Key takeaways

  • The ransomware economy has entered a new phase. Affiliates are going independent, groups are absorbing their rivals, and encryption is becoming optional.
  • Access to corporate networks has never been easier to buy. The market is splitting into a visible tier of opportunistic sales and an invisible tier of premium partnerships, and both are growing.
  • AI-assisted malware development is already in production among multiple active groups, lowering the barrier to sophisticated operations and automating post-breach monetization.

Why ransomware in 2026 looks nothing like ransomware in 2024

Ransomware_ Q1 2026 at a glance

Just a few years ago, the ransomware conversation revolved around a handful of dominant franchises: LockBit, BlackCat, Cl0p. The affiliate model was predictable. A few major Ransomware-as-a-Service platforms recruited affiliates, those affiliates purchased access, encrypted networks, and split the proceeds. Defenders could study a few major programs and cover most of the threat landscape.

So, how has that model changed?

Trust within the criminal underground broke down. High-profile affiliate programs began exiting with affiliate funds, withholding payments, absorbing their affiliates, and sabotaging each other’s infrastructure. Experienced operators, in their turn, learned that dependency on a syndicate is a strategic liability, and a wave of independent operations followed. Several were launched by affiliates who carried active network access from their previous programs. RansomHub’s infrastructure went dark and DragonForce publicly claimed it had joined its cartel. The Gentlemen split from Qilin over a $48,000 unpaid commission and built a competing operation while still nominally affiliated.

The access market is splitting in two. Publicly advertised access sales dropped 27% in 2025 as the highest-value credentials moved to private channels. The market is not shrinking; it is splitting into a visible tier of opportunistic access and an invisible tier of premium, pre-vetted partnerships.

Encryption became optional. Refusal became irrelevant. A growing number of operators pivoted to extortion-only models built around stolen data. Hunters International formalized this by rebranding as World Leaks and providing affiliates with an exfiltration-only tool. Then in March 2026, SnowTeam launched Leak Bazaar, a marketplace that processes and segments stolen corporate data into buyer-ready categories and resells it repeatedly. Even when victims refuse to pay, their data gets monetized.

Supply chain attackers and ransomware operators are merging. Rather than breaching organizations one at a time, ransomware groups are compromising upstream service providers whose privileged access extends across dozens or hundreds of client environments. In early 2026, this convergence became formal: Vect Ransomware publicly partnered with TeamPCP after TeamPCP compromised five open-source ecosystems simultaneously, then offered all 300,000 BreachForums members a personal affiliate key for immediate activation.

AI is an essential part of the ransomware lifecycle. The Gentlemen’s ransomware builder panel was reportedly created with AI assistance, while data leak sites across multiple groups show signs of AI-generated development. AI is also changing what happens after the breach. Services like Leak Bazaar use automated processing to categorize stolen data by type, from financial reports to internal policies, and sell it in structured packages. AI capabilities also allow threat actors to scan exfiltrated data for cyber insurance documents and calibrate ransom demands accordingly.

The franchise model is gone. What replaced it is fragmented, privatized, and harder to disrupt. The following eight groups show what that looks like in practice.

Eight ransomware groups to track in 2026

The following profiles represent the most significant ransomware operators in 2026, selected based on attack volume, operational innovation, and strategic importance. Group-IB customers can access detailed profiles, TTPs, and indicators of compromise through the Threat Intelligence portal.

1. Qilin

The undisputed leader by volume, Qilin recorded 1,062 incidents across every region in 2025 and maintained that lead in the first quarter of 2026 with 389 attacks on leak sites, an annualized pace nearly 50% above the prior year. Originally launched in July 2022 as Agenda, the group rewrote its payload in Rust and relaunched as a Ransomware-as-a-Service operation in February 2023.

Affiliates exfiltrate data before encryption, then execute a three-stage process of negotiation, public announcement, and data release. In June 2025, Qilin announced it was building a legal department to prepare and submit evidence of victims’ regulatory violations to tax agencies, law enforcement, and other government authorities. The group also announced a call center in seven languages to contact victims’ clients directly and pressure them into initiating legal action against the breached company. If victims still refuse to pay, Qilin claims it will hand stolen personal data to dark web criminals for further fraud.

