Check Point ransomware report signals rising AI use, faster exploit weaponization, widening threat landscape

Ransomware activity remained at elevated levels in the second quarter of 2026, while the ecosystem expanded beyond its... The post Check Point ransomware report signals rising AI use, faster exploit weaponization, widening threat landscape appeared first on Industrial Cyber.

Ransomware activity remained at elevated levels in the second quarter of 2026, while the ecosystem expanded beyond its leading operations, according to Check Point Research’s State of Ransomware Q2 2026 report. Data leak sites recorded 2,139 victims during the quarter, up 0.8% from the first quarter and 33% year over year, while the number of active ransomware groups increased from 71 to 93. The top 10 groups accounted for 57.6% of victims, down from 71% in the first quarter, indicating that ransomware remained concentrated but with a considerably wider pool of active operators. 

Qilin remained the most prolific ransomware operator for the fourth consecutive quarter, recording 279 victims, although its victim count fell 17% during the second quarter. The Gentlemen followed closely with 269 victims after a 62% increase and overtook Qilin in June. Overall, ransomware victim volume remained elevated, with data leak sites recording 2,139 victims in the second quarter, up 0.8% from the first quarter and 33% year over year.

Check Point Research found that ransomware payment rates fell to about 23%, a multi-year low and down from 85% in 2019. Despite the decline, on-chain ransomware payments exceeded $820 million in 2025, while the payer market continued to diverge, with average payments rising as median payments fell, indicating that larger enterprises are still making substantial payments while midmarket organizations increasingly refuse to pay or settle for smaller amounts.

An internal leak provided an unprecedented view into The Gentlemen’s operations. Chat logs and platform data revealed a core team of about nine operators supported by a broader affiliate base. The data also confirmed that the group used AI coding assistants to develop its ransomware management panel in about three days, providing direct evidence of AI accelerating malicious tooling development.

Check Point disclosed that the market remains concentrated and top-RaaS-dominated, with Qilin and The Gentlemen together accounting for a quarter of the total (25.6%). The easing of the top-10 share is less a structural shift than a set of softer quarters at the top, as Cl0p, whose mass-exploitation of Oracle E-Business Suite (CVE-2025-61882) helped drive Q1’s concentration, all but vanished (127 victims to 2), and Qilin, Akira, LockBit and INC each posted fewer than in Q1 while the mid-tier filled in.

“The criminal ecosystem does not operate as a stable or predictable system: operators pause, retire, and turn against one another (the newly active KryBit spent April in a public feud with the rival 0APT operation), so a quarter’s group count and rankings move for reasons that are often not structural,” according to the report. “Q1’s 71% figure reflected a temporary combination of factors, including Cl0p’s mass-exploitation burst and a spike from LockBit’s relaunch, that did not continue into Q2, alongside a notable increase in law enforcement activity during the quarter.”

Qilin remained the most prolific operation for a fourth straight quarter, with 279 victims, but declined 17% QoQ and lost share. In June, The Gentlemen ransomware operation posted more victims than Qilin, with 116 victims compared with Qilin’s 72. The Gentlemen finished within ten victims of the top spot after growing 62%, while DragonForce held third after growing 39%. Several Q1 leaders declined sharply: Cl0p -98% (127 to 2, as its Oracle EBS campaign ran its course), Sinobi -92% (80 to 6), Play -70% (121 to 36), and Nightspire -60% (82 to 33).

The number of active groups climbed to 93, a new high above the previous peak of 85 (Q3 2025), and the same volume spread across more names even as they maintained their position. This pattern reflects the reshuffle that followed RansomHub’s 2025 retirement, which sent displaced affiliates to Qilin and the other surviving majors.

The Gentlemen’s ascent accelerated through both the first and second quarters of this year. The group surged from 40 victims in the fourth quarter of last year to 166 in the first quarter of this year, marking a 315% jump, driven by pre-positioned access at scale. Rather than opportunistic exploitation, the group leveraged a large inventory of compromised FortiGate devices and VPN credentials, paired with an unusual non-Western victim base. Leadership reportedly

Source: Industrial Cyber