Ransomware attacks rose 20% in the first half of 2026 compared to the same period last year. The total came to 5,275 recorded incidents. Security researchers describe roughly 2,500 attacks per quarter as the new floor, not a temporary spike.
The slight quarter-on-quarter dip that some observers highlighted is misleading. Criminal groups got more organized and consolidated, not quieter. The top ten ransomware operations now account for 71% of all recorded victims, the highest concentration since early 2024. When criminal markets consolidate like this, the surviving groups tend to be better funded, better organized, and harder to stop.
Two groups in particular are worth understanding. Qilin has been operating since at least 2022 and holds roughly 16% of the criminal ransomware market. Its victims include a major healthcare supplier in the UK and the Cleveland Municipal Court in the US. The group recruits third-party attackers, pays them generously, and lets them target whoever they want, which is why Qilin's attack count keeps climbing even as law enforcement watches it closely.
The Gentlemen is newer and growing faster. It was started in late 2025 by a former Qilin affiliate who left after a dispute over an unpaid commission of around $48,000. Since then, the group has hit organizations across more than 66 countries. During the first five months of operation, it reached the same number of victims it took Qilin eighteen months to accumulate. It offers attackers who join its network a 90% cut of the ransom, ten points higher than most competitors. That generous split is why talent flocked to it so quickly.
The financial picture for victims is not improving. The average total cost of a ransomware attack, including downtime, legal fees, and recovery, sits at $5.08 million per incident according to IBM's research. The ransom payment itself is typically only about 15% of that total. The real damage comes from the weeks of operational disruption: the average downtime runs to 24 days. For a manufacturing operation, a logistics company, or a healthcare provider, three and a half weeks of disrupted operations is an existential event.
Small and mid-sized businesses make up more than 60% of all victims. Large companies with revenues above $1 billion saw attacks nearly double from the first quarter to the second, going from 23 to 40 incidents. No size bracket is getting safer.
The most significant development is one that arrived in late June 2026. A cloud security firm called Sysdig documented what it says is the first ransomware attack run entirely by an AI system, with no human issuing commands during the operation. The AI, which Sysdig named JadePuffer, broke into a target server, harvested credentials, moved to a separate production database, encrypted the data, and left a ransom note, all autonomously. In one sequence, it encountered a failed login attempt, diagnosed the cause, rewrote its own approach, and was back in within 31 seconds. A human operator still set the attack in motion and pointed it at a target. But the execution, all of it, was handled by the AI.
None of the individual techniques JadePuffer used were new. It exploited known, documented software vulnerabilities. What changed is that an AI assembled those techniques into a complete attack chain without a skilled human directing each step. As Sysdig put it, the skill floor for running ransomware has dropped to the cost of running an AI agent, and if the attacker is using stolen computing credentials, that cost approaches zero.
Defensive AI is not keeping pace. The SANS Institute found that 78% of security teams now use AI in their defenses, up from 50% last year. But 63% of those same teams reported meaningful failures in how their AI tools detect or respond to threats, up from 45% the year before. More AI on the defensive side has not made organizations measurably safer yet.
The practical takeaway is straightforward. Backups stored separately from the main network remain the single most reliable recovery option when an attack succeeds. Involving law enforcement in an incident saves organizations an average of roughly $1 million in total costs compared to handling it without them. And the decision about whether and how much to pay an attacker is complicated by the fact that data is often deleted or stolen regardless of payment, as JadePuffer's attack demonstrated: it generated an encryption key, printed it once, and never saved it, meaning payment would have recovered nothing.