Entry typically comes through Fortinet edge devices exploiting CVE-2024-21762 and CVE-2024-55591. The group’s dominance also made it a talent pipeline: both The Gentlemen and Devman, two of the fastest-growing operations of 2025, were launched by former Qilin affiliates.

The takeaway: Qilin’s dominance across every region and sector makes it the baseline ransomware threat. If your edge devices run Fortinet and your patching cycle exceeds days, you are in its targeting profile.

2. Akira

The most geographically consistent operator in 2025, with a focus on North America and Europe, Akira remains among the top three most prolific groups globally. Group-IB experts detected 695 Akira attacks in 2025 and 201 in the first quarter of 2026 alone. Akira operates across Windows, Linux, and ESXi, prioritizing hypervisors that host SCADA and production systems. When the virtualization layer is encrypted, organizations lose operational control even though physical equipment stays powered.

Akira is one of the most effective groups at converting attacks into payments. The group steals large volumes of victim data, then offers a four-part service package: full decryption, evidence of data deletion with a guarantee against publication, a security report explaining how the group gained access, and a promise not to target the organization again. The initial price covers all four. During negotiations, victims can select which “services” they actually need, but most end up paying for the full package. Ransom demands are calibrated to what victims can actually pay, and the entire process takes place under sustained pressure from negotiators pushing for rapid decisions.

The takeaway: Akira has built a business model where every element is optimized for conversion: structured service packages, à la carte pricing, calibrated demands, and negotiated discounts that mirror legitimate enterprise sales. Organizations facing this level of professionalization need a strong incident response plan and a clear crisis decision-making strategy before the pressure starts.

Europe’s Manufacturing Threat Landscape 2026

Explore sector-specific analysis of Akira and similar ransomware groups targeting Europe’s manufacturing sector, with insights into key risks, vulnerabilities, and response strategies.

3. Cl0p

Cl0p operates the most disciplined ransomware model in the current landscape: no public affiliate recruitment, no visible forum presence, all critical access and zero-day exploitation handled internally or through contracted specialists. The group discovers or acquires zero-day exploits to silently infiltrate widely deployed platforms at mass scale.

In 2025, Cl0p exploited vulnerabilities in Cleo MFT, CrushFTP, and Oracle E-Business Suite, following identical methodology used against MOVEit, GoAnywhere, and Accellion. Each campaign targets a single platform, exploits it before patches are available, and exfiltrates data from the entire customer base before beginning extortion. With 541 attacks in 2025 and 128 in the first quarter of 2026, Cl0p continues to prove that precision and patience can match the output of large RaaS programs.

The takeaway: If your organization relies on widely deployed file transfer or ERP platforms, a single zero-day in that vendor’s product can expose your data without any direct compromise of your own network. Cl0p’s model is supply chain compromise in its purest form. For more on how upstream exploitation is reshaping the threat landscape, see six supply chain attack groups tracked by Group-IB in 2026.

4. SafePay

A private operation where core developers directly orchestrate attacks rather than recruiting affiliates, SafePay emerged in September 2024 and scaled to 384 confirmed attacks by end of 2025. The developer-operated model contributes to tight infrastructure control that affiliate-driven programs struggle to match. The most significant attack was against Ingram Micro, where 3.5TB of data was exfiltrated and over 42,000 individuals were affected. Their ransom notes describe the intrusion as “paid training for your system administrators,” framing designed to normalize payment as a business decision rather than a response to extortion.

The takeaway: SafePay’s rapid scaling without affiliates demonstrates that a small, technically capable team with consistent operational discipline can be as prolific as a large affiliate network.

Explore real ransom notes from the most active groups

See how SafePay, The Gentlemen, and others frame their extortion communications.

5. DragonForce

DragonForce distinguished itself in 2025 by systematically eliminating competitors. In March 2025, the group exploited a vulnerability on BlackLock’s leak site, defaced its infrastructure, effectively destroying a rival and absorbing its affiliates. One month later, RansomHub’s infrastructure went dark. DragonForce announced on the RAMP forum that RansomHub had “decided to move to our infrastructure.” RansomHub, however, pushed back publicly, accusing DragonForce of sabotage, betrayal, and even cooperation with law enforcement. Displaced affiliates scattered across the ecosystem: some moved to DragonForce, some to Qilin, others elsewhere. The displacement was one of the factors that helped Qilin reach the top position by attack volume in 2025.

