomware affiliate. [9] Verizon's data explains why the edge is where they meet: vulnerability exploitation is now the leading initial access vector at 31% of breaches, median remediation of known-exploited flaws has slipped to 43 days, and only 26% of them are ever fully remediated. [10] Ransomware volume is, in large part, a downstream measurement of unpatched perimeter infrastructure. Black Kite makes the same point from the victim side: 43.5% of victims still carry critical patch vulnerabilities, and 30.8% still have known-exploited ones after the incident is closed. [1]

What to change in the plan

  • Set detection and containment targets in minutes against the 1.2-hour exfiltration benchmark, and test against them. Recovery-time objectives alone no longer describe the risk. [3]
  • Instrument identity as the primary battleground: session theft, over-permissioned accounts and credential reuse appeared in close to 90% of investigations. [3]
  • Build a theft-only extortion playbook with legal and communications, separate from the encryption playbook. Nearly a quarter of extortion cases now need it. [3]
  • Run the ransom decision as a rehearsed decision, with authority, thresholds and regulatory duties agreed in advance — 69% of victims now decline to pay, which is a policy position, not an improvisation. [8]
  • Close the loop with vulnerability management: post-incident hardening that leaves known-exploited flaws in place is the most common way a victim becomes a repeat victim. [1,10]

None of this is exotic. It is the difference between a plan written for the 2021 version of this crime and one written for what the 2026 data actually describes. Cyber operations is a full R3KONX track for that reason: the interesting work is in how operations are run, measured and rehearsed, not in the malware family names.

Sources

Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.

  1. 2026 Ransomware Report: 7,551 Victims, Up 24.9% Black Kite · 2026
  2. 2026 Ransomware Statistics & Deep Web Threat Trends Bitsight · accessed 14 September 2026
  3. 2026 Unit 42 Global Incident Response Report Palo Alto Networks Unit 42 · 2026
  4. 2026 Unit 42 Global Incident Response Report u2014 summary RH-ISAC · 2026
  5. Ransomware in 2026: What the Data Demands From You Group-IB · 2026
  6. Weekly Intelligence Report u2014 04 Sep 2026 CYFIRMA · 4 September 2026
  7. Malaysia Ransomware Report H1 2026: Who Got Hit SimplyData (compilation of ransomware.live and MyCERT material) · 2026
  8. Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Help Net Security · 20 May 2026
  9. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos · 9 September 2026
  10. Verizon DBIR 2026: Vulnerability Exploitation Is #1 Initial Access Vector watchTowr · 2026
  11. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline The Hacker News · September 2026

Researched and written by the R3KONX analysis desk from the primary material listed above. Vendor datasets count victims differently — mainly from leak-site posts — so totals are not directly comparable and are attributed individually. Corrections: event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.