Ransomware ecosystem fragments as new groups emerge weekly
Threat Actor Meta
Summary
Hide ▲
Show ▼
Ransomware operations are fragmenting and expanding, with more than one new group per week entering the market and increasing extortion volatility. As of June 2026, the ecosystem had 146 active groups and 61 new groups in 2026, leaving defenders to track a faster-moving and more crowded threat landscape. The shift also shows that a small number of brands still drive a large share of public victim claims even as the field churns.
Related Happenings
Ransomware victim concentration remained dominated by the top five operations
Trend
H score44
First: 21.07.2026 16:00
Last: 21.07.2026 16:00
Sources 1
How related:
Despite the fragmentation of the ransomware ecosystem, it is a handful of ransomware groups which continue to dominate the market, with the top five operations accounting for almost half (44%) of 7551 public disclosed victims between March 2025 and March 2026.
About this happening:
Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44%...
Ransomware victim concentration remained dominated by the top five operations
TrendHow related: Despite the fragmentation of the ransomware ecosystem, it is a handful of ransomware groups which continue to dominate the market, with the top five operations accounting for almost half (44%) of 7551 public disclosed victims between March 2025 and March 2026.
About this happening: Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44%...
The Gentlemen ransomware gang's affiliate-driven rise to most-active RaaS operator
Threat Actor Meta
H score36
First: 17.07.2026 12:00
Last: 17.07.2026 12:00
Sources 1
About this happening:
The Gentlemen ransomware gang became the most-active ransomware-as-a-service operator over a three-month period, overtaking Qilin with 300 incidents. Its rise...
The Gentlemen ransomware gang's affiliate-driven rise to most-active RaaS operator
Threat Actor MetaAbout this happening: The Gentlemen ransomware gang became the most-active ransomware-as-a-service operator over a three-month period, overtaking Qilin with 300 incidents. Its rise...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor Meta
H score39
First: 03.07.2026 16:00
Last: 03.07.2026 16:00
Sources 1
About this happening:
Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
Qilin consolidates into dominant RaaS position as ransomware market reconcentrates
Threat Actor MetaAbout this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor Meta
H score26
First: 10.06.2026 17:03
Last: 10.06.2026 17:03
Sources 1
About this happening:
The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth
Threat Actor MetaAbout this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor Meta
H score25
First: 19.03.2026 18:00
Last: 19.03.2026 18:00
Sources 1
About this happening:
hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...
The Gentlemen RaaS split exposed by hastalamuerte
Threat Actor MetaAbout this happening: hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...
Latest development: 17.07.2026 12:00
ReliaQuest reported that The Gentlemen ransomware gang became the most active ransomware group over a three-month period, with 300 incidents and 1,368 victim claims tracked across 11 ransomware groups. The analysis said The Gentlemen overtook Qilin, which had 289 incidents, and linked the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit, and AI-accelerated development.
Timeline
-
21.07.2026 16:00 2 articles · 3h ago
Black Kite identifies 146 active ransomware groups as the ecosystem fragments
Campaign Scope UpdateBlack Kite's Ransomware Report 2026, published on July 21, said the ransomware ecosystem had fragmented to 146 active ransomware groups that had publicly announced at least one victim of an attack, as of June 2026. The report said 2026 had already seen 61 new ransomware groups emerge, that active groups had an average lifespan of 4.9 months, and that the figure was up from 105 ransomware operations a year earlier. It also said the top five operations accounted for 44% of 7,551 public disclosed victims between March 2025 and March 2026.
Show sources
- A New Ransomware Threat Actor Emerges Every Week, Warns Report — www.infosecurity-magazine.com — 21.07.2026 16:00
- A New Ransomware Threat Actor Emerges Every Week, Warns Report — www.infosecurity-magazine.com — 21.07.2026 16:00