Beyond competitor absorption, DragonForce exploited multiple vulnerabilities in SimpleHelp RMM (CVE-2024-57726, CVE-2024-57727, CVE-2024-57728) to compromise managed service providers and deploy ransomware across multiple client networks simultaneously. With 217 attacks in 2025 and 101 in the first quarter of 2026 (already half the prior year’s total in a single quarter), DragonForce is positioning itself as a consolidator in an increasingly fragmented ecosystem.

The takeaway: In 2025, DragonForce showed what ransomware groups are willing to do in the pursuit of affiliates, victims, and revenue: destroy rivals, claim their infrastructure, and build migration paths for displaced affiliates. The cartel ambition has since cooled, but the precedent stands. Any group with enough operational leverage can attempt the same.

See Group-IB Threat Intelligence in action

Industry-awarded automated threat research that helps to predict and prevent attacks.

6. The Gentlemen

One of the clearest examples of the affiliate-independence trend, The Gentlemen evolved from ArmCorp, a former Qilin affiliate group. The group was responsible for 455 attacks in 2025 and ranked as the second most active threat group globally in the first quarter of 2026, with 211 incidents. Its most significant asset is a database of approximately 14,700 pre-compromised FortiGate devices made available to affiliates, exploiting CVE-2024-55591. AI tools including ChatGPT, Gemini, and Claude have been confirmed in use for ransomware development. Their ransom notes feature staged disclosure timelines with 48-hour pre-publication warnings and 239-hour reveal counters.

In May 2026, an anonymous actor breached The Gentlemen’s backend infrastructure, leaking over 16 GB of internal files that exposed the group’s operational blueprints. Despite that, the group continues to recruit affiliates, and based on Group-IB analysis, remains the second most active RaaS group by attack volume in the second quarter of 2026.

The takeaway: The Gentlemen illustrate a pattern accelerating across the ransomware underground: experienced affiliates increasingly distrust the groups they work for and break away to build their own operations. Every breakaway carries the skills, access, and data gathered under the previous brand.

Gartner® Magic Quadrant™ 2026 — Cyberthreat Intelligence Technologies

Group-IB named a Leader In the First-Ever Magic Quadrant for Threat Intelligence.

7. INC Ransom

A mature RaaS operation covering more than 190 sectors across 66 countries, INC Ransom exploits Citrix NetScaler ADC and Gateway vulnerabilities as primary initial access vectors. For exfiltration, affiliates abuse the legitimate backup tool Restic, often renamed to “winupdate.exe” to evade detection. What distinguishes INC Ransom is its communications: their ransom notes devote more text to discrediting law enforcement, recovery firms, and cyber insurers than to explaining the payment process. High-profile victims in 2025 included Scotland’s NHS, McLaren Health Care, Yamaha Motor, and the Texas State Bar. With 360 attacks in 2025 and another 144 in the first quarter of 2026, INC Ransom has sustained a high operational tempo across two consecutive years.

The takeaway: INC Ransom’s breadth across nearly 200 sectors means no organization should assume it falls outside scope. The abuse of legitimate tools for exfiltration highlights why behavioral detection, not signature-based blocking, is essential.

8. Vect

First observed in January 2026, Vect operates a multi-platform RaaS with builders for Windows, Linux, and ESXi and an affiliate panel for managing builds, earnings, and victim negotiations. In March 2026, Vect announced a partnership with TeamPCP, the actor behind supply chain compromises of Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK. At the same time, Vect announced a partnership with the BreachForums underground forum. The gang declared intent to deploy ransomware against every organization affected by the supply chain compromises and offered all 300,000 registered forum members a personal affiliate key for immediate activation via private messages. The forum provided escrow and coordination infrastructure.

This appears to be one of the first cases of full-scale collaboration between a ransomware operation and an underground forum, turning an entire community into a potential affiliate network.

It didn’t last, though. Vect’s DLS has been inaccessible since mid-April 2026, with the last posts published on April 15. The likely reason: a critical flaw in the encryption implementation that makes files over 128 KB permanently unrecoverable, even for the operators. In practice, Vect functions as a wiper rather than recoverable ransomware. The group may rebrand in the future, but the Vect project itself appears to be over.

The takeaway: Vect’s experiment was unsuccessful. The group published only a handful of posts on its leak site mentioning victims and TeamPCP before its DLS went offline. Even so, it demonstrated how ransomware groups can collaborate with other threat actors on joint operations. The underlying model of combining supply chain access with mass affiliate recruitment is likely to re-emerge.

