Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ransomware victim concentration remained dominated by the top five operations

Trend
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44% of them. A small set of groups continued to account for a disproportionate share of extortion harm against organizations. The pattern shows that ransomware impact was still being driven by a few high-volume operators even as the wider ecosystem kept changing.

Related Happenings

Ransomware ecosystem fragments as new groups emerge weekly

Threat Actor Meta
H score47 First: 21.07.2026 16:00 Last: 21.07.2026 16:00 Sources 1

How related: More than one new ransomware group is appearing every week as the criminal ecosystem surrounding extortion attacks becomes increasingly more fragmented and continues to expand.

About this happening: Ransomware operations are fragmenting and expanding, with more than one new group per week entering the market and increasing extortion volatility. As of June 2026...

Qilin consolidates into dominant RaaS position as ransomware market reconcentrates

Threat Actor Meta
H score39 First: 03.07.2026 16:00 Last: 03.07.2026 16:00 Sources 1

About this happening: Qilin is consolidating into a dominant RaaS position as the ransomware ecosystem shifts back from fragmentation to concentration, increasing affiliate scale and victim vol...

The Gentlemen ransomware group’s 90/10 RaaS model and rapid victim growth

Threat Actor Meta
H score26 First: 10.06.2026 17:03 Last: 10.06.2026 17:03 Sources 1

About this happening: The Gentlemen ransomware group has become a high-volume RaaS operation, using a 90/10 affiliate split to attract operators and expand its reach. The group now ranks as...

The Gentlemen RaaS split exposed by hastalamuerte

Threat Actor Meta
H score25 First: 19.03.2026 18:00 Last: 19.03.2026 18:00 Sources 1

About this happening: hastalamuerte exposed the internal workings of The Gentlemen ransomware group, revealing a Qilin-related RaaS split that shows how affiliate-driven ecosystems can rapi...

Latest development: 17.07.2026 12:00

ReliaQuest reported that The Gentlemen ransomware gang became the most active ransomware group over a three-month period, with 300 incidents and 1,368 victim claims tracked across 11 ransomware groups. The analysis said The Gentlemen overtook Qilin, which had 289 incidents, and linked the rise to aggressive affiliate recruitment, a pre-packaged intrusion kit, and AI-accelerated development.

2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates

Trend
H score32 First: 17.03.2026 23:41 Last: 17.03.2026 23:41 Sources 1

About this happening: Ransomware operators are increasingly leaning on built-in Windows tooling while ransom payment rates continue to decline across 2025, weakening extortion returns f...

Timeline

  1. 21.07.2026 16:00 2 articles · 3h ago

    Black Kite finds top ransomware groups accounted for 44% of 7,551 victims

    Campaign Scope Update

    Black Kite's Ransomware Report 2026 says ransomware victimization remained concentrated between March 2025 and March 2026, with the top five operations accounting for 44% of 7,551 public disclosed victims. Qilin led the period with 1,358 victims, followed by Akira, INC Ransom, Play, and SafePay, showing that a small set of operators continued to drive much of the observed harm even as the broader ecosystem fragmented.

    Show sources