Six ransomware trackers, six different answers
Leak-site counting now feeds board packs, insurance pricing and national policy. The published 2026 figures disagree on victim totals, on how many groups are active, and on which country leads.

The numbers
Six trackers published ransomware victim data covering 2026. None of them agree, and the gaps are not small.
- Black Kite: 7,551 victims between April 2025 and March 2026, a 24.9% year-on-year rise, across 146 active groups by June 2026. Qilin led with 1,358 victims, a 443% increase. The top five groups accounted for 43.6% of disclosed victims. Manufacturing took 1,660 victims (22%), professional, scientific and technical services 1,389. The United States was 49.3% of victims, with Germany up 48% and Italy up 96% [1].
- Bitsight: Qilin at approximately 1,562 attacks over the trailing twelve months, the United States at 4,294 attacks (36.1%), manufacturing at 1,641 (26%), across 89 tracked operations [3].
- Group-IB: 2,393 attacks identified on leak sites in Q1 2026 across 79 active groups, a 4.5% quarterly increase, with Qilin at 389 for the quarter and 83% of cases involving data exfiltration [2].
- GuidePoint Security: roughly 182 distinct operational groups tracked, with Qilin at 361, The Gentlemen at 182 and Akira at 176 for Q1 2026; the United States at 1,084 incidents (51%), and Thailand at 33 making its first top-ten appearance since 2022 [5].
- Ransomware.live: 264 victims posted between 7 and 16 September 2026, and a year-to-date figure 32.6% above 2025 [6].
- Cyble: no aggregate total published, but names Qilin, Akira, The Gentlemen, DragonForce and INC Ransom as leading the first half of 2026 [4].
Why they disagree
Four mechanical reasons, none of which is an error.
Window. Black Kite's year runs April to March [1]. Bitsight reports a trailing twelve months [3]. Group-IB and GuidePoint report a calendar quarter [2][5]. Qilin at 1,358, 1,562, 389 and 361 may be the same operation counted over four different spans, and a reader comparing the first two figures to the second two is comparing a year to a quarter.
What counts as a group. The active-group figures of 146, 89, 182 and 79 [1][3][5][2] reflect different thresholds for when a rebrand, a splinter or a site with three posts becomes a tracked entity. Group-IB's own reporting documents affiliates going independent, groups absorbing rivals, and Hunters International rebranding as World Leaks with an exfiltration-only toolset [2]. The underlying population is genuinely unstable, so the counting rule drives the count more than the criminal ecosystem does.
Deduplication and validation. Black Kite validates leak-site claims against open-source intelligence and internal telemetry [1]. Bitsight runs a large language model pipeline across leak-site posts to extract victim, location and sector and to remove duplicates [3]. Ransomware.live scrapes leak sites continuously [6]. A victim claimed by two groups, or reposted after a failed negotiation, is one victim or two depending on which pipeline sees it.
Denominator. The United States at 49.3% [1], 51% [5] and 36.1% [3] is the clearest illustration. The same dominant country moves fifteen percentage points depending on which victims entered the set, which means every other share in those reports moves with it.
What survives every methodology
Four findings hold across trackers, and those are the ones worth quoting.
- Qilin leads. Every list places it first, by a wide margin [1][3][5][2].
- Manufacturing is the most-targeted sector. Black Kite counts 1,660 victims and Bitsight 1,641 [1][3]. The absolute numbers are strikingly close; the percentages differ, 22% against 26%, only because the totals differ.
- The direction is up. Every tracker publishing a change reports growth: 24.9% year-on-year [1], 32.6% year-to-date [6], 4.5% quarter-on-quarter [2].
- Exfiltration, not encryption, is the business. Group-IB records 83% of cases involving data theft and documents groups moving to extortion-only models [2]. That is consistent with Mandiant's finding that adversary notification accounts for 44% of detection in ransomware cases, against 41% internal and 15% external [7].