Group-IB customers can learn more about Vect on Group-IB Threat Intelligence portal.

What this means for defenders

Cybersecurity leaders are navigating uncharted territory this year as forces converge, testing the limits of their teams in an environment defined by constant change. This demands new approaches to cyber risk management, resilience, and resource allocation
Alex Michaels
Gartner® (February 2026)

The ransomware threat isn’t going anywhere. In the first quarter of 2026 alone, Group-IB identified 2,393 attacks published on ransomware leak sites across 79 active groups, a 4.5% increase from the previous quarter. The trends outlined in this article point to five priorities for defenders.

Monitor the underground before attacks begin. Access sales surged 44% in Q1 2026, and groups like The Gentlemen maintain inventories of pre-compromised devices ready for affiliate use. Group-IB Threat Intelligence and Prevyn AI provide visibility into the forums and private channels where access is bought and sold.

Treat vendors as part of your attack surface. The Marquis, SimpleHelp, and TeamPCP incidents followed the same pattern: compromise a trusted provider to gain access to its customers. Assess every MSP, SaaS provider, and contractor with access to your environment.

Detect pre-encryption activity, not encryption itself. With 83% of cases involving data exfiltration and some groups dropping encryption entirely, detecting encrypted files means the damage has already been done. Group-IB Managed XDR identifies lateral movement, credential abuse, and data staging before attackers reach the final stage of intrusion.

Patch edge devices as an emergency, not a routine. Profiled groups in this article enter through a known vulnerability in an internet-facing device: Fortinet, VMware ESXi, Veeam, Citrix, SimpleHelp. If your patching cycle is measured in weeks, your organization remains at risk.

Prepare for the pressure. Qilin is building a so-called “legal department.” Akira tailors ransom demands to victims’ insurance coverage. Modern ransomware operations combine technical compromise with psychological pressure, legal threats, and prolonged negotiations. Group-IB Services Retainer gives your team on-demand incident response and proactive threat-informed assessments to prepare for these scenarios in advance.

To learn about the most disruptive threat actors of 2026 visit the Masked Actors Hub.

FAQs

What is Ransomware-as-a-Service (RaaS)?

arrow_drop_down

Ransomware-as-a-Service is a business model where ransomware developers build and maintain the malware, infrastructure, and extortion platforms, then recruit affiliates to carry out attacks in exchange for a share of the ransom payments. This model lowers the barrier to entry, allowing less technically skilled attackers to conduct sophisticated ransomware operations. In 2025, Group-IB tracked 119 active ransomware groups, many operating under RaaS or similar partnership models.

What should I do if my organization receives a ransom note?

arrow_drop_down

Do not engage with the attacker directly before consulting your incident response team, legal counsel, and, if applicable, your cyber insurer. Preserve all evidence, including the ransom note itself, system logs, and any communication from the attacker. Notify relevant law enforcement authorities and consider engaging a professional incident response firm. Modern ransom notes are designed to create urgency and narrow your perceived options; having a pre-established response plan prevents decision-making under pressure.

Should my organization pay the ransom?

arrow_drop_down

Most law enforcement agencies and cybersecurity experts advise against paying. Payment does not guarantee data recovery or deletion, funds further criminal operations, and may expose your organization to legal risk depending on the jurisdiction and the sanctioned status of the threat actor.

How can I identify which ransomware group attacked my organization?

arrow_drop_down

Ransom notes, file extensions applied to encrypted files, leak site postings, and the specific tools and techniques used during the intrusion can all help identify the responsible group. Group-IB’s Ransom Notes page provides examples from the most active groups to aid identification. For confirmed attribution and tactical intelligence, Group-IB Threat Intelligence provides detailed profiles and TTP mappings for all major ransomware operators.

How can organizations protect themselves from ransomware?

arrow_drop_down

Effective ransomware defense requires proactive intelligence and operational readiness. Organizations should monitor underground forums and closed channels for access sales targeting their industry, maintain visibility into their full attack surface including vendor and MSP connections, deploy behavioral detection capable of identifying pre-encryption activity such as lateral movement and data staging, ensure virtualization infrastructure is included in security monitoring, and regularly test incident response plans against realistic scenarios including pure extortion and supply chain compromise.