None of these trackers measures how victims were reached. Leak-site counting records who was hit, not how, and cannot be used to prioritise controls. Incident-response data is the right source for that: Unit 42's 2026 report puts phishing and vulnerability exploitation level at 22% each as initial access, with previously compromised credentials at 13% [10]. Pairing a leak-site count with an IR dataset answers a question neither answers alone.
The regional read
APAC exposure is visible in the detail and invisible in the totals. GuidePoint records Thailand at 33 victims in Q1 2026, its first top-ten appearance since 2022, alongside India at 43 [5]. CYFIRMA's weekly reporting repeatedly places Thailand, India, Japan and Taiwan among the top victim countries for individual groups, including a Thai diagnostics distributor among named healthcare victims [8][9].
The published totals remain dominated by the United States and Western Europe. Some of that is real. Some is a reporting artefact: leak-site counting measures who gets posted, which reflects who declines to pay and who operates under disclosure obligations that would surface the incident anyway. Jurisdictions with weaker mandatory disclosure and a higher quiet-payment rate are systematically under-counted.
The practical consequence for a Malaysian or regional reader is that the APAC share in any of these reports is a floor, not an estimate.
How to use them
- Never quote a total as the number. Quote the tracker, the window and the method alongside it [1][3][5].
- Use them for direction and composition rather than magnitude. Growth rates and sector rankings survive methodological differences; absolute counts do not.
- Check the denominator before repeating a percentage. Country and sector shares are functions of the whole set, and the sets differ by thousands of victims.
- For board reporting, prefer the metric nearest your own exposure. Sector rank and regional presence are more defensible than a global total.
- Remember what none of them see. Every tracker counts only publicly disclosed victims, and Black Kite states plainly that true volume is almost certainly higher than leak sites show [1]. Organisations that pay quickly and quietly appear in no dataset here.
Domain view
Leak-site counting has quietly become load-bearing. It informs board reporting, insurance pricing and national policy, and it rests on scraping the marketing output of criminal enterprises that have an interest in both inflating and concealing their results.
The disagreement between trackers is not a scandal and not a reason to discard them. It is the visible edge of a measurement problem that the trackers themselves document. The useful response is to stop treating any single figure as the count, and to read the method before the headline.
One finding is worth carrying whichever tracker you prefer. Black Kite reports that 43.5% of victims still carried critical unpatched vulnerabilities after their incident [1]. Whatever the true denominator, a large share of organisations that have already been extorted have not closed the door behind them. That number is a statement about remediation discipline, and it does not depend on getting the victim count right.
Sources
Every R3KONX article cites its primary material. 10 sources, in order of first citation. Links open the original publication.
- 2026 Ransomware Report: 7,551 Victims, Up 24.9% Black Kite · 2026
- Ransomware in 2026: Same Business, New Rules Group-IB · 2026-07-23
- 2026 Ransomware Statistics and Deep Web Threat Trends Bitsight · 2026
- 2026 Threat Intelligence Trends, Cyber and Ransomware Report Cyble · 2026-07-06
- Ransomware reaches elevated new normal as attack volumes hold steady into 2026 Industrial Cyber, reporting GuidePoint Security GRIT · 2026-04-16
- Ransomware.live victim tracker Ransomware.live · 2026-09-16
- M-Trends 2026 Report: Executive Edition Mandiant / Google Cloud · 2026
- Weekly Intelligence Report - 04 Sep 2026 CYFIRMA · 2026-09-04
- Weekly Intelligence Report - 14 Aug 2026 CYFIRMA · 2026-08-14
- 2026 Unit 42 Global Incident Response Report Unit 42, Palo Alto Networks · 2026-02
Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: every figure here is drawn from leak-site monitoring, which counts only publicly disclosed victims and therefore understates true volume by an unknown margin; the trackers compared use different reporting windows, inclusion thresholds and deduplication methods, and are cited individually rather than combined. Attribution and tracking names are the assessments of the named researchers, not independent R3KONX findings. Corrections to event@r3konx.asia.
